sssd-tools-1.13.3-58.el6_9$>Hda,FETZ>2?d   C .LRXbb b hb b b b!|b#fb%P%pb&'9'9+9(,h8,p93:GbHbIbXY\b]8b^(bdeflCsssd-tools1.13.358.el6_9Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordZU=x86-01.bsys.centos.org yCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686*ɤKS@ |4q"1FQ :bo3] 10m:+}MHOt x>tH dC A큤ZTZTZTZTZTZTZTZTZTZTZTZU VpnZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTZTd7e7b127decba56deb239179ca1ad550f9d1a7af1d025afa791b01329ab072759c7b46af96bec45781ee8108096588020da5cf77b593154f6d8b18013ded8bfdad131b0c47e6cfbafa199f67d951f145d6e373b1fbfa9f3749b88b03878c1c1c2e599ffb7cd15c37f6f505f8899527511241322ca0cffd3a0abdf293fdcca22eef4f6268d6b5e2f9dfa0fc5289b4ce5d48a63d72a1b7b04923114a4013b80d90074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e392be566a7ed5695776443792b81391b8cf0599d4b662fb67f3d281e915d2bf248c553abf149b4a7568c26a877ef0241430bb8e59fb5015ea7cff0dfc4fa16905262ab1ae9161bb5cd95e9e8f8578677149486e86a67c70ab696bebafc920c03882e0f68e57d2f2f84f9c100088ac8508237103d5d3f280ce1d8bb507193204781a5fa9d915f5c56cf662051c6c122a25016409bb2ffe73ce6a65fa46ce5597b8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90313b06097b136c5c0d5f655559c2cf20fab26fe76fca5c20564392eccdf0b5f50d3000aa080ad7a5881c8a49dd3da76fe1d6c6cc9269abdf8bc222819b42b9c22c75a1268599af05ed0cc0a04dd9acfd73e16a6412a5d3c0e498d4555e31c84e23425506bdda4af8cfd3b03f3564419d749f067940c0c4d3ff4e0be57991069c4fc3bcefc263239b822919149cda5ff37e4615f1f84ca34c0a1b625e3a2c687613b1af636877fa2912a36482b24bc0823c0b4f22749f376848f870a125435bed91e77ff47a91e4fb1698ce16a6091e14b9676da515362f6451be42bf4ba169e677417db216f67b03a91fc7ae16bd95b800a180d9421cdc2f4dc0475469db40419ea89929e20a817960d501a690a6f830bccdc97fce0eca83c029d23cca69bf5b25c78fd3eb592c4f9ab2cb3a846bece68363adca060e3ce994a98ca81b5e39a1e711ebdd751d5e9ce7293d68410ede3a69e6c79c1394990ea2aea526005a814b678e88f5546250961f8fe196461a7bc8eca26b4783fe9fed974fd577ec6abea703bda376ec5b5419141a902a19e988e4f1705248d9742df853cbab42301c2457d4296d67d7241a07cef458752761ba8bb724e2b9647eea0a61dd91ee240c79a21a224a1d29ae27e951de1133babf06b7feeb94680f851c8e898bf278bfc946f22111cc48c43bef44f58039b7e13f5d96972fa7b91a9b635c8e025f4f53eb774411d95efe410e12f64ca7ea89d33f87fa41bd7b44c411967c680b7274128b11504ce4d1519200914157e3ba9df7f2144fd42597a5f26c58eb4ff9d7aa7e54f162e1093fd8e3b76bf9aa1be3c4db4de63a83c7462b0c47d51dcae3150053145910ac2791378f73b979be8e47598aed0bf6a13c32cbd890a1a8e425fac4a61038f5638459a51e976bdaae341a3939ef61aa0ef40bc1554bf9cff5ecab78453d144f11c64364cf8e335bfc86a6cd797d3f7ba1591a3c01890dbce7ff38550996451ee259d84cf9d99c86fbf343b3d1cb1be9e942b14234675d8e7a351e296f72a95d39283bfd4bfdc79081fc113073438d656bee0d1430b484d67b4f9517e9e1a335dc9d5c7d37988a048246906108b3120a7d9ff465fe452c55515cc695b6ffc826ab9155d07bff1e2ab13d1f2085be637c43d6259aa920f94f408d8f8f2b1d239de59248760a97b39d664d4990be381eb364a0501bbac3f67b04b48ee635ea6cd9c7e6c56021308ca05c0b83cb0c0ea4d4fbd7a2810f60c62a9adbfec7051e2a0f5b29d34477b38628aac5f534a559bf3c0e060ecd176563bb968619af6d72d510a95212b7a8db0393079731272e190ddd161edc2ea98aebfee9977075e960eda2d85f9f1e4ee2688fadd88501aa33e5282741dde4bab11d5151eb1362434a7cbc4ece6145931276559af488a73f26319c36bb407ca226488069e039aa075e63d39c1c9d2836560a2312c6e811a150de3844c6ebb6b008fb79d8aa0cdb9cf1a43bf9faaebcfe61c74bc4b7704923ca483a906c5af3a9abe944496758fc8e8f0ad18083beb507678f3e7258d4a11c3c11c2fd244a72dfd9c83c8df1270033ee4d8f4e40293f0fe07b24134fd9c470fd1515883146784f08d5bfe4de420a01ca628a252f40713fe062ffc2412cfe92e68fe89fd46c0b6a38c09229518711f91ddcd5073bcb21e9372040ce1f635ef41d1caf1f9916196675e13a0007e42ec3d96fb39fcbde84bc7807d6d5d034d68b760788623eedfc354054975c58b79e59a378b94741cc1e08a1162835244b0fd3ce8ce3148d374ff988a79e8b12b994a9e664ba5db2d423a54500d801be898bc7049839217d8ed9b25ada18f60f0ea5d9ee69e75130755250d88fe9bc46cdf1a23416502a148708b819d763c72aff1e0d9e74d367203e93cfedfd64644fb6790e6df37bcefd9b53995b5c12cd376af384416ba54cd7a6b486bd93f07033099981735fe5a3cca9bf7e8a5a449d04c20c0c9a917f21e92757db0e35aa2d5f50f52126ccc2a56264a88215dd8178273e8ec26feb06488b39cc94bb3ab1f7b668ac0c35faa0b5816840161293c41ebf2c81125e1a5ead6914a501130cf747f677b00c4c4e60becdd2f27ab3912c5785783337aa0aa5007987b09fe5d131b62d51e4c44c0f24859dbf7f7c6c666a30100ead481f43d0cd3352f3af15147b499cc018c662026942e6dc93fe4a89506fcaecde2e6f54eef30467bc4422ed9178e5e3029b274592bef4866fe443cdd826af758d8ab26ef59bb0e66d29bd5e638afa602b9f8eb6eecde0982840dc302d5288d1c3aae408c81e1c05da6208ff91af41284064ed1866149d75229cdf9c31477e5f9e83f61670075fe73c35439e5f72368db8c7a0582b0fb75663ba8e313afb2e936290d917740515c4a6ef5a231dd83d15b2612a78208128e075999cfa225bc707d3dc3d420840e322b7f414b854730bb5db58efb2a18a216d44a9f2c71c76bd9fd882259d9345da4bfa87ee06e7a524479a3a259ba83ec126de750c296ac6d04f07ae79dee0b2fd01d1801ff04457071a4bdb34ceabc475857c8dcae38730b872e2be0c3e0915fdbcef29372eafb619a4fe9bbe13cc478cefa5ae70fee31a81ed1bbbd78e33cfbd735606b5e7e84d56f86bd3a42152e9cd068bebb4e779ae152a68185bd519bd26683eb8161fc53a69b169224ea6887dda3f92d37cdd63ff924451154aaf87b1aa486047281a5cdc1d258ab35cfc1db9f5fd27139ff80bc40dd6b1aaeb51547832eea1c30b3530ce6ce83c669b19c04832976a26098cdcc84bc7492112a6facf629db70fabae3473d30d823c0fdcdd658145372088a2416ee2d9b1b921c638cae5a8bb41238f48f94e5ca1240d87597fc0f19a16e82adf868918564908a90c69d91603676af9a32c792fca882fd9f96a6bdd493f0afa9334bae95910e1a6abdfcf1f6c246fcc9775891e955d279f998f47e3e94beee36bdb6c92c66b4a50b08246e7d5ad5b26b544b26f74f6bfdaaaf2b1f0de96026e1f123e1172b0e4a8cf81c6def5a6b9d39ff828202afd7196eb74ba0863db20efdaed6eba97eddad611c7f81116d237cae5ec8876bc6f0ad1933db1a4b041a1fb58f901850131eea8e3b374eaab9c4f8ba7fafe9461d5bc82c401e4c49f3bb82b18cd4ff1fec2142067a9ffa6bb94e58e6db8553bb59bb559d848f62fbfc12926972320c6b1ff62fce6c8e4ecd1945e5fe47d7f89f021bb6f80b8261cf8b50dcc3ecffecc5449ed8fd1c611844095d83f328a95a141efde0595bf1363485db8cd49c8d8d2064fa7e32bb8d9488cfadd483ac904addb95f1cc1a58c61566d5cedb021b0e7a00607592da03cbea0785a3dbfce092723e5e7d5a012f89b1108e4692ce8d4184705293a76fb9f56fe82692298a2f764fc49274392383f6940d5f70d0463ad0c6acf61e267f72f3feca4309ce8778d13f579fe68c8652250563028d777c1e9e58d6b35f0a2f0b2ebe0298fbdc90350cf56f0cf4881e205543cadbf4ed7ec338e1a084f1d609cfe8d60dc085f8d43b99018ae3964327c69555ffc35a598e13fcd24f4284c0aefabd661bfc1e66e1a84740000a4f2ba79fb17b36f331499b7f5f890e22663f9d56a921ff06997567b3bbbf6c6e6114f11835d1c0391dcc093618a9591c55b60246714852e4821adf67ceeec96e2fd39b79f80f3efc499d76d3f639c9e03e1047fd7c85cd8d50e82f110fdfb73a623d4e4ec14901c6c61a4dff8e18c0fb1b9a4a015b926d7a071cf1b5050ac02c9e1aec70aee74e1014b5661cc44630534d1a6cb2cb4bbe1158965683822eb952a47d193e69cc1f54700e924ee1104b8ec24ace3rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-58.el6_9.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-58.el6_91.13.3-58.el6_91.13.3-58.el6_94.6.0-14.0-13.0.4-15.2-14.8.0ZX@YyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Jakub Hrozek - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1534618 - ABRT crash - /usr/libexec/sssd/sssd_nss [rhel-6.9.z]- Resolves: rhbz#1473005 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-58.el6_91.13.3-58.el6_9 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6;]"k%}:w{!vQ_99g4ڤ 4Й1Z M s *?s~ɼ9-~?,?:8'=)/iTVƂ*@mDMn%KY:Ap5x)j` -z&ZѩC7Aަi;4LGw,bZ`@+/QJUdz&@]synv,!; 1WȭA V* 0S޶./aA.qk$6j|daqiLK}lT7A$uG]#6eJŦk, pӑ/{/yt8e er}Q% 0qV誽ֹ8U#6As2Z܆)B|ŋR>wCXQ[]w[@?_|أ.Dumd Cǻgn0'@@ZuU${341|K]Y0;6Ǥ٪jcl`# av' n͔KG*-giWsB)JAh^#'5cr8,dtɺz3Pa0&s"Qsc gM;@=`~uofC٨ʼnq{?QOF x\~3]=^~16 p!'tbFf_b ֿJ(QQxN$uDԳ4 n}J?fn@M.YiWO<[QP!+R B䉥|Fnu~4ը [z&V[ܓB :UhivUȯI[{[U.55Hj>N0R٘09c e]r(!G-;kt^.|̜9Xh丳^U_?D/z?_Cט\P#4z|/C|RIt;5QGF{2C7`lt_O;: . T7`^|Z]Vᯚ@. ;`ퟎsVvN622\˨_ 6 њ9)R5"k&7Ty\,Ed s" l6@?=B2#[1F`R]ټ-/ )5TN#M0dK#Dnxi^ $(5w -ԉ#;#žv`u2!HǹK:cg06SBe 6urKL@ d)N|'hX6w jIQ>y䶾=s_lEQG-|a_/\m_+WGO"\ I K%y$:ٮ$k2߱"=2~Z{@;O&qz {\beS+FK򁘯ASLd4U&CAjZ5Y[%ﭶ|Be]pe\rqɜ SiS?<~39̃/Ҵ,F*d $r]|WGHyt)XW$\C6$(i Du6fk*% Tp"3vĊB1cB|!-WIeQvyeB\+ۢr1 yng_MGCwoȲ *pocбdNS,,ߊ]WL3I8Mo`ҵKn5+(~(@~Ոnmp1pjEdM2#.%P #38%E(|WlcLʣw&7SA'%=4ݫxebRA4҅u)$05cZòDz^%y j6)IiHh2Ǻa$I+hk= r:^0>FQ4DxiW^=|3AM+~n~^DC3RHפݮ!] c_qqrz^GH04 /t;-KbaY1peqM͛*лR(4.Ve0@KW Z6-PPt9 \N Ujԯj0vwkݱy7E|m;Sh)\÷)q?ZҾ=b;hϺ Ȃ0?B(e9cU?f7o{-9=Do3YV] i7oRr *j/IO?"`D@f =6LKI5"Bػ&[ڄ}X}IIl"ВS}AZ:Jܨ/X0qFcZfE7cC [}Q|8,rN5)Q0@Xd y4_ zVfBъf\]7ÅdDQBP$0 9T(i=`AW~*Ĝ}%2zeG&hZ ]IC<<6݁SpuE7 ?Z{vj\?:lyEV=559LD 7 S xDs|0A;xQO2cK@4C#;o`_~׿ 07 A_ };&mo-R=4YR,Hd,~/!'z\~s< )oR@˃LU7˙֕_귰_ڿfZ5x2=@9!/4`P03R?k 2jg1}8օk t+wAVc89ǧZ7o/~b4 ,;r.y ĥv7L&OJ%rBE]x@w %c LfEu:y;w$ldX CfmݨPs_:w'|zi=2@>KO ctH_8XB?ڦp#qN]Ɣ_ߤRM'+ug"8 cCgg_< #::nB-IG?|&UQzN<֟j2ג3Mk.݂$L x2$6˗Y$IJLbRᛔmZy6t!ݖc1>(TA8\m@ʛBv絏g߰Mܐ ̻M5#tNj+N#:ヰXuXg$~VߨY"LtA[dLy9 `8j񰋖6әB}X W>%ean!o*_(}co[mLTD`I{xBBV9esbGk! QYGaTM&aQp3ܗֳ^ sgydĎb-!-àh5!Y w[Vh 6{!8=yщaodu"j>"g\Bzbw&F;bwAtr~n{ã>>G,`X]N6}]1- #oDz喲ZeVQ*;hub<~/XϢ6q##{C54m;%%n 3)a;C5ꢠYa(}% HԿyYXӼaMr0kg<#9ەΏ|JőP5*cU uX[_i9 X#B6n2AM4Tx*FVxtwԬ^X[Bp(`XOJ?ʽm*L:JEd)_ l}I%\b>M;tύhe`u<=^R S*N[>HwdY 1G%PU.H+)[A.33}| 7a硜#ai 㐐?ljGST  %OsgO76yZw uw ,1>EBMo}\jsŇk4kct$R Ut]ȅ6Acohhf&{V>g~j4J릯qb[\9FW$S,ɺĬ+FW )CU QDew(lt6.u ~G9XH@7XփdE ݒC8]~MoV[g9 N=hfK1}t^8NKN֫6Um+`S26a^ 莮R5\B> D`WpmI@ ?p(Fgٵ9xDc'A:e[&wy8=|yd^BG J@vNv3Ega4Dy 3x 2^^*yڵ'hbk"(jMhm&s\5A 4|BJnϻmPڧ܍K2`V_e|CN#/䉗85<X=ưN/U OtsvTxߧMΜ(~מ3ϰ3)C)qCa1Rodz̟}R?"kWvl7k臽K?aeT~ 19rm ݖn;pឈ|1ݣ>+E *浾X&c eĖ}3{bܥ@! Eyh r];~Lx^DRHƣ vUӃbJS)$?T29o[,=s,j6"Uoiϙycsf9̋W3] /NԈwalZ+(m1|!<7< $vTBE hg*d8FQ`&{IP}Gv_g%7l:@'%SALXbvw@ 9݄X/G'WvekoDǨңbAk,o_d$фp~7&(ay~-Q(oB]CEi<)J|lyp1|YXpNnvy)mH9}XNtsE?}6.4^X  : oW۶TƵ˵ڑa~o#* UaҿǪ\i' MHRA=UO1RpK&rp%hcmebk#]XGTIwk^ѩUJХ>: vg= 7t;;JћU&ϝEl}ʇe7L*h|Q@S ՎkrceW+YLޛg7)~p#M2:=?m(0绾,p WrnWYfɪ߁c\HB?!ž=Zuq-ś5x6͍x_ {]`58:'I&.80!ZT'?>^'iY`զbYO۟yR<~I&S@C^^QR}{bwHrv{)oWө8=Mp~ROpŖZW h_Mj` -Hi=ΕMO]swT5-[wơ{.l;& *oDgkqsWuaJِqS9Oneo{&zIDH'׵c;BݽN@a7kZtpM;lefGE=p*LD) 6~[6{oh\L-(y,ɰYZ%NG+oZ4&7!,E TQMDɲ@0ۘ;ҍ>+P4EYDyB PQ}a435a'r.I#STi8|);E Q+8}K}~C-Eem졬.wY՞tX!h$_9)#UUeeCIˆ,shKK#S&u93`"ϜEGOk:2ĝ*p6իzF&08K۰C/Lt73jlQ:xmn|[RON2$v63Λohd9gI VON5㽻VIPaʽfTtWQؠv[״^`d?D{50enm@e `EG>ܴH5$ GTC=#E^ qpR U|S k[Eh 80p/F r; ۃbw <zUrϔ|$8©*GcRSf -t4J~%F$3uyVvALTjQ(u6%L{C8ӦvFK h>nDڻ4[,w;ʚ!4A30ۊqZ^VAOސQlp%iV+#d =U`?37ȡx?ލ,&Zhв|i}vV L ;(Ev|i |L#*澽3,ޔZ(4Eˆ)aۑpȢfNSʐ RKQ9C %bK}mgސ"ĈAfH\q5Rȵ;0`"=v*iui4|XGZ"d :ogyVy,ҦE\ɚەi-զ1bbry_I@VqH 1*m`JSfBr㰣Hb\:f&x ,͗UT;L~:'ۮcV y ç; cOl5SG MN;̐l;&j⨛ ܍5ڎ]ɘ5.WU(]|$לhcg~HL s?3-a*wfN ?Gkn*YWda:=:3]/w[`'XQxށ؞txFAuT)p]J|ёpG;A e78;ŪҨxR GzvJk2O$"5=0e7?bؼr)3&׼k̼C9^ѝ`0hj oyen=x_>$ m*Qq!1TZl'dࠜe`y^48SC?I%a.PZhY1T-ἅSz[c3YL͚3K3Ko4A+0OWvQ͟Piޟ퐗 -! #44a8&Λk7C*{1 S{ِ2PˋŽEzwNP.|xGDGtHfS}W" ̀Ըn{xJ*z{.'N8^}8+g*~82~30 Lt|_$\Ȩ啪/c}~PkT=ߥY[ kHBwE9KsG],pj]8/EݯRs1(,0B}lv~C&!y(R0Gba֋TEP P'Ү(L#ywp &1vX01'.U-@J2]8ךiVéW+=JՏ3=Q '1"~vc 6U3kDmI=D9}hG_6P&v!Qc7q<9 O]4(7Wl/Mx>7ZR1ȯt-cd jjiBʛsVkpxaGyY51k}_)n\Xs"xX>N#`.O3-%w8vT.5Ps [\VboY郱6nJm|T 0乐gI(7jbөS[ŽYɇFj[m(Vȶçt z!~Wz _9xo}L=qtĨ*̳CÍtU*eip e kYgbusڡX <1ʔ+\J`ˠFwnjq0{Ъ27d_C9 +7*hP[[*3^4!z5ELvߥmfJ!A SRpya@4U q*۝ (Ow[  z Sʷ&F: 4L3xMϕJOIN>XT !1ʮh$ՎR;O8HL& OQq^G\ }@ Xx粘N̊4T&񣵮]B!9h~W-Lmm$w,1 6Wrb*>h9A N`a^Yj=s7颢(*h?07jdsf+=UënF-Uab둝ҁW-L6E%RbY3F.nlY{{RI.s6_a)k1Tj J?eԣ.z0><>Y/#DnBco&6;Ńae$ خ+amآIb`1 eTZ JWHApQ9-qe 98Kl@'FA>|ᘰ5}|bF9*%1wT4YMo7 :q0x suŁyoC%XGOJL^ew #VZD.( OK떇x5< OvUG""3w( oZ)Xim=篨Ij@W0['^&FaqdPش?cŜ.P^V[  3*, Ge2b#&$c1Vv^ݽ&glΈ`,Rv\3$i-T/>c7DU,}?R!8A$k?3\mCHl{#ydt<]ܲ(7uLJLa"4mbgT2)YG0:~dڏtMe1lP\MN=-43%dzXsͤ6[,b$#OUZlDK&/bG~k,;J|a1|Ld= 6 9ÜR)s\٠`䓙ehIe;b xנF_$A^_2_ [>S ~pVz# 4m*d%66*tUE|B4YAОF`؊9U3mR}BL(5e؛(Azs"3&1 b]*83.wSGm#WH)[H%SZ%%P%.z$í钇[etNp wC;te :)[1GDcj['l+j"'fQg׀{Y$R32gٞ{L^7 KKRʼnzR,rnz4%z7т|LiJUeG+L6<9JrEfdsdD r^Z9O#LdM6̽Дu4DK4EOQĴ$vN{n4G7Y_|Fihr$ƛ>T5X 'F2{]܉yyX8ebD"m?8 N(=Wܢ ] a$68j<&?]GƮwaXWÁ]DN~Ƅl:T9/gIw*E=t/'a`gEVeW2TǫljosoBE}BޕQz#JTМ(,f@/S;^+ƃXy'TtHA KtK"ߨmra33mcFu_~kVh{@B?zDo2Q;$n6Sp-t_ڄ0<ԙ(dBVd0c2SzPXGɘiZĚI]5UP6+W=/.hl;fZYEC9^Aߠ6鹜L~ "\F>4QIf ͦ墵HDg&6ʻln㩃ٴZU:C Ԥ> ԟ5{>P,W* LLU)eH7WlI]if._sol3 qGr=*+C2J x2|H8FPt=*MO,uBjyk7`܏~(-&dn!}La/ɀ#J\@0l~YmP)˭@mbDv*, mH0mBLb,~ôpmgrڪF|\DzLEWz7ȃPĖfɜ?|Nxέp6FeSy:*3ȭ6R FA܊ٿ)YHh9dJL#ʪW TBBٮQK)g/cWTNsH&S'ܾ2@l&\Ӽ+(+0{f3 Ҵ>6ʜ:sX$-P(* H :>p+ۑ\FB+IEaシmBz ֊'4lB,'?u^7@l_bP]zd%JYNwR\77W_x=g5}*Y7TڎȌW." ۧz~7릮<[Cv,ll?eW#EVl(qFCQs z媖%H'5HrzC"5C"[kr,g*w?˛[Gv@goH2j-?njt*l&=)< ݮ>=)ӞˮG-0 j*sn %IcU"R V;d]kj5&i/$^3na#yS̒+9utY} ju/F+t'tDuʝ׻8WF/+®v*9{a$maKT_gjRDf}V%Hv #6ڋbܝ_{uj Firx֦HM( b@=Hq2yQ: l۝*yMx𔤧&Οb;J `CbZqh ;Xpq<2k0ƵǏ0xp5E~4?` Vӫ} v6`a69CS!9П^'r[Lk *hxO6d+."!J4/JX:HpE0!6T1c2AY#[k1:HiIL_)Dw'q|-h(^coBs}cSvpisSQ w1iy\6I9 f3cBqi,ldLjBr/O-ًԶTu͚kC\J7TW-xzO*m &uW¡bT3`agvƈuKȳcoJhtDp.] )}'#e'$&-&$ӣO]-Apd噖~cnnfYjוbxWla2fм3LpM; Y`p<,劮%#+ r,p.cuV Mt'E/O.D\tl1vOox•'wd?-eHː7M;Oǻ. 3W3c=>=DR#.c#Mdj gGE RCj6fEjAGK09c}%d<^ $lfژ77bZD' b17LX*k女[Xw̅RJ@7V<^bX3~5"PV1c9 2:C^=0{B0 - Kfz#sa_  +ʙ,;aQ[g7 j`|1KJ9A7(h}6UČYa|fL9`W/@Ze"\9n#p~ .r\sl TAMލp\QqkBk;K 3d߷P2! g{Tlhb``f=l'R @\4MG48 %NX-e?3R?@BWB`hK] $2atuW6Ob/u)bC `ښfX*bN!F޵&f^HWdEx~.[W;[}sՅӂ<.^L d=d,6.t*bDb!$ x@ZՖNdow l 8N2Xm%V2cFl mˣ%#`!)GO2/e0c㱁e2Y)! HƊEYJ+O1ObNKqEc{џWE$[QDŽbX!3ϓ;ǧ6U*th}4³dKKL[ 0jf^H@8@NLI$xo;NsA N2+iF)9LfQ5(xǫ,, XéasʑHÀ ~ԭA{y/-'Dbs QߔF`п$M4hgN3ef"]')RAgoͮ'~0'#gEu +l7Qq6 QF@xXc1eX8v|xӁ[2Vt8daL #˜%fLBVHqd%ILV ϺM*Fxd3;nD(APJ_ȒA&8N7,y~f<f *h>ֶRa,)Z[ub8yN3Fȣռ ?+E߁aq@[yV|5ݻ(3C+O E\T/2b61 V`%K,4G30ޗش_*=n-j= vBa :5wA$?,_93=2)ӨԏRo B @b)`ׇ.ڋ{ 84o~ppw'/B~㿤h#@-x/E#Kr ]-FF CC\Ip4sBFRC8C P2zIVdՊn C[ D}!Zi)8Pߗ̶szc;Ѱmp?R!'CR}?h`3ٸAl/OETLY!;gRHzF{zVLg»IaSD ]j%VF!Q%) vm8TMM9%2o]}5k=ER/}l ;zUszl\f`R`)pmYK)l7 !j!X7#lOkP@xtsi#wU45]D/g"c%䶀~A3]XC{yR:էEdc3qWO xXj!to8*05U6 ׉<%W&- ?&˵%Um?YLȶ+p;AIyRK|r'ĥyn,rO;Y8TQT2AO`|9rU$/Vd{Kg]O $@4HcҲOpsBq S8.[ ^DKV[ka> r;gbs{?hg\<<RNFe z T ɕ%J*R#<7= fZ >#TԠ,(l24vWH.2D9`*QeJr'4 97m|g!cN@Tld}2  /W *ri~0ePcmG )>2(5U1K^/YOINGXM)cNȣS/>*Odw Tb9d% !ndo_|K;5/yD+w yfE+':ocV74臻TwG79g-ԟF`׷H(b+H_v6)`=|3OJk}\XD[BirRLJ/xyw>>`uW|:L;ўHqL$[t]`ts9#U2Nx {4-_@e>5#Uv ~9i xDX߻p%nQ [z43I˫(+c@jYwbめJ w=Vwf :N{(EJd딬x a=\Be Df9U*EvȯO98r"ʁG$Zgy ?.Jl͘GbEmvOeyqQ%`RACݳI8ћzykY{[6nbLgӞBSkt 7'B%*㷤T4I7<㦝oK8ҶLY5o;^o|dg; ]8l&3D.NS[qWawc_EaDA]$##k^Qӭ&4=`; b'e+̀3  @JJB_o_(%1 AlXXv{plr>g lI^cZ?u$7 tW> 57$'CNW"*zZOuL@Y)G"Īͩ+QK1g~&|mxd$ @ MFT~i?9X [@w{QrE},D٩mJ}ESya=`΢gw|(|W@UN5L⏭p v)_0bm܁J U|Q ;f!nA3k|Z=1&^qVw*~Sd=B a5g ,v#8!td׺ezg;&|bqMP(W7<^~As*/N9UI9k`! glCIzu(|:OAC yފOѕRTuY8Ԡ晚[#שP(gVF4Uvxj2 e[OR"d$rlǖL"HlQg4bcd N[ya}J+Yi2g[5<$Q`yL|j;-zr%nؔ N])yeԡ4%!oa-J `eSS&Vg&h*9}MHugbBo쐳ɇ1Esxa mb A2dXN<]@IG]m3YK2s$ҖFi.;&$[ 0K#srm}9Q wɁVPrU.ίp .ʘbwͽyY|#)`s){+u0 D O/0TWiVfMv`#Hy])"pzQ>)wˣ"O̝=ΚP| 9I vizOb\Ë]-wXӪx&hh+MyyHJTe 7j:^.$J&p]"ͮ:T* i[K1lG,!F@Fu5n@M5뺒XV@7>TEK9]~,݌`Q^ĭ0gY&|lO̢0xmsMX_p1܏8k! }`l9f tSo\3{<)ѿ0twxUUt }*j%ECA7qn ae;S-peYZNMelܮmx%wu'ֲ6U288 99|͜ /Q^ب&'< p+Eq'!$[j@ EN+NGQ̝Y2(d} Db#="PNp9*  q+d;HSxV5AN84B^Ì8v>Hc}dZ8»aac-! ߔZ!)NE4Ilje(AA%oJR뜜%{W/շUx;P).AiuGhZאhSH0Uͅ}#S=w_wo,렆bJ,#9v`Ma4}'aRКa|S#r<&%@ץga3PcF\gR[-"0;76zb^{tA1i~Tކ{9%5/T!C4uKV:4zTGm#X=Ntwꔪ}.pS 0V7Q+j+[Q~jEnN,@Xq8hvM7$ogeGv&je˸A!CPM&@L4Z8Hįڛհr%Rl$L`e]aY`.y;殫: "|kW؉ٛ#rO7]sKu1ZFe-HB%}2t$LM_ͥo1B;<6<7Tp]qwxI|Iۑ$XKWq %?\:K0q>}:$)!iAM64=Ivȧ|8];i^T%MpyDm%Ci~ qT\RGDm 9N}TydWq|*enL(pa_ہ~Վr ;w@--gWw[[ƅQQp:g@nfP =7;7jWC`d1TdוC]l9K" -*2A_2B}]KO&?| rܥ1i L%8S5.;hb!n*,N:k=C=.qkZX}( !I8 {E{LҨ1ΰ9Z: i? EA_@Ѫu=⊋^ yq>6y rf$lV nC@.Q3"z]@/$hf|ψB=JREҳNJu20 hSCxtc*2M 34וB_d^lty;PNB4@ѕ&~ml%H~d͚pp [z]{;$-lh$ f:yEv41 Y}͑u9&)(/{6Z6DҞ&8<y:OfK\.X\V$fZ=pMfN1ڬUI"!"y}\4w(#>'I<&xFkv0Ѥ N'; {γ<u/i⛫P*B}{(AsPWd]`nm M۳pV1F|S'۴RB(놙 q9ޱ?3XSLWf)=,7P+5YSHl %`ٸ+t'=I+nHƐ1g3u]@}f":k~W\c||Nm0iьDMd]9\nڱ&>HPWJ~}/2/)%~9&?)xk~ҒE4/&=@rs6h :9xC:_H9X]j =OsL)qz2GTN0SZ 95#.Vg)ߔ{d>|&I^+5< j.̄{Uw1 2#\TEGl_Ҍ4_KRxߟyaJdR_\5WabkTo{q!-7l>,nHbhanSlk|ʆ : jduCtߚ4J4!Vo&yw6j4{gc2YP`_V04]%\LNHnb+d䢺yܶ+E!"B#m"PB 7+W^i3~wAkA-RTŭDS dHBF̜ݡUSk.W0C(?L){iT4/ *=?`w }ë_ h׼=D܅}OMHNX)IR3iM#_aJ4_!]ͪm#%H:aDh 5cB՝BƜ^m^:t8P$@N :k'NRj;+mSE;"I+4_L -OXP|a>jo0Y]?Iy ֻν^Pt6qG律!ֹA|i}NA(xؾB@'i$K9vXq D&v_2pT[/og6޻*ކCbd&)MCmϗH(" eoO1R=hP]C*$\FKxcIޠvݮ>=Kw:)tSIlDm$I@-B(ܛdda\Y5$he-㮣;4|~ j7Ax#j/9#ra._.۵N,s['$ռb_:s+mERn5'5`qT TߍHZ""MEtTg :>c: d̴ˎV/p~ ;j(1ncmnS2n+ +{NlW5D헜[bÚ[we ,-N |F⫞jӼz0޲I*1_`y,T)Aa |rf _.@n^l8?ђ@OPjHqئ~:> MPT_ HP>i'$_ x6n@["Ff,M2 ?R9%Q"[K(GU"'{Z` 0q/СqCW"&;GZl@'jé4fkpSq\qBOPԛqplm?*Y"]7hlA} -p~ |%,-4jxPeX"e>iJ=5$-Z~4K? ,l)f_c nR%J!U]\)Rj:\-ȚS8x1 WԒ76N%mOAƖQnph懀fمHqn孙-,w$wtNa/^[ZEWV{ KDnxSE<Ŷݓۻ?_ra?;\Bj5әlPJvbob1ΤGሚPT`#tXs Wvb1a;. up_^5MRq i~݀wsr {oq[A; vd~IBg//bsP6ϗ?=h (?(Vy{2co2E&BSf {d;YJm(kqMW9Oק R!zpx2_ ~ K D0W 1(m?Fz[~_40AZ$~?QNZƂ|NHoL>"B3̙xOE'H̘fcR". /V^Z pM˚eg?Ltd]iy|~kR c;yggsfglui|I# huB6u>[nT`lSPڜ]vWpU*B?|ƦKevc_ƒ'ZoFrxcH<7@ـ%#0M=²fw^Dڄ5,ن;)Mo>2tMiFAy!#vLg5cE`}("L\&j>LJ.9o<6wDAy }v[Njc|pV Khŵ۔SAӐSX3m2&%ޜ@%1(ο nKF+~(O6;5W%N[r3NoK:`p9> ,Ar;'Ԛ7M PX(P=ci9lv`I >B ydӨX:d+ǷU2AM(?M:X)i*Kmȍ#Nqh, ~\XHZfF詐` /:D|!O@?.ǜ*;Pt~z;'#aHFqr~q '_F2r/zqQt ԑn(G l܅ W"9-FTrX B&Q*`.:LP>E"`baʉRu+2gR J[ݖ.!;Fk&?*L d;!Z*<<бc}~)56 H*[+'#0kٮlԡ]u8A0MnMIY%{(炠RrQpW?nh'gFERx\k_H*|aB qZRL瞈26Ņ[GNL}z^: gzg /!#5pkÿI~L@~(<&J],T%~С4yRw"OQux)"eMYؖ藰6ۥso9Րw ФPEPZ4;+ȕ61[lg&=ڶ"7|NU TrsxE?' ҳRJ%B7/Ԫ-ǀmj3 (ΰ!99Q5~i\ºV"֗((LچYRƚ*om w.ds,|2>ֲfƗ _jg[F`i P4 ϊG72.A 2#6K6D\|W/VRh9ۚ- ASnƜyh̀%M`si,͓Z,XCU}[%{=ڒu:QZG7.ٓ^xs8c <#L?cî -+oM YG FΙ+Mٮa @,Lj(6B}m\9h\|f^L@$vYins@'{9_ jFHU4d- Q.2?NzI%г#k͐<Oa cu.:t!Bh?Z`mK4|gW/<5KnLYE;uBWM ßƕIm$L1%ab#XbaDeq҅K .!TL߿SZIX(}ɾWQ,46萮1p>uT1K1Q?$=#Ӓq c RBdF lCID 4$)$^[u;V&@Wt:RI|.~wMDDuQ>Z\/ۿ+HU80k[5CAiB-Wa7ֈx1:By,8tu" ,[F_H?ˌowD6QsLZfKkIȷɗCqύ nr&7çO_z%UWM'n.d~0vrLTO>,[:G딥`1>(\n?˗LYqcI3XQPLsaT(,ɞb"~MB}?C1F%Nf/<4SDxOi $h&ڣ 3rQA^'b"2w9+}su3S?DYa$%5t\f>-gMt Jb ?U9X{Vql8.LPifVEzgbUQk:6qjpY"bux0ʅ$ d֋TMG7UrPD:*5hLlPj̋씗G Q "54uNѪMf+kQ!‹$*yM2ܣ}M4`σU~lZ->Q<я[jQu%#S-?X~Ժ1fZƈ/pXeltLSV_I,zzKՓG4(*C+otqo*zW#DnQ"mj~b 뷖3/W[T60[C>,W "a=k^V|,Q>B_2FȤ1NzSַ_5UːKQLd57j||1pՒʘDM Cr/=gG: oISD# ʸ~1l9Ec\7vFk lױ ODnW(D<s- &M8h~VamQ(n~J -)$+sӏ~fZ$‹[{0gfa Z݉_( ICf8U܅u wJ&$xV&12ۼ 뙿 qܲϏIvNS&Y/΄5S /Lwj1mGCϋ 6Mdۍ̚1w5a1P*>`UQDmd/I6eڌ1Dss}F`.[]SE_E9sxB% Yƕ?$/ner;69o(뭫 *А34n'aJ1"}P13Jz1L曣yF0s`TЖw'$~d!ԲpMWJ|eFB[i*}=j%ӕr;P Ϳ+_JF^ty{֗]:V|=}Q0"avmib^<" HKoۥل5k;>`Q Rs{٦ :BP"Bό!a{7w/bxۯ<ܵ=#y0ԗA;أ/)ӶPX>r\H`xzIGQD\<|6aklЀO\cPhZu_>0ke`R!+ށyr'N£{ tU Ǔ儞D'TY&"DxO-+ +|| sz"bfP*ESU ǝW'YDq-[a5-U$n@r%(늧C4'6]Q[Pi0V)OWߡl`TU(؃)U24PH! x|`({ LxpI[,n)orr;Ko!4kKlf B1~]V];K?6y|wN=6(,dU} s$9o]'[NBCm0Q*eb9L(t{8 J! w<{c3dV6~o"(+Ψ*x"QSNkMw+I?" (-NŹvO+tZ6~!Rڍ|M*KVWqX~n(ww^M(4/aԒBPܜN1Z.Z->Ij҃IPݚiW\]x/ۙ "@ RA*BsԬ^f_$T 8O 7d%:spOfbcc\yn" ۪c`v Y[1,<"%F' a"o %ѐ)J2S3YouW; FgjePZ ?K\+olMe9XRNECn@{j]#NRI&rG` @hF] ~ NǟX+}޿ K!I. Cה[]hcvFP1n}'7=[e)es^Uᆱm#/,'9:(4_6c N+OQf2[ASvg8K_hjkC”J(8gI."Ϯ(2v}T 1c4dA+U>[H~F|6槝Uho/GעjbVmGA+)5PcF,%S`;}R7AJ'b l#ŮBUK< kbg|.a@RHo+6XPTXn,RÆ{fPE Wd+ݸnO$Q Ԁ8 Ǜ#N9F+] 7œxKц=pHp3GdRFU5DC9@쭭L8ivW2^r\lA@%_ wԤY[U.3k`Rb߈ EF싂|&Vo‡fpxEKEN;`ڑԑ7[N?3>rV݆P)l aKlEdWtFWu4NSkvm /Gh8ٌ3é7|D^iTAsٮ٥)mJ> p&I|av/;'-Slt!g[(Q3δ5J P[C8[f`Dr^y 1trnLw<9\h?{:}LYc{/y¦|)}u;_v?D/[ kD4Oi;pSJM ~|f@G_>h]38̐#B U 0?q>4ʡU(%Č8#z>a{`9!{90ᝐJR*̼V>,$ތy;M w]( :NPO|[Wsf-fq 6'Qӏ٘0 s{lap+82ezCo98uRI]R(4#(QS "(mMO[q!߂XnAxhE:HOC]~  3}gD{OILTE8!pzP;z̥Bb IYtpY``M̈NTZh ~][ܮ?Lkc(pԱT@5D MӚѶ+&SZIU;C\xpA=1QO+R3H`ߙQTDkֺᘜ/QP̓AlBI:ڨ1Mɗ'P8so!"3w<+R[ro/f)P9ʳ }YkW[]0+$>Z0 W,^qqvoGn>VtCqIo`-3`Cʹ1DW^ ;}wleW䖱Y2oU51*t#35UC"[%Ua ]ģBBP$'iZO뫛z ݢ(k֋ %sISsܴNNARhwF60Cuoqz8$nlAT2DN(e:7ޡU~X1Av'=}=d~BH@꾗naQ[ =.^j:[Pۣ펖^α~=3soG?brj8ut>.Flpe6d)W0$4g ]mF*j6S&YY-l'JVK?Oqe:pI%v8Uvd*|N7  Y$~ӣy/ Pups}u+K3xEf\4N9OC[FYyG|>[/&Oci~l~(KXaYԉf{T U\L'^A wYِEJg7E"K3ǠM>hL$ə;lЗ+5t: ]=t}(vu \] 6F< ߴ͒2*bܩHh䝫³CY~ō*Z#Yq1f31i`PuA+ŻHqȔ=lKopњ87nYq)umEr-"D@YFZϗNfQzr"s#P$L I,s(#cY}lsN_V=eW(z)5\a}}v9]Qh5U8`g^H'Z. R3m<T=. z2}oĄWS aZGϻ%9h3gѸ]kY[UK&O:z=9ӣ|`;L 6 Ieb/{/KA:W (t9M,P*Ot% qF)GoaѱVLFɑ(nx*(ޝt_ê3/{}j.#E\:AH"n<MeW^%9n*:֭=)Zll{\2G.E*߫{Wtp5wu^~H̀7i45(QwS~ &g=ˆ@ ԯc&fGђ?-1d_ Rs㪶$=FݿxGx\a&PQOUBad0>ð7@!!ܞlSݛ`N>Y}~*X}sE)-B 42@ 7 7 G^1 vZ]1 ao88QѴUx8L Wկ}k h|1]k-|~{XM^4WqT%a`jJf \:k TSw᚜GЪ52:t7E1K9UC踍J]<ޕ,OճMS!HZS6?{0p+H]93i Ϛqvja‘GHVTEr)uD@ϽhzD1ks-H?^↢V+V{ѥ6zy;}54J챷BM╕Jao'Tpt8T{8pObU⌔`b"mʨ`<('*3<ūTANoHP^_^gp!-ϰMӝ!Xv%E:MƱ4~ c ;5֨yh b⠉u朂L+͕0 Ø;a"Q/3g[ggrn6,fE뀡j T]GrNdf",#D3M+~)A2d7\pCw-/G'6MB?,$XݍF0/wd h Cw_} &ad޿#}5$:.qT3WDXĿ:ĸ0:xHqxWx `g@^luS dp7 AB/{+=啹Tbs TXh{\F:fbZ|J|_".xمƱ`Ibz;0ŕz%_y3#Pcn+O筃Yi᪟Yd`/0\w`i6w?NVݢ+>7 |\vEcO_Wo۷HcFB` ,EFOoI%Qׂ Zύpc ^2Vn~(+h;"*tA[$J"hp$1-AWW. bjdm^O;R"Tp9211f;e"yqxbam l$:Qݷ 쿎Ci%tU3.Yȕ(49 UAeeG`*?yV/xu=C`Mrc\D\">w mԣc3_C$\&zyy]A""o2Ic7KK!ۘf -DE)"hl_痴)uuM%3Z1l,*Rvb r%m aڜHa3յ%G*s'世GDWT}̯߄m{`fWY(P=cy'=iu@r S|vs).ovv}&Uw3d6w]bD$q0cJ+9LE'wйm̕CYg> 嗩Ks5%_;B%P`~'x$#=z+ǃ|K|B1ÙZ1S`'"FH-Դ@O]'}snr"5J-@QB-ғ/D !FtKlfDBZO"R0xSݪ }>IJa9MJ] jse&㄃hđ0̥R[w &ãJTLkա?$S*ioWLJ|K&A) ,i1ƾ䄉c#p9ypUB`t.Z>O=[c{+ލ"= iLXU\~^@oe(Qw_3'd{˰\_h3!\ufoQΆpWe #Q 4z\=}]P(߆J(UM68OcN`J"R-Z4IOKWIc ϴӯ>M;>|*y@ƞ줡k̔&uDŽ<ο.<Ɔ1&_,~"yCqg#6҇r7"}T"N NjSA JM~!l($VAGESe$v?dZ)jX}_P}aT8nAQ!ل=:f4&O"K[,RkB hr+܆16p@V >Mt8!])H..<Fj 1KQ`ЕLY~@nfqvM(P+~ˡOsĔvzj2QcʐE?q.{} ߳X@7їV0)jH*pm I|{16\֑tG71:nRIu8K:0nHNm4/qRf6I>9ݼMv2dIh'%Lo{hF)y/s}dhQ %apt3r(NĉkʏrP8N5#*zy&u'>(y j/o GX/rXhxg7loz(/wZn_wSϣgXu?&uu~S?5 3~~{322`)]b5lM ǓS ]ߙ&Xw%'FC̡ڥԜz#h[ a%(Bc/ V|MY2YX ]S0- 5 R$"n7%U+~!I^;W Ns+_"Ԗىz FXmI:z~t_tI,kWLJ nNQ~JpdB0rĺNQ!݅y!9=3rnS?18AOmx3^`6rڐP: >ap5Fﳹ>z\0L8 p'M05W?6Bybhoq߯#Y<8bսLW4 kPx4 Y7eh~wjq4ӌ^H~u +4p]sVaK@ل,$Lq£#(w5(&oLՕ,U `Ggb1&$d0,.e61RcC-CtdqRۓ<+ UO2J~ ĺG4-s=5[%2 VwI| 6޻.2XBu2Gn▃xO|ԒBy0cMǚ˒ݤw;`HHȺ8s+ts<[b;F1DTV%y0/2E\#h#kuҽ%MK*ؾ}t%omƀ;ȑNN>g_#xC SR22A;ּw;_͗Ԗul h%.R/`(cZo~Z_=u@NdrliL]\|Jr1CP+${.$&,O\R7R= ĭrrjVl2Hv'Ӽ?!6RuNV4A{: 5(Lk^A0"$ξB~U yo95]_J[r6 Rq%e\ R"DC+׭@܃Poan O)qpK$()Q 4Ɯy 5->-[[<2.#=b-$iEoDzZ@c< ,79 ]d9T|]y?3 w>wAmdhw-8ѽW?8vv=|5kU"O T}oڹCl:+pmv"!M( .A/օ%]Ƒ\}'vE0C* qNcL /|`l*³T4?Ͽ2r4rǪ16_G t0[ryB%E5$5QFm,s?j#ɔ!b'}*'e_xCUk-$R+GFC"02֪eI# iƜ6PE'8 6PPOru5`Ѱ/@-jm҉].E%1!8x(W{]a:xjP,`eh <ۗ^^D9^&|w#_AO-C+PUԙ.;0qaMfeN7J BVLZ-ϸE:DSqd]++PqkWPkj:"ll?ȝ}/ / WQ}kWɑkRsgðt59EKk&ӝ"[tK}Dklh.`*+40,Zku%: _H# J)n̔j]g8-zgHp9"R)&⍿5&oAQLJFl~3Wa } V"ؕ2 =U ƑƏ!uc ~Ӷr>ָ$>msr{="&rUq4_pA N EVY5[7niY-9^/;TjcV]ql.S؆ϣ,p^.s0Q ՗;[sX\Pgj葹^]^4m Ԥhq>LҚ_4lFG!Nʺt*dwˤ W5$3 ~b| > ze?e9Ά8u Bv۫&"70/H HS5 ``Eߺ8i(ժ 1&;Fo xc01 5譒CK|s(yJ(.-ep.%l>g<1I%?( jA$dkz5y^yQXEXqfuo 01Wcspgd4"ߦVCFyo2ٰ`Ha.{ _)G'd:akˋI>phdr̘Ohfp$,h1%go' AQPZ~$%3 ['>r /Fv)!Pdɠvz0Y3}R㰵/u[a1 jLJ: , L3U80T7uEt5sx׽3zӈsJQzAD/0$W5Lo+0~M/|Aע JR5ئ:9 ‡wj16Ý:w65#M%C3ۇ ߨyy VƌLoO=OIp'Kb'b\"W'VNw=\ L~5ܼLO}Ǒ?5vCӟ87Ήuŋ uGHuCp`ػsb~.bX`M7Ռl5PFۄKdE[K&%>o7o&CpCxS ?gb8zD׉4xӌ4YN# w0HHbo3KGNo2&Vj`8¶M6"h-(&3%Υsb'?FQ3 Yk+p|6\\AÓ#YEp; ̝E&ٜ9j-)H\3AV0 }>с q޴2i&H#?v opw)}PWʔitjBr={HUahϚlSs- TOqj'X.`OLśôC 7A)PXX9~ woʕzs(7SGPȼ D|A9|e9յ;>mg埫!GӌtgéLTbBF);6*㓠`Cd-Ewet<ɬPЬZp%%LO{IVA Z6Adue2AE\w}4~$foq# pQNI,w.Y O˴A Br>.kQd:;wUȭ{b +fܓ/v0ᮚH |4N\;&kA\̼Fl!]S$/5׿ߤ Fǜsճ C`\ButЏXa;'% &)pqzcٿ+Eb;'0YX\KQL(UX tr#Q_#R~$}C{TxdOmc2d8X/D 8hAnR{ǷZ[2Ż`gk̸GG\R5+QLx'W/K,XmKYV|w\Gg+^⚰w9 X#tko^v)ǣVyOMYOG1KSR@[^ Dp@Qm\IP sOE",Gtl D}VZfu^sSqŁԛCwG~KhuѩmGΡK2E"zY q@$̀'aHsR%/ ^@C1gp+ j.hM~՟y[ IJ8"r|ސx L@wx+=(?O/t>}D' $C!a4$cK@▯؋yݖm%H|8$dI/Ǎmе(QPl+YZA }dx$-_P'|lmJiO[m75v>b\$☥b(v?3eIrZ7mR1+ļOo& g*+_VtYƈF62GlC`.HFrXPWj!`ߎ0xAFȵ?ohC_t0yJŏ F(B#REeˣ+db릕^)%/)7HDwbzg70Q#I[9!;e-f1 uYy5tQ*0,IwuAԘ(5]DT}Ӣ1Rrꂡq8_B{|~|u% X :=IUj\=,.U6-^]Bu6AWAvSp x d!ʞwj]ڳAWfk;#cX +@= iG/ycO?P1\qp$cxZ0Pn'V%KU0N-Ӣ+F΄@-k;7` 2 {wmߺkY/=MC?=mYAִN݄[Rl­U_wauژƈbX 7~뚙? mQ!a_J)/?J-T--YQ[<dn]li\_R9I8nLdx ͝ 0ń?8mf!f$sq/ԜqlzC T Qe»4bӏi)ARx7:kLı=&wj7 hb!^x?~8fwJʺMYLLΞ1Vr~H* 9JŰ% "yLm9mbRD Mc֡8~dW2W:i鵮M97^s Ne箌*1YvVV7i aw Xy']sMDc3#>7¡;FrFm)3r#!2NbL[ƶ?^E#<>=1A2xER)Hٸ$M$=(8YIfDM #fʌ ̄.b3cy+zS׷g G"nMK>ѿ%A1 ]P$azۜx\]\}X&ɤ ȧN' )dC'{%KDz?x}ra!DVcDW^HƦub~tiAiЂLt4VtX03QHHʎ xE1N.Aݏ._*/0zM:jLt@em 5Omg<н~FJ/$t#<4!Mb !m y|[@4 `#/q ' O{:UuJ8'jlT2jf|4-P'$zQlTi(_{tƇz5_X60"׻[Go<):V!,wA\;jHpxO 3l@QS q &I8v (Y sW]Wq#)O'wC1erǁnh>Y c EycPG 9{ih$:Mf5BK=淴ʔ݈O?1c\zhXTS[ץ'6̆kZ: J1P7)D2Q}#߬p)\ml%EGL+ >`3%`k-g=+t "ƀg)= Euቅ#ؿizM2 V&SK{ QJ:@<'\ 6Q ivY s^ӎDtQBE|5N&<:/7Jm!4 ɼw_'2qy$[j4uċAV4'Ԍ|׸05'T&#hfhB4ìR'YHOblS§ʻ@ɍYTe9p"mkL@ B7.+׫P3= @6 [*.znj*ՑCLUq׬9ϫěGɳY9SaUȜil̼вԤD֘"VĶ*eFrkGmУloe/=x7 |zpq,/d_anY3 @n"Z2ւhdap/!5z;J!L3E|AW(Ą:y[o)yGk3f;RAX2[{V .xo=qeQ{4NNnŵ&q=ucg?ѓ3O"k|${4<0U!Q6 xë@QLY;3os66 ;<д="D>4ɑkȳM?=&④,[A o]Qi B8HsՋs*R ,ߢZyu>Kjq9;wX4߈]i6q݅֔zoo]~ISUˆ)lm\x;8?9=vr>$NkV[u%Ĩ7' ] ֧[JD|hۯz|ZFf UN2sҰHեWDXn7[޽+zn6% QRdd]*?VG>VMny!8%/0Bt@oG/U?#__DŽڎt%Pxq}m!xޭٟۡQI{*/j 5qUnL> :s__~<,-2dIHjc /o(84=-WrmX !8bUhTENx4xIUI~V hNQp ёQ@X3-O@/J$Wk % Sb5܌&>_J+S#'c hݛ)4;F4fNg)-^~f \-hk.xBHEޭOq@[iGtDT%J!elbb{yY&Ў!QSK]ѡE:'{E. kJ XfViTPĬ$8n`4Vj,'0zMfB)[z"$諪4 9RwIee\ hFUy5kcNI9a(uAIpn_q'sQ9 wN)#'GVU$ٔ,|EZ=kE&~ȯA)N[EЪBH_I-'S ^]ILrwjdA O/wY6 :#$J7@Idu$b>v=іp엫*|:i` r*$BI~%kܡiY'6HY/AaaP='0 {·Rvw[؝KDOvodqyDվ  T_ߖ,7bNmEfaH\6L i&e%Gnb~9k;;lQI{8֚vfO09|ѭ{5ޖEQVs6}|1-Qsӵ{qRuW_?0h Q(H6|ԨuEVg]s*"bxG1+os8˓lc \[X\vxȐl2SF+VZ̍gPdX!hgb_OV6TXhDV WosR1G'@%v㠗ﺬItC qתK=G@[51c?2β}txO7m-z!l~6Y\2.բpZ&Ѽ3}nU#5jS48 i&pWCN^r\At&|x YgQF(>TW*;2dҍkt FrK*9נOOYDA$GL`bNz Zz% ^28~Epal76 3wsҤ!l1bޔ0PV]wujy4HVЦMz;n#tQ!"Z;&yF Ia^7Y~4 u"CRdJeQ3^A":K1Tʤ }zq76[@`w.%,*k')؞ب$(%n!T @$ v6_D.xY7 @E@/iX|x}`Oou2wFZ %2a$6ś'8JZ;vprK}`vZaJ1 g#&W:;}GxM20#ݔ L*X7mdzq[jf?{Q{ m!Ҕ&b5v`=v>e Q8|g<'q{4ݔ\ B?њӇ0SEA%)Zc[[(6YY6&Q~Nd玞=n-fN**C^YoXA.zqA֥W2m,HwS@i8}NS\;>B%o9DTFkDx Sa\9e ҝi2lAǷDZͻۄ{_-ɼK 8qg"qW*єmlp~uLZ nHU 6:M\9-Gkjz͢' q=Swb lA$r#f|V Y~i6yh\WD&iW l-MF "w?1f;8H&#e7ԑ28NAھd4l n6Od|AzR˼yfTUOWk!Sq,][nuR6⬆\HëSTxI4@0Dz.73&Dj+X^<2B,;u}L UMU~WV$HQBJ Ř?HxzOdՀPC^+9uiML\VBN9Q{Y/u4գ0]N>OQ}!#>\246Эm-V9yI5Et::M0g!/puA2NB~G.djk[B;g,A jg|R]1G,b?vzR qg*ij $ =V  hz"')pE:Q~A37w.A}6(vKi_s1v2+ǎ%:ЏaN^eV[mHĚ@RqӏDtFG>8)\_T˰*X6bPEi,!Pivxڸ:s|ȈݫҴRBxB%O2cDh5,OGqx@\0AN}+O+ ߅mhk`@(+PmK F1}7 a51稨 7HC-d oNon"Ĝ$:4bZ\#Ib<[R̽kӗC)J1ĩZEJ z|g/ _.\MnΙS#3uD8;k3 =74D]N X l QKVUaF JHM@n-PaѮ)3e+ZJ䨙dw> ܍:R¦wu|g7We;tl?ߦF \]Mר9H]&hmWQtԗu.7^d6 Ѷr𝊜8qMƬ@[<V(li)*9{.W9H QɓJosx2"vy!ގ.[^g}E!fP%{wD2& zh|teg*c44#ZvD+"̔-!`'2QDCU,ۼ#P曀y]N^`Kth);jX_Kx`8DGv|Pj) pg[jӆKOK[xr;=Έok>#^'Ra;5nB5Z.@?(yB‡ԃ t$|v8Zb2Iǡ6ɱhhA+{0.]9ΫW\̟:.`m볟`lnm=g>B} %_c>B{Z&R?7芙*9=[Л>C?q")qhhB}1SP#2 ̥h+[dLA31b0\R|a˫ $l> `Wt:tqSA/]ZP7" Tۿp~rzbZv~?t.w| /ٮR@)S=nt\5^W@kh`w;B HdEDQ} PS}%)h`{iNحtQ^CvŁz8rRv)1u` ;S=4+B8YbJ{.pd$+W%qZ?{VM.^깁mov@kx{SYcF~ У [A͋Xs@Ҥq匀4]s*nǘa1!n=(_'#TfJh+|L1if TܕzMexf}[LVBQ䍱, @X;tH.ZpS5˞h]g^Yo(|)8;uNJRsEpcwPcwU}f'TS(%e6_\rޮn}qog!t`CCݛ@oZC\tq5(6塢,@~y6O냁"ߞ Ҿ+),RЈdߢLqb;4c!B WEﱜ kx>4r[o3ΎI ?8hFQ$CcmU[Y=~Fv!㮅Ldq< AlE:Iƫ)u&E=1߾7>ܓAe/7'LOvqYxL(n˅X'f~}[R8pɛQ݃¶ULX>* ],K:(ݦ-it+ye! Vrȴt̃42uRYeB*e8[+ c@Y ǗWKo8[F^d QXq%.9h-uy8ON֔,Wz l./v2(̈{ptS?jdhiN LUHg|Fr5abʲXX* BGJ[ @t'T'"BM6ȵ?>JtQ.lZ7':&YaBUn92hG:ZtoNq l3)qC}X}&K!6z6'2k4ےMIKSliM;+1fZێb|M}$+ ew0~93N:@~/S =EIqpXk]qmwUrсta~ TEq&9䅁~"sF:Xh@>{0pk>Ägu؞9 w |z&DG{V(\=ЏI!JK!g bb >i/T^E}34=Q??%_J։220*nӀ!xe@Un AQ%$9B6 %E}kOP ͫE/VXMdoVquIEkڏ}j!U| zCCR\~)4wGx(-"K "k]+>SvFZf&=a)f&U»+ h*) "ZEwmZؼ[Pz'dZ8]_exO4U`;ؕ'5B28xD$ImƋL>;,REv!6+ ő RUֳ3c%v/H y6lVA)g~K{ O[ d0h$0b]NpE _,c }ʌ|cQږQJ0LD攔>ڻ}'_>p*W4̵m庿R0jl8,DU~2r1&&4podR, ₦whDRG@V^iYېrD!)_"SőB7}GX c{lRA!b2D*[] 1A^~^Ha5zݺPTyr!%j,[5pPֻTms?NjD'a{ J^1&mV!b' b&iB(Bhc\Ng֜B [U&sa,ýܻnD{ҮF%P @K(UmnhL:_RPq$ } $!`}h#Qli G1BkujVDˮN8"3/|x-m֞$&ZN:GMm0Ty|;MDmcmB}y E2#_$kM+( 2 8{_aq.>iEO@J-dgN_ğ pݶ\eo&aE<XIw`͞EZB4#-vI-'U%N%5Gr{hDQ+'s{ K;hO("cRr;ϟAA<\W ԟQ>Y&Ş1a*HC*߂v'6AO ڛM_. Iv #0M~;РO3N1wyn0&Yi ~urjEl. ^\n U$E6 ^ j5A9$әLn:CExusȕ1;yNY:DI9e,Ŗ0y;jlZ\k_̔%ǥ*]%?f|޿>/RFWUWOO] }29ڜ) ߘ)_fyTR!)so(bO}"h'A knJoOwߐS)'+}x;) I!PjPO>$r`àTip&mV ?2;B>lFq4q6Q8`?}سǛTpw̒ǏO[0:& ;rvD5JpWZ qzB5#MEUCIC,R ýy,1T[({5](}M CT8C¼WY"b2x'*6o;oy\ ֐4"T5p5}(;|lV#n3o{v`6?:I慼`ȶ~?{ Cp5je=B;wߥ~80okgxdWǼLhŸ޵1)Ze,If:0Gsy` h-ϻ|=%,n/J mԄQk\y=oS׊!66tC*25sL{5Psи 2%B<B^p=-$w swiJu D+b0B>̜ V-F?y sR6ɪ_{v4O5{l0 TRBc2 %ݻ'10X 0{(!ܵ9[z%y쪶Չ. 3Z̗ =|H.ND'fƐ&x!+tkSLżskhC,'-|8ʘs9>ltNE\.-[Wv'bpvn Km_4Mh)x |)NM1mNoms^O99J khT8l!PVjH:Aczn O&%U97E!4W|R$![\Io7*ȇ@νnj@`Iٓ^sjTlUD%ޘÆ S=j$Ӎu͔BTmERZ:; !EjKtISE猲 0Ά%ɖLu}vzGcQ}*LD!v )diK)/WA<1l `?n}swEu6DG6VΣ<0#ga٫hIrR#ӢO, *VM6gQU1( I- o]\ɞ"p hs@c@&Ď`ΉZ 5aTCФU8|?NOGQ(b|r;uf3"!P,A(Fꂍ$uH9\:hWX%sa᎐FYӴ`(}k'ImE*s32/G b8=ɏ_Py'Do8P:&3UncgDiҏ,rg {zl>RS}95 6+J]nÆ=Avt(Y`p?ndHS ۢ0;L Z˭vxXT]LjIT*e5]ȩL~9^rR;\mjL;ߥs;b o=cg'ΕgwIx*ӛ%56o7+"J]4o5&nfڂ]Cp,`C|a^Dg-QGݬ׃ĞT`4" >9,GpW:~Y˶b(4D8`~0p=@*@Hk:)'392 I=8 1 nQ(.h92-jFHx6bc/[݇\d(Sh/Sy vM8p48-h)]V6gmEEчKmY,*DyU#PNm`P}R+BaWp ^{rRGpw@)KZ ^I8"1!W/tg@+)Drl ?%xȴĵ3٪g{@D 1*FZ?jF&H5ՙzLʟkL4D12z8XG_;[|S3uz>N;&j E+,Rb / ED%})3Vd]8_,Ỷ/#ʇ{rIgՒ 7j_8]Ӛ|k_=K' &Nip| %3ݗg%"vWûa8g(,p,^[baKnVApX?p"}8.6zMHSsx"u(pf[ܐɭ n3*W';*Lf.y-f]RO~qUh a/M#tPc1R_c٠ŔyxHI°:G #6_YN=9ػG[&Jħ!*M[,f'|}~Z&QAĀWHcS>![ϯLQ- f'CN/"XF*wrZ]H+$SUXkz\Իc#e`@hǭ폎{Mߺo ׫AĠ|6*k!0;w <$ C v1Mom}Tʼn4F!u5jk^T8['>כ9 @9"(:H\'qCDߞ;˧ W/UCV Tэё)qЂƹGG}oR%peZV9MbDN!QZoyI PŤ'08w4rӨ"g SgKJÚ a>pg}Iee= j}T N|wՋબ'm$=U*SQ= ^&xi?d\{+([SqQFp@ tVЌeKsat!ZM`^&ق.UctہeمZo{YW u2k$mZgr{͌N?8vgxݜ6֚y^(שcƯȇZa"gH١{Wݭv8)ޢ5vR~?;ۮ/V?œ:Ct-4%J U é& 8~@vۭlЦLm $f9§ENX/2}i2dh#᥌.ѷECjpc@s|G$_x %DHGqߚW]oVy]1*WEvPjJ ׂIJ|[l8 -^NQ{K0eh=)Ylֶj\͌4̓GRSM:[N%:5PR8iwr[)No/| Qwh:&́@D3~mNyJnzUAԲv^I`Yɟ IN|T3hȐnj c9tlq݉B-,x0 wk'`ά{6tG+4aK4ȉ7Xa:Q{ .<߅'xOj’Lد GMmƶInL? M4XZ6J(  b>&f[L:~Z5%cX9P&mo* =Vgڙ:XR D<ܣ{ZfCض%EZ:3v"@S`f5NI T,:F'q]aTWTJ~)ik"\ "<6 Wwhhf%4G[@a2O1kJi |MD[BYI058c?4LB(4e9;a/ m+ %vB_=h?Wd!:>?-&!*"S|HX.Z1?D2Ob8+qqu0_KAҴ`8ADC8 @ah:o(Ѡ)<;)>蘏Lǫ)3*Vzvǃ W\,뤰p,FٕRUjk|yr!7`ML͹١`֧$m/>Lٓte4V"1D?=1T mY9Tsꂎ[N!clzlҿ\uqȶ^|YJMkeԸyj BGڦʱ+'UΞ,v&PR䜱rj5t&(w5vu t?P:1 vespa225wIqCl략w/qʹ㳮DMi:icKeZìS{z պ }٥t6ucGՇ]'TLucBC"2mkAK*?ASӳm4V$ ZzDTE3\'~d0*@8DHwz LqyIY&N]PÖBG!)@bLў^Kϯ!9*yXbW#xr'rp3l%8Kz|R%=7HrٱerNx*9\yOlq?M^?BK  K&?<5PSŬ>_o OBA>T8{l@$`8E~g `s8;XQI-E1q҉_0qq_Pr2,b~"-knqɵ.vs9D2]IWxfGh|3ڮ|?g䇖JRrl^ϽޗN[=gIduQPPn)p X& [p') oZog:e C6̾B27@gSoc( 틍fdAJ & WH>(]fnvem¢/9,ՙ Xq) %x~Gʤ#`tQTm`QQ$RT1:ՔE U%Y |pҀIU7kH\ma]'>2%su.OBƨ} >5 l2.RPv5¦2"Tڀֆ7]s:׉a:S+}+5TJJ{۔X{koȟ=0!7ѳTu{Ƭw%uY4~0 |[mm1|aBISƼo-!jawmVvа&uz vB+kZ=-=e[ O u͘YuAC D%Fã!ٽ8;2.riXM" tZlf0 *H̳Z#BO݆` X M 뮗9p?nTL3sc`4%%oy)83F2*LQ4?T_?T34/{^-VBD.$|X\KZ|Y# z92ǔVt=;-g*^!e#ۭwGJL>2Ɯb}N|tsWt=S=𳒭,\(ki%WodnOᚶsAOP )U VT˴H pY6f:#-kcQZnwk#kT_WݒK|\k҂Rꄧ%ʛ`.BŴDLtɸ8 8e]M#4 ˬ4`2З2wtz=KAUD#eƄYCu,-&KXVUv;9sk ٬# K"YMr) yF.cY ݫeƗI6{$]y5 a9k@ƭ^8o/OpTPEe#JA)woasJ0Uȯ 6-׋ѥ?0\e [`Qتh9XrSoRf_cy9ww~Pv!S nqeVF:oYGދz$ju[)~{eƊu :+l %}ײ *{rD1ȦW2.8uH>Pu'$6{p ?VTx gN#n'A5 1$*5 2uI! Kֳ+gOA0 l܎?{uhk&{Пf<F3 $n/#Ϊ]>|’pxstw[?C Txx&EYy."(u1+k--cڵ)%HaʨWgoIz2Phni7{e6ĿbyR:⿷Uuy;9ܢ)6 qq*ބyϹz}鞰5[D gJJR {"R¤@0rڥ+!`Wѧ"&;1П{/*1W4-_mf=[N<߭.LA\RԶT1m}y J Z,ქ7Oc+0' gn=f7;zԱVS?22@!ݼQ 59ߜO,&f<.?pjB*:PUFWߪ+@TE2y49 W·x/[: *ͅъ ,D3@hv$~ZX\͂|o`@j6CՓU832=ۨ:M\Dk)fS#{ bV;(NjI҂t=~K%g{]Z yhbD+V32,gu7Kk7>qXc 6vNVĎAh}.mu+T'𿥣U(VԸ,0[ X1.;%&rYid7iN?+sVD< "6Kq7(Q?ٿ#Zґ&K(ԓ2W4ב-s{!1I:C?f7`|F~M`AL?QQCC=U ,:62tD.C0HϹ(r _L>~OI i/G7,(3T_=\ :c?e`K԰PRj{#z2DmȔӟpM _ƮvJPtF%6BSB-&9X{Rk/PwRATctF3ܐJmd/VA澾OG@b; hPW=m la -D0| ^KAy1CAs x_ʰepH(GasR"z7fG%7b>kR`ɑ0y2\$aPoP/@4;sd(pi&vY40J╯+DOAXa^.&;/6O;I= ȶZ.#aÊ;l&מ"D[8Ĩ3;.IQ)j mYJxLN<#Lw";`7D8yX`,Л7 C'G"JÂ`t>ވ?&pcZjEly t3= 'm'tܟ#O tFA06 x-)#s*rZ[ Ekhбl V0/.W`SGE Eu?+wkTGܦ)zЕWVWn-=3e%?V1xH&ԥ27~DuqfZ ~bhwuaw-0Y A:Q}r#%FJֺ!i^U.@]죢 It fDQ/}ӅٚC 5Z=Icɟ['8Zj Sm(>D@:c?ɞEOXrdiWk> նOmu%O/ /K@0tlt̢D?ς+E͟:d'"C#)yh[.WxB?G ]Cg*6*jĩq"S놋 8u`pjgfy>){f{I)s'vBeD,p:TGא_AN#~IdjMʇ֑6l ^jS3ƧSd1 -e;^[^P;TƊLPo )mw\)屒ɾL-OP~`J2mar/>d"1hTXҫ[U!C8ehHO\P~VزAgvp=%F0A !]~GaXt#dl~P ?Q8J~%R7};s|r:*# mCg10U d^V$V+#Z {8:xf+A R&z}3x{)G\ЀYU9;4zV/Ȣ%!+xO nt&['(EwH[KdR~ˎ,5İs . d: G Vk.]=b/̤c0X^ߎjO^5F2%!EO!2G-veH3RfoL aN ,a3Twoҟ=Rt*gNbJx'uO-nKi?`ORo&gH?0l:tMw.T*!B.BT[Y$p)i8 ~K1*'T@ =Ј,Ǥ]Oo$,DyW#s#kV>;ǸoV돎\%ܷL&Gs!._fK(džt7p{IO+de8b'C0rH|#!)(oW*D%RB#KY4!bˬh$R [Wgٶ 䇃az(FY('v)|Ddrcج#I m3UGAi}'R|ߐFߧ,ARNxf4em8,OA3UZ  bwR5u=؈Q?cf`^/ ~L+Q~o BBʐ[RBtӤ/nVoϕċ P_h# :DTKǵ/03}lMah=,#`iq띎 ȶ,\RCjboYETD.m3Mc COv]7g.Guȿ8gjqiOSpEڕј'|x־({zs15Y|w-'2V۽ mlhV j\\ ?1O5J~6i#71j.׌9*vq%AgXT|IsnH`{P;窏'yQ' zU( S{ +I$<嘛)DzG'"_Eғccg8h΄2ddN1 /=K/  ~胊~%ތ[RƒE m&sV+z{?WT>Ani- ҌFHKV*=4MۘG#V6δF9o陆,Cm.O"“vtaIܸؔhM'K맣`oK0B*}*dW68M}{Ѕa ЉgYK,4mZю)ӉFS']i,ۓٮt<['l3˷P>Qłe*<*'nfk6Nuk6`,hT+~l22!0vJb.'"ʉSƙB<@shhXgD&lz1DEuer$Y6%` 3NFg܎8ʻB|IS~~Mo>`@:rx(y0&^ilIM*ɒwTu! + yfW |y j9fOCXA }=v}]ejɤqXvwre&Q]ԓȜߡ?*A9x!4Hi r+4ϢԖl^]%wSZ+~pG-1#R`5'ebOjCE^p$G%sQaK0ZJЧDW+ v̭6yx=&\>n~7Wӕ@)Bk6n娎0;-ayod(5-:A'Kg*KV HW&1}H V馭$% I'x36-ppF I$>,Ӎ"0 I%?"!:T nl rr_I8{?O!(J3a=>"+Zoe4a¶vAlMB 8` e'?cLu IAˠ\FU|aRr7ZwUb _BpTL~K !%)m- t+a8뭈[wkgKEBgl 4ZwzT {QQ7L M~Q#ʼndiTXSh+ &QPqvJC>szQ*bаC"KjESWYqA>ܚ ahdG]|Sf&@.1/4<u C?_ʍ,D Sv~GNM, 4-sP,&wvBvܼAαB<59^Vn7?`3Z&pїwP,(n',* +)*$yS_CUape!#䈡N}Gi>j1-c޲ҞZWh;'=:2L<׼]K $ɫ5ymOJA4) 8(+}6MHDoH~!2 sVg"cPHZփ PwIK^-&gΥcºb0&'PBa=a*57q0ׇej1 j))aGvF(i(RΨelPK8ƕbxD8b_ׅ8٧C#D S2BfZӀLs3q,[ BGM %{3 i1#Np.4¯}]y>J_SeC}|^aHU43][y6#Ń(>@m0Mc{{{_Ͻ#32r*}19warR=~bM.v"XgwMlym>yVj2 a .W/w|}.) c4"P}ynLRٓ[𢜰vDߚ"yQ֪oJϮp:~/Th~/Sio?chd,7 a)[HkPc$//^e$P(zOK3430Gy6o)/l%OpYXS4N!,YE&oͩ"ن.V"PY gICd7XOO9*^t,-wux5]jbC*"B>H~ieH{M2Qnf {yqfՕj  L|3!6^07Ow?O45uOݞhԋbq=nY:GqJ  Y˜G`&fEgGjCfyvQNl`۩dqwq9{ ;ƺ`(7)׊Ϩ״/[~ȵE *Z?GTxk럼uWE- q4Y̠dFC/@Sο9 jVںPz?b館ݘ1RLu|n6$\jf!UVځ֓V䥆E4zwlPhrVq6uZ-惇vɖ$$EJ$Ze/!FW$F=?KV!̎kg% Vs*%f)⍌pyc>oK/ _g[@K.qo@}ԛ4AԒd5%;ĵ #a4P좏䒝Z?^D/eM8YAZH K LĺMP[&k {1]xHHswCsd[MAt 6̛c:Ӄ- E ec Mo0P8 RǕiѯZ6y%*JFbQ$Fu$k1cw & s`k so:L(Y!`\챑){witm-E i)=d(Wjf4K/|O9kmlfD(n&3OEx}fm+Nrri^ UjT$g<2c'j^'<O犕гl "^ULGijոl}i~5 ~r '[=5b۫˼Z5m04[5 WRB1De띹 1Qhr+|o?sRzjCA_+;TOgNs_[*B#dbmV)_VCv~')Ju=*JBNhcgd28$9 2neMgJNXU:S4E D: ɀyŀÃD{ {0"zX1T5^Vu(X'OMslי1|sj;aSl}12)8p+Za/V4+u^YNvբ i^dA(Ĉ^ vLZB>b`֦?>6* ^Hu+WJXVݒPBFei6}4LB,E&n}p}=&PE#T@EueWl$irW'YZvD&=06t=TL91%p!|9\ <ф݁dB8wL&.qr2t}} s [D_pCx90Ѝ=Ո SS--$$9ѣlMuQuKB&*WpZ=X[=.^XrNqV1)&v?4Bmu HJʽԬQ]{5yd(&* 9}llR F&S"3}㿅oF.PLޯB4Q?W?p>67Gbw,51Qfų؅dpq VWDIЇA48vt}LXǞ\0 F4jrBE Ip'G# FgK4yb:1%C@A`nㇳEt$Elz=\s+gXnaqHJ |c#_ aC05bS8p.jOa_cmbCt#r:w`X,S=.6׺Oa2K0{Ѿ蕒1 'ƍA}jgc*3I81{X*=DBX ,=ξщmxXEds%Fٞ`T]r4#vRʿ| OBV9l6QʄcM |xqĐ:ߒld*6Nz E:Ghˀ9] =WDGd>BlP1kk'\H.v4aK{$Oʢ lɥ<9ƍFDҗ7y^ -o⶿O8x.Ewcڰ8HVծXyh ֭Uu \6.\w uCvȑGLi\E@U@h~D7}#\n kWNiU>K qdHhT؉֤νkdmכD&EÁm™DWS|=ⷬ=}j Jy@r 74.DuyI8_oð}rE-yg. ,EՖTjE nzgy.f۝V =Wg{I(bbBy}e <=CElh;W MxdB<~4ʾi0)BOG3h|2EJ#kgпVv,…\op` M^-FgnN]Lrx}] [諮:)j?垰۵pQxHg1G) cY"eC)C,f~&!]JKFhH{T4oW/жW:Vٷʴc޼mHOUW5Ubs1RT׽ϣ%(j8!IV7kee= Hq{B LJ#|e ]lzk#0v\l?gzLNm`M+æ(0~d\2 XD&qWC!fX`ZFB>Tv* Uж)ܓs Gya TU/=|!Ss^ xhr2OUh\]7vVk/Yݔ+}[+}%76wN>6/cz HzDдM]Ӫt խ_FvJC Ȅ56 mx jgu36 W77["bNF)L|]T"PnAټRƽ1andž *"1۪8rZU;RG[T*a}\йޒ,wŌoޡ51~î}udõ!v~.1鸟銑Up~Jh4aeFtUp$k ] ^QhKX_5/+4h mUܲRgY&Ĕ9k\nUv cF,t s(MIGo{[d@4t1N\Hg fPa9 > `( kM,>qJ|#k_rmP/k&^$!3CF,yA2lH{[Qm\'Vw-G_prʚF!?y&{ejGU/;=˜ϡ .PʢcWW=xjuƍx1 .7 |s,9"g>x7 Zm8 x'9^WsEs-Ff`_rph "+ghԴ _yLe]T|w=cOqW>ۈj Dp@@R0> f! Z&d0ڱ Tpf8QYJpyE,çl9P%u;VP|QTp:y U1' ~E\ o{fUJ 'OP!XYBExFXI%z6 ,-~Wko[ڧ $[Nԇx:p^4%YS@k fi|*.e:kXI@+VI0O~akK%][eiH`A1]~ߩ$? ]!}h֠s /yXrGsZd L K>=#A;-2~M'<ϥL BF<B"0z}Kk(1Z>讯׷2Wb]U4t)ƔjV:=YkS:*h TZݻ8wB^*l5r W_i a(O#~ㆲ!5 592/ $fOAu ׄohľxA :=@_6掞%q4<:2r 3Z }~1@=zطV~TB2d_!j3?ϦjYt$q~2]W$b5+AB ^9~p`O2ST= ɪ_c|9syCV$4I>RZ]t뚏?\ ^*H}D~b UXb/փ *XlltO5ĕ[ҞLMOB;tgM 2LRm:Ib΢[AjaA5wYr0g+t]V* 3AO~&(Nj>Z35t6s^=0ħLRqi4Se-S9v)oA+T%Ȩ u~1 C0'hijz:l;@E/xyYy}tA Z2"b1 ^= DJQϐIn#鍾Uw{oHҰښY`G}*T(#N[PPPv?rRk8%EeGO ~br͸2O*,0~r]== CqΤ%aODs96X?ۜ6Ko[^߃ qQOFAuI؃ϐ %/Vb%'%7+rH.}kM~,QTEk}*\G/1γ&{&ݑEwt)ǩOU1iKv H ;S3%*=Ll}_SϜ$5 +ā=%z1|ZVЉϚ>nw شmv6jFlhh^F_X߆, s쒌 ?xQ #<6yڳZet@7@} hBaljiIAS<Jnh3S,7(~3&uIEֵy0v9fGf? sZt**NϙzAo/=bcWYH2 rG'7E}qm9sr|X~#nbC]FZ RG`(~hv7V;:Mw]yS6K{oeYkr^`u%o*Yhod ᤸ*yU52tdUDg*xBw`B.\}~}dYdet2tL{)EwC{8*5w*^hDLAL.&֤$è ?=c "'d1뛁k{i꥽vNyˉ85ulwr>U$^2OG "Ny Ƥ5:ϕ`p H\΍JEi0uU+VS-ENם$GҁIjH8!)Yk-gQӄ]mq~y@ ^X {`wRc6ב߃F'h$C)ڬ@TsJ<.H":[frx[<ñ86I@b  90-F/yd t]c)yo<@:wA~ ׹58 ʳ$F;aǩ=cv-q׾F9SF lhχ,p=ΘB%(AU" <<"LpAtX."cWN)xٜKڦ[CZxQdK'o=T X񭊟ˌyBFp9[ ]:+6>p1M2{oyV f\F7f(&[1MÆn/&YaW bz(ړ;b[2tUȾ}khUaƵ >>?$n>>ɁgC-ZppJmf‚f']1^к?uby )NWrFqGOT/-Pʉ&u `\t\~x- AwNiFY^lQ .u\b<{OTH¡'cjGoa&LLBhzpcɈ>qs5o3V[,lePt)ŕu L # ة?nolk5ش2uZfV~ei`T92. ӕh 2yy Ud)nlWb;ci;̌Y';ɖ_N{cs pR5<ر 8ӡNz{MY<3ˇ\cy5S1c͞`~[v 2(!Ȓ04]HWl:¥ň3[j' j9\yTXaPL @kq`nt D>jOn%6DɊ8-@JTXӔ@]3&&hJ(Zϧ\a§p^Q恹/9YV \{(;hƚgz¬| *[mX`FWdgM6;SMSSj ,$cSXN3D Qm(6K5Of7N@$ <-HM1ԈڠEG5a> *)2R .A{T }!]ap\0JwGݘd !#ńpQG[p;LXD_,_v |43k\O91}oSlZc^L$F}Ȇ=,>=G62rZ{h˶,?ߙp+M\̑ זBoAUXcMu5F=a.ykDC&=y{glU%͌f>|I-k㥺LRb%V&둾!۷1,yBku}BZƊ:{gN}<)G9}fV.÷ma,;;٥KvFP3FRM{tZTά8Du/^r,}y`eGrB sNh?pAs5b5MK $͘{?HXo!*O+)2#W fNf(N$p6eBzMlV4>&AMTUT1xs"E,/55ғfBz9+I w&h$9]GԼ k(a9ڵPJR{T{(7"ӧ,Qe*ܴu1(tph^6Up-=(% W٘xj-bDanze/vYI9&1ScZF#3"y>澱(x勂d#Dw9^ΖpbF;=r{ G . p~P8xP%

M4pb,KP揖dREj뎃|g..hHAјBj$&J4T;d& fZH`o=u`BT_[N`L?30yD7\m7fϘTlr٠1:7~goC ^@t8 t2*د$Ӗ9ę# O6_ QeCP*fE˛;esݎ\U QyGɺyOQGO7 \#[Ve3W F.: JmW<Funp;J|bvIl1I.r|4߁[7|{O+r<>ŌG"AaO:gDoX;C G~maۑ_6J"!ڂZؚ7Wz/9T [7Gq)b NZL ȎssG Xd ':\0g<:]~ ciokr@S jʡfy:>kp7J)b88v*qtŠ'Vhlj3 {j, W '1],LL#|è4aG|l;9/]A' ؐyO/Rk{&űt\ߐG{R AP^sZK!ex':hZ@(_ۉu,7.KfR{Q^3qVf6|h`>KNvIu8Z`NS~5i^^^Rsi".}0ڕy1xdiDcۛ![VHUnIN`U{lS@A[C ~P?B ɬ%N{zK{!EJc\ xk4 <g YQ^Q&YpO%m㢄s 6nq𗰮[Ɉ% ҒO}GVZCSJeZ)5n7{[2{y_sHa88-X nXy*زmQyNc?y:&p):ps`#R=zSQCT\]]EI8_]#/t%6 0|/Ґs7b} i TYʕ:;I͝}IxZ-t/pvK[XabzZ;1xJQݝ8X`~K̉!W"-yE^bj |7|0wC ۰)H+X&Y]Pcc] ʗ9@_/`DLy;=}"Ei( &u|n#ogrE#їNXx(Ӧ"ӑO| fօ Nՠsb!E,oq9zu J!v>*"':W홪NwO~'D>,$ˆu"k|cةzТ/09PR_R6UX,|sp1,qu.`"݄z9ZxiPxeܫ-y0%O8jcR*&%ihoѤuea 1VzENs'Gک&ygqjG.WR3]&+k{\[v6H #!JT3#G=,y2nd*]Y_,iRŒT``n3> S)-7p+g8{'wmK/l~vV3I܈#nU]AķZ4̲'#3%Ĩ3 n~R$.b/\].$7=MK qmvɞf! Y,HbtdJD.LWcoP&/pR Rϝ VsI`N_Ph<)ϺmGJ4Usgv+XgXq ._DN`# L#׃[3+s3bcM 6e.֤Z ;9D>us%2sYam q?+]ױ|d0;$.]syXPTBE/0}@['ks)EH,]DM)TpB $abqqz:3$ûGK%iHId?CZv5\_}4.Zhp<{ka=P |%ؔG'Nh`2?C>If$3^Z%]gT7p祰upTw1rY(מ[ >, ?j@w2V"ªK&3,o~1Ā!̊wz#`4][^3D,`6Q75/4R%uhG0K`pP}z"'u(ƘNJh`XEsX; }Y4^){x'|Iqe1ɉm asŨ`^?*iNcM?Cox;B; .tGz'~FWЌql0)Ęu Xwj]Ś$<_+-ΘAL&VP&荳r.HeZl]Hy+eKD>&䝚&֦{a)Y\v<1\*ͻ7/[ hB҂J m`&4 9X&n+Z].K+Y&ep{\8~w\CðmLGܲGWS}tmQ,7nۡqt 9-B,l858!*l[/ր8*AkǦ:5+ N>9JI}+EUù:Pvu ?֞ M aJK:ʶHM*b-ߌ%\?:ge`)W=JaR i߹BBB[P4I5I/lC:ewWԽi>al2fZ3gLz&wkkKZZ,mn^`QrEmիC"* MV ! *YdiA;;a^( (92w흋 j]vvXk !sC3W#Q==tVۮނ̮vu| ҩrb vܟGN_ZQ+ :3<sS&GUaXt) c-蠉oô4-1Osd|5c&++C:9*d)Dѽ_2S[İ_jR`hb[fpD] `JÊC&̭68Ekj`ة%p|sYYK|Ðqr\T} v񴇧Rb~D* D}٘*\x\F:V7K5*l}e6ǂ+_$P.3`Mr-$p;T&B#K/rJeOwƧ8pF}L=MP_:Ϫ32l }pSqn6vEB>kjt_ryrZ;T>S/ߗ}5=B}?vsΧ^#$0!CB2_p̎^?V3Z[F5kSyqH;|+o" 5VFxE\'>Ꟙ p:\+^ .k zeȭ ̈́=`6V:E~9(fnߣ5 i|tVm` LfsƸ<R%GՍ`أxpԗJh/ *KS,~.22N` c._ 7lqVm^PddE7S,ݶމ0LDW@;ؗN) ER.2! Sh|s 'i'`7?HiҞ *Ty# zPp+:ᐫgo+K='fSl%ٰrSN,XH]IWDTT90TwEmz]o]b4!ɞKQD*jyuQfvz$+0w{e,3$q%cBD *x WQ/RNɴۣTOKp9 a&~p6!GۇJN6vO?lWTt2fc! Hyη톻VWP p@]yʯSPZVjb L8u^9 b3w0 AntOA)<Xw(!}_I=r.g9o$ 6TPE=^:a#+Tᬦk,O_l{#wvfrߗY'I6)IgZL5\&OjcPygK\{aW.ceeޒG mۙrvm8B.'+6W-kM:%B,PMm T1%'d$a"P{d =^{F>#Z96Q~(m#SE-X[bϓf-F*@v\ TGᆢQ Ԫ +$w锽_;5XFė8Qk%l¢]=XɵA>xik'עcy/OU`m@2ȿ'Ȧ#1%ǘ;]P׈Θ 4+rZlx2gnh>qŚGimuXc-7. %˗8H#P7FK{⻼* o\Yq9倃V~1i) cr82O&҃Õ[ ~`QL*H)EnRw$n'uvYs@ aGK8& JoX_a R!CF%; Cڹ9\hXF34RG; zRQY "v+A}jK2bjShNJlN) \E4gz8'd=BLE,+q"IK`ɰ@4T teB:x/v7RW5pwn4m̿P#栣N'-t[:u9g;L8b OKYLϢ;cx+eti1&r( ZOwjdZSܮG>՞PFBK,#ә^.v7(\Y_~6q SW{~l{0j# _p`;ZNti!򰟯\o xE4.q jQO0ρ?: g%%TaH5h[V761J8ႢxqX3p k̉ \.ze|fn-4B%snUr, ~*ڇzL}j ,ɃBjSYxrZ WG"71\]+g,Mڕ }U+A:@/j%{Ür=1uMѓ \"aupLXX>k ߪѭ-}9=o6sJjNRa@wQEpw0Uܷ9e1qܣnGO AŲU55^ls p}R@3i92-ep.q9Eڻo:ӝM$IB%WݧA UjBNFĈ㏾ϴ9?B8QDGN>,Wb,V 1v+YUF#sAc蘆yt&yli*0iԈtUqWS@C%Gq 8ʕpnp^mtzջ:H iyL/㍩(<B Zj (x1K0IY{Qq^{>U9yC O,X 1'QFV23ɜt:'yN!"q_s~\;ʺ#fY'TKT'%:k+Acg_Vzf'l#kB-X^P1 u{S}7P5dж:U܄W9t-Ѯs v!G)";ӯ=}~q>b(#]]j-c2Ic]K&bdםsYI#WߔsOå~eП RAޓar{KT V[̞}riv6 p] $,io7YoLhυR|~_݂@]_ylɹzp# @zb14h־ҳvލ4WC"^mZ7+J0Krq9yڸ 0mE_ v_9#b/{hz[s揹sixl<`1Ӆd\/ B܄tb;0ws,簣 atʞ5H5Js?уbi:XǰG+T\FY9sgbRʀ)joEʤcMGѦv` #d|jk"!5ż$0@@W"X~%ʍ 6[ GJ$ظ|ܼd&-r)Wf Wc 9ʪr=C˜|wU7{*lgHw1\0^ IHYÕ)3=T>Xr͍yDi?rJ_|.)S }7R m#ύ4Sۙ>$MCl{6%V'nHhp}UF%S}L?[D6GRFŗl:Ew0K;H L,ZC]NY9:vH #u2ZLz/_V_\)1U0H ؊+v`E:usœ>OZBVr8b_ow3(bR=O8eXQEIH)̒{6c%Z"P(_m ]å ?A k͐^Lu߱n" ]^2s XhGܰQ: 7 rP|ѕ bByz(z[ao;s?In !h_N1#掺4|d6sia[&/&DjcvMH~3 ;Yq9;YeU]H`QEY3C ->gjȮ7u 9$\7^Bsi*i{I89c(/m6pL;<|Sp`w۝s'%54s){' / r y9)UFi'i.*TczXLh1yD&aLeʸq,Ъ"W i))Q &&>ܱ4i;#EnSRZB?5)iW5. M/T"屿K̽^v`}Қ?ml'ٲϠCu .ׄx(#aefTnl*Z3W)OaYFX 8H1|L4 Sc:188E̐jMh#xuҭ ؛j.w'4@](ZW5)=P/S<.wx9݅LhQW:Ȑ:} \`9 ↗WR6#^4UNH+0̇va=[V2jK$na!l(eKCҫȟFV2yaALO[Е vl_l,\la}z1:` ?7("_N!>{6r}s.0+8|2oK~e@WK+% a-emm~VO?44UG!l(^%Iʧ,~r/9K:ջR3;:SDE_ F/."?EO*kn]  HiE+RȽpoiKsx>D|+Y{b$2VVʨ8Iq*ǂN6ovKMhLYT8b⧣ R7%lŀW7qxa%D ^&鍀6p\زp eh)2ze_9{{e VE^-#? AKv젡}K)nLk)ѫWX:cL{4qJ*M4Wnjj6ҷx &Um]{q2 (qdR/z0LǵۅxHu *w'rvU^,##&?:k4rɞxY)0ęgUT/~:r؁r .`T)LpI'6#iƖ#7`rTrEB2w~rb"M%am~gH ᕒě6͟_C=C0c&3 -xcA׊Xܻj$sڥr/oR)fǛ^_pbk.=.(wH&!&[18M1zUEYG:'sK.=ֹzeho.)fFm6C1 j*C[zJD?Mh@Z[O* OMIۘ*fk5B:ǜD]tpt-n~}c4φsCwHLb=_ &T}W!W+v5:Kl䉜D^U7_,NۭD% V3V.,X/Ij^GQ~[>^_cqB9͊r,L[#`q73germ ~Ѭp7`YH0Dc>.~D!Shrf%/lH+ I "@&R+5 ~LĀ1{*59VVH$/ǩ$w%&ۂzɯ:ef4bWs׹=;)4>FNLd{q1 QUbQ kWIG":>|)7Z\t$V=V z(0'&>TM0!e}HMOH^JD Eާga壉-8`0HS=ri M rNdCO[HX/OcK2/@EGvq~|'2)][`E%P+mX0$1aZ;, '~L42kb}J4.L)BR RS|Idqi)[c:($eKb*aBM [Ւ %YCX4~Sk0FP=s \"Uɰ%q3a(iE-b0FCrP0T jI;v, aSVҞ5OM UayArJd&M4 ]7jwJR23::TthvaG+n&Q)[@h|xbS4@Gyɩ#$D~V9=wOBFg$C7oT;, xp80jh~ƞP"=Rݲrb@#R@/=WA%%gj8ZGFurڡğ IlVCw QdP:@eιC3DY=nT%jxmuWBG;i`=s(\wJO70Blkty'y ɟ ,hFaUp^[:p ܂>#OVlĭFC״V6raB4X&m*Z͂8ZJU ImǎHweM57hsvz5b}NȽn`f[5UkRa3cbYqRòfgʊJCl\)FcyKjU6;5_e*FɀמCZXeWڧ%I, ?)YHsv;3:W+t>,εl&JM\N8"4t]pCt/rӥ[,D`Q~3FR*`]qHklxh0Z9딏.`;3e}-n|o~2_f{ њ2 7lvmЇnݞȌrw G5-XLmƔ&a\e bXv#ʇJp2nf 5_ЏXOixܾJG0_DcO=Y/ AxSa硻\K@)}(z&CTCg4LeDmHGU ˂vHف-\#8A%2Z$aoG۴3Z4Q˾}*eHZM7(_:@)^>o/"OH;Ay楇H=63GNtZm@\!~$=q=#8ŒXp,zA{J2*@/@]ڽDm1}҈x } t< k? PyUv[W7yR\jJtK"t֩Vf0e44G}7Nd&wNc,S.c^)+V8\X?dZǼ~fNzSwG)v$UyS*{ u*٫oz wA@#E~|P |ݿW#+R#WCwv)bwxG D5n:v%:}:VL~¤+trmkdzs 3B3gp >䎤%HiMPX>tK*{$W6DW35 8@-q=LIe89 ^AFҴ*M%٢ুfcFsig-! f :Bz4+QY3Z#eeʨUs!|1Үw`] j;HwXB 8B$? (Qw 'b:GLd@yCT>ǰ?(4qC @>KN$`j !T;$fpYFځoL(3ĶOZv6vQ<=tYr2#==2F&ILt/VBI" (] i0vyL08ccW!u!mW̐P3n41Po5F279QL6t |BĦ:B5qOW' ($[ :C#3X\0sE(gE7 뫕6z`wr8Y?eOч"pG<Ŭ?I2 U 5纓OR>ލ'{k_r%wik6 !6i[w@pC3mXdNi\ 7vɹOqP7P.ZkjU} 6ظ&5;%2cj&)Y:{%_)UWCfY]TO:",o`vZ[֪^FYٿLj4 )g4͝GFWReL~7rBr hf`4w|K;TV΁&n-Dz';A9Z)cGg^*ry{UJ*}p\(_=i#X#$ʦz$hOi%hApAeTd3l2 -rj-ѦSh41S9!׿<e&Ktqn%~a:#Lcv9)YԜ!c O~GͶV=E;!˞X6oͲ^0@* sGxSA}е95V2b{׺Tʷ ozX{}b’BK|}Ja_ BB=jDž9,hNEQI4V< _$s %UlJmT.lZ8pȭ #Xv,u*'Ҏn \# )9n*'$þ%'R]oj K9ËK'ȋêf$t+C6^m%m6?e0:h 63qErf,Ψ=6Ƃc>'{"9KL6yâPEk{#Dvw lЮ#q>nz;س4a@t>(dPM(#_!ؒ4]j8F4-ЋڢMlT:Fl瘋JqȂtG~Iu!_m'6 zc u::F;M:: ?[PqYx ;ē1 [VaKer0[?[>c[IK&L{Z!۳(9ێOlˢh,f>gl3pQ!z CUkKm9܋U}&dA/ur혊7,5esbU/1+|b@E>u8>"8F c[%QRq`Z6-8zeV /$C b]^3O Q څh \ Yj՛:L.>v' A]dx3fje ”R@}4i2S"rVcyyiff>FUYgiK`?"㉐͏$E.۶~a(o LOP* ]њ`h[ewoi4\n3=ԍg1 oS&v2t@p$3,6̠nA=4H$uLߠc,+U ۛ?wXO{B8vw;arNdJ'3{-gZ̹k VM9y)PH"?'uBbE߸VTPkaV%ޓFxqb]CLwL}_7lN͜fVw2]hˠwͫ5xT 6I͜yf0 '?1^ j^%{ck VoYSx!" TXqplX{JG4v]SX-FM*tⅢLf)%>?~:3 _<`=84FQ` YE J {Y Y{DVUM2 j^0\>5ukˬta9 mQ=*6>?5dTo§2i<%3FJ„FkĈkR>x*̛~In뻆Zf}uXG(M r6$ . ^DE^+q !!7 AY8?fӹ2r bQl^q3(=V]l؍ʹ"  f$a ?8![PzhBܕKP־Xt#UT ɘ&kK/? yp^t׫tJE٨Gmc9{{|ga)!+yX@!Z1bv0[d<HB. 1 V~T1jڰOdP,I0 `֕-C9"B3Y&Ҩj"'װ/'&kΜm1{V7SF)\;?E1):,`I}!?1쮣EZ IK j ] IҘ;Вe.~DSw(HD}@8#۔Wa[Pv7N6q{⟱y6.bmx,k2v'yU5l=<*㡘hRYT;~0.nGB-n$n|ThL0nzSﺋ8Vpʏe:of\&Toy[JI$ܚ4)؟ߡc1FUߓZ)ݼ rZbU`qx-OW5ܮrڡ_?E.&MgЩ ǑXPl@rUk}AnʔIs`Ɍ#yeG A4HH6~CCeg5ݲ p9DzF^ :/VNB*0C ӯ+(^3aDr/Ck} <Hs§N3DԾ+1 gPjF=Z*dRA@RY[՗3`/ќ9o&JؖOe%}N{?yҟ^R|Az*ۙUqƱA̕@_Tz <5v=RVfjZYw^+.X%pK`[*] K6)dg S"_#0u\%[D42>0ڄ!QƄ#djz)2,xp]浗<׻  Ge? d5,S}')AY9=QyIz>Qe;2襘H7xhp&J%DrꉛٛQ'ri u\|+M)~D FnjpR:f` 5DBt'JbDo^WȗG })ouY(:ؒDTSȊ+#l,h @(Sl0+̔$[>H TNXi ϡp_0 S}J;WX4Q\淑!qg˹,PC A^讨2a Nnn(w1]'V"n"ۤM`QHQ>6V.ցnPw}D^Rwh5TjxkpڊvŏqaMZ05ReFΎ8M5p^pR W Go͕>TQ.mI Nn+WhM?@ F@L9EV8QE7@f.٥R#,c8*8w g6E&3j;`Jz"q:㼈!@XAza08`ŤR6E QU08gĖS"50PɓW(~6 N{4MGv_|zoub89~,vqenbybhNQEH,`7̀fehHѡ>{E+i9r7)_Y# ٚrT:SS =unHm~Ak-{c#vtx|Ĩ=:%\z ^jAgrG?ZW<\tbSsN!WG=UC]t2D&+h"p5T c*{/Nʸ' vd-cWB>muXLrj6xi^Fk-ʼnYQ4I$hRȒv\ͲG==e9ג|V)5W"\pUfmWHTے/+'HX5_HSժe$1@ Wrt[nDG/)ms˥GJ~mn F6Z9gߛH(oHVP }І<DINi>➑@h_q@]UGl' I} Ξl .D`a'M}r<7ll-BD;zT`P#P9b c(^29tPomfaP(,彪+y6%i"Mҥ_A HÔUK&~9l]9wWiuo^dYZYЩR>9;\/dMNa)U5~יJFAN/D:L(V2'+5b`>UIDƢ1Jg.5־y&x; ٧^/ Hj Y6eF*%\JCx N.I0 %&B*_ϓ644;ѣ!=cJxUyV<0/8bкIDJ"O R옪9|Ԟ56?,8UN^Ԩ>Kr =,59\Sv:qx9 ]'O`XO#LX4fN7K 5v7׉|M1D $X4bl&9O_o]]KK^[NɲAEzGDaӁ$|PMVɈ1')Dg-E&x}[Lˢm/zoAa >gwo{=pktȱ-a'u֡dMeg,4!=G6"J W7.廒jWގyl* 9'}a z5a^9RV̀SBZ|9Slok6yɃui\ZV8ݖB]2=gUd0K0N$W~Fu _vĔhJebȠ l{)f?kfrQ1'֧JܚsL^W!jG^m-_6b8MV${}6:?]qRo ODŚW #< |@\{>A)/( ƖB ];ޠY }_CRI(l_ 3m[ k&E0؏w/$-n`fyCmEv́8V? IA|t;R5e/Y DD+1u&@%ۑ`/PH&⌜~-4:a{8D#ѩ?EbWH+$6d$`$%wt{#u:Ę Wm}@Xp$ڝkCΉCuvgd6%/jjw#LJ)(R''MpMCS,(JF#sEE +rZqՋban}ʇ I ظJdys/-3yHt'KuPɍ^c Q3wh)Paq}ekGf!~@9;1ɞp ((mq3tZIvlDk9Hz)=Vj3T FeS#2lR9p:/ ?N_]o9izlӫ3{³'WM KO@rctUKPh+y!ouLVGpTяC6Y,ŸtA2>F!_"2 ޺Ž9glKóbr<Ә㰼 T4;$)Eǻ6 h"l&#fR^MZ9/X„R@H8 *?Yg i9ӼU(hK =? ?58@d5 HrF-NT8 9#%cٹTV+Dڬ" $[T0dˆ)C*]^ՙ5oJ]"ëU?xkJH MxFJC5'-r$A1I%XpcF}"< p7s!uynq#k=l,̉5{|*EZVfDd [ Z2) jjޒpOVsx3`2 |\Q,;9bm?v TIT1ar7@Mcx٨FlIfrؗ X.Xֿ wLr-k U =ރr.Z (z!DKAlc}"tA q $LCI™e@ y)5S7GACM,ݻ9]V6bt0,2C΂λ=cTQuSJZ=<Lug,'IuXWT5>> @BkDq8fi}&2I2G?A}jPIIϕ*aG~C!}+Eو}0v$"N6ȁNB>L[/ JezL*IS2"T}_hltO;q£h%5$V$pgV]r,E>6F'D ;E`/AﻇE֤;& ?X0#o͙|KA[c}m%4"[̑oZr'»!1j^['78965@`jZ{<=,֌'tQ HGyٮѩ{HHpEc7i!#`2@V)fa 5H%ը'OO 2Sf,` ܦ7iѪuL;["QNXzM7 BMRc wb)6{za} pJ_iJff{ li;؞߉h.O9Xm\*N+b6 aVŒ a{皁N8:|<$$7O.Fwztsg= SCY@"0rKyc1ەL-Th R3#ߪTl {-<|20vj`jdȳ:x *;6PQ .@xrodƻ2pgA; ٚ)4 4kxy# @0pBRɁ;O!5ITo%΁G2P:ٹK(ؠ2WTؐ98/ L~.wi{8a$ yKKd>z4Yidۮ}.;Pdz Ovu0mݓ!{s-vaL%M%ܶ+E#0 7U[N> Ъ;(D;A9kEzܢO@Ro;V3egQ qqM:ÄbF彑19OTXJN=}[` t~2lTvYP+MZ|.|zM~Wz*r>:E` oYPcZ޳R2g6P .ǯ,1> 珊KI'Q׭N<)<'Py#I.l d()6#S5w*2a{lzlZS U>t؟A\*c۳!+T&QE'< eXePzh#;.'.P2vZxc05Y6Oth{AYʸdQ2Z@[/QӲ{ ?RUˌ(w)ɗXW!DF7 Xz :NlʀJiN, c9EIT8cD0I hۂ/M9gUO6TeuYf~Q-VR?n8֢mibNgZoFȭ<"ň|ڣ ȣQ%X,Kd7yPU͓7@33:9VϷM6hIOu>zOS,I$%+|6J\:,ƖN}ZI%,;|!inwƌO;!u9ˏ?EXK aX8$&[Fo|h꠷$nSF!NlxajheZzz s椤H=3-ג0<͏'MT+ |`,z)dFuJa ZK"Z,( o'oo}m6O连] ~Q,a/lB6r߱C"qn'A5h 1x4|d_=fa2:;V;rS!U/ xD M͹0*/C?VnatDJ#mG[ ertn$k5WpءȧQ5?)/KZ9ɋهۂ#];$#e9d({+}DDYx!85;:v-ezeTi\7 [:1M3\E K>NSI}^Ѫ wʲNr&˶| =^CT|J)ⴚgfPʘhűDR1=\P`ʓ  k{L)\ >>Wܽ[[$@ J0H=7fm9}4%* lʀxN=NP!9O~ɕoƒ =?e79J-D4"R\cұdW( *^36KvAu)Hv7"[q.arD|ÌʳKmWj? \83❜ٰ@yž̀n&Er= gz2 Kɜ*$jseGC :=@wpIm h_^$Hn-$+:p,3]8m׽JЧi<1_`ӕmF V^XNSR81¿\>Z5*=@ J hx9 KOs6GFo]3 مHPZ%h~/»?;T: _w6FGY#˺*=]* fK;@Pf f;ፀ!96x;J`fOq$K,\Q/StCvh1}[Ns[g2UH[x:CI~M>"0 "//Ns>ȿ0BPsOo?DQƯB;8oWb ]/ҐX뒓@z'7L1GHV<~v bF{_r(/NYՏd5= `gjJ865^&AxT-B݉|,J1?ǽ/Yϩx/ ZIv2`gL]1JDb.48BcTUjKк5 ƉnQGYl_{2S/ t@L#VTh:؇w LU޻ٳQlzoBrGpiRL{E~nA]0 L;=HBm:~gTi[zb5*(y:֚ʿQ%~wpSCO e< < ͚K/T^;^g+4?j I|~I˂x&гB x \ݜQ܀yp885WNxŰ*nkRz} {+7_hY?g^;7 K6/rY`aLpt X2˟M>>qHjNAW#Խ1X 9TDU1'5kQ ]=_5;9C+"ϐ܀L2z';^/K{u7!( o]!/Ien6Hf7et1%VlS@J8/>>Y]|:'3^_lSᢁdh"+:(t(Nn|ߛ8%O\anԏ, * ;SK'6B_(6BrPqi9 ~ZL.ܩ]tX&,>|r=i|irnW{ucϣhv]Om%7>Ph)H<+;<Ѵ+#;lfP׋/vT}U hz糷cJNE:`4 YE47kqEW/J.m(#ZgW0vz+z$rIb_#sNd}@̜[UXC\޶Dv*=4I5]? ᕽ>?hé3*أ}'4K'ib-i'jAPVlBz_ȆrDZ@|jvUgcc3CĤ͑ń}ӵ9T> 裨HQκ7c{:T,G*[JFr"ϓc '%0e)jѨG:FY4|B=c"''fYTi(Kv0z$۶ON<~򤫍u;zXCB7k1gbhYSo܅+` A~nRc˜ "3SdNQ+*.ާUXzDbG9WI' M-viB%tm~~~g&,SQ vYbh*m 'txr'2 s0CɹFAJׂ f[. l~{&玔$-[rJ * ^w "]?2}(o# O}!G5zARN3%Zܓa:JUB(/")jT,'LSobg}3>@*kJjF&vtU߇ ;$Dhcu_zPGDӍb ywom!E? ^OD[+LuQYGYgP.cyJ|؍)n0'&(52Ě?ȦNXνW$BD ,"@\+c#d]Ŵ@nI "_+}&^o|UHX8d?$5ٛ6 wsNğZG`Pm4d@C0*^;~okTNc]R -b ,\#p.x&S,=14^EQuJ>9u5KDЫEtY\jQ~Ng4ʕb"\{}Xd-|qqb0Űn-lq3f0;4B2 孓0nƩ ZlɔRZ3}bO+({z B/:tK< r"Xyu?ǝly怐ˀ|{Y4U*QhOn7쇘SR) &rH4L&KCw7?ڙwٳK) `,˰080- 3kYT]fYXԞn:60bh i_бdTLEeNT?yn,Br"[ *Rs@>\ W`= +]B1bi? ʒuؚ7-2u*E/PWϱu+%&@c0}. LwkMQchV岀wRt;ba .Y" ˢw)ueX|9ˆ̠S_x~>?w:|[*b6H+>hT/ =o>V^t2Yʯ*ڲ%0EVlBͶ4vMTBOTkm=hYtdSI5ܨav50mЪ#Hjf$J355nNvI|9 \J 0aͯ0†(4EVV" 뭠x,5.; mR/8Wr~ "iYP"u_}߾m|,ӎOvt7!YV4ks/CzYj AMRe"sb"KFcdzIڜkbƈ3#X=)ܘpH#t!Cӎf~??a%+63 JH2*f$D)z|ï;'@(vY'd *%7С4% %!1Hn@@ W€b~^RAiӤ.)”?ވN[޶/+> Z,.dNߩvjc~7#[BU:>Xxx~!KC3l+xs\ܰHO,͉~U^z ^լ{RcQ5щV6LeC;4 >`F{ er'!T.Nfe,F/~jlwB ༁İPd|p7@" /t_q`:;OnnE(F242O2On ?ŝJFF5`Z:"q{)LEu[QT38'%,Pw۩\V ﷳ;@vB2l,HDNة]+0y\SE>'6{(+4"3ߟ3l}-^"P@oEl7ݴE' G}z[L" N]EH@{e"6zD?q!٩P0Y K5#K: ~)we1+,m%=dĚ"\d!pW-C |9@NK1m2Ύ[>1[:VN(o*Fj_c,=p{KQ pO u giTH(r/2~4hc!P$m{Ljr=MK5t [~9&Nt_?,pdĂEr3_l"CV9' uzfP^\zGvFʺB0{6/·+fshs)vЛmlfE\BwIs>vj&'Bg7BA+*/㓍vE!wWxF㈎ue.jzL!Lb (HHWa-jJQɢ2o4V,b(PF#SdWUd0Zwڍ>ƍljRD9n4o &てTE7`c}c_5K4H!b Lϡ~0.Ez\"a[.:&q=R["&˜ lt2EU޽5 pCpwp|N#H\wѺp^_5wՆYц<6P iOcz7R˸n&,҄WE?8*Ldgih{)3Iy kT@n38oD+H6D RH I[Qu {h)@&px5+'R.頪 `T!&YrAj/FE} YkxpYW euy;\PpڶO` Uc o]>O >;4Еh>l yoGgo;  zeճꅱW?21Mڀ r5I e.ݼ)@0̄Ma=\O՚=DWg,hΞ|&!4^-k'^<&}%Χ҆^Uz0[Ux>ׁDըK~W]Eݕ >͏yV hϣ&> "ȏ@_?FZs=ND0;iövcZ]W4wTϔnp8IR@hz¿R;) ajz۴Yiy Aw{=W)PoX 1 );{9Y֧e8jF#Wy Sv0d4J7=[L~х]>ΗX[ Q3yFy ɼ o~z#8<ԟ6i-1W?o@{5_({ 膹!=I&nt\C(Q|zr3>kqiKFrH_L 挜S8'"1k"G U{5x4i~mA7>`vڣeKc3 (N&yPkѲbzek&g&Py!wI UiQNlI!+rYj`OLbɩZJf}m3XZ&[TfhYhj(LGv U"7P MDqw#n6QG^+B3-AKX'Lr9P'^a TJ FuNFu,ߣnD)O&!x{[)܊rpϞS[8 [ f>bP# Pnf'nA0o"<`x I7g^QNl%zN|2>+da`l7:ТJ4V > !H4baJ򀲆Ń  UQ=ǧb!x#I޿1FTS尳0i% bqS}ِHy7AR6F5$uJ1`>pPxu&0_87ӑ .f>4gzsqba5FtM2\1aɶ+9>T$>0[I.(従>GVZR)S ii5W~+vq; Q#-Q\C1e'LsIUZIϖ-U'F`Ռw vwT(xr9f>bа5fUm>npO\ x+D@[Ά#6_b Ի&*#yG>E 2uHR#[@TLn,Hm0 Tk{BSmT!~Մ3hBy`2V /gFUӿyG᫳@a^% #lEJR.޸9=xϒ1& aUnj@WH={}rPJbs-j >F旜j"`hhW]<@ JiuZf7nܩ:9A4Dp&U{^8Ĩ-z#,9#fJkɱ2Δ&apydIAd< {ͥ ~r%|%kM7lǷ˚9IU=H-¾j=UBz[f^JU0UCT QB+-Oþ ͝ Mg6eS3<}j6Hb{#D@&T&dL.~sI5.XԀy !T+IA5.tK+Ck^6^8لֹTC;p/kkev{i"SWR)5,&WH/^'V]a^,t`(:2`D91S4!C:|ϫd0>t+Tyg~7BpY}ȈZӫ-*@>W{]66|ڛKrv鯃 lڧCk|+Z^$|[2z(3C)I;ClʾpרEt?VA%=I :``!) AsiG߰Nuv 0AvH^У8bmA'YiIjz;л{߾uab0 1bq'sV?hcNcַ5F2.]ܕ~KV󘈙BoӨύ;#SzWpYZ4ߑQfkoRn83GctU{%k^)(2ݏ7'8 sUJQA?KW6Xfy~QCɘZ0ΞQ$OK1 i%P [0ΞA=5g'AX:(z$O{eװYլy0LD- ۃ[?s~Yܦ{c|'M„g>uYqmʦރS:)% \?nB b͛^RRz>k~bȡ#"pɢ373n"-Ĉ fHUN97v1mTD266Կ~>6Wu'\2Z6ĜJaM z/̘RS2ذ%vIˇ ȧ@U{3Y7?cs 5 Σ_}\yfT7_ak{aQ@+T"D2$ FD{>Ι%'Hk h!MJΤN͚sӎ?NePx+"f̰l`Y-l!ɩUj0O*lǓ!M'P]:=u<` sjdž!A5>j{i2?>rom]Xs\cpg4#s,S滲cKPmR#W?ލ%8b?3EW̘&ݩJo5hjp:od&_7Ws]eۭq׵$Źc\V A3B` h@ rbab!juF P`wkw$e ["WR( X w$ r=[{){koSduaX'c֋f mZc>Ɲڨs&eq /XO͍-pb1>0O"{0YqzNB;AW^*0exTu%dlhR+}_l?s`3x;1o+-ۚ2&[mÎXlքI1%1k[WdB@|J;q }ʭ|ߏC%[Z]zixy&QLY}GL \7A5&ÒE^w+{ DK;Q| ^Srþ&sx|J:obETm'J:Qe:wٵITIT_#WfIvKL2FTP?MT@iDSIҝP̀Vz񞏧JYahcsbZhYnE]N٢&NQ5mCnȦoTcLVЊ9b>9W]䯭TvΌdRi{#JfO6` YPce$}Ǵ"ǣ>Zx(vrs='Pf#vu0oJA1'ҁWUrQMy=D[9Hx;_+Uh&2r(XՅX)63W~oEde1]+/ 3aW Mu8~{H< MVT&`|Zx5^Dž:ь3D A=goݢQc`46آa$X> ` Nb1$7"\gKoKT2݌'l i-җ?:?,oRxn10HQe,M}~4B-9pid30W\S.YвC"DzG|TMb6q30""=0Sنi{nfE5N⬲ZJeO/gX j]5wY]~q8J/5df ؈q8ј*g3 ~Knh k?x! YbpŎpnYXBul$Ÿ^gߒ;zY<[i*TB 2p4jYl5N*jWaiWۡN*V)A?ݾrƁIlκ hxzdYxWE#Xi *^0MQec=C%ʬ<?}Zh>"͒Ōlܵqox/{xF/WX|9^ZTLاA˲x #;=t;Z3WgIXgVX{7OّuLt%#s%.GB dtvKj+!g?o0BW_l\>y/EJV߷q⩠)rHoT-pl ~_ܝ*%?b =f*lMEOm=ZG&*{h`d]\2s0oŶ~pɋBe#җs; nŨyP G41!y/*.; :xg& i8G͘1S^!;wz߱0/f`,HLU*[eӇ2adN[җ Z_I8Ԧl%BTI?Oi~ЂJy}/vk\Qz΁5TJUXcd"1널D>p>ҷr|V7O49;X[L` ?̖qouԹ9с/u S@L|0$&kR,Fpzڢjdv22_iw;K`ñw)5C9fyf.=W\W?~3{Vlȝ(#:զL5eǟ] u6/xG/uBΧ9*4`t[#C23]v=Wm dEBsۑ4Y αNw,'M@ N>Fw"CQwtif, ]WNP^g!_:i(&6*?M'LbPFBm1 ߡe!. >Ͻ.P"쵂e(ۘA|,#{;]B* [Ugrfcuc@3d :S$`)Ȍ!fzGY dў3s8_W?u2V\]M`OYpDkk k%P.uׇ!x_-_"1ˑV9-58'$srk^[ AۮAȬx8fxK6oVu-vaRf EQ=FGؘY&.ɞ&iCH;joLACB/{Zl HDwN@m>2u"^ N7,A OA8sj6R >C_|6rQPAz`JG"kC3voxaц[񜺛n9oAoWj=vJne.E+pEʜǝ$wye \m<2$&ߊfuxhƁ5D@9\)dziA .ŨaN |s]N0S,_M+bख!4GC \Дk)6Ctɪ?NI\ڪ]ݬ[lke,[fRv!B'l!޶hИ]!xj!nT1bJ0܀cJId GڒU2H`ϨLdOzO5Wp1ob:j˗-$BLfK;2\9~Sג-\0: vp1Ef|%7WltYp}àRI ݬ:vJDz¹CDo8DV!u$B7 2yα]z\l@Z(k k9"=8Sy,=y֏WS0d o1ԟHb_J^x6s`SHqͼ@b~-Vµufc36m4h OvuSf \Orml<{Ho[쯝:#㻲rx/d3yU& ]1dhv@!OeXSp\sw@տywԂGTbz脁+E"Lj?v,ﲽ =~EpZnA_2mF%ao2Θ7rU!*w-KfG"*J6>pVָ@Îh|2A\iC44vSܾ j1X*hJ%(!Ԭ> Ӱ=+6%)tiXlH.u 7Ylq\In)ΩL5NϤ_h'XLpj`_+bg@lmԸ ĘMs5l]0U$[ɘ; zz4%1<ƫd}s~b'c<ɱp9޼E0-*51-d /LwGw99R@nNENIpqrWX5~Sd` ;PG.d W_xYq6RʪEh4[~%P\̋-,yN.3/Y2;Oצ v#+b&Ȩ)X[+ G g g*&v>(ÍXˈ<1tU.<7}8WE7!_nypfYjt)go:P^6=OQ2̌k-Oaos7e(=1U瞻Ȅ{ Cy9fv=$ ?0{gvM"9R65cMUL+ ZEX/~0A-s&%Ӎ} Ww3[:HV l9ӡK|2dK9b =ӨW/)44ddc)?T "WC'.3HISu1"b;ijVnFM'51;LDK .-sl}S$e|zCsLlKdݖ\yBō2V|{C%8aЙS,ht'Z*;A&9PNzF&~\x2/PQbYCg@Nx_10b8*"V-$xfF+Dp5]c<' >>z&zd_2ʈq(0JsۥreFl:3 *>ŻX †7O82.ȜO/Y7@1 Ÿ66֖zmA4OI Lq:]c_2Cgj挴;֟w+>x/!!skY2D//:4w/VY+($wq_ 0ᛌui2`W" Sd_Q={Lr$8W;!ee iAQf 0IZ7Fj}hC\0`(g KX_g3 㷳U鲜!b+&&j=lϭeYgjcN4a%vn}%W zޗ"޻tJ5O\$4 LF8-=9\ $ՉՐ%9gk8ěͭ|<'[qғU Uƣ=Fck !"> BVqE%Sa:?dڅ׋qnTP,TSz]@Y `StA&e #;w6)z3F(q_y%|L!j'1HSTIbxM(T:_;JH5;ҍ V&<̝)~z#&$$K`eҔ,&3)ɐ>,O qw|cRN"L9{PyE!Mhߪ)n'g #8N$zKֹ(anW1,Eݻ \j% μ?y) .-렀,lk.of/P92p\fXP7yZ\ ~PvNNǗG/78$C9cju1k //ȑ++rI-4Xi0VlV8/ JPLǔtNh OqW,fyn= s ٹn10 #h EalAHl2_4 ^$\-hiFR&[vXA_%-><~1IWvkGr{4kaqboC -W-K+ ${h깅 ہ x="X5y4GǴ8 p*rlWFG٢o3$chwy> .循$A>N`Z3"i'3FyUxkNp GkK_ (~ ck@? ZO;e+BnU}bbB`Fw>98ؽŤ;' UBR`Xomj1!/+m@M;U^\W0Iofæa;{Wy-&ϻ#@ XJN* \K&yV|\HCzkM#\SI>b`Ƞ< 5;~9 }Jo ^DWIq":i ^+9%Xbn{CTii&#,Gި̄{ b&mLݛ(rAл&-3|^Qӗ!Md~}DHO LʘS󽤙̤k=3l\ßE kJA|#id!/`q X/G,Y~;'HכN&x]jdϚ[LMTRJXɕ(\5c͇BGS; `(_|"BAE>(TT@6ΔMcY.oNJ%I '^PZD2Gב\INU>Яt% o%NbǽrFTh߷ ͓t>+}.2IozHrbH)`^}v"@έ̋[)e]ޖϓL]iQ{ 4e~֒)9Z 1n^LCɽqSp.#"}H*w556>f) y 0mmxj+$/!2hKl^t\ܳySh.ºbl/ݐ/[=wYP2Cx! 4CM.Xy5dR *CR%&2AH6yCwu>Do\ar஌ 2_"P-,F.aAȢW2DGiw}T?7-KL  c L_ Hr78!/lR{_';p괦dزG{4cIeJެlko5ʜs>.Ғl?an:ʺZg}*kBfWJ F.$87yX;$]B<^i/d>B+r.\39%6νIyc\VCXܐ{nwHԚ@'̯TXȧE%Y֕c 6´#VsJ[[N;\(/DK.mzGk4Oc^(bW FY2ڗ LrS+rc8@'t.E +ly:ؿ o;3BC]uoA+͂$K!&fޡjբYO`^êq|:WC+_u{SSDX'0;U G>7(.Yz#!cWL> esNbE˅&#_\ pտdž voH=Q?+xb,M. ;CW~E|Mb _i_?KYWs]'KUL34c1;C P'F%372 Gu|It 9wta<ʹu@I,FY_LN4% 2^ɐcL:~8iYHYjk"7 GQ s5hoor~;O*T!We ;Љ:C)ej@ dKm:B8# ak /w 4cPsXWPG] {o r _wߊSFp\Wa= a؄ %3O 9αq?7 wV]g,"sj}wkghw[cAg+YB#0F~$a6 v=딝M h< /.JRX 4kS,=×=MDY,Lhy.r6Zm16ŢT;zSuɚVBΊZa_'L6*l>|x0㝹Bs #S>W }iu'[^Ye`3so]Gu0-/G9Jl5MVPtƆWNN)<D`۷<@m0^ u@DtIa1b TϢ\B2SָHTӯ@!H]3AǶoq|\N-y%5wb mj֮9zs x"<Ñɨdϯ9blBM'bU!VE.qt"7Ct9 zg:XA ->OLǙrݿy+8Zx(D8j0vHв!&|si~YqmK$HG~f=~$+?Rس}! 1iI[QV\ Vз A|4Gx ,:T33O_|#87.ۋG}B_Й s&3q`yi9upwsW޸\{ @Q > i+}\4d4I)^*ck&q,b>!hmG yCe5o JHݑ#u}}~+joM4kk^V,qm@%<P/RY:6qŊ6MbZ{0RǨZuW"@vL9qތ-I^%SSpF2g7LAǖY ?l\*uݛ!ĬQSnVlt.=wƺ9ݡ e˃8'A(w&6[;͹rXK_%m'_S/ l$98WF ]䪺 I, <+tygtkCZ+*'my#^ .^?`\ȻXr}"׊*A6N aTٙHheR,0"TzH~?T֮/U7YBO7LtDJM;({!􍳾 %k6޺X3zkU^@әFޥN=Hf@ՇP.](`qOF-xs }?C[#U\Wk:Y{-f|B=92yX|zH1 (9qkBVGlfv.qwR'*(%JVAbLUn3O U ğ"{k&\+oejȓ(5?kX"f@~RNK tx9(-nG*z120\J2n35ݡ@92Li`ڶiv!P9^n;6p6 QL;qa-t㬃@ | >Rݩ/SDPc<4H˵kЯr7>3k+qV'IJr﮹(,wC(j!~._Ì2a~ɹr$8;|/_ZÝE8 [rS#g5I\!H0m8%ZUm0M(ٟw];Vøy 7 m]iV[iyhg$c= ̋`blGw_`zf}МXL+c l^-|HB6 Fñ<)B(ԭ8{8Ub"<:w2eV#=Zh]j?I s'9WuelN8Uc|;2e [fEa$ 07ǰD`r/x. a#$ј9ܰC8o*}XNAH(c|.Ъ+6LXgw[冯8)C 2WΛa!o6A1"P+/4< .ft-ܭqJؿTˆOlm;ʇ;PEQJ 5YHOUL4o?kkd@v^ øaKNdS9ow⟒GFr3W=2sA 4R@Z)y3pc)`Ϛ!?,]zfLK8]<ތTVq>qJZ`)i4 m[dG.KE5U_".͍6j`QQB~P~GUɱ9R=e+TUZNK|%$oFن\Ty+7 B|[ƖRKf` VS/ }X6 &>,&;Mes@S_ 4-vu7- f54确Xz*ѐuz M E!q:l&?4$*V3 ŊZ`ڍ` 14N6i6xp,HfĠY4 I~/ ȶYGRi&D 4+,P`&}kMɯi::CtEʮD}! %?7%G~.rd|_^u-hP8e ɼdɩDBr3戹Dbw=-WwoUHVr+ `= @Y M8T*&- osgK~F_u}ڪQfY01 sXJN:s]''*-1enVVz+F n ʪG'pqK+sa nQ-OcS/Pt2]5JPXӂ>)>?Hb ,GS#3W~VČb!pfhp{劣͔z߮D QTBzs<& v*އfoc3Y$nkb_&]I0 λgUh"+TxTm,K#- !ReO$Y!+DŽU,-~Y`? mXZ* Y@M^φbY'ѐUM{ǪNݜ7پN萂[J"_Ȣdpssik6 cyևiHuUJEu::# MbPU͍XA;9B;MXRfLX)UBI3{0w7o&ps79I:zoaD5 `uw7T]19&,"6JZ!KP.G ?^ DPZT'I);dP) -z>U b jD=P×_fmy'#1^0q i^=(eƶϘJqLF@:ӉՈٰb c"Ɏٶ3Ok% 7 s"h  K@4VkT͠;PE5Yocimi UDw{Pӂ urxֺY J6I ֚5C:Mkalza61蛃Uz[4 bMe(Fմ%LچN %HA*#1ptsmnb͒.4'GйLl}=ƪGҢJO]d:Ȟa.С^ E S8ƛ9q?lJ5prpڙde/##o9-5eaKuc"m}4o3 t-iΆwK̸E{ 8"u,%4:Tdxi2:}!ԜT -VEZ"X,ᨥ էYQiIs'_igʙ:_YNuBa^Ğ U =*}?m#x'0jw҈|n}R/!*On 6]uKn'yZA|;!9==k0F5o!n,-:OZgl?]s[oX"D~)K7a/K\X4Y8@ɍEږH\?:Kqkر2ʈv2okiiJa3D(+m .Z ɚ*_즏Q4U5\RFUnI6;ޚ.h) 6-7UK] #Cef߯U)`f'W@`k>)npC}adl%V0+ql0WyXfv9 ߋM$d:wOMw}C,MMQ;x q{o>37S*s٣Bnm1~"[fM4J>Ob w鴰'osۥ.BmMbKCV]w;cdcQ/Cz*J). l%Y6v]y?tN;TW!P 'zO_'^#XUx&IO{ȟLkd籂 -U$O~pE xFDy(n39pnT3erfU#dx e oW͜F~= I4u{w54Kn؏BeSu"i#EN:k5qo>oE0$d}GDcg=.hm(a?2"Pݹ H[Z3>V.pgTԂ=#JqoE;7fhM-^yT'pGs[/K{DAUa & 81y1/\MElk]'n$O5̹\i ЧA+t!^VZm\"uy(R` cI[>YS#7p(~#*. 4ݽV>Fͻׁ/r.`e,z<{+3 0_Qȣ;?V O#Řt8&,nF>[r8N^1H  Ns-XՊ kqn@W-S𑯭6U̐= FiML!+9OWv bL5~o8T,*U:T& CA#~i |>x#(} Qrrn;wOsF@g~NhuSrOP%9]}=rV{NK9G;@%|yy!+psK9Ad!`OX6ֳ97.#cٮ-PakE8