sssd-common-1.13.3-58.el6_9$>,7ELd_axG><?d  8" Nbrr r xr @r  rr  r"r$r' '@r)*_,X_5_6P6X6l(6869=:>?BGrHrIprXDYZ[\@r]r^_>b?dͷeͼfͿlCsssd-common1.13.358.el6_9Common files for the SSSDCommon files for the SSSD. The common package includes all the files needed to run a particular back end, however, the back ends are packaged in separate subpackages such as sssd-ldap.ZTx86-01.bsys.centos.org1eCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64/sbin/chkconfig --add sssd # sssd-1.8.0-24 changed the startup order # We need to make sure this is always updated on # clients /sbin/chkconfig sssd resetpriorities if [ $1 -ge 1 ] ; then restorecon -R %{mcachepath} 2>/dev/null || : fiif [ $1 -eq 0 ] ; then /sbin/service sssd stop 2>&1 > /dev/null /sbin/chkconfig --del sssd fi TP^uF;`NXRh7x1] ֈDH&(8"H#hKuCp%|v*RJ1 G?_68qH(sR [ B   E  @# ( ymh 9U   L@ (ZuX큤AAAA큤A큤A큤AAAAA큤AAAAZSZSZSZSZTZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZTVpnVpnZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZTZTZTZSZSZSZSa95890608da8f44f59b5ee4011027392df092f74594e3756d54e69da6311c5441fe9104653e87f6ea1046000214a2b4dfb9df62b464c2d082137ffb00c20cd79110ffac8e7d47ca858a9039411e0586859a7052ef05443e0f80e5ec217e5850c67b8b81f3ca714c502a3be9f108fca55215725f3542bcf7e68dad2e72922d11ec2d0551259a125e47477fd0a2aaf04aec93c2ccf7309bd30dbc991959036088a7ac8660147008feec6e8818dd41f4fa4cd1a79afd956cc6ee75a3fadc7832e8e155dca84a27e56ae1e3343239242ef16f8ec044823c1728e884e254d15fc1868c5802c0a26fe322b5022d48a89b8cf050f1b20e7680d28bdb7d307ec04417b3ffbb736b8fc4b456cec68774037d97f77b769b712e61482488ba88e33e9c4133e1ef9e54bf962ddde3c13414574d02a00f85705a50659022dc936021c94ca0ff043c9820e5e58994983f70538a5748773592ed0244586cbaabcf34fe63557d950966e38403f3c753fd08ef4f2ee69b783471a608ec6fe3ce3e547785d5f397d5385f52ea6ee42bfa18338262b2bb70508a3ac574524ecbe9141f6afae63f03084f078a6c7c197ca3124d39798b872fcf1e90950a9b898677aedb71924ffbec07293c96adc53c9af0df8a86c8348ccad67aa0d1ecccc4cf57a51605896c8fdfc8f146f39eea3f5e647dfedf7a0334923c916942d9973153b4780a619d977394c1310a9368bc3162658ff12937b0f0f23a187df0c63e0ff882e4d32e2669eb78789a70f3497466650fab33714291e975d564870127544562f4cfc1cfb4ca2b75d5c0aed23be81e2a293038f7067ad62572c55b9ba6c7abe5d24ab54a71fd9a480c5bf128ff2660084467241d9895f5cc661cdf9da89951974dcd1d3ee51fdd8da3397b20c9d0cb7e5fe0cb892dac1c1bfaa6e07e732460b33bff82373719579b6e1b58d4167cdf6377b51860c1c6ad5209570d79fa84b7d2045fe9f126eb9951421b850385474ce291a33430ea3cc7cadd00854967f8fb8e75946ad06977582544a1a9f8d91ce59fb15c5d4d001c41af443de6e7ff0afda0c92ccb9cec2bc69ebd4219c2efe6f6068b8f305b30b054cf715bcd870dff0efcc97ccb33610b796e109766367dea678c0775d8b0d35600d9a24a3d9db7d22446c28e514373e1bd42c08f55f9ed900adecb54b6f628724d88e0c7a147301b28d4107358d64bc2facd17c0a215843fca12a6cf61a6937ad2ffe8c4f44d10e32bbf07484678fff9a403a848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9037e916370dbba4ed00ae6958ce8bbbe2e7bffafc345cca62f6d6ef9ac14ee8b465bc68df64cfb432ba8e82f9aafbb46d3697858e46cfd3e8fa135919f7d324449118e48ad1f237aadad63e0ddbaadd3c1603b7de65ebfa766a0d20eb0f2ef66f523573e18637891900888fc00b0b7f3e18dc9eb64c0d04d87c13c0312a5895fc65eba10862419aff3d19cfd2f7a37dd208a20f73fac16c06cf7673094e87c9bb772458136e557c4af557fb8c3075a315e13f8010636db867e341d40e8df9099cc877a9fc54d659bccff15cc8a7f8916d654ce2c9a79d2107cf3be99805907889e44a3b6038c09d49520919646934e36097b576759fcf9f138a5d0af25e909304dfc21e8af5ff33512024e4c912b0963eb8b5fdab1e10c140596199c6be121902982e15be9d75e3390f12a038773f181d6448768f0e5757f69097badd957b06c442f270c369f66e2b386351dde22e8e9bd4ecf005493e0a7313d4268969b588ce9be53ed301d8ea0ad23c4e5ba535a252bc8fd346507f54afff683de19d1c767660457e0294f5704529def6046df805aed6cab55346bf2a429ef50a97e31ce26071083176bce79f53d55a09d9ebab707280cb82c73ade6c9d877f52d90b75cda68422d677d94a0dc251dac57b60eac3e3df32e0edd915b372cf3f2a1c0cada24898643093f1a30717229dce7bfbc7561b09df240751022f2a7b66cd36491a026ef367f5b37e4aa110fde525b26067ffaa102aa4fecf6e4ec3fce9b208ce1bae8969cfe0ddb1098283f041753c7ea72138c8fab4d22a2926bb02d48ea640df96984b6caeded49ab719b510f13fe73c5f9ce19617e66f916ccbe5f00398853d0bf4fd77ec26f84e8ca356e7288a0a6bfd338d1af969b65f5cc51a53957ff3197c285f22595efc84b8fa3fff08f80f86cd9d769b797073cca8d6c09d09d3e16da8cca5eb1bc7517489dfaabe4d5fcb3bca2d4b701197c63182c28b9e7d15873e86eda876db0f1af2264cf6c3f20e4e8faa8e5fc0dc9229ad6a422abb57d62ebee47d0287a20c35108348b7c67ba1bc172e191ecf270828ce50f1e31f484c0bf1797b6d477f23db6724331e975686024fac2ea20e575ef99282ddc29ff542143d60ed80cbc04cf4b9b86e1561fd39100d9cbbfa2d5e9df4d84277a83f3685c27d25a0b09c3649b62521cc7c792fbf249d29340b680c5305486e95fb251de4a5da7593d6bce82520b6be6b189c3b787e2113a428bd5ea575be6bcb656e8194c41a124cca1c6f1f4f8d7ff93e1306f501f7b8b7177d85bb9377d1d232fd10983b1b44f86af6adc8823dd41e5f6b0454995927347c53193e7680f9691af8ac7aed90f0345c3ad2b91e6baa9859ce92615129af36bf1eeccf6f8fff6783a32d1516082b3751310072911ae7c6da8ba9ec8753a7f07f038437938362f8e9d654283b8ab73792ea84ccd5379688e9ed344f1f688325e363a513f5ed7f2cc2c73b889d8099b35f9ca88715c8a6e5c8850e2af645a89069b11433439cc89673f277060bc721ab34b4be32c262988ca3de2d0cfab2285588011d7a585a575881b6cb36764d27b7dc6e8c088800e8e4efb35b5ffa6752e98ffb08d93a2811dd985e41b08e3d4b2a1e435ead7a4381158f068c1bdd4d16a02f35d881252c992385b10657251f753078a08a00be8d86e5b197c45ff96bb20fc83f1ad864dcfa338c5b22cde3241980d1c41c3de15a648e5b9ba93758b2296927b9f8d89e569dd9a00bf58e30c00b84f4e470cdc6922d0755c4ad051add078c89d63bb8c6fdb2361c89e51db3429c1041f461de12a51633cfabeba8cdef43855599bf599b9c2f56d31156ecdfb96c425f52da0644c9f3ca063dd59ca9e71b567367dfb27091ac53ae6843a89be7e7013253584c0ee52913670abf783cd64ac97ad0e96806655b9d2150e6cd115b93776c6952d82da605b903a1f8345541b9cc829e7f08898f1f0307c520b358f0c343d5f77b7c5e181557097d55361145bdedc45fe4f87c1885ae988f9494b9169d07ebc3d07e72d84f9cff1992dad3872bb331a167bf3c30170c41a6b130f9103b2d12b2271bd8390b146acacc99a3462fe07a11e643ebdfd37dacb5887e116f0ac27316d2db5d6dc7474d7bb59937f8528ced4aa94d7e324fb9f16fab0937c890d079d3b3ce0bc55061b2ff729aa4f0730ae0136e7a74b1d5beffd10a69b6e72767920a41c0e0baf76c317682b3b50133c78515385e5f5afee136d3544130de8706705990116b6818f08c7c5eb8a626a254c1f4d9829a85d893940971e90658e3d58d7a785e2ee1f5ac4ad1814555e3952574ccc3305bde1aba08a92c6609f939826d3f2502352e13ef2ab2cee184c4e71d0103c77fdbc95cd1c75c44e70b0371c8c5b7bce714e21ccde4858d1b08938bcd8bc6fc72eb4c5c05d3443b10fb21151efa875862331bce7ff250a85cb9b4d0413b56313b5d1ae643c1a351accd07334bbb43177e2c860cf8e0d1a6a554b38cd7073b6cbad0fbbd5d28ebeee09b03076e48fcd839e1f92108455be157c5280a6b944e8941504abf0e0daebc05ea381d3adf4bd0200bd1d1a78b0cf7824dded97f5fc0bf96edd5c1fb728033ec057c2081369ecddfee585ac310802948250d7c7619e5a656955745c176310e849b35cb817ba097be507f0d8ab070f092bb83e2b79624da7117d671c8e560991535272e4a21da37fb82bbf6a3a8a7efb7535eb464d64b59f16d62795fd36b714f15160c5b79478b8ad1324647d396822988e81baa12d0c225243e112ebed4f744ab8d407cbae0adf5d12e3396a60d7562ae2d437191fbd493c8b4e6bfad8ae2377a1b91a223b8636ec48d27aa8b77780a10fc7cc74aa4cae3c133490196b17c8ebe6240f85962d3bf3ada7ac8d6f83bbd35c2794b01fccbd8378d39c2a42606959954dfc21be108fa3b1766000f92e48659deb9d4b450641d0fb8e3c00d6f20b427963c6b8Q@@@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-58.el6_9.src.rpmlibsss_sudolibsss_sudo-devellibsss_autofslibsss_autofs.so()(64bit)libsss_autofs.so(EXPORTED)(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_simple.so()(64bit)libsss_sudo.so()(64bit)libsss_sudo.so(EXPORTED)(64bit)libsss_util.so()(64bit)memberof.so()(64bit)sss.so()(64bit)sssd-commonsssd-common(x86-64)       @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ libldb(x86-64)libtdb(x86-64)sssd-client(x86-64)libsss_idmap(x86-64)libini_configinitscriptschkconfiginitscriptschkconfiginitscriptschkconfigrpmlib(VersionedDependencies)/bin/sh/bin/shrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)/bin/shlibbasicobjects.so.0()(64bit)libcares.so.2()(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkeyutils.so.1(KEYUTILS_0.3)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnl-3.so.200()(64bit)libnl-route-3.so.200()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnss3.so(NSS_3.10)(64bit)libnss3.so(NSS_3.12.5)(64bit)libnss3.so(NSS_3.12)(64bit)libnss3.so(NSS_3.2)(64bit)libnss3.so(NSS_3.3)(64bit)libnss3.so(NSS_3.4)(64bit)libnss3.so(NSS_3.6)(64bit)libnss3.so(NSS_3.8)(64bit)libnss3.so(NSS_3.9)(64bit)libnssutil3.so()(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_idmap.so.0(SSS_IDMAP_0.5)(64bit)libsss_krb5_common.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rtld(GNU_HASH)rpmlib(PayloadIsXz)1.1.131.1.31.13.3-58.el6_91.13.3-58.el6_91.1.0-11.el6_8.13.0.3-14.6.0-14.0-13.0.4-15.2-1selinux-policysssd3.7.19-1661.10.0-8.el6_9.beta24.8.0ZX@YyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Jakub Hrozek - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1534618 - ABRT crash - /usr/libexec/sssd/sssd_nss [rhel-6.9.z]- Resolves: rhbz#1473005 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/shlibsss_sudolibsss_sudo-devellibsss_autofs  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrbgdeeseufrhuiditjanbnlplptptrusvtgtrukzhzhcacacacadedededededeesesesesfrfrfrfrfrjajajaukukukukukuk1.13.3-58.el6_91.13.3-58.el6_91.13.3-58.el6_91.13.3-58.el6_91.13.3-58.el6_9 1.10.0-7.el6_9.beta11.10.0-7.el6_9.beta11.10.0-7.el6_9.beta1  !"#$%&&''(((())**++,,,--.//00111122333344566777777789:::;;;:<:=sssdsssdsssdsssdsssd.confsss_ssh_authorizedkeyssss_ssh_knownhostsproxymemberof.sosss.solibsss_sudo.sosssdlibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_krb5_common.solibsss_ldap_common.solibsss_semanage.solibsss_simple.solibsss_util.solibsss_autofs.sosssdp11_childsss_signalsssd_autofssssd_besssd_nsssssd_pamsssd_sshsssd_sudosss_cachesssdsssd-common-1.13.3COPYINGsssd-example.confsssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd.mosssd-ifp.5.gzsssd-simple.5.gzsss_cache.8.gzsssd.8.gzsssd-ifp.5.gzsssd-simple.5.gzsssd-sudo.5.gzsssd.conf.5.gzsss_cache.8.gzsssd.8.gzsssd-simple.5.gzsssd-sudo.5.gzsss_cache.8.gzsssd.8.gzsssd-simple.5.gzsssd-sudo.5.gzsssd.conf.5.gzsss_cache.8.gzsssd.8.gzsssd-simple.5.gzsss_cache.8.gzsssd.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsssd-simple.5.gzsssd-sudo.5.gzsssd.conf.5.gzsss_cache.8.gzsssd.8.gzsssd-ifp.5.gzsssd-simple.5.gzsssd-sudo.5.gzsssd.conf.5.gzsss_cache.8.gzsssd.8.gzsssdsssd.api.confsssd.api.dsssd-ad.confsssd-ipa.confsssd-krb5.confsssd-ldap.confsssd-local.confsssd-proxy.confsssd-simple.confkrb5rcachesssdbgpo_cachemcgroupinitgroupspasswdpipesprivatepubconfsssd/etc/logrotate.d//etc/rc.d/init.d//etc/rwtab.d//etc//etc/sssd//usr/bin//usr/lib64/ldb/modules/ldb//usr/lib64/libnfsidmap//usr/lib64//usr/lib64//usr/lib64/sssd//usr/lib64/sssd/modules//usr/libexec//usr/libexec/sssd//usr/sbin//usr/share/doc//usr/share/doc/sssd-common-1.13.3//usr/share/locale/bg/LC_MESSAGES//usr/share/locale/de/LC_MESSAGES//usr/share/locale/es/LC_MESSAGES//usr/share/locale/eu/LC_MESSAGES//usr/share/locale/fr/LC_MESSAGES//usr/share/locale/hu/LC_MESSAGES//usr/share/locale/id/LC_MESSAGES//usr/share/locale/it/LC_MESSAGES//usr/share/locale/ja/LC_MESSAGES//usr/share/locale/nb/LC_MESSAGES//usr/share/locale/nl/LC_MESSAGES//usr/share/locale/pl/LC_MESSAGES//usr/share/locale/pt/LC_MESSAGES//usr/share/locale/pt_BR/LC_MESSAGES//usr/share/locale/ru/LC_MESSAGES//usr/share/locale/sv/LC_MESSAGES//usr/share/locale/tg/LC_MESSAGES//usr/share/locale/tr/LC_MESSAGES//usr/share/locale/uk/LC_MESSAGES//usr/share/locale/zh_CN/LC_MESSAGES//usr/share/locale/zh_TW/LC_MESSAGES//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/de/man5//usr/share/man/de/man8//usr/share/man/es/man5//usr/share/man/es/man8//usr/share/man/fr/man5//usr/share/man/fr/man8//usr/share/man/ja/man5//usr/share/man/ja/man8//usr/share/man/man1//usr/share/man/man5//usr/share/man/man8//usr/share/man/uk/man5//usr/share/man/uk/man8//usr/share//usr/share/sssd//usr/share/sssd/sssd.api.d//var/cache//var/lib//var/lib/sss//var/lib/sss/mc//var/lib/sss/pipes//var/log/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?@7zXZ !PH6]"k%{f}z'Cg /sJXy4}BzTmDOY+LYY4]|ΫsXkɁ!vS DGqSH fpqA GˋlSI€/ú 3X8ն9i8ڡ.{HclK\1nX_PG%-);c̰իDC-@y v3jM9*}m!sPRw*S!0Sוq %7Zx0qVSD>CJé:ֿއm,4Y};4KЪڻ!4UՇ3%ySC+ @y8Qtl-eFieNxh8:AAiVwQi0!A`W;g;ϓw gv,'SR!1;8b)gsP0kD-WDp/ӣ$ЄoOZđ@">?b~YA+8to:cU4(ܷ|'{b5* ރ$2*V `qM}Y20!H2I`y:e<R!+̨K"S_`C /H>vOV.Gu-+řC?դƙU߄@8ܮgكgRbAtWl\ -h5ӡduAc"ljXd (^orQ\?Q<հ_Nغ(H_ j4cIE+$cC?%w3s2 ^=GUf)[dQM1L[,^)v)d/UpߟA{XSgX:xI Pw6q˸7^ UǵNX+'@U˲TX{:D[6P.m$oj'w(obZes-MV3f_znM@{ҍCT_m;ݕdA̗?UZ4֕,4>;HRh"D<) 7#m`V(>n`0Q ^8Uh*UAߴ%q 4 #`6i5рMuCK_ɽz|喪([ks6%ˏ}+cr\$䔭AbRlkfF|.~BITKuAEPIF!,]=+ ұPS&e`33hi1_iCo>'i1tY0%v4r W>UJk@!0#.DSWЀbu0!Ͽ3HTB{0U- 4ۢ 7(Fa Ggi^ř1hEH Zi1w0 e܄G̯O|)^yIl`Bķ# ֚;r?@\:4eCJ'LH`cuu3@i0=W$?$8*xH+^.{oؘB|Y0D|F7aru}_'+>Ǭ6p)cKzHldax)w`Z~GZ&d11תK'UHus5)I]NXeJ~E3}sп>Uh/ҳ\dnˢx!g:췖9(گvNJ"d{! ɌWi䱻P!5\Lc zfs}xpZO,>-mپPie~8g,n79/$ ެrȈakKJ;]qsGmT3`=INM*Vmw62!AbEyzG^hzOپSY+uvyucڏ*45;-rM%)s҈6)w ;Pɨ'ո9\#'!4|ۯSja&B4n{z@c/~EFfcdHQ%W9(7I 0O Y qފF^%73顒e>šӵ^4fW?ړ H|$1F'JMEF}gz:QhmŴ<'Z;4|ݤP.tߝ C2~7؉[`F60Q(ބ?l04yQ}[cn+1֎/ snCuW2?~} RIkmI7M Wb{M2@7s)!ՁSRV1tL9MmVZ_E'0aU"43n"nK} aK;}'pʡ 1>uOL4~F`f:E-kSk GVVQ8B@81| +%%nFs qZz.Tqp/V)x ΢n@:6d1})ڽ 7),z'wvT+>!*!EVP&˷+.fMhy+7/ߝbage9|[ky Kt(;MMo(̭G{%Sxo==tײ]){ X]dwtݧ[yT[P(8`#XEcɉ4'3.h)>E$b* ) w8ƏJdfٶv%G[I%Nrͳ%a7C@)-kcq; SIH e ׆Y\~*E`8S:a7L?C*/,-0 Bdo?54pg:C/_o?rIɕ8{|*6#Zt`=:Eڋ `JW0/Z½wQy 9/uǭռuxG,wS:'ZܡA2̴-}{& M=̶Dz!U$#QeZQ'b,P /nڎ9֞l8 \nj ]ҽxљlT"g<:JpOb,gQx(׀UIsYz-nQʐiljɈJ>VZbR1Ba'!˰\|1T">z(CEnЗbA0>RSwʅ&CVIOHǼGHʃoa kct8LBp'6]o6!۽г0b_&f[>%ܯt*"7ŁT8pDPKD!CD&>M5"I+ Y;2]JKX9Fela;DQ _ ;Qt@.4;@M0Vmr@1$QJ^BcbJüw ,ЀDzJ18R RO5KMm NR/fLGxg0l,SBO)S JxI2II oz\LCG{Ay&1 BFJ-JSp/6O*|]b#3Z$4'?x1::bєJtA~>ڞن\R+ wgM50-\'jvmq23`"djqEn(+'@**A\>(ȁKNXRՙmpV3SSLk!6]#7Bs ='$38lyG{kx8B|zGa|ܷrD=glE c N->{Zg1,p؜A٢*?q:gLkQD'`?dSfv!dPe<^}{Z7mY/f@#O:fڹv4S@a9.~CCwi|>ʱ?uai;-Tjzľ:,۱EwٽB"MyE~p P¤ *u}zUbhI7wqt?`俣hBe70\Q:[e(qZ!E:JݒɹubISpgˬ`k`)Dj 4$aKXkZa!GM>">~u>$uzuaۼUgl?6,{iSիGrLce!Eu\ayf%]zcfN쩃Hsj 9 Jfkk#ypz5 "ٻJ$G@bB3-fTke %RPnpRSNofEƽKr"BE{*pA%'M8dD9c],~PnM1~F!M]ށJi# p%CV<0&\0 Zt&,M_%`v46zW>6$)|yUw>t\\l,Xn`SDaRhc A#y [BйVR) i',>``c]stḯ [.g9-8LA9 &?2szv&|¾nQeHga(eT{c7ݟܩՐk}}i2{4F2j~@\7Ȅ'tg[l4y׫Ծn˩\bQ7MmT3][[mIiM;ͺ&li:B򵡶ig\ z|`/ vGc)T/+ƭ9`.jWKdgU*J3SMM8MAJzrj]T "`:d) ̔ 8F-OB~Z Z;նP IN̟+K*HruȲ03"Aą ܶ͝D"_@NZ0eQP4i}yRQ O Hڋ$cTק޷r;}8DdjR/&cUvKs*5ԕ,_rCSB^3!iV4ҋ½tv9R6sD^`nmEplW jQ,Hvl[YJ$Ƭ-j{bg"4ٕ.Ogik L)ICdt!a+i:G ;:tTE[eϝWUlmn1wi=mÙcCh݇G噼%Ni]:6N0H] qjR6{Qm(XE J>~;7 T=9¥e¶7Co<}D U`1xC>x+KP2^0s5\L_θj'j~?+TƋr՝׵ɴ%AVBc1i'ass1&$hmL΀RuIqD2oh;)q)P}tiBSGw\#:1X G'ɤyZR(=< C"}Vdg{Ղ,ŗC$nq3M?p]dU|6axSRҘ(5H/hbTT x~6"M?n u׭`wz$Ҹgb׷Zsf]-.0O㡬i?3z(Xm]L9btmxF'HO۵+笊s-7cLH&yD{/- dA& PzO,D U^e(JTu\,(yBTLMcR}LDjI(WMKZ.Mkom@Ǡ*ޯ9Er/C^58]<.~7u[THJ(Šv8d*N]SM-Uo(qطQ& N{mhd= *w+c3ٗZ``ݲu6%|=:UGB6`+!YϺrRZn1zn,4YvPǴpĞItPZ|\ZtȀ{8lu5L36񘰘˦LfѳoL8#ICkeyٲ ~`LO:L;lD)󋗌`J߱{5n7Nznjpm'-,b33)xB{yf^Zcӱ0e~70p: =ʲUjbT[K(Pnɻt6:qWLZj' ř=OH3"HJtY4&ސ |݆;4\A4KׇytED "Z֊WPT"0~sϙq"X$c@iBI< sgSK~f#I17 /h/d >ihii5 Bldv-0fkV8Gu\7O>t ?vȐ{Hhk2]gϊ꙽+s!Q ǎTjع~6VkRDFrH€[RԢ,zDXkbgT]kz1M~dE Akpw|D!SghZ:\(zbC$^]\QKJ^EUcIv'tZ]|9z1bhiV#I.}+ ( = VN=xyB#ل@%@`߷sv 99QHe% tڋM["(5XRx# s%Jd.Ta_oO b^淑wgJ0`AUBǣY+y!ۍD|ʊ \ƕY.s v;@c4m ޫOm4U.פ*9pQ]oSnws|JP3]˃<;^BH"X:$I${N*ߺ uSl|Y*ƪ3ps {ȐTD%&AE]o:WNB-d$Um$~v S$ŤasQ?PNE,PThm%_ҵPy[b@ NՓG٭_*s)8 Lwc)iif6J='X|;IH#vGdn`=狖%2!UdCqb hU\PPDɽ(ܱpbSp'K-TX*<-2(S'\'[XhL4@hn1KN}kCV(Eru?SO-6 5#y}6?xZEyL>E9J=ŗ%CT~'sC@P]ΎBz6Cmlp5/(h9Mfw\`]Ora6}u>FTHE3x"wp+ A)bP{"ں.)'@L*-M zR~i X%aJα6ojWEƗr0#| %RI Q{ 6`L#_ x`rq`T33$_/ul=C'ٴDY"%3 ˚OM m[<9'o7#X63㛩But)d-Z7Ζy'LP@)ê ղf5 ,"fm¯zdk/h'TpӽtQHfݨkWx|x-%KnwϢDjq/bܤSΪ04 FqLVًrZxTV;wm0|?]m3cqF#!?UgƵni*{j8i8 cȗ1\Yl>1:4תi%1vfܣ!0otܤ.nNF>:G7,sGA{6o 0#R'cY U8"ߓƱCF!E1Zyc=VIȍp +-\]!- -`)@!G̏"v˃ 8~o2J/۬!|)toZZ9Fe}GJ-C!^OY? Usnط<!zDp]j(ŢAK+q7k  jť/ŶOUN|ٸcP<9U>D"zBD4hUJZEr՟z|!ͦ4"rLB7FNł ]ko&@7ywe3PvwuiHm oVU l[xV_bg ʄ\;f\+Mow`QGĝQ"ž;=gȃ.@2'² \o\dqN j>G:U=s2r)2`q%eJ+%!s@ePbF͓|HaM8g;#Dq-hɊ vZ4!&ʗ[bЉB&y@4QTD%:-ؠk4BkUz:&߫r`gt5<4H:5t\]3e |``O-4 .+BsVBW߂9fQ!撰 tP@X$y ݀ˍ5vRF<Ŭr/'JA؄Wki}|e"# q 3#@rhZAe}UTJ1{D)q]`֘:L{Hf`#~V֩=tx3 CX5.p)QTCf|lۼ=K^ӧ|x6uLIM!>Zb]r9m}i pb;if$)=9h6ZhU<8#u_NCB*%x{p ,KjV*?qJYO)6Bh*dQ|h8Zҧ}_M51Ƨ 0 L8Θ;~|g e{/WY)|!wH~= q}&o@|7;c>.iE 9sGy<Ѳ C;`kĆ26@㑼+cZp*"~5bzh}.ѦCfG(:^pXZ+f OA@ vJLR}z~lsw(d k7֝~Y7D Ý!Hm T֪ 7k@2(I]򫜧֓t,5QEϪ&sS備uB3f=ORP 7^ZZ~@߱],]TpP˼N̮_Z`Yi25ˮ| dbE?j\|fJNzrXg)h,Yw0[Z,Z-ib2\꾭~ۦjsFuM<Y񋴋 A2 -n"~H$e1ܿ긒oh85!Mpf\9WR* Eɧ?nA0ԡxՌXsD"r8iYN״2<Ⱦ "u_Cf>H@8%}sJ_۞5π:*u^#Q,X1:oqBE$yj!U>AYi7AYp9 Uq\qN)˦)'}\#_H9- InQyJT" i0O07%3 <lv.*m3{ԁufzʊ$ C bw3'DmrlSczSO !FUD'+&C![/j³ h +DŽ| Vt치RwH^l@uLrA*ɅgG899ΞUmuSPi]2i ?oeӮ8S)Mw%Jpڛ$DZuz|m<>\v-m2!\^( A1.*ҏm(:<"mOA|+<\TG \3Lq ȞzU f8~)D<|xVIb~ M* iBdX$OE;qFĪ*ܢYPy)Sddt-m,}rZ&8prk$݈ ?6͛Q{iWN " )8OD`ZxG_-.K*Nnʢww&ܩ[N/(O7,տ[a6fOC":6] ܼA邚2i$@tE5L.L6eSUw[wˆDjyFrbR8_xw2\L~Qe`'7cVۃr_n $%d| F?P5FbEwJvHWȌީDe?LȝsqsR'm_UW@o%(C#w;T.#T^>2Cw-y>f4 V Z6wqe=4Cm'}޾6?J(:koRil.k$T> U_$pweȧo;i{I 5E}H!%1khbt]zq5!WdO_^' d|.P:9r׷iA"`;746(7y}aAbh4J)cCIJM+#w,X I/P 0r}Ǥ3K ) +/*6Wd\5zNjBqο>z^sM851(a^f4UA\OEN>'6 b(V b!؇G^70(9e!M=fF(+h_T(}Ø5XW \RZ),;𵦻:l7QxS}As4]#IaTV T_^oNRJ KS.3L1[[ƛ$f&2pM臜-8`flsUob/I~($9޶Yxs 곥2OPn z$S>rb#,c'y7xz!Yx-EG ^͆,|$0<{(. C;C~Hyۓ;7-GK-p* R4,afWfp[\H#Zd'&4ܐGutش@xfEg-a[a]hdPE璎 #y믻e0E`vxJO隶 7$^S6SŎr2^¸Ɲa iC\K0k]AS+啗E;lXJ(VU4$*+;c qjkTG .=jJ,*(hH{Y5bkU}&g&}`BЩ$"S5o=/+ݶ:`i%H~ܿW`|i3%Ǧ'ݰ8/9ɧ i-H e6ɞ1]5*u>7SV :`›ڌ-*-LC-,nH  tnD@j+Ϫ4tT+  R僒1[:l0|zA+ͿCyvtO=4*].i#Cˀu>lJvj~;+,ߐ'MMQ:g$M#X@Zwc8u[05k\pQ:3GۜB'D,%lV&_xpV XF%΢~ "R(8E/#p=ksx:<\q.S`YxAcxHyC'tmV_gnqXگ&V;T&BɠևX7P_}3 MW&ޭ7g7,i X´fYɝZQQSSL?,21# qh ݟcIcAu9?nmZ-G˲9m!5غ@.KRH<է!a-]֌,Y72n.**pֵ8C&$xŭOvըzÁ  j/CkHE'i͓SPd0ULqf*F=*˝Y.|DhխVYqջRq>w#Xb3b:$lKDTj w*I"5q:ҼK3GuÞ~neY%ؗ"!"㠹$8L#Ϣ ?@;t]p)d:$\`%ݿMNl !3o<:8r%UtsK3Puᯓa5'EuAeb*6arW"j9C0H:@G+:3Sijz38;/Blm|Y>{UtG̩(%uQ$R̍U?/ʝ\k@uZ3ͻv&_sI j;eQOۆs)_a?|t.zpJe[TD;;uiGMnv% &x#dM[uђ:ጵ` ޥJlWgA)9s:{<Lj 4dŝ~$8 $@()s{0@2.>CA|Łq=;U%<@Upynѩȇ4c0+ӲGkݝpHni3g0WS,-ǞZ >AK>qm,|{Aġ:WuiLd|y/+ ;i# _, U6Wgh}IL  M1s8s> 2'S$f ڔb>ٵI${5j>A."!MJV,EksE ͝ćY.BieVppL//d'DZu{ \;iO,nMH6Mmlo+W0ƩW7G6W]OAEeJ7;^-KI 'kn&j|k Ǚ!~ݫk8̸SA0[HH:}}n}?E1WhRpK<=v<ٙEI?AXx )/U™⊺jcɴش̽Knj"AY h$DPg,GXrʸ馋*u!m?<+64@rXT=QqG1GS6M9R6oӗ*ҹ<â Oq-5K$ zز!5D!͔~|(pۏSdY@FT[136CIJ|kH}I¨Cě&NxFqg}m?F6h~J- /z.q[s+i( ݿͩ2/OBհ[%'G7=~aKWp4`MVO4jgV/ıRv`QG[3]jOݡ6C)Zyh&,uV 5UYÿ50[K|'O`-︴1隖P̵1aT5#QۄŌ EXmDqAC9Hw>蚎".[v;d//2Gj*)94r $ٽt^`]O4:͏ epAgB"N{ So\VQiǾWm6aTu"[dB#mCđm69=!l&E53bwY[ -i=NdKye~ar)|F=WC]챃3yJG/XK1ZCSi] ePW_ľ_&{rɹ[iz5eji0F_ Nbț\Bu84qxeZ9GN}Dqf}Ωr{=}{ے֭k9z.ϼMq8р)MbV,fA`PHaLַriYKg㖨@  Az {Vƕ 8L9wNL!5jn/0ΖFSBS=/f^gB?rZ>6)n7Fũk{u݌ZˈM4U(̫#p(qwɈ8-腞C7ؙ 4n50 ͥnʝQI-~*b[]+ e^̺#X ѝذK,H2xss "_w~d01e¸\.)V~4_6` !! ubę:l IfHzܵNp(Hm'"BG]q+]}i9?uw=>2 |!ڲTڣbJtA@ NH:ZvG9»Sq"Q$!kFT8,jZ)67p _M ЋYodnL 9vO7>Pz)ڨ[iubDoqq-!|@ m/]-"G3 LBއ{ɃZ9kl%;E(d׷΂6]8iv YN4DE ѳHSGKcmJP5S XyjH=R|& a&1aw4ycD=\Om7JA*2EBH+e[)]߷]K0XӺQSjpߞ\j^ E6ŒKʦ'v*(M]zX<~hs5g|ihn@u}zY>sS! kLME, u8xy87mpUGʨ@@) &9Toq#BƃDb 93k4K8if%:7J DZ.>x54I_b&S+n%dV;nkH- PBU3u(<īi0)EVFXNؘl@ԤR zޓzFفdpN`9ք:GB3uFl"Ps_2sІ,Ql{%-,uGy$ʆZԾÐ2_D>=:?pۊk"zS"*T X[HV%}Q2*VQp/0w'sTEwvo!1)̵ɄYW(~ 4ngAh^u-[ ݧ lʪ4Aܸzaꖳm w[>:!lh!Ò_q&3eB.> gzq鰄~¤[I4(E[j}oˏRQP(s>@͢\qy&:Ú"~}'ȗxQDH 3^oIolђGdjnypbv[$Hh:s磰xCYonp%7 : ͖< ?JHx}6bt_U<,}v*v Y:L0l(A)RHb2\a?:]% Ǵݪr?%,{?uRηn}Cӽ,lآ0G nK?zJpM" \kcͯsjB Y΄\ PYx;6=,\*f)Cؼ–Q+ZKE5w l8xj@X?FGzo@G4{3U;|Q#"βoA.~׫x? Ĭz1-~o%$4ܴ1$|i$rjE3dy>@*/9PÒC"0{R\Ojr {S;s7AWmAw-Ooe tX=`2,mX$Phɶw3 }L:H.{xB1ycs!W~Rb50DsI^̧‘<% 5<%U, O H^.|Wc'kVn?OU<k Ǜm1A|d /!)_"J6F"v~'{nK]Z4)x?ۆZwb**1نcz9|⫏4;F>ǷG =)7Ֆ T,& /=tL8pu4݉2w;_C{ڐΞua^d 8Yg~H@ uLIT=;T`۽RL~\| $l?F6KZ0.,ZZD/j&mq_mW Ao* u+ZmJMxX0]GZk/mFQBA3Z5KYhqڰJzIPAB/YfVi7aEdm[~KtJ񒬵7' -(RF_8++c?˒Gywkc`E%؟XơF')B]aHmjkږ~ebw7L ,{GumIJm)d4WIfZk"t| FIf ">75 oU7MsIY?W*磈Ap bi^ORP_OJBNz$g˃WZ) 5|'zˉ刯C8?m8YrF&9.njsCr5ѐ0bNXe-2c*k/b<<` of8a\">lx9E5<(~ Y 1݋˄mƹzƈ w>eMѾGC,nkҿidٛh5o9tzGV`[+\8t]{c"$1GjX(̹! ]<.qʄW儬+Q@'"Zw'Z%kz@]e+"S-]Mjb(ReoӶ!.o.X}+`L@45s2\~ӓ߈~bb6˻kq_c4Ys(BBn2_hPS;"0/HCc E)uZk? a}ijUѵ"UE\pNU~g EKYi4 @kZrV{ ħڡa[CBHyqe]#|8{qWn[ 4aW,Hg û#hX~* cTX+M\kM6(!7V'f>&S-F##i0z2G n5n85uxўC{ *ux9yqpT_S9pT(ؼlK7!2e5pc$YyUtf5G6S)dnJeα|~th <79োVjG;Uf+A: U3:J:~6o辝uZk+#0N/Cowԛp31H$SF cƊ3OKij Ԧ4 ԔTaCۘ2O)Y^Gdn ȯݩWGgN[ChѢfA}KU̞7;0; p"ߦǘ|QU'Db3[ʜ[*H؁=;W1ONH9/ں:N`⏅nUW *`\'LNM xu? ju=ĕr[9ߘ*RFǏL.acX9ϔ y/b׿i. Cla>J />o}qبx㯨ǔHh&u1*KY +6k8). @O+C&/J,J R'U\h7JiߋfA! +UɇJmM_oW2q 1v^u +|{r(wHX!-&g-05|D2PaQAZNߡWutv#,HJ3 `)xZMk ?K3+J#d2fEwѰ|fh 1t՘g!C WSlѣRdEL $tzK,-uďdzԙcI\3] >1_B]|(Y^9f0dR{Sd3DrNEcMsh6׉ydŲsЄLG+\ܨWہ 1x"\* ?"m-/$SfE|c*/BjfE*suw; g/5 6E_j4Q6R,Wn}Nx9yBsz,*@c-$a{@6j!VΖDkDTk2rU̠fht dɁ6F?+^D t.,b+6eC\#G/ovV FT}NF9 |p/ٽs\tʯx6ld~d9so^5 A/D1 cy._MCCe8,B1qM>PTPuq+aLDad:= V I 7tE ۤoey{6{Y'D p>:OG}<ANm׬\}WiAgsY6:2xX?W_ a/=d1N|uN 8o b> E ĤyW*HJ?<"å&Aد HKCE<͛)=nHF7 \0 9Ksw74b.-p+J4 o8[CƖl/P6$pQ,v j-snFsͼ o3{P^փ:\].`AԽ?+";>&#&kD H(oye6s<|XK&ߊӒIx96E? Ϥc)9~O;^N G[tRٙM2n;R!Wam%oW6>}No3v7ye(Jh2`15lzacO%O \Ι<Z,^3['3Wy'w-2BT)Ձ?Η/cҥ[>)#aQwj{Խ1}Zӌ:C|yoEPal]3>.3T N $3 ?kأƊhMoX{S>~u xym[Pgy_j9~=\&yrGnc0oe2{p ʛߥw/ɇ7C$/.z=|#'Z"s9RJA L)(FeE Iۣ)q8Buo-VG\Kfch}] -t+uK0N_|]rXGi@W0%߈] JG~ ʁտR/+Nf"HP qou/H[@.s~!-AīO]׾AGCW̦`@li'[*2hge%h"n;<=}A({x@ ިzJ"˛@TaX"d~ZRc6XQc"ãﲆќ0bJ1?:BqT^O% zo 82 ɂ>*!>i}5=,ڛ( -xmS,|jЮJ-+YurmNM-9e{6jj?쓦ﮈg( ,pVkLb5)^1躻O~ܑا>n`߃bz%FBh)e{DlJAy1CGx';Ֆ?h`&>K)vq[^!ɤadqܵ p(>:cY1yKX#d+ HThfe@̕y}3QyMqyVf=T|,nݚ;dN>MM$@TР|d6"Js^qĀU6b`zu(2 [ A㉵p)Wtt[>^XHGaڸNW^81X=okTL@<4A8N CD$)_K5C!G[Rӿٰ+ہ[_Ǘ(JVy Qiն@1iĽ뵸3AYAD! 3r'HFG9;"P7$m|͢ݛ"AڶTm"Ĺzd3(mԥ$ !~Vu}ӁxyP./X<Ÿ]3rdP ihP:_>+$%j;P5L7*R׵Z Je% !y'hcwSo|Ӌ^\m?視 e*v-<4.KB|,^|jV^UHXF%&T]# Zuَˍs4u,ўݰS"nV|І=ۣW`% g64ǿ`1D\fv0 'NSvo `ɄscmQ~juő,QQI bȟ5(yok$wH3狹֞]mZ2jo(,|_'ec*TsJ(U+&cuu/2LU&|Fvc89Қ WNYBa].m'=5$3}G6@hu#jb!g&osU$=Qz朤VQxsZ?춓#"y&S:Ӏ*5M<;$H,\QG,v;6PlÝJh\s `8AZ銲pWH-C3e=L-[G\!ݓ#'a}sFh:!@+ ƣ "s(ѯAO5yI12 ?JmF$%5餓iwƞ84)>LRwo%6Q7xZR4C~Ħjl7h$Hu2yYZ]p-%ʴ[O@Ɔe/ʶ K@ d *慍nOТ Ϝq6\H!ZtzB_t&^U}-XCI \hA$}B|E~ھ!XJyyȉ:0~2[6P7%n[zx2lE_j ydÔKGߝc0,hDdM k~/- w/ մ&|X(/WSlO)mnm:D4DcqzeՀȕԟOhD n-X趢y0Х#j,ȸ  sKS!php=9,Q+SU#_1$3$'KaBk,pFTqGJ&[X@F\}{^h7 gix!ȘTBW@.k7|e`l(8p]eK3ͅm`'1N?99Cd9cJSS5H7`:eA;FƏsv[[,0^ST47t6??SAC!//zHt|L_8؈vyvz*_ˬmIY֪ 3fB.O+ӇR7Y%E}p!q28.Q[ "-VGX]o4*@E Oc=@&6Q5MN!үQt\#|Cwҏ0~]}䪛h:?y& #y-tEI_ً0LW":dE"Rt΅/]lvP@^v\os4+Ћԁ-g TlyhHxFܼuchQ!f֣qxe->\%&16H.NtHژ6X---w- :H&P )u.m FSC\ uǓֽqt`_'ŝ?V}Ѕʣa:P΁;8^6Yinj‡bbEqOc| ⧲Z0ޤf!aҽrX?evdأҷ1%eπuV֔y$>=':!NƟ/(]SQ6?t?;he.8FOZzu ъo9`F'x~G:8~5|sVyTy@o\i)FK3{ =;)NzoEg6*K\ ٤kDD KsxLi262Q6-vލ_o[bG!%:֜& f%tOC 0CU3s%p![}7dֺKHl2HD  Bͧ%_Ywdu'w3zd\ħxkg\S5b%s h +g\\qb;!YVxK*KǮ3WwZ)36m 0qQge\ؚz7T~>4]eMrJܓC/qRڗ&6P")a)qt 8=l.7B܉BGK4. Q6A!\`aRYezT0*L,_;1 \R}#wsJGΙ84/68rҕR2@?( $~My?4(zޘftr#^%חwdm} u &̊CJ @OK!EP֞ɷ~6[ ޷ܖC_!*M9˳ך0aӯ8S=|.FbZhT+hzOOLᄙ&we(w3O[tUFjQ`[cZ5OGsBe8h1FYTƉ҈c:R&,{v;1!|DZR:므 |rЪ _л&fys)D.[Epf^Y,qgZ_9_Gݰ*هÖqq}!"$8!h^}ן]͂!)~Ɇ*BmSiZl`~UG\kpKsl:DQ~Q`SCKkGc_[#&gKz=0|} 0AKS\WBi(UKT1A|X̝׍QinŸlb-܍v+o!Y"yt:[2VMu/QҨ82(HcKݕaQj0v>n ^PQYVAUzU+yl0EHykԃ"H,InG眴0&rH 'd6Z>밐$=ǎ)`;p ?+F뿒#҉JયߚϽL,yɋG]~ilcjۜB Ǽ~\J[KS,{vvoM-f LJTU\b;qLo l\rwp2/iY79߼e̹10"v ЩU-X^+Fѩ pF* KkF E(۵[&Լ Hb}^:Q=WVKY-K1sVT0OvVITf QL?Hvm>{DG,W{ A@ gDN >Ln=*Oji @i&0ڟӁY^]$gw|C"Yn(礟scBKݧ/\,aZq=[>ֵprwIǐ4C_cd%_x<͊BݑK*w[i_~eVKyS@Msu-|1orQǝK5-9v$ "7@W`kd qTq7?vFb/#_Z7OQKNA1'd;BH #Ax#@%hTAm=&9W@8Qqk߾,UEF%Ah;v$-ٵ]烼 S"uNm2AiTavw3v 8(!NOlJX`_he8:$,Fh]"68;If,#2Zc+1 !ù'&sbTPH%]Y^;;g/ CDl#PHFj-##3)U>{ o?oDhCw ]-g#BM)"Sllw[F}\hqӁyB^`nC_ %Ԓ}ʸT zIB`zd)cJƆ w sͲ|z7x uy2Y"%Z\fNH2%Wv;"(`Ap?~ähݾ4צ= W yy=/ gna!eɷQ ^n=f-?_a @Jzc y ouMXh2B6:a&WXe%Ph>S1 XKY#+_Ck{;vA@B 6jLxpTݑ0Y9)10=awYǹH[JZX`AkƳ# )Qh!•4é]sͷ$N^#^E袐m6\덆ΟOqo%پp8;`R,}R^(K6,0>F%T&yM}qû 4 rF.S29|x$I` dH&Wx%m $;Μ9,;lh@be*fil7w!{usyJdL,A'U<4Dy>m&Cp2eGώ S{!+/cT>L:sn URߋ  QuYq D[}pOLw;~zJ_DS0-V,~ȕcG*8c(4AZ]@t L>ٗ<$Yﺙ17 VP5sܖw}*Z cl5+~)+jK&Yy]3{!%oEܨ]G-־VwXVЮb^jmg"Yz鋫+c&KpuEJ,+d==hpOi_άTf`V A I wǴ v;~^O4̎p9',-Zp5g#$قF]8(EHղGM /k0XnĮ. ]P IOkdBm⽎s_rypr6-/-,gq}U]<%MBVfPn{ .4y ̓ ? Q14]l @|m&=w'rK(U^`3ێvI6VK3.2ePsp`9MxӮ Cl:Xr }w}I-oƹi7Q'0Rm>P?/'qw AqZf zY7mbQR+pG^ t"B[[6H}F H4XuY TK|j:,et켖o]t|ɬ*>i c wrدy>5x&`Vcjȗ9t)%" 7,pS !^z 6Cc$Qy̺lꦫ0?3(n" iuVj%~(enPAN>dZB&䓫$TM.,,8rjȶ>z`Zl~f-ے>pw<,EУ!8?.T"Z$KtA+j첻0z`}&`ٮpR4[CIjZ_"hEJb)Aĕ$}?=iKXCyq&۵gn4pN.i/b8!(@}݋<>\x3jV ;d?- <֢B'R'U|<0 Cj>ZAI[o8u}15.|qLO~a=SWhIj,S~UֳQքy ,{9?Pn8X&!avqI5a)U@ p("8DiI  (nʟ:ĩ.` A.Pe> ^R}XT>5*XJ> bFZw'ẁ~'Yl0Кg&t\rŧ&rC>YBfE!uv1NC4% 01XctFsfF^*?:y[pQ6//Y-S |~/US[@M挿]O?S ~zRij0z7dM _CsxEPxt .:f#[*C[SG6wG mviVBPeՙKW㏩iRJ?#`Yw b P٨~L9K$^(NZQXI׃8_H5`.rpW?ru`aukvd@L]]S!.@(sjnGF]{PM|Z̞!DCky #;pB1D<YcDG8cfoX %x,!rlt̲dS: 2_T9g{]PI2倐6^8u<{Ϝ\kģPcP!fȋ z;u`fxK[cAQ؝2+N}B&sy")jfs"W0,FvK_; /Pp:mKA[xpn)o4$V +T Jiܦ%O]a?jDQ>cm'K׌9c *[FUöe)iAbaP͈"RT{[ۑS9HchxKͩHEpx1C]ˣd?51"kܸ# H-.Bap/>X3W;xp^p:Pz=:YҤu3a>dĩ;$\'/]vfF9lr>wK1{ .B_WRGHaGR-pr[]0eK ps}>d5pό%]]Y|}_݂ kv'N94p<ɞ|yDtg Go~ޜ2f4x:*Kb][u4B%( |qQ_A41!ӭ"$&ЇL4!vKtr:d~:LU05r^^[:qYH(bV/G/q+u @1}ZAލ-ma#jpT'}6 >lEud?QFEdSzѐGKg:쉾`=7PE~n-[4<o!&RpQ{٥s}{WXqSkx\cŌ&TiͯQ`~@P$og@ֈ ִKo@<%T1zҚ;콕:m΄<0).UU7L/N3,9Vtͩ' [E{D3aoKtX7\Cԧ:* *-g,15mQJp:2;nxm"!ej?ˑ)!5b慆F/wuZ\lȐ|LcX?X$VHXم\_qhݷCh$VrAH~: @'dkYSdŊ/_㧐 IOj o-zUCt}xǃ׹yO(";IEf$b,Em _ʩYT]r:NaWJIntG;rfS[3 0]]3&rCW>!dO[v3J g9)9⛠9lM_@"˾TmYgMQP^][kt%ꤴ,Gv:|5zw/>hju(rM@iVfe?5DK._(Ws;ĮD(HFN'ZRP .LF'.x!uWAW zsA6V/^*Չ>3ɺLupZ jhK+>x1jgqHF)&|ĽeAI70$v6b&Ê*c2H*;ئ-2 )K:>Fl: {iP^>!W9^zsj"%ǧ{^\KI H!%4ԟ`-1;ui=zB/ehPWu}X@]PNC`HڱmqLǸ!BCVw9䣸+OҤ g*Y˓ȼҷZr2Y&HUt25 G' @Df-ydWY_k20py?ÕÍzX4]Dp?Hb Ҽ'}#h$hJns/c!;aϛp"G}B>w,YנDf!}fdW͡X[/o2hA2. ݅u'5ռ^=EXAgW~DeRCKyX^48V;P'Ucru^UZJh$oYAr9q E?QPa`FzԏN 5E"Mc(\.̮).0u@Uґ /Y*mL1ë΂8`f5W(דe20B-.屑 2YӒܻ,,zO0Mbp Vjx1v"k8pgR H:/ p9oUX7NYX5J ʎGL#s?ݸk~bQԏ35$(2^}' [gId:NPE[;/f%kK4Old߻#K&zz ѻk+׃cq 9 8x%d ZmQ%zY6!a{h ݰ6ys^a9V_aG*os_iNU 3jB g 8QjQ}iϬMo%*'RfR2 5 o1WXʝQW<&@>D.GIΰo[)k[ΤA<. f Zz+Y %x#/&u&"+ѬR0 AMXJ>T^d6XwI7@P3,{6d#e(4#/L6be9p#'CODD{[K\Ŏ2@靬(0cY CK()W*d !cEH[>ed%)pVpǡFbM4H[swu7Zsϯd͜M|Cp 76jiW)jQX08p(@9\~O6 pPNu d3/w7#.n=8f'R6mjLr.tSqI7Hu@P:h,q5RD䰥/lWœRvXb\6>}J[l6>@2<90:4 $)LC7%NB5ܿT"O؜kpޱ ݍm۩\D-vbeW _TY4_vЛUL*yVˉBcø}0c+<82^AQ͸g? Ud8* -/Cu>5ow퍼%wW(+$&#C%n"d8z[n '.}lKM5SRkԥXM/|&㕡ϛ z([*5NU"[ybKG:,J꽓= 3NS?D1j ַx6;:s ](DUq}O^֢5GVu9aHP!VNk/WΗty}Sr{q1>q=1۔Y{V&=Y ZMj~!UN?d+K UՕ,e$1^ 3q.ڽõ r ZR%#۱ÃY᭿Q,i@ =r>(Hә)riAtYTOV(;q8 y bGd޷0׺iX3./R@w83DPy <iHE=P\;Sƈ0FY?R5[{ë`MBvﺔ&~_9|]67+1=L"[!gP:t6c,7oCz(0ϵD1+vCB}#+uN]- Cr`,A)00}Nfz"{2iN . A4geK[3¥4mUm ㅨd#:LsC(%:&?_BW;6 \L`L&b9ZMgONP}7rD._/\4;G iyyldF_@#E l<.WysTa˰'iSj<'[?r)Nkݷ/.;g, /-ַ`LC'P&Gy\~su(eE!o7SW@BƳ;V:φ;t opңl^c0H)>u~܏P迏!0k~ESFRxW*ċA|繩kB@ y]>}L" ^ca,ٽx/*րa+wo/=>j]jk։~ &o-}9sĈwU.]iiLI8s|h6]@ɺcuҚ< ZS\mo\.~HQ졈dzoןW/̻"]=Gwf0N%n¿У0hE dau0[|i2ߤ ZLf KWˆb2TvMcM>x q"q(n!gSXqKL#]CW~ fa0 HMȥ^}f-P6 ?R\+. 8VHJM4x+̷/ pc\"Fx~uX[lx|7Ua XLN`փJTXClg'8F8x_LYg<˫Aкa }J &!29 jr0/uWlddR z-O r 06s^,PRQ)te %z@]A=Tid* ~, ؒXo{|&XaeWեL1)nh̺"bgd}S9q{!IS> a9B;rg[++ֿ)bbjFꯙP. ΄~reiҙ\E'IV&9V{Coz:r^C";RŠyo7 ltNԨD>#^,CsA`wxpK!CkD'@Ԛj M|Uȫ:n]82& /|C:ɤݖ>*FoE5XDhFY設AQ!v8xoc4FZmoƅ6xĚrLsb7! ȳ1;!; ~ rKO"vslms:-{6?H]=DjJT_K8Uel Oi6e-ly_k@rӨ0Z-`ftx9q;_NlF:?3aӭ-xӜXGcwpY;kb Mxoog|k&_<-OȬccJKEfIEN8of}-KQ9{UHxD+RkAn]F[POrK!ջH R7dU3ۗٮdfi3gy7TcIdЯ{#QYY)s0K  c+sUR ( 4]!#(ak\[>k?ͯ}Ҡ~2n":)9V<Ԫ`qBB$$'䡄JܮHP(4 t#˖+-* ,VԼ)s>(>\T_KZUkѶ|Ïǝ\}ߝgm9e't3y!2ÄeÀq!37rVO"?x̭Ax4qQJ Xix伓Ž /^d/{|^CJQ"*C@sv5DQ"xKE İCyuRDM$.ŧ#uI9b}Mx_e.:`O 53[' n$heKe$UiơOp*)nM٫p~n*z/{?_vNۺ_yJu,c',F8KhGP{Vn: YѲ<2&p qe:J8.))^Ы|@=G- /xƕnsiғa^pT9Mg"fg!Z LjoxBCDUGGq}r4zp:3Zl|/%!Kn(ud ǖM,<ɓypL`qN:ղ&Tºh]i^ iHw'+I+·AIϠ=^qCf! {IaZglp|F<^c6LRQؔx$b螰QFq?S ʻʓD R22gcu N> *#B,RJr,*&AV7iu#mJh:A%ddfU`;DXS2E٥C?P<0{lz[o! "&ƺ:m]Q} bS䚀Dvg8#Г"^1RXʉji/S! vgyBxeah~-@ӊa!H <1}Y`9Ċ(_%O2ݚjC8L}d1'bod. Rze'\|x͋|qEK=qp5zwx׭)CF֭`o %^iYYRs̑ZF/x8%Ʀċ.3Н:#g;teS 1MuPLZRhg*T^Qf%;$5p*wP/;"@s%k> Mm٘tLkx[.m"G4#5O@n4'|up9𣿜ֳ7h9rs1* I5pGsk'4ֿ%?vvO rS7J-2eg# W%˓_ǂ~7O=[Rׁ \j k .L!sFKH,~. sfJ$~UUloUv鳖)'䳝#:G ]I4.w0g1uHaGB填=6B3HW~#r[}#kFب^v,fN~e±]B,Vk߇\K tckezolW2$:0y\:'4͈C) MĈF4Übê,;&_J0$Th(9{A*WsF/q5t)E ^01ɣl5xJ?ҎE=:?̡grD3oD7U%D^2M,^>v8odھ]aWr}*"dR18!v~q*~qK)E]GR[HtRJΚ~ -֪0}?"T iLK-_#k͞:djiC.NY7}t@gxr[ VZx 3v3u/-5m%vVe/VFNk\ǺE+كY)1ofN9|p?z QXVR%-v5r.'#oDMhl4oTI4*;bs6⠀éO4NOk ZRw=UBwnjZ؎PDXi"*)O+l('h؞Od~M[ǥϧ/KF <'Paۣ ~|-80h'ߠ=ʎwy.JOTDFf{ݒ {FzR粿')oC@QjY F3|[PhqkL#gK@FjB&Yh.Y}#v,u$je{aa]rh*e/v('|VDt:`&OF,v( NhCvI7Ů}wʵczr9 $b(P׆A l-V(IImp=Uo!7D04lLTKe;j}*C+ֺPy1T3iKzt AF:bgᴠMny4gf߽P +'"tOݠ,!`֍07!v$+.܆pdf.cb=CᏠ v~gqۈh["Py3@֚'EZz (5b gV0o$KSpl%nNG U|z'߈E%nO?>svбKoݲMoQt8|pr] UiM qaZPahQ O@֭9__:6u,pyzzj-r[d؜()Lo/5'>SuUboI ׼tIM.f@fNdChjSl6I39b:?\G^J48O􎍓ᤇuO?4F@fu{S2$KACjAsKqCrKZUSb!CB?a8r]$ΓX"} ,yUTdAmڂ?lh9'@Qt(ot{Hc6J2݅1 RS_QX'bA=̙IY¦:i?2:$Bz^aТJ [_V*ÃRBP{3Hy!%z4Iש6'ȆZD3a=)ΖFSD'Sq feD><7'1U@TskG~9kJJ1esppF,o`Tm䄀2ܧ/69ZnNY}ڼUonBl:8-,7֫uN;qx"[ nmQ y tը x$C۝A2l*>.鐻n@0̉9DIɍT ^NCLpo =}ǍV،u1 BD?ֻ(j+~4 ɗa>vR‹;Gv]_!Eʂ$N%=TbZJغs z E_/!NtM=ymCyvpc{2@Up$ \ŲQꕯjNN㦤Y@ۓ%KۥA35m51)(g,K T ށ.]5vhnmpđ4vd]s%_.|y# (c,ޓ" FLm=8\ lcW&٥]jr:6o+ 5~KOW $oD0 I,ovsw?v=}|bƗwj@gkS!VJ'kB!ʽcl|02ZBuql=pYЇ*ٿe  ) "Ҡm̌G I\^e g`tv瓙u#I2t~f87\ױq*ɎG66v]9MdO_T>羻euY]J-Vbovhqf=2CbeoO Γ֬F Jx?>߭zr%eSW!C57"c0LZ Ui w`: o'icp@& lA˴#%XNJfM^M#UA*K yGc?|uyƨi= 0aÀ(#Vp+MuH͎0g cEL~,vmXzRĔI$TSCq;mCr;LB/ U\@ j $Ë~27jl\nSiv+aSp$]30Rr $4JY,N%~W-Jp XBz|{+DZj>߶)&ʛm4'",~ͥɔ{7fp&Yx*2. t{p= 㓄n.Z2'џ26B`cK {*Rl6ΥۙFjt]j+*fM(?1gmS k?Xx1Gn60[>I{:&S-96ca` ¯A͈҄ {xqi\OymzbǔjiF Q{l1~@MvQa4qnSأ;ň^k׹rT_ӹ9zlfMቡ2x8ѣN1.J@Hp\ai\ xefڹ:j B=3=aHߦ(~ۏ|各y{]VR8b u8n8猙 {39 GwZ{Ҋoe Ӌʦ2bۍbs,D:AQz7 F.Ő2Zb@Zr5>>#5Tӆ0JB'L~M?ɴ FSSPb-Gɟh= PVԝD:S'eqIn"X9sx@>8veC`Z ,v,u|Vi!9TVeFdovpz|d\O'fd|M+!ft;rT( ݲP/ BhN{UUbaf)f =GLrULxh1XgݯGohtՒ-vE'zs%hbHlZ=BM0}h×Rh.EV}OZr_Jنg5S.-*4w(mTeWqXD>NʤZP4D;_6x#~cI% zHtL|0!Εx!I ΕԟNA"ܲ }+ˢ؄[d>Z~ܕ>޿3@ J(gHW0|+n; Yل#z 'WEe Ibu:L`:/+7K$D 3̲7k׶ ƏEԾ A ,iT7q6>*'?`Ie u5,`sC&ktzӚ/*I<%a /qBmiKDBhR"60$UzhlYx8`1sg>3Oy6~PGCWqS-7Rz.D]*14qg+ ȹڂDΑώ~z`MY͏^"mOTP<ʀ'! a:j`iH?j/9 a@4ڻss:=sKUT*_gCe ɴ4wv,` ۳^$=EY:Sq3y0 h l) T~<) Ӄ}aPV2+`_@hOc٤󖞚S5 7 ]o,? |2}3ViSd\DHۛCVRz݁g;"/Gڋ弽kwFq\pG>zOV.29P2~0a%4RzuZj8q˕mozk;뱦2rm53Z"2%>|ޮȱ;b::;>쳃y,ޙ!2$2ˮO *)e?{%!:9%V\4%[MC+gﶓ4a +,Q4 :׽/sqen%TK6w^4,ΥMmQhJ^" DRgln}~J iƿF\؅A!j)ZYB g8Ӝ3P>H? d5e}^Tjdb*z9xW_geH+ֽ]hB L6Vw~vjq+ڷf@_sdgn B= +,uǟ]m#|+ng22kdi zb5/5" MyѪ5g +8xm"A%<f'|JF\Fb_FU3}Oޕ\ҟomBWIAFdR\a"dҸ=$ F'k'f659 vŔd5 vN!+ɬ&9 ߟR>v°@ji |ϒ+?VTfn;{ҼF;?1Ow"b;!Yag=༩)+#Kn7[rNLФ}%ěe>k^2uQ m{'U\cK uCm=FPM]vc(u?`\}/$hXY,ayG$/3#1%z=[ծB̓^#æ"^h s@iN1fV a>to8Be hp.LC9̓_֥nrG`Crq}q{, Gnp4^EMtPOo "$1|VV , } R-= '"LS[zP(Zc a>!?YԁXrE/ ڝ,hj,.?Fh <28O:)AӮsd~ yNBm P<2|n;<;c9Cbr({}"=iWqw@Q33M뽕$XN"f ygvP8Ioi]godo.ё Z>dx"%߉yyaJ&4Pgf.Vu'h`<;iʗSSEjЄ*AOiQ7I&Tڊn[TG<){cf.-f(1XUUV: #vw/`L1Ԅ+ ,Y~rHpi/b wWڎJ rM-lDOpX y{)Nوք!_Z v CykC0\!\4[?J? 74G }Z4cJ|.giW?9p8:M)|oHsBDw+VQI _^ C cΆmbMTřIa~jƈo뛄;Cz{ +M>& ɵ} GZb]wJ\*Al "& 0Iݦ#ʋ%Ď6}?qu\ed([cFq HL#X)$E|(3w\ vWLB=Seyu&J+ԡS-c NvX [ROT$/r=fu4rRB*I;\G3jWuJ"FAԇC v{BBl=߄9N>N$A? r/Zs,cdlqh ?p5"&ґu4DP̴$W?ۮ*yA#EpZ(5=!(t*@xx@9g&.-]RȑzFPgYc{3(;f-tl>fY뼔!?X1CAy[y1}Ɯ\,O=Ib]-%o5i_>[| ~^:NŚ,j`IWe؅KCw 0Cî6CBW%=&Ia,+="阘*KNoo)E* {]t_r%.7KG9H=_H|ɲe~W+fF辍6&7a2ρI`;RDztY렊|TX[ÔPkxڠtnڑFu1_cBC{uK/QM7 w(yXrorie"vmR|i&B*Ž +crD?)";{eG$ -OXX1m\oxrQw{^D,)uͮC*c$ #hMFL=Hr{ezp 3x+N4]:fGs"p_X̷;zvo@}j@6ƐmY#|ha$Q[#mR7tß'J;O+S$/nLv8hB 8U_e?boN\tS11?+ b橷hjL0NƦ9I^:M1_kMMYn9 2񁠐x7*֢fxp 8cI3н}qq{Jrx9*8:7 ى.$k1ơnw%eZpZ#Lh&3jsXv5{DI4 w*POn HW}cC&0UqP?v5GP  }Ľyc |xT`,g#HbOhFc 8т'=%,qM(5#^g2@0V3aCj\Ax1#0<ʃϯ/zQj1ej8tF#f6脴 pU>|leE;n#bwQ|&AY1@WK XK4X! Il9bde qdFʕJmTu$^tcDQƾwCxCE_i `)r!H"Y8fAP!Z\VOh,2|}EP$Om262 Ui&)e?1שpP]hMSEG4!;i`?k8!&7i֎ ձ75a99>W˙U>*+o'lweE~Yr5m%ܽ!=6s*#Z8D|4~mWa:2~7iӳ]0mqY16ZQ'/eZ_ [D,TۥʮKՃW4X9)#|N %"ezc[.zd`u+rN_']ۮN]-C dI[&Y߈!Z_8?AVz;,EpԱC<2w3 p#t=[!ˑ|: {yh P^Q{3l-LgC?s%R9.*bنRfa 8JK,{Y5?qT ݏ>kيdDZ}皝 V:{1NO<\vlާ馀PzcA0Yq̻G虳V۝"Tg>w*B P}1kr٥ΌE"ã) |7Թ8X J_Ȧ#QeDaʱY9K:,0x/Es)0>dʨENfn0n3*SX́Mu5R,erHǓ2k:dPP%)Lci]sğVkˁLb]Ub-LtKa3X#i0JȈa |\B-ݡUT^4H%ۂ6|WcOfI'8!H4 U̹NZ1b)aU|-s=üFk*6~]2lZb!P1-2ռA(_"5V#¾D1î^xnesIy#wpV$Z}ϱ;M JpCOze )H*\xot@Q>Xeu9+)|xhg7G3h>N 2D,Ju&GמdE2D7ݱoe_u$g%#FK*r?@cpR,)C {Z_1C YL2p֭թx, TܲRk]Rw†t ljSz ہ|-ϗ1.nbhE[vPRdO> Ƒ%/NG'@!Ye3O|LMDDi(kRhޤC&ŧ:\o #mtSFIij GE nhJV8w*;T U H9+l!ИA(w0r[Fm*ua{wH3gUWˏ?@h.ﶮE,%l=GW"Mڜ5ؚJ,IʀDp[5g̔߉ 4ibިͨs'D$,C(^kMTbeտlGxDs(2A:bfH<7:Qo u À Ҩ:6мeax1ҡwa. O+wTAs>D<)y0>Pj,1jc(V~;؏5E5K C>KtSh:qytL v36޶}'B? EWJTο`Tp X:X-+[~A;8|, &^d3"ZAZIͿ)~D2Nܬ@ NQ?{ D@4`v~#.ΓtXdN$ |}Cb宼4<[bsF2<q >e"GͅYu_F '=Q>9GTͦ@G e9z/X'uy+ٍ˃qp H* #&_ݎVH)VZT {gڔʘ¢'hݝs,>(` lX:E+g޽m!/@'uA˟7->yW4dnxa~%n?ï,ۃglNJ{'vh(/~;eFOU5 %H^-fN*B٪EDg<q]Ky82Oڄ>Ѥ+5Ju Tp"fH3T)g{ˆ~1Q 97A,layQ1'I^e[!쩦]Y0%gtOJCnlE;=\岀ݥshٳ!Gm C[Vwv1zOV*lPsP7..<5"`rUי'jN1(Lkd0=j諃|%~_Tn?pZlC ϣEҊ]=9@-Ÿ)\|ȏ^ J?؆R6O,?Ts=I5Ћe9Dgv/hW7%׬E P:+xMJ"Tfどb$@*HpD:NAa&͝ vhv2?Tb{ufsQ?bH_~pu6p6WxOdzz[dQBrY41]@$<|C hSIQ"̿Ш&;)dd&Ynw葿Yh^uOٌŏ(K)Gؙhk08 TBԞÍ/h)L3ZLJQ72 w:iv%$R{7 V&%(jKsAF{8W~Mf:͔{5G7B2)'t,J] ľ}+IIl`)GkyMF{aT) u%lȡ w'X˲3FlnUV<>QpV#*% 2ynw$# U&Jz){”B暅;N0aiEd)(&%a W'B.W%Ed: 0Auk@-γe*n}[b6dnB-Q{ yc6bc1o]z.c |3r1#[[śq*Я]kPhv{4vɽИ $iu_gy@?`#O&=o)f^a3M^`m*~VU ?%# ̑Ɛd!2۵ڵ75[nTN -Wڸ*/XE.xGz]DnZQgo;Vr~Cfng^ fPEl!dB bsxaS;G['@wa{l@ R!`51fЁOxW#OYy,ڵm6`/oӨdB Žs>7`sb%R@ In< rܱ=qb<f8Ν m)AK,#hioLR G9'`-~ʟMZQnGCܽ-'t@iKѕwQ(Jdf<:(g[O'ʤ!l(Tr+qN ]@VS_=:ǖ@ۤ0eH:G"ZnnfwP\{4 _*z W T))?R/?MHm )GF֝] ?PY<7Zr?`~"%ocؒ@Oȵn Ŧb.Kr i`oiu rNGiwT"ٸg#A~E~ 7L=ɳi4$$O8ʕR|W߇ۂ(P&C_$N!c%!O"Zu(E}[qe <3w!l6a~{#B˘B߈[-KvOzaFj,Vkؘ4QXok`1POmAwϬWyhLc;"(>:X(ڄ2MX:jQY*ѣɳ\gQFϱ_ 6%O h0 @SPARrcW0\/xXLa⹮KYI;]x46xחIc`^}=tivF>  PaK*$ -&!whLE >+UfnJ`eXMn \4Be2m PILwl#JzPZhO:׬f9r<;cRRCFt"%W Ch @ͣ#zo  4ջXJoܞey6628Dۛ' sWk{A}GH[r&a}=]Jk?TIܷ#K6RXǤ>Mhdɷqﮫ ؉Y]@ y &`7*hAkn .t9,;pݒUmea d Epq~:fwť|l$&iv[ѴEddHdiG,F}h&h8쫩42`-E"}̬AVC. MfjJEDR~Pf Q=y~?weW.UIF,$17ށFkJi{IVMFl(\l T;VWI1Qi8u9~](2Z ceN*$j'P/oKkǔH{7'a $ χyN1t }q0 oU&hGpSp/Xan9NNJG3a1faS5Y#AG yH=;KXGz@-Ik?DEQ\`CaEw[+Ye) *K#~~X'l'6{Zd:tq״ B1!Pupk<3zX 9W>dRG+FIѷ3Cn+v-M:dT0 TTK^фj)f^~$e-[{%tt ^͓-H5R#/̞Ȭdz}lIӭ U\tIr)j j/*RX.ۦ)^{Tm1,TF6a=s]虞7;$IsO%3SC5!Ma+]pƙ=}SH+e=n85j*w=#=MK2G^=k Af]#GRY.^&}69e!Pȭ Jw  ܣTx`>YV'HNㄟ}`R@@ N=(M@%o"Fc|enhIf}T0\dOkݘ Vf*ͨ4&q;sf9[P h3֡3ԹK\iYt1*uM*<#$hR|Lvrq-(:$)Z9T#&N 3}(V.VE< ߀iq,~Y䦄.dԄGQ=5piœ&T~ģ}|ɼ'z:?J5հVO_H a$MS#ZcچE?-w+Ut7Ak}B[J;Őܹϼ((Oі: qK&? ,MD_D52f1jǶlhy:;Cl="^GVDf\ Q8F UC@Y})c~{v;}V~/Źx42">#/j^‡&wQipl:e$Dgn,{҈93<9Q`гbi7BoBI(9tldL?~ZW L{\r'MĝO[ wU 2y˰@7ňyCHIeȹ+ޱ"šxlKq2bU.y1y\ڶ|0d%_V0[Mb?ubթBgv32Zl:2iȕ(a2lbȴC42,˘0 a{Άs5!D4qW-d `&|J. i#1ym<~鞴IvdOc-Z@(RQU{d()mg)F5XRKx$tPՕ&_ C[ڼ6GnW?EI04:)ҴUj_( "Īƻ`p6)W❍B^MYfٯLSFf;OuX?Ti7;n[Ǟˎ|&+%'nk囪Y8,gH,=Q!nb kyM@ 4KQ~#)kiXKIV?Lqdwg E*L{E!-^R(3dns3;4$Z,~((eb=tyB$aQHZK\ғlY >1~v"dbs'Xg"S"79N+Xu*ѳow':Aɖ^6)V|_\r> K;OrwK^ZK Wk:>. 8[*d 8{L?FJ*|ɧXl$]R\jHeq+2xp|HLWoTc1.FNq $L4 a++IsX%ǐ ^M f-V q*T { w.j<˸*qSՄD*zNn>z/fU6M`kiiPW8_y"9\5X5S=ZJ$wu <b4{DA #͎J[QDt5!g|̟645Vh$p>PZJ7~v*AJ!7Ay؜882C{Ui1(DFbu3ݘ=' m(R*ն █պyò:~p} h"?`[n@|Vy ,lk|5c0stW奠2C\Ya,sYL;~RX} VHS7:l/~ 8 P4"V<,&DN!L{@Лe<'&!Ng79f(vXn=o^RYxa|>`Gx 'YK÷I/6hM2^Y;t]kmZ -Ret\KS$c;#jMuc #klLĶITP 7֓x5˶SD7Z $X"tP}D=a@=tB%IrIZwj }myߗy1G׏8vd(Ӯ-nD ͚dk ʫ [/"̐-wO2eF.~.y6#FUIOxg==W0cov r#z{PoLDO"KY 0798Bm7HxE qRyiCjk ᳲg?~Mh1/N?u**2pY(kaxsDd+ oO?‘ є뛽+HhR_6IFw<+8!B K :Oo$d~؂~[Zp0 (% cxt8p޴,zcII @y˫br.[ÞLtwWbE&Sow[6&zZָ&#MjI۪b9 =\0LDX.u53"?*%HԺ&.gz6}(}>\nʸ.GwH~i`V݁#dVޝ#f_v 'KFK؎fBIK Al]dN4q,{Ӡc! 6V)$JQnڥ5^j3\ fU՛Y*6| $ *NѼmJB6Rd0%6= RNARd"~Q_v]P`qͮ`$ڻT 92e=UzY1]eV \y-{ kN "-C.}G. )_X^)XAA0x p_;;(Yfb#-E;voj|"E;7AdT{Xl§P''j`` Q#%N馣e$[rQNFWB(jKZ!i0m*b4^,)"8d{?lKFmj n nlH9 ͂Tb-8 &**`҂rI3/ȚƂ ].gG@b[<ڣ0ItؠD«dOJtaS@O w7@29IHGE.$9z{(~D5W\ŗM&[pNbqM}"v^psb`;gny3?(4 &clXvQ6 e/RNC^;Q&-4Ts̖%;8"wHDC4bC;7#rס8]+ Z4B43XTT8(u3cE/[,״+Up5Nv8(zœpI;~EtewGn܁cpî`-U̵Jk0,/\l:,_=mjc[׬ٱ~M8uP)UToz!yjl7xL*#mY@Wp7Y*ce%-ʹ}Yˠ1=L3gwe![WؾQkŇʕ4һ/y%qO[WwW`Y˛bd Z!t>  'P([4sN\#G|mu]2RߪzδgjJdÕXT4sګPzSh!\L_*ׂ២@Iz:d]|AGo%p<)!%%k4,jHU%j|{t(7rSOD[(,hd G{f N~#^:As$;7}<#{ NT&K2+Aǟ[ #CV `ʷ`v+ɰ+6D`IJ<{ŃEfJ k)=w[gL ޽ Z?d.L@bBP̒F6Hl2r]Y.Sa6y]..ԏq&A:7'+r+h[E[~ێ ߎb0!ibq0Z8Al%ss')ܛH,:j\f">Z1yrn\oG5R}Hhї?*ت\o G PEcX•) %~҂ZM"׈|a{R4`NSߗ+b.EӿuIG rpzE[u[gEq0SϪ<N8K7.}3K({8 BŢʓ%YEǖVL=[tV_pT'/w# \⿾-gsͧդ KS"AH{j^joN>E' yf8")&栏&4*?}ŏoʏZ̺dH] اyRQhCӷQ4-gpZ }HVf[(U˿ЕeA@%Ԓ;u\gdb'P ks/.@N0غb3^Qyˮ9³qkFDIEEV BzD1F+t,/A2.~=S+kNf[2Ǘ7SFEWf`! `'-9B̩̑G2^b˙d)7ZC.]o mwaČ8{ˣD NٿAE[,6j|'qd|Wka՘9j 9y}jDԉj8hb3 `RY+F㌅sE;OMc2Ă2Miء9inY @N4V_}ԣJ@x%HhlF !D6D7vX7Vaoqg>bG񡶲lKjpksv{j: v{ʆN X )}@{+q;8.znf|:{|k"oDܭadҕ us72ool!$+q}8R~(#j]XNŽUGs{hw xs˟gXR~ 3Uz&% bm0(,ѝS"5QlJyEn.焗@SX@?fq@8^BЄP7+Ip8< > 5mZ8=03J%5x%4w lUiU3VtP!508V4J͹1N`)9}Yeo+;jwBH4ʇwnU/oaOSd?j(ĺvJJuv::]1%rskkL-`10FQi1Iw㣱 8 i3p fO 8W,g%tw)Yo:g&1uwoJaArc{Y[&O uaƙ|c*~D,ȌZ}Y~!jx`cWEl\PPQIxwe$)~YىHe F:]$FZ5r=uc3KpMȒDJ,ZoH?=~рn6Ù^H*  . }Oc$r!AZ]U7o+luUgcHdơũ *pwN:fEP5zht)R%lOҀNOeP5gܱ~2O:)ϧɡkj8z3bXw;צع[J7q^@d:-9V{cEYѼG]O/oA<2nّ94B,* l&02T_m z+ !xr.#{iqoS!ETFp*[ ?''<祠 @B0:{WD^^޼HmEQֈhZʹMO*6%WVּ _hvJk2t{ %midXP@\w$|.E5;B(Lll+C0X7bZ#М[Z"66됹ƞ;&ܜS1+K(zc=э|B.6b|*HӜ ZiR+m?Ddc;=FpMD+Qj/$ds5 xIMg6lg^S^e buN}Kfa$?VĀ!oJZyX|¾ YwB^\f-Yx\NrSb3.cxcy[-vjH.0snPD3(.i D4xQ.LB)?zj3Pv8tC`V)fr@FsՁ"4v{ňLfW3dy>^.Qu*NI?}|Zhr:-G:X]+d(' 7$(ߘ+~ Qޔ_Z=)?arAe?%慿A/ dQ1[F<6Gcs]IԒԓeJCFSktuK&'7e#]ꓲF$j 3u[*c:'HiB⠰fazZfijYz04/ߪM4١j?Rg%ʴ ?\%lnJ8ϸGN{lVsV" P^ϟ`́PɱC*#/F=(]u'v3²J8.3Oq F =@pehv7*ֲ# /5VR6٨ VY&͞{82 Ev#tT&OcEvOOf4a'jPv҆T鐏hTp`]Dc=#C`JQ̄m)B/b`IDNCC }_푎 x3 uHã8[dJZFi=k+<;Z7?5IBe.-sR  ( Rg|m֫p7Uh`{v _ >^x +)=ߦˠ<#z;30ac[@3ħ?zej=MzAiY%E˗M-%EwDuYV1Ld#.60ux3ڦ ;&@t;)H jvx~P c(Ԉl[L_?r57ӐQvX @Rg~LP@ѕ7pTge [La>F$SgtPkKe,&ם}96#Tf96wPV9b"Nk2ޢ.Rd K&*#5ԫ!;72aG9gX0P5ʊ0X/#@tq%4Kɂ+W.j+L-n)b|<5T5 -vu}Xl*g9`E_!xS1` ^Ou ߑa"fuđcKs[+5OdTIݪFQ@!rs' p% JJ8׌6yA+m)hTk 7ڲO0qXmlnbֽwYυy \%.uSVc7*t>?Qy TTRԫb{͋,ur T^U 堜v`^b_s5&3vR-s5+0*'BV!^S7IRCg@fNY[.u%Žb`> ':Lpch$|ɁwO]G3fVi#ϧC6~>.#t)%KM\GgSaj˭^Y|جxfG^"?b fSm/ H/KSzSu:tNCp}24l(KE:ɑ{ [<\%PD{8D뗾@CV$9uH1$A9 ICOE<'|Seb{3@sō5|\!'ȵ(a:@A Y*_u71=9e`,3q{ `k4Gq ɎtN2PBћf.$+H1x7rvnPN]T7 =5ɻX (Sgo`>89Q--\+Գ=6Zû|O$/R%rko ,g䒲9iCrH{#WR*=V"Q\vŖ5 ?_. Q?D"#<Ĭj2%0cqv˹z+3hyRikh+]Oĵ/{uY}xǿQל|ңmQP:ihD`'RR-LB2-ĥ8., 7EV؅D-;C~`HsIsȊc:s^U5M=Kyl{f.&+1ω >ް ۻ:5AJ.5#L!*uGv:4C{?ünbl,ȲA"D'y,{%T :MfV<@ hS̕<d='5ۨEt?'nY'(y]0 [RJk7x?Iv}O,ῆKSыyILfig7Xu'c o]ŶWO-+$z6 \x4{;ϼ^}GSϋnq6/d k'֞;;"0MI{W ɺSK5n G+\:lm6B=oNsD}L?g8oiIJpԸ kL_ y6gY8)( a%dyOH)oNg{ emO 8=OsS ?d:!q6Tb[ lsi~K0+@Xm݆nc>"֪BHYU*%PnSCwj V,'rRPƋ ~建bɟ-c`9Z[hVg-;L}}øLmMY_r cXKָOȿLȀ3J7LS!d‡rDoaYe̓Lɂ: T6p^ՑS\_Ј(0l{d>=駛XC(wcc4=O4!DΟK\z`f}B mPJNܤ ;MI=c#,z# p 0O,LZb]C,cO<MYwCPO\1\x~4ŸJ.I^ZS)a}<4U(}6m~g?[@?Jzt|aC3c#Y]$"XŞG\'93gJfIyOiMjڐz*~PX h\κ/J<--Kp|'Q:`B!2b,Lli>[!-[vq֟%:Q 5)")@ט]8N Dv1 ًNA),Nq EV] E)ɴ2ye-h5[zXUVH^df2K@4GвAOcQIT"UbV?*]q!J{!pm1uVq7Qa{$8vqk9 7LrE+_)4Ig8ŝq Ka!;Rb=&53UusAnYyuP e[v:CPȪ3Qva}!Ke@僤D).`)HֆTAwb3 2!Եדaw $6nϳӟ7u],,jB8n8>jZ)uoV@]xzkۀU ۀFr3ERNը7*j c( HbIS){c}hff"˦QTDuG[$ ư!떋[QdkB특bhX)js䃷8JR+}8A΁p%@ƈO`t ߿]kwn<{TM=9P&AkyXoS{xD>1 Qj#3>0#7($Jǎn"Yr%qSv8qa)DzkaqsFYc_WSl0 ß⛑Y?XgB8>ΛJnޜT bE\z2Y88o#پ6qm^>2JaVmT8=:YL)#6Eb,4~I]H^D 㻝}i_{ghNtLy Bm95BߺiM#ݨ+ %'8S{w$IߐnKѶCJhм+wA%Ļ566s+¼v@BQ?ŧjWC#0J5yɛ=Y[טx^&iKī ހft:rh\PTUtdN6 ʴsk񽙡 dyc6M?þoK.´[^Շ`ֲ~7P{o;Ĺc@y9V];ӣR)Y1H+I/)` r. kos_f-Å{ g5AqC[]NIVò^ʟ}EpF _-h֚wJ70۰ IgXp#Qk֑jW=Y{]# ,.4a (2e-^ D%Y aݫ4ZYʹ4N%ԭ+y3.% AƏ?OZ)]ago͔f tX@rd<#po쪺8#jpu|z%0 uo"iוQpyk %ډkJ548E<p4a36YyfL*\NU 4GWN|̓UhuMmN)n t" Ù#8=DtOQz|<1dYYqNc H|47cxv#^@S P(EyTbQ+ʗn8؋J: Ռ*)7w;x9>FƼ eԢTmUCЪ-dv 0=c| z>{Qspq tk*(Շ{4^䲯Qv76ZOTi*&~d =?2SnLu* 9vgX apդ]lLF5k7X}:XGC @ &U3dJr7 &VΊgVB *1GBI(Y_}~: AG`jQ =Y2nuir*=$R6=[q4–&9fRU}10(2}Ц>3BBYҟEduI@Pů)-SW ZŠ;ڄ,OT2Tu;M+9fԶjvoU" MiCTrrIrQӋHRCDexb њ SSg k0Bu%4`x.!d'CrMڈ{k# 0cdׁ -@,[NA[tk35QGUdtS^{3 TזּSܱGtp|zSJyy6|VŰ\%p TnG:B/-d]<sRчe+ۼAV'_dS%2C.!"=(x`z4 q׷+øw/Tm.F`3}s3#Z)vӍT6pFr\KEb Ţ{'ZǬy>XσVfL*XZ1OR hQƸx4y_ (n}7BX5slTYUJI &ڨwVCE$IvGYn=&N-ԅW] v)<n ׊)=ElttgCesI CÒ t.Ybs)6Ml.(qvOkawA#]*sq#8أ>Z?u] p {hڧ(fH.1OE§x`֡Ci߁heŽ UYYko[5~iau8Yh/ [%[`*&D15&I{AG[?%P7Ϻ!Dfof1㿂y3m;eBA  ^A+Th|[˕QehV@^g*nWzтc^+'u ɫGxPk'~4ͺ6(z={ys [~DqVc'SW>7Yƻ @q73Ut5Aw#=OCB[9&1_`oER s_1T d]7Bq =ccs:`~wM_9)OVNQ CNRYa?{QS)7 UeDުeܓ~kktn`Njp4s;/j| oњ.t88ʩ r𱼝|ߥ8iAGKRNI{I(䀸e$o#mDQ`YWf#K[$X}r:9kHDL]ӓ.@׸.P-ZCiNʚI"}> ,U@)meeQvbUXm*pܓ4 ˹ tvZk?3VMW5*r+ä>ش[9., a(E6F`6fO Z!'Ikޯe:A ga ޮ42_K1ʚTrUπRS\ad|}z-ɷ, /Qum\ez0yO_YVЧ?;XMצ4wנ@Tu]_pw׹`^P,2wS<)2,Jj4lއR;m! i1 BqxS{)*(Q.\l 9']Woh.|NীXz6;=NIMRCSրN<64HQxA`f}Ge8& ׼(ޑp|RXns#NH*| y?Am8dIWNjnft::ԩ%q#IXybi[*mji[3Z4٧,~` hsi'bRP$$i.znK%gPă9`T1-ǷȁKZsTld) Ow${(l;!2’ .-ԯ}FĖYMR9H_ID2_jmG!pN.w.į^g_ ɐ\l?$Ew&WK#Ha\B1ݸ=EҺwr9CYKCsw}꼕mE|?1rKPuh+&rͅDK; 6iEVݡ ܳ {֗,`R=-]әox3D$gk9Decji:!$0Reot"Mj_ G%6f!o݀6 @~YC y1qitǺFd(i뼘x^K*}n~./d>/$#-Mȋ9qfRL"wDžq ?`7]#DC06\YX*\kڼW*%g}n鞾gSTMpl#rMψk˫v U:zLT@B SM) eoI ܫiJH>9%C}L~A(ڪR`h-m\NH9D̥aאnECFi&2OA]0([a͂ɝ$L&6Z[r,ġI(fPyJV>PT'|X ,@%]zз%x7ݬ5ڧׄ]6h]6R(x- X0؇<-4r\nK.8Ez1'tp]4ja5ǀ"'AQ"܋ sbF'i L#?>Y`(&0U_hX"dO(uZq Ǔ4U[qKBEgu-[ui M RI$>jXLl)jSu#ʌ b.qbۛ r]cej2 _Ot/8ryĂ8*+)Gލ kTbgb7Trx!s,?juWMKuNՆ@9[>l$' : esЦPrP&t c 5wh(1H[K5Xb>{/ ŞYUaI,gRt,V:{}ٌh.:7f)|0Bx«v. --˧埧.Cin^қ?hۈfW9=2~QDtyvi'*w*R|G#Q2eJ,^j:0e[iIRviCRĈ:ڤUll~ӫǙRoS^<ٯEaމr4={XcolMC=lț:Nz {Zt\PaO*:< :cdq7 Jwwu~elcN3&wY &~dI׫dLE$ʗr /_EEI.hAq(q ,.GG^_+鰩'NM?<ʲUٻ[\aTVCHDvP:Vb^[|"K,B)y ,_ }Y!'@_Ud *vP޴nFpr,#mn 5DB~Z.9e̎]mH'o eXY-a\v~2ic m4msxz~iUgBCnxsAyFN& +9L,Pd@Mer=s9A}em@~Pø=w} yFB!q D7Go⒱t`v%PޱH EoK]`drǼSuy{Ad3(Ѡ:S%}㦠ĪU0_XRK̕cw0]PȣPtpN;C-J3Ј DyE2_ːX3-®Śap gAtmQQ'TM>S_M:.Wy18`ۈYȭ GmL2cM , Pf+kE]smvCC}7xbGH"X)PJnN.VL\s6Yxy >hӕp{_fVV|!|یr b*lSA5o)EF'#FG9Kam5]߶׼YuRO˭5 ȄY)j8I@+ -II{shiXꀖ}H^R,L!-z= $Yp,r_[B\x۬cHSk^k {MqizsQY ,(S񕠹FkkSОq9ͧ r<.mpJ^hyҸǀy\E8𤳴N|{\ @q=<:gN+P>kxNa :Jq{@}cC]!2 DLVGHds*ݤh ާ10!FҊ-ov B3(BI?HEQV=Vqjv/vAғ,f")dUذTU$@#Y!Q+T h 6ܨ3s"x+H$]R;Iq[o+ZhvJY}&%{5Xfb"F@RF7ae'D].Qȣ} }ME!>9/% iK0b$B YT*\o^S3Пֲ~]@;6F׳sn|3N{~\CTR<+v2J¥| t>ҠۭOe, qy /ue]by+( Q Hz&@ꯜjR&BW➡ҼqX۰-l+fp(7I[HMqq]pWXBؚ(,I 'C8L3B*vU Nk^@yL[:= Y8,*ٱD<%Elp{p|avql1Uޏ7Foٞ{)p`1a hef<0|%)z P%e33CUlG4"}Rߏٜ! +?KW9-w c߃wrQ__`bu<~W,! R?-P =73GF1icfGh3̠N2WeoM$=ފHl혎g-{xxBBq{fǏ]yMo@C?[= ~m(Kϼ/'uKvsQ_&7y"/#h j֭"0=Q0=JږU>7ousȝ @HvYd@"Яzniر)w/@O3o:*`Qk?n dP.>Y _Mca _HX9 Zd7\W|zWnS=U |T9paɌ6,;| ޣN"{BA]qx:>`|R;B {o5cr:94B<Մ~> peUuu SR!*,+_r[ѫdW`nO/q 6/=Bs+rNAH^ &),Y3ŬBPDp-ǼL `,Bt2a(o~3\В Uo[GybZas,Lz4Jo .;BJ`I'jZ*SehW^ F@` 2D+U^UGkc- HOۏ|M(" &^;]?fTg]S`8ƫJ?D dGWK`ђ(-ޫԹuরeա!J>!){bQv[_rhRsߓH'Fwܙ&)i!nQ O9DSy 3SH4,eS< kd & ɚY 2V&9Sl@AyD3B  b:w-C .g}|02~:7U ^3_ p3XюtPeVǢp,K2 DNTݯ}iF+sՇ]28σmHmxMB4]-;Ī&vn6$6[w%Y_wvdҾ۱װڙl(ณ˂5SM,V.o rz}1&5|dW.bZ@YX7[Swi469i1TCg8"ߴ0ݶg6ݼ93qE̺f/x=v 7[dVۄ[` S#shz i2kUm`-A}~|f7 leit( 1sm㻜"s~g[@|׼_0@k _`71ؤ܀/<,!̟$*`N 9Zw(Tc9 a!2v֡l!ia~qa^R/di7별&2 ݙ3DH>N}T61lzȋVԺjJG6Z,uި2[6mL@gι!`^ߺcRɢɵ%\'Jg2~1y(DԓvM0hQq`6䏡/`]k0PP]@ʟVfM9*bK+k)-l d'5=BՖ؇-0̸.BEȫVۨ Vˣ"9b/S^pL^Q10rFKo>傟kp'z<ZY[ڱ lm hwqCp&ѐ>qOcQ^q̝.C[ `wM~%U{Qn񟱐0jnV!4:܎w~WiX2~}*0u ܩ1_MX}U?B$!ZY(jiŐ$Sp5Hɩ U^k-=\-,<akpJ>q{;@[iY!>p,_%PZYR\~mG~p ˆzLZJՀSe8нisoi"Ϊ:f+l5PZp8/$vN"r#v%1t1&R0K_pڿخ\ηA::HgOī]UƐ"jg4'7>Wq}# FBP8s@OČR>%gzbHT84]BYkz)F鯼L7Pe$2J^/3wG"X!u@MbOWt Jxf JD筼ʅwAF$!+(H4ի8pHJU,N"6^En)Z8ɱ8 W/IXߘwprfL D yWOy6 qýŅ@q27Mբ:BR3rtMIXK VkPJG3K$io~ߗZ~ɾ=Rϥ؝3uK*u2_#Q\kamUΔ۶_pWYl"?49YCVy q^F:ySpt땡<-X?.34%>dձqTR~* ?̳ʍ S=-6 elv[_OP͋_~#)'0P( '+? ?VY>eLZg5#Ϭ^3Yl5rEthI]euLJXj ޾Z7ˁ8hskj; j^?wa`#qbZo%'U>B$(N铃οz`iV徰6;HGPFm.ݟw\/4z2qTE8.0w?}BEj=2ō/bN3#;U^?-Q&(fbVD}Zz){6/ ti4]6E*p 2~>rX+ftt)_,.xrTrx@OI@aBmvHC l2Ȍ[e w~.`/mq3htݷ1v!+fna> 9֞zZgnmEHG\4D[l*\]ʌnǦ@;h=``l+lxnwr+H\^tꌉ[E߉ЫC.+ŇqZB˱Ts+N( E+ѽGƗOVo'yP/e +Q7orIXa&CT8xu! } A(2@q _9(pa)g^ {:= k] / D;R%":e~V_u*H)}ȕ&QE;d8{~n9+-4?ASVwre?il.zCկ_kJud#/B vabg"`IN<}f8 @n`N0Kcϱt6E~z츃UrŞ^c|81j<)I $2` gBeV^8.XDe#ޗ 5ȄX΍ړ;㇫tI78D')y\ BBtvѹ޾F:둡X;NG(^!n'C/ ߅8,_AK}E &iT]ejT&.J;_ Jϲ2gk %¢'|3H+ko[fM5t~Ÿ@4#XHbn z9ysZȵ|IV)+S\!zЮwcBkYUg@[V\ D]7L.wDJU#%X.d0["|$k+նLN27,'lĄM ~NnLlhvw>iƘ /&ebc0o+,$'0޾QRXm㱁88:˥&Imb8 H-|p/הv!yeBR$Zr6cK2/VeFıs!|oQXb* pešz>yyUL8/`Vh瞯iPٗvWKl0'9Ӧ1#ݲuu'85"l;NDOxhUviO"4ڜsF>E7hT]g3S[xlŗbXք-V`=^l'KOO;(h~#Fw5C- Dlo" Cw1,@0D@;4 6 ߡS*sqj?smBS+ou,|~8=v8+j$ ``h dobkDN$~q zEetcӴlOJDk`u!\`M"_ߠXDߧRkˮiP@ֵ@9qظ9ѣxbc"7VwïYɲ"n9@"(zk<v>ft(rVTo96;r1rv`𓜸Ƣ)dWOFT!8.VOMQ{JRr/ZDŋۅ(^6#xMl'%A vgHqƞQ_Q`yfāi)ջ)u|j}yK3 Tj] в^$kr'W9cRtk/#DHx䞃(fh!d*Q/g3u(+S9Poi.6 QKW$&Cp5V] LW(D?QѩYL[{: (WD]̇#U65LR)A#yBzfHFPd%m4%DE9Ag\_Ϛd Zdҝ ^953vUa)n+0F)vxykA"p #zp1z3ls+5jBܾ6 ~ C(ċ`])"W 'Y 7ne`)PtWus#pXL:\@3)ˆ:|AoA^{P,kާ MJ^˖C13n%e5wy Y1(ZT|}T<! ؖyӎ,1 U jm9)npT(jdI?lQ9kABa>n͘,dJ,3ӌadHwn%xriRiq= fCT\c9, kX# T$eJb ŝ#ɨGor+K: :8 tegCqd89GHGO`O;u$~se 6N)."Ao/B7ؘR}i֯'nmΑіy1ЕI[d{²KDe(/bv?3 v6?b Tx^a~q:}@iA@Z3t[.b x+UE|,1t_UŨ{-: X^o:,Au`Oj>NsK]Ksm5[¶UH3hEMf(҈&8ͫ& _rԖ JҘ9pͥOḲ̌r7saTyHIN\,8IV78pe,}{~q k#mLBP{Ԝ'Utp}b>G,rgG`xr$ .Q5[H&gI}NOC8ݞV rzbz^4U!.羀P]a6Q+c$ݛm_||ZiΜRюuѡ#޻NLfNhԚeBA"m\&0QqlO(7w/;ifD^;y%9sx/e'\o솓-Uq'4Q U?#Kxu1g]T5 UuUIOxSZ@nNZ6_ [ƺ +G`<6 D0(*Ҳ*7ؾwJK52\S| V'ǧnjsV G)bOܝ*җ\EOZ>˱ bogʻ2a7wHu~ w.#p{+K=m: zR9ZC"bJT*oyA-Կc| tOMSmmgőzIܡLWhs?|iIF {)wI6qeeȫw#Ե TKCBΔ¨Y{7΄ds#qzX|͏Rd$Bb9D\qJf4mF>+: 6<,:D#,w䝺r@W*:\5<ΛX@k(0Q_x6?Nu+T(/+q3ϱ\NYDT-d/sB!WAcސJOlq%\#%>s6eL&ywEѱ^cڐ12c-EݾDV*@rq,kIOr#Í# Gƅp*F$l:^Y@|QeQEԄn/+gQsS;Ѿe#Iu&Ý3Q],608o1PxQNfS{z: < zVhdBx k:]ZHP' &@25 +G\_п++`vTH8Co "䞷Wx]Un蝞5L؏o%-:'|2IYAIijzB6H@B۟)4|(GTPq,uȫO[FYj_Kt(!T48>$g㬂@}LT8[BȯLpĘ &7X\Fl|RD6<<-c*WNc}fWoa=Wvœ:l2e{?dHj|­ 8InVhy}qV跨f4Pp6_UU6HÌ_hVSٿ&N8~`9 x嶳Ijx<&&NIB;+ O)ق2l^]W O~FQ87ՍW<y)9.Y Q^;iA{ 0#Y".A[Dh}2l ߪ*U4pUKP'3!=;W',6'qikNy`|77N]0?RK1JTc(kNh剥O 5P?ˌ M5W4z:^7 ma 9[_y}8@ԡjE]t'aw5Wn ݄-qޜbD~j `^S_^%.j.!>Zͥ/1fN6mzstWM=J>~{DiJ7fxCLjl t}A׻ YMMy U J.@UwE=Qxys/8s\U/++}Cemr`f"X \TW53fʓת1`P8KQ:RvO&~5 _o5=xOy:]qtDiZ.;+ ΖXN?xM\68m9Fg!H_KHT,bg{ O+s8Q'PeMnd*1PXVu ~rFF\:c; H/&‚W"W&6}tmvVD=4Dp1Q( LGrnBzu\Ǖ.TX]\gbz< ;dhw7+N~VFLz⑊/;gah'ce]]OY kgyQ9!o{kʀG=2!=q II[i%i =y Dp`\0  fEERa jt_ 9 Xu,cP˵6]``$N)⠞w:V\(r gEd;"Q32d>M %I`ѻ=3it3t㕊S-ZG9 eb䩧i>z; ؄V'Qye3 rJ\tta:Dr6$hlwCxtH KZ ZϏcXQ|ȥa/2}deHJQqQSW43}ԛěj MQ6lэ.zОG\{ٗҵS?%pkY3 <ѹ[J(㸥 ;prT<>s`AoG͉oB19/3Q:0T U|fPR꨺gNҫX7&ՀG !=>XǠ3bRJ2{i$"$\1"@kW筯ۋp,<n$tM:L$-=.!n P8bP ˽$J$ёbHcDx[EOJؔ9mv4lb)[C)YiCom&#e9['oÜ=B!Y2Yӱlɞ pBsYg/lv2jsg/98zLCq1W,Woe:~6 xZ<~R!&v]R0 𴌕ogh(Me4H<߆)Zj\QV ބ%[?xĔZoh}h0[CQG?ͼy,  𼡊9'y|꫍Ps /NDqp#+Z29R3Cs R{ɹnm6ٙLBTK3`G5 ^+-ga"# +iZ\`cFG.=i%9x%۱pԵ\ٜGrvqO` e֤tGfFܭ(h %e3[gB՟zA1W[d) `s̃'_liMH9ͬseAAE@W_9tК7࡯F-Jo2MAbdȥUQ<ǭ#3Q")h!./Iq5|37 7CS%G2^jRk+l;EҐ3V0W!5rе afMm /\RΒ2!{>uc'#-/ep\5xVUl.{Hh^ԇc,1iQ)/F&OP[ Z|bmUlw} 3OCf}YXY#M\tLo{ ţ.~Y/ ni3ڭ3ia7Y9#<E;zWVbFc>PzHD] {k:D€u&2)xQJcYC$xX󔟼 5-HuMf~=rĖFh\ŠsFl@ l ? LOm^NjN9ȅS4 lF]4,G]53TռG?rTN۩5T Dn#dTe߄ }~ƥy4<-7"~u{46ƇMrΝJzKol&qd"bzf>3. nѥSbQx%3mM"sVi3pyO?% GNryPAĺb!2|ZrKr42g+(HUjDWS'imeG;ZW^_ g:6p:D Vk{U;[+qؙp씟=NOK7eY c]"X*qE'.J^=TjK:V.)g pΗ\NM[*WLt!1jWH:N/`ocj: ^oIY5z&"Ud'@6xSzX¸ݍ7>OnATH<ҽuݎ4x=iث?^)",Qpa3 kxu3Jac_<"}HD#g%8u63Œ 7PBcsu5sƈ)e FT IE Dn@RhdaI$07ٻK8 "vת V'gM5vۧWo3CoQI& JEԮɫ{Bq!µX<}% ;`%(NRU:[̟e! ӍATS.AA372ߏGuLdLhWj;,1!4O'He2eB1)\ޙTLhK E1yT`j!a(]n=>Os{hMI+Qp좧sc伬V_3d P},zX-W,!8F2iEGaww|W+~rE.:uDNaK|tvQFob0ρ(Cfˤ;AbǕk\ ,[_ڹ`㾋Rx魽 A_$N6#.*w"ZGNXu[/< U8\6fv1<,~y IMb~GPk'S MDUwJ&.^{1r~EuɈSHƋ;N( Ք^x'q؉3!̦g(G x][I ><, ,'>P`PFO Jn!@g,wZFb4#\3;q#B%3՞uSG}zLHEuKg}v*m0Ot:=3]u Vd`kz6Ɨ.~f\-K1ZcI1ZX}'^AlՈoh BzQ#y}K)+Kh 0'"4ݺ?$EDզQtCGeF$joz55$6#YJK"Vt9B2vrQJ3K*x(,yLʂS:H m~Y*l|- \+ 9ĩ9;EFvWfD| ɑ 3$ ?gtep4ğAZfoB5"{~_j d^vgRtTH*UKf#2L$EpUb$*DU1iU98=@,'Qt-.qx6 ߅ýoUV<ܧ9kFZqfJ1큕$Tue5:h?Q C #mc߮K;(c'U4k7nqY17>\ֿ(E6^3<#ZǐR}7WE|KvJt@xQm%߉R[5l<U3|ƍ^LһW^l{gļMu[?DI߿{5?$.ӇM?W`V@QiW!Qsh2&>c2nAOZ8M)̜C /2F4tzdq@pSHZPOs6҃Y%+'iBG3"LRj] l}6bNkka⅛ot`RMھ^G@*^H) ~Ji3/ F s##39řdT11`Yb>6S$tnU5i6VWI5cl4w[(>S :UIB[QQ6?k gcLyca:'e wҵe YNz]vq[p]U%o'Hi!,+lt%a~@ :v}8/G<6$|i պp 0PjOifF=u_}?䢼-R@]FֲӞ| $,TBsc3*KЫ$%$Vr\-6OHlL;S OmNatJPp\gE:CJh6'd?]QmX-Ӟ_"C-=pd ]r.l+id 2{|>&KM8A{"gJ[_rW <֎,e<Ȧˆ‘:g_䧼sK:%+}.FҢwccy]4f&ɽnkx_R7֏ 3"B}vU_rubPєIp2n/gǎ~BG K᮳!3%iCl{Cx%uO񎾍U\$ivBڋ1kYu0m. ;e˅ Lj-͕[rM: i hB8mkac !jp{M'}3%{Na_$ gv@ [ q.>x,Hz/wg^ &۝ v3> UŝJ>?UE~l@ƿ܋~1'3+9U;K [rXV3:X;VW-{R(M!,Ak &0:^so05]6FYvgzM߮D[lײh&?qEt_r)Ҁ+am:Ҹ$Uoxh k BV.Yc0|CQK]S:MA+^!Շ,k!5ܖ9Ծ @(F}rmtQ87u):MLE^;('<)\b*,@pF>]ԭ=| 2wQߜOڎNN! {'5(XOvB1^$Y3e9*z vw|>/Br3#V9ؠ0Q9|"Tj4RyұF j[Lޞ|.޹<Ѣ,`k? 0=FDذܟ ,yQ)z/5(2(6{yߠh/-j)YDD;:p܄liQI9RcN ho! Qw}+$^G!fu_̝3m-vp7=a FI6Wkh'hrm΅[79͛L9*ޡ 5(v:]$iR 6:CB)y, :K7?'d>z$AwiryNSLm.zm,@R^R丕r2:#e`JS& ]ĭkb3}ņ/b @N]ߐW|N(9q<#гG[L A[8u)QQ lcGauV5(!:%Ö`D< bjC!Nʹz?y. 6<*Sb# LkLuq,#rۜ %x+ZR!ތo%a(9[؈+L@s^39g/_20R`oZ>8J4⭅,rC\F_G P} GPC|;!K3W[NSObKO@{$#tMJǙ6HZQTyPHB"zBp>pkF:Y7 u^l 'JiWF7JPs]a(YLۣG.$BpR C\O' AjV+q/6~=j5su5sBCoeˇ81H_r=@ϺY BAT'$GC6jmaRoD,e!:+f ^bb܀1TۿV,-ۑW|ˠKn%U>Y8<-ofH &B yPڀk΀a=y7a嘪rvit ¶KdD,&u,A9f j^zЦtMvL7ߍJ͎"9 7Y&JP##( E攑J5YY$Bq +$<{) &sMTk Vc=_}BcRPI޻5.gxurZ~yӮ} ] ,R &]_?; |ݾw] C[pVXn 6yY!hnȥLlctW l<<9CdpX!jJy9ԣ~ ыʛo\4Fu!f\u &0ҧjp ![;"Aכ@_vf$wA.CbPF/\ބL|v_HXO!{M -@A$d-@0~{>->$| T$Vz4f [=Y`er#V"r_ 2JrxmħI,f D}+v~GI4OP!-PsYk St pEJxi5X'ؽ*ca\MA"WluT 9\{1Nۚxˢ!^?x& ST:|C. */|cKmGՎe#mw#.0n>WX-BL\rwy"LveDtpG'Vj=dV 3`cUlڋ"Z$X銑~rϺU9y"uR5)z%bB}F,e^:Sϻ ,|C Gr0OH؋zf:.,L) f:M dcʔbo /fݎ2t2h$An[<ҞB %C 8N O';YHy _iMU iDK(3D;! ;26gA{LY3 >#(\o1٠\0%bCc*mM.9CsN9hC8= : 3g#co[(nxvؔVnxӍvAq .n u} )Zp6dYǷX,VxzMcINz\Mԫ.ҢTmG2hwOI0䣩)4abe{ p-Y,77q(K9c7EV0Հ$X63X+ SI; '"K˞&'Z PlN_| i3eCr\M(^up x7KS>y8ϮPۂLQ54Z2 iBŘ jzu~ݳ{B=]+e@1|L R.ڴ77\PnÜ8A9C+4XoRy3)a`½Cz`+puMm(W|VPTlP^8gR3\\ay]b*, VsAZ6: 7U!N2/ݣ/815o2O:Ꟶp>=ڽc%HjEMՙ2YIGͤZR)?/=8'He 2X0JTS{.8jG;lvwwaC x d~s3R#Fz0f M@ԡKj[BL6x?!|~aNdWϻͪ &`䳻ь?݉y.3ZϘu)T9pǣ +%PP7b#9l|ItsnR <$vSaRK tM)p$qL{7pq-94^(sL&Ϥc/ٖH9zC`\է񖐛G ĻYDXl-KtzWEqk쿽|t4S mJL̑~d3s_ĂB/zhu>֟ ux0F[ p*1"eP0`l^],/2{.a-l\ MmۘwGlNy42glx3˨#"?3p?]X5+,՞ dpgJ?܊`'DY[OCx)չ #:;M)נRWnǽJVwʬ[FJ.(2H 斷dre>xt:)3qy gqS*tD Ahγ*bvN4A&Ȕ}72et wB--׶06<"Ў[ș]6noXJw15[,ݤ&a>\E>F@nf+6{9sJ{ܠ1oM6suan5 X^`jY-c%h&HDo99Rv@@nSUSo& 1sLCHeҫH.J*Rb?e DݷL\C>lʩ* #=q8=kk7wNۺ`4U+s (x96g(7՗ {V] p+P文.fs@Gex;R2]'`%8IE[MFƝ8tͤFpIQ`>22v=jpÂS߄,zBdMqvA>hP#W6d#Q if,Lvk?isа^ꁀ** ̸ XB+İT}Q$ɪUy<ۧp pc2%BQ!VUWzXyS[]g)J@Qӻc)dw+H"~]qGdF`~fbnͼK#9J [&$d<%T75uĞbwC MpӐ_+.-*9{ha|Cts9>aB8YdQ u1u|,<.`nE7bBd6`UŹ%'A}R b%51ex2Hj>đ[k@'0dD?`Q5V*\0)9xjCk<ލdQ󭴫cJ{r)CqQyblv^iGԶhˋI&!*س4Zg/?w*ԯ>*~%J|E>vM6Qd> t* u* 2<3H]ݰd'T` +ɓ!]`y&'9`\g[JE$1WVYNwKirZi_;$d-Usa guݵWu7)dT9b|.)Ub9E5eN9`HGOq\&6a-hka>`iV8UeuVm +aZb69 04E(,߳NW~Sݭt~Ht;Y@ Lo3cgz3&b ڟ>!8y ^dx%RKN^-n*b1Q+)W/1T c$zhxy{ V7 |0$_:>t:fu,Qİ5!Uci1?42=qztv`%'Kj L@䐾#ZBe 1\w".f*~@戩'K}/e۫1 pM%!|n (!z fCmsE~.:l L_XͲ86ʣ{sʼnKFt wX費 y[>)"|GhQ8[d33R|gÈh2Z%dB&d&P=`G"z+wƒƯ8oQ<ӶIe}wɓ! dG!Iڇ(n5yOpUhGn ?3dS oy4UgBgh5=wno"?ЯsW,ർͩ\AhA68{!Ä~T|K {|hܷoЕС#?YS Dq垍'KO}^ -'b=YTLJl[Niv3Y . MM.Z^ÊX(' X+k@틁 }K[9cijW`b}BA;&pejjZj{5Lp{"}ceU ފ L][$|W?׎}ԎrAdo/4rmG),ѫ~QP8{4ut>e&vîi[ +u*=[L[8`8me^#>c\@j񍿊$ONCR\pV[g\P s+a>ح\(yiH]vBϽ -ƻΨV:y\*{ 'YHxŠb@ kHDYPۇ {FvfR﹝as<$9#u o-!rR#^[E(zɳ+kF=^HDn 8QKլ14T 4ӯi|' |U>5Mu!y[O`03t''@_Q`%%NYeS zX(4I' =Z,Hpze%F|>g kͤY3hͯeRR#6B~OE#@\8ZҎ%FwB8C_\jqӶU8^B$ uɻġ#| tOaFцo0)i;w %6 ?FњdkwQQ0>e7yUsN*M3gts[&_YadCB3T},3&#%3r ZJ曆eK8+jJv ^J-Fe6jq8;:4#.sޣZz1^jn/BTӯ Z \.UTh;h!ʔXI1, +0{x3/M`VBW abVD N t2e] Z^фejm8V'H˾.Q-Seiw0|@i +ig'lgBs6Ylû6 p؇:jӶG)GUgrBˬ/¹sFdd $(!Ta}9KO\#Ycj}_: AtkƠ𱗰c#4+_m2TOA| r.Yl Nz a3X'_klSق\{yc`"K4ܗ^!6y-?*ط(%I˔pMJfH#j} lKJ[ɚUo1~&( ۉĄc(-_פwd庭M#Q]|1kv Ɩ5Δ)\ Y=͈0VxX܎ QrU#+ Jg5 o_%9B_"h"*EBGWnܠ2]Z眩?kOh~="CI-BV^6Mȡo;7.O:!vgXFt5BݻN7h ,tu;{kmm+*2j ^"W_uAdZ7~vEjs:Tہ0و%,X9D- ZcW+PB!Oa5AƜ|S7S'if};HNgU/4h};P.ux|}{OGm~ZDGd h w\r?Ǥ4 F~z ]uؖ1`'T WYIaRug"6a E 7Wl}r?-Z[jz.t_LYJC=nϗo5sRCpG<5Qi5!waN|:Y7CLh\g.GIJ&] 2 Xɇ@V*trpR B+(d+ÇU0sW ۹{JlaڋJ_e ,1bו5U -2Db{[ ެ>8TbkCgi^E^472zHuа#Yl/Ʌ ^WJHQ~IrLk[UD7J(O#? j^Kȯ ZPiYGƓH=ʕ8!+zHM-@GkD2Q\$kp+`(; piCU/):vj0] 2D E'eyC=A1ϻ9ئ]rm<"3*zmB p ݍDDKXAuVnGxF BrWOgIw-&O` T׽oF 1[(Ooj`*. Z!I E}Mj@lz3|UI"?Uޱ͸! El[`3tZ? a=D&"CCE`|H_|{蟝]BxI)T!3@Zo䷦<ň&۸/n|$Ƞx P`\[V=>t324" ӐF<)=EN{F Sg]b&adơZ&W,5ɋ^[6%'1K#+|hc$+q%;}ДK;=tV\ӭmR6GIf Wp"ȶ,;#spnչ۽;@& _3Ff3li0jrzm5>#kmqdk`xiAނ4"AvFIڏg#ć %%\﫺I-^=sYpJG4#\K>OB$U93^TE:7bO=v]g5W|g4x pT6B r&uʏ;)Ѣ.=b[-qiP0&#e,&, Lh![h/JP[%iF2ŕy9#~:C8>N?ryOq@CvwÐuMYaҵ&?I:4'+Bs8!oԨ윟'}j3>:Ku-߃w\sĮY^߶JK Pl<:,g ر>%ڵ93"Dw8zN{uV v(jFhhcy(b`a]"4sit :}F{xP])S7t$@E1GTCq:MQ 8zY4`{qce(k?ij_C;+㲣ƭDjqP2[ E5MCOrh<p+`7; 5/{ԃF?Ϙ辮 B dTﳬF{'| ƋmB#*ł%PEéo+Mp1yA\O$jg %ljE4Lngc7R8%?eBq݃!of+yS LK;qAF6q܎&bؤ5xRPTvWب}ir 4_8u3]]a ZZw9RExrk<YSg- r#N(#EXmH%K)t)K)_6',(QK*%׹?MfvaqK^Dy<[P9] WPW%NB+ 6=\J~>BL/ucl[5/5=܆`"$`# p퇇x6/ Mы4>R66 6~?=)?Yp+Zf* Vz6kI#vr 3|MyT[gXɤX*ֈ̋!$&a;~ vzg7+E:s '& 4zSsN TxݡYjfYo,iw,7x v/d FӳЅiw*dvB\Yq{Do\]\E6)=3f5K9YCF+sP3VF䁠[t[kHI1h;9PL.u긙u$-0+΄@ң[ !()mӝ4PG6$׽ $t֢]0܇S}&=fa!*?fxsvX% `\b>@A*=6'ģy5esdXx@AWzqL6XLi+9c((ф|NSz1, =͏CR2C};!AT& āiߤݤ6yD똕HdϚ G΄h.Ʃ3KG@@]>* iEj"-S[pK/U*)t{_A$ r%v tCMAӋ c/"q\m9dz07PN/T|at/VBs~W@j?lL~g7;Yn_]-Ko;)Ϙ F[ {O_c>]ӓež Wr6rU(erd'dwY=c;hc {+}+?`RpP )K)NYD~ RTssT=}fԠ6^(j I0 : .CBks(seX3VבK+܅su<ׁ,j;9ǜ*6=ˑ^ .t.;/3u9,r ͓XL>Iq Xb$hH^J YXhU10g6**]RXK!s*piD]˔%mA|pLਪ_M#>MI*kʬTʤ_J8ު)?{{Z'-X4ABJwF?c(=̤8 Ӑ`$"\ojQȪ_uQoy u2cJMGܨ9)5$lʣjјpϿJaWFjc/a=`q֘%u0R!jJUU}Y^ .k .+1 L҆Y4J\ 5Zw$QG`8섉{OOW()MMwLfmWvm-0 .k<\Ix>d*3p,=f.u8t90+ӡݓ-< 0vQ2G-L :ڟ2V*[W.E9u+ O1W\CNaBOpFS/ Q7[JSEc̯OE Ł5T`^g]e8ƶ]b6P>-SDPݶte] '|i'^~=nT?? Y"(F6d\ lt0112u4_bzHiVM%ߧ"|""yZKz--S+b\iE($H*r#d:xțz@I\OVLB,ヨM[gH¯[R1&aD}C6$ASLZȔӱ} YZ