sssd-tools-1.13.3-60.el6$>?̖5&x>2?d   A *HNXbb b hb b b b!|b#fb%P%lb&'6'6-6(-8-94:`GbHLbIbXY\b]xb^hb:dIJeķfĺlļCsssd-tools1.13.360.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password[)&/x86-01.bsys.centos.org sCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64P02H0KSA |5r#1FR :bo3^ 10m:+}MHOt ?tH dC A큤[)&[)&[)&[)&[)&[)%[)&[)&[)&[)&[)&[)&Vpn[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%[)%f5c397f38b0775d0cc31c67a713b30ac4c3e8fa5aa1bcb2b98a925080546fa83b94df0ad7e7e6f501583bcaf112d7f37d9a581e72ac22d193501a1f0cbe8b4434875ce29300797ea14c61a6f5396f574330416512a85246c7e01981a4197413242b03063b61c696a558cda4617e82a7c02b5e13948dc9edce397d1a7491e8fcc1d2010459a97c7ad5bbb048b86030355c73e0235c8baca4121f7841274c5bdc7074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45eb180ba6d581afaf319858c367b19f92a887d40697918e6e10cfb37fb4d3d5f69650d72d90ca2e9d64239f9e5500b2ab18a9fc9bdb32fc4d187140ddba6a6f56156350db3af3415feb9708cdeb7b07beaa673c8454aa23a6d9e27264c5fc18a308af39eecb3b573cb1261d1d1ff797e5fb5c461f7fa6566c2f2c9588ed52a215a2044d8ee186fa8e993fb3407381b7d1781e764b0aeb22c6a8e9fc193fbb030da8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90312faa0bc15ca0607109277f9e39c1d5b3f8f870b22ab03d9cd843dcb4937f23c898d9b4aefa781bcf8722e504fc5ac11f5d42eae2fb68dfe61122b8f98044a5d3d205d14a01e31bac7159e1ba9e65e1cd92e17b72af1eefd70fd8129c07bfa32a37e4f153c7948135315a93ebc523b5da3ff74134e37db1e58707f69f285995751ea01896d4b36ebfcaf460822c8e1fac3591ffb8062729702047d1feb185eb0306a72ed47048c15ba94b54fbe85fa0488662543060326e892178173483a35c79a25c04eac19642dd5c1de9c5715dca1978179971b917e21570b05010d9a51b6cbd6c2adb56fc77c0cb0e14d4575c99b507f6258409528ee860d6608f5a5f4e68fb90fe31e5abfbf19ea48c634aeb350f5c77d359556d5bddc40dd343e3210c50d992b8829d02b047b0aed7fbdeb05437563cb120618042e1607c36876699b64bb8e9a900564768929f88d57e798bdfdaa250ca225e051773c9cb698bbf9cbbdfce91ac10376053bb29a9e7be4ca3d0b44a5ee1c40066c9053b648581938913e6368ecccfc089afd5d2db3d4a993d685c9e24df43ba9b89905ef3da0ee317577d7359fe269dd50ceffa06e6d8b31d815fd3ffe14624f40d30bdedfbd186e803c731156edbde991952c524cb249c9291fc6f1f32a72b048bb8427ec889c6c3be2ae986e869623bbd719ab0b78d7f55a1c56ecf6349e6d4bd126636f890b355e35139fff8021748cc1c1f839ba681f08b2574bb6c7a5c95ed81a2eaa4f92cb927c5eefd7f14a2fe6dffc5e3daad37726aa63767189e2c6b14db2b80a8786fa81166f7519010c5f1a629c2b526106f60aa71352c22deac55026791058021208a55563394c60ede4701240cb3f1ad645d2f050d3fd896243dbbe21d0f918c1ca668ae1442c3ddb536dc94607fbff11a1653b979831a1ae879514a37a3b2967dc68bfa063fbf3e17dcf7a075908f24983b99d9a29ace2c27dc536673bce4f5c295ce806e2e3eca024c9d1c81c9ae926e676c74d2cf28f27cf696877a1ae201716e810a34443659f203bcc26033c99f1f44f636facad0a96186f185c4d00472e1feabdccccb36026a8c926867926b2f2c7a905415c3762260d12af95929b9446f51a1173bb88ad62e35bdb2a27feaccfcd7d8a24550b32aea3537e54e46866edf7a7b325b4546d68e849c368c0acf4416aa1683d9316a636f7a296424912a8943bda31b812282fd97808def916ad5340ab1201943355c75a31b4f60adf5bdee206dbb704998e25bb3b089fba27be6304650028b61ba8fa12f9bab1b7bbb5a94afa96ba8c6775d4712280211e0787dae108363ef3ba1d60b97e78a532362f0ca7f151995fcb93b3d7179c666a6f1ba4374e98880f3999b0d4c18be0b8c5690755ed6db5ffa1f41dc2848390ce1c1adc16d936d3bec7678d75df512aaa8c65ab05a2360edcc4f8eca8c6c7856f81172fafeb7b3fac9f6d2e4fcd7d2cbb3ee71259899900c70a0feeefe148e9380948617378f68caf855a74c6210ef6975dc2076f80092a54cd54279190b70df0e6ebafcd73e1d78c155d693289d3cade81c583a8b861197472ab6727f10207ec4bba8e70931c3c7fe84ba84ebcd657e3aa3058a8e4d1c9d3e47121dfed2cec72d72ecf81cebdc0e3c304edbfe18e7e03a8c92485d1b4dad2edbd20d665af641b9bb99993a41b4706733028b299fbcbe78c8befb5ef5395daf0302535a4b8b38a528c2f5e1447f05fea574c180504982cda4f30526999f9b097ae202cc188ff261fa7f8bc26dd13fc4e5699c549d4b181ded57e3c0720a9a6296ec70ce1fca467a8b2366d359e5f58532643db85c3896c5c2c2d3b2c68a41a713c4a4d055f6b739e2f6e77cf70dcb4307e82ae2b8ad9334c1fcfacf837e1de8cab1147201585bc8ecf5be5e1455af4c28bb081336f004cba4aec2e96ba5e93a0d6e9c554d9e7ceb6b78d89972e86b2f77e4a47c248930958cf35de382e8dbf61346453cd71b6673abbe15a9b68e0e1a9ca23df9475f8a49917be1474c238557624a79130062f62e9dfdb579f972293dec8ae2a4f083d349d624bb2ed68c952191737112f04ed07bc723c327a1cb950c81ebd12eaa17a35822e9cfa00211406f322dc890b40a04379300f907e65a8a541e706503102f4d8a5af3254f5a6f1c3c7cec4d9cbad94da713b12a9a70fa5fd5546dc97fca80c9f3115be2c4add4cbf8f405db62bec3d0a323d50892b5ba8ffe43407551dbd8be7a64fb1e89a335debddc88ddd59e8e10bb135e896310e43b55570617f0a750f8849740a7ce5831149544e5e45a8f85569ea29b3e521f27a3cb1418e8876d29be98db14b44c0e74c4384d2648368c6865b7de8bf97e183dbee9b1728ff2d7e085276f99c941493af78689d832a08118ac282947260339f85171549f5e1100155814458cb6ccb5e4494864990e6c2563b101fae7d70d85bb6dbdf2ca19d730d5587ce1a2b573ef44cc773338518ba1c10a4931d658c8703064c62c50d49c1dfe8e9053e1b7fa95856453a88e1e1cc56ce71772e1f8305d88fd591b2e437681a88c3f49d3ba9f0eea405562aa031a6fc9811410efde0bfb9150ab93167eb0c9742125a7b83f66615b57dc7c57da2d15b1bc49d4a2cab4a8f47af7ededd50cf8a6cf6c809a8fae4098a5d6d24a551458fafb42b3163c130edf0bc9424482ee50fad0ef35016888ee1ca7048d44f71c7f73ee5a535970fa8ad4fe6168897d9cdee7c7fc629f6c7ebf6f91d868aa237fc7eaded2b930313137764a5219ecbf43cb34c44edc46f9326f87fb8486c9fa7474184b14cfbe9a56fd3d94e453c3ba02c7da36cbc5304673d0b710fb0bf7685c2302ef9dda9600b606d122e91feb6e2186fe7b23dfad9d4119bc602b63b8fb841e07302111c6cf39ba94446af50f58e9389102129288b081d8e1273b13c622d958c18edc37fa36dda60f9af3cc4263c599c7b035a514407053884423412536b3126aa677c3994edf5f55e3fb0c4f1827d3ce5fe136083251bd6f207128f4919b7eb764584baacf0346e75f3467f9a1e0664b128b2ea2528ee22a48c7d1b360bc1493fead5f8a43f6a1d9c40bbf656c34abe221fd89740c6da946685148f966c8c378148f13ea8b2353d7c7737a509eeac64aa79423d69dd5e48e3d1ce70b89c012ad0c5ff21e2cc508d6cce293f343a1a9414d42a5e7ba039f982dc70c8c003f6a0aacf3215914efb1f85dc4ad65895b2a883be102f5bffd4b5447d9ece7b535c19112dd777d4d068848d84c51b13fd220519b87d8379fb8ad63d81f1f3a691e1879844a81229da8aa389b6e7236ddce33b6fea7acb7750642ebedf61beaff107e4d53e93592e5d84b85fad07f27bfe720b52deba680abc81b1729a6b6cda7f08b92cf7a7d61acb16d925390d1ce0a2ee2cb19d3f18245647d8e43c69c4b6309ac78ef674fbba769120dabce7cb535c2b0cf880ca163296d752dad7e464d6ad704c850b3804c8ec5b4355c88d8fee9c8b049b55558229481c0f7ec0ff83f557336738850452169ea02047a437e71c085aa5205550c9c5b54d77d51ee2f4e2ecd18c39550b260db95664b1b3eaad40ab0c33dd1545e3eb66c787d6fc4fc8a07428c12300db06f892645e41a5a2c1268c46db363ac492f3eaa69246ae4f4e15e6915f5e7648ce96721b7cf53f7a3f9357e26e15c0c58888370719041f9c5c098919ce2a37957d10a735a02e828cb555ee4b1371fb1e8f2459dfd94495534a2aa3529f515d066ff6b0051d70515e53b3cb52395128c684923c1a86de81bce6f77ade86fef840354705b578b2d4ce19e6df1becdaa80b818c5bd7236frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-14.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el61.13.3-60.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH61]"k%}:w{!vQ_99g/I^NԺb+jڃFXo8ŀPZCkg\w%xqabV/]?LU]7?I xkym/|hVОT>f<3IvAI#C)QD4vn@Dsvu#XA' M0I~ݥ>TES΁(щ JTݨrӗk3`mLԏF`X9[Қ̈ M*3ؚ"4bǞNO2K3+m)Ț \p+ŧ6AJh7|R.c=phV&y,Zy\ŐכCؠ @T9eM旞XКRCҩN(6n`P.kP*.a: @ 4XrknF,M (ZKy3h@a.^.[qdXU}GWBho7ˠ۝2r͂Ή 074!#` 64% =6qsYG bfMW\lhyFIPن:nvU "nS @%iqULbE+$a_Q\;a rB <'ֱ|{_}]PG̲s_Ecd2nRB`0 5jD<⫟ `FxQ$I[1]{_* +AСwcyʃ:MEi))*1ȹ~.&c۠sף5pm 4~j[ͨ;L8qEek$֊|Lþ~8 D)a_[Ɋ G}k>78d a^-AW,$ 4@${Dda%mEboN( vtiF)8fq*d$q|Plr%X3 nFVVXYvFmQ%\~Ԣ!6uS|iL4PΨ+}$-0[|}UNbKw_u: Rt17kH Ɩl ):XpT==(Q0dǦ`DҴ}ӐCU\!6IT"+}P<0r@~5PTGLQl"U 2ZfQ| j.E{U춤Hw+íY1s28(ȕަg^ITOJU]g25e6ʤՙX'P'ѻ:%i 7,2 O)k;j 3ƣJEVs]V8ցdC#$&uN؇jK~C[XPFsHo/-ߤühVW53%gom}Akڼ'  yU:aEB+>> 3C 0.I~pQySj Eh WJ}A$U^Y(5)=nb؈-BOIBJUsÄ`Rd@IJ5$*ķXC D:"PȬEdI?ōzܡhP#5B8i-6> K` P˾韌|S`iID\x}G~4s%aJ!*1сޫ[R0T'd T5JHxt0׳0$IsSJgr3O^4n̓劵2K \`cy !WWB *1\ VV9 d?pM]Ȭ ]\8P=P[6XmHfukz^}] 6 D Qv{ۛ۔z_w2[ d_ˑ!K"rA-`\*ai}i'X `ThZNύY /j#DZN\*!{NٞhDޫmS^d$R!gKK6Em1G3u9{[ *K8lƿ@KA"o,Tȥ{^T&(&f) L2Y~~#ϩmۉؓj$|Uy*bcߘǰN K^`{L(G\ ܽhVGmʼ֑iWٲMG٦@\0Xb} g2?^c_)r+DrSURTaGJb~qWnxhY^HY%Tf0ѨMk~t.?Q58pLNkR"@a2x^Ha0ҎEKF`Enums6GgsZN^ՠ&{!چx &78!]% S{8b|hdyTqkȒ 9C&Q~~~w%[.m3yc JNhLU\9ӥt!y~2+>ާƢYp K5_O#r#;3ӑ[&{qW#V. %{K3]]VsrP8-Ԓkv+u4.uOhuqjAMgC:KA׾Tߘ%6jGI]y" dL,ۯ*pdR~'|`sMkh9k~D|HL>NH%^VOIsQ4淟QEN=E[8գb:T/ZEF3);fLK rli LȽҖEY"q 鏜ׅJ֒=7Y͖v` BԺ nج^N9lg5=fUpZ1Df I8yh K ŦUo2Ow> `W\jJ4KOA_zt^(K6>IRz+~s<2MNxzqCԍ6sD:|m CBpC:{,l+^6l?@aSebbMn}}"0'vA ZF EVN I:rpC|K׬xn1oEa1H9ZxP \~~mw_,Z0t8o{=M=e4˭2챎R 7ԙtb`VM* +A˄UJ a ,9_3=nRD,̠VڂZ%xvXO*MEȉ#-( [)GyHcF#< aL\5_'eVYl5Fk,cdߙ)FO =+"l1 C=ABu^ 䏈 v x>(*#zĬIg7?p Ffcku6՝{ k'p7Fi?h2@Iu]~.?Ap9`XKR% $K7xfxl!ޫ@i >A]qTfaXHXRUU;nÍU.nt*XBGDqc =d=ݒkJYoB8@z =EF?^n)L,+_ _Eٌ'QkrZн3n4u~N` iDx,LǕa,jOJ"gJ֕} _\йNT(PdݒT`l\ݶLEꌀ`|8>H7S6"`D/ R.o=媁K٧$Xr*i߾qZ8?"\jsZTexA=ME+=JS{fc8WJPj\*redD6H`oo܉aNR=7 jSfEM!Y|G3"}4GXvS5+'{<ZDaLе#*yI@XCb]?haj3(@^Nwo¦qn_2n-ֻ닛v^BbC\o5Y"&vݛ1z(5?-@52°@¼L{܊hxٝoۗ& <[!gmTU3gg9:ܶajd~t3GC% pf)T[ɤJ?&a#|ZsIKN27wyUVg%Q>(> c ٱ8Tkr1@Fs-}eDRM1vy`GYusybaP{JmCxoc|˫K@9`=%\#Ķ3EWUĽcN aޑjylmO%ʩy|dKu|zcHI^/ۍ t5C`,DMNtD7,Wz\3.pVXo^l\1e܂t" 8nHx(=umx5!ˋ_䉱~M`&,'Cݷp.;[+xGYw6ˋG<574hWXÙ57Tmb2%V*@w鐺LWS yAWͰu.:aR0 xJ+B[^*۷*JSv`x6s]+1w-h6&TVm?Yuʼn <}bw:oY)jQߣ㟚@A3 V3OJdg2uUs`pD.UHv7۸/78g"JP>cvƙ+^K=+HwL IΡhR(Wd ٧1Ɨ#!Cj#=&ȋFc% A.xt%9`]nLɊʬ2ZSJhׇ+QKɹ'k7{ Hk8OS>}48k {&aVy7Ev̼>Ðwqب=.GG4UE9n6j@FN%;8 wR+sǬIQf(`})g>(\꺺CPpdRD`\~J~6ӟlm[`@tf(ʧN JE*}XIRcgyGmxv⼳QOhL@$e[% \ )Y3$qy$)jt_x!q)FϸAfMWrM_M'1_.m[}*] iAUX^SCqq`/'6"D@}rloPQK~Sq ˫D/Y^_UE)wN}W vd}K 69n6~U4(b(O',Z Ó@Eu o8 8X2.vɑ3,rsj tBJc (tT@^m|:// #]VO(AwԜ̬s~oy$U+b ,MBnZԟWQ(DW"(/skX!QtGFl'[zyeh-pzuli[Y["ˇyj:܆a>l{gKE|P̆{X@()0Ț =1lsh.Yx.SxJ!C9jhnv{ 8 .?,M<`@ub M1Ģ'\Z>@q̋=Dv-DJ<ßXwWěRq ,e5Vda2=ͨ| k\M"GoYDuF3 F?AnQ~jdt 6͕@l ȝ,;mLN7=]x׍Y)jDÁH{ em*Vz.e_ ŗh%B\ܢ4!^uC"0 vgw&xQ0K].9F6cN|FLtfP0P1w,Uin*( jKrQ_ﭖr*].wW؃C1[4:P'z# 1KJT4>2l)dMa 5# IWSr8@m, m"/4kfRp+Y1CAA #\YΤ4aQi!^Hw$l/dO.~ L'2ׇI"Y>mG+'B)\=x+UZMI!V!hPwxh1y1#u*MY2V=̾l$gD< -DXvmU G stU;3]ޮCqZ4%,UN`cm=o԰ Jظ 𞟯wڵ|/]'+pӄ:X  S$m/u e 8~yW{כX%H#KIG%ONm9]k ~:vlTkN2Η5dxp7] LW2YƺKy qȘYYɎ,5\بL״nGֱ1Na&oLuzAEF>`R. maOk'F˥ |{J|Δ!| CBVy 7xoOCǴ/g dB(.'F!:׸nY5Zcᛏ޵{8xIO>.7i23Ȗ޽t_;UpUȥ};A]?/0 [ HǞO^}'Ba Vډ 2wdzmO58L/oKn[hN#^u`J|l`UST5{Vr @PK ^V@1:Ӝ[* ky6G)T,Y G+6Z^.W}Oˋ7zn90\{0 >`x҇๯kf_u 7n">#jɖ@QK 䓱1OֹGT8ws/OKQʀڵ)G"Z3kn 0ܡ2',)F%)}%,Q 0|\.)L]'U{zKN"+Tm@Sp}Xs w T U۾ۄOո:9R_-x^3;5 71+q` /ʔ.c/ÄƲ^9zYR@px2o`2>p{@ճ #j\'zmL.]O$.ד?Y(TT=S?(e}|hM8z a3L^ QKh)r6B\zɃEt)%1: Vj}K3Iq)ZVs`6h}9;[D3HK 7^AiiߎWN2nV qJk jdYٟ2IŦ=0uXv:85$ĔKw zp3@=2?蓏\R ܁q_9SJxQs#|[3C8NW 9gE;ӌB. SMӔMC]bg.sT6Fߢj [(1AĉdO%3N7mf}2Ti;#>Y--KGdAGkY盛(-:gsT3@#o,v#g5Ҽ #62wRj+?WPs,_^ #;5)KUf@80wSe:'@ K3@+PɊan`>,X>JqØ;ỴV3@><&6L+4yk{@7Cgy%Jg߲[BYn!kl /tPu'T03_#LZv.Vm:rdO4tҖҸS5l`|}wi|gFb1no|g(Y-Fj3v1e&F`vWT\'- 71v/K2'x'dC7~ g6#r [ipQ4Za'I0 QqBi#e~@w{=c!ZfM4 Hd:k۽u'la~D[.l@l߾̈́ `o t0 ,_kB3d~Θ./e!7%bl Np6}~5oh?WbTںY)_/JqsYAiK˾~κm{5:~P*=IJ ֛٘pxLpL$I+I-̈TE<+Ր3dX,r|Ӫ!5+c&_x01/ڪ~+}KaA!W5F[ szCq;յISdt9[mWpi)5jGMeq; 8]C mo| 'v{V/,S)BE%&5bRV% !jE|dJ ש< j!P/ऀKf<1o`&:BD>>~/ӈ!g":^Oͨrm`krb9~M Qz2 cg*(Нlu!UZNY{byӕqkd۪O-Zc U0L֢{#18Y( _U6΀V?mgG VPf;7;dnӟ3Mӆ :6&.,%+bFwB} a&΁hrr|&=Ph8L9O3& tPγ{ŭ_< a'KORG ? aT!5=B^IM?b Vlˆ^ST;@:F ;ĸ ǿ&`=3H1aWܥ~^3lإ 䊗z)W]4[؟iѯZZ-Z2sT7 RAkqe4ˁQE-a0 ~me <[LrZt iq~թoXDK6Zq Ϛ21n)%6, >wV r$aתzx+Dlz,/o tp35{LuW./e1_o%`֞ >t33QX^Û[<_1r_ Tb~%tkl&h9J $9Z+Ƿ5y[ ูa^Z(" {@{ۇA\!|G?w"nVlw༕P4U_b4:hQVuBc]y?\-ډ&a*=lW!I% A9021})LYdxHH!2b 8G,pô;z];f w4*aJ\(y6e3_?77[yo5?Z *B;FC*qgRX\iu/]|0cBܐRQ8Qz0 5zԑk(39&?e4>yZG^䧹fϢ~輩Q}}{x'?~w<^.UO\,;)݊؜Ֆ"HXPD8BM^OI}Q L6&ZdʼeF/yvkjG%K]Q,%ςŌ9r|uۻd(=xCP?7ɉ+=%`FB@qzh͘fSaB4/>nΫT} m>9iO5c@\R+]vOD\Jɪ;:D{ T& ?8l2NòA͜A*t ;R;^gq K_hz;Hz02^Sl,X`X>۬9tPw4IlξuA$n/HK' J< 0j܀3fа- ֔L/VڤTsf!wځc쯷cq)QfQl*[Un>p= ok2xҶ0f} 5tޒZN{FtwQxy32}qRd(%O$AOAK~aEq-q__$R3jďGd eB&6qKCl¾>pv 211w:Ҹm r.9/K*&yewrKJ^Uꄀg2mz'{fBE+K]pqKO%4^6W<@EGcw,Lq˫͊4"@kjD~@hn21+ߓM)~V-XZ>U8O(M1bebeZ}1=C"bUԇ^z crkp~6X;?*tHT2,G݄X 09Lv/lSj?RA` G> 2 ;owնW DD[,B-tY^fΚ{H.kCE̙o&3:\9m GW&[d!*kE}5ژ7<֒q0 %ANAUL W⮣뉀PzQk4m35# %yA ,϶ nvZ.Sz&}[ϓb\;yNP{BO:++3w٪ȏPӧPπݱ | 5p fgjosT}槾R %CPÇ2พ޷L!%cBףql;!)f{>yk{<'ve+Zu# +/R0j:>A=XͅRi_WJ!""sE5*[[:9ffF}S7c??y{3D n"Cx@<VԵ(sltn(ⱣF%Y]T;m;/#ǙIUay>9Ƶ(!djȾpĐ=;sSR 0С ŠpaIx6؛+5,ׅ%8츥/Y0TPAiT):Ihy:Re䡖 ˶8>Cʙk`iX\g=i:t<lE I<==!;kLN@K58OA./s>LE 51@Ώ`\R)0^h NA؟zz43 6Im1!9[lb̈\W1FS5&R7Ǯ`1dW[f0R%DTӷ.O͚w>@>R5zX|:M\;\$0B V/ϒ15)֧ΰѱ`2E65́T6L>Ҭ5p+*#oxgJjc p j;øS QQușKklA8]X+UO^rԟWG$oV4̫qy 9hM2٩!&"(? 2h8Mvz$A<Hsp:m5PcLKim1Pxvn6(%U27փ7a" `c*_~1GԱ\pH2W4*pd':?i PUGt|NE9fS v=zg󣐡bkWX;LďDW,OmGN99g;l(%q 5kk;sɀe7 Pc&#y1H5҆8hm ٶ>d?'Rpc72bQz!ԯ>ۮ!i$Ufߋ9Y71a%XJ>«Vͅ AgI?|5eœh U;8#vZu׮zCIil~w#-la$*XzUe|7u$}~_Ɵ_?o%Ϭ^T+Fh(D'l) ݈×GPQ΢eZp4fNL_}-mb|1tA6^6+gxn$kn\PS:P<^>R=Ѳ7__#;P~_F('67rb]: *%&/=|qN*aּ[5h> #Jl/HÒyQmְ 8\K;jmMLY۝uPrr<KμOAa'u:ǝ:R:ͲFA ߠ0mZbĆ` ύEHCDE:@,Pן$}6|Avnh#KJ6:eJ|To*=j+0HRC;86 HGo?dޝ^" ހw灁RZ$)T=96LPxC9%lkt 2E"CjׄxD]kS(֝Yޘ_ Ճ5MƜz_7U+ALQO *|?tedqt>׫`P}wrN3SAؿ֜;TFsΫ{D T]D g^#ڂOй oBqwh8: 2dk,dd d~@!YS@ҴSӋcuhkol-ތMl6' :#vWy"j!k0=c%VgC"C/lnk{='-H xr -KAh7C W5SQۤhI#A^lskr1ӖUn:}vtj o a>`QԺ2;|Sy[<6=5{ #Xض996JE,}g.Z6>Gi?1l][Fh.ݰ y|ӟ Aթ4a_jG&{߸_aɘ=OlG񁕚܈RDP59P sW"HU !!^wq4~m dx:<«w.VO[N# dm~IN&._4T*rjtc axکm?zEw~Flr=0`, j{c)wR[V%dR|gႹ|֛cA{%dCj+g%#4QGZKewTOIX|L]=P|ֹ݂` wo P)lοH8 %t @?2fYT2~ -ڷx@G YԊ4'` )НNΌB}E28$X]_a}a! :P*ts 4NT|#=»o,Qt|$Ό6ζ;Vߝ_ĀW?yQ2y|KՌ&x+P^o"OFА<ѹT2wxm@<7NN2DxuDYb]GRUh?20O ԁ[]9V8#:!?+N^Tӯ4h:spf.`eֽiZ"!MMP i=+JEP_ΰA!l$(?>~Rt/mGK\9h<;K1m߰Q:YT@b67R4W觱<suSbCز͊}gJDqq65Ü z칄؛.ʷb3=DbtPnao obT-@yT5(K@A˭z[0#mBDs fI&Eh 'Ĝ-HXԢrSg}z\}>zzTCl@ ʅf~iVr1_KV_gr! a{7'TaXہ+$ Q~S GVL֑L DSW}t8w<)z$N̑=GPw.L3O*.+ocwUI.7ov,( (uS9K9R G|'T(yJ{T;؀)kp8e]8=YmE__fp >8\hjc]d`Cq"Hh>MìkA}503b=GV٫ YdH.HKLrPp [vWi`ˆ|KǢ};M]s&ye"eܙ.$7aY>Y-a3RӁ _羺/$ @}sN6cjDN1 >ptKD-2!<]7&?fq4E(5mlAIF@Ĩ}8C8S;P10{,$N%[đnMKn!1\Ƙ 0o@ذDض n<"Po:CЉ=hdlʐ`=#vާ~z=͍?h jF[ PSŀ{ @$z @>U<,Ye[_#"):CǢ]i-JꁁhhGlAexiHLñx?7N7s""!> צDN6 -ki E2,9cl!/\Y*׻/wGe>s0[aLFs{g~ۖ\?AhQwPt:= Ľ|.)~k.+,&^yMƎ%;Pz~sWx.)#LѽpA0vo89 !~J9MUqDM+.?nhވVhjO\¯B<1v&.w6=?dj -] `F°g@tv:FGX2p1buӯ|h:G<aIe}Cͬ'ŮTސ5+e{\DZۆ}{Sʏ }r`<3'@x0c&iC6i4V%d'Ej} %'?t6SiŴQ/:PCQUT\h~DyЗ\iNOϒUEjNŘ{y/bo>,NfBݒn +' qsĢgf K2>QKqՋg#ZN_mVYBMġN^gsǷ@')h^tWSЎ AL?qxOCm+w ?m#"kf-(mW4w'35m@qU&72|FZiIIҫxvcj#vH$TI vĴ*΀GCIKCTQ{>Ai91䬍Wl3)V +^J'BYcUI_k7+bj@`46Hy嘥>ł T*.JA ͗U 7kEipdgٰqu,b u[b?@<70?SIDFb%B:<sZٯi k8c>=b[t 9z'U6 2]_ 9fFJMa Ӏ|Ԇ71zvL*h5~{"$:LۉiD^hhZ ?{SI_ڮ2rh%" tJ0U綱!$~_Zl<ɸAZ}BJWVʷI<8[쐸3 '8s J+#)Y|:IhՐYtI i|V MmDŽw4rc3ݺ#;3 1sVSyŠ;.U{ H|37m )CvE~ \72Mxиgj&f#6%˄.45Ϣ"D};YNm/s3)ݙ!2,pcB楻tapYΨ.7FǕ}\\K桽RMQ7o.B֙Q6UO^; ǧTZ''K)4g uc1ҫh:y g+u&! n:? 'l Gi$ǧ $sKhmk+9 ?rPt.J=&C<0}MjNzv|L|[ LJ$W&cG*(:8 pi Eҥm٨d0[ Dt](ˍ 2k9C1Dz[`d2"$j:6[Gp]:aXeL,d~$#dj-&B\={T]}-Y*ĭKuhpޫ7*bno(kR\{er9%6Kmx()`Aം范Y]\)WŨN,.*odYedK+T#O&ab-} ھS\ʒ'7p}U;\ uegc~9X{ &'-%|ea/ ޹}yf餕i9qr L/Qn2^C4,J6n# *~L'&(EɎnTJcB3ӀHpUbҊS5y&䂭YZ"JO)g s _G+2Z-ݰLЮU>C! ]#IAB>:u+y,WB͗oM}5ж,͆{e5lt^ζ5;pq$xU,]R| n]Ʉ޵`뇬 O>jHQ#0lݦ[g8.\ZL^J#-ރ:NC՚E /j|z"RG'pPCD: D$N*i1磳6MN>+)h.li.m|f5+%") $txq=c[Ŗ[Waw8njO*Y98]Y4^N?̾~9TF%ݢ_;Tk eanaaLM#9^vhhĤ1<6̫=Ǯ3>y)Zܶ&j@| S)7&GsჾQ@=f\ T,¦fTiϔOEYRڠfoF([A [5c3r;< Mbf3 B\#+i_jQ&)ѱnEQEAo ]3gH*_:h}GbiWk z'\S5sgUy,*zū%ڷzpV3&cBW Nc /K GTu8.;m2ҾGBFshح+e݄fӧGkFt_3>"LumY6(z>^PH' ?kA^,emd9}FNywN`UNP1Wn Q;;XPX[ d ra^4bhg u[n3*e84GXEHw0 #&h rK@hyS34>qT|SH@Jt.m>gyv}/9f)xq]zRMz.'eKyođLn[δ(󳌪7~GLS@(bW/ Janu7o8-NoUG15f:)8:8^YEғL"CmwP@v*."r)Ƿ"ˬfwLŲ0pyϥĶkKths;HPS?+ +7ؼk`qtֽQ5o, 5"ݧ-\a_l䯒$/Ȃ^ ٿpBa_UER3fh}]{n 2ԡb6gL"%4ORǑ0TxVGaʓ_S%ېB^1lH HFGV,nkj W}Cڊ֥3*'gX)Eb}MtX!loGm_`FSye塋`qZY&`#'"Џn5iL/HsV n#Jw Av#;kKGдgFq*T5Uv".58? +BSؖstNcݺf~]F41^Tԝ_7Z*@O&GZ rb?qXuRO|X ´4x=371/$H.g" oBRN(1tH)4Lf|cX8"Ӥgg7K0v*$q|P *10[#pT`̕ pd>y-rDjK$|bVP/=r#,[g$R# _V5c=Z?ȀA+eSrW91+ݠbV~40T13n&J/Ӝcɳnۣ=A3f @a :6jlCKffE8{"س諾rs5KdX@пjN;gOW&S -]Go6=3rv%z]XcM! EWH:99kb`hDK!I[<1𳷃%9O4:8r6fi~+`%P&3y5 fo.k_`OZޒo{b{+esВوÿ4*W+EIA6ۖ3얅K`= }WDU>6+bIYJ,PJ:w(LXS;-A~Qԝ==X4^*"n~$ VXNR`Ɉ}|3NPSpKdJJxSaey QEC^8Z'j>ձ1P8g22-WkaP4*Q\{lx!Y`+7XY`m}!gƏi'Tp:~qð4l36#jELO UTÁ.,| ~) Jt64 N(.(E5&h< V[!~uzARP;{4x;uKk&3G)yVXPc)2|K]ezMjz})FyBW}O)l#yn5]P/suQ(n04MT0EiK n. )K 'qS*|ð>Yc®әC ˖vNSs**?l&RD&ැ==GM}mdaZPZnPq"ـ/Z];y0' މc,383;S- S Zs6 |V(@jl/nGuVeDzeJ$Ufr;0Hq;U ?8(P{]6ntLa7X^:Zx9KO+ܕi$nvOdnkS.Ow,pfU ds@yoECdE"ohXBSVXJ݇ UԔlK"c-&TȄϨ2-6H;8usr+Wk@P):rFDikHsvnVj|Je%[_3D9g׳ $ 0@7VU04|E#eL{Ms>~\b'rPmd4f@j IU)рXuW =ڕJhXK^4Wg t>&Sj^%m:eSsۛ"B#6lh=b+=J}W Ge>  m<ٸX%]SɛƼ Ӂ-dF CmՑxWCs#;IaB˖uzo 'e.C3A'5 =])_g3 ?mo4zV!դgؒ$\߻=)1bNjHӤȜo\# A4>$Orutz#9J<ib 4`\]^BhS؟~ɳ37uu*M{]nDS_oץov~eC^ k =O֊m^L~.+ rr='FNjpqK"HD2i Po2 U2egJѮ`캙r*^u$ޙ${[ݬ2dèE69J y('Nf,f_KEK~#axUϕ/a0c YtEVbM_6}4\c/Cry$| RQlyMK`~iOAwH`juɲ}-!Pgb]PϜ-dxp&_ԋZnND.fJCIssy˥^Vd70WH|eCvK͛ ^)9 b|Q3 y o;vp#1^'(JX ԍ 2zk4Nx(p}SZI*3 ʲ}8*#܌Zv:)%fË|yJ.ޣ}ӖoNX`Ъf]؀oWƮ/6¡I/$.saaePP>8s3ckyw)_;P UXRD !,03Ok= 4O6;#,2Ck=oPh SὭY詒كg9)(#pq-čpۓ R$Ef^cqVFv3ٌTzYWgiH&9Hq$0p䇧^a^='x{Jqwb_} Ie rz6S͂Ml8ULs#8`MxU,þ [ :tio~-q/8j}3{SUb:k[ ej,ft  3~ .XCHxڿ7+Tgp`])?'W }gJ0%CJɖ6UO^##OghGy_a.` +lt2*7`S (T$xtVW5E/tMA] G_0ݴd"B N)M聙15 3#S̤,7ml$It@Sݙ?Ŗ ` cSzt+߁qKy͗Ai:-} ɀez#F}|-^z=H-ŽT489ǫ+BYGB"__@Ef|{TͳRXxy:I0Jż@ԑǵ-ĽR|dB5w' qNHlf-wP d]ȟ7w_iTa/R2^>g{λKm"aL#Qp+>M.0.i{<5e$%߹ Gnwb}C-OcfGb-)PSe%Df64umZ|RBۉppU4" =O-PZ yC?ufU,&;w\;bz=Bp{?kՀ`Qrv!36=My=.82{E#.a @>ODzV"d\VOio?Y|H[V`́ OE){ru)Љ\2⪘jCG7|U.z:!ItO/zpds|Kbȃ9y/n| t.#y-{;~dRӺA7Qe!\DsJc jCQ7RCGQW@,;} '3@OZ9ib#@}DDǝFZ=`.Ɩ<5SU ۥ ɔ6ө\CM ?dA\4ԍ f5k82y8SƝ! x03 檆3mJHTqbЀuH}qjk!ÕP3|!/ʖa`_vglI@#a/ zj;y=q;`hc C-QVuD>IኬEϟTpk4o=؏*y~LoC`r,GHa6B}Ofȫ1 K1㐇\mj/4 [$2`4}ihY넙26bQPQ Vz0 ;FZ]j25N$Y SЯ/K ;dh p 2;g`I]h+5V`ݘDXH<9$bKGCEʼnoCD̛qLPPb$OEX] yX%w Rե`="ek+y3LsszƄ*"jv#i!%2uLybJ}ᙇ`myqߟ6™tO9ޕR≓eec'; 5TU;kr=3A e6y+и\:]}8kW!Ư0zPwYϻ..@; tt=mumC1꯺/Os31] Q_ 6wyA_v@KC Ӽ˰QbU7?lSϦ:7{UFnCkh%㛏Te/|s!SR#xQAFj+Z`կQ\VQ~+aB mɩRL%>D9=B3vzakJ6ȶObo|-T%rE:ZŲE0ZGy .d?)_&cK9S U*|.[؛j_Yp7 e fWzz'J]Bk]hp~8b~ &vd1Sh;*u4 p6c}ogЕA/3.+Ę՘9"4X<kQ=l饋#/fi;956V`}y`7]c݉ }"dYBĵs.q{5 v8Ҽw m9h\lӻHcA`S/,n"G<\/QT\9צ1'wMSjG70/LbSӭHyMz*lxZ2iga"Gdl))1>6NKO(҆*Wm9^Ў2! 4e,9N* HsTzȮ~k3]')"ۊ" U4hXfg7mZMJ-`Q1}߬mW4\ q3 ꏺ8]xPw;w ucЎݖY?i0C5A䂒98zX&92Б~ Jr{4>~~v/()5wӤ- {b6i"mO2Rʞp4@|HMh_U7f ާO}ܚg7էh%zb蜓dC9$zH!ј盒btcRP;YG3wf70;'>یc6#=5wb:Hܧ EbcJR m[=uj$Zs02DʹcJ .6PwȫkczHcP՜~䟑)Wrsb?]$NJԈnۈ_ 2Lz.p;=\<,*kD q$8KES#˜EƹR6ξR~לR`DyUL(#l=cd+>=ab7X Hjjt7U5꩖0*FeT'#C#$\%^*5'Z1Z=}Ipj;6n k\vDD&7ȑ7Y9GQb)|k0Z>:2\|P7J?NM׺'~p* s _14_4It\8Q6Hc1 q/y+B*ci-rt 0Z"tfOμCΗ߀D%i@ mim]z |?_Bn7(~%#}q⼭W y PEoҖŎbi` t1fuX^z3T)ג 4k]y5!5O?ujy䜩eL]ߨ⢔ DzW,AJJ* Avx桿y"{##A`;_nbAՠU%@2@b0 :f,HnhMoBobM>oetM8@Y[Yxp~;ryI!- 'bKY2;a6݋Lv-d (Wq2b"z1gO)!H J~z,nŐ?jټu_~`FPIP j W'[G4L Bqd 6F5dɱ-^^O(/˞)@#g$bKt/5c\G-:fk_FE;*d ""0ax c!(*cFùa, (' Ko,GYKDq#1&wt0\Ǜgu "b[ݴaNé7܇WonƂO\HF|{hv8^Sq0j}>֋U \]ص bƴK3 .f7o&*'Y շ;ߢt4Y"'˱]~ RZȏwlT%,be. K@DXYU\î5P%xtZcvw'o.D6WcITkN&l :3Ap}eP8 6\5<(QVg2LSqN/՘k 2hrbbQֳ߰)n\ŠdN5Y# -yCES%2%@qiL '8-hf5c]f EG`y?fq+=cN35ǫZθDzՔ|h ^/ʠEp,P6QLMz[ɶ7*yT2j)zc B=ݲtqfCYrXݮSƸ.?E%1 ߖV܀A=pLU%Lm64{{sKa w7,%Tb ëY݉:%ݔ6ΒR:)V?]MSp1BuHT㯥{ăژi"6mEd J{$9BbI'rEz.>PYW۲,΢WlXk5ŠA 9+=2TiĴjXxL[(tʛƑ^HGuE_JLoX9[U"NrHE+qp#nhiG5Nb\i>FxZbŭMZ+=A(D4z qt_;_]#Ǝ|ǡw,wvg>`Zv-:Dxp 0޾z 0RYu 'P9'X՜翋- HH[Hl}hTNj5T+1.cRch&l*Bw+=QDMSR,ICfV\MqzCqb*v%+u.sV<<6ob J%fjd~=FƼY *MztiE|}@Ю_582x{0=<~Ǫ<\NjM yɼz!!sZ9iT1>6hmUD7_|5mn6AH5Mxd?FH*4DQ;JL}!:lA$ 4:# ^q`dtpVfKСPѴXIUD!p?4[h;'O# j$%7HZX=R.@qTN/'2-&kl〝6 (XU־:iIVUaMB8ee-4kCZܽWrhwS?8]cR1R@@:(ce~nq ,E\bw%v,^3J{.B#,t+V%NhCØLC-6]=W\it 8EN+d'ujf*Јsinf0%xA'W1h&5IAJ!JLt2tZ+M PصANWר(k|,vL}V*/ lI#bBHQot=ygNuJ(h D*dw0^dd˧Vbq A<$5idDvJS9?H(lE#(M}4<4G<Gٻm=[)w\om)ЕIFa׸3U079sI(_|jHQĆr=0aq.jBUOijvb"lZeЬ>% y ?p$˜BP?Zj@4qW= HSh<m`1e]kZ\$0˸?4ե{7 -ynOipW$oH*`y2熞hB`9ꆍYոsɱ :uq}"Hl1Zvݫ5;L XGM{= hN1x9Dȱڽc&`S /!OWg/p[-?_VM b9| 2{:n:KK콾=j8I7p (/2JFM qH!>uˤf$,Tsd_D/M}#sBXUW(W2J'=dc{5vΚ!4nbhB]aIm cov7â);6qC7 2ud"XM!ZO㽨aK#W9ˋՓᵐNdULځ|ʌi-ARģgcT#23鑟cQ+V3t<+`Z"ru lq'I7_di2l~q.Os=chg#zHh|`4X|L`cԅiʣjeњ{tM޾8Ew.LuWB!3R$ѹH[SXwo$/ph:x8ԕ/9-)[@ qjh$Z3Zd[= 3z=|VOak2*$}nѐVMdS\2*7@Pvsk D!S5##mHP%!-F}z8X47A#|ax2tw*bvW }ړNlUwLݎӍErwu;Z#$}K&@g9Ò%}pg:]Ƀh>373m|O}5aKI=<u{yT 4:5? U9&XW?8W[I~ԫG%XED9K`ΞrvV̊߈> ,z?`jTmDm*|a@:rJ 鷠gָF/;\JmE)&3ڟU* @ eo~r魽Nge#-&J㜛B積f!ݪ9*ck8%jwtI=0m7fkebj8ɥ7pаz` bRq 2.橦NJ*$-d53c S6u>+jm7OwSĿJF̕8{-VE%| JgBj 8-<)SBwT}!;}n௲{Ana>= IiW.?;[Q74{V2P*Kq`/wߔX5, h<a6)ړ(jT6-*HRGmpau}vrԲ)wm'q;a48ְ>0["-<}(6k-#"h+D^PT} ۜ%[PJj2o~Tc&ols;6`|&ˤ\Q1# %R"a,J0v<4;gT̅-3sE@4hPBR+3bA;-vvG4ǎqw^pT=FHJ g*^LOpvւY*? fq>f(8 dvnn[,QI aĶIw-iT/tKN 8EHu;9rPwhKI  ca@~F8/(jm YMC$eŘEAA/`Y-|%5砓LV︽O[,[Z&{vhL{SR95E4Ə 'p"밞%*V],Ѓ\i갴|7,FXu{c7»bii%b){ƫ~)Q)jh*#s7b)=UaqnQU^<}  Й^%lH4pPC0\уS5k"3jG |]Š-1Wߥ\̑+hM+.Cy.eGdZzjZlw&O-Q\4}k1.J|S೼ƋgBd vF6jgah~t})ۇ k1=Zn ?N a3n{; '0hŽ տՓBFqeOSǦ< ay󍅿?s 8x=j:~ðaXA WsKp{_I\6'!6 kK=W. k3T-_;qbW=cvzU':Ľi-VO{qVHw|s4!džUG/u-%?R6I:x 4yB#=DYi},ȘY.)&m%DJс'U>@~W{TcG|ꟗ\;TBɉ"u(ed2W$pCkd$%MwI_5tdAxoLPUt?XqVӉ0gVv~|-Eo!y ܶ7R9~/LR‘_<@B5F6poQWRKp8];̶McFQ;ؖ~o.ћ |^ƸUv}>:џ[6zT_n^€Dگdd%iL JW=rP]Mp.EQ!X֥wa°H8e^1n`/185YĮ+{0zjX j?4A@ a{t?_f)USAYebXMS8:Vv 3g .`&`G\ހ=U+aHڝ2l.*v;}'A'tBaA߽fY@o~!}N)=Yq=P,_3_ð|@cVkm(~Hj?} ;C.ۮi]},&6L7HE_X**3E.of6R0?SRm 2;HjK秅\8\#|){IO\!;Mϔ*C V<)~wyXVz%^/֎:8_GN|KE<[sziQ-, KcML;h]5 pk^gĵ)MɲUw2 ]()7E9FM R`tďl7KVѐ= y?N$w'ږbʎޱezՃθ_?d|?ȸSf3 u9bKP[B$,YFٷ[w5 {7 {.܇eeY~NF&  r [c]аb R9ҝ1)styEj1 یzuj{%UE!^E!EjU!ׅU ɏA+)}`C˕FIjcpH6z[KUuGUdf&e;²T)]}}[SH>6ݙ<9 3Х4փ<QF9WӦg!ƮZyu?8 jW%|Lw[MY°SpAjd~!%j~>w{k/)>F!7 a@F{&Jy#(|{+|i]D;{FBK+{b]Juܧ#6`[uy2GwЕ956Ö($ qJn69Eu?SoA]9z9!]gq^]%q<'ΙrOr׺p/܌'jl(҅1>ƻmor_ϓ:_TQXAo'+k|Vtf{En}&4%_S)CB !ݞbz̯ 7rF\L&MlI${_¨6VxN0QЃldKZc!ku]x6X*1dlO$v eY2@kZ]R54tq#'fH;-@cw+ +DB@N?/ׂS3'Qc<]˞aEgqM2unfW)yi<>#qVn^St`-hfwSp`x&`ohYDn,~pU~=ƉFAasstNv1t=; ۑpZ~n!h@6gUe<,w5S@]P!~= N~tK2'dh<&q E*1~6M4E2}5UȽDh׏wMRNG~s3Qtʻ)`Wx Y|q6ζB'U(xA 6Cr9!×Q*oXIؐA(d˻;yQWebA(z6{ Ȝ}S7:4;g ="ޭd9)ٕ1̿Fpͬh0[6| SrB빹O7f&m%KKp ]j}Ppo OID,qBBQ^ X_喳2b89I&YLv\]nc{=/&'_yC23:!u>yGPF'A71 )E7Ue6$Q3dΧX/'_Q\|Huiʽ4ap2]~ۺ1LM1VG9tŦ>19swڂJzX\,l1h4x~ǾjpŁ4ls(ŵm",*n@!)dprNZ" [N4&1}/X$!I2`5ٙiiC.Y )y\j#q5=PX[)A.>[ElB2:etwn`v"҅!wCE^}8;(|&e Q-yM7` _)<&ƗXۦ ؒc>5p X4 )ŝ76ڒ]! ?e3=AOPH \9⍜PMQ=녹SS 5FW ^ Fik}G[٭Pr`!mdyLgXGŊ2{((:uU½ph_+Ptؠ1J V\'0%f^)fN#Ƞx͙WCfTE7gV$`[Cx #<V˯5b]KTZ >x-~Cj//-ބln3W3+3#mt6j1ulk3ߤ(DDŭRYrUw>F'w';ECxÓ^`ťXf5l 6Š'@#tlܜ1Vh ׸FM꛵̝$>tlQzG">^6 6&BfҎҘ7\o35Z&΀BmkoziTۀ-^έEkbDziq8ɋ{qCt676!MINTmG-ov 3zWiӽLt>e}kUHH Koan .h39 'hЁ6pZ;FZ_90R00oiXF0AYH[ŋ]H_S1#s@b-w ^ع[~QpM6-P4apS?>}qXy*˱u"\v8"ƿ]xsߒ~c"zBTzϴ!( xU~` t>M8n;jVL"Wh(e,y  1 芛J-O9 j13#7}.u >նlAQFDEν8[Ɠ.c2g{A=@3RKaM 1勘o  )Z}J 6t-sRv w7Xݤ}6aAuU&똆`! ]ʦ"o0[Gқ#-Ba-FWj`%z=X/wm!ݮs[m3" [ CcqOWj%4VDb)P ӛha{9aW)%q6;?^,FY)6'vw#F0R@vɾ.8ex'I2j~ g3qt$0-ATbG<Z+y>U>yl1{7t8lx3huN>#IpCWr:0NOs ^ Bc | ՜'HԀJ}\4p Py kփ %O5M*nc\A[. rS02E!@+llz1je <7 q:k*`T/-|[ Y٬9&/S "m K":8Īn?57| pd4Gs C]5 ?\Ao"xE! |a! v]H, Ĵm{ΎBPLgd:y$ S!fB̯*lV#ҺѽiZu?4a~Y?)zDFjg ZՅV\"X?wI]:韝tZr0ION:UHAsE^j6rVa[m{Hs5GA m8#yo`?KhyT :̖̬7zfѨRP!8{_aAcf ZMA?~B4->cfHDŎx3E-X#\7'uLw(3K17éfNZqJաn6fЯQ~;5w'$(ήۥ!!)hWM~jk({J?{(SQ\ZK۟ݠ7Տ.V?TzmSH 4Z|;_:B4 l0Zs幐㌖j7 L4 >H& x} o+r@H/wdR>Ȥl[!!z4.j \;[G/<- WgB\T? f>)uzs Z ]lRѩEW65%jw~Aq./\HyOr8~Bs_ҒαG^tzKhP8UQE:Sjl|׶W9fLx1FbxJJJsL6PIK~֧l>Qy%83O}/bZ~a8t=C*I`aœo>NJ FC8!叇cDomӳ0b*]MU)u?MG:d n DD<`{goD;LE] J'bzNf>X`>[Y%AE0E!#o,e]HЕ K ΀oH\(\p%\:o};]\(unfoE`}엃^RB^l[ヹł"u,!ꁹVQ1A¾PX~u5>a$p;hCІ\S7|oIU:k)(nPXi-HlLI=ZS,o˂ aW;WL:^uA7BDfCcM !֝~[.9Lf(.2M*23ޖA7I w./u ?#u+nL(K9Hd/qm 5jЃ"RتF iHjGFޠ,QޱUzA8#CotRoWx0Zb~Nzp. SeD2P-sC"ΑA¯Av'-x @56} P&i zDcjH?ϊ9jXF KQ}Pky+5>|^A֧mIo (@]kT(Uu50HJ,TS3羮eߜq Uj)g\R7 [.Uyfr bJ ɉi! 4=DC}A**8b$"PcoZ^^1eeXjH=2 x+c솉 htk\"5P2Xb M UP,#C37CdZH l jQ0LX.x;GHuΟ#~*tGE(7cϚqAƶլ>d^^`;wj#(<9]/9`2Ib@}@DO b*AkMD^œ,V&٤}X{B!ԓSݺQ~{(⭀~eK!Fx,S)BF?dE-zE% +,g?,eg'&}xPXY#`:$u7Lh+o3clR%57E d!c9L*($*}{C8Ve׆ \o7#rXl~[4!6@O˞ x kwoHV<Ժ\ij9u}O9k軣|2?}Kw}:QժG&["yveG* iK~nMͺ0/лt޿j>-:6B7qjz@3B=[ l"(^u`[+YfȔ2Gwpb-0 ݦ1"4t^SP5Ttt>ٰw bc 7Ep:%3;a%pkԳ4O|29X1 TԤh.i=`;o X~im ,]/́ ڷ~2#d@pYʧ-S!w$aK9 xrE>{t) ?Vx-g{Y 4]rgs2Z`{d\x+6  "8cu3W9Jo.qmW.`g0N=98SKSnTujl95ɠ%Y5s:X \q  f܂58 Z\#Vw~{ՊDc -w5MYR~ΥķU"f[~U<{-y, HF-adZ=e;KܢW4cBNp/Ev {oA79sm&HѼgzEv Wةt ^GwQݎ(gݷ?}we@9R6Y.%00XUτX%ͬbD$47ZHY x璭&'dg+wO>9U>MpTP `[YTt-]Ǯ%@-k<،{Tr2:#(h&j'ھ 3= r8 ̝jgr!^ϸ9fR,5*Ob":da~UeLE{ZReqxkѤqWR"T7X*m!9-kY1=ځOAa4b< 8^2}r/xJ;K7]IJ/6RŞ.CvG3͘x$KQB&TAB7oAF\n-5?UoݮsAf > E =R㎓m(nm[RGDhI ,-McBf/-El.&6烘*.uè-cٽ\>͏d H0QCEd\_l3nFT[v MXݐ50M= nsW?ībӁ52VSp*)§'0O:Y C\%b+(Mu?.*:W5qݎuFdk㻜?4 |.H֔o-ᛄM'[nˆxnc$P9YN̞/1|u)kF0 Bt6꾝351f~S pS*<]5ms{k*:utj9ū+,xPKdr!X&ʤ} i7<"`8T b!=O>ӄ3m @ ~uk9 fOut1Wq W[`J&dA6ˏ3/p`5O8d. ާesQ^=!L7~̥ox]E^O6R΅ڢ5\tmw~M凊,nX.SQ Rv[D-ARo"=4I4  vz%p{Wש)) sQi#_ژi5#Q{:RBSjޒV$Ql"bymP'tKkm3@I `,rjĠNAQiKlGZi0o5 2f+p;b1طI η;-"f__a,na#\Y>nӣ[ᇀiK^U32Қm Ь*Cr,kT}Dȫ9YޑF#)}SDm<-X-uпvr9oʖYo-_7 b4P$+)\8[H>;lM.7)0;m jYjxߏ;[^k5SѮMorw CHwi#/8U'I)C,e^fnXP01HH=dl ~,Ƈk,#juM/7P uƀ@4Mm j-hqࠈI+j3HNs3%x+XEx\$v# q5V'ڽH 4$( zNƤT׷BL Πިx bt:HHfGjc"."~ EzW!>0S_%Fp!g%m S^iƬ/Bq+k@:J4h\V<6U+PuՁk , nXZ&+uBU_vo󫦗I!P-03ZE>Odw /[@44@yb0ݖU0beۋ˅ҬD(Qp3j3!4JvYRӳH`.]ִPX=]mѯrxz0Z!q1'wt[4Ic{T)|. uM;cȪLRc.Mq.:Kp=hLV2]PBlϖ+r}ęZS8@J2K9ҍ!Y<ݡ%b[J~3a Z4hv=_?JX w(9Ҙ "O u'4=>݀-$46x 7B01+eXX-w0,}AD}k20 ΥpF4BΩ:q1-OTCrM$Qt%(0{tc-qa_^C~x`Xw(  z/u8s!:g 7ֈ);]f 1p+mLKǡU84AyGg ]݌ڥ!e+R9da;/Fc] -ȯzVPt9^HwENpeXXyZ)*h-DZ jG|hU,#◕3uyD@g1orto;;Ԉ#?|fc=lKa8IDn]U/L㿱bVV:N#Va(vj\J_,wCB;bX/mJ:{ߐQKr# Ÿii TVcpYe\s jϺ*=5UL3Z+LfBx}C j#r;QSruW@VᘴZQN2ejF+O^ǥ|^C @QSEi')/V/DX9YAte߄1>QJgvP\Ȉ_j.{>LyR5m1AhKIN3;Te˻iWR ߽~l>w epvRVqhG3 po ϖyPLrpnk^>hV" /5a_QJdT_R+hJ9ylvWs[ @xO27,Lk7\_ˇ-gcB=}n6~ N ҉߾l@'9aV!8HBL0qJ0z; NדIWBF2wNjkc p|\cHCqߔW/vYB]|ow:-SR{D" ΉXyi I^o wkzaBDY[DBWI)2t,R0P p@Y$!{"~D}Q_K* uv}ˠrS$M'0ZfAHdv~)\nКƼs51? |O.&!<ՂaZs8sTLS9\|ESG$ׁyOͼ\P [&1|OAUZ53bTX` (t\;J51N`0Ϭ>TBCo5zf$ZҙG0pde}QMpYZטi!ӕ *0qOrTߥ'9\ c9[89w#uu `ŀ'"H$6he"'ci,q&5!I &*)9<1D{/zԴeHJZ_/$ݗIKYA8Du1YCtQ5~甯-*m]^zD=ٯUx\ jEJeXl5W9Kº?`ڃg~oO2f: h>>ü MdiFg'lXcG'~yN-9I.4/կ =׭bЬyjj0L3A e{Kru2#?6btAckWJɦ0JN:3'm`e_!N:_FI{ @7l&O'_GXJ6޾nX>_H4des2 Vm ;n;ޮ xKO"uK6| No-rDז{6Q۬̃UQJkKFs!aMn#{RcgU>ݥǚ0K}6 i$ D`[=>", YtM3k+~^* ]gkMudt̒<+GsGbnD@}j|Q'2tԇ{8t*ʕxUOAX`8N:eaJ05Ipw-dC !E4,g̫ M`)Fs+#bB(YtC%hђc3] ]+ul)6"Q^+j52j3KkՓ7=ke[Gv\iPV p3v<j9+XY?9Ǯ&o"AgrpbEJ0Mw6g!&] ~ ?@ 7>ѭb䑗hT' of )_+/5'~_2W|/ ۻטauGf+{To&UUUb罠m*؈j62i#hb3Z?Af3YihV04Y[GDoLLeE~M%[#Z2F-)(5,e~ Bcoߙ䤝N9q-uǻxV)(fO|A` #=wfUC?*sxx#suJ@xO.k ,c4ϫw]-Jpg,xQ=u~d%^]L~"Onj 1Ju㰖ߔ[hL~d+QŊ]M4}~t zYT.-ȅI$t,j*$Pӓ}&iEȉ_#璮#9pc򙰁n<Sبx"~F^\&!C2ک]&B* 6{vN@W ̷,mPMCpIe4n7O,kbt"R.?x g|Pְ!K$80ޯ H\_L8(\o tD*3"ͭ05I NAw-oxR *bON:N{C]UѰn!g_L('AA>kc:L {ď4BGf0ꮦ7K)V1!:,}hEQ@c5 pDWx~ /}͔t>!+-{QGgX˰xUoTm f6g(L zPp~  ]J{\AaKG^}@)5BmXs)a-oe5kT}Q0!?4VM+>xob_X5I2R3-f#%ci5¹8QLۤ2pdČ3sZVzȈ>V/M±ݥ. 4࠭A5Du]W3ieΏh72 :qZ..ǔ\`R~ .}HdF9i%tμsYk[hpkY|0mKaRNjRT/e}m{cװ4#D#WkFӮP@Rr Y7a@נ!9/"MJRAsO^`w9 lEiD3kC86|vcڇn'ATz㒌v@7&QBe'Tg &v Y`zLchvj+2ˎ٥aaUyC&…^+apQӧ@~Y|ȧ6D.QyG'Nٻ2:@]$٤/P .וH͠C&~nV{3r4r CnD!@Z'f^0fٺ,~n!gOl1ۼ$[uz1.n!ױEʉSѼrO)lq4U831x2ŋQk; 4[˵vU ԯo鵵]%q귑hBp@?b+0l̜x%'`_Ɍ$jU'`X(ҳz MӒ1c(~.{VMy!{ m۰1u5JOe-V |8Bb+bTKs7Mηr5 >&I#q'z.xiӂeZm`b媙徺 9T@V a@*i RfѼG}D++Д>ŕYs-/طk *NB@4w.F^xw2jy/mQ0Z@VzmUYTqZ;&,p~rE>IjiNڰG g|ʼnv/]‘ﴚpw,p4Lsp0&Nbq&C758]o Tgr55 z>-q'lqpΨL: 8Vm_k783+Zoe+!WNA0~)Rr`/7ԛN2B=P]r82n]ɹҠ=JDgF2գj} 0a"@%3큮&qﵻJgSE0ςwP<hL@-{|ֆwYQOi+I{]y'tU0ao{-McA qG[)5KOᢌV"PT-K*DΐY2#Hp23@E:{B:Ecv8fƪ!&0ej;{Yh!6LwI7ާtUx`qaJlnwj-,ˬp8][#`[<1XŢ-nX]Fm[8Ja5LB_e]Y$4nzP?!l̟; ]*{0C!&.va7[4;WC@^1S߭V1Y\' m= ;**B6DLM-cnGw}ED9m+PmIɃ<.\ǵ "4b\ :H21-YFFP*VۤigW5|CYb[:"Q{*M@PV,$5bGDKA(׵KKA\edG/kp{5L{Eͳ"?g\st9^#O$7K8(пIi&2 nbA˾rdƁ}`v'G`wVE1nC~t^M qg ^PAB1 A6 l)f #z 쐕C4EsJ@}V2=1NJjV8ֱrgPA0o l_)QeM߃j\#{>d1fLI.œ>҆-2ch&:OY"R8r )n. =W睒#=D w1߄)܌wYQ<+f AS@ͷ S\9Ҳ2ҕp[Pn<?(mKd]e9愫9KP'yǩi 2pdi/E[P: kVL6qDow 3wZ f2=UY<|):@Ȁ g߻_S]:l&1 hrQgOKBi'bˢIk&0jFԁ*yG Ⲕ^gI Z J\IW(J9cP!T( ,bK.SjCҘz9hI2ߐC"/)cT-n1: & \:Μcanĺh.N&UPdFSǹ(G2/k1ǡr^'ySh+l{ iN4|4%@u& 0FQB7֏S }3;e䰗&M4 a9};i;X%,5ӹJamVhU( N,ZNվ1h<ߛ[9bXwIN`nݘ,sEpw*()wv!A0q]puH ]EчWQs A32g ]۸eI3w} <1-"dg{\DFT2V }:sθeqtR1t}-7==d٤h[xTwTh|^UVzuz /oN$/Q?5Ԅ,)\'$ݦ423e;,Yk nzwXQsiXχMI,ǭ\ " ʹO1RqxGeN.~@Cx?ڗU *~J^М0m!p0$KFDj'[}b7ӱK~OzaNOxs6$Km2D뭶] }_!6uJ(XZBb]5V1*Jfy^Qξ'v>:ā uB(9COcoB<ƀvћ|/kjm6&ǢޖO7]DF>oY+.UGzL([|ڛ̻|jgڭN~qpι*w $>i-K^۾9EsvTK9Qv!̂>DmuHRib`#}yd% '5xt-y"B ? 5Cy6R.ռ^ ^:7+p{/v&cѳ^ 4܀pFV3$dx] Tta=?f NAAڎ1=y,qFp*ez !\'|J?Ļi>ז]a _;qELDΎhӪ & }8/-}+U4…Uب0;O4{@Np3|TxR9-D=}"΅3$ƙQl&ՔP",қ*Jn5S㋪6/aeWv !UN߸ 8z վ.,`S¯ߑtt!<4Bnf*:C䶵SQ"-s;%I*vVs0g3BN B!m_6oZZ5I!t݉?YqéRGH]Šnr~dJHkQ' Fnxwl(L`i΂]6 ={*nEs+b0ʯu58!Ume0lf!8!3~r+_Mpa5"}13fVjض6 3ܽl||Uuh \T=p_6'`lqo J14J;v PiWai#+>4r4 0XG¦}89w1FWT;256[FT20rd`f>pipn[{MlG<pc=f慙B@z& 4ѸzX\<2C}{G FH<3\,_0U2Ǽ :oYڨ+@LҞd[h( k5e%cȬ쎪I@uL r(Cp:2*^vMg./M!`-If▕p<"`j]ϑ|4Ε57y.2Ȼ"^32w )=EQ'[ہ^k>xb"#_2ȉO儔t<f2kBb|cAlvؘzcWhO:*Lgv5WE"+(׃YyCR3( 5t.z T<0 pP\OvA$02JSӎ%֝Y'EJ Z:c|~qh0}Waf4?x/]mIMaz`Z:#}E>ccRnjfcB&Wpe/U( W4#*_]DU=Ъ}Fi`M˷;9T%:*U1\JMyY_ٱqD *nW4=x0*Dr+<֯<ٯEt|}aztyE!^۪yإ3oe"Y{ =[r>#n3Ϩ}@WKU\Ps7Y4~)b.lL{[P)^fjk \BUShߴf@>줐n,jM#r dˮֶ1D Uڻ}`}} O*0s9ꅫnMQE!GQK+N\aAe5Àҙ`M=VFyNEp帔 T:!3DzK c 5EHt|S7naN4\sy[ Tf\| 8UBw֙\8 y,Œ< 5 #6GǗ2ް[Q.7]r怳S"?k]_SY /zEDdJ 7~MG\ު*m":hMRbh1Y>vLgo '6לIt?\O `-*t'L}`HKrac 쏪@#5 p#e8Q=(2fLc2dQq\ 2~j} oz]]pǧ[@1&:EsyͿea}/@aЅ!㊿'StG#HubG*wJ˞X* ͱh;֌Ŧb?Yf50oxPY3-7i\1 (@)]k ='>3m_c}Y)n!]#a'ϟKσ3t}>@F$B-bU]VmF)#'kUQ;usaSO!@ۦ)M^Fçˑ}, >+EF(GC/D.Ⱥ Rgk L茙\w f:VŪRqn,4:,wTrz~:YIs꩹Dx @=5Nqzo^O)d!ƳºZRù,ƯEr%]#_@S+M3' [iQG 2̤jN8:qd@W|z_n}#Η !k%g)3ԞY-,݈균\RE ]U W[ܒڊӨN(S-"^kɰ#O0ȟ'eS![r4\\V4iT FeEnVF"I*Ŧ°Ifdv= ju^%oDxtE-zˊjv9FJ8;-y~BH P%dJ _$7/84Ab E&Rq a^%yym9ɪZJzጶslyo"C~DZĕv-/\[7KEcѢMN4x0Cp݃~ǍF2՞v ?f(Fsz<<{̓h#(HL%Q\舰ҴD%ҁBML?V!Qfc3&lQD &×Z\sٳL~ X-q,nԇkUQK=4Puh]sPpr4R+\ˏ<6FD׉,5]"ɍk͋y$UOvlN \| LXz }6璼wNyE\' |3*KQlPݵVH" G^ܡACj kg^eagJ 8yGĞׁn,-F(1AK_Kvr;^\IatчO*F_- u?lu;M[27Jc^,ϲ*w[n<H4ML$Ԗٴ6[ƔN#>E[$-B⦝iBΑ2hY2HxC$&r(g0?0'\ƤjuӬxZ0ZLYyPtm:VȞK(eʢ^6'ub>ML;sb^G2 :)!pvk'ۉ;u ׌ξpAx9gT}g8"0^&[U?rw 2Cѥ>Z>Kď2{(oXM d a]_ ];l6a9@.$3ۓF[L^j-mC+i9^&-@V+- gMpYLY30 >V؅Mzȓ)|y^.gpaȣ~MCФ>$~i ɒ3:󿫲A Z)az?t1ڰFt+C,l,2 95 d01.+ԆY4SΛa 8>ދ wU%lF%lKнI lu ©> D`%iEsAL%UfhVF]^P͉{ ]5tT??' &͹0b5zqt܍t+ _b{`h},DWEiʠwcĕ9pUU>^"⦂FY6~P}܇~{twFl!Y L3B7sZ2mK0 P~ J?t(C Wǂ:}h}TwBʦti)eˆ ! o "nWN֌H?lhyt=e&wvI6S$[HڭN0UITCξڛ*^ABb!/>^^c[&ؖ b󭞧3W߮ST_yL[Qs/5˙l~'5-XS Fӯݵ[PK6X.VvAnIn@XY6lv}cf+E? vYSotOɷ^%X$WׁAb+8'e&-Qq(43P?!!?}gU6~%\TZro=TCjdўGdUMOhwJަؿ29NH(Qd=(%wlRޛ. t!  -%`B6 5h;"ETѹ*P7 vp ==ZHi4DE}6]J*ܴ29evDx;-3h0T! IXkiR#(Åa4䊐is]n*9~-+cQ%1lC8I7f,#"_C`"q/:%$9 e0?P54saG]N1I4~"}GV[#.*dwwf'x8Mwhhz3O.no24Ws_6cmtNy$xaPߏHO,, mj4O߫3Ci Ҷ:R {Zd]3[.,^65j=[}ϩOԩT67ҍ""EQXXQ[di4I_NY")(UM/]Yc{eRf% x:봑> ph$o<83|gb[Z(4([aĒBt݊ZO^H8MT$~Z_jgH3wD*-wĎ):Bņ[)ɚ'AAL8v(*!Aַwon~6CJ9l/,ozxՒ쭾|=x m}(KsrDԱeۭy ZoStey@ @PhG =N/AՖg}3KD~6Q2N "f2pRȟ7( o =2Km`ȑhjZL)a62iDW\N R<4%?%Һ݈zmvrGOzZ<+韇(M6OfHQ`lmQuGC]g{nl=,?jtlp 2 3 ym6(Hg/&>"_Sb;s"u@w5ƭ"QG >'ޑNfgI"M6Nm{zmOa̽+Rx5;(kjHU3H;ظoe`~Ӈl"SUG-Le]Xc8cӁ^-2tؤkì&DI|mZE@yƮpXfzt Pi yۜ]oIy[髰̌/R@U1R D$I59Uꢺ vа_oK|oUm2׽,ߗK0`'%1:KXyoAv'TuM_vb _̇G4S UN Jm+ˢ3 ~).`=]8vz w*(iփqdj(,k$Yy/2XScM~(b,oЬ>6!uH6 ߙ| ҥ!%#B3A2L.! ^T(G7/Q$5k-HBs)}9fA.2'PJ!*}UylYh)`T);DU{$)"j 0$.ӋȂ `ט=6>ؐa@: [n2 6-Z:g¾3j0Rˢ?k-[_ux!Ӧ*Sh7|ILr ^KiQ\WaT#'A6 ^ fٛex%*j\mk@0ǰ o|0fgd.H>5qYfiLBF)"zx :X x lM8AȹsWN2kƆj5FHFfgi qO'+GIMpEDBHiVNh>4ό v|OCj7JyѴ1/+ a8ídY ey:fOOp A# &=HğUͩCH3%;xIK${;'0Y=85&҄4svn{ZJ1ycFlR.dßE"<Ȍf.iQ[AN8J&/J:÷\~n~K:/uWi=]r~zNQ7_|Ǹg8N&5ei k{a`5"}BC8$Y֭(F I eBk)|r~ $,T60Zh^4 MLP xUD+s"gq,'&&zr{ Lbp~?YI ? AP['OS5HTc `/2wB'-)~xϚޘoz1H\( |3r7 6)G\om!Tr;;8 ZJ nLn2-_^DV~aY Z˵Ab*b74)N07X57 aZDbK/M^j +&f9Bāp%Lm\Ne%Jp,I{fznNīs׍ `ֿ/ :lꑢe< XV梼& P61XZ=ߓ3umAOfQ, 8*\t86CHIzD.Hk$qznSWP_ 6E`Ҵ=A[7ƗѰ_JX҂o"3+Ww!dG$$P՝1nuQh4>&D-_IM紡SQ{ժ[zWܤ$rMi͛ IC/|+<*7Vj2f5RFBKNK֠v(DY#;v5 p@ wWݲp"i'P!;8H?i{e *˥BDYkJjP#^L#쨔 ߼XC}Շx%k `L!~z1%}YQ|t"z YWhԶc yVW5.JV8зѮM ؞mA%1"<>zw s<) GYKMmrj1^+MF/*["s[:ErHjb 쀐k1dVl ؿVBc-?AQ:w L'I?_;8-Րa:Vn2َţaM¤V 5lAVңLޠ t?[qf[1qH8[1 '$Kۤъlue`դH]f3ʫFV$BZV - .t h7=?*aU%A$G̮QО+c#SSF _ȸTDt'bN]2sQ*PB;*[3, dU{B:/}ʣ6"JRY]+!,]ڷ9 hǍ/Q" HX$i~h:EܰdcU$LCiǍ8?s֖KX"rZ~q-*)'|G.❋ܝsD NJ=' ?'?3H}l/Y~ 'fu9N W:QE,x؃4F@P 7TU 9,r7 `Eio9o!svGZCv8$lq}7?4:DUX9Hzy(Zζ 7N1VSi|hF&$U @}p?'oGLWrq֝0 (MN*+|MY1) V@S(,]~: j R1IԵx2K$p4Zn(оaZ ˺5;q>xGCv9LziڮWu=i"-FjTͤ|MuՊP'1LU*qO 2mͷneā*|qc!9د9wfk˾M" V35 ԸxB%*Yl&0s{K%~ 6lzM{HpW k\cd};@,KSi[z<=!4?H*Z8`|Fv?%YJdp)>E6缁n[T'Ӡy7FZ_Ɍ[t^oLlE֛Y>YUap"I$׌џpWI>?~L􃙋呏qNO5!^QWkAt.U2݌꾐TRUZIciTcM a%x}ת455x]..U^ #/Rt>E;cN px2rgΌw!U>Ov1\^73zB$5\Ur*sՇܚ9o+~s?٠o.B㌧!ieĽ$-=[:;Nc:Z;Gx݊,ۯ꺿h<L/Օ>X;3gnuӭٰ}9|WPiEoQ71u ΟycÛw!b5"IN5[P-l8^ Ȥ0%M*#>>Q7, h'Y@m~2|yM\cL+1rfM\2( jE ȑn iBJ]C-\M`n]VH`M[px]OFdʰyhXm=ҟ7o)UrI"3ٽ&%.Y߲@cÞ@z9lDvsmaRVa5(9O%U} n?݀%Li ^mU\:ÓqS~z'_zWbޡÄsa1O-=Ϳe7c-$eO|~lJU@!Nl 2k$#-T^oY"iG45G&!̾G݂i_?i?h1qY7@=5c=T)E&x߬$<ݣIn olE9BǗZd:` ]boatacƩ@8U7d& *l;p /f 5d6^6h/RyQyKdl^ *Gq,*K?a4)8зD58Awăh)0N:rğaH ƉGL=TnSW!RƋ!Iafv81X_RJ<⢹a .2P-@$uLWpU,KgU+4c&AJKl/Z]M1_]?sJ}6u \2Q@ ;*u׉:MBW*Lg..L9|llltO9DQjwÂ|@>G11+2GYPVesǺw;Yn~ߊٳЌS"Y_a8kLk<:QY(d$?G8}ÃOo~!֞)J AN3z5eâ#n"E.H6',Sy@4vXxl!μ(hCqT0IPCf Rh$i#eDMYvLsmL $qIս74ӽ%)i"$|}ZU]$}d:KkՅD 2O@Ckto$&Y4u;tC]"@m|r|Q 1Îe^V9( Hu 2 /{"7`G^rzgoy![ Ntim&*V)Jx 7<8| UE)e]#$f>{x1"e(+K3PaEr4 z5I#_w p}'1օ A\bݑsļaFW->ƭ07OapdA, \ X2GqNӦtRe4v&OesoOT6Y]A+@1c} g~ٟ%1*Y*E2^pufd;x]vlg5#`B/Eil$}^>2 9= {L @js؟"`6l2ez{_8ODu$[h3ƕO#qUoj$fC kO)zL(uHO}Zx`S :B-@pI#)MBJ4BQ8taNrURqb!J0jc8C:@5ܖ4d/ʌ=%6|f'y()f8Dp[bGw*D<ىᷙ)>KSa> /I6_b (Y%P~ X$]Q-HdQ;ni#^M%t60idZyu%o=qPbOGS08+(*7@}4)׼>E1͆IM TQ"t1XmY<ɝ+k |ϰ '`}K6V܌_j|}bvM'`xY5HQ]S/"B$}Z'³wբx(oK$ .P`bRA04|fiq`5rc"]*- LT)};h{_.D}$uPX5.f鯰Y3Ǹf&,$AIrM74q1(/-eK?Ld`9t-t:z2Ԅ=S)QaH_)^%Pt.vM`7stq'RUڷ$ |FUZ(z.Yj)Gf:4mHP'ux0[G%W*pP&?TFL IVxN(l{3#nŵe.ALm/ώ?vc#D!.WY)ph@Ͼ\u.*4 (Sܙ R 1vrVҝK(;ĭsn5L$ɚd"I@LoXBh4:,l+y6  x( #RPzO֤q"_f>̀3kZ7 lv,zkf-WKA N"'SίIYn(10Wmꗗ?C)扂VPY63.{LZg/OAkh50SyM;T^.wz'U#zu0XO' ̮ \5=Y?V0^lYBn-Y ;heJ*ǬsBW%Pf.&TR] }߭] ^=S6,/0ӺO7zI=7>coTyh7 {}CF| <1Rư`spy'1< \hs״A'& 1g-6=Ux6d/]64ps;Gk(vmsa}3aQ=[G γ)H AlЫcCwM.G8E5JI8ǙHa d趆ţ?/ou1箃 M ]\1mk&ϭѳM2r.Q9c.Y=4I^=-~]ZlR%[fP=7X2.ĕ}ʃ ßX0_\B%BeGBa0Z-}3zUG(@D[8T|<|zg*AESYEusvЇG|/"靿Dֹܬ{ۤ1-J{Ecȸ;`ۥH6!kg0#lͥM$9+醳Θ5y{DS !@d7'ÁܸG %,ذ¤.nl4&֫m߆)5VD$s$#{WcH3ʢIϢ D.~!xq}MZ.˵~L}6g;ߦBk9F mp seK;BjbF02=N P4j< Rƾ8XV&:1Jz"Ƹ=Ym(`~.;ׅIh:Wڝ b}k_M,9_!lߜHT rL}+iuKK4`@x_ppvJOFRʢ@rn7!%Cw㚃D $kxXJ9@F([sEpX s"t7݉WШY n4c²"W~Esw(3xN[ƅIl/Q"fuUv[\2*-h5'vȂx0F.7jpF!h҂߽̈́?=c;DeD_fr?/5K w_%Ψyac};IF2W3yH'qlpB'^ue!d+7JNA}ɗqdC:s( 9*ʙ\^Z'?>-hUӢfEܖHTrJ/y|q͎J3@D|S;ˋJ0.F.6JvթStBbzkiūŴ6 WG!(a)W&w"mU8~{\ꜻ]kI4˵D'G7`ucyYo64C'>{?%7୵NGȤB?ݪ;K N;E)WkI9is7>-/R\@1B7$tj/8D{8v+(">_s9}|by㽕UN_ N ˜?3YD 4C=>1֨4 җ$KS)2aʿXRHru kCÈ'.ՔC20@ FɳPGMƝ3M9++(}CMd Ϝ@E @pJj"lޭSixBȭnhr`Ì 'HCn })ˢKXv}u[T/?^Ŀz<ǛNYVC#(,6_f܋ M PI7)`y :%Ot.D=9,MٙUPAyx Gݙfv.6o\?R?Nzx7Óh6dʵA-¸*(HWԿ2;;P =nIg=2=H%Ħ?,K܊"\9 D/ T ?ioAmoϥ.oMm)O 4*3lI*Oyrg18"iMSwf]n2iKAI?Mx"w\vwJ(4dW o^,Nng'f%c [ )AJz+*j&W U .tظg ӊMgXl;Pt똉L\I͊W! }a_@z7󤲂tdF*wKrxF7 *Sd6&WgQ8 v+HeF$?Mi-Y#߄_4Z2"(z@*%Œc 7LI<} r/Ugװ|O}>)T+QO.!c?<6RmBbuds3!x xCTN"vQmuHwad o'<0Q\J%BA?r{PC^#1u͹Z;qU O_QnJG:_Ek?@_aԊԄJw TCÜ4_F x6k j>Wa jD؈!$  n2+f#k?#GҼxG3jl270\Q,zZFaNOgd27o{OSU@+Z|&{^*AK\IN`,k]H~NIsKk'-jI+XM|lH!||$k;kt0${ (g/&[Roj<Vi SC*pkl,%T2?r),xIԞůYLy! -Ph2h^ģKϸ4#H. "N1 'NPfDT\D:ac߶%Djp=|`c, p(*NBiQk7fj-y?\4l<\3!2z^DOy~e¹{4WTc2或䯣cڀ}*?2(j^ɻ4rRR:aND,1 McNc ɕLyX8M.2y,&1TO_{.3l\Hؤ{1(ɁnI6bnB 1yn{Xmo%4^n#n՝jxW2бWvOLqK}-`qGl; y%yK"l|ѦGS ,B%[p`u,G\qrWa )3D3&SO2EX ӥA[WM 2v!#f2T*8~p 8z;tYpWn _܇´nᦴbk{`!@ù;7n{kυ;#(7݄͝'}:1C%`Z49,G+Xc(! ~qvGA+YrϵN!0ZT=/H Fo'Io4a.r\3q)3XV _+Ρo <ٱGD0I ;}# }Tc_N=}7;Qxc|R q?=i/F m`3/o.`gO>(oEvTҧ1DGӋ3ClqIńQ) Yc?sj]us媅mPh_u+`mK#G[:r{: OaZ7xXA-Q;ሜp՟n,͓K."W&7Irg4M/w[O$=#?8.Mi8)ܳxd=!su$^}P]~QXO=oj/cnvԤ5Qx@I]lmjjצB!UяrmA 7<gDN5JjqOؓ Fu~;] |Lk(&+9P_>=^y1s0i2JHfZ̋gF;29G^&r$6#,=Qw…LlݳϚrgͨ1״Fwϰ3蘪\;Q@V s ++՚z}7i@D9豐gˠծkZe)[ 8T@Yh9$/mC\Z0qIζ"eէS:9{umv3r[?Q_,-{3 r pہa/yt[Q>qIQ^Li,?Q}9g<$|B-^,91rIw/K6qiOٹt|y>Z% ))~GS;O\ӌ>x|&zQNC^(eI(!mHyWCQ8_?ם^ E`UpkQBJѵd,M>uxGt΃Lgxsf]l1rJRfe DGʧ*|ûR(\S|b=+ք' #k^>Hws+i>H@s[qcb Yu2^jEaB.KxhWdv D?>|~iv3 U1ng٬7g.""&*RK6"[pxz{ե´CgrfECcxq;V+7!DR<BٖeMc01_/}~\-:}2LG.i( ɍ9IޯYbpIzR!{ j%mR6Ra<׿q»Qi8S.|&R(amL1q, VWJ>ZkK &Uz=ġTS:19WsVpsx<߈q$z OPP^xB3{|7Qk!u,K}ž6w d)Ԛǀ۠I0"{%p HV kؒsrNu*-p)3P&RȖTa`֜㬌KlҼmǡԥ`w+W`K.~SUW9Kc qj6P4x_ )eЀ{b;8 `<#꣣e(7;=Pa0ƀIp1|e:l)=7>_I^4OUI䒈t䆩CA0K٩F b ~0(Q7;6|},Y~j0O &)v6>&T^u܇:'ņF=oO WԲTMa{qS!eR^L܉K#p5?m1^DPYͿr=)YYXcԓdG(]q}gn$6wю c]Ε~UdCD[uhhrRN=y5JH_GI~ +h`)ꏄg3o Ν!-C* &Y_TT(U@@Zg|=-zx]ftՍ0O_qƈ7c9!1%b/qYNVP13~OlhRW;Yݫ4G=.^?%]M&Cj_^!]s)}^|Q,B 1 g1`tQ Ӌ5Z/F)NoDGnwA_B \togG 2OIaqS 9[@\mcsQ;U/PP|8]++δƱvQg[O~MI8i+{5mH t6hFzd^s}f"o!9jBG"o}97qq&T!aHEм[xwi%3sZAQn[|D0̟_jPӄUtxzq5TJ֫^#Y-;DZH$?~>PsӚot~_ ڶjt @:Fy> v-mnHZMSH}Uy[fAK!q|½V-+Zj"*^N4=Gc#1t퓔pr&KnAhBnȞYSV\^ĵ| o b{c&ggZM?gn$Ɗ͑z-'iX)cy1댄F)I7 n2BNРT< 7['??= Y(4LiKhZepfQL[Wg=\0﷉$AΤ:ƺoK78{}g*زObז<,SCfTxVHnT"&e{@k,9I>K7Jŭ®e9רcODO>cqaBMgi1auE/n>LN,B܆Szx?rO &ף@lXQ4Cِ<s~WH'&Yv~D3us23J.dZl{52w~ Qzjj7oC-Wat/ԎiEFƂ״ì>s= d0Ivl@bR| a@1dYl~dlgF$='lհ,3ydQ x%iX}Hsh tw֨QT^<(\itlVNZW3J8W gSnYа@sOW'@ІϒLg僇Getr *TȜ@KmuGb8SONV8I%ݼV"3z>MQ>+Bq{D<5kE1_Hf5mr$8ꍄfސsnD!\K=s%n1`]=w]-ĔsA@ؓ_B,s\ ER|_,$Gez,K:&3'FޛmT$ݾuuI„≬M.jrs4nB 5H:&`F$ %yY$GbM CIK`QhJd«lx-sH׭>h8VHXR=h=.r:IϏz[~_*@ CZqq㼞8A)#翰+8ZN$R!j-LB C nV3d bǼijnZ%ds +ac>fMRNmTS2wza8υ)pH/EgVfB5Yi:k{K{OgPjfo?uT(A\o c {!gHs?l o3gjDk ~lU^;&SA0veQ8RJa嚦3lY3)#,n R|>81b`]m4\&3Zy(n2n>ʟpɷKRſ*h}#Ovfi:&*A0Kr՘A3 cHi;+Yks6O(FG(Ik-$sL t&m!:P,AOx/z/l6A{e; n V3{01&ں`NBZ`Mk4\dNʌ sE yU8B2>NY qjHJj>g3Ͱ6ًsVlP4(}jwK.Tq7k,6' !+t/[<%O/.f{F4F- VO?2\`dU3[1Ӏ(uv9DvW9h&` $c9LԋEXŀC ؽHA5H`Ԗ9U q Mv- bQ%yg1|=O >UVrh3ZƑ *uMgφBű6F;<3,La}'/ hڷP,i$ Dv)R";z$%Oa2s}lsK"kg_Qq hrJЮОZ~J~vrս8`^N‿7~blj/~ oЀ :Y#ϱu  .f0RSqaUtcVϕҲ1'+xOng=\ Y?t-KAA9(+Ͻ{}Ѫ/wiΗZyXh@}Tj_Ct3*+*5q'gܞnS\fg{J 6ͶNJfTC58he8GӢh^Y1f>鐇5qPEP=ƪVO\SDP3*j$R۵?VIN~%Bs"PBe}f}wIVh2ҒnX4"b@ȅD AJiX0-G{Ƴq4F-7야\͇Bw}+>4uz+Mqg vUj4z*SdT.8&e%BҜ[JLVi7wHPa(>WOCPXgyb<4)[){CA|T"bl[TxyyNC,w7 ДDFssFz{TX b(0QV3Qy~&IadƤA!2|i [6TXmtTfZiXj^$iZO%4yZJy}DVIH0a)]zg1$=ԏN$)p*Bv:&aj1 ޕCD:5+eFBKBɇs0;iCk0Rv<`ڑn4$/ܧ{F hwS_'׍}[E BMb$VI"e'DɥJ<[ae<&h "3Ge AQț*$ ŷGoe5Ii. d"5`A5 N^9FGf7Ǧ/82nxDaSS8ڭBQMl22*ʞ_^b4`!G+b!c݂xumyZ VC2ȺEgv#ѴU5 bxV(23_ =l)qL9-7G֝Py \zp'kj9ߡ#U?^ ƃMЏLaEXbֳm}fhjaonk󳀽Le#.6́&l{RyGî*K,/${r8z#y C4iϜi.p`C_ȎT.Qk# ޮbuDzfC /ɣF_ iL;;k5`釆kfBcq7 \oFr.g权${^y_ɥ,ITdSPB^܂0OCDGq3E[n NmU[&tʶC޸H>V Ua]BX 6:ޠG{ЮDl TTϖ]%ָ Bf}C4W_V3ukC:\8C[!L'=%icv=R]-9i'ʔ':}JM+UHOmռx_S4ǖq4qU۸t@WU=uYOSL3ԅL<~ٚ)P6idzOr% |gNYD*!NV{;.uh{Frpugh=J12 \1PKm e<퍧V^y 2oUDRJT\a/]:^ g̮=)|-G1%w;/"$ݞ< ̞.puMzu08>d-㐩+($Dܶ3OFg!ef0Wۛ0!|= 9e2 >էڤq,&KtX vJ.xq`e@>ҤMf)\<~&y;(hj.I͇Xi}l5]nq7͚ 6K8//Uu6ϡoZ(DEKx>e xJQg}KFiLU4:|bɃ7^N_8i XRK jGan{zCrJc.jcv䍦IPT͵ɠ73qP4=0%,J7e.h`X(;hw\?eb:͑C98HP b̾Z]=+LOdzٯi1Dh%s͐9ݸNC(}Lﭲ4E`nyomǿ}, hdBO :Bfm&iƦhrK)G)V~A؆1JoBGgGJ>FIsltկϙOWn%,mQ32ˆ @˘,Fi^O/2 is`LzHz_0ԣ= *g~zy(|uK`ΑO/`͊+Rrm+<@rx60%a@;!@rhk=tEߓƝhЅ.(*Uk@ Z8R@[G1{"cL+n\ZȼЅ/GWޞ36a٨Ovm#4j1$3šѠqsi!79~OF}J*<ӱZA e<(s#u -DAJ~tu6㦅^e.-jxq/i{e(ϴ 1IokʎK.*D-c\ y9b <Mߜ6^Ds1ټIRi[ت-W/A+Z-=.=.qB8dǡ)]˘gmof U7[z-,2᰹,=hzDŌX ^<39gY wF(sEH߾x $ 5~EMZ&AAƼC}`N[ 6[Doӣ'[1pwp*D-Q:D *uscw$vM cDm'`ζXtȾE0a3,ÞL8;E꽱M[yސL+jyԬeū/ Lh/dx 6C-fg$A %. 3Ksq1싫uL?C]@!6b}ɝ_0)μޟV|^t*J5Q%7M|l%bhQs!j1ʇ 1 t;Z\F2J  ˭/s ;pC+) m[I yًfwՃ%ȡ5Ij)"j[AmgH,`fοBY )+SEB}'xC"s^tQ S>,ۉ1.m[),Oÿv)l.ugf'k(j6W~EGS*EIr_jy!zC%D.߻$<3k\WI eԖH 2cg;9e5g?Y ȘKR!D{iZ l~Vm+LѽbP Wĉñ"l~Xy4 tL@óf)8FwJ{ZHsB4+h ̈́xg*sږplhHYڗNnX0ڲWaoqGї9=AټMc'o ~+2{e:ˏwڞɵM>9N?Մ4[gU4 5ci%e`]AK}Bw\W6Q؈㕑hi0ƭf΀28on6Sܣ tL82t/\?IC fHNK=Tf &t? T}}TxMkyWPK굘Ch"-@VѼhi \ n0mKLĤTx^GȺk=wN ̂v箯 wMB6{_R7,R3oHCϺטp7-d~OcqZ{[q07]Rq34o:Ύ`:1uJ~yp^榲OI(v( C %£Yg8Қ6's= .Uɳ8Lk9[v) a[9VӨ\'~V.UO;&ik㕿fU[{",s8yjvt=C- Eq$xUwFl,y|g 47q,jlVj^TZJϤB͖I60aP0uo+Q`Ch8b, zߍ0!\`>N9Pl7`s cC'+aRhln4Ɏ@f7 ٸs8wP5+=~NlE(~kQk5Li[% Vۀ['m)j5P6?Lbw"+ / 4[LT]8BuP%HZvU k=CeܶoךI]i=xF #Q{Cȃ/2x_R5!P:YP Ku)0*:0qo{cpHӴt+X:cy+`LTڗϗxkUa#/^,CM̙IϻuRU}u!ꈎ]yrR-MmBN!'_eN,uV0$lMە ldLOK !ooIHl+ɭ<6tĿ/䔝 zh"?r;\E=Od!Ɇ2 *H@ы >Js(Cfr2(Α7qj)HUh3?yX;_c)`xH=4Plg.,֘VcQkh6ML¢`wg8txs%5g !`pݏx] ,[{SsknJˇ^J.[qHITR6t|yw+[3h+F*İtvk/H7@J!RYepj^%TU`Thٸʥ;cƹ**4#3-19Ua[' "25=8DpȖ h낳N|Kwo[ih,&wJdos +)zCʾR-Mjw xY Jg:Zqђ71f8?Zdg}8âC6! wb絤 *ufv8y+st"4L8S["Sƌ;z0FzeèBK^ Mr7tvp&*= y&~6n֛UrZG5a_\0 (,`vMSZH\t#t!ߺ._~u~'7ቍο$ubӯXR5^ZBXoR|O)pJk+3b*vF=a@lȐ ؔu$:̶ɠnbt:}!Ui ۋެvW<-`'ABxV"b TYVmv!J;e#Kt6><ՃF3/ZՄuS .̲zXwi-frmP7DmfpgAG9P9Mz)yb+짌nt@DG &, XїG{4N]qUŸ- ``17B sӜև eFy@)@*2V Ccvrxt]M@BqtBF&6?Y$kް :7Ot,ix:J>r}/UZE{"4lr-C8:esiZ6:k%+BٰdkIA֠"SRλu-B4c+ @х3B*Q`-$g5U8>me,U%hmE`{B{/s7jҸѿ6rݭ2NMtMo\&m?N_hT.ÖOy[>Bo46tM(9K&_xKLܱ+O>?|Y0k1*f8 V8+XlJ)07HGa|2vӨw`yz|l/8q^fg' d97[` wR9gҽ>[0I33uL϶[OM12h^mRơY^iw > &7-@޸:3_51žp5Z?M")? sJQ>GY +RIPl ӕ&nmy; Qj5; = LBTءi:Ee܂hϼNӛ&2qs "TF @T#] "DZ%( OiO4'j轾X#M2+f\J;9PHQ^!h;wucX?bLp_ C_Bb|݈!”u \Q\٫=@XZB_$ۮej8Xd6 &jR>"D\AHDiʮu!lOgΞF*YU3G`ZG)0͙ϣ2E4{{k#rQ厁Fb~: #ãA3= 5m~dv +nߝ<%27\QػHuĤ܁|̇S {"+Po!N}4ɶ~ziEFA<;YI`0T2 @$% 6 8Kϛ||A_rK1;dҞZd)jq4nS uڴWYKA$^,^ȺZoT{MOAD֗:$HЖմqo40ڔؓg`?JmցIo彳A 4;B?I6|0M,eqA7x%wS#laɴ`*YQ 헍n@HIf7+׷5n$$68F`Yi>,{XvHn /s-Jۇ9uɮ("S^R8Ō RcEY֤A',;rBew"re[s{A|.M4C gc i&0Qے0Y NW@ `AZ^+{ghlT}! Ҫѻ9a,ied?2ԜZ^ވ,p d?Euo۫9es.9ؤrN{^I׍u cwľׅ-_mr2P%;mDE iES{JwM?Ae2?|zxϔ&Xy_wcA]n'yF&9%vP RMX6BRNkCtUJ 'ǎSPȒd[c; -wun'0{HhUO:9)'q1KL>7MCDlEœ~kZLbDžD xr\~WHx8>F(h,=3)j2“sXǡt" 5!A $[ 1XwļvX+b+<,-df5AZ'Jx@dUw! g V3w{^^`ko[BNN Ia]6$`fιL-XHM#MCWX?{=.s?єm?X*JMt'q[7ꊅ0U@jv.½_j8=9dafAO@BS;,#_/l= 6f/sP&ܷ UDI>C䧟lrl4L!oq;&M)"fҵM"-RRi'A`X$!R۸)7SQϭJ/8%1-(ߜܦΪH&E]):~D4ѩ&?JF% 3ެޑ]=ȋo0.[*0KIو?}XN9?6 5`U$t}FK^ژJ\qI'Sz¢9言z3 sYG^_)Ҁ/ְf_hYmp^sډ{(=5<#;a\jZGCZ,TR*'́ Z{F^U ^sbޫB2]\[> {!Įy:rhVޮ&L(zQڸq0wqΞ1 ٿ:5,G=[鵈geRuӔ.QfRI~ 9W'S15N_N26󨇰 to1AgEoxʈM{F$e$X.$I֚~C&rG4#B]$SHbL5ۦ(Ûl9\KfYA6MXig7Wlww4NY:uH303?kٙ&`,:SKTϺ  1.a0eʋ80K͚|Nh֗'.pz#rnM4'ďG3wnn.|8,A"' ]B}3!nvCμ'UXRucRؗйY4ZAVGhNk( ̽B]iBs&ιUU[T"ZᩪoƠ4lwk08xm;Sy3zRJLօ݁6dg>°{ 42EFџC{㗍BrG˸5C}5@ZM&I,LZ"C, Vpd'Ѓt!+oI&+d3E ô|1voiԪ<:W\@i Hwŗb 8|U ԡm53UJ` %wa8!åv|ysIQ?d(]z{h%lJ9\] I*m(C&~ja+5| H ;gv\s7wZ@}0k!-RwƁ3D.7ؙ4ZY<ڇIwU |kBnΝ_qQ 7|r:t|p8z4\4 qs&AhWPvphLu=Ii!SEӺg>DVH{Ij婻ApҚ0Tڍ~Sxr{#Z4{ Cu`qh˝VNAq:80fRcq3ע%CHFs:|(7m˷y,~rvq:/q"E0k2~DH|e%e)NR0IN9%Tzz-R" KZZۛ d=*bPs@Z}༉XcP17Zp!EU3}?)3Iw!cyL}?xOh3cd IS:1ZšG2zID臲[F93cMosp$cIv9"7zAW1N7ȴL&;w:gs LfxtdK2a{LLb6~g o<'/>Mk f@LH9thך _PQY)Z:[6>Ҍ7 -x2+Q.રaѹd[-6O|@?2+s)iXdTu A^LJ+R!btOmTЁ"dGo(Bf@Jl9-"4Mv["Dso# !˪EN*B(%{{.#z睹v]vJ4@6nIpAܽjPݝb^0 lR]: |*E"kp[Ng5b nFmx@߁_K̪@ʍvf x `΄|)QHdLJ^͗p)Q>ZF<'D?ΖA=w`OCsL'NR'pRY!eD = $`H]6NbrЉzfѺ@'ƿfU) QhVp(FP_TeXi(!FB:η<(}1.8+{lNZD 0Nt"XƁ  `T\TʉTTauRz.JXj#aK#=<1+wlS8{[fs 2>(ڡ*oED桉/O4.{k3mt oo(ۅѪI#uk7Dm sW5!})#&6[#2]E^aJ O3ߖv?YDMFPpUcj\\j1h^m^F3οG!d1o G'ftn[ПbꄻoG$r2mUKP<T\b@TXkoR埐a^-ZB/04W 9 /<c3~/$צ PD1Mxu 4tAvtxE/07eI'' x^\t[Cgn{2 v 7AhNJcPFD+h]ոz7lݢqm#.XSx& \*77ZFL'(J )K;ɗKr` 4&rI'S'Bۆe4%)AڬMXك1śJI1"oUXa%k40q5iOOp?IRķoU3J72p r,#D}%f:ֶYfUDyohR 龜x"ebE~"Vd0,YrDj;h6bg~M3-ohM'.f)x#<Զ EŧAzT3>uT%E߱[Z(SS@<9zSlB=̊^t+zQޜ-e@lǨ|/{\=$ɘ<݁BP<geƌhWdIƿʩy\CX@ڷa4=fb~opKv'lBD !^ Uk.;ʀtaD$SG-浬vdET:+5@ϓ{H7 /: Hk(Dus/IêFC݌ [S 2}','#d T@,A M9w2c v"9Ytr!dqa+AIKct\QHX(nu]Դ2O:7R Ӝ :BT$GI׊]E%Xj?mR&KCE6GwXQ{Z7BKC͋K. ?pQ:`%<[Cvy l)`ٷ^tAqiCp%_/ u*cl,GqHp؂0nI$88Ї)UI2fVD@p u|X7KKnn${f6v焬'M Ut]WH֛-< 1y>G@9?<Θb)N JVu8 N(HPV9He qĢBFԶ=g-4mIo-~y $ L|!-xnАĞp"yYV$MbD%ei-5ΦP"GpJ˃C֮R uV+3GgTN[sL2OAcþع.?#~<65k)|aqvLG<ظB_k1ᗜwD9Z|uM7<x7\,b°jI]Ʉ%lʢ/aA/P}UOi; P&6݃! $A2Kce,d9DǕa0Ӵ !@$ QV%)vrz Y"{}gNH5:U-2myQn#~>/A?*F-g  ;9؛d\`F=~'\f>ZjHi ElE}. k! i?6#Qd0TL/2,,8g44Q[ifb@/ X|yz%b _KcGƔEuw~VAX)Ů ,j;m>ϓH`;Uoy_ 8{*Dsn~$`UP81u퍢d6gWى7 vmbzp5M'l,*MН\/<ºPp''e\|_UiV)(G ̠*Xո#1H9Lu J B΃QfDSvbyD0_6Ogh],WvL)gqʩ7Ut,.ҪXպkpbJAޙR~9F%U )~.y@ՙ3&SzZFΝyǨk 3XwZo$9q*{S&xJ"F.ӶWs6ƩX鄵:)Yh7q8<q<0mMJ뇠]ۂܧie4vE~[-<ɹj}(5- m_ҨSNqݜXY"YNb>I!)j6ae : eA`I[<]=[^}^/bE]~([_L(}$@uFjzr%9<?~[yj[X2̡䟞߾Тy.J=/R >bDBx^=k{Hr`NT,@nZe;u 6yaƩз>Rz3paTZ=l,>·?Spo(3~&{>C``v*|Gk+J|}NMG z<<  mfnMo+o[NkT ['2A(V-ܭW|L=j:1D;lZ>@'#ޡ:wDNE1 dMӱ~Hb`~;ݻ5lJ0/X nG 1"|ހWbGݘc! Զt\c?rYo9?! ^(W'ιuCm>:h#Ԯh "]uCq1tZYeC"jȒ'LۂሢTj)Hsn@@B8׺ vpN|WإlWc+lD~A1$k˝#T-9_,r(-zͭy>D%bS+GZ %Jt$7f{m(Rmѓ+}S )ANL u^3O셀I:6bz'C2 EW*ξVP}UrudiC=^zF@v8~һ%TfǹRM;T4iLPpߙy?̷2/4Z{8T M."2?pFnheKiX a65mI{ kx7w|4! h'[YJ`X[dF;0"ywKQC%yƷ[leR&`eVzBO:+ýa2M![a>m[m-3,;.`zQ;5 tƸL84ZeGPB3*8}ܨ-)7&:?pjtMު?ǞJ'e\Wǃ%*]"7`ʱH&7&K%C=0+~>"e(2pDPq&C5ҽO9x$L\bƺ"M-֝Og=zm ܬ.zqpY AOSS:%v)熍X]cHڠ^t"=,ڧ} RM}g|ҡ%}Pm!;N %x+=zFN+I PM? {ŴNEߜZ kn[pђ5 J2lQc9gP*n .?ċ 7@0_Fx,#4U8M9`9 58PH_: !:4ԁ^/>h#SG{Ħ.XI6`ĄFHE+ pHImHL S$,T ~;ޭLGn7* !J0*3GtQ܀F/3UeZlL0m(=݁> CUl<*(4@Z)t``Kv@$͊WHs |Va>Vtx0 ~#ˁH3 hW?kknxahi,^$;x%oO=1ݵ:P2Os;FT6G22zZIV!2X݇ <}n+LsT=2PO?Bv?mWMo4~zP = \x[W" >t= ZD?W1Ⲥ,g׼/, %?\!" Gqߤ Hrx.!m ۍKis<CM%^woZu$z=ЖPŬh՜LҠ]UB++…3}=dWhKh?eWc0ۈ\AS2;ĥ #DbA"0CjHۺS Dpxs줷mNcqjwh.x_Px=rs׀TC4hVAթ̒(Ū剴{Jo rχI YB 4 Vv+[D TM& +tc"І3'K7gi4¼RJe+B-/~2 oORxki-MBc? h2(t(g(ǀ/ʰlOҬM_(:yJkRb7PX`e|ѻ:LyݎU3>x?`zpdNPR%{HHhK#`|FCpIšu7 vNtEFv >Թt;55 ] T5L9$뽑IKDՖKgjxa@om79>@{v9α$^ᬞ72|$kCnMHE2|X]w6?Z<~aeJ: X *hNFr|?-7a팈6eg(5k;4H=ı"Љ N"YRLO }lևQ?aGH$D;8yڗh܎.IFkɡ7{eqg*VCWdl"U=7 eM| ;KS._Z8"@HLb2OShf=ٍ=Ϙ5þw|cTv-;N,n$twNRZԯ!"+]+AhkQߣ! ]~+Ӆ)}y7ii?hz1p<G. 4'W6Tkg9)'YTW 3|O#81ذ(~Ib G5Aǣ-Bֿ7aH5.%ѤFD`c/F2u+ư"cʀ(4p{{$кa*{P "jD俣J3Aޣϐ^Kх$’J_[U,=qWOG!Sa/rV0a̩$AUTi)W ֛~X\'ڨ{ە~M1vӑOQ?1\}+`*YQT sbʹ.[n T*y! s ~ډb|VIRzv (5BWB?Fmݿ@bM2@#ՋAY=>eHyImQ^ v%¦bGZLaCJ']ĬjZf$mV Zڿ&Y ?]qYÔʩh1`zj;KRDJ/'NbkuyL|#nQ_!Rd$10N}֑@2>ۉgr-ð{(lgz d!C.AxR0`qz]dp$ozܖ iػّ@lژU_dt<ށ ؆>G[%.Æ=Q6j  #vPΔNT\VÜUeT-t90$'n;uzv2Z$o 4ܴ^"YGI#+qҖTKm1ȌaP3.G(t>G8HwukŬ1Oj%٤&b)CK\IN:%uy)G^؃jeG oP`5Qf'Z%ߩn6zi,-R,%VtG7 \vU(~Vu}4|[>O9=2YG|ﵔcBJh͢x?lcNʼiOAi$``*ݝwiS |ͦSkH@u.VJx/j]]>i|CjRmLW*?; >Q0RxLo;pMov<#!Yx-,}XbiCűq:ߢ*w!`%c( )3e?w%($K΀{9 " 5$M–P`>D}\h6Rt J0Ne&?cpSg+ƁQ"TmI3mo\6!⦿Zh1R5Vh+J7..Ǔ {8jd1'5YEqtïk)t˃P`A 8 Nt.l> 7kڴ)}~ t׬d(:[-_$MQ+:(VdЬH ()DV|3Hm%3wkLzg^%F# HzXL|SgI`p9wGNR?zⱆVVN)u=TG ЩJTuH<%`NxoYt+ZFSTT.QzHyyY]@)ӎM2g7WasNٝ{^/`1ߘ4zkZaAnhhcf0-3v&1hzKBxlN-6vPUD6M┺U !ld I z0$rn>;A'6]&֣IBy!2/or{ Ue% Z0viů9TCH0l9$8> !UnMbTt;Lf9'j2xS)N`peVI f"@F,3վϺ蝍<,{wF݁~"KI;!}(u+'}.6l1Rj1#~ЩBg'=X>ox`AB {*wGmwimW+kT &Ѫ]{(RYa(\ʎ㲄"h9i@dz[<7W4?G4"ALT6LFdܦeJH5<45ك<h8yR"Un9OUPUx~UE0WĒ҃U*a^!U &ƸDĄ} ډ<[ |\}ۺ4L9O< `;wwsdX=t1ʇDo$F_?g]iQCTᵀ]E|XEF;i@;rِ#,([O)ڇ\dԍХCi@lnIH(.]BȺaVrwgWgtFX4,.#ˮ Sb!g6QbZ7mPBź=f2sn-qjT! Ds=3j^urdD"0|!!t|㸖Wӄ },sߦ1/mxJVwgZk T\Ϥ 8l mOƫHyⱡ؄(/%v6],@E+s9."I,)Sl5 ~@Hsx-o<[jD%1E"ųSBj @2;5dnH,'9CF]`f峠keTOz$^j?ʕ=-װAl ,U{W$[c%j?dٜCsl}Ag2gSἚUT\hWPLEH\-gUR/A N `c7#Yi#Cf8;Ti٢TiILk*[$tYC4cb¯vmEA^sV&\*yvp\, U "1"3y˺t1Rꀷٝc'X3WIiao"#X`&$ .B$%wlE{hƈRXյE-ֈ8d:!akVq/m? 9^%&,:lЋCn Xk$q .-NZ y̋l:G?馔UX]9SOF#=S҇ ߗr_zN؈F fjrJ{xaiưYg}͇Y-7 ̜^:Q *):!aɓ }8&c_$Z=&0(P!.AAo0oG|CARדAΆFH a[cN݁ Jrb=TӑEIDzJUᬱr(kmdf);oFCC!i!o .ѕȼzu|~I}w`<.{ L(h?6 CMP6m(EQn[J݃10ɟv#'j0Z7Ț-FȑdU2 H"t?*lWx 467! w_̒Uc&Qfx n\3ҋ >},T1ڃ}u%gY׀xG ~gi{ڄ~~Ͻweʮ=0|Ki-2|c5\Ԣ<ݻdf8ir.D,0:_o/|9aNr!$VI/vP!ƋY^=RLcLCy4U2C/RXHhR*+$cʫ$eעލ{EvnɆXLulPr2謥k?Jf~rvP=hҤط i7fCE4`a讜eVCۄmA Vh0;y@xEǣA0Ƚd];N%H$b: pيA$E 4Si7(#mU bVOR щd893G+ ˇn3[…:#n@[{ "١8m+kBx[@2YSϭ_ _o9 _Gk!۪,̀xJX^U'1FƃNzKR8TM2y/`]s)KVX$$j3{ bxT%F]ho$b[De[.*]iJgZ60 ,Q Dʢó#Gҽ Hd=U=n}XJH(5Iv,d~BT#n,e }CI?p`ʣ g EB1!Q6&~5A rݑ<ذ'ǴDwu #o{r[_|YHm^)QDͻ.b"K8˃wfJ6N9:m %>w!ݴt D{:q{t?byph'Ky!8oW_h/6"hPqt J Sf!g/We$q|< N[MKuΒF΂8u_)tn>v>4)^Þs8 5R\X)ڊaՁ,n!(' H(NW%]ϕjS. ,) Z-$b &<Aɐá֐OnMlSWQ%&HRHjKc@O˭l B$nAhe{1 D̸x~[l^^|3 7o4-f Ѓi6 *;f寸heHm$(,27UUܗEeF]$߸`/fO<̐`:'r fVYѮM:h-O]Y$ l^Q;NTLo~sÀYжL8"=NGV.7]PFH3k6Rx74m@ ]6K8[D 'Z.:D/8(zr:YcZXX?VUٍuoK(](+_ _"s&Q>F qDs)VOaPouoSi :T`fl56LHb}G+sΟlOvDY\hNZ@x;mj6*_ﵵ{0lŬGNXK(۪^5T'q  =g'?vpN q+@cz+#+5߃ m@_i&=;`3{6SH- ^O:?hyTPK/Ԟ;yvmBك~Ԓ)~?RR˓`+dصJ@#f:M&aTf;+mB?hv1 O̯RQo7*AA!"*ݵcd e*/TDa/ȲkVЛuATArȨIɍjGU꺀U̩O'((<=Q}ϋ0NDG"mqނvojuoilSrsJhDOD[! s@ h2cgd¦'e=+@Mp^`rm]!h6os Ɩ#`{ΑT߆*>͵l zk[Xa$#!xmCڬoa[;\JhrkX\)Р-kB`fiRJW%4}wDDI;shx\qa6$[`@󁟹1sg_Zh")#8LB,+oq:ъ$e" - ݉K'޵ d9 ]Y>&z⿊5 b?͛,gz@1{cZ @?[O+jɋ5ݺ(,f,F^APMb" 4MyC {h.:XVR,b:Y9]xA$k[`n:iۯ a9;-(9@480ݎQP\~*IL;x.^%H}ؔC"lɘuePxЦj}B!u- bigF@}K8>3^p鱮#&@FM[^CMT($[A"|8&:rU1mۚJl=kLڠd $ODT\Ah&YK!v)rDjmPXD[ݒ #@!OQpP DT4RG^pi)=%lˢ!ӤΔr,,Dƥ؈DR.1DUx>rQMzCE[n P W3͍?^z~fqUtN@ |f>rIcj1Su|-SRr%hB <1/^W׉q"O /PzOcu>O@jM )~4j:`|5S$`2A8 cg WԠs=_ˆ£r9V!4TB0$1"stڥv7fb)ɒ[Jk1S3 P OĿ>E$Ӛۏ\iǰfv%7S bGKKҔE:IQaHZխVN-ŶzziR>?@TR˄g\ ю̷R[|T5Nw/4^_ÒF/tH[nz%HC+S29[hTQnF dSVM|[+IXom@3 O|w^fFmWUsNk0Z_5eRy ;{.PC D6=\d%s\ ?+g^؆/qlJ50MXS}#B'.v;5.Fsv vs1L ^V?gR۬҄VFaXG^3cipiGf"u+$-%6FfNn"!8L"qSt'y#~/2yp`?9-ޤ$USƝA*|HgBn4*|m5+]~ux* ,BHH?.P-{V޿wGC1D#+#&oZ<&%݃ȓ?g"1pxOn"9H>?q*%&JOnt>t,SOF0 #{П.vUhazJ7 5U͕ZⰡ굴ۊnKzAWk-5BF,m)۵Tcb7r*XWZ+rxZP]*mq.C!GC#~N.B(}Vې+&&a}s,gLG|y:Cradfr[I\@g}uzeI\cKc1B[dרM%iPY!r|vt#Эybmzz;.s7xOV~FgK!˳4Ow^ZELpxm $Qi Z([#߹"s#gۊ0;[`KoI72w1&%GW" "qRo`?wf*~g^_z{pׂcC3XL-CK~O;6E2k,V^qӅXPn7(]+A&k^IR`DX͆\SAd 7zŝȐYhdfGf+VE2:Wg!B77[L ^e4`rX*F S玝c$NCVG<7hݧ>\=Â@Qf!hvlGHU flЋ,^ޓ+0F0x%`->1Ry8#0ε-S~%:p^TxЯb=+ "fY%ђe]MalX %naEŦquta"S%+?O I 79 ҹGﶉRb:gTBم0]Ґ-+ƢH켖&Hϣ+M#;Ψm <2#'lT ͨNf4wơLŖ{-LɡZu{>)eeH@ y_TlBqHH]\I(epHihw*@'зWb $%h'dp+WN걵pWW߮OqG3FΚ|a=ho"_f\gHX- ; AE]?DwP!;Uc$Ys,c'W)w$.#uǴξT2 {Jvcc=7S a]̹+yiR(JV{'=$FyA94wV\ Ŀ1k\DM6Sl!G3.+ۧ%ع56f{ƾT,@+0hSs$A>hTcУ%; %ܢ[X:GR{lkh—"Ǫc^ޘSa-4(ɬ0D==ӐDYdFĤON1ay23@EHj#}zX4f Xuۤya+ee? K |ό0>elJnK4,-֟1CL}-R(CbRx#ݤ:N ̂:nNnl>W>q-" qF(P~La6ǒiˑ݄9WiQ\$HĪ2$|p{gj|Ǫ Д+fܣ>d?1Qc{؄]i"׮B2NccZDܝw vZ0 r_#DTr1:٭JP:p҉V mbnhC@z[&(-Eoku7C bG_R pf2st#6)R~Ѫ.!궽?(4\=eVKkˁWes'ĒrD?Ȩ/X1:iP:| r9 'LAuBd/o_MxVEH;g/ҽ[V3d-87+?1:LAѧYy&D#kNNd<)&P9,2O45JDiRH赸Lx5,bggG X xz*f96X@gj)Dr_AR bp~_,w0YiPV'H!.y?"gi;"N_N@\!Uז9p6`́wGpV7VI Yq{ZaǍZh4u3|9X==:[#̫,F >'M0y-]_\˲IOso\ ڢuIF;%uNJx33&/=e 'y)S]~O#mup ota'T&mْO[-&VP v>Ts`caF>Ekhk,M:Vب=<Y4uTooByY!GB] oL }` %/mUG0x1nS bs5݈1OCT'لHDN=3dzg ƒ{=u %B_р`Z-5"FUn粼@+X|䠓CՇIbƠ ijq#x5BMg;k#=P0J%;MIĐ]Iϧdn5 '"OQzz}C,&?a3=xZuwW:-^9:91RC}W*V}!QsqXDޙ_oav 25E;>>Bf0#I,!ÈmDW}0T(֍ͱdO#bXҫ1HQ|F`P¦5t܀טj/*qnK˱a1slg#}?O9\ 'P nPY/SxwEu 9W B>c薲=Yl*šN3?t\eqO:+)..qDӬ54x 2WS>cGSb0t] ^DHߦ%%QhEOQ1v;[X TnYօPzeJEÂxG 3fp9 %@fn2+\ ǻZ#\Kp{\^z^|O;2A+1\|ᤧۭTĪ!2:܂KE6kqz sMui꤅b3>AiR!+,BxjR"Čc\/dl> hT]kc"sj;=Sxã)jwc7=o3yXf$9Fj>*gnyxn54 |LR."cC?K^\1ˤ~7PHZ?Ƀ"ėgoeAokXy/XȕѺ7z֭ $hBv6(F2_(OF I ֆO,x v]Oλ; Gj>4<0=k0 Fڵ2wܑ)66@`"–+ӵdmn3<ن\WL6?70+3]Aߋ{z?wJte Q& 'Y*iH%}S?dA2\2qz90.u(kC._i @d}߱,# ->:K‚!ui`$P< B.Xw\SDnטt_Kwg__r}݃4v65TJs&qlW/ف0OLL@8.%HpVwќ&pfsZ'MSI)kPCV-^LrB?3*hgfg~$n5wIC`^=YqٿTEVA!SV|sdFvKJH)"-m̔H;izSCf3F]?}>!Vz3fqQM,>G\.F4qֽV>.rJGfw/_&7<;]1m{`epAZF@v›z]r<2z4qP(sCR$ޤκ}l5)/|jir5Sw7'$7w RmUy?KmLۄ#lEX'y Y.=^۞ 0Kmybh4$%8Lj fr"&l|zt CŋNԖq5 !T+ yz(9Io3pxhaAX> a{!ʺ%C\F-O2o kMṢuMl9x^j Z2 ߆tH7ƧK1IB7+'76f6Z8{j\}U&Dq`72*}*fNV pOۿ.)A2YWt}~cfwjSr, k?CSWXDfkԃ͢Q=|)-dbO{l%D=Zۖ}RwyͿ]s)RmC) F롘c5}'{Rjc10\9H53J9z_lt>!,W[H!w}gY6rC+)89|CIkHvFJ1VR {7qk5<]|`?^#EikiRHLSf^qlAywʰ2Y3>IV#Ɍ~L̊$ غ> 0Z©깙q"oiG%X>?fQ}x1=_Бک7# `a]ӎ8kjّօ@x߁d+;2 K[~ /5WgBb.!)<:0&~pmiV :Kvq~'4lu;( (M|gjV tFm`1S<}͢ aÜǀRR9n@a`^os׫) } &;"^:ֽbA ,8b){-$leʧv2fÑ]τKce&:.㇓yV{܊?g= 5ܽfgNP7zMPIR/rPVY;(Ĩn1*vC&ډbc8Iʓ^?FF7o/(^_.3Lʚ:: +|%6<>2V 遌KaF}ewɠ5vjqA`AGKAᕃ;5k\VLDvߕ7h`;JuC]8JgnLQXhcɊҶ˙}; S-'+bŸzkiuJS`6Yr(RhUμaN^Z >Ԝ] !|hgs b. Pɗ'BBiw>Eu{]H7@q\+AFJ+"aާmGz]۷%m#+,p}62/i |ӢD1`7!$"%$0ˉƘ%t.`dz TM`M TRP?Bn釦>L/ deP'\C*sxhؠN;8헫\AKM9"Gwi Q[(oB:/Z߯ T!B,+(UwVrY'im@zG_ITmd~7mE<>kydfc!RLAQtqT#"ݥ Mys63^V0G¦ԝ$!yCW)'FPj'© b2ʢ Fb;05 McWj>QAyÚK3 B'c(# cAl=pQ΢3] C,8wS s _0(yu !S=K&Qo#ӼMs˻V1-UMF) - jytGn a(my8eӉ0H"\4qI@ǣ(m|ABۄӅbP>ɾbb V֩L2 C2i)^egԋ DHn 'HdΣʡ)[z`6XdNKEU簒 <ڳځ%$3F~㹈Ƃqn7w)@$C-—vMߨ.S eP?YME{gN xX1{_oWwckU:;13nꇐ 9/'B7GCZԍJS;vg3l5uF Z2(QoRŕ6Pq|́4GP|`\bRrv VoGjw%;柟g"wo*џ)m st, J*+/76᫖z41hv.ſOێ>ֹG^"SH5s,aDt>]Nb^;~i݁iݜo~hTvϩzH΍M>jO`v cL%M*NzA?1c)}i9^7wKF'ihə $.wyCkUw6rA9L]Q8E/uw pZ#D`[ܛ$<.czcSMJP>5Op  ,R׀Z!T"*DZ6mQ2bGT`AFѲP8t,*n4k~o4S{ᴹ'=~6'<:?ێwl*01. ,IRnίB;V w{6ǺERW~x75Z=Dy^Kz{.l PchÄ́>ͦ=3Wq"xyGw+*Y:uI,JF kז,'k ZIk魣>gˇq>*?_)<7@ߛڿ#":uR[xׂpxp Dt}2%摗 .D|weǗ~AKUsweY79SoKKD%Ư]ֵ]J}G];ݜw0()h Ǩl|5۶<&դC#XLyX;8Vr|[x)+~IHS8*EtUo/TaFm2=- δT/W}RNM(lP^ g WI?MDp `mp ; w~E1ڊMxӽ.G\F(zR-xDOp,+9cK_ڹqƶz~ۼM"dCRfUsN$n}H>e*%apZ7Mv4s6PB#xQvHfX*XO p:\49QV ڴqQE@Xk‡M˾ #3N.z;~Hq9b&Qtx*d?3*,eT:4+(8F57mPޮGqhA>s Xw[W.r)g\<õ hOD!}(B"V (*kPX@dﹰsΔnx+@1}3dFuĞ_D" {%8/sKRWX*{-ԩn-ﯱGr;z]Y"PRzd1-3pc6mDVTbT"t/Srg~ ; o  1XQ|ܺF㭄$-;6,{#:GSxOU1WyB' 4Ҧ EN/5ʻ^5X 5,,$VI2VsQM 3Ѵ0Z65@;*ҍ/sEiv${0\BA6njC_qBA]ha!Չ90E7AoEZe~! #B\̷\6祴 )U9jZ]^hfFZu끽f ,wL"Ub S c25 ]N)<8:wvʹ!]HONCStYig1Hi4w $v9d๰AǁR^(BpD H?a?S`lqboY5αIreIF6z?*hX#s$[Bwf}[XU$hpƣu /CJ򫨥HK4M;@(pBQA^ ͏Ug8vT6ciyC3qSۡ!Xߘ]t#:<.ӵ{dz(50eądH0d o*wL%/̧{g(u߀ZhW/ jOvvS֫ӦgtF;U4ap#>$`!/~}֓(Si8cxQ'%Ar ,7|MXkd/Z{5}IS=PhNd ̣ =)hM^)ef $Ԛ0鮽;B{":V`D*~+){Rn&bOӶ;fؚ,ȟ@6h[?Wf- t꫗҅6+_P9Y g|Y'6R\HB#hr0zh2S~*ߙf^g+Ӣ?`PN𔑶{ b6M7`!HjI`u+OXX|O;Ps,cr{{ w 6 b{ʇsE7wmG|)ɰqfzn6wL-}!0 Dѻ樂Cmשx-݂i49&eD5G94LķЀ~,<27(s2 e.@Qڵq ѽ;N%QL݊wR,-qr?iĜl޵A9 kD93 Vp({ͳ _dQ??Kw21z-uNŶڛkzD>AfJrYP_wxPZ+rT qJ-]h;*VEIl?])kBP!nL,qtS-hu.%QaV0,8hWeo@P 1DLwPGb$όbf*o!I4P:2zrJ[;ˡ 7uVoO;GrVp #0 RZ/ .QGF7M@ɐ a1V7cK=nzL(af@̱@aPF{nuǪ&eIkZ91I QȢ!!5\I)TQGbd&Є?)#رC<4@5@ IApWr97;RFD׊ *Hx.!җB!'12"\#\JPE8ۂ9XhQ5f_s3ey+;)Mu'M5Ţ>NyYhTrb(ncKA#(ޖ ^d|fl/ x%SB; ENMEp_HyD/W7b*7y(;(QlRw3q`yL@SH*bF+:шJ"e0t*hMdMd5* ӈ~=17쫾 NƚؔߑmR<@&a~fXR@ AM jNJi<%9+c SNJUˣZڊdx1be8t6ҕ#H_n @bOM]1/J@ZKH1eY_RŒjf|o[L :ѩxTiK3F0Iv#"1R ~v_Mn<+9/ee_/ Ɔ  j 3rJ|!.q`wɏm95` hlhn XV*E.χSX=SWecoI4PG_2ߘ@-㢃I0Qʯ&c e+ܛ'"UӢI-"30p:L[~8P=hvEiI93Nvb8tngTaL(b(~-|) R'<Za6b.N3a\-Re;.K e"j!35s͝ۉu9ݚ䆻C򬇮+%Y /,^]2,49Z2~Rv3lLB:E93Ͱvv^='m_NMW熝qL@  n{ vc &NPIw:&ZxD:iY_Kf\q8N FNHi5bZf׼iDߖ]+B{PNb];2#??bX}m*Me?XwKrzL{͊edu%[`鰼_f yjT?&xhӱ _3t}*nF`z;06ren1,Y{I!脍:[: +NrKs'AƜұB [fs >7xXe:9ȿiWBj,x/vj ڐx 4-h܎.rI|S$ ơ}sD2pEK H ^h#9N]Tt|1JCTY3ߌ $d>Kv?>8!upW/G{3ٿ*2m'OZJ}EOo`wD4𡾐'LLtȌցDR5lp$%E\BAխ>r95OR- :'@]Wz~>|8_T#>r,Կ[ J 1QKϑNrs A|ƨjuՠdE_©xg9Q\)g_RՍYay]@vB/@p; So_zwbGQG.*ߴH.r1V{Hy?\.Z%<^`3,GV<{Z;?;0*lcGmE>GQK *Wv2{?:|.m,>P͌v8"zzM,.I>] 9ZNNTT]B?tk=G8kz8@`e)fgT!?c lEDo] K󻰋PݕVlъl⼃кxZ e Ap%m̊ϵs$i=,)(=_䙕oiKjwF,T*E$ja ӻ}e>';}"T/~&ܜE@'ɻzg0}e"*wz%.W|8bj>ւ)D|\w0VKI$qŌ,0ʰi SGd8.RlE^I6;6@J`q EF}-Ht:0Y &¾"|AzFk0Å7Z(\ o AWRt3 JiTξ*V- c@:{UһQ $FjP-p-hQQ:IP=9.ۉ8.u77 1 uL~lAE /h? bQymx=3e]A|t,ǝPWt h4e:*fKQkJNmegLl꧔o\=y5B&Sh ՙjiG d&E) \ޯ;t;A>;Hm`}ܫ4t_\{|QB}c|2AYa <-5Q^/,'WЩY B3XG5ޠ=*diߵprݽyJ-&%]dw!V4(v,֐/+Ra8ay&ˏv7}vN.N-zXo;WpI[g~oBmiO%% a)m]N^@Jm^k)λ>CFy]s).Yp 8Tۃ#WiH9ΒvkW/)5d#Qa{"9 q!j/<7{WռWMϛndH.#>!V`i/:=M^.A.lArnzPdm] OS-gD{]4¢S U :K ^db*`(= r;`+˯EVKCw۫į`!Q)Ҵdu/.h ,oSwNlg:y% :eaMȍ]{ H4 UUVύ43^`sT,[** Ie-+~WƷ-oB- (;Pq'BtHUhq|xDR̊Oh/Hdi_P[ӿEC6ւq=o-){Յ%^O*T';=R" c,:2#swעFIφq" ] fqj +Pāg.hFY=fNM#֌@ˊ;-T %#4r7>+c96aG%B>Yw_E pXHA38]$X}bj> :'FpD,cNBBlxUQB|x?-P4!J7s /P!qR`C P[D!%޿Ʊy)> ~_pR)͌ApH}j5DsۏAuyL$&}ZNfU4u-gP\Ĕux#ga|ejU؟ @9uw{# 4B+Pv9vסɿ޻ z U3C' _%ڣIB( LJGDkkp= lgL?70_AUpؔD> JfqڸțXfY,D!}}*v#5L*4+1 `tG tlpRp%^irhXL6́75w̮wz+EK,U İ:j껛y2[qt1|*v cup GG.+MWg'߲!Lhp A%_< '6P$3p،J8 [,yҞsQrrIUF\%^V s0t ˚yq,鿭csSX+"WzB &}d⽻Au [.Q")MVuou-ss*#cLYjdqs ?2܍wUnɮ^6^F uQy*YZm?h!+YKbZ1XN~K<ݚz4LD>m DGOc0ga&)ޜ g֣ɌBTo@P 29Z]U beǽtox m$I"؂㤥؇#;Y*nlr5MY ly^e6#o&&vj f?ߕUW㽬41ӔWp'\I6ȫ.\MZ ,[v-k#|Á7RP#}Uc=ndWݪʑ)f Mw9ql;85fq7r*?O jNj(2qR!$%&? djXPAGy'Y_}s>^MLw,H YQ:Vt-.J1#cdCygi1=AƐS ZgH)+&0g/[7A %^q%B l=k e%a.5gŏ<ޛ*}haN,VsgiʽLy$T&jڔ O?eE,&< 8-%bUAg_Tc } }Q(Y5ޚ"son nB ar? VB趈O?΀JmZ鮵H>BLپ9þ a?mX&aF{X*#Ew^ɩS~_PmFpt )0;f鮓oPn'}'7I.mjc rem8d&5F~_!"OS=k$1X6ܪiǵ|6q^pQ<.|^WnAYKa8Yo0H4{(d7q{T硌PᮔqcN3C6唁pxŏp@2R恥4B92L4AYg<NI]4k;D`l 3\Tt޷] UW7fSʳ4|r&6e*ܭ|D/܈ Pdt?һ0S _H%Z ScW<3'2=goXGS݁'5wj[,dNL+N?L'`]+h*`4)GjWHe_IIx+i˜!p`yd_ Wˈ1z)W OA84k*ܣ2>F)Zyڬ;tn9Y[r>ͅ"Wr VELQ #*uGX<Ȣ} Vl8}׵|tK Cv50fTmdo@ݡ` fv!ʊڢ:TdY =hU*2sO8ڹTN΀tBo=Qaؽ P~gٸ#' q_+fb!p¥^$Rc6_.ơB0P\Wmi:h2c H2~o 0p=5fJc2jU\Ǚ!sJ18E% mY&CSsHX5?M^^{{_GҘ=׎^oe-GYV߿pkVcSn 12whjbZY4~;dk@I~+7,b=5p@$,^E]HoXYP&n ,fgGDΥ7WRƦ:ɘU6/hyS Sw}xaȿuSJ|b6 ?ρz,< 5Nq.3CO5p;^>eC4rvKD+r]֋dG Akc7Vm,HX6xK; QjVK& uɛxiR:Xrɇέ*Խr}T,MRڢ2" j 8dbiF- d& (/7KYkݝ#t"\:aRB 0?1:[K wܾ+XjT(_paaHՑ3qwa= ⋗!.߾Uם9&'|dyVː-LU!b3-O:s_-B|i%[8_c;B`Ϙ9(n#?Cˢ1`2ۮ18{Y aCa?o(nIoP`KYZۓ kHL#5!HqEDRRfA+2|~/ټ x!R+ w7wYP^;`öL)j/VWIgֆszRIk!JvVtGëڏ>~з &X[;ɃA'mU=աrvv-&I]B ;.\Bx9m;MxYKsP VC&_9 /3I d@6;;3( /YB´4!0XN#myoy#uKエ7PąizKd m"{Y*:CTaDu׬AC=sR=/gB.Ԗ%z։qt,c]tF5 . xҕյdo88xtrv/R#02Jd'4]Vg/xK4[8!p-iYϧMg(e\6wыe˘1)[5 WZRGulzOM4P9$]Dpsvz+K*$ )/~^"~; )l]φANA3L{_a~ir):I3@Iܙ0Š7DhMTgi~;R(Bنd օ[)è̦i?ƺxZdУdCR,[Y]OdPW/O/|y&.K[fk_KrDYW,CK+5a)D Xx篨.xkA4VNj ,5+Y௙ Z`ip;FWĦzEd%Kӻz&/"՛WI D~U("\++ rŖ^X= |{ͪ* lKOfGʅd)̨ZPFKv& .xkM:6鎷0Dx o*>x"5;`hdtu cg~+B4%_G@MH ֽm"=&tߨN܇deCRX\z- L:hg2dwa?u->ֲs3MupH m2e%R63\QlQg}cRY%G&P)JRUi=I`- GȽFѲ]'@yq*[mIMK)^CH؏fTM=֙K1Ɨ֟A V$CӚ !'eFG\C@&.?ϙn)wW\^(E'gK :G@T»EQ錑+:ސ!P-YNW}[&bXWXgUώ[ mi#4Y&o[!Au Yd (œ/n}bp?J7+<4e)!r" j D&0⛚Bx*6e&\:أ}S6GgNM쮙M׳X-jVUmX-@gAuwPnƈ6F`OߡbB`OUn[ D5IEjo ]0=0W3a"3~jk714Lm3`[G~4z (u|& H/Lmp3"_- fm 9߼FXm}]itx]ś(oub%VV {ln GǾn>j:O!T"R~rH__4ÉBpx"uGPu#n O5jr+!0^aq(c{b.fUvRL.26Q#Zг3wz@p[z*vT,)=ReCXEdPvJgbԘZE?5SWNZvnQ1-/~Lp|.{|EUhV85IGv_FL\)i]H$Xelxb0}t)yZR+3# V *j6ŗJW n&[4MJh|6!CqsKFp*&ܟSL*kE= tEIĔR/x8\"e`5Z^pyZ>,/-sXRW _#*{2yc9IoG\\QST~}Q G:Bwr͗Byw[u`;䵭|؈: & ISoT2(g pdj)iwuqB7S7DhM¡:Dn]Ѐ̺hw]q%CL`lWď, )Mʚg] aXL4 ́I+Z/5@H7[Gj-;k6Rێe4"msoeGVd_QH'Wm'據b^L_h ]m8%KIrߎ6֌u!8<޵O0s^FD*\| v)dUAIp3& yXIvdOtKMAvp84ui0+ u0>밊v݄a"#jCHo-6ixm=VT>yG䠱g4;9żfÁ):VgZE @@EƉU>]Agn;X Div̾X|͍ 92);])U6(q"ÛEVp|m14VC|&RK0J3:q^PHl-v?)guE1)3p 6^ƷT-Wt3*<:6nˁ݊,Vlzt!zTP;M4u0@xVNǚJCljgFF<˳@Y97h ;)X*"zmgQǮGPxӯ튊BTRJ㳩tNo4i!\((NHř#aFrPvZ2#_JAG#P|pϝW.V'Q/ѱKOu_i "Jf";'$\ؘpu#vyRŭartZGJ@?rX?\L Sɮ9=N܋Yyb#Bf 6 &^użqQWۀZd0Fm#kLa%fz<̂ ѽhsb5m/@kAn~*^~㇀(=֥srȭ"WՀ&70M >y"ōp'/lМdha[Y_[L$Y77G`.(xS5Y2I5)+=sL]Ђu1bS:'pP_o2] ~Bi,& J" C̭+J&y؍ۤw2ҁַ(}xS%XCqVj:gmgZFu_ܱPkJd`t;'|j4 3LJ/C]jG}SD‹pIO!<*d̓\Qɻth[$N˿uV{AFDcQ ;//.#;M1)za`6ÌM͂ Z͈-E'^",S7K61EAKq+{9󱍺D}~dwdrLI_>fo'1X&&j0!JZ,)w~_ա%[$oWRڪOvVѯV]`t5 5's l+y>*s@EQ}}38AF나{!zUkayd 4C+9\PF;׵Km&NV)cwQ[l@צ uu)6^$=@AA%%[Ӱ$ 4ys3؊7,l2.F5Ģ/uwuAĶxk9Xh2o_ĉVQ|Vw5ea\f Rt1; W99j/Ϊ>#MKItGCXgJga({5<- Gfm'Z}6ӷ")L7oCx!^90*H*6 % ǐg&u׏;"e_.j L13(+s'G* XJgBen [r̭wR Ykh n #2?&yBV#N0"cV茞^vtM뾽(_\!N,ފ$v{*pGy;+1׾HQ+yg )4oψEtC<ouLkf(cjM.yKYYXO[4qo87ZLi;*!:t삄UẂB'8g&h[+8^дkSHC:!`]:Y/ϟەmTHKIͣwrS v:MZy#x^i/삺je߿e%TCj0,sޫ>^rrIQΖR鲂