sssd-tools-1.13.3-57.el6_9$> fרQ20? d   C .LRXbb b hb b b b!|b#fb%P%pb&'9'9+9(,h8,p93|:GbHlbIbXY\b]b^b^deflCsssd-tools1.13.357.el6_9Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordYc1bl.rdu2.centos.org \CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKR@|4q"0EP:ao2\ 00m:+|LHNr x?sH cC A큤Y@Y@Y@Y@Y@Y,Y@Y@Y@Y@Y@YrVpnY%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y&Y&Y&Y&Y&Y&Y&Y&Y&Y&Y&Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%Y%e1ec854f68372bd0e1fb6291a2573776074e921bd39bd69a8d5eb8da2c44dbc38b16a09cd1dc9fac7c51768c27ea19bf1bf0178909122c473d60b317b832c936881b770495b8cea72067643c78870ca9a78a6d1471110d74d39710050bdbda0ce2b77b0cdae21a8dae1bc315ad375eeab66c01151c46a8491e86e483a753062a82fef17872487505c20965039a68b51f18b63afe029b14ac4b0e403703b050f3074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e21af5f3b90f9ee2037534ee896eb380f28ee4c8287ae079cca647e0c0d110f48686963a818eb925ce8bb0c94f9f14bcedf56014ffa17275455d2879a0fea2fecee8dc6123da04ed246a9e7d1c724ab7dd4d41c33f7923ee72052bc8a4b934763363da7e47f2c3c6df61a7cb83fd33d9eb3ab5c8931126e6aa274c347902583cb57ad3622cb9e17d2bc083e990dbe9c59cf2c0835cfb21210168a04188196c9e18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903bd56d49165be0f793ea9bc0a0fbf88c27c20d292672b84cb0e67952353c8b45db60546e2fd0b1a4db5a5c7e199a68462dfa6fc9d4f70bb6e847428225f1c6f494941f3ec9c6039541ce3b64bc650a29ac1097c57c034832ee664ad3d8ee9bdf2e101d1cf6b834c2b2594d4814a8ee49b2dd83f3cb46fe7e766475e8c16b0ad94a247e6d836cde2ff962ccf667d769b3d9efbce2f1f9398996a2ae5d687294743202e62142bb856ee5742b66c06e961a34aa71751720461f02dc4f6ab4feac5945ff859b4f742a42da0bcd5ca82b19eabf4278c3208d6fbe25922256e09d637f6b7113f225a8077dfd00b558429b3af533d564d0d3dc1af0ad2b0dffbab753eb5b1571422b01d7722370b142f0707c410579bc5ca16ddc3ef4c74d515ab4b1565b81e7a4835bd45cdb94cc2bc47f767333d4a9e8eef8bce3f5eeb2cab7e7ba50ee596e9230016e36c3762f835d7cc308d3bbf367d8629b3d7fca841e7bd9ff90088178b4351fd120291cf8a21c604534b974bff38336e4d16d1fdb7b8c04a3411e1a7377e97d32187663d74ed14c05c6a2eba0a13aa70b1619187ca8a05dcb479071b8350f3969ebc4160da63638f5fcbee6b6e4af3bb0f09c0e42ad72357d778d6fd567264037a4a4c081d4cabb5ae706d2e0fc2ae265b623320a5e2734b86190a772eb9dda989f2f748aa3fbf99df359b0282a7098ea86131d9232aebc105cf8dd96f4c3350f176c7330c5e9cf7c09d98f5bd0d91252291329241719dcfa0b9440df973197410da7a78b4d71bfe834d9e96447a69843a061e7ed624189ca4382324a35ab7cfe1475c12e50bc662685f18dbeb54856b351f9ba86f44c104cb95c7199386d7040d98912f4a9159b0d24b4bb54ad605d2c0f38accd6201d73f5a228e8cc0dc10bf14f9c4457fc0a7ff36ecf6ac0f9c7b8997b3e99e7b14bf320038c14bc3a74a2b5aa1dd09670fa25a5e78bd3781a26ede2186edea3a599c2fc5664a0198285dbaf1d8c84418d440b18902b4ff20bdcce840d9d9e54304323ea803696a0d5f50485247879dfe907fded7b808b941bf5f36c57052c5b6b6c02053cf8b388567f57a1bae9a7eb2583ef24ed2d283fce5ce51f8e909fbdbb3cbeb68359572abd8cb7a76c64de1f9ca5b2de01c9474f311e167573601e72cc8e96c39d65bab72582723070ebede1641cdfe7490b0b9b815c8f716863b4004a140579af919af012b19f32e396a2b6a3358cdabe04d4feaaa26804e1068ad2b9b4f06d14d568dffab20416dd8572935ed1b2202297a775977baf52b0d18ab878337d9d0a71cc23aa014f6ec5686b7e18185d4525566eb88f2444db80a6c1a90c4a473d230b76a9dd02379a784cc12d8c748eedca11523b837dbc5402e3c7e068e2d35b6a7a2dcd9a206b010ec6228248ea2240d38b7411df8eee8260a634dc1f3c13dea2d3bbf32f0d63c491dbc04849d3d895bb9b1e89cd9dbfd8bf065b062cc280c2b277bfa884e21ccb85442c43cd67e0ce27b030855220015afb7d7b64728bddc14b06e644234fbb01d0cae463085694640dbef5f1547d8f5b692ec09177b4153da4ed567ecf238bf9490b4c3ee4835876d16d67eb25bf01f31e288ba2451f53f857f37b21ad06a27f043efeafd2060e114fd21cfeb79da55a2f4e7c2461738b52dae0a97cfa6e4091c10f33d360c83b987734e1029d19111c1c94f5ee3b812f6046be8f060a6bb6473e14c5aca92526ab0b4f670636faf206a64e1c1e04f75b07f37550f857712a297c99b5aaa2d982edd5f70355e19105ddd08fd82cfb4a920725014bf9e2f3765c529b0306ef3666bc82d7982dfb9393b50b0ec86da5129aca10aacd24b55eac3376acbfbf7c42ae6b528aaef55b6c6fd09e0e79616c4aa1eb73a4b24bbaebca976ed1db8e4035d7f49bb188333cef045dd93ee401a137eb7e755dca3b9743887c87c29b86498b001fc55253fd3e67201c4c62745b82f9038f34ba89689da239fd813677185207225a121df18faef1a478ef1ec86c5c4595cc0b7bcf86900be9b0d7e9e3f90b7312ac036a6037bbeeea7509e39284396bb0b81bd9f0a7fb14c5a7554382b42235642b694fc2fb844088d619aec8f2b56f67dea6c8c7dc23146cdb4fb5e8c1ab08f34406ba4b5d81415644b7c0e91ca9d24d8cdf89c0fb341fb373de503fe2016354cb7e095b645c8d90a7a04d1c3428dffb62f1c0a3602b87df92a82efee38565139f243ef582ccf91572c3ba0de14effa839f70fad9dec318d40a00f0dcf8dd7d791a0bcc6f5a7dfa01e03535dd94d9efe39cec6c6b1a3106a18261dd9bf9652a0c2b9cabcbcf95d39770754fe14b4658e290bdf0fa2d16f05abc74bec20dc1eca7ac8f7b54c311b2a3d24cc3c691304eedd07c70712a9b23a17e41e2406f3947aa6777f1c872bc33dc80b39f647fd5a316b7f45e735e64b48e2cb56da6ab32e5ccefe303025d1fb78ea3e0fa8fcbac58faa728410ed7ee3d796210e1e4ad44629d81230f97ff4660dc87e7fb555b20d8a71e97b10ecad2a06b72e28c61e402e630a03a8292df8ae343aefb039be64273b5845374692b887f00c6a8bc836bb04cf32857e6e90d0986d9bc8ef11545c81d06419eecf7a1a37ccab90c96668a2d20cb09fc19a859648eb59fc2643c3383181b7183ecad97575561bdc647b261fb46fef28fd2890057b53ff1fa4b1f113ec8fbeb7abc1d5df60684d684f02fe589a40a01ab55b08d7a3b457fa03b5d075164a2a48bce5762ef8741c8f51083ce661309ce734f7dcfa64eac7d56cfea1fcd21694a968d28e0ffd54470b9f57687bb4740ce760a79acc1b4454fc36b1f136dfa40628b598c33011e00f24e6a129911669183670f32af088974c57b51eb9994ebe42a9eac9142070bb43189cd1b632a87926b745f207d9722864b389d6f51f60e16b4280dcc21e0603fa02a7e37057d4e7dd8ab556de75ba2be7f572f280bc117c5d1f795a89cfeb571e007d1a1840cc810e75e33966c438ee0f412a535c6ff776299f58b9135ad8b5065873fdca8b1ee9287869f052d1885709d65752709a34dba6d5e2ae58cecca23d231ae5fc7bb295368201277b17bddfccfecf37f1388b61ba99d8ca06fbe17338effd295807dd87b0df0032d066201eb8bdb2342a01939f0fc0feb0ff96f6f3a651cf642d6a3859c2d1ce20b55f41dde4c0506f635bef1e904bfd44a9acd0a5e6ca4f062bd3bd2106c043dc09349bc0cb505ac4c8eabddba264e16a3fcbf2a40bfdac0ccee0a777dca0b0919fea5f2e60b001eae37b27af3f79858f853fd6971dfcf3ef36e99314f1767426c294cc4eefc1cffce6f623a91d2e0a0a5f857c735150d8b90a7dcb2f46094a2554b9079de23b9410cab36568c842bdc0a1dac1767e42ce2160b1754bc2f2585e0fb0ed1195793e99fa22c649a4860672ba2b16a2702fcf15ee90d763bdee1518c1353fa8162224c85150faff078f6fc5902f5178f4c7a033d101a06ab04fb6e054889130336ac41dee67141c32db1d893bdf2afa4d2fa6be4c746d2653d0050be744d5a39176bffdddba2c220106940f0bdf7359bced4ad8f339c8ec511accc04fb3642ddf763948ed68d152a5e868c28eefefdd55a7d50cb766a9e20217b7eae427a517fe93654745216ce23bc9af7c69a8dd15cd283a6ada923cfd2dba38109110c7da5d3a1e60831624313809a33fc25512227f414c580d72af313e6dd8de8eeac53da0f925775062a87e0371ebc854484a80c55d60d285856b99148a13d8dba813c7ed1150c3aaaa866333b7d0c6cc75574db59a9067f3297483d279959cf7e7d68ec55616cf58f99cf7ee12rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-57.el6_9.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-57.el6_91.13.3-57.el6_91.13.3-57.el6_94.6.0-14.0-13.0.4-15.2-14.8.0YyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1473005 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-57.el6_91.13.3-57.el6_9 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6:]"k%}:w{!vQ_99e[7h  YCu.7NjTlzKVk2){ NӬmC=x©X*֩ Eb.xC!/͟0j@ EU`M2mF-o.Aцp?o\^t쇧uqJ<7r~쇧*$$"ykT >>$)epL":VOC@儉lǬ^ZQ:쭝(&a&'@X, #xmulY9ult`ZJ^)@|79T -Y'\`嚥 ^W=`6/FIٚw>G%u+MJV 6PC:%\=癖. 30+Wn=lKY,e'{xO 7XF7x;͛\gfzR |̈GJĪ ӤۆbG-`"Ut^pJ]Ydʂf !&< O$!ۙ{bm{z}1WX g@*($9ei4kǷeǥ0<A( &Sta$Q!+99[Tw$RU 9IqQVwcOz)AҮfVbx{|HdIo/e) o,kB,+ԉF}iAU-%>e6лirfqs$SunLDRNx>fVKK&]i~6)Su湬d2n>% ~wrR9y}ɝGGd=džMLD$_XH&46_S'.JvBҸޟ5u HJF#^> )"x[+͸K[®v`^dE 0hCA>]H칷d }g3@BNeeJ $Kx('#'iV*,?4YQbr3EZAa-9UXDH:L4{r-),X$ئv5CqYZF5]xʣ"`dmD‡}Uݻ \AzȉD׉bՕ1 =DEֻ9Oj܆լՑ ;ߒr6jy. `G V3ii*nJݸQ?,|O蘺LZxrɝ% +DD sozfm7i;X;Q\2[Gc9aR[!lPzr6;4.fvf{kpD, Ȱ{ۤ9_o\aȸ*0}waOCiI9L5!S}vhzف6gwEay1yIa̻Z2MF_3HBuHE L}q5[ UA͈;#76=Q̭L d# ̗`;݉Xv3:t%]iGpr/`@~+ z k:Uح\XҺ@RQa 24gn#^Ywx!]|u>`pӪ-5 "I)/!h}ӑ UaF !*Lp6;X(+A?ECKNܑê!azN~[gO \W &7N+qw}5s@Yɩq PKaj6;C&Y- 7:q$2W]y7#N d'p_]#R&>UF}"_$w5Ǹ@it% FN ZUC0\ARUAWyT};c6eܑXe[;^ ̈́Y])wp/y9_Mu" .7I=N,(%JI1Q*l-r+!"d}}xueQA./'ɻ~RdcKÊ,liڍ/_4GqC+qX9{ Y4KS}ny( GO®@ZcuSix Q >IqRszz#Q"hpg~aԹs8,1l@I\d? L,5ڛmB(ghϋD&J. R47)b]AL^?CjHe-me5X. @jA-|;JY t4J{GgF,:|\hb߄S"k *ErNTHfaxBKjxI7rw.=nzR"’54mk\v.#jTn(3 Ml+Vzqd<IӹFbFg&r똋"dF߁m*kU󾕗'P9Ҹ_Κ6iWQ:51j38YG.=3u?֞~T&0Ig' Pȍ8&Mpk!­]4 zAgnT{w?^1/;cf`0&v^ d4WNh6+P}dk ;gJ~.A Lm@3C1~ pR'}kTOV[l1i& /m:Uc߾_Z,=.sB_4RH 5UMD_OXz [V",/ 2RiE?Zniz䨲ߊTaUPkGrbp:sGuiAN[x}tSQ? [(p 05!?[:xyxt< }A_{8TX?G5&wc$HۛsR$"b9 O}Hʬ .˘IacUP:]k `kRPMVS׫҅x$C;Шk(ȣn/@ocF BʝG,.o0DV5vw#%$Zl)1l۲#K>A*ec \.q]j Wc#,GWy@#&~6%r3F錗8tqQQUmviZ#Z Z;PV[E鐎FhrNUH^ry!D!]k掶WϿ)=2{7n?CXA@G= 3@~** 0Cv$[{t 76QI :6`A`J}ó;-g@SgS?P{Ĝ%°6z6\.x{Vx_X}`H +J7dZwϸ^G9-9؛F?/^7Sؼ`NOeÐPiu:77f 5k.# \[!GE1d@+#}oUhfiϱ lS\S si G֒~-[;YϹ;V7\Hӗ<ũ~ ]C9}zr;'H0DUH1֊,~PkUK_#5Vi߭'0n{/dq*[^ f i溌!QLrUco` 81QNDmb_{hlXUR!߃׮,Si\7}WN =6-}'CM~'Qe6D Oo"$۶)̧N_%ac[CdaEg"s"#b\0^_*]aڏlk^ɛw1/a/ݶ-ze+'Ebf*S~8R=ց.OQ$ шz rO}ٜ5l3s 48kЖ=n- hX`ǫ:02? H>J{]5#:+U9A1wlbqpyƗQ?48_Ada$'ҨJ q|Y?/Dl򂲓!G6y6W\.$ N3h|pE+ Q2u+v"/tK 񏸼VCG\kbj-8{oz3k8{2yFx&U pގryYB7@eΪT[չ 2ԏ`=/-g-e K` J>GƨoLkWn@fa eܔRß7x<,Acbg4^^nyOfAދ )NG]igUImQ"nF~iyzf 7#'9Y@pkRDZL<qcH{euSvFTFyk"O@ǦߓOZt(ǽZfE/5Jr^]r:m@IW\^$0wvK3 ]ۜMA:pFl]QK_4 6_{*7=E9I+Qј {  TI.ixG+ƾWsbIDQZWCF5SLEe?go,.p\|45Wj 9nBeݍ>ü)Kq;C99Khilv{0 ]=[/@.tڨ&!`:)KXǐW<НL7*B|YJRC(`K3Pcn:P~;\B b0ؑ۟?hދ 3K ȕ6@KO O TIOF| dp|j!K\: Aխpx5xߟ+>5lx5dCEkc0/~|^ON@ p,2 k\2!]4'^yjk .+Ѷ/xYmWAB ijPk Oh}zK$jDw\3dzn4 7/ `r+=yM9!Nq^+Ą uҷ:[ 'P$c+]ՊVZzcU 6-@([8<""mÏ>Z+IeQ OW9I=zvzO {:}) ځ2UON`@#>pVIuafs7;W Aaio_}~"Zzf-V|60B?uy^>ا&֔2OLK٨5kpDlf"Ve3\ݴܓ@uvX֖:w>/`?5ؒB<mTѻ/ Qm&MA;A29,8yɆOѾӻ\UEď}Llr&d9]9d+p_=3C,kJ"a+B+*ˊ(l{:<{@S {wA/r2?E |H*UVS"nLd6&( ;fW:_Xu)޷+v&FYIhJǍ531t{DeRɧo۫C93űQYt%z3FW|^J?i2>,~%r\oӗlwM[)47؞FӽAC(l8:PO55 B@Mv̟v{r3j5e)͡^Z@*:Ɵ}}8M;#7aSd,Q@#oЗy|As1a1a U5F1 iĵ,B4v HHqȹ}[ghOm< *o ε$M* n[o=9jb7432lcNYwnޤb핇!90vf|ĶX4FUǣc_waer?uݟrE;RZNqoZ}]=v4Z/"&2n~ٸW_ CIQABv\;jI=w 5IhR̩@& pOMp46A/C>!<08U83Qʉ2"IXv0U} ]NHɕհOm#hZ)zl(l)I6$V >gZwwN >%QsKfĒ-!߳%NOZ93Vo8З}'t\]Mn|Fc\s3m('7a 3~D( W̪5׻8G#T^fVu Mϯ-~^02&OG0נ@s L(0 PeeOh3j+G5%Ai㐴^Xo4tIq|uEt-$JXߕ\WQ!fTsu6Oxh8Vu'LFtV"ȣ…&M8r̨js2 8A!]y>A:2ǖ%ЙL*J.ȃ.0RG]9%>{Ne$jP.%.դ\(VlHnm1jg1>&j%>WlSLxMf##ts'!UoѤJPpf_r#]?-XTKVߴwT,-hI-R`Dl]tSƅ٦8Yj"t_i q#0zۣ0 q2EoWX{c^(Pj82"p˥>ŘpKjOmXGKjZO1F.̻k80 fy""qnbB(f6 /a բβk#q3!q+Qzg"`&\?oaՔ,>d ^X Oޚ8Ud+-NotKtUۯ9!o%5!H~ܳ("FyXMG|xqqnK!rֳRx[^lRI˔A#1 k" q-k y̦,?@b0}-!DFd{C x[2fAhc0x>_DrtKR5S1]ԗ_#L!h+煆u i֏VxAt\3AĮoYVF. ހ_aўŸji5qs/ًqn(5q0)}u:bl +0JL==-gJL"5qo~u}KAc6\{ṐU`̫`$"͸$I0)kC:$S\eƊ\&Xh= PKC0xdS6T4(FN[̮?Q૜,Ddzy]b[DFq>$_l֒~UAa:R(dPJj$BTC, [BSN'k͜gKCK=@4 AT8Bvksܐ'0[ȣߪU0IA NYJ[FbY.s/d_A/j_Xv y[A,r[45MxazD;WM'Q H聏7?zh9LƚmBG`:f<n" TMK](\q1#G명Kcރndu79;8{I ɸD$W 1cqn&GF8VtR‰(@bipD1MqWݤ9Q 5rk|ķȨ"bTxVp=4s˧6B `xw]Jb]SvxI aMze/qXiv4!usI㬈ieڢw=vZ9tNk^qSqVrk}zm'3H1MrNi{"I,a{ߐ7P ۤd7>XWJɌh޸qۈhGR^|'UHA+ LX$Bݩǡ6xUJpuK2J?8=$A-?db߲%=TRfW}+.v(Iy%}[eNuVT?p>Bq\tԇ`jS.JE ]~n3bkPu_D's?2U$ :;󻅋ƪ _n$YBy] |4edv5d腓Hyzj(4c]Д"lФ6OeQZaM:ERk T3f֚HQs<7e&ue*byyy_pT D$$ =M!<-ik¡1oťYquJ $i%/D E/3eZfo9܊xғ_6j]cվ؟ -&қ Nݡ8+Hy"7ijEĕoReY/TpHz^:nBzH}EɎkvDQlPE#r:0Z'C9FϔxZط1GU! eR<"UM8L,"$D1JԷ<T-XęPAf9BFhZyr?)gb2&ȴʯa!Q$T~[+d<$(me #YғMvS(泮혺S' h1eҶ05 ۖ10S Q'&<5`DVg.( -t⣋Owul2M(.c -"NV#20Az+٨e0ެ m/~Ty5vܹ.,MQ*K2I%*ǯqTG#ΰQDC?܉ `q JX1cZ@2g]\\1z-$)Y;Bṭ^y l!TLASlU=/e'݌7UvQ .eo!] imE;)t ~0m@X7FTp\R~gdd.9[y9UF?3:}IRhYQ'۟4{jY;kCqDzfAA RԳs,>0<%1n3X> R Id b:kI͵4\+`v7p=D&_d6lk wӝwԢ6*#9ss]5b'9&7@43#pCgcִ(n=L nWS٧߹sz2]6w#>ccϠ̦tFڌX1όG}|g{Pd,?^=Uޫ~8t[8vkdVp=D|'6l|>4.jmL(%$ÚU]7@KV@YPz)&aJQo4@ zqTnK%^vQZ`іDl}X V_~4b=Fď? V os!qG:}/9C D-R_S$tӌΦ2nv1m-xt}Rq(Ra9YR 8]W̜+dVu }kX.(iDlv2Q zHM|9>ݧjotu>j͇^h{nc6<)9;vrq&(vn9-)HDV7?U"=@[ 38B'k8@Y.((Ev@/rW@_V4hMԩ^cMʡ4QɅov?ꯈRcpHzۊ5Ua3 PK#$5[?G;Kd?L+1k0I9UfY.gRͿ*0.lk]}K(;9‡w3/EM:.yT,F7ҧ cwe|eySNHHv?vSg5Xldmb7Np Gϝn_4}P#{ZUdop~uc\ԋTv)vȄ$Bz]ݲ78 mҕ~jM9/__)C04Q>W5óh(t^>Yj^>]}+YE! Qu걅6MOdΎy6)Н8;YxF1bTo92NBUzqxXՌ+$wi1\ a'LJ[LH6\V7]*37`?}=4Q`Nl{HAk8:'iyn@RuNW\-ƍ䟃*)<=g@$~fV: )ͧ56?:EƜXa1ZZӹgLW+"(=j=J@&e/_/dJ\mZVpюGIpQYmװQ :>gYԐH\/_wู`,Ү|fm3\+z σ#qc,\~ 3s `_fQzW{b8ʹs;Ϙ9 WE93I ^}*pP0 C =p¶I5b & F")QP(UgW1uLw-R{tog; u rfJI  &%KP}PTPcKdJ|ǘƊS9 N9$ahnV.(8 {.gzfY7Vk@|]K #o'a3Ak >q6Zpw`l֧$ʼY왁08]zJӅף*`=9:b4xE'4J|?=yMo;>CCaU 9vPX..*Tz" Wb]!&?$WЬO{{c0xobN݌}IYxZE\Z //БxHrsܢ Ҧ>?ap[u\,şrٽ'5LxaFM5 eϙ+ij TF%nG5ZR60O!(wI+LW\< rWyqǥ0ا&!?s^xw= K'/jgA5ZEC]1pOd8,ȺɠƠ%6W'9@~pXOXI=If2L[XKaZ]}݇S uϻ4u qs#2S\r3_&PRAWS YĻ+"8<7~~pٶ RgpێdzщuyA7aӺ=1Bb= =+ aNLLEJKXd ෵L}mF:[\3{TeHH*l1J $Ww5"PLTk?B î5$pAzz3pLciW( (6t"sTzJD@Hx̞*2L`-JWƒ%myտun=4tݕ萄%Kau\mgP_1pk,%a^L]G6(EIx.ąbwj @.P8~; }֝\q|aPN"=M0G,%%&G<΍lZ}Q݌ dԯBmP[{DĞ?8&VD8$Hʡ2ҔBp7g=cvŤ`FŬ1_o9t;q<:\L4rG*Gnv<3X0ڰ<|m>I}MtCUyqTU9gH.BH;\BiMN0G}y7y ј=2J.ʞwN;_W!Of]Ť@ASVc c,aV@˕:@nla{ B2rKfת{kRsPGڟg oQdۚx+ܯ3<Ρ1Yyb{4%cD>2CsI^ EkPH1X!y{Zs9 ^M~81O`~.#b#tn] ﹽgVL{/go-Β0(|OhqD9_R#cݭMmB[ipčyr4Jv<ڜ~3OA+ hvAW׫})'/_^2^Yܐdף-Hko HYv8'ӯB_ ^V"de^Hci2\1x}Lh~rePBYe[0?QE^K=QW'v5To  S [ͬ$XA?4 v%>P4Y)厧](L3 B~pg4\kK~R *Hw QHh8HB]˷8kk4WxȺy^s-Hz48¬(-37U/er| ^͞X5w:eމ[+ZM<ώ3pj,ڷEtm p¬?r >TwoȦ)dJQ"ZNTyA-f !Z.\k]'?? Q77-<:w#(FE&RTtON!%>64ydCٓ-0]8D$%6w"}pϙ:5ֵ*z^l":q$ %tw#ԎTS.o&ۋƬ$MpD~P_ReHtr׉R> A)ؠcxޭIzEJZ=&k;ud4KK~8L3t(?TġmKU՛ G Z%3L@}[$6GfKgj 3=MceVjT+&G!/#AnM0gcI[ ={'1x[FF v;eJaJV\7ug17R. #dn<v:(#|nOkE: h:!v,eS󦀽%$赬{xl|A+0ZvuxX,-Jn )fx a=mJ:`xI{ge Ug6U|9nNЎ7=^24OL;CLf*~%؅ΗYG@omv7W翞mJ}@'Ha,Rw^CUn}u [@cùCiPǽMR*ϐEHi}z *1T/Wn 3H kzs}N+4ZQ1f\VNX%#naV|i (h5{]No$,ƘWjǕҭ9'< y(jn,/t30b8p&KF#^&@4EZ{ 5FE†8Szm9WVNǹe(B|<v0RESf9e 2R'G Ԯ_gW_ozНed} qU{϶)ĦbyV1 X TNY>,\T*D6e?zT$nx?Qw!Ir*}Va>eѦq1:r̶q269<#+5tBw Vp%s^DcȰ`#͗n59)r"$Qf#I`^G_&dOs18U %$&X\Q;t{zgJL-BP%^4y %N(ad*J| [a])mGdm%_ %x}k i:و2k2[ԙD~US\x& }62(Y.n!+k[ sGy ԗ|p0э>o$Zɻ|:J}NYb䳉{~p .LU&V~{ҷK$2 ^H+UJs8EwuiI|i_#+lH*1MX~h[f绕"X9TU,3P˅h[{^]wzޞ~o6_`pN="k[<= _=4ծJemvMA~~3W`'ZE.KQ0mh>_ ]Ǭ1k #%Ss/,k }+gf&-[*Ѝ8@=q{NLlٝZm'];1"k&vlxʹa]BC(= w-E,0 K1k<4,5۵r<\q\Ryoߝ5- ۼMѮUjHĒlV:[!zze ;gdswiӆ/fm1H`rmR,jktB`-;?G>nJK\z6Dp_FDCzyOm|ڄbe& bښ'iNtS>s J'ҝPz*dKM`h[Q'^75uƔ]!oqb"p'0eC ~yFo67ܔEKˆJO"()[Ȼ F͎r.[!X 4E?&xj|pE 7dCNg!D vsl΅м?xϚ]90gȥ[`ws9{<8)X/!cE?r_(/qED3]NIU1O} kjjzH>kr2K*)\iW23db=hc/'.VA|A<֣)+H /TpJEV'1r:izOW)|A'KX\j9!7`ЗM1.y vBܩ`D<%Y_t@/"-2,,FǣtfGdv` ߹Z_x^Yjbƛ4ة/?pA'YvkI0[$+l%y}ADV+͎`#Qhڠ3θ(|uh$O3pb_V.Jr>p2nVH2?HĘ5 : q ?rꀤ$Ip^t먨٭Y##vs=?e?f559ar\(֠J*~,LsnK+'(v{-pȷ&K{m 0>Zn@g`sqmJjィRMq oÚ, cmZ\O<|#-^H 0iBAs@҂P^#ES׌g#vI=> dh7]܀'fZr^` x=KjYn%6Z8-WVu56%ocI'I=$9E;#2Fb?fȫgQ2S}*Em#9Wa&Ԇtj/GhH\݀Df vБkxm`q4okm;#qFX'p&)wޛ9فJT{P d\^AS*hεi^=")^m6 O.?[2hLHntv"w҇Џ*=H ; wv?~,nD\SXwW>~C,Ǩck1sC2}Mtᆤ!YoDۛ+Ԍu"-%}kȰֳVr l w' i Wbr=0=w+`g4ʹ_'L`C.\scI;Cқa`rܪst>nT8/uv_e0+]3r}[DT[6@VYoMgxq*1 EgEm>xmoZA_1tֲD%dzWCgA iߍjՃP:uFMHy cZqlz46j2PxmEd1nOSq8LwZp\˜.ԑ&Wsn1s7'uB:*Mw2!4K5NFPI,~ĒIB Tuv#q(D8EovrMe4sY__oᬃt3D:U=)5`ҷIx ~cMyq۩-w(BiB$)r dd;g/L+-pCj0vJw>UGliځN̮hW +ꗽvXjW½9\Q ]g甧一vl~QmYΛhһ-LAZ*l DFka7U(^{)ܽ@4Ld]Ol`45Nȟ\A |o :KK:_V3ySܺ*_VhLzߧ]2ܰ3=m%8۾e >N/c})k$ ϟ~3@m'͆ ᦙQC#$&Kd~Z*yUg>ml>-ܱh$m'uW~mM(C)k]u o>ZU]uHd?(";`$痒U\-Z>`%t: G&]Bְ42y`_HwoKOvʆDq(F| oD~F)b_.6h"m~<Ǥ͔6}(c(u_1,15HU .F- I?92+heTÖ =5ם^I+/8[W QAAu5ɛo+B΄AYv-pëaU'Fˇ;`B5U_HQ~nN(yZc, h`co(9Uy]vEu# h\UG&P}#ĊQ SA-RHf%QZܮT9:IJ4-U3]%Pe}d -!$^}]RԸ1 [l r7"Hlz5s u޳6ߨMc܅ YTY CPڨ1&1H7,_ƵՉJF PqjK2ZBk:|T֍]o\`S<ԼBFU~4h>gγ_/eوQvh/t@E<_B.ݰytȮzH3[aLPvh}~ !fdFjȑpje;QJN,=Fx+$\+"+V[@ɍM8!3죁b;bo9xC9Wo%vvՃx>+e ,ԁn VLE|Q4\7V0%>Eb-f^hJ/N*$&ˋ']'kZ> ƆP[?LM>8 COMzx:lqpRM!rGسv}4p>pNZ DYG/-sosQO0;'Q9i(+I7GB,=+w4ZhyAI@G32X/,y$Q*ZS7 LG.m ޕ|n@NG6)LNǰۀ_E kI4?[-x,JHR:N>#I*op8%*&x^-aIDzo|J͢`(m[p-' !:8 hT),0F!h* S!}Vla8ccˠ4HNիPF}zJR#0 ]~vbPe IB&ci;JNt;gYWm n $&tP]Ek3H2CkK%I`͛ =!T'94S-?D@W@\\^ YgҒ] nhJĺesGJ`WVxX-gG$q8iCd n>ooG7i "Ÿ/amhQE%.@>\"I0Y2?Aa1>/ᅛJ:arv=*q)hf%ǚ" bB3LQ[`yp6ZEIڐd5_fF?~d"8f6^M^)Wa]䮩V_CpZJL'Nvb6]wE}IMk phn\-@o|]z/uAB |Z6x60Ro#a /`b, ?SņiSlSI#d$ԟwL6_QHFPMb*[ (C /%Sآ;ro PZhlbe֨}*^i8a{SV̩Y f7{S:pWAď0#BO)~+"GetHo*)%WfI.7ʾ:v{x8Ѡ0'χ >`'2HFرs(-cgx0kgYgw 纬ʡ;p2 }.m'h 4̪D8AdMlgY guV~ᰳRozbF94E~`b=*7&ɾ; ]V⒑-R] r&ABe( 7H2FltV1F }}IeR#d\. \(j# Z͓ f5VҋbqRL@>}#XOMKeY{{B$}oKZnxT,M-l0AιxN9T OiE{ 5 j3\aħ6wq"X@4 jhH[WrC?T|Q4x׵4MZ ̧fLůכ2ɫU](IAV{͝XWYt&Gƛwnc˂4WR2MkQ _v$aSuh?S8 dDI0Rl~?TI^?=LE| m 3ZJKW|w2I$(PqƔѫ_T 2w &WFG\FsuudQuwT5o2q*o(M⇼2?8hޡVg4e)r[$iyJx+!D;.nyyuVnos|YUۋ3&dn>X(yE̩wXWd }&NpP`[.BFF#W#Áp_ dC/.K8 (}NpJv^^V3CT[gtrѭ}ľ/QzƚΟ+Z]ϟyA% :cUdȬn8f`)_V.ns U%T^J2Mᑃ8):y[V0KpôzAb4c²[c8!%'|L$}P¬-HSOK5W+o zcgʤQZ N t:u 0s4 7.QyPg'Wb(BBN{xqo4׺Ep+WƖ&4׻R̟RQ!`fɛ盟iX&o$|90CK -@86Tu*81ѽMf<; iPB!x~=5z}'<Ómz_zUgIH x0v/"6e-)G|ZK}ͤ!_*_$1UƝ)3xc,Y(dߴw >gڻ,H5FrDVWw'-QT#uU9Rg~>Dj2O0Ooߡ:#AM ^F1zX\7z㙪R,|׺ p~K:DEn>c[?J\Ҫ|{SDÃ(+rݯiID+)<@3+Â~Ѻ?0e*po t7ld8bT6I\rԷ\57E^Zo1wьktڇpJbhKͯg- O7``=x=#*2RRhFn %yH|@$`ਃsz\@klמubG[1 +Rva.FR"J@k'`6rj<&7hp-s4oA-j %V2NEOcMzҤ%%x"ͽՖ260~έ (濰/&<\Rz ZJJ(߹^`4ڝ6ұ t5@L=P(};X5vWY'K3NMH Z ΚYHF7$;㭥L&y3~1s+zX~C.+cvrDnwsrV:FzW˩jnjjsLb)Cpb,7$s<y䥬]IHf:I+c>t܈!No+bNbNaDn|a CU=+^H,7zy_{egɬ*:BǡWV[Di^G36X8iE.sy[rolCtANˎc.+bu_۠lȹv{( I-7rPPbXg|;--Kz!b{Mfr1&N偘?8`FXGOms!;jLÿ#-y2DⰂg}Pṥnw윾υwjhc3t LiN)m~ ى̕`Dh6Om!j+ia>FL7vLZT_~Oi}=$5\Ysiy[ȯauKSG]N*HZ\!مaӷ6!)3:9NL g7K'Ĕ>/6gū-݁|F]W~35ur g+5 wJ"Lñ` )R¯b!F08NQkCp(0=IUs)R /-_iQf5u(CKIw~8fz_βgxHS9vmgGx+{~jCJB^ Ɣt!k?>dCtRJd1wWYsz+ kr//}lk"<4WP/XWTow4ML\C)gM4}3@qL˺,q:CI?9VBo$+8V|ϱgҚcp N\&f&09K5>3_sH:T~ִp^t4l߉J19"z`e `P0EhjG~G̶,P{P\8kyD jIAWƓԍ$j\˰WdѷZ%>u @?D*wB>ߚHҡh(+}b~3/>Ůr6sy3H^3*]UKR`a|*rA/g`-{+s$-Un[zM(S4MJQYCTHcwDщy{9ypc㲋d&\1Sp ޡ"a۹&Kd 0 O!qOd'e U4"rä2mkezj[\~d0QvZ㕃 EOW8?lyaFcz~̄gs \IKW N6BÖXfTL<žјE^̐$Ǎ)ir!9~psˈicTZ+idlŷRtqz{sT^.,]gtjJW+T.rqK4NO]t-3*pxfўe5ޔel$uQXʩsҌiF|+pϙ /2*,2#v@5"k=rPQAP˕Hvv6c.=N|hXYvNr%mfaHEmDGp:$Y2yw"Fïţ[p*EJ5r;c7Θ,_@T g VFmk™igY7 XXJW31-T l3gs(sa-7OBO98cԗ9{ٵqɈ2tsmdx3W&O kǒ`򍘫2)v*4:)we%GYqWix [kCfs֒DypuqɽF΀[ݮ2{^rnu\v  jbWl՚Sz!X`pAmo`4>H cޙ/6,&~%lPb7ว/6OǠn(V FM+_u+'vm(6*XMF-)1?~:h^MUw2_ vL>:X߻&y3NT ^I)5,ʣ^¿Q6LEHvR\ rʺy&ɏ7bMٲ.kv.kZ CXiuQr%&A|` JgP`߮ 昩MM>gAKvA^ S)Qj+uK}|`74M7D7VS*6 dMŠXڵtEtUY:t,+GӜO1IA d\=w ^HJV.5^)5*9)&w}G_li.O4{abLʹ] %no)MvnT8hqtc[OD!SzkIl;u ]1$p;Z^c֡unv0Euٜfz #X`RQ\\!*\ L}8|OU1:w 1TEXp(gՍ[kql6 YS2x.*/Prs\ Ш7ɩT. ih^ޓ5MI<ƫ6ͶSs>vFmeh<ɗIBŏsi|+kk%8~{Nxb+H=}?M6[!׃cVxmaP`eh_p )" j _T `B2i(CRxzUji3x/-Xx=4wU\R)瀜/"{ygXzRs{xn[<|^Q `-ض CiӝT )2j#E2Lbe BFhN%4Ut) v{NDό) H<,+b'~^صw(^>et6  ;P6,(vut3Idc!\=("Z%szݞ!lU&I\]cF^f* V7zfAU$󣲹Th7čJPi2;f x<-_WR,Wk";œ.3^%(fcɈqD^^V=캞 LiI:\)!FC'=T8")Xlts %qFfܛ=4d 9~M4fҟb_c ѷ%Wo5YHMȹ\6]fb~&]g K3)Ԕ!:cxŨ%݅ˋVˢz\ =fe!VBrݠY2ƽ^f@)>2FJ|eQ5fAG&"6w;Wk?%"t ֛S1FrvF;Mbc}T:ᦾ `ɮ#:@㾆>ez5<<2K!i[ClszE"bKT[dF{$vx5aaw=D9-Æ(W.BX ]q_sF>o#ӯDV!Fȣu2+QϟM!,,Xzjn 4ln =Ӂ+zv:H_xRzȈ^ .Eai fjC]n&q/]Xu[9J6PgX-s"Za@Valo\3r@t_ό;2ab~1#6jR-G;.[p9𠘞a$53]m 5\^tD=k%)URx O)e&2c$,[y~/?ŒTp;bdFɣV>x .>(RИU/W̎qHH]a",D.IGB܇>ShԪ/&.;i1~WQڄHMD_ԃ* [w1Vn0-=8TФ !"q)jEE:9CyՋ}l%HE&PN}Q\Qasʃ瞟H:dfLGY^x>MCmbߚB:mǐ5RaWufXpVQqf%;WFEzdD{ ߇edIvcfllJGj޸@)= ԓFh4Ū&p2!@z\o_ ?mB_}98[1irǙ͌I{d %TOזٙ/;R }h_(YU]T 2 Qf֬>{LL(긬?n6K`3a>4=p0*Pps 5R;9a_+r3E")!܈'R~NyqwӟӡA_jtl}:R-߰h~1Z@A ScM/sԙ7$C4+{S,Vg~U"H+Plh>a%ա\Qaיc5"LXYGԜ7FwsKNZDAȕ+QKzv@U r8z P’7"%-ػjԧ[*J)m[*=qyRVL]9?;rRf{&#&RV=GNk{A﷓xqLīt§.f AK_SH:*u~o݀7n,sP:`9URGf dsF)hn2^d2C5*̤̆! L w 7Hq"_LsRI"cbF7J>xj1#d4L7BDÌ{5Z|=8$m2j~UN&}̞7*0Ə&8O](W귕H[gsx8GL gw&yu EL4q6l}fAG2J(|qd̻d\'4odP=!^, cVЯ=}˼rG73䐄}^ 8 ^@D!Q {0A,@ﮄ/ dĄwx+X9/Y.o\`]\`t6܈(g~tH@0j,=()3d853v m0L6SS_ a2QgHk26MBd;qq\_n*W(5A & l,E TOlr:Gyڔ ߝFᯉ Ut浉oOw0麶OW3,idls_cn~`Y4x• "+>i%FͰEdC3ctRnu\7Uh2[k妓!rL6{ @ڍrіTyW: јBӂZɍW`b8|_Y+Po8_6!sJ{|khJSk'w]f|tZu<:|86lq 3%M1~|[L$VCh] }uh~U>)>$匹魥Awf1 eϦВlujFF*C|#bo]ذZlofy;!BNT~ >78YVr,mس!mѩA4KBOu}'2$q}SVZ?/ ddW}bzz[mL{iƞ8 p,xy .|_ zFjCPVG7~KC M@{e$LVu r~dLqn kл0xQ=-3r6<_){.*FFX%\)J=)S3l} ĐM!S7.*G#c) XyaaVK6&z:4,J :ʱXhx!lCӸйH {Xއ"dlm9FX]En#vh%ZCfؿ6{rl7JGjZ){AXLB]-ȾAo]H؝69G1yL ~ble~.6 Ŵ"ڟ!}*CҔ;?G/ݿS)e} س>>> C5f$Wl^~;J4"J.`nDC='UF*|My剔7sи]<v(3g=qԟpRS}Mү>=Q4S\-2ެ޲FbTذb{]#VC{ned+zYjR(n\e SC2N&; }朴ǦO"#hȲt r0FLJffS3?r:YO{G1ٴ:^G# \1:Gl Jf8^-tWS{5vVtgCbװ_U4r:LhӁ2o6 9]^5t1,'?ؼ h9Q0"=YB,hMNsJb߸." S9vu/.ulTF~NUJm8wԵ-Ej6FM*4BƔ(i8-4e3o@%. %r gA7̰>n`/ڊNv{ ,T4Kkm'X"N:yv$꩸j$5so,VӽM ;??/Rʼnq<I:P+kOJD){6=>pOx C4%OӃ΁ˉ>6sDp4slbk[pOT?sq0TyFaR}6䲩uک!l2>~Pk֫_Yf*ĽO=$D6v.MO$)=/w-+~ Xڂx>xA`3lדH6qm'kT"/KbL -OԑyAŽ+~λӂ V DHK߳3Ocd3t_6d{DQiCL\{WMi&4;XxIXN͙NDՁ5KůtTj}Ѻq<i)Iðt )2Ɓc@*1QW?s|l"0/  (E57mVv±B(+8;aM+EلA}pйM z,+My!fJyu>ba8lUd}4ڨJ: er(D:enn~[^=o!RaJezRcu)h !dtH2 wjڣjEܖK$4nvtߡ hHPU]-Q $ݹ*i oG<؝,4:j8Ģ .cV-x1BOasf:d]2>.]_ڄ<`4M`|[ggdLEE/U eFnqb*2t&ؖ?AfmiJ.׵ 97iñ2tx^ ֵT6%T3V m1pIcqlnh5ˌ6,$Ldo _PMH:+'fL3\?C8?)Ju.wޏ-a;-P-5Fn.,9$4-Drݿ;sX߱\}pQ4\x>B\ph(ʼUqbtl/~zKʰq=;D9<ĴPs:$&}Q-IF@f႑WG,`7:AifcR FuW| R"?lLG@{ԲMLz]G[5J:3ծLo_J9X}: W#T}GVУYeYBtFH2W֪-R'Y:Jژ2:mY*҉2߽Kk(NFUKN'2DA| O2T+xWQ_&iC`aM"]h?ʚՊKlD`}u}8HKjZ7Bx$Lpd#N_>)WU $(08kEs '¥%uy\:6uɥCtqԍ . :9}<)͒I$1aWkAvZm/7G= X }(C]4;Qjq8P.9 (y#&x!kDL*a~YcYnnZj݅ Y 8ػF 00tT$_nͯ\QV(OUNnXdXV!BCNJ /|J\Gi3gipGȲw]ri\z50NuN#ڛ3>'&< "LFjs*rTH_?GfE7k5/;Z~lӓ)E3)N; ;1k&t0Rb6ҟElnAU:%MrHUnM1!w5dc&c,RƏwiƮCu#~I֡29 61]8ؒ2E4eU`WHC,^Hwo>'$ \ݡ~d'ԮnWt)NWGgj!3C70>(.Hk=@2r|x)ǩ,c>H _7$XCfTl=^6IfN ;\#2bkp.Gzz8 '&ywcMߗ":٬1%v3]foۇ0zUe=/ΖApzŃK.}ėa)V &I:4]?w٪->c&.,^ } sq-XT UL /S~=npZ^d ^k Swy@rႠIJn:۠?d< y0Ej{3({fSDiqvG 6oDnaPhёPܿ _#3OH)`KK=Ӹo'Ϡ $ѺXT?B1=*= Eȩqв-Bur $sxrJ0/"%Ե W0bv}u3At9ů&b@i{)`ܣAJ ̑Nu8Q`E AQt31W1rP&p;-Ԏ$cy?1&m{Qm-VXoQ'LQ,Y o%+=_/ -MUFŮӅ`J_04 _ MGNXzS# Pܕ\VF S)%d|)=ueA>j/s嵋9i/uC2tW0`p%W,D%`߾Gz޲~8,.Y,ɰJpc/>L 1 _A _ CU$]>eՄ/Th 'sá6`Cdi b6/6(Tㅲef^晇ʋ13w'-82Gx\ .l 'O[s]<Թ&AȤKţ)Rj+Dq!524~@fm=j'8t{nfN?g)үFdױw̅8[[\UR:(#DIq-vojOP~Y>}6iwFI+:07(O N`f Kld+[#n4#%+6QC(2`bf*s.PDAOHm$$Xn0MZU,7'G[emg6?Jpwu]Dj(n ysZEf 霯6fAFFTO1Lg)]pw5t}R.n!~dd8~ƐZF[ cx'\i9vVի&(ȿЂ'.3:IaUru"/͎9a 3{a\Dbi/hө fxr2jˉ ,ѨHL$E^EPMPA^n|e} ]@]y\"FJx&un@c$؆I(i9n&}&]͌ߑ}sAʞW 03"-^d巡?撮vԻkWgFOTE]9^TZfT  Jc}9̝mK#$tK%`bgwgЬ&u,!z;^οmb8:b,EDŽFϱz 3GE(,*_ ׀jE?/_zzSM*9 FǮ5:r+P(qfN~ Sr\Hz=uŇٚ\0~rt/8B9gWQ`{M5=P#kpȅp f:G/2^`B簕قe#DwGǣn~ɣ3]vT:6贿+-PfWnK5}@^~ R,f~2F#yg>ΏoWQZ(ИRgCvf?!E^!AC:sX#: l# COTr!쫄<ĬGsQ,\s$wָ*tS ?4V]KT),L'LM/hs2 Pf#;xE邒lY) Se dr :˧hl j0PH75z :+'e̜l3H=ogaQC@;}/ #iC?uKX3g3oE ._2ѻ)64]\YI<s ҵVUnh"8jLz' EE@dLO+:[`l`:yQzeeqZ3!z٢ pK$I NT# !(ZrWI>R: !.ԎE<Ž2שANmɅI_:{"1K>{,[{kPxlBbջ|paiOfCٺq)c}(9 a)J8C{3!QPN l 'u=jy>.ɗ !\λAc!'OW(kF}[d7EgIWg1xqv\0Nuw߼^,}1Q:&_T!g[a1k`oWgS3mlv 9[h[8 8X:ؕ_jel:>.:e+JO uVǬmE D +6{r/T|yb` G4*hY0ӔTǓg U 4K'f*!"\ePFvO|ItD2k/ Lm#63L'W#DĆJ\8>`f0v>qcqB;HNqm g\}y &P&Ui)]:Vc,HklsïԩJ\q%5맃`jEHW1Un| Z;"v{]brF& l9PCu noέ[Y-wṿWAudCߘe$"kcfo uI;7p[RLDtw,TژiO1K;@ߞ8ׇN}=D:_\+*oa9|%>㩉J2?cK)5p'M4YzV;o-vh7kZۂa$f/$ƼjÅ ГUZ#.Jj۪۾QoK46"6ژҀ[tN"<>QUfȈρj8bqh"Ҳ6PBU1\h^˖$OJ"6, v^en DaM a%ȈiS\9۞oᐿ|ќhQ>tsBc⩫s+f,n-C& A4c޴Ys帮V['WH]DMR~ Xw4>R䮸y Чt?spj~Bj1!2ǂCnBr5,=~- ?nyauog%x^ D)mYiv:iXd왆_QGkcmxQuNq]:ڤ, 3b[k*r{{O^h߻P0fw`;=nvTf=biNR~NOx q Tq>H`o ”woAxb/3뵣o~]{>!@=u; h1z{w|!4V&"cMϗ #7 C)S~lc勇o0Y}MvuKpr˷`D4`ѓvo招" @daH"X6u)'*U3-"׿UKJUl,9̸iJUgG%`P^@Syw'ʼnPn Y]=)h l>q :}`*q؛74dP,}+Iߛh+A"+z`m6&E]..kb>?w)mt\OfI$GjStg .IEv7T̶OB@;d*KU?. ߍ5 ;?(I^bQt#*.ch4 N \+XqYԞu#ЯDⲳd〖_k_\+7㩲`Pǟn YCuM 1qgW5үМ8~*':iqb4J?Gy6S$ҖU #7$'" ~Ӷ:|򃎢ØcК"w@*x>@4l1ls"_$?)&șC )PסkkCgKѱ#n'wt5.7N8>AL&.+cGIL2hqLuK}/tׁcfgڠVJU)Q۳NA`< 2Շ'81{mZdxsp%[bČk|w;2@8%fi`-~m~sJ<@8ȵAtr|-ҳP\Y tVH8ݺB6`ۻ  4bRt+f ̜)r,7dZrRV6w1\_YG5iup/i>n!1uͥ44"W*:4Z1Ε_ dQ/׍L~D#Y<{sϓ&v>'fP}ù@pdG}E6f ?;֏)@^h+< ʢ<44ٰyi\vIK|kU~Cz:cu;4WIven063⬇x'wRwΥ\J9/@oO!Zg8POA`I^0$u3AM(h߈0clP˽KJv;_HQ>yOþ~+fDW,[7N"I^Ҋ! *`dePqRL۩rǴ˿-S4$t—btfSC|aMU9]h'dZ_fOg#`^ O>wu|1yjGv*-Rj,aq(~+x}OrAロRi/Q&+շ,ZG$ӀZT;aN4m*Tojj#pxsǽ  7f'_p?ΐ ,XMp*g>%]'αz㫙{c_lY0H̥2qXl)8edO>¥MƿXޙEEZd*HC$sHPF\hCAiU).`W[ʊWn%]v7|AN:ߞې:e-/7A~'C3"?ǍȻvE۹Wrj&&=؊S۫Z-:>NZEADIwo㥖XH,U([ S =OvLZt^D!?3,vBc;G:U%v^<HIGV %UG4uW+H]XVq{Cbz(]^3V9$L2yz#oRέ_J- M:L.ȱbOlW>ZAaSN! Ldފٙ+$흤\0IA8yO 5^E-_@;| iq |C|ȗ"Wpg oB{ELp{NZ9uvQtϴ qAA1hdǛƕLҡL7y.{.yҟԉB)_1Ats}lFr5 k!`C%7,!ػ2Գbݕ-V盰EX3ێȔD~R?uBiK]"Sa2%!0t$J.f]{N;";mאpj'3-dՈO\sRIK2r"?E3jHϟ-ΰ'Ȥa|ʜe/]ByjX.]> xO]Vn<[>J N?! GqizH#zgb>vX3^ɱ LFf)0L dž5k\0\$5!h g'1aq5'jz8(c~cL|Q\+O| _jv S+\4]N̻Y u8 MA0DF.Cs=h} /RP*d%tb*3) =dʱO~.rtD`qPӶq8=9"r@K*{IfҀEk=# |@{.B9`0ׅ6Xn*$tٞ14(\H΢3^7^-OI%"ylc5d;@O|6r~@qW׆ԪM.K"hW侍c,-hK:xosoKh{h/q?fOF 1 -R.-1RB4(g 1jhY̯X`eUz l[g!9INKVw4O3oOiZ ZZل|[tItV&QbGy@`]h0?'I2Sӓ@,ϱ3 h`Vߡ\Ec@_Jܙ"٩b˳Sas, tQqKozRJ|oNƬq6أ^98X/W MC93歾^fpe A!3#hzv?(h?dtq s?2S&eB Aуr}fAQ8b'L4 Av{s4̩$_O2.j+x{4+%@cO1P "B}%z!Zݵ޺n5tN+ykQc/c{bc8h~KݵJK_!KADL4sWԺ=x?Mڊl &2#cj0Iѳv,dsoUxs$0͇̓#زCf\9:{r?I{KI`۹we^*^(h=~.j(ߵ$c\"A1+: r>y*SL:ht~l~ex9T| tL:tbT{/hxmIPj:;ޤzE;mU0<"lliQ&B3 65& ^ =]Uk׶"7`+\Ʃ Ls1>¤UaL/`haC FQ``CD.;an=Z 9=j/4yX^ `b>H)7*, dLӮ!DLbGR Zט—VD?=;׳Q't ~Tڈ.ǜY&׃/HFhu|Xu~Q@ܰ<|)C`U+ot@ F`:C8vN#؛V)Ql_in ߯R;V.wLǁy8Ngs3ihX{$`oӳ@]*]8ሇI9Q醐{6j5Q c׿ y#JPf78}#+_Tn&i"oAo-<}IO"a70Txβhs?kИ/HȠآ7RyV'v~0ԞUAtbyykPӑi-EJWះ}aoZ> Ul>8h7խn/jR 2aC6"Je7rwFP@YhcB!h)t1(&OѵfuR׊'yهbAo~X%“5'M+9lfģ؈ J/ 4j!Bscf AOqMdQ،S*D=f7+2gJ"X>@-ʆ!{4n>s>щAM%\^z@XnyIfvKHNR"7=mJwq$D"[u//^POM 쒗tqD<ڏAۻy X-8[ _e d!.? <3_K ه A)3s|JʴZ)j?Ջˬ:rucYۻu;r)<4i*nk>HʃYN1Imp))H\܃z6$hc#/k\>M]FoKm>GtLko5mM_,hwF吹5ϵq5`CAEhBZc˚&dHS\g77% n{LxP2/Я&?G$TH>SoW2ӳ6׭ ĂWH'qľ&s?q9ز@9t^b钄EM834XAB~b{:՗"5%u- (uZ*:5ݯ*=Az +$՛K0G+ N񷗝f|Nw{Zu] j5}d` (qMl+L ѻJ8؈]*4)Â,YLؑ'ꦄ2TpM`:yWW˵ 1v, >ϐanhVDk4TwBNJSVfu70׌)[h%b)^Ϙ(o 6>DHxyjY^LKz[E6 y^ßGJ54lf3X+ީh5]ؚHp;4bWJ!@&Y= ihdp4VrNH_*Qw0-`wY 'b)ȘǍ I 9r=xL8gF!?bwJP'2 24mJs ȩ̓ːU^O&jf"\.rե>k ] DuޯpFսF~IEð@gu+Z< w-Ἶ'ߤMTuWM I3o*D/O˂elҫRdɆu"-G٢GodU,%m= 8 00(1zDۭ=E}oU;/vfEc7{D1UG" EnM=`US 9y6w2d|F*Fz[X J 6(@hDA.q"r)By5>n JjYINVLX RXrz1SUSl\l@2@t"'ڞ x%IҊ{^=X,lR@rsۅxM>{X+ b8ҍ- &]e EuIFxcՌ<#$IV|#e F>aMbʝo!|Ag$ YU!u1J1g*!j"c'9*[0m N7ȻKoZu,Eh[ԩb({Ej74sSx`FԎ @4Z(j5i~A3K4MTRS_)]OyIKZh -bQ-Y,/ƚ(u:J},@p@# ؋?tE?=a-Be>rábJr9JtXDK-#Rn/Rqv_gGa`N(I@V*&PŘғSh^Iladc]" T.g~J_tVK>Xm6iJ)4%䗾0Eq|O"Ha>R=mh\~BՄ[[[ jcYpߒ\+A]G\ GQ EG! sU BEJ09Tهv/?,E v\b%U+ 7_> $Q]ɲH :~x//'>%fJ9Ga tN\"|׈aօILH=9r\HBaF-m(QHO{55X~G}VxgoZ5| BF%lg[Ҫ(p&)8Ub.TC!)oL3̭`#_ jTt;MQп Wc$*-luTA"?`t@1yPl{ZO$i,o~U~\b#7hYK7]-^ӌFJA.Oɛ ;V[2bz⅝ף4Hx RY+RLJ{FqV $m;GZq8y `tl?MfU?g}hF"db.Wrd %\6seOyD<xz(^M V_VTdzRPyv``M#E 8ԫ;F 1 eH 5#ÖM\@*Ӹ'oj stoY-=N)kr|ՍO7W,w>S1JI\ؔFGc&P EaAl6%8 KyE- j>$^G4p9WCų )b66D!m:VEG!Z%Jᰅ5r0r="-j16)lXdM hE[U.Z`ISm?Lhĵ k AoZWK*۪$4ߨKZw`KN43ŠT +5u3SmEH"\~h'VwW0ϑe,.(GJHv4Hks7`@[.gbҋl@5g+ Ʒ-I P؂a3jUQ z|EXJ3'&پ>4Y <Ⴅ0J i^`H  *͘Q :Lث;6>ҩ[*m R$ VdJ-3y8#EI1Q lJ&CP3xb;Owt=_ b?ËN1CE:aLU- 6ZB:IUK x~b<Р e}d4mqB5xd4`jxd{Li.*oA'B/"/#!WfI]g.״#Kydrl*3/6JQ|zJ"CaA )┄8z]]$F"9_L "Tӎܙg6?X!Vmd̒z0[BX{.i!We ,oBd&[{4Ʋ_F9ƺ=0} w#H746Vx I:9V|~y~Dؓt/ HPD:@;Q5V|3i#2=ҩ=-G.NlMv3)0~3nG.{O6kϑDivs_ktpb~K8+ju›_*u8EX<Kq[Iel%xuQC1؏_9O♳pbƼ] A_@Mk0߇?Kio,U1 ,^U\=2Cݲ`p]_q܅2P"sf#avƎ&n6EbvלdA[ ݯ? zzCǸ<&n׋LZ%:O: m 0 ZOd N>﬑O1 x&Ty5sÜdס҇UWHaFTD76; "U钻-d%>L{ g-9!)U1Ce-ZjSdom*mH?,!Rd)9C[/r0:=d}mJ2ɱl>rT(-Y;f= At~~?e!/+6QbP)q:7zaT3n1 nr vm/3lo8.ҬvC8 ,+tHbKxy^'K$|˙Uq6Z*C@\ YJ'KòQ98ΐ7kV;}9LkUvl8I*y0dSR )6 ɾ>(HI*`x?RkVx9sINFqgȼ~ 'A]9;JVWcs)Dt=[ 7#(>~0KrVN:?V`ʈtufG^I(g,4_0c&izQPj:sy4ԮaXHMG7? ~60f/jDwdb]㯗Cf]oڲڔk^z!kT E'TY!t]^^ I@((0X34 ru[lDq|}/}+\%J*"}` HI#wU?$im12i o"o\ԍ{ΟT<'gcwbp=\D;B4BQr#I 5))^y6%Bb<@RTh;G"Wb qqt:biTԟ9ARB0T] Dk)wA4P+ͺLv~KIBj5Ea'fO3Fv[Tufg;顂-X7nE pUT ̒M+^5rz!7ͤѕ.Odez! @>@&Ȳ2OI KkZF֔]/8Z*t=Z6{F.3hs'EԹ<Cq㔈`M,H9^ǃ]Cӑd!5_J!>X:{~F%}3㥑M G;T$ Zd- 3~]sx1a^0޽V߻ 'E eүDkɄ8{6\t2 /x<';ޔRv2"O <Fٓfdx~=wi9X,>B[lFl`ƊZc w[A v-P4PA/:n.+|T+38 O9ll]70X_ 0 DPi*fҽ1dX'"s Vp(x=t+3`]5#]GD1)3h6 Ța ӲZ`8ZGD"w~K6OXkrRCΡԐOTZA{} fK4f.s ڟO=Nw^r>S׽hkHf+VmLnb|1xx) ##5L17(|dvkfSŚeXZ^P w;lmnj b"2xx J~j)S JcS8}0}<@DW:A3-caz{jUX uԍdkg$5C'(>]%yޠ~sؒuL5ZP-hj)1i.;n)Oȏbc`6d>Gq|K`uӀk>;~>!3C`b*}9n_)]H g/1]V3Z~4L\+d=Q`iPH71];I%D \OogEGu&jw;nFXoDQMm.4+KT&u@ I^ې+uKv⭫g5XK_#8,AKslF\әxQA|c󉖓'vf9Jtѣ+= eˍT>O+[ ,=Or2@qhB4ߕ~c9$:?w#.i?%py-۰zJ ҶHe{fh6߫z~ᵹc/8Zn#vFR Vyx;_G#$U.+`.roy?fHV`*+Z@yf=΢8AOY-K:dLYL\`9ԞÏ+'].y{#l{"8 eKl6Z0b*B fuWZ >GQ=~yJ48 PkUJ'd֋ZiW*Ђ<]`VTT! nA]?ޗn-6҈vZusK꜃vKrТzQƋ?Ɲ͇a ;̮tVng1dOM WKPKZW PK;ɥZJѯD'2[O#ޜYG\A[Q=f|[;l06fm&Pi ,/(\:Q&' < ZYz$ 2-Q^\bC,|NQav9QCZo:tJl@ >.m8`R]8MЄᘛ'7/GA@1j[ C9~LhI zULeÙxK7o zLSJG0Ćņ=AV{c! [.#en0 U*X83!B)sUΤN1IigbGrP>PC܌BqDڲx=Cq%_E_4Ó9jú~ o);!c3Iu $mW#pYR]AUYg( x"`bafC~*zBDzdgV$@<),$?sR<:̫ěQM1 UFD!ɝ\cʣ OHdzq4s!ğznqqF 7$RXS<폵$= ~9Æ+*\=4?nԸΟ8=W f-8Va{ٛz !NFݬ4usYE;[~ ^n^]=4x0xX .¨|Tk{\aiw(xDO7f{(iw٣x&6J&' բ,  9(P]Jž"SY-X-\Z'wTT1蘪}!y68FKN?\13GT\ tKóSK Y\w4r)82N'7y(Bc\'S!9a(Zĭ <Mt_~7Tp(}+Tm+Zm6+M'uqP#Zr9ns@ 톛 &M`1@]a44)H fRk}Bs$fn oT5 ^;Q VRU v`Qtv].#~Hk1Cb< a1!KTޡy6MYޗEzA0hz4c8Δ#۲7-ȚSmętӯ` Gt(Ă)G1J7TgP_%i! jD8kgrO2S_ZHوrx}H<g@ lKbA@p|c5|qV$:~!Q|0s 2t0X94Q2 :0V7M`!R߅$}sNmتpGg3vAyuqnd43 ,~@ӸвT>iVG/=;WأO>]~E@crv$ gp#{ e܏6u1x31 V60ރWKc-;،%[fd%431Nnf? EhjXGa\XxyZu A*'뺇LL%Ac^9ΛP.Men^rŝRu],[O- ̽K8Kj0I"šp`4t3C8FfkZ͑|$јeH{ o)454L2p!\ X%VHK &̫0#Î]&р{t3kajPCχc%Z: _GR6dph ?wrz3b#YiL;EĀ^jbN{ $)Nsz\{fR*EK$͇- LȋPF lIX3ͬisIX?Gx[q!a o-d%{d z~ Bp tL uvq<_:`؍3JlS^"@pV鬾?Y ۱u:3WWaJ!?!BMSD~)a{fT]gY^2 r@HlL17Ku#$&l}[xġ\W;>md2-|+zM w7cD+s-7ƥt| pUDڗ̩$#QL֍p:7۶=E 2~_ܕQuB* <11.yG;[b0*4 ; ]~iDC wliYMPKX)m=]:ލA\ƥ܊\ֵJcO,׮tu_` )"~]@[{IhAJ: .#:% v?R%bdN[3Xf2h.d\u o!zFVj㎤9^%Wcy8 {bfb^>K1T|4q"[+& +Xu>Օi,>khļ _qUʙtke=ެ⇓1AnSUZjenC' "ݖxlL}y^վ V[uh?Y$ջClJj2ðR2B<Vkq1<ٟt$D< L[PIHnw 2&umH,,,l>[eB+N@DdkI(UR1Mnx~$9ob#wtɄ)!],ԃCz #%V%GxèM9 Pis ۱j#!W_ KM6C~ iU>VBRΪ(ۚj=[х2işsi6s}zlGf6N;&ߧ2T\e(2ޝϷ"mxk#,sW1͊hï=~y߸E%הafaܰt`6^2p -_X}A jvBݡV4,%Af5WhJ9I~RBbOw*5^~O,O`BZ?0C,y%hwgL" >P#ڴQ(luijJegQ/gyRx^mhëp WvugH=7w,=>c H;>Iۥ˜adݗfBZ%tgl*N]j)a H0U=b_BA{Q2mY#ʬ%+Zt, ]R0="[9 (&o:.H2VL,a}ިk 4B|w48 :H??fޛmi7ƭwC6VPB d6gTb̩OSl0&?Rp{!@c&XѠbT'D;k[za|gkjo1KQn'RT,eLReR7&$mv@gp,Yࣰ.g;Yl-9!єp|u\pcub~HKZ0iD)6צ).qԹ +@*oa+um9Yݙc(_ڡӳ6؋]&&v{S[$2Y=c=t&'C.{@7Yb5c.5q~ɠ  7( W$n#5+R8nGƋ6h{_RVSx۪#YaXo. 9O@<?h{%tӁo8)ppYɲCW6n]m'㴏\䋍V50UJEb2rYDdƞ?%\Cۅ]E٨Z~Y^ihϻd(?vQ]s0U^K, H~o~4WPgߏbNS߰g$Qb@ ''E%U$X%'TfRoMjd~sݻƢ9xG'e*A{D9ۊ h}<0Nj-V:!,ク}UɻRkߝn}(?ޥSp,ak}aG`aL. rywD_U -D#^jb^^SZa_gHfw54 mmD<vd ?XpC{K7Eކa>̐`=ūFQ[::Ǝ/D/>|BDSLDPe]gˡlƍav1򱶤6K+JO M‰0q- s-p&0z 1%35Ϣ'FjeTgur3] )~p;uYa[e dYߤIDe%un!Tۏrѳͬ^Pdrd")˜A2xbr $?x bBrlŘk%1y>Uy P@vnSM'S'MEw蘦|@I/?f[y+i.:U{;}ur=k)#^}˹iӭoUOT@S ޙ08俇Z涄p`L94`[("J]CA$OFJ&6y'Oτ1ߴF.ͪϵ"v idh "(=q.<=럜? żY;3-svA5;˝ۃf^hۦFkѬN"%^lC/=A<71Wd!jFe}՛PY )j01PF;Jbg=Z9/pa%"Ve1$ľknfxP^|-u{HF aCY%YB^XI=HNd7Jsl(+n*B[*":s'GNM$-> b3{zsKz|-%8 %uV$HV2Er] VGt(Iyy4Q,y~vͱސCbF6fB޵$ua%^"ʞZ2߳jP+l#}GPl{e$z 3+,6A~"ʌ"Xy|hU|Ooo?~eKĩȭN?`I\_JϿ[:R,kXi/ +\䦭 K BklN/GV6I;D.M'a$DŽcoilP˾=/B; .@ jC~J܃5C,j"ABe뎽|z l0پH&] C4bMl55le&L񡎸/ "l PڈӚ[HƄ8LJ_Zo@ԔXyP&R]} '!Z m+\cW[|Tj OΠx}\_;igLC2Tߟjl$saDPw u8~iwA0,OnEzIEN 7n옛5E > -J![& ͓2 5=nuWx~ie*5iu1$@EЈf NƆBtWXOxɯ{*> ࡕ}ŖY)+YQcgI1!/l>Ϝ%쉉¸VJ#Ӥ2\&Dƃ WUy)=("1|k.3YYh\yp#BhΈE: "'ݶ_Ou6i+Y]3%g?a E[T;ɾ43IZRS®]Wq5ajNgwJ&yG*x4NsnT:,fGk-`Dk 1nnl[(6}b$LpoN*PA4A"#[Zϋh5@v?ϜdAdGPLP~k/=n!"䐅Y>G}ШN @5EaVv6ű)CbhMBwтA(k&9:_i-nlZ>JY?d.&ڻ[3[Sj@*JXtk|}Ux2+ނr7ݬ Q<".mO[̫!cTNkqwY]+.ڤp'C3 B`T4-3NpTKg̾Cv(*i!+'&ȜX0T_j&?tHTւaw1/G. YsE4_ GMXކ$k}*c <x=e0]iz:d:V]"R H u`$^Y`C xhG^e6fV%wwu˜>J?RwQ䄣&A ,3JY op~]@!|՗F78\W6*B7XWU=7e15|:9Ax"CzČvz~WZd[9.0r[󂅆vtLHOץ܂%ٙouL =c NHt|C|+PLA 2H+&icTXlY1(5q%L5TI '1PP | ?e^>ioM]7ŌE9LGn$ +Q[;?Vnb1_d?6Fg}IdaȨ63BI5RSqǁSRku8u0';e3rI#*pFQeNR2=U0"Jv'7GZb3:w/F/GODs!VTLǶ_'Vg'T-]tHEB4w^w7J9![5/+FBw<4H^Μm>n$@6ZRRS@愵{z: PЦ -lZ@8=C1CڇTsDp (ZJֶv}4&\TPNF$?bg/D{|9MEӊP Tm*yS5_)_>?*xs]}̿8uH[j-ȁ jGP~o%fCH?q'-Y.vlgˢIl1#k>+}C[whS>ȠPbe3;By^IЎqYwzt #ɀF;ؾy '8;G\2/HtpBb[V)[ pfA4ZoO&Ť[srz*ŠwR_ݞE$вX{[ RϫE6PՁL{l$'x:`& E*}H{]68'سH[[W݀Y'ZysP03y)8ݎs PG--*JEwm@tc vE6DfBhrf/#GFr|f ~3B0) w,*s[؏Q{rG~kLĊpCOnagDx!_12e@&8IsZ]gGlXnw IJA2íROۋ1h,Bnx`(NϏ@"w[39S':C}ЍLl/2ZW"BBM+&TӤPzDj9jX 8] `[d`o:|.w Pr QO_&*gj; IU kfxNR\閹 WNf[rr9SZL=jPWoX(<84ea"kzWE lekH) };|R8iw\m}2 Ԯ&՟!4.t 6;\X\NmyrSNCbm8t@-@F{wBԔRNuJrc1QC O01yzB~\|%⏐AIyq}2*͚( Obo6Wpˉ}|JvgG_:YY *z*P"܎Tť>*||~X&+OC1&_@\sxoΠqGZJn[pG8OnImSBi}Z[\orӚ<_D<kxO)Cʚ_!)G μqcJԬ13Ig}Ew2dBB0#OH!ʬƒ{kHA6;^"7#?9Oz8ȻO\Ej%j*Pgοfy[dLE2Tl61;lc6<.ٷT(Xk,oaLzV&A@$t|挳yޝK"h,$sVj+AA:Nzx5x#IO}]P{D[urݵk O;廰K`Ƶ?R$Pf)oi/W`]:?!@4xZzС~ύk}(V[g(#g7 4O Ĕ{٬tDa?uoށSAQL^ƙH?> i0`wD}N~&ՇH(,3dVw1mVbD ?id:[qWs@BS22ڬ$kl(('S!@jJ*ns| %q}r.0U4=S!}fa-|s`Isݗ fJCUSCԮ2"aԂEDYv2]t(+$l#P !|tH\o9٬Y At=L+.jǐ33ε(GqK"ٯH"ХjnQuZ<ۊ,9&U)ڋkЩ1]YX#H;cZYk~< \6hK:~3C7s]w^m^MnxJa˴zPъI@x!6v6-B4'XM.ܲ'BJ8p Յ́L2Y S0w4ݨ]--Raiɲbӣil_ܝ £i,q\x$u`l[eE)?݅lDR'YEa6B {tO48WmXUōƠƣ='?hHr~B|8|y+5Iywkx~qBN+UVj=Aaozc ( 3J\NAH\4u2y=ޅA%) PDKn-ч+̽S[-GO%;_V(#QeU)^QI8 gH1rG6K2SaO x&^7*!ɸNlq(|-S:0'⥼O8ձZ?[/Sfʽ<[.>H{EaKe2eui?¢qs!ȐSa=Ie ţx>XsCrN ]-*G^sBy4 Y<mΣJa@h6qh pܱ+sL$y"ّ$#"z#$Ǔo[lclSK땓 A"J] 庣Zh9CԵԗSePyLZ,>+k(o8t6F9fI"3ŀL2f㵎QLhC[W?P70PHRXx8pVC'?D#z_`A>ABqحLyHYUm!&G> +וؒE 㡥/vѲ:eQi2Q!BjB~zL\ USyF ӈn1DqP9(XQ2Q4&+ ,nLNQU//ô+$@cv'}hΔ}G%P0~,Rn]Iiy $z$C,FZ% |bi*cXD.voPVCD/mޜ;ķC.ckܲ8N *Bl&"=] `.k)?'s)5+z$])OT4vNq(p**DEx GIX;L-"|:y'A D羽.Ę Oe2*-9UMq>dZT_ho=m-dkcgGiu@2wg:Fq Crw;x8ONJ+<@u>zPMGXJgqN[o7_!pW'bgzZ}7Z4pjP:΅ryu:kޙ` U(^ g)vzф"p~ !ATV7z\! ~ Q#ӂ l .DVRE#mf :N 2fq㩳W 3m,w A=u,ϷjAzoxm_TW]R]"1@`" ,;/7?_߿[m3 Ð܌l(˲sd!k`a03~d<0yE ui:]՞%&f e2rM!OςYPԋ$Ǘ`2ý-aM̓V%(6pP2Q 7c{_ٜ Du=zyy*uLrv(@1^x=,K^GG;GitQE_s95$|͋d(4 \CP0xC̅HD ږ\qI!̇@$SoGG>Ay(fGqY3=&wcj(y$>NnM(#Sb~ăVP Z@"M bxx Iic҆we6va?L ҘG? '$Ii(5Zwg !r>]]]Q5v6C#ouܝN;΄ mS/u_@ϱڤƗAQbx1L sJ2Kw9Wj7hTsC~G&pFz O Hq Tyc񽦑Ƅ-\껎swi" ͲT@SWǶnW*t/<$L\ iM6[xjr! 43oëFϾFi6jrR[rZ>Wpj<#Uӂ6+#F6]vxKZn9qr5-MAQR.i~49M= KFz䃶&XU')N l6u -W!I Siؔ-Q?o=P*C+ kekYFQ 5 >oֻjwMrS]ė?sn*.'Nv/܁ԭd܋R^ w䓠#`5k[إ㱼 SV' i~c5=S2(7d8؇?z$=l=6aE/$o Ez@S.GT:<ݶnX*;Sr A1?NˮmfR@x=@$'MHp·:p@4l~]˅ݦj>0P=ؕn*`5vgE\JIn5L^d_@T*oUY157P; )0;JbNȍQw${:؂$k'~7v\dJ5AhK>q#sc:<~H3fkiZ Z+$pu'_Ϻ! (&"kBzV>M7Η66z]If%^w&n(5iU-;iw1~E-w (]N^yPΦ8`Ni}ߛ|!mfb3+Z;+s) :_!47N3@dZh)\)`aʢ jL!YA+<8ݗ9Q909by^'(֜5pgFɳ2Z7?k)C{#?pwLr TӤH]y_7S=%Q(sm\D>nK2f)o-_טh8_!#y*go/UU}䬔U=Dak1rK{l[/9n f7($q%00V0nC.>8w d0k7WӖh增k;ކzp'>  Yd_+~ ѺD;-8adI.Kw.j-_:݁ uZ=HrnT&Rv\$hE#&h9|㓌Vӓޅ. |j%dPdgSv0%Kd. Ml)@)m6l6-%X5p|hžQmBS u֓[f~᱀w_yx8/\S`șX zalZ\Nt(}㸄Q۷b}z, y¤Ÿ;_-QAp`sڞ7'B'Ŏh@hC녡*p\ԺNb&O`C)ܷ[Ma2\I|[) VfIIW.V;v*ۉ>]&ø,/_@CܕbraJpJwUoDy U= xȘ$ ̑("D S!`/>ʚOKx[k ]=ymr ]}&!F]:͇+QL_R#(Qs'/YZE"͙s*%Mw&VEWs?`?IvZ[*-H&{iS0A^{r*oal*0~/21ɀ_tA|&Q2S݊$#Op=a P9`ո184¯<| &OYo?W<_^{B̻u,(BԗEnP B{ p #ZZԿn^ܼ~ydG JxM1ņzDsmQew!rGIpv~cqQz;%WS {N9!5?1"Ovs;mV9Ɗ %@p\M稄yϡkW_摕*4Y@ɟ%sW uny]ejm|>co|5 3VU IaFe]k vc+L"e7o㕣/h7ϫ/6Cx-FY08yّ9W>6phfdno~iRVFGB ?/ OcT.CCS0͏H /;pd-[|LEKWYL1X-;e1;lq'stp*wL֎ j TQ ,ou"]Zzn_tF̫)_G$r+[ݤ1{[O51߳'+5 p'N >Ylad(pևoex~IJ4EN&yD;6.+_TW$]XmFyb9.183sJr#A 7ْ=s;[MW2E9eɈ+5I+`v'} y MvWP1vSof%m W䦁Z +VN8v1%o0u$v;@|Tp K6AqԹyJHx#NLjFÙ3d2v:̴w?:ˣz0w!CTJ!i㡒 ru}K@+5hN)+Ւ/M8`#K4 UjZK)2Cpa9ɞž``MnvMsH6s?R񂐉 O9E}+q&r7kVHy+w'cQO`]XirCzЋg) J03B5|xFXYƾ* )W[oypܫ|RE5#ᩬ'0 Y(WB<"z|@[q#$zJd 9/ǭ(T_ m@bDIOqlX>@#!^df%hyW5s׽Yy I Pxk|ԡQqp~Ij8"vVtʃ+g+}kwI  dߨ&JL7:R~{,*7vZg*DUՊ\( ݓΥiu;K!K7]W?\e,rGZ` [^W`ǚ(\KthB6fr]5;Jr~B}6e\S׵+z:- W>Pƍ).͢ x a͠?N eE 57Iκ.jx. [paO86 CZ_woQ]$\Gt63$: 2 淣=Ai$bKM/ex+>!eW9GCY@qN .Xi + Cϧ"A05 Y{ @jox/e%Z)k9jv1m!珌Jɞ$T1bb?۾׼JO"W%J}aKΔ]uUMypУ ht`t^/$-[̋ 6U9axX_i= lćp )%FpٗGmgX7PQqh\޳{tg*dݛp-83 G]{v┼cT)_`,>dbX iEjN&P J .` Iא7󖿉)~yh>6~sN`\XSpٝao?'`h:-q6e6 yCQDߊ$m#$yI;șjz3Xgh(abY_FJ{5ёc/L$RYG*X}`'5sPw~\oR90Eʨʗ8pi1oD @ȸW꣄! C̀RΊtU6*wT(r58z DY.AS\E;3\l HVv<N8۔(t,qVA*V8+đ-? ~}_n6,o1.TG-VRX-ݵ`lrGBFCXT߭sޯkZ7m.8]G?n% B's_n)c◀Ę-} ^qV%#,Թ҅ɛ nw߀u}p{Y )X S:K^@:!Fn^![aч͑#C5iQ`sB_ӫxQͻ o>N/e@S.v~W3FwmBGmCD;_ 4y0|Ji9"Yq~u?܅ < R QK6?;"oI #&/s[9TGG$*r@q$ o˯>=J+yoA.:6l4KXЂN;-*I;4Ϝ+Ւ|dd7\w}4VF5cu&]hmT* ZAˀaWlr qk}:~K.'4袑I}54 9ȭI=Šh`7oƮɌu6u®N.5>'HQr1M'.h VPGm^yofl3ϑIeEĘ|]n>e{YnTE>z\Z<ۅ-Ylk׾6Ԓt(x˝ۛ %4SIa}qSp &H=[ڬ9e51,{04 Z$?&93rk{OS+l9v瞑D-V/H~cZ4WmX!Y{o8QJ_Ur$H U`BEcV)-#V0Ghޓ.ˣY1nTG0׶H-M4jƠ^A Gd28+e㭹ϘuyS^h{qٓi2Chؙw_BOs17DS chXb#,r]Qt_VOEPʶݘQ`Z)4uHJXFK7NB&|Z[KJ)KݥQ)A@XN;Ҋ6Q& miPeq bmFr8@s0UN2_V>_SM4"Ey3$Eiw(de\Nc̊WL>$C+<"Q.brQ% 5&hѧ*F7#(1#R,R=~[&X 32}X8OmSHS[@z>HڴF? 8u)+Րe^=xMR-L%jPǭ,2Je>f>3 j$u ;R橭D1 )@,T Q+y&R'x 5JeB%D8CZτ͙NH*o2̤Ikg9ҿ;FJ4 sAY7E.-ǙݏeMFLŸ =j)%ہ~}TUU|֭XL۶_Pr@b.o+4>rVÎV3N,XZZ ՜ MtB"R\P٥$v38R\&h9)E0rCV)y. {l<|Hq=GgT5 x&Kb؎1,mHu.ƁZN_27Hc1EM̰ ]-uNY^qNyގ@0L>:eŖ&ѲUs5쇲n{ v: weh< 0KXGt :R>wy極\gQS()eo{^qc'7xl=3Z ;NOQ"KF) c GO泣/({%GX;+ }/(P[&m=>N|OUS@F\*Z;70"U:0~( 9# >Iʙކ\Du `Ia"!h ?M[9^P34q\L|î&JIo[֚@iľA:CyЩ :(c65+yxrbbv]~ 6|W^,A~w xM9F tK؀FcjZEp$z8957!t&f 4=_PZK'h ,ge#y<׋ j؛=!"ӽBBr\fM S7a)#oOǂ8=)tۖsŋ0Գk \oR";az/rf`CWs'JD~i$'qB\@2w ,0R/: R1)ǥjpbt~GI7 _^rڳ3ޒV΋OFx%N=<ѱhw:D! Qo"7*Pni4BT?)2qdRLT/J0BvEOi*΁bbkPa/;%AqV&7ox | $E+$99vK f0d&UZ.VHoR3,BesxhOd093;CX^ysLfy:lou璞| H G;s%|]KBQ`+y}gSZH*Etxb>.$$!yՄWliUf1y|T8] xZ1c+H뵞)¿ѤFBijýk!cr-jԻVS"S_x_T!'qc $JŤɪ)@0R"e,k:dSkؼ ^`5sI;;?M6x r߱uW)6rӡ ٌ@E!tGpQW!9&e%[\kJPz/0Pk]һh; ѭ~2U"p=yLі;d]3n0Mc "@ΗU~w)Eй {nh~}FLjWp~X3>G$bhXIcJ2\{t;~(GU.XbLC^#vuL`ͻ&&v~SK51T4.oЏp"z9Z»iQǪ/oLR;SSMd-Lq[o7'*PRe)PHG8F!B<(jJhf@D1;@5밓)TdQ Hhi9c &HɯԿ/]>.+a%n0{[N#WzCeN"M̐k .|/- wQh C9$7ᇽeP~w o'DC;Krs 獀C]!Z+jwo2pіGX+(@k)#ȨU^>M?mQG3KCAeN_Z[+hHS|LiWR7\]kn C _ŧx]^NpO-8?4{}>aYrڠHBD0rDl[EsḴdbzڬvFRbaqlFlOB1x`yju ^nBxcW'G;Lezg#Sȕpå<طx d8U;B󁍪4 ||mL$/π"ͩ7SֲrFpaͳz(mP]]&M-#sk5hJG3ɛ%fQ0ᷲbp?9z1|1ҵlj|4n%J9q>AS1,"PߊReAKd+)bƃ]b+n m?ׂ Mck G0?L0&W#е*7g)N3#qI@B'ۭX>_4ڍRˑwvy"9K?K)Q"P 3nB/f Ĥ'_boa!<7 nҘ-xwF^A\w֘f{M|]I#2ަ|/H[k_#>$Li>9=Q:9?7هpiPSa9bQנl5 ~=lis-,>•u4mB1)*(0drm]7R0  8_4`Jt)Z/̩h'ܨ'd_*B6.[&| :a}8uP}ہ@zk x~ƣm A}np\^o5byDE i%,'հ]D+&(etU>,|TI>G dX᯳&|4<+I-u\6o2ߣBdx~appu꾙0W@USV&b+QBe'[~ H9iŅrtg]9ŢĽfޑ[|MuQK݅vQ3N'jzKmRn-k1 ЬPS4"k3jL\b7K}1Y><Ľ" zN ߄8={0g9QX-Y $63LeVIi6MU3" 3N[\lakl@Z@,OlV>Z@'H_W/ܽT hP'{[./YV?lEfi5~n"˿C!gE"]j=jt+fi/*22(w o?L ?4n<qkWt ݽ*mXƜtסּDN0c5o,Jx%Ŭj gEjb@99I-<RzN3/,Zu-xoqF\L)~pnB5F$mU8/*jI\K6nhI .wR2mܶU&~w*nIh-9m1(Mj䄐8a=kvA R}Qk*#zUfi@y!=Cs^ϸ_POD/O+&^7E1}+qnZel2%Q(γ>@6'_Nw!UU,KB6PsLz: @++g)}4㔖 ϗhvDefD/SI HfNUyT> -Z7.w[!Ȩh+ {ת!7D֎P3.4Ï[rae.x\zxxhA p1)m/Gs|ȇ-вV_LibJRU˺WviH)LP=7|7 e JycMEIF40w6R'P߇%}tM;l}L$.tOuecU?^|w*Z 6{ _9$BsmiʄHL65IW8(klv;ew5pZwL],n&Lm: s0L5"!$'Hn]0AI(:|` RBPgQ^R?gKPHDҾx2C 59J LY0'y tVH:p3BD8X<3q3ɱ%4W~RiwȘm0<rR:qm_w_(SP!T~ Uӓ밎(09bNЮ /e /װs6m*{*,E grꘝ8c&V u辞6/sYމi3;簥~EG#!xr9j˅j j78wjVn'`)k<{LW`ol(b.z 2sj7E š1`7/v2gV?%ܣx/wy l Ǖ95M?:md^%k@Ç&RҰ/]*c{L!&TxgRBZwje^eL݊~,]V {L;f:Jp A`|x[ittkhq AbMnFd4B#  SZ[fSHD[lcHe.'W7uOy.-R9*r.VEElpGez@䳣bۇfbJ#%'&êH[Օ9P1J\C e~%0;1dP>!Wj3%Tx^^ 5^/_yޤ'ҼjCzPlW-W*Uqn5VDJ,fnfsszDx[2g"a79G4eA-GQm{}w!CEo=ɹbɦ[pu%e)YӃNY/#mQۼ*] Vz«@N@GjV2"BoƜC9ܸ U`kcbgӬ.J.aάd4OP[#m9y ђ8 Z٥?_ :'_05O}m2Y>)5ZJ:C!vr:^"/ v?hV-i*n'-tLNX"8AF?WO/z&(쩎z lk&2L\I$6Q*_MmjP,]`7Idc.ɎdseA _~W\WߺN}XBwt2.OeM9uԝKnq7,LWNr9Xإۛv/k3$lĶ<!ɅT-s|ULk5t8뭜? ?ֱ=%59S`Hʄ|+f I|DbD:T[.aLDŽad'P[:vDS.ݽc8 q:(<[jJ=S ?BlXj&"]ps+ d09|q #K* ~3 9F}0'J(MFD2\q:k10֦)3Q5_LA!C"c\O'nޜO??Z  G#軉]y2~ҫ[p]6drM[;Ri:P@(=ʛ+[.ECKSK a=n щC >m7ݭ@b$XH/xǘV]SGՊ|"gaPI(SrׇP׼Z(Qs &">N`\a.' @72p1=ё yyOSAk#Ll"~L+ް?M;^xI@*'D)"Q(](}BM2ظpds^ ~8cQ!)Qp%Я4Iz (Sef,aVj3cS*ۜLF:uPRЙ*c= C PiFԃqpYuS_%5>=0;!ܽ*9_ZBxbiέ!39s~c4ޱ}X$P̾؝@( ewb5$?k&eN RZ_pG/5o9s# a\`o_"u߰'ǫ"3jV>6ΈnH.3܏p9Iqj&jOK+",mWU= eF}Um  v^\FQ.z'*w-N.lOSQBC}JS#'"? UrS%V$[Kp ElB^]G5)X F~Xo~h w|珫(͟4gO/f]DU+ E]J_Ս` j@CH ֚UjHN,5;S d,joYSD/ 'RB$X`cJYƖW_(Rv#=s.ha$^ܡjDnq>UnD+GautRR.yQQ@6~4&-nabP$$>e~N_""\m3^zJ1ގ$6xv@Tɞte&޶e:6#?J(oM(XwFPb?Q.+KD yxBa"ԥ ;0 pCHX%6-J3&MM:jy6.?`hz~[˖Eh S W9ohIu8|kvMB% %kF'7tڽX8zg ӇbMeΠ cMQXV0mGlG ?@^ʚC(!W^6J{siZՆA?v&S&݌U%ILkp\KJ \9Ӛ~S >Y~"#>(4we5DTUivq4$16rA.{Z ?ڵ*~|6ZI{zLs=/<\znFj%O2+SpzwNe 8XisůWb!2\,AsơD{i$o莏~F4ԓ4#7ǴqrƵEljϬ6(u x0(7Sl` 3in"YJ3NDč&Z鹊_Q_}w[,OsI\Pho{2a0&Ė^6}' rdS 7~eA?0q"oR?=@fwD[aA禥h3HdrX`|&7hh;i}s@:MeMzQW{x/4USʾ2< bv`0C)SQJ=[ ?ъ oN yd6wN 2G2& />dU@WFQv'LkUjoCjnbOLIzv?t1^۔Bv޾5< T؇{Eи.0d3my)FښY-+ |!~DHv`Foe}V>mKOÕoƚ+m"`-O]LEMR Sae9ނY ڒXW -3Es>|JިB#=TG~ؼ@ БSk|<[Ӓu?P'!\+;`GJ Q'tg:t78g @7, P ! zΗmVA$u =r!#%_%'̈́IS\/ W6$7뚤͡(셚bYy|sqy7>i(; x $ֿhn\ a" Q铓'K.BYa7Jf ո>w-fl]T}\\Y<%'!:{Z3cZɗi2R ֨0_BVq@DZ>Ho2Q\x񱿕\&)vnh(H*!A OJK `xDO'RԳ6\34\T&ʲ#9+Jiȟzm0$&~(s5S{ǦШWS/ugK] HP3&= oAΏc"q޴ez! $ 2JT@gmlĤ8T' >&\E$fC(Aa#@ࡧ dl e,#'nL^T}N-v+ 89̧KDnE^:lwAЃ˱opuz *dsb:Yq30uUY/0CVimԞ'hE%U _L_ea:ލE O,)J/5 RGb -9Sϯp">Km+G>V)V% JLm@9dJ[jIl$<{'3OT{OFzYrwy['Ʌe9C{Cis])_L'tޟDB{Ԛb,w썯&qǗ" N$"fD@; 7袥@G - (عraVC% 8,~5{B9M\'>Ws_׸`5.p٣xS4Rj'b]SiJ?`n㨲ߏW.&: ȏkGoYuws1ƩOf[ S;Lݳz;k)(3pBvТ(w;B2@9ހbۆ-$/ poׯť4O}<ڎЏi P=8HWe <}ߎ=K 9N, > ʋe$3ɝ3d([w دéDVKC,x\^B`_58(9A6_YzfR!뵭B U-LM &5 tZ RJ}'ZN͖!Ƌ~,< OX@;4ZV:2L)͑[R!W$蕟Oaf\L^Ga}ViC <Ӟ3Ðeb}^ ob|9kn.@n -VXp|g01:uElCo!K-~=gnXhL V"}eD>†P!P[Hގܬ f!ޝ8rR4֭Qwg|fu!mcn;k sW,a ,SCӤgv o&+Z zabϒ?]¯_hvv:$ku@;yزKdKSirl)5=Mb3'"]HPQ9#:I7#&%Hr!mŎ LB-XE^͝lz[״,#̃m u/wpe.GկړВ5F?d'[,\*-;):-&@ h$28Tډl8=s%Xs$fs@dT"C[ 5s#n;=I"\unQ#H5_50jJP1,FqS?++:(.QYQ5Gi֜)GU~ AIK Sb{0p1^6)UhBO)/ȅ:mHTN;__fbh]npAk6z2\lݬL!|ߪfAq&;GGlp*"H}JeV$XSnSs "פI@Auex }3e,y(Vx: Wb^ X>GV"OYoҢ=7=dF٬[5/{m 3$,ӻCUQ#U/4kD;eюns[Yxt3'Iyɨ Gm-0- 6`>2i'7K1쟑R0׍x $AƛA{e,0p0+pT@G1Z'`?=l a3=a & x@3ޞ:457>c Vt[ Oۃ $ x^ ƲærZ681C(>1z0Ic.4P;@ztӑBc0FJHݧSD(F|U;ZÙ댗w*'-w xL.R/ &Џ=+ǽz}$6(;dg-Q6tVdU#s2 خGD)µwW)5ss5z{D r OaJ4@pWmaՇjs}~0}ZTǥ4Awҡ1·&(3*[}:"5+Xμxpum`9TXOs_^p'R|\_w ܀zW@{G 7 h&0< XA(ugN-f%u^ElP B퀿\o ͱتȵ#]Ka1[_53~tӭdD\$jDD|Ouu_m6^Y@Jy/[%˯.:*cQ&w+h9wjr 9"rAf:TJkpo `[v{ȳq/ {ˉDO/,l^C}yp<.hJʗ-YW\gW RdEߢ!8յ-D Amt]g\L5)!#$R l]#%`ذQnv0G~9cl$y%EwW.hLb4]4GΕQC7V B~zu#`OaR"Z!TKAXAio8㱗n.O>* o0Ț*4 G9bJON+f֟T'^sux`߰A`UҎv!+EXkF& hV"4 k =ϮXwJipT[B 6aϧV aoo,{[3Ohӌ+a'MJm&K/֏}4`Y5ٓPh2V[Gާ!di,]z ir[ in2kpܯg7S"!eVt>صc2 h< A SaKs(PUǑO_iJi+ ؍6 {XӐb9$Ti.inNZ0۩th6:w>YJnkBG‘LIwT3h}-a >=f`g9XѤXr z4b+MGٰ_G +2Rڪ0ɠH8s21)b!}\2`uX|:S0Ji8T8/>/$x .gK&N/1UpKaE-&c Q%bL;z7+v0E%%H)/:1K ]ܤzF;~4Nu^boq޵0"207Q!7~Ns;;8keWZM4w3D*ÂCwχ 0lƊDyz[ ]T$A䬨+ʜnl L(#7/Ő迺m y1H{7+ $Glm+)2uX <St Њ9=?2ҹ\T€.2ڿ!\iSmR~+W*$օ+(0<ʑrVHdM {B%2rn):8 ev+:Z1qTg"t['ӆS8}k}jN͘V# @(I(` Mv^zkNBKʋ˓7kNU?'JLOQQ_1'zczQ :IH xȑźISgl?ε\MTM~W̰"=`bdkІ/3)<mf~<אogldAݺr85 #μX$F C/Y'iI}EZ+̥qҒ\u' &3㦙ѸRDTt$ƽTy,03&A-gۛ#̒h`JxB׊ Xn`~)T Q܎1$P6b>pHb0y @8 fE,{YZv4VhH8GB\Z"Ɣ7ƛo."5,m gOJd"p[Jc̑-NB}7Ӿ'D!عW͍P֓-?u6_S6v;ex^J a*_Z wnhn$3jORK&Υ%ڶx$~,jŽ`|^*_Zk>vŭZ'8V8bm:h%#ܒU<`T!xSW,I7M^=7gO* !CA]JD @Rw!C 5܋ո>F5b~Q,@6] ~X "6zvJPAW?O bY2T47_sZ z.Z[,ގf_pG9]1j’Dy>zhj^$^.{o.4 Io'߇l,Gƪ1zg0VV{׺BH0ܰzQ(# ֧Whl?~BsZ9)Ick fs@Ȓ(qBcXQ6A>i@-# $P}I'Pz=e ˾"#sv4HK%'s&k}xSR zחZk&0,G#v)r _ARRY*.Zwd@\AA';l {뽌5GX"yMUBs0 D/ئ`yHv>4߇z?233QjݣsWE; bJS}.պ~'$"d`+R% ƴk80!ni+YPi7lxApcɪ/v3[LZϵsf{Ī2<͖u^q4A5<Y~]8KknYQT%OG.g8ߵFwŶ02jb0{O5gg#)bDX6`-v'I:rBN'!-ht.ufL[N)Z}|R(svcޮ?@?O`)@Ud?lCzcJld()[bYEH:CI>Ɖ5q_9di C\B}N;G[~r: )zW}H][l|etK}NH}U5ٹ"+7I)4s˔1dH̸5qq))uu(TsTP!a)C@u^Lgc?,iTd9x(Ѽkf,m)z8(%Hxw󍉡IG@8eM%x̉%yJ:[`}gr( A`p[yA|i%P؝< C꫅?7!=}AR/R SY5P-psBh( hAy]dEt ?vbn h&kHEm)o,R_bFs랯tsnZex.p*1C guX09,Ö9xP+~!A;;,zM؉< dHK%1%lUc&d0 `n,,w:xcmOF9^QUl˻Ԅ ="m\k}/TXUt]$T;םWvOAGVI=qͱaMp;r/RNDEUҖ 9Z~LѕuF @Q =6"`z-еbOg!UI{t>E0Sǥ(r~UЁ<1u!{IB>^ -H @h`H~i5r,jyx tOf xqYA"~|$jaWs09Ի'%]*QT#ãhF '.vDvNLyOW]AsR91P8ָ2 P&$|v * .^Yu@O^)iOy 66h9׭凢ؼ x 'sٽ@oOr,(n9H,}2uq{p`M;9J(5+rp/&|akg]:qM70Ѥ5PykauM#ft?3jg@ fWCvcR؃q;#R*4CDg2c?V[OT{y4KsW]J|iYjy3 yHsos\ "9+2k %/jC'kU~ Gd*vU3US?hK[LCMYjObq^DjBn $OYR^5 j.&i4F5 v _>jp{m9:\M.#PǎmGΓg`{-2˛/&BL9fj=@n!ޙ\+ #J!_|LCGJckV!!# 62OfBpԬjs#Ķ&y+]-ƀ:8N$huЉ8H 75%Gc&ڬz+g=V鈴U %tԳ'$D #n@:kZgS}T.ޝ-phhgVV>3gV(x}b ' - |,k NJ=7Y)e*`yF֠nѺWj{Y+^M?AUNYyd. e-`[F=۾/K~2čO 1,)R$~vy n:"z^rnZeSڮuX4.z Lw83edZq.*b?ɃB3ϗ%S O.?5oSoԵ|h[3J ~L%ԋ#hk/E 5 RWq,MU/|ٞD:>HMۖ2>,sW)?cUhs'(xA g)?F:_32N83kRr1m)PM{Ҵ&CaVrE<,Q&".3'?ALP\mC!b a&~)cx xk>:u71ķ7Y#~jI?lq1(Zq[%//gf1 y*t9 \} AяhڕVQGnп_T8a7 Yd::fd?lM}E4ܺV/ 'tiD_ØN(i˒zO}( l\ ˼\F >4Gu fy%|⏐8FM>^_k~tD1FNnzUvwF C9 <.(). q7 VAͨߖ7]$gS 2M ڬ|fXm4&'v{K%x{ӱ 9kK)^㜵X^PzAZӢJ/l}j@qdᆪD=} o:;{4[. e9;,UKQs gLүf80Fڪ!r<r|wI6e,Ade._g^w"_hdț$}=HWҐaZ˻DPIXAnpgb!NT q16"koWv`@؆C4cŨvr2꬀7[IGdH,|^+cIe.,/N+jqAH&_u^ze Smˉ5@7d(Pǽ`}diRAGNx C@,w Q]41M$Ƌ#nC&S.t Ց\ߡi$LxZ<٬Q1Zߴ7 HNRBxcyLVtؘ3>0q T]s'zq$6 XKX5u? "bqdW8DӽgULBm?_h3}AFN ]ԯ}uYhn1܋IUEbDr+k\^XxW+a`t߂ )G+ xENåNўKrrW| SZag\6n[%Y h-פtmשP6=1],D#B k,4MA9 4ܮl璸bOr&m+|1'w nrl(U#೰cڻ[/iˢdX6֝ 6/]0łE= %h057iƙz 9pY8nQˋ:RK*&( ߨ*]j[ Ufn f_+Cױe\JP$΢W塞{pv׬>z,}M7Oٍ2esEPbMrM͎+!iGٔ B_پfwR}D)sj,CVQq.+cӜ) w~f>N JFE} ZnɦyC]imFuU#||*!W_ҪU) w9U|vGx's#f4^28m~5?ɆG䃅 gtxztF6u.fqC#Mmg}l%&şo>1r9 :F?ܳw J@Y_^JpbE> :rC;w4aп OwC[6o:BF %oqa͸(&'c_pF1RWY1ldC<`7[& omeW10c\܀%-,u93%|k~_t`v=4&$Nj9MQ|lzVMg=Xv\鷸T^q[mQ,t+I۝Sgg|l^/KIvA&o'I5eD>-~~ `Ӫ4hq??jLH/Ed}uOS /ㅍ8׋oe3#[C,]=Q8-@ 30pGbd< 'Dl߽x Z0WuxLHJϾ#({G4 41asXfηd%fT=*,ݒ3U=yK koe6 Gg q'621S5R9mtIkR<ĕl6EIET@^۠iv@ Жc͞+߽YNQHp9;N: Jr7+%ݾǡeF[JC b._8M !|=F&ɠFstLۗu;x,x ܇O|:\@ZR_p!I.@Hѹ*X@Biz> "(w 3@긴h5߀SGㅸ7TuP+H<6FˆuI{6D{Zp ڇ91mKoyfs.mk@@ &սg-3F. f3} PYpuxCRס.dVT,-E1`]Wt7S~ @'.!Tf}s{eԵԮ_Z#Ք5j"2ϳ.&ArcPB6C:,$D@1Gygr4{srp.50[u^.]^a) `#%m(*$|G_{< 6(07Ѻ[_o9sU*QߏsF.7+9k.NCܮ|>KP">x 4{$-;tCURgIޟ=]3]T^0 !"ѯÈzemlVV 0T`0Ӯd䇃Z۽UNDm5ppИC*OXN > bNMBX;qHܭ IMnۛJm2fmjJ׳:X<eƽ5Nþ֬"ywz Hlm;q$M\ɞ`Ge9\9oAsONK_R6Ǥ4 @up!!ҳh-#6\ PKOr?Gu̓t}t wܺ@n>[H#OXS? ]PjW )"37"U9 x/Xbfc@ @IeHmtziQw"!EEchTGrŒe!]9!4[0Hӭ^L|Id0|ІFd #v_.;9ƬH @p 7vE9N %n;IC_ju\t;: N+DQjXEʆN2(oщ¾W~'d P/5 Ё'(yI_zAQ&ssBOf"d,s8[-r'Sv.2(}Xp/4gܡo*i 3CݻɠU5Htnf;%z%Ih3̷z R'I0e~60SQ,:X35G0:Af`IF]d_lde߷M,SIKc42߸B/;>˂ t "sdEO]Jɩz?ێr.?r h1(rpdn?䴪2T=Tu"]W$d][> z/a[>"a=`/bT#x76AS?x_[O,E.._ otpL>7RxzޘZ\8@7z'T6]i YR.5<3,D?'Z$HMxtGv|ZJ ]I#~wvtd[ԊeK(Nf c !Zt*q]Kt*un7_Q!cH/XSn٨[pI] hid0;e.)ޕl{(a-"LDKGY"{Uo8dntNK](jcD,n#JB)֒o,! hXMaA1k皸ӛA~XE\.O 8Bvxl m<"3p?̔+(}\}܄[ y Vhh.E*p*x34N}}N_L TH%-wHlY*PJ4R>✅~0[yz]qUg> Wfy61&Ÿ1_ls";~m O]`pdTq}Iv grn'9GJޜU}rJ, }='ƙk&*X)}qu"c(ue&Z A!Wq2@\:K|8[v}u~A%%RQPʪ{ʾ\dVyi(ZIn$q^M*O[y.Zs?-+9J`N|Fԍ2JwJr8_gZՑM,Epc>ٝ܇#j=}(ziEYK(gDGʒ:e7rfm~1gr O ^'ɹ?znX"l >ƹMOT`WiM(``G<07t_S~֣s^6)S׿#|9 B6(rHYؙTq0zK{ߒd%c6<)+JW2t1 ]!ڱA"iy}}~pV@qїfS .SPt`HPKʹRԇQ b]_`Iho*8&Pi7MԐ8+ QSz"IAjQTֽ5ZxDc ȫNdhȌK2u3@0a"~u>nv<2L!'q$j!_pv8K/C?!?Ċk€5XTFzz= %)(Lս?z.yatHW)}h8iݞ9\s QC j) ^NvMNG^h홐{#.)TMo~uXR+(! O ƮrD:n/=P8kLM+ɇ7Dwy9cNPl aM|*Gq zB $9R X:ѳ x$oNjU9TD wMߍ2y߄9_a(PhQ'$UOF28|#ZF2ϩ%_]Hr< $L:׆jۆ>הE`tlPt x#i xhbb!npKjD{q,?a'3{8rtkإ7mV/Ι0UVPW *KmosFClBXZFzb/Bw䇆N9 _<ը-D{@~I(MGU,9@kW3'oRۛ@r2LF`uf#?5S`С~_ϳs c e+u>ŦXgEe 8.m=+;>OB3YLN肈:G +osnMؔ夘oM 85L"j;mt EK*+~YB[YD%`P ]YYsǩR+s`}6F~?j:qkB';^Pɓaw/VǐtwcwV$1Z-q@TÖd. keNu&PQ͖57 >Fn4azxi,AM pbIZt{M4,q1Y2K(%AQ #Ae(58%X1Fյ ;i&x?7,MJQmg .WK h(K_('kL Y>1K 6VW|Z ay OQAH'i$"i_^)&dce9TV]7뵿Y(~w q׋>|Q۝lȫ j `M4(w`&-GO1ݡ9c%fxuR0*%"!i4(fBD:]DNk՟ hqYJW3y_̥e!P%9@g`R@ vaomn쪮.G2 SMuK:nQa zR%h9#$qOyn^z2ca;xIx7={ !tV_=8m='P=u1x7L2$mzD?CzOYe48KK²h'k@CJ/Sye%.B\;9 ]DФ ѱכ_8>TF]"ցt8Q#f6P8OW)[jF@>hj@H^ʱ%>מ1sٹ&C/7}/BB)\JN_SGc .(_.0DzC}U1e-_BLNT\)sDcBȊZF~Y66CP屓%y1iA}Sk}FD.coZqSDMiuވV+6JdZ;ǚG 5a=M6Ov.?Qٮ*5+%*)cezt+?G"Qƍ7<-u E gBGཌiG43TWvu6[i:g;^ XċT%XL73? Baٜ.\ f&v}_v'wjDG?HP7b{.gt-l G_(6h&}o&}SJ`skK:kܡˌiS-!VsUTEd(%2goxƙɦO '8۩-Dk@v E _CjK{7(A#E 1P 'UZ SG5CnF(fÛ"!)rlNJ"cIt\pK68sX$StKlZl,00Y;sآ tG|A=g(osYt/>6S?W*/ ߽sd56fƉTg]4Jv;h#:{ӸƘ]1}ٞeTNo A(핺hnY42X`N;lܘc_Jס*\07PH:VFҒt͎Pf;7Jy/ҿ}zBTm6uRY\.rLeMjԭ1K͎nR1,y$m1Ŗ_wU@z 7t3q{U-Z|?$ֿKW+ LI$Ȫ/=x& R= -q}WL'ZRzgO $Cl<"m:[v?wR{nRbLtxeAöL~ }kCԻ]\y'H]Tdǣ#闻-XU҃ _z\6ZX+yc]닞 T(ϦYN.W4 y M:'*ZNҊkS"˟<ޟbmW˭ ȝԚ*!;+VF9η&:o`mQaf} rBT1 X rS;\:j  Ϟ:\ w]oZ%XK'a7RRz297qCjimM1Z﹓>EG,i&{!U//~Xi"\7C&Npyoz;܁i*IyI2pI)ׄdž- *ev$Lpdu-H<豵,|r;= 5B [JFf\H:[(bр, e\aQ`Sqڊd6@ik< dfqiMRWgޥ_wP_Yɘ'+ϓVH[EVzhWVmג=CN?%=WNpg-ӵ3{Ve Dt6%!Yd eR?.j-DfH*GUN[UusfPF w.sDoP }N!=WI m3 ckoT 5IE vTEY.O%ޡYO3,˿/%Md?5(xfݾw# GDY)43up6Ijhވ.7@7,x1bvB ȷV.Z9''15..W2O\Rg4LQ]ZtEYn5 ,QEOd,5.T,q aEWCUd$##6rjƔsīk=l֦I{pL:MߪW[FAf s S?r[:[dY2_:Dϴ ݛ$/dZ5)}/ rzZ+V$[ƹ ?ߙ{A ݀_3FH9iC(Ibi^CK\ċBitݠ֌AsG({ǍбUR]B,Eo_?gTu}%uHt[rr> F㈱XZ-q1kcG ۃQ*N(ky3YaY1Mpߵ,窫:!c~ci> UT,QA dz1zdf*#!d;7 O+gU]XЍ:1D)FBD Df?.WCWrWa5;; `zYvnהs"AX*(%uG!([IV|[ kZWZ.MwMFuȩiI:27mm>^ Md*FuX3t6SvOlDco³SDj9z-n#?6%~0\(RlA+dC  Ûg/F8˙A+H ڍ6)ՆA\hN<B4F̅׭ZnuP]*l:y4Vz{w[^=w)z+#&H9;x{rE%x'2dv̵ Ύ:.Zmv `_Kkls:!nl,dGqGei k錫jtffݵOۍb_[ʻ|I8kxNB t}ZD`C0W$p{pD1SbY>`E4Ґb1k] zz`48X_nwd8gs%-h™#?!xKz}0O,.f,s'}Aޚ RN?8Ue0d,q<,YXK$¿U+H08uMkc̺>nH$ H:1}ibf+zL\x1NzM'kp$|.8S@PL ;>ZD(V#)c3LG9=@00ؙfμIN ξ_] |S<ɞ\X•L /۳*D hk'w!VLGkTvV(_]dyQVY ٘Ô7 )ⰰ"YpmAU^_Q !:gdmGpn;G qI׽WJdGY[?OGv]/%~{?$P\ERV]gD ZN{ǁ Y{o߳h#LA.ȭzç 7T‰b꧛՜0t1u ///c궈Ɇuq QR6kYvCcߺ70ibzw=`zpzPUDq3T~Kmkycx=ؠ8ު.V*5IHZ:%[G.C:ϴБq rX-%Yn(vy(]U,鱶נ{6]whFWdcR_d7n³+crV+X;cv5p [leϐ(zoM_L2EOI{dypk]y!h$WpKp0W/hρ}Rw~kgrQ\Wd[b+/\98Dw"P~YNR]bKGkkfx6H?ǜd#-OBq5ۨ|^ 2nTuu7p4Eؗ&\S`SXVV Cjܰ)H.|QgD4nHA̮Л%9}ʃ$Ƣ&$8ߧ0XB.vF8׈ύ"0O ~ouV+=f# Pn$9,:^d^F^"GEyPǻ]>'!1pؤ,3? U hp}M[s֊\RJ4 E1wB*Z(62 ~IYb1KRxPV(BQX6lYNCi l\J}WDBR!/,X0OqVGp'F5aVKŠ<ϯ@8S+Z \8MbO[!GtձyYXq䴽 ը[(t:QCH%0GղBgBA8OMؐ"K#\#7Q:[ܛcfk+*ɍm8o!d->eϿ!?ڃŠ8O!h,,p1;{D7 ׎uj mk };CZCoD:('xW,1 ";Lx0S:z՟`y`ӎX2('@iB$4&տQ(IOiս JyjBvjr'@ #-,4spZA $`kD7DiZ~P&$pHnF#aB܎n_%0|PYAȉMս,it9:e TG#?[Q%ʬ'a-@ C)v>~v"Ze\S^H4`-<1t}&4߃%.(9^JR%! 9fc{ ہʉSJukĠ:tV⑫^p33]ЇPd&RZ!mR0?dOÿx uS!6zhnu*,ɒQѕbB51o;a$EnwHg`\\qrFH>I0+pB Wgn8 z !.2Pn `dҦQA0 s"!%1F@>,>-;me҄mSٚ5f]۪aa_)؉Xq3$Laܩܢ&$%2znRyBOr83vOD -ו)*OR1Ρ^bNe2Q|U,;csQ`%"%)棴n&7Et,j3g{&2[JN dh30V}&r#Q6*LM̿Hч;?5Ngk4 >yӝ6b<2-ULQYXqc.'mԾBmW{(e% bsa?eqncX"&=Y>*֜тڽN G2G'gRrUe]LCC_>\}]{1-aB;ᚠ2YGo8cJރ ֮O2&;恱quà U} 3sgs2L_kp]:Z!pK˟1~>>AYӲ>hă,1 #?1>+WM&Xx8O#\\@.oك߻M-c BTXzK-kK1Or0ԜcC>E4EE<1(|Y~"#!{j[Tۏx!R7e[9*JI!z, x!ǪTm<ӪR%lrgX7""0UNN Awg $(\3+:rQU24*F&WDKf-s UYFT;ΙcU5 p5!"`@Wc#-iI`sC:\2".%~t<)mF&iqd8{\r`qGPeb^Le11^J>EN =v` Oe(VKn҉RlҠ$4`㥹OiA8T9^q;R QRn݄_a>>h6yP9i2#H,wG;!К۱'z>[F>L¾&C}*x>E/L{D -f.u| b*5Ӿ8.^~"\^'sNB5#0=oZfl%2NWoL:LlO"P unT ~/wZ2щ.M qxX0BK_,,tg z*2s7!b KLi?J](e;*oMF¾ &! *uPCiMH`f]5cIrٚ-dP|ihDH#.`6gQMF }am,lR|OITҜ\Ht^/)@,|j=TǴfOd&"EOK~p) !uGB!u>8 S_^~@MĔ˝Ȑ ?X^W!s[e P ά="7h:z,nod 'av<)Ĕ̈́ܔ7۶<}uZUӌW~.u*rsR/$S nˆ$ l%rj"1.M\*\^/Qs2kmAhT>F~^S"{V٪q~Ip^{@r "<-j>ˁ7K6{"@4ӏpMye]b?)prE+rtsP;W'FDnyM|y]Am)B961Mٺޏ:MǝPV"eUh sBk.1m=) !J8F3s+UbF 97mB-`%I_b Witm}ҩ{5G=r IFMl Ŷ pmYy~;~ S`2 Y!6yJiKLj (ЍeH:Fie9NR;v@&F G) `z=ZTG~C 8'FI ܡ@ 4-Wޒ}0Z=39?M ŊaJ/X%&p Ubq^7a]VmF[CP_I|=ϓ+Ķ#VUxlt'*إr9ƢNvVsAEMhpNAqmM"-r2(nX0ў^(>bpG'sԽ3HYBN:n5l,et3RPyjн grp1,OfK+iÁKvўV:4&0*㵎SJ;)oP5 u?YƢ1c82hoȧehZQ23mA,ZǠ}a|FWԆ}NzA]vFD/# TSҢdÝ48U*+us4cnX qvy,FvgL󴤇4ީ.TUQA+0CHH|2a,p e@ea)E{Iѝ b Xfٖ@\4:Ud+9,Kre^Cگ̗`ɼJ1iAWf{n6d~~h[dT~EhvK5Ȥuݧ#:(@?/HK7ۛ `l6ռ}ȐT^Ԡq!hqE=e(3*$=p^uzhR[y DUup䊽ꈼbm| S:|D3>=߼m(_TYqIwzBNDNq0̐6::PrE\u 'ņ̥ \̱}r D)pJkWD ]yYJȁɅ͓×Rk ؤ/Td{*fUc Ū.<$`zfsZ"uq=qRVonrT=!S! D_gO&<Ԣ ,.'u>$O1/Q ;+m9NO*il*Є}WNbe8.Yg`gA;Rvs0ʫR?k M8mdT'aT\b-CG׎Zn5rBhiEZ ς&3!ݐ-Y.  ωg9 {~>%km%#ߖ` `"U^tc1.aOLkC{3w~mS'UC8rhS{H:IeXϧ<#4":K1Z쵴 >KOTtB׆Am~%~>Xy`P ɷBHԳ/]Ke'6Ÿx24yq< uŊe&+Y2W㾮=< @ER{^ TC%d\f)^Kdt1u{ PD[̨}Δ7/7LXԝ;TmS4 ̒.A1v2/AjG%\29~)ܰs˩g I%8z$j"0 A0G`byO?2ZXυ] Ϧ:P91ii^0U9VJ,O/ʱ0Dy3g uMYCfURX8JP }[ ', T(rȦc_PaY Ulwz1޲L@[PH2*'3„yl$mPZئxV\n&S@Ycau M Z@+LQǦu6{Ty]l D, Z.) A뫑)/̀ф!tO?%/'c-Os: S0*h gg/:fWdo?\0 G/zx!fl$G j }9N 9c i.w"Qԃ}D %hUPWDtr c-*[ڂGbqw~b"׬=rPjk9q0U_)iG~BsÒ(>5hM'jIc+[?wTN֬xH.UxK^ng6Ts,`KHG0R tK"kg4w;[ܵ8m=&,ϩl?G_db".]>&`I$}xI kB!/M%Zy8)O֮\!;:"A%ߩCH`p{CIs WT30ۤo ڇ^vi7<..Ģ"Q\ N ac_%-9&* ŧR<Ùj/b<8ZUO?mrr~\~Â7C{{l;ŏܷ(D-S spՁc.MQ* Jog*@d Ep$S]sӶ:Jl)~ m"%#"-vif/ຣ<"{@vE,͢>JAՔ:Gׁ;Dw C21N;nmutЂX"NB uv}$.7ac>;%+k>+to |-B@qnl6,P }' <06Bܣ6}ڜ.ϟšDCg 9@所s^6l 6A.1/Sݝ >$|~|tqkAA ^KSM2x:ѩ#^kn+7'>:fE̦4#" A[Վ 3<(P\؟"}RiLܡX`@;F,)q.b5'_6,U?jXIÌb|Eov6.OWWn/"%\g!jBjeΞ{lGYteѲ IthF@ԓpϩAj[|fⲬi]5o * Bh~:%.3{ S[>ۦQ, \+`v UUEW㈆A|Gd9qp_u6o2]4ni7]8fkB'+F>xC$?(#%]u:FU7/Cf" EZ}&4b~pێ.Ү8JZL}obfTI+Cx?s:r?=4 Lj3n.1E^B <pa⚬xڡlKSr^ʐ)zmh )S:bEw/ƔN1זCzDa:O7"b)(K84}w̱J/RքҝOzH6<{?,Xu˽%*A.."G*|A+.φc_s]_dVم s ̝C%$$nʳ?<YY, qU)S9?klydC}#*x,~Y ӄ[곥Fg'שN7ڞe&"&?/\9Hu#H H A|xC5@.3bڄ "ˀ< 8{OU% D9I_\ vM׍}s+m |,-(?J% ;\rjT6{d0tE607Xxǜ-CVDeD63G8[EU~ϻcDw5h;ce:amPB"X}ngড[*{,D$`/<GM:e-XVXWFsa[AIAVs]{D{d]xE "~i  r<,kZ~SaLQ*c^y#] (L=ۂ@<3㡉J.;?F0ւcSsl;ǚ/\ADmvt,Ky"X@٫ɝd>fEqsҠV{tv=.ES)IVuхb)Q>*W;1۞ { DJӂ?Fme ewǼzAØrT.D0{wmNVpHbfV7fcfxNG_{,u ?DZ, o)ko&hs>QYYFL{E&y̵W13|BU;)iUicCh~8[(my+oQlPyٟ莂VmV[-EIFQ-`k "Y~B=9,1s[ٝ6er=]WM邿ހR(2Y q d9 <(_(荓=6TKƬ^ۻ<*7;|Vͬa8FaPu;Mؔ Uc|gcLdGZx4+(Flh[+ラY I'x8} ns:drX(u$%9塗<eIjgTᅵu0 hlD'g5] $i7v{6jj/x.1Sos_Bb=k`C-v{˦ A2u.:'?+jkκ]:EAe1-CCbLaT ܸ[)Jb*p-.Dj&4Lâ-fcmbBYB +&ypx^j}s[~^g0 :ߧ2.66S D/pUE &{IXb{}Գp0BS/񗫙g-zz+Y,!G:'x]WmS QSfZ߾c+OV*\[2ʉH4ќ5`Hf=3"϶K|Z6>Ǿᰤe2H/#۝]y9q4iVg0GԪ; &6(y ]hEyhnowf56}BҰ1%3zK16OO[w r]d#Leζ+ ҏ6pHItMR-olox:Xq"mk?|jƹ1fnrdJׂv2`D|)Xh,:،cl( "$,eʡniJ5 #kbBX%YSձ6r{VGyAEھ_ T>#iX3[G*Ϸ!zx)4wWPcMB?Iq-Jt'8dfy ~Yg逞jo mt7#do jV&#b.̗%KSN W P81΀Vbu.b ien} *cYb<)7;cL=K j٢u{6.h{0e\ Zt௜ ;Pi 8{>J"76o+`(^b`tVFYȣZ`X;yċ* SHN'^qHŝq+m"C{9.;I3WE/f1/Zۆ{cץOQgdn5 ww[ղl+jdrmkZ8 ҭ @Q !sS$?ux0Ncy*ϻ0t|Ʒ!g@D7'St'B+%.,!"pd&]@],v\fͤ<ɳ g2PA݌f>mdLԅXEy>Csq7NN=ˆW(E7j?7;~ٵb o%]70d*ƀ4[N@@{‰ށ?9ihmBƴޯ9~BAwxVF/b2JB\2arTN + Vmq2UV `R)⣛ غ4'9Q|$w|CzGa)Y+8kn b_AU],m!@zf"XLs_^5IiRӍr g@!Y{OQc~EȻSR+59/lyS'tP"-st{ ch&a@ײ3mG6l/d 1E1V+LZ".K p x6H cަI 9!&zWh]}-|tC,P@-F74L^nIYJ`cvRXE_.:h' DPŤJI~ falz. TyR]._kI/x C@oyw!Z' +O;npR|o(TG逍 (Hqȡh&*;--=J PZDخͨ<[vzÌ@J2䚜ŕ 删7x[52~O곿g8'f$5N7J>ӵB8>{wж[V\^G)c`ӀWԑc+*Z+ Yv$/Y \^r FPS!!)5[D!pvD(slbLj 򗢴K*#8;Sz|,jtӲ8G3&qCݺM~=!g ,$ڡ\Y-0x8r>ŠƮ^sp]mx!xzy`Wֱ@ZtƑ"jFSjM a))R}~U~ 7fu'& |ȇT"L$MAEĎ]RDXgBEA0r˪%fרkHcZ"G FYπ#tlhqNxhzC!'M&rX+xuZ")·@E?ӚSJ53 ~ %mf~ >Fr"NKShmrc:qXUg[#`2uA pG;b| EbQ2lFq%sÇ|#9'' (aKʙjkrmF;oMruuTP"6`Cu@a-+,}v +ǽTS.}NWo&ۜWU'-݅5O UvxJq(6Ƞrp#"x}~^e6n9GW` 1ؑ,P3lxP>|PkP%&tF\gJnC5er[` c(q&^-/g*?LBmX4RLuQ^<JԇA&Q#"̾ ?# 橚%έwQApz“t`*e"C31ey v@~__*!w+CV5,ӜC_iz KҘFYԴd/S ȦjM4qe{ FJ猁rɜd<yxU 3[uhz\?!g tqr 7&i)0N9QՋIbi[j<ai藕!L?" ~Á(D:q mQYO&|5$cfK TH9WJm "*K&l=S(/d9wPtuRpFZgΩ6Ӳw˨nm34Yl&\4?087%G;m^:;?;KL*&e|RZ]U? wPu _w HgwϕP6cuY̕B4~^h0&ZT+_Oi89⫌#N#M{;o523I@C 1lanwx/g$~YeQ=hm a.;|uhd'zh H gBW8IUQOf6+^O)JIWBXdjMMRJr,o٨sL ܂4&it ֓qg1^஧D?;R.87<{n&>f ~6},3c緖v_Ow=ri↪L7e uOvYCPR:VJ.|Sϙj[ _O 'g5n_nSq۲-m> SnQGQ'y$lU߂gj'8HANЦY &υnI'ʃ9`- )`*~ )47wt_aThfM.sN|jSLY[{HG4P8~/W+=ZmgS^qc%RHǾCaT"HfЎfUSZ#EGo^(V9(+C8$x" 7Vp YZ