sssd-kcm-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`fȎ ]mtZ`#$s+&u"11`0tPtWɰzXuޗ?O[l|_wF‘{lĴb 6dN kyFRRc8+..$Yl0ӜVH ԉ6KLI6TgrػS[Wl܈137j Րu#% l@x85]rb\v%"tGTD'1N47r\)cƖg/uTA*₩%ɐm>r()wf YS!6qdE++3?l*,5A=ͽ?AjrS},F9a[U|"Z|D(ؔ[3]m}1lN<.KF6Ƚ{r0P z ituc?T2|@X#2ͨ,EF@M!PhOc>pB?d   E $8U[`u         m     Vt @@ H@( 8 9:hn>?@G HD Ix XY\ ] ^ bd,e1f4l6tL u vw| x y3Csssd-kcm2.9.44.el8_10An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.f ord1-prod-x86build005.svc.aws.rockylinux.orgyKojiRockyGPLv3+infrastructure@rockylinux.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxi686 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%QxځAA큤A큤fffffffffffffacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479ad849cb78f8c043b6df7bd6e4c7ca4aa5035997737b97c42172c57d1bed76d011d4e6ddd66cf05cccf9dada545cb809b0736a634e2a901c61cfef05a62677694b888395d337632803d64fc9d7c468518e394ef6b839e04f2f20728fbe6d7736758e1777258fde4a90fb670ac693ff97c64f7e8dda137559fce46c1bb2b55bb9381e9a325854c644f3d0b0daed37ad2216b8490da2ce4d8ab33beb58ef164d41aacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-32)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.28)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcollection.so.4libcom_err.so.2libcrypto.so.1.1libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libini_config.so.5libk5crypto.so.3libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libldb.so.2libldb.so.2(LDB_0.9.10)libpcre2-8.so.0libpopt.so.0libpopt.so.0(LIBPOPT_0)libref_array.so.1librt.so.1libselinux.so.1libsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_iface.solibsss_sbus.solibsss_util.solibsystemd.so.0libsystemd.so.0(LIBSYSTEMD_209)libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtdb.so.1(TDB_1.2.1)libtevent.so.0libtevent.so.0(TEVENT_0.15.0)libtevent.so.0(TEVENT_0.9.9)libunistring.so.2libuuid.so.1libuuid.so.1(UUID_1.0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.4-4.el8_101.18.2-113.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.4-4.el8_102.9.4-4.el8_102.9.4-4.el8_10 kcm_default_ccache.build-id45526602bbc8a61a3764f903d4e3aad908e4e5casssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/45//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnuASCII textdirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=45526602bbc8a61a3764f903d4e3aad908e4e5ca, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)3R0R,R6R RRRRR R RR RRR R RR.R2R3RRRRR5R*R"RRR#R/RRRR!RR$R&R%RR'R+R(R)RR1R-RR4RR:utf-894815bbb7c3d75533954e79197b868a941794ec5ab4efed0b7bbb7dc7d91a011?7zXZ !#,-] b2u Q{LYZ!\PVj$C>Y `Oa[4r'?Q@XJ/k1qR!لѹRʋ05aHoݚf2 aS~ `v@LfFPLjᴴQ(< x`+Y89y,h'Ӭo*a2啗ܽtdH\գJZ2C}k8(QjIjYs\B:B92 -b8D|Jqwѹ_'o0TBDVT`qҿUPt~^Ue ?6 <-0-S;q@oR#ߗIbg.LO&%x,]ɜv`pw!p|γBAжz[dfo6 p)*Ii\o9ݰGj$e'͓6m-jk/:ݶaFVW-P0[#Ii໳37%gpVPEh)24#1ve}CW췗j!xd1F5}Z半Z66rAbJĤe{Na 󫒊JKpl4nPqVjڙ8+ Z=pXj0Ϫ~]wWS v"墝yfsr2jOJ$C8R+L酣xˍ;bjAtc`鴵VsH^;2f"p_G-Q^YCyO N,7/ -M8rwfǟ5\ԇ 0{HNۜL ),r fPWl"P!gN[cc6f/y!l\sHc/ɺBYZC$Cί@nuҥyy6iݓ9nWV\d 2倊5iy݄|1N;I:c$+c9yBN2wlӥh 7bHcb쵱,pb$a]૤ȰX a kzb$^ʽYyAM NH{&acH IĕA(4rR!$0?S֞+.oݖZ8)7 ~IE)4伆?_OiX7E^彬b2aqZ6ūTA,ropVoaA_ O?Dye[dm`/}߃]W /H'JoRhQՎ0=wϝ M,L͙)=z̶' NUL*;VHڅwiKVȎvg$~)Za(LpXt(kk`jB9ϖ*SPilt1 l=OIVaB1rRh;"r]v4S{J> UZf" S5Z { 6pE>5RE(Ǡ$uSD.!tߒ& 1I{wꏾ^|%DqŘSU)]6I ʮ'w G97-.BMw**Ul6nie /&6KYжn/W8Ya\x=FmȘr'tZ1҆?j˸ ;N\6\zK[©teB:]ߵ(ƖV|Y?o+znJAҬo/|Bx60#zx гFX]y+V[t%X[U: KMi qQ. wG൤4|;:Lc FsF})Etw`-T(/3)//pQNF9wshlKU+6BqTc)f;e\ xɎY#&xloIOLr].¢{{l:FN JoA$?av iVЬoү^+է\ڢȇAo&}RhNVm4lzI$ު) g}P0*SA"_ HqP׵c}g?x%NlxuD֡C|SVP(N1ׄ@4`u5AYDN+si+)dLxQK5kBP)86BXĖwzDФf'0ӿ@YW`c.u0?{b5z쓺KD** SK7%Nq]:K.mF?A_21Obso@[ uEA{ #Qua![$oWCN/gXi_Toz= KCI '+k3ul"z.IB z~4[|Ц@،;/U/̮0Q}x] Q /< z{>c؄J,=Wg1#ˎCMqu4KEy Jz7Ӯ19yW.=&][TZ#3Vd+UZ-=CYЙOD7TAu>%saYMzXm?ZJ\ݬ[7xW6,06owQT598m\ns.ILRzvKsJꭳ}HUU.7{y"peYjkY"9<_[cG?ͼ a+_(CCzYҷVI?GW˘u$ La}j! є] 7P ۉQTMlP PL8&*mIkŝ_p;68XQ[n-|'Yn\48 i op9)œLi^RlҔp4VZs·y1nV'A\q1E/) TA0/U1},bM4b5Iy`\?  g%c%Gb,C''> t<@t|\̲X2ŬB@4qDwؔPܥd GYB6"}zNjv,`u|9<"/2; =Z,mFin͋=JGj+X,s# 1`: f91!"D+RQի15:}uUP9vRߋ6ۯ_MC(KɶcJ ;(N'5+sJT3QbPO>[@ExoOev"2UrWCX^^~-w|MbGcu@[]qvwC5\fsJͱ!{6UboxfbO`sY9t09pnGN3z>$wV1U{zfd?Yg yBuwÉU<3!jezGw7E襵Jy!/`yuIʫ)kb#mF[k$) \ |7s)8oos+s C4TT1? (;2Ҋ6 cR mKcXKGy6VmGqŽH O؅@R0&@ttTVۅ'M?#pUFmÌPAa}ʙ.H7T&Ō@r+>ue1~5s86*͑pAGM*vSkl<  Vݣ=1OX (HA4?w)ݖ6 _8dR-2ǩ_}ʤmƖE~vdL Dt77>4%Igz lHe]@|^"0_W.$Gx0Tmmv(X;(^U6۠D.mcV<xT>idy/sHtH>y`(fڎY껔78(}PJ3}㣦hY;L\y<,rrCCtyy#^3tux?"u}BʛH9ݘ@aɋ܎#,o&yPi(Aϊ 9]F`0(%k:Vib oR!v4 ^̜ {8<%t{vSzwbKwF V*oX#+Y&OM~BCg%0On!d7RyFҐ9>gLDkFSS N<Z{(J0Aӓ_Pߏ9R-x1 ?6Mըk(m*g^nmVb:) NIHsPN@~l/fI"2C`v~ yN%Q/ӁkX ߖ^uf*CQ>2Φ&{ۦ ~k 8x̃^D5AL8G& e8G,mݷ}MH)/*[og#:u8h@S77-˜^Bt7e4gp>~͑مJ .d^7p.nRA'/g\rY|v(yZO!YsAuD`+=]6x!k WCL>Mj_ÕUn(m 7EӸV>T[]7wa%5$Sk/&>q'Ҁ ȳ.=Ve(t arʁaYf1GRڝn~5#Ӳ'@Zt YXPhٓ7~_ӓ^?w&FW+g:2CQKJH9.~hDNxA L>X?pG{Zi7M7Ar2sUm-C@TqYH'B`fQ.F^qwM}vU㸆3Ov̤En|$RKIe+T~0ư1߲"7Y+ E<L %l4M$ܚr㑳?~QXg>H{PEAG*jWx?jc ^k8b,Bf֚cɗJ -oJ>lB tXy)QCޯSc}`lQޜϿHk_w{wQc{Tji#я.:YEW9 srnaBoѤæ1{AR&[1hCTs,SIիBӛa4W禴be4PcG?`^1;?4Xbح_+Ic3aktx63r uVjY e:ZZdc6 B%#.&пE { ^kƖGآ />,al=n`nELLqDEZ $=WRʼcH? AD }%8ebx1Bznyh1/7) mHѕY2 1Uisœnu!Qe[qtE;~^訲xh%k|%hct+ȶ*S⛛Ϯb̬s,.bb' ys<ޤ߱y%ATD~_9-]z+mlN)YdR{q~%-솽iH?FeIޢl3~8IMHDv=e|x!@HEvV@ݬ Q8 4ذ5Μ|Hˍ͒OhuJgt+7_zP[(:["F&юN'`NFn3qt(\@4Zh32]F%OC ӜV5KG*򻺉 8ja iHa,Xo8}oE@g4Sw`՞vO^.1>k`r TJ!HKW9;@# sl眢B,2N$IIn\<%Vv mA΀ÁWϡϋ}d@1 ) ;~jDW0W~+gD7 Mi;CH#u?J̔M'6lo Ћ\{0+i[86#"Dx,2̆o#@tAE)L;$3kh"o 4&*`v9f}amf>elcP,@snJu],d0円Y3㏥j%95q.߬4 t,haE⭏2_ ⧥PAJ?N 9SI9qv,'Rb, =VQ'e;rL'@BW[3 l/O9xv>@|ñ cqE @aۤrlWLJ]fzh.X">|L;Tz9Qmb~0 (M8G+{erˍ#*WQ1Mn\A1':,m\T^[`A#$DM2HA!u'_6T}1+ džaoC<)aPh5GQnS\% 7g~0af4̴t&/&EU[ؐjn4+~;G)-ua!'s ۞pMI!D.c a`91AH0W78 `` o\Eپ4_1^,u(UqU,i3 xwGu6yy>^e8rSpw/xE­{[$'XfF~S? Sw ֫״J!2g< do]"8().=Xo W'ɔ;C^ ||݇7{LqJ{c2yL{b:ʗM E?2o];Z%FEoXafxQޒm> r>!ۮcDk_O}p2>NUQ[$@4 *ه {)ȷ\Ó˫uW]kKm=KF׼=ʨa4L)eTl!w$dF)sgH嬲oR"8.~]BcJE yzٛW(+Yz9^ Ә" }]94#Y̢2ᯎD7fp0 pLJR&w!k~5KH.rޤUSm,b*%%߻ړD A'tB Ju;~Au^] ^ f {{; q'el2?sAkh1=:RI{Ύ`0P3 ZTBtD&>SmNeaD,#4O/|Uwx^GphzMSUo]sG-6c>mQ0N@=Ⰰh,f_%3i5-U 1c BdSHOt]7F;W$O8a]slqddGAtl&ǓJ|lP68wEN Fȟc:U Dq5L׮-% 7PoDRO9yL 6݃G;$7!TaO`hYxxS lFj;\LAc6 o!RR Q,'އ ɫޞL+9bD?{L\yٟE ul{vbDQfvi}rHu2 M[>쉇Ask+w gـӔ{yJNYfi Zot!NkdVpD$Fr`쎉>o"$em'"8)S 0[-)c.1YXf@v [&nrɴ dGCzhĢcbXZkPŁ98=Q5gB:`jp\яJ_Hlʪ@2 L&kk -i' "!^ocxyb6ECKQ[d Cx(vLwD 1(gMEʶ=@hFh*zM#nWKCAoJ#<:7vV%s v,?`]RuȲ67 3P~ zgU\>DJeH<=Ѭ'"k'yj6 Υ&ABpt-#|W0C|Ca1 u9RdnIH{x UX0L $V)FpEX)%)vT4,Wy7:>$9H\rx&wCv[wHr`!Gbĩ/ӶBdxT"%T3`W;>h%,a9^LhUέC|Aa G6+&$.11CC`^=d~IZd0gۇR9\  L=*o zﮎfH%;ti0RwoE>_E}ΕwpwN{zkv6cId̹%K}\v[uZ-!:ff$bI*I< {U|ɏSVc` $t-eHT KW j.V̡ۡ j5*Ӆ{68ɆI2W{Wם WP4p1ipJ}>gF#둍͒4fteÑ ^2\qɞ`%Cni!9<IؒՓülS2ys4Hƿ`QnaLFazIYuTw+%seO \<9}9LEp hlD6c#= )F6IgǬĩBȟL (ӌOd d|1QVE%!fh8D@ 9Цjj?`wK6nQkmrQE֛* |sVǨm˲tPJJL^PqğW>N0 ViCiKW6V|Ov\õ1t$3P` ܝGZ gO+^]~=H*CM~dϣp!N;{ pu!OzxrW;Z|";V=yi"k0iPb\$A9h u= vqe.Ҍz/08E* < hЦ%p#G6f1t~~,u3^HYYd! yA-`KA?ԑ6{QPXzgUze[z ㄃4d(T3,pc'2G}Y WTHRYX1'D BPb)8\ɆXin Y_Kҫ4z^>V_#y $k<;fޱ7` Lb$%4@,szUC 9MByPG|ĴkX,-K2Ҝι;Oʨk๛!4v!g͆8̵W9|, iSg_ߩoVT? K*4: 2Qb2 T^R#Fu81V-?U\!mŤT; tKױ1)[ [N|ރ$\IT\"Ti>BY>#ht[ UMp[<9EEZ[s /JzC1㌰+ #E'"Di1Wfi R=Eԉ8X|=~'WoȵٝtbV˂IXt7!b-̦W'ŀo+>ȗW*}?‡3qdf!0 aAԪ+j@J~P8եԝ!_7Ei,ݎ6šz0 W ',5' ] K^1~h,=(o!`C 8/zE|Ap61+[YX50]D.\Æ#DdhꩭnVk_vr%}0*koh5o#}0OFnCRxgT,YuZ NehI\zQyqFöqr ~JBBD c6Nge1 E2ӝo ZG{,_{hx11kl; d-AQmJ, FCdC2c~@kAVIW!*uC.TŐZfIU0?.Zf2/QSN; ӌpE25VElzۄ ($r;K|u| l!i"0ߓYX١P/&_ Xu"5BUAn/!F#Q^8l]6XԒ fg< qd=\-0_.Ԍ]cU8A7k+20㥵s^V7()4hrܤcK|V;pˢV.Hl0y~I6{$|m@,bA췲EVj(1B a|n-*Or#Tv 3nA5e,HJg&;m!&;ğfvM@Jy9MR1y-bM[U8!Gc&63(16)0z_s t?J|D:vp)$tOEDm&ʜtԡ%9yMÕ;P|>¥u߱qІM;R`;4`w_ȞSzgOvN][+ԬrImJ?-4=Dcڨʻ]ԯmiKOͧ1]Nk%ѵnc}c栀ܼQzX)NҺ͒Py0mEcPƸ (}Uza)~eh*L&:x6Vwm6s#9-' z)3pYšT̼w#( nCmtZjF7=8$qꟗ׈''Xdpc^ƹI1Ct 9PP…s/kЯf#I@#X8/lrok2o SQ L<`m/"5R;Uv/0/ſHW؏ 6OEhŞHstYGx[kkZDӰrae6>{.gWA [ޮ3V=q<<7qZĠ|s"u \#~> DӿcStYOq`Y╈Y<w,X {0-:Q_0WgKx)w~9PML@s/-TCm'G-L.B_DѶXH}'~P,N܉A0!y!z rqJEf?[Icw#i.})0z"sa3zJ_͕N I h&孔,xw3L1'j#7TVb:d%lG(cdM=qe@$ݝ.\*(ewD#tV^MWu%HJ^jZ@8dԯGu>n W<:y8I f)@v&MrhH[-^궺=̷>qdnU餉Ueƿ]U8۴Nm仵__Jd( 1$]]f t㾏sHt+߲=V|flℌ~M0p}+|'dCFay덭$0?gN>nk^MrMsP,NM?uć^!7okP|bY??~3-@$>QHr;:Cw a2% d~O:fr.]saQ) mBT6YB}zQ#+i۞0wi\4UJ"S1jG3m?i:aiذt[Q#23ME4i3qUߞ`'VIۃ'[B˯ RSZ;KPy7`I{sf7Bnq, Bٯ\UMK%7\C>i%iC#稶ԫjG1҃ uopĜ#z30숺66Tj%%] %ĭ2":)'=c'-_t'1MA9F$zO3rpKƬy5&&Q}BxtC|nY'^pY{Xs):M~?P`NCa.:x3*`[,_4Ww ׻!(K]!)y4T3)g\)I(/a@?lg:|T0s;-;>}QgrxCX9a+@\Cgrq4&v(c6,ڋ¢cFy 2%L`\_`xehS&2_Y!4~zG -z hX5gW]H\|jvʼ-@92FY'N׌X 6sr/@QAE6*@tM3<$tK~4!$QYA5:ߵ.3[7 ,1iH-$X˴)]2iqЎͯ-AIp`U]K_21U頢ZhH.f' I0)?i"̗%2e{.Џ*`F0gh5~J\as޺ :+*7x]1te5/|1<&wA-u4ɮᣍ]?Z ǜ( xa[L]=__;0bcL[&p*MPTg~SFqNAd8255] ţaԚaJy2nsX5zRhy~0qԍ ;zS%|am!3Go#h-w󰄆/y6^ HB5+'_12-L%* =5z|4I)l0f`(ZLTZ3F2׃78^V3`$zc*)n3yӀ'&˸5 f^9ql7vNpC :pÆ }&vBWzo$'{'~a" vB6 P&"eT#V.ى fFV%cQ'G$!lHsYÛw\8m'ؗh˂ *Gj*D+@SNߋ]z̩Vx;)j: E;I,xAIA!&ɾ'U5 ~G@9(64QiGnV+lI<<#xJ/)bu?BcVqJ7V՜\}9F}4&fM?̶tAܹ` RH¡YP$ ` ]VNlF-l~\p8޽#5Tf4x]HZεJJv DTLjٺ>[r.+Y h8/Xe;,]\FgI509od Adӧ3`e"a'-wgy@Ñ;=p_2Xν+u3ҭ.p7f"ySvcYV"l=tAAg BnCc^jجO@{Ft쓶'kq'A"P8퟾:TZ%`t#}oXZ;I?4t |ODcM;?.,&DV=V UĊ,@ܹ ߕػGKI)Ը\Gr4htlgCAFo-TRphqܛٔDqJܱ{ f-Ad Z_ǯ@ɷw h0<(FEїekRf W* ]GA_ll>@],A\ yw99 6D,D\VjLVbQ2m7"prV~ቼd%i8}5j>Ϗ'G=<|ܱy$6ōpCU kzY=rLohn5o̫9~s,4eL3潢vss~O&Tn9 OIJǘIt6lZ#(Y,ESjQQ;@UE!#EH,\+)L1u!ܼk3Z\ 4,Vàd$at R H 9819(TBꤷq.&opm%jW%(nx/4jm?xu!J(,$&ӈj&g ;a}%{'CnDnW39t|3o wR.w,?5ѪD)[ߘcr Rg\9!#(n?[yGгEp]Xϔ:Qڨ_1I#MIY0+d2=Se'vDneLkIi݋xI,r*(z4c|J3-=}vY.͛s1;ͯDt%;xK1+11lx9TŮp]eu5Av0wJsq{úV3ev~T5cjS8!nq1&R'H+X꼙] iqg {Z/E}OR: KHO6(dpJ˄H=lI6m)!);Bǵ~¡&(_O: D>ʜ21) +(/99|2H9ÔA Oыk>źIKei)洴7r,D_GE%}OY0mm-y6Bܟ﨎DkOCjr;H&F" g5 jU~o~K?*IbPK\)e%48J '9\V q@ N\l//n֗=ca{6<9fs_.lieֻ,^0wύZ3,e_i#`,0+o6~/D#xHꦄβ6{DmSewӃ6a;k(HyLnaν7m`Y<jU$sIT71~mSȢ<ݥ؍bqDRA(./Nָ:^Jxf Y:O`9^ 85lJHO^+ x}/VE,owY8+ϵ)-?V,da҃ ˵[ sPW,T8UK 7 Hnj !QNrp nVBHuo^e/8A,7[) '^LNA{3`[ç56hgNwtʰ!b*|rPnQ3/96dA+Dٳx?wXS?o,Rhɏ"¡cSΔ6Zv1sgQVr|yn6Ez}eR!銺jx#D6@mNg5_O /3K̹xo𷔭:nbZ^ )[- /$qd. 6Qc^ ȸ.멳> ^E1 b^R3oJHDz0‘0a>{>ӶNzA VﷲK)٨.TP8|Û"};e e:+ԏdzΩTxg  rz̥2|^Ƥ`E3/GF8+^r Y# z[ b+UnI묨EU/3]0cχǦIb[n%GMaNT z.z,%Qq bRO~ii'x6cU_ u/k[ /s-L|olϯJhoUU%Q!+ba%}f0'eVȫ&k-6GҀzVIJ[6%pfUkht&l ^#k9IML<%ѦN6N߃?@YV& I!"ǖt=C3j UV@k l`)?,Aꊍ'ҦVRRo?]RګIJFvEѵ7A!eh&Vn}b4'xP d)h* ˧`f ΄ T* wՉsgjv>nWaJ˸˨' y+*t܃ÏYw'EuwM*V߇yrJY+Fw+GWnT[r LJ^P} eX~CB^{C܅Aڛa]z8-]EfCXE_JPKM޿&O gjUnf1@`Gދ\VMknjLj*1J ?jw̾k-qb@62_S5mSE&ʖ&!@ũw#ĀsQ@, ǡ07 %dwƽ͊܄`r1 ^ 5ȱkIǞ^mԶR-s2]6-EƁ(p % `ѥ@`krŅnjd Bkܽ283ܶ;$WlYu BgAu].Q҉ϸrгzi0%s>-g["ϼ$Lt`\%\@Oz5ƠvO7UӭH4^~N~+Ifd㒞_0rK wރE ȞQyͣUl 8)#ЯOA ,$UB1F^"ۃtaʦV/"HЦyoefWh"r<>+5Zn s/]-m.)\(&Lѵb&] $$C;z^yrf3Vrưˮs2hDhC2zg2=1ci~о_}/!'-g et?w`B,@3 V0Yovx&<_W=c$UtrJ4ſ<8б$3{ EijBw3yt q¬TDɀJs>-A7xg;) Q vCB5PD׸?FZㆂDyU9*(X_t([3z66|U)'ewF7&YG]簳0Mn֝D^_Nt tf>' % zS^]DZj47S_@g8?ʂmw?}PP؍ݔV$7q=Z סp7WΐrYK, lyN&Gs*av| edœAh@mTG9!Fr#:j( U`j * V,@&3h/D֌%X sytf;%?0"HYx45ۛ??qu"o<:ZU˴漺iɋyU| A I[tw\lLУiAu%cNPK+͌(d i /1fd w91ZoPbxS&O*=·!"_D `SFT# S]g}:"Be{Zic$rāJ"R]9%uTy0Mn,r;#])}sF.9֑*(6Ylژ lU7;%82 ʅ[t9ߌ?[l<*FYFY_,,͒3ѷ?-l`QP5!kNO{3`nnyysY0oOOi%L>vIW͙va O4X hWX&O0*D2yz'J !5 g89Кo8SnD$E -rRA:g@n. u,uLS(i(zE-ϑ>4=aE7Dq?!11gU!p$EgnI4p.B&&\YW,',"X }B#U&ms{P$yjOV[R׊u*K._osG[^) &̰k˚.t:F%d'ԿpZ>~*E+`}-`YS࡭; c,\(3g Q-bhLSḵ3.j>c6!VbU2ir  ԏ]ZO'2IH 8c/["Ќ9$7v1&*!"JboP[8eTrTGO]5{يE^R=@І@Can~]7bniqD@;,v DpCQhfA? =VZD;:;#E /dq&mH**x/T.DSD Ͼ7$׊a%٦(줤2Q9--pEBS %SCʜ3:_%ܰqf)(}XSs5`KURr3xjc}!ZJ@>`\H ; }qH|/MXw V.* ńHN٦q';(EJ  L&1@_2^DAjy3+%DWi.1zH̘&Lv^?J%fƾu5ɉIl0{jB2K\ |TEkq -pĒ,5ڦ &S2ۅ ,te>kS}R/n=6݌bM[CNq*J8tDLi"j㇧00K?0gZcRFhYp$*9(tnp)Oۣ1. O(^ɠ-UsC,mwkIEcEǃCƭ,2Bv^lϜ/+܍26ҷ_j.",XkLʽyVqh--|#ly)Cv/DOŚLr^NiߚL5-Qo &2 Ѱɂ8&vLj0j{4{71Mʴ`R/" 1Z]fXv!abA'.OB\ȜP!&C+IZi]pbYJqȺf삕G E Ł0!l#ĀbUx㓂ON6݈ H^_9r!9"trynNEY}h$ IVuc ]f\` z|eSn:5zUIDPl\q:d<}fNHCj!SlPpn7E*8sx%HL樯uIh(slm`M ЕY},R'[K$&և6B+TveM&d$ s9B;Fl[ήuU֮\n;y}gΛ0 sc׸i&'V.v() n7X'yjĎ>.tViSn]ٰo!J<ȇ]՜K0qv֍s3 +z^\RfF%ZheFZUnHXlH|ԫ% e-@'*ec"ۧdԞЈ t@6f r(4J#Ic|'}Fu-pvT*B= v)\uHE ,f(V (MQȠibdYS#-獠8uV/|o42?BE鮛D1Ho.9./5bHpy/RQat9[EîҚ@Y7p]]MĮ㈣='RLa|/! #+将8h&Rf󜺟\4ho[fFe'T<65$AhL>i$[`zF{S虮excVOЩZx{;%#CLd#j}sr |BX+(]Ogd%ZE_Lo#|yL_z̀:,0bSn{ɭȟB5km] 6LhoY>u`g0R 4(!R7٫BoaX5K25X[u& HKdu'f!cH vcXtRߜy ^~Eu8o+|s~\E 4()$$} IߧޝU؍)~| ,r ¹2S0g e<r47L(Apf0[=Zm6_\"g.qZÐ Gw}ߣѩkY|K%0~18\B1.7L?&RU!%ibJL:[Lel7,eO@pZ,F{ IVͰ ֕`_& yɯe4kyq 8r[TaoxX#BcNlb!$:?t'z՘Nߧ/3n- ۉxyq 厭8˿b jM[ƒ,&Z*TTGڅ|aBbƹLbq2< =͈ʅ[/$$oʷu]r).M )K֓mU ږR4ϢͲk! 2Unji<%b4jA~YEvhd|C>;i _@l+zPų-true@AN4gnkM@vJ /Q)b2PV{ӷ4RZ.<񛯐՞·NuJ3〟R-]\lB25QK!>7peF1KKHr {!4ub+"Ff9hĝ@VouV> ¥Ʈ<-ڞH%~/+IL<3rwdQ!ֻSnƅŴBhu;P>*O6[qBJle zWM,|eЭ#@CÈ-I,7W& pJC|@bLQ| ~-ГTd1r?{(z& xk.+)-1: 9#:R0SKK-V9<< Ic>s*F -OLr.|&RZ* Xoi84S+%˿yIQםD br{&+;"}Dfl1:>j\ Pc^Я/" ^wю"3&,"vZ?X}́Z=zU-&WPxr`kqn^[ʖW!r[6DVN7.iGn'hh NjH5Mq:l>dtnE_`iRMYkDA`s[:Ƌ&&we5*^qӹz<%S}G.FM[lɐZd0 oȾT51͢94k<,z$_,$#o0|#3PPajx?OE"O\ƁEด;yas)~MGo><"sW )Gv"sI8K}CRh"S~x#qaD VXMǝu?!jly.) s B\E&TVn&5SZ}ҵ+ik.|38(AOL8($*5xdhg-`O0}63%?g7Ur4'u ⩧xt.@QplW1=)P? 8| R78@iy эTcjR;ㇴwxr F ɾ>4Voѝ<[}'JrNrJН$L|g~!㡥堅R4nGUs5Ei\6|{D{+oi$хF Lo9(W \@Nm|C}TMxt׶.[7keLYVP}T" )jv9)3Q[A{4>JCgkE/x_>s*R>;h y(ࣷ-\r}1Ty08;@H_u$h0pPjl4ezc 9䈮L9ĥՁ0V#IsO8ItB|GnE~}Ӵ;JCE2!WUmj{ݢQod6qM51|~:䊎ypUUջޖ{4Ꮼ MYgĬ" <>!a33ٟ=s[LͩVOTg/G{Y#΢JWn!UM c_Kf*9&H@!OW|R^\=j[*j9)+}wwQ&1&2A"eıjUȬF))|euܓ_ 3ފg/jA Owђ'tn~.J5T;#tw!O,tW/'X +6VD꒻m_!*\G5x /eFq]^9^]Ҷ8J 0m9ڝm EIA^ vV ZB7LtU7sq- 'f 睿I KH #n/ެGNjdCpL v[d eD쬨1k"μ:]H΅3\׾ j Z˫5F9W]KӨ߳$41Tf+e ƿ> Lq,Ȱh2tnW 'BHP 6E ŸLE>a'kQ>Q[0V?NbtzO`<5a/ 6H җK XLSsm%OdT-/ޫ̨rtե$\t磤Niipoٴb3EBVu;"6~ύ|BxRI*h\ s=J&cQGػNv ,|rqD@JiT纛oeBAFoy_+TvuVw}ԝJ(T&PDRD25x(]Kw2qRAڂA.J{Tؘ04%A}:3>a<52$,=2Ű40V &%E{#iϬ>_fb⍰lN,I-E#g*̔(E(T~]0Hed(%żkG't36K ޖ]8>TNE#\kںB1eNOhDiLyEKHu NP0"iX$!kϛ_~98WG ۟u04 @bgd`UِhLCptfpt6Te o(SmV}KPX&LR|x#Չˑ,aM_SArwП pn"fNlaMXdQ@A9\nGR:-1 z92x;uĆQm1t9*bߗFCITX*hFNMSI{gE!Êb(k=Ƿ * w%g]H/ nYHVhO}hOt/x_xa{^?=h0 RlDaq08=w 2TQ,6Y1䇉1 Vn^%X*YqƝуjp3ށ7!{sI)D|QXܵtxƫh#lCV=Tӟ so|by)jT*R#pz^;(,rUC:GsUz|*[Qphޖ}M8b7 yŜ5F?x5s3W7PqA|L \^ƀ9!F4% R0axiDr⏳[cYʡ˸##g}Ap%pJQc*dEGU(]Mx _dj=6,sIX8 ?DΟ}wkQpy)~(d,n1]줯 2!M%؍4ԍ?&Ψ{n&IJr>wN;^G?VL /eS3fJ(R [&3.TdWST}/iuTጢ TD(),r1k-o SDURzs,Kvl,p<ٰvVHءMzr;ю/zS&zoٶ?2箏f>4( =ς˘.VKbM/Hf#]N C_h?#GZL*Kz-2Uز6@nTW #4SL}Ƌ[D3D! kk{qOB^*db9$-^?[R& ḋql6w^iDSUCOK<h'%B^6gb]A'sw,T;']QUqF/ŧ)5H>ߕݕ o\A0bCjPgo M fuN9C5ꇐ-nV)RN S*u'0ZPSvr8٘TͲꘫ;í8N d@$ǵݒݘ~D15ȮJE sU2)B0kXY{Jm/)ђ,v!12d?1nfprZ U1/CeͳBV[McJkm~걐dgàKU>,,8v,_O>J󩄣}/ZΤh8) syfn D\Nݮ2u(q Iʗ쓱{z G1nRk ?up:!Y).UWbx8sMAHsN=+ZY&aͧmCn<lzV,G> h]<\dqb(Rx h66懹2’!O \s C9%U$4S ʒ{itB|#;syXnzsVUdkyğ-XhbQV6<[OTPK٦QRUQQr{84Zj͹;pZ>l'C g*-3whH߱|4ӺAUeFMK+8 `_'gOuE5Fۣ;^{  fQy%z A;Ԉ%5<)J}We5dm`j+P[z%$| !ŜGwkFX'Cgp9ͣAZrC$'Pt۬<+]jpRfD$HЌyN" Ek=Suo7#܂ H#&߀zk(SaDN2y[Dc + I|08JCIRmbJ$spF% ͐59 m~\ zP;=#Ě6}ţ;lB9{>QcQX6gxa0!:ED[*I T$5X*EY LTM$gxXó֓hKsC&,LfjV3uqP63hMa7ֿ;md$&_{qԊ=HퟡSeIŭH=ӏxjo'~I^s(eT^-O`W"sD#H ߐ79}8̀84iFgϬakedPlOm%!_ 11nHW_rĩꂲ2|/uNj^cPCnQ` V}+:c ̲_;24:fU]JGreʀ,L@ٱDsDH}e^Zȧ6B_XiK~V2ShJ~F0!s *M1@5 8*Ts 4iITKi;Էf(t0Ǝ]ln@P'}%^X[,-E(h{^d5[)TyOt(dqEu 0n(gT=2GN7ŕ^<=.\~Lx{l.pL Grj~)O}|:s4#DHquזH67pqnA~Iu7Ud)n?z</^+W^٘h–Լvu#\*V;xa ~X6rll9!xPJ+jeC Ì#cPkFfdtb: h-C3AFyDT5++E9߁Sͅcik=vf?wtl^(?La~Аy1VE%Z("RY970veR$$+QX+Vm"p*|1\K%"ϸ)j7:5YoZT'7HUF)2վꕃe?]5ƫ:|;uư] LAuDR_mykK򳗅 IA֣71lDR~dMGes4̋.?I8P0(+PNg ~Fo"o!L%7_ kRFYM5Z5g͝ CpKg\Ҥ-Qh+&󕯷w㲢P&!l(;tՓ֣ 'rE}w+̄H+xnASaJ1oP!(=DY'S\d2k.E9]_/2* ϗK]t4>A2F{P bꑹemK}РNb]֗ tL_Sea"qf bvj`)ws^ʻ[˞mK fBDTג ڔ$WW7VJ=dtЅ{ۅ$U඿[X7;n)TOY߆a6C_O1hoZ16mvy2$&?doHׇ#|.vS8KhPN1ZvU/;ͫI̮rZjYцY C*\/mfv# ?,Co[qU/o)wCb QbXypv>fSf IE{W;52d׭KOjfIz(|{0I:s|9ؾ?GZ! ̬n8.!w~k/2ki$(ʊ^IJ'J?:lbj8ui̺JСZpjH*tn_JG2%bN1M=83 xY9J/he[&PmI?7%Vѡ$7*΂Ql ÀGYS i ;Sy6}\IQApjT *XDJ]-w 5o1PH0V=¨C1 ݈|+2RY#U=}y`yǦ~}IB__ɮ%4R'vk}WLx:N)1["1?D.vPXv ʦWU1.iTa|ZU5U8ɿ\b7M 2VM|Y̘7 tS){:?;Nm;ĸ]f}:K)17+ hpD w[* =.O5)v!٥/*PAUact5#!:4,~b=mG2HjVޅGpO 4 قRvﳳZ~r}#"`>;Y &Ss6;P4^>ꚑ}w5m2Ę  Z$|ˤ`~LKV$3>&D@huO8z0bp*x!TsN$3)rWc3u`* X?j^ńg`ؖ p枡Fh^a'ybPi9yʫtʫjeNfdM  kO73 Zr.w@>Ge5&-~۫t$>PBH $hҟoˆ笿$UH lg;j 5=(׿AVҨ|;[@7~P2vZ\*M8JETi칺]2o#2` ̟n>i4GƿQ :'$,p=vDR Vʼ;ZQ+H)16Z_C.K=sD"zG,~qvW PڴcxڬaHS$ؐIԢR{أZT07!6wWfX/\v"_3X=@X]ip $B Aҭ&z4t1(;-ׄfBbOn$Lq K8ݢ:lFJötTZʁ>+oU \+d<6mj!2 0W %zt#hFr܂ '}$p:Dݩ#qHS3_I@ۋbSv|xWaFr±3Uέ*X2夐 {~4-k0g?)PE>iB7Pղԝ0t᛻'Nv= @TX&NctIOi,Ahj'^Th|M&?l ^V+3|&ȸO yx1RM״3w?9f*߄ K[Y{!]N  $2ڔ6.Pʗ5%ݳ\7̻ P6~y ¢i 񠝤OA|NlH\Ysae Tp·7`#Ve"áHL }!c:a my91~UwO"rH%1[{+/kcNޜwv%w67}d39][.H NŵʬU1/[?BC'O+IۗiMwkH4#놃V@s.Ŧѧ |?$`$=- rL%@($VC}_*|CXbFz3s$b$0Y`Oj~̅F|Gg9rU eT`Tä3bLv}7>T-PM1? v[_c>$V|x~^뎊,uZ=W^f9pfq.Yjbaa[P^$jGSy ;Q7XC͹\4smiZZV)?`js]O{CJ6SzPYr+|wmPȹVOn'_-ʓi@Lp3a\~ViNT'Nސ`D !j3eI6<ZmyJRXG5)W:z|dŸ ,vs^|PbKOpdHr*8֍8m Dzp<=mҒD!eϛQ[ d}ٮ T#a^́DqAYESGi@XAȣ`X(k<~t\'_vdSQ͉p'zg}ehd2v. P7$^ewɹۖ΄ ,?3wNAi 8Uhp*3V"܇? 7D16M6NkDɇzk͍j KmˮjNT 9kcs9v>nJ^K5d!qya\HtMdo]=F0VPMBIZJUHJbIԁ`quE% o8H{ʿ IlUpoў]6qs'JS;ҰT:VJ,I0&7Ȃ>Fi/س]|ۈ61 W1MadN<>MQZrs`_ST-\ 6U3[%m`GV} t H:.7N7(Cpwb P1 g2!;iĚqN{"iv Iܒ3"~Ǘe !o%^ЩPN`Umߠn t>0UlWV?Aj?<[?ML+bZZ|0@W_5rf:Gj%d8^UƣuJs"wzvi>8\Kq^&G P2(REP6\A 0 ~sK^in]FRtlٓ􊰗*$V𴈕fD+͹W2 KƒuDbOYox?|exr+lg&~!J'6VXz0/"ca6#YBޣ`>ִi&tmk! gpśƦC%ƫ_NXq6$u WFʆ T&+SW޽t)AnV5CRpuϳHXtʓ16OOaEk5LFvWX1/ rBDR_-(|1)l訑+DWݖ$\1ȺJl>s'b[9iՍ$UH*V]3)~VȭX!{MN}%ozRJ}q~Xo̭>8t]8FCtC\"֓%o ɠ2wp3Vqhl9%} Lbxp-LɄumr dybŬ@"]rX2i+"XVrgI ̲]sε&j#-1(}^3)JB{Tsa)`S:8XBH?ឡ˒&4?#Hyh&t~CWDU8/RUTJB])wmD)M`@x^ 8rAװtJRfHe mh@mf]U!CR#ө^Qdϗb< KWy![^/c;iͬㇷd΀x&.MbUiD[8]e]:N AOSשbʽ&րY~ r5)w>QR*a)%f&%nx6|dor^wQtAn`/b*PZAg|q7c X S_Mhѝ!l;/Y+1LI)l;Rx?DВLF. #y>?/ψw31rg۾U[ˑU?7_$r4 uvPY9,d̺Wg:&@ӂpeLRuVW|7R2Y;,[StkyqhLHHswgӀ77\wpEw aMiXx25ߪ=hܟ:TN`z)GOEP:;өC.zZPQz捨/IaZGͲ]J$X4tZ3mF J*Vbt=5V.32yy#`N7s %`-|_y +$"ꚹ6v;nN~QFC)scՅ~jklB[+ JT_[SZ*kzP@,upe8g[\V Cb-IcX[k0b0ў0S</)##DIx}A8}Y]|ɘC:%YO_ MTn37.Qp%P7D4zJS iF+xj/p[0JYxu,{u=ؠA%∲. (7F|\ТmC?t=,qfY=}8O3P+b?ԣj Z۔Nj-ZfzM^a8u6Č!qᨎ8kmKέhiEV@ vtlӛm4ewE3CbTx#6ےk&'0KK$=5n"ny[FD -7>).[GP[+xA: GP ^p#52cQ]}t pjDWuFҍ|* cwA[<}@R  )x'S0%ŴY"q?LwNM;GZHjR;bIʾ J*N] P 2g"2#11 ".E 5VϜLOZ8A. ۠Ed2>̘Hh)\$o`lT,s$O 7H}]yz;fhD]GS;Y<&):j,9m1z}Y9OFmTDl(Q_MK4&!$dJ BPw,/j{}I@[K~w+f*{ V zzc!Lv? ) ] `tǚ,D~VaJ#D?\XCrH|5ڑ P.&iSvƿ>;Zo{5H4(AwwžrPX5Tٷq4׺CNlj9;ٙ^vos/(G~(̜ U&TW},i{glU /zJFR _W/m}¾tr+Sj< m3Gх&%*h|M_5Q%^46=/qgjueɿ̼3jZD`iO1@ G%b|(ܦQ}JО0`S<NyJPC"yM&jAz'<9k;@c:qm,mm,"QgD/\Mrui@5R]/\@TӰx}c6RO pEb7#jʄw rGQ!˨qD7x45l˨.$` oNcj Aè.nFBfJ|JZ᱒r1T!E6Ki_@Ha Z9Y4.ņj-qM)W%!~WL A F賒R!}K2x9þ+9[9 ae`P@+z5KuK Z==SgSp`oH* xj:W N1+{tY,U@wf`(p;=ye7qd%;=JG%S;jx ȒT;+W|Y)T_Ԥ)ٕ< Ju8l=e3s'PwDA ;9$1Rvځ.^j^ 8s'$F_"aɫ-P!6U:]2H_iewkI+gxT&h^-%vS d \^C9PX$"f1gsNbl*Ff|$*RI)nWSܤ%eH pUN|*scn. s,W9w/G7 :l(qSwpQxY93 ̐( )ę$I X 8{gLO^ ![.3q4}ʃAx*d0Y>TD,-C~<0[_=XMN ߰ %)|֥g:ߋ9ţaeLN%7D(z6rɝ!ƇWw=[D^{oS,p(YHй`ƍ6m 4B=޺EFmgnxHyn_˜vy̋zP~hTDu-9>0DMskVp8۞B*#tE| 54ߡ3x}dIDR(ġ5ya9 p&i0& gEQkEѫ;oΐ_{D3zj$F`ӳ"ψFQY{)_]?y ΞL1ݕEX՚Vypξ  ]~J\P%3`\puA1|7A^ҙ&T,tO%QמD Y Q36YYCt$z'm}c!u`~"n=@`ƴ{S 6fUMJ "sOAӟREBmCE0fok Clݥ|ow gƑ"PM@G@W5<95q"T6k ۺm؈g`.2{|kL4h\w׻9Д'.tQ6MV3ՇZbd]zec,`Y؄,:/_,M&Ldw=JۿҳRB !A\7.}OzgtOfO/caD .)YG(g0"ےAi)AUk1Nӯ?I/mok7#S\Cá3PtY4tQ5 {P/ U`)c*wP'qVԗ"H}f5`B|sΛڮm/DbF.<*ڊ4Q|_V8:VŖF@t]Kwo OL΄aZZo )NUGwq׆^asìDݯDj:5hjxMnJVM |D_YL^N{yS.wJF8kbY\H- 5ݝK0'phyR ^OC)QɤB؊-};zao#ÙW>5ל!M rn P§Nc~9=Xi%+F/cqlbm\B&_$XAg(6~ j|6s$"Ҝ& Ho6̥T==KMwCj!2 5P5#ELU`'k,zAMh-6دAWsM/e7+n z8+gk!S"U<p#G(E'dSr&_DzZwGY.2${rQC?Y )I'J) @ ! Bgo!ttW#k{q\#4\*X$Y~N\ U2GqGUaTEW@'$7oix H]K 2:<@qYiI;2* dlo٥MrJE[FPs97B*ߚYǗ?S8lz)'^}.΅nm8ΜJ7+v9#(SEZjwb/-OF\p  x#$ el}\6=} WI,4K!j=\>'tF=?n_|}H|c|;yv5E<*'I'Z9h |bOkgQa>붖byչi X_ASɪ|X*5b꧎HICPM@"8ʥoZ":|ȟ^1?En,ֲɍH_?On&|˅As(/ #Ts.|BDRQ-ƿ ]A]JHf:y 1pMC, }-m (]+|0RF^fY 4әځyp I_)_|+ '\c6aYP祼1&َBp#X7)]~c8{_tG3C{G!5?=|ߊHpmZKLӝ{aVslRDL&\uM>Rx\7ų6Bw2#Ԙhtmqo{-Ӻ2Bde,:t({H4j3S1#\N";*A3i0!$3 $k{,gj *dۊwn}B$9óK*'5#0R/vS+ƙ3E3[<ũSxH"#$EN8; j)7 A4Q?̾zA^[ D2Qbzo80 m{?ЗM?I?$ pT 5Cʐ#MN% ,wd ځBWU2B,Rlo=N-Tw#dk{]pO.I󼝬A>HtYg7b\ a85C2 lQd2@ $F]X'}#st%""-ou,O%fqiQpK15uKt @tіZ[H%3>x͵3/06zդq!L-nf] ƪg aDUm@y9EO;XĺHts/ 9w@zx`Fda98? 69,:.Jy 8+ '{"r.FH4/\aYp#Jz=UB=,U<#繺5Ω2UBnS\8ly^NBŨRjl] RZknJkzCgӕQα(Eht̮ .4LI^-!1:s.Ce\Ψuݐ0sYt=ڈͩ![i3@b"zԗ:%V0󝰌qߘeɯ"udA]F&8,(7?  ^gV#_9*2_/ @Gu."wvSpAumqdGx)2@52׹!bkӴE"\3l->Ǵ8plmOw?#\R8+,Cf naAXX+Vwq{1L.e\YEޗAJ_$[)EJzM`~g :Z/v!0DiqDX~WD)}/)9H7+1{#ENe%؇HgRz90 ?0 ? ȂﰥŘrdEcUx7kVg{SóN:3NwTB@7m h|ĭxNʚq1ގRC?ؙ*s2/Ye-7FE p W9OF*  ˌKſPj͈o^V 4k^O'P' ECL+W`W`u(Vu亼Mv -F%DZ.]4a@T:}ຢHlld7B0[cSHxQM,+m"TM#:ue ^&(b80!Wh4Zfp]c(wh^N@5&.怓wɫk)KaV|?A8u?λJ!nYZKɡ `ZN$O7~X[/ t?}.feٶ%rhL!P `@lff6m[LG4쪒:7nVW5R5ϲ-SMrU'0Y'5zNO-gSm".ET"LOP0N[U+hw7wuJwWϤ{ahXNo_;5}wu~K.x>&\X0BY(S9yMV̥(S|ELl }~˵Ib%&2EhrjL5w /8,KrnIq1HErpTz+6u*_ 3%8]71tH!]֧OR΀2c?i΃|瞈&z1b;fp:N)'FJ#"|zd9X#ՠ6ojM"Koۑ Gܭ"Kk c3^4 ޛ"gq)spoH9K1K$%~ל٥%#puRnTƜjo+4 =ԻPj ,Vs,ٱ@kYu$!.bv1qj[+/U柳Z_HNpE t[!FÞ"Fk (mA (47 {hިf #A#>z?ִavԩDN} Q3дA(iK tUŁMYm<} >*l4ĬYCEn#[m 4Љ\RHwJcҜo-HMX-Z [4*+x'놛9[ ^ PӋ B ! }Ad)a|:ziTEqkgTѱ$3 syǽ3nͲUnpճIC-[`Fۿ[D cHFPZ#Ae)}34gby'kn2:@Z?7ZϘTARXZew tRwXٝ~L=? m޾Rojĺb\!X4dk4GWDHDn50lrNܗ 3,0œ躤0aCey7lq  @9v]j&8" D0vyLxY;롵N~nxyH/oD3XmXXH%?RM2؏Fhp~{vzz7gט}Cxs=,m'%hH:?b3(MZ i6NE5wZoII[ HΖn"% Z牣e&QB{)+}KL_$paWJcXfy2|}ٶ5P{Wmm{Zs#4z}l R /xJycVm+}٪-i`.}SsF~n7QY؆lI F.sVɅ.ǥHGB-$kG9ia亂7E'ޠP!)l΢*o61Ժ Ћ!L!ݶ9fE9e{HS+ǻ} m2ꖨIKu>Y?`a޽sHP\(i{bzG<=je!W6/3{vQ&U~ HBkb ea**j7Pr̟JL!sAɺNkԥ@$2!O]e~e R,C$LV&dIiìO250}TB ?b*3{ž j'{u6 8bl. 'ZIKV+衅2k;H1=? s1dG(lM~$&Y32.]?QKjCERܹ^O`AV'1O:n߄*q8neS=ɹ8X tJY7'.k51r* 9 805S'p VKNEOl0WFZ>CVAF;㈣pvΉe~ dܓb!PsβM*p̬p~W 7}+Y*:@L8vT[Q#'-R3Ė- =a\?',?+(2r/Bz4wqӸ\toL=Oe /300ktuaQ&mW,5+2wWDBX&K 71ڷCJʙ0JPDep]3HrE4 &LgI#:_’B:j*^y/>_93rߚ徘)`+V YyW/}.%UUMدE9)П VcpE #eoXNjgNmDhsm@nwqJd鞩e8/yDfw_ {ҳW}|MDL Gċ}XOU-AKP{\H zg3Fu!Ydo8K}tC Jʡ̗ݤT W+~ެPw@:+Ey = n`=\rW^$rfKJdػ@8=nD P1I<u2ztW/*m^yaL7$آ$|ޡ 7Uw11qyv_Hg)/ՓH e[*!B<ɂQǻxlN'(c[N}Gpg,,Hў`J0fcP0#ycC,TV@^ӇM:x6h7SԴg'l=7DZBs×@c"@%s bz]@1ґG!0\~Z;v WB1i{*[Ә2 M2S)JyȪ-bZщ_hyj~Rckᱱi.>ù_pϟ6Y6PHthڶ6Xg?qA}T+7>r^mO,tg8qzx14B %V*Z 1mϻ ˚"p̏?fmi\TnO<+"SE!2>8?0>> OywPh#/XLd,*8R٦l Jx6=8RN/jw&aS{c&z4aBcb*{gb=b|AF&,4a5 LH0 rj~5lu.#T)`(Ӆr5!!KtE* b-V#PW 2)y'am& k ȟMc&=&\>\Q@&qZ1(ww BbP'lS_nK`^ ',(i&:2K# Ad1櫷LZ96{ݞY3J>qZ)½H%ncÃ!Fuا|* T3Iy?t?0-//WNɬ' )eZD`P_OHfMkT/2LܑoYܲct,9iٴ%{;7!>4겅,10Vf֯}De#L*ҙ#=c/gBGF&%Lz @khDT+k_Y̶Y鑊QtɄ#No^@󢭚*}@2MEXc2>B%for*55`ۂKLXf"t~V8" IۭYWcp(qC:"Bado3r?z%PηN!)𧛙( b%1p_Mh`4$Q@C;_ٓCFhb-bE%-x/3PC).Y&;1&dSNUrl CŔy (]\U dW)c8'[/ G'UmUzi}F={eZsDZ±vԍ19"̂^S XZf2:*-,vx2L'j:anOn[$Rwܶ0='$}=fZ\awQZQgI=0'Nwkxm,rͶ>ZlX*yYd#w# ȏ~ pĘmQJo`d6ertWzHR1xc:u/y2^ߖ5tkQ~0B{9#?/Q\IH"s~f]Evo`IoK be>ڸ?our/y+l&zc>zx`=#TqtnA'Chd;L܃}Tx5\}hu_#4oXC$)Բj]JZss+QGE/;b+Ԩ~X.gƖj?vg4^iW8,/L$04oD *?I~7!xxUBufw2u{\klat;ќ:5=w|_ɊnFњo}pZY{.c 0H?wGwFmZbU/]tҦHCѼxg㎧,e%/$*/o$<c#f(aJN;A)`8gSv0 Ȭ5Oo[ft;$Gܛ;A a 1fz"&q$[y^'oim3y4E}gX \Y ɻse,1;\'JU |+`"TP)M7I]cioUxAПkAth`֊!oC4{RjBcP ~fց8>Mdyx@BrO`yQNgPxCb1ݚY9dyGiR6@z sAb/.Ca!"M[Z߄p+| )Ö>}+̟~ d@ 㛹BzxDAd#9tyRӈ"4ѭKc`4Mm唰 ,TUDܡ^drW1nsvFd3۩ZQR* KLR wm /iYV Ű)s&̀>>؃:P B%MM:lwJ.K}u>< \LAhKܓd:Ա OE[[Z V~y *#}뺢`jcXq zm }:H00N_eV1%d5eo[=^ U~bwJF EUo.wY<# 7ާAl?BfK)kFj-cM`p,C?Dz* vj8L̏aDF.fh2\q]QcPd$rw$L5TX6K ɸxO*O[-$SBXɬ'ybp*O{|ÖxMށ 0`Yqz㈲`jz|`f*=Է<M  J#\cRqb3G&p`D-){/H\L8Vc-wDOı6ʉLL.]\ yV]In9OEWxjIZפ5Carm+ڨ,eU UiηWK 9.`ߏ [!YAμh-1?pܜ!<5} Lf4SӮݿ(껾f< zi6QəKoFG')_xɰTƉ.H[/#G ѴGAZ%>l1I|^BpT>U3IM"Ɵ;X  )/҆: r"F`y;q@먆mZزs6ye@.7Ry*cږth*1ExnіPwC<9 +@5ByRHMbyES?$ =êJp `+7Z NegC ߮iԩ{bky9R V%Bs*t3l[vH.ñ^]t[zC 'N7;tZWGh(AR2?I84ɞ7}ef~Eb8lբQU3a _oAF_ FCxk}^Dhǂ*wJz 3z%NgA$oZ'1X'u\~ &Im3ᐬ -8GuҜѓ h#KE^-x4Pf9kИ#ka_NRE7Lgs'U! yMڥXRsv2(cteRbpʝx U c2Txt J ,)ӦjtnH>e Wּ:TX'ڌΎ伍S `JcaD$XόQ\"Z+*7 9HmO΍jM;#r-, oǣ{Q]b7OKtS$[ݻ'ޣd 6bSڶ 0{;el-kU<'U%R BMR&ͷ 앾zHHsIG/&`}-ۑ!%%L5@1œ[m0 +m&ߕc ^]fq:Wvu%EJpt)4(zzsE" f5"" gB$S]nj#"ğH\G?`q(O.ڒk^"Չ#ԂSGm,JN=k3&VU髌R>S_g,XdFmV4{*x+iO.`Ã.?YYP%/&+tkwmg^O>i $A@E#xFvmxI?J>;RD9ꎋtZn@WmHHN[LM6 @5kv$ݩkW/7"=\95,q#Seei8YHTpun_}?\' y3xXlSvb6toD#]81gnP֠*Gd:Px`{$*ނPgb{&*& bE *L^Z iLlֽi R9i53]+aTILePXQԖ{kEɳ uX/9TK؈W%k7rܘROBCR|w;7=Jޅ+԰YP{XQ*ɜč[_Wqiwc{ӑAzg|"Αwam;*%Sj~`\2]}a +cU-1ݵ#3q5tU#Ւk\,o)x&Y5ڛzt/qa[Ԥ7]>Z[}uc+fD,gO) ĉƗT>-$ Hr Lyyqm顴UV ]o+n2k#"j~Gص</왴.}T3sI=gED;WXl67B27tH)lbӤy7+,Bvkt˚9|k1‡l6\:k|<iVib9lX. H='oARWݬfp^X?F#x瘺j a:|s.pgNA A-ˇ߱ULs;Fك񝺝&xy+JݝByƁ gr >0R/ nE%'#P"MwRoYsoJ 2;!ljB!@;D7"(4-0z`E)ޤWX`8!zN.}F[lw(+9ya7aA{daz|<å6H+ԓZ}G*j6/f&S2//9na\RqPYG( f7єlX֔QvVܕmgv d)&eb#Ze&(H|(I7|5= 7R f{-rUgn&+9N]Oi 5ɫ-U ltЌM1m2)Fmļu(CUvbc KK>h@rJ@69 ʮb%wc7ev4 yؘsHbmNQ)6 s7폺airC=xs z\CKi t#r(l Q .Ƨ]=Si(́jܖĎ?W)э / F5*qh68v.]AsꃵE!2Y߲1cӊپcnP&NR$')=;vѦR\dv de8w;x)b ҈.l\ܬ=JC9cULbm@lފLr#x족w_W;23b\i m ٙ(v% 2J~h]@V ؅SYTE\î`IR]n~UlLS=AP+0hK75<0rs)*OG{5u2 Ta+I$28BzJh:G-hB`+$yN_8 ?ٍ4=h;tSzA/S[%BX-E`FMudUFY):5(V:1ܫV/`WÒ2614EhJʲ>c!W)f-dgp)>4Imb,a w7-=37mm[?%lo@,:rԸ, 򚬾[`Pŷ=n`R-m>Ќ߼ĐpFX47CUC \w_RT*S_gE1w2=*UVT|ߤBE~^ [xӼ-._j%`X'F`Bt]>ꤌn]){[Le54IH;`'Ih![7_m5pFFPh g˶E~Sɰs( yTo Bilz3`[yFvY{5,X:H/|4})6vSrEryHfi|'"2zہ 6LNcu2=.ʤ7ƾl:uT|%vdy}m\"* lWDRc3A7hyV8EIe&1qb4v)qwk %"\l}ڰ],qW2~8pr]塽D*fxrJlHdJEMmv+lU6w&$$Q:S2"2vvAGY"HCQ `hs54 .~.|P)6zÑ7$2&^}?PleIBwo{1Rw,X܄Ph_4@b=w3YB#.p0 r\A5BU:`wMzTVIcJ :W~nia%CґT6Gpȵ<(Gѷ Eީj8fOpO s"VËNe;+/ף=[q?q>kATQ$R#ǚQ~^ŋEs|CNU𭱽4fhhff˱tC|b5˸Qva7B—֓uWTjc!u!4;$tp`)I 6q$a;sf'*{C[H!^B?NvŤ gMПA'"a>4nJ2g6fU#RV$N-~bW"0KDQ5EXIf%)NG\hP4ݕm?Tq Y9g9J;_ML*Wӕ ޒƿV^ D2$ XӬɯ jA8&"{zfg?{ΔE72X%#zE1 .F3FxvDt?{ n+00{oi]L&G ,K/C|:pdAmbAED֛o, \p3`8f!Tэ} OV施&`uPNBA[Oun?CVMLJ&@Y›849gF$YDM\~;/WSj?um&{YϺy(4уb,` PΦfUEص]ՁkS6zl0N*9w2[8a 4pA8?TC{4Jw[U{Z)Zoa^AR۝O(95̨{z?js &3uur:֞||XPuTaS_Oӻ@H 'jm(IzE eliO]xɠrҞ% ΋xAv/`'(`ԙLd4 gK1)m=](,gM{ro)#}~gXb)cϛ>9xԂiDS]?^ʬpNQ$'M{MM͙3F~iNwCA/mdaSr>7(L۪Ǭ W|kgIJ҅~=јr#jOշޕ2Vc}G.-QC4zE]V(XӺlP5M[TS|'69Lgҍ^Ԙ4 PfZ6+OP;=&Խ]St # 8;Sľ.>`Cz"7*&/#*Rl{;2~0glءҔvBYT+Ce#f481B[".NO ZQ9HpeW>Or9~mMaO&6lӆb1g]C5\7__}vHhӮG Ji@}[.$rS$!f|$qF7 Q?Eh+W\~0eC 2tq7ʿ4Fނli*H;UTMxZmyh>黙uaܿ%E'pTr-*P6CX;DɴfB&=Y[-ZahG\ ќqXhRj<OW }}VCuf~iأr?&`!878iП e 6Au~ P0rL*gKɥkl;n+uN HA:~auzCN=l> 6jdh듞OxsA1)CW(~p4\R1Gř0 +qNA&3:{+~&*is"؈2}ʐ]?4 Yd^, 3Ca dI).ck6BYO$=ޓ:Au/$IS\=F}r48t,nMj.A>/aXPz k9iUo4gox 5(~cO9^Z&/_-J&bME!ŝ\:=S3Q+MM&a%t$YN_%-L[+ =DNDl18\^5xAaynP&)+\G2X1]ۀ/\k82 bS{ΩZLw[Uv! UrD8,u32`b;@3qHb@%S-Srbqwhwŗq|\tY]-;bĜ隅_ij^ bs?ϏWLzq?߮xJ $E[EɓĽikJωOX߇7Kh А%|]C(x20tԠH|ǒSzJP"VlBI3ޫsWsRITM qpW/% !\u+1wpL!jQwsYlFMlz0ZD}y2A[h` ƌ(S̃(Ӑ]$fOzzb%2:?ùO"GYZ^ܤ{zy5r2> mRջ2)tಖq3ڬ ]pLS R+!u2 .QRuie7^a=Z߽w#AQ&uz}A&C2.#2bC'>E/-3,%~557͟¾ҘfPD2R\* q_dg3+.OuήN+{nUaIdVUi\2i92ؐ8B")0VjiJl? psRY?/ ϫʜHGXaxp=$W˓u '6.2 mʻ9jHV ә!d!-$L ȒqTfkFFܷWoOؠOׇö[>b EÓC?]V#';>6F8dVjG1xwٶV.ͫTEm)Q\{RнLF>gOoaW}1-{Vq"] Ir֤[ؘ=rz,X1 %a{pC4{495 4~61 i7 T}nuo͏Mǽ seFpuDB |nma7ʂA57S,.BQaܵ,TE%z˸i'Gv8q=%' XH6 ISetƞFT^ 6uD$z{vd R\hq )5MYg(4)&{LԚ[4д~iC+1k]s1LZYWfUHFM/Hedӈ@8,qS:@AbaqSqkGó}ārV/6.IzLN p"Mk?iՀds}4Va:~Ĕ-wo:3Rkp`< ^E @z UVko›j@%hkJ-Tش$#ﯿ^2lu?՟֔={]4NOo *]=IQhypn .m!5˪iUnA$歫SPw0SCoxNZ56L&󺰴9FS?Fx˱'*vϵ9 8$pVF%_YHa t,@9M Yo7+Iu-$I[ң4(5[_p&Û6ӏkW^"_sFÓ ᮧ^C+OY2b} 05I3- ϗB+ٔfe09'֏Ԫ. 7+DD|Ӻrռ>eB = ,),v R"[^LUT {ms^{ݴZ-nZ4} FW[Gﮛ֋SAϸR\AWnc'qȏjҙ''g`˅YGegZ͉\ -\CJʟFb_SqB^DUFӀΌeRqhfׄȫg+% ;,f3Cr=^m1"Wf1ԠJĮmall r0'H](B GQYNnpؐv7țS m:dYqEb;M lպ✵.ߪ);3yj6D;7wvN}h]oհ/\J%!B`g-\CoPðr8I!eb}:9y9mRq7hd{@u{d]ԷWm:OIt;8:h4Z$2SOgF*գ62^ ?Vz1[CG{i"l"AuKπZxoD? ueNj~XSHԌ\9PK&$ hN OŅd&ҟP9X's6g[#Gl@XT"ۖ*l5+7qjd|d4 zzB o M]'XK1dzήc_yawx#64B,|doKhu5];͌¢ x)O̅DZL3.4<薂٧DO m3@XApO@Z]!K$8v,颹f|m!e1|l@5%amUUрnEhFMVúa *pϾ@%8U0sRIcdQCNq0 !Yj%uܪk+QjU%a͂zH(` %9 |T,ڔ qCYPZ8})0kvf9s(>>L}OcڢEB];5O3uۦiP3Ĺ5LUEWww>BuBy! ,R۹ܦ waMx)@*'pL`9OkFvAfG{OyT㇥vBv;鉁C&12^wK$Hg#Ԟ&893qQ!q O2HOF=NX'?h7[l%B/ym,ꈎ|,>Ebߝ Ckʶlf]hVݪ>|dkQO2WZ9L$=8qeH5{!4v" ȷ&[ A|21_|K0?hy#J u*]'(gd6~IhRjEf\_sMy^¼9ҝwJ~?>=K@?fsL?돠]sh_:`Sꔁ `W1"a)d'.T!'捓\W6Ѳ?LqNWn9ё0"2d\Ձ FMpɍ^E$jt}Xf{J܅!{IzHn} 9$ZfCQ"sז1 ;cZ),늻eL7ƨqc{ˇ>H"w~?GH1huפ |s{96rҹhX~mÌ ED6,8#n6liV/1KKtM~ψ,e͗~uQ~wWԂ +uC\߃ΌðpH}|S;ެNmҡ>j+I.3@TI kΩyы4h\Xk&t]ղ-"ylDn¼!.4|\1;DK& &bazɯd&?@T&sk|b'8a‰CwƑыV<.ftR;W U*è[c kU۾O$z00ejFit>i|vԼ78`sD>hȿ_凱)xG-2'פWg׆w\nՔP"uL'[x焗"qј:h*KmEjXU|4]!!C#ՓoR;`3R#?Ȃ!@ (|T;,}zhp=]'@',P39X.{?dmf[4(0'qsDb^O度B]X{P.\*ϙ -*6jau+;˾4{ݧý4qݛў2mE+>Ƈ@9,#.TAx,H ^~jox3胀tŲdGl1-`9eE$($+ <]єh.38Jј  hTM)MVl U0tL1SHoO^.pm,Gr"-{;d۳Nҧ)E2wܡ濆S3VD|H9C!NK^Gw5 S~j[xLoU?Җ"ÔnuTfe|'! F rK)KA~F] ~D!%W1 )'*bJkDU7 dK0D-HV?o(lK>39jJ% cKC_f\Fj&Dtª{~*Ï wEE ݱ 1akj(3Di3Lƴo9=*vz gMYcv$!//_0[} ~)i31–dފq:lz7[o" @{m_z\մ,B%F_T3H1SigKHv@^ni73;ftzPU+Ni"b?~FѷNY p0I՟讝w9"lS) `!.R0Ze{"ee "&ɜ[/tl ΆtWN">>M)2'~O@Hӗxfi\쵂nT(3.7ǦW"eY,L@B/5@<3(~mڗR͂;Ϋk,DvB}V}`_!Ű>8#9I;3rL}:o'N,N,Sq,fի?{ 4{r޽f `ۘ+< 1Z! rKY}M| n_[kNDt䧱д>}t+)|@BhE8e֠pk>@ݸ:FTdh&X?RUYi[a}o*EcZ|Q:⧅KޢR]-S : dx aXd2#ŧ{_ESefrm#,Pۑ.۳E fKe7ޢ@'@-t IP'x*KcnՇ0B f]^O~l2G^(o Egw9Ac&#Nrd˖gIt-^O܁4h9wZILլHz>"BO79|b \fT8 OY hVli$4@1BrEPvfissRf lZR$iEo-nS2Q ‚; d}cgFӚ`wqg5BgQKI&- HHLchY!Dr9t0'oVHG.?$0^>ZșOP ~٥[E͇QآdKL_#1%2N ̾oJRW̍!Bĭԉe/l]J9μG}ف!` \'ߕ[R% F$'QMWrJMZR= 'SVHz[t4decŎV7Kl E/JlxMǬbˍI}-;x S':t}ġA%84Ud0aLrX{A~ E\1$X#F4ɩ@<* #fIFU*#뽧F1|3Q^;qRaH#6uZAC)c̫[DXg6.ڎ1й.P2M+b(3A$:~sӅ+%s %b:\J+_X'`o$t!HS*r n:C#?,aEa^"q3KT+&Q_, 7g % )a+>FZYY8˾tf_'Ϣcs_,dU@/al4P 5΄*-bBm"ۅ)q'Jn%pjquab$P)VCԖV#GmN,zlUr~nţ]Q웾& "ɥ#_%r>gtMxJE0M-b7"HxqɅ䪲ME27JGq"NhZUyn0n,! d_A~j^^" b!2q*).wѯ@\tur"h䎂CaSN(ܿ"1Ohڧחdfݷ~LbwC :1o&`򅫇ITî0Y W/00RA^"T Ah28gv ^\dܾ=o:(N!XNkԫ (q>!qķ{^p z; ߇^! :s5޻]B|;>fFC3Nj4-e.nl43-'Zc^7C2Ӱ~3kRՔdWF1k`8vMƌDzC8eVi2Skɼٲ|d!gHV+!?Er4չ&ƪy[⸼Γcگ5Q Dj>65fZuTŅ&!P/|T %]O$xGkrEF ݣʄ-~kw[ifF_wqe߭xpdqO?T`[;"?\*z? #85LՑ\`W`lad-eە4[ͽu 3,<;a᭞_K34?\ӷ͔ T[!AM玎 Q LR"M`CL5=rSΓ8Я3yg=@"{2tkD6Ғ7cs2IJYuC8Nշ9s&AwLSmXM@JёU[C ܒQZevzeNJicq6Q'4}VE7`M&6fF_9Mچ4==g Cj2$t{Ad nx?[)\Ί{".z:3ݵEB\0uJ+jJ_}™W 8N^0q@U R:0$HVGW"23|]PWE&*t)/JĶ8sBbxGcò&IFwbCrOO5|'n/ 4KmeݓCRS=_E&{~ "=E G ιB`ϟX!D,ϺIF`(7;b_TnET`FvJvّDcrM%VnGL@QuZNp=`eY rDV$ ^ϔFK͟T.Xli7a?y$o[8a&;I>G`Ҡ' GVKj:E+d-e'&ŔƼ[63Vr(בwde!1򔿞VjR0vnw{fuEabiiW؈%5|7.1]S-ՊyĽF$2P\d|74x JnAɠxbC)UCx8|wb(V@=W3Y͕ީ5BW`:C&GG7x1&.@Vf<]wc\C4hZ`]j3@ZЁ lvV|eyyHj,7`q*7)ǥ pE xKB&2'y Er󅽓 IEdJ/n>aF-FM%d`]@ߕݖœj~6|pzcM6r uQ }3]) d+%not)dJ[G&N-jD,%FpeWO3kT\Iw^̏N2#SkZ s,b籶 Ά1a0 LFS'" 08.V(BmR.Y5ȳ%Me_Wq0jC% ^We1r P~-R vp$R[.@,O+% P>蜱)bΡT>ا{&{yˮbQ#=Us?R_c[/_ o= +X#L Kl[ɒ[3dܛKEElpx{5a͔x)bnCܼ/v[_#"qlm)E;Ku¢ٟ$dfeHk!E+ĉH@Zf`[S9c"` dÌP"!r ~J41N0q$5f%~L3ؘ ҬpнrK)sX4WBlAM͐(s'QԹA+7886*E x[`8y#ܱ ަ0JalHra9knŶJ 3|7S4ns]6_@ bqpvtƮcnp}]p27O۫N܍vtpO1Bɛ&oX)( {ωyߑlqgT[IC6)xG*FU'ER+"g)M`FS*ysA`hh6?}E |$C.ã`aA7,1J[7us YCy? 6:a|;h?T&[!:sb8jK%gxIH; 7(hHxw< (0}$&A+ܟG,+J%"L@?ՀήUmzFex6 ۆOi%F0qSߙmkWpGxep{ "ugPg'ieIɊ|kty.qiZR&/ -OcX+7@_chGy1hHk9"a&2$1>t׀qN 8>Vk}S"Ɏݝ"8QXxzʹSWW. Ѿǣ; P{h$XKpuu.>82B*`uݬ{e DrkoLp@UG×[ Y\ MuH{Fʐ/R e1%=s䍳[ )l, E0_g?{@)c6@ vuOO UjcY/-j=xNw_*BձYoa!Dbn[AN,&*%QC駱Nn"fe`˭?d4o_s %M4YoL} pgލy隱gbƝ*pG~#Sz=<$Jfm/N@[ň%A;njÛE|mA!"5<11cmJ_]K_I~74PHUbbT~3_jW]\{ARQrqJ0=wW!!֤B2#c ?>&ȇj.⛊4Bec乁E";w*JhFWzc}XcAaqeAm0 ~+< ^e|K@TP\wnzZϧ?肀NtSOc6lBsQ<$qaQ6r@o~L%XqOQ}(Drปj=F&]Ac c E'Q8NWp$Z^^v 8 ZRt4\~'3\;'5x "E-3_AX4Õ{-C^>x&FvpFa9pyYyV\$XFBf-' {gU].]-Do!(khҞAGoڜMlƻ$̄B㎴p~[҃^$KaG ._T ݨc|[4g3+`&Y]I%r.7T'>P+1lbR`8A4)ZlLLV-GNk>wAA"~< 9UW#Yc|MyG,pf1q*(ٛAoe +y z6S@n!>ű{=Se]9'1K:ԗ2:$=b&3M\{R "ϷC*&6$ng* N`8UX>VR8k̘϶1vGD)]=9V%SXE_&$fV:=W:ﺺ{%:u^7trGi T<Ӊ6h-}|k6|cNs m0;7ȭ>lqn{x R!%kbn+Vf,}>gJSg5I;frRWQ2n^qh aviȓ19S GhݐJKCV`S({)-wa@]=y~B(nf8j֊Kxoֺ9*:GRa×歕<<- FPTt-4ReLb22>u'f]'2r&T4M'u‘~\-lџ=!U;sƻL?N!@61nO&d!QV6RR etY(k P@ڧUV逸({CEy&Ѧ81Rlu$hiX7V F*9g"|ar'̎|tx&U|[,L}@@ux5N_.1D2ZAGg3;5E5ԀՄiOK9ojH$*UK3H(/ : x`91K &8mM=N~fi-GU /Q9Z!%pj·MIOC$)dy"](_~½^g CryxƘla вf{mӟk:Tr{韎WFދhPN$x =}s!M}ȔWu[ t3qi-HS&1TOyerxDz]1b DwAѶݴmѰ?h#BW'-c&5[! )W{;Avi2~Ԋ̾{ 0kF<\l]5TբU n X,k:Wakd*R r(< R8 D*Zi D*S5U-+!%w(DgRsPori/LX_6<{sGe.h @j\t yRFݞ-1Y CEiGY}U}T\sGM$5\ݣ~ۖ<g4f.o;XkFZGٍ]h$ nT e1fUU%"[(iֲ%1sBh|N;;P^&R+/I9ėPJq,iE<\$d >yYIM0ߥ0u,j 4pf+BѠ'6X(^'?Ly306xҔ-ٰ}E4 Kmڈ a\_81bǎ/N-PҲ+.5X_4_?ܗ卙h`c@!|]o;$"K9M>0&L&/_ PGͦW@9iXYQ1 Yj2׍_|;'E7!s<*lz(d"'sm ``9l7׊qy4ѿBy#'+Mlp*.^G62y:_):Sh[}#h;:K}a9p qʸ3V} -]m g> 3˙\v>*X/. ׹\?Vo Q Ϩ((>H{;WKɎ1#,^RTO?T?=s_ LRt[@61<θC?GW-8pu#2]?ZtOr"^W.G__` L#.Awp,GI( \ݫzQ}:dH*.!2_Yp LbBdlr_kƇ.3 5%M8ʡ^Jj%0 mbPGb5lݨhw#hFxk]/frAjGjB5}gAd(lMh46c;{*_E:?Q>ǃD,n>_Nm'q 'Rȏ*)c*Sc.tĀI!=cu<>o^R+fudDA9ڌ?0M;|eY4$>Ҥ%5ΆzOY;N@d[ϭdO!%.A+kyWdr,9OPnF=쌘ray$TFIBY6Ռ{qî^>:*!IF prIhF<^]c䓖ߨAҲT4]g&wZX>V|ռfJ$\l> AHJ j  }Nm&Wڬd< 2*(lu˱R#!@nV(l#OMO+$!qN-/9Vħ.>,)8v{Ijm45#ƣA"r(͔muYc;-^bDC3G0 WD'ő1+=v(XҒRwDs*yI'"@Z0g㡄5HGl}~J[L+Nza'PjC_˝)b՗8S3-DȎy:Ҍm_t捼e@e>z\i7!HnQQ'ܓq6BᏀqnMh (={u=]\;1&*~Kݑl@1I\R<^+Z7skt *I2fӈ!Li&~z*ӛ;qh )pfQh W6XjԠ->j{:z~՘a"r͹:j$%Uli LKHqc)I/"6JsÃW~rőo}H`yOº4pd%bfjo+NMB rF Kj; ;߈ mGyΎvpX' _X)?|⤳0Z\͊Sl.iKS7)PϕJ`6tn>_=ˮf_V7,ou ԭ{` fw>׵A_-]!Ampй+>J\DWT͸ԨPuf.bf"vxƎYjʙW; ļPm)R4/U*4c y$!΢K ekiWg㳷~)9Xy@gW@>4Ql3d4( {3ܸGyc ?3}"H:@pƥ6C5+5,'Gf,7'(ж\Snc;#y- @fso.RݫWt%Lw Um[(*5^Jۣ5W5hn6S FK95K0 ~?f; F{L:N̑lMKwHx.ij\rq#,DL#pg W:zMZY,SmdV9G_ZbfN>֣=46#0]0ԖMKC-me'i\hf>$ L6> f7%L&k̰0Jcn^Rjƞīm#MSFR,-QU^^a8ÞUc y;^yϒ27i&?n=ty?9wc7`B 6 ǒ֜L l|$RN(wHHƴ UAjm.SfݎtU {T)L<2B!8aGARBSk[OB// w,(XkF'%Zoɔ'ׇGc²f<Ėl2$cZ((vrdR8HҶ&ֈw J7{膎>#N,\g/kG$sעܿa[JN"B@݊aYHʵe`isby(GD`GM؆ɪ[oƃ%v8d"G"šO e^Ph^8|uh"n,C)R{e(aXx鵍 c.yN1z=4]h7xO@{5:Uyz714h|{۠PA,ܺ/ n-| sGʉL]ܐ/Hov.flLXć(f%8αh'i829dp܂+]֤1M[ xcq% -g+]nHs#e$@i;?45xf$-GhgFW\;Bu]a]7I;K`y>}1sIj5} $-q rfGl' xKk[ƾY 9&,SXs$,EK&f=}dU:e'y,/V=@w$dyo}-(6 j$b>խco:[mL~66~ῆ✻d"hVuc[n9ٱv'<, TmZeBjS,K#Y**>Ke!Vw 2MM: URƲ;3G ԳY_LE+|GA[NY7haݹ61K`'j @z )ק~}RW/WMH^ㄟ ySoqM</ԫo]g$z^r!֘`|D&x$YFL/]>(gsTl*1] q-kmg{!riPf֗mvun[ \\:S$`v8ۂ64^߉lʈI yxڽ4[LnEi`dD;züuPn՚^gZV3@hR!bf žĠR8@eA%m7F輛y N>(CaٮvBos(,U3+?tFJ0=ߤ_\OIv^1F1V^!7Ъo,\ H4G:*pEӈNm!D fml 6=2;q( ^y=l/dP8 +YԳ-"-hv?Ǎ+.豯:C"aupTJǤgObVRZ xQqL^*pY2=֪O\ pSw/Ub}lMDi!iភssَO-O 3?O9$s)x|z4bNKx9>=*P"SWyW֔w؀1\-0@_(bD.70 ݦ*ox_W>L+d>L'tkq5M|G"Ȇ#4VΙӶEcȃYDD~[]"ˮ} gj虉%៕{)'lI rd悯n wL^MJ.o5Ve39l2o%.#X-Lg9N3N{\;6ڤ.y E_8hX;Ca/Ȑ-+jN;5p"@od ^si8UP$8 XEq9tYVH~2&YErU .#6=WI+~+Dk/ioC37[LRU/mK3:P/C顎Wݷ B|c {34:˲d"b] QJs@aAm =}O6ʑm,-a},6IÐ×CGc@CwlI1^&PJpU#`о.3'δʆC9L=)qì'0<\Z7Jň-}kSUP@|4{C!L&t]k~qjP+wAҦ} ?u fM1Pa;Dh#wpufh(?IK m Mq}A t8_D:l6T/BQHSݑI7~tqKŒ\Q=ǖXoϼ 9, hq2pNgA2ir dmۇlQ=$IiŶU>m+eYYZ &Q܎NzcMrO B|K]CS7¼LhX5GC1)SVIvMT7n ?Y-@:H6ZT0_`Q]I}klJucx~a醇}{/EOw w\ <UG1'3n|><|qڭ0AF,Q ZsF):/3-A9ZhKf! }/D1Oum -qIdh4+DMǐ`ܳ .h jdg:jTpncT>aވeeuE&ۯ'4#O Ѿ(2Gn.ٿs"SZĺK`\ A:۳82+狦p7y(3`[w>t"<סӥeRm'g*+=FnQNKZߎpT*_ 'ڵʉG|p'dqF{;>cUc![Gl Co1qqtھ7Բؽ'I= 4U3 .0  CȄ8d8Od2qK.W73i}|A[TYQaH g2\l] 4c`7+\UF"[v2Ki"*+1Di|w$I1"Pgn8M@6';NM\MPb(FYFtOQ Es>j9:Eߠ!ANL%|n}b^RTx/yvThiXA[}NG2_+UN+ !X޹/idS9Nw  3Ncو_ARwH?bZ2?JEwEp#L,dɜeyb^Fκy=%-ڔqaKa H qd͵G!&<UZ_U.0x˞ғCx?4Z(,WQ K!?{,k,LF5~b4 d@F*?Ӥ<4bFZ‹fFi!5F**MJ5Tv w (#*~? 0^XoƓ~r2TD`IKTxCefX&2@iW үBKJl,sҔ{ŷx :m9/Σ|}آ}`|ui%.b[Gj3#خ˩,RJq1=lD.@tc潀7`I,?s8 .e %\^vcŕC3"~.Q峾C6Oѣ* >Y5ԉDܦoQLiZ;1l~Dn?>A,dy4ekk1]X9GZ4LB;f<6R Hݩ+%Bw~5ǟ^o*Z!$}PڽwwO quF-JyվNװoZDx>$w[q %!&3_ִNdñ15.\^GD*Xd[`1[yIrB On홟`;[S:c˗} b@rn0F}}wSk2 HZN/jJR~3L Yca-ߐ=Xh'fXCч%Dꢂ7{ ȫr=[vOݜD؆"L~2Un>M )Bbq Oy]u*\2uk!Ļ5CN)vG{Z5sL`IUj]e_\\_ ͕8\x>-`Wup`%i<0_nu6p!&=!c"OѸQLh/W,m}NfOԫ=q py)R9oyNEq$}ZSŁHB󼟋@֝)O%@p?|st\bX|МmD<7-qnf.Ht䕴/2O;KtWq*6=p]_ƙ}@3 P?Dh>s]t.\-јib+"5>Nk+]vnbYVO;\.`,1VF?q{d< K]Bk?=e_RŨS{p= @ׄ*WRp߅B8."6SIKAajm3ޭ ˔Ã_YGDg? T2e>=s*&lf,M8j|Cr[:"#Ͱ|Uy|2v:ӓKUdM@+j&#.BbWdQ3yf;W4{!SkFapU{YTڊVP^v(/ͯQ>4\@jDQ._ѳ)k 3Yfn'[U?c]X'wϽ"F1v9kЙ7[Nn鱌|_|mjiau[N;*>=:ѻ0JdGZ g~.EA2vo &҃MXځgt/@k Oq-tݽAL^ NދwUu5 JF%=ȫ g}` 4r5I`:ĆD[#3ʍϨ@7'PVJj|lS]7,Q|!U/KⅯ*ub?"qk3z2{*xrZs58JS%-A/ʝ1(LJĐm?9Mr4~#y= \yr7AQǨ"`FN%jqr;H ϭ Џg7ZH({[%L )}qD4G߾ $ 0Ǚ1"G}vIqS dp4;FظȣF{gm Gr_8by2g9ݠ#d\$Cb1݉)%شv`jg7q<ۚ[z8x w{f]QUy|vBd>%!0|:{hP9)-kIΛIh1pw6N  N#VyR=j1%9} g腼8/${0Ran.SGaTwT@ܕul+6?VkGmOACY,}-1g=RJrUXIlxovNG*V/ި_DG° t`'?d331ΗSD@j|ZN]w eM@ЭVB+H)URtNQ[o4`V9Sʼn_u@D~tچ9{֞-@1x8bs2R+c4ĺVTAih[ ԳD41"mwClיpQN CoGq) B=rB$\YsCTVx@G':!sRLSwzJF> ½o2pal *&R8U7W /76\*`kI'`t%]礴R3|H#LcY߰M$g'X.#`X@`㇁xpY:5E᪕(_VWxɕ x\gͼ%>|âhDdO ʡhV`fi$rQans xH)qsH8;9P??P*veףݫvųyE& ce8p%`tvo1VS$6X[ TKfXi|/; C#T7'j}֜\0ou%O$꾔xN?w̎nWg/YBh:75~ZA@&`>>+~W2Wb>_#%tInR9}ATqAk.yyd_ݮ&H0Mf,"nRRzu8 "8Ȅ3T^}CYdz87e nABV#ӊSUBm܂-aW`zY*J—y󨕫XPGx|*#+-jis .m5m,&E;F fvv? Sp7c9H̥"skKac\N}T"(ZN(zM| ,JmF`?WD 8hz\[*E#1EK/a̤%)&i۬QJVs/Fu~6lo׀N%:f2*C:Z/$ ~/ƭov~Έi:ܮ ye-@A!^x jcz (n*]0/\U! P{FDDkk #B*#5̞Hٿ?(C-^ 0LO+ 0K7u>^l~nZ,Z*Qgʻ#mS mS:|-!%|39-ž6\s,օ[6`^|\F' (̽VFX#g:G*2…!ƛƘLCR }-jC/U2^(%|A鋀/۶Ruj. x6!KS*fț[K XhӲ[֒u4" W ^2'#wzcBbOc;j92._ c1Dqc>.em3+8A!,%*4gikKZ75[2 pMM !:cǚ0t0Oc2+NKYHHoph/)mnOe{~{t+ C^gU-A ǟQ9 A}]{ud-n3Ki^ˌހl-TvX0܂y}v$> ٔjKƻnq,(5y`,F7+QuS:ON2$1q6obf}4?r^=h1\Jm fdTxϐ]|.\ ]w=#s6+^?Dg5gԻ%aH;-P1Ogakבuh!Oy7rFZ>~SA9kuD~V[ܢDZ$I$oQiF#_X8jLjNMg4 0mI;h?n# yY~ܣ^侯8hh-T̹3GǞhF*95|2G!Щ}ЪdOg7 ґ+._%V8JQUx{gXo/,co%x&{z2kgv7Psamai#G?*Ry+{HzYl}Zzm4=f|Ee`8 TP ;xaLzT$5 󆓝 )5g࠲ItlL;jIRӹ\{'FVmʊ곾 Eh. dp_ 6^6h!:]@@~yIm z\T^1A5&rn;TRh> b[GdVDaBתl}31գV+um.;-=}r&KBc0FpVH U$[l~&-IO6)6Hmud,,"*ݕv{jJ;3qf咏٢3k] t V@x3|#27%'ҌO'?HU2='xӔi CQ{{ӝmf; S'+W!5.Y+3hp\{ꀐ}F$7ol*LU*sn ؠJ˱`M#7MSȨBNAIJ,LخP)Wu^7Ҹ%lh*k 񍃽L @FG(fNew&a;NVA=yͭF=w 2"?oO\[ޮLUcET12DP`ƇQZ#~:~6.~b2*V22oVu{HH;{!QJ :[hÚ"^PdTib pm庈 ߕ-gTڡ"Cq׊~!2~l]R.ݔԾz ;wgE1*mwi4Q֭GQ^aF`>iTgĖ *9Wѽ!iqIF̟%ʤ@*(bq <&1:EjƤۇI>FJ9-Aa?B\foA( f\&SoPr,FwW*àcj gڕcpmu?Qm3vfC=2ufפ9]TivnCZ@PXlL-ڎVI El(0MY+\Qߨ)l, -}4]TOʧ"tG o8FTp͵xo(oũ;nU mu{$dp%OPF=\gVvm"ܷ7E=~ RitqN{zfKb+9 6IiFq:6R9c6M۟s>:m|tJCߟkQ80s%qM9D @D9] 3p) ;D'G1_WojL~{}`%Vvz ),'8B Vk p61m bZ_5*/SYI0?ĞOjVs6_u?;䲯*ù1Kb_0(0h,0c CkrŦ @sCۺI珞zPq~O[ x xhC.\dFcJC/TGE/fWo$v%RXL3DVS~홖ы QԪ(buk~@3HZ0M&2MYu GQ Ĕp_ʶD1bn'6t,!!㺶$!{g? E#7͈%"Nԗ:n~t8}R Lx1t > h5(}x;.Gܩ'"ф(ޘq"('c >bOnD͎ѡoȤ{-BW8 qz6D d\!c$FMQp?<=iݮ:(%AZŬmA0xqLA= bp ֭|l_Uf!Cb [LE6_<Og~7RvF XQüL+(zN׾ I:okG83}`M//aۉܼqo+õm2~Ij3i-ȉu l+\ b"puUE0" )Ph u`[WE WQlْ.)2;wS18!7 GQ9 !HȔα5Q]wKnVyN.,Jo; HI8E;ye|k?;6('j+jC#xy3ԩ*!tflX|"m@,f T$o6WǦvڳF-5{^?2}6ͱx1PszBfN͖E-޿ДG"lppu p3f?>W:1rұzڶO&-0PBRjC,I}Kypx7$4Fns `.ޥG>FWZ'#أUJ9yjk'3T}mP+[  oz<8dXsPD@AX^Z綩yɳc?ér39 *(1V?Mv'r LV \>(:uԚq{Go@mͫ}{$B\ɪoOD̞j7l]Vx|h6ĝ$|; H@'=GR/%P%9wʔfR*B{js m{`kPܻg"RQDKi.R^bR/e=5Ygu:7dFkXe&|'#|`|.QF|]}<>Jiƻx.p:b<)wf p~ABGC{Kfev8V!e4Ŏߧf#:AJ4NOqĪo\q10Xs Č t@k:E 0 ja7;,ʛ!˖X* 20xp,:gI qnK[>1efK ʫxh|j еN͢jɯ*] Z:'Zր @֔(-[|EU'C;[秡x'Ek6ɴOna<4!:.QtUřsX+X`E}fS!"5bo,,t!Az-(9kdz'[L ^'qHMtǑ-WXH"tG6VgIhzΌ/I-OK‡lm ^R&{`B0ro:4/_HV 7[0v]RQn1WNNBB5i/zxQ3-.H.봱qZ`1ỳis(QyM4 ჎VH֍͆2hRوs22c#)l" r7"n ǥAN[+Ԃp%U >^/_az#w.c1(AVܺ+]7pw>e>ka#uL ̊3w«Vi~@;@詤KCg/gb]1Wz ])UTQ- .I cyc;;艽"H-/}@.wtݮsčھP[0ýM`Oד'lvUb9J%_ƺjH0-Ӑ+:o̊L^Qtlkr8!߃=)"I|~`1vrIYxJZTD,rTyE^]h%{oF +i2+3q  hJVUb Ky}Ml}Eʟv A^L8 Y0Z\19|a.!JܯW3LlGC?GhZ!19I}ı2E]TTHK*uag34e5ln (Nˊ@%'u˘@ZE/Iɳ@y\ݽ2S~Ke3FtQo~7~dy 7؉ο{)k@ä|>-{Ey u2lW{X[ 3\Ӽ?sxgB/i-oMBP;Cz@ǦGf4R%AfE%Yp M-J !T Q]}灋6E{Y=HZZlQ͸YaÛq ՒW KQ k f-5TiʾՇ}ɿ`@&~5Eo0" *;^`*qyTP:S'Xp)|T#(ݬ-==LԢnR 8\QJɧr;{*ŴE\Жv/t_eG :X(G?#}hˣkf|h/iGEX0w2F7#ߖ\BO5P;b!W)- rbJu ;-x{pjEy򣔳c!,B])ʡF%ӷ }|&Y-£)K:1;8Z#u ϓ( 7ٝbRUnPĶ^9]v~7u`ԍy+1IUо#e"nMWzTP^|- e<8 "0Z%9bY YVz9Rv)(G1" s)t(Jaj?Ĩ7)W 74vm̪f-7,C2;tJ'^v8uCőkp[a/ /J2-od2l9+~ ns]J* J_&LY`s O]587V/˟ ;B;2|>I<=i85?f$hIwhJ>`0Oƨ =i1JAG wk[E@Չ^4Sfj!U04m€͙=~%[nw<1vIZ4ئ+M*Ϙ/x{' d&=CȪl703To+X֊8&O"gYpQ7s>ybRޛ]Iױ1S+*m>IiҌ&: [Ȍ;xl#?<8e] N"ـ7)8-nR& zo!< ]`k9D%8rC=%͒l{0ĕWn,7R9tn|'``l*҆WorI[MA*̰Nr%AˤY>{=rloL0٨$~: -STT_sF2}Q/V..A ~,Ԧ6Ǖ1:Q]:@!5g'=p5lVNv4iOΊG!Eե\"f:a )Wv=SFn+1tA,)C%O.&d k)?qM%iJdc.*hr2prIK>a2g3ͥ PB}3ArB?VvT 6@feNE:A^>w f`E8*>A%Ipa,oM^!@좠8JJMdOu`/@;' \1VR'_]sb"*KJv#jMjoQ!:ۙ/]g tX,,gYV5]̾2]J| [!V_ t;k+A;@õ@}#xХPif(9[k#fՉ7=&LzjH,f*4utuR{?W7Lz1. v!S<#>Hh&kCpj2f8cQ0؎Y܋>B>:2il" #ujne-ىPl^F[# /E~]xZb0Cg>`\Jo0,0s!Ry<{0x[ZD\X.2rKﲈ+Lh@ٸLǪ,EI^r ~gkS-YHWNF} ;Wjtb2ÙBO? PIex|s\;6S/X? W@qD%v=]qDTo?xsfطG ,a1_`av /WCPpȤHx'j;[kX-z݇(rw'L% Tr2r{TTVTćsc]sG=[)!\lTW>lX'\I_9 @ GKd!=d9 hW|-LqxYo( C 08Y:stVZ/׌R]{M2WAۤt1h0- jnQW[5oOo;f8Ϙ+]ifn5]n\B&moXذ^JlluRPtq}MqsZ=yq.`(0"-\)%4 :!h:mt8HO~dg! 5#k|(XP W%Dx#]t.2ߤ:X\V ﰹeQ9UϞb#I8bs 7+϶|QO&Im$Fػ='|D.l}bH)v]/ )i'U&i <\K'711Ivڰb/]4zz3Y? Wڐ%@d1f1ɯXCqkLl4ߢ|xHಯ0'V]Zs'2 8WTvHڡSS82 !\V9@[mJ)QZKJ׈%ۛe;#Uwgh_/1Z%YvgN"7#rqpb(Lr^c!o|6}$ f\ezx̒c7c!Hi$炞J.&os0J"PCJb`YL"w'2TinOkXC$ 'mYdA5*u'//"y“UiL@\J(ʜO@D) !X}M̐U6P;/S)G+Kj֥t{wL8-zt2l7+-XqD 0~m}0kt̊\poe ""Q7Iuf:-9C& wɐcBr~ܯ?q݀LbAT`sh6s+ߞ.΀ 6ܰĆTr;̅zp"NIϛģG,Gd%7\Oaܳ@"C_Wr(I-74y>rwx;v%_,;S/wUbg*T`TDdJ!TTr{b?N$!>?:ֈyn`/Pᛮ8]fG6|zmI`цIUڠ#YeYP*+)k50A3GpYZ8nqvӌ#}WrR˃ ^: `?h+mVLϺqZշ Ҕ#0)~pĦPY.ui uuꡆZ  *|uoMiVT֏>Tx9IW){巀5qa?x^T1`m1Nro9@ b0FB$wv%+at"ju2ΐ"{s[Ӡ˺M dΏkG\}zD&U:x|_>SX<2A.eM3V^14'IwiŰ1JXe# b\*ݓqEXeQiD*STmA\Vo-Tg >FI ]Cu8mJY&trXV"̝Pfd$_ŢhaͼH`@]{=8d o.se#bM:mNy'6e]~fg )P&d6~4i}C#-B{mO_Fw0|"W=Dٓ\tݮYօ!6#eBK,L37:f0eO#xqseD:#EEEwPYZ}h2aBO{Xaꀛǽҳڼ[7hs$%(I*e>8eJH5+(|SjYP5Xtl}Pa,z@^`EItZVO ۤc8-&kOBt"9ӛuN^/]ԔJׇlvR̲(Թ:rMCZ["MH{2V|#Զ%Ú4@Xvz˂W%H½tƌ>F?AN% LVnhbΧ^PV]7PSʮAѱg g[jw c2Kn{:e[s̉=@ATIg-* 4&d?OߋoQ. $-tJ.Vwiyv_O\܄{4Y5bR0uʨK k>NJ[RP +X '+ ݬϝߤ/N 'l-O<JO$ׇ5[ ˓>V}hA]°`_C.7};N@wxZVw"IS11=>ǰ ;u%yիl nZ 8K%wp؄'T2LXH879ߡGFl:ɺQ 6h9z%!1>_( em/ud?u4Kk3, s^MPBx6q:8eHvIQ\mvվ6~QhI3K ڲ_-i.O(~M+HD8^, (Ʈգj[}f1ȵ])8) •h=DLZ (͈AHwG_昍(ϩ7y=H'yBFy]|uÎ4T^bi& X:cn۝%Pd77\{KJ[qY lAZh\F&(Qx5֑_NI%.ĽLW})ܒ&@\f 7LLnPk@3E.W3*}li/\B BB:x_%PkI잰'mA6}CGuߠKٙ+.ib(ǫn` <%OzTti.3'2tDV!^I,` U6 pT fh fϛۛAsq%k:_:`~Q/\KrT_(uH2> !p 1%\=J4j;X3Ӳl [(Uúk&ʳ A;FɼRBa3NbSO@Rr'e67.(\7«Y8V kg%cbQ2AIs)g9$9^GGb~#5 \eUj gL^ӴWKRT/M۸6*-R,NW \;1vx;3Pl|*[[F?kU29qFy埼`@,LoOPJ\rJ|+I?OܠlcbY~2_wzu-?x ?+:m. 0}LVNW}3yQgsOY% i(p%HZVVjﶨګgf^hfKޱ][8N-<#xGڕ=Qh4ntHRТf zb=Ljlfr \>7ekt LQ8n߬I/;TUNHF.lmGfv0/x5rgho12BUQrQ55ACؑi ѓ((XU;̦T@Q3^rA@WM8!-',7[a#C(49Ȍ\q'dN&;deEwgDuK:.Ph!i삥bg's @/X* Bk57[&*׬-bZ3e(Ґ+<=ǾՊsXx{S=2H',Zzm˚{jC=DXp(uZ,.bS<oqlsU53bއ8HhΣ&_=Y:v/J V[]6`=A)v\P2ZȚEy.F7JߊqĢĀN}i%vQH?~oTPL>ӕ_FqÛ|ѯqI`㞀RxKyZ`++(㧦`Lwh'0&j9_$"Hj6jϭt%S-!$J@6\-1hl;#J>wB\oϰ5TAʈH~\Y9ɮV}t\ BKdU>}-kN$~lDkEu{8XET}ΠknZ 5>Ux'xx[.\aY<1'd_l& KlzMS N K hW|ܯZUq nJ5"*e՝m.?BGz>ոsFLq>ơd[Z+dkJlϓ ݽثȼn 'scWgDr@mڎc$w(n{dM3XHXuرVMlb Ok*:J@*ty(pEMk/7ܶ˴J<\?-(jRt1y,4yˌ` wr2P6CJ̧Mx6~9=W2^Y݁UO;H}Prə;hFưRLe_EmrSFHX1%V7qLW"e}گN U>Cz)hh =r{1b zmҖ6 HZR|[GFLGٽ_26d`I.,NiFΨ*$y3Zp=6݀FXƒRlCnut\F-|S[?pfTR+E,]8(\(F)BKmԳNx([U.0Oh`fX;Z6--tU8ϽMcQUMLz #em2`Vgp} 1%r%@](&@9ݲd|e3,ytw};E҄ ]Pi(QHuYىNܝfQ"6Vdm4a( T={t5})>V$[z94=Ϭ0vzqQ;˟!UhCaL19X OGLjEIe$}b@ )&6pMܙ\u,Rg~mnM{r-$Wn{MdKijU"GS\*){#S!/gLˮ @+;:Gh)(&cԱdJk5 c erh1e"רu]MMoPj)]T!`ˤIJOu*u#l?c뢾4`!tSS(T TWF"oYY9-2Ũs;Ƶ>0 >R˿1]l/*ѿIFӍtbB ;ouja|z^b`miAs#?"a0Ō3Ec@! vqrJ, iM'+αشB= (7P򏨲7Tt dZC)xeZp+ ՛%Q&\FdZ9}D#y}آ]YTT6pW ]]_[`DaUFqXBNJ]h$ݼ.S"Ǔ5 1oŭYĪjVW 0yVhI!ДA?K=5~պ/H_ݬv*um|VBSru{52B+8S&Q\/E/裭ëZo?611Us+ p4Oъtc OP7IK Ϻs*"2-;BR\s -e#7ȅ}JrgMiG5`hwhR?|q++yͅw~GTLt괊&i#Y( k'X@'qAOڎ@dNG%Ig"9o!9ZOqYSqNVڮpu Kyt,!nQCZ;KЦP)*@ql;  Y s[(E> !^ajI:-R@*YGbN׮HQ#sM5ofN8yN#iq7әWḶF!)о0{]φ[?*vDW%}og:o >2\;5N[9YMǻS#g ^0 4t)5?'gT0j٦b0SyU\թ3~|?ʊ>zNqx4Q @p0 $t?آ)F;(x$D% ZVp@[tJbyWepvٶR{'{JS 6JXb7;^$\n >נ/bRϏ~&;tL@kK(0K*GUAHʂ1 l& lnJoQpKKjTX+<=y-(ɂ;2R \܌NG`Q1$A^uόW{+{]8 Бj7`B HnݴOĄؐ=WTҖѲUHMufzgoLj@6/-uRA`# avqӽcC?&q!:q;qMtP:}lZuq5]­+kF hƒF@SE)bɼp:Xo:?|K*~LPjoF9.$&H=.+:}Z8 9arg#cEw6LlaG;묂7qvٛyRg01I X&e5uSw6K;IF.UeZt^1U3{"s6ެfLVCZmX0qE)>8~깨uR]\Ktڟ)u@wjTxpD] u̇T4jA |G\w)rGd}+zg^nI!<ЂKanȶfוX.bIolSr rYF5WIM|<XBpC;j9˓!HOrO pBxւN Ty5TZ|N2nqSԊS@g|?6 =tt>u$0w}vNשCe,>{a8+i$U4f;CIs=:䒸x g&t'h ÈhqꭾhFe;FO>evAdM1ߐNM:);-0)f&?}m쓨y~"6{C枢Q][_k%PIwl)4u|*s)hipRk&_"N4%x*8q evtZ;>Υ 񇈘ZL:,qv]bYUSx&C;--:Zxo`CM8t:)(ژ5o88?}RoA[?&τݶ<艍RڱN]}{aVldw9?B"FU=R%;('/ N$Gҹ 'ksYU; 0 ^8|^)0d"=Yrj gRW=dl_cĿ'IFJ)YRN,D@ec'= 96b٭TϦ$ oe]>KL:bZ'3Xi6(Լu8T6D|c FcߨWK/D…iϗPFRIB{ \mX: uT";ª1$]z3vY.߾1PmumN|eJx_&Tֿ.@&mǢ6dv}Q{uHvUz`0m}3xt}ݻD&<iVCSO/_۱WFSE1R;(Tc ֩6aTM7f T+Yy!\}[^!D1 q,T\DQuj%1xTΑbqbp)9,gy9TM]{IJ@5DUݮ53`o#5>mXf)k^g8Qr:%pYI&1W0w*Գ{;.)gړ fp\T2sqLa6v([KZR(',M8D z_JwQkjW nS2ZZp=lFhN!#;Lү!O=MU Mk<*dSWJ[Ok|>A2}5O҉P{_-Ѓ.CnaSLm]l,;YQq)bzL2g<h_X6p] E4C ۛzIocD$9~!ib"J,3U{,!_DjOHe)gTY_G/Nw~}/xh ď䡢Cv}}=ZUWתG,ZV&Fox tC3)HرLBROM`5)ܽV۱?(M y3xqV~"bA])DE`4-$.pa܇\t6c Z K9>g8<'GΨc`=qΕH5 )4Kn|'1E;ܭ/쥋ъbn!@j{ڂ c/%1l. 泼),M[Ciq<7^=C+ũy19,x0'EU W,8pzw%[=$jeB&\"d6oے nIM3?0sP(?!dnI="kF*`RcVFn S9GQvŴ s50 R~*]H%wҀnr'pGQ|q>yCS߫!3#}v!n_m8/a*Sa1//\yL(]q ;C$=sC!j[6Y^fh=Lg/St C~T xٮ4K`䶄T, +}=mSlջP?z} Gv.|AGKd]DͰEtuC^_VlsP|f.L&ykLWbXAnypN|j#oVg;?hL,-s\cO)n\lϨި*su~Ԣܦ 6L=f&—9}3CS`R !FlMTG}$${**B*3`x<洇X-< Ǹ~7Lۍ{( I iѽ# bY ȫqk>,O ( YC]'`]B?ڬh?esۉ:U+Kbς:q>lbia;xgT?S#dW֏lc}k+;Tv4 )>`Y)rX%Nmm!o˘ 2(Q& %vKs8F&X< ? 2rưQddž4h4 {lP \v'@k',MyԀ% %LwA_ZB]E<"72A??$ڷz@K 1AM׿I}}m*)J:>Yqzra_HɽBH6{i#֝өj}爑G)__c#ހQTzeRp;~לAQ4=jun({BL ^20ư^ $zbCQ0- @K_@෦fy.BU`m䵚cA)9I Pf:ͬ*xRȢv fbۧEwXũ'ȟU;1/R«Mb'DFY`4F6_C9R42r= hJ M]T0 vdBMyݯ_wG$Em[:7YaZ9ܜ7bņCÃneM[kK0,tEi@:fճݑMl"fp$ ҵ- M@kzJEd5,c$Ou |A@̕yp闇wflG =TC98Ԃљsqrhb+Aͧdx7:5AbLr"Ky8I168'9𲖘ܛҾ}lLl1my+`ڳH<4o*,DEcv=2x`$Ik!iN $.{ sV1DǂdА_(ebCmU Q5y4o\Ei[U*K_7\Kov4Iߠϻ+HĵV&eVJyOT4Î(_4.uf#f3qN6/*cM5`MՎ\ :kVS|C5 k[$G] w#}1@~gׯXRp;Nwqe@ɷ!^!!|EbNTvO~A2"j8 ތAFd[Gg|8L9-JnvnACh4>Li @@ڤ),g^[jxu}\M'ZLB[;E~lBS\G˶d-[d)4XJ^G6;rTPWBCh`-ŭ-!uKNF _bNxrt6o)^7ȥ3m 76\G\Lx~Ev9$1;,M~mCf8#*Su@EH^:pV?U%JPFZm5 =љ2} _#yǭ3Dfb6 ,2%&ein *TeqptWs_\ڻA~{o.`(S:C0 @{$ &;(šX$xdr|ᤣ0=L] _b#:YnL5il5t^pgH:H:Q\b4O|0sAQr\".LēET ZcJ^n%ȅ&̍ n=;*F]x&(^DI{FkwřO6 ɉ(F5Ӵpt\\OGH{ZR#UHrcq+mI D2h[:03Drw"PG.8FF`*J/קQ7{;\;u$ϞRP%q*OI)1wn{}uf+4 Աnu|eSd"QZC!ċ&rj2P}AAca%kS+M?5 *f ʹdWQʋvX{BBn_[[X~"lJw?U1Aqw/apK>zǕ$$9J>Axm^֫qګ ˴$$sڢLs {G։&qE&rǹ|&=~SvGz! @DF͘zxFTe9Mѽ^|$\u 32@"fY<Z]~uY] Pn]hR/Ơ؏*Լ5 ExB@$JQ Q.ߟb;=EbU$J0Yu٫|H"+X3PiEN1bvgE<ɺ8Yxgb^o%|ybRB)H zG zN9 yba7]a۵&b~Ђ;$TWʚ;7#nkbMͪȈ"B҃2SDOj`ڨxA&pڴ͑QP&>ڈnocvVտRJ]ayx2#VV/V r{YD/KK <9{>v{UȽ!M~ED`@hl] 9kGLUMCJ ]9c`5)o8[>=D6BΏ5ß=`i*Tͷz!lqf1K,QF~AEymԡv.+}Fc s}|(@(0+x7BmL "4-4uL}x&wx)4tn8SH8~yCJXV+yڪ-+]+")\݋wPx'By*Ԓ7|GgɪNAV@g&mhP1ċ=EpI P!#.i(Zjtyg,.4|+KJ> Qg\%;ס ⛌Wf'Z5_nI%ѩ[F-bJ`F*u;Xm%Uٯr|:g㈔Ja{ouX.ۛnqj:e_[uB6ʄ>U EUѤ,QoOS! فn/<<ɬE{w|(hޑLC4J\908u'aFUe)6bAw0><WI14ϩs[x10%?ӭA@Ќwv3&5PL(AUROW[Y,ҌRUI$ZxL+԰"0|eԘ=%]",`e/eѐfgw Wo|]o^S3ϖTr)'yQ] a P:`PBZܱG襄^5WI\%OToq ЫM 7yɦiG2)r:jdi#+>P#u2I}k*g5 MI"ARD$f'v 睰liG6BW=PQ*|odwO a>G#v(]dC?Q\[!US'xT;oMtH[:|Pcc EXyl+fҒfSAŲ /CۓsydS$F5L3^nQrhXGYVk#&~RsD\Q_m}gn1N ‰2_B+~xWxH)0oUe"2[N=!cگJ!4=o{pLFs x/QdS9Cu qKQ3jvUV#҇ue S_`ƨ RD6&DAPG.8K}ޢ F I9dY5c윂Z5,V'D]#R+[SyCM!{O آZ 6)p:4=MH6ed>ρ%Ep\I$I݂8_8X`iCI#5O u_\҇Ό:ЄT[G\$"ZK"kno$R-3+ImI g0+jOj'1Su#z$ 3vɜc(u.H2ě3u]!-+ֻZ -C| !CI2f _p{ &/=ϗ 1 ߓD؟5p7>Ƀ |̿jߏ C'ϯtU|gna ,NRZ,(7Qhy9*_2g\*,\LfE/hTpyPҺ>ڛNsdډT1?BH1ePpXt'%!1#K3X6w O-*ŧ:q[&yZY1_6;9*A!ڌVTgZCIy> g%5PqϢYw&bѹmLUwxIY/ }wjqCsMEeMԈ6q"=ij`1|i 9R'T8vྃ{5*{na@bpr:ww:>ܼkF$fq6>@!zpQa1P b1pC,P܈ s.M5K_Ur[\-s3iix1;LY|J;#QӐPڜ%,l2V\eZ! 4)du+"au[{Ḋ^?Z5Tf/{=ǹL>6HvTOiː\6~ƽvy\cFbPʝ8"-v+1w$LUw Ӌ]ܫjW4ޥϿpW~h&۷2{"wa @ :$nBL<]ôՌSvyHn^P4jܷޒ·Tz#!r֖1L>e?ck`n$$!vS)vX]i\ qsxˌ&3l+ÄG$љ͢pMH/ W*~ zω;CpM{Р1 pŒ )'^ z8?id p]ъ)LWݍ_4"C盆SY5ZWVɖ|\| -'8rmBҝR3o9oR+4+lM F_A,qqo,}ڎ)=xW2g-? fgE_ZL-oWe?Ҵ -CN9 d݀&B{` D}j/e͠ ˒rJa?RZRgGzk) u[[1Ğ[U+!Bh fEU7Dх@Il.W DK=5?j}MbnҮl(5o޺ƪhBkVU߹!+ &uyͫ|Mἡگ/b8)agMJYپ Qqwsעs[z rS|oIgψӏ3'kKyYKB[dX-F&w=[OsUw}kjQAJ˦(']M""&!~ VQ L,5jwoM¤ąd?$A?VKP d[lXf~6xnĠS BW$*w{+`>Ҏ1(D\衃\vЁ& [1xG&+ۈfE?e{_^(ߌd˩&LU j2f\hBOA0 \~d@&t?ylzVIџA0dƂKblCƶR~VV{#NPGccȺu7ٿݸ:?|{H_9iֽ]٨ꚥE/#mA|1JAv4 ~P/~JDX6P2@A[Ӻ_ 0[II] ^NtGRO4H(Od;3sw`菺7GX"[!$H-#zٷ62^Tm;N5/8.(,u\{@)RPRR8*Jܲ}tƥF4W| YuafGK(c"ksQOR/ǦߛlMeN&VPTkTҠKN83d( 7? blL~^٠9uH)uZ7٫kYER"OOkȊX 9 ;^EP%5xu( _hɧ&~A `WI,Pfsm.MM QU P 2_?򍎠ث#C_K}ivuI-pND];yhHbO[߾zFˆFuve9ͲU{]1Zw˜#+]Dk$Ҝ+eElxӛb)Ѿ7ޗ7M ޲%&-&Py9ɕCLJGWЫ$ ZXBpp_£Xlˎ5@x/gX' Ex[ηeW z`+pʶOk۸V|x*v)Ws)=@axpD(>4Α6֘DAlX^qNVGL@' ﷪cs!~CБJbxl抨z|!P(œ*ZMG\*uL}"i<$ӃK6TUxOɜkj-ǤSlΛDxruϩ!\;$߅?>;:"ˆ8p5g׭  w"2iUXEf%}DM>ݽqg j;S♁DHY-PO;4PTN,( 7{ n1$KǦpǾw@n(& RRa&;%\)ֱƿ̰ G˙>+; ~uª34O0<"DbQ*I3ֻ8¨n%>$UvYAr'G[*e\!khtK9.}=IcAC"M #vgY쫏`%sr @Vc7rԺAjFõ_;? RF?F%UƒB5qަ61|P&HtdPvLq;7 kyᲄe4K3ǰRt4q{'!`XRu*_$97>:6 Ib=5;j]mTǹJAOk:wʛ)3t&I:}jku uf]·#NZ]jZxuؚ xnU?*lGW&oQcTJӤjo%d cb0>'14Mt 9(|ve0P3ꢅP_-[^S+TFaR51(p}R 4J(&9*w>K~Cb~mR5/`^a2073UW͇a\6L[2M2W>;UN1tRV.yv%w((dSq&5 ;mI<l"xHn 'kϗROspzUӢ}ll *g̒n\AwNZ>tW2啶)=&I<*]D)_D[RZ@ƀ $e8ѻ]nVq:ZLl zp#TC ΢.zn^eAv7H.Z{xtm,QQF3In՞ % -=eZ4rźHBtkρ\<>c]Wĉ5IG GB7T͍S#>U QbVCr[E<65ASϒh9lz`3{O.rݎn# }\ :ρl[ac*)E*ZGQF;KrOzGl[df*CkΚ 1uZ.Tgu,uV?QJ\8|q{f%O~}rR`SV` 7L.AYcB&CrwCv9.dw CGaSm+45 xGZ9- ]c%(sNXj"\4e؃G x~Buɷ11cчoOC.GW{Z%{f{m.h&Ra'A(OWO "VfxzScWL,a&rCe$֑7/{aK@7>4:ڀ.^G3Jeaͫ${Zpe3po"Pz ?`cm?qv~jRl/V֛vL:h Uk\\/~z HƖW=|-mu٦I.4A HtPn }``i ƛ@×}Qҝkl}ϭ tШA? RtSAoqB-HLƄMK#,oyRDv]HxXwg$:c0zA!:L9m\ܴ Tw8ʣ nĎ!;N70Ķ"jyi4ɲ+-{?r@Y9˅dw+Ԏ&$aJ+v3Zyn;/riѡZ5]:w4gΐڽ@Ra)x ֌˖bkFyX,6y@]KkI@ߤ:O'1X +jWv=d"88.,[iSkXYW??Q zҞ5"RK. {)${Wc53V>y*ƉrYS|qoր 7Y>Lޞ(Svߡhw!߄r$E+l ÄV p4h4?] f\EίʢD<=#*,sχF|a]挄?9RtdCw,#_NsFX-0\Ogh 2a¼N,3p_51BL rDƏ@6ϤXzܑ>, z5}(/'27jۻsh:yJzi|w,?K=y+ΰcSU#(Q‡j/ ^lVn FĈ1z6KF_S̗IoBNv'˃ho X)v6B8D#ly:ҧZ*Ⲏz0XhUfwҷf7epf( {\dc.;IkQ Z8?ERaN4mf//fdW(jYaJ)| 9:Qt $PٱR;=L6ewGNql ,c  qˁеc#%xqjCx]ʣخ2FgjE(lRAEqF*8m@8Vi@at-hC3n77aH+XV[a-=KB] EuJd|LlBӆbfp`evg]}*N>IGö I\0H^Ԭ3LUzb͈>7[QQZ|oj4c} 6hR,tAbc/##/k^S%Uj"UxuhcF Gɀ;00>@ +OtNhu[c-Eux^&R i|x *'jdY#WQ֍M"-3LNً۔j[T˄-a)I9.+Fp^26k7.] <ęac[OvW1ѸG~}K#[R.65Qśˉv1\9tM5`2.)vwtwV Br;):(hgv N21f[Xpp->ӴI?+L"*k|[Pf+9>mԥ8m!#Y3w6 ;UvL'9?`CQS`4mS{RnGU=+x ]!u ķ)Orr)+: EcM4`Kh׵l̵(jQe}Xh;zqh{nW (+txyQ X6OEDQovƭɍf?M-&IEz,I[>)5v5F#xP4aѐy 7%mhڒQ}Q+?hAh,eO~ xZBb:?ŭф +sqƘ6%I *2H%au=lZFI ĭc+!Bb4l?:]7ĿU4;{օ,eRU'C*bJrz]ZԲc_?.žv#wF57I ß&gf>URw(-D&dK6?5{X ހPօ2W%r9nY$֡(n_Wy"@ Gh'^+(\sVyqQ3l@^ڝ>͡K˶]eNF}"w 1l# 6noN"$I|# G ]s`L@958S?Q䣆w'F`Dv_8?,OhGy8V^n_]Vx"y>8w(06ők \Lbnev"#9o_ HɮC@p G P]^LQk?X4RêOY ;"xO<}lD)p O($F%:yBWPh5  y&TYxbZe^W&>Iow/[=/ ݙPHJJ)'c km{뵒w; tCwlr%IOiQ:TFP*@wck$(b əpq\Oo9Il8!0묃Uum&[':9H'%!b'u6596W',C!>šd֫4S%U՗"Ν&1.}3 8ΉaOSLui\mbcĻBҊJN50qs(cbw@w KeZ65Vm,nGRZȡH秙SB6]|Pq`9c<^ 8, _!0 [ o$m1WzZ =}ˀ M70(XmP׈5o˒|NȌ~؃ⶎ(RP?.9aT{~e֦^Bh1HoWəؾ=d1{SLfDdmɀ~HЀoާ|_%\ I`Ét0Jʰ84e]؀`$wf+1$sJOD/\ :~ײ?&@מkQA [\`vR[3/=zZ6f9C\&<"/!x8<L6s ,1m g.W6<ʟchR/pEP[/Fg[}HˉK=b 4(>\O nZ߭vhnbscȑ%Lf&CY>[PK%hrSfxg"|R@ eN|xS/l7LJV,/dsq~MgC񴨦گ2_?\˻Qв-O /xZ8~+HoGNna5iʝ$CYƻI V}(MICiCRA׋nW+ AGWI´ƟN7bm?V@&oXA[j-Mh&̆_g ђ6CieTmjʂp!~P-L6| F|&1@ &mU~]}/> ߤp\]kO>@۞2~ <%F%kEJ8֯Lذ̩mTNJR:_ .90|N#sŌ bRFZGr ՂS#Ŗ=DmS={#2LVlrZFes{\6KnS7g̀w9?{@ü?q9qTDY1"\fcT 1[C5hvMK=|l; x "ds)ja'qv ,<:r.CJf 7+s3V5r#U֞esg77L8Xpܹ6J;H:wMr~w;At &!uC SFT5a 8R <} \j*}<$cVo]DHrByqm紓[ܛ&ȕƐPHn϶{6֗CjZR0> ݘ;DT( Oɲ-֡,1[15{FjV8$J dZ"n&C>LLJV|ǥ$TxJk+=$Zz<4RjP+DAx/DAu>Z3nz^-ҡS5g] j&'d+PY֫$؂o*Uzx*\θbޏ03Jr\F/c7CQD$6!DK,>eK.6K#t6B2 {@<? !PSR?şC. Ln68$QM,#Za ZSH^%e=(T(-R Y߼!y sh1 KhR yryiu}6ssV9D sc.orr&U#@"HF;<'q{ &OVʖP@lBgйAE=q3rs-+/\ 88a=<|āSiG~jp aKT{ ޤZ%=Η8!-ڞpwgk TZeO6r]?j=z6=*>~uriz{\XS`n(DQR%yΪ{jCA|(dղm:G1󢹔67ka˚w;4ب+pxSۯJ1?z)EP5:t~,ipRS*3̀TC:L@+;=9).puU,CGcϘyPefZ|\N.3f{GnYW$\g_`Br) HX k iA^qw3utgRt GgũU:+j*D7^h Sϖ32*4AME1(G/YH Y ;i;o[I21B-19a?ЛcM.c";KP>) Vܥc C(yuj?uD;Ti9Q&k {NpUBOliYbGRv^56U)jxj;hԾnZVЖ^{Sq'0/P+_6C\! ^c)#CQč# Ac﹃%Ψ/K~ m)x$Zd{6^7 itHD.r@~8JL~5@a@cLKRwRа0Pc?r/c@|]D x;&W:jN b$.Fl/}+:V^J HR!QV7[!o;3io2f(~fk$暄GНlP:U.>.+#8t7>0A}7VkUaݔX-y5X̉.k$N6ό f?*ےcޓl45tf6~ek X,_ t9VU5i_"w_>qw4}3O qXV'|x.fZpF!\6]^!]ڱ! q usDc5XƞhTXn7~An=-}׋OSY=H Tx46])fj'r#0S[mS3U!x%͋ dD)!@ȟԆ><&`[ QuTd)Jge>-"HHu?R wK"nkPyXWs0k$fz^uqLT nDBN@RF |H.}+sQLwVksPgUZR*(hZ!OLb6"ar JJ酣ɴ=\cO8)Pb_d- YZi~ "":TBb&(Z4høkRz O7-G/;F~zaIгn~25Y۴S\t&v%'Tc=,B"QvgS1(3uс~X}Ah>s"0ز+6E )epQ%/Me?$HT28u"\`ܛE>!dpVNB,cJ>%{54שXn\)y3I *;,HQ,ߝD=,ŧC#ul}[iz(QOSOW>m|{Njo0 ~E?FfJNheJf7]ǯЋa $UN,Z@!H:,'{?)Vlu :nnTIŽj Pw⤜npzsvMɬ 8A]GO\Av@?N_uPi!,aqIJp+G# L1EĠjb4KJ$^Ǽ Rk|PA* ۴QCnx.CԗRR|c4,y;J쬜$~uhdSoxW!~5ܡ42vȊr5^f`!z`@Y#ʿ[2S%8%EIBVFݶFbzd c[fnB u*V; 2t/?\fyճ.Z6}FTz*YH:hD69ߝ<*8=9nwwg^0E}RJК9(#N<9B[B@dDI7gLV0$f|Gz'~Or$iy1k8w@:9c]8`߿lkUPW+ |ףd3Xqqn I4\n|, IeE:kh(&qr')?2E&Cl"c3*>0"2UlI3 ^N׉*nWGs|o?%k_$dр0\ ;BW@_=SLِt `K%<ESK5Nm\ BE^Ri"cL5}p(i'x~,(iUSH0:|G65tU5FUcy= eމzjґͩBd[R~=eWKi9ӥm8u2Vx@orS6ǜ(I*1z办cK ${jY“2FHjܮ'B <,/J4 ̺pԑa'ݼ#c&i)orVIm)x(?5-earUw{H+N|CbK M !!8,+amI5Ųt`ގ%pTq 1e<]M ,* Au xK^jdrLHN9]&3tXyT|`| KuUL\ }^@ 5 G1Pſ nc.qg<4;avTr,P{(Y3"CC ;$hG^-+:^`}}Cى_t-2e,lg/+̉р{iA-A#;]SPmڴ]#/ )nU-疊1TOTK蕱7w1Mn6BhqWQ @c6d !)EwR77mlha6qKm/I7%Zۂghil{eW]Q璈o.և:ZT!NuPpok D:g۔ؽ~!总E)v]Τ\Ti "=(R Ei5d~v+ HVǀ)qgz.Q rkbM3 q?ca1aR72`WCֈoש;\9Ts&r@ihTUu:id[i "B/ Bz[se> )jVv`=20DOh /ZV4k`슕B2{V@cWȾfH S<ٽM ͝,%k5qY q@s!GQܾ.2\ &&;kfqPU>t|-nd':C'_L(GuP,-p[VlE*>CQ4(kD<@ZǸ3aã2?ګ/Uoe!|NJ)s !DSVI$7GZiKnQ~; T~v+g?[p6&9iutnۘQ8m@ƀۻ _Jx7 ȲK>Zbe"[/zMǎ[gpC-x1ƌdvh9t^HAh+ȒGUmzII TuQ%u>RjY#GXOܔްUqC3r}8aLILx"k,b׻!PYg>@3GILB}WX E"7ڷ @F+lG ͩ>Ĵv, X^]VjwuԉT`ǓE3x7kV> A*sDjG|ѫ|Un4i nF(D+jtr\Uw=0r#t'M(J! zTbG5`yDMaN"x1逫+${czψҭ} I=^&>0ȼ~>$ZI uOAC*WJ3GlN2HWE+@+Fg92tS!:mS-a\'w{hɠxr70~EN+".l;m 7̐ ü$?m.]b0!M A`<),$o(}׻B~kj$P}}\tC>zWIB/vM%r?06JʿQ6aꧽ^0- Z Qt! ѥ,#=ϰy-)f&^63]2JLnv&;̷?þS9~bcfRJUEiU %5[΢7ؖ7}]WqCXQMu;a[V uy;xd/ej^@_%\,YCsDA@Ef3#u>2P0x @$cQ4Orɤ$=$Y}ŶӼ2^m i;o#a5ZLG/ ;;w93^HQRA|k7Wa.yJ;ֲ 8PN _501 w1QW …PtA _6d/%K*][q }D]WekK":TVԇEk|!F $wŔ$M}M_PVѯ1=RA Hu>3%V&R4pԤbLpɵc+ ? Tz|S @:5eFysd.'ې_J6dJ}LMvv%Tx<F7 EMT`V1Hu-XnHV~Mu@^q0<>9*gĶ\_?+sl-srB* "ٌ{ %TPRPp Y]x?COܡ۠ T/"~bٞ# O~%8fy#$4ZRa' s kWי^Ͱ^N-"f!SжlL3|]e~IMR14QlkspcM%D3c04wbWRC|f]5ͩ57eHhl;E>A%Hx/#4cZ"ר-\WՎQ6l?D)Dj 5-=i^fD~ad ""*HF ̆}GnQ9]rH;Q[^"n>SkzOt"ڑcHAO>!CvÍ{=><Qw^A3əC^YfX ?yԳT 0 &gn7u闶Z(9|Ew8pt7ؚBsԮ{z'v.6yJWExgx/ڢ19<2x{A}wH~ |i'd E?lJ`w#%XNȉK囧'F.>\Zr,ʇ+#?6JW5)39V Q7_XbXVsQ-|vsM +}aH|-roP[ԬC8:wp %T|lHS55.!0ȉاԬEj^w⹜E g#C%.f=]Ai31l]Ev#P|m C/Tk;NJb}4\"x#e{a+b;!,,:b&^K0sRyGqE ࡿ#e$#&vRΟnj}X郡,+u>%݆^z D%TLӉ15캋H S`Z,sХEkQs+dnsn}/swvZ~ QF.:,J8NQ#Y_YfEEj :+;!ݮ/weH~l .;y8ػ}E /s{/͖^Wd8(֢xaRxn@=KSbݶ0 6!h1fq;P Ӹ~J$a|VYЌd6<κDrnVB 5T 7j|K_C{.c;6{ZoC*n*6\?체ϻ0)|Ft|g; !+V5O+==xaX* 4V;+ PVUakC ]c ɣ]cݓjT_8&?鐝_]ѷद&&e"}՞\x%kjlJ^jh[VdTu+S/Bh˦"eG"FeFU=Uzţ팗<oN Ae\dɾB9lI@u@{T]+cԿ#B)1aױ'5ҁKa71L ͚4(fu`MT-S4yVEEXhDˑDYJ:=z e^wX/>}MZ'9ŃESKRԀ(R\Y=z1 Vw>5c%T3͖ӣB)'N+]ŒGOK|\kΌ$QYx=&'1Kc!%?S H>,TX8xLf3[ 9='DL/z3Lg{Hj4z>*x،0>-$Ɓ~h g9SBT% pq-6x+ZӲJG EUh^WD/s} ˂ ;G`q It!OQ <|k31eB={' h04{}m'R 4lu Ats"/TUrbyv" )Z%WZl<G*Uͳ|cZZ>Ԋ-ױ&gj4@^8çﯜq0ʓ?J2Ht۰o7@컩vaJV9Fzc眘; 81p_ T3+E9z$EmjCo K2/a:5>ڢlp٭0W@5~[Cv߰MHGt<}LF ;{O \W| ==Pv6Jt㸒ͣ&)F(A/2_l.]ey+Xk 85L3Qeh_}2~Gw R^5rF);箃:ś);$pD} l_KDV@szA/ُd%"ˉF~hpLOwT؁jPLRG,RV5WT8,`[?PݗK ƔR2Ma`m8(t݇š'4q'-ߘ@ɂq7TxrA4sB*oZO]DIt+ 4W̡oL 7 B?d!3nPMuYyB"_bIZQݠckwDۗȊKU%T/8H;q (Կ71^&T6Dj=lgO$EPSJQ0osY]&Ҏ(GN}8G߉q?wZH|{PRJ'Uȹ*C'NZ3xkZcCBnjBm' Ygu5{)TQO)JiTX{Ii3ĚIʑftNu=tξFF?1x?&=7sJL?5H f =e E C=zҪ絆B(u8P[>!_<71 &{7$ƤˈHi<+NE Am`!&Br +."}.[ي9^b0'=~ud[%d0e SZN+4.瓶;IT*[U#tv0gݟ;C>Dۛsb!NB2ijۅY"c*I/!d3U=(@@Sh§͙l48YץZu%uf+5F}2GzLzJ':xezƢ\ֵfP$q+r`QcO#!Ddܺᙶe~mPgyDS!p#m qDt4[@H hLɰtٓ< dz'=ʽ8s€̹OjQ!٨]3Qp~dd2|uɐQ'.kRMNߵ.,Y>yFu_gW] KTnQeWm|־xP:udg>AQY wt$ft-{ZDxGk& 2n32Ncr}ČԲw c(\W=mk x uC(W8]#F]yRqaN腋\_ DW$ w(ezj/TftUQ7Ξp(VۂPsՇwz̢}>p@1ږpϾܒ1rsԮ t7(حV]FM }ͪsb IBBna mԇ}%Ӵ<ܩB)r̮TZ'e!1i]*>f2gBȭ X[o,-q.;!9 UCFNLo,6gIpP,YۖbJC+S^ bJL$')>S7 ,?Q,OO6P>Vݤ>H M(!vf1c,9oBS@+# ٘ > [O!]4呡'DfHݎ{N;nYoicR$ ˅YZz]VĐ*dHA TLG ȥ=ujDRSU D^ Bܶ YZ