sssd-tools-1.13.3-60.el6$>A>.m`n-d>2?d   A *HNXbb b hb b b b!|b#fb%P%lb&'6'6-6(-8-94:`GbHLbIbXY\b]xb^hb:dIJeķfĺlļCsssd-tools1.13.360.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password[)&/x86-01.bsys.centos.org sCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64P02H0KSA |5r#1FR :bo3^ 10m:+}MHOt ?tH dC A큤[)&[)&[)&[)&[)&[)%[)&[)&[)&[)&[)&[)&Vpn[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%f5c397f38b0775d0cc31c67a713b30ac4c3e8fa5aa1bcb2b98a925080546fa83b94df0ad7e7e6f501583bcaf112d7f37d9a581e72ac22d193501a1f0cbe8b4434875ce29300797ea14c61a6f5396f574330416512a85246c7e01981a4197413242b03063b61c696a558cda4617e82a7c02b5e13948dc9edce397d1a7491e8fcc1d2010459a97c7ad5bbb048b86030355c73e0235c8baca4121f7841274c5bdc7074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45eb180ba6d581afaf319858c367b19f92a887d40697918e6e10cfb37fb4d3d5f69650d72d90ca2e9d64239f9e5500b2ab18a9fc9bdb32fc4d187140ddba6a6f56156350db3af3415feb9708cdeb7b07beaa673c8454aa23a6d9e27264c5fc18a308af39eecb3b573cb1261d1d1ff797e5fb5c461f7fa6566c2f2c9588ed52a215a2044d8ee186fa8e993fb3407381b7d1781e764b0aeb22c6a8e9fc193fbb030da8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90312faa0bc15ca0607109277f9e39c1d5b3f8f870b22ab03d9cd843dcb4937f23c898d9b4aefa781bcf8722e504fc5ac11f5d42eae2fb68dfe61122b8f98044a5d3d205d14a01e31bac7159e1ba9e65e1cd92e17b72af1eefd70fd8129c07bfa32a37e4f153c7948135315a93ebc523b5da3ff74134e37db1e58707f69f285995751ea01896d4b36ebfcaf460822c8e1fac3591ffb8062729702047d1feb185eb0306a72ed47048c15ba94b54fbe85fa0488662543060326e892178173483a35c79a25c04eac19642dd5c1de9c5715dca1978179971b917e21570b05010d9a51b6cbd6c2adb56fc77c0cb0e14d4575c99b507f6258409528ee860d6608f5a5f4e68fb90fe31e5abfbf19ea48c634aeb350f5c77d359556d5bddc40dd343e3210c50d992b8829d02b047b0aed7fbdeb05437563cb120618042e1607c36876699b64bb8e9a900564768929f88d57e798bdfdaa250ca225e051773c9cb698bbf9cbbdfce91ac10376053bb29a9e7be4ca3d0b44a5ee1c40066c9053b648581938913e6368ecccfc089afd5d2db3d4a993d685c9e24df43ba9b89905ef3da0ee317577d7359fe269dd50ceffa06e6d8b31d815fd3ffe14624f40d30bdedfbd186e803c731156edbde991952c524cb249c9291fc6f1f32a72b048bb8427ec889c6c3be2ae986e869623bbd719ab0b78d7f55a1c56ecf6349e6d4bd126636f890b355e35139fff8021748cc1c1f839ba681f08b2574bb6c7a5c95ed81a2eaa4f92cb927c5eefd7f14a2fe6dffc5e3daad37726aa63767189e2c6b14db2b80a8786fa81166f7519010c5f1a629c2b526106f60aa71352c22deac55026791058021208a55563394c60ede4701240cb3f1ad645d2f050d3fd896243dbbe21d0f918c1ca668ae1442c3ddb536dc94607fbff11a1653b979831a1ae879514a37a3b2967dc68bfa063fbf3e17dcf7a075908f24983b99d9a29ace2c27dc536673bce4f5c295ce806e2e3eca024c9d1c81c9ae926e676c74d2cf28f27cf696877a1ae201716e810a34443659f203bcc26033c99f1f44f636facad0a96186f185c4d00472e1feabdccccb36026a8c926867926b2f2c7a905415c3762260d12af95929b9446f51a1173bb88ad62e35bdb2a27feaccfcd7d8a24550b32aea3537e54e46866edf7a7b325b4546d68e849c368c0acf4416aa1683d9316a636f7a296424912a8943bda31b812282fd97808def916ad5340ab1201943355c75a31b4f60adf5bdee206dbb704998e25bb3b089fba27be6304650028b61ba8fa12f9bab1b7bbb5a94afa96ba8c6775d4712280211e0787dae108363ef3ba1d60b97e78a532362f0ca7f151995fcb93b3d7179c666a6f1ba4374e98880f3999b0d4c18be0b8c5690755ed6db5ffa1f41dc2848390ce1c1adc16d936d3bec7678d75df512aaa8c65ab05a2360edcc4f8eca8c6c7856f81172fafeb7b3fac9f6d2e4fcd7d2cbb3ee71259899900c70a0feeefe148e9380948617378f68caf855a74c6210ef6975dc2076f80092a54cd54279190b70df0e6ebafcd73e1d78c155d693289d3cade81c583a8b861197472ab6727f10207ec4bba8e70931c3c7fe84ba84ebcd657e3aa3058a8e4d1c9d3e47121dfed2cec72d72ecf81cebdc0e3c304edbfe18e7e03a8c92485d1b4dad2edbd20d665af641b9bb99993a41b4706733028b299fbcbe78c8befb5ef5395daf0302535a4b8b38a528c2f5e1447f05fea574c180504982cda4f30526999f9b097ae202cc188ff261fa7f8bc26dd13fc4e5699c549d4b181ded57e3c0720a9a6296ec70ce1fca467a8b2366d359e5f58532643db85c3896c5c2c2d3b2c68a41a713c4a4d055f6b739e2f6e77cf70dcb4307e82ae2b8ad9334c1fcfacf837e1de8cab1147201585bc8ecf5be5e1455af4c28bb081336f004cba4aec2e96ba5e93a0d6e9c554d9e7ceb6b78d89972e86b2f77e4a47c248930958cf35de382e8dbf61346453cd71b6673abbe15a9b68e0e1a9ca23df9475f8a49917be1474c238557624a79130062f62e9dfdb579f972293dec8ae2a4f083d349d624bb2ed68c952191737112f04ed07bc723c327a1cb950c81ebd12eaa17a35822e9cfa00211406f322dc890b40a04379300f907e65a8a541e706503102f4d8a5af3254f5a6f1c3c7cec4d9cbad94da713b12a9a70fa5fd5546dc97fca80c9f3115be2c4add4cbf8f405db62bec3d0a323d50892b5ba8ffe43407551dbd8be7a64fb1e89a335debddc88ddd59e8e10bb135e896310e43b55570617f0a750f8849740a7ce5831149544e5e45a8f85569ea29b3e521f27a3cb1418e8876d29be98db14b44c0e74c4384d2648368c6865b7de8bf97e183dbee9b1728ff2d7e085276f99c941493af78689d832a08118ac282947260339f85171549f5e1100155814458cb6ccb5e4494864990e6c2563b101fae7d70d85bb6dbdf2ca19d730d5587ce1a2b573ef44cc773338518ba1c10a4931d658c8703064c62c50d49c1dfe8e9053e1b7fa95856453a88e1e1cc56ce71772e1f8305d88fd591b2e437681a88c3f49d3ba9f0eea405562aa031a6fc9811410efde0bfb9150ab93167eb0c9742125a7b83f66615b57dc7c57da2d15b1bc49d4a2cab4a8f47af7ededd50cf8a6cf6c809a8fae4098a5d6d24a551458fafb42b3163c130edf0bc9424482ee50fad0ef35016888ee1ca7048d44f71c7f73ee5a535970fa8ad4fe6168897d9cdee7c7fc629f6c7ebf6f91d868aa237fc7eaded2b930313137764a5219ecbf43cb34c44edc46f9326f87fb8486c9fa7474184b14cfbe9a56fd3d94e453c3ba02c7da36cbc5304673d0b710fb0bf7685c2302ef9dda9600b606d122e91feb6e2186fe7b23dfad9d4119bc602b63b8fb841e07302111c6cf39ba94446af50f58e9389102129288b081d8e1273b13c622d958c18edc37fa36dda60f9af3cc4263c599c7b035a514407053884423412536b3126aa677c3994edf5f55e3fb0c4f1827d3ce5fe136083251bd6f207128f4919b7eb764584baacf0346e75f3467f9a1e0664b128b2ea2528ee22a48c7d1b360bc1493fead5f8a43f6a1d9c40bbf656c34abe221fd89740c6da946685148f966c8c378148f13ea8b2353d7c7737a509eeac64aa79423d69dd5e48e3d1ce70b89c012ad0c5ff21e2cc508d6cce293f343a1a9414d42a5e7ba039f982dc70c8c003f6a0aacf3215914efb1f85dc4ad65895b2a883be102f5bffd4b5447d9ece7b535c19112dd777d4d068848d84c51b13fd220519b87d8379fb8ad63d81f1f3a691e1879844a81229da8aa389b6e7236ddce33b6fea7acb7750642ebedf61beaff107e4d53e93592e5d84b85fad07f27bfe720b52deba680abc81b1729a6b6cda7f08b92cf7a7d61acb16d925390d1ce0a2ee2cb19d3f18245647d8e43c69c4b6309ac78ef674fbba769120dabce7cb535c2b0cf880ca163296d752dad7e464d6ad704c850b3804c8ec5b4355c88d8fee9c8b049b55558229481c0f7ec0ff83f557336738850452169ea02047a437e71c085aa5205550c9c5b54d77d51ee2f4e2ecd18c39550b260db95664b1b3eaad40ab0c33dd1545e3eb66c787d6fc4fc8a07428c12300db06f892645e41a5a2c1268c46db363ac492f3eaa69246ae4f4e15e6915f5e7648ce96721b7cf53f7a3f9357e26e15c0c58888370719041f9c5c098919ce2a37957d10a735a02e828cb555ee4b1371fb1e8f2459dfd94495534a2aa3529f515d066ff6b0051d70515e53b3cb52395128c684923c1a86de81bce6f77ade86fef840354705b578b2d4ce19e6df1becdaa80b818c5bd7236frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-14.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el61.13.3-60.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH63]"k%}:w{!vQ_99eW@7ap#ifF,oP'NR~o2{ڤ/kg ݻyJتdCʋ{̜q/s5D7LY%G $ p g޿T0JFKE*s u .+006n4oB냀u^I h|JZXb'*拨tz^S*!t!?f"b/]+F&c僥z+m*L :蕢"@s{ Ua z KTdTmTj؇JR`q4}US8j|}-^5c)9J(Lۿ m6PP#aK}ZyJ  .5C܍dA: %ܒ՞>[*ԋp]ll ZKl٦w'?Oo 3A[K[;O}c*y4iW5gԌ:c!vZn (=:B/kLU/PÖ09Ǧ5koU0cOa6mc z! &L—d]`~p% ݱ9›yD%7f-_Y5-_Bv$R§PBtn^6EߵrXږٖ&K>%+O>|/'R:x4Q ,Ӵ@67NwN';!Mt2Q0-Nn|ږjFS H I:!UzR[t9.|LoZ$"MYYS%M)զ$y>zzr9etGgWN ZFYW).I[h&w c`]q nM/Gy6!?&CmُOP"3j]*-#P-n3zyn2I6cQҍ&-mt [讗ml~1a_[Xa2q+`: mΙ[՞#xSY'{CVx17t m'0|9ɍk &(omhϷmeC܊z+=o8I٢WQo&pM!5Ք.i j v.Qq739>a ӨH.K-/[.WיKV_ZU;=eksPQ5Hэ]s'M6CZ' .qtEAcFLG`G.:n՞Ij C+d3S\J}QI-% zRLhowb 7iû/5'[5pXdc-U5{3%w2|8|]i'a:Y \fvFFc$YCCёܖM\'nԸ}<)6D?E"1f)&c0D:Ӫ'YSIY5%H\5*⡌i} f*銼 U_ڜ)t//;~iu\lҢGdg\H\Xm)0j,хjsнVQ_O-9=,YS^HuӒw U/I3鴬YQ(ʘmz]Gdk:0Jr*0NĄH&ָAnAlI騾%[y=R%mokvrMIפPW)+~9?ϰ$}BZm[<$!h$\pp>lO(bJGL6qUQ#u*_Y :R0w|}?7:cK>._ iZS Z[U=/ܑ~ Ӕ{DI5ᜊ'\<&ve5d -PT~(Y HT`N#e?$cy6]0)(IɇZbCLObS +kb~PvZJ\L6İʓgTNӶuefe>bMIP,S9fm& nm_6'tÙtN݇ 3l =I(p/UX=l&~ J[ՀiĦej|E/\ $q?cbv(#pP u²MoB53ުLkR9C(Aӫ,AGO3N(6N83ބZ_;_ݫ$ vO0aZO*ճ#yp4=gd=FPiT)Cq:A2)h UG NlSG -q$!FBI~тQ;tqS0 e+H mk!DhXh(ác,l{mz^1l8R"oUr9\#RwAT50iZJ>__6:,s琹:x ޸IʬMhTZ˹%j Hp#G %qbHqKDiR`>ޝXȐQzX8 ^LnjJK Մ.IxIPG;ErB}cˊ\f_i͒@4.t(m53X-jMXxѵܓhԳ[Ykk7ݬ_KGcV^{\w(e^k uoJqXۜU1J_(cP<`p^DK^{[7~%adӸȮ}`$-Ec4ٸC>$a0vav^7%}fn:I5i]ؐ_]զrH9F0S{?mvS't{ 7 VL< z?LTFEu5hYx$FG.QArw`$ؽ@s9, "2gIԭTtʿvuH䰥h!4u QLfTmEd3m w o2gEž̂[)Pݑƕ#[[lov;0kQ5,bmA ARYG bXYrA}i* 2!ɠJ=B -ƙz ޮ(#&DFG2l[̰>lN /? ,X#&Id*E_CnEL)/%bCH y~ϢŦQn/zmerA*P?Z4-O|>YLȎJEOc,QQtI?%ƒ.aBX̍@wG. ]w!cQ" ʟahtk Z+[T =6rQ3@Nzʿn4zZtfh4zo5b3{J6CUmVBa6v UY"l3{3Uv*<4S7ۉY=Ug6MmQɈUQ}"2o:+h tyC1"ߜ2CdU˧ikT·0&Gi=F8bb[a]џfc*bg%  Kc_;!!oKavdQ]\z Kϑć4}vek v4UIy>>U ]zY ĖM9Wrew5Vm L+jYv캖cdž@yCѳؠ𞍗F|/)Aݺn3K@s uzhnDodlY(Xt4!-+ĕ"[P u L7;=\"S 9?U?Mq:n\}"RHuB4}r+D6k]ЩQuwjv*` Ndx CkmF+ kiRߔi%,F|^ל8G$5,r@|i~*<^JemlKd1Vp}9*v[b;1)_]ruX.zpQYƀVGtu#o5 sypjf_ ێWqc.-v2uXyspjPT.Q|I A 27|8Y@8?- J"oŞ rrQ_ףNHVJjUmIz^@F(Y82&RͿ]ȥV-I(]`|¼ay0| o>ήRHM[h5B>?V:6bpfբT6v Ζs8_{4ZIfq:6@DYc bF4՛_V#9#2;UPIO|#IS;0M5=˾&I)KƴS]NT.k7{ƣ>nGh\,"r/8ov1NVRNӰS\@S հC:}G wMlOIGieB ~{5CDQIPDcbKZo\tǩ=¸%V4՝lh[w-)%FK꼪2kz4leQӊkyO|;!7AJC|\c#R(qMJ,mʠ&G&)(j OYM&*{UV5\҅ioͮ@BQzt3p "9:i%J[)Yq=fb#'|,8>A .:s(M0#cwWZ ?o/R4"@̊%^ Nַo?9F}۽- H[[OX*n1R;(q!]:JăGY*u$Bv/ b=Xôii\Q4/2\G]䏘ΤM5߼1Ht]RYnZ*EؘI!M8]YK\cd 9ps,U>&OE=)b˜!b{C:)m71 𔾡+xۼ߽G7,~MYb x`M?oykq$rx(EY8 k'L=k\(я]@_V ;#Z; 3G0+$jy>4f\ W`{t~K14,5bYw T| v pc2uߦa/X^O~JVsv ?*_xmE}9εV'0V/'IeN  ÖSnqTH\?.ɱ_`+yXm0,62Lugk~TшjE^h0%@Jl0KִcrZuC1A@򴠏Ta2R֨wX&<wO5@CK~1ytk9XBu ծaY7"j ;yl)a_}*w>T CsAޝOP';M,Ϝj6( hXWphL`& Kw[w,YD[o5`,7Dr[ י[$)P*:`@FXQ4#>vy6;Ee`eÀOzqB^GLNaKMŀaǁquF[TEKr)y_Wh9ϙj,*ZJ8IYǿs\2/`[bsO.'#j3u~Iȼ ١!ۥ+ <ۚv; .V8òV<9q\G]HP/ "]of2tsh!wCT8/UF)(ifE6 8#4Ծ{2 *l6E/,=c|Cbnz^V7On++S{0]Ȓ|41,K tZzB͐b夶^JK8#'#'P戹κaKSa\ݑ Ԃ$*uI* ݨ{۴_ς}*W {\>e;S˫4yPO՝axO@pC9t<\AmwNeñ{_]Xg 4#<ϏT#҅1Hؓlso ,YH?f)_'o⍑Vɱۋ/NՄ/D9ݻS^ YHmLvQ$8G K;c{3sN;P='UT.XT`uΰd3h:8)v*ސZ^PAo۩r44'iҘF Qj1y[f_Uَ F )=BQfC_L\AkQ̊mhdv2}lՅꐌYN>[KF] _^ R1b]aU/џ^ to<1ފ,:pc4!<ڐ)HɒBaJ CptgCr[%k'oN}o+iRΪ9`BIq7I.<ClUe0eʿܔFH=:dФRznC<\@'xIZ^-|%O}_kc^Bm D_餹HV/Vs",C X %~f% Y&[[3庶uUaվ,5Z9AR;֗B퇽a>'K_iaLЃΙIKAяg5XsLq '̕iv]+G`C1r1aBHU+Bdp9Wxqv`4<#C,/Wv|ι o(V=>6sY7ě匿8a+'LiG[yhJ7S\QƎ?XCح5<  x}@k]?t$ƫa;N]"g829 #=mS?=(G _}<S|.9|c"ƑҔ{e>? rɻ(K{}J /Dr c̚z;&(Y":p[dtN"q%ujrfm4-=CC;¥s4ՠ'L7;oŧd KĻ@ ceڒ%4^Y,J[YڧT_1 ,ДjsJ,7A7 ?-5g$*nݘ@qiYD[ ;-8@tD8m/K _e-̃:4׉Êo W `i0A#Gd.nV5sJpk_ .F<2o&z)V A7!/MZs,2j<O7rN\qxQ\%3JR8:EFbKXh Q  +tS^e_zꓱ ^l E?ݖJGTћ\c&r>mZM 8a,?@ܫo[.g=zIώW'!Rn"&^O:>gV7jD{dV1lu}qa'9G,K% x[*/&׷k]?]d8AqC2 CW hg2'BaĒ4[FJ@ū.t&RP,r)̋3s]kŵGJ&7_d6BLן1ǙRj@ۢ  vL{==G,i匽m\TQEPgj8 w bk3QAd#k%ט"!W)I>mS*?+,ߑ+ѱ+>+NomIS= f 5Ў m;d'8 OG0I|$'Rп&,vf9Ā1\ _lưoR!>n(|&^0+}|ܴ]Wmƫk?DAk^#'_1a §-5S0dZn*LZi -&ڡ@98y^y>Ifv$~sf=s:[q?Z{$>%WSuNJNQ d=82i% :Et.:=-gPhúDe],HK@ZKfd2"@vXiuރư$rd^?J:L.j*TŪrGHq,\=@bTҔ:]_#1anpĔJҙ 4H i_} TKy7B)N,_?i|PO ud2%y26:Ph 7XAH>dT?a7Ftf*dS N6O.6BtHl+@@ڸSEn)7]V.N.$sQL0VХai熽mJ9. UNk'Ug[[ݛӤ[q\pZR*d v$*BsN< r)fgMLCm0j^SWP{҇gHEdb inxNJceag#$җ{Zߴm`z2zo%&b۱^=L줐'@-=jCf$ |i$e]Wo"vK޲1T[`y|t?;E:aDw( HAU9'UV*ӵRw}Ř#Jn|mw~pbqMDݺaedY]h._IMAؚ>lU2UDq n@ɓd}lg<,"tgz;?"e=e&VjU_Bhyl Ÿgѡ1Et%a}xh*_CnL)PV.H)p-8h\:cҶ QER9Pt4}J$BS4+*l2j 0a/[j5k쑧CDRѧFm"J'c|KVTdcp*LK8k5̧B3#- "¹UKtiHZNP @|`;͌$M[F藵^~_/V|kJC oQ_PDJ!A3V6+4KSF&3:,"6+p\E,:P+H#Z ^Dlʿ@rGi[m-s]L'KTl5WrXZq̒17:zyNN]E'=o"`9a.GR]3Nr>.%/1Nԯ äc9.ZT\Yˡ <ؓb3 |ԃZZꙃ#=4,KRP]_W+Q%qbL5mARDEnvW+NK=#6r|BpoY3rQ숱O# > lmxl M*k5!XEC" ߵ3WR8auͮN/eZ<ZNquv?NiXxqz<.78XAi08#2iGщrw'xҰ+ʵ?YY9^1%3axI >e Zա`Hi}7 ZRW1Pƾ'@);HOq1<+(*3`MbrbmS%l{|Xi$<ˮյlQԼ@UVzӶ-=,{ L\c) *pY=[]1E4ԋD*:9PXQ_V_8W-y Q>VqS#,5}&c=2ު],HHe%7TwfKuC͌/6כL03*w8S%t7y"ZQth=[)94^@5.2|cxi( jo ܒ9(X揰(! @dg*Y6U6X^k5Or|`RqؐBBG4qNzNwh?#x=@C\(ޥknJ( PynY+ ܀=yqAsq9-JSdz*]Pk„.{vvF7jtQCO C gEzlvm44-"Fdzo#e&:\l6aD%0fY\Bcv*,˻r$8AR(ʵf3DwH@Ⴣر as6]ڜS T56}GUTUG)ހcJ"ۢ}J@*C1BF%.* {GYUAƂa*VrA'O1vئg2y)V<0}~1oidZj|`NC`LA_zDA*J m w|w s.U3}1>nv5_1ūLD}3MNbx" 5nvNj4 |j)1 g@F.+;e3Y{CvDns]2g7y,[QVT>Fxg PJ"<'ֿM-X]]E[9tMh_yY4[@8ebT*֙mQ5OJƒZlW&a]'3XtAAG|\S?$J;P"0s20>gNh3!?­ Ճ%̠}uQ>+N263 k;.:ؖl?g_2m1̆0IjZaH`^߅M\#'==e[֥j:3ۨ+ M{jwkdNi2Ad:̟XoCabP+?7]3m">FF*UIzh;D!"gO8D 5mKO} qŁy\} `kW0 ?=|ľZ|ކ {|_=eӼ7Zfcu)ȁl4IrWu;7sgr4XD2Vn*1"߷{ڤ/ޮʆ J (RƔaYcA}z3Fpyn] _-F]{2Ò^2+@r2w67btw6^ӓUvM%X>;ί 5yj*Eq%D< bJsL&F6_ʭ-KHINktgCFԬpFQ?U=%D[|;F9Ի4[4u -n{}ߴҊEmrSQΣ:"h@~.柁+eb2QWBGT.cZbyc-ɖ<-QD}TۊSTN@I?SYsAV<2wi~RfrG!p^<n3Zb('@E!_u*"iڸ֞$> H`,*q d6E/kfʅuTtEjYUG{`S%%"~EކYEż \'eu{)>gbM\t@j+\ӋzU.'KVh`/>B?RG6XosNk$q<5f)Vf_wQI05w,uk-Dc3KeݞTA$]4h^՞.3''(Y{%0~{AhwI!O l5z7%P Oau=K״U1Wk:c12Ztj|3ؽJ =jPJ&E]{Cr7MJDጙ 4A&Ies\]bKCjXD  ~Uא.`- PvV2;΃2eU)7z-8Gf-:Ug&a^r@5$]ڹ!SJxjgtC]tC:R{nXaAo~Q0s+gBm\ K#&q`{:̞Mbi[4GM*4G"W~'': $: Ӳ"awN/< B e-M /Ų~Y3L58zzh=oxn۔p-Ok_"g,P[w%|ƆAȘ |{HiA#FU*Rʑ74sǨC_.bP2oH${zM(~xѼk;6DJo Dw JϰIChqqnZD>[o,W@#!(o8k= =M(PetJɤ*~-f@`~ō,(w*(ޞ9g%85v3bsC Q7^?f)3$Ar% oۀ"ɔ%n{G~.`qdJi:+֐c *{i~!ctxD^(1|Y׵j'kVzFR3g9 )oAy‹Tm`j Z`Dyʐ*8_#@mlp@ZF]` fcb>ܧDkuߛ@-K?tMPUl9 &fAhVhܹn" JgW) )p҅j.6z"1`$UF|`\yovf)o_0'6 oA_|W2NGd9丈eǑfHVha(#\,IއNTYr%W\uv)Ƭ-k~!^ $ڷJe@ @&T`>$~/@,QvZ\~=ںsJҤ spH 4Bx~U۳1OH-h0G^k" 6m*% YEX l(s@XthTx"bw3GnqT4Dxofː7"<*cov& xZ E7* AU۝ L:x̓ ă%dܗ,u.k], aH& 19"3'F `5WVRbE>;W.A|f;*d*5E52ޗ$g 4tqz)7eZcVZ%m*4^;":٣9-T;<{Ee`t.ɯmA]WgI QPGjx9Isp _'<  o+otulBu~KY^3`q. :VirW2, PW\-Ӂ~[BnmN*CM;t v h@k$Ѓs{wjV)6?S/&Ȟ1Cz"aEC!YhL,{r7|01OF,1&tYȱSa;IHaP^(]ǻWroUih﹠px˟oYH C :9o vbkѽl #`#{;bϫ?.YoQ=?6Nɔ3GP&9l9'˃\I[ a^ [=P >s|Y𑱌{v;#{;)Y H5$v%Xm7zٗQk* /c,s )7U16X]1Kʁ >m_1VߚM%xē`u9j6pJ,;بAw䓫6:\Sd,Qkzv9=Ös+r]KlFN\JCHohE!. "ֳ4 34"B<4)xoPpdĸJ+kpfjg`{CRHJRvͦmVhG;z pW/ۘF|*VS$*$asZrKm44KԮbН%[ (@ %Cbp\V3WXspB[}Rz/ P^ A1HK55), J)K hض(>zPSbtcE>&%J;5G !"#Ng\0V,k~L+vjtJK"w*6,aSɮQjm@5S |";J}i<ߤ֙\ }QYZxqFd?;"JR 1`PDdr3 _w|"tN]\X9W@ύ$asVxe ë9sb4-3q]=HNIf%:B&CuIE0}k*P5s  K%K CdPf)I0~ZXEyݰ_^7(2=$,rdh89~I!,(,þz=b5[B @X΅!` s9ɩ?B;: rKICί#`5 Dž% PiZť.Sy#}D݁ҦFc{;(tٰᘏԍ5h81i:0l^7ѳؒi=wO4ŏ{ s7Hs@A:EGRiyP0D -~aHJdգXo|h4qlq0'mw)#!uX{x&Q.L{rEM}ScArP?mN9S,-2:1A@(Lpj<'kcǥJxVyn{H?Hj]2M"pW-_(rʀ{b=ؾIBn*BgxeHᅲ3#x z:v:h2~\8>Y.T #}˟ˈ r$&*~M+Y,d҂^Hb:UMD t-M  *D^B>be&Dk^3^3o(;QҰ9 9&Jh!1n>x*j s?` 1^2Y: ll@u|g6Q QG> ^d6IRcD"r_7~w42To簍Q`4;S2. 8K)Dr4Oz6Kϡ Hm핲B:7~^y(z-KEGRClc3K(k42h+ 0'?zH4VVր, sbU>!S%Dc,Oi B&N讋WR"$#ӊݝ(\;xW[v3jTZ4TҦ6nSãUy[&j^9n ';ouc=>0n.{  . 4u@ 2u'㏟]#@se0'X*)~ᲀʵ`U-Cs E&#N7y#C8'HC+s",am+Vf׆,i[N20??]Y WdL(6v4C0R7է'? s[ ~§N]gwHQ0{jK=>Zm9]q5omQ?A I }xBO+](tNv*<J'qy6 ]2@Hr1gq=RC޼]8)s4h!O}ϑC$];8fԪv}QIzk; vZ4,fOqD+66m6Ƨq񓈁s>śqRecU}n=cs7!/nwˊ[~ i3Yk\OQ$`xb\RM^)t* ֶ-uE[t{!&Z*#xY!OЍIj ?]% ~ą[Pd٥J*޳| '1Б(J9LP^*6qSg(,a0=dl-~DVЁX%=JKtTIS zň)؅eZzY”͹ Ļ ^qM8߇E` XaqŸ 9ױ:%-WC{@X|:y^f ɴQ2I)bz^ ^ZI<8z[W0h{>I=ZeZ}7s D@d_'onոy bl69ĪM  ;'JxVhE8fFskϮ\D`mb@u u[ql ؙn B2dp]?kjE.)SzOCG5h_ ܴu m֯X#ǐ ljb" d}ifg>r*8 %OkGQ@m _ 1ްuI"QM_Sa;6ҳ.}HޭF:PDF'}rn |,W}ĿrZs^8/՝)l2Cr3uKa)wGy])=Q"#,mN̓uT?C0udैr-ܷT5\LLҘG rs89RXC|>,)~kL$G#'br 3<w8D{^jDPiz| RWfxA>+@ܝ˯k%P(l;4n5đG!EWƜ̲0+!qU:-j15i̳VZ\^ @^?VevEǽ0о}~YpJ'|"=;+ޓk$ 9KVJuH/aܬw\*qG QG<4_KI@`sK`?]|98'$`0WJ&δ`s!)3ZsYl_bFW6 {dR8g!+V'F௘ ~;^Wێ&| 漂C RM.5b~Fw{ 欌{PK4VםD6 :Y r%Aw_Ҁ}my҅ >;VNyu,{cdsBDzwk w![866נW X!B}NTȺܒpt'N'\Zj?eh-?j$K6DpI=КYA_=5 |ۯC>=]TdH"u v$1WNh!IӞS$J8 }[?3LƐ4.Ռt) "Ouf8u rlō1>O Y=%V> #C(IFblu( dω\˾U%rmu P9k@abL@ < -(E< Z/j,2s+r={ۗgDg}8N~Dw;?$Cqg5=C3o%]yy7/Yu.oN˥ʼn;woh4"NcYw (˧ 26 If}9W<潙T^#B9? N!GN E])U;䵏wo\Z}g" }O\Ā|&C GtfvJ¦I,=Nڛs` 6uj*C4*K #Y~kcE؂!6#Y Ej|k-T4`YL3'=X+m^2lնMmP|ޟ}>I6;Us7*uĄFb-'6Kj~0AI~Y<%4$[/)/*ě5O!A,Lߠa:D"Ԧfs} 9&2{-I@a8SVؔ7`9"<2fËCnY$@w;'U)Yg U,l+EB&.`$mS.1$8g dTw;uS Lsp0ٌ+օuLS^gx`yp_\laړ¤<;߮k>S9AEFk'za6@,DjTLV&>üduz924@*PK#R{#^t#x&]Z5./'@.rv{gv=c/;+,Z-|I=\a`9Hޟ$h}L M+:n$W^ɹ 1]9x/QSXQS mIᗓJ]KX]y[^/M0oP|C BaX4XՒ 6s*ڭI?;sVNyÃqff5Z9>ϵMI۞-\/09m[Q( JB8N3Bzٶ uÞ#D|j@7 9NU!/T/CФg6Qh%W&46,bgpgleU-,=qDcJg>UHs! \̺ >> {mnK;-Ep{M9Sy^BOĄZ569K'M+. ZV/)h-:c2"W# H})' >8 k3=b Rb~#x%-v05^#ހ?fSEf5X5}^ n=: \^,ɞYx.chˆh8DàFa8:93/*,:5Z,e"6haU+AIƠ]qs49(UQEpvZWhCɽ5@~]cjk9BX!^I2渭#lm%ۈN[&vz#q k2$e0)"R)cv:E|BRmiq55=PlCc+0D=SGf a5NƑ0G[@@_m @DK~-]͎,еg, (k3$Ge#yڝOI"VqLs mь>._'J $ =݁鼩! K/|)A]MPhA{m\5t.TQ>ƢYG SsaG'kgQ%-iс HPJkqc:ns` [Hoɫ9qJh/SG*]%3#+ȦTD>VZmq2 j@ŭl~FQO:84rU-c}ΚQhH' ׆hfl4ue xT|.L&o eT2 42%0€}(Uz!seew BJi(DdbL4G"IhwJux1ĩ(!!2wK!)[gmBQuޝF#ZpKHE 9}x!åNVQ[Y[?ʉPzܜm'6o,kAXdO Aeeyk&Ԇ,#/0i8ldGs:юGWgTJOic0Sip%D;dgdDnsjͻ?_>aC,|7NQN?Tq1tRN0*01 ljt1x1@*EWk90%#|9gk2K9,wxaP3q *gU3sٿu͗d!?4N~b62`AJ%3+G> ?elhD?iSUuwmoBjMMvv›+ݴ:O&|Jʳ0]$vߜ26r>156[K2w }G @Y{2'pDR,\ԐjGm{Qy[ךZj1ܥ;{wC{zm"9q 64mm#ޟ_$!^}QOU =pxUWQ$ı [sײVe78' ‡5ly«eUGc N"sP,%BVK*G6;):a;׉.1)Gj%U8CcK$~F|; Pܰ[z4z:W~wWx<³zAN!| >*'6~̃Va v8O׏@]ɘt_o5J+P2=QCJɄ]ݟ2wam_E pa"z;ǁw.NH=6{-O*^Pޢ˜q^RB*o/p[M$Fu K6V#Y )J1jb ;j~ 9< 4YO:i,)AЅo$6yP}_7J)ԩsKƊvƴ^4h,6#[aSy.F-tݬQVXIOZ wߚ'D>[-Ei?8s$6K2c? OsW'FkO[g 6}I8}y,8aIjV6"[-z&ZJ}%woA[ٴE#z J%"%k- ^ew `55( }uN7KJ6y}M12x}J-J T(;q?4\sR ׋N/GZ\wQu;M,{b@pPֵSK]ptԠx,kWWHM(<&+'*uL)&'!~Jh D Ҽy"i'[HgDhY`o-5*.Hh:'k3H -GvLO 2v]mO*q5̭ѕ/Dӏ:(#ӲkAhcȾ?|g${U9~fijekb+ŚSE(2asҤ>L[p!GG2g` Tv⇊ߪJx4Ә}}XTo2~k#ÃI<̏ 'ׇB=-o &Ȕ9n!>OqQ$&w+L7\hLj iKBNuQ1Jc@lVg{C+MO.v?h&zE@q4-kЫZrr@95&\8VGyjߵ2.~4i0Pܓ*ȕ["9Yp@֥9Nk~ }S߰|]iW>!B۫'6b15gb‰5jw\{/22h Rm{ 673w!ं4.jơ}׾FkbZ|cX x{h,()GkS $G^J=HF`I_^MKQ8?/i1qBW-'I UU$Ԗ,* {atI,% j G!S&3?ofFsƒ'2A1 fqKѭ= K IWwzs/Jt"IPqUGC 83l6Wɋ8S3se RfNROXPۯIk, e1<rOMRt*_uv)^r2y [W\hV+JPQlw(jL]U,ˡ+ .b>AbQlibG\P_> KXQJU 'N3astk'WO@5d2: Bz#0%hf X~ =k:D4Um_;h~ ,|Ԏ/|:nj#+Q*]V; ʜ}fHws%/+( W I|jkǯ'P9b·dX7ٌD@蟾Be밪gsҧd xCa}9D,LY>3B<ӑ+Sh-6UNp3ga@?ٲci[n.T|J֛)zy 'JbMi| =%6t j?3G$h^ RГ*aB$[{b`O7=7DёR_|cmEkFsbEژF&/di93u.hs]~iGn.{$$=dzzث[,#Oņ2{fց$~}Eװ~U&Ϋka-1t}[ptcFV<ױSnG+@:Ym7iW^ئ˳-a +Q"+V"b9`0ߨ)zŕi|o # ئ&B"&!%ZeqHĉ!PWкOA$qtF4UpWMvA8|X LtFW~/ّxp;ՠY԰rұ#10ʣ7- []鷅}0'B~CzM21pnf/LaV: Ir2>vb/*w:& q$9gk7' SS+JU3Ht~?5,#]ψUmN3Fw< g0I^gac!AT7~^HZyS7LUڜV?=֘L8T!p"J. ;4ݡian ?'BOF=?0iW~:"gy愋_]/$~" )(5km@7)\WYb圔χ!-hR$ ˋݹtyƤ@+4 DhU΢p#ɵ˱08ڮU#11C_guP*T|d!fε{0EE~chijLafp9~Nxq5^ JaHm ? $[B*kNjW6t(gtW7]\a }K2NOV\4H})y9z1  vMR.A;h$r}A4d>9M+TEKLBϕRɐxvxs Y]ZE3mV'$;B{(Bnt|쨯LwUW1 Hpa ~EdSY~,hX f-?Ad%*;_H1ZV"Lk7 Y95S$W M5YWN?5p SjdYy*.2ʕ]3D2ƀ+Uݟbb\jo.l/^~4n\7,:ŞTZf>Qjg,:z,|N`yvٲ˃]~7\tOZ6<7g][RzLJRZ/19q殌5 &=Wd?h6S$mðS: 䗯TĎ}+p_O{E\_ ߏ*PˆAQ|C.7bw. {U+̴r."MtA`+F=vEpb%co~RL7ct u srjZ@2"U h_`t`ohӭK8drS *Ä<-o#`E> DuK='eK!yG5kr!t4/wf#Agxm9dʈLu(KgtZm@ˢ*ݦİ*~)xte.]>ljh,)B!"+c*2Q4 oyCn_\ R]\?&M.9an_Qܟ27Iw\Fu8diN!h0*/cF-K$5|J%%[J}Ey}Hc'T_JiSiP+hHuK=E^Eհ ¬[DZ䧂}>̷8XQUi.XM'fӁ"h69J@RnbM:8Y8-U0Y0N{()D?i9Q8EqY:ύmj`7<\w*p)>?JV! ;zPV 2m/y8K2[nRJU#ÌEbo6ogio] k4.݈ǟٝF29|ZO0jQŽɹŏ")RšUO2ՁSJTb^O8n{aꊒTepW-fB5|ӴPc'}@G/!ZlW(l{vJQ-mX3_{#Yf(e/EwŠ2~OMC{i<А|Ֆ8n Zd=DdR(l!k]v0>'Gg,KK=ei %,;IpjyyR:@ҔKGy4?xXI"@"NZ H4x+A NDE5me/g7eAff2;=.eo0 ) xP2Xʭd_~۸ `pPEw @ m(ᘃy$gB//N˓ȐeY4ϸÒ)BŮg;`<&SO\lyM%FdL% I4I[@{Hn}tU?"[L ̪~bJX}/)|}FcسAF ?w~ߵe‚_C]_]ThcՑE[ U6n8gPpř5\j7@*%;\hbSSV3όƎeW0}_;T{~YUf];%9 dJƥ̇r(MJӋ>'` 8Os ͒g HpyacD!GP9JH>iR{U Б'OT:g/IWmU"xhG FLC8^' F@5zX^R 3!. \-=vHޑGOPeFA\ 5=퀀JO,\-P޽hl&Aқ9&`r܋iT,@l7yciJΘwVl[`ZM53ȂΥ$X迵$Yȥ lpHyEyMP;[T@#h ,V//48 KE`Bz9lzl&Nv=Ȃ+ux;.)45 4t mPϚ7%jz,O! GRc k=̾'Fg$[11n'r8pB÷(ӿV-/#i'KK 7:KW^tՠ,Wv!VGWS+^GECGYvE9<}邤Fg3~rs{] Yʺ2+=-q°"]w__'VUn ~4"|NJwKC +8m^B &ljvn3M#왖Rit( @t7*7!0Ѧz=5Y U _w8%^+OM88倳Zd@v"4:r#tk<8'^W5ņ]B+ty=#z"e-n?gmmKp. Š}е>x?%UI'6Gf;gO1-W&94A9x4/WdPȽ:\NNal Ƹ\uv+&(fiTJ+y[k.ӚksKkވvmc;n͔~Zc͕+0ZARꐹgшb͉o׆_ϢfvgÆ*W&?'\Gp4A"s]e :p0׹bG%2;9!xy0:eD8Eh 5bϙ5:AȟrUeQ8 Dk3qߑ(ZiP؊=ՒTʘQmD˹Z=Z;Oh2-.6mg [©+"euj ViBX]e,".[JA 6 L]v~((.䟦FU"HN#Xdu43K!ѴNZ%xԥ4ȶhuG m?G"wC) N͵n ^2TÒ3O}3]=Nߣ" YAt1fkǚm:򩪗/3[sg U>wpPV)qƁ3oY u./v:zn<7 ,sa`u׌segU:4}R Υu%1Q)w5K1c qiD/6հ$afÛKQ3Cu9Lܑ)XmCPLR/  _vuj*?`[֢ R&lH6˫HqǜД籚$oUib`frVS5+Z_3LX + Ylz8T/$Eoeq4VL\mFTb";x؏`d,5q[駈M]WC:LTu USţFDa PJfnQD"7}Q$ԬLŜ3JIr"2IByS&AzoJDݧ-Vn'a 1Oaʬ*Vt`y TWw:쏯:~+Q#z %y X"$ڔʭ.""axhNens5ZݏT37ꏪHsm-?*/!'9F1c]j7t'?FO_%tiɱvhCBתG =ϴ)-a;&b.T sU?lg+`Ȭӝ Zx1O :Q;@,ojRU0Tb<'9&Ui;"v8%$}^>|4O)WC2Cmh{Xe=*ZU 2>g }4o^<Q:@ȿ2 aa;ß/IJtdbtVuĭspBS/~#TZ*>!ks'|@cwQ@N%[?bX34Eziˉgu{PnBJ.ՇF/{xV:wvmv Q#]J}dxUI;@}KXi)o"xa| 4[aOO 4%?=IiV4 {:HJ9ihdEMÃpEb Agxr\-KѰDx*p64K[OM?_.$deJ-}AҚIѰ hB\9<ÝܰwA ]Mm몸@JSS$iB'i[8Ój) `!Ω:_m9ι51Cc,P15U.?$lL\+CqPj{*dQbYB>cr;$ Bpiu֪G=}"1XIzZ}śG=:1ޠ> ,إ[&7}R.zzbC:/l9dMUvM[Je;+:@!N"1PmBCađPŒ67q`0 ǐZ%8H J;uZ$GV3vB=zr,7&x\95EZ')xOx\';T` ("%:޳ߢrZT7&JB]ts3rbtjm{@<0:jN<ʞ+ep#Aakn50*sR:V\G|rCE\DpKD$N=@Q-bxu/LL#hgߖؖC}pq ~Iq3 t+}^>ásNL -քIlnX§ ̗/6.FG]قٞ?=-컌"R(TV?z2sts AӝpvѵGTFQ.'(^͛*VX!bhYDiĆ02tc,V+~I&OP6u^]zg-Xdpu ?7)kq"68Qz aLCr@1QOܘ?o5:_ᑒhLNόmܐfҁIKZ*r°MS:L}k $ǦSeWA7|M9 դo#t8]VLYW?!wz;:~`lAo <M r=1\N}vz~H׼4*)q%?l U)":|Dx(d|MJ#<$ r$;+k/yR}P}\nuy{%0/G ަ8m[g%f>^#Ĭw$vV9p# }|w}~`$4v>>T&O)s<(ԜF \P_:ܹ|Ar$'P78x'GDTzIw Rk,PVdH_xT)ȡhԭM1o5=DXyZ : cn_"c5#gH6-ߥgۃkoI7, a }g`Y-ݞ㷇윴*G=ݞ Wf|RB/d|r[A9,aOX>Cҫ$/h޸e]y";j4RG^͙ M--_& [el &*`P3RNl!m?ul/CXA5}d "zljԮ"Yg*z= aHq› ;T,=Ԣ*dH/6C$!ZiPTuO.QԮwq :bYV~N_cᎇ0Č]tfc.kkl8Fen8"@ }x"e+S\XG-yI[w`J›˘X<9H[iA9 xr6~p1@>i˸MՋsY1ΧuڥC 4/m>Q<*MP*+%zo02Eɷnu~9d׾Hp(d9:,Q]tô\M!QM#RwH_Ҏ nF%ZIƗZ3»B-Y-}=F, )\$'y=i1Sƌ`#'%z%D`u,xV gDH0nn $4]QwkB% L1S;#? ֏aO\Lࡕ\@䖽ڊz۸ ^W3g_Φepjf<~%?9 D-Zm_K5{>Ki kǎ PTTw9Gn NJUw0Ю@cM)-|ۢwh4=^[ҝcY6~i!@ϗS$l:4BqL뉛p[m^,Un1+>)fevGN=7|Fp.5 †VRmH/K^@ ٚW?0r^vsoo^wlp6DÄy=ˑӁ [CE $GPi!59rFI :EVoLڽۨ+8=3ncGjy$sfWZd@zin],Uکv)b'd 5 U=3!cOtHt">X~yMI"3+D(bzF,Ψ8"ة^8d?HMi}C ܸmR'z5Ya Ն;Lv.qHjU2aE67Gj 2ڇ%תht#96sцi 4 >fny[ OL9`z'S*"zW$+ENϚ$wZp1d(cbn<,Je֝|ݷ[cq 2Ȧԫ^e(>tnY#[C˩Hݩ<傊Yѯ&륁vqu\_΅n 4WcIlF6T9{LYZ,89@oTQab|em4ܚaeޕO7cZBQvNMr)\ȗS զ}rRIF:(okbGJgk Ձߗilva XV^ި31'(bL&L{W6vpW՚*7HQio-6(u1 K^Rs){rYW c!}Ӵb$MaثꧬEƩ)-˻^R;1#L:[)-ѢtWG<~|]n9>Ƹfnc;"j/w5bbN77Nԯײ]N 9{ z\~XDn 1G_:t2*J13fW@¢[nO`mѾ%g+xGaG0 m &B/% wvtTe 6? <^=ᚒ"U=_:Oi0r78c,>G`g(jYh 1'_WgAQ-E ?{<;)$}3f{ҝ4L2/Ty]qrG^}.uZᓑu 7z  0b GI)뫐F<]kK]Cz<~~2wQ^<8/CC8~Ҝ$9[xvgXBx*uT]7zӥM2k͏!7NXNO:8yo$$ZQ3 X!sSkl~V.sPX(bjni0jB]_v=\_x -n#}A9WX o]OW&x.@{i?EBw3m?܍eݞ4ϊRK~ Fc38ʊ^[j򵙾|ʡ7r0afL_J=JuS \kkRP=I  \+y!w*W%)bLZ'x%?bjC\ j;>\vVB abYBCrOɤ$̴* auuͷK؎Q-A?ꢝ\T}*>w(cJw߬R]^|G9@rL兺ޣ7h565Om2B(hB`/ m̀ib/5yʻ穏)ݣx% FP6C?AZbVo)03k sq10@Ti.7~4OEѵ610u~3#H#IfAA}Jtbef76 ^u`KPkT=0&>ؿ=+W @O$U%d7:$NHG#Mw.n {BefèS_TyY*:RQhncj6|^_X`cq6&H ^y[ Bm:&)*+5_KLRN̨I(Kmy=>f ډhiZ>*ζݭ(oO9x9 NajҶVEܓnn*pi6R{QD@ 65}ʡ5RH0=Ms :]!AJ$, [0IZ*paQiDu4F)}17t~U0ƽ#j=aJ~AtBy%g[{3IaB!fClP,{lzQͺW5"ђ^/$#[ڳD[" ț,Ц~E2ilĄ/LuX~g:u MCgajG5]Etq_ ja"/E5]?\i̘NKLwWpy+&Ò#]&[d(NYGܖ2zZE9;*lV {ƺ3wvSڨO@ 0's$ [*ov|xTɒ69E~}g/1lqLNgR$aRVUe=1Ƙ,|AKM'5OiQ ri DkX'o*MߴM ,H"Exxw@YM DqZȐqwv34k1.˶7@ ѩwB{T(Fed s|cN=?8e-}$D6^nJ,;xW0S6Xg~5m5bs@F} UG)uG*z[ bOyNbPV>pn7s4,c}5Iz6VhNfMЍ%4&X5@K5GryK||k,PFnRd&S8PUB <ٹqU 6Q">'V17 :>u>7+_I+?[w^UwomxUFJNAY RXȈVv*hjLi;QD2Ou9G#"*15OcO\ վn-JRZḛSӏd;]5f٨Qm%#eKh?3: Dl JtNr3#(-7xtmVIfWC0KϠPiЌ>KX6T^ԍo%^HͩDN)7iHCD(~ZD,Swx&!G fGT}rs2upKI)\Y i^Șm:i"XJލW4?┍ӄ$hrKdeeyGfRUkVRf2v {qڑkW}2*a?%WǢ6 sѷ;lbqP\kuX:-`+U*4EjW\bHEZ|(|슱CaA.f=SzV9vG[Q%Z"f!B Jlz!"d`\,huM<|l'aj?3}C!wB F-# 7A&~߼ؿS7l&z5Kjg韎\Ԁ[ƿ'L<3uRMUlfwmr*kW55jؐ#9(Z=D 'UM愄fUG&+W5bT nV';w ՙSOadK%n1e ~2߃΢HrowKkKȚiw>Eu(c6a9{"`>ryr-X.E1 /6qW'!|*o!N"haPPR]ȬؔaJ1JT7BH2K{ΓoYmz!}ד},^R &/l>grTe7$DKacMj@ر8p~Ƭ^Ëw@*EC!ky3}4X9k'/Zꏏ?i>GH pI\vryY ţ0 eUUE-qW&Fbx @"`M@ d/㻂srKT<.0iQ%HE' .V O%4)iS ܬ|/{fy\P4IY%Y?ˍxjQQv/pScEMeRcSkH}MRb MBif ϹN̅oRF{j$BS϶v{ !JAm=q%>կvF:\l#z Rv!6&]qOv"q7P7Md#i4Y!Y쉨R R\ݘoWP }X8 Ӭ4,%%b Dv |thf韐j̄ [=V i4eysgBH 7ؚjyQ~)=~%ϑ0z eMU᭱v] hyR/c-y_V@{{Gv+ q ]PM˧߳hwelR&jVRomTXWw_" S@_NG+O_@0;"(џ9sW'!X |)Lu_4 tʓCmv)# \mMK˴tىj0GN!6b*LMRJ)/?,^fTy046{,,!]`|4xswfN>2Lǒ ^pSO5zEE&'kxkaP̵> nvmW.o]=l+f0U+V+ QĿ̙(!X.ѢO Ok5g8^Q ZYf(2e!" 1 Մ-^N[y.ݯ# '@n[S! JX}@{,/gK8t4/yYIJ*uK6/ګLwT3K}|IQfDgf暬0F/3C&;b6CdJ-Y2@C)w4TF¡Ќ0ʹCU]3XI+#Ǚh[+d޹:=KQo҄c((*0cYV([,I}jaCNK]ئ dL#̄x%&ʓۏt|s9؉p8O,bMuwG4m{BB6l:$SE׷֓]RIT1&rQ4pizvESU/YLJtLLi8_Foâ^/8쒗9s/Pٻ6 {Cx?y:ڞ3P{HׅjUEjF,o֣ /dr\`}C &7!ZBAYDt08:A (e]}l <(+!n`5nwWBAl,)\Riha ]$}@|\+~B$0o [cbnMsք+! b ^nw /([^峩~;0lX&3'6QVA?kn1q1i'[Uek 7pL銘 &4[n)L`!tȻq#Ѯ%q/c6jN JϿBY@`C).}:IZL1R`s8q{U'܊/&N!0a@/;QI[.CAg!Ҋ `>/Œt68g 1&Ю8A9=#1О<\Geg '/MGY;+.& z&NnL $wEfw&:Cv Jdu?,wB`\A8FA$)JCZ>&%>4@Ys!\vBe~L”g4aL h*?e{y-"\YMڥ]%i|\۟P!1qX$*=z^($%P5_R{zWnXWX"hlƆ-C )IN/mR\^"ZZ%Q?t?Ib g3YM,\ ҳ&R)LEIhnxV `*1ʫI3w,le:89*j'@鍞Ֆ+i2t_]F)W҇yjm-(yy3TUH?uƋQ7K Mw}bk6`! Tۣgt1Rn:ogv>gÉ5S4WLA@$l1d|,+lJ+BXmD ܏$A.Lm&G)8s2asM8)f"V&nL 0Y/iYqn=jW`lk>qdݎcI]9g(Z>V-Y4^O4!9w[yq;dk n&$I%0iv/.ˊ2 fXzzvPW׶@蹽-GH68##M<\̓3|='Xjl^lbIvVʼnޖ| zazd=G_.p`*w8&)8 *wQ0ޮ^x2Uhb;9nǝ@\ۍã0,FtdLbsYK5C}A1̕ ܀)+|h_AQ-q\$r k5eۙCZByE,ZvYvT1[U3q|M'lNF8jAt;oP`Q2-tU [vM0cagfT~)M pqf&#"߫ݰ@fYd'RHnY.̀`h?_+!*c2E!u &ktlxz0 Kg%u~#9ergaLA/_JV4+Ģq](rDxP%'?ȝGGqn}[*f nC~{#~L"b؉xElp*Yq.V<_1a7[P4d4V-hK?Js=sN:4֒R} \?AcDy4'B) =g(N" ~JM*`d,]]f I?:JZ=Jٮ\)_'aėŮƘjA)f8U46N9~ۺX^<أk*?*ZQ yO\抬>y1n'z'g{JU S\ԑe7tfU#>kT1_@B% v=#35;$Kk.J?~9 PRMϽX[M\58ft7*hÛ NWFs`_;°+mD^*@?UPDc?ZXTʢ@Wq`HQݭY*>/ǵs,)FǚE73r9ik8S7zGN'f҉mM2}ݵ#`0_QYє#^ӭ@jI\+ɀJ3):G'oI ?>+,Han2xFl*ɱNxU\X4yMnPGY+À)MS!UL=TH7VnUG,w.*ׄ(_dB=eyu;BoI][,;Z|s֩JyH rvxezwv2}7D1ƙ<m]V2@1Qᱩc|Hg5qqzdS{%%l͏8 ^jNA4)B 䚾żҍd sQ={:XIVBAfLqe1#2f ]ZNPXA3.Er誗h5uf^TB>[=责<`>_ߨ(u.uO0,&#ԍY:o'o^)Iٹp /x_)5G2]hNH\GOns[4 vRz-tE.k}GEخ{<5(ÀBb;{#߷`yar״1+t,')x-*gu} bT[v!BWJ·I8 @5VSݦkחo{j w-y[ęLڪa͔^5yT3[:_<% oΤUS6r!O,!J*]>2" j2԰oBur+8Umg^Ý*b{s͡tɿΠ\曲)XcJ:* d9^aX„w Bk3[6Eꗊ-*Na502"PuV [1yAX$>NChCm:GKsr;Gh_ȟ)ҾcbwL6}|rm$!Ċt&RI 5zstv뙜"+7c6!7hL nb?٩DRfsMѦ9@Tg@!)K{)-gv*rKCi \SyQ)]pr6CHGly 3eh\Cp@vY,̒`_# iEGB;ajoWk,m]܊ nd\K,p\U ȁߐӷʖ"9=,-OXt^[@ׇmq{ʆ & 3m$ȍiZ#kGŒ;GQ@q;i:Cjxj#Tc3}k7= #I=?$?]h>oJdBƼmKo2>І~Խ Ξ(qTYʦ6l@:tm80Pg)]݁ilqt ^Ҙ +$nܰy3ZƩw lW%r:igGEk fO73 @@sL|kJ^JVtF[lOQl!y22Yww0f!.%LZGsP=3CWZ yd]581mY`읿 RfZƒ/s-G^_OswTjj*F;7)h3 Q ^@E_7#%dQO #Bl67㭁CtІ u><6\B&yΗj޷@=#0ڌ+Lݴ73N/3u1a.ϞP{.qzAޫ.d;GXȑBW rjь/ᶴ.|9QַhJVoo,XPVs-f~ QB)n'׭ yi)|Vkε_f1cKhxuқz2턔TH!xBFpc(0=F sx=J(G'],ډ0b*,~/4/smJt{,&/(ΘLNy \kl?YQ8Q״W43L,\lb|qCfU$p/$v"5 Mɬ˅qGܟ0C@C,#1._6q`@H2@M44\-yW[SXkd54Bc׍p7ɊV`n܅bT2憗a=rEyhZjP)%kArؠO Kx!D:%0e춒dGBˢ֠bpb$Wog9BSy_7:=.=pD|@CVkjG,  E~'W'bu47ZkxjYJ),HLM2bēNXDyv3)'Wq {<ST/*T|B~;VFp-?D%` tJPPh|N!KWvoW|iCc 8[HkqMs~TM V94WHV$ʉ;ߌi O\^;vYybj ܊86P%ۅĬ7*u*MS;Tfk{8MV'æ]EHE ͣP,dõ4&@ )CH2|P[n#ƍkϏHrk)qZsۨ0}83NnDyĶ+=7Qrd׼S`f->2Ab["fU| c;@EoG"x_FwvKaDXd$,aڴNprab|6ֿ=Gu)Ǧ\w'?ќ\!L[ewNL%&kjJۡ`R\>PM:^zL|"b+Gi[^ҖƆ#fAi,NO=͝=ɦe6Ց/kN1$^5/ǭ^{b @b+}qU»nD3|"T~vG~J̋UYAl#j~#Tm$'#ت ο}QJ Id@V$;H2`* r9h @Z]^EjM`n+"gGXmp+x;9&h^Gl3#U5R ` [bjuGxj֓;:#wY~z/8cPog.9ó+'>`vZl1C+͒1oU :Va2F҅z`jL[Vr9 $Ķ.W n/눣]nYzBR4}-i8shlhW(zUK /gSm04X=/r\OR(C*ExyίMG"Q,iQm7C7ӊ~BE E(Z&>}w[;ސz!yTPI/  A \D3U,i}0e)#`4Kbra*θf2֟X<4u{A`=Qf0L^i)P3^q//N˙У`J=ĥQ n O؋BR@5[c{AR ;G{mq 1bEtp_zDP׏ mM<@j'k kg;ͷE !]- ,-[&" Pu5pF.G XxSiF_י~O>3[l*&]]3èWmaZrA>bemEK3|^u Պq/CQ)qAY{j ʈ̓űIh3@Y2P?Vt‡TbQ4PccV^ N9K5Q29fun4&g!r"siZ o''ߓXþmFЍǮwh%7c=iiʭ_cFY3oQӚs fT|G"8-%1F3fa;Y!{E*(U'=^M.k?r^ÕSgW ZA^jIyT!hz"o3#&eb`j|9! F'JFtMh#v4c^r#b@m$؁8c35tِ ܩg1/_hU؝,هYKCoB V)cޜ"AǟJ:tUi'巾c힫X/?w J̈́fel]{ JO*N-8gTٕ}PTjx!D!6@j͑拨 6ujsbP[{# +y5"Eծ;1=2>dhc쇶aDעÊ9y &7< Kuȝi$kjc"(xrz#lܝI-Nf/'љѝ)0q4⮣-`˛{hSOKfWc[2u43m w=2vabܚRޘvּA ,dO#dlN} PfDr=׫]Z*uë;l%NYvH#90si5#n-7 )'* ˨\Iҥ/*gFqZ5?-~Cb^>4I݆Ywb9ffUt|ßu^ړ@[һnFDHcNr@bHf &H%o'bkW-#ܧ3ylZ'c`=de@ن#O3'*_Rzķ#]u 07sb$$b6pj0܎Tցn)^sP;stF#2[dmpt1U{oh @ЬyxtVUCwkqGT7|5L̋`O}tp9M)?Sf@,fŌ6߫iȴ%Rr"m%sBr"hHux )M.ZX >^vͫi*\pNhVaz2<, I^vd@LG[?{^3,Bϭ$HպW5P#`_f]gI#,|/\+1{Ot>`c0_Z`+%S<-C.ƬxZHD-(# xOV>U}Yz@*b|8+<(f>4qEV)ހ|kkEӝ^1\Հ݃skMRJ)j648n%'zDLM{!g$DgcUǸ5 (mVPR%Fe9^3Ezx\QRQaKj%I֒pbլь^i9)TI=GpJG.aT擩O 6:Z gjGAؙ-hSBzGu*TlرAFXж+A B֨>By2i`) fM#򉿬nnJF/Hψ+sT4g8 yUu(0W9-Bߐ+=FcC0]>-EN#QNYj56T vfK>dN?LX&Wσ)]laٖIX_]r2S}#|rP|߀_dd*`tےdKn.kroj1ۮ_4i+sgbSϧl{ŞzwSn%%ͲC?C,4,9 )Όذ #yp}v xGEt٩'U"1:,vJ q>FyV oǽ)@=)xaS (uף馸cH TJ}E{X +:P\?s#!B3汢Q& *2AFmFA ' "cYʆ2,!(4:]DRkbDPt$;7}VUbsy.~mAn9 QC?[>} P f%(j]q-tpIs G8*Ui/쌡5䡸p+i`yi"{^%Ɖ%/V~ G7-Ewx<_A"܇bgb>mg\kgZK j5ܭz3(%2E|1:8tw,AjI.t]Zka>l@O6.]*iwQ$fw$1쩙XP1,aG-8x(SxFڊ"`MUB7/1EGsK^oϽTYݺc鑘i'/ZmYf sE@<. +=Ǧ u{u%?ilyY cQQgz8+ojuvĠLVs5xw-Lc)b1 [ld6k{tл^Eu0`ݍ:K26Yweh /L㬯,:6hKV9ծT<"t\m[CK:XO?XsԻ"׸jsdհ(&@LʧK@'!mpq; 8z׶Oiz!g#TS2M]D{X#pQ+J`43?7gtA)+y s*;jm Ft]@hq:1u2,5vܚ#ڸ^o3.JE*q=bh|5laE"I%s걙XㆵaEWzV©h)sog͟}9=W0>M҂Pn{ =O{rټGfSq-yDmoJg§&[GE@';Th5k?zIvtVZ^. quj,VÒk`}{?`-և7DHonbfZ-V  nQ}X#x^Oh{QA w]WqN;̑´씆-"m3&\3Hva*EڵKȾB) ;ָF|K _*?E9sfgEq^Ovhl\Bs TneYXG)^BQ"G~xf9FO)c.p>O_S(6.]pJEnU /&R{p}K{9A'@'tһV')JAABCLP,Mi᝼`գo _^Kj)MP I`#)M{ IZ$tXt4&%]"_E߸:`F+IK"mĬ78D|Ƹ)0}*\'p.G]+?pdĆ8qÓe헯38" S6[r\J4MT|yimT +*2} _/%J66N;YI(O<<'%\QWِ֛_+D#bl%ʜ[ҚgK@a8pM z[WbXݕ4័QxoղFc\n"#116!V\Uݩ[¬LUG@GW>@! 6)Iv= -=RnH$]:XT{г'}B?4^Y"z!evP0V˧}=+܇&zC9P*Px.8lcCf!Vכ^LׅGҘhJ$O\ʑl}0u),5-9D(yiΙ}?ez"#Hytc֮y"OIA[kKεHJߪ{ ׯ~bDRHa&ڳ16ucG;j,G (P }6?&_J#~q=wGfc|ql'z` JZ[y`gׄ]Y?n'%e\4-e3a7@e]FVE mZKY1x0De 6{VMIM|OTA{lnM0dB9Ca0;q&[L}|x$ '-xܳ F֏ 9UkuV)a\ m /dSReO?hގK68yO'NAHo%%MFx- 1!F\\ %U֮À.joTAda\ xƔ-Kz{=NGjMnT5: |qaCb& 5@S֖1gAwحCZ:yآZ\WH ,Yqu["+=;"`t )ti`(2H4Ջ*M'^9qAO7*J][C PzMO#q퉼^}Z[f_T8}%|0nuzqUʯ_hap3/#-  ZuY/ӂNV񧪱}V=chԸN86!Dbc0\pq;s X蔡%# #W)i޳DFiA+Ī_dF@6YM-zcG2u۩WH{"G[qfdPxɦyOXTXFuɪ $LZkctf6 zrofv`O i!k['u]9) 7V;>5a{Mq=BäP)ル= uw~6wbA`y2$*.\ۤdߋ[$5ŰCSE<0Qk<9x{ĕ*0oaTW.[=>LANM$gC*֐C']U'ɜGiEi(Wd@t8=W~~]V2TmP$uiXs3u)s5XlREp%ܚ6k#TQ~}DA$K`Дn@]Z#?B]2"O" vvúAð˕KNs#'ikkC),=9pQ<("i}<.xSX4#9j!L$_643մUꘛqD>Ee/S&I}j52dpBJ@/h 5Hǚ @tB; ~+@ ydc˧Ghg^Wi7[AljM216^;ɒ[frsG*y `f<׃b,v -K$ UY)bі@1jM6-l~Rү@ہp=q~SGt&]|%N$nt ܛBo$ Lˡj>+lo03/uDž^*VJ%" (ŵ5qcv=,7fVSm[p\yIc0+&}НU8r.8Iܱ&:.&=rXZZuĚjܼk찙nEZ͙ٓOs\2qUXzN|(+'"Y2Dh(6QpƵPY&SE<$ (OtG}1*K2>"'U{K,}zqkb#N%[~ Tms&%F:oq&NzD9` Oa}wjfn34T{`?~:|fffQ֛{!}3%"܊[hQ?~Ɏp<ڝ?#VIo[S .2?J12a QdɕTQz"]xJ::mt V 4!JoGo;V 5hvyfIs2Ԍ8@r|^7fXiG3T_l_1; R#za+[} YYX" rU,ԠC?PyLz {ˉ}D!7R5n$dՠ7?ŋE/O`r/tY%\$x<نMd; >E{\{,"BA؃g1*y՚i [K}2RSi[h] TmfAU@v|pk/ZK);6AgshjvBsieᇿ'!Bu? G4#.tt`0[>w}z}R{rj6Y|spH y!J ҅4Q:fGG ?fUִ oIy'K@tcYIsWkCbmOw`(힝B||%7Y+4DoՄC.XLFJeK =n$Ee yi:)z4psʱx~U1nUF`gtF..>S9@O.Gk/j0mB CT3 A٢;]27W) op$ʏf8tуG]EIĹ. ܯc)ЍԈ̈ԓFed,íu幗0")=\;A.ssdbeӽdU~b[#>Ŧ MTm*Yٞ|LGf1{yq0޸@jA3, nЉs'USUBy%mtc4lT4-tea<)d1yEbTA+yBqZ%ÈCvBtF2IbvZ`<`M3B |.yO_w2XyvDDa2:8rg&&}O emfUFR+2vk{ D>ƒֲ& IC}v*Kgc~t~EDѮ_2$&M J1o&N6'{ԍٵ^ Y+ {nxEV|.' gjݯ=F KD?0#ۆi$kIE;qO&𔰵| #2mDr$Y`y `6: 56OT9W<3a? J.p‘͒lŧ_{V?5v@#bR<=>_zΒƶOtJŋH05!'* qk.kf nb-0_"P u141J=6z~A?jgX+,3jOORtw mkoFvh侦CSmX{Q W ùB)ZV~W"MuX$N<Parg^ˣKA:.ܤSHPq$yXP̫APMQ D"rRy6zx]LЖs%je*S԰bX&^pIȽe9Gȕ6M 9ݑ؀U}.iVdu8PQa|Bs0ċہE7 bDv+>eO-=?_Z'P^RnIɔ%@ 7h➝TPlƉ9띶ES/UC_]-JRTٺ1ZUJLsl=~e\: ^߄ZŜ5ILG$w^NXdTTuJ!SQoDhnvZ$'`UyXXKQ>h0=iGR:OKLRNߒMy2ņj{żO.Gո@~猕?zFD#:؇ډ >jA21' cc h00 X0Tw鴵z'u㽰}͕(?Z bOSdqUluAk eZŽ+$1B)ՉŮ7$m+"HD,[sFs-=LdI k);Q_tTpui<ǥמmXV 29  @HEVGR?MȲA&?/=#eL G#t::yC,c^Xt 9o 6.Spϊ#+b#]p 1lMC86c&>XԆKա֑fC J*2T5tC@h5YXk#a/Nss [sWeXV,J[nhe'Y/ kӉlw;",qwJk%Iqmwwk +G/Hl0&Fn2fբrG5׸7D /h3_0}=_Ok"7*!$nuy.oeQ~-4ݞU,>Pyy q#l/bO'_صNë(9Px)!zǡ]uO!.p S$82:;`@s Ͱ{[ip2P`}RY/pXAg"]N)*b7wn:g8Q0$HFQIU1Fx(d@/D7h3pc\)k^ʼn6edd?tHS j3eB$ o5zgJӐ[)^7bߑ0%/=E IPv%_!$Οk(4*( :B/gjr}A8tC(QE֠\KXB|BHr?{%ԀV©AlKD{XX)+SnݛI]ҌkQ> %5w Q>d/>ݬ`EtՋL{ZXZ #w v+U >[󗓧V3bD%3W쟅>o5y QW J.MQV+}Gc鄛DHwH*Ѽ, ]|%DL#o`R4Ly*J5GY{ʤPh($A-M_~zJ c= @vټ.>kk6~ӌƷXTGftO$ŋRLߪ+(g0tҒ<,|pǫ~C_$O)HP<]_m( 0b<R^~M&(P% ad~~Ed 5O^m LW@B2ȶH=q^W:WђpKO,yZϜ aTbMg\Qԏ !b5nut fT41$e,iP^Qcx Pƫ(Z}ON7d[Uԕf[fKH7$VqUp><rlU HڐzJ)QѤ`Ss3e DW5Io:NAat6n/!k1v+彙8#M-M]^SS 2Gq- \­cAyǼP[ukbWtla"/Hp-';7FPM3 "wxSqL&Ł-2\~DJ#$5,|ޘaU ̾܄bq9?s5=Ys&ݷX7r M=u02JLHN=ÿ:uw$G@A\dX#a>Zdz2ޓc$b|/A!A{$~n=6W &SRª٠o Wɵ6da+QWj7OVLJ\IhKEDּ"h2AP>oPHn7nZHR3K=˞QP?zH*koGc;ʛk13QQ5(TS=9Qp׳i@Ҍ7#IS1[>5&Of%繜m] 3܁ĻhPN!.C\oר!aخU8S9ry".R[A8Bh}cY! s>R 4%U;#ERѫ .o"FECBiZ/y$LݍXCUF?܌T:j?W\UȺxBPAF*7(Oi=K)3&V LәA 9fcV`HEfQ}<Vo0x{.\P{AHX.GmLUXKJ\nH1}įH*@*d+5.ii],Wiݳ*xq=@}u[lCr[X K6NZTѡ ]l@/$7졦{ &Y*`/iaZOX0UP-pFSnAe_K5P\Z:yM͈jbj085PQaqUuUez|ε|-z;tKa]"XeܺGC!ԉv߫f<Y4+ؚ~Ye$_˝_[!q#_k=B]N:#rP}u\2ḩ)4| !^gD!f܎Wk1BV2rgaO|} XKO:Zw27۳I}K"en=(ؖFY`U'${Ŏ%a.ֱC-Dl#>M8}4@w$ # }|\,݅sCX52k"\@2 ۮj& //_pef2#Lqs7TkQ@En RoS #{WPiv.(oRkp}3a"s(ԏ6}WPKTкH1n]CCp aYRe'j ZUst/>ȝ\.ƬozkDR&\4a? K?-wAUUPam<'ݢBoZfh/^궬VfŵaǵRPmzOvB*I2XNRסC |֐9P, OQlH!hNP!d5#XΟ2+wZ6 ^j ٰ9Cpb2lN\9ҤG$;ZfJng$l 썹S](%+1).6Lwk0䌬{$HCջ=[ڼH=8FJ9tVT%l2ogPW8etJNEZ{Kb&?qOG:)2?]M ug9s|J1 L##Nq; Wp=GbמJ {%M?0l|w' XO+5>)q̝Xq$ҩG%?Ю0TL(ú18`X rm&d??-0!ػ"M@6/!$'M07-%A3?ՀkhNйw'6Wп/p|Їy#=ρowY1 |Nйsӱ3ra~I\$. BM:w#"ypB*'<{f3yYj: M ΋vHK#/,1bdӒ/1Lz2 o׵7ԑ_TZU('M^;p6R[)Ж7͝WAk" j|)yzgk"dMV9tݜBL}+ވX":5 ;SP ?wn1@a.N<`+NC= inA.Nhse[*p xhD9}w@'G*%ĀP$H|Q@z[{کGt۴fY /}]GNoĜmk3W12|J +{O_vc/lt%x:e]b38.8q]XN'㬟NeCvE~V;A;4d?~l7rPf3. n]$4>Ikf ;CO>Ԋέ`0z7%e8@lxrטU0o.?i P-&[~[]HqKY"M&N ˞$(+br CF #I)=+4j}LŌ΄,S>mޝR"3_;꧄t' ۈhzyQ#OȺƮ%~$K A@M+J} Ífpv|o_jInbAZZVkq9Zh^߽$vHLrc0dy&xa%*Cõ 62?hhxjd"4hûlO Lp aY:*ϕf_d@N3:/mҏ_b-M^(螶fZtF}~Ӳ%Z\gdO^"#t2{s<(9i@BfP¡=emS2V#Z]]nt/۱®p۸p Q~l8/PߍbI>9єŒ Ys$wUփяΗ)&;._m"w{-&cZxt Nznզq &;'PltGd$v'æLO(Ki^bX#ݝ~2N /2mU$CMQt{_Uznݺy$QJJ"֏g4: ZoFڄ] Pm&O޿ HȚa&Hꕉҡw]=,zF4pϖKO0%9$/G8ioB|j8o_FSkV/ZcLȕ}¥I反D\DBcp=^yow f[*fL@n XjYC[tĒ; 5O+.?ۣI߅(P7ۈ#]r!>E=f%{W =؛䡩;@F2"DVwUz@@[^'*Rm _7$t4Ʉw C9\=^Xݖ*x (08&-zm6f 1՚@EXvK @wawL1ZxmΊHZbLYΰR3D!SC5uxK9U,eeKyOh.) nnV~2FeW833 /̰RRRpK=Gu1q BVe6gRL&,k`J:*49:?xCBxހ6s4Ӊ*HWI?YxG9 !xds͋;^/3:Zzj,qu[o2v*8d ٷ*_]=pYilU(G\\Lތ&%q'nۀF>)h(†t @5t= /@svX+pGxJO"{+n,RĨ ?}Xs È@:|Q ;@ZW[plcBUż[KSy913? !+[5޹/ac,=!LYSmP0p8 ҈_ >8E8k!nZw+D~I :#d!8$y*2INY7괝ſ/lp\+y `o#eG ̹/KK"=y!͙,Z}krS]&_\t1ohd62ok+Z;W :\G:$pySιs摘#cۘ4*9,r6үǘ|zݫF0KB.UBZ`)Wqk*p,.{gvJbR]ignN KL)?~[ v|yFZP0ry.6@4ʉ림N~|W2[d)S"⚸Mx(O5&4a\ELՃa"{TBb @X6iu+M㰻^ǫuYSC z:,=B[Rz5a P;$S)$e'ϘYNs?ʟ\x{@!u~3X'}5&/bhaFWݯɹ;3]A0cB l[x@֧]} E)B G9qYW\=`\J+M|Fsf&G%M O:1Z|1:@Cw&۽IϾgzpj ~ۆ՘T#s9h&flj:隖Dy,yZO~i˖6^+,e_ Q(wDq41YT\NZQ*XQV 26pCH(U[l 5Avx#11u`"C#ز2%iNZirtyYhУSuuR7*nXa\@l:_]\2 X%oT.t64P_8 RݓYc\9W2 p\VSuBUYnom?Q:ޫIhh B.O̷1T"ir9WvGvmaW ha5}ǔU^]Ȧ԰Y+Fv|a^;Y1/H$6PD=j43d(DފAݢl\9l($A#eX^9uT ?Pz;I@+ƙ9tgGA(;JeIO t@](YQG!lU"F{S~l>w6ػomD:ӂ—M_$ >k"Wc?~(7P~uf;Z3&7&i^2_T*xaG|C*yѾ $?ͺ t(C$w3U߼ lEc(.ʢA=7R BN4@_;yt55q۳=(j}M,ƿrҽ=+9MJ+lpոt^6F EqXH1 kf(96" -a$e_w&tpa˷l6ll*׌Eƒ\wg ʞSOxOlKONכl*J3pzeV^1H\ ܑl✔*K5E 1'JZC8,Iq+0\+ӎ!Z%&Lݣv]wfaceHt,h,fM^cv:QeΖ 8=^(ˎs#xPHXZ\S犌)uD'cs60IhVm,$dH: 0"5"ahg#!c6/x>P+Z NyDJmFLȃ`|s (ARHXT?|-nP3:Y9Pgs>E)y'0+ո~PM;.%Rtr>?@Ϟf^T-(; hLQ㋕D=ȧÒP- Ҋ9|y*A\p`llTaWz>K?Lrwu~sH~WbM]\7QOKq5Ͼں`S} 2_0#g\Zp3}Yj^k_p@w\?։m&$(oUu:u!0k"*%%I^饀pw=Wy(7-=_`E}b;?ϢF&we#4O%@ l䌄oW# M%Hb_ DccBϪ!SY1/Y3J$lgvDmjV6` 5+: ul>aoS6w=.q!P LiN+CwrUi$ڲ+:e$n 7 ]8}؇3#2r/4f諏Qc죏wT2q2?藘 R1ܹl:Rh6yM6y~8  ST4;\&*Clt,{ Fվx8FRRJv\sW9#>QxLQ+GWV?$JpVM. >L_;+{7 {eVi#WP|wx@+>vL 84 ,'(`)MuF?9(!5\=Xj~I(?):P+PPHC6:^ _W[#AΝPZh~s\HMqZT`VD^ }E(phz{'9*ɠ*d֭ug 6yJD{(FTwRRߡ3Ƒ$w h˅=L9kƵ !SO}t"{<u+2Ӟ8Oxe}^.|s Ts`$ōhίQ3ҋ;g@x6ͰqfCl.id(_c@€1ABZ-ce.4~j:n%Fr? GȮ锁2Ń ZʤhK<406bg.ݿ'og{;¼^8-t [;A5DCP`φwܔ^6fc"DC#*Ѷ q"kU$Dk-nӯݐfE=ZpGđqfŅE3Ius5vAn7w9a}ܫC~z Q=E1 wx^)k2h/%'iamP:#D5G5<&0Zc jû>w)$Tte}(/f1RD1-1o҆Xnh]GXC m~²!;9-zs<9pImRY#?|ʫ,&~U =es`k^D^N>t^4ND}.> ]a3L\%zW |CF[U'e$q]ì=Vhp&`XkQH>ꐚh߹wl(u}AZV*)rdsGᾩOȄo}ˡu7.#(o|+uY.r̸M ΅D i3;34UU(zbBW.DD!͜'Y L" x} mna8H7)5 @P9FdOVg҉ُxgTʇ׉"Š603hluc2`ܗ-WuӭcÁSw(,y64Y3{" nHXf eT/P'”瑿6ҏ} +z ]E3&DsRlvvZD6 w5ztĎzUEw`݃Le9:ee}F ȇqa9B14-[+l<:*<ĢH=DtkY% _abo-r=Q<{mm1A%[Ψ{BB6 Z.ÖfSG={edhaz 'E("hY(/4*0[ZA}m勎#.Ƈl1\n4H ѳњ @) u总lD.e=DY?ce]R/Zr{C:B,pIsܛDB3i&/_Ή]V6l5@4Rv!7E KkF@LԼkz0Yq/AF ^L34/nRB&˥"90JQU2i ֳ&sψm m\lL`IgTWn6 t@h'4F$C(-_1Q>"!{M)] dODDsf~6Ȍ9V_OOw$XR]4!g"&&gO@yn5N '%u:UٿHI!) 2)\sP`Z[ǷY,z{wa]5NI+6q;mz_92)ǰ:)kD9 4p58Z;BGuN,8Ϟ)f`e>pPA|RfZg>}$,ۿcd3] ~p`>@ Ww:Ӻ>~ {yr q[+RgzWW}<^PPm{h B$d0B?϶'8~Q;j(O`;^nQrPi ;Aq3v'o2+, \WX`ơEv guF⣘Gzu,$/;8fUSsX|Ǎ\Ǣ):gO@9>5˛b E+Ym͇+BHe1^v=!p᳨HcУyHZ@Bb9ҫ .r++Ĺ(64V99~$q.Bő+RJHр+iIFQdA`Ql`u'܂äB5~(6S,K&bi QX*dH5Zop/sWsf˙W9:fpxΔN #{KKyROqZI:k.b+ nRyYՙq"7WM'^)}_d)ִUAt8&Kqѭ.=bp!布 k\ 7l _!7XhA;]H K3C2P{$x~퇞9|`#\( fȫ@1c-];@E~iPuNrrePaa*ŠtNuqNxfxb٥NRA|ky|ꁓ]$%^ڛYXc?|/<~%؀IϽQj2E S#!;T aCJJ%ۚ¹2ӪlIî+ZA+|?`}*NX8pJ|AՑ$6Le>ŮvOnrk*<1J-\SrԒ#zi̾0 E2Us+2DLԽpijvtUa[z__DVO$W)XY' J8 \4-Ϧݬ"-^ۻܐ0^Cq| wiNl[O`|MqʮbD^%i6%`0Da iXI^A9K_x#4/)tEڍPU%aw'^Ek3щ~LU*兢~w*k(|CzjPv dgm!xVFuZ'v2l'ȸF2Or4Y4,EK!~GN8k2N_1]09C]s*bz35dL\7ΔYqtuʻI1\5[<=s,osh9K'&! Z'l1[M&7za50] ѵwu@K>eH3l@0`2[\"_tOs ]=9jl0=Wiɕ 2>􏪐72Ș* ˽95çOrpWwKXrg?$2e#3.6;)`}U;<t+o3XДpP5b߱Zڰ,۰x?ң:aDyPg-693I^vA'"b\l͉j(m^(,4R%'#i1+WᲢM8G`o|C􄊚F8T@O>]likCL*Е QӃE2ڒBɫI)<p$zE<`LHH?Xo wN+j5)/XT&TugT4a#[9t> 6_ptYMRa{<+Y~_!r?*AL.|`G}*]]Oetݘ9bB 3:=Ox[ng\@Ai=lh* Kjǿ}5ŶF7CF ꁎ;\9jݺbo{T7C{[!YBoxo#9`׌ :JfYi.'M€sfP0gWz?NiYN!b:eZ0@:0ȦuJ׃PU X> ԴPN+@.Z^ZzΌ= XjFHsmԩeO?hg= fS ⍔Cgq5k,,?X˲> K/X[WHJ޵]~xHb{Tz:^֡xvvkgd* $&D^eMkW'a4LaA/Pޔ4*[$>vCK1]mߟFRX-us=(x vYԏPe'MlgtFwKSsErRܹ9|m%{cI, gj3e$̖t,tl칺*7|V QO2/0]~-aQdߒw!)VDE/.ۙ~t}oUVRKsHF8wlrssM\F+ֹ1谕DsX"L(wpXZ gB}Y! Y2XՌ럌^.\oqX Ga:'u 974\8rۚ@ckt(i?y lz6#P0n|uZ0ש$cy8{ b:B|'S8*Ȓj"4,ySny ۶~.$ a1Sr㠬lC<5\tJ1 -o0ʚ!U3U#>g#FuHNꅃ8|:4wiΆ[W앆A\ur%(*v|?3 vI=ƬNr~CґSd0YIw;:?7E5݄w 2k4j -wc{hIe'.`շXe?9x> ]3,V6荦5\@g}ʀKj`ZCC}~w+i%ɪ* "X-L! <!1/ʷ n6(%DDy'5HxH>IV Ni6+U~ml")J%Y}'Zr\ *ߟϠ?j+ $-Ѡc(cRʻ]!=1 . |j$[% ]G t_p9 %*d[qLRN_Ӽ4/s׻*6y4Q[kxI2sՕWG\pShYV*JVv1.8>FJ- duݿ?ә&O ހy&LbSFgu5dA`-8Gb {: J?Ǯ,-$5RS/ߩTEEnYXJa]pХg< ,0/w;)!rώKkeDNd51(s&'~m=T=W&` 61I)\_ТSLOS K7y Lk J6ޠ:tS:'^(:=ZP}cE1;ۜHO&Tj׋eDBLD aHۧVe4 uF;[YJ-gwg?b7X=8j6|QpK\9!}YR殺#\Adt0gb` 6I*@ fo#[^!@3Xͅ-0A iw`n!m؆Hܥ@O)Uq BPGf>-_Ӯ;t<3!/DѮ_F)G`v I"oCklm5tydb0=#+۷$%I;[diEʥ\TJPs>j+bȤjE!ji'f/,In{ԸNvyA|kahF*,K +JN&\v1Q6R$]i9(?T^ɽ˳'y+xKm.qc=+\놁|]8@xa,#7&ֹuY:1Aгjv<[Nw {|:*#JFcHfc] s(CأS\NepD+ *%Gu :_["pa`v{_y9{IBX˨ԣUfgzn壘zOgc SMI#gi<[L-!"*A,C⵽uI7dZ! .PrQk!D'< C15t65^ds h?4C:uC S eDz& eX'ݯ< e= zx'ʅk4? 7w\z>kP&@Lq50gm]Ӈӊߙ sMƷg,;MVag&ppg#B~U y[OیF"Rb2Ati,</=nR85 fAS+( em}"dR:=,E[ٚE3qP ܴ`b|!W2|Հ*3s*?-N=\ZW+PuWs$}Un~K_BQ>djc?IP%^e%KMv<\Z3^X; 0cwS)P)m`{ng|8eOhJLWIo6#Qfj\:K1pv r.ڃqGedS %1V.pbFAVyyIǭJO!q:9a䨺H6Pe2B0N穅S(%q-n. ,3nUǻ.Cx4֘2&$ǹlwXYM@Tτ~U] Qp'}X0c gTA`e8k?jk5`Ց2v\ߐR'eQ"wY\K:Z/(J}vP{ ۃ ݒJ8ȕ*i1UHW-Qw.ķ: *KDd! me7#L%g9Ј0PĞoQ-;,lfIGփ6VEEniA016J(cKznj*\6. (͈X~aa2'ֿLD%/~Dݰ!w d~&t&U~ه& 3G+iOMz`Y~JaɊ_Dh9 ]?y"~r!*0hoIǞH`a RԔ<2c4?jYBTᝰǺ~BX26pkS)fR4aˇYZ F(PkXxYJ$USszM".QUyi?t涂%ZILQY~G%zc܊ϋ#",9DMҏ Xg6}SfkC)<.AW AVֆTX IH涹[| 7@c+$-P!IuA/BmvϷYsCe7 @:az? FB3@L*:]JgJe*:5F52JÛÑR!l{eju0:}~~P,L{z*zn,0l(C1u vl-`8gb͊L٧t*ĊYvV(rraѦ Ug$fН,bBmZN2ɦ\FLg H" ҡ[U$:;m@Aoϥ#80<6 ^[)g ﲈc,C%3&w̛֒`yԻ%<&Z˭>^6o4_o~f?k_4kD `%E*JSLԷiڤD.e\򯟊,ouT'ՈRGwX\HaY;\kyspM\5G22$"׻sl Yz~}X7FlRȦ\ʔio?R3гiI \ӐUz|&/N̢`%ZpM؍Unw{܆-6y%۩c lz8iƓ3 )Q$8Q"115Xg0xst¯,|JN r頰%@o%""yBZMeƧf%)N(B%1E"~1v( <{}Ї8ۤ1`kGݔX8m?~ cM_-'5~S\d\g[CW_[Sߞf9=yhN%XKz+%̴HOd1g(< Bvb7t8BTr; +=J"^MsD\u\9֡ F.%( ЊHOEIv/lXn.uNs.02_ʪ*L ѸGQ?޶ XC垆AO! 1J00.>m]0oPD!ϮğOȿ)!̺ dٰEa4M* ūw$;܎`B$n$֫Co*fa8'{ 2Q̈́6M=Īh>LFCeU23>nYl. ό3ĽB4*k&G=8:kjDfuZϻvr[=ZGAF2| nBȤSmfLaC?9r[.97eRx: ; WӶ*,q7!ڳcB1Br: :NΧo}QP|3U?[whj( +*9avPɻ  ےXdჺM\xv!s\,67N+nh596xq/{P7sM!xN%L,ԞBX{- m%krЛg Z5~"̊Nw4[S"2 s})˭3ڿ)3d§tmkҖ^W\}=vkmQd^w48g%"{8L*kL=󊰭tCDiX1p'אzU@gيz'pu 0wUA)w1nXyzXo߶4˗ 垥P,4KTuYmќK>=p2Jl͞ `3#=[kIE1AU?u W\K!A~OyM1 iMc( ؃_mcքҲ)nRzc$=;xR 8 DZC]>89k}N\*zzQ^ C6@zoFՕlxD\?(0r)1Me֦K^-grn3ltʲg.@>\?CFOV~·FZ2<^x_+I@Nw'ܧWȣo)r3 6ŽMUl VP.L LOѯn&hlqYX} D@FVb'"x ^آh?o\DWQu"$9xPdJ_%S%80mqz6U/gҳelyd@@;Q6lY2dcٴF?%8Y%6 . ]`,yH$Y)2̎<C3CB!_4.84Q+е-B$*[/gỉylOgQ(/noȩ?S?X$ctjH!gMc O'T1f l-keV_>rطbv+Y+6QDŒ!Tch{0#rw<]pl6Zb]1 @4v -3TVpd9Ya:Y⮯{s(}E URv-% ˜uf#mm"]4g )KVl[\( ɽP zu}3"*WjVݩB$<g|Ûk :tAlfglTu =j_{A6 a|3<[%+3 9eӋܛJ6u㔦9ӿ ˓Q{'srqmK[⃾gȎ"؛W m,Lf&`B CPT6Srۤl*:\P|W(!42DW/n.qeFWa<E (㕝v+]BT :%Lu!c{`PRQL)B4<4J54i.njφU@|mru3S uW3D~EZ 6.S4şq& 0Itjkzj"qΜ䊡Zn&C/,UO8yP-2:ALRdprr1>ld*Ni4Wn t,oK2ލv*0hA^tuL|̯;8~Z~1P7#I% ,A҇KYdczF( -h&7G'~q6!E5mC0r0L|Pӑhn jm.TEgMs,I1fRcRP i?avOO.Z cYJ[+zPy&N|{e< ')j'2z?9tr-Dӳ FR2:!B zA>,zzRoZ;G-hz."OX} Ms\2[MK/'Rȴϟ?UfXmb-{|#GX+l4d2ebRl.@08QYdllA 3вaBhN+E_&CoӸj&gX}#KY.,꬞/ý &9KOPDQH 7AHwƸ_٭{Py> 5Pk[m!KctxC?R/9nl %"b mAy[04_D[#.t2Kx6鲆ya6kFhK}ĮWH˧j 6/ali̇ /n-h70X*(vkay<(^Č=oI 4Ǎm잸d?nomE@֊0{!8KV8$,A-J87r"4CjG}y qpl; 2T1i+u%}l;DC}*V8t5!D҄M5,}6OUڬ9?:)nCj/zݨiϵe=bޢ(P}=șr Idf:zx[)%ds* [\J*XȹB6Es(n'ԉu\ 탧'1Wc+  lt0PIOhb4k* ޻EdsP(GPWEÐ6;Bj %n  <F4RӰXV@r?.Ԉ8nH*IS$1.IǝYnIwAumVEo7aJo#R`* s3*p[6X!Aaiď}2x=tBkAtc[ږiwNV1xmN&?Ozg{9 7;#KWsCNE𘼯䌭|./'wsELGkD܈[SբĎ+f Yr}l_|N `awD-] Y(Fr-ŷh)0#NhmKʪ<@ROUGL >՘th=HvAD d-]A<$Tٌs-f(-*&{v4ϫ0lRIf#WYR;ܰIZߏ=b#Y][jN b52ߞ u;\@ ~H$Cw7*w͌ U/ mq1~I= paqxQn+k,9w!GGViS4[;~_=m!^Pb-2@W)}l4ّVn uC_~B=q0 }rƑOzaPAM"_P(uyovPڨF"[N\fqѦo|pj!2 >tֶB'Pk߯,m7Lh09V5jWG>!תfm)tr`"h9/,Jl5 JatZ>(̤C\G1< iĕ,;ؙ*y_JG.L?0|01ƍs{'H 5&fɷ:^\4L|p 7Ta`y+1gh\PQ[%8@O hXNʼ6`  [&:yl,EFE,AxmxfwVpb2Ud}ʜ+VB^jw$W<͊Fg0@s_ff-9. \SiBYnG  `@X h8ErU"#otRP^IGTEr|˰<ʨa k\$HONl^¢'>_nj!+UJn&QCv~BUwU^,;Gk_^R[i5ܡt/iT{~J% s5ǾټJ鞋{' ߜa ħ/нu`9ӣ>`a մp ݾV ]ȦfQ7n AfXΜW +D8!D~+wm!8(L`VEp+Db`0/'*௒\,P@]&2TS`8} [ zvh! UX$K:)* 84"-R4\~dC t`lkqDS]r[e 9j}yrTQ$$ϲ >4䖀1$藘)pq2Zf Blί,Wӹ<hٻ8$™ʜ747}Ҏ% 427%)ٗD+2m wTdm|=>"HϾXLnY Fj #eI1jna1rM#W5\NL x n7[pTu9nHյqWTj.7ͯdnO9*o pD9kkΧKvFsy Ĕ6/Nt-9Jx%+]>36i%2+h^mvG?ک@͕ʙ*HRH/Xj]kYܜ0\D%SG&-/,J* *dLӢ8TIφQx3aXyQ`φ $?h4S(kro%oufn cHLDy)JWI\/V./&fW՘yXNU#נK8]˂d\EGV4_ WJ$HQڜ ޜbqy<bޕ|yjW[<@.0eQȡ_7j»'~ҡ  2UG<`vr缳նٗuĖa^lwIctIBSSv,n ۾yN>c MC~`I%l m*p,$XTjK5%LR~>VL)4Ҥ'Ξ0kI!# N觞R9( /7U ':t>* ٸa-ו')7$ǁhSPFY[j ixfuҐqg!BPݐ0xѨ\YBBw'}Z*<m:i/pG/Eba{ϔELAMdi ?"wZiqYJ8ެpdTPuڑͶӅG%F8P礈(P[]Zx'K" 'Ҝ Ú͙ >Η?9;{ZӥUVAqHY*\ &o%lǶrdӆJ a|yv7ql)eoG;<-X=0ijayQqŀǜOh_5&⢼%goU[e' aPe^0P$yٞH$c#x $<g'R@Ǿp'huݾca,)o83\+[f.UXx]@Wt*tERW!ɨgi3ՄXvrnEû)X@zGwqֵpe Vv%+ *Egl-ߪ($HHuJPDjTͶDWJ5(cnmimH sb$dUohzF̝_MG9FL[n?p:w:%B}nvfGj^x@Gߩ,b)%bE"seQNb_eЈ%qC%9IhB{[g`z$h+,AO?#M)X}hPxCiLeӷ]84G̹&TjZO,6Mq`a>Z<1yF&4lE21S˱I^m@400%M{-m*iKDC~{.=:y =γ!vHmLz!,F N;Qr ę/T 2wz{hDeb7Ēn'-t$e(kԺ믳x-sFkz_n麿Arp JAIVtw%D3J؀Dx*ŮpB`S~t:+,^4LKxz{A\KBΆ,KFq1ίG'ґ݈W8Qqᗝ[f)󴢄kT(AGǤy?=itg-H^-!Jn59-BCv~D_Tޡum4`|$BYS]N\[*88g0:AM~+Rpm9u}\Ij`ӥnZnCߩ+ p2XE y̓f= DAT"uCICD~dN c5юSyxWRĝ>*l׹51He>VNd\\o̶`,4RjbOtlO3(?y7+)S'>Au@ y/NI9 {6Ace6n^jE6_էFTY>q}?am/h5X0r@W=[yqǃubx.O E%'\>LC?4M5,ر6ĝVcKpY;ÛRbv|Tb]2-&oʉ~*zCaݮ[^ P =2n-borrkbpȞjcKC5~Cͯ%&YsA}X7cvw&BB.?<1!,m&48%I4￁6NwrP_x&4̀;T8!ɹ>M缡(MmE(?)5/ڮsxa ɇ4|f9ZIL T}M g#jxT~ ϕf2r 9,`xyߦX 1i@FpnIVaN쳽[ҥ+!z&%6 L[Y"EPCмŕA)6p4>I]_18r!*ԡ麢PDKhѺ[ý[;I7\{|0#?Em;g<yUWUBvJ&W#,'6w#(2RX55Dx.aѹy)BWC;y 8a<@>;Ll#h sʢqNjsr}|>9mbX|t{E5J$ يOb rvBA {"MeIjZf#-Z; a GfEb]'>]MK{MʃWG_*:<#P}iTm8Q!#˝vx> ~8R,Dlv64y!C|OFòͱڪDa bffiTYcQg" YzH2`3ʾsQXN\ gݺ>ޭ/yZ&nI3N_d;.wVsS9ݎW8`"_d>rf{%RD2lϲO!DL - M/?C EP5EF*X)=f}Τzr%$Х㯿Wн?S!?`Hk䥓@]lNÎ'rɞ^ ._,k:=-%?g5VKNZIiqvW^bi~׾j9=0CșfbǗ*OyBBqeh~)eRb,c (ta꧋m&a! "o3y);n"{_`=w.Nv%9H"si|e4qʩ䯡GYq@Gi i~NPu7ՉV LO)KC׾Ru6Mǁtjo3f]#k6tpF$d,!}l }g9~w\_n)Mp_wo{9go`%'3k5>"Lj-0.>&*O𖦙)z,T{ AUQH&>yDݼ0'lz丳OQtW4r>.)pu<]!rhtH?^"xpLhN/ 0i:Էmgע޽bNm4]\$A 7~ް!fIJ9/X2I]WWҍ\iB jYh(΁}m)jJl[ѐg^DK1ZiG{35 y|uԢ -[GRM>K)~aFksO#tʍk q*AseeNUХ}EN1hVENEs$D(hT}OX!L;77I̻`h?KЧVѝ+D(*eRiԙ@x]NcG-n|'Qt&ZW=Sȁ-g6菦|<ʗѻO؎ZBsցr) %R{`ho@a2W\o" % k ObO;1f2a3ȑ,5Ol?&Hx*# PjLZ~oxt"";+y_4\pͥӴǵ!sm >:*U;ETL v,N]ctg(2ŏg] c-"gW#<(/U.SQ%|1 V]ah@7@hO~TE(|+O9_s$yW8W5HݰUf [ ˘IKEhmvT$#ՁhksH[)Nח/Oa{B~k><}*Vrd4W)u:Gv+iz=E%1IJzeI v9쐙vY#"}+yZV?#f >&!:>iUgR( ; eǗuidXτ1&lsX?FOG)"iA5$]}KXq,;K4S.;q;7,)bdqvGv_]hx-q$kn1fň%d%k1-ƂDT#Ch04r6]3JU/OzbpFׁD>@!A[M89{0DS赅D|+W 6N󅇱8ˀQ.UI?(H4L$(W/滗XWn.f)5?e`m½ nElXZ:Xқ$x[*+q1U%H:ȧC%}Ca[8i5孷D+>3V1ȷCo?o-@uw-"P!˥/-z_Pb*NO17)dT9BK"'m 7VHԏA\nK&CG ޝ_R CBƈ[jͧX/`ɢsޚ%ff-/ A6uq#r; 9 D,vtLqϮEv<DT"8sճ$n )`n) Tsi`C1)'e0䨒>6O`[rM6DHMZ/3 1˓jZmf~H1g"V6bTgyU6VK]@:6X`gG}pOi2X ~sh"2ּQ G$Y̫v듯䭭3{%l wz.lkIMȪ-6x Wn)VrNf%pJK|S )s\(,M~)ވOM5oxX3S/d^bQt%ݿ r /@ڽqY͆>³@,t C~}'#|m=~C0Ĝ|%J yV@]3`gsK$R|3Nn!6_ES1 pߑd[rU'u qr*RJX.W{ęƫr'9RLdN6LXm˺ǻ3jOZ[MY܌,m 루[34pq:_σ<:-";y~0PLM[n^B#"= P` VRA%OM>PJn]-]Z` & RF@B- dL;gg&zVwͰiSw~w {nÉ7KᵽE$7N/|u]Zz7IS[ѠXLV%}`.ESɺ5NΘOө7=K64tt"߰Bw}=w  xD:!]S%Cv"q0 ͚PyZ]q: F N7LG) yz( uҧ 8Gjt۫Լ'WoXb:nhrn jxh8[YT =Ed)ZF d2^KjZ6<(/ `F0f:DAҤ5E Je_DqP2QV9މ‘#C Q4wڢ)%UDKtQ )^";anm)xʼnO-~l8!G*H`j4Q~׵Aǁc>:UR^2iLXMQ>LdI*" oRw3T1t($J–+Ga\QЏyWe/u!BIlE)tibxa-tٓ{sv];AKУ+/. 7ei#Ry5cbIH^eWeIT(3s kQv^1uZlXS>Sŕx&l8|vD-W깢Jmlg=$|Gm(dZ87zr2ƥPoHEdلV6x#_Z 2(Emx{ 'Z}^pF[[AE!q?qVP! iFK 1p-6kҸ .;WXeN?-.zW!"ո3gM\rj58_ݩ w*SHe\ .J9'2YĞm2ÝC0g=L&E5qhKr*96ڱF eau$eIN ;gkZYj'vI9ɢ}ٕ")i:GW;|FuDkNitj#|D 2IE=H3'o[jAGI?9hE۬g,:='%6yvr0eiaE@`U^> 6#rfxY~U:EJJ%1ijCZMv@b~.dU2z(أ0G~B7╜ur&n|zt\Lr_`u _4xSu~zOυVmWh<}IUb$^wEE}4FK^9M$xfD;(;;O40MV$ Bԡ+D,?1K"P)c^kD٦!U/ḓFSֽ*},\HߞG;u7щ!u,x|Ib7#o_%( ıI 238#poW?ڛ9+|FH9}i䨭}Tc4He1t1"Rö~߭0e a̟Q\PoLa*f(+yruQEosNKVV<AQB[ uk̯^gNLYG !WE;L 0cv{bVݬ̲ƞg).fN1"P^B@izIs% /x[,62MYVe,@&D_!qNs;mv_ s$;m*!8l_"ؠ VaQRXH ښZhⳅ)3%j@52&wFQn;MJ{ pYbh6(9h"(/i;k}g#  f>Na.hMr"O8/P[G KM"jS=2DT]**oL1Dǵ 29EX hΰO&bj:bnZ½AuwUm7 4.k8Ldq 1I~#gczڛXM0eԂ!Hـ*_! [ݎP?DE0nOBQ>(rk@|ynDBJ~HsඤWor!ַ54o\TjVf#ZeF'CLvMnlԿN>C $3^s;f;rvmekK0w/pۛBv;0TYQt_$u.a)/UI)_/ IaI44P@zKԵ֟`8*'iElfub%gB"B'M ` ^<%_=xW.=Z/6!g, ɀDAHły:%>I]7t7YYý#RzFn@r0­.sDIx={lƵvLXM@ǖYBA wB_̴RJ@[L|RtuȋBt"^b[m!`.חg *wՃ7t?qӚx ,cz'UӦۤ+OX5SԱkf:H#{Ed d"K8UڮcԦo S d3-b8#OE,j]i} >"ʃle/BɡѵY#}f# #zqPjءN'+(p (hׁ<<ޏa >#c/dL^Xh|vXr̙Z;QJFAVC~#Wʉh&3nKH9zɎ0T*'Z<ӻx<8 ')KZ5z ) cᙖ +DDڀ.wb={y'-?IXgTBwiLZhb>8Pe3t̓n'Q:Qw$≄;TqNPb I1-Vx+2XDq8[lAT pƜx^NYsm>,dr$MTN˭/5 k=9H8ۂ CR|xVu:}"WMN)yQ`>^/ "I> j]$S}?T{dSב7B~}7oU"s40mn&=O]p1/( hN_Cű:Pb[-U$fCothL Bt'#ʭqM5`MB9§ Lcסd܉++6K;,S>) ᲯfiHM<@Lly xƇ{Ss!6takABHysr@nC*zX`_*k4]p"=2Y ec8 KYh]s+vA;fA V; z. f8\.-Q`4⇊V4Nf4iu4je(89\H_ƒMl9?ƵuIPY+rö+4(W$@:3IWXes֌ kse/0؄rn/;L0?!7 vglҵ[:E`<wix4(&}hHF A3-u %ȖE11mWFf*boX lc}I!L~ )D+!H%h "c@A­ny1ZI"v >-a=B<T,ZEg+uiH}GpPB\aI5%ׂ_r_%mU>ؒF) )1[{<_[=J¤uxg~Fob i-$GNx~)7}6"7#Ƅ4PZugyDllW`=Ef\ĘЯ`uBV8ݔ_Nm܏JU+4sLP Eء0 0YVܴ[3JX' ;> Ѷ(4(Y5Ak>='E AFsXL]}k-8H#er:]U\$w;_G~B2+8Ŋh1?%j}+ɥV7faƖS!֑'\G¥Ë`C,D.oۛY$.&lNl#`r6)x@j 1}܀1fBXDʬ{D|GV5o]+;xwn HvI 0sSZI%**y >4/z5 bu))??R7n~$zW:$|wtR(S;vۚE\OuK.:s9Ub6G+~l/.A]7H,Ra(n1 4-%p=u!xVrYkEVF!)XÃ]+Wuƨ s 9'Ƶ1]`}jsU&#F.EP3s e6)BNu(j-M͊ GdEP{~7*dmaa۶EǙ2+ԽRKމ+ʙ_@=f! SPl? fD:wf$;Lp6SMӨg}yG)$k J =wBN bK:RFk?1cltCS'9Lbg,W@Рƪ%|2>JbdV^X41tŹɭUK*FaMvvOٻGx)~p{>pӖˬGt${ D #ig%Z aUop-A&'r9S'3'R3tP_|CR(m3"M?` /- ԏ19'&&T`1OZ|D/R],A/ݑ~S/.k-n}'m}6|ξ XRD{ A{W֠,k܎etOPyg:D3 }hXaً-\:>iK0;!5u7wSM0}zq鼜]hawu֩"^!O.Qƺ Vljo͛'m"EIWLߪ>HC]Kѣek)^~, (EN}&Z[KvRC 'IQfTHCm:IaڈvQ0ygk[xR/ue%0}*j2y0,E|53$Be 6ŧ4#nrf\m%$3! [ci`OCOTQ` nJR[it1 tZX%YuQ\ 3wDŽ QeI].T7gYMWxy,SS ^N䭦ˇVjx"1ke\{,`D)3ט,mt?^A֨=N"|vr_LF4ˆ9 #bNSEp!bA UP_|YaE/?OKSi6yȘLQǮ;:/+4uXB³9]*\|(3 9h'TEbbni(=D^%/tn]djwfe;\)/[H&ymb^t*6ʸ IaW>h/xex-ƾ{0pq.ZnM }3!X(?3g!ɣM׀+dO<Ŝp8AS\ 8I*%[d@ 7p׉cﭻ*KⰭUHDc(FEJnGc0_t'0Xe(ٹ LvǷM. 1ڇ bmaFgEsT9O{'8QMOWVګN\j>蓾_1WGwvx+mGc/p]סh\z[J 1dZ.lzlZΨW'17uURÓyI (ʒ)[sJoQVZ8~>k#ma'*ߪ2mG'Z8^_aBzV y~&Ԍw v^l& \uUg24 joiGnj#}Uo-8CW0OX,&WL 58nsh'6!A'5xDY^3Fz6[{1WIK_ )dA8Ӝf^CoU_vj@`U΋.SQ6eXYF2m<.|P H"1` ~mP]2%xUxY0q8c naP"Q)tk5f{.kCA; "X4Ox:]`!9!5dstl-|[oY'hPZ,{Uxhg8ֽ[3-䟥ߒ!\R7ΆñͽMқ 6`W&<)ڭvv9OEj>b6ns=[KUd)D2MAPe̘Ek ֞.Lb@͊lu`ܳ4<5QQ%~Puӣso.^'Rwp8?1 A 8f%|YCup4U,̺b}"Gk͗ek 096C3b`x6rv(@;Hs$A(g]eI.VpV2׏ToYA8 w+rI9p\^,@;T{%<')"}i\$^sf`AI{+O^6lTOY~(Y]NDwkiͯ$k|,wY٘!%܅! ;1 O^aܿ۷ӎE^pkZ9մl}ﮠz=J-,CĹ^yԑF|%s۲@~^CGsRzP[Y.kk$E1ƑgPI{X:dE{a\b1&`ZBI-!! !^ j3`eq>VnhoE-Z:' 5&ݫ}ƎY$,`]j ב |!_TmpS]̐Z rQNu~}һk~ Aݒ'l|и7^/D%@j՗[5?+߸!2+Qgy̼ 0Dr,UXTzܩF&ϴC՚KvJ56;+Вn?lGJqd_\\Cxd/%Ԡl5z| npV&]٫H&) :wcgudaԫL"ɾqĞ+_PxH_\fjMcP,I-/BݖD)J \5>'"mS2&j F%'м Pa,"FoKE4zv CD5A?1F&LC$e Z|z*| LEpA\oHvRLByl6fV΢- ,]3TC:jzy'pf7q/I[1!LU_. j$#嬪P軟N*.9T[ "B\bpnO\ P*Rޚ4 eն|N{&S,}3qg8;=rp)YrHÂ':OM%SQaP [i} BP 5 h{Iw]R:DUx( 1 ^P+UnElr +ۑ%I^ɉB7dHǏ^ blf^/%pn*7a ցٜKؐIvـ7m|38}0g2&w\߷w;Im^4WNWD ͅf=2$_-,w2 {!yӨ.41zp0_vN .S94s_5 (I!nBOC:\^2XtX6l?@q аyܕ 2S|4^U7 ? x,T4@VBP;i&e~uҺQI%--$,TA|ś)_JYײa; :Ahe7lԎ$7_!@%SLF=;>j@fZr?ĺ.BqqGT8‹C3+@\4iE_b2VT3x_rׂ")"4Neb'cmEV;xmp퀼6GGFZyuK_mkddZ]K_W0UkMo e5C~ ;FzVqh϶Ɯq7z!:+M ;"y5-y?F`ᾟVX{;clD2اV'w}aQ45m$@y5T%]ψ6ezXe9ܙwtFs5T^VΧpf*wP[Izj>i#GvZ}<8h <*KU /Va!LBToo\lj`S+njoTOU86^]*~ۋ" ?*-V$|&OC}'K"pr*>i~ǵ{w/<&r~'qЦIMUP"Z1h_q{hSN&9"vUB6J,.؂R-lu!w;#!æb9gRa.sfPGh5csih@[S!յJ#uj7&9WS>ap3̓]=z>tS!L#}YP])I r~&_K3QP1!'E"Cz:S:5Hei5Ӯ*: XY,,}]s9L|ja;v",dǪ3&B|\4 Q{QۄOe[ِ;^HhGVlހѮW. ֘{yfu0z_:=XNXhG֢+rahFϚZ6+}}G;TV˧ ̩ 2*L *#ǶSՃfߗ:DѦu\V'g&JDF-J2,()G.Jp$sɒ2| q.s% +#8; TaK<{q2o1Yaoybߴ-vON̯/ww`. F8So0qBrUH2 ڿ_nX"|22FB>MVw ?Z[>(+OԠ[EA뉦J/gpST !AISRGQ'aNޜ&:QY~pk܍p{+qN$ C%;"Q n!Ī@5B՟.*˔?^,j:s27t7v?|(JeuacjRjZGtWj/ď>$+"8ouN $.OM\whƦr j !bf¶Y TcE-`0 6L *ގ];@K+%_{Gb.5SjQ0-01Av:~^(J{QoĔо3qg>ؒJE V iMm`^W{Vn-戳[~'$-qqnB dvƎ`|}z59 M';eT?@7ecQ_CXXSY[>]hױBy\W1ԺӨW]+lAL}{,0bEV~eH l^ |ؿƵ:8E] LID^ʨxڃ!8iUb\TMsu}IMHzHڊ}Xz`-G}s5e> ?Yfw!2HÝS$gcLadJ~YO"2$e_ƍ9"XSd'No172 8I6Eͮ%u'N} uܸy ud:I||^VvԵ~pKnW)}0v!MK9a/qҟ]5ظ Js" eQ'gb$4ƶ /<_? P:BE_XTK5Pd"S6 ;?NyOO_zGV1md!]XShBulxDhZ>ԓbq"bóZPg׶_Rr`-,?IihdK:: QbIjreF@4H%a?'s}OI\}* o%^J@/ Y?ez=:&ά&'QbRp;4= Qwyi) {q Q=}KЃ ؄ۖȤ4.WEEh(~tVeaz#2 Ns)1Uu.497 `j{zu'wVze}͗ CEhNzT[  1- 4\B,Jdg'P dBcr}G:l3Z.U(#FI'zOaY}]@jf: 7{.㚇QK̈g^i zyʣXKu)mrGꃓk,K SIG9ps)8]R+.=+eT)!:Og~dI+/Ex:-ǖX=#ֱ-nLkEYid(/6&^V;S}EY|qI' Fضt4a+Υ:pN]T*x|FG^`0LUi>lm)5xܚ4P^{<8eVk L:qiԳ$+@ܘC#jI SaXiNٟdžU[p&QԦP}u9n8R#4ζZ8ZN|\:+V< ‰)jY瘐.U_Aov zi<)@ q?d~h-o5$ QiE^Nt_6 ؠR{1aL:5G2!"E:E9DŽYmКiL됶|K.J])2PS-Q9wm"+}XV:$S=sdt=Q-z~{i\iJ@'4fCя9sMqduЌŴ#IqtA @vo0Ӄ56hIQOtg%ø#0Hׅ/njUԓP4r.ȸkϡ wr Y20I't+[ uaS;c>i|δpN@kA9} }k _סl}~/C(a+%a)cNx$3ڄoՋ"2`g&c6.g4#Ѻޡn~_^FxxW>0-"ڧxOﲎJ\ e=7F Dfȗecwsx"3uHZ)YQ(YET{b&5~e؎;`5`Qch{: +>OvQ1ہ ܐ-}[ÉptlyS.u'ВcΙ$ Wx}- £ŕO*˃Iy,5S,V@[=bEڵcd{qBi#(jF @2.Q &e*NW޾HA؝ɪt{i[HE\*{f#ԑCCK;=H܋ۮa\!&a"yzbk~y@6j~")x=S8A<2|jЉ2@zbucX;;ʷ4ՂZ:T+= nB iWO'C aԸ5rb*J:TGtF c;5Bݶw,dۼ#>h A(/ϝuٓD1H0(T2fo^lkP <Ԡʵ`Jjyg{W2Rk6*Ⱥ13ܟִ(ao4tus  TaRnu__Wɡ^aPP Ғ߲4P|Led}>KOkG7'W?8|"l؋ 01ӄK0Bq)lhuG U..&oŎ殂x~j_qBJc $:1V1'C4,G9 waKOۄJ#c7A"qxzAiYBxR$S}4~{[*cm *0@L)>Oi,W u=X 3,~ ms;|Li#*A ]_fhm>j7]~=VN6~x.?6 hRA9Twmjpو03{Cx͝[VqFgvױW6ޣU=؛_;L*F_?*\ׯRG6Q(j?=|{$/*6ZTP"F 29ިOn "]FgFhw+2 R_țfW|ɼ`}fH%[usJg3-{HH"tXtt,l\5M숀4g8ӌ[NG-A]_Lv(ś&^ T-i`&}=_Sr#'7O(p\tY!PaMd-E=MO7;[R{B ఝcv"!]iD6(NpkfFFYODV~ ;1u|C|?77TpIu)W=f~}Fxe r׀`[3(-q;k^t)_>ߪJḑkv0ӘdFADnPf#]$j0[Cg`%'N9QILC<&s֦FDJgUAhj(Z*E[ڤ{T$7_*R%SjG>{26{y'.gAPut.vOK瀁}F fK r!YV7 W _uHD/MI\z6ZN/R 29HZ7U}g"ʜ,|$FGQG 3-xCB !EȤio7g!f.%\R]qS[v)M٤3TmIU/xc}gQ#AS\UNF SKg5jzQz3z Н,Fq̡S^xqV5<QҔu/m]"1R?̏+BѸN3rQ/]8WuP c6G6ũ&0ì]j$%i+@˃e'9B>TL>?r;)6©j+U % G_Y (ؒ\`1& 1("mN#W |C󠼳#YXπN[:H֕-A |#!Gc|DKx 3\霂ʖӶ0G ]bH"x7Js>OM? m÷QKĪDuD^8C0Y(bjI2-0kbI$+_yi9.m2!##^ 3aoڈ9ѧ8L mbXm?7$u6ADr)Mٚɨ7b'-O'(D&6:7Hz!T%OC)e~/$;np=PNx ;Aj5蒬3}W¶7`S_'XXƼϱ/Rw6B_m,VU*= C0W)L4.>cuȯ1AOTĨ D2y|Zx+`Sex1RmM?O4RvpPTa;O2g CU\ߕ_'l8z8]iڤRCBx)aZ7CTI'~S>l 5}"`43A"Ȯ/9QM ˉB,OY*2k8)RXDŽIy`HKc.Bp)"Bc-y[}P~ֵTgx >lr)fypVWl]Zid\b}k8>TM&8f3˛A{TbPFC,N/^֐,nF&4-v#RT-E0X>vlȆ27^Š@tt>,0}EL/K\吻 [RZ p{eO-ʘ*D^J,;bւZ=qD&o*z.4utԭN3TluFwQWp{Qqm=YAMx@𖫫ӛH+QF۫I&=At *^(_uN2!3 ;zek E03pPqpEk[w,Nt&JG~кVL𙈷cX*$r" cPIS*/h?<5Yܳ甘.@t!9/\?oy#\a>'$AePJ?C&^e܁Pu 9âFLxˣEu0 8ka2P&t>$hۉRR#^1,dI g0L0 c!yN8ݙ㣷BEN8("i']hDf#D 7+r oF88@ђ TfOsxsK?f˾VOE R FdMhD{,I.hʵr}NGJp$?eDQJժ FZc5Q 0 LvѿK,s98!Jfulxsf-OC )>qSoPj?Z>%-ap&o0m[>T&q" RT[Lt]hj]RN_mvCj4"'Nک%A%Za{t[]y>f-K9oUE[NμGܬ9}_SkU;VYawCN+`A_%OY7 S.\[û-w?!GQIYȤ!Ҿv6!m٠\ɀG$g҃kYT9N19x?Yލ|9Mm%4r - QVA)Wx Y||P0dʼn)t;BKwd{;c2)G%]h@%?[m|obwVӨ&:ixyxxTr֊?z[˩ ,~VJW94OqcK0["I<9 P^6?r}|6vcO3QAaVZֿn D4w}@T{r ^^rj0pF޶ό`p! l#cp]pZŤ W%q]i{`]o@]*œ>Lrqqnw: W79|~aRiݑ><8jufG!/31"B,CպgEr!hvl}a~F$ugUG<~b1fም=6h@"..d)ӄwV}/Pm6PBfs[ *ib9hmGƟZhv[6XS;nx,>TTmς#Am]>F*&pR@rD݇06G< =-O,%eؓM,F#q\ئpJ2ߋS*Ӛ[GP™#kLjr/`ݳ 4+ vV$zoy@sAF*"''3尒Ϫ#Km[~2Z*>"%SK=` dn$o&KK<Ͳ`DNxDC% !>>݇]>=z}4)$o#ey!gfvq5X0k#K{]/+JAa^c%Qj2W8si0sϔ@sj-a[9=/ $]P"xŐK=Bu[epqpB3` hc"\ 8b+5$S&qR >;7,<_c}8?bGG"/Ȅ )Y|(£&㭅noFW8} ߣ p5Б31g;\ؕy6};|mQ##" M9@3:-ݹ ֻuoL# ic'-lҏx}vY+N9umR!8O-yt:TS%U=Xd@E",2d9{{C׷(4I:ͼJ$$?$$CLk )t1rxZb_%3)C5 [ׇL|+PLy0V8턔ʷ%'CZTԈq[L(iJM3n*ȕԾblr`HOy);=[ha#SoLvT{-quldL+ƝIVww~MݍhMQ[+*Qp elP.tA-@V=3rÈ/m[M&vy1QYIpowLY; /C*f$_F%z1'3eP8wQw^RHs9[7v.3|@DNoo{sΑs *r!їͬcu>9/^Hj^*bOٖ˱ ;><H(|>:R 4}d ŮᶪL*| |*`e_]6?6xԞ2Ma :쨙`T.Fv|ZfZ eIz[/@4 #ڣB# j^h).|5rhWnnz"= |[[ Š'ı)pš1<ach4 63P@"HJ :=(ґ؀ؼ-Lb{od<ʌ~D8QQDEo3 6ug:ӯKh~-#ϔ)9Tvlw/P:ؖ6$W#IW[To\H:&?e;\W U1`ɓA(OF[ObN;2]lc׈!>:]@ͺxg)]vD@AcH٧x5؞KY2JD$[C9o<#8C6 h =Xu"Unk ᇳVLX8 C(zo жҏ-u*@}6D5=R+|F](ЙtW%4W ZTh=yWZ3TYK'7@FZmdϺbɷAJsdJ6 ^pM0bu[W./I`#!Urr<7(<<]rVUlUK$/jSùZCz(\,ZcTI"k4Z̳ȍ=y 83nq6T+`!^V]HR`_nlXq_2&Ere7;Vuvb!e!+mV $z?!^]gϗq"erXuMuU r8t?y]!CtмUUh9{S=dSq8ƻ?cL\[T6DVȲ)Z=iRO>2w(yqW.υ+!6+6Ѹ67%!w T e2UvR6|ﴠkwR_Ƭi@^/,XS? Vs[KtQq3yruX}I:RvY..OU 1A@.c &]F1*i9oMK >ʞe2OXi^T֙p(Y%b!̃Jd(wLr'Ҭi^>LjNJ{0pG/Z-.<$X$y&$Cq#d`҆Ty^`n,UcwLNYt[gJNIï"J." ^|ú _Q+.>#xnWX(Q1 2N`ƋefLЎh2l#'\|P31 >5yhfWTYq͎;oq}K::F*A-^ RRXRX]^ȹۡӨj؋f÷ehJkBhm|5O,Gȥզ4 R|LuNOEg.ޟEBDd69_BxLB}MIh/1(Ve $:HVv6#?\Jad3:5Kܔoc׮߄6'jukMc+E|@ʖyu!(#¡ nyk@m jo)$(-ń/ k2VFH1%]+(p((jO]ik|.)vwZ\ơ73\BHJ\F7'+ &;9A($T-{u^Ey/pDD~ܳW9IH"+1s p#{"ɒ1|vjBAŢ@2M:~R5m<an2 1Lj8O,W,W4Tt~_+%M8!S9\:W~ZZ%"-q`u"JEg1`aTG [FтϦf9/d#qϟn*R2FZOQ. z"ɭ |- hLyhA)© ~U6S8j~NmzzO¡DfοF6׎m|\ĚS"C4.@}&}d)lإ*]^P$y"ܚY~K@O1=Y׽6uSUO]uA/>8F7nJ ߅) .co2rڨFĢt1b3scd, Jpa/Dr7p_ -$F͋N8"׵mDmȖLPBk9Sjެ7NvՅRm5Ɔ_!ˎTԞExebW:AD^c}`X _u3[a}͂%f-E#+ gP]ÊIz:s%}iVh~Le"=t}ìu*(}ņ7\h bX C7?Iϝ%j 8k]&*H)Z*me\}>(W9gtOLJhUp=p5.[N_6'oX@E*>2}1a3أ-Z,>O}]J'C3-L8m]dvr 8xisbVtk!ހʒgl_t pt8|ͅWMu|]&yBO@7аa>h@2z M"tW ni]awP J3I|$bh0xeqYnB$qVXAվW;9|q%D)5'OcY"X{{D-N#g5K-A\ZZm3U< FI8hw0/z^-4P-5eH΁v9ona!%HUѵOqN1MԻɎB3_ѓluL,Jz)>_, |XP*"nLopO"\`qњunJx7\&c˺=m o+~xCUc1nzQC0t1G]9#cjESIszɋQ)/TGb](N~ƪb@$lɻT~1!#GhZ"XB}X_b}F\?ې 9%*zjq@hIlL͆,t)@<R4רR0c0i0"ꔂ N@䩅4nuk!I٘W3(: )IbNfo^؈E͚9|0犃s2 '_DUd 0I D;+RO_KaPjՌG;WrWTO=p) ;\Uu 쇿ߊ}k1ϫA=ZUqDwxjM "`lˌ&A`CkŨܫS]3_`*GM0XN1]a9KX\`LiubәcGM#]m(n*ޏZl@2:_a"| Oh肇om$чcgxvD؉2-)3jzݤ2tkB?Mwڟ.F.<6TCU̍Υ1243<˿@|Z޶ˆ篕h\>G\L&o {\)X@w }kLq5qFl Z9b r]'])E4ᚂI 04]=qZ xX<qTOT LrU9 ^eFXĘhۋ QgaP] ݑG ggIE[1W> # \H.Ȉh@<3TμFu1&NCx  f2 "xfe}x06Q46ؒ0XJF?(pkbKa˕g굤vT>AT:~eb$VhKك>1Ux`0Qe5c t=˭v>7ԀqBM(ʺ9 7v6!_9Ces4} Vv&K,Scy݄9f=ARx.l*hX*ṵ-WnkuaRhL. cƘhBb87nPmR2د^E7-UPdHLBO(J,5#܋x}.`k x5g{;=BI1Wm1gEg~&Y;q2QG5P<萍_3+<8t_*O.XOn폕CQn_K@@7\nԷ'V?$cVPM#t} mmnZK1flZMS{yo\\TBc݊PhUZ&Ԅ Ye&X^w3q` j׋xqk(,dm4Ы2nKO~j&+;-([Y=Zm)4Kspk̂}L&5> Z+gI:BWuSVhvsk 0 =s=u߇}V#& M0jTٞqgeSyC`YeI4tBBk:g<,gqta$j1U})*QXbOuk Q9ƧX94 J‹xx$e`(4 n:4w@>L3l, 9wsa4Rw=RHO!EF{_BnXyW|] /Oﭐ9)oK5_KiU rTi!`hgf-hyP @:M{}P:i 5 BW #"%jSeO`8*32Ď.#=b8Dt~ҊUGP@] TMhWjd;L .:P U ]' Ë! GuW5)@VK{w[|r/kO{Di n(O22bQ;+$#Ο ESϙ{5JCJ}X)F,| )NxX'~wH'1@lp#hfVwqgId}<r~l͈hSD<u;ySf..Z 5{q^y QoJA@rnԱRD\ ?Sj CjtרԤNCﮍlJ11_c>L~]-D/A0=SˮZ5_߼Ql{J~E.cvMqjq.to?Acɍl#B w'p7icnf?#V\).RJ7fT^Y]ʌVci敓Y͓r"yֵwKydj+!Xt6h_uq&INLB"$̲~w]aseAC+ê <%ؽ{>+0yb4edXHFfN'3>FJMnq4K,]x9 4L~I x;A҄pa'ۊI.Z\9tkw_Hjqnmʛy[x#S $ERTbi0G:,nH9GT4Di@qM񼏰=HRPUND)M8%)HOx/w=aRH=-$1e>{Xsj:B̏MfS:I[`ҳʳ&t:~Ã44Vx5g8o42gY:g׻Wko4@U \p?`qAZO_NM$LGw\QXң\iԆH,hjOF.eC66Y hZԚޥ%] %vEO {% BSIX#MAF>`F(IJN0w%R L h̔+$mOmG޼FzŁ-i2Kыkbhk8ucfΜ#Beu?ZLj0[DnfA..X{^JblWx*gfD8gD0UaWk&H㤐"|n|| ڄf:Q?YH2 GzPOx"9coѩ)u=p(/K>JOϲ{^4\w4CCKH*[J{ģw]:˜qNy1HZ5IIŶW-mㆤ!SxDO"d6C4H88}kV!1k^d|a?`:zKMX~t_Pup{v_u~Dڕf9ҼHugzSc<40:Xm!w/kMl^5\BFaʣq@_\':2u O{q{@&nQ =ڬjs7C{2yf)W"-f@2BoBD"VE]rb˓IBm}TNY-@4]dD}~t<7kAmd&@sV_=m)%Is̲7sv9/3Ҍ L~QF.;4w1b ^/gJ䥋j:Չ IΦ8H~C _IEt⌸ANR-BE1;ˉώWSd jߞ 8 s ]920otn,8U)ne13A]7<4/V|lX;Q2[ЅJxk}#V:n/voJg)qY-'漬Tlz\tFA< ˬ"H%Vֱ'7NM޵aًe:ꛞ9p/ӐF=Qls1_uAP,{Ha}rad`Q=.~ި_-'"x oV c?ΌQ^iZ4*,aҢ4]qmKS8K-`_I_/\u ڶއ#evB3q8oİB4 2}m, wUV iPz"ҽiH~ý@`--ZXs9MU0[$6;i7 0]('۠(t_% " Y}V?#|ڌ|wQQ=y,J kAZvYB;6PHA 7pjޣW4aH7 )2d$[U8;;|d|/Cp:lwxb7[5$֘ -7vGԯf$6 9\T% ZFufܺEl&b}T)Y:BS*<\&F8R;X;\·I!C(0A*_0qK_ɪLdsu2VTb!dcE.-a yCN+YA1hy,D\(u ez+[0{,X6-z} -"Gμg0V1 ͝!w86l "T Kћܕ)],? KOƐ /.ԍPZ?)܀I&3nԖbuʒt1id>(;x¾ؠh.#eAKRX^aRÄjID ZFdR8nA?ٳSLLݡA)JLݏ a#ZꀔwcE(6b'Lw`DY6Ԗect\ W[dL a%wÙo MIu>\ssLmAuk)Z)ױ9^}Ykt=ؠ*>01Д4sݧ , D7xt<6щT#BK &)eBwx8G=ReG){h@!|ט ^}k1S?öqr7,& /(wmZ< C(6g; A6H8>hgǪ;S2aK:X+bqoFfx8 Xf=M~vx@տ7Cs~^W 7!'><[ +dkK%NG}C+ȳuXvb^9/wC,.RذRSfCqڬL4Bۺf[Q>M+ݗUkf%axn?0.m>J CA̫~۬dȨ9\P(cG1OIۥi<q cg5c9?*" {$OFBZ?`083S۸;tr u  ^v&8n Rpv"TD7s\c91Vmp6brgsL) 68S':M)vq 2ko7Ja.kR]9۲/fX6pU6*$얪2j'n4|-z! oDuWeYdDg6DEG| -Pa'ha{Z<[ rxdMx\Dlcm_1%<ؾ.{7Iw>5b|udQiⰗjQE[#Pbˠ(rn5[I#aLV [0Y')_? cwFmA;1I<y>MH7wR+wGq\YS1VZd3j 96Rhz3,DSٞJ.Yz ~^J>f_~tT' ,π5[(J^gH3rdK4'dvK^ rLB}}V 'mSͶͿ;nbG mIäA%j&FǕ3lv}78q+T0pr_xa1U$"L.r¾6?&C 1m {DG euQl.G69oT,x{EC_6Y@="oZ Ñ:`k_֕2!g7\~/;DС@ tJp\(KB"H,љ!AoWe ԇ!5Oc 9`&@r-?!/.z$40BR9C+3l(g wpoZtFqt0(T^{Ls-G~R,5>!KllWbWvHۿZ/_Fszs[lLQ]uoNġT˭yOәc@% 3]mE/A% #+HkXF1 NOԼY 6l/I\@Riݟ̽LA<;Rj6)c Cqh.ה54za2GQj 4n3#=>ģxQYVƟ ')"A.=^o>w:iH׏^ ^a) E48:龏DtmZVu9]*Y;TZXI}>UdTC:^]WPdPno=--E{'P?- w8:ZL7z&ϣ]AϟNgE<0 >``[%bSgfe25^3oyģoTEc; ndr~\Q@Xݡ:ʚf)T,HGג_(SʉQyJ@2 +H4:<; L4^r]@n8C̠B pS K9t*1o)l{f$)~"UzOq5T,Ӆ{.ui? X-`S$dnYw$,G#Pr|> m2j_oHL!יֳ,@{v?7K) >ŕz^QONUOFm&BbB[@zdo>q x}R߆Bu"^HD1gLtAtdcLI2p8O`vc.k+5T{n_y9 Cu$L;눱S[neЩ| !4kh/WEYIlY3DA, ^U&u> po V^U0b٠H:J`Q m.?fݦHΛ+/Ґ˗}{N6bt4U<@:\tƄ4uII]!w9  RꮣmH c VϷQ%)3IRFSyT&&9DW$\g;Hq_1}C~;Li7W4j8e <bs/Aŗې--R  _>.I6Ebb9K!A8;b< pqo=cљj!60AЙ>r8^-LË66/$j&iZa 񲧥 ҲTܥJSpY8έe8 ԧX|D FMޘ[3.-9xME'a!(UU0bCR|x||& 8+{N.L{Ynvk X<ﴷZ: ;lSo/sŅk6 1a!߫s]ƔG "н 92Oi>uƏ{Mz9U[?ζ0Wn8TgIt N~6]/ݢLGF89=) UϝC'z3kVṋBM/tWqOdD7T)\ōGZN9 A}4^D:n={׺\1X=БE#XZdp0,ET;YkWM;S^SҤ9~(~ dy? er˾٠ I$oklyS{9N-ѓ԰6'C`9 n'"j)hC/Q&]\t-`Q!ɾ2z9AP\$ 1Ssԥ`EWU07 ^|2*nf9Q+P-` d?3TǛ(B`pR7j0MSqe~J\"%5% ymg8f4YEі^r\HHi@iO<^*!8rE)džnwC\HAG_ ~p'Fm4SQcŨ1p hpeNg#oo}(FҬ]T!L1T.?ƶQv"L0,\i/,Ass67tz2ӆ߃Y΍*/vOk ͙ۜ9 ! D8*_T_cÛH0Pܡ'~6.)06֧ÇYuB18zOΠNQ t]#n~%nZ5wl= yr3idZ\$}at;*|qp"T9Jn N;arVvҎd!N/`PZDjf8`pJY\Z:x/0?tq?DI]]= GZ=d(hƸV` >|e= asCE(Lrl70cJ۸tWNVdݙ!'P<=9>VZ w!Î+!~+ZX4 V:\oj]@f>AEiEKyl$$Nun1sYl ܢ*,ge"K`˕ZUxnѱ1N02H8["R1 w=+2i` :4p̿ki}8t=[jQQ%?e=:8=O DDjpRGCEd 7uCV]'N`OyPo蜰9ng} BA^hPu:o7mfsBǤ>8~,;E < YZ