sssd-ad-1.14.0-43.el7_3.14$> kHM<9~>;t?dd   9 &:X^h     2PpHH %H   ( 8 9:eG{4H{LI{dX{lY{x\{]{^|b|d}Ee}Jf}Ml}Ot}hu}v}wxy U`Csssd-ad1.14.043.el7_3.14The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.X%c1bm.rdu2.centos.org&CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64`K(Z8YA큤XXX$W~XX1681f7fa7058926a20c74a4f65686d09120a21277ca8900bc749f3e2df380b1bbd2d9a9f90697979304ba2edb3c14f79e596e88361a8ebf1ede9cb1e445767418ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903396e115cda209347e2af89da76b9dacbf4a606aa41c4258bb587b9c6b0c15b7da7916a271799f0415690d8c995920fa7e62b42c5a97a08167cb40f8c5a4987e2rootrootrootrootrootrootrootrootrootrootrootrootsssd-1.14.0-43.el7_3.14.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ bind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libini_config.so.3(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libwbclientrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)4.2.3-13.0.4-14.6.0-14.0-11.14.0-43.el7_3.141.14.0-43.el7_3.141.14.0-43.el7_3.145.2-1sssd1.10.0-8.beta24.11.3XBXpXv@XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.14Jakub Hrozek - 1.14.0-43.13Jakub Hrozek - 1.14.0-43.12Jakub Hrozek - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1422183 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user.- Resolves: rhbz#1418943 - If a long-running task (e.g. enumeration) blocks the sssd_be process, sssd_be can deadlock - Also Require a new-enough version of selinux-policy so that setpgid() by sssd is allowed- Resolves: rhbz#1405584 - SSH: default_domain_suffix is not being used for users' authorized keys- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.14.0-43.el7_3.141.14.0-43.el7_3.14libsss_ad.sogpo_childsssd-ad-1.14.0COPYINGsssd-ad.5.gzsssd-ad.5.gz/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ad-1.14.0//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ca4b3c1a626bc01a7879a87361b20e1e680f2107, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d48297b8c3fc41b10811a3401193b534769ef495, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)>>PRRR>RRRRRRRR RR;R'R5R*RRRR)R,R7R8R$RR R!RRR(RRRR+R.)Aݮ ATN(1jDºWz%q75ZZా"'efHQՍfHJ9h2WH&^X"T]Mhh^|q-rw }S o?cpԘc}oRodw\8:l.ZvMΤA'X\f :SB$*FAq9AlYVs2O\8bl)rr2z AJN5xh 33; ;;٨V&~vד#Uɱioe>50(%åySTQFe*A' zHr.ErƜfaIK)ig[>UPwŐp0? U`E$Il9KۥZJ}eoCH/eV"dsjxo3` a(bR&<pm %:2'7 J>z5[=lɐ;C14T5wMawU&N2FD;q3\wĜo6U&nJwþ<ùͳ۵ʤ.h<#pE n^Jat}t⓮ H9Z=B)'"26%=ii0/\އA_*WmNκLzKAV>*u$wi^jz {ZrK+f%:R2G/ LjI56$x*y1TnX &OfQ HH>կc{x"i,Agc="S2UmˏgB,P ~1]WR=_JS}y-i-=Y S:1?zRH2Pc"nH\](^"qܻw )cˋr$S%p)cBRZ`y[VDC'{aRngUN53BѢohޜ8鳙ȯ=}aqk Q5&hݏ]uW Ϝ^ uiW03COv2qwb96c?IQ߯*T\l1(~,c+ b]M:rHQkMQ *5c>:6S_RH @i*gqr_ j"*/έ|I@VtF7"1>#Aff>vqH>J{MDϣa%>0,Tl1EHh!9օ]m0oy:z_ޅi]Ջpulk[L17[ qX>6ZJU\fG 5|uέ'<;G\5esǗ]+04YYCy'F`st9ŹqsTs@A>mbl.E*8uE AJLCp[{8}bYL)$1؃8{uIϢ%jbٓrq{cڶ>HI15U?F$ދ`Zr+F*wP /ۢ&} 8 (&Mz|W͇Qڪ ?& 1VSۏXr̃US:f10$.FᛘNXd`mfF+cS.u'$t~Rw{}[ج?% :h@2%u߇zKxS+V ےwg֌cffԈCږlQ AmDk3o{-祀R)iRTR QIy)7tt-\hC#s ڣ&&aB=@{@ Z""7l&T}in"U==a,V*;vbWfuMJܥF:;[)NMY$(,T!ڭ28n;?]Khqnin͘[>[{I>˻&ZZ΋3/eo;'uLcq:䇊XrnlA63b[8iw5~iZɻ +}g٤%[_e,Ǟmv4frnk[2 |'RdGLqNxaEŃz 9X'uv'?h, _Zf^|魓ul1B,1^Ǿ̻OQ;Ar./. ] մA"Km\VywOOc4 #bBTMIhfo_a':(=2s\6^\QrpƖ7]Ȉ 9]>Asitl)($lqN 唈ڦwa3޹yL&ux]'ؘ*hn"%2w+kPX /In|t SHG5aa#? ' l0#D%"NZ9aJ֭)XP7BوQjEd i4 :`Noh@ԁӚ&}y3&;4g=!90% K/0tRfiy? Eh%:riT -h `zΏ9-! ë EmKZ. r|Z܍H3_PN$" N^Ŏ$,R kŎY2 +<Çi% /\>'aDD$բVN ߦxKq&JǜVXލC>sJ]F];J+L#ͩ~jXg1Rt7v+~6goTI>tqjW}T= Grn0G'~RgoolͿ柬~~5jy19Ĝ;ڡ:cIY u:!M"; 2x[w~)nmbWhX) ,ʮS>+]  k0l4etlIc.N~& NcWon,Ќ#&p}&0`EǷkZjWQTGP\';۬j)Z 2&Z51εr\rpJjam7d m-dSѐ^h6uȚK:ax6@_|ƞ)caҔVs"OYsg1H[n omR܆c>JԌNGh.^Ҥ8 V[Q {MBhE*k$QwX[?9sV *S _irniddOK`7$RAqH9 8Yi%O1ą @ nOpx`r@$ X `I#IrSVkl3$7/N;,.r]1%xC.g 3-xeӴnPZ{ZӜ2Ū;Q Qf(˺wXK kN^'xRN;H'{( M] x3eM;|<+wJ>YRtA۔'S[gm-bv!z y8cLȔkez{|afj63v"ѷe&*_KK~o(+?p~ 6d%(Fl]WG8Bɶow1lS҆@) qA$ 3L'ITW\JVt0Y{hd*UFt2ȹ+ي"# dQL!ܸy! )_PЯJvQ%u@.3ժT. hߺGQ|'zյkdVK<Y tS+P'cm$W. z8&*~HJNco@| -]K@t(X9V䧿 >[z$`B[W4j͘*"I*&V6)uw& /7?Vr6XjC3`4by3)I~ɦ7}AGb `ua80+-u"}ozͰ.D /)]HK/-"mgyD+pTVF$BW s8C?]`,$h<NbǬrA"T/8dxMѦQ'l>ʢPmen- -rim'k }uxu%BϹ_>BM-O3}dsBDrNjh`<)0>UH.һ G0nZ+l,62vO[3 Cͣ@J{ j; -!tWJ%..qwܺJ ek;ކ;t^!Pgq氣39FX (dW& ~l N %&^0rDXW8)/F-,㯉`jՆoL;|be[_ iBA>3mR!:l0~DZ2 T )Q{5h Nw$L!W;HI,!{|J׈pH"H6-['GiE7udٻ ylz8Ш Q KGu٩i906.cƦAJ-^ cY φh-7 ܡg a"ΗWCuKz3tbRX<5jx}kIȞd86G'cւk}c la⚤hvke.tB}秧x|_&ϖK7c)NbkSyE%%ʹ'+§&D26=t*D$hBhD_WBNQT$) v7~'\ Q|!6J7~=^x̃?ڃzw E:kc/[oš|_L65"3@FmK?^W6fۇȼG|i@X] &tu %K-n( ˽ ǟk7BPj sL̈́lo.޼wɜ/amyTYT_LyFvbA5es4yZ_1ollB1" !s@]cWq( v'qVߟ@` ̣B z4 #Y~2OIw0`]U\ċѐ߂:y?[jyUMaߠObƷő[@@Cc-Ҭ@=W iTǦ=#e`#R^fu+?sY]]k=^\ x9O 4#nk5$WO*{fyD0L5CuΞYTNvGb Li 3KA)=2|cG/DM1 9J;/p2?2tkPqNخx:dV? .sd`eW2z >?Tvb򂶘̄6n _Ʊh6KG4hkd Leԑ1ȟQUjU<͟!x^yxʐ/v%I. RR~;Mkԩ#M5+=0Vlq;Ɠq7ޕh ;+n؈9DHX* X#ZG~q~E{uw g~i;7%̑s/3v㜃4^^SxCL?Ᏸ0D8dNb:c}_jQX5%NJLk JB 2 r@d u<\r?~%ۭė{ nX9gHHS`C3Z͜7.y lc~˨ZKgc=sF᎚H`(9iwC9oTh{"3 -%x/ [jUrKJ{GZHUur  n#se +:C9L͂И |ypH F"9[7 MOʞ~ZQqQ}Aa tfky @4H0.D٦Xk%~:″ 47uV`~U@c]]E5)vyuׯGgeѰE*_np8ḣ@C iU=NyaǗ+/:ƻAp0x)7Mk=Fb%#>g9z>C?\цWX:4Wo^ISHy8pkP݈ΉKt:Ц;!'%4h1pZ[]TՍHBnp]Jf<N@[}%|\>Hg3>FPD6T@QĤ, b/Y'M£EG¬_(wTLh;9cZ$qףih A[OX o?~r㘞GZS+AYx2[!!C?jq燻'˩j/y(ްͭɿb)Pc`W;Ihr-kT*-첼l7KV `l`5# D[Ή\qR͹F؋ VdԮҖcd:K>k*]CCTXoҁ;$jCX߇A뇘q~fucOJ4t2iݽU5RөW"!R~B[ԥ̆y1&STRCE;U H_nYm{H$I@[ѽnǢ9`rdբ:Fͩa3~oC۴CD|k:t.-eff(;KޢZ..{JŸ٣jsHȬ> M_tNb-c=ޗ=-V*_xOM16(~o̘BZ>6d]6zX9);Vo+m=!UO9E؃Fy؜.]/6c!\@|gQG&~FH]䩪CanvP4ϕ hﵦc2\GZa /&qHz_޲ Y_&qg;j suǩ ƘZr8JכƟVdP3T ޽gVcw325?فSi@8 LCBNϥVvbI@'! 4x[[-(QjyG}8~##1ŅlӽB7JyXꬌh5a7}$~ x&J&ݾj|_LסRm:4SjFzpKE83-N)M~nWLGb{%Ty_kpS]/TL z @?C>N[o{ ;&Å;C%iؤ 1VtY)Du&4 ŁJsTDҨ z@w~V jeV-Fl"kNVuϊ*KآOo/dQwL!GoZXVSQ~yZdt PV6@Ԝ sE@R6`ؚ d$H~˓5ƳIp6DbXW<ƟJh?\fjcjͲj[dj(dՇ"v`{s"0FlͮAX#2!Aza]#c j(8VZCsB+qdHoXtx+P{E iKnQ1^3[rq01֨TELۺ=7Mg'Cl"XEs`^.ڊ[ìۍ΄dOR4TeM==0T"D|#s週."I[ 3ꛃȯR.`}zs0DJ'[s>֒ ]9%7 ڂPy%YX !iZ~gŵo^FUbW;[,LO4}6F6DzS4!O8o ]U}f7tr3UW\sn2|&lPSO8%_(cNWqt7-;Mz񛉰䆾z&B0Bp-qS{r7!fJdw$n_4g,YwP{ޘ@=@I1Oan?󓼯 o٬f%o4~I8]9i`bc~kny܈PqKh^ C#9S5v98H va f7τIsUw*<;z(tQ֮].wݕ:9y0 yfv3 \eB $DUJ0gTL~Xա1ɴغ37;EV+fiMԋb8Mx[/L2IbD$ ɔ'hҴq+D= &@f$&lR ,MC|ޘi 1@}h}#9R-.&ĖT 4 dLASa]A[6% AJ>Ź(2_ S#Qc=j>sym (f$#`#[/(ofWʾdP,͏P/ Z0 '*q|h [fꃬy0C z[~}G+hyA:1R!B)V~:o4_ڂ̫bzF]]D!t9hwiPVTŒwf줸|sa#O8 O*Mо:)IrF-EV]mFpp!KPTehszޟsdK]%}`?}/zSQڵxAQ 0 "x?5-gܛi2 41"Ǎ7ugU$$3_{ F,0]Egw㖽04 s g^=lS *ƾvkxDapDWȢnq능8D4>A}0Ԟ>g%=8=| bnfL '6IdnJߥUg?v j LU:[g}Ē0⏀f.7- Rz!X6huQ9D*z7)YnL<uv5wC!(#C s:dUM*_иBYBR'3(ê:ĺ) ~9O,* B STմO-Lmri0z[>]BKcbN}~劬ռ>8e1U?/<?V.,݆</_GCqe8: ʧИm!TI2`<6 X˛jڽGD 9r;Ja[цm n~lm}: yVI!DM=#iOq.H,c@]Юd/n6k\aMͦOD0„?6r* OrFPtzI!#B| rs)$s;q~|x-8x^A(Gtxtp0r&XHɂR;h'x`dT`zv>WɶCY؂+]~_x&C,S |)X=Ԕ?SlNIkcM:n,=frnsn 3}8S>^쳈Ѯ5OFJ3j5vE$0uefmVAZyDX.g܀sԇyFi)ӿEkǡ}!YH1uЅuϩ.qO=lG^`5:xu29)X M͠ef lYNJǴ 8XZʅ"m_"q+ܹKj]9s/POZ{L$W暧~,t1f./=Ak%%Ҕ8}2;˙]TOBkq?agtߢAjqA辚?dz%@zs"rVō ׶&+11y?rfoD l7[/,ݠai64U1ُaY^gOSEcdz}8K4ԒxOe*rJQ}B 0 8 0Cb23pI4CK8NV =zVZ}jL]̟ .o~' ӷ#o}Jfq㶓Y[ $hclx)}H._y>L$wF;Nn7n/^vQ;qN.P?ΰP]:?1|zX/=ɑu)|I߮y|Z? FAɄ (s,"( u-f~ >#o}9+qbY2NM|/%T[օ<#)@~7 yefu,?-v$sP KmʑRQlT~/.o*5+Oc8m6j`D y08JYziTfr|XMg35g+ ACl%&2}}Lc,DFY0\LJ ) "4")ZAR1Awy9es;~,bV'q줭<ǜs] kXSm-xtIݟgbiB4CȿΖQ߼UwWXt~.k5eJ4u)&ݟjF%LG)we)FyE/v(ȯ*:I#3} l19$nFrz+ 5,voA/N ZCbCm;^oflw-<JlM ZTDCq~I[`I$-T@n` <0GBUeˋ & Ze0c̎MHЛ@+="@%ekBmtٵ 4̟FkթI /-hx7ID)Zŗ35QzD%;ɲޣF*lz+@ aS^ҵ2N5EͭL6sov| E'BPXSfQfTijW֧0769@;k*[;'<}yp9PC&UtWp8+RR#.$mrƐ#U'd[^(1 ȼR̖Ozyw6alZ#Ad㣆^̉4'#0.fiFnjf-s;(NeȂyAśSd1'y\|f:*La2plQ?̏À]H-r۩X{R:3=,! \}rQf)LZ(*& .fC/nǶ;jGxQ{nj:3Z.t+sQ&JpAV{hVNV#帵Fo+N;&勢zfx( zG"qh~XFO7YNddb+4SJTj{];xT.}ԙ;\qQ!'WQ{Ds_ ʫUqyɝi_@ƕJ7O*+RQHC!6g[H-+r2)R &BZ\o¶3@`l\^{,[S 5.r ܛZG~9'c ?#O:4?2.,i|i_՟#SwڝcUAV1Zօt>9οJK~O;?~@A@\7PWu! _eSY;I@U#}-'AM?ֻuh눉byWG#烈q`T5&XCۊO΋a4ZTh"bm_ Xb%`VeX!em bqey{rbzpy>b>1s &3PtF1yB`4I^4>G#.D6ΥW bT@4&TJ[@kpf8 9rY `2+W=;4ҸN۝] f9͑6?0IlFitE FKuH:.xQniݞaD9XfԐ C&(!-tl:.xW .D;hQIcҿgA6hN lW|J|z+8v; ضfF5;/ c(DU)f ][CXʲ2 irw{l#ƚBm%TBE0. 6gT:$Q3pFOwze s_#*ɠ4(rl(O`9nYĚhfaq(&LBl3iMKd"E_-3E/qQ'xytR(?J\7?uV6q: ɵVdAwXB>=. 0֘_u e& | km%3ޘ; 17ew%\J͈<m-(c@څzaSL'B7lzZ^0ۨL gMȚ bF6ġq'<`HX~sTm4Z[2%kj݀y+oHzsi}3{JOjSDY @T:*mMƅD %\/hF9-䔑 ιo?9.[΋1?{ 0`䥒ӣjǣ5e/A}LPIfUdoH *Bj17 NW}ː5dTr$nol.jMK8G3,c"&!f+72hI~NQ|wF#cN*mT.*09< # X4Vʜ9]Ùy,t! n)HR a /pUp\JJ!9,T\n1ܗsaU{HL!~(׌+*g_FKvDz2ϵ{dq+W>0k~XSGl 3%?娚T WzO3]V'?/R&'@AX}6 .Ӿ.Ml>^&RѨ7P]0nך7v8ykqu3}l $1yێvw75zW|5x*U1\T‡KOf:p5J$ T>r@ܾ5}~? @]mu{ږ".2jОrE" -+ȟ+0,i5os\LmɎUZ1Uh8Zknk}c]1+IM^>2Nn;tF6wHe2h7 LC %̆oPl/'MI?L֏F7ڒ( n$%(- B>%)тsWw#sv kFș?ؕ@ #[82&P '~CbMGGX=l|Scx+ h^ vkV=)iK0{mIaN[e_;? e3qJK%H-iv,tֽc$K'YOxUX- df> $Е?^0mQT^+ 铱IE$ʆa|?xGESǭn1ge{)|[YPX^?+sltEyVyU!+E1yn+` }_Nݥ12oߞLt)X~vVa_6K= `&1`dw6]meIZ$FT&X;L׵P #׺Vcz-Ey ZnޕR^Kȍt™e+?q+f=4:j^8(a#7,v*@/C*ꋭAW<;Fve<yts J^V@,2 P{_cfl}m(iB5Od뷝0RXZ6|V'[/U;-C,s[؁nP}s`,r]' -$<\3RdimLj&ʿZV&aòeX펕lKJ}/8S%˩0c-D$Jg{S]I-8OѰI}y:Aj.q,d8XX@'Zr|0 ~7y%p{QoscPǔ 0S-d Vg̡ɩOPCG?]E#1``X~ 1no&_';U٤Qo43y,+aB RJdP kϢP~fEHYA^$`,2Z6U?Hv !>Me3Ɋ4z#")Z(rL";q_{tqd)FLB[egxVbQ'~9[YW;ɝ6< J{TbI/̀#? @FH2JkB>l#yyzGޕ߬1%y|c乴݀M.Vvg§=I1`VLJp9hZv'GٌvkASZjrLvn7Aa_aaLa=-5"NcdGy{ 5S8w AQl('No$YB1V.IK;.ӈ.6`\dUKGU}rϤ8*m}){S!(c`G k veѪx'9S#Phi%;OB`7ag}D >jYȨ D] UY*dX_@2P$lͺiGs p,ߓlVYf~RHe@â;0[;?ߏ)rI,3]lĽk>kMq9iPQM ;lI;دyN SE@p(y!4?Oknm Ĥ 둷@ ׉d),DىY@tIIO8K⹔z)bW<HJڜ'xb c?`}. KyLNZvK Cm&bcS 5)W : dj4b?x6 xGhm(-:\.%ocORtwSF}ϕk[)wˊvs 0c2HmMU; ?ॊyGC$3%"tp[r.BOBT8 Vs`'`(p2=m3SR+э:o_ݩ̜uדHm2r fcŽ2`0RY5 p;Y;Hzv^?^zgQTYǩ6gy9D8eW~jJbL_o.(^|{G8 audK/v"0I ϴ/N ~qP9AtAlsT5 %mA jớ^iogZSa繷aC :ǚJ =.Z%n*YTEqQk>h50ރ"ar8xTf2r@QQVð۱J'ѧS YSHY zw3kkrUo+Fex>oyxշ(zYPVե/|I;1lCڹ{2 "w:iv`.J3ǝg8۞a z4ΡMwJ_cN-E/8l"R7x}2۠ DX5W N<ڕAv?^ Wj݋AUR9̈Rpi=jZ낪/t\wK0Ԉ8!da9?JfgBfLqgH0c9~o"[ m;$12 i ,ԊS09?nI< -]ţMj[3-2NBYcZ?X,ZP(K7БRvJ 0aY>J Ӵ~!x0J 4X> ˜F5(\Cwyh c- %%`UŮyn+Fo?FeNiD:o^@C",@JR{AY%o^Z3׃=hngQЌ] <;3w,N<ǁR ̅WN6 ԣ.f+ߺ䭉þW=Y? +=#2 Q8D=Pqوpblv{1+3 d[HMUvZѹ+w*23{"$L l: 29ʑ/b TpsVϨG#L򅼑 ZьxbB&'-/ h pط/7!WeA9IOX X6 msPG2{рQPp$:o6S)ynt@L 5 RT0mwΖ*.8TC40 ~*fQΰaVÄ$_4nlsJN'(6Y#y&5y^Hku34XI`:1@kag,R0:xz%@х\͠R3<Z `dì8B: js2TodD6":P2W!]NuV;؛EvEQ3@.1H+|3WE*NDv=?:׷z+|/.]_8G,fj|.zzJ5#IChH]]G'{(DY1QT{ r y08nN{PƱʠR䔅 BrQ;^IiUԿǶК|_Mtk#E03yoy84VwhknB(]@r-}>t^v`($D4ǺZR'h8Y@Ff{IuRr&WsVv}8vx+[qCzhzD*3ђP c֘> 0Ҳ~' NgѢG  ,׭lK謰xM3snW_*=^&Tɤ(onti0P7vw'\-3Vs.! v ;d^ "l-¤QzyxA.3b<U)(V]-Z\O6ZJ6|{M!ei}0%]I(k;%^r þ F0Wƶ運4=F=zF.ԑCWP%TVqQ;ˑwln]~aS̏ KmYqi_8.(]zb:+=ri2U ltUWࣥ@>݉@r}}lu_# @>Yv*r\{ɔ} ʘ:<k~e/΅煵$ 8+yurђL#c;E[Z֫/ΖP.N冸m31 J4QL*-زMR>5kp} ]*Vˆ}ݩ{J)Zӵ~dUy*<7ʼn~wɂwmOyglVܗr.NdF:_QF:ϒp{@xcoD^ a>fES;d xG|n|ĒA}SoUNtA,U硭8h`16g 78C׎☮^1v?i^kş߆8[Cp0 5[1FrA8q !pܤ't-BTH? 7%=C 1_rlD yR H{k88IF=<1?d Kz(Y$=|:o 7ձ5Q'}8><5uke+;; Hjfy+FZtMg2M⠔-{ckY"*MrSLCu)]/rGHM[+˄QGPVlBOÍ?rjcx;$2}~)׆_(oz;u1ӲQ\zլG"}RWʓc@۩\[س 7%nQ{VwK/ۗ+fw!.aϟM c9t%.`"0b5C`$Dl>ܩzMX(i|{w_8 Tс/<53s%fO:v5&ykn_豺 6,v:LWAoqbAf6iy`xw=}CW#F?ܺMkщZ8kkIEGuTMȼsdQ4~%qI3}TCuI2X.c׹ ) !Lp9`d+X0 f J}jCDH[ Ag%\rHgN7jm Kƌq{ 6ͭ IXJ_7$kb_W7Θӊص9q gEW,u i _ #?TSsJ {7g+3dgy,οT 'NV T >K ޭ7!w:V>W++-z(mGװ= 0*#Oϣlz4Yf~HG e׮a0}Ux1/dƫ  .baЀt~Bw?#YH (Kq]9M}O{t]^,I9<ߐ#KWEdc~G tH|7wwʶf=p!&ҥeQ!eQU\F9B?)aQXjUɄIgF +v$±85o.3μw}m&y,=6tpwE8GA[يxYscqU/j&/<%vʯX)-7ZwD81A \ {sj]| , !KZ_i0$G"3&c Ic燂E3X!(b=<9 '! ;DjH\b_^_BA H uծ+ z Ԉȝdynɕ;{5[M gMjYC"kN4XAxbV/ ް]m9RjyYuH}px>toAH *-L8>"wEYB7_ZOѽ^g!mq{i$6|hyX>96t&:'g_ o Ҍ"A(q@`tK(M©~:`Xx*Iz}я%AiEP9Zoʩˬ'kFOc -xnփG@l-6i鸵'ovH64OX5rX:<5d P={7>3ˈ0 b{a{{QlzYA\eb87X\j$0ls cj1-dkLp|ds՚=zD_ /Զ,@9εA!Ka8WF7{+U8]X/ӌ?GgPɴHId58PWS:&7[ !ySK>>*EyMyI#EqApK\{?p8GT_ӉP:NK+I㚉8-i_%#*w YHFLQ쉵Nء0 Fw lHz4|F<@Y}2Q8T3ra6b5S:;0upPojV8qpv\Ks$i:NGdbUD|y6̡ujНơ5 aF$gzڵdu8:n_'E NQ6G;M@@]^(MĦ8Riy $HL)Δw 4HbMqN& |pX]Gfcy5 +X`%'{#"v&ʈ3c<џK$Vcm6ɠֻ} k9եh$1E%E(4~Hg_vYq)0FIw5Zv[t"%/j,R b^Ky2䒉Ev ؂v暮I~kH7?3qh"~jϳ/Wȕm$@~:}_m! /\y[-CN5Xmvol{Ea)I'lq#ӊ*s&PKcL\_Bk,RgnY[KXw!7Ik_P-1VF po^~ǏH~:Rޤ-fp(TbJ%R7~!8A$d!_ Ad'pohploi bKs>vaZ 9i"?5/1,ƣ'3%E8ŠxE$:^So4nwtݢ?IpIra*wsQDbz7zJ;|k#y`>g?'P-Y?s(g*ЪPPVCrsi(fṀOM<{/ (݌Nqϔ (nb\\?+J6ˊOT=I=.M=uE[tz"=i?{HtQs97c(:p;g/'Jl4ϙnh5"ڦr@AriZ(2˾o둭EJ9 ~ .5̄NˮLO=K޳/uDYZxC<~z%.p;L4̈́}4\w!idx#.0wp"wlFt_Kmfɓ/XqH%gmų"b[PC*le`Hf@.0eWkc2:!;"JPƩ,XQߢ?c`R~i:N\_X|Zk#jA#fY5q2P /<2&2X=m"f9b@ W2;hY<5u+ro$,$<E` Hr#$*ڰ Si8e7fH+ FIhGbWŽ (Ā"!ˌ.+XO(y /o<O]A#G Uo%?ʟMټhˑTRIt@4f_@>saw1zRmh@b/Ȗ:<&9Γ\h\ܲ *ۄ O(P߫u ^L}$(76[Ha.֩]NiF~Al=o!! c(y2ֿ\kc}u9Iw*5<GKS};E ֆ2EJjdTwgLtZ] >!AjOiZkoBiu}pv1#&VT_6_}Wa1{½f'kvʝH1˥>sQ{khu+s8hr=g穔Fa.۟X>[`Zt@t(]HXK4uDW}`B-rOY1g?6szSksc >Whfe3DX|&e3,ݩ9#6viC}Ќ߻yrcA/0-dJ +.=ViC)lCJzVP$;:N@_?4(-Sj@ľCӊCr ݦ̭Y,,YHfW O]:8BX66K \mǦ+bѮ󓨸5+7'̻#4o0`:nt@XzC7x$ 8̗ ^WnA1E6ŔxD`G[ 5l6)e{OxkMaQ(t|u(1 Lw_<v=Giz 22xiqҋK& O>dT`&[c+Ƿ} )iݮjb"z0܃1!a @#ƣu{ " eכd~"ۭ:_*Z=>% gQ]W^/Fkd}y~ =su1vܧ2w8nKa .2 ׅ,KAw)L0q8;qhƪ W#+FvO~Nb⍺)6y*8Ac3]͎"+P~Tz4"1<[S䚺x<Ĉr&" d71[P0h ጺ,_Wz|KE>/} pMa3f=M߳bCln*b[N̚W&mD>!kzj=6JQ]`R;k;#lA"ƻ%#\o_:~9;-Vq!Nilse)jϐ-v*R3-W78AUf"y!G0??ƽcL^ORvP?7'] |E0YxNn93d+X۵nW@䋱'5'Ϣ.]h(P;[K=FTs^gN.H`; {@{kC띥7C3|^rT4$_n ˞MP" Or=]zaVu<^3ч=)QDe%3* -` ׅ ߍnz^F(6Ha2fz-'9?oK=&AX5''y/ޝMo1%tCAiҾ(4ާ Xmb@EMqA[m^JnW@ʚrn"5ǿ:7J&l/s*(vSX%'M~@8. aMoRyDvqIepu"iCGyP .p⃡MX2E 37&5t?M%p 3S!W3˭H|΁ZVN<,,Ms4 ׫-@6n,b>%b:x*Jk uAvǍD{ 쥍U5MwG (D&}JiȮ =g[c[ϒH¹U쯣 ĺŪs^(|Es"x/9%4KiNZZk`ZF3GRq/F8e3؂8\b-[cMHRZ}w|ə;=,w q/!/`,].aL%C]%ge ?5~llU/niΎ.k|'Y_N]"zԥ*Jxn)ěՄ=.Am_ʹP;` Ts[b)A|<C[_*(!f,ǁI;|e8 YLZ'~;F/[.FH)v$wBZxe:Ѵ_ɠ$+0W9P-CQ"Ӊĩx.eݮ/ν38~̧|/ tEF%" =ã;#UX:b-8xt8|RPr w!ަ. s1PGGz[g w8'-ff+V1d^>-?ΑO'Kd]ql1w5cA誆nT 醞ё e`V_5io 00k+1_0ro.WZeqj#SjD {ZHMg~Nڦ*דB&~,еoJK/L°%v6<0T rijm vt2~!lxFҋRb֞r^O;c~-SH~Vou?w*AӣC1Ei¾ B6MPvT`'A.2=rj{!etx׼ɥYM)[n("4D yKp_Jƚ &N2ե"q2*n4QJf+TT=qeP=;nMB3w1 O=,(Ko[gs ow7bĘlE;M|ytVS^ 5󈊌U: 0\~'Jg"{7{J tN֩ qP*0'4tѐY@h{doW*s:":B]'-#!O,_Boy{*P4O$2=p[s"ٽ9f]mKWKԤo޺bRmxv7:`y=x!CnE?/iܠd7B7]N*%c}fN%%~a*h@{0m_ 񈅓EȚ>ʯgԭƷn;Ajgli`pR<&6,8cJj„x=GF.2=Ct]w9m5n-GJzeZTr}'<0e raS"${ 6\1mY!j;8"cT-oÍ| FLegm[kނ EWˉc#ϙ0YK̋D U`RJ. J5S#]ڶɂbo4=>O&IC[Z-h貘: c9>'J)p#E0-My՗iҡm }G~9R+Q7`Id݂ > A>f}ģ3-;pU6{FA8Yk)P9%D(aY_Gsi.:C=3Ґ){Q;Uv~nWisʈC_-o\cD.]%9˗xْv@>9D١*{1҂lmϜ0tUuEs4նZůx B5vA:JohKc9ttIBvR?ґ?;W=A`JǁBp1&8W P{@BjBȒ|ur/юu|D@;7 by~Uqsg @ ш#RעL 7c@ȺTU8"GHylI}1Kj@(i܌FJrhic8TM+)puZW_@ `#ILE6&S}Ԋ>-ũfi`nf4" Gm5^tڣEXHb>yy/ߩ WNP 'ڝc$KMCo3!j#iPMuUy5WQWXk%uF^Vxt+c őwvx,֍V)JUd8O⛾3#eCܶN~o+r翓q.OY؝K%Q=ri˗W1{ƶc).^'clOx;$ %;6 vz_6\*#ʁbvv(%SXڢ PJsDa1JXKC2ñ{=F?ڼ~ V~wy|BJđZ&6)8_a@N]ݩ4LH$qV1;')T$VIU^S7i~$SK buׄe"' 5_R穯SiRTQq^/V]prչP~% rpO~!~HdV92<(zu6jG<ۤWF3 gNuPt kN NDqSו|˅<J ׽-F<˞v616n)zGe$Ш@eW wT@rנ\!nc-j-!e º@<$Jzpq3^/pEߛWFtF5iMDpH;m^@='l59$0`”*U^ 3/޺ÿbBo_9Be*45Kw0; b'l`K*!͗.-L܉uL`(`Dcָs9P4#LvuȻkvm0pJ6h:E@Xg>ZrJ\#^^q/z;1^ox jq{VP$%" l93~h5lxlMf:yYNx ]^as:E':uP#(Hq0{]6cx>Z-r%1&XOm3L\jv8(K?>댁 >4;-}"u9?H+J\`]#I/!>5h8rbV"BBKt ,a4%B:$"۵a 5|SYXf}@@w'mgnHQ/t]FV`T ]߬ (r&5 ixCL^f~dEMX-es<%}{,=[/ZOao:8\ExaڡZq@zCW(y@hj TT}Q 4T&iGR.3̿uP<`1 BpSJ}ex]ՆxZ9AT0;L J'T6s5Ss}]Va@ Du6j$FxCzn #FvJiW$#ǓVLr4eEh9Z/.&i|ZO]*Bb[WW_ 1u'YdQ?V"y[iaVP{CV2t٭ wz/W}7Ҩՠ|?oW rV[YױϸOk p(}5r 0Psr y&C7 ɭ+ -Q<~xge؋tr<Z GL(Q[)<HZN4wX[aZ7f>kSDY\ez٤"77ޕ,tN>g;[<8BU,DuNzy2n#KJ3 Boi8 d)|;dhkhQp43|XbM#W[+H϶r0beϠA=j8}M4hBrPFNϫ!dnu0Íw5n` -}jR,ゴ^xтz?=﷛"?g8|8.zZrO6,3tpJDRCJ/'b8[ĉ{i`W>S}7H<˕oF Cuqe{*Ňv㫳NgX7%Mv{3[&b˜W݊]Gc,$3|Mע/WbF2ȍSbI7'Dt#n2e~3˧h8?eu" i@Wm%`[)R=_)k4(Wz4:k>R r@;] F4=<!4V׵Vv0_m_wK(?R㩄<pl'I|q&jb; 7MI<.**[z&>C-uxjE|Z.d>mD+Ґ3!ɯ?M";XuU2q!=è}P"|h_m :9̂orҥ{$t[),f_]Ipjk;ÑM*ƒН^uc69!:].6ǧU0%"Gd?m k}WUQM{WA ,=n:D/!77$UIs4镰vx;`sPUN&7<-T #6Rd<4B x<.x֠I:+<ɛl~eRT@b }BǠδ7m7iOR2ۍJ-r`o޾c_sed:W\V+W[EhҖZ?li;g]M?^unN)y c4ȝL١)%CWEH0S-L*u^єNQ:-׷ŷLeTIځsk0~|^]v&X%1O=?#fnw9R^T,d=?'UQr]V1wϑYKIWwMl+bV9܇ZPQpQX'Y})f]~ؘvA^p ӓ>S'*M-UPl۽ak{;:"`Z*fnP_Z& 4ٛGz.3~Z !Ȃ]WmO 6LQ6,B^{pVyuXv Ӭ_z*scM1+ىb]6W9Xb}PG6,e0uf"(@ȳ<@([I$o:o`GId?k Q,|q m&'r~aSLLࡽ/H/U00ܢ:t^Ǟ br>%[0Dub{݌m wy}Y{ ܄=`]C0V@ ybΔ64@'c.୯oBHb-OȸhBDYjbͬ)+ _z+lĩ?x 醝Te+ SyGV1x̷tkP8BKOɢzMALa_b2W&\ d#]yF)b0b=JmDkUJ?wk^9vƑ@:ݽk ^ u%7- Qw.2Ϥpf'/i}WQ)NܻnBOGUv;gţa::QI ;qߒm[稦PJJ}/-lǰ ڥ.yMIGVtHdwg8C\N83[x`pӬ`!gbcpzh,{GټHbqQdĿ(ɋzVUi -jH3yey\gO"<4s/,E>{{9w> p1!&P9 z%Musa틿Y\ goF.<U+ S P t2 ]'ŗNcLQ6PmhH]CH~w3QMشͮÒ▛ F챨(dYq)kEH+0 mp6Dϴ&a ;ᢪhuCn"`RMm-Fʱzy:}32@`Ws_#lo+lK&}Y÷F&h>7 4me. vt4C2jNӫ3FJM5ؤib f-CI5dLL9>;|_s)kW_ 䪮]W5Uо%5I iIp x NƵXpRg$N5m*a#E ȗZƓW0/IU86Oy=]VO x[pa> mAho"uXVSt:qau&GKդ4-Z-*e7ZUO=I@XVOv-(T ؂au t#ϼ|֍8]O|,cKlg|E!䱇^Y+]  tF__'dUNlR"ie~ EE&wEPV0^\qC&fTU~A\cu/!ah=:6>0؍U4?YMl#_G'7.xC_E~Āve;`p꙾.rf7/OiUכ&HL)sw⊯x}bV6?:mRKZo}% } U &pL^ ޺>sl(O!{N+b7GK9#<뫡ّ6>FyO2C/1n2?Ґ͉+۱€'8m ƪ+NJhS"tPn fCn&Fs[Em3je3ʠCA-%QMke mxg +M!6WH*Ta1\bKVᵳX<א@.rsSrOPWi]uME?aQ=N BŋŪ--4*8JZIsbx4:[5)A&+z8͛U3u'P=\Ght"Ǩ <{NOw_n҈`i-Nʼ`qv?SxS/ѭ3?K}EUaLCHiK *֑ƊcLYӒV}KPg:,ESVT~Bο[&wd7īwy?UѬn}.l|E2v]"Xe%P+wHv\eRYP4y%Jn {DMHL7tyug6 PC+ԅRnw2_v^mc5`d;ACnw2m,0ir S񸨨$d@'sogJNc0oRqxa﷟轌@%թ>}Os'Y{YԬ Brq@cݍ;1![An9|_t׳RgT;f_;[eӛ1+ wh腰3}>(WqvGaC!vqk ܙbh 5vL-FG+ͨPA<^mhsB#ݚNJ''.Htx+%$ݻVvRgY2u D]&F!vV,2ҳ<(:Gsqls $xh@@n2?NYvUh_?w4*)#5- OCqNCmUUww,Lr 1 #m`jO{CNHՙ?u@Etp^D;#-M* >fJilo(($ُn3gF讳4 82zj\o[:xtN}h}u2e!xYs.~逓*ݡvL&)ٷ{rkyaHB rE}*?>HNaTM""ocJYτAEAxq&pk&v ;YWRt[(gz]rH ȰL_U{D?QAj6$YP潚Ҳɚ\0YܠMJWw obg&%wu@ 6cMNqF  K?}^Z6i^9& M=o]X;$`tv"̪Y={0z䵩IOҪ w^N^g *܆;|>8ws5lFˬ )S q\U J>GJ%$la+6?X#YG@6 j iErY##d44I] S l29X:Npqr51|J[ Ac5>c kg{o<=9#Rzܕyuw8l7ɨ qMG/Df~om3lHH>&RwnLY'ҡgim"i 縓MpQe 9AX1"hi܃)Z-8+biED5-rjR0NY2s!ƒ`́su)zmsY fY ٽ|x;t;v~`QBrc;3ϻ/L6?j@%o}vae"ZǷ fۥ Um&ɎTNZ@2߫EBly|S]m?S<+/|'+m+ty:RZXӭ82n.(YJ<ҭT*;IsQaix}sJܬ1^ܓfA5}xfԡ+@c"s ]?Gq#B4.bquL#'һ_A^6De5k%J*oy:p'cA}p4S#돁G"}"F)OChf 2Y>&<&A*<_.K8 +rFIđWQs-ZHGc܊ 2! 2ׁW^̩=]+M?hcjS `_(J:1!gKy *<@sjw7t V6*Nd6o&a`øa>.xHN#D}k5uǐ%+G bԒp9y3? tQ/]#( o#lM!3=I-Y &2pм$6sXGٞHGw]$@&&-M,^)OȊL ;RDZ>?pcN(T^Ppo%e\d8`D펆T"vR}axڒf;<,BoemҪb BWb<os&xJKcٯ6cلٯos. ' 8b)pY&0[r{4˥2~Hk1UQoSI9Ja.* qDɸg4><? ^}' G5SW^٤}tBu9gPgquy~BKA- &81k8|O&u%~QkdFLUϰ&#L5RL}p3Nʹ-+x(29kGe \@Bh̋E;j)H6şJ|]C&8Bơ:nvxQI!-g\μբC(o8x-~̷(krfρenRR'!B('2Zيw3E >aD{~vJ gdD]I8rbFu7Znm1Sh-ì mӛ6'z1k`>Cv@G=Z뇳^ 9mW*; t"25byzk,wz-XW`Єc>KόFE2dXhOoEÃb v9︹ay +sDtYWEv Aaݲ r>J͎Th9y]s5FvrFKtJC5vqG@m{ק)`h#.t8h:#e75S7|]3(h&tI4uP:f O az.|]p!#w\~neM{ I^$`E[_cnL֕ 鿞w+ґu͖(JoɏV>1hvRRՏDx5&S<giW1+)_*H .qzJtzLʨCښ(J/M s;f*+ d+3gEuCBGcpz[Rk4=ڀaA0ϜVF~)T>3Q@Vt5'5 {t3w=& !LǬr-xQr5P1c O r&zw-8!T+{>)y. '̓j,gl*Tc5US8[nP"rUƈqEi/Qc~ }8s@jq A;9Mv7_wb,{ĞƱv}̳~7s#, H٬L =^#Ss 5v-#9 Kag{ynwYҘiN2l,q69Gd}}M`$`ǻ9)9A˰6z[ݵUq-lbAaU3T/[cվ rmOR$I_J.̝wԎO{N 4'BiumNέ ÁهM\C +BZ!P{]Ns4ɜٌNםF UMƀK1rRbA0/ChֆB SF6_24,_\r[t3ͫ[5b /h^lsp>̜kM8pVϕ6ˀ2vwLoBÞg^o>jl{tͽOtA\Ź")fDGN)cCt(\(tԌrãDmb8`F+L?_l?_o1}|@3.\4},c./O.LO-+YXM9e#~ɿShϲ3LZԗ r؟rB0/Q'S\/%(zhތ-VQJxkfk5AN(.IɷӌړJZȰӴUJSn9l!I3x6)ԏ*y'!bЪm~;"(MMQP'r!BF'7 j \3ӱ!z+HN.`_ ~Quc#9YNc{'0e"ZdnP>ڽZGt !-< Ql\nOe7Gi/Xԁ$m\1TaP0AU'* 4@˪@YAOjՔ<>}}Dd^顗Y 7TYwLdg#:up K|:eRa`bwPfϜ9Ku!գ249nmyUFeYL-y¸&Le{SLZSl5FφH:w@3ﰅS_ˈAjj65Dou n٦vM#>5=vAg.ƊE*v@2.fΌ^A)CEj覱ȃ'r*)3[y+h-xIXKFIPmBR˩2DI1*& 㼗 jZ4_[{JnJDG&*n2v]݂U XP,dFԭYszBRuvJgt97x((8)l}GrDm\xMzݥP^1&vf܄Fde:NBʦnxכҐAYn&ԊQqN's6+rZA ƨGf;CJtnI,^AOI!pl-~<Kڑx(:0)=YAX̒<독_-@ ~#qb<ɿ&ږb{7úkN12TOp#}Iyr؊x7ѱ[Ga9bƑg)pnDhcu>t2߄.JCǹLoFnI1p#:A`,\MҀT'D:,wQpX w! Zk+/)SU (r>N%m4ܙGC0W*`v+WrWzB{6szv-όHRKh p:nXt?|;-)E GE6⯏{tT[g jTʡI) :L M0ʗ@LEf,P:FSԽ[![,ǕnMyd9]W 9 V3߻.]HY7"?'^#>ݑ VVȦ㘝bjG&ο"?*Ә3PFk Y߲w)niaTiO,⡔XǭߺVevt{,VUہŦ@Oy_`o}W$ WA~Oqs7Hh"=R{-5M*n=TSǸ+4&SAQ;IAxڑ˨ r8I.yuw3l#iS8p-ƙ 6p|' w{Ўd q xàMpq?FF`rF08xBQwgb*riqmEov/g+bMKs}R@ؖQm1#Ux Dh"}29do[ߍ$I"u7 mHBZœ8GꑲTCD5+99/G̝{F]JK1OTNՑ6;y1V(MὥIַ.}IӿiP tYQLA;F2}2aW?0Ї#K|{  "=B;e$Mǘ#­y_wQ8AWrm"BlRUCӧLȇ˼"ǥp5. ;/OƔƷ͋@9PZ/_e=Ey7spfQI=xac CI= W@w.ne~ATEM/y`-)4=о ?TR)CCh'\,GDKA,%lU d%R-̄ 8ӆ{r8g GwqeG(.vƄDJt`y=gB`j G.)]F8Wm42?93jui6< =\+A>C;289O^*t0&vԦI2H#Ʉj]<4+`RHy SVkY.J;x#p[e__Wk@$+PXUɿ7"Ҁeϋ c$LVmIizfv F.^IDKXuho4 mvq$_ 0aΩ yI!Sh춎 UHվԻݝ֦CI6ՐJ芩9fSΥ ΕLa3̎rt|Y] Wg +1ni}! "oi+w! (1'/?:.jo%3A{ ݜKAUڣov3٭9a q](57 xFI{Ag&s$ ǰ &vYPS ]ܙjIRE!Ӎ>H,$(;#Qo/:xΪnỏI^za/&1ꬅG~PҒ׈|.8+DdGTCЧԟ_>}B5= |Q?M! iZky-1͈ZlߝIͧiM#Ǹi1{ +8A湶 p:yT;ЯLԞ?"jyokȿ~?;Q5}9"ةVEv!$9;Y*Sn<vntŲ^I+^8 AŖl~X9dI$hsYc* |ȓRZ)Z2?iB59VIsܷk& U"&gTXDC<}P_0sN>Qfdx9"22ޥD~H RDS0zupEބe Q ({'L\+t5B&imatxw{GƗh"$i)xP^$Ded7LR $F`Ix_\$h\߈· q0x|dzJ+ uV&Ԁ)+B*=ox"ґJm̯MwŁA))HH8~:nd~D KQ1?^h9P@^`6Ao=Vr0 ~ŬvvKFo B3P02iR2Xޥ`˂ܲ/XHJMBV~(ȱDcfJE"ڧ!c &l댃la{u{9u9颿 ~;lkn Nʬ`!E#/_X3Θcs/yk; |3c* ej)y?] ɭ?,7nd7$9 Г{yT>aNdj5#ρcٰ] >EerXN$/qQu%6"tpҖƹ[SL,3Gl.N58$%)6׀?"Vs%Ԡ2ƪ?R1M6'1/ʩ/J3&P'DpXz$]=D:V!2OU?9պ z*dVWpJ](iq0_k'\i#3dg g[ѝR6 hײȕNM}ᖘ.Dth:u+6~_\"GY%+dĤʵУiPEsdO kdO+"8ownat4 !=rJe`n}6 ](~:.0Da{*95ENgs@JY mҹ#ё>*0}p˭Vt ]3)WMJ:ZzBQ>)\oIRY`U'̅?S1l#vM .|xt 6u'&pYi%!ס0_zϑ$u֖;i5Bew٧2" +p(nʤy]Z7zk%aUĚUZ._(Jls.-@&wD tAB_Z?ӪPx^l)z;ڍ!Dly@uO |xdep= ϲ{ob}F~6u YAE>=X3,37/@x@!;2B|YO?;q80?S \ T(ٺ}"hè R\}ZjϋXN0JPW.C-KZ0>":z~|iQ=YTBkx5ݝ~}Ƹ5m9H+:\èMоp D; @iémOMw|jp5@źaj9wajov4=IfVpm y [T#9髼9dnԶL*u(0X!bk&:Gê%rnoQPNSԞ2&* VRJS Vѿ&M.=!n5C!zN2N6%.nƱu1R)j2I<@+L,}ɖΉAך*q*0Ж7g{):#@Ď jVU4z?JH%R`롥,]86==y}vئRm(?5x>M+]E7UhSTB $0Bœȟ(/n؝ڭٹ?6 &.^dU& rq`yi\cމq6=t+v @qdԍ|}u_i \.^3lz:H q?[pK 0CxNaF!Qb=K@M;ɥEWAtKmN&2,܀^+tzEQGC2岨tƵ5n1K7K.Fϛka/rH Gv9ycVT19& d8m #h@"`=r ݉GseNUOA?^+}7Zoĩi+A@XY#0%CgvDTu ɔ#]6y"]%޴pVO,r˔ FlS^i'朢?2o{kWܣ-R⥪Vbjn[k#@#EoFөe$I]BmN`?"&_DsN봕"$9"Lz2FMd߈hb,'Ӂru%ENrUqytC%zr2>\ⷕemͯAӸxs#Jd*9R{Ty5seHƼS h(N'®9CIg#`[qގWLQQ 9mvFY;~@"b> wzz_Y" j94?ZWtIK7ȭ(]&_&WX? (ՙzLgr/èM2s$`\?KL?eu$̦*D\SgyC+4UP}F#}"&o}u&ZF1$O<Tm⾱ݚD|֩vRD\v)VogAr`^SF(%H]x}Q&}^wZ-%J;q"jHڽPҹWT3,tck"gj&OʵY2]+N_XujVN$U]?{%EJ@cj_Qsc"Ơ/''ZF踕Pά: }<8sγ"i pqD FKPTq#)+{1 Ø.?!{WL&=λ:]dKDRfXԬWCxi` t4䌯K"l#WI^U?঒K=Zm&M9[w.~n˟Y; is특UR|;]S^QFlU;D/R-GoLqB$6_W;/cjk*Zkp.+ꥮ^6} g(&Ex˕\ &ș_b:õ> T倲5֖ ` l2LIVCC vvBuͻj0aŤ$|1K3zN*xQ>]~{~gFkS җn8ڈBΏ6^4X{ֱfa3.L5~$P v*?b?0:U^EEw۔Qi#́%µ?c5=8J[ a\0\ v.aAK^RSB+/0W9Ǧ!TE4{$+!: h<=()rіI)$ݿY/[= WHLCU\[=V82lv೪xYyMֈx0܎\7|xmUzn+$ qԂ Pp(29~G8w5WjS=L ZˑiP@ U=%y.eK{=]ˠ(X!*\sxzFBQ p#B$Nu) qGS؀x{kM}^ '9F=y PoX:R0*k2Gaw+N9&'宎X?v@V1SEV`u߰)H2J*Ux^40*/H=b?-{I%3W OIx8.5N#DYuvkVbhp׀uk5x;FD ᤳ|ެǓ"VUWoW/==9h6g ez$݂/ǧْ@W֣~mʭjlnCa<#.mE5Sw{bd3`,$3P.#FIgVV.h&MA{RJ:V -.0jzuw1rlLJօg]EZd ̻iZ̲y H=8(e>Ҁ궹t0`p?ڔF{uI9*}kxPT*-߽BaP{ދ1{{G~"e=wxj Fgj <'-I<gϒg9#H jm_HiE~ &m>P=4Xp}SMłfsJ*?*c&`pF\pN'-F?1.'MӨ57"QAۘ{77j؂ ~u&Ȱ9eSZC8u /(z3zuy;副:W !)#A . oRzFa%o'Ah.(mϭK|QuEo!DlM)(v]9Gxhj,73Np>9 N: -k%ithšuޝAAu#< 5+SO>9 %$MKwh^%$ݎ2"2i^8am>` 5ybs#183)Ai _o1ϻ f({)@@ +p U]N9T4rlÖ~vD8 E$"SF,tyo|R=!SըKvPm<;VQ!P"E蓛p8ԾTOJ7phYgarMAdLn93-$HX,. <||;q<77s΍CK\ &2I h_ⱌeo7i!{o%G+Q#AA/>ѻpLDP4r]wrUҺpՔ8\H2$>oC>ѧjDgo7j0y/\YB0)8FZ XYq`j@(R,zK&GIPeFG3"|Gnl ȥvr a?ʮ&-mh3.aoWB,4QT64D!*Bi%=CJ9`ALh'z<2xavl1$/؉"{r'ߦ 9ѩ {Շ.aF8h`Aey/ǕHw*1p@AW,}/K>DMaR3k?qo, ^ɘ V?W;Qfx{ :v5 (t %*XY?/L0_aoL㑁x7W`e0ɕ|LzJTpr,/˃8PN˪WW{dYlZǑ!9v~^g(9yaHxTNHupPlŚ,(Y]=Z!NNAp U)nE71۵vŪ'f@$e~뤋Ssi{9aԷ8Ex7 g 30QJS85 Ř_cIݲ:s{@k5S$J#D!iZ^mh=32sQJ`hX@2@3 t=;$p'"HPX/bTtjqx9|˺khټ%X}[-08L;6٩L$$\.ҍvrcؠ!cL³/vh kgV9&(%vGͨc)$"_s!t<_fZςAc)R(=]Gr-*/cM=R Ѧ>isV,VS_)=hB,Ό1OМc4hmYw3G @\!]]jKْfUq-f}?&urrhR^sKmr$ 9nw:dzCnRoG)8 G.V[lI=3(5I)Ҝ$t|19A @gOC3H1 5RVYGa~f4?0"OE ~L,kI FTѧePva Z"*azq&~@>Vw'Zv5S)^S ;™<,glIJJ ҢBs}$z:NwTƭ2un".Hȧ?W>6ѿlK*L{ mrU>7,* P'G}&䱟NO*nǷ;fs[@usQ!H\ Z?_*!E^+_U)1xjSi %~gפ 7r_bf5̀DvBm>1%:w1Zcx+yb% ꅬA/2AS.~)kFhHŭ%r3}Rjx !pLve)*2իu?c._ "in.KyS]~5~X>Ƴ޸XH?Nd<2Omoo]P҂uSBG]=/ZkĢayq8828i,^BE^Ʒ^m^z?SP_|‘SNhÖV`=T,0dJV} VSpi$wUF C|Ӧ0VjH搮 Z&Qr)-䣧ar#" `ZI``@VSznIvJoGe{~va=cPA'~;߆Beɡd""@_ e7I!J}ΐQx~y3dbLٚ|N`վn7& u,l!"~ƃ/>W^~ ~~"|W*ujF֋ZBC&yˋ=enysj}w `G]F/lR>5n,}MzqDNBߵa>fD^z8~ZL֤Oܰ@ƐPUa6=֟dn vꟛT&1)0}B.vH"ax^]+CJޢكaxhn `OÖ5V T6i lͫwU?ѳVͽV;f~GȠQ&Xm ^8KؙE1Yű jB2#ͅDfu1Ľ+_aoYש!R⠐֫AؿSX><dBXD@D!l̻ZOIPO>MO<882 ;B%9˨QǬԃ$߰qE3>dGXz.@jg (班 LWs~aro<ȽRCAxvU˽ϨCް*fmu,_DJnl y";ϮW0zwv#V\% 76]^ 4ޒFf {|$8X5LUy,R9\%npx,TdwD6F9kOo=hDVn[/څ;xJˊwR=܎5b̹DI _5C?@t锯گ”sr:L g>7,}RLwgb1um^ϾAօ@06D8@G2I[s-;$K٩r_^2J[Cw2٣-ۂ0ٳмY9ڵ灴@=Y:Q ƣSVb_^i%rbaI63Ѓz2 5W h(YX7b~ϓSvϷ+waIܰͯ__T0AF4#tO@N#b@׎U,LP(ÈuLphXvmq.!q1 Y3!+lo˾_{:xBs3z,< 5?P)NWrH¯#?$G::븽w*`ӝ;!Cm}۳՟,4Pu* HrPBUT{bi:;hT;*]#swV0^`* rMUiᬰ䫐8]s 2Tesi]lN5Kѽ,E>(`|cx(8:.aX!s1Ѵt^ 3[Y%"aϜTI>=8Qm%edQ>BP@oBkVwf#*w 2{- 3.!&[.z-е̏*+ iӵ@1 >՗>Mb`ΰG;gxS6ͷ? )%WЊ-^T13))%i!YqT<Ū-L{Ո{ZKw:-LAӕDP*@7QjEc80(0>.`_@ vO{/a2B9~I{Ëӏ+23.|h!AhSccn5WGSƾ{Xԩg?kq˂TLh 93KRn!qu+s),6-S"0I0|%Jar_vjXܯ |IFR^sis`hȐmwCV7Q*ϰ*Ox~PPYKP$J(sKeCˑ:f(A0g&9%&"џM;G:)֠Bh:{h+%1@WBS %-QЀ߿# Nٖu@N# 6B;*9cf85khv HeR+VflSc;?9ޚ>Pka57רOU>+X,gS$C|Ň1g@4je qҫ gPS c;b{7C#l3 Jen"pQN?ۃo/fݾ ^s%eJFuyK7ۼh NC6&@n#/$p{oЫtw_=ڪ$leZ`ۀ+ʇ7-i);Xة]l:{B4kx+Z|C{rʄ㙣 dRN,v =:m5tqը*V?ULVQͲ'& QB4.O{/%5V3>r72=5Ғ[ވYiI=Ar8P'aVy5Ot6J5`6>M4fI.7=h0(* vNFN# +TeBŦrHժLJA31)ySeymRHd"4TZJ~vǓےPܖގ3Ám,P/)ny*'i2v kNd$m&,4l_qkEonh>ֺ\Pf+l4A Ap. 6$ǿP)WUeVFQ˕,_qF5 ,glǐecQW@P$>\ۤڿkF:5H7]7%lP2!nGϚI磌j.ڹVL8j[ena!.lk\SOBI=iCti s CXg.T:9lXFxYBn}c Ql4@$,,HL"p̐cj6;{ %@L]̉HR!61 hJo,lXS+K|_53~ˇ>!J;6$6,7+N3| 5w\+ {0 졳E>%U@fbb.eZh{t`UzLK(o-5$T Ƚ}M9.dw~y|UP bNlͱ,C}ՂcayڵJS;Vo7vfJHZr) vzlT4-)4H(2:#l{@~M$[f*D8KFf*{QW?Lh׆(y:6H˘G& 6cؙ.'EòT9oHUܪܱPfqIfV\ӑ@ 'dM!ɸWL^o 0H:{ÀVO+_rTv9Wc6[OI$^~7ϥ"q-!!>c)>ӆI"ae z C 8}GEO3q1V#r[&e8?ݷ( |0W/e.OY˪) 4;F0D8X4A|?Ȑ=%Y_Z`|fHX?q$jn"8rj [c1К}Ndb "2*wS'oghH9sґͳ1%SXY lu&"Ǜ?26jPPa s]%HV_ %qXOĝ֘3y~(}N%6X 5'\kkufI;U|l fUۉ)x#E%m u S& dN^`,zV=Wh mqoںAWV_ unqqx| yhZ)GiLWFʺ wD}i~fK|lo-`k^̗ť!#_gŕ߄v[ZL<:ݏ V>g(*<&ʾ< fLB6bsf^UפkTXɌye IAy7^U ;0Dy]nmPH5 #f.ˤHvd IҒ d9W$qF83\" cUU{$ŜS]#<զ:$kYO&p \@  ;o-ʕٶcdB9eo4jHklׄ _|ݓv` he/"`#n{-%]x%!k߽tdeu4`l!,opP<)aÔ{Zt4rdk'M35U(}2\0Vbʦb!Z2O"/utpWm2 NKN~;bɵʺl.sH4)SN5='el"{G&{, @14эPыcjCDB~61hJFZ?|K)K!ഗK(C;1Yh~%a&D eO`GvF1(_J ZEsH>f;'D2mu,̊ ,p<_)zp)QUL'WKa}fڨ\h|Ö8DQPQ"Lk*GFd 4 ֑ʦ+HI' C~uDBw3xѓ!/#J[zQ&t͏Pw@]`b7= {]mIp(O gˇk4Tq]*AUs{*)S / J3WF!]H;jzP4+i#a DT'C-n͛dш8X {@Y’:Xu*P q_gc$hԓh8ijbH b#o Gk4QMqgAwa2G( ۺb/n/ P*;şނ/DG7F7ȫόWp@R;? pγƼ)(Mwyv V[v`^;66:43E`OAM(b|auE7鸢e,6W0`D-p6" t@OQ4j})ߗk)g#YVV6#C}〧gX50$<"iU6v Rf#9䂤Zpυ"]KcV\%6S-))cRxX ~W4Lj%MRnoiUA[Y`~Y 'p;wq'H%=yxy9^|mA^T&*k 4M%~ގIF_PL՛;D:*W;2peb,G@T\G%I\QzaJ W^" sD0PԿB͓'=>N_*S ad8aT= (Mn,OXR`N/?qoT;v*tr#m%- knWd"右|^kRKkKODC)6ecd{M'׮-8T밨˘NGZ%O\]zhpOKuWWW 3co] sEASm?eHӐ%]6s" s/'=_BJ DW<@V\'g-J) Odk(Gx/En&H?"VnIo"o:_%]s甗 w9fpt(Re5h>YY) ֎%l3ð|՝5ݣ,'IP^7l"=}wjV񳱦hjƟ\ǭM }Fh^DyúൿO0߯C|&BSjh۞[o[z@|2{1J|VNi,aW]wQr#@&y449JYW6>bp(z'k6dC.h=W̫8q 8}t$ 4R~+V|L,88Z/oѫ?^gau:jh?)ּ(b2P`pq M,q떟rq=wcmQS m`o kz_>dc ,'aj%qߡw/H@i2 V6c.Пt) } E4+,Zic҇_^2}Tqe.cs5Ќ֟Jp1^y&CM?) + X(ҿT֬Kّ>܋ ku|Qjq /b0)x}:oL;,̯-COӆ4eWqjUQ*(wnRѲzOU~b#;RL鸹@BUS`wLk9ֺ_ ϐ4 K&/_ d';J m<׭K >հb;o[dn63cuԊkJ/ȅGI-vC|488*]x%ӎ99 &ֲʥ[*41KHZ,䭮ze_+\hp%]J#ĵ1zKSB#˫޽ q_٫2r3VX0o+YyخmA3߶D$3rkv7}FҀCM_k xT+3t9!)ZW?{ON։[KH\O-M5< hFESd,b`Ǩ{3x{GT/VzjXMJ - 8{jI%`۲Jx${9R 奦4ƝT|@@ù%k#T`6oJܲàCOԷA,p'鮨;Ŏ}ռvoqY}hxU aǍy[p^A2T&%mu1Prw`FLP4-pWbo-n0il&s4GiVzcngݯ_M( *)GX=`Mv ἧ2pLo F"~+vًWj ?ugB.ēWre 3~s ֍Un]ǃOF-~t'lK45QH hAtNe9Cnj>aqB&-,8.x;> ojd*[='m,_b-EFJtǫ(3@q|kI\7s$z=ɅY&NY:{kH^$8a^S1-fLGYE BߘBI0xb\6|~1~)Z~*M!\\V_wnXe7]!冮}+V2Kk^ޣWZ:Dwzc3ZM,+GBV¾2S3`,)a؀u|>`sMM|A'gO2F pWO&iw%-f14\߮% :w1b/Suq)8 j0Si5ˤ(#y`4ԩM1 lJ,s8O)q#%+\+3?zB^%iDjjOyv6"wěn1bf@B h`ݏy`clX>CO77J$NZF,8zf+2&r/ a"3ՔH̫*W&Jl_),DB"Vcs iQ׋j]nH3UZRG/aChf.1,8I 8Ime q=o5f|.pX榠 cq0-Cx.svȓj+`HR2읶gÞtő [UBΎ'`p>N0?XK-].bs4EN+cH o =1um-9֋lTF3 ޾?_=\s۶`~*d >{_SwE^6σ'-X(Q a1>w Pqw{r "<'4G`ۡ@+b/yĭ쿤Kx!'cAOQ6j^im7^yNJ7cI&4O+lcA؉nx-7ʵseAd8ːpC]i,"ۥ}Xx\Va U=<ÉnaS qTx<^,Eˠu>~qgLd̼@4ssaUd" ޿x(sE>J7` wBƷs1 ;D Bgi5/+Zڕ`bxuE#9'}W6I ʛK@==Ѯk5.ødjs,+74ݨAsjOYhN֠"TEF*dr+!;C_\^6j0wߘ7+.b/sCVr_9Zl?>9~/Qv|u =Kg ` O2 mÀ5REQ+n"Uaf^Aѐ9GV0(VgQMni==@(rM;CKh_q*],PH)Чѐ/|ۮZpT\-ߞV&_\V,&6w Oq%{q A<*RɊш`YzPW߈SEV*|Xܷ՟CLח~R'm N \ m@p~W7ytaxv;k=c!Uٳ={Xpr\zI ΎZKA"4cZ߶0K;(8G#*hw^Ǩ-4PSV |@襐?<],Yьz}"C(57u߼LWGX`lA\$1w-I=C>H Gh=Mo.)XW}[QZMo8κj</"73tɣ0q $K"ņ:q ֡P.~Ku=J]0QMWP{RE67  3{ږwO޴{Poy D5lw.Q։1P(5M8䒺j%/ *H9H[,AaRcՙ;^ȺpbOeʳu~7iY_~u;r!AsXcE\eD$'OMKpNg} vO qaChеs:z [G/,(_Wb"I"y<htjGTMX]az)HLiA)ۮO㈲y5,m5-lA^-={MLa'1YBķV [;^*CD^woi)|n"ʪ+qx\Fڝ72OL9siqr=R @—NOд;}j 9zDNYA`W=o!7}ѐ1\*ݤo{R3EƲSLGʠ=-m>אsN뇑ڋscD2 4ߕu禗K\3}=VV2[(<3beD֟!Du?Q u ._TsMMgAdv%1_P4$?*磗>iL b[ca3^\T0)Wx~ؙPtyN~a9U`L%2@P-G&Lț4c0%Tc5pu?b5 -ih7xBCrg}#FAW;1т@42@0l:zᚇ'ē%L,6WTsmzrNzsK1Y"B[h91Q\uTb kw5MELjumn$GH#Sj[nB){''6#77l]A,CxdA&jkʓ]{_'~4oG]twa&i 70`t#wi k4xv8LIAXB|J(sUY1ܖ7>C; j~jPRgi]Nn1tŊ`?_\WwW@ޢpfG(mQj2w6 &33y2 ~US H|\PK_&Q2g Lk-*YCȳ!vA%#b]8CtnqdB_ zQo8}'v-|d:_7 v) !9"6^EmZqb hl$24ᮬXT"eEL\C|>|.58h/Qc-2sY~Oc!Uf+@VQS+ȹ z,zpVLi'ޅ7P0߹L*fK` b]kTy4V|[}ą;ם\y-=A) |]9z3 kW ؙ*Grp|Oє\ fhIЩU6\:Ч!kpv_rFl__3[v@c-ZΑ9W ^[wgM.SxYs0=worR  ʥ4?Ɋsǜ!5Gd(cʴZZhҠWJI(` 5mŅ٥DPypT *3H!1XIq(Ɯ _%LޘNJ]䥉; R)*Abe%-8*^b}B0|?r%*&a'nf+Ws!OUG\־|ZJL*~0Z9?u ne옒'ٯK^mޭ)/RnbՇ:at_Zl$:d %=i#C6YBM )t/vDGEn]V5ï wb 5 /38 '9ݿDpf<9Iieo݉}ܛ槇I3˩~)w0qh'0[-t'šO kyڡ≯6d&N4»D@GN&\Utgz9ICL kބHs|+ P8i"k`2EՄXmgUO?Gs'kJ_ŗA*I^t^28]xD85}8A"ȕHdhLz"YWkkT(+mu`|3ifha[>hJZ>R~wrl{=w96W]&\3HԯGƖ~-QI$羜Ɵ,'<'Px]- 3Pf SwrHt}MMkaXV%#?J:@I/|CzXϘ i-- [wpO(Duz:-,k-^aVX۝B\lpMɃ̇^ ](I<' )_b׍#uߡC=F^?"̷Jd|&-0bVCk/H]Ʉ; U0ݍ=OܪO:+)ܢu]ͮN#"f`4-47˫E Cj$_[@ŀ2_kc] W .Nr> ɈuqyGW=*1DuC%Mg X$Jp^O@,Ҟ3*N2Fobf;uYT&W >OZĠ1%2po\OEwKNENEjdaPE0B L> ]Pi/[-. b~Zh$g0p@hYD2nLCz&q5 hoiʘ+?S*wgw rJ|Fn WC»`nm b3)UA*@B&wT HB푴.-8!"O :֖Qsm!5ᛪ_m@*!;UéC s!}L#j"FIb1򢥫6 @Duw4 j89h@Y"s?dq=ʾ2=葮&][q,ӳ3T פ'$$eƒ'<҈@vZQ6.R !9vKPtʓYDPZ[<!.|#8QCw_kA-(3+R)'Uarov!&;as{wODK]"`nЬM1V~c :&\xL^z_y}x 3ni>{]i@KYP g5^ c0}k8=LџBjBȃ^NbI?LU̹L~ {S1cAϤ&VfRj4XunP~A{KSPW;Zӗ*+\> ~V<=p $+Fg %p$*lG] !܂iSx6Q0峰惖joB^9,4!Җ&'0͞#Pū-_s ӭcXhj9(K<Te.ec_Ϥo_ou q~:A<'wZͫSp!@X, ߭Ftm[*#"ipW*'>%zk~&leҷڏxf_pHDo {-Stco=v@*|L$lሬ+1@VSfVl[Ͳ5%E}O\)fr?FdPL< -Qخ9|wJYr> y J(m$(仞㷈6E4sb3r^U'G)h;DL84W.XrKNDK[.6ۆ$iN+4О_HP%"ڶLj$oX%3d]/BW/19f-9+F{b )r^:O`)g\pL?3տPn$!gl'3#UB)a&IKv蒡zqV,v5. J&m@GzͧDŽl>z@R'KZVPf|=$ڸ0Iԥ5gzA J߯x)oBw60XVt%RLhUo+%WIKgWZmfre(5^%[pdp/4`a  }1IJ' vJhm3sԚ⇘7ĐGЗnAq茵&jY e=9DpS,0t kf;va e ;79)8l1*9U*o,kǴW TVnL-mz=r(i?b׻1@+T~ tO\; q/pA0e6NQĮ.`T /ŮCATݛT 7l8~'9c{'TO3KCzv=6ii{.]bGLqKZٿw58@Fjt+B)D[h^vN%PU&K@X6P xw `-%dueuQl+K3%4pS{0Ȅ+W V۟./M 1aMhZM\}KԀjbq+dw~uVQ rJJsB!4 .q~5Gd1=h8I[ݘ+2mzS.iPRt ۜJ 5aoP, ]/ 33rB&űnu rhn6wҷźy>>< 2W.|q iFfZ`i2OpH{x=T<`5_Jx n+fG 1y~lE.%a 4Q혊ȼf+0׶_ bՀލ =ܻͅBN)q1 2x@@d_{|g~&Ήp ]bH:` oUS+{=)GY%tk 9 Sb^ | o IwJGttyE%FiPJ8ׄE,dhXH$ZvжV2/ Qq;)@/&YF+V&Xi/ˬ1YF[_t;ÊN.:͘ y'pqA0s@{" ts ܡtbI2HVMs=´Hbto,{KZy]N,7R*3ҿk3a3F*4Q AD]ЛiB:ݶ(Ck٥=cdIkfуx€Z_&Ss);g Ef5R"tS7N7/ZCR]h1@qTVHM )>s;XxH@5 Idn=3p+MQs7(c;Eo?Zb8&*aCwK$W&mFEĩ,AGJI-fB5/hXХ@%wx )k7 w}š'S1AM)X\UMxPTA ~ۄ2k"gZ_PTk,l|.OQ: LgN 7F!Ja{d>ڌܹ /pEf ̹?Z."dg׾&18D=%hdRavsby%geǢQA #Ty4yPⰜm2Ѕ:ҪKW@SXy)jLG Zg#WG & cոGrNLy!\:iv鑮zDt u5IƠ;#m)}:WNX "8셠S1%fTn&|-]!orzӾa!qozzM@v^fJL`eW4ݎaX6# FW)E9tZgks؅߼10u g`tuAsmοCqG!b=Mg0\ O۾ЃW. ea ^^x.Z#QU7;J^Þ8\Dl14 ̛l>xE7PRd&hp5 :PU#4d<Y-Fc]zQyЊn`p'AGRRn=ɽTLOqs]#gFx^NKȤg?{ٮ?I%YLK}n5V(Zgx;A2 h LI}MAv1丂ҋo-gQ^ {W ,w+H6,"'&;"dZM9K/I`+,+r1E{BL ̶ u%RiϦR{gh1qD卥nwdɸ@eЂRғz] BEu+j P,&{c <ຶ)uVY4D g,%)9t#=>`z,B*A4Ft0NMo'PP\njeLsC۞T"WT殺w@GD!s=1H}Wv0i92eY:2kcy}zS;Ⱥ L͘->cIe0Y^ԏ6IDFajhj͜(AG-,?%D^zgy,ѶL$ԏ,{lV%ޱl Q ;da'h!SFE3&Ы&1`(e۸z!uJps9yQ>QӮDb&sb3^M+EDNp|KR֕IZX>־I?98s#Z^0|Lo(Luq4Hܿ]{31Rz$n$tΚ?W`|ozn9O@/ Yom}j؁nca190W9H%C(,i1 I6 `rWpFĐXk([SV3zcL_ܻ_<>sZSX.ۮBuo?]ԁ[VED.[=x'7 ({oOzvMt:Y,P .hB."[~/_knks hv5yOU/.s~Bz>a8`iQQwM(jciEDB93$T3u-("ڹk-v*sprx4zW%ޒO0x/o F{828JG*(9xI$ aQ/:5v?~}dїb;5^_{2ѧG=*9~"Oz+ķsCCVQ۸F9 # iEQ`O#k7>Ў^B8dVPUPۂNz3CsS(bBP"r&Mm.l=(– ]Uux3{Xt3g@'N=!d31ͲU:Twь}Cj2,t`Y OnX9o a5/Dw`!_B!R= GـcCkp] ֐ Olt2HNN)8Bqp+2PZ<"1)C 1g, va->:P 8dnT>8ϔ2ԽtԶ+FЁĚ@CxQU4^דk =^V*]Eř E~\Aߊ+ 2. i:צ'?}ZU| [g9P=5ք"I^7aJ;Y.j#Nd5Rw &40ֿ:oB@0>T- M|Ўr'AtAPԁN#,_/׋ I\hR{}tJR,#WS]cXtjHUˊSV=>b%Fcb3FjÔׄcl+hv mB1"t DgA虔bL 2ǚ&Z~7M>ОDoiIf) lAn~q)9 V6Ta<[i%r&1[nvrU<Sa NZ4, wBC^:œW+ʊ˟@}9Nl.T;/bY Q)+sC׋GyoNV1LIAfoNwΉˇz6ĢnVĈXM6m>Q!}\iۗ暐!QaOtT6hl= -|t%C!eЙjHc  T)q4}Emӽ4gACN2: 9\;7k^e47kPe0^ϱFfˁ,z9q˜0ѐgD-G{:Z=t{ )GaDz5,uʖY{D{{ J?W|yG\ŰMS07$AL" қ\[ڟ(Mg>ƈ!<'5zzPGZ5;:-Z| @`W.o;xK7boI`QjVm{ 䩖oV)l+Y~YWQ։dӧوiC A%hR˧;,XNLi[V|Oҗ ݩ>R//?UIz; Rڭ7kI61yV)&s (Z3'ffmAc9f'a^wɥ(ΥJ5Q/CEX.g%uU3[Ӫ{q[k:?gD M,Tٟ|x܃k󄁁q{NXGiփ $Ybӊʫ"ꑆ,+ * !;VW@ߗ3>piq^U˚R@'WB:] 0"hbɭΖQ-mͣKlʈq GH:hHjh %_@\J>mS' tޱQA6V}@2D$.i:ae1m:Iob?H,V>z}c']s>%3 \ʲjQa\{JIzO@Q),6a}Ŗ<;WϕuOUcn:rj5ڹ2Ï Y$[g-lbxaF:2ka(qȺiC]-uGK0`(f3i(p(C?` ICQ2SՂt@'g?XXb.xk>Teµ{D?mN`WLJ U=B8[!0Ÿ Nz#;3" +߱fÓ5 .z {Qc,Ŀ=MSR:~{O'fgqu:" Ofz,mH4Kk~xQ~,S#ʊ Tm e6Kda8R|5xlڬ4pfD%1U!ruJ,Bpbms/8v%__jeKڸv}Ԇ^aY Ц3Qw-7tfuot%fWLU1 ߤ!E17Vqa0BFiڕUXQ-dPK BEBIءAIYb j^ՎtS!Jnk/Pćd=1H}VkneZd|S9,*Gj?+9phʧG-uqٓ'[NX|J g'U)8~qI0Ue[dqϯUOZ7# h+-^̞LzQSt&f,ηJOU`&jleFv DE"|b޻Ff:P"-*z;d/DG, b1ВչS-a]2a~8r9(ǟF泌Z;))8&p91ѪjU.;lwj4&9'&V$$ŶG(Ƀa\4#L Rv *J[0KBX4FctId7Bt):gT3%JZ%UЯ>_KL_іiL"ɟBu/bU(O)xo<lPMʒ>gql"Vw0{e g NB vWqѳ052ETr¬OFZ PQ9;3h2Pg㶲D2M[k@̼f%|(W9pd_&{n?Wp+qc3ls3aU),cwܼ-aQf+KtjMܑQ7mPU TKV94]< vɝwjk'7:K^sYka7*Ӹ%HmB-7>/t`;2 o0Ou٢ PNfwYI5u)Ll:qml0kz4]gY1LlO>;ڹNz5LjYgQ\4 :I5'f"'M829.30U%ڣa@ME}T7,K$uT~% 5Hw›e?+v ~/~ 3䄧 @,i?W/Z]/b]%fSx!W0CWC \JM*l^"_$$k f{UW9CÍ4"꽏57]ɫ;liP_O{=9NmMrJvZ lGܛ.첬01<. YSR!z;M^۾%AGNŌCm>4+A-uQoݡIWHOz'B'&dHƺou1ьҔ!wmd`;s"с;Y~baјKb8J0x$v췋 &5uL'R#Β#'ޙN.m|YQ$dpxdx,5*%YА}B56l ZԱ}7w>ֹ8ru7eA/tijfYɈ'L[ 4~n8<x.Gѳv2 bƼ2U]B*g#c/>\1T7 |On)2y<"n Vŏ8uc1^`ɥM $ϚYTP礭X3ob6G/nu]o-M85OTCUB=U3{ ӭQ>1ĥ%t#=ԅu/|HJ쇹YY)OS1g |g|Fݍd|Lbx!9is$r\ʉ\KKZ< "O' zS*N0Pp~EԜu !Ύݍ t|*TH (0saعpfJr!w3v{+xy̨G,qvspWKk<GȮqIXil`(Nu_::ɂϠ&d ˰9wC"Ώ 4.U{JpQHbՌLGgK L62A̼VtubomG'/A4 k@Ǡw?7ژjcM0 f0?3'q%4X8{5wf t rU){2pG>bEAK`8mZݿYgx^ h.EҫYqܾx\\KDZ+*-EY~&&u]bcߗ?R;fӞtjN |Zr+IϺ32 3;Uַe=&p0K =W_h۷3oO)O}!J[``AN^"G81ZӭQ+ua,D߀=kWjl\{rb~;uNK 86xoDj7[ylC$OR~%v`eIeIGX ɨU*ZPk6Fd^e(F#ۈdu!. -N +:?a!ؚDi>_లf[?=>w@!CJNȧ߫BnKdyҍ!" UFwI-?]k"c~#QdDd$!$n=ܾ7ln.=iQgUx3Y[;"U` f%db|ёC°yjX>\y`mb(JBU>+9ʿ*viP!7*?U,kwvr̛)@<*cnoR{Փ$79Ym-Y@[TƷud'dT2\1`8y_P cd!\"9;wA1N Qsy O0 ߆u!.(Ro4̾o *I ;yD|ɛ 5[b7DgA#_;mR .f͍TǍ+P-w(L#d.h%`!8lt581 !+))h`yf?!H%̓Xɾ\lʁnOwV~XI1lXNh&uU: b!Ϫr2qL0ʩ?STzV-#Aulg>3/F1y_j:ٜ}qa/WUgXZH ܏'c}m5]ҫRRh>yE) @焈4 !bH?fԻ=ʊ-޺HRb<& c$!l-3&]b.PcW*g{|K_ubz~ت lH3nR’p{͜*th:z^ìIqC)t럛 9< `cK0VdSr TbRu 6˘ Gok}ų:wB0kT5]4Bު^*숶#sYVt k{τD83ʦEX#E͸wb V4uM@Ԣ*n- 7Ua1nAib6ulˮn e vq"dB Yp<Ƅ:Ae{@Ɨ=c[#YՁn sG;O\-H){nr=b)'TKT"ABdrPE!Hv<½}V`0͔%'C Qx-6~9!\NFQ.Yh3GIDwx\VYRs$mbwl1 ${}v6jms*#V$Jϻ~=6wA(//gj=u010ΆUY}!PlչK+SYo\*[4H,v Z[F.63!ؚj N.px5pI/iB>:# @>ډ>E22R_OilR.<`.i>1ez[qWN&vlǏ҂A2)EIKk?2@̍#qO!C4W{"2jZ# 3Ɍ[,=bs}<: R;!5@-ˁ|`Ǘb;USQuUՐِ1oP'\A64m2Dgb@%5p<*a%g~<"=m]O:)ЦQ\J˽QbFyG:f%+cr 0k/YIw.GhU!~|0k2lh,M R6E%23eBwvW>+C pZc/1AL%3pة`5-ir BZ*2i͸'xø/ÑnVΦv yjɊUj|IE^6Xv CrbbpjomQGV;fD#X a?o ?(,&!d(=NLނJb(d2n}'y93qgǴ`īrn{rG=5I%4Z[R_X3.>lP{p%j>nV9Ffʶ\C?š,g5([c7~10t?dYưc{m 9S#ю6R~i;=UG; 37kXYU?\+Nf&5rPTxZ%u.F>HMf9euw;ٵSSArVI@`~!4dッ0q(gfTXvJbK%EyΫMM%FvӬU'ӳ%$'rOuDP"P;m 50~-u(uՉqF-9H`߳@;ֽ EYX%1Yug>5CTN9-}뎈sCG 췿nɅ.enVnKo\K .p}|ҸC1]}S"U&zsv j5{[路>Ihȿ6Kό)n_BM~i=mΊ|^oi%<Kxi/ixd8R$qa VC00<8KОc;E)) vs{ + hc ,8RWo>R !%aÇ,fk..KΔԏ,eyo]5N*ڼ_")9 9aÉA{O`6HXyL딭σ;LijB EIُHrD/ZRF*zOF7L@%+[|֭nGEPv.@P>;#ykY z!;t[ c]H:AUjoܤީs=pUD~bkNvc/DǰE_N'ޟb'Ut36`7:үǪ.U֣aoH5gD X$A=is/Uj0Qjj 7UuˈnP!2V"^dU\_QZ$k` 'Q9 v_zg# iHhą=_~^j_!r' L0oƝ!/1N8踆 9ݷSh.!46}ZݽQ1k܌ʟu23K2-Uɢ[1 sӋU+,N N0'l'ĀRe }"K;-RRAM2dGhȠe&y8 Si_y]]!쩯aF酋ie&HO՝j1oz,Tӟz]%H_qu4kAKT\y6cK5x'@ѿyK5ΒС(S oդfOZ"ϰ {128&NU]萫4 :;"[i8X: <; ƌ 7 :2  $@NۛݑHոf]9%ØuS# 0wntY|5yQNW9)]GnIR'/9Y_qGx;4)v?f'М\ J6rL $SdXwOPLrWX 5n.=M0糹cY%^El23vMG{|Z{w>VۙaTe }`^ dj%`Ss)'o=DDž`$R"߁7i{qq!'7Gv}hǕSv;F[?^=(~<ҵè6ݎčw :.=XOfyK۶0 熦rvw.u4ahO(=w&=525ž/kU侚jp#0_g&x9YOV r}Vx- kL>vO9x[ϭtIZA_mz[<Ҿ;8ǽo}M ;q/fKl+θK*V6LBJ sPbW :q6}t)-אָ.f; .t︣kU~(7yJuf0e &s@Y=}K%zQb bBӪHzfw]T蠇|0w!LT"{ˆ}NJ;y~& q {HS0: 'Zz+{.EM–9HؔIǬFPt8(Hf>g_>^>{gs,l<|E({(dKƜ\nZ\ߏ궥J>WX](qnT~MfmtNWwec67% a=];-v]79=9.OL7@ eY ;%-Cn6nUs:#8"B+dt~+es뷾%5Dsi. y^'EqQNd_ܿ{Sb9_Vϐn򄺏C mo$-5Pxw T,}ߩm]骍>/Y|2lk4h`UE"Ջf%؞N&$l)I{,xz@%+>Y~ӳ/ >nj)pg: ciPWz VmA4nG 1=c` 2N H~dY&\)~dˈ9vQWEA!@@>pV?㱅"rgRA?hWEtB`*%1PEG QG/ 1>gg&Wh7__,iKƔv3 =+<uaK 7* P' 'Zy"Aqs~~l2M´~Iuap(@F=Rf(lVgW>F.aԁؾ=x3=)"Rd*ͯiDUIn0 y Hz[2%T3iNl̍/TЄ0 c|&FtϿGc-(Na忹Tc"-UtSUz,T[UM3Á>!*:h,5GA(NSN~|XRX@ Nϰ|}A$45v+1m"ϮA'ʬMgaS)Fyc'E ]m YZ