sssd-ldap-1.14.0-43.el7_3.11$>tRuxޔ<>;{?{d   = &DJTt    | 4h202 2 ` d i( x8 9L:bGv Hv,IvLXv\Yvh\v]v^w#bwdxexfxlxtxuxvywzxzyz-{Csssd-ldap1.14.043.el7_3.11The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.X~oc1bm.rdu2.centos.org_CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64\KM7HJ ?YЁA큤X~oX~oW~X~oX~oX~oX~oX~oa72149fa0292849947c8bc86b7e749a537aa910d8376eaca5b7a68ce7fd1f20b8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9030908f95ccd4066db1f5906e1b579b66f4f1f83d5be26c16b2b882f6a214bae1cf3ec6f614c110b8432b7a959bc79b41bfc402cdd881235096e1f96e92588666774a4f13931fbc2630da3972e92a88447cbc1a8ffa64237b9b9306f5cf4b9d14b43b1ad419d63bfb38cef27b41a760633561ecc06f42321736231151d7e7e180530f7457bdde0ea294f20a0802aa8b5eb47b758ce7c5df1459a8b9f4c6eae07b1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.14.0-43.el7_3.11.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpthread.so.0()(64bit)libref_array.so.1()(64bit)libselinux.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-krb5-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.14.0-43.el7_3.111.14.0-43.el7_3.115.2-1sssd1.10.0-8.beta24.11.3XOX8'X6@X5X5X.@X.@X)@X#X!@X lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.14.0-43.11Jakub Hrozek - 1.14.0-43.10Jakub Hrozek - 1.14.0-43.9Jakub Hrozek - 1.14.0-43.8Jakub Hrozek - 1.14.0-43.7Jakub Hrozek - 1.14.0-43.6Jakub Hrozek - 1.14.0-43.5Jakub Hrozek - 1.14.0-43.4Jakub Hrozek - 1.14.0-43.3Jakub Hrozek - 1.14.0-43.2Jakub Hrozek - 1.14.0-43.1Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404340 - Use-after free in resolver in case the fd is writeable and readable at the same time- Resolves: rhbz#1398673 - autofs map resolution doesn't work offline- Resolves: rhbz#1398169 - sssd fails to start after upgrading to RHEL 7.3- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1393730 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Related: rhbz#1396486 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0- Related: rhbz#1396485 - sssd_be keeps crashing- Revert the fix for ignoring sudoUser case as it breaks processing of rules that completely lack a sudoUser attribute - Related: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392946 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1392893 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1392896 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)deesfruk1.14.0-43.el7_3.111.14.0-43.el7_3.11libsss_ldap.sosssd-ldap-1.14.0COPYINGsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gz/usr/lib64/sssd//usr/share/doc//usr/share/doc/sssd-ldap-1.14.0//usr/share/man/de/man5//usr/share/man/es/man5//usr/share/man/fr/man5//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e7cbb7a047c92b0d746f6552d9b7d05ba30a7f3a, strippeddirectoryASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)-PR*RRR'R#R!R$RRRRR RRRRRRR(R RR)RRRRRRRRRRR&R R%R"R RR R RRRR.?P7zXZ !PH6L]"k%{f}}ݱu()d"V(9kj7@Abj5"؞rOh؝z9K"V$enh@FM#2;fQ,_F ~z!B8SW.q" [-Y !gf(OG@d' K3 Gkޝ<$eߟO}z>3uD$pwqD$3z%yaYCUE%U`$PX񸜽^IxcPXb{H!v%A\qԘ藞%$6Hpqh~ܷzmE+xï784${D"w;x3G0 9Ko:JU  a/ȵHy0%HvS&A*v smfBp+]eumPa}`[4lυX@,_}&.,AiyʌRC[fDnF ej>X}}š"/1J98 uz<WN˲g63&CytTG3;пOi*}XVt/n,kO^*q<]<^e_uC.I]?uU|D[ve*{h/+Aj@G#]Eei5 ؊ΟӜhA?owBEgO0ʽrSZmo XKůVMZ:1 ۺgZg!3Qrl@>ay9\B&ta0≑H@.c&T#$lT}IqX.C-PSqeV藬F;s4ˤ&K1}N:!;fk:*tUDU͚IeWe0㙤;C=!Ws M JZL@!f~ yVqD1 3>/D)Bo}ϼ0/`r²5Nao~kM Ư>{ՉѬU ȁ;6TѢ1{j`nޣv! .Q@&մDGh͈딼&tMoSiG }|Mw'2jdy]Qtض,KGĘsȃSydF2rUu| l}dʋp>1 :ڭBC$w} K ot2 ]NlU_߀v} %N5e=6& pPW~&M>hF8,]A&?0!OPc7J?8ШU_䏭 5aC"4p&XpG)N%^u܃*@1LwYPdc00PVgI΀70[](!t ~j#HRgW RxpkkhtOx"=lm|0P +In**~ZzTH1g?-p1&uX?X>F'Z$D@Z+Yqw 3dxEP{_ɟ}{UN.*EZם* 8p!1Hx.Hoh;PZ`4eOS5=4SDי$R)Q-b-V;Rq&vb1;m<^Xieo۝YD1ԃsSMȽ)_֐{jpYqThwY?Qie?dNmb`JA2Ԓae7岜Y&q:ףP`bR3/fjqZZ~1!?%>R`&SΔ>s-aG92BUvaB"P kfRq.0p`+ʼnkt=/(R_)¸e~e؎gw/U!eqf/~2Wsq̯pk/L tUu_S/)>a,a$(q'! 6kv@-ݑi9Is[UM9{7l^HY1LsKi\cg\O<"qãIӁ(,aRzT3pIQ{_l0ۅ :ECT:8]X>T/`~V;@"BB3F*ȗ3A8]Gg*\KB`ۖe7qD`"DPyfV1Z0:eBbQ!B f1, Ncu FjVLg63t zQ?$ ^1{IK \n,@"Yw@Aғ]CwBќ-L#yc׌ޖ[7讅ya4~)<H,r{!qavoYY彬<#O0mErU'pr!;f|8>< 1[oƷ*)]Xm*f_uMꅦ}{:jb*G: $,(yNkYa}R+g˓AVG翱^~ Ⱦ,ɖO>qwbP=;3UN!ҕ*"{vT"_vib9B{7d; Cp,`MU! F8EE:TTiBH|x0h̊ 3.:ܳ!mfc9ؼiU;p*rզfퟥ-F)@ҊDQ4{Fi% ]1ii0Vb$ KC}X Gl 2\`6ǜ'ϿЈ\ܜ fCz=ۮ\iЖQ}̑ _|3O'[Ea@;݁\YFV|ۻEO6kN&eR5}?PG., "1!7UprD'`HcaŤ ݴyٶU&|u'ӈE4$%Fdz7e;MIp u I/>Y @ąGkUgt\j Z-fڡt.gmlyɹz+{fn㈫R&qžжH SQkzL9^S F?8LĴȎfPȧ>= B-A,Ӫ&"Vu'W oʹVTTQ TWMU*%oS8uœ/f#n\CҌ6!)isTO ^6iqrX-g g,^WOf׻m 5G@kG0twYhYFĉ#FFf'ou2ĭ/`ZX=`UmFem-hxv>7n>|)G(\yyZHpcBEA^KR/*ň\I*2IĂEPf-7[(F$"a4U-m蝥}ӿ:;O74]-;+لᏇWzf xAM~|YͱX̫?PCn pr5lA!'Y6\J% 6gjuZAngiw˙C= -p@D'u["}S0`t3<є vkʹfZW}b&/תHdx ,YUStL3kt:'s f|)H}PK]t+BthC)r/f(!>Pw:r[9,|U~qaLY frý?` 崠fz+!`(.?C&0KTE{Zz;=C%+DFBatѕ@qW0+x-{k=:ɝ:J]j[Yp;ULU\IvohU@:q "(˒/#Xeuݛ:X߰㝐ٍ$-$ ij gk ˽U8)ٰ gD}#ȰX`,'X̽?b]eJ% w(ZF&y{)yTґ(2lf>GI7NGs당نkʮW?/X0TGUrM'?'&M0CWM luL~Y.%a8t\Oi]懹. Vm^AZl";CoYvЋSg N5(z =֩Eq'L[W}" >o+%pY'?^5Ooe,"72@qc:O{mg?F`l(p!ax=`F !JUX3~qMP_ T2> kAR=iRiݼa.NEÓO+_lMP|pZUwS.Ly4iXHH|Ԟ(&ddͧzfS(^YV=@ou muYl!nʇ&I駠p 'yFTɌfriq]19) ]dmwJďjl|\棽>s2tKAKtv8fv_ w[;Dwt*C@{%!vig\:(f䵁t1P019Nu@hY>Y,h2ڡC|:p{$#tX'XeI } ]:(*m=ž.mB3ZioG-~ְ'C[q~~VժelX)z( 9hʜ/)*Ƶ1屾.ʸžqQ6M(*9X2ŭFu: EdDّ%BeiڄmL2¢Y;2MZ!sO?!flǘm9% Dۅ%'űkACG]P]hZn6%l-˛.1vgŧ>y>>"Ӗ;}ԞA e]9Cc;)BO:/h90IN܁M: -XQSPK ERo!U[s?~Cq$CtSf 3dVM'&T8UZ}@Dp̼.yjbƖ,|Zt] [pmn䰁/FTA"mP~{kTkG޿{ IGv86Fh"44k$\WhzR*L{|akSfTR D::QX̺veE "'ie?jSZ48:D ^#Bp'Nyli`D W:FzUYϛ|k7LOdRh{_KA ޾}`062DS [5V*ko)x 6Nx|gb W~OůD ," i߇wX U3&=EV}pC,#F_>% 𒢐 "~ `*E3hZ8a6.R-sa6&Sb mvݬZot_<vq#o5FĻJkF,*KoJښ]$:yNXmB.EtYũ,a G6&ܧ7i*ѣvWuq/ZC,y E;U]ꂋ;irlZ=D;$;+o)M$>4d6w& ۪uژ cVAڋjg4)8wV(E64n C س3WW %,C:.f+r9^fW(:+kj@o˯((SOfI ^.'ǶW𶨼"4 `UgQ>D9c (ܼZ(S|`Z[(272W20;OxL]Z߷ l$`b* VY_9RNP[ ,U:L%WKcЍ<+.Uy@2LNѢ#3[ܲ\gHK:"˵}H1 , T`h W* F+ U=~X}@W|gxk54$,vHd5 oZe=ӓKR'hIn{c,ߞ3KՑ.YN:L]P T;-pKD $b@=c3_BЋ)*?̧2N]u׬\b$r"#KLK’HR5-=i }H%@+ H%s G=5[U{lOUM4lnJ聇:%ma2R}k(t%\~He(3z!)GC卨窄d5%/~P3t^r'ezjw?FΒP;с( ʷ|P0Xb?Cg.-G??o1,9yBL3Cyn ]LYK θVB,A"α7"z/@^R2f k}!\#Gr.T9gp6ҽ e4,pގp+H0FQ}}M{ G>>VigHݭU5 6c=y$eayJpA[P[/ foBxؽӟV.>:.~EWGSIԴT@vj >*j( :T"x :X5׆^wZ'g+'x}\:aڈu6k~:k՟:^̢P72H_"<,tbCѕ_w;6ʰL,tբ5ϥX1*wNO"pmi1JxkYPoOa 'ԛe9,|sSbh.CSZ180E9S'%Tw#MGxHD: ,qsTc1`tdV3Ki{߸+0z)D+|{SϪHo0v97+_7 v2D֗VL0R'?H3$)R5a|/*+w;6o=3a(#3yէ4sl7-ɞ `x[U9EOM pP`Z]qGd{U9/En mqE+y7)^a[RJw hO;UcǣvQCuG8gM>o)&% <$^D^>Q SVO*<$R#LZpTP?J[[@X3^i ŹPuVdrH7|BusێqH"t%kZN3G2Ÿr;/#hhA97H^߾8άi&1x̍'ӳXlMQ,B? \ 8y[z)t,A Ԓ]L #| pR؋[%YH]x̉i}88('s¶LtQ:> n Q& +t]լi]a_,`ʁØ\ (SLeJ`3 Y bdAQ 3||~Km@. !2V}Y} nɉוZR['qrI3^Pa W:GVnH?R;Tꗿ/+fQa >C5e~wOĚ3mJ$T}P0b4=sSd[qIQ C+Cc_kV$Ct"`}50 hk]Ky{ŠTUQWL5*hELqӈEd-z5e5Ǖ)hv2\T=T?;WJj-Ku^S;;#ߪue~Wq5/d}J3;F2(lM79%ѳ]fz>矐]k䷦nn6.=.TIٷ'F%4(yG/#y>έҥ( l #N93zU OePuq%lk85٦95α[~dEW)~Ra -Hf*wk>k/H92 o&`jHjcrktq[Kddȋ:`]mۇ2ge35r,nv; _ZMqCOvf+{5NQ+gu,]W++[l̤XY Wf1wIwڀ4nQֵgYVDZ>̋*=&5O6H;^1׊B8D -rDSOyc sg$OSd[)BBLYVȖbFG+_]!]y=1Z S+cز%XiB `;+̍PrL33NZVXCr?ik!cSO;.+l`;/k'# K673;b~*좺?^ |OjkjuR 웨Px=f Th{ɹ*>c[/ q+}'(ϼf"{{9y]~R vj*;8]xx,}h=5Kc')]>Њ=&'z;nj{͜/l0fb,]V7|7hrih9$TĭUlЖ\;L-IRm*Q$O֩[Vᓻ)8\[syM>w|P y Zo}1M>U{cWJ:@o%7ѹ;gL'рP(>YX0sF\$gCuD^u~nOXEA-WV*0GX"iT=Th4kw`\?tmkKGYY&P*Դ6P.!$USE5|&`Wqٺ ,?hsanx=0ĥro0_SJsG/#Gi"[?\Jm6#CP24qEg%݌sH%}bC sDhnŢ&RA'x s]$ǾĕrŰ4%Sf7u! nciXwFG3}':^3(4 +I?ô_U%?)+H/@`dhPo] V:`fsijgn8pGGFs՟mE7ȩL>IOme5^e| *kk"t0KbFOyj7h" ?Jm _IќE<"V\ZYsё5j}OUtnF Ph:/tj4"b!~yExHf_+E\.BV|ۺǴo\z8/eui,C-]PaOb*JغW4 2V ''zTZ%𙣾#ˬ v0zĎԎl>NQ0Uw֊sEΤF{5AYY(ݗ:24鸯HYLJ|3Psѻ9XQkCmޝ3(i |{Sx5dCqFW;|xkR\hY|;c }vL-:Q@6<A!|x 8aʄZqxsm׼ضk͋~uM/d+$.]Y_EuD&AL7zM|| t?'5wOAgSK-},Lq1rԫJW<*ACY>P8 /ݑS>3ݹN` :1ܒDߩ,0Z;ȼ|^#i%49|+FtVbCM F1i@i^s[%"uz\a"K+M$]$yIOFAxBWa[4*$]=DX7z+ӻ +M١+=XrTRŚE+kNT{#!R=p7QĈF鍯|Ik(1˝QXbU薛jγnn W@m{J>VߋkqnBhPAc %Gs.ڬ=| eg|WzECo]DGاȧJeg*I waF!ʵL-5fvbE4nK ^kXa+3:eS=X@jv3n֥CeP }LYOQt-:2|'mE_. cYhs&ሠ}hquTCdECKd%l8ͷkȺg4mCP^Ȉk)^lGݏ1桨YE{u6b[!hܼLJp~5K+Qȑ U_Vۻ=6ɗ%FrQo7(ROi;Hpy0e Y1xpH~'$ օ:˵^O1ٳ]؉j2u'+ev v<*qYn _rdx"@gD0ǚ\A5{܌`BrH6' ,G$hq 4ҫ7HFL||io& =#k~ j9*Mw,@BӰ6Et]{"j[R÷Y n;X+`S'!lP2׾w  [P{@S[L&WTt3K~T8_)DKE! ĸ0_<- pɆ๻fXcҽk*þԠ/g!q~Cr:i @vĻ*3O(ޮN@4'hӴj (zZ'!bYWauј8wӴ>/ư~&5Ǣݹ NO\`3 7^PDLGM<A#P oQӍ|,#@'$,6%X}ɨaLt h[Gц]9/NMS;A( QsB8g}iZu&Z\ Hkߐ_(=#h>۳UJ\QyMRn*~&K._@e:Ţ\(IPMX;4\CV災 ml*]w6ʞfl֦M46@)!泏$UoYvn@륭y &Tt4s=5%jxHxm%O -hF6g>G"ނZ~^r e7o?n܂Z.ΦcdF7c|;`U>`K¸8gOίL`iѸgBuhz%3;yE2ݴ\zwAeit:Fg@'g. dZ㾠OlY9e~[-)5[9/ ;hb2:cp1ޢ$C} RŅAL7?-tt@{`4Wc]EZ+*K};0MOYbf?ȎZbn*ӷT2 suVA Ǡ~ HG9PugXYOyVQD>xSWl=;& 3RBj[N. * p${ ӈOo*<3hBj)5l~IKh5YSD%PH“> R2X jkJAA"Pه8WkLE=qu}}"R-^עIɁ,Qkk̓SI픡2RXdSn<:rnUDXފerMB\2ܢfNsVK[.\GZkKfn2{넄2}5nVhYp-@d֞em}Sx P:CSOY;gh:E4.u<]vKjvٵD_.b+7#J=bʤm0Kk0D˴g ;v-"o! 'G]!E5S2@0?#w񛣮 VӘtŚ'tt:\Iv1nor!љ~׮;E(z@fKPnntF9lb_SRTsLbªql$5A :pi ]6ۡy9ook=6[Pii8#5YlR1iYk(*t"+G2 gqa\QE$M1[ITC% qfHS Ix.M2&yd@#zƐ`c%X:w4ҾES.| J˧H(wRJq+}beb.~~+)ݸ&PǮqD5D'%y8BQ[c0BKcRCaZ}`t8NC*`Ƚ:6N-}u;_"{}c"Eֺ+πKT=ߐb|V+ezY;^ʺ)3T+نpYk:wM}I^`%2 /&#D(u^$APyVCy77Z)]EUj >3\5$Ѻ=|"vȯ]:do Y潈"-ia9p֋޵̀GyP߰uS$9k<7βQ>rS C3A2~g pi=ᄐs:-phh-.20 $|&)Q]cdiWK|1o=dTcsV- څT*Vi1drqIIq#9Bī:5\ez .bM^(ʫO jTs1$ ɹ^ak=B-JCaKx2KFhIHABvw *wNږl]Hb}_wV  ]߾6`o3BU1<:rTfp\K.v%CCIyk IeHa \2yzC E![SQr+5Yoᐵ?-PiѤWB2 T(NQ|7KʎcD. fٙt!p)eYF6# 1ijV6Ho(Q/mP].ȍ6$eA~zO-1"ew^d&hf]1u4'+Q|ج.aדToYcߒIeu} WAXaR#?]8^v]_)ԯkY/Hބmߨ m{umR= NskgNexqL1^U*:cʙe_hlD?'@N8f * O&hT#*+,60klF>5vv`gg8 v3-vs[qzr'_EWCfw5 /$-pZ ?{l$LV!~*12loZ/ƯBʋ2g'OH'( s,DWot]\ @CSԥf[p;pt<퓿d(!Ҕ[)P Kр M2iVĨjтʰ>~k{f|Rͪ3taPSr6ǜE_'1suTs~ݟG.J !$мL -yni|\\MbcXկgIw$voܑcSUdVP!YU74M[ -Wl8#i&]FHS[g E?XSn &] U*ܘKXՊEK蟢dtվy؏K $Yah@xAI@L?pGJz(x٬.ن.J2cDE`gQw0$b+7L ĤԞbsIhW*|& N\D ̲2QTH(']mWQ!OB ᮄdu}wcK얿~B΍}4 \lR0_ ؤf㭡 [KD>Wn1Q9aDm4M^-(vB yy0f'@~&Æl ؄{_WhC,s; |B+v M!3ȂD/-p8hGo֑~d3"rH\7;J?Vʯ+9*y䛦,k~&jf;^%< Q JL o>Ȅer1!8Cq/mɞ23rՉØiv3ԣi^8bX[(43䊗7xW /&ΊXJTM)6Y=iT47٧.[QW9P'P`j|xAS顟ƨncqPY7^ШC[b\>]\ፀ #DdwY~Bkbq\]Or='N`xuϨCBuz)9 DU:nR?5Ͼ{H?&=9UK:h;xxͳ濔R6k̥#Dk*#1ϩ& 36&7Tȼ]ތ@t͝'zM]顱M9c,ŗ+q[) 9)$Ӝ}bZVj4/Olz@r 2Y8AsTJ=$3ؽY3Owɑ(UzfQ'({D},ͭ`rXwc7Ay! D-7Ѓ3&g3&4̨^!# I %t% RQjpx`wT _]8Y\AU"fGJpw_:@TZ#oջ&3$P葵0@4k*y9`QDMf/-=_!#⠿ę(:mɤif4-; ~~U+Br]&+KfԸ&&];[Wp9nWʭ;|QwZtL͕D @O2 5m[Mnap;w .PMf(>ůA:UƏJ}S7&f ݛk͙kVfh;J*5-VU}'t3󛨵k]&`F$%?5cnReUӛDCKjŷ9'`\O$MByLAf*yËpNF2bڈ< S[NDpQ~xNkP P|3=c/yp+UcBiRK"5w5vs,ܸK.w,؂{ (tn`(_I}Y@!F/x8@9nwqu^P~ ;2x7FEo-+YO~Ӟ0p  #ф@bYINGz6FkT ӔT7kK=bKExb6)ߗ-hȠ\ v*ǶtG0G YAm$3ÙriY|urn}&4q;%o# ׁ+Ͽ V4&fmZGNh c=Y_S0!+N?XXۇ b5S>\tb&?uJ*͌7\|6NHjhf&N?.`bYBңDP7¢ؿ=8!*K i2 k8fZ r\MI:RA=%LMDNQ{a 6Z83qU*n!M-I/# ';Uj{TGuy6׿(0$8"9ODG2vE|\Ҭ](>!'SP:>\_|q;ah4LUie-Zn&|_!*" 4FWh2e. |j#we[S sSHh:` :H=D" p,'Ԍ|Ip9kЬٺktG)ԌQOԋ*: l}H>e)c>iY~mr򇤯8p!ſ%p3dWze.=Dj fe%ө$jtB̬ɀuCAp5ם?1dpuDY~Q&ʽ I>w}_+-m(HwKk19x|U`W!5hY?L}^EnyohP!QDLZƢ_vm!oBY82{jWYόW~Q5A ݒǛn%GaG/YކE2mjm:OhR9Qp)FiJ-T#G.P\ZqT'z*g)[VbUykc LO* gUb*us 0xE;PafHrBjڙWrEUwy7_nHp+>8 8Ȃ/>OQξ#{z=tEʉs$/תLg4G3&|dR$ b[?+PuL"4d8}=o@#rM-˿^V#C$q{Q7 9kUzi3ŠrUAg*-`mxJ cש.y =spZP}H M/|/* I"B5nT̉h1MWz%D\m>+'| +1&IYMjogUQ]fDfD̫4>2WZ>>m<.W(1bgA5N{jIFZ,УL:rBff A_G{Bog֏ 둟~e>߷ά X'2~ 0~K"pygdqJu]Ï[Ucޏx ц 5){+_V !&ai]\>F Y\*m{`F8-N`a93k/&&3XMR̿«kv}VycƺUE2b) 7[{_,8I oK?) TI fo͹v0 ?4H/*Ol%4uqY; [t:(-vlZFEO] p$q&bjgR3~.̝5as~eKY[pD+ARPjSizRL<@}"$h/.UūINdF8rBw͢$wqB)^v8hTٓET{Gb5`J/r8^(ŒhXL^WLDr8KUA_%:mî@d)8l6W [G3ߊQ.ۮb;wrpH`/UQr[[[%] x8,6 3'"Tv`aPJb?*68 p'+jsDwN# 8T8bV^l!`ٴ?g̒ǗSJxk͙3Y8'[Ej|ՂDœe++sspLIPK㩝2~dk1砿j3D:͎ b9(i^xAM ,\=/H\g%p0t1")zC!xտrSWB8PWIPlVbM\07~Vv=aGGt~x?öo}wL<]dc']i,Q6:MIois73R:W&,oF#~w`kMkKI6(h#mCWέe lJ.i#m=)q$?@1HvWW!Uw=;4ibgǛ+3xguL*Yۉa pχ6z@Ǯe,ɳo*jLV ѿ%Kx0xѮ1S8HQh[-PwrҼaA,,7A*,E/ iH{q{{xU$=?LyIjOR7|-;ebWYO8(Ǖ~ɮ̐+sT#>ˀ =eV/Ŋ Vo2&pc[Z'=D+[Ih'QN9A*/㹳Xz]yu1ҷ#-h> Ȟ+fbtڬd` H6۩c3A /"oڈG <.ֳ׷4y~5s80|`Scb%"Bn}[>s- ,n`7@gP ђ2C FM$(~z'Yg#c ~_+@HuĪ5Y"m-IUc 3e,,G8{"4Şa;zs;qekwF:tfMMA0`'B/_S*N*=nQxG#Fb-Ip_#Qx5T m4E|bG{[UڭWs|"B&}*nͿ&b%vyi+*؄Var Pڕ RA=Qk1qcDZ ]n ,.H-a$5Kw%9.s@} HU~W{~l4Qcƴ;&mrPgu6 G[y03v{~=؄͸56qqTdlpppW"'hEA1=kNb;Q,iH;9'|}o^lm2&~,B""7F2[$t1\ǗB#pM|3O2 >AMNQZCĩngC E!1CBϷz⼶L Ǖ=2r1€l?euN /tC%]=@_MnK)Oxh9r$eYw2a=ED1cC ܠL:": G|45-tT JɍA[R?s(982:raU#ː\B?d*DQ/_&$;RsÎڥ[;,, >]% *G-XA|'kLdq7WaSDfgd[ADqYHxf@D>%RТ\ k7eQ 8q;Zkᵮ(s^}xq`! .|LEww t˧1L+a؄NSnA- о)cxGOАS<\*[5+RYF*{Ï#N\C\$B2SDcWA.t'oqr+;?BֳQ9qXk2r yn W`+"#HMyb4#뱍HҪgBmm #t-[8 I0L\$ȼ A`:CMJKZRɆ> Hn݃jRqbu$[#5",D:J~ e!05SZ}iX nؐ.7HVH21Ϟ6 9:b-^BnߦCwf{fq萡۹ֻ3̧5WIJ5e3R KjjDsJ^7~R&z 2(');[^ُD@'W B5X=IhjRH]2I 2o'gReɛ̿OH?qEW\h9fZ1;}u,UW#5{<a 7ԓODfw.kksZ{tm GaF?QVW܌0e5td^zn+dosb$t٨rǜLV,jY)wd,CܿIjYԪyyYkl+C#;MzIuDDw(OT@A;15/<=i6T<DL4BxQF1Hޮ)`NU[Wwi>ֱD>z5Y3 *@3ݣ8 x."78r]M&cEu#xőг˂绯8q?~py@h]ܘvr=`_㴖aFƱ"4{ RF.dv\1K<r9RܰbXch+d&Á=ɑG&QbzC6u 1ݩ >EDt&3b4 F"3?z~2ՙv8MsLP+Jl>|y(6CLa0ڡU9/OK~8JY=w~氖~"kHlOWx@ÓL Gt2SP{Sb-'{SKsqe[ ʑ3åŶs#P-`;%7IxӼO#V<O;QĥNaׄ: a;$5 dMݛ^ >7ې`>["E~<[L,~ LyHGO@U}1]W%&:$} 62>Q\Fn9v)pB,m2k6yQves}yR(<#F=N z5 I^ET+-w[RG;8vjA5rĽlxjS-( ~X- 2سQC.$ }I;l8O)),|д 4`yd&pPcҘ=eJLߛC˖[9U\|N3ZZ|n*'WJ!>sP 6.o;A dRt? u5 drm@_ppDI^vaN#?) ]C;Q`ǯXw$(U[f$M{$ qQM{WJp~F3\ K5T#7Iwֺk8CCbsE<;(TrvyylB[M_ (=ڽV7TZM BhJ.h_SM2zN,B2t?^|qJZҬC:Vڨ4m3iSwƏ|`rB2:|$@cmWYc%}ƭuy:~v~5gGCxپS'3p!-҆B@4Ŀi0z|>TMk3IP. L} U,BT7ibpZڋ-Z*6TQhݩ>c`96DXhqJQ I"PuyYDlC[pC+M 3˷D2Qc;Z"uvsm5qN5֔mKһtWN==@ƶE\󱹏S0uzCԞY; a哂b\Vm2ː:_0= N.,4fcˁ-^;xtv`u-A'0[Ty+zpQЍ dCh}v_y6m,G(H٬65Ɲ!F;K=*^GDA8 ߏ~fA/' >{  >OS>:=cߢŻ5q0QU~ >e=C@И̤)J !DyX^"%%7oPCRKWk"I(WeB2YAJ|!ߣy)u(=9|+ޞhMe`Dm giOM7=~>o\30(/(۪ mOH`27pEor}*32(ɝ.5U5>+B <~HW{"SLƒ8HB2ldb<~cQd>5_PC8loJ|ސs)@9!jC>2gs9{k5}\f UsТDPyZ Ľ73?;0tas;w`/-i> B9^gd.u uXnQT'஺DT-L0&@[4I, өAMmWӛ{lΒ71SscaKUvJJu WE̳7z{QtuK7|w FcVs: _B;8:&wxgV=Ӆó-aFZKgh Y5j*6W̅>I#.y ʆB#d)L Ij<ˑnz_@,| r GT[3ZNe{"N מum%y,x C0 mp?sA4DoTey9O2;[C{?lP_ kr+%Gokzyyƶ~YEĦ4&*I%qa~^ j.2^^YԢp"*kyL?[5ؓdZ}Υ_a (6OZVvIx\V[v"NdRTIZia,0@n[Q?5\rP1QQ+TJފ]_sYDP?nCK&8rl*%HYëd!*]5O%)_t6PJ;+@E5J8!x#2˲ 1LwkjxQv]fQR\6n)䦄u>p|:l8.-.8+⴫dъcIRCH(OtTlok]1͐꒠^kWBCόe5X`Ra9ءlY41Ip_ZE~*:Tik<~#]ec@T]olJ$ɀ<نL@&UnMej)b7u*@Hꍠ~T,0U@.vԇn٨ !I܀_!gOH[R%F4!wWQvA_PКb颪$+ ث*`,NC|;vVPJq%qoBEv&2߄6"t-!JBTvk(jV!'h[ڡFˉ^9TU\K 1>)k7UuC&yR.X]NBUl* `s{,@EČwMo R,IrYV>{ƒ. q~!ˆE"Q~CǿʖF0HS4F"!&Onw2֭|FOfLdnot^(]C}//4X"vfKPdFrCW$lj[M4iS"WqڌaFN^|ة>ZqS'9&2.%'0@<;&s8Z :1nbL)p;W̒v%ӒΗb1ܳ?xW ] />>EC|Agy–RXVobCN_Mlg|R?n;<'FAZ'I+Za ѝ2)d5QP(s”_EяFwiPP+澗kvWw#7&D$= /dzĖ6DcFٲ u>yv[-<=P#JSH!QA+b*͂k'sa.Mǂt>u;[Vi;̇{P`j_KcjWO a}F3Ɠ2+/ii'fՋEi?#]!evw4MBOF*swzx) ^g\ %q"[=Ԟ6Zy\g/I&<7DG۰niZrU'<ֻxڈxPAEn7b9?Zpܕ~Q{诬uxew^ jҌ2Lo+ū*r1{5㘡eP{<\ ݝ+BfGBRaS;蜻]|XU?>ŀk  9.y; WV sJWӁ8i3H?ⶨ׸S?/r.ʉUX[}j>_ [j;jI@L3s8KI2/  01EP~ъu:GEcZmUdjKVU=>mizX\,.17^:>Un˞ɟ1KB/ >eף@JlnIn\U8+DN_JҀ[#ƥD{y(qv&?K(_v\ϔ=Y2$!tֺ?‘+b1 [RTcO,F1pLk@}\ZSF=ISׯY͈48>m K9mgGM‰qd?=^?9%0@ )ٚK(}:H.$T'CS{?ԻOZ5A*[Z3U 0iL1ah`]k$mrʣ ij $ -_h3E86ֽc "b"PEѷViHLJ 2VmeO[`+rJ=\N: 0M~ (Y\H A*IB+ykl:+x~ v+ĺkzʣ[^D?cvF YيR [C*C Vu2[]0'R!KzT;a}=Eg(Fa+cKx7vS)46VBF!OR%IH21믾t!V0o 3\B2)t10lם2L3 ոt؜V|_ A=8Ƶ445|͚y]gKWf&(BӮSM]@] ;:A+7? n<$/vᮑu*(6ϟ~U:D; .Ң Oj+)}qAQ*W.kܚOA'vNt*"ҧ_^Z";ry<@I.T͎SHͦ?JHD'~C\ 9< 0ӱoMRƋKeqޖH&?AʠK;ŴzPE{'}MG\f8({9P=D@ ? w-^yW Nc!wzGMndN0zrڤL:&U _K}߅降.|CGIsݧ.p><Ća&y`4%Pӑ?{DG,Rd!x-(fΣ,`q3\7vH,$?Chm pk""sa\^f鈱q"c:YLas30Ev`V NA{Dx6.J ·"P۶6ޝ>IV{^ٹ:jaJ,jlA2~lU/?ӛw U/0l\w!Zõ=$Ŷ]?Dhd= N޸&a}8(Y"ygN&'F!]QRy~iX87}s mM)m'2p-uͥ`Y;;/q+J{6/X-apzK8 u_ɜ qpΌ*n>@=SOXsA}%h`TZɲs3bWq/Cm b]͇S.(k1y㙝[dr!D־V-3PA\T q/mm}% ! , ou_h'QJW[79ЋN g3X].V y -97]V:Ss(4BAEP,~mjǥ*G]s P7KN&{$?•4Pq)tlD,8;Xwێ]Pή#4:`;;>,F 5قj(+֘ Wapa_FЭ=-Cs5LWuX\ku%A 9}{0v2i(c D򤚛9Ҭ`ag'^>T iZF 6̝B؇~*JWG3h+0"dQ0!'Y1$vKzj_R;<xxz0XFNlMF5u%\Ozdb Ԫ#!<$l4s7rAS6(H\ٛ uup|NC<7i72³ J{3(u(/ a7dKV_@EfCHл3藚}0j;żtu:]߷lZ嬆/@#EY$eiPFL{yhDnMc|@ihaNa_ 䑖Hz-wSbH"״&f8 /|~& `cq.YIY@mcD j߳^w!Q*:h3FɠI!ܭ([&r;BV۠"td53Rbi6 ž tkv՝7c hwupcJr\=g8GJif9| MDNY6iĶs`#N%Vߛc3eI?e߆o+w e;7?:m^sl?}RVu"n7]?|[ޖylnϮ'fm+^!qXRb"Klĉ՝c9)/i}x})xz!\gu`CaH}dXp?{e9+]Z7aPXTyuv9#l˹Se>-jq`IeC"j5D|ꎆ⸿etO  >THo'i աV2S:Yy$}oo+CJULYѭ,){x"I>U68#KD7-]sw?П }O`:5>q;*HSJ 2>0a *i95 3b BO5cǘ44I ^M TYtCÙ.Q0V!4~ I!q[&i䥉Avˏ#df'~@ɣZAq–ͯ ^ pj}OB9XЫo5r;yG1ˮR|_hk˼RFt,d9d9:ȖVmGyӥ_"Y1- ˌ$6?ڱt+L@"T0G7 MQ揬_^1{g82V 9 Jooo Me 2{W5}wqn*zU,Az]`cvbc൅p6ڙ*˿^!ueY|cʲEbvA9 dCIr%Qb C8ea)cISQvܧ( f.p}y9UVeyN"oDTl|X'"m0$jg-b@>.3 +PEW:zޓX8=1(O՜;Qr].$z3]m)[8=pZa '!כ*U)5]Ѕ|pX&o!p7RS[ j+֫>lfƅxYmA'9Q1j ֒zM3|6u?}wc:>{&Maóܻf,@o[I.S9TMl\ Cs?%{WC8l]w?qTöG{5yL>_`GB5\A -@9.ws0d|5j &\t$خ7? DXԸө(D?`j  e>LQ!#Z}Puy'e"D˙l] <(?Y`Myt`hJ#:>ݳ+ƈӹ9/քƑ]ܬ}̌rgYdzipNx&~5{ۧByƕ7p Ս[@|?aI*w{Y_=ΰ8'¶\E}/&~4 UT0h71[|/N/?CC 4/YP3ƯHN桌~euZC0deo* D{ɮMZ1ѲtJ–ꦾ> Fd#)34CZS&* oOw iBvC&4SqTJge/}E|z݅T)֒P XÈK-+ۊ+dRmp*πXa`2+ݶUf.,TwaP+[#uo)Z6Ԣ'gG*Va/c=Q͗As=χkGzیf*ʭd+7Co8rg^̫$vO}tm5B֒3+*fs,pkϜيj6-FcU+ ܝ,jpAAin$Eo3V] pzg #%Y^QEeNqCm~[F3#NL٘oP\e#uZF#och'yH<7`c̜IG1=}Y%MZu^ rݱ|%.:W6 V/)LgT\2qf$s)8L* =r!5 W@;ǟP6xJ1:bbdklX tgA5+Aګ[ޓ&F )-y6}2mz4+ Eu$n> S*ߡxoMH Y/:Zəz`5P8x9؈!ɟ17R#=D@:]&\~`a\d_v4v\Nx\=|m^Hlrʘ .QSXΚ-̗,M{F1Hޯ8}= &A8^9ƐkzwPxh;)Cυl>…%ldOA8dBly|94K;t)"Wkˇ&Hz+xipŶ#vN%sLӿ mkz^G $Dnt8÷LbSTpQU5zd?:7g6}qoBe$ Hb1@'͞Ksєl"ԢC /h~yJmE)Jc{ g{-T=L$b8U~8G&l8*EQEc`LhRJ˥ VH0!zXb]S a=MO"$jdN>Bw[k-)pj!zBJTzKHTB:uxۺEQX΄TVsjO8kj>\x.=sg䧙ZpfgS/Y͍-*/sg4U_?^:/V2adVbB*dFຐ⑇c&D֙Yqqn$az&va\}S+⊟Yw Z{~6|nx"jmA %xq\%%Ly$حTؾ` w}w`9LLڄX,xdg2mxϸ맶C(7d P1Kij&g2/k. :Y*sE`yn'&y&>Q$";9"RA|B>M똞̈́6+͋EVa$C5AT&ʷm$1?lD}N|Pщ._vŷ {jPzp4yRiҊ|Aa,6p UK9?uS`ժse"=㗛`my,'_|9`AKzYȺ{\kFRn_@|1?{{iFT 41CPPlju[eś9C▮) ^yW \Ҽ`<|KMDv[X FwɎ g@I%9/۵+p~}a4J`UD'SdRaY[Q6) L7T7&9Fu5ڵB9/22S*(RUGoxxt7,#OM} AlGP;ks#< Rpw׫wuRBLI!4:(&&O53bwGlLl'~Xqz?c!QM I})7laT ~h$;<\|$zXm h5wAiA&u=3i\> Eцx P4EQ ՕVlޭuT69JW)w!Q+ZBt%e`0 }QUU"n *<W魛*h >DƌRxU=9eGSw#.sk!D #a"\Bf9`zID 8?QR]I 80A<F1U_|<"O\v2b9hioM4z˾M ?KL6ߏBĔ&PqXpwJ,&] @u oEuXnCTI6Kl"B-}Nr;hH!8s_}( *0P~|tr`9Hx2QǴEPOޭ%m 눃~ޤ#hHb2yf*T[+$QqXُs~}#ܵڣ|1L}|aχ%CeWlNWb PKKe<ֳ%K23W}aP´:(k!_{n'o965bX{e k:ήD펙Xᯇ< b)o.:[T銗fLJT ?jv<ҭ+|VN褒o O?dem1uW((sM)Gm5—O"l0jt^MFq p8kBvUoۉ$i:~/3e|_1|N'NdO"+~n0ӧY wCi8_jDw.:V mtF'{y' K"pJ:VeGRH r8MЊf],d)kWؠGܦ"O2=XlZ?bbU QB/u*Yd@p#kk4af _uD{ b?p&g;|P_ti.{ J2:Y.~RUw ѦN Ҁ{+h[d3@erߴ4PӐjE񱩁1SoR)' I`+" a د+."rtT, bQ*aIʕjw'-);R]^`@KdSH?c2'LcY^b@I 0Л pBs TI;H'6E顤YLw  !^%M*3s%8hoAk籭D2]λÕʕdٹkKQmprJU32A}3 mOuc@nm63mjZzڐ 15zXzsl\uoo<OBT:Ϗn+ӂG?+^TnݠEWj(6!6 #WKxhF)qyxLv@AAPsB:˗2 U\l>jL[L[f?ڿsߥ +QIR>Sb+:єzDž,r|q$ wqJl~vb*Ad= %op^N `GEkAǣ*H^@wKSzD,Ϥm~z~9ԵY^?*Tdzf}ܭ/& IS3ҵc |dN WS}<)zݬ?T_:!@xUz> eNٲQEj>CaUY1٘ID&iT.gTL89;PF8nh蓲n7w kWKjL]i|?خjK;[H;eӛKLS5 b@2E%p/0W4x4:ɧ)UJ's''7 K67^P+vدo=ŊzN  ,K6}EICE'F]8Y&Z1v,2ɫדDB xM{=kD݆ @~$>K^a?b!^[Xk%Ow^^jӿP$١KWKsT1.r?z? sSp5!i!o :?!#s2u P8|_٠IXKTP-aU`C.EEW[M[HIeX\!vC1`Srq2iB_Iƒxq Y@:#ĴㅂeLiP]ϣTE>\s9.C\d'ߞK g#4i,YE1ܛ& I03Ljb07B< 0J؏w%@ef*wbP4c鮹 qi4"|D%Ej> B0GUYck3taMxxO6(:jMnFNV&߀'OGD&8+&U g ,ʧU LȾcF+t E)/uml*]}ƛ3ʑU -ߞ79'ΪΥn!0>$JSm3N2 ZS#C]bHZ@h<~KKL}Cwg}_*-N ُ?dǑ}]K甔4I媀n6b`?J G %VTn֢bʚҀ YsPxj;x&!ʗ{b{m9}$V¨ՊxF<ܺ2%fa]KEVݑq=.4,`\?(ٜޢt2$)2ޱ /*t[wW1콑4 TWM9nᯡSj-M3C5.jG]sXʠawrj]S8YrF+]y y6eIS«ksD2?P\FjThťTfx 4檘=m_5oFBEu!D[02" ,mT:Z)SD١xވ { 䄍HtʝIF2O<"d@y79^(my XelosASVǂn%]'j D:U8#4:lmǵZYJ;"T]$+qJΟZ%,"\6*.?Tًw'msW͕V:)i;ɥ׿![N fl5Z84AmhQckAA˭Z"TeҸ_ g|`Ԇ%Q5i8ig_,O3OEZ;hxLSQ"ylNh kMl ԗ9YH !A(㢇&d/4-ҳɈUdidا\9.GRq4-H oU@T E?cl7 wA j<6x#2?/"ʣU,tm~so) U{ vշF~:Ghr;1K]4綮haĴgO$$\`T !7KqPQa gœΉi5 ^8 &^Kriq2ב糲~:!h]ߠ =haB䌣qmPHf K摴9?nL8ݴ<]ݳ׽a^gyE E?/L= \r7 b9;)>b{ͯf,a-C,!WSMafWLq@GtN/!E,V0̞wyJ7)q;?qʙH&2cA$<X*f""SĖ 1o _Mc'Xrog BS^IpJ @ 36g4[ݼ: 0Chyj (ziTLߴ{\GM-J6 ja_'&ɴj`1ǝф f[”m5[@񘦛J E "!j/&Oy9xY7JJI") |jb'( AD^V>"n4\ғz$"BVz83Ch4=qxVVZ18 9P\0U*~>~$` DJQnw|^fjg2oVr~gh SK"65A<b:&]&a.@1|@G_*赊WEԑ{pPKq}&f8xÐҵdȞltTp ].b]9u  J8l|!;g/i4$_3&V-M~61 ?C ǥ˜i&섅u $/&&Z,<2JbZQS*hn{'B%|9OPE9xRs߬v~62o| 2 zL  "urL: Մ < q.Vf y#ޢ$By4!1jh%tM{ț,\hs4diܺdMs]׈ʇ3{K#G2k@)mHxyb^ULOETk{[K"igIU4\_J;F(PǢ17x^ d{򢰖n'TGAS0njͭ+k?mlh@D>S%LUg#;UF)D6x3a$n Faɪ=!o@Y=֧٤,U;k|e|f: ؼx?UyӆMXn804P:mtL` \M[OyI?'G+;"PhllJ @ZצZjd"2Y>V6*@SһOK$+Z9DyAIyYz͌T[kv * =!n.ɓE`ags xXk~SZU)yä_C7ȕdk HRnj5Yo9e4 /z`G$^ t_UYYʳߤKg{.sٛ{Ծ^.y2}8܋/ 4GGE"wPYagQ/kUp@g kT >碥I!:7چ5z_>SCkg󜞥:&7 I\!U|%AAqKFNvf'k#.&4pA {Yܽ=42ӚU2D Vo&3t/MWq}ڈVZQdM'1vD&CO}'HI6~„<"XGmU-M6$O"emԏSM<S!Yn/ GQ4B5gE!ƾNF{5%LX5^!Op0/V&^u*uF_&GŜt,ax/C̠ `XP/{Q_Fj-#&|]A(| L]uB^(mʹD+V'#Ģn)I??;i\$O}l ~]8w]9A$t;YxrFኑ82 |8pc#"}U{Ke{p*[!HNV MNݼ!.M𞹼x>W UW3gvk3^WY;W^@ v,CS˰RmDV͇B:H#`1 v [lg&@0ldrn" uyg >A=+/ Jn+O38jDC||{F(S/H.ݬQw҅N#(2J֏Z&Y%ž 2I6|*CS?GfF1L0O\l$WƃsB t<&dkig~ 'Q"P)$[@MߍXL!,A,"98~, Esy]ɽ˽82ʠ]q_pֿ0w 7r#+gkJEE:lþt&S1UYmsAGm(`夤KIz)*8(]{P >ޛ1piuCX6iBGi*KQZ0mz n<9O6k"t%5MQcd 7^n9]hDeK@1 4QDO`vyGQ}}jX@Ue C/٭Ʒn^d5}b9p\2W\nBY`9FMmxvc 1=:k6;BomI3ulq)cT&v6.d1򮇾N$uu;>~ XryǺ}gIQJi=+\iF`Iǭ ny]SLsFKЗ`Jp!ª-ʘ ܦU~Tbe@DD 暺 xa7esfA:݆⎛5MC{S{b69 h p'4@P#';97hF& >$JѮ[bP2O/ cxtbҳC9eͱL8IQBXv6V{X] Rc&z#.FV۩ϩQ ~;yL36=Mj淂 ݙGUFnk5vwE' vϼBtPR2c&f v34|3gݹ;o;&o3K%#smw**:3EUK10r./)eI KG[ՠf*47],AE<꘯"u΄DpH-RQ_+iz˕]qZdZwO.>1k(u,e_ P8ZmȖ۞URC+L*d@@44TIGoSWyէ2![՜"-dEbIf HBlfo/Rk"!vcB4#s9lQ1B#'oF!2,n1fGW73Noƨem0$XyOĶ)$UNhW5PوxbbS՜&f!$e i4 ˂;^?@O<[  ߬YxdqOg:0,"ȔoL֫rL0 f= 0墮Z=;|p? !Bѩ|xCn>/D eW{|Gaۯ`d4:;@^/Yz ؤ2h~Xa$H(7Ԉ̤d=x{ ^Dǒw*{Ţ2wmM\x:5/TIRI3}ʄkT3x3Bziq(-Tm0nmRÝ^!|1RqI~ |a6N:?p2 u8"ע8nO@%~`~0;hNH?VAj s3 kĢ'6ucyf / C")e_D8_8m:*c> X~ $R@/`9\rx{seTI`E3tq # m%USrvR/'u ܘ' z.Xa`M8_,‹q୦EN֖=m.g8;H?zrf4RJIqjOmA%lہ,+ҩ+2)5bG?E]F:BS%__t+x(`I,~l h,O,h@g+ vhzC9 vPEqaRq8kUƈKF9{I~#b|l<LiM $̰!I@̄~!0JwI@6q lXL 7_k ԭz7 VgsW:tB檼p㙜6 ҆N )`š.,Nj-9uS3{^JOg|Nn";>DtLe2:|:U1]nFF}">@O!Ҿ1e8-$e<{9I!\[Ndr^U8dc}.|&|qY NAa4C{ޟ@:hvv|rϡȷBBFBHgk` Fl߭VTW̔Wl ܵڼSC*!bRRo(%̣@հ:YV.oc}y긠 b@sé=X?Gb]b㔥vO0 ]qoRǫyGn!j R1* XTSٱ# t$ɧ? <c)g-5/]]%&h$]OͿd\ W[PѦH%/{qDdΒu޽TsYFzL+*Ȅ4."Kx9:Q&~Xi8zOnd5hp&0w1L2 }A6hR{*e'Ѥ9l3l'6\+6Mx/^6 Y5CKx(bcPELAO‚ӌ.#o2es)4Z?T_a*˰k$|4I|;GsW]|Y_" H}ܬXyQi9poq} Kq VLFmw7595<FX}z{d.g`-G]$dkǤ-CeC..bۣ"ѩ6?k&NRc. yA)d^D()bO\\hFi/̀$cS%BܘK4UkfW f\@r) {.1K (͛>EO8/p,?:JflH{k |-8?'-_ yΔdâEΞ׈f)2!ZDeH%F-yĕuo(5u\[k=u VE&5MDz1okHP#{匇+i-OxmΜ.4Vcaϫ/5C,_y_sq ; #=Hl KJ٘ YB3Sd?3`W;׆˄q9\4Ѭ5OK5V.@C؈\V6hg 3WI{^et9`987=nIe,! & S,U2WGD7qRlO2a2a2a2an`B[Ar+Hnɭ V%$V|$q焏NV]wS0ަLϒ/`?;m_ow+d[4koP_?驄^V`8c_I`s-ko+Dq6(E=/V4gb"K<_ S -g~_`F),e4%)U^VRӋ/CɭpVoPŃy+Hnɭ $/Hw޿N8%!,!I`oy@L8J׈Ѽ\py* WF-@p&SO*{SzBIPuR}рV vVy4Whc@ $,x)5P P_8B%#YR淿4')O:˔Bs`~j^Qjfެ*Ҹ.ʜxMɜ2=RrhSKP|{Ϩ8_Up #)Hu`-2*CxfpeZNRD;.Uw`Frdm>y7Df+֙uH0ǕQ2o"TG@̂ 2tuȷhG,a|8C1`!ܬtQ gIK0~O^0xU.=+$>cq63si5YNO&ڢ|Fs;8ݴB؞ wݰ%T&ֻ^$/޽{u` #{G(Kæ9.R F<[kFxɖEQL\1 x{pW?xeד5.?h%(]C9LС- YLoٲI!]-'ɉH}\Xi6o| *moJ1,0[\?&y[N2}!Uѫ6"lb~ yrH)5OIEpieȒq,1|Nt0֕៦]JMLK"a˹ T\y{q`k)a?,w%:jۄsR2i HnSa-++49x]`$yL=r"nV揨Z I]IK}bK ρẹI)OV83P)\0@[XF(la\?f GOHĔypP2=!W5C2`6;%dd^‰M`5~)MѥkCα i\o38y!O>^/^$ɒP<\~P ~9+ =Ɨ}cw-Q]EPJ KB9ۇ&;vа#/kdDM]h`TkɳdCJPU"1<9gH]SGRQuB`PBMZϙu]aR.ֲ .2@@;OJ$MS]J"\#+構-"EVv b0c|L§] @솳¢覽YE[=fn08l({¥|8ɽ(o^xHnxͫ["2,(F^d'O2fw(5hD-=,WV|:7^cgt@SɆ;e+ @Orҭ$S&9ABEZjOs$f4lYӂ# =c!;ӸK!"#`,uuK 99m0&1M;UޜlӸF./9KР($謚"mfsJp \ Ecd}Tvgzf ːw#i;p!Z*:m)$MHe47ܠ=L[>=B~{ Ifx&ǗpGn0ʞGriAr2*(q W!WLj@xOU&.4&k^MFgO H9f1΃ts[[ !L˴T;.NDžI'|ݗ&6ؓC7Yn(cBDw 2z@Sߟ=x@vy%Tx'.3G`׳-PNɼɘ0Jb'Ii%hv_xe4Ҿz[HEC4Ѝ p+I 3Ia~c Яx;tIAmeyLQq/C ap|V%3 OD G/P%]Xy1kJ?AX$3f#ym;>М>?k bQKY5όwڟQ)vF8>7g14ttѷH#>7m'Xb,4ɪ̮jO-ݚ{y%kX^KD!k՜Lǜ!NwG I;RAȳI2PC.-E{;O% #oȴ8ձ&O$i(LzBCS@AJkNK9g'4v7v~8hbSl>zM~ 5&M?[q"*aMDfBNtEEO8>Aq✔S)_4C07'[mvch"͍UCOGgWgor/.6fн |H(+ pI#=-sffhSE?̣O;RE*G^8}{j?nXxh4TFp*$PEZ[S)30dZ!<9QZ%DI& sz4PlB}!au@Y~,_XDEbeJߠSBNY|3[1z=‚dۡycs"v5GYh@.) ds.*†TA`e!rm"B2!F!Di ~ ؈TurG:.TNj&#Q$lu0ƌǍd vz!xKZ>d5?co!IbU&,P%p4ˀ FR!2~մN?~K?<9"4Q [2}AC-AOv9m 3L9Ih۪L D\wg3t0c>ؙ) ' :#n'pxN.)t|:=9i(`8uT:zh#(\ N@zz1sR ΎNG}60ld QZπ}E= 'D]_04UY] L@پk$R- La!sLe^ϠdqY(,^ ~_ EM\A6;؄cuM\m7m9,Om.1A!ōu蕔pCd߈‡iUDFyIq[\'l6%aҙk $zl :[>_i|A׃@`ks)YAښ:ZLkm2m0?fEUd﬘^h]db> 2"҄R,<װBC)8PDf!#˥ʶ(s}U*K4H)%iD2AKcIlxs > 8WhEY" IT 4\\C.JF_05N AGqkU3Ȼ!Zd$ /5榐6pCLUI/7̂W Py~S bl k/(|y=) zHi.Ĕ?Д+)s(2((sT}a+b` 6Fo}3MJϾ p|$6v.;=g,Dۧ}vq@+(L*3)JY,)+J&3s`p_ӗ}ZUCJBx;IFf vNARaTؚ52l πpr*9T9b0!w咗T;gNC`'⥕Pk"L s=&B;f)JWU3e.Qk.GX~1XK+O ϣDRDp:?Z/b7FcAU!| #kZjoi1'V\\B[pm$kPcjx:NK4A@] Ox, t 3 pi`P.(໎gb1ȅtʾəH,*-u;3C$q-x%-tHK_Aʻwgǻ/2ڴEp_3gCh!eotXpҙ|ꏥr_ K~J*qƴˠ'[\p_+&KC&鉁hf1.4Dd_ρK!BU1;rG 2"WZD++Jg@`?s6Dai^5ɵkT%Kkx!z!49Rk{D#s"rN'eR,SFw)of2ɔɜpk.]q*--fboeOÚ6Uy{gw H*b6iIN)2 $z2HniU,r~6,T ZM(P))1k?)}(qIKm"72a)@=ןE~J[4&WakLpntȠ2)qQIa{kq+-zO[{e]3u=F^}VEȗ3 1ZܝjsK!Gфܰn7aOn{{r?q߉5\Kߣ#p{dM#'*6qpz\ؖ n ѧe`A M~nJvj +7$FD'>LCf! u' X^u+YAN4 pğ"y-zOx+dD\[]`~[G3U<hp8"1 |_z+>hv.7E6n} q +ɉ%e$uE1i)#|*>;}݉85BujJN|3]ʬVUhAHwh6"`,W9# Ej~7C󓏴4?K s5aq{m5S/fsÉZ`3DGH2WE>mJRdcnU/Xx+'^1[j7S D-WmZGtV<=i-57%K\ j>Hy^/F:36s#qs(4XJdA:kp5\ɹOi8/(=_9Ye"֎1V-nb@C],njjY~Z"o2VcbR#kT}rdxzZBmc"RWW1wPẉͅ*͂5Z @ebt'Ed,.5Yg$+kt- r;Bj[A'd:rG9lA٪Dҕ`LI{C>VhW+yjS2B0&Q mD mi)NͼJ.9O_˽v86y?p(wf VD9s31FQ~(?oTqGz~.w#sf@5JM}3PquNEҊ*EA+X>_ԁ#A\Q;U[l\Z!~uGdTyO๗COP.(N+Ffɱ54o]]Y59GeWwC45F4G <~e7%DrAfeX|Fn@Xn ݴzq훕>ayW@oԮEVaЊ0{ 2Bs ݟ8ƳF[x.b7K 8ҥ%SdQuw Mj?)2ރi*B#,ܤX%{xq" 4!譝{&ں d+|&I&t C Bc3nh*)'Nx7I5ƇX z=\jou?ҨbFu ӂAc, <BKQ=V1h%L.=*`_/ ڻ֦4ݿBڙ1;<Cj L2ENK f~#u{r*^kzf!z`=>!B2K#/S6$ND=gÿ:;Z(c9gTߜE-Ho р`q!2mNm/{K{nibZ`jHob[To%䲽krj,O4&Rp8\Ka`ϻko`v) 6B9Z3 ,)\#޽_SL$q!_@! 9J>cՠtZdX<0lLbXTC_4 ;X;ņ++Z g MUǙ 7Mc ]0=Eg/L8X\EMH@Lȡ.uœF )%4q㫐,݆,6-l88]j4x S0cUk&InwZFF\bj)$Ç 3 1a*Լp3B&L;<8;=|jJ}y|)Q~aKXew}p`淒!9.ΎiûW Ǡ [ɏntTr2.NхVzZfAք spQaO9⧪o F(-×SGR>7z H"&OKmr^}'loGձpˁ6a 9Ȯ rcagbI1 xG.ye=g7%CH(%cS=;8ޕݹk:)kŷ_?GԳ oj #^B4%JqMlYx"ڦОQQT"W "/&\&Z9Ad6'YC!ǖMNCnOȝPbE裆?ޑH>47B \Y'Ghy7f~Kzѕ0LD[> 4{Zj3_5&'U>301S&tf#7H¿)Dp.Zu`l324Pd3na޻ ݾ|weoP`GoQKV^`aW_")D0M}>KiaUj 5S\c?wp ʭ^V-uM p=4j<ŸFZpܐcW_ Hs~A=MWU͌=F̡6}*p]z]x(x*!zP&`G7=V( R^WCK'U0AՌm|s$ Cu:9P=p)%Lhsi+j2[r4qM.2omTdw+LC]]z#L9p:On2PK˛r-)syt.$)pfWUxLAUH_*ǹ+艙$H3{`6 #յ3(IiNjy 擎 F4ͮB\J7\s y>y.&S5Wd؞&9rlj) -J9&WNJYe.z+T&E yCAim(#z`TF:y1\4t$#-lVҕ@r6Ș?ݟ582G\D<`|'`N! ~̱3x+1z(a<*OMq% $v!mk;U}!εEiHƤ圃;Ѥ^EU`\R:AH[W!0 qNSS-Q g1uHB`)dc/G  YPڽ;XKKiK%A!.Za(ŕ@`h_@UP+ =ʖ2U%8jy>-UH_mJ[4 +Ü #W!ޣ76Mu_ zm"UjÒN5(R) 7Jքg'$ӍX3tAW..>~hw&  #ZI#4xb:=n{5EIzӒdR)\@NT/lXG|"6H"]XTup{! w[$o)ð/hYG@3.‚뇢X#jQ(pB˻H/0Ͷ,.G H*ZݻN(k-^@[yk2{^%caR^d_nL-ei;NDazVQt&&Ƈj%$J$bUU%;KO%XOoINg86q/~1,T`BԛI}\vAPXs%RV`-R0]qcL9r}\T,;hנ֛ԇC~}]M_ܯ>\JţDjNM#pQ V4IqeYV\g)o,vԍ5*;r_AN{d ne )ȥ/Ih)v?y%AB%Kxh\ڔy4݋ X?a0Ѹ#K f~s/I_hjH}plXGR(6I?XL|4Ai/(IKD]NcU?Ǹ:9|OO}y-@Ȉ쁮3L49oTIh(ĠFA9/Jߦ B͋"X8KB>H:Q-0͖v(`k;bbn Z6z48eE13(RKp,Wv(G87qSUn PpA`%;1t=%F֥eo(YP!~͒rK uR,EcL`ЇXBw&Qm=ir<-Uj+B&1'S;jJGEMj!*'BH㖠uP9㓷{Ӄ㣓4,$2h~芸lziE; K!\&8DeB0q?>{p7M hJ8ЊњX/Zf-a^%CKP{~".uduioO= k,Xm-4Qd`%^ D% W`oW~<볔[El Z=F"pW>ܴ7z]18:O?xq 8 B @ٯML$N ej^`pN"|TLֱR3^ϐRq|'ef,M@rtYLc|r4RR2lN"4EJ!Ll`*ߗE7?e)IzcRZCyB+&ڮIk޾JA(;=l(Vذ5_Y nEephۓ# cQ3T`A\)ʕ!>Օԫ!h1X/K'OqTX:8,J&koj`LN(GU҃73vIeЬRBKϲ7ˑF~KDݍBc4c^9VbpII;v]S)DzxW&SLNRIYNb=.: _[}~!^R^E6u܈-p͗ϵBKf|ǧfj`{A>Ժj%eeR#ZDuVa|P}Trډ_u#̨PQ>K1]]@S=ѕw+z*o^Tw gaI-Q%`ӣ-D|1#;Ic\0j%ɹ@y45 PmIU%-/ms:{rgM0"UՄeHcHgLP%3%%]ǎ#%xOlVҍ/_H7~S P/܇_./F 7bXqAz y[׻95ѮzI~m ,ٳ6d/aK~%dj~ L敢#xeů]N``ߗ g HZֈ ^[8BEn $>A)Dz8OQZt7dLF+Q5%םixN 7Im%7,A\lEDRQ<(ztv:{rysOgc6':cu/eϞnsJm[ԕOYI2 |~ -ѣ$ףC mȵiy2Wr)n^ ST{@a"k,H,TmTn%4 HH.ȝE$Z*xcʋ+$gw;Ie43L2ӣOdEs1G=o؆6EZ)tuwQ+/{`oM lKV߈@.8"ILme2yЈ_rizM%3vuDOR,fiϓs&i^q Hstc[%B='4{&EZۢc} , aL; Ơ˓V)򕪝 !E6/e_F&HOEEm4H AJlL_U HT$Βһ,ќMW5lAs鬻*($Sz=ٸD|q-bre =Ƈ' ;Jr)D E5 W9$MbIU>.JVtI$a̮0yPk=\~ڻ(%n sV 'W YP5{Inٲ)ENО D܊b\:] F /-db/OT[w|{pt{Oϝƛl.N1}; ޲2aQ`ŭTKU/b_t 0oܳM~n n⻰q_-pOֳa  F^(d i(^*y̯tBw2pǫbJ7e4ZGAT# aw涊V;'g[g_?~5|{|7᥇Lk7ѷ8n=! 缚_o{dFr3|fl+60WMюǩD Agsy l_ f&sȰϡ#X T˛Y#D,"#]M,r&o6:hY(θbvMZٿyzwsm&([NnʇYĪQyȽ?>jAc)z/%vBϠ Kvs9ҀJKd7m5?-)b2MPH3y2/J 3{QăqyLI/Ӆ`u}8lkBIT$s FÆRb.#t"1c:5u[PM/j&A_']]+Ӄ+ic*5#HGy:;&{7꺜I._Ͱ/{;O=d$ѡ@pL5L+VI\7h+ raE"'W²Lwalg#*N*gV *2 ΡኖQ#j)u2֓qpaRݧA "A3VEfX,gUmEZIYrhKhCIy_Iɹ?*hT! 1Yúx oV v9Ʀ!LJgNi 1,}Kl Gu;YU#۰tFBtJ+J78EĊAGTvիlOoN^߼E'/.J߿=xuzpĦkwbu-,,f_Y( [ $kblÖ hIEP Y:KsO4_,eNc=|2yʗ0b^/66MOw&(MA񎾄PV7iA* lBAf&%ݗ/AuMg3ᵣTelҎ!\ 3;oԍ"m#iu0^HEZ(?(Q1oĉMMrxYgNo5C{`3FOyGDj~菾2_l bbm8poÅO%49J⪪ӯ@sCIB^@Zس YY>O(b1QEY7ى! Ԁ@o5i!y9q1'{GON,U;tͷ ?Vg}ͤs qG`Co<vU`];7nsQޏ^>ykkG=Sψy ߺEç<:֛I IJ۝xިwFY;;o/>};%3ěoyļC,C';0q:_,4εY?qB6711qlFZO؁@-N|,vI6=],Dd66:l^;zsn_QgL#毶fܩ}g:z?\:W5N(m6;עƞ̉Sgw>8{ݳ '_5\=q)MougI;0=޹;7#;Ao8^s zKuq_l%x`UxZqxu|z*8';7@VYS1kv훚Lcj[S@47cq:<x#`;wv>OQll;sGQVk{b;Ux |糝%q^KWfWW[ćU:(e|ȩYQ3Ɩ10oȋQv[]sG 7CVo~(>1_ e^H5Gb,aabbKuuX3| kB;m`h^Dh`+S j5ɲqMb0.$|+AS y@gҊjx.wa=Ĕ@hA#&]8=ypRh⻏ICcO͞\ˡaK![>úskpɼMD$`5AkB/636,*nO8 K@`y̞/PtqBj 鏑 ߻?Wq`\ŕ?L5VxI%%\P<16hi7 _\Ϛd[L@DT@ad\ŷlz`$VMD k Dha=Wݲ\C"_V$ 'pjo1XZ6ZX$l/ſg_2|/N@zYkik{!:0JRF-$jCGw™0HXePcn|D#{!xį]~#2+n1~ ́KZJ!9 v^cxh?NL;vؑ~)N!~ceJj"'Th[=y#wx *&OZd'xm᳌ ,V]=ՀvdZ3Βz5n 0Xzq#{*(ÕvcJ!g66>] 7m÷=ؙoVxG↼G?gN f }CX'YsN lFT11Ӈi3i$A gKug:D>V 2k'&o:{(`bŲ:,^=xpeBTIgV^l>|uqs XxTO FR?VA5H5!Cf2j8VRWe%cp|=wzBbrLul\:O%E&Kf[f83Ou !zxp d(Wpx%0zLƣ" (FֳC2\R#GJLԛZsk e{M{"Ph H;W[.˜% 3䚣J&Rt>BMi3ݬwڴu}P7HدPCN"(euد~ 2j(-͒t:NWA}IXǚ$gIL|by†nկVn,'o%5ԋagE-O:b2/Dr%^tm ~TuKN\A3D ,ϥ 4@,(Pvlޙ5f=\%Z0\LxKK]Ps\/}g'AvrJYm,M8Ǥ~WQ:&q"ٰ0 P\k*QbY-0gI31daӿLjwOfBkh ^Y}%ifziV=_ˤO˯8[@Bz@u[|bP􁨺kfLӂ8C-F48vQ \98@]Pgx'XH-e'K5+#vRzLčFԐn{12 V' [eCQݻ 6!oZ]oVa&(SHrӎN> W8na!ZfDSRJ0CV蕣ȝѫ4ƚ.SD;Ώ1Q _n25i~y ͒J nZcM0_pnČV*Xc-2{m-XF&7[ag)~ G^k t]BEØPiJ$Z_+PSaHὝ "/= *m&wd]L(j)T;}psCy0SRqSe2mp"^F$U;]tMj~L<uFҚO SM#Piu1Ƚ1R.x3. q*I^Tx)TYiF`*qTXt.R`]˦>Ʉۢxp%wlE0ivtl;'ݭ)~nM*<$[!6:;:mg97jxE~Uk 9(}Pf ֑ Vn{.:F\p#ccJ4X5 q!r!c=ΝBDmve7k\GiI$7cƱUnn$k> G]*ETK˺hM ڏ,Uޭ@)kXpsSp TܥT@=uY&npf>N)TF'e\;QJ>! zlثBT;1Ζ7ʘX CƳ̊YQs'8)L8fCnvDb.I B?_z-iGB1/+m'+, e5kBq5#1?㖑 >E)zV!yA8bL`.Wǹ;a@qEL}ڊ7#FDwc z||Wmσ1dHV]cYBPQ<2t-HWtʆX|cfo^Կ.<6N&#;"=B1'!," lj @Y|P<8kF0U@=ࡏIzOq'bZVˁ/$I.} 3GJ'i7㆒Y]oɽ}A(bhu@>bg>Dd6i'M,XeiNHLjH& q lDռt!i I؉3`xfmA橎Bb8Ca-R<1vx^gIm U3534F/-HP(:BldtI{dKC8q{G*sNܖ1H3^#+A JQ<;子(*YlHLh+ :r2iԉcAq·З1Q4 rBKX='$TNP*ڪ l'P{qh93Ux Q^Tt5n| +7ݨ!x(ЃA`Co^$Ǘx㖁 h8dEBp_2cu n&0 L.ơ1DV,B2jQ1rDΉpj6e NMnewq7l+"F~( 8"|6BwG;_COpz@*25b!ngvr5w`p6T|OW.H,Kt6^JSM ӂy*tI'` dJ;ZdBS];yxHM(rRK_* 9Gu%apSٓ jE@2-oVf/<+`(qf١:iޖЀ"O2]ަ/oX'Ƃɗe!c斒p_:PxJXܻTfDJTfbK iRJ ѾX)YXFV({LsBzFW ~>5GP1'Fr]5 \ aۅvSl+MEXkFjT֔2`m|c`wC[#WAOgy4F?[N>Ag䣩_q [7jɓg.?OSS}4U~Q=?5ެw~N&=̃%Aـ|sS1cSɅ Cn#'^qWGX{{͓)KFdLr*Um9'чWUQ9$r4=`w<]PpX/}IgY5@e2&_8Eڙ)_Bzhs[qx^eKYz^B$^2FF3 1(1CY]o5KR)yIiUbăƍFek.G/ocS/ 5Vn{&\t繑Ӗ`Vmnj4s줠 >{._tv}b 酧ƻe,l4i'}ypU*֘YageIP`U ENoXN,VQpي]vilbo;6 fi[kw;gS w.$} >|;-Gwvڛ[}2ie* jo\աz7/4;*@Ño!{4mdvB~С#P1Nc6 C+7{~%;y%3Szn]CEkEEv-#D3k65zp[K>3cY׸JX|iV܄HRhcI|"̅rd5NٜXq8YB 5BH+C*j}bd6ƭ` #3[CPXcKfu-I6PZոo/LVN#۶,*vt>jT#YFe]'z( ExD{CiJ ڍ/ȯQlrFKJ҆{9Cw³_2"2{9* v[iP}@uyZ : wF[e qN Ֆn&&%;U96ou̞ '[mY;q9g)ӰSh+4p"eףߜ|'L +-F8O ߞzj_()l|Ch;NOnPVEٛ @FԈ}1uLt4cdj2Y vGz*H7Ûr_PJ0ۢS ''O;5s9iv۵4(. e91: BX+mЭ%YwIy>˄]HѦE K6Y'͒ϻa~MZϚqF⫮:0U,ɡ _a%/F9dlO9bXkRZ< b[S6! 3r *:a^yzFE2Qtʨ39ta`F/is{(d֯n u%\"qJW"CxA]lop3'>m*#~T.t,-ɱ+uӶgX#uvIN7K-U W^FNe~bB[qkJ2e/`Rd$sjg-}8q)#%Ḧ" 鵁`)g+-n7 :*- @F!ouf=NCkf*3_bh:}M*3 K ZisDdrCYbY^~QvTދYՂ3"M*x[ m)ߗmN.}Xݟ, .fXߖ6z9PwtkS*>SCc_**ٜF@Ot7svmNf;™6j|G@Ĵ1ӷd"<6p[9zT#Wjs1ccsUw.O3,g r2:*B`RxzLsKe9 Dĵ{+)U >w|Ь$ EGUcv&64@ZԤ)^hj,Y`)E`pgqui˱m,C= AŇ2$@b6 (Q:cF*hDKGŭz•XhtlЦTYC SdFP c7NBgp>V{kLK$8;lnI8`E~od[weF"ZzYi9Ɵ`*0cVyeԭ`>yOṐ̰bKwݺ((ZWѐBj1gn5 &-uhNQTŸK]c`4B@F @mPoNut}V8+-E*Js #&Bwm(OMףiwK[0s"ddmrx3} ?}xPUR 둪kZnSo&T4ݭHn N00YW$-F1jM4S;}ASZodcP;bOMYe[herOUmJR QHC5bدuEV,pZ)a܃804]Ef=AlNx7&6޶eg#Xmaށfȶ(%iqYҙSy9z pGlNAE5̓D8O({^?+R'c c90|~a; k17VG(*?7e&Y%wtѝ7o>ªcE}J6vg2a6ի:|} ւЗN*^C/uuD6P5? o\}2mw2iGB;QHeiLxtŒq#Fչv]w/-^40ΐC8z)ၮ΃W0l|Q|[8E1Ǭ~fJZ5ì\u6%sRӸ.ƕΓ-}09T9j"^njN5!k9,.LR凁F b),e} f#CvyS E\HUXlY]gT)ChliYRUkk\=$E#S (_hdQa8Z}]u!Ms^1j~`JSCJ®~_j:Q6.=xVjl8"PG k8ecT'ge[{wN9p UF\`ˌryzY >q[ Rl.N k%maFAgZڥCݗaF8'(gK1/=ޣ7>!w)h^_yQRXm,jf@9- qj; Fs@5{*3}/C(, #E{ssRI+uxTM|8/N6`k7+|iN,HJJjf bPߪk>9NO9-v'WX#^ݔ 0\ *@xszel TXx_UUE2ZFZd )_Cīi]Jj叕] xRxPZg} %-?B6#,KǫY2 R&F[X;A봘tRֻl4 ؗߡ h0?TfLZ o9=V~5˼^ZSBQCJ z 8Plv()~6A@>0 q?{/cZsblf' R3L45ٳ|ۿarhB`Wujze!fK xfT;7T+G|A#lo<A0mo30lrk?hKiEo; Xs=x4z~ 0n+ YAQoJGA2y6Fcҍ=C1x)Vo鮲_7cEE ;-YA7kPo*bnfx 0hVz䦮[`8d>@Fswpw ƶ1GCR`Zdߣ8lPUTX@Cm|κ<kERs P~.65<] Ey܋"tsJ6zו2ƥwOF?'`ڡ栻1~*2H/j%~€ʾiK]WeOFCw[23 z DerSBDIJ$ng>md(`#Dtom1IcPi6qaW4óN Sa^4T lA92v5MNX\9zr֌dJuDP{/˫E=y YJoP;]6lÅ3\b&*J|7.X>NkKO_^0bCբ*<΃S=*J I%c5](s6s ^K;hTk(i\N{"42,԰(CAg?>Xf%L_L$n,W=_{X4ڰ9S^L_nQ$(x!eM'zښA`lVxsz6n4lfbEkKi<x8⻍ېZD0PFʢ([u-41!#]BxOe$X.B.TBgb)R TWtdJsXQ)XZJ<}.)NYP UoUSĩDsF:! .8])yT=168 jxCV<r).9Yx,[wV{, pK0v#oEɍvbLsI1; pi'kBC:(ǚ*OUOQղʌNg,J ?R 4VXp.6H|A=uPRbQBF}މN2l%Мu[эi3'#lQ҄ϙwDtHZRj65R%G|[HS*ٍxTs6=Wo%Q;Zi/Dd2lmt9`thLV<@|?zm;O1xאBnO+g)[K-`t b?w;R}1r̡m g*!oSmt"K"ay"$i{O$*uذrP: k%nRcȖlN lgovxp~ YDٝsБ * #[F@M`zDYOܾ7፿%;h T.泥F+OZwT#s)oS2fAEcK S݊o om>,|Hv )φ.N5Kas>c)ܱ8 f~ I@ n+!,<~i>{r-N* [QhJŀ vߩ=H|~}ecdda ll'SL4*{6`޴r $VF#6Щs_!,}QC @%[:^a(( 9iw-^e(y&VPs5k bשlUTj]G4{C3wjznjK1hRUQ>+D/e nIK*f3+n3jkuJѿͪ2KvX֬65a%߅L+6UNfvvׅK8BNb|;DH?t>}>ܦvQ+ fNAX7fô4ICޠ6xʲoeݙN;OEօ菗_'V_a:H I4m@]=2H|gqPȐ׏:D4$}t0kk6:d\`0~-=r1hsQ~J'P$I2طMlmsCjyV5N:Z/o 0++?Ѱ+,c qenӌșԯJtC&J4<=|H5* pܢm눚I\#6p8z)4ȱ>L\{5J.+J.{(\^.+J.I /$V[DӆU ?7Y+&g\tH^i'%um@+~qgmqe?MxB9t'4Qrq5n)ou]SU}!@r ]\klu9E^/qwc H ;h'o2q\CG/_!Wz+=JC++J/+3o|>Bn')ԓxvvm 05`0mi+maa>0bgV_{aQZܶ. ALDIAS/!V3&L JBYeG6bpW|RhlSANcތ<®or0}aT/ŭ:WLM@%.MjNEkwi;ʧ R U82|>Cj"4xSEDxp}ȈE}~!؀ݸ{5"#$((?l;.#Y374cR7Õs(oc\?jXs*D6 %Uaztݏ*[l{P=BOz7O 9A.JZ!AvD8[J1وnM;fp~ݳ$q* AGPk\y<-T%6u+x ':2q+j!-(V d7P$S٨CDa4'l=&/RckwЦDlpa~3 l?,ANp=4Q(oJ-4Zefl@9kRwv56^ĄnGrh 6~d^ovؾfgU˯æk =8.zURx\Wv 4CVs.9*nN`5"(vl&锈Wı1LG_Aa3o>o5ݫ|bY4gxַ) 0]vh3P_N]ڱjH6C- Cjd[4gv9H!mjѤf43sUrD^Ћ죿ɾ R"plj-mi6C#R; Ž5Z=Zכ 0Zi:& Aak~*Z&pxʱ#ĠCN3ھxN׌~V4MwDOt?C[9MznFO䨸M zj”ln3WǵοNtͷk3yp_I(j@[bRm n[oE+"~ˈ|'~. ih,+-'͸b2!$D7li.r0<~Ḵ&Fz žf,)oȖt]5Y h~!mvybjnȟkg5zNj4ó gZH&Q=ο{j']}RmX7B>홿R&{TYnY)~$ >g'>{[v F^$,Qwɜͩ w=z6*e@',BZϨGk6Hbhۤ҂yxZ*2-H=.L u}i(.ؾ-)Bמ9:ݕx'a ![Ts!9sIJwEaIndX:fNlCP [JaCLj8t5C[)=2fG~} syANۦMtŏ8*% YـEpSt\XtTD5{6*wZ ^r6J;~A-#0Dڡfȿ!|f6z߼k<f ǚomRZuZo _xlG+%R-t}1I&rz F`8>cw*ncor3<@QnPĹ\8,)AsT{+nER(uﲕ3 &:BA쓋NFwuuhIwD5+S#nxJNl)s(݃b)c$o/MKw -T$j&DΏɆ y桥f4G%1$Gd;PPVp٩':wC^SwV8ԮƢݘC'3*/݈WK*GkF4xB1aTsLӄZ^K_̮L64`n`WdWZso&J T-6bZ}lջ$[m w}eu[?Q5(c=CZ~t8#S]5'W|!%h̫{dZirj K@ 1{vl@Ef{> Ҿxx4+K8M0C%<ñMpە)-t_̨B$aRucSY/GHnEChȪz P4Po̭nI;甥+`G4,XȹL~ igzq8g: L>4 Y7Sgl3Mj.PMoؤf7'"Z),[cbƓV-[姷yTy"mG ~LH2vʈG?7_=9|ç?{uTղt_ ;YwɈg7yr>->np]pϪF3t+r0*_I ww/ZM']erұQydtl~]eK9]+JO2tR:fy-.W\aiDrR5kldB=5|+y#68_{i;J FRq54Db^IӸ:?Ւolu4g2PhjѩG~C?Ƒ׏yG^x}ȡ׏.>4f%!H#X$Q܉I,~_z+"<,J> h#XK}AJHn+6H `y7Dn-L$ܺrP(?D@C ^t Ay ,X 1e%̐"a%|sۻM{xrOi>I)ޑ/=gي=W 6;SNOT6}lpX+I=șs;927w'k׾53AL;Qt/ss[;l_ph\ծצBKp /`!CIB~@MbRrΙBrPބPhX$DaXoԛ5fyf^1ms&a BkU|dT)сTg,/ǰ;0U6:}Z5ƐM{&Pi~yGfݖYs~7|DV9[&nЮh oO{~MFqƩو ԑ'lSȥ(.4U,XBIl\GQ5 3\ɘYUs c4SL EnYBimrac>҄up]< 4U64ıʙ$YkVY1CWI#Toz;- +aWJy%UY w ms yG,9U̩[cC,1# .I籑CP"ҟAWʽDP 2Y$nv2չ:qU KSn^Ⱦ,#;VL RJv 2C9{Al /w &C/UL70L80ѡ;ڡD0Z(ż_+SW~RiߪD]yxWău#[fb]Zf c|霽xtt?8'O?}29;=q󡏀ߘWɨO~u |nB6Z@Vqd 񷼽PA߰1TGE02f @u3 ì"e?gI0A+i"$5$ hg i ωX Qum?sR{{-CӽZo}[KZ|U֒53?.Tq\ ߝͧ φtfU;,IN ftѝV6yP.%W3Ykp t4du\w5mij~l#~LUE/.j ,q _G^<5,I-m0HtAޒ\x$עC^ ͡3'ώ]8#=SXj j;َ nvQiZ%٥N:ooo]>~9;uY( 0707'_@ٌ5 Cm]HY}; YZ