sssd-common-pac-debuginfo-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f7 ]mtZ`Pkp1V!p(8MV ]Y7]zQŒg3H8z$a͆+CF2h&`Xŗj]75 fqTeu 0̩NkR+P ٬T OG~~/Lb,D;lDs.qC'Z{?LhS'+(9;sLAu7si8;{W +cre JoX^%ȉ/82=Ս(CI#5]lg$6[w׬{Iɜad)=B-=\㿼֢S\?0rdT$~;2}g3SJ$d1414113f9f8d8116d33b8b0227c40f09ed03af3497ebcb9dd231fa78c375d636b09dd2d6114e1853272fc33fbe8adbea80a35613!pQp)Tξ7]mtZ`f7 ]mtZ`V=#;BJC(vŵg}m=TAid{Z`1-+"c,n+Kw: ‰XGLiP.lo~+l ;K1m!Dz吜X;DD\繕\ w{4<OX-}3˒Y=?2plb[p.Ry^ƻ:w5fQ?:؀R$8۱q0#s׺u7QNq\u(Uƕʓ/I 9o~#wg5vvґyNiE}q}%_DV`*'F $?heL1(@NB{_-8ӈ!eSvQ~|Nl7N8+jMR XF57};# p>d?T  ) W @DIOV t         i   ( U  ,(89 :_~G H, IP X\Yh\ ] ^rbd@eEfHlJtd u vw x yPsssd-common-pac-debuginfo2.9.44.el8_10Debug information for package sssd-common-pacThis package provides debug information for package sssd-common-pac. Debug information is useful when developing applications that use this package or when debugging this package.f3ord1-prod-a64build004.svc.aws.rockylinux.org xKojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxaarch64<S xAAAAAA큤f)f/f/f/f/ffff52da11c3d8b734898a110d3ef4cf0389bb53ee26064964b713c6ea4e4ee4695c../../../.build-id/9c/c548daf1f03488d6ac3de71fcc218240e0ad40../../../../../usr/lib/debug/usr/libexec/sssd/sssd_pac-2.9.4-4.el8_10.aarch64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmdebuginfo(build-id)sssd-common-pac-debuginfosssd-common-pac-debuginfo(aarch-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(aarch-64)3.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) 9cc548daf1f03488d6ac3de71fcc218240e0ad402.9.4-4.el8_102.9.4-4.el8_10debug.build-id9cc548daf1f03488d6ac3de71fcc218240e0ad40c548daf1f03488d6ac3de71fcc218240e0ad40.debugusrlibexecsssdsssd_pac-2.9.4-4.el8_10.aarch64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/9c//usr/lib/debug/usr//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.7.0, BuildID[sha1]=9cc548daf1f03488d6ac3de71fcc218240e0ad40, with debug_info, not strippedPsssd-debugsource(aarch-64)2.9.4-4.el8_10utf-84a2de5123f5f9c7f5a41fc998e8478bf736585e9cbce53ddcc38e889a727a70a? 7zXZ !#,L] b2u jӫ`(y0DiiEၲ&n&`t&!V8ԍ$LP-ameOV zn1bb"lt,uYn -xfE^_/[_|?B^ZzRaKqIQ`'o+b@X4=݄j"VzfUoCD V॓K ݇UX]Q=[#K<#]} ~$H/_5%GL!2-/Lm:EnԽ7ƕn7ݦ,]]3V$DR,6)8] %/}D*HRTY{VHثUB촌|0L֨cjc(2G'jԕN_#/XRT_03i:~}(nw%Nn 4 77mhe%"X qn:7L?ڹvPtkydBw^:#XdGy(]_s+dhrvx_F5@OhOW̱Z!,i?mg+mj"ҍ7 9,Qv-vέ?o٩mAG+O:ѾX.eF1CL™%>- s[*^*aZ:?iG"cPT} zi]"bYVZX3}~ >;rSiWFe>j)8}Iȟf>ְeQ؏lmj66\NԬU:pX!Lw^ /I8ԉj/`flS 9i7j(0ctUqQ2Ӄ%+곸lJTeS)09.QsS}}*AhDs~l  PiZZ8k}Sd~Nٮ|b{DM "%{עx&%c$ u&6:ކXKӔ7n$6KG2pr$|2uh!*FiNJQ>T5c5$wmL#M9rH Lj m-du vx3BF|BSUoVD>awŞJ [-ZP{ûBX2F#+'6QxgU>{l34}g"ĠRQEUMGs.ud'w; m-=vĈ( ^\gE1)_b߷\4YYgdBRcwA;= {*n aP#+KvØs(IEF{xX }>'WJcZ.f'A"d>˸W$DnDfdobڅWf)U JᗹY_ݜ(&zt`{593A; m:fߏ ./zx-56L,$ &2`kv X1:bnv O•Qp8|q4'EK8C{DU`@81%HJF`Z.ZWR)=>?PWx}CyTw4 W|)$kR7d\;wEEDPU1gdvܭm ȊQ #5u(coGzʢ+,(ٯ6 rɌy4a8 Zભt&6rZ8)pՋkLWyI,)s({#ZظѥSG[XlWW}EGU@Ԯ8f#H8A4plqly-Ȇkz|w.yrCT$ 4*1gՈRګvdjfދGHi|_̝`6Ȕ {wr֢zxMRN.':=<4" (FRVicStJl@ =W.L O0.u*iȋ~@w;9p;c?;KM+π~@mp6l?> \fe18Ω邈N[ C4 ;-1X:^[ldHjIf& tA3–Pi[ñ S2*h7,EOR)J7}Ӥh!$,ji7x 1iI,35O6n8voBf8m 5;0,TV@KuQX[zcnx B)#)kw9э;x>6efpQfcPߠB/g?&*sɞRݠG<8"k`"ςI*`oOQpȤjAJ"~ PhXw: @$.@>n0}d5̉Bખ$+K>ԬDLH򶗳<(s|DQ @eL>+JY.LJ4ذ0=J/dNO& )z{[> a?KڒxY0& HT-m8ZZt'”@BlElȩ OƟ5]}{\rJc mq n_+?e_C#){[heC[zc(t_ 봫9~zXqc}z/o0 - {'ӶK'#k >{UJ$ 2h)r*&ڎh<hچ~xd֭+l V+,s?[7/ %%2Hj*JgĿ؝Z,hUCRz"øUiV+ &˙f| 3ЗC,?)=C`)MFt8hρr-Mca#2OV+Ӭx%P% 0zVduUf_.CtJV5 E6npevo](Jygb(!ٹ]LE( GDF1FeL iwFw1A~ϓ~1))w͂Ɨ;>Ʋ r nELeFWIcV-!vPɽv$R JBSqa;&dAB|> fk%@C2]U7]+cvq .5@bZq۝DqfG/dċ=dx5ׇi߬(@]rExqƃ@#X@څ)EUv ;sMcxk.bmzp+pЗ"!g͍0 ,F6\sc-c+O\W2cGDy8' /UFIr^ѫvW mBuTVt5 Z#@[, 5ղcwX~̱@ ,{XT4~GZx|o_b9!;5N1f ,bظq>-=1ZX5,Sr z]v`Q]"|0_,h%S&HALǝ6^غTA%7ocU<|TT1 40'bY7gЈCv9k:=[HuKn{th,cO\)g6.\3=VgDc &,[ +bX>5a,_Zc fk)wQԑRT/c,ѢqN,z~9s4w%I@VjD 1}Jjokgdei+1.;~m旹XqRWk {H+cg:Ƈ˶]֘%S;L; q:haՔwZ&>ͧZTkev T"3k#2zcxZ1_:EF3ߧ[I싳dfd*q`WzHQ1wϞl_FM*Urtu) s$$^'6O/&|B&SsƼ^XvJ4a:$mI&@t[ܔ` PX|( WE5E[dKY*jξEI /*Ve#}gؕM`ok-(MYvџg()NpWDF#M`-Vy+(M-ˢ.Y?s WH4*]k 'nE>zelooPЯbR7pfZ<}qk쮌h:|MUϽnBSec3bDZS#d΃"`iX?iC=G6%;掿^s,T1(e.Xsw*cG[[1?Л8MF(Bv / _>XxL&g7z(Nxfb4кH 7 BKs4[hWI߅'᪘ˁYwnɏ}\pu * 0!L#J.;vOx8*b$=o.4?( [ k?g=D-rbi @ô]k|+$̖E -tŬ<G9z4AolGH%퀔 bÞϧ3R߭e̎x݂kHhNCƪL$|C'Ž(R~7dO@c7#Q^1C;7FT kF 6f<$8_Pqj_?FFӸ4]jV֋T8.C8], (uBN' o*&jmk̨wΙ}9񒅬Pߐ|y?wYZK8]Ex" 6oyRؘuC[:NlCS#] ז% V(6Z?pU]@}X)]0V M 9E3V!2)U6A^CPrdSi @[8`h+>6n&%Ab1CydZ3ɳZ&~H$)׵ۂ@ΐ'k&Y/ `a\/j@N}vOgPA80߇\e86N6VL>!~QP:W!cQKx !BqN5j(j["[g GӁD+((AaSGB {d.1 %E,kϽ^LY)riz}FS9l]L=fhCvmEfiP p#,ZOhZKaU5Y.b IPN9q.QTZ&" C L;I@B^ RK# ظ'z)I%GDrOh=_'.ӭu;d%XI})t T򛜜ʪJs}$#=HYÐڞڂg,]j%T-T]wvS/Bމ."Jk/fo)W|/vy[Kz.8H˃/e@y;mf^Xҽ$5s?_O7ܞi1`xoyy4%@hjPDjh}Yjtb/Ǿ {?Ғll%oA$Q{m{gB $E#FWs;[>1g=&SNlhPmQ>ᰇTuފS ('AրܹuKjrePQx` ͊J8VݟjJYd*D/4,fhI\^(+!͛;O䃛IU*ڂ8~LH86/ TT{%zp9MZ~>ZkXNEKҿyě{8YZ4Yq.?;8\&T,4hT%4{ƪq[h`JaM5!Ԯ&})U<͔( }c=q9ע4'@a\oF~CjlYMx.4=W/`YC¸6ѡ{ (܁.t1Źo&-.-簼d' 5M(y[@Z` 2~ڪPMxo%8?#*8ߦ+{_{i چ1"/e51XBv&N8mg̓? ԣu؈!.9 1< 6g@6s(}9Ч$Ԟ45I܍jf0L<;Յ:NźG{yT:UxV]Zġ~1{@iQ~ _Av5DChܼ\҄QQx #&7;25GeJyӏ4i~_m~})*c6%.+ްXk71 .+Makv릮Ts,/p/ |U腚_) KCqR葐,G fgsר?8=H`uD[l=`z('787SS Ң A$FV:7Z{7/{ B_r\Iy5\b6Tl0y}GNԕ6L6iI,o^OZ(ۋ- 0EOdS=bXq4x˗G2)hB0Vw3S⥟LGkQ>)bDm;tblbpKhW(ÜT~;W0r#̍kY{K&[(c窪"ί׸-pPpP>kMoKUM'ڙ1Zm{9qfaV5[etkL<\7'$Euh䒴)VNodH=6 ~5[ɩ[TB@+l޻:+DG Q|o\zMhL#=/U뽘&5UzcNqHvA[ kƃ O u~Q=$FF| X4gt.Ɲk8Ry GUs%c ~8U{hșՠJmAɭϵ$67̕aW/t]ΨU9xjoˤCETF4|?l!|1s<QM'6`BDqO ,,ّ'?ْbmQA 0|;d^B^ 1}6AF u"բ6;m>:tvN|!SiYaVe=KH\۠ߖ<-ĸEDgcÛ\km̀a67"ڹ g+8@Ab|RƥLԺ*ϛ]pHj*eNRic#yc07\{}ʓD<ˡL k| k/Y&5f@"~Y~Sk!0?,HjCb29XˮqAM{#Waċ@cbN\Ou q6ڶxf{b)gvlCՀ :BoBlq% Œ5BG IGC }[-lw n{blNTK!63{Fׂ2}%y8`t% |pxl4#q$#ۏ~p}n`c=Pq pDKwaR]2ZSY`C(<΍&^Wc*{[` DU3ͲN*As?ncdIf1Y(`z%k71kׅv;L@b 髝ssaL []ˈݏ%KX=3g:>:}S#JpB>ܔ@ QܻJY ckvasZ=aD%7ړ9b:3@FXФ@k͍l-$! vk^ny٧~}%$4zTIdy՘BN ?fpZG'>P !s oZw:; KdSCBmՀc\{jENhw!N;?o5 %,Z>p٦;~>%B['z;yʲ:Ą G> 桤gOFP@nOC*}~n8^(19K ϑ6E .d? uZYA|P9ȶ;TJAN9KFPVLqfI[-fF" 9勚{d_?dÌ\)u|\EH"}-Ռsj HRA'AEG/Wa楆]g0~RA Ƶfgfx,Vy Fo䅨pz]ڋfh4]0Q!>رܠhcwyes/0Gr S*$ASW?h9'+}`rq ~tԛ,G ж4h^P\8azB3-Xh֊C)y0 ,V"XMxܰk98EC O9sXɝZӽЀP}-UAF9W= g\鮵%_YS@Hh)毡x…&EmWV)U kS,+R&# ͈^n#i`c nļ3=4}MmрJ{PX<`Eh%ay SO $7E0 [y4'Ve )Jwհdr^Ac25BХ#qG(%G,EQ_,6ϗ#o>ԨClm 42gfP{0A@ǚB ksQ ۲k/fe(ʯ^.h݂>'e;c&!$ SLrIbO .8(쉤<Ѱ}SqX̹^)i,0tGj U33Vf3QiqYgRP e2JQW7PPbZ;^hH ҋc#6  z9_1C~ '2bIR SJD/)0e9&*O7hǯDBZ 47r{?sJD_ܫUNjK^'yi6%Miw9z;p؇3%-,1R'M!pL! _a85_ A?0X˙9|I߷ DP䶷*vʹ4t36Τ^r^{= *Ce"5⍈dbet6y>q Pj#Q9XjOw;vc sླصtkf%ܱ)莚8s@X6\dv W$PN izJ姾Oւi^RX&G(epBq^^u9;D._5)^+7FO, ГL|2 \D~9K<$!c0!ߐ/VVx.PX .%AS"PƭؗHb[BoI>"X|9&8"ENf<瀬Ob9͉:c^^Cp nf!8xCm!Qacgl@=%7L6ypVpy_7K,㗔؍G&x aWs$ZQ{z"{7nSˠ>$5b1®fcn̻75YJs:Y#e3̓f 1aAY O YttmUu&_a}g2EB~wu XC Fd{cwcf d1C2: ?!F@?qA轖ӕbp%(IC&VW-4€ZOa!t*ef)!Cxh\ -Tk$8bqyKwda4Y@ &YGf`ȵ< jgϡ*u]DWXi@3q˒T(kGf`^H y9Dgï߮տ Gݔp}#aW^nc6/Ge҂'~i`e!QLt@3bgIƙa&tx5}3.py-s :j>;׷O~lJ?u&Xf;0|W m'j2Ia~Uoۏ|c;3 W8qe??+tb5`@TKچ%599V=sǙ"pc]`" =@g0#^t=Wf7ӎ%<%iG|3)>bm蟨E9 nDd[Z.~_ ^!*Ses]Eo}4B05"?η/iW;+xr@cFLsD!\DNWIJ&g|>Fͅ f˒ $ ~eR?GTgʊ1HzY~liϕbPDPPQa&u_L %ɓlDK%"p>aBx ^<,z\0Gjטb?PD v=P&B Ǩ'0\uxI=ص\?쁄mc|}js1z_6K39c$?'L#带 a6_jVJu ҡLp=飒)ʥ" ]ԴoqVX.U4A] Y1(lLxvu-bE@K8bf[&ABYqZѺFEĔ Fٷdl#y 2R ջ{pR1¯a}D ?OWf Sve3+R" ]n9P#R??|T!ɣȽ/OCN2L'#FG^úTd>&& 3ʏki ֬8@Z:wⰅ0ǑȤkLK=ĥj HkуW,(y#\V8\}W06sZ7Nw!%L v+ g!9D$U}(I r1:kZ aA&@oFʀ& +GӸq̸W~!tD.[$qn0U;E6n-2`-_oDs k"D-7ӥodI:>Sxe66 iH! Eb$y팪9o)z[oYH(\k6J蓘UZjV p{Y zvJ JIRO0H-ƿqbrCLbC{C4R/hr?k& t/ !)~NVx)4J,J ۋ K$8"y6k OiWm3 ^jwyA "䡥ӄNd3$ 4`xel|U@adNxn̑Bc d~Z6O^|d4Nt.(E3 @L7]Jifs m,Bn;dzA^x+8OS5_"yy\r`xuֲD9,ԉ$ z!P([~mv}Wuv yМ4tlS݊6N@EKݭR|H>H0B:#FĸU WO4рUHe'vjĈݑUYWvY8 h2%¤jybwe/.!;BGx5A4m$鼛%Vظ yA߶`;#Tqh~{VCk㲒,2bjlۉN-c';/ah۽LG` |!~n;'rڹJxG5#2 Ov'C͆?:jX7P-i(q뉧 9幢*Qb ,x>Uh_y/D~sCC- .r-sό%y{ aWEcd_xw5~$w}YF.R /nߩt+wDcw6x_³'U6LEAf60kA Cq:ECy8Xc :h$<GȳrjqH+]Sa`aij/Č}(G{`a V @جS̟j*"R.pa£WDppv6rz?QUoXsC IX'*sƺņYNJEAxL9:_D'?euhYko@n3'-Ffs43DeNWo*Tzh>M/J0x,j( D2qa^.%]< ^ @dvX:*u_u}1L*~qMc20݀(ԛP+xGY2#֜+Fxj ܹExBaLӎ+Cp1q@m T.@S0mA*ӻIYr:Zvc77EܣA=- P!NaNG\A ޾cl!SۄV&I. R>2"BfHzS(cZ6Sa"-7 vSWdzړNFpbL%j(h1 )"ԖEݥxo;t'G vfk=W$ۼ '+}TxD`[6ԙp-KL\rҡj9d6JQm2"gŇKc*M:!b U wa?p|Qb6qpOCS(8QFNIo\p^diN:mn̦ANH;hhF.X/ pp";jU.p̐O7`;Yaa RPWYɖ ncr"Hp]o:2@-f`m-]o͋L4sU3 ڢzC.QRQ^7Qut1>(m8h# %T O6+MN8lSi>eZh @m՞i4J#KX}= Θ&[ е&_9:y~,2ުl,dS 2on?ײmECܝ闤YǛ r4gi~I<֎>z{'.5ʎ[Ă(ǏKG8ъy:VvDfx+ϟ9Yi>hFU3fTY ].ϴu_`\smt^L%%_P)בڃi2&~auUjsJ~U/!9Zb~S>Tj҇8OoM~ʿU~e,Ƴ]% m B(=5鞘v<>O{J4P "*C5z0V6a8L2l#?X^|).}.;3'sf 36 Rqn3Zz`v$] 3%.Zܰ=l ĝW^j[(M߈sOWE,X0γchJ@gIɿ ,$ $  lcs\uQX[H3y!lq tlU:Di/B.Ԑ_#aS3Bx"]Tyn|m EeOA&}%y&8~uguy0.<|v `^^񩐵U;~*MKHX- 7?/mυ)oIF{8WG5E_K*C[feA4B-A΀-͜Ksuԟi{hVV5b#y`;n+UdԴG SPk"}ߓ6(r/)Ife؂(ƧgQr¬іuڪb@!})%Fx֖r*oj({35ϣXrLw t-*{z6;E31-oYK[d*CkBu,W\2QPeE`yΔ`ur0Cic]ҋ8pILE`S+h{I%54[' do\C*cV4X=f[lLVX9IЩ&xC;|=*@XHtj BRI{If4~ P gV;0x55l:e$1:aݟ@L@E8Od)أ1Ss#'KĻ[Е~m-q$CT~da[KW̄{/\Kkɾ<jJY wg gKdTon3{ Ϛah|L3h֧FWqSh?chu3JjZ̨s)Ɨ1zB}ʋ^?UN.yK}Pbɖ@[[\NUxnjG]&(o~5o`mމm'j i$^le/9bXyW8 +Fg_+Ks}z\BF2A EEʓvҖe0PtC(TPj 2bț0NJQ-j :8@s<|]MEK u wH<DBTh û?yRM'6:CBSS7@K(Nߌ(R+p\;$Tnv> u<=iA]PuGɗ2k$\Nk]ʛ~0)h&WbD~Dba_. 5Vbpit| BLG&JMrÆr@)<>KDYWmF13tŐDlV#qsL[tH;vDbI/B qZhsFP{;p9L3԰mRstPzGY-mWFg15ڒa='o_ks3ߴ ޒtYLwLT!p?H!l|#w= l)1F* 9kS3)f98wnÕ ebo[jNr>'f// F]E2-\ E/&.S)\f#J'+RWOCaVR4'U%hP\IaH&=#g]k2}{ kg%ܤV^01h^i=(nNJϖ)^V/W3b.j O: ??CpQY UPM./ z~ё娘>ޤrX}جO3@|0/!-N5Ԣ erNP=z)YmKNJD b״'%C/g>*9`Y7Ѥr.BjS6@5',˕o]ltCFѓ,|WK"E9*ezp˜p^"z7B\~P=$r*B1+V>Bl ƬcbK Ozi0eviVQ49b tȍD[=%`%_Qg\q`Hl H@[ @;UF')xݵrw0:rP;h,s?͋ʤpn,jQ)P'nc) *fIVqg&"ҤOC!#BO@ ӱgY<heWA 8 ;_\:z4u2~6 du0v,AbNPw5CF 7IvZm[#+ 9@@ŞbԻ 'dq7LR&yH4]ȄZ05ƕwV{dȥ ̱+zw*c?`\FKfuDO;'PzTY[I5rԍ>/<{Ȉ7MMD7I۱cz$\q6+381NF,9vpɥ^{&s SI"W+b~W YPVˣh |ݯZClSPh; C灂>^Y;gw;iX ) 8!f^tsbCG q|7vM"wwf`}!8[&+)N2JJ^/!\EWN55˜f߅~ c@ʍx]PSvk{^ܤ6/vȟ2g!ssr0kQD(H"LZֆuFBzò*}Ґ=7 BO_\3 AE*H[,\ }:&x-C{~s-6Sj 8} ǟ+N.}NQ{7ye8v ͩI\`)|=/ol]!8ڊ}> $SuE y?pdhFojaY]>g|1Dzg`sؗ0^bY](qH`tX2eġ@Gr%{ >ya]L0Tle@Зh4ĵMS7/aѺE[F.X3BYʆؗ1EOr?B/\>Oi3\s::;׬s<!9U"|mQq ߳$PRV8Z<WlkM5/% <L3mlnQ DzyVlA14 T\ԁGڌ_OO`(@{HF(&`WY;D8Jp,[{qƷ?wTF6#w펐?y!o Bгh |~Ss6+6VLRDvQuBwq-ŭfž}S]RSG,@~͉CBKV|Vw39w2 9*:SJ:SwF9h=|ː +jJ[0VNt =OiuBApNj=;[" ڕj?@Bs ͹ܕNcNg .J)6m! -`ne}e9q٭*G鵲cNoxClbq/=pUddQ񃛜KPe{d_6dJ.kA-sT:JzYA^桡9ku'唜dVW(X; *4Nt+fGvgZ0nI pD3uA,u P Q쳤3 0%9-㖓.Vy]\fM]`# aC li;?!yHNdL*r߆BnʋH}z1ıJ:&l7RAx ڬ6[M)B f^ 1MSƥ[Tr/ ҭv$<" DdJJGq!y +)@A}~ܼ}2 'i[S +kL gy4ZE4 OXȂߖyH2/é`O#?ݓck0zNN.VHe =< Ј 9>jlSkqQV=}^<bې]IoX~suJ/!C44Z'/.M eJ3cj@*8 6(kx&s &]3-zUs,%;t؊LD_8[j7)"V_ښ =D!Э]<Ʀ1h.p9CR}/:k@R#~M.4Lrfh̡G@4νzJ'`{IYE[#,fJ=0nr֭MglWHe' *_F?=\2cLB֨ơ@ߓI Od;,m5P<ĭqg(Jd]wm aj/ @V!:@"bgK0|1{䓔yj {aPcr݄FAq2Cq?ӣOS'Da*m/*;mstH C8m6mrΘ:RĽ xX.ku|N3$US7-WZT7!yL`Һ[Ͽ}ڡs }rLeCȘNcc@I-Gw<#4HL@~-'5Ǥ?S8%).捞<B G><*idNUa*dVTi\L6يbNN \4R[/ ,Ax\ DWj7Ls^b/M7kei4ugFG!>-;+EGoA u^$$b=] ^4J!T 1mɳغBQ_#!* 5}Y@VqSe鏊taGLIBS[纥jrU{ۤ9AF\nTfgU˯6xl$F,}Re*KVHiȘ:=xyO +06Ic^ŇD#ݠƅV맂@4*tnrMgr0v/oiqsG+zۛ z=]qāRgF,jgx(kXC۸͵mWhla Q!! Ʀ#`mϯc% Zf(S]0cRç`}eqw۳ $3?t]:ݦ4dЎdCI۪(GK@؍V.[Qœ`i}<:V/`9඀43оbeҾ !5 Q!l\KD)zpv]z#G@]%ƞO :Wegr T7m"|)@첗5\8N~0އc?mB!biCl jmZ*ڊ.iˍxm,QLx C'8`Y`Ի*I*bc'X+ ɤX( 9c{[{b.1~v!B~cQxaGhwfg:[SlWFG q&zS%t߮ %#jH-<(>/C-fs 7G0MB3Lx/" 5S,㵘Un-]t}nSm|!(>6-v;TӚKg`;,^mPھ*9)/MdamyN*cB'9]zU̐“Um`f⿶u%ɮCkW0m ?M)ʠ9xj3r @G@@U: gXE-I )J'o)(ulVjNfaA@P;aր|`0݃$VdfgoF5 v(7< _ [:Ў,Hד;zf`bV 34XȪ4#b+X!'J Fj+y;C|<И}ThUѰN*Ė`ݹ Ncه\4<zY vf.T"B B_ 9wbώbnxX}cr3sHX[%g,1MQPkK`rct)]jGE0L !Ж <Ɛ>×!Rt7Jȩ\"R[)CXͱI#qR7MG{gVCX7\e=ч.`oL;^:S>K RA?k򦌗>\YG1)DC9i-j}V01"׵bmUPy&N5 {ۭ4{}*)lz̑|۪߮0dp[us,)4&iVx'|B7tL˳b/Qdh/ͷqǏ5ˎw*cT]"% hZ>l7ܒݺb촳47Ejτ+U78 1ZExG[&bkcW-q~a}5Py"E/ÀC' E&c17(p9Gș bd2ܳah_o E()yxC)26SWy45?qzAӨLSQK9?䧠]Sb@oPf"% ҡPT"I'#1jڵԍ|gOD!pU;=xlATN_W5X&B\ oF!G= \KpyܱFhYie'KקSD8p;wvTsBh&?k7QTZ .g^y!}s\Q47֤[EoTS|1M޴&kWѺ٠Tb9ЩfSGV&Z9J=qôS߹0AAIXF Do;-S1:H5;fi@tMBy|jKklWB7c{+h_I6$Db'{gE‘@,k"3L=={Mp-Y:Ǐ|MW8;p 4U35vYe[sq]EF;INb +]W Цމu#o8겚ʼnNQ5 Ev8Z1(5_fcV);"Kҙ@KnٵK p=;ƀ́ϴa@=BrVRv2 _{;#e #DPC9_+@ÇBkSl֥LD6֬Nz{CV/*qQ¿x HKKHe:)Icn~z̅|LmK> iNU2 POQȵX}(g173W_(slźyv>lۂ~]u\5>GX$'αv8Og$0AGKQ;u%K%OOuBLFmAHSK s4:ɡ6tp})pTbTrpZ30VvC mT'"\g4ٿW=7x0.9 tJĘ'7g(#]EyGbZ zwNqHݟo6[3Ӛ jL, p0:Bs?PVlU#(|C$[S X[fʍs?xA_!Yy*xG9;ľV+NBĒS:j%Y+?tU1C6,:fp /=O/M.M)!C4q懀2vؐ.V6l1ϻ@\TXadhӧqՋQ҂V&P7EDcIW#;sO=xm1د_Qg&|Dq,{$a}1 }-ߙ!xk7O/'| m/{9_wkr%.*{WPv֛,dMkG-?*.@[ 2°1O,ެ}]n; ;_Uzͻ9K:򹳰Ȋ;xdqJ_6?*[˄ả~oξ1?^{[i\!P&$l`$E&H 5,ǫO(ҏ$ 1;k #^+w/vA I1}n$+â'KM>%؈y2ƅTlΝwt'CQ,4JNQ(PK }]nh}jނ9)؏_7'<ْ_'+k_^,'WeovVhߋ'Np]xhIP\T(f]fVcgOտtwHIW>!{BͽOrzGz! -T?KSk_km K bFJB YHy%{Yu%CJ}iAzQTZI{Is{G:o19\l?ޑx+e1u'Fm`twTYqj*l"1t*`d6k&_m:yݘYb#;eM9 )AqQ٤Mf-`@tD8dC6PmDؠǀ=aR7kl_>U ֣SJ, h Su'I&ӴGV6b8H[л.vw}`P?J~" %!ȓy_r+gtY0VQDhjƜ+CʀԺ̎_هʁHp܏d< 6mPQħo{x"@\Gj%Q-Wmoԛ@T5i}׋" •:&Jt%xHj ԞD)ĢBn|+3ѭXAUT(Hx-yPF &#y/nMDR1F8>D֐4TWʼnDGu T%CQw.OO%NzxZwoɔC<7~f2=ym_%-1 X d&2:Jj89(H4l%BsM214(6D𾯥غ$ ӋI!a_}༷$cDSvo }|/+LƟnDP{o7?5閾Z#Ҭ?tDŽPϪ 5GeC7KP~Q*?zɑ<ęrQE l#P~ڤEL~Հ?0 c. Q"l[˅,sOjaH+&P@S_d.Pzc!NvD^#s" ~0f;sUk S͛;*u? OW3U[F)=|n ܙ?X}b"iYryl{VuJt:G s˻"ᴃkTnz% 1l<_VZCvN*TEA p#T()w)N @-!p]m `]fgityjJ4\eAlm,^9 M=v55%U>(X:PуboEc?@KmV|l`"RTd5CS7# -&Ь1F$rYt0 *ŭVDEt{{B/'xtwQn!YXK$k{ɦh:to_{T5wX>p HݬߙFV2LJG8'Hvd_ F H$a|+3&|SAi,6F0,5e1&n6m~NJE7Ȏ?R :>Z[?ꍏX7ZϘ_?nLMSolC|?զYHSՆL[aJ#k3a%Ŏʰ}>Lz\e]aŃ_w%h,/ܦHD,o)Ftr1E~㲈8?%sk_)0&QL=\ MnVݙNu[+WLI"λW?*OӪr1ևh ~>(x9YPٚxq.0_)fة8dJ2<:S/ԪLHI-{o -Esa7dd텗'汌Xʂ݄edQ.8,xmgzLHw|N0a&^E{ك$ =lzIz9d"ߦ*#VmO;愕f}x }F΅MQ(g\q twѲ7 d6x 4P 'Bfчu6NR<9w 兦,\3vUzWgs6yErt%zU:K_9.byyF.5D}cN$)t_,<&ԡAH]q<ހ:YW{ +cRzjXi4SBxYpDIHH¹ ha7aĻ\hQU;92vB*Bm5L<9y(1=hFӨ[[Q•tx13Z)0]6 i)iS[[@ +$ő(*4hk-nxU/%J1X髿r>nC)Da-uof"p"+ݥ9kSQ4&vMlڤ$ #g=YE t%p̀^LBWAh1:mNsB@ebIȦ,~ic)C6)3]FaȈ#r;B%.q%ؿ@LA~Ajz\,^>H8O"c9>yǧb`,Vjٵf \h6Xrg=R2q>R>m{!CƳH w|_eD>rH]1d#ْwWP\giSiϼf=AY_γ< BOϣ W!nZk+^?E-⹜Zq=9Ӷ@qlCwv[=xц'Av,k#njj%|DhBŏ.9;%m==VKCuiE,lwZ׻x;u8*F8@$3zM[Z_Y !^lYj;5gOP$ կ+ؔ:\cL>Iťy+JވwРo3ddQޕ=|n2/}qO0lo(8Akfn)q1zWBkSތNY1W H'gρz$ %󪩞|a˅Z0L~8Qg)cRq.&z8![eW$7[%^,I\}o:ȴwIP̓U fskS@H+12EQ֎Q#ON#:0dv+`_صOl9p8/C #t2w ޾Dv1bu +ޕ\ZqB cJ!0ZIhV[Gx6n(ƚaw.1>}x. &{(BA%%mC4^y1 92*ҁμ9a Ԗ  n2MI02]3 0٤hOWjP<P1Ƃ7g6,(D6O+WÑAJCFn# c!8i' QifWv59Zo8/R/Ew}t^2Jv[8DʦP#scB-\hpf倉'=զteغL Z9`CΌ,09`)j,r0#WI~W % բ3]JX6s}%K zM1rSV S%C! 4ofZF {# J{3,Urs$4*v-cM=1y\* $KGB@>,N\`U?=.'%#~ݖBiOy7{j8r7R6̍1=e-@3V']tN;7y+g.F7hT9w^*3Y,gx|8:@-C%ӦR>h)w̪?k7=rK`MàX,}%y>i~!v7 p6eDYt8Ŭ8Ti6TV;{ն" ybVO+;T$nYP;lq-Jua-Er]g=7k@Ӆ0R1EOf,߸5>@<"$M@y\?_4$kJt@ Ԣ]"KkjZ£-;Lz - \xGr;›zJ,OHE^o kZ<( o^plAr"@o^#dAOxK<4m_xWj4z_UG3( O K+IA~|M[LUqpWL! ˋ-Bj >xY,/@UUK7WY域$& X|Wyc&q`82,{Q8TaA=Gٝ)G68!NC |n>:LƵ ǐxhfĽFz;qU0 1xxI%ӳ7ӥ=7¯>20ŧ1ټ`FЌ"4PqtdɞeH5j6fkgX~PY$&9^ت^6-*?ap>uGeyy_['p&Q{Pnm5f mR)KmM̟PR@lȀwOO=o^ NhRŕQ-9q--{YGqGU[yBnθꅝaJֳ]ɮOL0]ȟíU'jᏱP!{}Fs53S{ZQ]Ucz.}>U@EU& g CCDԼ&fdVdJFRu߭H:H@!f s_m p(]t-P 5ˊi84+=[.3R$0_216!-i9fjԷ&J)l2 v+u֪?qzr_ •DViG Q5WԄVaZ9Q z|Ri L7𸯵z,=E:E?Gn@ə嗻V W1Cɒd 8GY[fڔ(V{mA0wݵaݨApf\HD?_(L]a+I24 ~>4oѭ>Pr aPMe8 [{qK4AL\숑2'X_XZ!@=l1 Fq&it[OFg Bsjx+rA"cu7_A@끷Б [^| U+Ǒ]_  ZT.>F8n<C}~'D]5~$RpS8:^M4q;Pn!YMxJfo+ۢ݇=^g)@ӂZ?pYY*PBSerlSRƾZ}I5p 1TCW[Jl&Yb:m^̡P-*囥%zoz<= 4W>mEuNT]p{+4C4G9uJ!Z4򆚏ċuPx]ڒeQFr5t:0Ygu_Vg |Q09NTck4tNnJP9T0Pc ?!BE"۾3f[%DfuT LP,'>dI4plS /CA{@ܞ,MDd9"̞M[[ D֭ڌ/JdMeR9 lw=*r{m춇M`p ?GE2Vģt8;Z.nZD܇ᙷҮyh=P {4(PYp[2BǴFGܨ/ga/ Tv7` hHKQ~^PE#HifwN`9O*Iģ[d1֖*Qr낇1ֽ"W_ڥ#|*^ 7oȺ"ʋF]~m6(: ](pyWah |g 0ʅ6xXHA@>W,wnBtl_C?o8䫙'k~!bfkO,ļj_nrFl CHcKNhkiI뜶ͧ3Z.I⃄dfr7 N'6ȦV NpAHoU>2fr-YJXݲbEwM]o2dEeҗy""=ĮFl㠯j*,$[or.h9~ŇjU41֓vY %EE6߬.nyɵ^PyT|wDnk(֋1*N-Bqk~Cg_YrߛLjnσi}JoqcT's}67v~{bieJQ `dCsPU6ߧZlF H:/irknng;A{ 7Ю cz=g9’7.fOX ߟ;+Gq[ZzPLVQj4J2ʪpHi}vAoHvJWCu]ek@21$V却6Ҵ`܃^G#-f_0y[H%D461x ;ֹ mi0-̻$ H/$_,*gdQ" %܎̂w֮'nEm\~HY 2"C:G5|s=݆N6`NNDƂ>SIӣhQvEhBJ_E!XCˏYs^ثtF<3JV>ǵBn(U 0Zh "oۄhl1ӑ+a 9W2[T;ˣn)94'#:+"|~YYn*q!@ u!>,+Zde|nJW\J9Xc).kPF6?,3 ӘG5CpFdm{7[ǼŸR0KܼzcsqHZR5HPD&~3&]*vۧ9R'xhjS]1ura¹$ tI‚Xi,UD/!&ɓ-Ag H%,,Kp)%ruD&Pe+K,IDH( 7]dz?ӌ :,82飸Da0cO)DV?r't(up^`XC| kȥe9<3j$M0Z/RѣgX=e3P≤cc:Ϋ03 W_^5_.mo]թN'U(*0]J{R!E/nAP>P&ܣ"<8\\5lkOY2 Qqz ՇۅUF*V SwI`Cl+$fP5} yx6‹zq9Z}1x\wQ=FV !kE"'_^χ"vgc(f.΃2e_WB\S"2 ztz[۹ňXd͋_)t?=0{2ڸs6/څ'PΣwlp=t*-@8!Z¦<2SCs tQޏ9H *.Ps.PRϳuYKxƺ}7؏FrY涙AHYdZw/ h;g<05BL z{K`- F gE{B‰q'ua`G% bpZ%): L׆~Y\:>BlܮQO 9MP8TW/Jauryd({Cba,yy6>Bp=jmȚʎT\6Eww)*bؒuͲ܇/hs9rl&I?ܷ\ 3Q_&l¾L ^'s2VFxSRRN;}?=cj/=hYq䐺QY:59W.u,/T`ycY :_Sg/M5őq揆4I[W ٙ«{~^v`I`"Y\ sBf-\+EIJLh)b4/@B4o(Dwg-%6?i$C;}P s7|y9!1b}.3m_y̼,ȂMUu:3AJ#שѦcc)8baf <-up&YڮgV9߀dOJ 4F!\}ф/gU ȕ owL͐+o,~ .hïަ [v83 <љӝFCW'OalAnK[xlq!]q0H8vGĔASCuL9e4-PJ2g5k"0KY;_&4m5nkQA M`^T>/;1e NS菘y1 w>[CnCiSns{/zËՏ[bIƹhvat?_A^ +{G8PӁ_ ݌2-~03y7_5f?R 7SY6E"+;i'9>Wf$x`>@'M،Nq筩Dƕ-KX+V[AQ^ܝCХWC'EN"k~6Oc 7my_!h.bQ{p6U5$*zAp^?Q]œV|ad] ('_{S#r,@뺆s ^zrHxLHZ0b ^wXd yLs]T}>渚xīM 'mޗ;>OR1@l%y bUT8' XGˀR|ت8)uYh/ ~TVl #ZieaJ:~˽jy*ZJa^#'ΟM5C+3ffiƌ)W_!ZF .vѩ9[Ct~]{JxՈ7aOwٺ;f8kuijC:hZШrCY u/87 B;Qp&=dRen/'we`97.쉫ʦ쾃".(Qhc ]ݧ9ᄴ.V QWA#AeĹg+Tج;VS W* gve!\AG`;ct2SWGbe88fK=uy艸.6YX۫:z%zm2Ł,ѱIW*ٱSqe6Ƃ< +DphE`?u;SYWu"28 p=6f2)A.6DmT(N?-^2; ;OeE^KY]tT Vh=/dt'0Mʪ>C-~t ?1Xn B4t){mRz|cbPPrlDY_|@EiiiuG-A%*W0ת{!pk@΅6ZOA6r)_zV ZJe`%Jl]di⡖K׳(X,qxޝ|Pki_#Gk&qN hĀDڄZ$*dEЮ z%eyc:26`qh<Xv6#o ?E-O>ܳqaNr-"nrrAA^75DJlGp.pz#9  Q@QOK$=y)K^oӚtfTl2>L ʟL8IGGD*W* m 0PծBHR zRYߥBҽ 6IMh4l.1%Y36;Sr;az=RSJ&aMFUґuA¾pC}@=*"v>UҁlR a] `oE\VIm@KWdt$O bBz:9/ ӶKףN"QT*Ts?`ظ$J̕ |=YH.~ʅօ0yhb F{qdȫ57^q3! M _gL112XQw!Q;qS"CiћXDsx՝힂[ă `Ps8GJw+GxA43| <aXUZafc&r2[g~FPԀ?Fӹ*abԐ{\_!… z&6W2>;{h§;qݿ:dgRCϸ(%WcQjԇMsJRd^[;qĤt8 Y]5>ǖ Ns[n\aٽbA:vQM,j/|׺yF^Aaxtk)o#L  {hJg,4PW2g.`$XεQ>z#AD0i(q <ېXv^U2Jܮ|9GJǛ!a*<|@ R' 6Ŝ&ځqh.;]&'GV ;,%[.;x_3 #-u=^ǒ< +A`_]KmyǸ5%|ڕzь}ޫSܚr~=2:[ ;B|(nG9Be/|c~nJhB$9^6rmdkJ^^\eK#fJKy32>/ِKe ЇgOoyT3v8\{K! x\U &']-.x黩d0ӣo#w3JݩDD =ũc,UƟո0kWmv/;_ryI)]bjE @ j%{q~6kF<+)wኤ-JvR:Lk -!9͸KQЧjQBk]]Ts)]RIe>2Z]y.,ܵC <2=$ 6Xs$F#%J5`7LJ~<(w{9I*|2;qsuAІxi0NfK:NٵiQ#v:^Lu1+7 a6w*H`_+_Yue$`))lmp$}-Y7O:p\7V3DZZ#6a8h):4&TыtinBpX3z" wr$)&g$=QهdͰ&ֺ=K_0sqC#%.P󆛟^|s%td Lm Ij_f@T&`*u9gz1>p3ksCJj+Fl2ưCZJ=|7#Rѽ63k6Nѥ4Fq5j:eɯܘɹI%xcj$hs=c=iUjdKuqz? Ṽ<˅}\#J ~M5_xy=!ieYS,iaXt4o'"| %uV_ NSVDyme/m2]U7R d9?Xl/,5P\s1l߂+q6L"8hS6˧hflgV*abA  [b6:0R67V+|P8ňǵDz2S2f3oEAI\K;T&v4 M[s2cOBht/c@ F:"e6a]_ ۜ葕s~&MBcssHma؊J{x0)US-;/󢫤ufKݒSN]f!"Aͮ "ɓc *K%3=QWL,`fo>f40唳т>%G C?tfjN*K&Ydd< Q5zLȖz-^5ϒsQSSxQqhDqK'v8Zm{8`~ug-+K `}y֑,&#;S;ڿ0q!nrLrXc7Q.=oUV :W!< XqXO5"eS@ pMZZDŽkLW<1Y\dB R< A6 yz,݀G8Ǜa@Q"O]Ҁxg<۬1:v֑ryIZd)ee|ͿT =hQJ ̴Ie߸!sb@zO6z#8'˷X:d_ASe=E*?hYݼdȫ,@X8/">a(MU{Gy׻Яwy4lAl @b~|UrFZp2%CL>X6?f:x~8{>i ⌴t&jiZ.0K]E.6?gcB$IU&Y^|_4򵭁dW;1ZqiD-.Έ׈x:ʖN>ʪf1 hAB=(gܩk0'oO3bǶK.HYXCYi|t <;ĕ*bMkiFHNml2ÇGЋc.#c"Td[Eī $$91%Ռdh /\uTh=`D9[qif3̅r#ڬ+:[]h{dihL Rfb ԅ*|۾oO#_ U5 h7AAC7sP2EiJύ~D_% x"%!* Ns!yt F;rDyhtkDz瑝,na᱌ҒIuB8 SI(SR-&AhyJA:SGmnQ}tatk-j餮 ѩIL+dgtVINᱛͺ_ɨ?W ~O>:*{?Ⴥ11'? )+W[61 M1Ne~+:^ Z S 'ˈxQB"pe ڒ912ҐR=jn "o 1l8;0Y ~Ms*e@:%~Dq_dΔj9?Wl3OPVo1]CBb!ڍhX_ԍ#/~f@Аnenynг6.8pJN(9_o.E3,ԡҮB'&i:,O[]$Xk:2))!񮞀|Sͥq L9`6uhJM 0{#wy/Qh puKV$j?&}V-u.HۿBXYN&Va#;TCzL|Ϸ0螃1VWL$xz^T߮9̚_M K~P 'C^'t˝P-VOMP oRd.X} :ʔ<6[тi⍾rM58f NB“[ΰ&?ILI7U_W΁V9Tѿ@J =uwÀ)慉U1''@BjWS_SZ97o6B"2DRňpuPE} %jw + fj̭auP.Be)m6E\Js1PxXVgI^3]d=\}{O ]s56-|JI%ª*B?7N qٚ'6FP-PLXSF[TkZ SS#ڽx˘g=*^?t˞tMeYf!$O cE 2k7U6۠ u 5[3xco W ~,Iԭ?V#$1f)GӔw}<_d)vqN5E-s _ 5;;1MQUSY$(GR4;Q lF'Icۻŝ !:\}>jRlh" $ I95Q~ô;-Lble/4AӼH;=M} p %V> Ex+V MS v@eozndǓ2  ?`/QdZ;t.w 7AHvnßz86\mn/G?i̽y±4IdXϮejqc}zuu{44W,J=}#k& ?gdj2blV@7 Tfr=Vm0E ʰnYwoJ άFmEDwle`N2fS$@3(\E4&."n9lyACem+lEk~Q@;q/gHq=BO#$0KcjIЧH 5`C>-B{ =n&Fq~P^3-K &,d3erk̝)wm3j2 kW6NJ~#Ŋ~O[|\j#CSVPiC"7 2 B&Sf͒j(-掩wu #OU&_7nAp/mC+OMb {ܑH>d*hsRǢh㷟_3l ~{`@蘴4T*㤀̶|&|?DKzd DYBEwoj72ݪ?7 ?'Jo V2L-ކWH>(hّmN?FaOR:$=b8MsOJƼR)}Po0|dzGwvk[l=3"z-s{\2&3jwJjZp>pc,)ج dEHg ː}jj{5ǰHu0$(Ȥm+5{B4ăìH=#~o^GjhP2;ѦuhGRӮ!]FXdE.Үռk2ޝT<,˪fG+gMs+ue;az!@(Doa9a `1_ +9K,hP.h.lА)=,!!OQ0`qEeΓ4$4fh!1;7w2VeʹF%3)oׂuJ3 Re**^[ T @c9%clj/CgGZsGPH\`q⡷*[%Pg!/<BBeybviWN|Rƾ $ fZ:@'\洫75! HA50y iOܥTga?ٍp')q@[q94{$nCQ~Grm'a=u+|bnI5 k'}JcM.TAU7]A< Yʻ ʡV:*? gNwQ"j_ Kkf/ Ay 2.lnm@^8d,ʻ#-KFgZH;I+f&w"t>JA^`ծ^cu61"3W x5Td4Y j(id53f/~\W<140m8=`wmw^HGyMy.%_"{ M}S͟ߎ{ss#A-Fα_YyLҁHҷ>"XI TaY;ղK]0P`!jճ1yCq܇b*PLL#էvn+aƷlL-ֶ[臁',띩3'ߜF$ِ1cjUh2pCxL$σ?r/2'W=S o1f QXq)0 fni-I{)W 3Ttoo\KD  @Xyʼ3|)|9148Bt KM$_ehܳ+(_KT%.;ρ4#럠T`(f䇏"b56 XzMD[m}O6 ] wG}8tۑ{)4?6j{xJJ6/4&*35prъg ob݈czm/5ԲWW bIʼZY6zL"}Tjo!>\+L+%@J9>5k b2X'3ipUV!^h @'lD\gܘM-$+iFtǧE!ΓO[ϧeyp{_)Hăa]߶m(CЎev]Q G"SLmj}Z!fp^Dc]+n͓3V,.S_\Z#0@Z}$ȘwKQ C!L/l%T^ʼnSM?,rQŷareROޘ˶ (Q11 lnq W~YEOпyǥ`hvGx&၍dvcYAȌ0.>$"ZsS#DUiMJ 6$ʝ]Ө1A!\ӂ l ohWD}1yBCI|,eh5~ ?NNT!FOאxi8?QN yB$ C7zN;^U dSˬqOvB (Y>ufxTߒ"`7>((zhtذFgifWWθQ zXʥGԎx /&S)'lyd~mG(2/ZB:2Ӈ p,xnȖ @Qdi%N4 06 ]Lz(F]{KNbqŭVe%I.T|Zpjny잾 @[Epq^|&zOwA:w߂#KF͓4SmZGVϰlY˯ m }=u-Vzqk^Jq;sr; uwVr<ٓ: x8[z 7 '4,E~G}^ T=X94'PܕD$[I̓yUNŗv:HnўvOWL`iTdbN-R8'SX!&1ǽudaIȼ'J^r.QSOnοP̨'D3SxBTEF>=_}t7"Z [2wDP=P7EάUEFCiv/ӣJul_W4XpUR)pWT.?~8bvS2kOi'7V2| ͚Ө+-?7 3$qs遼4q7<6RzR謽zO4?^G]oږ%f+dZgb}y!We qy[$%{!sUeTA|JjŅse[Bi\V$y⦢n-Ic21+4ۛd6y̦gƿ 9 JI-K]R]q_vtG=3ĕ,ݡ *:a2M;K5oLKbmUV| , dE>dDJɃ!C)'_oHS[6QIC.J33R1ўJ=6*o87Xax_lKZ | 6'$1B}ލ۴QO#@ޛ6N>IPB6KD{/O1 F|'ڦPB\WDz 7)s|,==u,-d:)ǪqEp6|uVXuT[ՀzQ i̱۵&8g1k1p"@G@-ڊ*_m`vʫ37cVDaR+L& m {ah2=w.Uy9TD7GX8Sz `_:p2+e lq狌jE*Wb/\E;e)Aj0#OU݀O[TX D*.,ncs9hWl2IhFUsgS^}Kڀkqq{a@ SY# 4}IjMV9}uÜz'wV}om R>˛,_E0~:oYKJ1ȯDC4/ $t.bn8>Kb@f C=3CF뒪m +ˑW:;9v~ve , >&TsoӾ\?LDWϵa?b~=_jA6<>.udn= ߱qDT^- }H)eMğ(}'*Ӹ#]J/ i:Lg| wvqqi ,]ua݋0$y?m1p]d/}v.* 66ir RJ5 66-YppsX|#A.KWRe(0Ra6߆ɨW ĘQ/5rn7#;a)f`زHJz3ŒL#q!z'y/X J baT.\˽Y `x;/=_ӗe)CBV}}}|*yaltIQiL}.pn,\m!Y4m"`Ee0W%|,71xk+V11922 d6]/kJ.և 2O0;T4q _1,"n!=dR`׆p:͒}*(… 3hlE/x]-.4LҎ%d^2LYg!36̜sMB׍IUks#-G[ edC-g+`y&v-"Fh=K=X(gDi'(DJ[ e3m==CMۮI30P&4: }Jy|͞0`>UfP _\=j#dRЪƑZ#G %ozzgkp`]Jzw F5*$QncmŴkM94q!<ߧF1MlT0 r,W^2)5Eߍ ͡+6qsqkc ܡٽj®bB"XJ#{CLv{03Mw=I /QȪ|p)4EwUXX?ˁܦ큌BDGf@b(g:2\_yp7,2&lW-Wcbh`po 7!{XCw ELg|)e_ %Zq/F_K[*P.[7-j5%\)~QJt#ob6f yGܑmޜ՝4#d?u fl|ѥQѝgϐn@ʆ<Ȗ}Y\fG,5mi ⋧ R/1W#B;$s@,2΋R׋ӏ@OP\k1'pLNgg9y=_"rШݞN3e?O8!8kR>>ᄹ7kju֐n4g+g]g#?x>aeTQN6Y;Z⯿sc8];}kd $g8ː fK,D*+jwksHqռjSJDxc$aLHC"t RJ"]CH7m˳dѡ(J36&XsVY 1Em!PE{@¿QQ hB{ {(BO\SU;Dݭ*$h+ mҪP} ٴQ*CcVS>\Ϡ]'ev&Pw3lBlO"^up:؁XQ<'9^VBefN o{QMq+lFIَ F* ag̬M%ԍɯuCϘجse)z*d(QA/S?֢?SlgeDB벁[{bpе`|4< %1Xьو' eA.ÈyH}F6( 60eA0쪲NU S)X1ۯQT@V(Z^W2AFK;4qdl{I}-MRp>J Ugi|CSa#7-ν;"]ڱg;k99_t$O6S'/dԟ(PoŮVΨJw[ԶtR4:kIłXaCN$PJ=OjyFTʬ9`Ǭ?u(V*X;OwkC~c0yo(',熒~V]c"O"p1T7X"QL ,#LWŘ FD]e3+X't.xMuvѰ$k3E(oD1 Bm1 -U -Z#̽]dت@V{7 54XŒ&`r9 pc5̃ژ\ _Ưe|S&2wfw⪶:?DTd'ss1} tuDӎ[wYL^dZc!amV-!"dpTSn@O ^,Tf-,9Bżi! ;m)vyv`;_:Q~ 6fC/ u|$e:c 7f Kcx?]!@՟aTӡ>;? S)^nPfn7K?WrbQθ䠥OC(Q!#6X)R9Xr끗k#BAv}+q9j^ibtBE?$!V_$&BxPQaem3N ^\'̑G hBTN y.̩nޗDZsVLy$NDqh?B C3}Te?m!?l8IO2-,DMór0EXJo'܆^Ǭ{f3 mOEMa|x{[E]mB*^ ENHs&EӁ~8 ^ +#'nEǑb&BG\DÿMA'z+bVV}c[qٿ$OR |U+"Vg}/٩~}jHbg]A :w9{VQe 'ϑzۖ3<&&ʋxBK@.R?Ё|O!OjOJ2 i $]*8*)Wܕ$]R>g(’UXE>.6k)@6] H0~Pލz|M롿\wK/KU&2\ӋCCС?83A4tqU ޢԐWV0P5׀MPo[gZze=2ӳ ئHP'%U@Lu+%iq'NނEj) +zLet?E;I6K[yۜ'4%)$;PnR#8lQMYoHn^%f 2&֟R](lzv뙼 0P i XaQ;UIj 5:"+-Aw+>[ǔ=G)鿯=gYbFnvv-g sOS $UF2"BWN^WmQYWpb˞Kq⿪-NeH|,_nD5>- 6#$Z-uoNڗeR4;XmBD3r!ت!qP(}#(E L@'E!eH\QNqK-li q~YE`@uP/(H)>0#IqWFPRy\OxdjaY6s7Aqe4@ 6x ? (p$dō\ in^5`c#xK䧬 c%ah=k(j|ƙm#`dG"s:U]ϖc>K:V.ERse̓D+udPU }6CgU5zX& i–H9RHS nd5gH:ߏlz˥MnjLQr~"P9H8\Vb^y,w|T/Qya=M.P;9_ωvT" ռޒgHHl72V}. u&#NEC8qf*Ɛ:TD)dˇ?*E{|;PSC 66hbejhIQx7]_sm?Y!đZX,<8ܥVh^(s˺G-R%9_ >N7 %c3‚ Ҽڜ9_׎jK^a/vH(̺*zy%%?{3tok`d/<7d Νc%wD)\t\?lS}-WlwؤCeMaX#9%|/$v E!9\*s55Zl|LawtsXK[\Qlo뚷9 G4Rbu;0.[Z{2!d[C xI:u`Z8ccA!rA*Զiƛ)8"媨Un-ߤ( }=XqborgS(_$SZX!u DZw+82ZT^ٜ7H?3$@O뤉9YUjm- \!&p5˱2frEkMsw+1QMkjlv:?akrtf|oom8zӦ]bZ9_ƛ]toc6[u@ZPxT)4v7yZ/t5 \R= 3u+Nu wSUxB^}WB:ۅz 5)Wzmp$hsPT-ug~KGDETct5 k^X f  ,EB+;E`pIe!vwv5K-UPq87{D__a9c<@әˡU7Yg4Q>1#Ŀ{NEh#Eаc.~rh0'ѻXQ"\qSƄz[öǥK2.c+o1#XĠ_\asjU-6a+>z;ܮC"Eʺ5!$BX>G?Y,Y|fI0Ccif' IhٗXL{x]o`J$zyT&>76$n$ DVd^B8nOtm&L -2 S޾\ӟ`Mu?}8Wpě[Ix)]ݲi;q@=`:%ն~\ھ)4$csW.5dYzuk:=9+Y@ d&Z"hه:V0iEZX|ui2ߞ){^b? [ssygaX+-d_gjb}%|pUQk2,'l+?{Y*0p0-llEV;֘a?XIfJ{Ϯ.e#L @t%@^6|>F5rwq?ϸNE%('b,p~-3-a's2Hb&e K$kYwO|+jOā'˰3kdO2Hgsv= 5 Ow$^b@F#y.m@`x~ŹFM7wݱco˱BboI(5M_vn&CZhq;<7']Hq|ZAnm}P [eH";P/spQ9&sJ%ׯzj$c>DR0| M߸@=sPp؝jp\YV)?7dd{?ަqmK~g:z7Ci3Q]q$)ex@. $z<AƿZۧ.)L/,"靄nܰiixɷ mǒa5J\N@QNk`]_O`@a2GLi=c@CӦLoZ;o2* l6#C&6r>!龡2HkKa l̀|m<=N5d=EnmawvKg%u 7_nNB!6{@8ĸ[Kl'z յ%؋nJ*=݅A_}az6c>eiܠ;8 U3`il~OtmB˫RV|rn俌]Nyc@&q]$fvwzy&f-;FcUHǷ{-ظ1)O=h lA Cg1+, ǚM؝K  0o'Urٍ*xFj-Zc "N0uCD&n&wOHf6@»jʒ1px[e&P_# O2y 9N2DvtI w=m|}tOdf:|ZȽ̖hc{^?J&O}.{ b^) >^%޺. .9f~퐡j[Ma/<3Z"yUL!͏4oX 6]o>8֜;H z2{!ОP|%S 4->@_PpG !Ja:1Wr<+ w{6s-}Y^=0ֱPPt>l֭:7w~%65M`8>szp@nnjaNDԔb>NRLIpϐҽ%3pc!⽈QIN{c:o2;0»9^B07S:@ U PÃ4Rqr3p,Qr8%:A˝A#:Z%hXcT} ; br}`F3vvƆNor~f/&<9ChOw5ë2vЇu*&QrL9*)wO@6hd4hW!A~RXKTh >%,e*AVb܈! X̚^ ;|i/NKnB,% Θ Z3\@gh=sx[ힳ12OYuxP҂1l^61 !ij 0-˷QF9?eh;5ttWPO.U9,FF_^zctCU~qnեP_3nzjamNKUkYl(@sת[=n&F X?>DaQd 5Ɓn6|$B03iv$8K^)%Nbtin0m= l^`tvU92h<_tuو-p/4p+ͮ޶hAW@9F޺|`~7i Ё[yEkCdZH͖rMno^&;W+˜&;gO&E;I1]6F/;R8dt}k$=Zj~xKln^W"$3$0RIi qf$*\^O{}S5)\PA~F K|{k{,휫+n%CO7qؖ>(b4?YB.eND@5 ,ӻHDH `ف+?U <6^ 2򾕳hYMR&&*=Xד-ق51U`nii0bJs˿l1C"Ğ7 #i ui3ZK&S%ϑ " Sz&N"W:w><ط&},+Lc ,&[9V"sVk,!)ܖŷ`b 5{'[jHs.VNS^E-[O^a^ }^E!~U:Ze(hc WlGpV $@yWgQϷ}4]VUycBYNr3]xp|4hk@/Z`0lnw-С6k'Lt*s:XC^9z"!}Slߜ\(-iaǵv>TnM>((~@DpE2@MWg;$(ᕓEqj+WH0}[.rN}8Rys{ 5&Lgʸj.^SHsXĀj:Ou؅sjJf^=iɅj$ܘlk*Voz8`e>M0< IK TMf FBJXk =֧-& Hdo|{JŊެp aF(q#Y'|.&o).ȧWR!L]ڶ q9qK\`2zL} AX:'ΜR΅)0BFuGo5 zm[8bas,A|GP5ƑlpdNٹt_ 0- 4%m փy/n-`"8o_%4;W}*V<&+`sw.-whD#I8ߔŜ.("7t97Tcq/a_uRh Z~z&CmlC/۠ NwuR4v GFrvmqtͽ`p ֿcp,F­5jgKbyYUrB6LJ("5RP2,!U+0& " sVk]L_[[iՄv"KFa%Uc:%?Â2f ~u4.aK[ S*۞#&nCLoA^iV^ 5-k8W^\LkYIbh(]yGT W ɢ ؀Q:-)?&M?ZM hٓ&8]aF>u9aj/6њ,g.֔|6*N*iuϹCoTOCO6;(;GHRxZ0Mfhؘ%UPaA$7Ošd e-AR\Uvf̔"WO00J햧Q$+3@ hXz 9GaAC9&" ؽzS jQeRC\ȣv v=(e~w#*"l9갦3%yid<5 y[0♢\(_e*G{ ŅsPb9 &~` ؍#-¦hRtRY-R&//1w&*(%'{:wy >D2 ( %\y"uyx'U12yx0K>ח^J=P1^ⲚH}׷wI z33^olbo6#րj+CӼoYkGHc[oѥw؟(#(<]SqbOmL'_Zr,tc<6쪋'v$I>@?s-L@$p.鴿'˻gdXܪC\[&Cd^mn{탵UY VD=>Bf7OHGNs}V?r^6$ o-N\" GI`΢I%nH97$G/TVYTeFmQ5J5nٶnWx96r5W$c/GՎ W*ߝ }Tzð?|4/;c2gr87VVT3<|>Dڗ/2F35cF0ZгPFqLM*a<`yvqM ϳ j ^ 吼e پ Ğaq#&7dR[TDl3xſh*S'S|YJi|< ǖPf315M)y9\"NS ;_N[c볿:Bӵ a1$[SјLeFB+{`f$H&$6ఙ,XL`*9C W@ֲ)~_ #&# Xw/q/7|ӪVWEĮ$`9c8< KDP&!xW}TW[hӚgBÝՓFukCQPAXwA:mҳwΰeBvSjA%5?13=i^85KY!oRIX6?Wؙ]Gz FiTГ p^W)Y{H^hE;9&Xܲs `y?ʋK΀ qWF>RkέP"5-6#WBTv* ׅ}UÆz aTBy9")afu6ңE㫃*3oVhN$C&51/ˈc/JbKF,DH)rmvO % ۣT"z{^@XkL;mf=V9} Q>Xau^U\Sy`AJ/6O oBmL%|nFN1P!˝SiePӛrn6eFj/Z9xm:pB0GlU&M ç#^eTi8"33HVd:׷(pI#΀kGU۷>5Ow#wL jd&^ͯoP zbVtd^NJyz\)_}g2%93߆v{6+ϖӮrb;wi-O(C]}փ~d!HJ~*>%j(hSG ˃ss>hœy}Se.9.> 2a,Y (&aS0נoIw$Е9s֬G:]'b׾Ԣ(qk&Z1=x>>ҥћzgeEWA((,)Y'|]_lcaA=W`O>A(mGWEA Y UE-H8]lnUHjZ <<%y˳Z"% {` hURz Z6 ӫ`kǙI>o^j(p'u0?!r^* p|[cr>4fo w-8( d?&e!W!-#h#Ϛ7>^ZBS3zPsw+JqsS?#z2z8"_EP-{pӃ mN{ %:ۖǚޛUM-Y\dNɚkf$e#5 31:y_>1j% .j 3jĆlK)nFzb~tͶaX-Oxĭ`l5Q=H%Rbsf.8yXъ5*ƛmwee}DFpơƌ;0iL#ت%B4P_`Zؖ@:`{%9}FC~wʞw ȴh:)%>Өv,sITE3mj/vsF R`56 DK_q}.׹9{aJt *FF5bܺr ܡ4Ex@Y($>˜|;RyA' (S .^9|KCui ~k ?ZV=cZj'=1~-ބ~RS.E,RK$Kʚ%-|dUk1 :EU 4&WV~ 0Q@ƽ*IV?2 ډ4"N\ؿG Aķav՛">ssA 'apBn(V uf&X漘3YSd\m?dhYHAJf8V|mpilVQe{ o^2}P߫4iHe}3Æ(:w E :.07[*)}\uח37cf23W)W @#pB7_U'z(1ΎY@Q<„&d_CjzHU.i $PP,pnMޱweuNkL`S O MLptp(WŨ G ೿QJџBP$ǹGFFTR(yBUe3_84VI0u&l+Шid[FX>&>ߚ :vܧ_ :n9fkD|JЮ~ҸzvĶ@?hO!a@~#)H@ܕ5KP}jh"Y>F8aߊal7-Q"C0g-[ XM՛AۢBWIr-(#&H+gh1cM#4'Aṋ2&Cաdk *ڬ dpnt\Jʄ8k ؀7Lr00N*w)xm@C p҅L+QB&lw;`ArWB)T0[ZVVP 61Ć`[PP S㓯)&ֆQi[3wLD!͇H}R4 &Gޭ,R֯ $m5O]B=F}gW¥q!A^XUxWe$]QhgRm. ˓q8;Xw^IDuE,q iH1A ]Dz ?5~qIQ _y*KJ<CkVp ex/9Ue}CS$Q7X۔]Gsǘ^,QjcK@Cvp] y7I.6RNWlJ.-o4(y|Ovb$)NSDl&m 65cQd;(X߀dPu5ߦ1-LuLP">#.)cR#Ϥ ވ\WBìcuWΞa2[ྕ bY ;&VI῞X7^a?G{?պ,u3T27:ȜX-6lW'46d7,\Ĭ h < ,F2vHqu3npRgSFп xdݲH P(2Kw +Glv{8c@nJs`$R8ԙR ?5E5AK U|*/e>) 0Ib;ۜ[<[EǺ˗k!̔>rΤ -e0)mLr"mp@͕E>yF۽X9w;>EѵT-^6aW R+oVhUrHΔ^e ͏Zꌊ{)+NbSc)Rp姻J eQV $[6{VVMjv#^ յ w[AKmO5>Dd2 :c*op*wfS$b"s `~+Xph^=)HE 'ߥvSjQB餤J$Ff %JWI/^-'y l[^{'n3Y Cb2Zzb =֐srQk 'yˠ9kR@vt2߉cy{'aP6ZOpsKGi'u t:T[x;~Bp;s@kw {: d)<+d[ü)͛Kx.YmtJ䓲orV.Z+!GT跽:eLSUhM Pce)WwFqwΡ?Hb&\9 7lW +`TWX ZswbW9:DZW$U= evԻTSkjd5S%u /|­;F겼G}H_fAvkAWITAo"7PC#%c2PyĀ|Hdz32#_藘8tp<8H: "Dq]DSEZb<=[!yu~)y(a9 w6p\j1P7=dc})}Q gdqgu`WHckڶ8_yc,zZʿ|@r`BE,CuY@i/.>(Y0OF{;0F ^Ǵt+P FWDQ SD}r4^xoI9Gc_y\!Z[X'vOsg`<0˴=|?۷΂80%8f0'ɡ4`{1r3LsLz/˱WZ; VpJy\d69dܿ޶/S(R,_ѝccsضԨnT놥=^Xa_Rm3=ͅژKa?w?n+]p1NdCEC[瓃հJM1 Q)N] NU󠱶 8tpovx=K]`   Fԩ C.~EaRRxqZf> U PDHAg@ 6m q-'m^I(~ LDgj=*zLeM(AǍJ2k aT}i9J\>''[쳨Xz%.~(cLy(ӓQBaXK}arRz1%m('U|A˒+-<FEz~@hDN? F3;4C`U(x118-i :Lso\s}mho#"K)tuc1k.L=eMe] uIFJnhtB[ pw.Ma4jtWRxƣOMp=;LރTQ٤m øt{& i~yw'Mt6*ƋH†hGw5oC"伝ʏh O&MP~wӉ+ ng`=\5`TSFs;òHВ%ӢJǺib^Wq {#?:׭av/:qX(qS>ө `ZnxDI|pݥp,cJ~5upfH2|Qe1h܎)'ONf/+\{m|ω(-oKZ%-z3Y͑Q"E?=JWzSKԍݙ!t2 2rVR?Q!Q{CSwNJA-V A` 2 i$#]:rWH?8?-*Adg!%2í4K=D&2aA 60yK3n cdۣ@>ΚI]O_57z>/3F2$M>(}t]'}loy]QU;wE,@K8Ly4kOp1ԁS6SĿ*weg/Zwp$xz󊸔n-s0C!7=ӝ/a h#'0MepeL7+sVgq 3I,5km}\Ci&7'~_] H>(U;\6qCP#/ə" mw$Z-dLvk/%[Lgjj4ߗV9}ٟBC=UPnHBm7A1sC/(a G_D%Z=W~hSV|,-V*^fbV&Mydo[#5Ov0:[tԎH<.7nؠTuhaGtj).:ZPP\kZefuU@Lk z:GЩdʕ*gndS8hmO eL /h+:wLI2ɻGR.-8W'S}qmi~H6 fz=v) }E%V ;E5U(: ljz h <|t,;u ֒۴e\&ؤ"3Ryz}4؆8AI|n %+!Q }ShT0 u0| WYdOsQZ|Eg% >4ܜ؋ljNb~ S`bR ]yϊYF莒9ݢ='"lyC)gS uş(3Gbj1!N;y(%K L vSG[hF`ns3=,j#8@mGmu:-˚.1tS֍dG^fdn&t.| T04`|Q"DǻIYs-\쒠f)U.zˡّ] ucԺnTNV"z郭 SԲ!j |Cb-`ex.660D8$hAaGqӠU4FjtP+ޢ0}+aCMi5䦟_ɻ=O@,X.6تmI_mG㳫yU܉Fq3;@ani lOO*c>~// 1Ւ%ܲhg8c$#<LlE =0.d>\hpm\l`٭xul(f3+vEτN=nNᔍfjjv~Ӛ_l`S= QI~f!R[@ &̂e QYIHbaðdy$vv$9!wJ?Yg2YE4-x Չ^q_|MLz5?I#cz]aåmE |%@/9?e5pl/L= wǃ lE;4^=(Yf3i0M2%CwSo!J W %ѡPTm{’ADѪG *^c+D.Z֋T2 0Li'#V\{cSYy ]L&O;j{G&nvv2p :m䞦p]mᮈ]Z:Ѕ{L`̥a A3v|yꏮ@[s{=;;q~#۹0yLjڀʪeSRH}TC7̇$F=]=Ѩ{Ydj;QS*iA 2'Pۉ#179MctTㆂw$,xZm^NQ{ȹtxjg;dկ=`.QOYBJI5OlWc栝 T-<ňK^`3=BE}. Q$ S49w,]Eu`FNmJ4iP bL7C1qqnϕdt]֊;ZwB\Η 8MOڟF"h $nHgʴ cQ~(iB}{M }hM fq`iRۨ.SQr@O~b֞XhQck͏֏ L9]\7= 9f!;@xIEfK&3_^0p -xPщq%PƇ !mLO""5kt1]KVƲJz3եm#漤Ruf=ǤbIUFIC]qd7@fמ!v=%+^uKI99͇1e\ބq. ya b^w{Dˀ/tIH(s@I: s6} [Ћ EwbrO^rARTWDD.Js g팷cUcTKz (=%E aZI?mwRDd:CJ7͒׋> Es@yʋU2?riƏ6sϏeL:"]Yg N|vth?LކNT'joPU}2N Bb۴ɿf`CY*dMCx"4gls+%RHܣd z\1)z -3$5葜$ul#%k)i.{tS$ }C!5 ӵ5^_+. K;y H@ 惋{cmA:6ڰWO jY~1Y x-풹H)"CTDMN|1|#`)A-`˧q.- rfodA[j(JGK$NYSbr}ٵ!]&^`%eNG*[+`A_W]H~sW,Km۫Fds CmL~&Y;'"!> f!Z0|izB/lxNWe^ZߦaIm>{ B8ku e>J,ql-yb*vP,G{(mm509䃁RTyU:'%$+lj.r kNCzMо:jNf!9 G+JfĶq D/ q?_5p72q լ:/?u|bCv@a9"1ƛQXkD_]DX nm>C~S4k! rtN~ H2lZH0G݄ߚ{v]sPNT(;X /}γe6 ~ڟ.Vd;]ٸ+3bl _7'DDZ+d0~,x*QJ_v n5 cBVC%ݩl)z NYK?G&`SW97d00a $`JcM{JY<㽽'Z/wNW|p{jԻ$V+ز͹H _rpDie B\vMW 'q+_G[KN0 Vćp!Ց0V&mS')s`687蒶O@HOJBSyQvk(xk(CI1C{s=aO$RF.0c8+h;4Pϣ=ä_64~m"9nrw vM_KosTWcAE|~ VL "]-8oh`|]b'qKr_RKcCSn8kv5F PCKeNZRVr8r"g^=x'h*p=>t9Q_t=KaZP5g#OF-^%q+UpܿlоZ釒Zk7BV Kzj!%l^M0si ڍ۬e;t\% y&$40͏eWXA1V%`e6ࣆkٞC@3q}%\Z%qSuUbQҖlݰ#ȳb۠,*b7fŮm#P0NjU?V4>Ub4}j D…ӻE!u4y={-H~-P9&<pzrz#yV7(p$ҿ1q Xr2ܽǘqxGBPf=~N YCEOg",XrO9syBo "a#߻׆F?/rJ->F,R9q~ןk$8w2EJ݊Nc?S egBm2/-G2FBW;TÑSuB$ ULR)軎=)w(vp2^˖Jk.tS W-E׈= pMh 4uOyñ5z_a `Jׁ=O$ >ܤ'9i9p0ѫNxL]%?vd+I\ɇY*<=Lz3"W?Nޓx. / pˉE P:#. 8x% INͫ"Ҭ5GF*ˢje2F>E)kZe.7QrcG+GUtE} 2Nɦ`e!NB>nVcjаvO$ S'W zE=nf`>ŽK$/8bR;h z)KH.C*^R 1B>O}O|31_O$TwጯH]?!jP vW(Pt&lꣶ j6U)v09F*a.iV @:ZveR/`@Y(g s )K8avL6/ DPiqbkjtkb~lD8a[$Ϸv&Y;m_L5/8_X{i9!jԧ0x@qWG.AJi09aK5a `xrc CuŬ 1YaFs3L; zU gQî)f0-ySVm\h_WHxWsWKPrjƜ~Eg_=Azt~!NS-[>&osg,ڊ0kU·P?McvT`b8۔0RjԿpodw>wuuxG.a1P'g:N UcđzΗGWmb tXDE1uՏ LYTBX { ![GU|K5hݩΕC~ _&t \V-4^ߜ-:T7e/yZZzS0 S2_s|o?%n$ʑ|[# ƪ,xJjEzϢuX SukI"qVapyY3+ 3 9BeWIe ԗ_}FSߏ 0j/0&6-FQ,s#ir f?|V ,)&88VGT@# n3XiʌX6P:%L0^گ}԰)>3kx !瞳boPH-?zB OWm5 $^-o3+lpc+n ӥ1Tkߋ;>8-Ģl֧]Y~-6Eلm v7,D$ѮӋZcρdv{,ufNe~aRoXE:𴄂{4\בvʫؤt F-l 4?'_7Zǟak#F^~A56oISڈ5*z6<烐12+e2z B 93G±OZgVPvtۨsʥC*RF?bSBƫ Aʿ3Տcd:,x<]~Hayvh<ڟ ps}^a,QZ1 ySs ox#)- +y2\uy)B"x "UV``IqltD%Ĺ?:| [j(4M/%)_>k(ip&rJc!Ui>ҳAɒ"?P7_IE3ٍ]%xklG9I\+`hՊ)PqFǪǑGq+ KGʁkA\.Vj&XB @ᩇ]P}mk%\|?ν M! <@{5։E55YÝaiO-xŠ90&6mqHG;l?Ľ/oI4b=s -mgs քl&>X6}U|`W/u̮RffDU0 f!oO>{d3 (T7 Qk" m!‘ڹ)+ǀE3}+ҡ/jVZ]38<)13S<*^x҆1] m'#i$Fׯ%CIz:~6öxk-)|CȂ9bW=YkOy,nwlАdH+Lv O-,b~Nso[>fRᐄp{0i ؟,?[ I?vnfJg^K!el݌.f{1#b._yjlQ|\b$|=V'C^=TfP)u0E,!0(nI2 Qi*S}&"Յʦ2d#c_.~>uA J}Dۂka(bgQNnt|d):7s!\q\ݼm? IT5LC`6w۩[ ݵ -LTq]js9z*5Cw;[Y/wQsCIoX";|H9P%:Չ\ۚXS@O5<jkku8\1D/2>W3]85QNIؑW&QLvok藌:``-Z7>wdXvI%~2d3h>OJcټ򸟿c6у,&xߕ,envh*mmP"|fDFr0('wxʝ(ኵD}$d2ͮ-8V2mXD5!ԨgLJ萟jn{Qwz;QˆRw9]_4nUt_)'\޴xLT"819ҧ6m%"XG'f"5/P*=ܷ4G6a@PhTt;xoEpC.1hPsȓI )(L 2u)􄦴fV$)$˾|:e` r{nl-=ӻD8aNلܕ7V\r&w$IMFL-fy˶0893N+/H3U8^nQ{, oT%j~g is8J?9mq]D7( ѷ7]uoG̲ÜF2Fn^ARw6uժ0|%:_m}.^bVoU(Yuo6nBa3χ{ lt2*|Zz[%Pδ16lѪҏ+*nqmt_>%kwea@z*uqM,$ "èt@'o 3 9z~{bb3xP-չ:ɋ3BM0hk6>; B]lD1?4sm싙s^r̬<od|{_6,rr%R 6ca"sU#3 ю5"YZ{]s˵l`#*Aw&n`,.6pNN 5DǩZaiمn@%x?(Tv@"|K$xEL?w!?sui=g[j!ѻ/U|Q"0++)e"D_]\qyǾAl};?W]k4%{yڰؓO6Pd[&wXh$R2%6E2N+TH &׋cٟ' ;GGD/|T(VC-GhFÝHJ芢=3ܖukXt2#5l'M{x{ `@_;wb~i2O3ۦ.@|n0}{ 5r<@It;=H.q{\ L40 f\`L`NE`El{l(ClzAth< ħaY6ͳF%ׯ9|o۽&sn$ɠ/?Aa_fy9 4*ܬyp]- lKݡ يRܬl&E_(qY_R!n9`5_ %Jc"_}ۿtf& >hxV4)O B[ '%P?nb)y%bY+Wx{֕Y{wjA<1Ҏ-h$AX煓bn@>?ͪlȒ^m]2*xT]-#c8wH]66.(57ȯk߅*Cl*3^z4ٟ2 mA t`@ g~r[ Rߗ*X?`8=Ab$Dk"F W #,Zd +p pBÏRKonl)nvYW%@L?NyN'1܋9sF'(8A}f-'CI~ߓVMr~0y#2gjJW!>#cjT_a@E7|u.z +mFNѿ|r6# 嫈Ne8QεN]z@=+fGS+ 5oi*!u],( ZX2)@qT-\[]gՏ m\ ʆ Oot/۱PH4>#d1Dxm Bp0T|o *K?`OpB` x R%PFby??[95 ̞q2o?eGY1ΐc&DiBYbe$0 f\/K1?uZH&P?VKamJ}vIZh Uqkٹy''21r=ψC 9FGh+mUʼn^}zM/;ܰǚVJ{,UZY+aKV)S-̢;u998VӇ飛*lYgOQ֣A}/tsd_@Z0dC'$BN 76ZNQ fJs k"-w?wKj\?Հ0K%"1?ϋsQAP,tA`dN:Fnc02~%m)tᠤ'vM6"jպ%e&-͐%ʿ)P<E$er/.}.4A֘u/Ys*V#'a?i,<t̙KJRgTJɲ#\JKXm5Jy-Ώr.(VJ"^_7jxJΡxsiulÏ2bɏ/1>b%ehn|Ubׅ/`T㊷RZ@Ԅ})C yh3 tDϤ;4 Wg\г5C'ZUa$}QE ;IhZU|R2'2&< t:=V B2l3ER<=5|TVV|]į vMRA /k Ud_$C>Pn`bP%b y6,ϧX 204SE}DeCCW0#Bl&XFv=tO`*钟cp N'G8Mvk5B܁/qu1周:$r2 LS&#&z38C@}pH|"0`Si0PE2^ܾ%qʝcVVZ#/hN4BFKeiʩ {#Ws7&͊NG-^5g`H$]"b"2]31Q켊נ FjϯH tR O5: 5僛/jlqfFpbUIm7 A9IкH+B6SlVavҦ|=-B1)e}_-l X0:՞ Iڬ(ցwXR:6> ][^@s/)ae;=Ůc!a":q^. |fk3!>o0s1}B#m=/`;#WY_e-G4tMNW ?h_ SBI /*D3,kc\fFWqwTcȹס>miqv R%8ΜR}}|L,~Xk!9Fj{ IhX3vԲzA03w0>\#7eo_3'nO Kr4 xѓʧ>hf[>ؾMԗ&68PenHZbRasW%1^*wl8-(9,e֨-{TtKl 1 ƛEN ,UZEBӓ[,U/D"5KHI{Y9oE/5Oc.:iK=GUTx & F9|%%r`C7IfO 9R;ł:X<&=@rQFAb;d/a߰I prY,CZՕ*dASjڹL%7jm>2~GB ߣc|P J!/yPa/DMo\;hS_WtAQ\GWtVpOd-0MT]蜫Rk!Ĉ˲Kxx`UFЋ?Wd{k(X΀5\n3}:9xuVs) \#Guc\[5=%MJ<g ?պ̡8r }d0c rĻ棸 .74tBB] _|MIpPlN 6nJ0od BYE>@"¶oKrbkw{/iFqD<dk0\-ȣW7GDtGV.],N,Up֧\RVrIvs%Mv'jS܇m qIXϳIlhH4a$mC>zoS}q!/WP(-2oB!H [m4Y"aE? |ȋq=VZ'݀0>yS͒d\"u~͵yo4FfaU0kT^WJ KsA8ٺ`+Fz}nN OsWe7LeFApYhm>&+D C@|bn8IY8AzU%&3J3#2#tw/k- ܴoHVkS j4G 5ӻ}}qVli7q0W`4ʟ+n{آ%34uxiLBϖvUl.y)W~##q8?Zo+ٷLJΗ߮e5aZW`)ZݩW=۱yI5 I xکA"C%KɟKԳ}B. [d77e3}Qr(!rC\QĀN\:4!T/u UCy\'Cv: ;B?TÐ.Kt`!ZvkyUeVmRq6u4w(f<<ɺe7C1@iE5M ZCHWoyQfv mد}n0ޟ|wH;8ݰn):ܓ6ݛX´ =d{/fFc߾2{qIfGkݠ҄K,Lj ;(VQW>_t5M73B0)!|8뾋=9 ]l}@[73W_0]хmi+z\8H}.%gQ0ѬrLMdПdVu8ǸheW'4m#^LEY&N.@-X4 &CHUߊaI(:=i^~1PF2wu4w$C @ȨfK6Zɀ~Jғ)ozϧ͡i{}z[ܾ8(a vƢ`^R}]ױ&(i r֩ELq`0>01tR+w0Q~5+9CGTInfEkMVwe\G Kl]'[Q2 ;SܒO:Wl{6EB;̴z7 +mMMJ.+{mgtRbntqy _^ @hmvVjܚ#:|.JӉgϙOe 2 gFHDKG} rl=G ҽ@nݚ3sV Al( qw"E,Jxkhn^giX5rO>kѩ<&72Z6 ΛJ)*©> EץT[,`\Џl:w=:q{*TJ +W=G(t|VӑsCeƪ'wupLc1rt h`+ "eDDa(U@#Ihc\+}/rIbFy~,\vL.)н,WVӭR0^O1(7}L펌8 K=752QtfsL1\T}%)؉ÿuȍr1R3#rgqx(XJmgjSk?#g3ۦ+!.hC",k>R98={H HC̜5(KN2 "8rCF%dw>kqnmfSʹUhWQNc.f65#82Ԅ-]2]oŊԝ% XDμiD\r2 <.b:}.w\JǼ318bfh:JO\I6Z*IF+s]E)U)!xq 7'V%X^,׶2Ve\Hf/‰#O#߼8 ݱe*%˃$F<]9}w Sg@reT`fwx`߅Sm{D0X+O(OxdyŔ-1qEKb w[e2, )X?YR{'^;07%I5줓pgj^(={Is&5ѥ b1܏|t &P^%ꄸS<8ʍ!CI)@f"* ]K"2ITC]{nAo:/C d ] ˥U9or1s2LH n\!}CGrge1K@{p2Kd(q &5D=CӱV_\Y56+B}5zr^HX fE1ZZ*{k_£'i)ÅڒEBf5'$/%B:cA}T>Wa7#JrPjĠJ"ڨ]᭴>d\+Nz#LJs8?*np?g/˱@t(ѐsP2vD[9x^4Q' Spc3eBisg.eJcnH[%*޲5us9/ҎW -M+EV_'L0)~%=L"&s0gHͬ)qS6Oq2Qn:ҎXa4 x.UyX䎍zl(*$/?޽k+'F I:KֲE-H5 nW4F;Q0DۣyB)tkgIJ--T !N#$=қDSZCO3[a\Gtj6|&H4%]#"u'17M[(n&ݢF-Qq'(_ར8a_LIg7>G7>6sOR?& &򇖇6yWVgJH&]= eG, k aA c巯V(XԶC7M;КD5c齶*Jz?ulzml3,}:{-Ҟ . 2dSht)j@6|БT 7mqE9-p싰 ɉ]R8)l.HOo؀f~Od(Cƿ Fα 0RcnK8tx겵aj)^n/CHSS>7<$G㫍m5g\})D4;WZÊ*&78rn Mht/C ҮUl!ɩҚ゛ '`"')†DcVֹeDz4[.zt32=>.#wa>0S?5A%'\!4 X0~|X[u||lQiTURPd+b/Ǖ+|FIBYue^_vVoI`hRg%z]"]YI^ !6O#dt0v[cM52%փ8Ć Q]w<8W add@h``/F7.1}O_tG`S֗g' Sg}>\${/VssCylMsZH@)L9@as Q:ųV)9wM4%Z0Z~8A5%Y\"2IcX1AS}?b `RBuFcaf} nhǛ؟SZR-sG\O k4>0$璻/TR!Фz!4v޸Cے{gI"}d66耈  G/G];Oi2sa(v>eM W¼(dV\ \5#,OG,챠:зġ@Y4ˆǬ&/OG>DMP8]ǏZ(,7wpxMɎ^X/G*#ߺ{4^{mke!:bRǡm(~8@T0 ?Dh-`yx[I@'kq,&*4SiE 4^AItiNh imo0UM%snQmߨh9X_QҜOo5+H4A:MO, >OkKr[% JW-"b.}rME`d0P*Dg\T৏cLzlcf6 V⽺)A'>&6  #x&CٞsZ? O(`~KIM~.z&;$d:7MW}7m0ܶi"ѿ<MobUn{kӊ[4̝BđAGc\9x8/F-s49,S|lЯ݉UZ\2h /vg TKEճ]aK.%Mă/*R T_gHY*~~r{"m{U7iXjl}`U,uW') ص[RP~jgmQ>8BoB@Rod?6!9T䒊q:3nƢsN_1/|\2r;R }C)Wrje(*m\/kg'b3ba10ËV#llڼx}NPѨKx!GT\3]JKQMrYm\je]ۂ{,$ΊSVpvBTJ2dSV!prku6K$Dt E-akcm^榽M$sQy/~]DJ(nN]T3-*jz𴨀'fZk'$9WȾfC]C<ɐ6ΞNJFJcM.gѽN7l-CѾRAf)]/@yv|uYC;QlO'Lcj7VXVha60ck!sBv69;4C߬EdT#d`||O,g=lIdo%[OK%!yD!Sk®/06S6c;abaZx~^L]| *R^_1ZvcnqyZO/#4 4szkY]>-fr֜ ! =c3X['b9`1]^ٚ)Ʒ3O]' ; v_c#DRfP+Yj]|PS MurBd_# b\h~VO_7i9 0F WZZw+-!maUxDaSߕp-#K/ȤApydf J3Srz.hF@8ʩbCy1z R_`WLlRlWz`6HyL=VR=nbbB stI#|N5K5l߂xe9CxUW6,k^ru=y5WVCP >X6@',@RW܉Aވn(1!|WW$+J 8ǚƐ` 9I[XT'  NSmB,o\4+L 錆 C{#&t4JdL0n7YH|V7PG^\D:ӽwS$zҿބaNE]Vv.$. {Pm5 H $in,[Ppm?x-cWˑ*aVw/1`M]NtZX1&x.V9)jڄy)@I-ŴUT ?q)T_GTqJצJYIiMJH ~%#xGii'NWUg{^3br)}[Nk >]b Իl19ҚXxJ6eRP1L%&SnaoBa _a{iɷ-#.|֞VEldhTW4Y^nĮ-rí,Iw[DDŽff"Y$xjyXԼ߸X!7E&x4Yw2}BN1e/os[ȶ_qN]wCz+%ijx^Vҽpr$6;-7)&s-ډsQm rLǥ޷ǥ e2T$f+[`Kb֣B9Hr9" E2XьS:N'OB`75HbD:QFgʫ7Q5@d"yQq+]e /'bJ%G)rѪi 76w+TرɉݩעAX}> k..< off$NS_okzϏnCwonvq3&b޳o""mnrBxpMeM')QЊ#[@3\lStGrGJ[~3 S8C. :W4;6>.E>9nO\}P*aw?'ҟ%*̶p =A BbĠٹL =J.J9yccL4`LJZFƢSHQzǻ͚mSm9f4fٞʝo|iZA[ܹ̎^P|Z_b4p[Ůx I (evZč)(oOG}\fv옉w|:JdT5!HwE#xi|yT4 t 0YXj!F] ^]ϙM&LSwߡXK _#-y|"I}}.L}MԭYHZ]ic"paJi+Q0NW{(֜Dx4ۈ\Vj_dJ{Jξ?fDã6v9IUz֜i⥻u_SZ{0mˋG{2I@QP̃`%.a#xAh늧,(]t}>ej/Z+8iE$Cr{h^U$,a,@NڕR<SU/N[쳜~T[_V%Wyk=\!r|8U ZxوӲc?s9'NAWe`բZ%If !_!Vr;,";"s=8O/!ZppPs v%Fwj&%#T*L+3gE3;aCNH/ȌG7@z_͜gy[j!DMmjyx-}jt!U -$>xqġSn$e5%pNHT}^tW>q%NiBj)MgӤYharדi2ơߕ5JzAPw8&N7ax9 (hIh燐 ;2|Ц,@UM #02Dp,M}Ud9j'_`h"Q3`Ӓj.8̕brMN0lX 8ޤC:5nB|J*~uBU ]a%b[nH:& ,sou YhTPRZhbsY!D"P6dDKĞY pد 8_^۝P!nL|3TmLsv]ǏL=8[UL2l-۠'@I#SJuvM+O0!4h-}` (M*Q{vtڂe" ʆ pK7lZ u ›3ې.h/ɼDL|2w|˿i)jIIQ)ťt-64$ "-5xE1ib߶xd~k Ax0l0 WPog w$ Nq{M-cΐ[˵UЋuƕ$@Ի+qAgwJ]W|Kx# zdk9Yj=O] yfXĊNV[+QNPXJ"#Ta>YqKbC+mLQϔPI)hVǔGd~BCo֍ ڲM̍:ca F:D2Cc*= +vf.@:u$S' YB+8LȮ'oO<ɑSj /;MYxrYR)qU?P~wY4H-ͮnlhp/|o#v#g5ϻy{B|PN 5_[@F9YIڡf)qȓd L$[\4D1gtt%V K$2_>,DlTFt "[-3 iLMI tIBg|Xn+@?2L; ^#(*&Q2.Uޗ,xP/Gg՗. x&gbWI%`Rߜ+7VOIz#DY @ `CI_,v3t{mY.S&qO<[s8\Q<&qtw2Rׄ8\oe;mN!!^E؋~ ۷kR|c@8B#oO?;k=IO,T'."«.3dDE]n}U= s>Tg4MWf 슎ga8"(I7v4!AX VɴQFRZ>Px'Axg2WmGTLSW@9zk4F1~$rYO;12ꦅl},˃ɛct?Al/4*Q<=.DVk(،!\H>;M(71$,#faM隐|w_ېSL=,&Uw"采Os;2*}4w;@א{_cvKN E] ly]sǴ8*{hAk74IhQ4%}}t-Cra퉯|i[b72`[!dfM?zea~#E+mfp~WmLiCS6YxP`1 H^ݎ\JمrַvӞֈs @njez%S흟p"d ejMTbvXI=z5V 55q';.gYGT8jby@`8wFxbI~ݰ@*44.K]l}3^ڤExEuѰOok4\Y9]Q񸸖O~ndlmU L G@WwT,s4X S1([ ,wɾaU_-\`#JUN%Ȗ^[D|$jߦC<68MDp"%1JP|qT8OB0k4tXpҧ,bM\ck[έx0>i-/.% M͝Q,2^rߜjrB0QRJ qB @P'fcU/e |O_߾^tRb Wϛq7e+g/LJƜW栝؈+w) h6Н* ^v {݋ K1T:E-_32J}"0ŵkҵd-lK}^:tHaC z[2]fr O!͆7Hd` Z>c{"m;Ոs~pYPsf,@~vHYnG!QwMNM TAkq<"_ O M2sW$Rnrf~57YWn֩-+([Kk-; y>Lcwvsr.rogvnz9qrZm~GOOA;zBKnk xkv@o R`,.0(7MtpRR=|Ӷ7AY-I%2cR8S~ǚBꤏνLlj\FR Gn`mA`ߧb( ,,[9H蒗#{89n[e 7|]4D69<-鲌ٛ1V $;ZN$~ bQ&_L0J>&umte:ֵʥ'c؜px8u@ ?uV`=b`+Sy= +QsNF6&G@UaQ6Zv}We|| .Q$춰*.6j ,q'8dVYEAgpEb,pn~yQX޹OM<p,3לjdfyeG$?r`VFI>Ҹ>c!{Xx!z[;luoZ!i،-f[頌6 .eQosHPLDѝYsX |]azY+6JCp1-X{I_RZqw+~X3Ǧſ 2 srje!X8٧iYW.Qh1qY)5ŕ/ekvO4Y/"L%V`,)G⪔RS3UfP0 iXI30rgw3ÒQ >hMa +j93>;|.S2UhhOlfW &dD7GOւLs|FqaQ\,AcnLj nJ3{ }> u >N1$_@~@㇕Q^r|vTjаpk0qTxr շf¿o{`r}/Hqdz"Mg$׶`?rI4i\\<S`a{y  ك+Jj͖-mGjPZ,x`$AjW1=L[_XXٙ=ܛR}u9x+CDv}wk餂Wh D  \B=E&D΄Di:j06cb>ܼ5޹d$@Blkn2fȿfP:gzcu*`<-xGCHP`2tPyιy,[fB8W{ۻEcwR:@P~%aDA1_.DXH*_Y`_GH5!tCV@APMu OًrU.Eؙ#l]m*+% ٠Uw)th4v=ٯn ky%Bv@(;N+{1 >]6s,:H@G1]k KKqmpÄ FNjˉ)9@g;:΂(+guRf {­4_̝{ s8IvoMHF}-IwSu VV IgG|J8?G^wmf&sN"tc hؽBd7OP dpHV T6iJ+n"2vt$pc?-C݉Eq5_Ta9@*Pn)5Ks.)m2g M6}}Pjs ]\iV/-n {wkVn-%['y8_1AEL^ͪ#}9_Խk/ZOxS1B2%PuKTEcUKddВGFq0;2Sc3Hr*| /}D;rEe =kږr`$wnV("`9hbl -h:A/5K%e,>8SM FRel$A?K2[ުih.Gɡ-h;5y<bp?vaQ6=KEpUnZ"~#iJnd(1J,atû>⎲[: ܎ VDX{<4 L7 1Pg:?秎 ^.t{*Am/݁ŀ" :sd;SA]x$-kSg1fE!DSAc]TD"B;cĴاc_Z yFQIO=fELE"(_: XK).،G!a~1`V8d gbҀDwo<O {ӛa:pKGP\&T_2T\_!97aONx6 ô)߹NÜLW(#yi'wiEU= S 0) CAdǚZ/8h Ɂ86:o50D2 6"{a-l/i {2>r#add5V9Gz2P)*ظ+]yma.*# rBp]_<9)%'F`.0uWKvHWh|/ Xf'z5<~T$~) )P̴j&o-]{qymGhJD==b@D`_K(m_{PT߶*zz_1,sw^8 8`(PDs{< jtC?ާuN(K+cYg1eSĝ7YރHl$=+'f\7|ã7vc;͑2yOb'7ZB'bW7&GPZgV(Z]\\*r^pÁ}L0"7hqqiV?Y {C=<)j ŰDBdkAM" "$ Y\ Oh`WDH-T TT={҆8@) CH5-% |(7)K3TWհk'.`*]),8ۖl7e DŽITwL<3u ?  #t ͹^ 3[zGV ktzT3DL~q d}{30guO ٍۢNo-`(zf~##rxY0!exxׯw)x5C6čPBd+3e|U/+Ws@Lる*^&Ux9Y2xh.gt{Gr2F#k'tND: 5l Ia3Ϙ2u&Y[: JN o$ qM3^kDH6էi%"õ-&xU3.uȗ+.:cK̠ ?%j53incޟh * Qjt+ VrNYm*D1ڢf-Fwdb쵧Y$a ŶSǫaj[xe7}"EFͯVZĂ%ʊ |}X6өUU}k) EJ U>jX/IMsJ'{#LPiZd%9dVqMe#L/|# )=[I$摔 ~` |6{#`'Dޑ8xXT7Uhʉ3zś8NJ8.OFvven>BTG0k؎f>"Kd%niHg.,YQvfp3Ҋ }it^4B(b#RXg h@XP^HO;N*E"MWp w/uG.;M x"dw!"*i䜣a"G1-`[ga _ڊy;>fH{?:s/\Cmy$ Хpzv;9th#ˇ }e2 erԢMcdf^zt 5fܹMօI^fߍfe6\rGL&Ks^Q )L͏!6,9ů3Ǥˀq&keWyDD \h-RbV`fĢ@=+'t*,o4]*ZX:dy^syx#4PtL仼GgXA]~6;$ Mf<}ƱAOwϩmߙ܉2,tScd[n:7kdҐ`)wJç>}"~ *z{ƌVC\'Z}iwb>(T FmIms 6u_0ޙuކtk̹G/ 4DCPgUZxl7H^*nD\iۻCAdtNß1@.PgXя2۔l 6E&O,*ǝ: 1k- ZfqX h"3~+a/XW̕5Z5Lr^1 [렛4/i B˘f,Q=`ȒӅÇv_Y\Sɑa%Ԧ$c\.51$x^){jt|=jhx&W`BE,P"ܗ  >}[R]\J|2΄ţd tI5*h-0ץ#4eQb7ឈU#覜 'NAGfT %A7%|΀jl{DvXX]Z*#RG2}Qd^%cfGϭ=KX0AGf/;գ޹=]N~5\O=6r=*ƱR\N{(vHձ?Hd#BNņBo-늱 9Tg+R ;4)j TICtIB',{/~ Dk[duNocbzqKKF)+u(4}v"~!Z %cd[%:!BGd h\) g֒H9CE/M,.4!!+$ %fL5Z!"H(Q3$v%-8\1hًYxRv˷\mwkت&VWeɘϲN6cDbH"`3kِ^ LFΧ/HJسKK=¯ovܡL!tm1h3bWVdXzGNŌ8CF >)P &Mbba>Z?X\x$"+M\jOvma1.t{Z28iXGy+o+/dpQט–Y,4 lRiC+/Z9n39aN<ł4+G%:YJd48̋`=?VB޼ Y>2셈/XƤZ_UmnL._ԫ9O/lPt旎n$FRXu5 u&sXŶȄe'.K^5 >Ngڇ.qCO CIߘoԹ.di"(㻍o꓿S"~G #wg=(KDO\ @9EV8 XLt\9j ԿGI}b2=MLQ]N*2e~'auB] 6>Q!0F!Ggꆨ7D<V"PkZ[ɲCY0;g{:]qhײ@w1G/ͥwo_KEJ4bxOm6"CaHp\jkC%!Mי `_VT8GK=\pI;1Ū6X3)7OԱh1,̤)J~1f:L}*16F#Q*?z}[|:%I Om6qӶT鞤S][vNCnbBIk:j'ouګ/ ۩2bI7)mBh0D#n?92.M qfVt s74 @7Cv`?z)ɿw2 \914/`jz5 |$rstq+M &xQtrrb\o3fA{]W-EQmT]WTf :ƇX2mGA&~fAhf=t&7*$&JHc2k kU8+-6LW 8^mn5ޅ a=/jdI7ˡ+7|T&"[pU?Le&.~nT?1]!T X/'?nLf+<kr ^GPbY8ǥ=w <<mcXFrm5?uʯz(&=0( @K1K檓T1y~'Rk6Pvwt(j)5lC)x[,Asݖyh+ߎ+:X u;}6Hr}3y%3(T聆$5T7Lf?u5 s'OHxJ_p 9Abbȳӻ=qPH BuB@׃^4 G"aoyG.R\"RjI#U+"<@w|y%hDvOe_98enې&Ls[k#" P0ӯmG-lB*˧[4!{cJSY= apS JUww{Nqʏ ]9!lD IIa,|rfL /@-\u4BVd;֔dO+h#ikR~Ȕ#jl=0ISxaYG^99?Sclr7,.{ly'<¤#t/',xM_dy!n {̚JcXNe-⒍ƍe'dYj*S{PSK8@*R[?>""@;eLeto1Q/#Lp[<# Zs/7";B}>zg1CMY7LmO-&!Wϴ.{;צTS"IBJF<^l kRڜL63QU>Ky]AbbTO-AS5Vjh8:;aVmHk;kn2xUrߑaGy,[CB=Uy3]9k6#(Ly(v SJrl]vE[k ӹ|bd)*N+AY6`y4Du.Daˁ;@ m|yτFʩ0)2/~ n5-+AdPޛK`W)pHK|D]1a-i"bN EP{5 C* ubCIזtfx!a6>HJ8>[N]J 5>0abogϪvvH8E{pA-<"! N!fM}J-qVbՇ|!ѫAH &+"1%5 e, ى#4['_@A:ݵє4ZD*CM,XW }X/ιI dBy_چQ ,vpijIDlX崸z j@xLZd">*5ChMX_&IL4KVH>EMþbhQP0VN^?Zd"nT}tot6ݗi uE<3}.^&AGbL>ώt<*A!0˓̴-|'#_z;Po' B׳ b/b+gd-j=C&cMj 7$)h/a&.m6"F-Er&M'uhhk9^ީ=~=o=T}Z]KQas1?yB!?xWuˈȒSeݗ'&; h:AҘЏŒ7cp-:qqyd| in}iZ3Cc162R#n-.mkƚL;GVV?\3w=`ISaײy nŒ?.I0 <$C { n)K,42vw!u"1JrY2ay$awȜgc<ط:,]mxE=H*BﺂHjm̮P8XpFЈ.&᏾(* $^,gZoGWs8f ܋?> ,Fif8BeZZd1ˉ|*21J`j_ئKRRhOZ_hYTRFӓMlaC[=88uOʝo9 k <JD6NCx՘'·FA Gw^QqK\p]5d!"I^\7nlD))? G7f c-b/CU- Vd4g?||C'-nc…gA ;vaEl7t{ǀ/)i xh2AbKZyg䒥crFa^j6+#-yTԝVᬘGyl*"[D/Lp:@ 1'm8 B2LΜCAOZ63+пB!L}mP2m5 (_C94vETSëN#k6we+:$? Vy¯, MiO,O䗞{ 񊛟t7q4]]%B3eAݴe#RtLY#u[2JwþYQuQW+1ﶗո_p,H bS 26_(9aF?*3G')!T>:Y7\p k2UwȁAvsnSL[BUjjJC1ӷ'~PUHH9R2U;%dHp*uiM':9)mȓeoaU#R>0(6`3SDDχm, \1Glޝ5lw؇p@9n#iGQ.Zp1Ԥ 1э9kfnK/ *,{ۊ 纰yɲ`#~|z-ӑW%Zx%ÌlKrzt;efMr{z}xyeG$XyTa5ApP'Wq[B:[&~&0E$Vz&&5<$ auWeRA~iP9K Y$_ 1Bd'ms j{C$E#ⱑZ}J8y7r\`$0ꤱra#}$DlI5p"H.kTmf\ad&ӿ9f|wm8jY =ٟE6o SЏ"Jr2O7780&aO-{۵h?&_GV#_+Go7Ssݝ|HbITP>q?ѭF2ҩ%"'QcR5A/0b.aK$lcUmS-9xɑyB2%z%/Gjd<Ȓ[_S*2aQv׳q}K }8T}|Np2tb+q kz~ݬ`\1Iuc[OPI1PV97nOc ҢBwxGN.H: X-iIJՊ 顯WfX,iOSј"s(cD/5J~?5+Es}.zJ!?{6yNz&=aaT; kӜ3i>YSmfUYp?f>^qWÂtwT7/`Y@.E-ȱ c3g(阃¥wg- 2g'wVl3$ tϭZ~qɵFDȻpEV_K:@o o"@r:Y|񼈶2|  }]EA7fƜѭ UúR-ہzt]e#da},toBo 62;%v,?rQ3J.I?/`VȫƌaxgIfl&=d=S mP=]Ei `K{x@Ǐd|ĐK p5t̷)o.G&"(>́WZr35:ɳX]Zc}bM+-M,Qߧ ,f+ %˼%J76 )`(~#,;%Qy;޹ ݸgɄcˉ(mIf(ЭT[&qجk.ԒP1 $&[=޿In;`"&N(b|`?/5cgIlcY٢*Mro?FQ 5ȦjkwFUK͊ (bx Hvۂ'46C^m߷~ժӲF ݞ^t̞4h y) @,HE{ص4+6`-aW%8 @)ǦhޟNd!-}9C8~ _t+GvhvG6IU`q/i?i"^ӂ0G|tfҞ*Hf$ <$o 6U5/{#{{Z@dGVs"[LnEh@ѼF(b1QT+a7Ŝ{S'4岕S \"I2@X%rf5'V8_[h"=>r\%?Dsk=p+# &2lT5l&p[:Wi;pZ[ `SKu{n-P+d< sgg7oݸ&: h@—S `uBԐWs6MV0~7vhqĔ~e뒄?~^ՃySjf-S\{$3G Td-nmzĄ4HgsC;DBH$8p?eĞ>:_| \EĦ_p֏h1 EJ\f #KſFk07nof3{pö!})f*t)i#N_>)'c€^gD_>=( {&P'3 TXh~(X0X7dAP0S' Ԇź겨Ң"Աj,yh4ߍML3Rym;H Og+1ez*[X;ulfTyCWk+:N fco|P\%u6>Jԩ>OU`2 LuU9vCwi]ϖ0BףN>+: e2Qu];Sl7wR@isף`V6f}ëE{6d 9l?9T0 T)`׈-[g 1+d/ w;[VkC@q G7*[ 1~jl$1svUԞ9'MęBwPQYU:n 2T"49'5SnY>;s1;lWChJl:7͉lsa/u/ZY]t oR<uMKq7T}Ѧ2(^j5:%9 1v`2|Û9ɓ(ˤhY8˺R= أ-"\ S_}n},|fqo#ح^Ƭ'6v!jS'􌲶u_,Ä!ʧoa-[$_\M$6G ݖ}8n5\$u/X^v)z-v& PPZj=M ْ`M)OcXKem wgwtCܵ XZԺ !6c.W!̑h! \4"ɓ%ehܰst I RSPG w}_zU~95@:@׳xlKs˒CEhb!=6Jг?*!P_ G.#ہC10[&lYQVSFc fCQH 8,xl<:rڗE Fѻ1TTUJ'L -QߙkTC+ oe6 CDz~_wL1O@Dxv-,$9sxlٌ߭*4p1ϩӚA-jh)m42YuxL IX:}qcԠ4l{*QJ}|:ѓ@U Op<,4 ʀmP\ԟStZ@H'z9S)3rH9*߲lS#'|E*7 8 m Ic>CĔt7uyBIHx+7Pnte<'VU-ImA3E`n2] DАclc,_p"^زʂzlĹI,ƎHd`9lm3>oݬ<ҝX{u` @7J} faO\򎑜U!&32ǁje cZ,!>,Fva䶔K:Ѳq@:(Sj:@|Z}/-!_KfBҕx&TEDHT"t{Θ cUg/ ҭy<#*n[xr8s'ioք.rz4_0ZXgd6AuqdkxHEQT@YdT5 0<WЀRE;duM`6~m9O5)pKȡDO(pN%6 O|0kA\/} o["FX#c=!L v R>@,f5Qk~p8{筱 T䰘U>NC$/h0t >Z*>.*8k"n"2X:@VNUf@A]%1'L#*%WEgr*@ mk^T__z4i,=Dp4HX'pؔM 06:=e%4>'9 *tE Vl -Vxĕ4gzBs=KRs\#=)bM 𠈓 {ݸHfFĪx\= svl~D-f0A%qt?a|8'qٻY&t!ʧ(8!ي]}=tgqOKP3Y5j0DͱËr!*°YocVTq ȥ+ES]?tkKwebͦm\WJOX l>7D%Ϗ- 'Q> }:K3i6:%[ZO9369LJ6pP/ux ~ntVb x&s|eqG7n;Vo0G|sJnG5UĠDLS/Aco4ŏ4< :(]W6_ZÛwaր㚧z?K"Nύvkssw38j s:phmEWwl|rB&T fQօ"~ _ &1W?`>Jw4wͦo֖%C4;\z4Vfo%qf6Mbj0~kҾ"@)]h3#(ث5UQ.T_C<0ZI;^}X37oKߡ\r*,Ng7>"/45V&%dl`!1h]no/f:fN dYU3 ؂'_Vd &F F~hA@MĐ>\14ԙg#Ku0fQVthO"3N} '.`k~k͇˩RVĹ 8h4<^~aQHq[] ̕hw7/x? Xx'qӉTO_N.O@v|i(7) 8C(3NVsd!sT.5JR}ּ5^k/[I1͝3Yp*`tyNh">پ<;VᏤgѓ^2up~Kh'fr*VH\5w!Ƈ!1xP#i[փtb@+/zzQxm2y Sv ]*4WZ齚CdH PuEC  3nLKe8PY" P̌fD\-z@M%>{וr[ =v5NN8r>&tF;vdSͩEˀqQTݶH'n8A߱@8%BiVzCQ؊ <)K) UkNAֶЬ sM[@Ox-j ;';`UXOt `rlIV¾/%C%e$d4iT)g8 u]pb33 & /7GA , Iu!£ :pHXлʖ12PxHEmhriD񙝔x`,n _[4qC,oꌼmcۋa7<&0H)j%H 6s;v17|$ʊSY;Eo}E4%8IC0*= Z1npsHO#u&mxW,5O%] NYC\+ j -5`Ue?mw?I"1Tʉ]vcb~tĄ`WXlu7iu!u;znYs}-T964=!\*LM(Nz5X Y8GˣDx}9$9i RJz kj5DӮ0KH@0Dxb[AzhՍixvSǭ}I[XܛO?;rg6' .^ % _43WYINb×]d(5y}9y"`9P aNȴNV!aJRgjq(, ]# 3{,X2TU{(K,kn?G!$dcZ9fƢx>>B kև`u>M S}ct󌬦 MhKO[Ufq\}He1$ WtLsl}g28}nIZ5+܁d('|jw@snmLYz8iR}+$TՙJSvp!^J|XkHA툥RF(bt*;RF4Nwo8ݼob#^,L.~R=RӆesQ e4Ǻc@386!M ],m-I8̄V<Pe}A=Nc-;C`T΃|FbHE^NTe K&Wb6鲛\\ؘA/򓼫Ь`!v/mA<9omZoi߈+ _p, vħ^ЃEg+:%" #,m]NX>7>-X ZP@$U܉,3qm,`8 6!0}_V xDIט}rYRu?|Ca}K4jH݀ZFt4|제 l~ ӷBbiϏ{W̒Ee0 fګ}47Mu" #OagOl'_߯u]=qXwؒ*6q\d /~訸ّ3Đ JHYsCrlYV0H-`+3J:WD^l%/|Cz&@7e,%'T3θ~:Ar)HR9_~ODuYpk/X;gfIM}xpM/u,,w_.vŵ۝$QfPo1$Ifi|xTG?'w<>0iVFhD5et"GtoNtM^~[[:+W6lژ Ģ/JybUa,XTJLKc{v(_~XT`X Qu~h%A{7]W̻$R_X<'c;oy _3mkbPֶR}ߣKR1u$Gc>fYM0$ay6XDlNl\DP!/ .i0>*Qo'L֡+$0wѪpNx9)}A&E``$K_fM}W^1>I_[ȏhީ/ƥX3w-\ZkaN]5X@'2Uu`5Trc?ywvf QBl%I}ɱͱ\qQ>>H;lWy4Z[eDBbv I?!,"p{{ݯ|G IPZ8TY_Ce}n]b k\jEJӷ| nNbZF3+sX (VRS m}勹 .|o4 =k'6tx-wu9r~sCvzu: /ƩSQ0БG͎=᩷bEx(hg#>veJд$3<ୱ5WPRgp=̼rs( };(]Psa+Og7xѳrɠ)?O4Љ{WsF$.M5tsqPjPeIHA&@;hDSC{]^r9c .- E`\Hr1l|]ϥF̃@T07Z}Ηx8NQZ Hgp<W?<ꎚZz1squYz&e=2#.nvKH;ۓd(=&ߊKOdU9-'kJ9A`Cڠz^K#1͚zI%˻T᠇\;Re:qtsR"ikPjN@:Ls ~_Y)|QSZtL̻wBLgAΒY_50Zy vB=|.+"!tB!m%oX|JN86ǘq0ji^^VPODl\v!|IgiU 샼#Ъ={[YV@P.[Y<,;q趨ݴg8~*XqcȦ)"Ս_c#΃n qCEJgYN!>ʭ\ G~AƼc1۔v*_vٷeJ`<['̈>lZ3t} ye),85xA謏O3zݙrє4.!~G[QR  ݃G^Y+^@k?HaT Uq>aө8 ,`w& 3tۣ CSHM3EDO}kr}|ڹCڵ3yHή]ط/$h)kJ-Kg]몥ʊVWqeHki пԙAAp*j[ʜj2% ?ͱa5p ? ΏCp ΡeO[ 6 +K2S$U75d1aa[l;D.fp8p8xoVm) |晪ʳbBq+0on.(f/Q1\P~Jh_q錺- v)b?T R4An}|Nu<Lv5so.6HފG ϭں(,\4#KyiE(%cTז+㓦@-,bMJ`+pf Bpmf+/Y~ penoz*V庶Lí9,7~D.\&3 A9m:J.T(2HiKH7 DYѐjL7Pz)cߌN[(j픐9iMCPcsǠod7i0WnpÊpq_l&@#bvݱirބ#  x I]=PnO%[KѠ=@,YzbtQ 5S*ߊеaIjJ^bbsJCOzTu_31Clki^ \I̖{81 [+i-,tML46Œ,a -TFqfolx(Yp[;5h eY8 7j_uZUea󺚛2 1 ͗}{m$-4/|Lw˝ @aGvT՚!KP,E7!`iۍ- _u538sַ4'IFT#[*x͍t-B:,ҧULolgjb;M[G h /4X~½|u~ҧ !p_ׇ=tֶp 5A(B]hZti1C r,:ߧJJP230zFW؄[`\Y#6hzZ4Y4\|ACm.o59)0lN|n`h")^wowP*݂Aa)#p4 ѣy$ P&t_t^I/v54.W;^ d։-c&4Tj3cM=}=l1CM@w9]ˑ 8{M%p鹼6QJܞH7b,LVYB1u[B; k7a|p Kfy}0R'x#xK [J)}}7u䄰ԒG1[DĤJ7m2 (Rgø;b.Lkd1r9k1vP"--AY Na}WWm2H 'U|%p "wſ`꫔/Y 9 m%G[jHARV 8 3r˖3 /έZpARY6r6HB nFuʙD Hp]0A#ͫz@3 F8+}]027Zpn+u3Kc6 lҁLYkkuxW3q3ԉpӴy&L//g7 })Z )U3J_jhm "}K_}?On %ζ~cwaŀ65!"NDx8 t\NqIVbCu[ʜ:<Fj9Vh|Y@ 3`G6~؇!\ʳN}mM(Fkڕelf+ih$D:񈝰̹u8Q) (AbxI]M<_OW6|c͡sf/"eN>9||Æh-:nY<u5Zr`w|8̞ƴx{kPB/1ݭ}}O'׮,e#Pxo))Wlyr!4e&rxp,Y=-˜$k{lS,Bʇ}Rpߊ/xpwIt-Pe\8yxX\ryR!;UG7HN4BO}QqO%Z+ P/:ͬtTr53En K1S) : Z%9Q(Tr礣zqb -arfVVDc329iOSΒԲD;g%ƚ>jex>p/6ѮfZ#%_R:hXY#HK~I8$']/N4Gp466Y(V5j NFɪh"@冁#ƒ^t}ZDyQ ;1¾ljVq/#jNަ#7p$ey2ve]_ؔp&fwGFP($uj#M?m‚xf`IkMWAn"}*Kz)vw>X!#`K:CNݽB`O>&)KfpfڲWqVT[r+d܍Azx~2c:E8]{sUHM\'t"pa9|aI~SS0q>$*?lV4tgb.t՜mH{qc|D\)'l8 w(\C!zt౶V>˽5Yݭh޾Q^qVG!nQCȴ\7%G)툐]WIa[vӧlw@`QL&ppݸ`/ĭ1RI^NJչ :)^=nhĚ y75%M &Y( ;6iQ=fN6$BHAdJ[!m>aٖZ. 'ie6K26]倐0 rD#_=;` Kn0ĺoRvݎ<{A 5'<Η/BY粀W'|0TFpLR]5"n\+:ٯ^9KP rh/k$mnD|7t0_`O""vŒA,{M_lʵUmDer$Ɨ5X[BF.%==R9^t9e D'b9 uG%O&P̮2яf@dT+~>)fv.rwUC4$1% ܵ>w:Jm*7KHlFxmIic/-IY,u%B[4RAc9CGsj  ~WܳToFe,OQ0K\K/^N^N;)xAg)>^'z "6L92瀇}Tѯs!PV @6oÒ*YqۣNEfN^#!5o_o9[qN0KMdzHzFLyw&yJG^ς4:gtMNZnD[ˏ'$PnG}d}>kto.ٔ;GZ$7Y6 ]Hmz_>oi `лoJp ڵ3x%ꮗ['7+W Qn9#sXw>=i?ߧ^*5cŇ%#E#)iF `w$rf6Y*)4$+0t^/C YqNa=%j\ Zrڶ,PoĀ~ڣ3y@N2gBA Κ@Fp iƶ68;qy&6xb~2;c4K@d <%[Pj7dRBL*[? \it2<$lېOAsvG:njmP=o^Xx `O: ȥ"7asK[L_ˮ#Z;$8xQ&fF>Ȅ,:_ކwa53QV" H I2FREKNw[3S}ϔo6ٙ MS5"cJ-  vE[ڨOJL2gbFg#oޓ쳵C+]By)h`g:pFϏA3ʟi+51w>5lc$qM?k/TԘ;2þ r q/q7̶3wTÑO>MYDF\ׯXyb4ioy ed<1}AAZSo>Iq:q>]n/k,^0gIr@un|BހMAM\Zkaaz^ ^L1piSL$҉0HeQߚ4űqzaGNËXDʶ~FwGptqbal4q\*| G44rJ_ߊI{F tW#[SYt-^/oV'("h+3jQ^ bzw!vY Hm8R$GmKQZzo;mm9nD>Eȃmۃ^Fܕ6 LMZ$7pdjfTϋA;MJOD|䄪nԸE?>!M/ nҘlL+ m*+hԍ -l35!WV&Kc F1I%8 ͙}LH#PY| !aB?3 L3>w@97w)/#M@gK*쵰`ZN F+N2W#!R\AIh:Ӫ9@TP714s@]n )ejBpbl9ogC4rbgs򦽀< ,SamFl5FTV)귐ӧ,Zj` \9CI nJʓgh9qηbulTGӛ8{?{ƌ:烵dM^8v[H FfdC_!ф8uUt Cӻ&u*ZDjo$_DKe|K[~X7F>xBl0ɾ'PgivFF#ZM&/r5V}tK>Y~Ap5e_ɏOЬRu9秠b&EUgyQKm>Tv-8ƿUMk\Jb FFLEeo["3tHK22"'(|dC4 pD…x{k [oi־4z#dBn@'ЅZ’GKLQP)zUb٫DŽ*A"#'u{x̓=ۜ Smd`A%/e=2G٣K+_X߿8*t|HY, mJŷ;! :4%8j5c`'>`\+Q/j)nf&9kxX=P}Vm^ ݵ D.Bl& O9Y杳1= rpV&Or1o v8"T ,@R>FS1ڻl`%$"8kIF_O=cIz{-rjH}#SÑMosVBLz ~(S]LA c,"w IpkG"scOHT@ h[A!AۨsHJq׾c-n9Y%P jk$9~i#m !&58֟Y&aBC25ݢY(pFJpXZ3[爂k/e?Icb,3=p{U^N&GԌWl/&PX6lml:s8xcJby4bBN;;T/&y_zH& Y=F7__zJ S71Ax9 e|)Œ|[;,iu){mW51r? c O^^}TS8&y4,8ʥ92?%tOI `Hlk+qlSto;אOMjv"tj h{gOnN vɅBG6jct[V*U'Dj)h [LÑ~bѓ0Ex7Emib$NK*Ӻ 0ڳ&ɦy@gZ { ]mα9g$ϑH)mbbM8d\0qYYRӄUI\xj@/YSPn>%zq1Zo(pBa va|7Z(l'FqG M L>/QSRQgF:x GE_Q' *%E1mTTdfh[qlZ%yGUa`‰0/* kMnCu{Wkv4Ǜ 1nE,ܑT˒$Y8 ]ȶ kME4^u3cUofKr_T?ƍ^h*zfB,58ݛ>Y-.y -9Lρ"t% hll&yC֒=shH匉|.=[w2]y [ $vEtKI$MCF&Jوq v a}R)- T|So׿rS-$yvgS[5ٺ>b]{UviO:C˞cy ҁnQL7XKe(U`9;7_:PRi uٵ•۠)h] t sF}"V8.UY&6c\^4d2/IC)2 1C a[1S❲jm .kYa0yd[&1H !@?M_X ۢSޱDDAi~n/{=,/)jUTkg6ɷ<W? v wp p\\D&9Dݏkwvhl-(uߩh@(e 樷HDt~Pc4`w2\@7$/8_M]'mj/;Sc@O;4N -{%օ#aܒ }D_ "8٢ty㶗>?Mbc[wM˕ LHq^d^b|42IP4Kמ"ߓ^ws'81?q)de+WL{ϝ>{xr6=6?lCN]yZ;pI R4#'N\9.;R於o:=!`A%FK0b&F-ۃx\"BǗRhpp*- `e@)Ƚz1eݶz.ƂYo +z,ɼAx85FE%Jg̙0%;'؋ >,kcQ>kKh0%##N1ܙ713K;Hi0vGۖ$.H|Fnӣp_G91>oe܀ht֭YOF=y8e}xYçPB %13sb[>b.G@tƠXX惪xtk0X-Vio5koQܔNk2ݍ%1epEv: .If2rtrP ȝq xh@*ޛ@)][wZ+I݉tu[Zo ebS"VH6~4<#|¡ .ӊIG6+06VUUHN0`tŕ~ _Jv3dU&aǪEQzHN7ȱ39eވ6*4)!@׻P3FwGoũ \X+'Y}" g]/`_b :ko{ZbLͮ"&7xJj٢ͫJ$DiM2%`V䲍&W{WSA"׻O.H=C֢>6Ӡ{ETö1#!ϻ`) 6i[`c!z3$K lݺpD+)!2XA ({+aS5 hȌضdm#ȁ PDB4o_jcr i<@w!jLj.gnU q.ٔ"U1yѬ`:n@i$__eއQ>M. vFDEy LR(AN2buD^"Ky֟NOj~\tDr$T-J_79 h+1LDϕV"B>ȉngaWS1-ˏ1!qp1[Ypq<ҤmY*w$xl#Z@CUʢĊ3{ e?p yϱV]CL7 =ElG:,rε'APE8k7_{ =<^!^jGG׆H?|IRBWJ*@ mJPD쬦< ZIB ‚uٶcǥ%V sWc)#67缔/ӦLq*qb#ކ.B҈Ppɮ HA[7%F|3FLN:2)ɴmnYBݗܡ8b =L$QD2jh7)c Rx|<:Θ ׍PP'Pd5hwq}|KGWJ(HH.njT3gU;/SA!u6ѼtbS9 vDQ6I{v/bR U JW"پjb˫ \hv~x"7+FN QSZ"v<ݶhP,f`95 CzΜ ^  tvF+mju͵pIxD>5gk@)P#Āf$Vxդh2[6m_6QS`CN4K׷n = !}hǯ lјKsǂ\Kﰕ] -ivjӏD?L> Cisk O|vKh&ur,WqjE%/1Z1:8R1hpL[u+1n'r`fLqalk"Zu7@{82d"FN"ߨetb:K>C .⨝B סau3P>ъq=3Ty(dG/wK 5ޘLz'kzz=Za3S3`L0+^,7i_~%ya<Dzf0p<.G7vu+ZzsO-4za޽DYo֕JhE<^1}Pnt%GJW=4T{MOCKOl R.LBNPٿRWZSW0cOܽK/,q0(gXqQP989 SFR+`3)/#Ae/&?VcG..݆|Py58xڷQ4?T\,tu3pxחpXh% J.G/!ƭ$"0w'c\̤m[=EYȾ2.,lw/ tP9pF]IUG!k=)nZ ܀/w !Pp˛, 2Y<2-˫V/#X  LbŪœ8We/¡@E b #P]U/MƯ`™ηd{v8103|?މkkUΩgPI% 4 q뉷;Kѽΐl63D\tJ\q[ڙgYKm}?};+]'qz1b" =nG\hRx$Lu`O^>-)-σ9`ՅAC7bq )ɦO yFQcI_٩GMXK p4/y]L 3??|^z)_m*௳J*) QHфƠdզ Ȭo)1P@e%7Ua7}z7&+Nϻ&&?j^EپX 2=S4Xw)p={QW٤v4̧MDAIWStKp]o;S(*Q' (A*%W)7|K]r\/OZш `˥[ީ_^ *tLަgslc|)xD`q s OUW0uךDA*8ϒv~Ez mf֔b:%^Hjf&,^J G9-IfKV2q JDqMH7`wex@2zEzֵGksR_'^B6H֗dcڳ'̌OI6%E)g*/Ey&/.3؄,i_9$gSz{ȅߙ<"YΧ@C6BdÐ%(VB8O+6EOv mat @n6J񐇨7^SJOdb1_<7Tecj|1_k ~GF/᎛mV0d|B=:YS9P YqIaIQLc9ר+i9Sz(; X-d#6ߴe΅v3=VEVa$e5!%ԋe0(մ˗\tAtVf[HL^~a <u7(nk_}%E4}̴< OMŝ ]- |j&/C6aU >fҥh`b*rYJ[Fz#hU5?2+ $B`1!IkgI;~q.>$Q%4Q5vn[{ݹ TA Nj (HOxݔVMkm^ӝoS)V hEʺGX$L4sL<_k^Q**DIcd:,!n0#7?]_\丣XdEǣZ Z{BBzI?gfK:.I"$ f%\El븑i;!d|Q}\I ErM-qe6 oDFݮgoM0}f\IٳZu8Cy  v<@B\1CזA(H:beƳj2kteQZK.ɰc{cO:T i~ps5}_2>a`;uM%`)ֱ|/Z%{25AB礶`D.E2<ݒ̡cD2(F),Gp˩Z{|5vtl9\Ԅ?{&Z&;ryU6ry!c/ނFV7$/ݭElG?&Ebe,4/m[y N>4PEBTI-FDt=GrNaCS@-H <-|k<(qPtS(r!\zSU_qKLwa32U 1|cqݐT ͆pJYX;x=˨dW"bo&|gݎ :w=Udwl>걨Yқ&vlD*vy%YEdDۺŹ%I2\^{zNHL؋8+R=b5ΒOGg[t pT'E6@c 4ɍX:+cBoO$1r+_c!qįdƬ4 i"0!paJ4ԧGq>-_\A>Aٓ@mpx]FRaܹ

<ݸn^!d{OrVEqc9[u%ynqȽut;M@\ه@nJweq.}:΢G?HP9a^bkGR"BO6Z4Z'0YTe;ƪc猢,*]#lLv@&<귨H$(Nڷ p";-GGF*\<>Qap=12͔2EN_v~0=+ g6Tn<7;Jbv}NEѓVSm D$K(:<. aõAMT[A Mv<4OS8L#ZG+DQB[ XvwFIz SC3>rukyhҁ`k-*/*U(؈P/tctrm3iVFCܱ_x/khUARzDa}[vf 8cSonOްn(n2"5P, 'dCo\] AՁEh?G{C{wVz2A0si=1 ZAu{gP?ڋ$]ˎ=L8Rĺdk r&:Gqc]Sv&2=]Sg5f_延D8:N+]B;m!kQ.f}|3"ZdW؅H,FG+G?ގPT= 1@KFtkV{tNR]iuaWFu42'daXR+tnzGhR̋${&;Mځ `ρܽm=79Kjksa*h/siY A6UpNvnS&^ʉOc7Rs ۹*WzgقhO\B>6;xBsƸ ,9c#C}VLjKaӳv7 VŨS`[s촏bn4ԁ c 0y~ćVjrxƦNxu*| :B%]ݿߓX;d8"FtH&ӰG=0 n.@ű 81ayAj҃Ya%0sqb?-8}ʙH&|Nlƶ冬FQOY$XFMĴ:"1w64&1zD>Ag]]YqLn"ʓYSk7ͦCMny;9!`+5#Y9:')֊ðn}7T#6mFv!~dj,~z4 e|BqDY_gOr|@5 iQUǧXT됒 -[RTO`Cȓ7v|&ȟvG_1M #gN)4ʎؾB}(iɞ,f, qRa]M1~]@s"$WUʊ֜\4B0d2}LIK$?;uUx\E6!)-\A#Lzte@#表SSڼo+oL+0&q#1#éM.Kg^ t%ԐS*QIIED8ș :F÷ĶDzLA @RS`6zFlR@vwfO]pqO?E*+i>6}A YQCE8Sn o2{@K|\fT1Q2Z-HUM1Y9@c/]G dkSD,v'xy])$Bl% Mn{L[SlQ)iJٮFj$='*ZNk7 s0c9<NÒYT3֚_zۗpn8 -OZs!C'D(ZҖ 8Xrpg_Es8ooBm@zXeG%[w]}K}^t#?(QĢ%X[Heb?F>H_ٔ+yhb<к߷?rF}[U~vb6E6ݏ}xB#I/^܊Hib.'8mUJE Uq] %&tj6+ovk.M&Qɹj.hӡXW^Uxƀf4*y|}> %)B: Y,>h{Z\ s̋[|V*I:LoØW剉:mO07"f7-+neZ\w=1)BiZ^_i-\*;d7Ueo^I?JGFIpqNc]C.}j[T܅Z\Vw(ͽf2@'ni΋ Gasr,0p&hHm ]e!@I/ޏ`` =8j~dϸ'8>CF7ÇDA=o9: #&,`FXtiPkPG%TzQuuz u>bڵ&%,qE)$SfM0+Ax`mT{g.cIyƍ奵>EѲ(AzU7a_b!jJ)NGhy%y6 ~tLV=94^[%AE{#Р`$ڝqbFeb'RUHv#EuqzXGJ ܏9T'/fQP/xͮi&ã1@6lvؠTv̳jx Գ@˼O=8U6W,|Tdgֳ7rBȈ9n>0L)9EFK MVeonESǡ@w \d}b 8OpMj.0[Օ(_kk8( KdY.'Lrܝr-kl.dzGYξS9ࡷSn=o0R, ~IZG\-HMvΕ?+ kF:nEpznhLaF K[#eW7I%j3b{-i2eE@#/ħ.nɲAJqK,4݄-dsJVl2=(|qTSB(VZ:#g{jC*Mq/ nu,aꄟv,ɩ7qDZQ搕|7FNibV6x xgd>s"(oZPzcC#pZz9 j'T1.cvOБcI+J>Sm=1a4Sك񛨽S.s澪}0 ӅIo\ra%usλ^S]%BF94:2%JrTc;fiPG/vud}jHH9 مoe95`ĵy >y8;ScmGȐ] ZwdĽ87D->+^&0p#L7X2dlT臁>-mm6Zv (:G>[G%53)z'-/ ve2Mrw}mbw4ɞM>MXab"tAW٬cy>06|a U9A GY 9r-QNkm~zI"T\ԠO̎"Τ $GC.Q=ԩ [I3%PiGsBWٌи(;ɴPhzY\oj)ѯ$p62?Jj$)mTOV?D5εIbmVVfdRTX( hb\Ws3%4IHA͵Ku"X[DZ;IpOf F/8 31Կf?QIFeݙ2H'/Y!KPВݢ-+`Ik _5N e!HU=H5Z{~]jK:EWct̽@; !nӧR/kZu)镔mݯyɗY1/~bre><$ SJTX3{Ot; uow^|#KdvHdgfUJRx727csD9ߣ<,i1~6]}Wh@a N H1An?;i>q[|,v YbN֤`6zK9޺,XF2 >fՒ`K$oGDNTZDv=w`*DE63oq +onMRy$>P>iX: c1Tɦsa'& O .)~ & TM pb= MoʙSK[dS/.kLμ~` k\- h$.YfaJ ݷ1 $_ä 4X'=hao1`4 qv?cCd&cͱI[ q=|.u돾.2Y8P;3ywj*"llj D&(wN`R2͒T*:*Do~`IpӉ`(ЂrY;BKѣ s/&ؒ@l2j(^i"32XTR#zQITzny@T<00bCYk2u w\搝WM!uȥҶ3':ݏͤ ^: '~c 70ﲾυoP[Cju.~㾣To"ϱv٤R gh\Dd͐ :;6&cנܿ̃SV>ᎴEn<0Yˤ#`)BzEb}DcnFg)ֶeZWҢezIGvƚ wû]R{I/?po֗ч3+ۧQ 7KѨ=ݭ_pB,-d 2Ǘ{tɎiwY_ĉbn6$'vRK/m XtAsUiw;ǼT9*8tE?$~LZGCn"1X DɊ'-K ąζVrf)m1D6I\*! 29|^„Q3d' ^3F,GnKE@{xֈ y.uLy\(Ay |jKadmԘ垀t3\lu|Z@M3-,x&? ] I;)BL tE-⚑䮺>j9/G'Y^kz rx؋S<{̘,mOSLw* &T&tffX]ay(-|όaV Mٸl tslrYhp ~2WK I'l.4ն7@P9zujL}bK~!b5ޔ&| +e/8rƒ-g&9^G*m?E8./U_>~.95%1% iu5{uLR"LC-," % 9! EJ|`K#ocr1d'edOhĀy%E(0ԨSaa6f?) 7A˜k偔/+"kZ@, r狸 "}b2@%n #OʌW0+fB=呫?*}pZn -$9B/@>5Ы BoN%\2_06=gF6꧜jDRls:B(L\`2_0ZRR#Q+"^ j~0IΓ)8CD;D+hp A78fxTP$}Ň _VY`" ),QNPo۶ٹ{X>~mΑ'#cGmXY݁(^aޡozAY$m.l:|31?<;yˌzg\zRWaSNz4I<9RAu!%Exc; BDh7.yܒbĺ5*@^j P~Y]@.g8 V |5 -KJ7z[*cY=.T:)5N'cT{qP񖩓"-*ɀ f Hu7,\ & 4_~q/&]r !ʊ1&<WLEzsh2&&3_Ai xжj#^\#KJ;ceyW.]& J< (6B4 ">Hٗ.i\pqW2y˶:.D x[p.LQH*_G77#ZE>%Ud6Xgc%~:GԂ4p>XZecڌZ%"zHuRNC[UIG]ӿ+Ԥ2ggDXWpq3qOva}&= ҈zI#YhJt%W9B21m(g}tqgB#" uU_O4|fC˯fH mH#p8%#6A Q^:~ :˸6G,i'QՌ=&w5CrrjCa(p45POb0<`Au[R (uu0Q>|W3y}MJ곘FA7 Ug!Ϗ-`E5"ǘ;T sdE~דtf}j5.YR `U9ѭ!}TT.LV~=|.CnӷeщD:>nl@'7/ BGae{ ֺĘ܎d_I"|RJEckKH]")=v.`Ydc{2!A{ݳE–7[2TD3g㓅w(?g@eتx&R !rNzw7`ݚYV/N=zӢQmyJ96; S@%AҺ [i# gu*9[+}9, Fae6+B\G ;Ӂ8-i8Xdv\iTT/zn!$ZwC7JP j O { ڇ_:Ed'8`^_pbwhQS_AL˟OrIjH L}‚i%MT`\lJ6l:ί6x )ֆxLj˸}T{4ATi،,.vv+G`Tٹ3 ]<`4Ns|}|_>% sG‹{m2\\`U~t7s(!UイMWH\U(XR4fm4&EؽV1Y3mk Q`𑗩Fڙ`7rLBq$ aqI#.-#`%`!:Pib-c8I`bL뗫RZ1c`i?6%}8KIYH׶BAoTxPbF23}Lc/8tJ%QWp| &cZ!0%(U%yļN>^2yę $XG_x* 5 *"Q*tiYX%>0V.Z)=^n`bj{]P64QiipK3}[EB^2n^;6^A]Vu͗^A{%Ch ;Z%csTx8m㻘3;UB߹ Io^iF(9۽P\J 0d<eIH߳[`Э_9m ́Snb@X ]@9IŮk#occNиP+pJZ(u$M4?y;kHjJ;+r"yh!A_zdc3d}GSB4:l̵%_ɌpƊh8N6HObif4Qxb3IhEy(h;$ƍynPTbM.KtZξWIjWAlG<Wc!#J,ֺYoP2 Π_pŅxNz2 nH}ȟ?.;@wp64ltBSQpqbx rIYP$-Ծyde[ 3y䅥Iir]p(13\cLFC<`N X@= K "L P픴%2:~$6>HԌn8wt篨:#x@;r0AXiiBr&Թ74 W)eL8Z56^pBWMΚc)dr#|SLpC/FkDOوَ|mX .?~Y} gMLq,lq1+I&"a] %6~=GrLvnAtb#ȱ*-[DsMEB.~ޑ4vmF0-l?݈ I"*Q:5˩O;v>nZ_^7Ӧ vю,| kVDp&UjMI (^< #rM^XH;\DO'Y0E+VuYn>5Yw:NLpT|QW5=>~J?mcE3HO`ꟺ@1m ^I?)b(l,6 nzZV5} Y;7_}_UE(c" bɗp{CkoS_?FY)Ttpz}ZG-/D K:!<\kA2g{U9 wfhO]`_H AmL[0 >q|CwV#%45-~NO5 s-uXHX h= rMTA|Ga!Wє,}>2HË+\s6<{b*0Jslp0Cnm{6o"aSV>)q"D9vB[E*N 4pN^^^7љHX:nCIf zjpLPmjZ1EΞ׶$HgWw9lO6U MdOc 6?'-RHQp=<  #[q=fhUYZ]͐p{ݎ&ʤ)P&NJh#l)Ax$׃XsP@h=J[ŇDw\ĿG [z r>$:zJHVB1r=Bܺ}WLk"3lȡ=yfτYfT]G@P`K9fvHk,!ca` K@ bNCE|˽.VCmL C|?E6ˇlSsqu !-=⨢2!C-I_{)ANljC@~+@77$o!AqӇuwVq`DOd M@tcTS_:?c&vvJ_խ@`ZQd2'fYVEm5unFH⏁wbL ~lrlBv hꇴib c2tW[}ihvnwbHl5uMuK ,T vC襇8SW]46MbF߂t4g*s2Q8BXob+w+4R&WY 9֪s5 d]E] ć)q/0 ^c RWƱ%,sH 0Pήj2,\SSҌ8$.\zMC ^FrLF* GB~[Kw0_e JC==#{hWX*Ϸfӷ( x%l` <ؔ@F߄NHǑ2MeLrø$5:m(l9Tt0x&w]꜏QdW{3뤙(n弍pQb5O9wN/T-y҈66THU@Xny̽ Oeb!}й1+tצ|R՝ZYyma ]]^% JO,!~pad?EԩE QܔEZ0pK ȉ`{HϖM:JLG8jw J`P+)6&P\+/)>˓FJʯeW|^\]M,}(eϱ42`z挹L&IlXgU.nƍtcRsHöGoMxKMPBJTyIB5{@?H&KlS&|$1u+7 %ax~%BD5ȡ#NC;dtɴ KMcH}g :aRKF 2I+ݹFY`~WSd`^e*w?cb'm MiׂѬoJv0;[g*2Y#Ny*;JMMjP`ܓIzQ~8vKBNi2*1-D'UMEx |}'d,ոDRp%9`$s beCq<.YKy#5jqT],z *0DIH#\W(ɺk' T&x.9ӳ3n#<mOz8Ӊ+k c-mFc%XG3D!OFq@]M{OfldINcczp(~k #\e?4"t+0zK`S"Ikz+1Xy rOsf;Z{y$ 2*hl*.t"2I2XOczHG JbBT2(i塃jeq7~%?ǚ9#} S0P(v9 U<'8-r -QOHy}S0nY| Q[2{ ϔׁ ơ$fضYxQI悊 v6oh?xJ'c9uKÿE#p+9*<ltxP4P3E}m$zS9@Vp Bq+_r(}́%Qؤ׍ A!/"#+p)^%:<>'^?dsbw3C\o[ѡׁ#[*A.cߍd<}B6&}z;s"ϴ(\O1iԾ'807 =(s-Ub~,+[mx˽ըDВwQcR=, oFlV\%/E:B1A"KPv있I ޜ싑S f=V6zo=GsίvHS YqX=z3[ANqTx<㵔pYhLh5dzv;r&q HoslkjS+y`gUuiu꫺`ǟ\'L{d披]#›e>ua[,`>4HĶ%+O$8.YP3bӂ&Æ'!~\}_@򘔺p<ԤFML(TTiTliPjM =ʝSk8ʝ] UvNg*:׽B[l! D%yX%{V VlܹLU)r*RjR@|_w]&mD|^iZ 4WyXZ\D4&gRB;NcFاZu@e4S<~ƳoWQZJN 4ٗ_ž-\{ nmVzu}~0&5 %ê VqTxYPn["1$1պťJcd bPdV4#EU~b2d=ԟ W`Of" HoVz qgo H--NAln L-s*&T fI."?AyfVFu"3Gᒗ/3s_Ha =j[[Ϋ'ڌcCch sixmɝ&6CؤSN헳~EgTv 9d(*2qWRG.D.o2U]Pki+]W""/uc@f.zNSq I<^I:ܸ۱&;n]/#rid:;4O2󉢫$H%%n0|ʭ'#+|b?v?炥p:ɩG{z8ZJ. Oxz*+˙*j 7^%C O@/1Ύ&Y_bw)Hjo?AȷA=$+~']lCћhnxyb\ R-L9niMvL4_vF[\ӺgþuJ- XADg?ࠇAvN(hN3nBsY%dlB^a‹ 0ۀ&ֲS8,dqU3֌- 8&%ρiD0ы*yv\Abdg4$ut:wl%V FM['f bnQ+ &^yL3[6 {bkw,ܥD0ީ@z;O:j*k zRZ+ hNji7&o2兊 ]He(qv!ī*.l.(AxL=toɏy:Qh:x> Q*+}ok: !v~J4fY 7Q3-8 Lc!>\A1L"m/HV@ [zXi3}J~sq@}uC_+Ҍko1 V pslK٧UegAa< RK~poJ,1Akh( @E'C.O׭ WO:~i9*u4lNc6RR@#Yb6;ێtL Zus*[Ҹ} +EX $Z^wY~,ê ۃp<v(tH[Pwn*$GFe.wg! D.<;(aIJ}z)o"݃N =p9aW_.E/ف?`%bZ2(ŊJ&. >$x5})mUͦuc+K ƶl^SQ TKC`[8ݿhΫT= )mwbUJ7t_>A6}Nrٯ/, \ˍT/9 Gr$`Câk9U|d >3ɧ~Hn`pM`/9^r# +}J *^l1n,2.Ȫ=IJcrk!ǐ_8eHG"571IΘH5>7.c}j˫𡏕BW qhNe>OR/V?/U8M6#t.鉄cp0qV7$Hls:fqXV &X ;_X84ԸڍpM{՗J8\&갆M5mt?wsV("\ܴ:x-1, d>z=[ vG.^TfytT3Z FٚT'yfVLH bx~I$bׁ?.?.'ReCo+7Bt;UU˨ } Čɲo"ҹTPp2wxg%^(΀]y= wڲn@&,KA1  +TODžy{ӝ[Q:v@㶯 di Wj'_roފ#g66 `sGژQ#ƍA4mكmaJU`s")n!Y#ֽСI_!=E_d5MZsQAbJkFqO?w?<=r&eS =;lӛd=t6&O*opC0EIBkzD$U md^j 1F YZ