sssd-ipa-1.16.2-13.el7$>P=?xd   6  ;AH   0 w PQQ Qlpu(89:v=GHI4X@YL\l]^byd>eCfFlHt`u|vwxyXtCsssd-ipa1.16.213.el7The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[!x86-01.bsys.centos.org jCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssdpK #A큤A[[[[[[[c791e754cf6b2dc670940d77db7271b29b98a316b94ec434ebcadec033a852ab942b14c10e4f53e65cc5073768b6e014954482ee5459745d1f759466a941481a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903eeb5cf3750b1a8f2d107c75ab72bb86d3cf95957b8ff780dafde23fb30f2cbb20198f3a6b5f1709d6571425d825ac835bbe4ddcc35ed12efff8597d35f98560arootrootrootrootrootrootsssdrootsssdrootrootrootrootsssdsssd-1.16.2-13.el7.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)shadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.2-13.el73.0.4-14.6.0-14.0-11.16.2-13.el71.16.2-13.el71.16.2-13.el75.2-1sssd1.10.0-8.beta24.11.3[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shuk1.16.2-13.el71.16.2-13.el7libsss_ipa.soselinux_childsssd-ipa-1.16.2COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.2//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f8b97db36f8b7907a51530bc7617c26d70a13dec, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=da55739921b76de3673798c5e3b1868a10368bbd, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)EEPR!RRRR$R RRGRRDR.R RRRRRR=R RR"R#R1R?RRR>RRRR RAR0R+RR R2RER(RRR/R R7R8R:R6R5R&R'R*R)R%R-R9RFRRRR 23o=u%Ni!O+gǘ<%AFN a(jW]^}~4 xT`Cw, cM#gF*ŔrF*m~YJ~&8.IENJdMJn$}yΰe0%/3""p<-H;jZ-'64,%`UcJ)A@H4[ 2()3 7:Tv0_) yo=2eZJџVK[ m+_x%!av4xwPY~yX cHc^2|~XnP,ƹ -) ⷢof'uOIpޝ7f#'{W{QN񪋔P! i< Y;,` y@`dB./fNDJuD, MV$:[Y^˘Y1@"čl%|Us`P$9Nwc޵cH\4:_ii,nq.n4eg#>#֮G}8~+N:芊F/za1(̝,%{ UvퟡȻrc&5&%,)皆kM XP彻ti%P7pP-7 N5h8غud#p/+I:p`spa?jKRU[O_Vzm\Bэ $ɲ7du` abM1$#ck_?#x$\Mvg vg~>f h.B2?8ŪVk&4 #kwxBnћI#l-9@BU4pj A~o;@\b ; * t_ǡH#?x bV;jXsDgҭU6 G Qf 1|FƓ;h!, Ԩ6FD/Gy{[g}R[^Z?ԍӘ$DI2)FG 0 #۶'#pN*L\xu Ӛ JH(F젝i>\AN1Mq&x󌂘Q_gU6xu?ƏQko~h[s^IJԸuG$` j!]`5>38F`?p <]"Y_^z_0.8~;EafX=fQLVn/hy֑PKgk7/d㝝a3" W5dM/(TPH^<jc@/ )q,]8Y#uOyPɵzȽ6cy6W^u};?Ƞa朜9δœ_ ,wg!lQAP@~G{$fM`dxiE\t }9g:8$-I#SUq&@L[ğ0*Ci!%-nLg' Jɻ!S*1n¢ZK$-CZ4{\ UUͦ;_ll%Y_)gBu+lVަ?n:/yx1?xDTٳY=~fݩl <bypڃ3 J”Za7´&{W"8xϏ*G}MŹ{Mz\b! ,sZ7mY=Q(( e ߃ @7(mC&$J\~OKfwg^`f?j$ZeVI`b0j25-6P-hZG"RRaE\& r?M ; M</HodnE¹QK4VO/& 4BFb{1% Q__*Xr+AHz|V$%?=^c f2KW_TZi xH.D`$^y@2F*;PdM)&||Tԥ$1FaRca-Dhm}pv_W'j_B='+L :=;nDE_>ؐKa6|rB*+qWJKp]oɣP{u NE[.0C4eAۥ&V7@6ǡ'9wfOu 1V 1 % "NgāeeEwD-tm0GIt;sP@iN$ɰ]bՒ.9$|)g$9:X2: {Ҍy[`flvf6͸WUeJ y4OBlYbiی(3(%(j"ƇoBOPܽվ/[̎(J3snCsNۚ_^tmnln&+覘̵u5y.w};YثO}:UylJ3/ptϸIhP##5k K%IaZsk} t"J̹ĭ|adjRHHU}`2*[d<ݹ8(W5x*y!QkKDDWmN*FG(\)0ևQTTQNfr$" ˷) p/P:ys[0 A]P,lQ ݟ¨gބ>E8b B$}ވONG#M=,~t0?i4xi"VWf`֮V.31XCL}RWQ1S(ttxs"+QN p7DWjG ˯ML9,i`l^`1:Ґ>sNH~&WB\~:5kvWiw[Pt@?ܪɑ-A7>[s`E7{o}R >7WoBu_dD;Zj,z}Lh9sTNX>y%- Ok5uz _r|"Mu YpiX֔z;0MrקυוJQ M4H]|IglЯaQ/ϻ\՞9?bf6#U2"LBբZRc/q4q-3Zk-Omk%>eˢ@)_1Rw}~Q'(~7^o33ᐊ5(|DKzz%m;{O%}x1O=fYV1>BF#4pvS M@h9}Hzʑzk5SXiɮX"MbxlĢb[ZM?oUM Ci vfZg爹 jZy?:vJr|샮E]DAr wBTy`ygvCy5F!R ġM-yEϳ6qG(|qr :cmg. XQi0wG5혃_>ck2vOi)p>&Et$0'κPB@FOFjO#4U6jĖPN`<}-?)OK:c>-#Tc̝*)akSp0oy8d909*!K,R09 (NC`5$IS`ag"vrV{Q=PDyp̥/€P|QxuOa ~z"@JrZP>ޮIG{:< kb 5/0 EG<"a gn/\x`A0l)t]/o:C O5" E vL5s~IS,/k&cUGkdSƹnZ@dž(?` kHn6~ AXr8-LTm9 aL=,"-(T:rܗ̸+ޛա6YzZxGXlmȌWRϸN~JK7.zNY[#=FL.oCeezXHŲ]N̯\[KuM+mTdBPcvrzJC#ύ$ %ì4oۼ} }̷k;'ɑ0hl`;3 JyvCE\`&]Xra/?0==23߰: )'u[|)$@CSHp H[[inU{wB;br G Pm#NsE`@liOW&aP?\8A'ܟ6A1( dMS1'H[`"t% 2ޫʀv ^'DX$x Ya9F?HZXi)7q-? fL) 76L?+D$Iw#BFj7 < "u.?zbV }s7%Dn O -$%s֧ vOۭ4n HC2xLH#Fjquz]!d{KYج ֨}i;`K{- [wGAƝSҟUVJrJ$6"Ft m4'L}#s%Jo6&p'e X ^)(y"vgFZ#Tfc|z54dѪSeŶDɞS3 S"pPqe \8 L/VɝJMȹ{Qך s,AG#{p{f h(\5x[ai AŠHa|'9OtRm%oE2F 1'eSx%a)TNǪ`[CFY? p 3ŽC-2h"29H_)Gx)ѕdhq=(tbU~b 2O:m/E_?Bгmneά{sY {D$29O|w3@6;l*fw4no e]2,[>߷2_:?TL 7#ڰVi2"ߏ_B9i*p*Ew* 9E9|PVdj``U1Z.si[J04^dx7gO#}'y*QKeHzi}uKy e'Slݶ>@P{-!˂oMHnlby7c۟B7w)6Lgfd[h_nI=4҂;ƪ84SEyҾ]<`ynqq)UBk^qEd\!`?UEfgɲ*C,(Al1 ܵ;Xٮ!"y.lkh!= O>7iuxpeލ_vٳ;Ic!SfV2S*$Yy{ }fd~_H߰gg~RSX:R2<9|)xR Ws aYBxo/8 zG\#b6k[KMfk4oA_2e:f=DN®ښqJa (.$Rt57DVwXHmK6(-Ϛ:mnU(]ng?J<טԪdzA c V|6[3{x]|@|ˢrN9ZjCx92^xQ }fU` 8ݣ _ϠH:6 Aj09h2uJac2dqi" a, S7(}8zN\ciEZ͑WctuSsho zFGr=_:\_ ୵ 1nQ=Ǘl 9{;xέbs-hI?MQs,ܯr+RJKl1)9S88.y\9YR& #(&s7C @BU<㋾[%-;e4+U1$֓I%)TeW|Glqjl;("մ'ܝW8'kXgD|c 蔛6߾5HKgVQUN?e"N{r1\h)샹A$۔3tFY+`A?J@zvMO KtBi T1ؖo۫@h@f P{W(Nu4 Gޤh댧 TXpP2爲o <֖xO /7V q\@QL;ϔBp/n ΐ{5G^ؚDZېXz 0jOvlӄd'=vY>݄?Xn 5O@pL+ʃ)T=hU] pmƒc;7jٶJC[vsMn}V]m.~h7b3R1׃d[K)]/){>GEp7=CXzٚe%t&-dɈd!g>|;.WL3/ːBhZ ۶ډAl䪃~|[!'rvAA.#h"9[JIm"iݭ꽉#inˡd^ 'H~c#/diY'5aP[L%ԫ)ȆMPYg7GJDR<md 4PN \ >X$n$5 1Z*jxW]?; T'):oZ%zv[Kbÿu/=,{>1"d6OϪRs[1vCuae<}IC=A3E[4I% kIJBf ]n9 4JЂh;2O1o>IM%g9zlǤӑ(hm:1.Z1+<+ REkDv&@AR*HUMLvWAꯑyeG x40X0>k2f&[UiͲNr F&Jn݅ƹꬬ({2bԡK0A5ݔy띙L,N.\z!f/љPa$?3tӣFw !`7d]V+`)Ќ!~s \&hm7pDT!.AGRu)ZP$zB} ynJ&ːq5Ϳ꛵rA#ҐEW㠦NE넮 uRSKWĄY"|-V?~J&;r ɽdW5O;7+{lk5 D.9DӷuTiޅSߑeyI]bVLu& 'T++@)=e l^ l{ `n3/-ucs]ܝ+leja&r}OO5$mSxQ!t ְS68#q ~Ԡ<cRѿa]+ Lin.|"0d.T"#)׬uZS<mES:m%ML|n)/z/+"&2d)*N MTj[Ħ{B''2㋰uIIXH_G7&Q/T'qlrnԲMnLv*7}1trfG ;/fx oN~I [Pf+,lހIp~-jʹtTi&^p&5}M$+Yi &]Ҟib IyFpϠ{c-P=[Y2ABZ̧53<),JS#;7뗮JUėW].߼:=I^1hBj` thQ^QUߏUP<=(Igм@ȫ'q̢B,b]];HtjD>{&6|i%?VjmsC2֊j;ZM~-e?ЃXa x!Eb=qaܴP&URmyb͸n'&bC\g fa&↭5?[*4?ܪbyl"%Lq_CQ8U "_G]%&cݯpOۡsnɬhUhpm<o-U0 ay0XJ)AN- A#+@n)L,tJ )uۂYelJ8t*7+ig/F@O^`of oze(V#쐑TLˡ݊py>[sfZPW TZ@3ΆpzL${/aN[kxJ_ߔ7Et:-ShGs EVBp//jxtepmtX;gKv@zm[+RAs ,dXHE25 q\24 >Z%ӻ"ltHzLkچE\;0oAV~?aDKLJ]Q`'PVtچX+͢cmfW8Jojyv [0;Z`"q|dX-.dCK\]@S:N;3gh9^ v6KA=FzݱXce4ԻKJ,ɖ_=XL0&+UzhRY(~ZIV.DCP(Tq: #Iy9) 3.ܯagƗ ZP:lTumȄؔF\ FF*#eoeFţuq3ǚMJsҨ)i \4UC%XX'Sgr]ӜPQ2ķ#rDW2cG~OW69Ex=80 >5 X3WO"$E: _LDA?zh"!T.|Uo9C7%P]i /Fް-`t(S~:RR]„k8UЬWs݉VA=1p59 @9q8V£Qޒs ͱg*LLxgYC'/ 5bg aDhzpXuUpxVp]z#ѧ̵>ʙf|).f}i) LϺ`u#d˷7:3#Y48&t Co cpO%/fl}fq;/!bF)L\.68QeX^q?~&1͆f퐄:wHpQ0e ; @y`BU-4[J&9Qg5ٲ*j:@:80:TB'V y:ТqE0Wk`qui/"LzܩD+$x/̴nO3ӄ( `$~)J NX%KiV) ft&jm7wg rj5@Ucxq,/#v%YGeHSdm9 )@g˃Kp;`bl톣@ږ^]>J9 :NkD=|9'ԞGC^}nȷm;]%qT!W<ŦTM=qLn-tY"轄3z2U||)x'tXMFFs%8\dyI*:J r.0|=O\ wPII8|#ţ%_t8ɰH~P ?GB3+3%`2L<:'8m3sW* G=Q&iJfCH^+~[M83w'OÁ7Zv<@3}O,Yv4!)deE> ű?t/푔e5(i݆#~翘}kC>ҶT;[+dq|̳ )u.&va'41̈>. 4-r%#dm %5q[--TS~ A MҺ7duxeƟ)qrqUYض/ WqO Pa(X !XJkg )l2$d%E& ADV'0OWSn;);ݸY`[&v:h^;ƘUB}j`bObZ 7)`и-+C4'y{߰d4 /{1(,Dҥ:F':qL2{n8Ͼ ,wpf՞O_@^@,giγ= i6KB3B7, ?ttIXyuO۟G%"<̨J|.}BosM̾ +qVcdM)n5Ca3JiޱQ7&s+!2|^?s5+1A}dE8 ; iFeD^ (<ӐU-L73W,˞ 4@ r=~p̏wZS9?\cWTsމ݉ADTf.OAS3EB 1{ GA6ؒ:NgKLϤէȺ+ODg48tQA^I@*=y]IOMBxBf(KA5| 6#y^5}F>;dŵuQ'0?"<F|bJЇ$.xMע=U%:GWM>hīHq ɩ˦g+Oo-(xN3,xgrTj;R1\ 7{yy>4\kG\0N%A߶r6Tg9T"]+e98ZThU\_q9 fGܚ/l.)Yx20v3Y$=HV;Τe u6aD2IllȺ6m辸oO|{>?/18ݡsJndΖuBWS#=~ l̈́yw񅺅XZC=.1Å;|^gK[Rpwl$ h)EBK,w'hqLw`KYR9."$~o:HRG޽Gɪ9&1%%47=Ş3sQEq,olW,FUm\N"ag!gɊKD)7McĖYF׼uvH׍kk6뜁|]GJr{ ଎݌[QJA1y&7)X'WhX >UJ N.CX:':ꖩ}\Ʌ#'&B&LJ fsFH!Q}M&zO4L_[0:>4垞(O>x2Mk_a`nHbn!"hq3 XCn)WNWU*us׏ȗ"u7b1 d5k%LQگz.]Gaaf=K2Z$Dhlj4qHcdK۠v~^97{,GXJZcfǑ6"A1t#]@c0L0 $ d3X9Oj׳czYIh[}U"Z||A-BFݺ[s&h;  #)u +F3;I93ddH \S})4YBgf豞&٩:d%N+l)(FH ^N5,<"ύ.J88{d++?6,&0uu<^׽{}ݻ9RYkLe8`D> 2ƶZ{i-X鶸iRbF{n%b{ wDC<'8tIYh킨1nmG!\M&g<|s4}\u=׋^a%o„˄< 4 mIewq$@ԷI|;D8c7) t6(b-G &^ _ \0ց1mIF:\\ƔB:WۤφXLRwѲ1fpQyGJ-rB1,>ה*i:ٝ~_GIsgAQFE_1٪Ľ"y;0+IGSr"JZPgAV7S=EH/EA G]BDU/ej1A@=J(ÃR&}i3yVvz5Lw $ y#G3t$G2unQZH\`.{ln('ni(tTA :E;+um?,,'R9櫯l˛Hp(7Z'SM̾\ݟ7ȷv8YPρZvpe%QftoelkDNLH~q&g* +nŤ&wGb{ ]E%9\ꌠ&l3|ECYu3f X[;;w+?곥 $t8%߫2B~K= %y2`R|3Dmou I4k3 Hqul?`a]Ge5!< r~3F.bg7nd3IWKXR*1کGĭnoXuScU\~:1Q'@ӆ:O; t oHQ&ɫXW;@62'L vo!f6g=ZSs0򤑟heݷZ3 ; 5@sz}fn&m(LL 0THA8џGgXεPl7O{#d.! $D@NH02S)6 ڸr54ߗD)v_%l |.\ U?&Є}+G3fzg"_-x2tD`B\M[ QmeKg|5X"6iY?hD47U~#iw/KL2Bf:?nSClcs}.@ :q|U6!R}.mOgj x(l4%Kof{1'餁mė= R%vKLM|}=q|=/\}F!>BۮQ+C*sī}ql+VH[u6 %WqiQ;)!:E-C]ز!I˧OUHn-rmrC 'ܻw""~fLdԿIm%zDQ_楼UXR(K>VCj5)Z

ОA_[Jt;naE6 B,|-U )v)@Dm#PҬ2: P_Qr{LT Q-Aρά2,$w{G!lEtz`054slo/ԙU56=rIHIܰx:0X+GdA55/9Nԅ@eV>w4mVz xbhYHƍDCɚIaZ.y=Xc|/$8bwN>G*4BÏg_@-CTądBR5 -FIߔ5Aν:{0i$5\ou@޻8LjWi3>(|,Cbԧr!gØJU`hcưPJ,H `dB{:jX .H=0+YWpF`O[p\ݚGj`'cedid!K2["O+#^T?s[m8Gb_<)XY$.]Wy~%9%F`xQxN;2Z%GvyvM\r/Q;KPkAy\CŪBnW-]#h%0-ZgnOMxm OϡԖ_V)u|;!xcڑiz6'q.coV,rE?"XI?⧐6\T+mi:7ͯq@\KL=!3  Foئ 4#k26oΐ x=ylP{y*2O` έyte%w]cfxVym3\hG,RtyfƝжrFxA~[yD tj11wRkR }%EϧH*ktǁQyB, ǭq ja#;%h}Ԁ/rm ޲g׳Z5WN$zŝ"'&aBJ 8]$|O i:27v8g &-.A6/1Q nBЉ3 [L/5++vX]A!SYMfn6e^j7rVG1 iV-E]1\"stWTZFTȪ""֡1tNn6r\P$[(v#ŏ [mZO<(|cݾߖMvJFϾ'|kOi ʕbފtvzYfc&Vj󼯓|uiCSQo_0,(L!a?w^Oc`.M\p- 32.1J@-01J}ۻΧ/{•i6-_<1@ߦ5>^7H,&hT;L+&p* RjZz{YOnEs= >D?YK7 NaUWb2I0~^s5 S #S#|3uBZ=pBj artm-! {+><0Jl)i ʐ:$M7@A拶c_6D͖>aZ BI`2hLC?X(9#?bmp T +Has2RCg}ꫲ$q4x:`ףbꣷx]WH` 2!vZJ%(6oND @n?(^F#" (vƧb/J+6J#6j).ˍ_n㋉qqdT 1(P:Fb2Pt"} =ݍS{0af̧^lZ1!sE|/;JiSX}s^ķf\dDp|sBM_FSr,3?QPFDa"#R faLQՀڼc SnAj΢P`RNeK~)Uv }fwJV-AG^4<_1}H /9 A/j6XUB_ǿl/ nhfWĬp;1tIc3 =/o?M[;QB(@nX.ҰBЫ]\&ozJGjrow}cY: @ɔCPI)C^U{'yW\N}D lm]^^R 9 L6IBRΐRL9 @+] gbʪujO0^ 3tn`lptvƟ-V)R :ˁ#f뿎5PPxn|<u\ 7W0뛠i͟C+U :~baX^-|rd m\8]ja@]<# GwǐV._(l3Y:ƥTg(( M%%B}:PwT7 wk.3B)FHx,abޭ&+xx)8Io|K!50|@j7QXDMl$Ng]Ǭ*A+pv3/ZCΧ;BDՀl1Flе xA!3rFRI 5DrI4~Cc|̴fYn%eaۣ6+f6?vTql/hYUk,7=0q)K$A /f\z)GH_4Kb+ɏ5!RԲ³>sRJh5)nVM"&P~!f,$MozӈmWv_^t8@`,i-+޷ad rAH n )bu&ɇ?H9 1u=RBO :">O%܎ X0ERn>V(.AIZ`7r20"j7liLuk3e%&=)m$+*Rt BvT$(id ŭaY,Dr`$ ˭2/ ],.ܑn67˽X:FLMd+jԍ4RA6,!2H/.I\WIuDG d2zh{$v~Ƶo ?p :=1b;tTݎ>M%AϾOH]n{`VZ{A7,v4Fk9uH Aw`l$Pý$߷0A:TN|L^[Jұ,2:.EL+_aD"ZAnP"z5lBs˶Ni{ChIMEDVC&H3-rqd2Qo5FX|8ߙݍXO_eIDDbme0+0GuVRp!ԋ|׌s~wGHO1=Yp9X}Y3AYQ~HiDu~UwsQ'VO#ھgi>ƪqL^TҷNXDo1aQp.9p}uN~_; yFjH1g7XZL:94xMFl]ءu!<dBz#@uBæloX+@<".7Eoްj 6yEF#Y;r t]Z">!myK#*'aǩ~KR .$UB$P;Yr[&8 dSf&jBVQŭ,*H4nPvׯwhwSzXcv `TAR˟w݀2 C&o2;ԋ^p_İC)5?^PiEdB^18lM!TvT.ͩr /vpS!-$D"OؑPcPHi14FbsU[̿w&j0ePoe<ߋFc2:늳K>< M'ೢjZs׷!١.ID.&7GE jހ&) E䲇2K+XxY*&bϛv&M_^쐃9MRLrES.,}c"Ιbv,C<4@֔_n c?{>6aw}˛af;FIƈ~B\3EUl+ٸtC++*DrNJS0:.wqNɵڪpPzsƊo18Yv8S`_?/X0]I˔z+V?&$s997hr|"'qMͮ)7;E2' mXp>=>'73KAG/WـtE+st`g'2o5QcNUz%1VNq-E<$w*L /k|2X@2NvuTqp :\*_sǥS56.bs|4o@1^I0 &j&2o\y;,>GU4u凬{~\NFZ YM0k]kPU 2/(}9| /s,Ȣq_= Cu-W1!OJG\]sQɤS|DReb_WYua;6gpS1."QeSlt\h&i.#>bqrqC d+^`t@>XyY WWhw0Qtx"k-]~˓,뉝v!e;v%SK> 6{7VM<Zz6HF 7!SPl)ǧs^E$1*5 WmꝆhDD6 f$^*9v4ǐG33z)Iϫ-aYԊ2ۖ#'-yvǬ_1a>)@I宻$7;(dRqAZ^mfD-l.0 t&pi|,6!N.!8aN "b`Bsj5t bLj\utKmv=}F1&3ɩOިܳ[frM"zҕpڼ ,淖xĞܤ:ue9o 9S?q䃤:ɨ kZc#[wmx.4cqP~EәZ+O$kyc3bPsH2!G!!rxUD0r زƧ%7TecCWHLa,xei߈i3jT׎yCànΞL>CZ e'gU7J{ \^!yiSkr>5z.)÷ۮsǺu7&B(ne S^Qg@lDtT+&"ٕA\\f7.fa VRTD? H6cD":kՆ$rAY [[ӃM^*4tGդ /de*J`9筕U[aZe6e82 7v/i&ݴM3Šzf~Nu|'oJI];v?:]6':mg,k+E.LI Lt+XL(ZE,IOOR*«,`+3bܿ6eĉC\ GKp?وjZG|XDO|9YJT6$5mYe ټfbs0Ymx,Hi珦u 5i040GQ=)x7&m`=f=Swn-&z֙;;]_NC^yertL`uȂxYTOirjjի´hr}uUǐ< uc%GQ:E"lz1Fg'~ 0.bzHseԋXّ P؜ vrbDL~{XZԆDGp(#pfI`xW+0cհ,mMor$TtzpH bAԙ>Y+휒$s6uN3/sKZ7tB*YrĦk^zFc#Y06;7!3Pa6_N-,[6oUƒZtav6!CZutPG0CӼ6a|R.[L֞o%E? @;3\M vKsb2+p4ίg4 *,} jH.+z$Rsݱo>|i_`@"tXqﮓ߳IP#dS9?nMQq!Xq UO 6NbvI<%[IG{-2ronϙ|.:bQ:>Z6ZE4z3jdLE -on:3r4ܫ6M<O.}>ks(-SIqC AߢXnyɍx->ii*P:VwBuɦ#HralxƬj]-ҳD-.^OCb+ܡGWEb'|y$4ucRLSg$P)Гp3Fyid.G?]3X2(5ɀ?hWǚ^->=:VJ#bto?Z|6>qMZڙQX)X?e#WrzYCh'  i\̏;ub9di/KJ8㱂m݄n 833=DyIU&LrH'u^)pxe ˨@U8 I:vIrH`]~X0:`E̥f:"aY;{G5NQ/EnI'ЂB`R4OaP%)0IVyH\Fz.X.2J@MsW'9!d6[Mvo@PLCqEhTa#O8 /%~X1eMHau4ü(soR#3~сL$xC+ 0a-fZLǜ'Ӿ0+8²:#_e{3 K8Qce_{xvhITƃ hW#ɈYCŤ6tzfotK`L~%1%d+20Kֹ9\@>A.P<shD/-}"!#JɕAVImP~Jg9`0/΍!D ,$̏Odp[70<.?{.WBG=tf'%4*w'T%16YKҘ{8X͉!/ ٣qYǔXG-RH{Rds!Y f$VUYK}f' L^W+1,BtL{3Dd὚$Ȫ|& xiԗqáS2hXSe.Q6O ~HB1L~OSkÝ"]E@!uʪwݏˊ:_>T8gruKN\[ n5Y.`ʝE(d, ]g(E`fHeI#R3 !aj yÖi~{PVO&4USl^a*#+ H#Ҥg{ \,ywNT$ͳ.{Iydhc)L2QA @tnKq^;.dLHzg"}@I:( |S Y`O[G MZ4'ɂūPLOgsǗ14Ȏ)LW爡^dGBubsjJFȕN~VUلe?9ȓX4iXnE`*J5RW =XwX9F~À'+":E5ŚLǫP E0r4Kq Re\m%]<Ə.4p)ί m#`򯇗[~6_k1,A KSrjh c;?AB j_}Tj Ѯ<~Yf -qr"2yڬw˼! M-d|Ylr6?Xl8j֠Wv;aj@˳Mɭu]WxOta~%#*& `Nu8SxFRUF frdi6I }w5A;:rt_d}Sn鈪hV_Aupmӊ=#8PqE5ٲW<X tHiMi)>$0D 5&R ОMyMZ9't9%_Yk4wHAgqnUpanG8 8T}ҌkqX6\5Բ%UEZUFj>6?[ADah ^sf$x#)|Wu9,i/oEt51ECm+ɩ 1$\IK1;eLE헵%$8[B-n1¯4AP=ӘXoMeF'G8Elпj²A%}V_{x"E~zSDGÿ́}' W%SLFu+N78֐4pmv_q '`wGr쒁!$¿qTӝ LK0.H_9RE/ICXO~ "3 Acn4+' h |L7MLӭZXaxDJ XfB/[lY]` ڻt`gal$٨-^/qbܠ >LR, ưXN!6#UL TtWL'_Cr]/to8ǺD6FQ"}<~Eg:R؍ .UF~`HΠS_ #KJue/ Wpr@*.G8lE5'gOծFVũG,P ."O@ܕƂt-Ũ=ʘy \z/)Ձ5`06>}PCXw^$pC<&xIߑǭ'~zi(4~i*1 ,Q}E)-! Ť֫LS/k%ACr;|ب,j/O෥ɃD‹az۲Q9"-^[}5 榭h8)^W*?\ ioIO_0{ v()umЁ')Q,ߜP`Ӈ^5DORIm3wtΑN" P5_t@ʧ}<.e OR(:!KHCV7Qvk6nh!QE(#fm׎G]A^߮F1hþ3KHw/rY~$9iֆJݙO.?51P؇" Ag\q~AS\T++4Gհo!\\H\vbLv:\b4&Lrnˢ u7:qL^14n(t-EXUư2z Z/u l/z`VMccqNh4uL)A{JExglrf,]h6,xXcg2+QcJ\(Ve:d:\Eڱyz{<l/$VRS-9 ^a h  w?ńcAKN/$VZ7d1- Ŏp5TEh"3]%:dҋEsq=b}Ӡek ջҠX 'Q~f`:Etdʧ \~51Ո^f[]Dw}BeļfF ޠIB8gfq_,¢M8GQI0D˿P]gܑK{uj?|q<ߗ*wq.*YKHlFd dldj]c^( {>~*.~;a$'+cK//c cH8Y2C*£v}lY5n@1M(6f>"M$рͻK|u'(pČPt j<U6Y {~ho4D,ж!Y~ok5-::{eX[N'AL]E&V@MorJE^GQ'o8^_C '*?C˃B>YVg":'hJ|"`5h tDnz7Nt0i_&)QT4|PļNwu۪q8 Dލh3Iy)Ί&@8qD \V0rHfxx>需N o$ef8# ,.93 gWƉ2eAe_amTR㪳v&nz.Dc\=_e_[ԧ UJmT`3~ V!{F3NBpAW^)T8{v ˖o䙦ctGf_1=Jrت<2HH ޣ3񥳻w^ߦ!FԠ0>6^/#F¿)캊3C?-w}mTvt#HB:Be T1ytn;oeRMr55<9&?C}ԕIZ?%}B~ בMjίC xţ~bF^?qRX6N:J;ݩ4%:PrAORA+=8D>rMB7gvj-]V݅2و#/B`/(-\^BͩcmEp"P.+@lGa ?TI‡ls%w@ 5.V:m&-hYR7LcqdUmB>xEa5dzW>C :C|4GaY}J{\)+i_Í0Y9J dl|~ 2q z6K%;u2?:zm >-jޯU ˞QnD }")lwf/D RA rVyt#foʺW=Mku/híƌ >}m6Ϻ}b@,+R`=5a^&8Vش;t[O^^3& ΗE*[h_X%Jr4Z'}zQhyRŕ k!7"/_R+YFmg s:|xj3p;A{iFK-+"meI-2!'NnPkك|sk`HGH|6<~UJK'{޶@D]s=Z#7yH-H֪o|jIb{׿k7^;er_ª #e`ʨXP5;@\94BSh8qgw!?D{3_;, ХAGzs6ؕ\f>7_qa\߿AC_6xL.,vkz8f9(rcl8um$f1孈4nڋ{0@Gj6Ila$pVhu|{:~6;gNԐ~~OUFl Ѧx /, @ڮb !FϯzZ ;YjՐA_z܏l>W-ْB}PörMݳh|L-+:uc~$~QE9O!G(17n9Lч[*#H{ 㘣<%w >a]JU3D6@mg;);/IƉveF R$ Dж{`qY=BVNX 7pSW. Y6կK 6?ґ@:Lw B?vT6>@&[zBl)X]s~F|f!${$cOXn B̪{lꅤn>Y Sp/"A/j,oZQٖSK?&}n]Ff_فai25sdMx_p=P"Mӛ/.54Rf{v9Nnl'mNy]]Z}}#*ҥ$Ꝕ}.B^o]=̄pLsmS\^ȼ#7<tk)8 tꀿ_22p p4xw^O 3,T]$o5Lه@u Na!.(ʻ8#9M0*|k')+w^ Qjw&YdR~Ǚ\=[)G"sR1< _|ݞW@]|HTة"3.6nԡ}qكDG=C[7BsعjrڮT*opSywD?9O(؊.G0mⴥvy #t8P:]aJ(%"_Vg[^A9B]ْk6O39tyڱ^?V;Wߕ]zpSɻV8"QmpeD01pS¿eD =d/HȝݭƝ4-EVYנx[[-S+qi^.Jr_6!ل푄`EdFy-Ѕb"!*4㿝O1aF!3`(5BNТnxd8ünvR%Aoی艩CJG6cqkC%B_k,:g;'ic"jf  8-ls?`/9BИ ʲbXZu'NxZzY^3J6In̉ʉ^fX̻[HyRI mkFp4SzecpGk]H['&,@q5kZp!H˧a;bpǃ:4V&s i ?UR] ž4}6#*lPphLL'8j6''u^!}"oK/zsV1BtA{}r+bըDN#)gFlGYv(5&AJD9ܵcoYK9>qZ,2Ȣp>͉2݉=* M9h_' ׵ׄw.k[U{ٱ$MQ=K,D|ImzFU 2 +{?5OpP٤UeY8,p {2,a_{E/P{3I810|sn>/,6p+/ x"2wՏ*CO/&x|qu7޶|nIZcf+MꮞUvUa`7Wi,N:v ߫- YPPaA-(K֧\EF?Iu&v\[B.g9yz΂K'N?U*s$o"nWqsN:x&Bz6PaSwg9NxOiʚS܁D ^|y"CylnE" B #舕v.P̒ +O>hSY}qk2푼,$ˍr1-5IA(q*g9jZξ顇s+@2 ձ,e #'qӅHccRE-SI KM5G}R $o* -``H޲(8g.s"f? UQc&Ky h=IAIwyA^o6VoA >;j)VG)qYPSu `+߁"9!"Q,kCeXur/1fNO"İ0t|m3omo=<2aiHب2&h|%և2`<]DI~xv0H+>rt =~מ)&y2$)u)SNT>Yu^ۦ^mWVݮFWƊ.}t8< ښ31oIDmƥPҜ@'qj2iB`c QjAV"@.c$^E<9J ΍Z& gE*0lUڐYIY6$QkO Q& 4:UUAޖWQ9ͻ]NEVRFt3 S%bjX#sYg7G<|UvzNrՔ4w4m] @Z^--W5 u"˯| xN1X3c`[?̆ ƇjMli |V @`1h3)ZX3;9vrSεL8]J| s AGdEuX{>*uVTڈb>z:&2;x*ׇT_p|ȉF|({t2q`M'DR*cEW&ӈFh1$?CDђau%tC/e4wxyŃ0#y wj g/be`qawpwg<{@멙tLU:.׵,(g\KC{9UEyqwA~9"꺬D:#ÝY/c%!wdϒyv%vK#&)ƌ`HsNkb%h$tRY LlahsGҶiŎoZgp]D5}(FZ1*Re*l'&?\Ӓ-FR`=FIkZfvһbv'x2<<u'\!gY$rZ@S hJLt)8FnUژIgY}gN"ݒ#*"Β?5?w[b?VCt-_uN·jKITS@79:aSD0Bovo/SَmteIWyMY<uMעeQZϪ<|=k貺M5I LAjD\E3\dQ_,5'%nK7*wެ;-^ ΋dz͇a#bgg_@P4A,6dTGGbZxvB_2sn*b8 9v0s񏥃邤,F[طd@MÖk Zj٪#WS.39WƘP;wx|a/{p*;mștr铦VʉN|/xcd] Fa6w<<3юs:K8]}aڒ⟦Ϡ DL c=./l6aH7JEHN3x:@p<_͡o,tS H}ԻS]Pmt:U99-LgOflЊn,EZyl8{ EDgۮNM'T-t6J!"Ȗ -z̪*$pmUSt@ J,P_I d= r%7n[3(˪BoWJh=/UvN]C\ueuNr\P2ĉڔk2*w'ҺrxjtbC3.7VSU4>ohԀ`$m=i&ˬÙ!G{QgBG81;>K:[=ܠ] }qT][`~Ֆw,շeRӧ E&:vLeOs|ߦȾڄn{Sjwb0|!ů;ŀsOO.Iu겿|POVbil& 9+/LҶ lxoPE@+" tMc@>z$ߋBB`02ӑ=GfN'sFX.Wt{o@U.SNhSHiC> ׼ sSYpܣzt}q:M6ƯG_=ƚP oQ+*D>J|6 N@mXX9N:Y=<&ʋhycQ$.Q;izENf6Öbc@FAEC“uWL= I/ @!F3')^P-#Y4 U)k57XB PnAx}0~lyb߻:EI*t6U)ZGh4ZqǼ, G#T?\ ;gi^a>$=/zo@+xaT1Ziz@in O $=e~+k+Dz\Ղݭ(qgM_$`K (_񔆫BU9,k8T5A{ {و{9nVk2 1Ϳ$V~u224r4TgĚUxcOw-?>xA/ rj#jʫ`1zۮLQZw ;3╀~[cšk)Ż!X-]e2DIȹc$b>XqW[VO;ܼ62uw ڣEFNblt)Ձ;phBW@``"ߡʦVPPI#3ʖj DaXGJBHax.ASKfu[lts r?Ɍo~`yP ]92/CmBFW M>(x@R>ē~Xodƥ#oPXGX r XX t]:8dlɁN<ad~RDe!fO$p+{hd z%nQƓAo"A\ΆCr"\$~dɷ*CY?w@)qlk=zf<6(_'UcN~=?u亿NVHmVGy 9:ۼ }sQaZtkQמe8]i`rם&I!c?5bΗf(oz%2LRq$̯:L>e-PS_b{3|DIO:ܹSNbpBU-ӨL-@ Rܵic8EY$4jyJ_!?} \/5Ly\VaCK L5!:螧s񴖱=sG y=[PEb3 i9$+ E&tb4ɮyBlcl):j3o2%Dy,R#WÉ"A3:N)̒iI1S6P%wz$73PA UD@ry o[@-N Ba|=Zò'Y'+?4tTp&!~j`sۧmR՟kPEnm"NPD;"|\f ZB `Y^:˪/<_z`ٍQADY P.*`9oE0 s NhZͬ'Ժ0:;uL644s墇""c%ɹmݩfwog}\M!$@}d\Q$GÔlEgFㅷQ7;5A.jv$qew`h~hڙ੺H5!K[s4{0p[ߕ O2B2^O8Xa##L5'4;}Nqjj@-QV/W!ݮ-@!ȓP98Dv|R-g2뾅67!.PA NLəЩ@iqt;$h`38t H{҈'NcoAGVPHF{hO5fmR8̝"D<}[ށh[K1PGg~ӹΆO6&>*-9 >"!PS*chxYH>c`Fo50O25ûbS%bnh2N} &&+ғ*f3wA hlRU۔޿GPGc_0=`vU-Ի tfL,}r5Hw_@D7J4lxn2vSQܞ-nj<`hcmz>u~=ds`4!LW- wNglE)%{ѵ;/,ʵwZ XAQ`>.Dcw22:g R,;e WPTd!E7iDrt\9@pudVpWp|X zY,/ .60Bc*LM%Һ`RDb$QΡJ|yG€tqk%J X)Y H<4-rxk E%JPRО\;"FqCE2"Y@Z6TS\bˡH1~W8f\S=rݩEZSwa{, 8eAΘZ9 &~RQ -+7"ӘK]h8c?󁅱 $\{!0v*T YSeNJu ? `4u@w%u<<&<,cRPJh ,2BzMu? u 2桧X` 2fkƳ fk,"ַEG4tmՔ}ʂEx9W6R$G_(I] .ZaZ@YFĜ3QWwU .qК* $_bxmͿ1  <f@Ml NwmWRUJ" r 1\ԆMvCJn^tB!CCۚ@g>E]8e_~j㹵11*G(U \"uMw+>jdU+&0͜wb?@]HSHG@7q!l; ;sˈ]*WnPF`wuIsGCN-"C]]'JdT4|iV"k?V;玒"`8<KPhG,|!sKAii_tq̖%wCCB6#k[>ዖW Ō EK_fY,.fDP bt CHyk3*A?q`ʫ܋Tڙ*0E3x2=d˼'^{n9}˖=vKu ]k %2+ 2Nee3'Y8uZB ]Y'3A9uGy>XAS}BfEe ҫ|̸ro="z\L ЎGq{NZqj!b 0 |m0[CqK=̦?£K5PЧyRqwo㧶ĉNvz Q4wլX4׍>NCc~55|:-C Z C&.:3헋zJ mno ""7|;NjOǐs8F nR1^Zt3wݻ ޅ/ zυ=i־xu̓UA8D7OI'Qdʂr^&U}7ٳW>nQ&"Oy #pp>s+P# 5.=FjS)&3LBuT B6tDHB"\qe8|kn@au̜[2~!'H͵q䩦KP쾰SMݒɷ!fwe\ȹw{.C 8Qb'̷p6i#PVQ0@yy%Rw8!ݪJI< &N-GM@=f?<|)JنǵvRhg8NʀϜ%^+˓Ӓ㪡uJ)-ϰkpDD)tl׌ܚC+ꍍv+;u܄8ڴ$xzwG H7[[a^)lĜs ѨIn?r~]m.|᪭3&s3w'b 2e ,wj+@dLG+Rv0 x^Or١6/#mr}?dɍ;I'.OcT®ܜD!(@aH-p.Fdž:9lEեѻ)).!ϴK2ϖRJ[W|A{:xe=M{/e+ 0qD| jzx{a8t樲,=ÐZZ=7nqёn(xՄ'/)ZibE87T Zq17Mъ|_Zj48W,9'v*`ӓDg YQ׍"IwL &zYd-aǭDSIB\i_(vv݁XOWE,jwy%ZZq}[Hl&B*{_tw3 Ulo$!'O}8GpPGo:d {8܃N+T;ofԡK=~~ N9UZ =1"4ĸ!^aTDͼh=qQZϗFq$pJ hGn`l ?^k87f&]V"z] O.V ,R:%M>̂`4/KjC@x Wܿf5>-)f08$?0Q(]SցZRyq& .G-@s];`9I-] ~**9dh<s8ޟϰ~ 8 c@s;8Jx\ =EPӬ >-os3'>?km+aOzCx}_Ȗ>n{۸D ,KJL릚?e\8qK;S 5_6Xޖa ֩Ӕlk)iQ0|*53eտ'k^egBhI:ɘϓhY,_k5;4C5anw讽AmH#Ĝlm]_FNs]*,Miu֨u״RSNEThػP,-!gO_y=0,XYSnCTJm[4'V$dLD+N) *.(:\9ލHxPוc\F$7j8ѷ kcUo@*yԭ#5U~I%z c%)Q0s'.2OXLPLAut0 5r-j >"҆ &M5j4g聒/DK6/ѿ!sN˻h(G_=埮hRرjp @;G|ߒ-njyZG" h 6fgFֺ-Ā6iBO25`>QBJzi6[Zp}i~ HN^g7FFJ6S["?CeaZ}$n˷w 0vrHm}[M#Ew[$v]:V7 eր,t#Bw`% J g ͂\]%U@`j^?/k[l}(*99 ;424%;feNa@/?+KO8nkd՟RL%ZХRq^_#:yzZ4~3"T %.%&AН'7]$ZhƩƖȿ q~ >9_ !WxJ|`h+o]p# Cgwt"4ff˓V]Zk⬡$?¥pJ#3ӥqA8Fq!lդ\ X1zEV jVY{}#u ~Q|v֭ Y{H)C;\OOt/ύD䫲@=^[x5HUJD;OBjB2 ۙ!䞛q5 P_#k\"Vu`cy[D9A٪7EuI 漣 q*vTV<ӓbo]N:,JǥcE;c ܚb2N}_ͼ&j} p+.ߪn@qӉij1e:ԣhXT*L[T\?eap\&9N>yp +@-D7-l/1`?'hB$, hod*t\mXB#PbU<?+z>SJh Mg߱}#-v"B:>^G9SR%m nT *Ne3"I$| 3+)|u|`X59Mվt|"JG~ oEjKAU d7=?EZ;, 6pU$SOheN֢ ӏ|ܘtoSesG{sp1e>U ~Z<Ɣ+ڗTjE@,jڭ\d1|CƮ7Ks#%F+iJ< 40=J^Qkclg [o~&<%¨K|mͲqNFB\ )S g"tk-$QAf+Un e$Ct:!1,e]ҍ Ȇoz HրuשV PMT8X2DEEsٵl hNc^wGV]7qK?Wlx'K'Mj7m\G7}ٶtGq"ZF"B-peoG,(}H<֦>*BCiW>#aۓd_duM8JD{;Awv.a]@ljrx`s3 ^!mTa_}.b2atI(xi=Y$"s~ߊoQŔ̊ Mo" mLS 'OZG0Q D/ʹzIFX5 ,} yIGDE3s6Qe͹ZBg tXKC'U -b72/8HY۰\7^ Ɉ^F U6"c1״m%Cdt@q A,3l]^_ `ZrAqH89%H`o%;FYNo? 2 NԘe̽ RCXSM?D%X dɂA%m0.kO*Vգꕩg]w+=NVM9q\hnΓ HQ8/CbG1iȊp<߬b*89cLNG'3=7Q}F/oRF巉!ؽ9G@7QmeeY?rIL~=j9HwMFYes2KʕABk?_71=cj aVeBP'%y7`Ң_r`>,7zWCԶ~LoxWE'>$V<իY*v4rN`zC4@ L6b HCFMIɨq)~a +~U%;}.7Av=}n4+ym`~XR]Al+x,I)ndUڇYяcF KUᘵs˟_Qw$P8D]'[ʝ`܏1qǽ5e9!{RCLfYit6yt^be!V4-1)IM>_-vPQt!ID&'ĵ(aSy^$z;[DBS`f *+$|mN5]7 !@˟z:(1o N[EHKQ>^P;'P5G[CV[6A=9Rzٽ BV؜'* sAOVH l!y֦x7]C5=k}nX=MWCA׌<9!]~3q̜l7 6*y9YddZZ&1ɳaQU}u3N`$qJ`J d`^$'l&\Y\B>Z$)vxf&udj;,ɏ/iӡH%KtiZy_.1sW%W"/ LYKV# <>2(v}s阢$]kAŒ:;]ܙ(Aq퍔fϦ:c*nr 9OmBuxzOR0li2Ҝމ+|Yc#64X{*L6I[ZU' w'"*aCA;{LF_&azg.jllE !\0)j'C} |6#Z`(!|V n$HLsk! K29`LPH#NI 7]:Cb9| QMGufݽ|-5n&|gh~jBP=QV22¿,)Xxg!a tǭe%趝Ȝݴ6'."'w 6gj*DɍhR m?…90V˦4r$I^x{{B3T;c'1q-|lp S0>DdFP_"+]ķEH?S]ObR1%Sr\VL9 y_Y I\s~)whFFHG.(ͰAM{9 9ه~1^KQv_xӃ: ,-:E)<'Bj18eF=# }w1DOFAwrBNv^\C)W2,Ҡꡋej&'6Fv2yYíO=2 89%hlz۫>3 q7.0zʫJGo*;&Kvx{keQ"sU z ] -l&\ leDY?\r(b"#S.ŨLe>PV$`˚nFr\,UHp;Z8cOpכcm*z+MDVcȴi00#qW_qY&|]$㬬;y)u҂~,Rȝ!>vǡ?c64fWhZD/>6EOTOv+qD7,RႦwS04´6B鬺12MiO=pyH˕e%x+4RS@feP>BЀ@鞾KuiWTZ{xyݸ$#R N>҆> W{zkHlɞ&wprђ '4CV8 Ր@y#u(/ \?Jzhnu2 w+'w`py~ث0X; e8*zzh?IY--Eb#{ydQGg(,ʗV 8XQƎlm H$2~jUVD? q.@kӦb0lv(.Cߡ̥ <J@~{*&:f'o~WdAH{~D-N#YC"QmOZBTrBy7å׵?q/ 9nkƉQ)~B POZn}M`<~GRYo m*nҵD]Rjb/bH tڸaC.5%5vf-fR" κd 6~N8y2rU6 Rޤ&s-zD1L5.׉P ~N8h ?CU@W-D^W\> ǃmw"#ZԞͷpI f ZZRR1Al~̕"iUͬ'WT^fknmF|;-@]!a"fn.K䪋>32֎!cKLq JӲi;p+ia> %k9|Ά[z:%KaG/[(Ax.?:6oz=c5R?bM>_|Ʈ:NRt<'rwGlicTC*Hó6 xi=%AxZ@pFHZY ky/Cdle$D:ĕ}פ'kWbw,|"^8z[̟тSb<ve~,$Υ F0rcu!v_FJ.DEih=C{{.07%JMh}\ޙiOח(j#/><~2w /G$""/ GuUhՋ=)JJHũ]x=WQ( ą3O (^5Ofإbj .K8>y%-;,!S"xvY~ A?"ՠ\nNiOi+98_dS?k^K8/R ysm`Dxgd,3t!r7h-sE@|8j}6 W1nRq] >P˕\Kaq5%'ٲwU9ԿІRŽL- ~YPs yUeaxѓc0t!Ҕv/:bY4Ԩ]ų htD0VEY zS۾5O 7"'jA YƉ^rmhml4Hw\N2 C BR^4t;쥛9WMU M$-~lK3sYvm1#x SZ d/uCEM@B| `W`E%O2KdْJ~!hOcU<7uç3ۡg 2ܕOl9 ,]PH+y|e).h=({J5irr'blHe(E9 {>PW3XXJ VTc_=Y @H KfU#U"TDP,USfz֘2Y:ӚըcG'1EX$ $)E4;K\ମ}NX2( =Y@j˛ž%/'29 ea<%c8t"jK!sYI .e=To6r ÿ9=%O<1\?*B6wÊݻnuQ)Qu9C"Wr@Qs;*.k;ʨ3%X`Ąl&5.n0R'_ s61ujd vB *_LوQz۠d .$8h#‘8i}לD[[v\:!Y8::% 9fT'z$-j| |]/~.8dU,ƤMoMyn$*mX<~&E4~{<0ۭP>Di AǏH2-y/&_;DڥBU[h fSڮ2*-}D{n [Jk䍿{e<k&a0L#G(!q`z01+]i aHxlU#/_{E\ד_y|n-DTC }sKiO/⩒`*η9:089O3v/-Wӿxb`&`޹t|P7D5ʹXo.%N)܉ҤCR :Pjq)Ս.#$r 4)\xL 7pHX%&k`7sҴH<I[o}$=eXT/4$ɨoݬR38<)~Gp i옾b :tY6M$6Æ .U xZ;Uv%g! -rGVy$d'ʻo/ %1mA@Y39x"~J h<*s:v?i`Rhn$Y3Z?<kyΞa. H^GE A¶wb\. Z ?/hw:];۱6f+bzӫgCʛ@ V6zb)|b+JU Bns"}Ӎ7$^m!0VPQ5-.Zf-4Aly8=nxP鐡7U̼& l Qad6zw@7a^~_V>Ϟ 'zi+P/ c< ܧ`jתUJD|u2)JGb3❶}֑ ~x.=̽׾hK2{RiHm*Mf-;\6_2T%URPKO9fpڷJm:&3{69"jT㢀=b0;YJR6 2#3+<Fж> _KBMZbiHx|7$G98q%DaWYogxJβ5l&K$92<1:ڑmby|{l/uz&gu.$R KmECp ݃jAtGNUu2m! P%/z M> 4KK{|RP?m3mD~EĻ~GNzڤΥ0mc+nZ4$29ɁJ6M|(gS}w IwzJ4̹8*>I '@V-~3H=LSw헹ƾмuL2i﹔@ʥ)uz&5t:؊[&\jm}2ckn/{6J]$ނ&;yX2@`X~0{$_ :>~9vJw6*⮘-N!*C{Yy;ܗZuiuaȺ"9K6kAcA&SDF*H/@ ]laD|ƟaslN϶Y/*ئ ¢{ޘ%|n;)e)ij4yq A޸UJKoܞKQTnY$Y)Y Y+ / "9~M DMۓzַѴRVrPLQ}@8: X\^ŠYQ!N Zl&.l$\3U%XX_$>q$_BEW6 $̃Ι׈BmrӺ&b=- ߐ"nrWMfX2|aC's"p+t O1?qe{ !H xA`1r`עjH"ذCtb0Ks D*|"uOd$NtEW;J 9%"4 ͗ /U5+?&8J;6{8Pæ5`е/0[֭ ȸxs_8:Je-=@&"O?VQ{z)s'3:EAgv103 a''ODVhd)';n]2SZXb8xZb ,.hmⲙ4ʷ(J%2D Zo`nwE'k$f}=> ûI3B:Sz ~4kĢ"2A˧Ĵؾn+9֜ۧ1h 0MbAnKEg$HFd:Cs1V{mݝF5a9ƺf[t fJM7kU1| QrD'>;c^" S+JKArv[^܃dus`Xn}%/Q(I *[a:`w2F6#: vsa 2<. ]aD+x#-ʚ+G0٦mPtw[!TVV豧}wQPv$MxV. F4?Ǜ Uj]_?{}B,Z0O 3Er͂68 SDFCRL<W7IދԆ[?QMYc&5LhSebE\}RII_-">N\ NʼF y} i .Gv_ySCGKIQ@}a0e/>ށ6RLu"lŒ;+a_)>j!J nʃVؖKshG-FOXƷKi-If T 6NǞ|nx,I8?8X^k4.4xJNʼy l1<$~lϊWߍP7ץ,ox IrT׳n'o (ex6H$-BTe!P9V d @R8 &r2/÷:ʤ^</kj0EVhZFg-SL;(u#9=9vC}u $g8IOۚRo``=p +\ 1׵/V?`]J/g14[R 90dl`d&oŢ)5tI2c+D. J݉`&xĿزm0y0'YmIn-` uWz/q̅X3GxmB &d4&Fvg[ Ox#HPsԲ8 r7ĥ8lΪ=6ޤAMD3o/[RM&tr3tb͊~rq?-)u:I|gH1@E`>C\J9aؓD6ݦ9,41֙i 3Sc]>ܼ 4otKq@\($6 T 䮇}tI ^4Δ`@0M=[HCy-0516SJdлEmi0R,=pFF i^̃hS+),RO[e㞟+%-xlՔhoX9H<͡Yz/-(3N4u2ne;$toȘ` ;n *9gZY&,&fG]I\Cn!8;FG8U@$KFbO~޿_\W;kOI}2C[~w€v~Y/0 2fˊٍoI g%vy=ktFmC:DkŁ 4t nllg9.Q 2L6.4ۥ)EB]Y{YBPphWrB<ߑ`0eP>d) 䀧Z2vEћ{˹tƗ5?ݲBLHc+vKoڿ0ch?9!gKZ(je4#}-㠈AlOa F }O\{]+XNjL$X H|d^ q{H'RqCAѹ mn6g~Xnw 2(Um}|,51ˊQ.` ސUŋ߰a]:fG@D2^lx ^^dT[g^f/)b]8V%< D3WԻB^?!66q>&Mk7*r_!hĕb b+0 [B4諦 ߦUgh G7xDq&a4-ҹ,Ƙ Ys Y3RpPOe&ȻsVԭ7u5_o)CU5:5C\DϞ6ʊ7h1 aIC=:yZ>z E`G"o[ρmoպ ms{gЎCq@N@ALd2Jƪ&\oi{f˷RF6%^:;25#5T&nRl~e]K M|W:'1y_ ~5Jv|?uJJ<$f/;>X_8Hef1@bÕ͝ /th†YyZ"Ϝ_Y q̩f ! ;VPtCe^N"}lXX([D&/$4jc0j'±XxgDe`uQr" K*)HPZ 8iA Clʈ7=t;.Ĝ!'0r/Y+=\2 x4`qūO9|)1A-5D xa/Ɯ}F% ۑ@ik%M>~YK鮯*bZ<(jL/Ѓky09p8֢avݐ 4pvͫv XrYS86,ǩ _% ./bdE_kO-mp=/[{Ce>H gO_40qIc2;,5%Lɬ%iv AZz@ax1/<ǰ|_~'?& .!&Yltf09װ_z6C70M86J&At-@z;ä\$ܛXN,B/j2E!s1&yD,;Vspϭny)NZ wJ lw@/Y' 2L6> &@&FrriAD@38U|o3hx%צ汐J>757">áx%!wU$1v۲ GiE9*bg.}p6'\6z;ZhtV%=pzh|ko_tL ~YMcrz^ݕ+֕GW9cGLgN7%|4H ]grd\"E ;;x\T \w/Lw ֳĄ<9rtoY1Z%:3Ft\T?BDw]R|i#Ӑw7oௐ[xU$rUd#nD5 hD9 /.?/׈u1{8re(ځkݼڪ2>pk'ѶiyKJv]*G;V6ZĊ`ʣj!˝crFFK(0INЅens>TDoe5d,XjOQZqJeg6IP5v..m3` ϩk}x/K$12e2j]M8b 찼EHWBeRdzu۸㱴2qKNX]G9Bo.(49y) -8G]`ݫ)s(}c0~_4Y׈˞:%IZ8B@h}W!!%fu۪K#Y#bJ`@:՞俷l q9~`MEk1c_ب'",m@nl ƄLHWGgHbjS[$ Ui.ZTThߑW'3F@n͆)zJ&_=fV{+: r߭dɥH*Ź8FXSAat@4OFt2_sL^?`k;(+ ZBKؙ+vA"-Ȃc!eY5n4=` cGEȗF.u2- : Ksc~By`n,r J]o#؋ _؃bɩ<\Ƙ,DkPMcx[;B{^c㻍0.kL{I0&zf si>W~6(GJG͜ efIZR R,NzqXMVw[/_"[V[z|p6ijU zɔDT3.ri[kX<ɋ(G;V!yu[#5BrЏ>6=.5pn$3t㭯A+?T+-8:#VK?zE7ƨON$/ue4s»%]H,,dj(g0!piz^WN0^"H͑?ݎ:^mqˠEnG6#1{(ftܒt>Z x,`AOЭ̘ ~Q-rGv 1$yy/ #) fKqZUc@UZhQ;ĝ)ӚI)ev{F^u__% AOp(7m8 Ӣc'G)7,nI9!R)4?E~틉}_$h&榬'q4.'n!4R/́f'1Tqފ!4+dPcd>C lFs0w'Lʄ(6̗_@&H5I܁E[ugn, $̴g/Z,4i=%9%Cܜ:;3jS>Iteg䮶}pġYR:}nԚC@+҉Q>8תa@@?xyOw`*l9v QKCc+,Q$-TBojEwPS zxIoIef9R9l!R?@$G RsE-R%qLsw_]]T eGYY@: WiV?)5@QiECv2cdB t'.ޏ hS/Lp:^DT@;; -_I$fUB+D9'5('GEv}G;|zľi5 -nL8N^XTB`LbsPdB 5szrȋđ}%iF;1UsD+S1UqzG|IN,8S6~ϲGľH&m.SƇ|`@MYTd*< 5tF53~֬)8o_~!+h GЯMdc^'AA۞,t7:¿`ƶ}F!@)挈gHJ?3E5+ a4BI6FWgF%@u8/68u>h v s{&Yd?a^5= "sP6M55=xRdgQu#ngr_%Q1W~IsN%jvS@h]͐ iöKwi90s}P v<9icqjře#YlnǮE~և]_HPO"'luiNO:bF\D^]̧yO]?H<&XaYiҾ;*\@iؗ*q!N'txt' \(qulQ , !uME!IBQ '\`g%yQNaQMq4t%xO'4o b?wWB _A|{r;o3`8Naa3# d=6 ZO~Q_@O|E&)x4:`!Mىo~< kV ^I.f>I|#qKlD])i?ɔ(8fIJ J->ɚ;`;#)(Ndb>ˁ,ة^ zK2Rp4?G/:"]-\ _.-\t/&3IgA|H efq[k86UR`WlT_QhjteD:Dž!2 sA|I'(K'~?9Qt|?%dn-o&#pqp/(WptxHVƯyFRN q[ws۞ퟷ4S *6T/3:SSR}僣@ѧGm/Vaʄ>qz|bB}I'w,'jFCKH "ovl}LUYuqtk 0۳hiϨ"0hw0O4DZ ?!kx^]?@qtdf zbAMbقc>T:h-T p㾦cQ*-7(lT:f [B;R Mp3!]n<2 T&M#=CL,Z {2Ct MBˊ1ܻ=EvZeRL 2Mx{|×Ma5 ޶6ek'Yr}QI͓\ Xպ5@u^~PksR;۔T}#Y]qU¡5Zum 0[zxӷ9O6_f9Y43åBRȾ 8n,yܳ8/5grݕR"CF:yp9%-k*#D,rvOr*|7ǏR$l;1Jye_c%*M:UDZ=A`\4eJF4c?倈͢ Dg"GTI;8!~{kVBq@rT-3b׍ӽ \{lYjn+8 d͡~nG "Io񳤽1 L9=nuHYiC u!~U*OЙ9O 69TbЧΏRdh;lzDx)zBڹr+S~[.LʣeF^zu3H% e=\YV [u&p;Ϙ z&VnюzT f%9X8].48R +fDG-jhX2'6nl>p!;^x(?%o,rbȪ IFQBQBKIQ1>)ۧhp&n^zVd?#5nQĶI Уa x+ݤ2eȉ/AS@%~a#VusT`9nҴfA,ҪّH~;J]]@="n2P (?ұ@Cz$쉹N2Ehev+Lo_phۗ((gT&"#_w|x=p (\kg̺È`@w_cSq9=~=*h +x&g. _ nH5xA <^ڛ+ qwwNZPb1N}Yl3aeΎi˥QPO Kl/ rvиdUfOZS+)nk nqF O˝$z'ќ0Ы9wXfFL F~0w*5{yBX{C9(K"{H+p1`t45О֩/n=ԡ7>>\d_s[/e",(/9<Ŏǡ>'T4Ĥ 3eFۺn3b!`M"5$nMmQ0L$O㓲L}b##woҢ\ֶWdk *Ӻit/q>aK'1HM&`{J~zeĎMvcW"Io͂~EfddjZ Tl2wO2vU0jŋ2u:w;?@8]LPX͑& |fleՂ$}.KfΑ1^])Qmt PXQdе %*7Ad>J>[D>MT梶z'*RDmƮiMq4"}@刳*m@TfL%wIs6,bL"=&;*ܢ#: l]AS@%l'#Vu y*?P+#ID `SΖdMmV|,M_Q3^;almy)HW2^٨ӶoGkL$w-٠]zcsH1S`s"KT9an3ܗl)([/h\C$47]·buY R,Q>xVD`C069ynyĮ˝$wj^Ga;/q6//G4 @ {\/q})u>Cbj2H YSw׊gFiCP}DlkU4J\"B=6DɆEӫ E>{1{=D|Gi˲ &^"]Gn=`!~a[F|#R CZk,X[ `l;4U4bߌᶠ4[ϋ4d6Loߓǚ`p[gԬ$k?P~q[xf ~[uµ.Եc~+-/PLB²Py 87 g?yS.!<@fr% ?@Ju@|I>$KJ~G]vz7`(ά^c#ج1gNoiweH^;(4Ղic̰7Fꗛ#%oNLh*6#LRn`wڿEpJ\uN6'dbyљEKucj0J7qxUYLwxr3aɵuQunGəv~Rݲ2/iq9R~kmvs_?jݤ>Tܘ7Ddj68hHpNV)w(Z9"C3-q>vc^_Z'=+s-Ȋ9_yďlovgZ"ܠk#|Y"gzR3.^!6Q tV}#X i'Ր7sW }\UhV&G^|g)? 9} ń~vYe~Z.]dmO׿Uc?*ULWU9*"649{:tof)tQ9{mKT]ԫq̴ڬ*Z4@'*zz ©t+Հ'r#vkvU8gЪ= ]x#w& ;ꀗ([{ ˻ XoK6 )b/Va ĹIL<)+6 έ#9|$xE.¢Ek;'"(c JdU+ q \:$&ѷOjoc,u%@-"ײfm?d:R-r?խ%iXfɷ83|OM0y\?*N`f!oUZd}͊DQRwU7+`rfXJ21U:XEt_O#̑zګ#l+cӬjY8$P󟴜IYӦ7ɼgF-ҙJCm%^`wMٻ [YS1/X$f6+u!^7,)67! ]rA&[g~PDuq&w]2:Y>l>D0تT[OmKӯn'Դl/DĨ VFUe(R^aOsV}ŞǦ5K1(ǺINK,b @Јϔ}|.Pop i U. kX;Cd'HDWT͏L Te損g!A  s3:.u!+drS4wc@&e/cC0.6ǸYcDоjy#(AZɩW!\v-z_NB콲 ~8T!{sVzRMet[-a>& 眡KF2::i۷ &Ѫqd+c Ӗ`|/- iqO%?YlXtW>3Xkrgr]*ٟ't?[63z6Z7UH'.F(dYsDBXd db? dA''0 {Jp:V{Bg-~\.SY.@s1\vQ4w{ м*tv#` ̂ -OG'C>Dy*TNG5JPq|D|o-!;-GʐdhF;Y҆.h+ 苧**{D.R5AXVEý0N\A0\X2!#rpZ1{ >Y)4=1si% . zB혪%{s[U:Rr|I& "҉ 1⩪C $Q-c?Q(מk^:\PtHKz J"}h)}!=DgFo"+bAnlբu!|OIY|ɋḐT_r W 2Z+Dn]ᶳ1' NŇhi>>M|ь,Dh`VԯlWܣfǭAf1F6QHlɢXF&g}NBU?Z} &1)W)'?gɭ$Splh< yc0.U1y`#9MVA[;[CR%`=Ig_4 NR9Qa.+F ڪtGeJ'\73|9iGԙ{er!AumnQDlh!X3T:Fu!:[Q#UUMTH4*KĔvÕ"9r7㉭Ppk,a^ %P8L~:9v7dcpiRLkFh˪Ӽvےci#AltږE׸<0nbc7}ˣbk;%f]xtC86If3YO|% l?I~M.V R#brNgf6<0TڐJ׃Jt"BݷY!<y~f5'Dv'<))'x[e-ϪZ`7񥵆*G0`gYW@,{deVT*?`TʔؾیP-΋FVtk0 VᡗQ' h5`K+@C6K-<鿂+O] qXmp^[_hGpڵK]F`٬Ac8ZL:"׌6B&$67 +Ǡ2c4>|@TĀNwhE߶됝M%CϨb@~HSyJށu3XHPjIk _YEĶrQmxz˱z݇#6 o<#Aqݞb& 80Cq;ErT1 M8ɡr,թW,̝"`]P`"R})|YE 뎔'gbmb>:"q,}32}+'X|I܍% u%HXn4 .8IyQLg FY6fl{ZfAW4%0a \D(6#}Ve}ý$(آ;wUM0*tR sԕ6Dxf8T8)CziE/='5l,Mxe`,60 4mdn,Ȕ`A $HKfM}kۗ<7iȅCii^_Zāw}J aoPQ\NtFju>ۤe)|q%O>2K:|^ҩd͚iBМ=8iJzQƒbIWYm\&kR_bq~[:݉] q 4 &; s4CsFrE;@KЮ9Yr NR֔eT؈L;-Á)OD/Cj6Ot5{T=Z)feښ&˧z?5bv,m8D,!~* L£;aaH;Y' upbj9uw(Q{-g>9ZbOE\zƒXN>Hr?/ ߀Vs.e;ļ=ZNM%f /ç6qG<׌W^̍OxGXS-)fҤ6*f;}9LO;S{ KN; Gl,LrgT,,*ĹXߛe0O&Y$$1֖<&4bb~/^T =p,Y`8w8x~ޛ\j"sNP6EUuJa. eXSn&:nOLJfHf .Li-]i0ڸ_Bo"^sz,xǵdz? jʪ)-: ^i_o3 E3 fi AI',+5)!{mʺpA&$I*6 o&lR`wuf@SZSW:PuJJ蚛Yd^KvxA|Ģ"FC^?cTQ_G7,ЈpH\^_|&^%OP >kǰ)KD-1{4U / b,>#&Ǭk0hdd0C|3uN&Gx}1%o,ڠqK˜R|DT,; 3a[UքN_Lyv\bܖt2ѭUx'Gp+FGlAJ/k>ޯ9߾I1y"&n8f\FXkVvS'kb{]p뵚$ٟWDUh5vcnI 8.>͸=z`?=z6)} ;r[(gdQJfY6&Z/,H!Gߟ]g$x|!VF|4܎; *?E3 $VunHV+k8s9>443LttK o S+Wݐ;AK$Rj*ʖґ41xqO%al'LD0JSJOk;ˀsjΎţQ 9iC]r6ͻk2_k҇ސ3n!*_wC07>ہIa׫W'y8w6@٨ȃJptn3]QZTc 2cv(2W?[\NkJ~سN;j)m,edQR$;qFR+0Q2"X9 yM֝65wgZ+_5,nϓUQɰ1Ѫ2iX2Xp @$K96'L 08Є*8!sAJBء$h]ŠdCx)LD nK(>B99] LqE:%G+*36QQ&Ijx$g\]jZl5Chc,+5C [4ua;UM6 o<d`6ػ5]RI{}I۽B:7.s,5=ܨ̻GW#~<;v6mBa(m>#iËX[uT :kBWfeWӶ!5SIl3.1!M-QBi(QH']ݭs}]CruDaĶ!%o /\FXbK&eexwMLĘ.Ci1gdHOJkYGƬŴj]Hu=,uY&r\c"yLaV#T s :j@U "*@/iٸ^|`=IIkF[~fs{mI'=Q^79;f7s~u>Dj$SD1ˍEu ~\o4ξq"$ZC= qƳbI)jCA }rcKV/t3V QmVET1@h8yT[(7 8=dKCM=@4`e9jkއ1}z;Ƨ <+y'Ƚic0l2`MXM[Aw#/oHM(b*~smNIth_@kݵ9+KưcʊGEX"*,QR sW9ORL "L,Id%Y.Ghk.3Ka0F`8҇e9g35 2+G)-;Uoh@IMZAʹ0O k_b/vv68yR2 %Ot;gf50'~p1[r%JsHX46!:8Q&s I}}22Vqx yJB3Nu%z`lбA/lxI#?#}]kz3d5BB]BsaQy7- aX,r@y)oƔFk q69fg).dD 5[]mr \{gMK@Ұ.%1 5ly4-~ q?%h9ppX-B~"|Z?MN0xt!9Mt )z3~mseiGmدv" r\֍/5.ٷS7{(&,@#}VvI0!ۭs{i\nHv֪GЂ0O}F-Dymx;VNq{jI] Ko-OY>S0sU)tz@ZwkX55U8, z\HpTdk/aw% -oM躔*HCzڸ䛸 gJ-4ƪD-BȌ&"h9[TGEx]8^ +hLOx;A ,n@ò hKN[mYE2gہ6SK[xEβe<V*Jhp}d|j:,ߡX)伝|4' %50 @⃀ يN}lT`jdW"q*7'^x ,Lќ?!}\^rXeg*mC{ke`=< P/~_*q0gȅƓĭ#EcMAh 3NgT(th)POTSxTS4֠Z|>`VhڲB|/\Q1d9DYGgǘ>筘"S^P׮t[&, B- zPϜj]ݗfG.bvEg{ D~ YDqZE'p&Ş6{yﺓ]TBrkB9D` jPHoh3K1ϕ ,& qr<&($G mOb&DBi‹v\Vd?,OqBI|Jͪ[4TЮ'f8RI4A mSp_h#mU~7.Nڎ?-GFO̥% `>Qŵ3G1|KTENonq轟{F#xoas+ p% R%%Gin<XKA$h5G eUh*t Mha> #ʳj("^M5)ǧ~oъlJؙ/Vf} ljyx~?1FY>=!MMMhIMf$7:˯jIIF1M]g^Jڋ0:Y!j|g(UZ? jo#;zWنjIg\sfxV[/% n=rk"xұ@G]nӫ6(Hq:̿q;|_ň"iFROR?b1"k29Qf|?uˤ]O?cUA*`YYeW"&Bҥ_K bu2AݲRg'p I0-^jUc:C q!Nu3 mC~q "*0g,.NDՐV6" /h)4nr.bbU%tv+ ~FJX-P;xr8BV>F}-}bTGnօ-w{LJ}]0Iv3VzR@zT ~ɠRS)ؿ} D[ɆL*fD# DXv(z)X-U2EJW +xNsI 7S\Z_C:wQy~mO\)_Ss i G$=!bݦn=|>9\e衳$>i4Ɋ>ݘ8(IvSC%CA*!-Sn'TRLKď&`O%,'? |\lu\^ 8|¯.ׁ/!@ȢUz[ߪ)7qagm)ǴC:PPA |8V?ma[)xTGk NH|\TU?)k|IXndɲ:3at,,{">(a>iEnaMZ]O,bDe_|TR?gW1-"D,w{Icpw ) dxtn6_l)ؓӎ~sg$B^QAXIϡ2#q- ύQpmQ~'>goe1PaG x%*0()D#>Nx5cQc/[VLZj k ?( |kojqhNy1g97.=U^u (<>UtN0=tz)P5+(ˇf7jVBk-pnH/u8 [Q:Ha- nG}$̑`vҗ*VW͔¯Xտ|% 2hpL>DȧJ=z̻b%) 97=Or5*lG"/m4xR#ԑ% 4SW@zKt TpS(!( ba-Vu;԰ *>M-wyd6ٌNFju$gI#_!%;x^Tl١& #c[~z.:Ye)"aˈ?ќpͲĐ 9-BmFqL&e=ݡmP` ]"pKJ9Xm~Cy9I2|v^]̤inodφ :F074EIc 3҃Vո*mB *6=cPYaDb!;&D:o?6)%r cVF2Sb`!ez.gr}39G33޺. .,Xb>UIWMu%D-M_%}7Og.XLRbaLr7|}])>e6dYOSВ;,viIRdG@/FU)d~hAesM]:6ܱjTrTie7*$%9kp~q5y\׃\~*l94 s)gm)\dqq(SJۡ5!SRbƓ/`9@xlvB$z6T2Xt~W}LHv5'[jy=fM4C=L 2l!VK<3 YDnLf@9BuA8\ ?i[ߝk'Oh^vKAuIϋH؀J%8@UrPԜڞ!0yZxP*Ѯ~.+8)WT+0jɉJƂĠO@ uhFeA΄h̒jb~[l_C3Z;&mbxc1##cVԋO'Se&lWbq8~'y]p0PnW`@ҷٵz)+ij[m C`V `x49nMTb4Y :d# 2c|O+lT'`3!\>^9@~7=qO)֬Z7G*Jʩ@hաѳۦ 3Qv /hGAZN_ϱP'`_k7DΫehz+ע) =R ,ݤ_&UZ.#,QR2Z= 6<]#x<|}V{uk6VVZ܄Uj y{qh.gV#<5 !˷%Fo(\tt4w3f+IQX 72Q:]Cjx$IMYJ%>W_N=*KsmtYϕ}7.a5xv>y=ُ?J) íD?qq~r;v0X|h!q\nP eyϴW>SʪjDOdűrŽt[(hZtH7l7f}u7Fzp[!aM$uʏ+pggyH ={֫SD<>tMbwVmnon2+6D<ӆfٻ@ڣG"p[Z>Hw[М^{dñpRTNV+:/UWy MŽ9k(i9yAdNp0㸝|#7ĆGx6mUeEv{Aϊ<9_˵+1Ј.6Σ!+߲RFLY% ӱ] hHڛ+#TIZ'6Y椰@Wdm >x&1-}#h*M_HTBA~z?Bk{bc2faIVf5XO;){X'^{~ϼ2ə7*c=aBd=u7J;DNwaw+Z[ )|UZw&>b*`ZzTa/Cͼ)GwEQY{ nN=>[L[s޽w.v[$ %}=Q~ގ/(^kqFqg_֊Tcj*X1z+ȡDA emta93w 9Á_qP"#(ujpӍwb \`p2J pB60j ,?Lpy:րz!bs5}vx=W5S ^x;(5kړ Ѻh*TD̾8><Ћi2rC ꔸڈNr<膻+nܮjT\ qɤpyR[RgӸq l@lXr:[\tb&m;"ୄ7pHz2sjWt ttmۥzL=dʬмȏ J~`ZP83-MA&T[2/֞|xZSѫ)辥:JQq1 [-lڞW:AwZ(ZCe%؈ Ӵhv~#£&Zup7?E{ @=/wK>a/XSd0w&2V)mɠiOKGm8/#gqzSո2ԁFQ7Ѽo5˜,A,ݫf(yO9q9@gYeRq%F1qfU&đ-{5զs|Yj|%^Hc9+sLd8AV>VG[_ɉ/5"w FVs@վiaZjĎ m5-y%-N RՖL (/ ! niY|umdpFAJ*5oz/#;Cּ*OeD! _5o6n%<ُ]o5| #[hy<(G%U.z<3<9QCMI:A 7,򴑙J/ad;4MK*SJD=?Km"0A=~6ӑ06ƶwV;n_i2^vzضɊOT['Y%yEHАK[eYnoD%F i(e(,^!ڵm}Wj: _@oefA|Ô?C4"oa95e)qBܽZ03BPcp _p\rďN0d}"18?_:4-Ei?N8Zf- K|(pqr@a"ts0觀7"-"}+)ڹ݌!::4yٚ0]-sQAd((1 wϣ-өX0Z9bejٍdJ/X9-T 5M'K͵*ܬD<`Odr"ULt> C5[V"*>Ժ"Bb`Q^ Š n)A!RX1qGȳgHi$MK@n.8f2NO4$T:e e B=2 -M8*K20'~Ĭ$*|5y z] SA8Iv>jL]4_ ѧZzڈ 'Pw%05^XB$4O6!cv:n oOlw^tp>]zC#9 8-w5RY]&rK'L+E ;3Y_~Ճ4 6,[AQ8^ZOZB36YlDspBSO h#Nϒ`\ !ܧ}`cܖHQ vx:O"7D2/k R3*T P&+S~{UGWZ B!z;t6w< xVY OeG֫V (&E\uQ0oZnl˥G?gYe&m5m>"4)络YӤ)cP[Ian " y@?^X>7 0T|>d(a`+$}nD^b%[4R1*V{2A1bUe:>PKTE?ߺ¹h$ &eW-78Q?pUw١%l&&`:JHꎥD+4pk!;T'gZrtB'n:^&K==eyB: ˧iTdO-S'Y}FPA."n6 U΅5] (RIT GMW h!qm彀4{-0j9Q3=I|PG*VԭE"p@ܲkWda8Rhp$Pr Ankz-4ftd hwI=*ƉvO~ԐªmC {4~$%'\kgWX|d"\Pg#ط 7iZIV;ݺxb`G 'naW n0n݇HL3.?, %tF x(pnlLB mx>[e[Zl4'ȦgE!A)/^& Ib[^T q{F*p*s#VJlΤk)GgBneʾ;548ܫz~8Uԧj[Nji865 kzF?]fmYf'7m#@9kA'kcOڥy׿H] T73ﱪLw *myԎ!$0!f5Ik=Ԏ⟧&mf=XRgҲxDc;D$Sd^N /둼CuSԨ0;' im`1s֩{ebCuv@Ig.dъsr4<;Kif">@3gcxwP=پ-azYX?~i+wӭCs/?pn!Z=EVc<%AiȂ6yߞ58:y @_'!Nၺn+lG{I|G`3'qUݑˊ$ AQr2TؘxZU& @B4uHlτH9z`h[쏃A'&{ uB(&J"3*_塎&'WhK&>Cq..p6p-Ha"4Q`j^WR"f藲o|_W QIN14@lܢGZt\s+Uo V9V>+ϳL鋫]jn.KͰ. _kSw,w#K:-.YK47I2?*dIϲ^5=u ~RØl+{F8>4E>wH00m9]TucW7/_ 7S\8~P ,ck Ոby`"@c -`ܸ+I8Kټd-h_yL'.\#k y6fw +b;éUq;| vvIͤ.7/vdxN;U-şS+4|`eFEazLO+9)똣X"0"$MM+by@cL/Dp{oXW"/W*ԫnTS~0 >T -M< \mq0[ݫ&eFߩj^jK2 Y+FqstKʗ.|q'bX}&(q7}:RbgkGqҚ8iWd27"U4ŷ)4CǒЧ`ƌ \lqjP#*(/Vފ`PRrUmKLDNUdsҋN\S:-8ktjv]"%H- XC0Yqk>C(E}􊚢jb6ԕg M+PA)FճOjAwh?N%a5mqb1o+rp3NK5ZӸIdk[4^ɍmB`PcD ;JCw%)ژ (i81^4!w=%رdN`Z#wq) $D\MѢii> i'ڴX3/n[茮f4<dl ^/!opzu?mf__[5bTf1\C(=izhP&I;dn dP'T'?Ms4IM? #>~\zYTc z+Ğ;hU2s([1HKHXLsRFO152fX.U!HbPOG>D,[9~dJ$F!v3ZMe@@(v2)x$+*Ά:Hq%oBOA\+_ΝQf񻁑!:YGUA|xtɈU"'b?٥R.42cX ފHy$z H] ~kv3p=+R$܊6nKiaBkگ5ON{L°]?! P!*` hfC2 ۷֪ Тs萪$NmW_[,o8ot&t ?&8:{xc6Ј[janlg&} ݑhpwTs#Yom.ޖIYl=hCbaEt0#/;tyw4-w:G)C~8nuX@ ғlOK1M|Grrd%?Ð<+Lȸlw`*N_ԿBQ)^mN~E᪢ `kٵA#%1zw2kɹw LRN.zNK+ `uQxlKu\ LP]I$^&G+J H6FctqTpt$D9YPPZ)Y=g)gCN?dNAdԉ=/*B$.^'KK5Aa*1 @_/V+P㢆ʺۦ%&[!1=G5N}hjy k &cZ}6TYOu ?@=Nrjx!G*jDfTpsF@Rh|,ZaZ<\SQɢvpZuWSOxW8flQK6O{"\g.J7n%a=p^&p|oзU삜6tn]r \6R })P\{)LL^dQ#a/fhו@W'~ 2*`eMHAms\q-mWqA1!֤p tHх}R=r -Bs_^ihS7ς~"Uo=,g a ]=HpnsћO0Pq >7" b7՛"gAu=;Yg1H"y@Rn?BoWeA'F*ޘ<&G4Rdsl\M,-cC[C^feho\ǪVYBKWʍ=/alF_}E|kdHrJx"E@D낕%ne! 5k q b4G݊cJ,:& ` Q!Ld<+sM9Gy5VSRU]ǴJJACOzV"")XQoH,a*@t4i<&c-;o/#u4hg ţ(J;ճ\pD'u**{XC.#D @!q%`|uCϣ rR`cgvq<ZTM姮#`8+^UE E,=¥Ay/.;3[zM7l#)Wml0*pȁ#EJHYS?R@h1ͬ9s2%ȶ%BaZIlGoQI'/d(^U F7;Gc&-(?>8ߟ#7B$"ey ¨-²ơ.W9"qhŚS78ENi} jhOFFM3\b}X~V?}d;o/b1:ay`ϐ{hSIٴCfgˑƻJy cm:}l(1B?6,Fyı W*n?8nWe"|=魶8dC@-^탃3AGmY>^oN.1R\UY-sQ6)sD]O"VETe i,+ͧcM^ %>4|耔EM~XZ,񂗼7 y:}x\W(0W@T(=Q3]r@~aЅuɻJZ?)EE2v8$V:q{' sx/$US0u&@9<*KP{ǯ]xy@ E^EK-]ƣ}BBye(}HY.ӷ\%Exy{e⢕R7nu;tKLdZ4Y7]fyi>Eh =@*×7S]?b?|p (|'#bxX*>\&  )+ `Jr 5#$JvǠqƲ) F%bu]Kfd 7LB,AVkyҘʣl^nj2\iBoϊCzQDNQ04Q؅RL#$jA:a2YA*< F;#au+g~UDVx>,-nާ3d]a\&7Bx#Ğ!q # Ki^ߠQ~˶pl&07AXC+JRsUpWU_XvR^r_ɦT ռ'ۓ-ܸn3(c`Kar=fZ|"ģتiXK_`jWNjI1;ؼۘ֌2:^dz݂\ 莑~] Tr"{|eJQREyKq$Kd++p+IfZ ,pAvc_c;;F$OVro!Qn{餷)VKEj[w>p{1c-ɕ!sԗ2om%WW,/;B>1x=>pN3G9[ FiԆܕJI/ܴJ풛O,w21 u |/SүCM*H2{C<l6^mo (e4^7 ,^뷾y{x{⥯4bO׶rW@m7v3CݭJa4 !$$bL \kF*/p`E[=<}ʗԫ+ KV j[L F& 0N:eU^,vxR`G `lkCHїC)XEw-NĊi+l{Bf6#oeV='0T}Cjs&=` `wCd*3`d(& "tMj,s%i-YV3@M-(Exu.Z1!UT3>AcԺD8JU9ĂW :'88r%?HbBT-Ax`Zײv,(H;bbb'_!D5@NDe=a.(NVs'7 i&\iyQG2_g:E> e%& ]u(X$Ji' cv|pe%Xa _2o_W*qk~֫ZwP ki.ӓP` ZAq<˥l_/SEEu;YUrV/bH'!X˝8hUw5\F@K h9+qR5vT*`Ey2RψE@oNSe חwаH&˞\.åMDr* tЋwt>Y_jl{խc4!l-X 0UamJQĿђS"r kFMٸC%Oc+u8t);$Ïo`6~F9ΒA !Ug(<7ɰfEV"@ŏum9l x7 9Z>7"UX ;qۣ}dTa jN),ijҠ}<MjPa:,-};cW~/ܡmJOZ|MmW4߬kW$KDyQȸ*PNf؞Yd~`zgtÍdR_81j=7zu$^F϶SW;j\0Бy#˽路5FR\Zr aei2 #o=Ti[,is-c1\GI@SٜYxWx^R(r. PST*EdLK0q3ƫ)>C_]pǃ 3 8S`K ;H>yIG X>rGElh𹑘[ E\ߵ?9o[K3>:bb-d% dMZ7x(C)Ln N?=|c-Md [=ϏNҼ8TC = > xlx [ϝY%_yn` E>}>Y^zajS_j(ؗ]i/W獚VDU UM6(M=G#^a'RPZ-R;TSJ).;+DT?&A2,sLiX˭[ d1<2x#wiigbʍ0]v3ҥߙղQJN^e'r%>V1$>;/dpDboK?@9if`[QZ͏Sx d%Av<ᚉvHV#jr/ZHVЧ,IuhfGADjiϵR" +9G[%Gv 39D,+u >fF:yY/l[0ڈtT|/f "|!b>Zh 闱6kb|ZI |ed\p єw3w$w{i)3z@~Hm۲d#2{#4vc~Z ;Ad_mO #k IME P K04ЬWMݷ6sf^4LŦ=PcHx1T7ie/ ᪡doh[iDqɺ79 ǡ9L%;񚴗<hd46V;wG=J$[^[ji6OhW[_+T =)QӋm_",Q1PznIpZOit~~]+<)&W6vZJ hg8׌坤/]8sQOuDݭڂU𖧃XMM:7We ?/wZN;U>rAGZu V)YfWG)/?KHMTr擅@K5e9`5rtwFO\'464ٗrQFaԦJ$y9'_*y< + P{>ز\ivq5ɣH9DT T¤%]ֿ&@[) NNYz&LK^ub'3VB2bE/&ƅ}g1QC TC /9ލ6vl|,Y˴.^OBRh9.eI+M @;ܨsaXðvzpM#Øɽ\HGZ, m']}6f'Ʌ\ƛ7w"%1O<^]8^Qtkfxd/ޖeK$Yq #M@"e S$W DMl{g3oo0@1f+Q ``\ m"Ps/"1<}Cnةyj#8L>ǜ턁t*gB-Fo_OOMs2D L9oaI@f1eW }I0uacr1 yF"hjz%ӠBP_3rSNӼ9$x,}cy*,tHYyRP_6Q >`;OuqCROSv\irzfCHb o L"?_qƘri <[O7RF<Ȱ2M%sɗIx8Yo hO*3+}uPf/+F]|):?Lx* ^=.EE#0\A!DVoSl$Gqon1UGml^~<ף `π;]s& !8yư vnPdOur 2R'~[nVd@zEV/=,YA3f,025vhM{i_NHr0[˶07(TVZ,᢫bjߥJ/&VdC':ZpAe[ pUf~l!/>@{ۍh7zD$1qCʞmFAxC֯CǦ/Nz͋G`SC_6΋7!Qxz( Nf|+|&\Av+)uu@q}f1l>@t'R;gP\ANpC'Dޓ2UM[/FZUcHH9BV,|mIY5ajRjw5``6&`\6mAR'Rie%'"{Q%JM!#bJ68K" tmQ=d!9sL\:Ev 憲ykNw%V*%E+KĆGf6+)?U)V 50CJRS&m2-ʴwՑ)&mP?|?ۋe~,qSmڎq?5/Ny rZ24D^IKh洱 @3GTRF[Z9+(J<ѹqixDVQuMN0\A>Q7 V[l,롒['ft{A?(s_]\OMf؋800[oXNB=w*J $p@nX1a]؛C U"~4l׺_>C {vX1%Gz )t:ٔ=[XGƀ7,Xχls"vO&g :`Z%-Ҋ,`C޸ '3s}y{hy>(3rM Db`C߷o40UGYΎ)865̎``FO/Gg- ^qUk/p:k.>T\,%D8Bp 0lc'@}yFoh ccb>$} m,DNMҭE|g[NߏA¨%}z6tEEpiIyW}`B!w߁xpԴ.W/51zMu:X$2 ?LtzfXSxTj gu 2Dx}PJMPvxiFdx>q A'}J!!aJk|xXEAcԧNOY bfeUZu h9 B#Qmh)r-2pZ3ߒmTz:rvxo,* 9tVS}N=W^[VܨPJuozW$j1dg@>oU<2_=W(,/!0A[k*ю HIn@x) l 9jb\c^Fv'fs"񤉺W!~oj/}&)mđ?֓]^ yhA6Pk%HȊ^ :3!`rJ2|iy눒'ljHT gWj펌?Z%rQmWzʫ9|Z>)R\ f]4sD9PfJVu*(e2M dIv:)EξvYb NaHǶ)mY -ni-7Kv nqt’)3S`Kb {UYS d`"Rt! baxܕ#;T@~w_1B|cM0Gѓd5<4s xYQx <~DI, l!,NX}IkT*~ ]zـaj=@?x<:;D7R9]ѐ{aWB987a%$EQH(*YєBp{K1(9p݉r 1(@i&Ռ],+>CcvӬFLT8+E!N|A;]#HE# F_t` 2Wy%י?eJEg1h :o;q,y'&ݮAcF*ʙ'~Φ1ª YCq*Ą=|v#޾ĉF*iÔ蚨t{S^y&6O$0Nw8(EF8p Zv?B,SDrPnh [_S(boAcPZF;},MV`Kt:(7ɫURfJf҈?9_\U)Y#$9:T䱰q6MM t>ӥ6{Ng~.'j7|xuD&u2>:庩Dr?d מA~DIK[h}pHBHc6x.qv1[ϭwt՝ԉѶ"n.t3IY'_%İ< ~D6D&^煡e.Ǣ :G> =nD*R/"}$Ӕ#XȨ[;Z|@¤jP koZर2B2W|/}a j- RQ\ - ȝ~i9B 86ej}6@K AF =7cSd߹ѯ&yC<#%v~՞[Gb [KiFȇ@7zp7y-q-(`N۱:C R}0Op1RQ$EdgddIEl1WR$MUֳY7wF /<]0ڿi!2EUx_QȫrxmqOI6C#ͦVxʄ۳$n5!Fu` Ҝ_֠5_UޠI^ BRa4P,!9D9Zy1} dDuY \xW,%">N36ٽ(B /R8je޷LۚL@|rpIe?sT?5n4S Vӓ).h3b#+cuܣUϟOPKA4ƵcL|sw`yVش,OP/bRۘw=8xU:E Ҋ&BrZA#+sh.&:h8:L]^Tw;wI+@5U2u=כVe.h ;bM/ Ì q8s*Bf$HD)<{Z_x0VHYd3Q(9N#kX;ɪgՌ`َ??%Z ;X;c (LZ}8PI,vZ\k5@c0{+|*A-1-{t1OGZ3A!s̉SPQnvӢC[(ٯt]S8s?KD!lF HڸvI|m31UOWXUU 2(kE ;|B <;ү\ʑRek`Jw:͛L_akj/PciǗN|/CL薰zsiiF!^Q=G:>&\_(G:8#<+?,5݋-'P֝PGCamDq9i:p $۞0em 5x6߅+]VTgB,L׽/wR6[%@T6-`X&JO3OD$ sOǁf &01%u6tc ,ó[_]a.A@zOf7ca>Vʒ> _W ReUx lی3,rg4SaM&xGd楣/<\bN;hg[b6$?Bs& V 9OxT.N<&l%L(JtҶm]!7\Ŝ.c1-o/wM{,y0W-;Ͼ$ 45f")J,Ѷj3HzQ;F].qK tOHo~v Y5^QAy ^ o^aAVTaXIs+,w̮VmKahJ B5_F=ZsI!{?YDx\"ء4Cf!d.v^R?A F”`#+ʹ%a {+N1#W< 24#1&*av+.=l:<]dg[j(MXC({tbmdNgLFݖG96=* pħjjΫRgf浪v@{ ڡv. pqd/؇sȖl+UV#64ߚcf*VSޕp$UA&k38ڲmaaIҢ'B#eS&ӠiS4!wuؓ7/eC{&d2zwٛ=EX+&C3\߻y"r':+s#L'5+:@ѕsNc-.Ã7Y&||0H0F;#4 RjPB$q4I8bMEcx3nz^[i Zދ3L+:!nD(jxaQGƍo.}X!XEuQ+)sICí[{+sYjJm$/L@]-.S_WDhV}&wǓ߮H.T ,d[&f[6|_rj0(EMи9?T"5,GE%vOcE+Pr:{\F&LӞjYb/f c?Nv R)¾zux˾BmOѫ7TTALjS^\ ]|.LEN]lc_0OSV杈T#X*틑.]r8#OAe %MGN!+'H&y|i|Av-g%mWėaM' 8NٴvܛԾ/@ L?ɲ;p9&co7e k@՝qG9a>b.XXij%d-E@>n]бS,=2&Yo Sz*nlbOHMg{]F6Cs%Z.M%'0BQN芀q!IEƕ YjZ"=g &8d zh9~3a ,tQnE_N^ą;kCCg|HG X(|:HډvJr >aNԈvl_ltn@etN:/MhK]g4!zߕoON|w>ժ>C-p!EF3~/8~+z_W/饳!ɍjݐճ.l3u'њX@~5%{Ѥg^6GȪK㺖7S$9DMŁĤ?_2`bU <4NGCjJ B)+ΒZ Ū#V@ݵM K,x7F| <9rٳ0wJ{-=]"a-*:iFjZ&gmh5i@>7;_sZ0R<>}\NgHK'6! ^<3|60Ik)ӡg\DX ~5np,E$5z~a9'Ir'G*AS d%-c7t6HNФfV1Ѝa-]#7Ck$'_͖68?;d2&Bh3Z5>4hai˚AGyKjϻZ_ɳ{ݗvT'!*w2l#~Sp;̑l?{amӊhYI &fy9Q/p%/v AɆi5h hsBMq_m>W'flu締؋$SndR%Y7PoBBbkf_)9f K#Q?,۪1hKW^ׂcރopjΗnwNѽ1T,1b5yhZA_qs`-;f3kbv6DT>x/қWڀAȮZiEce):Ea:aq Vave-,6pohew=sYTIyD?蓊8-kD#.~]K [/t`\o?nq*̱%5 -2I4oa {o!^¢ Z<%])09jOb11"Mo!.)St!/k \U>9ny9䥯 -SVMISͬ٭Z })R_ɖ!רT}gZI8 vCīu3sPUIh@dRVx8cJ_oOJi>J ɬ>3Av Ӝ-}5Ct 4~_. _!V$x13ʺ/)ԍ ;˭";h]uX?\">__|Ut/<}Xiϳg?R)IEoӞ7‰4TP?+HKfS†?L}yɳsvW#fujݵ+H.=/ ;)8.\w;bq{vuJsp9: zUIMU/w9V]*dDM_{Q/"X,:s]V"e2%d<@+p=ե5Dp-V-e6%b3̲(w: -sh:'8j͘ib'YOJ+7Ov#n_-$32 ."&j_L5^ vLck]̱wLm,_oxEi9}ںpgpEyGdfG|'߃=wK`nh,UPJs2U;arXvs54{F-d?! :ynmtQf<)ͺl%LOg~JAOy"(øi]E"^j}25Ȇ.OIEŮorSef &4'{f_7y;mU֤|?eB:y>^Ѯ^ |HK`Wv+[#]崪gn/ϥ<~(4W{\N$Xi&eMp,{d;m&Yw\ne|Lv'"k1,9v|*CC/ǡ׽Ab0TEb4Aeyꌹ-cG{Njˠ5. pwױmNT9 ^rl^G;L,\x}#C(6ȆQlsؙwӝ0!lz#) i;?(jSn6|@p)?<y YL f3jӿ6i~"#6 ?7ΐ2އ T@GQQ@re@?#.z Q\Eh@"Ó֝CّlEQܥ-̚+m\(Lj0{hLVkƱm.صcV= ܌/y8~TĂL \~M̾͹~iB,U2?],xku\d;\uɩ&8 )& a|Vou w=Hh<,r]#Ci(_V2B^H Z|m+B$rL D§7<1>ݔ6=Jh̝f1e5ml(IoGu hp3NB3^!Uy&Jz, <B'bg$zdKLlUҿ@A hzZw}j-~p?⯣`T,q_ݒ+` ;1FYԽK?$41!Y ~.6C)?AC1Q͵wXV>}Ygr>\]Mvr?^aZ4³OSPBRı`Z*9AH ̀~[ap)!˶hw[ M#n f2'ݭ ʚPvN7^R^//*:Jt-;8 Ô9*43Rf_<`kB.ݸI]'H쑗V'aW@rMT8 09Ok&FygjXMJXUTZ-V3UL1g-d`X+sl,6*?ɮ,GW'Kō`$tUTn:ƞYšJyO` jʛd@5t^JlܪC4,, @7$?/1X*Un>RM;W`? !kLg'-"ʼnFèSxsBs%`#lvU߷qăXye<HpxjP;O.5L#mqP zT3W9¸v9n]¡2 C992r2 H[Ze{=HkGj3#{&, qk9  WP.\Ȑ@,(H?ÍA]' ̋/GVr69[,JV&9ﷸf! (;x1m1} aA7T8yMn_5{x mD5ѹKHW1 u{?6tt"إv=#2"DžfA;W)(f&Q!zF=eaT=oɰ#?IؔQd4}drÅeg4m@U,Xܡw,:>C<'LevzQ)b y4\ꠄ2˟a ?7' & y-@2?=L H~)!c:x9]ų}}G;Ȩ)'B$[ M)g,.Zݪ(xFkBl_>_ "M)){ 6;s [t 4ӗH|pW֙ARKuº_qWL;`unH54{/u%A5wtiF)ep [@Zp[]8yGi#FH$!̚\{b-3/Z/T[kBc󆻞̉-3ZFI,s뒰 Y_~=iP[l߉a i4oNZbWKsQ-;Ggb(|ㆉ ga,&AUYTra/5_66mM'S1x$eB ء=QM۠/M>#L$@#2Q]Ëİϴt.zjgzI6p`Kuq|ՉgYM_؋JLD2D㪫@"Ow< 8^n᠕BGBuߖvX3{]-UQpsuYu911R$97 0I$)g,lqBٻ4,=P( >/}MNRZYca5 ]/cSGAJ=ִr̃ں5}bn1ܹ<`4NElD8[1~%"Q$Ȟ9mPncpp a?ϼsXsfo]ӝ-xU>!;.i 8uH"~gY䕆5)h|a<$s'5&r>#&-2f%U-Ig-<{WPYɒ%`< C̯ϵX$AٹI{Õ]}LO1HpP#hH OepAF"u :f9sg/CdeC8VRq37DS!rn5!j2YI%:EAV{f ~oV1gɈ6)c`*e\ : ++o>4vUr-iFqRUgCa/WFP+dreVt`C)HXjM;{ȳC2*FusL4T1@T.thjwn:DIU Vl>S贀L< ߳M8^8Gq8h鷇yˑv wU77U j H+Y4"CY)X򎘆is6=-fg[U. ,Tzs}JkfuYUχKWn٨H'[ѿ;7)A8|R.iܦQ|\woET@{qL͌iwݷrHCaKI8]opcE[V/ ~ބwQ[Ի.tC6f~EevdEI!9etg\OCytXɓ(3f:(L4%T]g O3ғT |)6{7)N974(i5Jg9M+2WmN.Q]"ܥSo,>1+{%ν5my17go6 Ũ)'( uֳ}A=$SD˂Ah0%HdΏgW%GzE 99uh'>xɼϸa^1tXKo'Nj!NNFGBbm墨gtgo$,ʟeK kSl~಺Y.g 8l1,F;.[yd K ­Fhcd#uE2@ N_&%舂O⪏/Da,F-B2o^QMӱg&LQTeu4c(3hఘo?ul/4h1ڎi:?Vs~ fHD)*t[ smpS+;NuUF-"ogv" C %:%|iצUWڞ?W< ӎ(@;H{{$uJ4/\/#چ:pְyͮᆰ=%&k%wt}ƛbW_nH!'MyրQ&yU GFɵP3M]_*u\G3 % ~ fSIW51a]]pn3'cAp6ڳo'c`XhG 8,.?ad;R:A\8FffTzQfkLnN lǰ_6.<4ȋ$So%WNwʓ+[ۻp3L"M 4WiL Md`nt_* L,XuR388teWV{<<W 4x9Db,NExSzͮ(*E:W*hS&&^;qvpqBd%ؕŏJ[mJkdmT9_ʕzCdrF/JogiH~ $E< \"YTKiIٴ83[%g}%,[dnԗ%Z)]tfNU]>FWJA! c!hפ5.)BVS<M8"g֨ك񹽻[+gzy:llEhMm֞x 1 *0HFP U5 C Tlt!KTQ42ࢽ첂"0ߵ͈*Jû'EEQ v.<{(OʃӖB$S*K:C ԕ GPLkU] ]tt''@r.œnc4g*'QPͥĚ*￐C0agG+P+=.+:,`?4%NVݝTrߗC4vm,iL"@:]'xRRziHOe/s90%:rv71Ő LUpQD:@4$Pm9ыxpUΆ|,;0hk;Hd㶓bMtBng{>.(,Z.}mbϣj#nW y'=MLh7 Z` Wzn׋N.,I8iݽb zzUo{P@@l>8!;4쏬io2?^nZ?^׻c%(Q̏Wr$h?7qC6@[bzMC2:j`;(I~C=R! ?qh󽹓cR1"*|QD+-N5:3eN7':U{zmdlhK尺x*q4[$NrXx!횇S1IgVuGh_e\--W&YDjm"-3&O.ף!2DS :}jޮE0T}XP. c@S/X#r_Wo%̎,uQr^eNŜ!\W!*]ު +'ؕ ,tn!9IrrZWN?6tU)j>ZW bɿ J=LQ:pU_?~c)xy .c|M\BFyjiN࿶XNҿ3r^WZ:ܞqB[ֻ |Ъo TDzJ|) HM+χk U\`|\iA X`S(%jsuf[5FuJQ6F:<)O:vƁ/mU!!lzݑݴ%k==`(K8.-dr@/PKO^LSBqY84$*C_*l[B@ UԹ۪OH76:|A`4)m[_9V~ &jX us+as-3%תeJJ~) GNJRs&ijtJ63aq<LJkG_\n14 kFpbdpg5JSqn-$ڡDL'w>wDoY&<=>_WKL"tlNC]}s% ujy=thr73X!<>[#Ǯc$Db1ZQև .3@#Z ]F+bi<1;"r )Vq]rLH<(}*h+)PDX9xAAʜʻ O7${xԶ .㗱^Eχ郘WA;z`?[tmяSFh,f'DCKxjt M#dž?r~QGRQ7VX%)x?5|ie/j=4#jk8_6d -6yc% yKZ߮(jDI`O!'y' GQu1JuvCMӴc PC>TjL/ӝ_&wA 5᫃7iuݪ֯LxPg0>(sѭT3[odDsuvhՐ*Jv.s,l:6>ξnLN4h" ,k(l> BppFf]|qC 7uVSx@ D!ZU+~o 5 d T$bOtˮ2)zU$A|e/5/~/^H#9;j`[:i4_ 2eP$It@\_5O޼Ҳl.1eĴga鉿e>Maj'*zx7C(S75;_x w싶 VMM*mt+1.q|L.}̖eV )hIhCԝyvCVlGNFƨ:< Lg0 kcWo |ȗ>^m2@t>0b$=2;s٤QR,?CS̈*viMYl"x}7zI)gYηY\g̼~;Yy7-#%k!!UNj߱Tj+y¬sãEED \o`jd/j"Ylqblcpt=i,Rkg*Y+Cc+l%vZlF5gW$ѵ]=p28=Re/v' 0ܝhfkb߱zy8&Y ĎY%ذ^ pkG* o84vupS:n@R*iPЗtuci A!yV{oLGs*%Hr(h`ZyёQ) BU\ht }0D)iЄhٿ' "i[{U}Lrմ@h(z{".8iP!H-t~ "j.;UŚ2 P`@xCtdAc4} tS2A4CuXM.NJ+@c<КA5|0Fu߉-g+r?GEA7WłimΦ&څoIbkԡ6ȍ11l*cY [fiA.W^A{Ȇ#KUGl}uK!Rh?g;h!-ԥp_RԵh՜nbԩӁ&E@[TeAL?}!@8_ŔwUq׿qq[\:~Ϙ!>SZb$s>k޼vɘc:@)v*D>ppW_e(?m껄yOlBs95NUE7|jSPSf]$Z($%M!&9ϲ⻣$'d- |gJbސN<0z/ d$\"E"^ӝwdTW ~b5R7Ulp0nь|\HQ. u݋=W}`3w@uꨦ&cL> u)dnv8 v>q\BߌSkK[*=ŦQ~JuI LU fxn㝉1ynm)]8qN_˻T 5\+0r +:5?7R=TĤ)!3;Zɳ1!]c5Nd`e}J!E=u`, y޳? /=8۹8?e19wVHp;wtG{8y) &ȅW(ڼ;T1R܇d، Dr՝PjTj7ǫyw)K{{(ٚƱ=NM0e: B)ǏȞEhA>*ěF{3Q:t@u9]L_'ù ZLJQ3WG #5q&xY,lz\.o&$ <С<2eMcisi.6MKfE]I3u1PCzWJkMU7wԯgd ׭!:3vFL.hBDwAJIqERU( 듢p0Q&PW`8.^d^[?'oOGhXc"*Tv bDXyҕt}biEYe7} n~|V흲1vG8OpDéN#I-SyY*|\a⤬$[UKSlym LMli@>%fEh"6\"eLn c|u7U] 9-LW5hiqS5WVZѵ))/A+`wnfx.*CUĦU @ pѡV*,CaH=$(!Ͳ^l뚠1`(!mWSpmd]Ip Ӿ"S"jk! bmmNc"~%O=e3V\Z^5̞ g]dQM.b ,>¡X]8{N<=c1V7n8p7tS[ur?Þ6@\VkNazIN"?ƊvӧW *-y俤I4L}S.H%myyR"ԇ7); !_)1؊&c8'Ws@rB"rW@,,uO$6  K-!HUƠ ]us]aTlw E**@!F^ =)w Al5<KYJO- VP[w ] /z)=cO_DࡷTo}ReUSdjb>={,ee/,Vep42;󕶮Ğ0q7>GnFYLwRb.8U#WIjG4#A:. >׺l`F.Gke-[j&@`#|rĎz $DПJii/ԡĘDоSp+o#a@>[I^k H/bXWm%oh5>ؕEv imtRsh$K9=0#TdiymH*Ǣ=`P?E+ `7B3SG/ZH9?I⶯|j#jGS2KBn\_|Re0 1i14* 0)Y6!@=azuesiV4+ݴ`*3\c:^ګ_>~yn5e+ OW>:PqBvG~lDWЁM+P3XIM:I,khz@UMW[X"qH:R.t۶SKqeo+Jq]Ž}AQƋUc}Z x<󜯂oFpRҶq(fq#\ǬӻDXX$XLVgW*< i(.tQf7pLj-Ç 2$r A:Wnzz]2^.ay7E;@æ#uS3x^1!a @sZdh*=~Ч~=)EwI>22W8~]dxN&FS&WFj4X^.{)q2Fu3 7s՛\[98\ѴrobR1 hBRF%*K Tqxad VE |]X e rN һCUY&s1+pOy?'|tzE[ꚡ 0%CZmyMR͠i\؟jNdXoBfJ**L? M>$ =P NuqX3ot]zA6aȸ)?M{ߜLta:|83 Bd#BBG@,:nub70PcuY% c;f7%eʐ/qVMlZXTl G湥#\z㐫U6Yo3ESu5EJKf/$P NȎϫq@i->KR01OD-ԢDS] \Xtߓ_łR߾~_TsQH0kZm,7&C>SP,O]r yg Om"7܉{0v D L](*jsχH57ިW/\5W2>⵿W8PF߾^aīɀcGӠF߈>ˈ  )@R D\ʤ-}hף)vaºoeZ?$=3Ux+{VgQ{{ ˛njNTnAѤC#A羠Ơ|WFTu2W3NcS:,:C|X`ǪߘV0YsS'Z<kưպu ws|9} :Hb@jI ζ&;4%j\| gkoQNAZWVd\*SlV}8sLђF|k0à}gfpXÇ ssQi =YAU.kǹ#)t Xrhgn ȩ-Z]_7 f Y1w PTpAsܚ&"+l_y;??ġZM[/UȈcuTXC\ij y&M˝~)(4, "_eLNOnT}Nԝ؂i|J͞1=:N^37ɹVjDb{zȖscO@сeW߀,Cy s)ikOma q.Pj( K6n DM[C}.`&31`06jyʧ>!Rt#^ifz-K ̳]@05rÏ. d"plEL ɱl]x(ZH+qHo:_U5b| wgʅbTf/I޼3=_8I*ա ]e wl#4ofm2T.n̝ځHz^-B eĞf;VQ(al[d=^.ϰ A[i?B:_]|\r=vNvrȭ7+ԻF π'>cn F!ӱ m2^λ" tx&eg7$) SA2<#\?UË*Эߩj#U⟋R^]k ^ޢ矿2!7࿰ %[68ۈnEaap'e;<;U'~~6y# XPwh 6]~nZ_= x2nb뚯JY=lRJ܆ʳPs:%5 y." FbTa*!tj%aӂ78egq-%  9va(D#S:ˇWmGI[<\MDqÅ΃- TB9G=;vKd̴φUNؼs|f/@`"J]!")9O@wB A^=0WG]qiC{{ۀkq?X hm\ȼځ8gm rvP;f,CE畃%HBmdc2ޗ*DIF9:/hr^e~oDh'#Xxj#+jVAJm!˦iUA~W #}FktPɧ@7v/_MXA+ȩA(ۖ 9Ir>L oz۳$fKǴ@jDJKբlS㑍DmzݚÊ?C 8W hL8I Hku0dCiЪW.0a h#ji6L+*y̸VЕFfJנ鐂ٚCia ֹMةk-MblP](ʐAsd Rqqgt-ͼN[Vʷ`oPYOL"o8ܗH N?2p/aXL/2&6"Ltdu9, U~υ/ ''?A{7LbrNidН UV:}ٲ*e&##}{j{ C $J=.癹 M!`Ћ-z%hc ,ifS`EŕLƈ/Jie(vIj85F&:E* p$L5|Jiu6A9CUSg(3Nc NL]fn+r>#=8Fq@L>I4Qi]Eur=OۛϦ3a?frC솏oPNUm;C;+duSnRyM"/Yu2bGR`h-Z0GK傆!sń8riNc &ct맜A}I\, i 㖈md ܫS({ئͥp!&] 6@ 2e~})؛#ta|mjEmYM'-i`4SU=PCɔ)hj=E(!fBy&5aw##Y(d.4=e - YK$l^C֍)KJ%!6_܋<!+,Z׻uN+[ok nU~%=Tmj_g^WU.[<;k>L`x: 5 m!{Uu| :eXlxC<疟,V+RQ;b]#]ߑͦ~ ;_9ʿnyk&@6FvHt.  >N3S=g|][O`n@JZ[LOE\z^OtJH]I8PJ~ s3~0Cmw5b[2Ȣ6RFC@k|lS@w6AZE-TS[)$V_!J*99MœHeE!ccǓVV}V&Hg e%ӥ!-jcmŽ'8&J X B-F#1 %dZ`H7,b] b 'jTB+b%C ?HOO88!?4o=ҥb^L"B#IP,J heN |wBmUI.K G<B.Ǿ`eԭes<zzh8vkETxVd@)RДK2vi'6ZAY0 ]DkVwig"ETQh .IHܴu2uդ2bҦV[Ӓ}3-@0Кm] W&l_e%qh[q5n cqrNu/Z!(:.ImlτӖ YRqW^ sbiH| (}4GSf$vG_#d\,rMr/*KdVC9v "ʹVDJ dV.Viࡾ2kj/K*bikyiW @@, B 3/ E=s2nWI8"/_ xV(LH϶;Ja%FhtzR&X`VR0$maYl~<\Ϣ; Wc窠k;+T8efCV.vw-~?٪R+Xzg\w"HnPbWr%zVDla6DvCǸ.ZŹRƤw=͊,"3<~v!CmJTHP3Я ;&.9RRqb]6޵"$?`ʔ55LH#zSQΓ3X="Ղ~x^@D-lza3u ļmJ%;"\?%s'ڢ$l#9BZڃKz]-mva3yIN R707prrG# K8:BhFڮ5lPNxZ!8ގ0Jn/ VP95ʫ ސ LoeB_A7v*@) +t$!?mc/iS$<ԟg[8'ҎFN'\ZLQAV9g%aqb K=I++1Ϯ,K_KF}Rf:0=!Nəw-WWz#]qz^ns[ȻL1&WU$xjr3IWWB(6 H_ |`7qh:sݑڀ"5̄ N tŗ<0yǧjϳQXHaeM;Z)nQ'чM T˞j]>,Ɩ8cVeMHGxnhiS]$goI?C/ɪ9ʽݜ==HmKv1eNo[:PqCj+ڜA:9۫b<4XRP.FS೧o8[uRxHcC7f.ZJ)Qr  X,LzhA쐥 uZD A7f#a$ܬM$(;UK9Ί^)w(-VHy4_fi K_hyԅ5B`փ"l qg8I1W6g TܭS,#)KOg R(c}`˃7 8ʦᷬV/FNu`QRL; {ӈoa`(.sX"W(t U:Z5;E-bgG &o$VK}xtg4`2j{}:hbŋL)#D JӦ05LFIGx%R_خ]F8mni[(q6}Zr=5Xn8`:wҕdhFXh/ _%;9oJc)}/uJ#DNqz݁{JyF;`wzqBpgV)~QLK>t/D aI|'# %6ԬB AVz0Q8T>DzrGFݺ"%L̉M@rN2/r/rNdw|.+iFe2zY?1ܩc$6ީȑ:k U] y;wߞ؞i[] ~xq(*Wvpa蝀 'F?< )dqPȘ횿{B`^8sYw{> 8XQ'- UI!"P|Q!g+;9(**Bgcj7N,wLX e5] + Lȿ+VCqIJ}H/?єwKFoȕZ.!CT[E28)EQ|wqG?qs]aH'\4{V9e&'C.,Cv|s/t l )e(ʙf5W'!nҽ1t(\!n{1spBU\='fj #};Xh57R#wk&](>! #s`뀫N'1esȕ('r&uwaoE O&V&LHl[&bT&(,*:Z^C3h4ךرnHmQ|5۔\o c kп>|ժ}$EAx2JJSOԴ(#dOgs'g{\+C{Ar8hA0՝eʾH۱_HZf-털q!/nX%' :ɸ_t MeߌUVZRud0MDu6Lzn=]?I>uWv cPW@t߬SF K\KtԝE^{>AXk֟yVwfP ߲}5cm0ޠ7MM U)T>޸>`]+;LlYZXʭ$Hf2Nsq;]S:Y9er•`e],2Pv m'=S h" .|>w :}>`, zS䭈J|iu#hx|YI*F y,+#;i(>%> 'Ȓbl"jDta̾'=:; w#*-iIGtsM|TSDd+W x!ڒQ!=ZY%GR$R5m"nɶo<@c¿_57ӗ oJM_aAN<}Jޖ  i[7so^H)6Ktma[{E36; B&s&A6N&AWFrȒN朾x \=GApu2dhY:1wK2>`y g5tS('$.iQK fp4AC֦XA.KR(lu*R .U#_K*S ZߧN@HG}wƍΥ1Mm\Iq\OtGn+2wiOd_(F$ZZqG1Q ,8dj=RɼvMI{~';)4uWwJP+Oˍ6;n2 =1xiٞº4ejɭ7SB̵?H *wi{Crڐ@Dy\Zg,LbȂ$Ћ"Rki356SSR|֝E/0n~h2*@E㭳#oajm>GH0@NV5O),6N_ߜxg:ͭ"}H>Rq{SY+ߤU#J-ұ5zN7:9)GU#.>?<|{raN/::pC]tBH[旑ܵZX`ڂ_"<;>H1wh`rȒoB@MvmD* Oȑ.e|˖ԩв5o+cu-U>v_Gpw Ps@x_J\(?CΦ_E2~݋/d# [TLфlI 7l HL~]2񄗜hF?xOO{\xB2ק&7R jv ౝ?-shEmHf e8HsPV`j0%E{2 9F&MafC^)V7'kCW26B]u`_^Ԭb CN!+=D*8͒w}Zs}L)e31edrɺd;xto;Q+BOtJQA]jB'?1+,4Qb7>`.-6P v&!d֛aPߓdw6{}P0>AʨTRnGKUijr*]ooiΪ&3eH(Ǥŭ3[ 7⹍Xx;*Z.ȗ<]4 pai^]lwL o[0lӿ~D)$mjzS1ՕM ,^$:(8KR 6,$ISK. yקkbIj~&G=pSMn q,Oo*jg+T5uNutrT0J_d`ݦUsc=XYjK)M? ENY嫎Q8uH)W})yu,J).䭈sVtO{\N= AFzR՝dmF^Y;.^z{ /Jjw !~vZ]9{,w^x\wܜ hٲYClJ<$:X|ƄG̋{G}+ þ'y(g ŜNؖqn'7]yqZ3|.f,Q|ו2v$<ɦpZ, 3 {UC!|aY:ELUKŪ(RX"ni|}AtSr\Vn]R̈h0nvzCMCk4H58Pytd]O ߇, >{(PK z7ڶ*9a뇚 ƔhE]m5h3/c-V3ݵ= jl13V گwX-S*mTڂj9h?>@StR۪Ov?n9ߦsZQ NVOv$k5ͼYj]^ IGU hOG{5^ޛOL Â4 p6šV LaR&} <r42KI?m 1xgQf:هx+ \)zy=ܢNev%ʿrSw!M|,%Uʹ5 2/tPYQ+ ; k <K`D e}g[j\6~`/F ךOd>83;%Mͦ^"h)>tCne; bb|wC#)SDxYˬ!WM۳KkJHN58t ^}H8ecD0=ƒ."EѤ]"Th~vr]~*h*&,J-\$ʃN⒯t'^|$:C^~m\X̖ɽ$ݧ} 4)͍W%u:SgSjۂX ro0&ZA?GN} ,<VB$!]EY:Q'G|R]uu6{Y6'y3D<U)X3y/U%д;8; { JbS>B3@."ԆќmagbY)1)o+`)z'664c|Du}KE.W,f:;_Ҩ*)n_"xΔ K-:,iqv c&~ށ$\nv~'sE~Qfl lt zM [,ou ({=TĝV, "*4Dk#}L96GFNnb\Ovϊ.X[hk`4I|WP%5Dƶa@ELx?< bL(_!!r`z#NXO]*D%&be;JQrwB3Φ Ymw[=`ƴЂy<>$Lf-s@k8f@ˡ/e5+O=(drlx$Aتs  wޟ YZ