sssd-ad-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!N ]mtZ`8F^c1TM騃jǂINTq_~.8P+` @Q৹?:ڬa㱯/p Zq7wӣNsUSpp6yHLFXJ<ժ:m'Sgm pwb<`FH$'a4 #ZEzȯMPgg-/Q!qʺ{M!ˁoL ( o_"y GS4VQA~I>pE?d   5  0Dagp           4 h   <lGG G(89:i6G| H I XY\$ ]X ^ bd`eefhljt u vwD xx yS +<@FCsssd-ad2.9.43.el8_10The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.f!;ord1-prod-x86build005.svc.aws.rockylinux.orgAKojiRockyGPLv3+infrastructure@rockylinux.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64'&K:N>oQAAAA큤f!;f!;f!;f!;f!;f!;f!;f!;e+f!;f!;f!;f!;db3a35b05a978518371b15060c3eb11a0c2bdf3a811edc7bc18eb68c03882586b50f4949f97e60acaf4e537c4535aaa891afa7239ff4b729d6410f92b46675588ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9031eb7f743747b2f6c65866e3c83ac5ca602b86264dd036d6c81e65ec307fd2fe5f6c61f6621f3761c9256bd8d9f98c7e3224749f908b2167348a44ab76a6a014fd7f0662cf41c7b180167978349f9ab1e32af29b88f5617f3aad4df5d6c4313df4b01b3f7a0f77bdcec6727b15787aa846c98676962de08170192b806a47ae98b../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-3.el8_102.9.4-3.el8_103.0.4-14.6.0-14.0-15.2-14.19.4-3.el82.9.4-3.el8_102.9.4-3.el8_102.9.4-3.el8_10sssd1.10.0-8.beta24.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-3.el8_102.9.4-3.el8_10 .build-id0ae9d12b2b127df483e5b5edfcd912b8e7a046fdf180837b35cde8506c28db7012ff204d5486890elibsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/0a//usr/lib/.build-id/f1//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0ae9d12b2b127df483e5b5edfcd912b8e7a046fd, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=f180837b35cde8506c28db7012ff204d5486890e, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)::PRRR;RIdMølu|=x\^#Jl#Nשf9r3 GI(K@b^iT  +V[N+2 MA-tE1hȘ `PԆ(Ԡ g~* Hd8=!..?bm,/飼=U0y}Ԕ fjUa7>Obrn8"W镇嬜ĺPB&fu^nK LSZԦQpVylOvJlfLk($>moP@[WU^;u~ClC m92'Br[bdRfE=s@.4C| ƺ~Z4 ?qot^WoTgRz EN&-, O-oU=a4YxKvgsm2siO NTY-Vx@WWRT͞v`D>ݍas.G( +}<ϭ)Zn7# (,*8#KO%6cL|k ւ=2KJkh̑E?D7b Skݨx9P4$A!K <˲uE/}"oXxmʎ ©qF9HXH^Rwld-!QgfI3Y6MtV)@)R6H,B;:reCQBw6Y[F3U%G [[QOjwS(v /+5*FQB,"j1AHh SxKNHi:"}-KtigFRiVG dMz,kMBFvC\.`E1UOTPrw8?7OЈfRʁk]] H[ךMQxo:27;*YuV|j!(z3!`l [P͌FAF:,B!A"C>/ ]K*ĀGI1Y ~f}wR@ֆ$__1T9*} AK֥4]3@x%Ͳȧ6 I `X5Q ۋ$A˔ѲE[6[']A¥<r*r*yɈtaaϚ6+K!50=w 6 #52\ASZAm(ښ~'Vu* ?I2\9Q> p++GNxLfrϚ!2`v#׾7RŒ3AZc]Hz)7WP cRm^נ?z *#BIY,M?-؛Toq"~IPFgZM\b@aU/SQ@+OdMz!g@0ݺ3]\SC\U>quaD/!(ߓ ޻>܌ (3i̟>+|Y(j|ּߏ: `„a5CW{mBm֞F溜zZt"uI;7tdfO ܟTo!xs0,gBAwՌrʢ@4tTͰ7<5d]ZM0~Xc=3 ٘e~4NH>>z#zq(ʔoh\nBHiwc.BJ-DG gTYUCsqqr$4~ս6&Ԃ}f"E쓮H"M+Px>)nJ )ha 憭2rӖXI*_wI G^3HIM2jwe+Z!kb stvH1Xb#t1x3{1P_D[ʳ.BBm9 EƋ~6۬?ZWY&_h)ǠZ: I5ZP{a6DC!N%r&l^~݁t{dbʎ86HwZzj` @UqBdOek4!YtNRn%Yt?(s杲+л@M K'38t"Џg"z'vƅ.kВanѥ4oPciޔ n7FWrFDܱA\ol-O*i 1ˑ-O-jJPb6yƍB*DmP&D}Au/7_ʉs y}֨^C̘$1\\ij{m%RO^R:r`Md M)4O6}N؀kG|e:meu.^dG>?anAK[jo|+LqN.7$A`~{|(#&}n, 'P˷S-m sNJ+fia3Ti"F.K<4j#kM]ߩF7hnM Ume:ѽMpLYԮmF-Oԕ|z\;{e뼯Dbw <ƭ#a5AR`To;È{œfW=Ĭ_*x*Yr!W%#%R2 0$3BK= 0L~%x%:{A{ >v7I0zCoaw3\JÅ%΃B3!Qp3Gwbn}1?Ŭ#TuLˆc{H_BMt?-G¬_{mșC9z9d܉naȚUHy&1j-Mz'k7OzNu184vx=x}IhׂOJ&%#,I5Gy; 7"nՄiX| %]ěՊzrک35kxkkB^pv}yF#FQ%"PE1 "TIg~#7.a+'01TDb 0_ nw2i[J-IS5aKL锅RX_r K hhZ 5s)B׾ >ՄOٗP.cX2#FCoG"F՜b=F y;/Ti C%խO `TH(8FW0ϡuU2zª/60x)䑆E4ε*Lsr.$9¦@~~tW%E~ʪ/sBDc|#3V}@Rx?.B{'^tMk3.~oW,Bʅ-Nu)4%pqBۏU-.16Ab,X;Ļ}e.p)sT}b֜)}m|Y}W8p-f5E\Fa2w#taV؈/@#я` ivPo -'n5i=94 MK3҈ &T;OFW6r5xbyH7 t6PE$,F=T?b$:d$F^@L"+0^tZ>$!H2$M5B8xkCא! /&kW 2+z \9 uU3-w tx2P!Q@ZV2|j+$ 5Oh$oꌢ?qqnq kRx]yui^Q\["Jn,ou\ԄՁ*f*?p6 ڀ.nH;x!6`SLl>?m("z-]˓:Bk3,!,z^viԈ7Xmu+[c< MNz:A5ǩ5뙥7$>Z _&V?G(t$cn?5K卧f/.@ND5}b^WEsehG lUTe!-׫N6/'dC"A?\{'YT̀&SiQfI`܂~2ݢ!ʖ^qAX,tCz#bt4}1cQQ%C>qSFӈ1`vUKl6O)5ষK). }AV}O<S(H iHiT _Å%U$˅;-::a*WbLpNV*Cr'QX*2OLh)VMܺ"s`r ị5yJr3-HFhXg㹞i( 2d#鰧*^ %, t{_⊙qX@=ewB EBYg,[OXUD$52z(J'9Hg4o W.է8IBdᚲȬI{Dni[V,#PZ { p}R}u'fq.?ڸ9=J#Ν櫛wR/ m>rxx'۫'A Ў\v%|/υWhL \S~Tft*E~ra{ӵ޵=̚|ZPKXYEgtna(1 :| p$r."'~J\%Yvydd{\dۻ_GRI\%`݃ZDb!U><|h F&Ub:a ӒS|Q(FnSt6;xE"sr*Nb֧-W1ЇM96:`K| vk75EM vG 8jX Bxdmd<Y3.Is{_P:{t1^<GrM\l dWru9;ܮ/ 44!De}nǠmtmQf[=񞪆65O Zu|. P8+q4]ZG2KnfC_i v{p_@ta()*4 u=kXf)׼9($G#әMZɸljG$u`V6L9*}/G^=wadNf<;"['Ѷ d:쇲xIRA%Ni=b S]UE<4<[@ iQ+Xm|i(e,u;C*A\sb~.[QsӨٹ~[J+,O\*|ϔRuX9bBO$q_e"PRT\(\ N1!"NqFPO?GI:ǔ =0I< Bs_pTQQ Gaw9,O 1zŀ'!܍h&5 F&U#x4#j~wSf|AIv`["~F}wlH֛-LٝK5;AQICo<:,}N5[2(74d8X|1wT^ |\ömn@yl˸~@3=HAi$x>אV)QfX/w:6fx;EM5?0W0B5 udd39-%u6f}N[I&-We,@u:U]a7)יX쩨%04FcCىjK"Xe?iH\ȧЖONz~#DӿQ!Z3JCWj$[Ķ]ܷЖ'IxU;@cUox>XxCU WYu`9h8'0B6mqXޘr&5o5?+sd6,~))s67Fn|wU=^ ̞Vc^ '0̰i5Qjʠ|?x&F eAyҕԭVpH2 `bDf7](`x?:8q a/Ydž^)W˰Y?)9WJ\k ![4~"(,z@ 97 tJh=gAC7_cT1ܚBχ]f7^ |=%SOqγɵQCY:wv%B0/xYσF #jM"hSI {Oi·<0ߧ|6iehM-- g_I&&\9Ii ~J7VN+Fl4pR=`pAc*ROV,k昜׎H'C%9<#w;?eJҰ}>v!0cQ)coj@5*cTopUUmc2EbdYqԟL_?xR4jR4ws)AfAMwՖ갰Iڊ svg]kf紉$ H?f%I^{iOS{!枳H!=Nۗ XJ#'LWRv~T9*~b`UAO%t~P%e̿ZKI Rm]ndB0Sá|ލxOnHdK R,j1ƒvM%l֯wuFC>m$?Eyu ΏA!}g^}zOFpHiqeu*"Mi-n5Jo`{Zp,^HTg5 Ahެ ]hk!K 0&(a|ɃXЈ):F-jEtt{hFb hD@He#ɑ<16 e(6ַܰv=KKQY*i ;>^L_{R,zhX( ~؏#|A<tfe1]<%7s~LQ?0uԀǚ9~B+!G0Y#GL]ϷtO1l{e'X2xaK[{ 7ƮbEa\bUez 3TUy k\$9 q9ilPh$PYOhLm6CVӴUsp/i6U/ 'D U}0UA{6JwFEWK۴ꥶVDӜٙ;CS@UPf5K%e0Qn[5ml7]^Y gD=&S0I5lw*>KŤGSŐ;5 )v5==(HM@JBx; GlC؜6{-uUυ{W+ʼn"u[VA-OG=&y%Nk&=u؛( @"&l9N6~@4Lg=)6lEmF>ә/lVY'V APm UVt,HJU@3[i Ȗ7<5y 3cfgtMe>YͲRmJEr:D'p^lOudl5JVɬ:̶\k1]phքцe,m<,BƂTP }"³DZ^KN5_Y˫Ps_x^ӏAsMVs,oO0G2~MA"d \1J@!;dz%|pki!n0>T;#BC8X@~ޏ+Isc|ȃMuM*5hrݞ#цfV Cm6nR:A[򜾀t0W54mFE'R"}Lfoj6*.x_Ŧf)VPB&^pC%/ch'31ÖN[iI#%"˨Z"ܲtm>d5`BJ&E K& qTK[[R9s%jNg%. ]Q?Vu@L^p9SҒ>08q!o/uI׭c.ϝ>mJ)`O: C^1;h7q#4~r/cO:5OQ{Aob}DT:6-8H?s$ j [HMĖOh!TP|[o?O*^}Ij2ކ{mLOc#CJ2DE>n v+2cIP:qFф˄Br;0ļX+*8XgL\d+ruo13X xǾN>_j,d:$Y?OJ9_Y*ҳu EOM ٠6e `I-<#h3ٶ vL?*GqYV^8/2(b\oc>f"ĒzI#q~:EhSL k}4id.#0]ԡaMU<9}#]yG[Ǘ#zǍ.Rl/`i '*$ "CV!nTќ H*qS m<&ĎSԘr[xt_"GH' GTK[KԥԸAD)'ۂDF"*)D"]UO lGMq$爴"E/ۡf ])I<8ocj sS_EK ߩLHEoXgK{V{HGBc#t| ܝI!b̷;K%)KSՉK .ݜ'+p8F}TN8j`}QkTtq7¿s--9=ut'qt]} M&9;+,`Έ{@ IWkbcrS(c3SY">, ZM4)6ɠ[c2\0j3gTo&GLZR@EzNtr_kF>S9ѿ6Wq?=O˔%F-zAd+\<0 MaѪHr` )1d}pEQ{$‰W]k4lܯ蓡73ɑP*.R,"f?LSeֶhDbOhjFNH*LwЦ1`zax.#`zu! ;== wZK ;R*\oxvbfcku`;9us2lɗ-L9q0ʢnceKYxe:†vi$eoLDDzm8*ph뛬'mf7REj@ J'; ՚ qsIYP՗bu>VTZ–Alz4K]zWK`_ jFP.nv)!nҔEV(cʛ5GCϳvhO2)^3tDl^py[r/im!W/ @N, ;n)Y~FhTpJzP|@utdh(zc'e|&xF]]N*Aq5D#Tv?1߫)Uj8ur^e`3JJ.tj[DpcIV' ;@Adce:qtyĥb )oF ;:B`tzw[hJ4Ӥ ])(h]@,mRUAL.IM9#3sn0J⶛fyg=JUU:}`|C G!D"![[v\A}? KIթ_^#׭7qrjOcpMMۇ@'Z_EJ[%S1{d?%x&6l&^}3r ?j1gEd1J pJ|6 BQ!C"Czg.&'4#j-ʲ*ኘ!p G6 ɠݸyGJ)M^Nl}7rAXPC 's'%r\q G/$LK{$A&MobW"/c3=076ȶ,j/Ҭ⠫)#D2ŕ'.wMu]%n|&[[dzPMnVIS)kES5y"B w0P6q&@J7,M 2T\u{,6Uo,?*x.%o"'q\9uR5 粢cќYDhln9{xpk Ω"$Y%=NF!ze|AVJBd^ůa;:Yᖯ9>r5tH|kek-4OH>7Ap˾]of6b|rGKܠ/ fsNHjhV*̚"sGDcp^8 ?}Fw\^Ö*ri4F"ڐ*}7(P\p<aVPc[oT'r6{4?} =eٝ ;OP^K6[-<%8r>o\w4BML n[:q)&krA!=&Nn(Qyw?Ƭx^p#V O^q&mR0$|C8> 2B,Bd*m>N51.)Nr/l+)!nB6ysli4/!3qY1z%ߩ;JCH J;8oA>ugkLj 8#Om(_/1Cˉ4ȉ74%*xAs^ ^7jTwS4$(EIP&3~J|'R,9,&~ 4\N%OWF֝0KXW)7:.lCqdeΉMwX͞[Qb(<DHuJKo\cf_@mw 7_@>>HYC"yYk3$Q3*f$`U7}7 ~]| 3J!Q 2c,DpdQJ=lR+z )G8ߖq/kTN'9x^Q# 7t $]nkM yJCqE`P߬.4+khЫD,HSI>F,7DGn zPV$nl.HcWFehr1ʶHƓH:} Ѽ C¥||@d1~))].L@+A^X(2YTB  E.`:W!]c] kdR3kL`U gһ7H)u+ (P<3TYwMޔISMMC(K= O?Өl_ERq2i^S2s[GUy/>14ɻ^nEk U=b ycg -19/Y)Tri 6@_m#mX+G['/>~=kl͊f"F:r h?`rH0SGzJ k8C2pXt:C'}}&א$`nؖnc>d[C2Ϧ갚!M[?"Tx;+7 #TW NrB;b~31P]>_4+ hy:l ӂI TRR /3H>TѓR+=KP] pD~h6렁bJ H>:xCv`w} %u QA̡۬QvKcB]E QMm!BJvDY88WGb3h 1tKLZcڸj.As\ĖX #IOi75X<G⫟15}~)c&&}ȣF iH3\eY'ĸA7'HmD3T*/OJ4|~x;㇚"A O r I:}Axqqԍ U?\mᡍ8wHϐ?hOej+𲣤wYC5cd "i}سYIx3z.Pdz R8tlnn9\X"F!!*PDݮ%YS{8=lD9gT^ .%e-:޴A0.nnu>4GvjLT/"b 21aHXOU  @3"XF#`UxƔ%z T Of;LlN.*ɏ>Cw {?Qq!v! XKs m ?S+Z^SnNf^ב**OCjS#s* M8#4=/\mݰ.}$tm D^y3û;A&@ oN Y)Ҫ4*V|>&뻶aCxK1*"Si YGJmʍ4Dbjo.רB#\]hgyY} k3V ZVty ewv֨ Ke$y[]ĕR ]3/p(LHb,3Vd*zp:`l[S2J%b3aVDesܟ7x->֩Aeg(͔&<{{)Lw&zF%[IXn1s t:~4 q^v|zi)P1gkƈ!5!bMNw2 Db(Z/18ݕ4 gv!6)x$h c܀Yo&FȅĴ EE`*SŴk{aGQg,W%Ǘֳi66b]yW]?qӜxPer '߿D| \,kqvJŽ:#zY˧ .DPF_r~fdm"DtF3m`thߵv_ƮKjg-%:O qA1߱&m'VJa2(bKþ7BK/t$ܪ~t{AXׄ~V+}B2JfxNzƿa$j?0:$Ή""r[n+ʯeHg$M4Bg&E݌嫰Z3^fPԤM0NqZVT2 cPR=r)*C"%SU%4BH$*Kgnn965P6Թxo:83(ssp>"`;*m`O0]8:T_;Xg\(EgW»ZZӈrq ' "$`#:# RyAd}ػri) ӇoamOg\R?sr7fȵ4nS҂}K KϗǸ{:]Ε)Ū ּ BXCY s [WtQmt0=iVd 0N ]vNw`~HkVC&yzIdE;3nTkm@U곜rz2N^8kNbs!"*%/[#oC{i}ްW@Mp|J20mYFJRrfGdH$]1vB{Ѧ_~٦qy- Iӭk??8&W*S_,9 C&})ӴteXeD˴1lNޙ)SƬDڂ$L/H|$`/UoO")& ~f!0o4wVm!KS< ~8|YBUYvMpnOсzm*KZЦ.]}0+1g28nbh+"dj0,*,y1-wG,z(Ş lSiߟ?Uuv r(e_qBcUDm~${$T6nzP>N[lyWU:`r~)k>e~hģGƧ]/r^B8,ҕNz G^|BU;|wdJAFK(}7`/ gr{D5e[sGގ$(OV9zQ Dc7k\jGdO)UσzVxn2ZCM RhQƂDB'G;AH ˰& 0[k_0J@4PGn-㍑܅\ͭ_=c5s[PDI}nvqwr+l,sv< -e9ˬcޏƉGm(ydSzSK'zb)Zjwqr j^C1pmOT$]~4Ul3BDLArNᩝVzǨgbmx/dMDs f" ?$H7XMyƬܜ'7W'LBjrDJIoԮzy id2?vu6"b9n9Jbe=~GpTiI7_Z1 ᆾ0^陑r8g/ J˻6i\N q+6=NvhNnU[[t5dI}s*V|`7Uf(Z&jFu|UlƼo"e|$#_)&~$9OJI1ħݩ_3fGv $,nHVzV-j/ A}Z(߭$9b(aFuBge CxT$0,vʏRO+J[Ek[&*XVkrp~GJY Hj# lyd?\/$mpvu_oH-=RGUפl:9@tJZiXdzzs_XTz.k!#n.gt@-CO[06Q +ǃdsKH5gX`%`ƓqlM`q({0˺eQ7Z鏩B9Kja>iं1ªRenK%!i + y)Uc';j/ZG QcAT :0) Fӊ}Ir{ >UOLՋ@մW Euww qHF^P9ppU{adG]B^?XptоrAxU1qqG-ti*v̀ϏΫim/މLsP}݃$h.̢܋DSSℊ>JϬMnsaι?L(1VߒJEf8W9ئ~v.j,co6 f5i@ C FMK@te/LZotG\N/ _EQ暀p| Tb8!0tZEBbm .CH3)Ɲ{l1-Y=ݭ 2<\0DE{X}W=s=꿨˿~C|$a,a.y@c^/Wcwpaq%-PWPyWSLq2%J;ry.O,WCccƁ%(2MO"Q"ˤ-xlCm{X>.CW+h!6'%ܩ\_w+_2a&JZ1v4a%y"ws:?;TbQI6 iw-9;}8V33s]+Xj eҰkP9l-݃b9Y` 6R;:Bdh=l[wA"c DDCAwH荎d'"řG& T%#qf,T+-C=AF=5n5ĭ "ok)Un/q bԣHsBtNZ"֬%83LsQ׸'iΓ(i8`,xwm Ͻ#~vڊ΄Lk"NN݊RJg_G'a*b֜Rޑ%#յ+4ɯcS͕Tw[z%S*'5á v򳘖~CR,8EcvErAkvlSl=HIԮp l-kn?keCv t7"y^*"AX$>gF4;"HAH{@/#ڒ|9 !8b`5+xC6љBeTQUtGD`a5Mo8rb)g*1gA힚xg~7 iI3@s ӓSr^k}^A{`Vw$B@vT 巖K=ӝU#d &?4 t\$E F/Us@ds-YC?-<ڶ  c:̧8551DVYd\\.~דpdqo;܇|^H՛U1?hq8=hq-R[̗i̕/ugX 8'a tں q@D2hXr zqVM!Df.sEJ#@/d XD?XA6)=-V-Gcg$(5%BR,:>kBvyPX9ϵ,F?8쎔 }9 XƂ!D.Ge -B9#|(DI5%ljx{NUwZ N_`*ٰ$P^鑳JO}F#irĦ!;$a%Fqd4_t16CG*YߦaWCI2ď݉pf+@KZ֟FV+x-#&1@"nU ׌@xCƷC@n" ?\Aƚg$@scRc(`;ğO[dcɵ e٘VB QeLRؒ1pB+2 {}f#2hz7!: iԘ0aƘB37):vrc}U=91`('XPP*?+6'`)qs$Q횥:%ΗKXf.Rr: ;-R|jWN؎;*(movmH4S4aY/0" 5@нdz\ٮUoƻfWst%kϥO)rN;|tevt1}@kf/e+ĺB A4 _yM]&-G!ĶLNπIl?8?GD#$؏f5~[꜁4Pxw ΝAC"s[w~;C\KػL}tHPa ϧ9BF ma\$Vyt#7r|l-`Raۿi <􃋞VpfWG6w2[=;5QM? VUlS|'a[Ul;Fߖ 7rCs!K2Bdp0@5U` >ϸ 9\x+qD\6w#?X3gW4xoT 6L paB" Kcw{6.ච<+ YEpUY2Ü|tf?i{1l|d&!JRQwv#8cEsrےp~@4C=Qlch A%:M?',ǓN~¾qkd@寅5 MPD툋ysm q,#:2E[Ӄ^%/'5CnM9Uhlb9Ǣ8,HmtWb gaqP+<0Ef4exn~x <54'䁋=~\C5ɜPҡy|˗%'bZezH-gW䈷 xFL3V];?q*_ԈcW`*][S/p?5'pXpS PluV>Ug Oqb[p#(+lLg鲮KL;I}x,#H[z$d;w?CK3KNo0O-KWSzm6Q.xG5p3ĨEPa<6 uhi%dY9E0 T&V[l Vi0a`vTU苲&$Q5`rXLaSH J?UD&I c 0}9Pmoæ}d Weل2+e0Y`(?㝖f3R's3Ѻ1foED.@6Cpb܀;MZ hyuh@9%%ErϬ&15H9ܞLuf6AUOj=,|WRiz37|b ϧt&Ȟ6 I`OP,b:ܭ#YWģ+C/i'o wttk2> 5T1xẠuۥx6E-ڙ?jqKzEp` U$|\F/U{@O8(?oI.],J0Heo”#5?5[@@')sHMz Q4lǃYXUՄ0S3Հ@񨬿l0TM=7!o@\+vdY 9d9MMYHP}}z^^xAKS/z).C]K17ˉmy{ UK?ƫ`<a{,QHYnYjWjy1}gR*ON%]:̇ _a ؚ3(oxz,q4G OIFB ѴNw0]3G[F[]__̍A !QioI lR΍ʱT/Dgn~`–u=Xy4n;'3Y>(H f((Sno 8syR~J0{wV0)HmژXOxb2P? qdK#φ17 [or'6C~Du7ƭ.r#0тU Gz[6׭:ìf{ YD/t1+0A44 5y{`E. veuNKzK#do>x(vZ-%GYA;;WɑwOO"@_V_Zg* v$ s'V}Y6w)qdp/M *on+~[cv\%pMC>KJʞr${ x,uv(T~4TԸsB/ፈt2*><<ǘ6_{ٷ#WxaFV:.OE-zjTYUّ3~]eempEظPf(+zF ~JωPKaN9)S =sF7>RQ6 KsJsDLJʗ:9ނԍx)^@\p@q;WrbŬx|n5/&hQLDH@kLŢ::a>\#1G)WH# )3-dEjC C+U1 R 7h}ы]7xͦa\H7ӫЌK7 5etv g}ۧ?\׸1E]Ojhqo`[m׷?w'AVwR{Fw//"N[}Ȧ MKueq:pFPY;ԹqX)皧힘AM1# b:7~KJ{ ^}9-iCf$^{rLfAs._,VgO494͒]@g'Ȏad}"K˙0 yai2gЧnbs{'2a)LSK'v 皷)5VNcXD8uUQb٫3q71a@iXEoq{*:]b9lۗmƔ+;u^EuQ@p/ L?akтG@.!pԫ~߬/VS?qWv:KXiBAEAY ayw}Ev4s% Ml#ܠ߾q4*ղ}kD@C m'D1 ٰn75rT_`J.m<|mt1F8O0EڨX=AǟI9wDL+nMPm+0Ҩ*~}?):6>\IܢDH輯8{1W&0Ybfu~笍rrVѥji : !E\sOUލG8fˤ]\O[d00NQr*{dk:"G %!n"~ZUF4S%T ;cLZwvjZqzyv+yä{sҙ,^ Xu<2@juyqar3ms%C|~c̕>U /b!I^Ѽdv#Ҍtr"ܱ\m]$VCY~+d#%OVw}>| #1m $ʼԦ'r_Ybh(5p_ XHh)-fwێ}t++#Iuj0~S-L*W[qGTRe84r)@X =}X~Ҫ-g@M`N7{(Ie>KսR,{6 5 4k |S3446{A׋;P8`&):isdBja"+d;('iS!8j+s%@\rNRݏ:lbe7ȣ%{S<$NOShmtB~oGhZ>׆#olcb%{$:LK(g+㵻LvNsy|D&ro+՗pI"0KE'PMn K[Oiз:kAlzUys|%V/.3@T݅X}B.9$Ug]oӫлŁ8`0K˱4v]`JY>nz@I؆5O@T&QM~E蹈v a,I6_ܨ#assc H*#~oܟe.UF]/9/ě=c.t(OX1fuf/EM } sxU<"0QDf_S"&9yYJEw7mBNJX ԑ 'wvBd,;}XF0\+`yu[%V2`|3C̀d4<|_QUt)6s"KӍeKKhw 1Y\>jcTxIj؃P҄'%sUӣŴM]Nsm^&Ό؊W#p@6XT5{զ.EzF  +_zIPNvUk+R{]w]Ta3Shw9p-*((~v: ٢')j#f4ap}szXDx$kLbLĊbbם<~V8X,S-`XAgܑM[A9QB$ՉaHM#>jBWqV ^+8ЧޖP2;ꅙp x'2 !յ6ܓtbHDž!) hHa=WBj.3'>D+: >ePÓд T}J9 eɫEPorf$2L.}712$!vfCS6x5D:VAW ^=TK`V8MʃSNNA ѝx$'Xv={/qJ1(2zuc`1)4F e0ˋ|㑲QG#XEʓT?4UIkFPcT!GӘ$lޫ5 y Spk,4BNmwz),˟"zZ%HD m: @9^rXV]6%РDn[:PF ?ۀ OyJԷ\1P(˪ @ԃ!U2Gnai]/*jBD( Q;lwç K=d4xp>/9zKm)x~5]=.Ô-3|N.U4jSDn8ZNK)P?rbi F="xgM~gU^ tpVK Q-[6˅ w%3b&J?wVe)[q;r#K0 :^8n[6M2ch(6` &xb8Bu!oG͆hj+ (Y8`ɇcGfF-W{,`"ڗOX*e'E3OG iX,Q~U7]6Tp]#2@u#D+ 2Od^8Qi"Krwn#"i64`%i0 uMgm y52o$BG$'܄4#{*z0iʉP\Ld{B%Y>]jr~# ml~{.jbH0l E_F@*rlBÕD F-S/:6.0e*KliiA7~1szR͏\GkT«;}TFEpb|›#tD&+Ӝ +a3d#m(rHN,Kb+ґ@( s\Xo0և;#Ea?b S4P7OqoM߇Vo+SqHLNK Q[QY#0^~ ݕY|i=*X2`@U&'=tDq(yr')%|3`% j͘n"K7?3);xn`Zlu]#Ns|`4ՃHqdϺ͝- l, H#eKN/VY-VOdJ3UƎay?:joq*,o1  0R\}"gȕOme[c↌icYQ|&nJ[-cI#Se1 <Q)$R+yฃX(YhύaA7/0~u9KhBZ-W~U^5(E[Ec~Fa=Dև0&D+2 ׮88h5 ΢+ 0.7VuF6&m+p"0>+ښ.9sN8r<ݥfޢ7b`CMp ;_;t]8qu@CTI`} n\0`sE#fas/)~Ì[a"p8=?$آzv¥[" [1'(抎Aнm+M"aSOUsBkO5y"R,yshmhDi|=خ?ZoOo1 G)wC1;BGI]񾸹u5j$|EY74SF* %; )? FsBN>U*a0i/nI r8_$pE:QMvx #n/' Ϻqhk' `N)[G53hmjLy3k1\0FZlFyyzrT/wȀXG.Lb{g'1&ir'K]z2"^|O Fa!J8xrQx^' t%!FAJ4!\[s2Ipj '/yݳ!WU.C(k.wGd03&DCޖP{6LwSp[>(c&9~Y֣ɡ ;mLfznx'N2@^idUo3y$dk8\^$nh͠ N4Ve=BOq _r`JrC1l>U]0CUDQM=&(m 0ψޙ*D_ꨈFyZT&خQsGLJpN È5 h/&YKT'о˴G{Fb ņocbT"jcO44/%]?;D5#3!c'TM3eVw{Z?BO&<vR=@[aG2c"@SBY f =TxfNpw]_3v?3~2ٍHr?T\YMl}@߬?ZףL{ƾY-J7p(xB`kXSTYRQ$ 6>1kk5.Pa{㹎 ew6rQ +lQC;_i,rHc98FO"Wga#lS{å@pڞvy?UN$n E#ʐv`#6[{#J "1{1'*m:vJW7V8FA+( ?*c6T^|Z'/֡\ [1S˖1IzQ -Lyܷ%ȇ+ v jkV1sDk ^[mR!Z#GtAM ef(5dIE> V"\S6jjfDlp*/K_ݥ &C|O"Ԥ?6E+͍|G:YPn>ÞmVy:LM5Rܗ w;1YsC#ꁳb(QJ[ૡJڲv[ȥ:w} Fg (=})2dr-w &v2䀹 UmHqC\v̻?R2_V,]J6~gC=oǦL0~iRbshKݶp9"$̅cdC*pAo6cg' d|7?G0`4ho; H`x^2}ju=]U_Ej~ Q¨4/aw8I?Wx\g< [9 _ut.7HעC&FY uz$MV /s&6vKJZWFΌ|s1 !Vc qvy!~!a#f/.ֶc\ !\(Nv'mݮ-3WK԰VPޕՉ3ou Zʏv6iprpf*8.ڑi5Y W2B˽y,[C绅%{ճ%EM^xBj#8JG)23Fv/ yzRLy/edN v!$'=$i=Nk*+@ "ʘ Q>v??&jPP΀}LJw[r W 912Jxy=p 7FGK<"JU #PG#zaqKF;N#_(aqhꟸ_0馄Wp,wq=t~6c_ȃo<$ 2LyUBTpWag9{5"dq8ʫq5gzVK8R> KX|t(W g?_ ;QU3pD@pN-ߙL7flE$>6hӻO5K:G3c/*xduY|A 8R뎅'n&ɟq#Y {; 5DŽtDKbMp@=HK+߉X Nþ<^=uGŀ(mvQb|`r:Q"-{FC W)!D/ӶnK1mT)B~yg$ e eivɺ `r KȠ΃㟘QxD2z@e[IBөOb,YQێ7nNIYW\d02?  vPy(`͓ رT!K1(lz}^;9uC5H:![W }>y,Y#;vKe852QvEռ"׏3RԵ}i{j xX{aKJ`i/>hǨ};i!m~Gtֽ`1>>Tl X7Xϡc#[>^sנ݂6ljrH; [̽p5kh*%P@mb[rY5,3" YR2jTRx@' NѤQLJd~kQ֫ [ܻ;Ļou~?["Lx/~bFsb(dF2YbwMM2_%猏.OꦽUۺp8z&Q/ny"4V7~hd  >KBzK]gܹߨ9tMs'xjG09zQ]MtĜɢ R8LQo~> "0GJ[f롶'!D*ܤ2 ,.Tי:3֪/W]vQ@@aWC{&9}[jJIp>tp3GӼFkA((au+M7AK/+zR"Ӻr?vRh΀PUK$nlo#$8ķV!26+yz^Ķ^\R^SQY7l ,;Vi8 ׃$@ :DP<؇=C', ׿2`*.FLfoyP2yPg@!,bIⶳ!8Υ]+ /ʏ-`#C@ uw./>lG%\L/aC epm֛gfhڝsQxs)n:-/R67&4ˏaT&HdT^۸]n gRd!!5~&mCj=/)+UPNkd>t&\x F,G` e.U.EaZ2 U>m5rRһn1/)Ƣap0#Հqb'^ëy@obQ:%SL\+ֶJ lp:Z+_<]S9ṄgyeZ3Wږ(vRdq͌mj.5?b<ؽ7^1W"JiF_*aTgf}cox_{?Vu3UwRZq1~5ZS4\73>G+FV x4Q[ Ǚ>Z)_ˀ>1A;7OTHpQ㓏0PCJLb[ńVO8^\V})n/6Re 5i3ΦZOia Men xCxG8aԉ;vIMTcTꈞmOpNj8|*C rNXDdF _Jr4$]~ȿ, TeMRMh`'GˢcJB'a;dHoqΐy9ws eeuVԐ@Ȉf>W?e3jN-o0n6VSl#rGрwZրY# VCژ'{e +g%M|AU͙]U aT($PД,G+ҁ2M-^մ!y#I("Qȵf,0 7ZtA5[I'W(5d(-)k7Ǖ gˑ]zOs9[W|I%3&H`:R:KJF)+r,HA>hAϼDzIθζvςt~1{9^4jX%y@Pl7-NMB"]{~RHgƘ3WM0așdC{q|bآ8-!H#B-AaLs% P5o[g#C0LLQD5nJ W}.8#G̑SğI1T҂ ?\ߋvdLtiuګ]C8ȟ dJj)7jr!l;0Tc}8JDcUD(H o%L!Bo~7)#)R-gx .oT{++Sȱ `lcS& zH/"_]GAm&㆘>{xMV69qqcY!0+0;2,;v8fT' ^!.KXIgd!ϐq`$Z [ n*װ.sZ50Ou5'RʅL_.2I-ZZDˮPeA3aJX돢*zpR}3ݗ k7aG)#. Fv9@8yq 7.8W\Ȝc{zjE@E0(6鷤9] \ r[K*^nVczƥljgkwt}(%V?ء =ICRUDb{63FPYuש^2mSUCa< n,~󦓄<`Uq]W >.T~b@=tGٶseR 4/귢tHȑ53I6=eg$bG6gx>iƅS um5F<$J#(D#ٖ:CP/&BjCSDIW*Le+y9=sn,ewG:Hwl&h\cK.I[<|B ԙiar<>, `t Llre׋8˯zl4"l1XNwtkQFd2cI $C̒ o2֐6z4zJԵm[k@rN͟>dNxmF׼zk#f`%6GIP2 {CLutJyG8Ԫo: 5w|zSԔĄiD:M omzTDREs[S0iV-aUJK^ix ɧ}=Gu%ntwMRnBqqB,~;Iv9tΨ q"Mɺg*X p(~`49@2{6cLP ("7⇱k'ZF `l,`̂I#3=Q;m6NGpeKW07#t-BGwVG|7;Hx-s2{".U o ӆ[}Z/XawZd{LeOZR{˽?&k<4]UZ9` c:䈢Oe"]fp&O?@s4;qږ?"fv'"%v,?Em]FޖrxI.G?;]Z -% G(\#dX 7Y'^XDOŒ Β8-tj(M9D+-=a2Q ;brj3Ϭxx8aK'u𠚗R?GO1AL+ V|rHe !Fzj[}S@ٍIf[zI'61N{zkCtH~Y䦲J[zZWiBC&Pe S$ɠi#@T2*ť;ic5J|Vl'Nwh7}?Ւ .i٭0 r_ NW3s(lGrBsJ/\u#*RKTH|y7 o[>meQx#_2*O|]Uh囫iV"j nFX5Eh6i9"Du@Ѕ椹gµ܉ZH-l4fͶ|4*sb(7&^(@J AG*jMz׶ $;G yd:k_T_8:d6 rɣ>q풦4rطm-{xZZi\O qS> >rAUӈ6ox.;=jFTkH[>W^duE: fKGyF kO!J3(170á: 6SY^NkG,J3i禷rֲXwE{, ny:jԭQ4A<#r2@I]#UA5) e1 Wzt o`B\Jɪ.; fo B}:>:FMP,Ӻ" [^l`q ;Vu.'iޭ@#h3$diJæm^gDN>}DVk:kV- UvfNg<({mT̔zb7bs;դ( Ӑ_&¿ޟj.^,Ʀ(e7MsUpUHno=Jy}'BA+h>SfRE'`J9R#sfÒōG:d!`?\ULg 8B$'}5O'\el4Ts[i1 C0sá);. ?1 Ξ-G {~vY[/ӗtLbՐg.(!ߞb,L}vs$ّc\2At/EVqyнӌ30D@sz ~pQJD繪R wA@ꦩ|s:[6lȃه#FA;ܒ[ 3z_b2άQ<,+~;3Mœվ7XK`p :q%7uz},NH!h>3l[zIӵ6R95(݁J w9| {}ʟ6ڮ(1?۹/hgIEMNzx#}iTmdC-by v{՟ &4L4@vI|oK) ,r>,)!.H/Aa^d~ō;۠E$m([5d6 nx2V-@BMP(g, =G׫l(ĊxbkP:?qp5u^õC*B]'R==Dc &y<H2OoI`QGn+W.s!K#8%6QRqy/LDDdE>t1 BK u<{TƢprڍgdD fN~;Ct?~B$)Ov|7z ]Suu@!iӼR&|{tB4*|1#J a {dK MB${z8EN"EɨC8t*>8!ÓsE┃xhk,fk1?p%' w`x4Dı"g:5[Z8)b:8ZtVqEEA4<ʎj-`,\uN2)ifRgq6L@k'W]}ӶfdD*Bu oR8-37}b%|IgO_xY5y@]~c&[zFHb#$[.Bs/{ԙ3V+ e|خB:4Fl ƀ { 5ry0F:> f+T ( fh@vD _M5L;6?;;\9da/bHYPT%,qhIn]IQk!0?ћv(cI|L̏+E WK=)sB}&ȳ۪4&p(EOjDkOB\z5^ z*u@G$7KҼG)qydOU`M-ZUK).8![B"OI:ˬGXHV<"mc}I'|lU%7;=ύ[0FGN ީŊBXH7fV>9.N6bSca)cGrLVRj6_Ҕlޑ7t]壤1#g?|#ys޸\jC> +CRљīoZ,h^PY 烴O'o$qUGS5oÇv?.=oϥiI@N>e H\ m=u gQG=y"7ah"_ *PТ]R׉; I~SWGR(l2)LNUeP~`EbXARςܑ%x]ncbO@hT4h\)wk̫^l3`?Exr̸ʼ`Q֏~Ǐ H1"=K)ԥw3FfNM}'곋τ^"wS>fis="ߘej{t#WG)*5c\DA7~|zx\bnVn$avmێ\g/Rzy;V̎R=M}kjZm!;.3+Щ"C-._'‘H͎zn1vg˜AX7$[a4j6[z&i% 8-B>9EeM^Jl(ŧ$d˕){k "H!/UճMtW<<)/PşZ rbmS w vgH (6UЋ~q|B1>E?M ɡںi|HOJ?ɴq86s%M1DtkC&k7k [3m UH&_ } FFubﻒ2{f%SBeF\{a7PBĻV7a.ddxw/u8oľsE: Xb^kw=Is}l;;.FdM\,Tu6 1Y!/:<?w\aOuES0ac䇎cKwbߵ:>}% ~+~gA3*dQ>u1Q F@so7a;zmiղj3)(18"o%6* >F "m.{z-qF<4S:\Dբ~>Ri%d;PF'J7%6A#M4V">Cü#}+F|d32`\GDN2Vs&H!VVLP JsLm*d~Zx:y3`YV IbDy)\D Eky" b!Zi-БG aܚ⍛:15h*f b@4da&H ~{O"ērvGNe2 K4ʕm꯺tG6Y?B͠1̾`D,fpq5%w\>J"= c5S&4 4$q&d!MQ6Xdcljiˑ]}cbL :skT8v3~q*Z8 =*S鬃37l5^!ʗ ]+c2s+!''j}|6+%c /0ee?Y+L8|IJxskUc$ƒ0|֗C϶V╷j[N*\IgHᩞ_N%ޘ|njjH8cƍt~LSp>sJMnjg V p0 D.;&͖+W H&ݑ< 1JGÿ_ˆNuoq HȔF*/׀|*'MFHb hJ&h׌baB4G8kFAYV7ο̃$5}#&ɮ0nѝ($Yn5_V&V(Ț85X'rsMKx^%'[ԂEgB/e1/.5wbZ+Z2dB4?Pj Of@h8މ+ˆgYt}zL~[ޏ?^%ZCȉ%R pLs67 0,}(|񽾠\ TBA6BuyTӿ>w)\,~?ph#il O)qY5/q^-k`悜<IaM6/Ӯ}^ gAoN?m4}悧 oKV-4Zpʃg`(kŻX*Moa w8Ĩj1'Pi~ I[dgPuv v2gN \ n`qƍ WVh/l273&;V6ֲHd"dR\Fg,|nx01)lG.6'*IӲ) T\l~[>7޿ms~94"˵T“"g0S9LG.ܔ&d v @1s4 tI= blؼY<[) ;BmZ۠\:rXݥ9ro xM`9cQYF8>ɻ+- |$jv.wa2IHwk 9c[5xu OT_fA :; X2<~*0d׊ϵIe EΠ9tg>Ns4@K޵WM-i;LQ>S#k(b|7YW^Y,wpz4!`-C"sEfʰ޾`F_FȌKgQ%\1;#kT z5Cy7O2s#&U5"M^#zxb~4bRsf 'Waѕ.vT$Wxt}̫f~G\6lj߭v.:-W mHGÄMW9l4"/ԢlL2N Ft?踹ŮK2BaE= q3zY%E 4T$jV!zq2o?^L)umfV/A>NfD\''Os0uANV#\+Oyg ]qVgNJ<3ՓhYB|nD>HT QKˑ041vAA߂Z[m i@iw)r\e˸@5Wk&D].ڒ2AKBbZ3Ⰾa^ e~K*k,+}teڱߑkm&R=HuCYC7|N!SR^b_<:oUqHAIL񰅐=ž> gbdH!ڐh(L=Uom܈^pmuHk;Á[^K<[vDZTy! *SW65_abAk䗅$htJ8t>? ;.Ч--^ c( rG2a; 3E͐ 1-MBt$Y}~ L19EqEC嘿YekS7ĉ<Ȇ4AQ&wx( %ag51ʑUs;XU8/Y5x";OM+͓(v0'1"29R%OVW3%C>鳎Rq^˟L':gv! Hh_| yJ:MgΚP,_iX%ē DTGaʿz2g;̞jŵ4*W6'1ZtUw+rZe.gamޢ(-3ӋEa1B2<9aS`6h8G 5!JL}z`\l@Y#]ݽVҺSu/mu[@wͯ<\[ʱB4JN@GvJn&#gpp9FxRg*9[vZi~G; B;/ysz! I,NR!G|-^YuǗwm{]GcrV$c"Vydj$ʕeC,&o[I%u |hW˼8£: _8پ9ee/3Hk[FJ|hޏ^rF@EBN9'&>Z$>߯Ŧ߳hm<_YBlL(ʿi h0d.PP*j7w1_Nk*4H CFu1nM@o9/M3< |80&]#^9ѓWw+c~A|D}P܆ֈWa5'(h4[-P֐"Z ~0dy%˳aaDn\-C{+;MmK̖Yn.YI:[ 3Ēޞ#DhvTfHbr@Ew w`fl3I^[צ?ē3MVM*Jci/1\) &^nB`54j}g%T3P@Af+CְaGږ YC6^^v70~@.j6_4m 8r <dmE%, v}% 3A*7pM E<3wH]T5Q?lJb-q]\(U'"n4)rg*V NVL7tOX>sQA'.P;1_}DxV):fUlrؾ>AOzb5o%$Wlߊ˿m5Yb U$]b ;]u% x JXo nA~Pcbi<}x~{h"N߹^\P/ ϻ_Y)5 |KGkQ/`Coƾp:=^:>ՈV3, w@ioa `@擘d_{g޽Bs6<_Pra?S:fzwfCttsa$qH3s|IHj&ȑI66H" 6C}~/t=|jJ&{ޅ  &6 }'^K*mՋ^hZ4\^iM[dv (9 OGu?O[|peeaʖJn :M`B"P WqN(\NZAeo!*hJ$6#ܭ6t( *I5G4qb7}qѪNWUJkӭPдuh,_HJ^ʪBSrbqt eNP=v TK,"iHBqQ`Ws _8}36M%TdӀaz R[_W*COWH# G's4')ʖ8`Fe^y^#5o ǔ":ן+ 1 ;\c2ї:B攬[+BMu;i( 2 S6 $S=,0(=}=O&*z] ȍ5̚ai 5#~iWp!|ۺ.-܇wV^r\zaҧN:q&R.9b1MnD'i@dX#`N}|SpU-JdX!>iwLzZutoFa2:Av8D> ʟFW>/ SWEXh-oŊƠu|] a2_xzOrHBZ ![Ͳ6mn6OJ{$*'uXTu\yn\1g//Аgz}lI#:`Ӌ9)HG|H t) 85?kVɛ^M!v@a_I`[;Z#(̯ao ;e9 \Ycd#O1۴s]I\5|K*+}V w(.+1 2 lHҝ܀3e-) zN]'c#֫{4ߣyL֎8>ЃWU-ڙ]rWQ`;zY75䝕WTS bĽݓ$>hPA1Rdx2]bAwqsnYLg}a JY-HÌf(kZCp9AS (oxț][߹Jr,5N'D0h2킱ĢVղ虆&o>(mBnĪz!WR(0XJ16L \3 .`vIä1cqq#@$Fyx]2YPGo :K =I=|%?/㖔khA̲(TtHB0앻1ܟUr+ ,b Z#@Af' } u.7K?vy"ޫ%: Ybx`T0~FpI 7__[; q٣3P5AEuܹ1 &~=KV&ZE^1l ő! 7D^ ;21I#=q){ Zo\"Y-)4ӧ:G;w.%xtylO Jev#[dVU i1घgE61.SVF 2ZEH ?; #r0w׳W"y O }+ʃfCR@3=;gkj2|{h42u) Lt ] Ao ҏVIyl g/F"n-nQOΒU@µHfg&j+7UG)}wK۪P*?q]Ἴ}F xx{ Ŗ̲~Q^Pdc~Pdw$Ҽx,kS+Z wϘ댉MՊ3W[~u}.tĴ Yy*NǐMZ1C:9>ELhg#uf n1xnl*zq8ozjn1@b '7BHfU߶$Q˚o*>D4`^PrEs LƖ:zz1Jg7"yR~*mfu:g|hSSf9 nQMVbGW _r-fAN-Dsμ\xY쾰_"(Z1I'L$@'e؜9^bn+"%2[nnYH2`07LX71OPt+tKt4,L2d7Ğsp{:`)  "{CO._iu4OC0^:S!I;_-wEkI"fDR򫵊l%SxlGLɲ]4Gcl~"]:Y/#;; R=bx ΞV/&R܌|R<ɜvmRqp2ɏv^BTW vM}z>C?FmcenYCQ#Sg[ƪh/Heο:DaH?h-^ OtuVA1h.#Agy]puYo("u>~[j =vWCK晫]Fg յ_Q+'=Pcۯ<= )#h'iWðʋE n<-';Udrp`}pJ ̯jɇĀ6$g"]}tu#aM~@wbbTU #zuQxE+KuL,Qk+Alp89燽JR% /MR9(iM*8$ہmM&Bp1=(Y*cRvcw Y ##龘QMZ j/ݍ˥U@Ù[*)S V~^ fwS' %ϫ '-ܘg9]uI(:bwB_>bc(G*s) ekBgRE/}_c.pm"a oqM9@Vc[q[_E-JvMb A||,(-p{nڦ@s֧#e\p. 1|?h rj-[d(>t?i>*a(U'>r%&E1f%RͿ.TB+P47fH]LOb!CM"sU0o8fe]ٖA|f. P+v)|ؓR06ѽ>Z}Z<~ Jih"m Cooە'ފOZ_0&cxQf>ircVPFddl1.̅2LAN]hgE,-ƲLQ Or [,N]ķr% [mI!W*/0=8i)5\: M3ʝgYF B>bWt>Nb㲜}N˹ovMx ؈2~L ڒ>oRaM0PX.#%qEA(#,[ /$㑽 1O:tYB fl``vtU<YmVc_b;:&Ƒ|Uq*7NHw؃UEnuiCWugSh76/{p*՘}#Ń*%~zfqd̜Nf͋uC"SQRD<0t<҂1\@0 ySk-5CY"vthnNdh[h ݴF Ŀg.ZgF o^n?;Xu SmâA90SkP1 :7鱐d03`t Wڡ# nڤ{WlWeuP<gy&'7/¿js Qbd l/͘oB$qp%T9jɕ\ǝF̀=/ As{y) eHACf3|oa6)d1o^ '_֧ xܯKP欅}0qN^^uAқx'+} (-濳d|Jz]37q931A'=T=Il_:lޅڪ\\֙d|/}R)pu ֭%LI01= ЏK_tzBٮ(#޼eV:拌diSRV˸1h& hFF9<$h6AEμt3Z רn~}w"jlp~E[P8%)2 {-2;ԓ{Rpb^ GpFb3)"?%e" P\6k%m}ǎr;Ÿ fMd0ȝ${heLX:`X>6fLP_IEu1:'Up2_Xj+^`T}A! HH~vܽ:kT^pơْDpgt .reepiWG?ÝC<_4]@^Q~CtaX5suQkS}mΊG {Yq=j3@ڎﳿl\؏h"{ $4Ҏ!{$G¸פ}h4eұ1҉RG-0[au6ڨ)y.Dyywx/ֹT=OvCSށS``5 70'-iwIeyrnh:6^c,t!l:OXj4L ѦJ:,lۼ.KYe;.a:]aX̴/꽆e\@' }O(ۮz9= 0Kj:P] /np{w|5ux0TObEL*)8WjDېv@˜JUo$3;akr k֧(hY516f QzI_E?=Xވcl\XVX;a XEkwGJ-Di2"C6tpXr^y$BoSj/LƻGAi]IRu)YV ECf z.=aAշr`  x,(;oz!a#Zo, \M\z h;mDum/jׁZ|z*QMjpV:(3]H7v r8tdE\IketyYN-םը^tcuLAek {o\p#Yljc]US CS#Cibz0zEll:@Yy]BGƤb|T~И@F5̨Fs/rDuWpŐF%թ:3ųF & r^l>) 9E7O?乻(Q1nry7ICvx4m5d̩" (eNYj=.f]-eQG֤ȍk>C}x+t3l?H /uoT $[\n/A;p/ ?[%߅/0E 'ك U|@=N%~jS4Yڭ_U(޶X`1tl; ! Dj^Qg"jߐ>8@+=!+3bDШ2Y A! IPc8aeڇ Q y0%BFw]te~jé+:ܗ 4R+Z9!*b M_=2~dC{9S}{SrMvY~ylT $P qh%#,9%bUMBz)Kv^loc1 ,G P\ww!ZÐTxI?sF^Rq2PسJl0]I,FgD0Ta2=b|T'V5jDmtal0G mFbkୱA# srfMy_Uem؊_6LܞJHsY["oL4wHme- -1B5 .mbfZEh$G*C90To6L DX/ʽ0COQ7 (gZ@ ÌW!R=  4=@>ʴ)w* t6)yBt}g&_n򨏘#sWP^mӔi>YX\~`AUͅD.hAºɋ<{|cʄx)x4ftGy8fQf s7rk bs1F8CrȶEKJqTK"1h`F֋xA?Z@3xNEW>hXoOKHE失,՞hHF]&{ZH*@xk&>asWlFӐD^,r]$eW-y3%"9\@@iuVJǮȜwƪW<{v1_R~Y炉B~kXdQJg!Au #^W{'gxUh SNφ EJk2ȧ7-^a"[JP|84;&ߛLNU'C AoB}4'Gc\-X+[* 6L1Lf>Jr&o{]4(8Q 76mV%G,^()HVi], քm) E`.F.ta1F ǁfSkMZ4Y/a2N`^ QEDiνBy~3+WG_WmE6_VrMwhvX*R=g2LP w|p.%՟(F5$hCOw2ތsغMIY1 mhMNp^T^: TȊSqȚ]ruYw0!aHXX[OLY*'< v|a(D+̆ N f8H ρKC1KHᬖ1Ow+#KG@g[ za/˹CBsgp^BiPQ| !~=/p>i,'SBY.Ϩ?wte-#B7Be U ,bWL9KYZ5{`x[&ZήS1"[[ ,'[ea1Tj&;LDT /¼^ o>08]o AU S:\qPq=:CmqgULelO|4Ô)_[[Rf e,_iFR؏C䝝̷SI=ROְ~Ӕ8} e[U8'U8 %\GθR8jC{ pcWVW2Ž|VFA^B52ކ7Ο)7V6k06U|T艊 #\2@O o. ,O@pR7Q<<^Cךxx'eYh0Bwnxi6KQMԉj|.1(7 /q7Ub'YuܜC)31b%+=/B˰Scs,?ݱ 8Sj_Q3pFqQ3 >@gqHBxͷǷNH*zHHlp{Tj>͟ [~E0ͧbL{COqY|4(L ߼=8d6̞vϋa>E#T(KA![*rT=hRꗂ%|[CRUJEQl\{^U-ۭ-Fw i#)C7O#*6BKs9 to(?q|LY}îBww%~3 oE]Uu||k$Vni2(s=R &2a&v9LPؘ9e?ꉋ!0eW`,dPAS6-1.2 Z zw7\ 5)v=Vfq1 w#x sR z,{n3}ӀpO/AX'Mo3܉g>G+u2A6m u`y2tF[{X'52הp<*%- _{KzFOW/ "lzNE-YeyTEƽ'Rqs%aMqLr a7rC%)zX9pƲWO^$z7Σ=$Ʃi E+|tؗI!w[7Uy5I-orh\A4^7ݹ{]c:hH/W]f+UWH## %)A ,NYtkĉItmi`Pvц閛6)eUǾ.|~|n:Gn#-v ,Asz7,q\UÞ JKN0Spy=<3fs6ֲ$ |wC0$3؉yUpSg[7;/yW7DU8pǑo%.YO<Ӗ5[֊[M]>;Z}rqWd ouV/8.u^JG_ՐL(^&:l5A,C$C~)/9Q*mnxtC0|ict6'}5U*\S Bp}qP^AmP7ČbDviZޱYxsR: 6#VI.)&tݕv9du-773̧$KNUƇhmqUexH+>1F s(?ZJkFS9س|)N{ZёIĔ.øl^q>[bgzWպxyQ̿6L+`\'um䶊,ЃQ0hXex p;RSv_1GZ:p|Jr4."@L$s 0q\CIK_{C?Ψs8p(vD͇:VDEXfNa$_@>!|fGKLusj`xg^.xܛN_cpkѥ `Uڻc)֘c)# hKh\y3܇hw\⺤0%mwūS|-6 bAv?S^˝,NDs&(?4\K9.}̝9:u`V]$! ;܈O-lTtx!٪cȽ%~+[]񃅓4ԍ).>S>zgƣ0Lb&@rzwXuZ*F'XޑjNl )[^8t3t!'Z+VC<0A 8t3pJw{]$A( G*74fXϔ 4QEƖQI3ȧH TYӥ'љ GmlA NPJBrIGPgn֞$KZq3ӨŹkfV&/A O^f%x0O] #зg2 z '"n=ĚTzsvW (!GtRǩcC 蠒VCfU-};V/Hs|J,9f3w? IUzw'++)e%3 FU[+*)]w %mh1__"Ddy QR5|釞O 1W MS:Xi1T7?3uըQ-atwȉw/pX*:VVcZqu(T!iXlm;X pb*.k, ua$В=b,M&&J2^=0L}2+@ٔ'B pFɛj#3 Cb4Iہ*D |NCe_#Wv8޴c+([[ {ސҪaːͿ|rFz|`v* D_n6Y{3'8g-pbQ-v]ed^5\ӣO ;:[ ^cRXנ-Px Rܱ!ɼ f'ӳMsg̿ȥ^lYiƩP䡚dG\yJ8g̳7 9`i) %Hf\dۆX\ȠғE樼oS{an+䅷bI3;]CIcP3&qS ,t[ 3-L9XC9~Ic1뢳4ckyE'Kd廆/{.W%b mXx#0M% eAKkU%{λU t]{ Իl($*щ-KV/+DFjt3գvfs,C.= ~@&&rg-jM:"Pbמ ?nU<{A`_|"Dd8 @`&KCe4n,Ϸn)V@; ƩmS 0votcҗO_Aʹ/Z]ZZ|9M z [_S0Z<;CbNU͵O6qN^I-/-"'a/i(3D4("O>/hG$.KĒ*(ΔJySΰvGZ>l,#7~&;I8]Be' g#}:~v-3>a %Evcv`S2@W ?Bڃ~S$kNѹyc>7 m}~J|2[뛖d;\6hk-B%H0MHgjs}Bz; fjܳNf.+ wʏtN a],ksjSE#۫<*s~Wz~8N hؼn@==]1 j$t4MN9/Wc,%CI*orL%NYR3%)t#Uy52D= {‚K|__4Ljq$C󁔧eJɜLd 4984jIcM~%t{xN %W~+MBTyEIgLAsqT #?97_N@wfhPƙ`~Dv(Xp eC(G+8ш#ӕށ]4㾀иu* jgN(S;雓(cI#c6>yXP272e??UwI}CLYK)@d?\ܛe!|L$rP}d.O*itpO#\EbKXgmA?&|EjBE̶_d3AaiHeƆqrnQFT&ll撚{b;Y6s%jfɛ\7H'>=c봚PTVŪ>xCMC!Z⑑͛  jc'ksE1>Hc* hWx=Q,}]z7;`=?DHL61;Y2.?LʋhyAwyMLݛ,2hc>}YB_ `m G~'^D@ZF%6WwaD*&H3;Yf: 仯9vG54R&g :|vRR4thިsŊ:oe =!@ZP |2=]CS ? bi O!el(#?tWyJ*BDR1 }B/{!QV0EOKn wو*݆& GHvKF [̿JPtX`8Uj unfɸ><7]"c't76:HvsՔs Ū&)ubxao]8E}2RJ]h;c@E=';7U =K>L2?fm\H5~ۋaA3W8Țݵ 3vcD/NJ}!ez2\8Ib-u&ɳ.C8?xUCŠU=s-8.t+䇮Io>դ ͎wMŊ` jb<ȯE/5ƉKE#ea9Bu8_J'lZ )+Iш=5t&WBz Pq(V5盐EYCl_|ڗ|Y˜8&;ǷдI1LgaKfjTl'qP -J%fe6,ng" qPt22nŽ>$Kcu,rU&&d23G[U,ӸKVEHfU. -D*cwg10 c T45ㆁKj5P FLEVTz$^O Jx{3kdxzɲ3j*^MRd{ԴH{+ +^u'jw]q4 };U$@X Tz!T|`/} G Y|a-_U v?70aW /9}Baiqb:+*&;;ZN as]쓗\6d} T^0kt{ɉ s%޳ZsĹ|Anc!gp)~X颯2I9.<6~$UcMWVۖl˛Z'/+FeK2ո>? hvbMe ּʖA*3ޒ$L02mKKAd޶ c! 0jy1/BT+\b Q\?'A 5\0X#"ٰ8/Z"%kUH CPGTnDB0VaLyT u|Ą1W,kߨsTmei C=#G7Q0&G `pyͦWb 6'駎Vv͵o"8 Qр{l|gr ( wq.S\"zmm=`d._IOi^Sܻ>Q`Ќ1jJ`\}M[BBSW=O/ N@9ވ0҉)DyuU%P|LsIbv1`T|Z|rg Aᎀh5zUM麂_-y92T:yx jٳ)ba+)w5lhd͠?b Jq.B,0Zk?<>\D#STMft^M`_9z0D2:t1n,3bR#nD h _+CL¡|/Fn`iO7)ZN}4aEV)/ŊSVva +53ZR? 'yd],n3wiPx|P8O{-KWT<.o $75\- LFy $_n0nU葶sH=^T\'|wJ64ۋˁ' 6?uY2K/NW̅FBހy[Sd%콎X)<[嶾.ݢ.>nh B {Am=*?w򨝚[䢫C(t·6O> N>k]hׇT'Μ-wx}K>entFݬyxfC^"T `=8t#EW N: ?] 2XXJ6:!wTB"Q*9֪AUȏz ה0<düp:z, vvԴ>cvJQ{گ1$ aL3ǀ'JO̟{9,zlNw_)c0\ղuZ'iV0+v$c\`$ I{gB'8(u/mN 3G]^3JvIka<}LtoNb(OOqk<+ydqe:1\' Cn"OPєpR'ۤ 2l}/1 xjGh#M1QQNQ}}9x~C;B]IN%dw_s!XSL5)*qv`\Rw_`m6rJ(Ut PVH*[&WT=" {&kB,uܹi%G:4\V]L՝&"NS5N VrVyW|+ HHqn ORv[ J5/}5Vݙ'#:rX[qσi |1Q!/8ɻ}Fj;0f̡߳T<)|hZ+x[Nd97~re#랤䯏H=OW K K>gRw>5bbw^Kzvnv)gccUzjQ>9 ^EMo}_]ee7Z̼ zDq#)<6Z#+JyS5?hRNpT 0nκ5t%Y.ܡcRsVDF@g 18{D jDUXrT ,LzSNh o3xu6` )\UPvBa%6 B'T_;vِE{o`y8 $Ӹ⺤][~tϨ)kqۨ6i(y|V]V]GL/2=_1]-RYuOZ Zfá}F@[HZZܑtա5R,56 ,xPͺ WidrC1@I J9TtWSfzUE,e .^̇(s9t8)~LPdE~~i'9zk7Fو%[#n2눤.ѧs&JȢ^S9~ߜ3|KBL6ZoYƀA^ʂUm`ʟb&]fjI2]əs agd>c ͐Ey퇼;tu)y)U J4I&2A٩2P}UlpЯR*͏~ԵC2Zae0hnnPH7F#~Xr_*@K0d{#b ZdAZ3 L>Q|~߀\ q2g-OjdQ,:$6n9xE=6~8* x򈅭lE}iVp@m !V6Qq|@T1Ċzѐz2aj ]I_2pw|pҏ{=*V1o.c @jȽ{T:J%фsq&鷴OS"+[W, }u2Ŕ[NvrPf3K!;] B&g}RqN!!sLJQ㪽`A:a- q^PS'3[l7r@wa| ˗|?=-)( b6Yopvo%:kԐr$<Og5Km<"RP L"Ar1^=~FJU~0*?>_*5:kҲAɃ} ṙÄfܼ|Evӣ\$uU1.4dr7Qx, x8:Rnh t;7_SHe'b'Ra Tfav˸hA^ݔTT;Xf Jn2˃Vn[d#RMAm;P@`)]Eg*]jpEְFº8(to $~?M Ď8P& 8jZWtf9X ΑnAhxZ6ZSٹ?w!t!*%QP p6+- @ zv#)^gFՋw.jtL,Nm}g]'fx X~1cHvJ)smSp49Rɼ=z @2eKIE8#׎V%bK7a1Ճ|*EIؖ`kbDhGcӼmkT0 9M![ ,7z/KU"هAvv02Ky5#"}}2F[u12۫GHx >肌5? [F*'d 1ǎ*,7wa} Fv,~?n6.;1PnmߴՑVj2BWn a4LEñlK,e #[SI,MWMozNt0t vӈ+] Y zf(W95e\Urr \;Rڟ6;YiyB ]nɩ3Au{$Z4}m|:}#z'^UhuI89@c`A/PpS t6 M Vkț\Y+$ k#OUbhfRvFzl^f" M'A.s;B\k~B"]b  (]̘~L"A #+Mk9\6XFt8 ,O1lէ^عS,;pi[+@P{WbL0;Ww}R&{]43&okT$I?Aۛ5eͣp`clk}^j#7n!L?M1ȡ\LΧdq=cBaJ:&TA^n_)p]F)V 1sZchk-++/ >〷 nR\7yciHch 8[PqKI3jEQ$ilAf+ȊaoX49RŲqW5z{kG'#+M Hk:hc2͊c3)6o}XU`G̔ءLSDPiGj#Lq9;SxȖEm,*2KVuݯbF;]Zc7h+URDeH&sM C*v ̈́6Uqq]{MDbרVJ,0𵍎()!U+;𤊒Z:WR?B:[S6A&ܡzH?Cr]y_͝QKyI|1!VP~B;LۿcIEoF- [1$3bJG_Рǧ@"HB`QJꂼŁF [DŜLP6cMN!8&%O;X#jnV9|D (.w~1ӒpW85գPiE qT~% v lq6ԟmP-eqP>\`P& 砊E`qR@(Y:TjoўS#}R 0hZ/o{vt0FLN!:%ȭ(=qM-;ٴ_UTY6 g.ԏ+D/=>`}N/eeAǫdAH|qiUIO{~uu :C!W}p`k6V A@˟#U^1tVYNO q}[lT(< gҵLץ|!{*bOuC+4͓nOq@v n5GǯflRa6Wڃ>H< [0䮰ܖ7o&Ss #A`UD촲~ΓTԱoؖ,`'z^"Ҏ:5Dn^"n}?$c$Yܳ<59LX',q:̷dPIjk:'f>N ,%)XKz]5K&]efwԑ1dj a2ܒTNťomv˞:Ft$ ;:-m47gz- IR8PUU=O$7eZ[w/E(rɋ:Sbk1t:o,SyXbPY=4#۔: W|2˱ ڿO\|+?n KIfW%b>']l\p&pəוf~+]~ U՚Dk6uT?HGMޝE|"`x.u6^0Ju*Tcp·mRyA:Q ķV*KC C- \1~'mR+9iCN+=l%gވXGNslZLUBJ6 ^ mDЯmk5Y%O9kkmY@m=~֠˞vIi4M0TBrDk@VRYk}6/6V^>P'ݏ<O'h5+@ 7m.f'QYh KIb<|׍;'xLNUgtZ=tԐ&`)] W T1IS؍P8  ]0 >JucϡZ5~)T2:OՓBN*D}/ Uxr9c`{i31=r|Cylp&$[>Ͳ:GPKxx;oK(I*Aہg ~a#QLM`$O$۲z}eOm~^q}bڨhG uBQi)>tH=Ӈ?qr|yr??>=hǁuA@0?W.8IZO>v PEҧ85aY4#vnW 0PKlt*^D?.Lh߁pq\nS>Ba$4Mg6Yf16c5"]2fq`XJ ҧ;REvKr)Bmq{ h@e榌>^_xR욈t6~NҟHS P>ޱvf,{-HA@lJ[9gYw ZMG"X4/#$l/P B~%P 5ڰRRjѝX[RGA!):׳iD$@E iǑs3tFg5_"*lT(lafI}RIf賊ŪQt w4U[t\1(@n!&OՀ4xw!Cw‘re 3,ohO1D!@ ,tr-@hԖMcj`ݮ׿_3okY Ӭ_ZQT{2.` 3>7Ngm6! @xae͓ 10Νzag$}$4͹C'Y7o w q6T>4P}^DyʑT>_f$TAh!@rL 80!9g˩z9T, :ސeHBec5Cɉ/@:a0ٲ5ZHwmy;,2X XCAf}y6xⰄf ?&0 ){ Id.jǿci8lV x cH>KlNL=wsQhCާmSE'7d3DY 2y_Zάص7q`:ף'y vVKy(UEPn8l()T:#!WSht9zWa;7ϧF$s=3?Q5:Z?!V]5ʦ9M@8:(-I~k|R  qCoVÔ,&ًϋ<@5e9 OPtm-2VGYp!ltJ!?ÀI0d$:x&k^y!7C-@Zɔ.Gꋦ!3[U |Gm;^@FP9{gj>E osiK0 /悸Ik uaK X,cpoqcb@ǀ~H*k1/ \ :|p_ vRe7F;q3;acl4$g.6 ~xxt%MtI m- {bAC2.A)}y):ҖZU~a  &6:~=hV'㳲Rn~"ڟPᭈSy\#X-DU!8bh֠YA0Z:*#$.G%߆0n*KИ~>jʲ$+/jXUҸ,Έ[6:4e%2/f HD;R|϶S?d:3] [X񏠄}#mZglEPv`g ?sNKC#Ui]R^/:8kJTtHyNߪ^yN~$|Z̀PL|FnεmUO=SV13H8^Z!A:%yŰ9Z T:|1I17L";֬WE9RXD痔"Pq×sS G1g9|Нבe29/i .h3h2$\D;tNQ-_f5Al9b0CymotW/Fm$;7K Q^Ɣ>#+1.;ʎdyOx}-7(z\ILl}8CdV=l6ׅ`[MøUu|ZZ% ݒaA[qn5iuo n}jOSH4 W]Y۾ n:kG +6*BVm6,|15s㏷=i˹ IUAO$Z-yBSs>Inh;Yx.Nt2nG䅜ҬP6{8 *S\ g֪=vZBZ>20\  Vݗ%m/'$ĽflLɟ IUl{CI4?|q܇ رKtZ6 .*v;օh&^] : `Ee -.% *㐤"7"r|`؈/t2g)E)x}j&`5G'zJ--|1@1jqٿmYgFF1p~LE^@I 3 H:m@xC zmhQ+U@ivu)sWq$ӊ@!::ّqz{!?&kzV9~ULrb}w[i.Ǧȳއ&a \U×Ʈ[gX̙hфcTln[!yL_ /6v0joez(]P0"iNJSGnc&e | -2jűHziC;%6nh52*ʤkrJs~kH`Mݧ/ i[B#Ẕf#Q(JWI:ҳ-D[98Gr,x„ ̒>/ 8%ѷk@1*sus:Π {5@q+ZA2҅\hwɯmPrmA]O1 Uc5 RfKV;P jOڟڔvu𯨶oF0j `KMZmE@2%é.Sn\:†PX#gwX ZU5\R.Q Z$Q6l Q;5>o }. ѿ,]>PU }cQ=L4TIr4c8?6C{*ăL,Mmqn 9]060t{ܙ.=PRgJqhlI= |z!sPԚ|3<0i㊝M4ű -1Oce }f-#O?Ou/==sěmٶ,)wu%~ \L?A v&Ctaa7Z:':1Ocsd+#ӶY. z7ǔYxXDvbdz.'J $vԺ+hi}~omKJ:>!n'qbړl2\S+tEE8ʻ'{ 3Ggީ58,2v60qY&t'@]Q5uoi)m)8U β_걒?]W?a}jk~Z ';Y Y{Nu' WxH{%)3hM!FiE`;Z;5woIs\ihљ>n%_ͷ0$h;?jBDw+FnMfZmo4*u4[U2,15ӝ?gֱ@#TڮU)C@2-~BY+ބtTEhUi:WΖӍ|=}.vn[B9,ޡqpu_ J$EhW8Tj 9Li߮{oJ(N"Gs%Kun7mQw21YND} /^PmqB}&w$(?m[1 w]?&?y"ffBdgFVdؐzDN? )&f~E*%,VF&`oCf9/s:}wËCw{_~_eB@;!]L@{ Zf4;Y@ad7{/;>v!hlnp/.l69-eOon1RG4\WwRR,mNc ґvIᶏ ? 1(T*Iۦa?TQBgw4 ٦h% xrLLy*ܖϧ$olT k`{&>w2wgV ;fŬk*z5ɍ0UQ tռT'ȿQqEhcE A9K bEئTKv\hgWj,{; F YH\O~lQvfnz`P2 nB?C㼱 Z\L*+]6+6\)эQ(id#>5B<ʳ."R U8,ecdTDbP9NCA"G990N.5>>*Cu*5ƷTı$_l{.WЦ6P: d8ܗɁt$* Dk)Je54**Zf3ɢR/hzá d'\21bAA OY)76`n) g- 7M+5όX#+3ZtVud6x:Р7"Pc/pyHuVBx:6&? 3z/^N)SS@47nXuw _a[-C=u\@S .yLm_:<&hrkGu,.Av!ދv#՜tLug-xk KLdp OVQEgM OޮZ3:$DžɼOre6x hת| 趏Z `TB &H1l%ONJ0(%0ks͇?}V} \˃Y/.m`># $6t4)3J@1۾mAe!PVnl\uwm+KͥiS|蔰HMO8b pIDhP ݫ{{ +2`ʙwXϴJ#E̙$(vFA44QnmwCn-C1 v!cM鮙|)=k!5#܈md{^ +ˏ/zsܩA|XbݍY w(܉AY3l'Gvn о+48ƙ3(G}Aim0Gy SMw|o~?/)_^ %VB|>KF0{@ J}ƫfꯅ%'5xZ0bCB8'$iɴ3U^[ΰؤyoEkBKјGgy )! lNtM#鉶4r}vI ƞE 3#8[V&ut5~Dd#_g*] P 8LyniD]aYztncW} Tfp __w\ c:g]W+Ljհ]u7b6ecmƶdR !6#(5w7 i_ϑO+4w 2jyF!ߌǒ!a@LFϫ ̇BzZ+qmWG,^sn}/xo\ĶJ/kv݄NѢcP:=sl葫z~E=_,Dx@iZi:U~6p*2WjvmU[5(6 '+>;Gwɳwd}WE/]jQ)^ c|IGl^u_'T2 6AfU>|`#6^@©p=(BLESs RfcuTt;A\1(9L/*,ZsVĿrO!-fvL m6)Iפ ώR Pl18&+YƷ,»vpX\'"1&4du2I*V~l%\<&UnQg㄄ԥw0CWyYE(31㸘^8+Ab!5҄E4 -~=(]hA-[MA1Im)1Dذv*AE5:Iw3tç 4T)]R3I͒1"VzWCuc Yk.['|rZ{R2maJKsWLJaj;Ql,>7VNʴpio Y$71z[T~vz#t Ok憎;vkm,y ʸ G}>|'BzX:Q>W7t߳[t\?QPBU>[6#VLy*x'$\I,1#8ؠ- x=eB UFt,]J?% w)Y Kȶ?czf̀J́z5JlC9l:3sXs@7 "+a#piq0;])0)AK;!$Sftr#"j ^͔NG  F"& !Ǩ]0_TQvBXv(KK!eHTTpB/vZƜ4+,}Cmp)Yڌy(+}YN/ #7컹m軒~S} q';O$Z֌SȐ؛å&)6$'i(wGtM;J IKј݇螻Kp|ʄ~Mc**¼0q%`UFbG F?+,!]>El^w&Lf_N4t[L21A1$r!#xM_nMPLnIiO4 4-a lZ ҤCPHBGϪHQԹC2$h[me1G{@1mN:bO1Soicps%s)+.#tP$'PH,BhoM $PxӲXDp;b=O5X- ߉ccgta\5H#Ŕ/ 0?]Y:N$d4@wCE]99r|qEpn4r2ewKgy)I3F-X Mv5nSȯZ*7*q3`2*kj݊oAUFӀXIx "i4dvE(Bl?Tn3#KC_uyg0DŽKa8Mi{]P)oGYL48fCb9>:GeBYq:{qH"N֓NVSeaO(.9-𱲿[je aQ7Zt63nb Guԝ(.H%C)`1_zhj8,h!cWxbBMTe]?fHv)?zZx@ 3h҂z.b}ol߉ z'@ H3s!&.E57'6dtr⊅jsPъ~533lZj^+" k{O℉ T5YnR@{늘տ8#aԚ9"wCe/tr ' }=/>hou/7 nh@ ' oOrѤuޭ* Cn%rtyQSwipe1 2x(;q}~QL!]Erdnpb\H(lM|p0Jt7^ I,~R*gFJ3;G[`CҪuiC ޳WRe. z] 4녃/9P5zW]FoJ5bF0az\\k͒,YO{7%oa+vu~J,[zdPA9krl B㳹YX3 \97;c&RX q]6v #A4ɠ#Z._>;l9.F :fؗpD(?sHË=gU+r{WkCm|GB ʤQ+)@vR ![!igE %z| M@slǮIpt5Fb5? x37~/jߒJ-is _XOW- sXH7 pAwyk&z\P7߲ t:9bD[Z߭^-9e"4:<ݎRm;mA\?=c6\,ѭ $8x& H{@f\d԰DV 2q'SKۖ?͸piRH/^3%)yZ #8 32p&DA͛Z0,G!%hx{UJ6cL2bivin.\;}.-f{F.{ySm@0u<*?-A(r PPbn缽*]ܡVB{);f@2,M9cW/"+Cg𑔄?T'bTBEqK+7 F+a+z_;`4Vq]plNl-dvDEYxј;3 \Ig_"MB79YĄgb5́QTz(F]#XEOa+/M{312/_Zn}Ve"l"g:A7[_GQ!Px>cPV&dԽ<,W 8_޼G:[ZuG-Y8@:̝$]K[GSpfo >U/)F@wOzȒ7u\HeO#VL*ssZ3vHg=2FB"?4]ФO$va)щBՖ$OKX_A,JI*jP0k̚R~_~V( Ik/b4:0g%ǿtNM*[Ak m[/h7Kw^~, V9SFJAQqo1DsWCb Zy'V^܅y\:QB Q8foOCZ$ܴtmpsTM| \s:<2L|5\MA#(kv1{58H84pRkRkI0Z>=g*VeYWؔ.gro0o#/E}B( _8{`s33_<`t'?"o"z(KEB% jhn9X|di?6<! O~58˂&J`D|993dȬ /0P,fLC(vAא$TE%UV1!j Aꦰ.nmSI=рò n\Byu,"$Zؔ xV7q~vBhNn$ю/xhm?{rH)Wg@ێ@^`Nx63?+$_|X?3nF}M_$tӄ@ q`W?qh3Bw|Bkl2CDz*oClCV@~&XEGlF1cZ< w#  π+%X zosdOvfe07qa7iږ]}fԓR}uI̩ Z,#7z`.{+ٟDŽmɫrҗQ!ҁMެOR~$wIre9k45ڐT? Ƥ;c8\P0ނdA9a_3FZN1V)QπɑJWgbaM}kmA% ĩ<nje%6(=hD 7I>Φ}N:yւ4{;h0E՛}l{c_U*ï3)>w}B(1Ia3-s5v$okmu~HuN";&|B߇oYGMuaQa3jF*7EqlXTZFH;m0)Y b"e8I&+,r|JM1D+$I $ޗ1ɾ9DERm /Z%] !Kh1SXP'LGO<{XrOT EO7pAߢ "d*v;|Z`ˬ>c8,vޢ,|Rf|KrJIs1w}Vl fWQG Y.7vjG1yuNG uVDqyԓǟ˜c؅ ϵeR`yVt:|X%Ø8RwdTBycAbnX&öu_~- r@W< _DߍI|2NLM7,٬HfGU@M!}ׁ/ ӋU%oE1owM~h=J;xa@rSm"?\~_uvUGS"Y2@!γ'Ȥ:Z5ELIʫs+>L{k \é$:(/TjfO+Av$m,EBb¶"1B 8|p=(L6{L&`I4r"Vj ځhp@&\րziCHeTn;ֲu1Ηnm[B7ǭ$[_PqT YI"\kGo+ t&5[{V\,$smXb;Pf)F1 .rwMykE Eq!a+E+"\Ɂ k_cᾳxWB>%Ӡ+JtJSnnBvհ%iAN+Н=[/|S}fAD-ԄˈIցQ[1_O 2h[E_?DFA@x]Xf7_A=u,x,IK߁ᜋ{"z $-VfIys$ҹt ZM(Om %>i0+ d#"i1.2`PVCFR>Rnu䜹 2gfWv96Oj綿u?MQni,EoiGd)9r#P-z{.I?Xh ˕m@e4Y5sM'5ޔj"BB7, +mSEikp s`\ JŒk!T~=Ւ[Uя tFnf\'u_X7-&]sK}[y؂7ɋz$LA PwʣpA^Y)#{D׌NȄ卉WuS]Z:Gy1-J3#8NՂ@lrֱ-~'0y1E-TQ]F.Js$ \(HGO"\k 1ePT!aDR:}yHZmD5U'{YyZ1ipqKJX w GÉ^,/-!`-T-Nt+כ1H.I[>}HjtW8p1? t/Uq$-YfLLʋ{wbtD(6 jEYbm^ǵAN/c S{6>rH{k~ooXd8KV*a@ǟGS|%Nob CRNq%w=rE}ݫ a{[R#t%-1 R琤3НYl?I34hBQ4.DV Uijxvv@OvLy_|\THy 3[|+#m;`o<2r|fHӦvGC>>Voؚo 7@Bؤ}x\k]k,y(ĩeanp/cL8/τz;+FVy4Ng&cʝ_EOBfyqe޻a:*K Jv^tsÄ̝?X˻6,7~b&wt;\G%nV&{v]nl/>xkjV:wom]='=))[U%A }MB8UrWò[&\Tk^NtYJn;֧|ʵs[oN8jTW X$ Yyxj#@ L`\࿪nƿ9<\TOӴ4RiL |^@+ƭOs?껇wO(!{W }(iEgݢˎ?MS&B7\o\r>'gU#H%NJD :El̃(u[vЖr ziegw`pd/vO;01$9V onx0*;o`j7 ǵe UDZD})XE\иeQ\6<%ouZLּ W\Ҹ'J_U'`;:\̞I&%s{ël<ɜB)fZI/׳Vi5>6B*s_tl/Sma~:GxԷDܧ?qU ۹C1uAZCth)eiM"BY*jcڌGrO+BiP"F,C5}__sO7GI]|pnLX(L9L g 7VPTDJx̆> 5bCv073P+~:rF.$=>BW? p5A|҇xteXYUN!ݗzX&If̾+UVwaW6@+[vv_!RLb7E$b"BcY!kִ ]1`uYK7(c`S/ѝΞю"1TnPfN|Qu7R*4uS{_)Jx#Kvr8̎:L䦜:X8w +&u6b h& E 5.x#u=U[mŘ'[c* >m1Ө&}-T]`/h3z@$PM7 O\A_ť&,B|DkId˨=߾zHIՓEK}5[`BpUl-[j4l6 03o&0x͸kBU]AVX,Zth8C ٜP ;BH/ld)"F{"[2u|-gQ0<}7Uת?`Թ7jaN6>7gmI$nryKR7+=)>Zd;PɃț]#j$T}:\VAZbͩWq Cъl(W\:y%2ΒpɠZD2HV; qB*Y$"\ 20A$5BAkߔAo@T nP+Ą< (̏^x<ɸDM/[F[] p9eC~eP_;ml+Oޖރ5$+ { zf,L]}Jȳұh|$o6 \~_WyiQ$؉q!]]/* V>᎔^>ȉ b̩t, N¯Շ5I#L3Lȗ=y(PRzBm:!Jov[NIdž( Bn,&p[Ơt/J>2=dmWfPN*6+ws 'ZVIb 9̸1u>#!XX.:5=wG̈́BATZSf3}6  Y2Lb.!oqH:UQwSuH` 1w:,Zt*~ [ ~CeMSp;YW,>(6ȳdJ3|~JYxk#ƒ ?Q-lMlq5c`KBܬ)1 J 5MA+>|Anֽ}]`MYxY[IAc2-$#j#jA@ΪTyȵgEGDsgb c<JB̖! #87&wθN0OwD7\v|fZANudhq/Adrba1P9Uiq 5 LVH%F@*JHEii3?8 Em8?^)a2}jW+ܳѺy> g0ab*M&k4aжcnfr#C'od%Ӌ\3jX-3ײJ:Rjke;؈?T&kB( 9-lYlkk==A _X0ƹDTR`с'a2z^ꍍrқQW&!&79AGgB H0tlVLm_5At2Q|aVqߞ&|'kD"%\G,?m#Ydr$p}VC=V.z#;ğ 6\>WWRvdLؗl\K984vq%`Rp4N ~~Pi Pr)2ޯ_#Epw$4mL{XP8,g'Ƈ[L҂[lT1?"0S+'M6;.ѸM\>D{d_^$< Ȝ!Q7E$-O B\5jwbw=ڧ}Js0aK-Y4Yɹr0"QD_X3[xHAP-%kֽLO /pŧ̲eXoL1+jĎ\ʄdh6Xڎୀ) 2(e #YSTʎ_WY4y7"L8}l'~Ȩ@DJ֘n8*]A$nKEPHPI{H_;Q -!7F wqz.Li}`ȠEdan߱$Dyc󽩦5,KBjutԱx'!sD.B(M ,XX}i\Fm e:cdolNqGkpk^li5t7C;K}p)Ά؟ztSͰ JBGlV'sm̡ \`4H54(A[6wVf7pӰ}d^+f4ͷVH]~1lS6TgGqH9f%xz q[AvY dClmZh'dY`R[Se|ӦSnReУt;S C3`[*[P# ]M}Zq?*ĺ+|CW>bVR^)=`|e)=mB47#4%S) g[{ ;~*}>@#Z JNBp2g2@#0Od*Մa.BpL 4G7L]o ZYMeS^_,FƄE%{p*7q/7N$!,{Iq@KXx׫UXHJAvʪ $LV"pWuA E[CqUK͆D}BjV]zsrؤgUŶdr]fuo? Ʀy^yCuP8E?/L_ 1+NhڄS,5xMlmoiPΑ>a5M .ג@Eyܝ(1ײ., jy+gak!>s]j|$g;ӏw_ǂeGC/\ɵIP͓‰IwSU mA"g;av@OqĔ|'A(ql6Q_jcVA*ho~< ]DFA / ϫ۲# )s8]MRU !7$D&烑]f<"T+LK{AU &ɕЪK<F8#IX6AnN+ 'T)E<_emFъz[g79^'xZocnߩ;A(0Vj ]g.@D!yc]>-nxldGIl/P(FVrS]qt7k _FUy <82=\YOtcRD O/3B }{Qpī[:N'W()sݝU8\4̠䕝\CwK}"K D=%ucGS&z4t嚀gWvbak8&{ҋIMNzVJ¼Up(֢%:Tsf>++`:Bt͚hoy#}LcX.WwZx\\T"cyܝJ;\E0V;ޜ6\{>nISasyMv ([ y֏~CN ڄ wgC*MN?̎Iy[sG͐w y>_%W^!' (UMHw/ gm8i>ӭ Rd^W [>`msyu)!:~X 7_))d~];KT+nxq_3R+7ǽ8b}cy 4u \i*RnXƛΫ@1w\—I_ƈ 鳟 ˸r;eX $EV9LmN:n\w PnR-\^۫^IM_a>nKMA8e~3`d ˫ϧѡfB( ;ƤG6G#Z G_'2`0.R;-xX gG" zljg dκnm<@hl-m;X+^oRq+pl5CT~"BZZB?B1$P+.7W9|\݃;:V@ȈVҮ>kF2>!m 5T7 uN0"3&-ZA>nofb'Rqߎ-C. \CUV%ፉϜD:/ @zaQ]g]:kNF<u >0zar`zAqOtregyۻq-Á0ڊ!)u ODCx8pt\Yi$+B0XHL]/c1_{ظ"4ωyNF9눾}ʼuyF0XNKLN}Vq=7HBVJLcz UL*nE6gc팸֐IV!7CLumg@x.,_o3T~'ލB0Eyo6R}3+h@ <]͙De }8^=[G_?(K0DlYhx$΃ mz΂gy)l8 ,XN ('׿/GgƷ YC-S )`,|7Evn:,%Nb}SqOq҉37 ^ՏH+&1=oiFokcfRLZ`Zwi06!!/><6y tԬAxaVe8?aEFdZ\bWyW!O|KlyTF>AXP?1 W窔c<9H%?\0~&iV~08\T-ė}̘!_{Kl:_-ڊ]wԛQе֯d<,hn9GuhǞaKSMs_p 9؆w9]gc`/:v_ƾNYx.($T//ڣ2"5EN Rz ׶;*ꋙ'fzZ۞׳b_W߷O&#{hTQ U N:y56rW]EP0)vgQe2'; 8u_qxP*q-aJG98C_4AI!]AsQ9JNkfYH?3rHE ϫ##v͔H~MAƌmcCZb{ΥʴZUi`$BQEJ Uz؁Ie(ט zc7\Rm-s]ˏW}a,E޽D\Be #Dj22KƋ;!<`Y4@ (K 9tmQg$Gթ%ݲ[r2BgcMКqp9D f +XAa֘86'h,hRZ~N1a-B◪.:wLăS]Yˌр~-6fDs=D 6mAS yS. *ݍP aHNηT uL@hwVVqbpIϓHϩufм;P|Cثp+Rj,-tAjK;O. H=)S ̯}b %tϓ8+fAh ~4G4 v$yU(?,@ln*K,p_`FʛLY 5F þzz.(V(PN8a'`f=\+C{=J`Z)kI  @KַO͜[i,ƑЌNq'LJvb0})mq߁2"-ܬ7t&+O@]_a#LL*.ة@bFS|\N AQynQaɒR2JnuS~Q\fSuOz`wdG '}1@Ev[y=gzgzE  φ۴DoT/;{Qm[1٫@Se<G>BuG5a_yL( J?WNveKl6\5e0~!W$\8VZ̉`4+ n8Om*b} Sș#m:P{UkiRvg(gGF~5'hN 8WwtSKUhHtr͏@ɱ2fE-;8M,:imԝ{ex&Ng5)Jl4/ 3xk g1]Q,9\h.Sz24Ll2:⥪uT@k@XW3r`!bZ(1NØdGK`-w0ۻ懵 "O'Dvq:9 ŊiHz*weѫ W)])N_IƩ݅v?,A2,sj 9mc+o$cQ봛 lLcDpM8t~#F ՏS34*dTք"Ξ҉~+tU{uzv!:᰿dBȴn߉T ~;?A[uaW͹ V2ia8ҟ}n\D'r5y}GŇzk$b "nr'SDoq)>n!j:GX(áѥNUwp3߶iRN7Њ{yr6eO|?{MD 1)WGqC1yKpRB<XcTF1 _eBUkp3R%m;¾T`D㳮l0mH7ޢ=#o̘elPPS?oo[˿(ަ<{FذQ(b !UvZgZ~2p_T͑kh @րN[]ltBne1FSއvn.^l| U92SB7V a/8RMdy @XWIt5L'_5u=DS`0s)n`66';#vM-d<"3Ҝ}IOW>DzmF]}7/_]KÚl: dS@/;hh5v{ °*VDS6~q˦C9m*sjb6(TcRz2X<~{f,C*+L n^9|9'S!kpK*(ѨϮ1I'᫃%LhJ1afrW'n5&i(w3 0(K:#pbzN1ܕ]p;č@D?qy5>LΌWVg?W"b\EuyvwErJzv=H0%ƶ/ 3-AGp㑭Tk'L hNnpM:zĘd/>N²+ΉR߷ )H }3"#|F2@n3GJH9Pg&!ۧA |cY)zޱfr f+qQ/q?OoAg(pJ*`ho_b-4`5iDwCJ,jB_rF ] `W]]5-D,FE]w"uf7aYmɥqt V,%dh<ˈd.tYZwhB'A͜5u&ٔ.n~=o0u?[Yr#{eQ3~?˭١j$-axZ5]}X N5es4qng]hN&/߈FTnd@mH獅Yv.6~ps  {.,Vt#SxN!P&Bh h}.'6 #qsTs1bc=b iSYG"?&Вp0~?#c(QVr^`33RWt=Ra]k /嘄l:?$#'DgV󕩅)_ʨyCDo<˝GO\)1[dz]TPkTl^ɹ&j`f ~ΜO*}pxLJhN"W…PҶU^߯BtՂr[O4j0F8]8̠}zj,cgd(ܾ\#w!`!=\Rٜ'W!Ǒh9kv\^DĶl"9ۄ*82m*Zjͼ}o[.2:fqy]Ѡ$wŞxJÓݖ~?y!wuܚ l;)r54#%wS̏U ԐQ *srH6L~fKڻYAX6^9Sf^W8o5 z6,O{>%zN`jSB!:y Z&]5ED?u6bPM y I@Eŗ .2\Ǐ?FnDSfȅwcϊHu Sya;@iQ=xlI7 HNk<(UbȘ]z0F1zoFj{"O缺h}ԟJ"L8;;U'>q r &/ eLtP5b?Ե(ĻJҜ~RluĜ4DؽH +gv?nJ(|&ɀ=NGgAl]zvw60pni;GE'<' w`Tz7 2 b6 zm$XlySs__:q&PEȫ ;%N#0D˄^"`irh_v~@BuUWzhMuQ~@1S?(+fRyU|kѫURnd}K)F"GdOC>cZ7{$,$?oY` ddn'oKEw. > .* IJ%WL6w =|91Znk;խe}McMXz\m$ATQ4Jg/:˪jB/"vA rWێ۾M^n(㙞*T~bj>%[Rja.s7z)=Ν6=?Wۦޏ>g n9b,wh1o71Tkyȋ<uFzycJ%Taڠ#FNnİh/gV~1OLNUDc/'rqX>À(;s^@VŠ2^eٴ~0ϵ@)q/l"v19 nמtx/u,dLڀwNJ^y:J>^0l>N{غÄű!j&ƍ +[' BG#ZDLnҲ[g_tZ>B OZ|PNBğQ-!;ē>¿&\CMTաWzƒm{]ش;eVk)nQT:7G^a` Y vInw\KXҫSB[ڌwkXEl)M2ȾG3)CGG5.7)xm =3vƎD dB 6k쮙ug!?nja0‘FfJPJwԅ t@is)l9x:eO (Mҕ'ZKƸ:SfT̢CV N*5wL.OПA'z {Vgc%K~ !2j u:,&^x=Ֆ8ݮU'`z hFxs3Q8%ߡ)WoeVQh'r24\.J"8U\ADwYK8@5<#2+I4ZcP="'G`i>;H`U^ Q:>R0ۍcD'}P-΍hQXJ8vhGPf\f¹E:lsk܇3`L8ϗ8ވ38zin|>4e%Ban&~4G0S:@voZ^Gx7lYt=Btfp3tEB:֛FJg죲&u(%fU#R@e+~jcژ`d c8ArU{$he]fR UKL:&Py遥n]|>*xsaڜ5)ˏTCpB9$H03F,-[Q~RFEϞ7v6{)8QyM&ujpxZG`(Z1v`c;;- )j ,M7i:IF041]8*4KT]d+]=p.2 Pmixu^Sn]VާDzX)1o |(Y۝}_7SRne-U.&'H̭KM1 +VXҼr_I;G|)\Y)<) NʿP|n{= Y bJ &"%mkațSjOOE#%Rl?lU^ 9P@Ed.&%hI\2(Sy:?uD%cp|XsQr*Y7P߫9 &K3υeI0%@1ϐE 9b2g_! uhn+ Y-Pol;e9il" ˯rk@(>t4W&)ST4HƁ.k7D6XCm50Fwal'v8x3*4jJhUMkPgM2כ}R6F_@5 , k}π_ !voP+yj**&-}hÇĝ 9H a0lC}j鄓D.Ξ(5_*+ap`u3TV& O8#>F+ncg,==])䞯ɃQ%'4 v>P\yϔQi;h cdp`#^|TMaȃdf(-[:<tYL;¶ˑ11hP;is1E)dV<4ܧ+]cZ"ZܯdIe'1<=iT%IqT9P@o %%>WvG(M 9@=S!7PR\]ۓ"Y )@eRmye|cA( H3Ӑ@$g+莌`!k##M &Z[ObbQVJG %1h|:u_';Y|X(! 6kj152f'i%qO1q.6fTǏ,uc b'{K^q*= @ ڀ*mAf'hd {|C|GbJ"VQgLTZn5 hutjRL :6mUϹW{5`Ojk)MM ٛIhS=R,mDր[/q#\WT4&P;YM1̴B;ډ3U\|QݑcHcC:v,q4yyUMR( wVDV=ϭBem YW~PA/\Ga=C."]lo|r{x<4F""w;Ó˺im]h#M'|q ~Gg$[YVR ruy_(0 O< -SA{vuÊ)B+P&rx{Q6m-P_+d;zmD@{vSc)~W>H~ ▋>TN4Y< ´?++׽G%⥫#Q?X'cDDoqW\;SVެ4 "V,jV`N,{ɼs^K*Wo9(>]n`^S iث ݬ!QZʯcɌ;3aͨrfWvlI~;O[64ȿ7^J>l**E+JD:S0ŷ ӼDq&pIƉyboz+o*4Aq %d0\i9G62[b "Eueci8$twW+v-_ _SLޚr?RÝ#VN;Y`[Ti!s4IE|–G`D-R@"lX<42;Լ75>/eqqJݞH|VE0gU#H C )ў@M['@qM(;1r2GUi"#"$r񼁊OƊOLJb=1,OH+&XaxPO P'AԿymG KPokk@pO[TCvV|׊fA. %ĭ֏r3ڻŐ\u(:.˼7m]ZYQ .8̭$)@{Fjm7F\ժ|(tr2o>؏b¤&yK**I̠YQ;#TfV w']-r)ps0E5T6:ȗ^T>5; O o1"Pnw`kr1Y}[o)HL@j}#ݲKĵ֨oF(]v"wK;eUL"ArFc#CIZTYq` aBf %%tS jf慭5Q?O[ ${v2b5luVI ?{liH(Ğ>M¢G=J"pFB%H~@v DobB_hf>GrCt(E+1v^+]fŗ PV>i+L kEjՖo[&S"ܝ\o+$RW77NU-Ue.mfqJ<N}O/zrnQԾw88S)c0o[*9^_F6oͤc=%;&86]?HsiQx[TL^N*DfRM#+,\=)Y>d3 p^7gHG/vïuڅ˒ z] v>uCb%#XU;KÜ_j"Om&;5Cj,mδA+Q(ۮ~]Ht~>Q>:![fd;6>CVn뛓Z>B۝ֈR'*oөV Qs2 UikX8S4pٱ hs }9`8 xkol VPU,BctG1z~-j|,^VTU $L'>Q#p;=`TE@S[svOW!knywG oW7!csA%]^o+yd;ɻ(YA5LsU.)j$t2ddw$TM$K< 8UN8׾eT :tCx%߷MOkySI]gF R[*aғqBŚ2^@T:"dIWۮb}Eo|2xV,۴`?V*qXAˑ:-ֵMfqX/kSjN!"KˀF2{c*압[] 8&3)![S(oCc_L`b.5paKUin>trM. r^ 19K9LxnZ%|Dy|j;ED@(# P,xH WZ(}!,|)P@ $2#;8! XXДd lnw|p7+yqr5mJ"z}ޛ%r6(x\yt.z1 < 8 4=:AYqɶyG|N`- ~[CQ؎:/WV5M~4Dy!dK[gbRAeRc,ѹ DviZꒆƐT9|Ai_ğiK~aq\gB8F8#hՌ?x #sE ^Fo?G $Ԕ1X+v&h=|M33ZUq<Hz`ub+boثA=4L6UYsZ 8r*,L6<[_:\WppڑU1Qn#Ij`3cOB偢%P C[4MMK]7 IAWː k)kU 3,S,5#ڞOE81J~AMd0VxD䇲:ay#.GC*w3 ⺵ @-Vg_l*7:m@c ^"mYg"SM 5V#5ls`I`vXxL0ĝN_'.};jX[{faAK_%Qӆ}ʷܷMNnCZ)1}'\!4/Hq#C/9CS ,nBB_q-DΉd965uGXfqN-ketr=bEƮ|qlDlDh[W4VxӺ*M:pŐo:jqVw*+2@2u;-"+3+D iag!▙fgzUܯUhq"-/M@Ɠn5u]4asm p"aQ} ϶kQq=&˛"/&^ks57ɏYg^ xީAbs0o 8V7+dOTL,^xbr$=YY˷;nTsҺI$$]F Wkö "Ko-鸙'ҒSP 9Rasv_D KPDIJ]}ZYh[MyQ0A0j"bopB#=GBw0wD&3"(%eP^tmK:(<0!LQps~ .bҔEm4r|قV0x"B87>Ni _Jd-uP}$(VGTd68xAk?7f>*0(M? O ->=v  Fx/,WЋZ?DqXJc6ŁW$;kt#4_u 9 M]X7NsXCD1ķ;ߗQcЁssH]xo=ZAcSޚVZOx]`簗.%Q ƆĬ_ tm(S(~ Sdc/ivVY-Φ,)& ?@~Ep}Y$x\(tɵu-Q?;afhd0H#?X'o1% XMԝ0%&fO֓y,oVGO`k $!>PSΝR˽Vٌs2l2Idx\!ħa%e;|#_!S5 Tko-]Mpzs}9Y.ln-]h:A=`ffM6j mYr{?OZJZq4E!0)[ܒ_x3u~cS ül,M:6YWʗa@odioT)ڗÇ_5b6oG}sbq䌡0_=ú Do3io%r>8ν}m+~,k0d(MN8@|r(1eT)hfL֫#w ]#&&]F,aRNF-B\2MP8}|S[S^C7˘KSxj&eA~`UnfmE ʿ7a-V4-f4 `Z*׽ys2ⅺ5}ZՍM ϥ1{&:tBU31niV3Mm7>ZY/{J-fic"܍sB=`j9 &l azl>p>#o0:JB9nyrpˁwyohq^l'dM7p0O+bYϼ£8l(yοW$7LGx0UMYǾ*Rٸ0Jbr[/|lrS 6cُYg1H),P__.1V/ ,PE<>\ ˱F~,TC{ϗn :h|c"aӗvwX:3k0-Gx]0r"0@V/Wp2i2_=Z4a/yYFi1OGw#no عLcS#N;1+iݑ41qMEatiDɲxvpMC]O6bP =rg{9* ,^F(\k\+]0^&C>| .G7 'xĮcVMlx ۡ}$hiYƌPUu48AB+u>T-hmICAKen mND ^)kq~Z_FDdˤO_ R,egdSo#e֨3zWCץKT#ESv%s5c(F'8A7GY3xWF{?'yD`G5FD1e V{E>9@e`'>}q rn2sf$|U~g-Pc9p[ڶDpcA(tW':ҎB;, z<ϔX #Hӡ4 frJ6oZm?FNBZܚQF˹:U|éj=*k8eNZMO7N6BKu) pV}#''ߥaشfwwZ }SON&|M 9i[b(0ȩHtbtT S 5|R%%>`߮Z !`.ѹg/aR6ęb<" yӛ36hҠ WL{"Yto42;6~1r渿 zz0uA8b㬋ZfZl0JRn:|Fxߨѵ w)9OZqmX@#:[XS-b)pЉ'cNC.l<zzbj]fvcԝP6;걥$-jAW 疠9aH)A]s7߻,Խlr0BN,@F`xnJFpp@ti̤ly~b~;1]g>e_58K+p.)fiD.!W@}?•m!Qd 2[ze4~#@%,O2+c%_a߷zknH-ECbT 8R -e<f<h$"hVmnPmeZK:hHѧbP!MQj͚?t\%j Nt#هVhUZ: `skϨnD)%l@ww3pAaWLiOpYU[5xc,z&Ɍn@:RDgrdݣ9tT?<n֚'nhQ=sC Nv䫉Wh'*̵Haf OJD3>H^n\lkAg]eXxdr,OjΔ=Wܔ):9pak=AuMDײ+*7aAY0FIƬ$R_G}dX"κ;۲&"WpQAB$_kvu 3X\ju{؞DFİ<;nO5 >InwVwys]M|gsZ=PミX98_oQ|lœ[s◗N6 '00f0;[_}YGC Su{!h΃+KvQr DžWQ6 :l3aa{pLS7 qto⿆f2V3z(!z5~z )0ں%=ku7 u}'dB<G%N| ,RFm Gd]o%kм*Uy;qb8*if{i"16oÙ )$约(w!bRZmp?PW, q]YpV(ZyQD@uOIҕO>\mGfY3~GdUˎ<)~1 I3gj6Wc$O\uLb%R>cVt; 3/6U78PX<'9s7!&$nD/:z>vn()n Eӗ 3݋DTrV{&cA?;ٰrS[+[IM{)y_Zئf"Q!KFW4G3w`+S}1y-Y. H (,UoMui 8l'>F/:>_aqYqNҿ#JqQS m\Z*9jzzqKyl[y1-Z毩09Y A"1yO@uLYsI5k{tԮ;,%yckw9iDc乼i6ǣn ruӮ31~G$xg( p/ `#Pl"u'0-q fh>C틬qSxo8- 8re.cLe)`En>!υbP8 $C)ErG4^xf 4@Kaސ{+28 )?te Gp}4S;H|-L' b;|+ͥLү|` ܈G:rhy *eTN)cم5qkzf0K!;~`N .'K 2Cd@j п6j9(BydK2B*Z0E$n.kC86?1YfDGĔHi Vd/~? c*e HHU"J_k, FRZѱ4)=OI5S^`\&oF%]R%1YJւbĎ7Uõ=&gm2mLAcrvڕCwUHrPyD6g(sũ=]prL 4 h z 7glf~jb]"ԱOyAD"zl>nP4ɪ*g=e!*s{@߈L] l_K}N偛+&PƠ"Nn!5<5u h6n27rnyY;A0`LϹV]ji}(oQN15:i&Wc- %vG:lYE_SyB |.;R$ 6;?emn؛HL4Gtk\N]0jb1̬.,/8DW[(0i gcorȅc+ji$I^~:UlBd!QpM9`Ylss^s "'B'}}Ǘe/pr>hbŦp. d& D붤fGӟzlg} E(PnQ ݥR|5!Q^F?8UOi3jRɍBu=׭f\ȹy aC\t+]~$w; LQ hl?[_CItNFGSgswg$)6VsgOHىE@85M8T[|=oXKDvf6F iM//܃\9c3 r?V(kSPGD7Ij^6萨OtgAߪ}=}npݒٖ:C+n߭SξCJX,AW/*@HHkV_W8Q2Ŗt\HE1mR;ݰw~T|9f| gqwS{5;BE51ܾ՗k 'M3PI!JNk [(hYԽHL!4cvo <{'-4ݩ~M PQPDke?̗ubןe}bNmrϗO? V<1[~ZuLT$=!ŇUWC2)pYeHx*SVxr zB|ljl< j#dQ3|:ی%g\'/ rQsv4`u ɉ"}ؿŌ$ q[<%Xe)io`Xb Ȯ^XzQ ھd TnX,1}F'FsEH&{}8~| X?qoRy-ۜU{" V_^W˛o$Ur36bjߎnRiӧf}?K_WI^%&1 cGDkpayʕ'oM]M&]b Q2C 0.(.aL|/^D2 CӲ.pcnܫL^Ec'Ěo9l?rOܶz N&.81e`^D/^q[ ZN 88(.u&c04}*;*&CuG|{`L AV(;~^::jGyձw"\V|QL B]_ܺJ7/Mԍ7<^;J鸖S _@wݵNM$G\٢51'DRϩk I zݲ VSonف{LBB3-C&# QIO]K GN=\1f(լaN];(NKO ôvw(pʱASU 4seJz㯨5&N6#1Rp!Z4Q@#;'dch##'΁dfi/?P1Tn۳z)K?0(~2}ҿh^ !|!I'=@`TEj՛{PC I- Qrn>.ڭcڭ&N珿hӮ;TzL qKiw޴Lb*reXrkwL^ry!uU> @,2]}{KU)6ZJǀGCq+4hv21OaYexʿ"zذ[Bx}" ܭ 8_upyZڔ85*9N] ҇h|OӻV(3eB,@=ҵUя%r~hoiZ4+gN- ֑˩%q;xӧ^&ƏY.JdDasw7P`ӕ%g(n0#,/mV0 hfCP25Fkh df9O'rf~:=Lw-ʇzӽ%\ A$v[|& O?r܍Pc/|R ($&1PD8䄸UZl6Jn5V${Bm&#/a%d̀[?Gd]̜t1puCZW(|"8S? ˫jJ2]k2#?]ƵO3 rJ]^-m|*͝[N JHWzI3vw_ՅJy1LdowA i(IX"Wŋ|Mw^Qa,ԩWs޲-FzjӫwVfIÂ,?Н;SoEȻy( D#>qrL92^{Z% 4ts6F>UH$O/{6\r mbrM5tH(dD9hMj*CֲSwK`;G^`e!bMcTǐ 1gImO=̌t#N&(9ոoJ8ĴKNu|[3k q؇i/=jiKF!jb;ǀ5~5[):DJhIpk=J#yfU9u‡5 h"L/ɕmV9{e  PK,{W%Ŭ3 |!~-t9E!>̂hTV4?t|9 ;yhL+~[S"^W@73מ};PBĶz\V CFƅG5e5uuME]6YR@H}tHbE izgK%\; ƞ"P,P[E+_$Tz19_jmp[!Sk}_anMN\"o:ni^=y2[=unb{gaufjQdn⋿n(˰u^9/7F0%dהmY<ͩ,E_=l ʰiSfePǑVd zӻYH]s?}!}k㤘L;gjp|W.pqv>MhF ;p}8[S >_|tNf[L,Pt5"dC_(v}}!)4G V[f~ʵ/fkT+C Tiwb9)zgKzr^}ƸUwTybHސ9װ͈AF[(-i"`8'KVK(I԰p,Џ<2a)g0B#K7˜PHh(QMDw܂tRw /:83,j*t"ij<!uoƏCxrbf}eݩM/Y!CԔO@E2;}\xPZ!? 7ϝ7&XhսMd̟s1 xEQlNhNUE.kk^-GDN76R;&lvQ;S!,zpڗھp[G4[2SIO83\<4{Z>GdPI-wac`K;\:֬nsYb۹ %eI`xh[K:>F'@?A࿆Ur#rj#,Hi4+LZõ F!oLs[ϴdR@JޠZ[[շfi{^\=re1y< `:~!,9nEk OgO3pez[yW "Lc)1rޚ(x~] (\ cn =]cLH9Itf52-z8rH%م/ӯ {)Om ZȚ   A_)eKJ!(H :RPJ%f%*g2ު{ q &S Ƨ뚀>1`7 E*iBc(ʷrr3h,dPYv!.^YK}sQ3p(Ic-tN/a a a*U 7oT XҴS;_U+.*TD.,g38! -jלX6 eU s(g[5h鎶+D̡7?hM6^reOZexu'aQ۰Av9ؕgA2ٚt  񽜸fXmWRmf-OAa7,9$;m+׈zjJVnDia\^*5b?ʇF!=/2r'`hsp\43G/ֺj%A.k}S@$r#~}oEVa-',-Rn=ġvn[jA^\^X[gWāH?u3-gzΐθFz"ftgד;_UF*GCX92a"VxQuUTL9tF"#bmIwanҞމG]xXWzZNg?\ ؉P?ۻ JCDJ7p^=+iEnD¨ePp>sXfBP/ymҋAVIvXgK&psc\.-M+/B+ғ"a[0<)c8Ș[z4GAx?HU1-x5UlԳOUU1C3B:8ޮ5Q-)y%\=͈LmiJ4IS5]pv.%3~'[r=gŮ3]um5@ H}nljvh nbQ7do TS2 rM8ח>Hk0;zziԍTG)LАl*Iv!;BlEPIރyt%U ۺ2 :6b3\܍W. ſjp߇-Wi#}j+HPeuҟG̅>R _Ӕ2X!6Ym/2gJP8c ;Z"qVJ6,gC`Wtp6W03 wځXs$l}| 9]-n- 3ؘAsީD ٟr1pvF0n} 8OA/8wJ+3u( _K-@bJ_|Â1I:mл4lLsgC"6j}8N&uO{L/o&t.l~e.VYE(p),4D0湙fm#k۾A6nOiU2&|zm5&BBϵ0V^?RpͣHy Oܻ%  #(A7: 1 Lm|tMpPqwhF ](WV2l^]ڟ8UQY,G~B:x5\_Ѐ& 1=Zڥb^I1⿗lK0fY0"+px&mtf}~@e^{UOQ NxQQYI#'Na8ν⃫qd,HKo(hhb~ިM6P~h B՘tĜ3$Fik-QrP-B+9d.AF'RPvgȹY`몳P2i̭=5hs7 "YA\h[}mbyCer&@jG:7qHLpwfӪA~V4GgF T5 yQePu_]̙jWW6JA_jÿ[<'Hiu:g/xTy wОLga%2,X0ۺ4|Crסlk`l F',\eK)qA"pdu|GK,(WC|Nst߻dRr 9s' l- L]/M7nU,jKx[hd('ND!ZYw aR!6Hb xM75Пnxbq h-S,U rZiTjȉ?/ #6[و%1p.2s0GdۀU%$V>JO𙃊(NDO*1EP..ΦH8>Xأ3;cx,;as*^AdQxWR؄?kcnb \ HN2z=k+0N Èۜ9%ۗij?Ru[rtN9/n$v '!%}6iw򱨙18 pI \MՀV>J+qRZW1̖xNR(bRy.!0[Agr::' M9dϫ"݇hW:,i^g\ԽGQ$qN'/n&o ^RSsNKJi-@zEl+v.O8k5WMLl @ 37W|cDu.۫k%<uj-Xtlf7l``i8܂] 4FN=n?=rnsi:nC9~MgŸJ{e@$f篍c+!hʫ$JQFVh߭E"W*d㎤\Uӄ<mhҍe9.T|+"0rX)ns oP"z,z]O3s(;SIP'J1mGldn#%:{ ۨd@)3h@\zP#LR'Z1𘦘!UV:^ۻ=&]NvCk$_EA&p?H.K:SeT U fWIPr-Iuf=h1<ǯj㤿'GQƇ{! FY"Z?:E2E"ԪD;9rꏅwnoPig3 x<c,-jJx/D,Z Uz_Z#럲r?xvfwܝ+ eaKc}9L9 OM~WbE 8s@%k~H(sSq<ێi?hڮmԛ!}P/bo@ Cnu[KFn{ idkмE*Bl(¯FF1+ G+6^7Y'EHa]PnT7F"Mv#nt|_[۸As)\HWrOm|H57}Lj˯ V؈#.`y;*p+'==&{י6 PMXM^6Å)㔸Q6DwAt3kN@3VѲfy>sکdڔ>9}o2FO!r>*(ς~i8!2q[ qO]&`_V6fy0/9KGgpF;_Cg-; rKK7捥Ijm( 㹣H "R`^3;Lmc߯WdӣuA{Z6 tDOg"Ucaxb;ȟ(Qi }k4jR阨Z@ ܪZYo2ڎ뱼ti6If4TNͯz/lDI|p!ە[䒞$i\, 7ȒfDmO5δ|݋[| ]qٿ-!OڠjIt0J K.iaǞ|@$[fp#woSKIՠ"& !螫+'LY ']WBT[ ?p ǹI+ӄp҉B3Kt~<*~]|Z 7CD-.CqU"\e<6M\98 ' Q)BGȚ D#c+eOqA+3 ꯰λ:L {hϪe` +ACbĀo0fs9VEphs:dE~)](@T /l{'B`âϼ]3 )='>>Vd q6ܺv jNt|d_f>U:,Uv1bUF[J?شDʳ݋&npvhXHjրqIfKm!HQv:K C=r&Tz7ŅZY9X2K dGi5"_QTC)ht'zOnTzwf FCp=R=:tN#3 1c"QAN1Els&#"0 ۊ.i>`wGڷ$ģ~K2b^QFvoJ ŕ9BGYb6#5xGxkC5sU|*/Z&ExեSx);:M6U_o9)1dBzubL4Bٚk,_㐛j{ sHKCkm"qiˑmkfpcs7v U!ժSw LϦPtZxwHYg=ʦ |KԬ_$,LǷcK~ߩuޭqg i-[Wp6Ρ\% j.Àe,5 NFt/V،LYf@pϛpYk -&*K=RP{vDdCPA U.l5ᜟfS <I܍WۈUVpe* ka5RH:7#= B\gD,m<!~՝s"W%F%8᧙ (nty:QHv4R=ِ*~OM 6w`c37 vc`>TNVH(zZi+zִ8>EGI֪ܼ3X}4z#b(zq3MĜ.Ytd8P(=5㹒 1^HSXC^˜*6_ǸSi5KrГ۱%7.f~{oNlzr !XFbӑ"wO@җj1JLp4 ,E+uHٮG*6l?9z{:4wZIX/r 0KQbC[lo'2N:T\c|Ƭ u$GCWvvA1I2_g6ӱ*Bs f7y|WAu"bN ( EzqFqHΏSTO_j'"?{uxwQߢMK>X S.]]ujb/tƈ<pRaBSF,wwl1Rl>|]J66V0PQLPnإ㩮xO UErPw)_b]FibIE[Qb2B 7SYnhNa?Vto@gu5dM~q">|qIO XDPŌ᪘{P&|{=ܒ!:WhF"}@žcЬSx( ;I⻘u¬:hs] D`ۅPxkRĨ3Jۀ0Cޥ% QZqzEK&P[iiBpŪSÜղbX xX+7*dY-X` b; ̊CWCo{5%v|/bs_Tf ;9F9*yu\Y XmnRɼڮ<爫nسʱ}Ic"-VNG*tȼ.oXk$^{wfER:{~'GDJЋ8ԆpyYpOaނrc+X/GJzɻ԰6)p}hKV]{y{` uX5ک\W;O=q}F"8ZAꤐطDKU甠ڒAjz&ӎH4vD9]6Dxt(ChpB3 G0_\b2R|S U`EĒ=z5nEf#.ɳJ%;eڼP+/)#Og9y[~h,A($0Aʭ1zEɫ& GkCj%}n?3^bL)%8'A5ǷWi.sLJv̛Õ{,48q?K Eie6l9չ]=R3M($aflĦK <郐YqLCwuMA)aY,2Jmfb1֥w3#8m@hbc,ƵuG l^*V 8($J=GಿHnf$@vv2Tb 7鸖ӹ6#&}_]ѣ! p7XN5 je݆2j o:G܇vlFv"91_UG;S{2J `Vvsm9Gu#mo|hQ⋖}闌O'@=t%[raUJJ<-7sa3q?}Eri,b2&P"Mɬ~9fZP)bCf|=;P3/Quϝ{Qz(HKQD&LuH:hӧ$ J)'p,`Mh|em)8l zCN O 1Dawr-\aR"׶;F Nz8OM2Qڏ!LlmͩJϟ6B@7|+m{1m/rׯa"1I~“ɵ+A;qbIlJXlR. x+|Ӟ럣V+mK7k)+\@Cogumz?j] g s0e >{[cjEVqi\WxLL>螅"Nq?Er8PUbnJM|B}~ R_yL0`aڽ3dB@ҨD˚)E EIe$H.UJN UELI3xlf5aˉ[^]@GE.7s,&{ܧ.W(>.[Kz$ ]8$%M ;"!eڹٚ/51L]扈a&?ۘa^!Y+4#Q,`SjV*s( uN!WH,oA 5BG^rlEEez_TgN"ipjCO,UDbZj )NK?JnUrP!{/c2*\Ջ^!>|s9E/8Ĉ/4[V3+:HA;d4'J|Se)L TXk,8 x|܄@$0`ڊ/3lK~SlQ}̹66.ROg:b_n6{H$ HY*U#eE&cTƤQ+F0k2[2z@f7ti Ra{4qVSuނsO# ъ萎-~ŭG* R9sqG(c/,: کzDLwb<.VzNO1Z/*ֱY/" ҮxfD=$~ZϜ,W6?}nohs}h B-}s(* htiKAMH׽T`9msڰ^<:;!y-v@$csS9kokos_d-w]cz/?[ZӢX$="j=Tŀp؄ hu*~. jo!c CI6_\VSJT<_H]!i t7_`Bc8s8"0vw&J-%g[<pSu+ۤcji;<pbP领;pꏮigOv  z#<"55zc7*oCXzuRA|'zI \c~HG0&P}FLNieXeUd;|1YQۯ~u126p@ #GDځ:@ǮcgBZe2TpaHoƇVp3"mG.  qЩYuʐYQs`u3" : VW$?e~7GI!ZִpNp?\;,ïKxZl?51Nr_rM=fUGg7'm64VBAMMMR@n2zL%j !Hp\7Uլ8?98qj[z&ZU=c MbV-{]P~^5&rAG+A ٕ$Q+ ;vTgav8a}:{ "\wd.g]Ա5hO7AL9EH1a߽wP yDE)d^*.b u[ONviFF rŏf^&؜I-Ntqr~9lhniL2eL~t|4{Ģe|ކD5?([!YyvA0ݧ2).Rʌ *b9!MO'R<~YJWn"Ӫ31+[G_4 ԁ/'@$%:mYf+P=G}Qo|a}^6IbzMx:_ ncA!+h * wRU׸? Vז-1EeQH: 7 Sv?"wFCE] WELr#Mw/ԡTnGIHoHR]s>ffTp_-VE3L`D(&:lu Wry׬< ,4Ra6%?E钱ic䖚I;U}%߼?0$l"PM/ejxn),yF*-hR;eKAɜ9y;;E~2Qּtw}^iY]n8+fKbW73. \YIPlƃH+Z3у6«vB ݈tMΧ5٣+B^{G<S N7hXaSx!5!v )Ed[Jx-*.ʚ[l%mkÅgKȭȋ!:@TlI9E?I=7Fkw➀ qmc4*[W@EF1VO|"_O)}^IlV$\o-r.b[#TŷsPnGwkr~>UB+ٴ,:dxo!j?G\:3[2ޡRp"%P8&/Z7I5`swܷ5fN%s n!wlO9jV׍IWM cZo A9weNs7X 5p =v`B0;.X MD5dx\wiZWWT|U3;=8HЕ9 ;5Eo8ǒ "YX*ZȣÝ}3Rn;uS%>G) Hg6xqY`Ù'(\?+`&'xVHn:rer7:/N\Ơ` DW֒SJ4V@<;SbiYsgVQ\=PfW=DŽz鋄mM @{CzyҴpOk ^` /ӌpk90rk-mh##T?01}oު#10ȱ,Z}y"o$ O /b)`5͔[l.3u¸IXӪ.~Iէ7VN&ܦؘl5}mz69"iSCf>yfpw2ssEܴ+{tG!ZxF e_?׿JϪ""$B6;vQW {C;BhS}>/`|*Fk0lKt@(WgD3%!+5fLt Guf eF߃ P֣O-Mv'.s@az\7<լA?-˫k7|>Pɔd_F~`+`! HsÊK6h"/(cC;SZI>~>Fy(z~=:"s.kTqB&3PoM #Ji1f_;۪ju s&+zϕb"Q (Ri򤘷 .nh%(c+2{/2K0)In9!I,{J3yMb1 )7`xdM(v_zTRaXV'!z$ءQ@'k#yF4rUHWp kWEdQO8G c \$#Mosc_3w'(sv;Kv/ʵ$N5Lci$!^ ~Z4LJ4frS:}?b a3!#OXX!Ԓ@\> St .XMx AK##( gAʒ'^0/kb(ų@EgqvԍM8z?tYjіâ-UOl2bNcb++@9أ:g!eYst' ?qG_p7r{m~+P7I m ϐ$a 6~M%8*B>Q4{4tc4{n,=%(07"2M! ,GFK\Mu:w;s<-:{eX-U=Q#H.__&2XrSMEO[j}߸F+횓,)XvD#DuLM]JRZbiܟ_=r7H~(~pT 2kYbuEuőND_|K%R $30/)<59dLCd*)Ln"η܌r=80Kk,"<itje_@4s.e&=1rlgD?7SNuP,gಲ(gVGsA);*C֒kKR.٧|Zw!&ðhV&F/%Zȼ ypy) Tf{a*l;*h9O9_r!,X%0@F~_$0AO2RE6sMeaDD f`,!=#?g5-u.,\2K9𢈜fFmC*۸/?=Ćhީ`EOqc\ \ DL(۫jƩH9Idܦ(LJ.[#pȅϨu]ZG6cl_znL&s44@iZĐ^ M\g~)7ciJq{NwG*ݓ3ٹ:zxC+;<2ku,[Cؙ\{;0&h+=RE?l*x"?]u\5d`-/ZWxW2*ei,o-o!?R:VQVLg;x4t4$K0.0:P(n5aaK`þh&oWcf$oW \ 0i(R!ʗZ'#h=Lȩ}V4 ƜH1vMg)%1ZU&PŔ| {DP[k*zn꒳{Tf'^lRb&2FhN6Iy`Mg1e&3pPbI~dnWX٦ICSnQ1crd1zŁN47-i) r|c8nK&,LSs<_(~q]=?ޠiFUӒSpE{i`EZaK¨c<;VJ<%.sr}9R(SZdK*3glP ^z35OMH- @)[ޥK 7^&$N'ۡ+<!R-ˠ~dȠM`giddiq}L F~.X+j~ [[ ٸ^8X`\z0y2szpleEH VF'^!c֬ -=BH׋BN}3W*R^]ƅ_Ɂq*#ƈ{`PbVSi{ pU+]$ҨR:'-c]st~z$EueWS@I) *y=bciVҿ*| ,nIZPm3X*ZAQO:C5 X^%T ﹆Vڬ*6[A?'vh(ǁK% -m.\P3&˯wCR0:EyĂ_£uXGj76x8ֶKIxJu'_|o倞a|Bt(/{b.zY7- 3&:'gM6鑷gˡ|x|Nvt޻#NSl#`ZG^F|cACZİLH7MH}_KW!~;6O~![CR/a[-&KO)RZfʹ?(i|&O+cA$)BSji8A[ :yK,LS+xSֆ a;qVLI1Gb3 hn2g/cpqV Vgm=?EH,> ꌄyי~XD%hl<{ ۧ *crBS3sH>U]Ty{ް6lw XA _0nQAlC.O1 0@t,qU%Q1_"p \RǛ`t3γF٫˄ eWeěFN.沵vY+z(+($\/>AE!6)f-rM o3Bܲ!@)/ehl[36,&FD^ǽG R+.p 4FCS7FCPWNig$x0fۓuUHd So˒ diz Zl2/cy27Shh]d`Xg̟}i$ d"}蕎%yXwjyy#gr'L KsMBRMꢮ n=GKmj/zC.Poǭ؊ۢ$"y*(u FK:YV+O3a'R羃itL9 =!=v4̲nI0%_TxN]&D'I>H%I'Gy4Y)HJ1<"##4xܱNǜ2ӰD[ SQTӒTϜ}% c UJen=Pǒ7lLD1c>hGfyhzh @d;_P(]w8 +lr>Z+E*NnpY*V!0=Fј S y9>0/of{1rM}k˹~_7CW5DưÿJJ#"Խ~ D<G=J[U,޿x?Z=OBMw^Cd/pǡF4N>.#NGE}JA7>{vvN 2!YS !T am,HNm_-PsȂi+dOK0 ׼<8[_bK,x1f SmG(@$iR3tXo@J;~Hx׹ȼKG rUxm=c^-kɊQSԵ[#yߚjφ~݈nwʘ"Nd,ٕfMo8;]X[(vө(|f?suO}bŞ[<*̠!:oUQ9( A?2e#x7|++b)R!T,Jo%(Lc@K 2Q, :پ:ųu[g⬕5 !e2m Y d{nt^J'k~ٓٳ$0'ќA7c"݆SI>"uCNܭ|2𿕮Yx2_{F";aΥ1i+D:?LGaHA)y~A="d,Fso,ܮԠ جy!b /z!I [lӢ4]ǎ* I! 8(rU7}y (m15$K5]$I;B0x@0e μL{M3,Xm7ip@iOI0dxFc.p6ofz@ebZUD@ fK$#q`I]|*s.~e>(HV})@@vcᇨu4JcO;=x &Ϙ: Q=5Z\1.RuH+KƧIѧ/QZB&* T/nG1r"lR@MwVNd# 3 ֱSF'MacŭS(J\4XhD5&mݗ׻ L Syʰ|;U[ߧBHe|PTtAjxg8b9:,RN[$t횢u-UWQPN,ar*$s\ J!S#<GKxpVkԘEbG%%\i[S| }&64F;x0j=IAM504okQ؏!^Q䭴#o5[h%-s?(VZ1˪g8000Q(`[~(da- w'ȵGх^Ök^s+P~xɈpdDژdH>6p8P-;L.әҀv8\"4GںT{XYP4@cNF{!?= CyNaxn#јYXoNiqDCVt/ӝEm\㄀/nc.scT`Xj9P [CkӼ:{*d񄲲Bdh[ AK ^nn8zJ R. 60 a!gtxrA#-6CS4 jK|g*(4RE#[GuN.cW2{5pB0ɑЁrW&vio@VHmND56ժy2qE \q~M"^moz!PXBM"n*C)l:'A _'WpRHQ.7pSY3ĴS WQ왆5v+93g?HTb((`(O__ԐҏNW= lŻ& qh ZoVNƄ)Aȍj֬4U~ћH(dƆڃDJ<\Ɖ֞(?Lf}f||īc*7b̐Br~Xoʽs@ߔzZ?{֥7Id!IGzy8]INRHQ[b?Kejr8^{e ' Q.O6eʄLV\3tk. 2=" uţ:sPÛm \S 6򗔍#(:D5ΛN\(ZihI0Ьw=8RZQ(̀P"Z<6AEz81 5!ңAB# eTU]g.=[;HXNA<7 E]p;D{g^露`uo3*`T )) NT߫9;j9>:'<:DzY?)JQ!"hc 폍Ro[SAlDzЬū(/e W/&i:A2(0Ko =5fR`gbCsq4|<1wJ<59¬۵g5?<6};^;;kr!oXҕ<ېatP~ UЖ #Hܜf Ly.t4TZU45>:֢4w_G~=KZH3qVt}[ZkLr{Wm_b3ɑY!!~7^V)sM)KJ|la8i! .cAwS1x8U5tvFQ 7*w4}4Nl!*U c K=O͐eeJ!od66gbE!!F)~]}&zgZ2]@/RŠBP3W5/$˦o;wo7=@cgIу|Ku{٬bc !P B~'&N폂;\<1WWi!VlIDhV/T6'!wS)g bk'F^y2I e%5佯=gWȠˆJZ;t NUn)WW]Ea:V_^!$$߼0WR^\z4#Ž>- 2WT= JÒm%u(uZ5+G%B@޽Va|Nw'0o]jvg$o{zZ&V*Շ D0ɥBÀݟdGI7ĉ~IY.}v#lj:-;pEŔ F[/,^ JX5y=B؋81 zT ۤI|瑀(;ojJ:q ި(kQ8Ô <( 9Ӡ=H8ٱ~Hm8;J0*WQ㳓8`4A2EmwS1tVh[Y+:3sE_`f#s܆nzޑ; O(*KLxb)Z 0βȨ Tzu@hJ;dHL. 6Tʢ `K]im?'\Zſp,SR|;2^Y}iiMUKІ"Ԩ5fGY(=+c IbbyvU04$(6|Ս X1Wfr?$A,QAl2g_-{csp4nz#.lqPwSN:+G7i|lW2u?w*mI_ y37 Ie;E|z[EZ/>OV$T9=7zY'#S3D Ѕ4&M=bQugQib?.o>{r4Hú/"L-&OKgbvP2o *Vc>Q|@8戴{C dOhHB̋{q - dq$2}2s]MͥkͫY?Y5бOs0.Կ>$Yqu; zNM-~t:^{{/$N[.J}=.}K 2 (dž8nl@>+"1cGR|SGQ p#\[||[r >*Tj$L?Cy%=d5#᤺ƇpS̎'W냃emoaX NӇM` l[ >D4vz\sJ*[hI]08>vt/=Ou㴳I0-<&?weBFsD7NF:6R&M֘Av(8LO]s]Ti#-(Sd}< v-߷*v囼 +y? uTr|bxcsbǭ"_u}KK;ƶ<@B@JX] 򜩓1c/E+@S%y))N6rcK^j.WQ2&d04IuJIg'SBG m'&";ZwmHt~?a=lӘPG@[5=fڭ p]VQ ?<e,>/bϒ%T=ՃDqXj PY/z'\g;%n < 1.q&B( ?@"oϊ\K< sT7U:Nu:%yC4åMl;Qf췽gyeӬ֟{2$/]8> WNB9d3#r% k2-;YLNb*4+3ƫN m𜒡;*fsz]X4atԒ"o xe4يGQ 3Mْ0DSA9AwǪ:V76# p36& :ިF*JMOC|@T Z6_vC@٘ɝZ#c%WU8SP n\ݞ6&il=x 1n2TUBWVu;ځ\&1/;c/0!+L~B1Ru|lzDr_lHm48NByc&,׈! E&}†` 2IM5L[؛8}tjoi+} *@gNf*ьK[X3ȯ9gf^aȓis5Q85i!y\+F<ΙÚ~O ])o3`l䍍@PnI>x(QS(/ *],^eEm_"H/e>ja W0"v#oHOVØoƹ|}hRv֓e<{8=7ІĭPjr>@y5jDF=eK|p?>_;yj ;Dؙ*;vm>"_%ֹDt0.N(g37Pq˫~qG V<;PŇgi 6fN~V6DqI'_L:A"H}ߊD%8vz{4~*ٙ:[(Fs'IYsE4Hp4ut9A%bӼs>L<^UGdρEfXAM{ԞsI0Y+hCDL(Տ9J6\|bryl"9i'4z-WnCZF7+FsOD%7>ĝ!p#]h%yj4Hx@<:+J*t TS0sZ7otms(~A6*]w n\m+0y# yN)1=Nޫ0~Gzfv5INqfJi R1"@*e[PG`*h#NS:j,gŦ,G"&Σfbt(Ʈ5 zDcD"3P澍 ƹo"Q\55ި y |Z Q*1!K?uHGHB7NђVGU./C(#%c<벢"2YӧR E]y=av'mqjU\9XFAn5CNdi72}kh 95!Dz](g O#oZg4ؔ8? 'èikXf!G_5Wvza-H߿`ofG|ϲC>@྄aB?jV + kqbVq̼!n'M7CPm+>47]n-$6Axo\xc8Fp>cL2ͮ^pJbE(E;J]SA#H 5mlދ;q62ͣ}ջXhCd饠)Fco W23*'c O? %|YIH˝ Ʌ!MͥfmzWSs/ȸDh8>%\ۧ/K6H΅Ok7kpa݊HT駕@&u-w&[=yjB|ò-ޢ :] hYrPVWR 7Q9OU}ډYxMs g3_$Y]mlAf-O3)VLOB T2{C**BYęR ؓANBQ=@Tgx:ܕ#an>!<6b )Ck2=XKXڂ< })*4V\idcaDhSݓX喢By& c !m6TzS 6u~@[:\K=T%k)̋[Q :!=WY &~)\)uٟvd],I$3ݲ9Z}JM^R}7MmvŪ%璀p|dAVcTZ  %rN;Q"Uz[L"{c)H2[=eՏ3BMT 3b<9҂SҁLbpD#ŶhevoWf"^s8tJey=)R9%\Kb"=ZP:8yO\D Z+=ϞDj>@%dor3#7|Quɉ{(ӓjB]?>&fˬv{b~bJ{-s!#+[篑GޠO=[l0":aQ\U$Xpץ"?䜯0nn"!o [?ZëVtI^$XC>TFvsi`D5܂ EpW6a(hwV1V U*Ξ'J_YPrJBv]qhGD M2-o"$ AAkW| jRsɖ:.аi[ tN>7wn 8|1rsN妈0?xfMvJ?=.s]H1 cKCzB/g`⋈nDJ`R-F'Ųj5"l"O 7-Ť*$tu:2n>PP9R[}}#l0&^->XBQ"w4GFq,Xa{>OF`,0s 3 {|Cd!83ދ q^@g%A$N wgp-x]]?@L1PFbeYA-JCF ~Chb Q&ln -OuA ɕ#SgSB 66o H! o,3l69W U'XŸGlH,(ܢ ' AX)llh3<͹Bvh2["$<4l*ρu;@!*>žC: u-rE^^0+bƍ. }_ߺx?xx> Ӕ vxrѦzYS?+Ya>(v42Gm,ߘ"A?PoRN uϢW.(ߓQN4 r!խ]P iEq3chVt{ w87,Z.6\6FUY+1q>}TGcJr?WNoz5\dlBS>@eYik ETpv)*[ӠR+ 6u"ɯ][ykV7&vP;55?WDR*FBy8Œf8{ԃ޹ 82qw43=j00 G Oʏ~*Rg'Vu}Ԝ2gFkZɡP,ى=@@]r9UFBHb0+]lb0ԉY[LdވݔWDo~I [HIg@6RNއ>Ovooa@vbhqT`k? 6p0vșTɁoujvk ].?ǜ:ߚ2*ٱ?L"#kEij& %1!AƝLe.pqkyw9nv[B]!|#7dd() 8ݖ+l.|n12+ PfG9Ys]iRE$/ZYƝ"ԞqFͪڿtx`aN [D:*d_&N&OQh܉mM}8[]:3 댭 \E+7ذVn$\0Ǯ z'{/$.2)5 Ā\1?NF9e3M~P3Uݘ ZƮдlZ*ֈP>bQF&dyt@w wm󞯆W'80x:/,@+$3ykȬ=<8\y߀.nzHh-)`*gb)>6m0|2 s?ӣN Fm[GI~k,d> o,I'$JJjq;/R .o]6J%f~10$_U\=x"4PW#|#*^S;fq0fK[vG$́ ,޸AfmJ6 BBUa cl\r0ܑؓ(/zd CUԟeaLB2Lڍ +:빗 Tx@m7^d7utLOw(TRZHLobk\ÔQ:ofue~d#Se)bQb"%>~@My,r l2Hz>9@R+ؠ"n`6u0xqLn_!)L ǝ5!VNk6yR-> "ݣMrn>vWU+5ݓʕ9S=cT*/ݘa~%D, K^LʛEOe `U2%M76(wi䑆z'ge>74IgJ>ogM&lK/]b7ʙS1/FB m+4&bHR‘:IJ2 $B ̀:Ih\O Lk)F=2yF4 =N //T$wRݍ~g#`ʨebQf")i1"~[F~hᵯAP{:*p uTr60\ TS'_cFN6>qsuӿͪ?~[S>( jzR sV&zOm0D> 7'`C} n&V|x.I1&MۋS_HԿ.{|LJ?zE%cjl?!OH Nس %Rdic~I0˚3MT UX+0踙6!{8ڭ'ݣ[a _3:o~qxbӬ"WYẑә#aЇWd ǡ/-)H[&ŧMIF-NǨ ? 3Aԡ`bs,x}lٌ (_r" UYʴ27R~6Pc/ z:<1OB-ʶUtu"3<ʥZ.K%I#p@K*b )b]UfoԺ4h RjON®uTXߞxZu֚P{M2.Ơ[ BIKf) G$"bҭMK0|{oHsz4sQ{gez e @G7V[ڕ_j8 :NK@K8%96"S]ZKzdc_[_rmj!~ x)?)yZt`U cutEVul@͚Dd P?eFK?'6U\:>I9`w +Xś_c-y [d9/2D~u;BoF'c.dУ^{dY|@7Wx\p?rˑjBvNW+" ,Uҵ+1IɪWToߝ^Tc Hd_~" yg2v!+n[,غ$-ߌ~&h]*J3+fFk䅏p<0&eBN4e-o%4aac+3- |DuDu; G_P20b"abc/(TĊIQĈk%O98 FVԁrזkQ?Tt@nWFZ)Fo0>9pBygƚ^o -VN%dX*QvY al'>;F*R!&#j xƲ% a¤Ҥإfsv^dNl!9Ń&V~x%qQ~+c(P-r>:xYWM T?e&5Ӫ^tWd!tRwLMMc߭z5.m9ZWGX}8=5FL@G+d!\!ee-Ԁxo4f&)7 JV3"YhK1n5QZgJ·ꥱUiY# o @ oÞz ۉNjyZ{B !FU~7:?kK&>}uf>F?Gv 7YCA8`t'H)p&][E4 xZ#u mC})P,:Ix-9#"4&>]Vwz1zyPY@b+ۺgMr:t4B>^x4y,07iNig_5uCA 1Gj T.J9gu =W[mͰvF'!&$g2]6Sm7LrT9Ħ Pv[US('@ %7/oJ/e dQǼӹKnifצ>ttU.&+A즁gvmA@ǑQz'0~h+zαýN} N8J.[V='JuP⭴dby>S]-в`>c}tLX&^/F {qkRxa]j\.us4<4yd^{צfqƉ_ݍ+sEޏۥeUeR+U`RwR  SZ6'\Uj_ 9rI~ذs7MV "7s<39` ڐ~̰JX -?yF:a9vh] $%~ڕ/T{pmo 2c;JW rGKu%wDOzлůdy- 6U]%//fv|>+TT|Pzo!PepZpHN|2ÀX(/aFwZL?1/{| @Gks\f~(q[3m6{H7QKѨW,Nwٯ jU} :`&Ǔ&Qs-P0&L֝czj "~_!'UxY徠 BdE42h, aI! \.7 kc;h:S%?/haZsSoy@;HY6EbcϢr>*j=4,ծhTbmu_N߱swOմ_7Nj7 A0In?ZDh "ܑ:kT0?&x>R%08hyq;Aj"?R{LXb XѦFfs qOf\97K})jTg> lL};b͊Ռ,8i%RI0? =3A6)6k/z '/8)m`\ bNehu'`3`#=z?#eʽ{ o*~khmRW4∃CǺ;}[GTua %Bf^I2%R޼?5DpǹFM }Z3׬Ozf9qQaa`?Gaa]R!ޕZ`ܓr? I7T> Yz8n/ cXD58e'4tjT0܉Ư6Zs)tMtlypiA1LtkT&e,sjC7U/X +|ncC˻@@+PDh`g;\:P(~]%'zZ`AA0fMEn˿&7i iS ٹFZ0d ޾/z]a";U8)ӎi2"\q to)n<GPeTٞ-:d ev_ R+j`aJ%3'\QB!7ʝlJ>WE [9ʫaq.pw/D}}:7ky AWe踾E\h/'CC$zmΈ7̉lq]W_iA #k_0VO?kZ]$i?:IҖ.W 0]yޯOR3wp_ܞf_P)]sIЯ>aT`wt"W0#Q8B*t`s >&j&?)la:Tݥ\NHq]@xA|ZUD-+ײO%Tq3U%ܒGxv~*ۤJK@O`fO68.u'Q̧uj`fyFNUbgA (Eڎ·9 ؾ>ǒХiu $t1MF5B9OZE_|霽xˆ/qIucd֐8̠Mo2$FI C^Cp,lq X&OlWxL~bZ$@y[#w^xԞnc'wxq| ,$ɇƙuVf]1 T,z EWegeY5 LD5ԥ /q*\xs{_yC[R$XuX<{grGӷ[k ;NqlvxEP_4Ce4?L8B)Z `JruË' @- 6%>5|$RȆNK8ufM68y6'b[>F)"FyIԎ\§`C̥buՕ% 4&G]oLR4ھ8j嫦BM܂c_ZYCɔꨉ0x˪"fTѐ6a]rnAxzdO8 rْ+m77Z;ے,yoL Iʨ*Nxm5L̄J%zN*d~0s1 +^yFʈ&%BD%'ds`Z͝mNϲ6Id'd4zZ؃PSԁSOC34+ωuu oO'#Sa?M|G=2AJ"m1 M(4;tK,#'*hCQ}LAMB$?EGYi׭-lxa99Oo@3Ve;#ϖGohh[{{l8.jW-Ë`LJHq^8n)_KH ^57l >= =63zפ@kfsUl2fx:t0z Q0n0 ) ?E>hTڤE[-E1$KbD t,yk-8o_ϭ[6X*C1M*OK4D&UI;~rf#!1B`zBe̙ 7Zl]pGLDBg:CM{2ͅR̂8vd I6:sn#kG9o(3t)m9JXfq?(n^`ɬc_v(oV/qD;eqnG\kp) {ya6V1#1t.g?AoNsP!ԆŔjceDw,ζy$$' `Kc[,EV϶}B{ҫQ2KGƫ*iU F cSbG3\ J"GTn#\J\G葤cyDd8pj dwR `;_d4W=Yj42JqwVܫﺲf&⤦rdUMXB2ˇQ?lMhZRp{jyE0bKKR ` DoL ვ'+0zH3bomSx:@>Uj[q 83Ju^}AcZEZ{>*۱gmьE e9E1_9߲=1 I_du,;c\M'E]/7sa=TfqpZ, { I<?( دЙ D͇#HD,#xm)_c*{4n:-JLI)D$Yg9DX]ks5B5oh{1xqj+)&O:r$²e9G4p@GkH&crK]6#YjiKœ_ M;C֪Pu6ī>y=XmSХNSp lYoyS; >&M=[@6 qV@~2 0Lm̓hSK,ΫcGJCbETih䧒R:/V'sٙ rX46 T {-Ao^ԝ]Z&z.ˈ`HB,]/Ej<2U ߵ~$ռiX[ĮkfuԿq?ͪ赗pb^7vWm\& Vʞ'pO[N)_Ll@&YT a؉JL$Фyy/,z#HQ$7A@ؚJreؽig=[uwTj*AD`_sm+K4 3;aLix(g Cϭ`]uHzCAX˅{:`O(L5fL.Նlx}IG%Lxvz-4avtݤ>.m1f*,zV k׶#M.ŅQ|]ף_L}۩@[fcB2JpD 'wZ2ѩ49-]aVtOlvF8T^LJSppt4h#`||i` 8ޡ⠦id1ĵU޾O+rQ{in6[j^D&X\i'iue 3q#zm>+K4[+Sh/Ƒ60NH aፗeSlcc%tps} 7(͡(b>N"z;[CDpސq]YY☫y~=g s,=Od/N9b@4/ T$\gS-eDcZhVPm1)P_Cۺ5,dvTX۶Md,/Ze5ЩS9%to:3>(p8uSPr-XMU q;j$2>TTW߳kC;q̀.,E'>>"e%9fȟ=t DҎfrT; A!>sz'kknޓ,n`gi R/ԡeH -99aPڐjApR"nYw~KI=W4,Sd)Y!)"#mgT^!P-q'fs)P!&C@D3f{q.ghNGpipЩSYpw ~-9b,l(?ng +2 iwmľuq܅եEO(г2L2y?2.YQ; Sd0|55A&2{ % ۔aKbGÐiW̝wS 57Z:%~nc%}8An!/Y]J/\g @wiUlH;|ݣr+&|'p۔܍r^0<](nTÌt|Iޗ2=\-]T^U Q ,TZ1Ljl5RkiO6Ȫ9>;oZ ?v9YF] GM`.nSn0!:*O`(^2*|:NpW~ -IE]++v9nJu\P/r X?UhįP QbV6ET yv(f{XPCzeAd\[PձTQ^27iH0epС),f-6jٌm1/ONgC&SoMi~%[iYfVT&Ezޝ=,:oPu#Qꯕ} ,bw/ i>cCa"}^4Yܔ438*}>;c>dᒗ.|ģ2 g VI!I\;zY]iT`4 `_"^~[2 ƕMFɽ>Te_ܒ43IMa`/e ga+}ÏᲰ0G9ۄjWD\ ʸ,54 uf;^mFm/sBR8b]>y[,Bt{xe%oo5]kSѕG1uO)>aȮTY*:z*PKXG}&Ąɩk;J֛{A1I;wG$ͥ,_0bPLPwB?ܑZzooLg'Ì/@ 7iat8E)RS:z ғjOS % 1(|N=lr|lkjKQmpXfX}e?tY7KjP+D,Ⱦyd}.|~8뫤L \:ѽ-ϭLɳ&գ[@^H`p6"cV62_"lZ3[cZ3Nj0૳L$dAN~YQT*hlnYMI`_&ϓBK}&)'V0sc,\diJPtL /?heJSBF E8?i(->MڧUbFnIoOa\w!kkWQ `rf45miM!ffa ^fn5j9>QWG^tN&{ b6m$o5w6\1yҴ/Df6􆮝!a6/n~bDiM9>o1QySr3tPl]G. VrFm.5"hwjWe92"+\cZxaI -HF6O4F$ɰG mYl1qp5@NF&<`GW1X%&dae&%Y% lhp 1DW, YYbUgzS2+ mX^1w A,g|?"rc3a0d *-YUBO@q(]{BKr`7T &Ծ1-MXx 7B[fuIq=2s~`EIdarQFN B'{0c,jIbRq iQQ&U\#NCI";u.o[vXW aJSQ/ 1*U-v\IP^WsA^A|2 L.z=P*CG]iiZW/za>H^0ʤsb `!B-V]O|(x}z;\>=onNקm?B`Qۃ֯qY~ o91LE vjwNl08"57d\q:,Ot<<_G0NQ .TrxqF~4N/sNQd[4AR|^e.-ug(Rz 93|ÇK[=+4J;dV,L#fhDA}. 2}Mt>- nH&WQEr@jgl)fpNkjecQF(#&6r;R>Ь֛e +U莉Fe1[X^ Ӓ aPe)^2HK6@f?Ћ-T^ޅDJs"EoN50ǫnc s,F%,!#nr#[}[gwD ;g 嫯lX&e}Z 7܍ B槷|$Z#$7[ƶg6 5 «dtkOY\''a#ן5057z/QY\#B&MvNVdD*d~%lck#/D x#,ƫZ/lo,G ِoYF8dt3T0Cauj(˪bo[9JcS ދvF1t8:BlfXNbhfò0ŨҼ37[<)xlIpVt:H(O.GG{0ICz~ԇCAlnnjutldzk8|pwb3>!Q0707010000000d000081a400000000000000000000000166213bb6000051c9000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz{sǕ'?>Ez $EI{uB"-1" C(t5ᮆ$nH РWoYYoĺ Wh|瑙' $ m& #+'wKQgwXim8Ǘ; XFo[SwNo[xx]?R/lEd1Ztұx~Fx>୤<|F~KdZ#IFx)]huSZYSܩf qG`ӯ=~睸7"Wuo~vR"Zցzָ_l-j`=UKfqT=?rnW^=+?o.qP Y,6Fۭ9u?RF2׉|kCZ8mxg+.\&'&/L\~v\T;^`MG/[?\QXbo]ދǭ[x0:_o'U1!{_WVz[ PK0buz@=>ifx'7դ\6Ջ77DjX}54v LϽ |mhNE 㨷L6ԗ(@~zIo׾Z6|x#wMF]aP3wR޷<~}ެ:({zi!S=>gmv+=x:?dh6+v5|rч6_>) î6fyygOR@,MBM6LQ7DM^Mhb[\@+ꡰf8ECpTppsԇ7;w@TBVSۅ6Wآr'bxD'Oc:ި}ڤû.Q1m'j7HՋ8\x@d~ڀ3῞C88]8B5.*j`P׺42uiR] s-D?|HGtQugI{6iRsg%Qjwhj@qd?X^mh*YZ4q&Rz:9p1Ń\. Gmgt#x^rx戛WmбKe&%)5<fo o阫hN.%Br WKf=T#O17# ^IPur"jvGaa)2̈$a-lvM8T &7 rQo->x_R9Ll7zxmz +bz S~N.  0 &o]G0?{ɝj^d-CFq0Q3Tx,T5…ͬ!VG,l$=m`?"d9*9Ά}୤s(AFZ8k3O"ZӱfYжFGmk2P'#eѹJ| T ٮL6~KC|s;A(%3~|Ӄ_ݽpյf%7 ΁yI=pwZQQٛ;AdU-2Q3Lk!vqxӚKpU𓫥rkp0H V^x׋js TMxj 3KZ~=CWI蝯[%E1C-z(۲V9fk!^'ccOs5ꢷfYIJy%.6K\62#?}6⾺jpþKU\7 x'|vfQ9hԀh6'r LXSW[(@E-7J\c$.+Uh^ˊ% CE/M. `́S\Ԍ|mTsn"xiޜ^~7d  ;\ag?/s .B q9_Ek0:~e4p۴ͺ]o:,tE;nOt 3VmBOm Eq/"N@_mOi)2?qҨs)*x[o3,Z3ߖH[<钕Y~Cv#c=*7qwR,.S5/i7o=e󅮾ZµV|~mjA1"q]>lM  NKEҜFֱxs}ԏJ0w:hF+7I#wqi{fR|8zFϷ"W@}>8[dKmGwfx?ë``zW=ew::{X"Ŗ܄鿛NL/{ӵgE~)c?wP;M!ms $W?jbT`sӯM 3FrM":"@C e`+p}v?wׁay 0`/z1'Rsyτrw.Ur7cN"^| s47yZ 7*1``:+q)#2J^^Y"kC Jr]P_ߺt޸xeR[q*54 v*m4DQOR܎;I-4KԚY]8OfćF#7[$QՀ*uiZpft*Qj냤>k7jYzrz, _|NҎZ&O|&5y5vw:r'IjpVjp/$;jjT =:7LEW,e`1hsYGYۯϕ wQˌz}zƍ.(^\BR7yy* ,z3^3q_r4iX//+A#lo 6.h'mTv2Jn7\d--am0RfE[̰pJ$ܴ3LQbDfK;߲rT7xbB*M-jJ7 xH)PgkZ9Q*N}M{vc46 >WҮ}Ii͟G|P?~y<& k5[<CFz='E'k0&,}0L`ij!{B+4c%nCӍدVq U[%&Ʋ JS0vd'v-9n"4oGLhmEzY"Bݪ{ș5:{=7o7\ʏ3Ed ;!ޔF96 i2꒨QnЌLB B]~-iI2+A`tE->Sw$d\iFl";,;5zLO]Q0Y! 'sׇ(fmZ3I2q#(ͅK&8cnZ.YOcv z ͈pD*9!?KV| #$bAٍj4ÃՀ"dk(5qitnKWٲAV6f&7H leF㦫cy*z?۠XD7,N~1oYQUT~@x$[XRdž 5c6؀  b| R7T4we7 inHAkX71Ѻ FtSqF< :83{fy.3*0a!CCGf:$Ĵ ]@] ރ`QEXۣ۸"֑0F J?ߑ?~=nCx*x_-GIDFO?:XW&.LNFo^Gk*Ê9`pnьjv9dn_p@h4,MъtC/rq0*W F{O4[+v& ݆uM|Lhx-l( yo VhYgXۥ#8#QYFFJ ?0tB\<^jgԟ^U>}ܹWe_>=XHu3ypvG,:vԍ#elǬ۴eJ6haG r}5-}[cH$Z5 ;}EaD]Ϻ+HFؖx0uhQn NR+hz&]̑wXږ1 h;=5yM!4a{W}#>ʔC܂4B9*|L9B!"!}tQ&ikhC0>zF>8qVq?9Z2ܭXY0uQ=,&+sWǵz3_oJ:| ~`aqXL/߹z:7Hs_;[{5aV%JZ88R,@RgOIJAV3 K"}%`̅w|F!0jQ_?x&{Ve]OcƲCD f3=2B=it[譄Dq(njfFf܉!$8;CaU[ nQGJ_*B7L; s~ jɌquټF`MZŨamsܚ6"\2;ϯovO!&=cZPDK|y @erXQꉘd^.JN807vLTK\ԗy9<ҕ3a $>>jiD+2 R`8fHGe,筫WƸD1P4۵V݄~s:M8d3feM6(1wc`[3g%€U0^ .=iB4ۼzJ" Cq]ꖌ㬑^md#r'bQLؾR/s4rxA[g~H%iQ6bD"嶘DL3@"{e]5=;zq0=i=BsgϨ^~y@uluF1@6=x!5_GBj8Te=MsDQBJ3U 39X&ְŕBaZ0q//HA-^XHuS3مY8fإk>ωSDmL:M.]Xݓp2Y,]fa[sq@ g 8~:R)C63q񭷧fOL\??su S4Dq|iq-z |LV^6\%^*wG&ĕK3oyarr`\}up=uf,jѻiN=4f3P$MF^)Hͥ_hEX=R\cU(`ܺL9(@>6#T>?pV #qU9qUWLѢ Ie OQLsvޜxH2Xa$LQՠ =7LL)x'hoQ>= aYAF'wCҶoocDpqH|3T9b`$#Pwu*6SC}r`D|}XJڋJRٗ S87 =tV u1$Q4G`~澉Q3TCe4*=QSn l?ֺ `5+f8Zפ7ɛkl %021:M=Neez 43\!V~jCyT< "wzz@E`3{?+>V"xQ½(> y3 &Klj&c&6CI :K"¿V!S_s 9Pq({Ҕju L07Zߜ₁ⲕ8TR-2qylU~p G6CtXgb&csך[-8;cH{2I8f"Lj.\A~DG!Ώ:597N<;86T߈(kXppROCS h4ZNI^S/$WY@ex5׀jJt4T F.NҤZ} G]KS1G8;r5y[/ PN?'}$/l@P"|_$2O=ƲQ3vװ] Mmd#=ڍ.͸ѡ zU YEŏ`(HWDزa]:phkuw&]ρM+sw DЎ) N'Tar+eJCm3  @Che7y#:}DlA*Ҥoʢ76XDmEj}P=‰3`0lAkJ\$Ⱦ,XhQ3S{r>"ovvLPlqʕ8X3G.mԚo5' 0$ ibEb"-B$1vϾ -yoT@ymy">ȩxˊt%Q=%8>J'1 Kf= *ʠ+3.,6^ק\.TWM[Yr_Hg(2G.^DP!(! `x'/̓3;,X=Ahh$]{&+Xs!uib+f6Gj o, Z Zj ^$8M8Yqư6!Y {}q^3yȪG]ďaq9fq>.~纡 PPFFqD[%g{N,[7 Vo!At4 p 06n<[.|M2[ѥzs#drաLK4Qd >'8؜(2o),$?~q_ GAR;>c[B-p\4sEr_=F"2h6ܖ b| fTr7[EV%;?Rj9U52B6M}f^U󌠱l]~Ok'`e^(˅<ܒfZw.r:0'G:HbT;}"NO`ki'YM/+j)~PKP3/˿풫e-6zBيy"xW6Yc8^rH¦8qpƌ#=1 Uz#!7v PvUD+Ķ\W{}%yWIdž++=2Zzɪ-aaċ܂~b8֮l%YjJr^iGbhw~s .~ 5#X%uGAzǯe [<1y**˿fq@@~m`?Kw1.ԛ ZΌ.2'2ygN$ i%m q3?p?=J{4cS(GU{(OżiHY'0=(^4o)+f7=WtƨYtMR^S4[oefaܘi-u#5\M["b#ܼ͢m*1Lc'8ק20t?'5WD6ǹ߲-6?SF%Cc:64`r2D4gSĔ 閨>M̋NBZ`;nQt]},½`JbUJˣcϼaZe>}R/9%ajν@e bx<h^X_vWuc=7~)OEt eg0#l*M6!YA3ً+mr>3{,'~??11BRO6'Tjs&d[=Ktu˝Ak7tp ;GMO^ykrrEm?闦'^֕]z0ۋ)‘#BTԽb5pӂ)9ѡ¥{Ykc]Zh:3,8oB:VKߌ=SG!]' [$S7P)DʍҲJ0$98ixm`:7^3 Ƽ <:޹[]@Y6 P۫5tCMlZpS3:L:bnp]s~Kь dxl%*,nK[_v3\hjվVޗQ=%#>}V!۟#4~F}z R_Ϸ[R_z6ߧ&FD5hty WHI玱ݨ`FZcx48ڕQ6hCg}ZebKv4j?z-Wze/ղJc}O}CCؚ n6!kocG[@<0!7~P+(t땫o±Cgv+5;%}ȊЁVg~Dr^ ǘxջ_7pgb;uy{EfPv X׏Yao8()&V3B?a4LƐ*OEDݧ`BkQ8G`A@41T]mT[H hYE+~wDŽ;T OjfJ;T:PʼnWb6,7LN9?H>HD=.X\isy"*t5\oc\# >UPx&]vYkW)U^!&l#7ƛt<-kuU-Ҳ1CB&yalkt}ūmb$tDVX OkҶTϛ@Koj[ڄY 6u"[6S&0V36Z"mjKp6YVDGm*GH?N+uw#Y3]mx>bz,}VW>8׭{ q紃M}Rtn*C]-IJcm#| %kt>:^ |O@BHSWTI:Ց۳ԾT[͹2 o:Fajj+o9=fAjW6v6>ok'FO C]GPqޫ]wWȪTHl;h^6y+);L[ÌpN]v@_<^9 ȁb 1)u,~J)o*SߡH{u3R%/wn`akxSJQx؊ ukٕ/`V"]]cC̯GJA3?g|o's$] |q1CrtNc41$G v Jx7+h6Q/?:;:G.{N> 7X˃Y3rP󶅇CRSN{Ġ~KOELK).} a337ѵy BAʨvEBO0*f4WF+GA zKpG +{!PڙYZ< '{qx^E\oB@vxC#&$2e cJ< D$ wVL3sbqmznb`)nNj 11fϵڸje@ Zi_vōki_0d'i\+ISS=tKu+^^f(ԛWEg+&VPgD4ԓ̴qn$GKr'\C/{0J^ö{Fgܘ1sLtYmMAoC(p=:4h墾.h6[Mz-U%6rs& X"MHM9Y]9QZ^\Jhta (R ~ !lːs$&He >:g3F7:s=X5lM'/IgOi!c{T\&OfwL;:-#߈(' P7 R`mJY6 c+TcyNJʪ9_[`*yMNB>m`C̲ρ '4gx8X-5< 2g<`]j$:'lrvr,Jn HT4TF3\64dm M*6D%gIaum1($W+ҊT[Exr`sgE~ (,,2?[ɞ'Syy3;'H2![Ǐ ]/*e16s3Kaϔˋ?ƹa4z?y[|a}_6[`4wbBQ2 y2ĝ1Ju l˔8Msq ޶)S薰j f)cJ(uyΩߐ 4!`IGj{{l#]^ZbX1k(#mPp(:WYs=5}(ɔԣNJ[6Q&qmAN [(N!f 0F pi/"c|.(X\^ZqRO2E֍>jYư< 'KֿD08nG,g76zA I@,'T X[-LnP#'+`Ȫbg#}S,VY^ FkY%> ax@ DŽy1Ia!^%sζ1=}IE_H}*as/oFč:z^c @>,%cʧa7@C8@oZ]Hc5(Ըθjč}|f* ,-zI1`xBOk'sJkz=䣥z[.|?A~3O3Nߑ/R ]O}eb;_I\El)O(n$>=N|GU6K<G o5ԔcN(/NrfSF?K6zkC*iyMjf^Q]y{H q&OA-4K{/Մ6qa;]}]d~S l=0OƯp1 dq쐌Sm>v!-|4b|he-qs?@Z HV/;yD"n<&$|aAai*f<gt?8O70 i CT5d4hݷ"nl+toOZ^F0Hַs9)CUsH`BaVzj4f1A^,9+c+#T}wjNVWxršxeÐ=$_ωj Y.kǰYIt*ySsMl \djP.E$ ;'n2.yw6 еFA|D#\}i]'EgO2 Hwwğ\-\R:sX8jԡ=$w ALf8JL9(6ݚùܥ]&xݟ|4),?TSl&{ƒ+8 //vMKF|~jM}^ Ga۹^(%РweT4ZyMQ:IJ4W%<`d8dAA6H}L7pt*rFc]%9'E1{7(6//se& gٷB|} 7e Ȫ5{?=A^ȏD\p( a s=Tm(Jsim`{4\a2Fd0kX @FQI is2L;H m>@Bd# U[1zm|{ERlL&D`ar)+9MOW${r[KTӜ|k7[A~L4Tyl?6AjH @t*w1&}y^q4.K*Q.+|agӥ :bϩOɫ! \J )+Q-b#_W*Ntt}RYLQ$cXT>%_MԱK+挵r՚8-{80Z[gs+VbY)GڮH\ L<)L0֜Q$mRG_`X[ZkU㇮-J6)ϝg<$jz>V{e-$[5WTfKG0u0ӫNHĖ9ĎgF;&ۯ\LbZY+ɰ;E>OU+񷹏svAmY7䠹^YBc7fm6.bg䕴.'}5\D[QN©BoP"fR~ Ը2SMKI;T?1i&m0MPm0NM6PqЇ抡Ql@iGH! ][$#k->_~i0jhd;z< Nn~y 0nC+',sAVF^t\DWd!̩TV!! etbfE\fP -[fen`[A!9SUVS ξTq*^ȜB?X-fugS]'놖IXPu_y3V7 +/lWϠ9ΕS?ࣷ#>tT}-[N+Eط| }OQ^`Bdz =\_+pS419jpkJ- YΆ3 t.ɠn(/L2VIk/rTlv`,Qqhs<3=̹X~ @6y+6B6sR1$l FOWƧjZ&TXu*e[VD .2%&`l߂z%q7N4P2;WTχ>cX hvcD;"xd\IȠ@Z N-].WVNE#1rQ\iq({xLM:2dMw8/Ld&?Xr'h%/ gxhߜmmdrdeZ֏KI +-߱ Պgi25y|=ٸ`ɸ(RN&(hH"8 C;jfv"Dn/ ~T!mq%x~۱}" iƍ'B+p~&5,Q=dĻG(I~KchE (>ji-E͹1;gg"SЩOՒp 72iFt޲^Sբv8k,Ѝ +{*7[ȳ5=}N0ʵoMzr"{9߇r[!Nf,d>d-E@gLCREs"+%qעn&̙ Eg\Nva1Y{iDYXf1~wzn[?!~`{tum3LfU,2ࣧEg@[2df#'&-~'s.8=,I 3ٻ-4 &f۳foÄ(=V&u:X记x_87l2#M\7JJ@V ĠZS0hLD9׷R3E_X,WgI3Tuk"iue_= -0*잮T5LŸf!M/)@>  f`_QnD=⷟ϨU} } NH8w$ÆLk"ϚSl9각N`!%m؃[myQWbqTxrˣ  j;י Pd[}3-XDT`SNt:Ýv~kfk8]\#NgIym=pj)~~_H"-@!:$cdf"Z Xq7=X8F6zaP ͛XnS;w@0.d*2̮:9jz7]+K|fCPDa[/30QNBԫG}L`]y簻qW@ Y}+;>V&vUQYQY?%9"G:Hl`t}8Q@aN^?G~\xvCwéƖkd DOc+9ņi,ުiwg5DκBwHw:|C~¸oX8|c- <nJܖτTn,Zv gM2.:r'j5X9N_6 xPçM9 Ν={+g_>{צϾ"w_h֊j]DǰvF1'ԃ v`"S># 6bڳJ&Z2/7:WV0,ҚQptϡ`6thϡvJ߾s9",|6Y~J.r;"'![I˼K_^&.cZH56X_tpy\]TMDbQgKx CΖeJ+Y_|urm3Ň36_bwVvk`J *akhk8ao,Y</ozyܰRT+q[)xu}|+cLIr1y~ƧB3V唻|RƗ; J\:!c!KN[Fdgc%%7,op-s{S 8} |WV&3pܾ3MT:-qS'{:Ne7|cLכmWੈ6,X?ԸmkED W~kxlEY8_gK|;P6;#[NgS!dșIxׯnQE}Oq0avGy0;O=)5CԾ8Ӑ*I] 9,eUUuݚtZe=M'zq~jpejbGe@גÈw/]ߝzũ"2?^t>ƥ+oą+|߆.\+C%_% ƻ/M]l1T{cFϴ%U^ucTv^RkK$yI> b3l9t83͹~O{>g]HNRЧRy+3>  k3KZ&@((_V4^.,řGSתyrv}'z>C2mHK”T yȕ T;QbyxnW΀!,mtZmzoH Ʈ[{M_\PԫV4diqۻ]3#1 wj6n?+עO'I8RoX3;Ƙ?vS$h!2CGqLON6: $L3gG_x ,BI;E APGϔ!ZseqDTp,s+7͒.T\مpFW%→7GKq@00pkqӮ.w9{/5z#tʼ\V\9~)N_%䃤њ[N!罞&o3 ٵ3KzV Ǖ/IZd4HTqyOɃX՗xTE5oݜki'Y$r!MrZd3FV'g20Q. R:62C8SMwG#Ϻ|eLI#QQvH\#q3OFJ: T]05'هs?s;&2T;t=C{ylf5i\M>ێF3gΞ}Sqm$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!%PӤthvH^\<'hI7IIK ̓9H YZ