sssd-tools-debuginfo-2.9.4-5.el8_10.1 > 6 6_6 3!pQp)Tξ7]mtZ`ga ]mtZ`eU<[I`IRR d`zcnєmLQQ$wTP!X /eBNh#~hܓvgycN^_"VcFkj:7}V1H՚Jd*vD@sghHl3=dGk9b"v#zn$g0ӽ$2f>:%M!4޴oؽNv8,ƊBa?5dzXf˗D Ey$,=uEV{YJ_~*` r6:WG3YU~+szfio$_UBb3ͧ|B|ń'ut;79{ϭY᝺هKaηa!?}e5ۡ[[򛀓[y7Дf_\ږ&oqwF)A`SI~pӬhT ѰB6t_)5 "T:ն bHn)#,80a3a1facc99a6f6f8bc2a8b44d3eed22569ccded730e03078a454e1f94405ad59112288f8cce7d0357cf637e25b5488fd9f81ca3!pQp)Tξ7]mtZ`ga ]mtZ`İ:M2=}DY9 |u7WuqXiu;:EemVfK{QMu¶5 Me tA& n %lrmQwP-+ h).7oY'?w p)v}H&:hjho8O5y9jH<ԓwoTIxbڪ.J)%9}  ,ė+:aQI\2a5&<dԋYUht1rC-lNhh~`IWr{YZFqÿܜZ!ʯE i?Y^z>֑@Eo+joy5]ɷ TB)${`xb]+RtXl:WKIl up[FSSLhXӸJ%yn?`v-nvܐr:Н~}2Iy!:`7 >p>? & O48=CJ hz  ( h 8 (x(((U8\9<:bjGHI,X<YP\]0^bdefltuvPwxyHTXssssd-tools-debuginfo2.9.45.el8_10.1Debug information for package sssd-toolsThis package provides debug information for package sssd-tools. Debug information is useful when developing applications that use this package or when debugging this package.gapord1-prod-a64build003.svc.aws.rockylinux.org KojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxaarch64<K<M<QX HHAAAAAAA큤gafgakgakgakgakgakgakgakgakgakgakga1ga2ga2ga2ga2fd21950700129ef2a326968db33d972220ce1adc1be1e9ac1eb9a6387a1cd9b3b1f369336077fc4e4841c25e4d11a0802540c94b75f5a9b99a20ff60729ad9b43c45ba2db86d9592317cbfcb4c18a3b76c4fad5d25977d3ae7edae05f6032754../../../.build-id/5a/d2cac055c8b5a74936299d72d135feb79b27a1../../../../../usr/lib/debug/usr/sbin/sssctl-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/8c/8cec9f4b72253fdbb7c8d3af40be59d9fb76ac../../../../../usr/lib/debug/usr/sbin/sss_seed-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/c0/7d52f55bbb019f944dc767ef7c06c0c568cb61../../../../../usr/lib/debug/usr/sbin/sss_override-2.9.4-5.el8_10.1.aarch64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-5.el8_10.1.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-tools-debuginfosssd-tools-debuginfo(aarch-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(aarch-64)3.0.4-14.6.0-14.0-15.2-12.9.4-5.el8_10.14.14.3g@r@f@fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-5.1Anuar Beisembayev - 2.9.4-5Arun Bansal - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-67671 - Label DP_OPT_DYNDNS_REFRESH_OFFSET has no corresponding option [rhel-8.10.z] - Resolves: RHEL-68507 - sssd backend process segfaults when krb5.conf is invalid [rhel-8.10.z] - Resolves: RHEL-66267 - SSSD needs an option to indicate if the LDAP server can run the exop with an anonymous bind or not [rhel-8.10.z] - Resolves: RHEL-67128 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest [rhel-8.10.z] - Resolves: RHEL-66272 - sssd is skipping GPO evaluation with auto_private_groups [rhel-8.10.z] - Resolves: RHEL-66277 - possible regression of rhbz#2196521 [rhel-8.10.z]- Resolves: RHEL-39085 - [RfE] SSSD Failover Enhancements- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) 5ad2cac055c8b5a74936299d72d135feb79b27a18c8cec9f4b72253fdbb7c8d3af40be59d9fb76acc07d52f55bbb019f944dc767ef7c06c0c568cb612.9.4-5.el8_10.12.9.4-5.el8_10.1debug.build-id5ad2cac055c8b5a74936299d72d135feb79b27a1d2cac055c8b5a74936299d72d135feb79b27a1.debug8c8cec9f4b72253fdbb7c8d3af40be59d9fb76ac8cec9f4b72253fdbb7c8d3af40be59d9fb76ac.debugc07d52f55bbb019f944dc767ef7c06c0c568cb617d52f55bbb019f944dc767ef7c06c0c568cb61.debugusrsbinsss_override-2.9.4-5.el8_10.1.aarch64.debugsss_seed-2.9.4-5.el8_10.1.aarch64.debugsssctl-2.9.4-5.el8_10.1.aarch64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/5a//usr/lib/debug/.build-id/8c//usr/lib/debug/.build-id/c0//usr/lib/debug/usr//usr/lib/debug/usr/sbin/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.7.0, BuildID[sha1]=c07d52f55bbb019f944dc767ef7c06c0c568cb61, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.7.0, BuildID[sha1]=8c8cec9f4b72253fdbb7c8d3af40be59d9fb76ac, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.7.0, BuildID[sha1]=5ad2cac055c8b5a74936299d72d135feb79b27a1, with debug_info, not strippedPPPsssd-debugsource(aarch-64)2.9.4-5.el8_10.1utf-815ed2f9bde07407608844ef3e10da356d7bdf3cdc66d134995ac89cc7aa0b71b? 7zXZ !#,H!] b2u jӫ`(y1ϺzM:`4%62'Ͻi[M,`wLJwJ)*|w |c\;Q06 xuVewPu=$Ձدf^Q [oʫUa,Zp}"hޭYtF).^P~g$%CJ>NZY\gNM2.JEkl_b!mKN%Nbk ܨ-] Ȟ_=F!auwH c<Ї/BV{9p:eiA':B9`ԋY#2o4n&yZΙL>jϡF- /Pbn7@,TShsٞY?j“9&AԸUb_`4Ji=Q@RErrnp~:̹Al )eO]^ 1_\=GÄQH¥e0N^6eP?X f?4(\5ڰ|otUfHD +APg%N!Dϲt$(ħtH5"5D4Ǭ-LX(, YF_˃Ŋ %t&vqC ͤA)/i~,Hw}Pgjne* 1tBHEPf"9O:fMq%39tu MUK_Qʰ;؎h`4YͭASMmo1) =Lf]a'x _+Ezon-/#Dr'G!.N]LaPPlKO|[u=G6>y/<{אw@o1h=꽫qlgx8qhID‡XRr~`=TV19tkjuo%%IzϒG Uf!6C&{S `S Vĵ q@-M8CfFJWԢo33,M@rwLX6o1n6M3fCc ^!jYD3ܖCYRl%x vyv,FS7i4%7 Vz(L"M:LTui/1s +PLiQ#ȡ{XH(A©H3گopVRy;rNmQRwy$fs(ʃ >~J˃g' ==CI?Dm xpxy|i=:<,!.eTUgp,< L 3*ck-~V };r6q,ѳyݗ.V_S,KIE.-&7p\ 0D1݆De$&⫍{ E;F":8ȄYLΘ桌? /.4i$Mݹ{-bCɐURr¯arb(&Cb!T79q"P[3jpܲU!Kbwyrwץ=V~| ן+rI#ZdLM)? E'<-O,BfibN*rږL $t{^ 97@CF^oI+=ߏ,¢ wv ->! %ڧـN^$jHWznKFpR7fz6=j>xn]hTXMGy\h}/~TcUص.N4ڞ1嚞((dKIّQkAKU["`jtUEJЈdDޠsTժ>FMXζ&×Mvdy aZ#klj=Il("Z0Kh",p ,!pO <܈}x]&) , _=Gv=Ƽޔؖ>糬 t2us@[LxY`8m5Dǜ,U ,}%:;s? Da#EyAuxU.Z]6a.^M/$\CYbyP 6?KOm=K 7@Z ܇^*kBEEC-ͻ0m,9e K 6t=9̯*LYJqL)|xmvҦ D݉Je J,tÏ5Eomj+䥑Lމ{=>:ǐ`:Fw4!c_Nw(@+8l 05D e8W]Pm85mB6cGZBO. 9]*jf|q0GK PzA~}r~Kzr/FMFyqL>ypO7ްVNcg1{;Pt&m?7;`y4nJURJ*lC೬c2u 1 t[КPݻ>͑S, OξNfaur⃭Z#EJ~fyF;وfal Yj<~ɶm<<~Btu5S(t V)),X'IAo ULSP|) pЩ(lz6'(_D8s P[b {Wn^֕5A%p[ Fs_R}pɜhgȝPDV T_5%NQ+eŞgs!j jmnMwܕ+ps<\wra2&#K?Kp6@fi>t砗Nֈ=%'x`Kl4~1,[<%%ud>nqx8.g+ 8#7LLW,|,6<ϳX@ kYʙΣ3RhJs("Ф xO蜹߰Sp;jtխJF°${48JcչtT}?mȿHC2%&Y4Q@  ԻŬf"9#S ݓ$u^].<Ɍ6kܫ"L.u@% xД嵯GR Ӟn.[Kv3{fxϝO%,ODc汿YjS 3Sd9%TK;^D)/M D x4 ]JH99X( yG.@YL/'{KJ_StSiIy% [Y n%y(RH*?FL[ w\/ Ba&ָ1ƽK Qrކ9 m*h9#[3&3A I[Q=%kP_Mb. crݘ_{,k_\2د@MA\@1S|}8_DŽ@)X;  (ln*v^`1+rǟt u3jӽ w + D)t-f6៌o67L[Ps2yrv/Bzc,m=|3K#y+N1P݉QW~A/.X^x7^*԰p ǰ^2lE!W5;7ڹϾ3M7kSBɾyWNjDRwS|Ɨ,GtRNz'i !TnUQzƴTD NJx@O'`/.?R(nաc3j}8Yh"wqCNr2iLy mNA}.nxY4=1@df<"?(1 hW^pncBt® ښ ^y/'`sϔE5S?y_qn|#[FP->򤍓)gIY71]7m7h>?&ĎT[e5g( 4hi*mgW+{a4Ϡ) BOd L6^da]#uK Nb< ^Z ubMy;R3.E04ʇi_yK(zPXcH.rT[Gi$QwaBIC pTAԓ%U)>Suc0&z [x O $p_9={fαq3^0Ma >4hR[x|BX{n1!*@.fu4oKД=?8y*xLv@(66%zi7N! 5Ȯ$%/)<]3ê{s ܲ?:3ӷN nEr;\ bô -CWpS n?B!3ye8,RŒ;7o=Mߪٿ^҉ P}{`kɧ\ <_TT BJɚ \6,8JԒr7N{C[ biv?v݋BLAB^Jr"S`vPՠ~|D~7ؓÿ =9|½N'| ua]G3t1PЕۘu>a``ԐڋRWQ=˘H~SS7F>^~sW6s{&SDwOI4mߩ'Ȇ!y>RO4!9) J6vЙ84Ib JI)J/8VNOCB2:'ҍ|!h _{Ʈ5~?f\QI ?sj^ z,g68Z}Ъ,憖 }ڟ2/^l0tv@'/fPs%{Wj>JOtvxZAK,_!U~/ѥZtцOT XFl~>/|hQ|`8'ęE Zi~LaF2 ooD֌8"]qGЧ g߹  i:pp}=E.9ۓ o45DtM".^idHx+fU׽v"cs3.mmoBeWM a'iL#I4&n7坮18Ŝj#؝Xrl| 6\Hז 7}ulCM $asDtXG,׉] pWK6nm2brl%gqov7zcbHNqw\jT̺+4\R-~A!g̿lV֚'pTCp/tbMÀ GĜXAI\_3I];J}"_e hnr67,1@#[\*;x(>Ғ\twȠ"TfǞ:q'UZu};|3NwƯ,jk>P(`J1vݻKR}4)~p]6nsNx:ff3t-l}8#(^Fw Q ӼIvg@>ѝy]ld6(Vo!wVNU2̕bS-a.e; [&e3NPA[ytY7nImVDǏw.D v&`@qpR 7Sh ʼ}mS3g 4* ;/q-fC0N/T`M8u~^bBmKCrZLG,(;gdV+e~f/a#sD\\.HA: X443Gz΃,"4eڀylftyN,{un%~DƸN56n2K=8Ώ U!g:EF8RcBOXBQI,r uI] 8n'#pmelT;U:GL!̨Ge|±t7͘fghr* :w]|Kl;,(?\o۱WX%x겉7~wNHDvbuhPfAilV}M!;u$s&M:A(Tj1B-?c,`GqV&9c?;7V 04ޕҲ^4&n:_c׉bcɛѡ!% hd@<ꡊlz,98凂${.\5 'EqfB$Q)nǝ YeVpL^? Iv)5)5 =iR94G=y^Ac*ȻO*^^mn`SKe2}(S7 (s:!؏P7DW-?oFѰHs1aftyrzL #\lyFoJt6MF_%>7gv&Bۉ1Ϸ9>4N}Mmm~c_'ͅ؋GՆ?x;DTPimmNXZoڏmv)Oe\6i|*+|q]V&|M ٗ(k&c$mL ~z(ץ=\W= ]E*t:s*WW\}]:q͚_r[3Сʏ(Ur"ry vWQp3'^%Զ?9'"[fKqvP(+ECfJM$(Y*IIEP Iۇ8(iJd2[% zH 7ڗG@l>|F܍}&gFħQTkֆ[?ZCᗦKj@B~X7.09!p6F'? 2Mz(3=$i @9r>-? 0B*@ q $8{sU&^QÙ4g JTyhnŘF%Di#{ƕX@x6u)`=l#*ln.zfq'4bwk-rdE_Xu`Q1V+͸ g8"@~{k[5X&߻ugT( ⺎E#;$I ^*'s [duFo fЭS &^_Sq "?[HdжaE%/n+`1AB:n c8BnB$4/Yl@{Y'2*a$u<3Zn[ҹX[ rid\c:DR8/FJ:^{r^Mb?괧F)tCa3k.|k¥x&G9YqHAnImc"Biud\UeHu+=ʂq t> څ}1]E-L<į>Ijf;ĔÚJZGDO肘&^c]bAγYApY-QJ?̓6@,PD%m/ˁ kP06s!Oˌ!(Q 3ڟjPS_;Qdk=`o{-. ÛH:+ӌ7n!HD۹LT*S'iK)L`{5=C΂[mcί7CJڻEc0X(V; (URهld`we&Ş9 ?ZvFoNcp 9&=LzC]XV`W,v"]2#1ѱ3W 'A ƝiRmk14]͇t /VONh{#ψcyD$%7eڈ bESރIPQ$LGt >+Sp! qRC LȸoP<5.»M@:8n{p&%t݉|6- gW9HYg؈2>SEPOhcq\jN\Ǿ1k}v#Sz\DYLDK_B,DAݺ25Wo)ro, ^ %\~~+ܲ+p^3.aڊW#+jɥ8/W0O[DmiB-Wr@׸`jbdEJefrPjd:N{vkbA%Y[Jzwݔ%r$ƴx^Qx(7/iRSGޜ Uڭ,*Yn'cxKlvTH3}~Y^\z%Sy1c}BF4>)Y%:Qmj5S{ޖ?2޾E^B'})ޤFJ1x N25-\%pk6-o-/Iǔ#33|&j5fdލnڃY_B?ܯ׮/Sv{O:m{ 1KtX?A;mLA)η mػMŁ ѕdTX8C. [Q77B쳖w>bDQ"k)Id[7 uY5~6QU ']_o YFVsIFs=ώ{amӁՏb &B_ i>b7YUr~+_: O٬;Jd6ڑ>hא%E@@C p)RBj8ND怦J!]"xҰ+qvjwPe 1S|mA*4|3n *1WUSֆYEAj,+7IWDEd' &b8/L- 7߱5weIKAFmHIaB_94[}+FɕuJ[sbSjf4ߙRDF> ~m.SɽKƦZ:҄+x}=~*$i]#T爪s܂\W /܈2'jzW}̈́ 8`AUaeByˊc+iٙo x)CK25kMܢz]E/,Q61[\Y ՛'|8Φ?xYQͣd$NR+IՈϹ;1 xxR{~ 7%vmWN>=2BjB=]83O#O4\(;dtr%m7@Ye[v]`;f =MBI}|te+رZ-OTh) \X/ 2= NH n|hCŇ[liJxz4H3x~DE 8&[}Qge ,fh]1^bK)Tأ|-zASj'9{:>$U;3y"ݰP=y#Z' l2a䫩Vy~bAVom眊F7_x:_9pp8jțJ"U]+ԷyBtZ |~-\bl'qvOC>!44;TY!HkKߨurf @PWtJYZ(zABL+XIZ:.{L= 5R*aBZ +$m 㴃/ C"Fr!n\#fhaDW-󏛠3%f'gzg!9wz@9aY8!d'] Q-Qv J0Xgn  !|=?4 ֓q~vR}~H(9arVyfߡÌwKg..<pn3S'=#(EnD|iVm"c}4n5b2O=9~/FbK?5TCv, "ރڪBɺǟE 6W]~ 8n}&oJSb]HkߎY# ;c=y'0ѻ]zE@~芘/vZ3gm(JU#3IIL{3f^\ȿ"7DI7U(QG@iaS?_sP߈S:)4o"1ϵVԾ5(q$(仨|A9UG}<;%ܞw'N{#>zl(Pċ?|E/%*0 s.ՆsnAռ#{)w|2b?,)~s;A~q+L_h\u5 cGBք1Lρ/wdsy3K =Q:J3[\",RxH3ArijuﮠN3n<~񞦣hR]6JauK`<]T?Ir`nC"w,l' :U̓=i#{8vTb ZQ󧦝xlG. l2ʢMRwbbNRn귟j8d#,Ƙ&dY"`8Q8HZiEY3@oCؾoVhN@ G{/gvM,>+Gc`qT"hǠ# X~K}>UGR96sNDMԗ$֣UP/c00,V (>+_o8ghw na)Ot234vv2gi,J" h'\'236H/BidKpBQdbvhnXcV5'feu t[~lݖ D\{Y$/Z5{2rb?,ӧX jۢ@DXR"7]u):k9Pi PO};YIP=LET/F} Ea/fz/d(R>Sqr9=CCQVJ"9orV;Jk'd2)txJ]^h6 Ճ{Y-%*E!$8豃Vm 0}\]B6pN8CPXNԸ눵㋒jE,u2٤5⭧Nj'fGȎj`^ڇ"t]ģB֭uԡ9i}-<]m1<)'={]@Jd?0):'oH5ZrAքML.L~'58{_U9o-t-<8ڽgq+w#) H%kW#kJaK3T#QLE}FyP|LЂD|Td?9W* x3"tLB`7`e:#]4,HHt 5=;$؟ݯ&㋇yA<[igu-7)Fp6Dch52'ajO&\Z[ zė’@yU?ak\ x1jCKh>}b|}~9z ~3ax{JWP>hf'jEL%gG%FZ<,k,{,0kg4J|Wge`]J:h6+03E_$V݅IG -@yh, eAKRɃafbJ5b̴&;}\n7|xMp=$.GbI B- ? @#GE`ƒyo¬YkD22N / 2m Z7bl%I% gmK+kjxЯAKr{Ђmw0?NTj@)i|iyLĭ: fa?NEG |PU[rڍ# ش,A9XgOG/nLϞ<11:AKתJoR?EUΙ&?}F-(㋻m vB[Pf71Yόxi؛ 8@ZA%@Ϩ溝36$ZK?pXOq%#[J{𠿩^]Dq틓 O&ġRy1|谜Py4Cyвbcar17zS 㕼JY9đγ7$޵CK4g&g@,[@_! r\9>4Um(0Եs\\Om997zCj_f"#ceRLb,TSDm=@l}y>e09vZ?TFdpm -G'x5?3Or7. _ NR3J+Ut@d͆Lj62Iw_hcM5K+vCE"nq,36 fA\NZx ~P޻pј)e.*/|Ki[rFїep(}b(ge: i):cu$6n1GGۘ dnC<]{`V3o[\T(5'ۂL @tJEJ!.hacBrf8 %А nֻ2y<6սZicF ' ϧGTo~,Nd ԰KsɚOH N(_i b,ƌrX/ |ihBGB ϩޱ{dGjikRZ+Kû C0E$5|wfEXj|7/,ѹfܲ@F-e#fw缮NO S"v)/ 5ξvڻJLl"jm} K-yE͏l*l˗&݊mi%>%(kɨX+X)x0mT wK^f/tV= 'iJ*zUהKŋA t Q;Mr"yD& .Y>{Xz7M:mp =##AɠˋaW<7_4]=+t9x_'QeE^o:djq 9$F~Nˏi +Kѯ pu)*٩3M:EWdV\9KI6c<4_cU/Ez Ku%wq93 wǁj'Gɲ6X'Gߝ,p>~*#vZ8M?%zd[uw'x s}R_ }rSIp_Hg䶫XP =~K#_EvN$9^j[:ΐۉFXuUtܡb}/V5+PfiV8 Y6ɤܷQ%L~)[_R@EP6#ʧJdsU4O+ھDEPՑHmtcFV=> GtvYI>{">.Fd̴)!pq`bODKބ@!T\ Z4NnF7"f`>a$9X˙!RÜ#`6.nZ狴ʲĮ|'gp4g&' }DA3o~-bDt`x-UEx(g0b]RpH$[,]Κ@ ɾ0=ǯ\z7ζnM"R; 7=ɠAKg՚a[G"6˫ұe tD[<8)qKY-f3~&tdJSl~1Ia$U?y=NgbIi̤=: oNJAE޲:s Zgt)Dpzԍ}g(+0 袸s܀< V`^Şk=V2 lJRTy#TW+NTSZ:?rP(5IS}{=:ƤXe !yU+:'F{c17 E.t֯G&?>Лvd+v*JfhhoRuWRPf R,ʦ2uvd5!ɫX/߰d/JZ=2^_-PJ\[0Dq1Be4bE%p^e hR dj#5fԈA&zVs׋UYLOֲ6X#B*yZܨ%U7O1\#J9WKȘA~{ h WXN4)> 4e;W"yD~m8?7 j7 oa!b,-C9y'\`ƺ[dz!Gڞ}5 /bQ^9ʙRaSPPP"- uOGbKhQPOǢgę#[MpzFmٛ?uȳP?B,b V`NAaxTCv hK 1r5BA)ζb~ʥGxTVqXl߉iV%hϘW C(,i~ۻ tHzZ#$vFxRź[^shlo;(R,Dn9gym7GSp!ࠑ88@/*~gqWV1;3Q"rO:+s'P`Lw-?ξ])AEV5Z3^귈i?: ڋЯBK&d g,.qXЍ#PAJ&9IgJ6dws%ڂ6޿ ~a@ggaHҜ1->2`qgRa:Fg1xaJs(T4ߟ1|{=|" j$G1hnK@kXx&laF2LC{e]jn%;@-nn`iSD7@UAEBs2fA@$Tcje!`%N^3b_1O$]dt*Yѿn UǙ\ ?[{Fȑ.N Qxije3U7E܂ ӂC C} 4jъPiTl-Rc>)`fU]C! <[T Nkc #I!iHX ޮY⤨sPmuX(= d{pVa kŽyyDCbtF %9H@owӨPtwΓ|RVm玅9`'*P*O_O>\m{8>*G޷ J6` V7sM6uiOyQ5cte[DIﱢ%M5Xq %ʫ*h` =t2__L c%>-J#{y7#ߚ E2]| y zpl<Phva5ƒGCQ̐Q}+!Z> ic-wfJyW eiqcdsD #pTș?ma&孒Sv%ny|B@`2F!fɷs Ic}(ZTy3=&ȑJ'x\Hk!^YXT9=Z/0Hڟ['-F~;_[3-x,` ʊ/g;\~wloEqUɇE`g'տg g^ʙ9cMڑ>C9Xxu ܵy@N%1mged 0y*\4)jQ^ڎ?B跦qlÎ/VJ|(s~ywfCEq 5Sƅc; J R3p/j80Tϋ +U B&/A4Vu}|{x^hVqWn%WF[O_+Tu.MKn"ywJ_ 0QnֱTnmY݀QӺI}}Fx H.x }EiVZӯZ;fך\5 h ކ-)i'tP F\ޅBxABaJ;23MQsߕ:d[ٔ;ڌbԮ!ʨi&v[JaBn(Nc^LFrZ<n) pƂ,N^ʹ*r~v V/m4j9JKf%ëB` `&š#L6YU̅xzhSFcມu͂*`YP9Ķ27ޱPrt\3=) *cg$au0Y P36m[T_:ݛ#L7 1}s4aC^IZs,1if$EчkL\8NaJR3ad"Ά?Qr}-*Uo C].+#Jy*wǹyP lUDqS>Z:m'N3 ݻ}d^b5+2le:PpkCbBrz\M9nauVlG䓆Y]̊J)7)JL Q@l 8#1!I IR=/WCpguŪ~~.]uDZhlXx44_]; o!3|/_6˙=sv]nNP]`JQB`LK4% $/E?r_27!i *rkڮ܉?8׀O`7~Mx}mo&䱣ړ9Vַ. 1\kꕎ)+8IfҔp~wd,|2d{&$" (ɾYio(B;(AGhz&Y$?&8VvyT)[)?pZAj{7 `hX\fb!>Ou4u L-{>S &`* zajGiptMNԃl6%*=4Eu kryMLrr5,<Y<6I 8h#HfzCm6<|+TovPӸK4.yy:~.uǺ!\ɋZKB##Dyʳ` kwNߜ-J̞9W'臭/WQ)U>m 'nb&PM1Y@&q{k@B^^C~ ol) ׽&kTuSDoA-\:&mNm4 8(mɺ\D$(vHHTcn^)L{Ʋ'XV#O г7r0:ʤb@mP B};,V,uuzȐek詝4֋ MOJ裭?yŷ+?|x P$ΚŶo5m Mfqy 䈟pKQI( I-¬ϸ|^Ɵ' 謫Fb9hɎ^Zć@a3*z{sj&q\E3-r/!bnٹivez ~3$Av0#Cf} ħY` R9Zn 5SQB<5Q/0Rzgs뾶iQWgi٨Nu&^96:JD8삭N.fOr*:s(;|! e I%I =CGxj5UpD7?bۖ=3)Qyw >tCh =} o=8*ow*sғle\e sZCuyP Lϐ0dg`A}NG"_)?õ%k9 J0Y ~<K Jg>qQM:Q`;;^ظx(" /-@4ky>9sF%pJ*$?p|UȽP!zFYb \lx/z)eUYڠ1YZ~:%j~q8^du!tZ׀eq-W|n2y|@غJ>(ׯTkxL͋uÜR"ɤ$-:}i=8mSn:UL@º\iYRE}dpE_&۰U-% JAⶳš;b$eogVHHV ]14se@E[!y\@bQvxYƂ uE ;JCeP%XQrO4ڸ]DO=׾8.[SmXv$ϻSqEo$Y^YV)N'SK_:,Yl &0X:`<'c/fhԒ߳d[U=\&Fr!I : 53 WuRʩyfD8Pd&%a@rRxDj$s3%ϲAQX~@u@Еlg "9wBA޾a*.Z9@@9Ήxi MInXL35c'Y"yUSk `\x1d‘tn5u caIUMcH><e);E )7հ) d&)@ǦWxPd#NZ";rnF5v4$WO0\,20$J=$ɲ_p^%HE4pxDuM){&  ::v`!r, LߙHRnohg`4mVeOUΛd%Uj%|I, Ocmaq*[ F)DI.rҜ>{Yh3>TEqW@y|cv Y1;9aQ9Skv-Ic&BGRwۚ5c4hO75 `3 ٍ͇< ᮆ&+&ӂk8?b[qx!d}շ8|԰&?%H3V!4dmdIӉ=|]eZ,h3Gxw/]~w==@a^+% kvQSmIwҭ,&V'PJ[`8c*M;>Z)S2PFBI[/h0N0Xo,5"w#m00N^;Qr@,qCkp#&݆awH+RR`m\!{a q1?lX'Tn{Ԓtʻz|`,lD;ѡ^1zVOM>Cwj* YDԜ!Qxb"Ŏ~s:9'U]= W- sd*+1Wi-(r Ax:4ׇ/jOtMk3c; sq؁8w#ut-Qyf@]SIVnY e «[J9m>Y9n"o;xL(H @kN)*In<7tנTP2ry7IXjR1PzmoWޙ흐yzgIw| VqbX5!'{BՈ_N 裌;j;m5^-.& A̽6h@$LBLݬ3U@}#@x|˂F:%a"Kxh: ~p͎ɮub]-LIuy~ )N畃12ЪQM4_Z HeoS%#)N?z{o %Zn;*WMϺf?[W([hadϔdRHb[Q9XR蚪.4}}xpB,F߅ -@7K.R@#'8"JW 3٬9S>fIda.nA!p[slu΁fA?/ǘϵZ+,-.Yύ"S#]MS~@ INR7I)_&rfX!yl i609G!כ%_m:dZS -Nm7:>h _xP#VLOCb1N:KmF8SF z!A5%o!M!e|` F:е6c'1w'+~몧LH}`>2I iطjb`$q0BuÃ.Í޲D *(pGC(0i&o[c"jhxm>JaK-C#pIsa\J TVgbh&{R x`LOrXBO%QDBD5&XoH?0)T,%HQĘ[Mĵ[\8_իȶ;!`^rW*-.KtRJÖԐsmfSAB808}Z~raXedjˑR, Գ,":^eֹ7ˇP~v?-*y js 2 PP>,I#d^ ҨԚmbޥ)ƽwJK\'C1Smʉ΁+ C^_iqJjxPv_l\,*!h4q*[1Wdzl$ 1LE6&nL]XT]!\n/:!8~F%*I?tyk5 _HZ^ rj"<#)Q\D3)M3ڊd\ #b7BO*~ҴDX*+z)U򀦢ZZl>}I9m4|j:9ۯa9BƩs7ad_@pIol9,Xȡ)AYf<" bJQ0JO傺͐Lۄ@̇D`n 8}.;VrD1~^h;,!RM rE㇟=;K?!OU{#VY>ڦ<[9,@͈#S1rOa&Nԫ(^suQG#8U:&G$*Isnz^N~FL\ "> 4Fcv)Z#r\ [N2_?`H| R5ɰJ7/ςNq5Tp9i9Mxy.PdP2Z=AY+~ "& 0چUsbpcL h:=:NVg?ԅ?7#~[\@ $^׽JUѼw53-Z1c I4>Td; \tg}#@.W3E$}XZugw+ŗ,Cm% Sw+ ͷ۰bPhsheR@[SäwdW78VEl& ݢa$5)㴫u."Y!8 {"4 y@#镔zlSY!hnLĜ 6zq<}QIC%G]sеrwՎ k.ǭwc=-7*+wqSfpb%pu 9  zg.*+eo 73J"ub/| FP m@R7Av3L-PhkC 3!+xߥxk"+s\M)/^H^!Fv|xY!lQ;bAB8 ~q8YlVİ'B++S=Mse;,(W(1h-F#`9oT]IߊFꀯ6 eڪ胧:2ڡT "T/S9 3v-6~з^;]FEEvPƼ\N?Mifyƣy׼Qۛͽ y ^v9`ӱ[s2*UtĩH9FxB%ݖ D8 4>] sAh\ iMԄZ@&DEץ{ec̀$Byi%8{ZNJ EɿH|}6NYUdrpCv){̀'Sz^-x>&9psP~E)/ιVheH29OzU[ȩ("J >bԾvA%][tIpOv DDYPr[C}e bc8RF7F(U?!3u r #9@L+B2,Ty7̍I1t9g9<5;.F c:6u݆3{!*;.4+MQɷlGVab* XQ ؝YYH~ 4t}%*%M"w ș^"@f ;ɢMVh BbcG"N qy BFN߅_te?wT$~N>9GDh-'IE-<ԊӍk< %-*g541tv;Umhrw{Ib,,PQA%)b}\y t-hh8eZ% ރo=8FԴY0gRDIgHԬИ _EeˬW vwZo cgl>#ɨ09'[*5kGs"RoĤ,ߌ7!)B)M/RGN8}{+F'|- ?jP\bBы3 02B%Gזw_fD˔>H<<Ƃ"K>QwE{.b} .E~yN^nIw._las{GH]>8zpn4|^ASy`+d\$L*Pea: Y_o#\Իe_85vZ-TL3 wLZ<8ۿȁ4qLV%~F!ѝFKl{4k-L<_? R,A:od͖Gx+D3?`jiUW&,ѩRyQBiQVYo`  AE ~[`lzu%dFѶ0SOٶ&h,*РSjn1gJ-~_*h!F̬k! ,K- ̠'N/ɰ,3ASbVÝ{  }F. 3ն7=3U6Iʼ2G#!繦A#27fܷԢ|tiZj#gDMZ3\AsA=*-gfq2(@윣b7~@8V)#ɛ\avKRGB7}aeg|Hٓ UiܑNjs/@&B *%fJN֕٘CW 5G͡|MXDEpCU0(%a@푦dzyBtF]_pQj:YιB͎IɣǎVDP'"`_uC[RĠ+͘bU/(2 eWunj6>V,og&_^wRA 9$lwm"5 R&@Ҧ!3pF!}x熿'6+p8Bmlm"dxJNR%6FXSOy+&(n䦵fWm36=dCP7ygS3my)J&(澝TDdjI##WMN;ԶkdzQ籙̊.QOcҿ@_ݥA`cҺ|g51?uvZԸh gz]8rYGV@0{kIк Y >+3b0|FK s~p [][? PzDyi9:Ѐҡ ʫ.B o:$X~ʇV3ػfaja2qsaP3p=R/idPC VIOFE6 7EbC. 2'E^_ybC^ߴeC+q,(WrZJv%Xp|㳓ER1&6â4B(`'hMۻ0udnAr* j~\Zcɣ1~8+D{InI"OX0){b #xmdd+PeV!;URfʵ2F  w wߔr-•Jls*͓ZNQya,Mq44 vN~ʋI5 rHAw.n+#eH~Z"Y63⁞EB6Hq&MAEIS89iw$i>FsR؎)ikg ="5JXxy_"V`~Yxtu[A,0_&q45֩lNYJ3R)hzI<+'ЦjS A [ש)vg ˣ@ `ԸsM@GBpȟ睿 T*yj>L~\hWuI /gB4gVyF 0姮,VqNfVwPjNr&>'kw\aJFOu1 ͮ}bvynwd]7`2"{ bQ^R|CQ`EΛ)5Z ]Rm0_BSf_u?%v8s*aOV"?|}~pi;M*_9&֠6;`Ӕ/#$+滣]BbSŅT.4A|:$ГßP'eTamAsh"Ĥt *{=?:/yC;IL^B_cadv?^[:O_ؐ[7+<-bcPIShC@`&$Eۧ\ 0Q*xVq5Oޜ8eXuWd ޺ĞfSa:pFǮU-[MJ9s(PR%WZDA1! KQ+x_p~25~mn$w@D {pUmMѧA[Ze/&뚶qƔ(2;:|HPk$xIb.N ^jy]b1/67֔J½}s@91` !=i@Mړ|KWºXVV{ [kp<7~CĶu>1ŸdRꅓh@dr(U!Zv-p2%s\*rZjO/V+>G1e1y)E` _i`6`FeZ1J:#C*EP6 G!lm~sK z NDbJ~"F\\YNF cDjly̍x@;_+ve5GrG/9 _~kJH2&/WOVCI֛D9sQn&97n"T~(N}='?τ3KھJjC}oD3R,vବvVWj5.N^gW ,KZ7~磻0Y9t;6rV4^8 >-axⱔ=:v8Z4mEK~=qXa4c,)3E2 0oc4 _IHťP VC§}a`Wҵjdl ǧK<(57d("+S}-8QY/DF[b|R;62i 756CFWM %XGF*cH2 ~BBk =ыQKh,Vt{jv[3@!W峣FaB \XwH!E8 /6թLzv8J{ ZL8Mo::`RuL'we ?P|Əa!ZhV4D,bcӢ-#py2;M#즇+pVo.>Ǿr^!2Y$}c-ƚ(C8C2>=(F~k?L9 ;*ZDş7F1>tXVs4;6ݔ̄ʼ/E vdYtÊ| gKpY(ȖC fc%7h7]W f _P BR-XJTnN x:zzaIo 9~Y803O޳,-,hș;AXu:8:,]B-L%IwJ~g[Y5g4Uvآ=r{~ba?Yԫk찺jy6g#U/h"ikW[E.}aTHXNVT_-2 Q x~X >``̩xu&sa D3M;W<\`=C့I2XYc%M1~3n4 w )r#gO}FJ1nSk|L:1e !V\aJ14'&~CNS0HF+^a5 "e}D%n0jem,({~*J\l^Q:|X2\=nU8JаFM2j?|Byrh%B=U`RT Vg%_R4Z1 $d X#/O>KYfj{<&DV'u>ɺِHx>U1Wl~Ϭ$^`{FM +@m6qG2uNqېh-ǟϧp+9l'4aU$/ f9d\H#͙"gϛ従hͰtƕ$L5:|3j]1b`eVh4 je~9Qs(Iqb3\b[KGD}W<.UC;*PK}Ícpe 3ƘfsOf(]JRT򻧦5e$q Ge6SR4Zj|>uf0RF~ _l|wnQDL*¢Ե7vC> Z ‴r|()LA)fжR$/e0}[(;ʐGc_} ͂UadTJ) c 4"C\9d5zOGG@\#'Yuw-?JvG)@-.dOݚ1h3pҙdR@/qs)H$)+x`@4U2g@{ѪcXzq(mWaWo.@zV }͛]S{X8:/ k+<,<{̏wv[oŞRՠ֌r&n3ܹ0ΥzHÜ' ~KRs?9T#qzjy}z߮}b2pV׸}p)pj=rxu|~PF $l48 !)/E*h֍{yFM[Y{_7vjJ5B7{V( $IU\)%rl2~^E$I~150;Qzu ͸Fէ:i ipPbOD>r-w9O8oKPut *`~unn:5? @ h cE"JQ N3H |bدTl׸ 1 $pMMA N{dOgmR)ҹ38WwAMFN&6܀mWO `Uaہg␩S$P@n̾UГwR !SS`NA j'Nm}dܹd]Bϩ="J6o.ZE<w_;sުR [a#IyiϫZ(R1, _bʱ 0ЙR?`^gs4=FOTlɷt9(b\1{@њϒw)5?,}^F巜R\ HZBMXiv}zb8^(Zbzh {w&IB% ]lՈqQnX 㐖; t% tqv欑j*Oh)HtuƢzJ!=7Eʷ L:/qiY'Im|XvU )@m#;4BA nYPCGܱ,@,pK/֨jȢR> Rm&mmB7feD/h8^(+|5^YS]gV||^FcN^yo7ᴽ GG]i?*{oIԽʢxnSŅu汼9[/2I|0'{k2;_ЦM|M(g bNS=ʆNGfڂS5ŚWh mk:67-}lxz Vg ?ӮxTW.RY]iȧ<U ةS=Nt]k3q d%q)C-er슒]t n\ɏirU^55>#+ŏ7lv\'8j0_uW |fhp;MUW}?&t H7n( syE~Kڇ|>((xxm*@Z?nRb;2Zcc[Q lC#PVfN*z 9 "ڗY;-AʓbWf~=/Utp4Kl&vU쀆Ƕ:(e/o+}AyS]4#~C'*5h*iIO#i؏(iB=$(HwwX s wt7kQK,{D!up*|'pih&8, \-ghJ>|5 my%T#$ `-6WQ~ݿvm AR#Ȥ9 X;eıki&p֣aD<)::@H/[d!LL4N4رx Y5p\ ߺId2!AEʳ.`}NH{;퐪W7M|t'~+zu0CeC]Yƻ=""u[=uŠ[Ekzh6"5o9 ܔ׫zb*5/YbKkjIm1矇dʄCo6կ~])Z eL{ 3H" UQF-l3İ[_ R )*ɭ_cD d!S˨tk()6%pt_V#a.#@q[34ߡoPir9(F穚O~ iAB7pW l&Ǒ:wԮ1C^mV_Y!Q a(Qql?f9JU?M0`Uv%#Q_`V\:VS-EI=fK^g,{`4cⓢh7Gt]lIˁTx7-r该J/'&a/PP8ό-0!=aև{g_ P ]0/auKcmM.Y* {wI B@ի`. ~s*:h$CTbEƿ;AmSyԂ2ie.eԪj@&MrûIo{KAymjKDb , <—Z3kø8yF1 J\Y K i`.OAs J2|#GԈGVC\^KbߚzqZ\4Lӗ|xvGl,3X.ǓM EG I`Nw eegVdA.8Cz2!r\#&x%?n&Fݐ:-@I%N(~Z wf_aUiEz6ۓ,rUj5{LB|KPþ:ǡr %X sc[2۷F9m* UiJ~ =a4|| 8-wPЫ֤PLç~2RpRp)\q0μρULj$UoхTl.aػ1{0LHiT iH.S>Q&ҒGF/)j_+xWן0(?5䊒4FHIwz7x̂~:g+ nA݇!2WȨڇ|ԉ2kR/m`Τ S^l#hnL].GP}U*OgMmqkkl)V\y II?XP,=! \'f+`UD1I鋗#'2:|=媠)lz 6LX<{#YtJ L]ajKz8veջvzwF/t\>)A0u2QğE՛o>nͶ@&{-F3w\)86Q0w|lvN/S\uG`*t]yRj ԱQL \Li2(X#R'RzE4aSIUqcvͲ̲H3PT( KwoȯTqv, /=wr4W v| P,o.ͼ` ;*حFȗ&{@\pu~LH2m5u@MpսLrQ$k ,>Ҷʏ5Y쑪ѫRYZ3^ޗɁ%Ø_fࠏ83`X6 euPMh?b"}+8#-I&ǹ$'xR3kU`ټ|hSKn."EMhVH'\$pq}b;< 7pi=t{ MU TQn6]檤=.U'\|ɛA2NlcD [ Va`9/o(_qzy4tJs]= 7JvڍEvZBAfFtU}}ͿޠSÀ1l[C>vCu?;)Q17N>K=+_>;Pܞ>)QLM:4 c7 ?bBNKK݊ߍ,Y5T"7k8KV~7JPy yFQ公1XF8|e+0QoR%t)yU(j^dx+HhKV]-InE؁r~m!(7sMadSo)#YPhI ot)qt*AuiI#U'-_o?3MqH>Zؚw>-x!euR:m6{YNS{p@UY6_0Qz>)&b{ߧ[ż6NlbW+CO.!c.> @xqDpPr\ E"jT9N  ޱI;g]TIM'>6Mu=\H3]#a%v6 bWinZ!.œmRfODžoW6jףǞB9#_󨏒%"SU=} S ܊p(x?7'f)泴&NNJm+_(@ެm=@ݒC ȽVdoO $a?'MML,]>DZ`AC C@|S;-y(u!O4gĤ=j nH[ 57hzMo^zz/S眬\X6R 1ձ`|&T%4s$oDp2+ Uirc?aBofK#-[5&g%R^G) P:%=0P3xZ*%Eհ4t67{N[:n<%`[ţ;ָY3YϴK%`5MÖvBCU~UGa#m984MuGؤ%'*Ύȇnra9t1H-lr$z/Ûh4a3%g3#f2#P(}{sx<|tg)ۤQҷQAj1~52+, %Oc(;9baw U;6izm 53He?V@GiMX/BYqXD3<4}'uhuρ/ϖ?w@Cr,bw? ZB1T6_pTd^Fse*xc5nY;k+ѫ1e?z<X`bS~1j 4R]bp 8$΢GE_E ɗ9S,'j2URqiX)kWXq@smQmhMCNe*Ò;n֎ǃ\h_]ƶ |_pݑga6DI>xO {"#:E$gه- a?vdqBj 7)5Ld4fuD 9Cvd9@-JP-ONC c|^˘RQ"'Pߡ de (KG։n u1Yw|J\yfQSׇ[cOHv6M^0'q`Yb=1DTs@8{a8Z 0*[wCRXR-F?TZ͛E3/IJZ}RK8p*O=3.rE~"&wWb5ʙŞ^6䟅ނm>dƄBHg.Ǣg'RA\{SAzמb|UV=ʢ=_JgsR7hNМʣ |_=Љ㎋4V>迊Bֳ(d8fR K1[JA('geg"̆}Rޭbe 7g-ؐ3SCJur7k|% !VrW}hZSmW#̴m< "pLc}@F,*0PfdXR(Xd Oųq#c0dxÙAÝewŇΥ) }o%&e.hݱz8O갏vcXe VQX>MNhS}CwuguLbW)[fͭx;"1{ڴ2:;-X#Kx ԳQ.~Q(Ok2&8pC G6l1؇Ң2W} x\ێ ww7G/Et(|pse N"HLIዑ{ŨJ~)ɼ?L!Uwa_Gw|*@9Ƥ$h 5X2!{')2I ɂh򫎿? l#X?%81ܠu=pm(dhĩ˵'$9V0_o,HG*_%_*݋&|(Vu5f+6>Zɚ?&@$eAt]ri@Y`Hb;<FȺ:%[^iޓu]~ZmrE@RvʑO<5;{G3jئφF*+Tc0!?T/C083yhI%w'dx(g+cG#5U3޷aGgl](HIJ$%q\^ۄnh_-UFrSl@!~\%hc=.^2V6 U7w67Re}N7kp*LTKrͅ?tu(j T=&Lim$[ y _FeF">3$ Ru%G@lWB_OsCA_>NJM @#囸FtH[_Y:z5kFeS)3N&U# ̆ DU?|GD ƓFgC jmlrU =1Q5j],-:,&!TP(598f?@FB<@D:Ek/`gfQs@/bG_S&;~l4 gz^;OiZm6?gR5[,e^Tڻ(c'?X!b3Gd\Bz<Ɓ).Xs^s]͚adJ$>4)ÌUF:Cw.i钔ݻRڠpں{0 n0GR!CәK?!Y!8hYed_;Dn0X)}h~at3ӱzRXK}]QRL0*9$w]cXj~( S8@Y{k /8sd:7/.J6jfhdUd} 0!7۰u>BTqpv"c;T=cFhaA;K)#Hh̠o&* KɰS`fHL4?a?2K.Nh D9b]?]6&}'bI㋿U]yovVM09eC?*݈}ie&.:9SCCV%l\fB`8X֘<{ ݶPgͶ(fJD8. j./X@#WՃn}irAX(Y2GQ^kgQrIXOu*8X-s]YZq噌;EtLrMKTP[VWoܑ5FZBuՌI/nZ|X je,^/!tEShdSޱ0f>t)Â.Sz\FmM{oȠ]Xo2ޔ&rJS)b@cgs5LѵG:6k"iV.BA,Ĕ>:|E]AW,EQ˂}l6Cƶ:rFnsg\2/P f<]#(t.Vkx ԍ Z,P۰+ ] J)sK4'gPY`'%TR/Oȣ ;ҹt W29Oe>^k[x6DAQIā⚺B {y7sš -vaְd 7+KڂrQPVGGa$a=Ǵgzש,E[sT*)Y)YRD6н13^$Y[Y^jDzzK ?hե<<:LX?ڻ?>0\4o^d'̮˸';oPQ^Oz&R|ipDFY 9i8F.FY'2օÚ\nTN[vJ1z2˒,AȆy@ D& 3.nOSCT'1/|b" O;'NDpplnь}0 ^IǕHi— T"xZOynj?O9U8$ʺ(g7F97-$#W#plF.x;P;g%J\; Jkۛ.jZë. tεSGk~J jG&"/Y]g}L7eғx%kSK?K*ǵaH%"]:;[n3}t. c_u%g|%ۯ]l<@V"$5>R r+WNqɫ黧Ez20 uXz!ƷGCKU?RF귍E_K,QRЍhfU?EO&NɂS^^H9̓; -HK'lH)[Ѻ `Big^Zem˗VCB,XfC_y<>emYj/*XCԃҟXAb;/<,SkFRpYVN͉bLv֬kM.dp!O^l3r@ շ}I]4p “ߎ@*5NG . :=ɍb3J1͜╒C\AN蜊'ģcR8\ѮwA ׯ!"cK~BLwe+6:zh@%Ξ|Ye8@pyћiX-i.Nq?}NSsY`[ܯ撟н)Z]cshC1^;[ ©h%}{Y&"\X2V^pJ^ Pw6S`#lFdCH(kz뎐/x;a`)A\T umyv)WZe}QH ="G}EVտٜy.imIJ2+@*&i M1916$߫6Agх!{~xJOLN#Y2ŠβAT`3/360a!ڎ 69N|:# eq7 sDְA&3mEf"5r7 J됍BTSgYpDyzq&B,kbcv+qX}> ,.*9hwrlhQs|N@XTzm^O8X樘P}[eD# +6e%Z #a|VVwnod]mʢ3gj\Iipn1]A)?xT-aGޞ~eFB>;J!ˉa(cWc;1Q@OhN61]ӆEcpD.d\`i"9q?*cyN7zbbcpjW=?KG04^vcoQ@0I{Q}P*ih^HCWI#gqWڻ"<cI#3xoIQ[pZiPA.$$̌BTyJN"w9!%}0; /C%0;Eى2ɢ0]VK6vB6/ɠ%5sz9t/%7^>ʴ g'RI郌\E# y, <_M3 =>v;GyLh8O Xoc5ѕ o ]&x;xMalSDQxP@ Yȣ ~H(4;q`fhI:;D`.ۚBgݗL5/)e-_Pp&i]Cm"[]GWAs᪛G 9*?E޹ B;q@~Q8-D0(U 6u|]#xl x}.'Ot„#Cf%4}nV+"*o&_$YLxy| "Nx>JW&Z~pO PUid9A3} g&[,PQgaz& &l2L7Ӵ,x06{TC e6`{-|‹&P2&BÅEys{a9 .qH/Jx 9+UEAVWse<ŜKŌbYÔ\88BθKrʜTlkّ̺0O{H.\:!ȽE`T#`:Az⍘;Kܲ4[nu$2hC~%rH>%n+|&݀6=(./ A蜽SE]Qu52?bk"Up d4O!GDڸ-˨°+hQDcCo\󂀸DdrDJ!3PeJ5.o 1| dP/[i'XflkD[`H V%~ ; Iנ>EXʦ Q`[7Ȓg #`a ;ň :zG/{d'D)h/eL,y̒35Pi rR*\P}z7گl,oM4Wk{o$kr1[jf@A-9ĖS6-,.N+@6o+P+å6?O-C66w/oT~h7L7E*r(iA3 NcoFzOh=@.\$bS|Y!ZVlBL.V4 99G9W),CBx_13\;>G>,2jߢjF7,3.L$ßTMVx~K8s>`lM9r\`9@-ݟg-^O:3;Q =K?O4(w0]YY6]>4v.R9-  H#*$loߙx{P\EpD Yya {;JzPx_0[9R2!SZ|67zk_*wH#M繎1M;E=gM|NJ8΢GJ%0N5(ۅ>[%epKBu;7 BV"g\^({j2纤XVjg~|2jDi]GMP}(=}|& y r.&=gBeJ'?(_dզ#]t)AN Akky:SX^?DH>10Rt\,P0Ge9-A=TYu.ISHQx 6Qd4v^bO Q}cj iFAhm}htO6,p9Iցf&"I4z}(1c&p6'B\AeRywj5.KX=0 W=VQ) w_=*Ing܃c/H2k=bUf4⼙lΌ:3;MgzKcP,?sDɫΒַ-; 4}x͙֎,;s`t`d$q;5D^vq}TxBQvVg jn#SD)'͈Q.Qa]z `Ф\WZ44jn-율cYh+}melA.ga8\FٞVѯfƊ@!+AqQ 7w/R37Vw%ؽkajtG׶|.&;;KCjUGǼ79F "jƛ*)C ? ~PKkf`q5$%x|En^qr Q_gT .w[KVx!tϴ{D(0r4[?,A [X>[6'g]+!$\ܐ.Gxh@C̼ua czMLO8[gg%zĞmӛCX$LHV +抋.S?Gxek8p/FmA,IV>02<Â&-SdLddYupԧ}z>&յG#dDvXjc"-7p_¼dv7Bap6VQzp(kV(wqO sHX^srLcUWG{5e(py?$Bw4d4b$ M3q1eSB]oΜD۬uޮw}@6~ v{ak .4οeV?7ԈEMr#?"Y#>_'#k#ڬI#T~ߗYc{i{Ī&<"[Gd"q{/{4N 5+DQx]ULJਧxE 6GfU.5*Ѕ?,!mv/OQUa)lY;@4.ifX0L2fN|&҃]Wo.xe:-ZJd|4 LJ< 3/E 'a*WAپ"i4*tGf3Qoؖ4TɇB^J#5|i`ieZt#HX>w P:1ldW1z x"QBptN.lrZo0f" \MUsnfka9#辎bܴg[N=-١BFvowx|+gQ?wClT&,CR 7ʁw>!O(&Jɔ 24sM4v~f*Ez)?2.OɧTDof"h]1$'?7<F?9Ga)X͢lZ8uVgnPeY)-ڪQ$k+O(tGms&^ ࢎDk޽(kaH>Oz/{|Zڠ,+’PW&|qoU@ $w"pp;&T<:9s> HAbp]}.R~Y)%J>!*9šFJXPߏ'|8p{*l U@N=O) m%w2@?Msa1(.rSNLAJuƤ6i W+/_tש__^Be%ef@u[ vm>d\|tLewbTW3V]Y=J% 1pmnu7hTav8:͛H~aю {lL7A4ZlϔB[nJ<H_lںU6o}WaBSU$nA_vaOܿʮJw<4-;hc F>Q!J{ s˸諔v`L,D' {qb.&z‚rԁCXtjOw ?&^dph809][HHؐ:>ؖ]l*\VsTR"2] 01mޖ4:r8\=EZÏgY5x(U+D2]T!|~p.sƯy6 I.r Wo̰͙9>{_Sr.Dк'1hW.m\҅,+`?nWiyJ7,4itfϞy8Oyq=`1kGFB/~JF.n@g#ܩ2_+*7!M3Qy=Lˤ>&vK%#jkȼ`Eغߙڇ)R@^t`Lɷ?33V]R3[MO@RsࡽֱtVΚK:;\_S Udp,N]Ӕ:VipǝSE@p /K*?<plgCj3*> qn1=ﶣSAE {- `2. 1N^G'VSmn fY=>6¼m@;YoŖ:0h"e!ȼ*p9p\Wa{;8ҬBwpCܨ+Wޫ‹?| ic$E'JZB! J: z1eesx|-Haa~Zb~d#N5# zgc2-!5&LbsbK {J 1Wɑb{j ضx,dcg 1 ~{ݕGšŹ__WuwX΁L@VuLU').O'&?qx$1!/^'wxO v4JC+ {Gw`iBޯ#ٕ/k:o`ػ^YtJBʜ2p4+ 57s҆.[eٻSѡ}Lzy.V-Biꊃ_Ȗ[=o&+UXG&– o3?0zPǡ+.7 r aq{LA]s`B:Yj6Oȸup[*#֦QfXmoy7yom T ͦLSQc=J"ءbXw9O| - 1i PX(B`ަ$q  yL5VOy~ UIA _ R}"d$){qӟ34IBiܚ(%Ald#3R'8%At5FiP&_EhrbNs"RldSM'jG 3b?Zm*=QgT QMؚj[?|;3jb;}1`|9Ζxϫ˶޿`2;zYpFD4d E"Q=3;_Q|c 5]u8~d1N^l;oP)՗c5;i4m[y>%'0eEb_0fͤh f?ATp?IvmrjQo4o#R6Q[E/soVZך'vA*e*2il <k3[;qI"*mFאv> fm }=<2Ov}MF3q!.Q)u7r\Fr<$"u [C.*aq~@ycQ-j":d{X~aBwVЪGoh5sl o5R?1W#C>s{"MIm }IvV?_~x%bѲոx8P\clX*c%RYy$DhGF% bY^ JqW%Do*izU=p$9B^ qnn+[G.ܝ*.Ɂ|ƈ6w GQvƬt+X2ǻHtOML$ 7=_Tcj'?xW896^nho=rXB[ZE'Rf]gڝ(8 ԏ{OX a010jxw$#F6Ixep# U;] gk`<=O wqdb%aZΙʔ(4a]3!A8S}er^<B(vpBIbm rk2?jlvwbk&ydVo ēdA}6\NKh`0pw9tC9ߨuBIKמ,Q򺎽%]k83-q> h?xn*a+~r?.KXO>8-m.WM|oޥKɵQ#4,En!I=c߻"OHق{37{m]~QkOEmC:P_$)[kų~k#s" f;D?D^/<[j}nnϘ׹LQ p55{Ev8Wlˏp|i#(g>cp1 Yq0߹D ͤ-]sk սӇ}i.jW[Pt}9nz$ N>xW4^J:LFd(|^tU\PJ;?z;3peA36܆aD ]|@iw~cӭFK36\uZ"T cB<5=-E-e`3\!Ɵ8D jq!M}Yxl[%f+s\9X&?dy-#7kCMP:SÀjJdX(6PyN9?\vF/e딻_U)q(weqwb_`Ȯ;@v|̨fx?P(?x lWC<"U)tGgpHШǝ?ԾJvL`Yr-:\5?d툼veXd+>#{AbN|`(lmrJ:կx'|HlDn ԛ (qKqz@߇;L8'V'hJ?*ޤU;qcQtN)/+@<0m((ҧ!>vτ:@DTmޓ!u6k[1E2x#NcƁE|ep{h6]J-:1::߲\$JjN0A\_+I4h틕/f%2eLUdRnލ˺C؞j#b 7ĀV7E"Vf/7Cyl ޾KIĒs/15s#l!'Sh-"7ۮcF{6d ($ԃY'z8q~R7aj8V)T0A[B&{}GA$”-ij #Dk)>F>,G76 k#t Øh+:ڀJB[4|Sz-H &˞%tbۺm;iQ?;Byhbc뢤dXԷ^Jt\0/ayUn(r(3Hsn5( R9H@ﭔ_  Ftρ5CV?+E~Џ[]OI(A'WV'>Ww& !akF zg}(bG?gd'c 8) ,힄tR }ړxǮzhK6u|c݅2O<v(ݐHJe#(iX~D,Bi`Gc| ؞y!piړ{kQN .qBj`9 3G 52P8:4Ӥ\JE;I\LWTj^eش[3dQtgµ |Q{ӎy߂!NG^@VYVc5]Ee i=_&;aXvo] F;[  =N?.bϰa-"zN2?_MɼEnw{CƪLwŸeq,X Jnq!i?ӮqV) Nk}'MS SyEWvv-Xwp u{Ojnkf!Nkf~~4] GtỸi1jv]בPR~GmʐNJ2_E5ZWRJJ%s;'Dv׽ާ|@@y.pآG\`5$ՠi4Yg8 Iw >M[@5;Cl1fQ2)`_ v@GcbJ0|6pS\MPBSSt "!a:]VJg'ǎ{M^YjYσr 7>r㦟@2%#apӳ uֺEkɖ__&O$} yE=Y Κ^)ij5$y1}W{amV+2MEv,OF`Г6]Y*凐I%o*-<|oÐ_}WݵXRpS]sZ5 c/"y*=T"v3VtndByE,`:tǻcDgf]nlMhOil5N^VƒGSL$4F*ac})O@/*ӏYIz{~5`譕cm}B=NuY54@>6r)N;`+3@1sһKdOi^h4ZMxW&د^U>#]l1`(3/`Z) @AU&9\0!m\:j$:B{H@." FѦ2 SaKԢHj&q> 9i\ޚwF͓Ojq8c >\!ujB}*zDYl~i4@ob#8R5[CPmV#r ($!] ZKvv1{(߭_1];~9~an_Wg͆(L : 0WTOYoiM3$+ySp{@Y)PA؟ZA '00"U3̕.Z5v:`]Iŷ@R}:6 ؽĕp3bqʲvvӚOqJf+bEǁ6?,*5b' d,cm ĆwR1[G3PTO^2 t7wZaŝuLiۄ 0 *5ntT L>T~l~dN|h?"$$v0q3v?/qy"^Kb&N`U;IQ!~r$չݹ'.V0o:NYW`%ɘ78ѼeT=Y0wXB,g'sW1lwu!Me)E社kD h\W\@D;~(zޞM';o< 鹻*ݺ쀩trp@:;A!M}e=VRۣSqmnW %׸ֹܪ#5z>=ġ̣͋gvx,l\`uF4[8F^Y`Nj{ Zpc1'_NP-j} dqIAa[~~Pc'aLB&Uos`P)1+^N;+Y'2cӜ3jC2p6HF͎ =M5'*bdzgް\}C}e H60Toxai \ WÀBT[PwIK{0vX}W.KFvָ('*\%nN\4ޣ5@]˴H#ŏ!-wަ@]@1șV!~5B;ސ<'9}ط72^9;FNGT`͹6 v:ƛhHͽWQ#1*AzQ8Q%r;q+JS/ n.~%+n_ܬ'0b5\ 1IHk\{0Yͬ z-R+))ss;l2N!i.4 Őيæ?%"tiu~¿smԛY#vdjwL7ךH"Pѕ ثPGQbJvҰkt<^K9Y۰g7Mɚ, > ǜa..bħ0~+_BŗOS)nEg~cm˔oƱws0z; lܢk%h.y16TV<[@kwF?u ϼs0PO-ZmwK EJ&%Bi@?mS(" 1hqW+ P") R;쮗IW(6qQ9TՒҞ+*{[HNT z~ʚ$wn%+P{&3pKRJm{˜ϷE;oy|▋ln( .0䀊f 0aC){25wE]hhA r2jz(r96.ڒ +&2F[t@UT) ;+o1ٓ(PI>֪ eow~P>CG-E3C;q!f2q-E*+̙uht'ԭ*irg En@`ش:/G@>?j!:ܶ䊛\]AwP*5׏L wtNuŘǫUP٢>^/;F\Q"2|d#8k!`&O51l.BKc|d й 8y !*n5tRO;<`s˛˫x2# `85ZT큥p[?Og͗f5Rn6c3;tg@X1WcjM.a}6T֖>hP mTl;vgo1c` ‹8jzq++lEУ 2&AQG 6ε:Ꮫaո.4ޕ ( I$,oU{M䌗#ege+ݰj/Ej2n)Dž:JR8s[S6tx xӫXz=;67迀(&|_e%76ڞNCqPȑZAADꂹg(KOd \RƍE9 mVa Si}AȚ `! Q;@& w#_rUFiܪiے/R%58cl|5-R)l3+bո0g{ AQoz-"+bף"lYB"GPB24"Nj~fOLtXT8[5֟i"US dm \opwT'x*DB[D,}*UEڗ?64g6aݠm>DS+`2*޶}~DazW45U䋲FY|hHIW"݆2ܽ4zكNaNvxt +Y8aRʣt*/LIo,.5KClw@_Ct-<> رg3U[Y8O]h[ZX*4# C5ZZ=ȶEUۃg#|ۨl\$q$szDs xn=dNx;d]0ЯOdq (Fԓ"? djBh4WBʗ1r9+`KlӼ@GuϨTL{KB>sToYN[TXipݽbt C}r q1ۻPfJ >7jnKY-ܿ8c1w0\MIC2Uݕ2i Gg_J; ڳp;|660qˍ-#LX"e8=+rB)o! /u=a{{q3>/8~uYy 0¾th&a_Ro^9^z܄&YyTyEm:dfqpu  '0d2|&WXc\'đͷ9b &@ /|d4އL֜*-'}t889:Ȇ:uVLa6z¡N_Rl-U;5âhlUQl1ҮmT' UL~PSE."wy}x~Wj00Q"S]cu)'̨Oؼ% !| x}l`Do{սK O8~vc u"W 2N]Ϗ \td+s7f _ iΚ{# Ԕf L!>T{l>V7Q:bYEe8u~Ոy`3At Pbx0$VEiuQՋl)3>kT,$d1dFHɳ<$ 1߽T!|c> DӽFnlkJl쓋cZ%1DF/Wǎ<}inҌ ̭rY }pݹhonG\3.Ѱ&ћך2T{!wXUYc{t#*/tiP%+W<$NV4~ms<~s7J~3oa? 1 dMDM+مOA'0^Vb[F969KoYM-:xbCdfCƤU7}B W)Vђ>#!Ѕ&7`=x.G";o4vgE(pEqP6-0 >ih,?jݑio-UÁkjzU :f$<@?Z=)8):ɲ-O%57VC4WcGEMp&w-hwPaC 4AS%}4H1Z o`Lk k.E28@Mn ׭]),||r dhx_X?5pOev=>B,U(k,:t+}jTPUЛ]GI5^(!}5#vâʞEw1QHUͻw@1S?cSޣe9WYcSYWl{}yA&p*{1/}zWN$ M +2*x(#ڲzZ .# G;NKF֭G8< aiJ(MX}<$p>IK, tpC%rVMl_ώl BzhV룖2H5;0drzű+4 .N:.1ˮh.yء8^v][q%-5hUoYDWDP-!"H/F@qT%օ ? <& 5 tUI zSDZNc2%ibY1R c&Ǯ|*A.ήd_@V󎎺wI4Y RDa f 5ّRdeb;<$kV%- fAܞG ڗ{^>ԡЁW$M#YX˻Ҹ:_*U Q, JhL62>*ҷʧ`zWd#f7jysFv5[ # kL P1y%cfq/k;TWP+\u|wbԼ'r[W]<-hn"qݘG( ,M\AXeXjObzcKUdž? vn7&$:$<=(a!HĹ[W&*9Kp*{§(.*6\?s}Z& LiQ|TmᠾCsU5Hr=n ;O\ +v E4V.{Tb;DK XĈ*Q(34ֈNщŋɛRkؗk{:I%JuQz)ȞUgnJg6ѦxSuzT~;_g_/sz{Tw^ jo<>hB#X̆tK#DMFO<)$!JsG0GUEQ'= )9ldiE]UKBY5XQnB|_J# ݵGu p7sŒ|)a~د q - h"ikD_]U2M>{7<<<$d_ H0}]TQpbu)EɄ4`08y?aI-% 6V<, R˳V$] u8ډG{QsO #&e.vdt#Xy'm\fW.SJǢqYjNO6LsS-.FzBskA₌:8vf *u ;b(^J*Ls\RA&?#GߧޖV;U^b'?'ǩ%6T4dG;gXhk3!@2Gݤısd4i,x^:"UoxRB}wlhe5hObx`b*^q%W]#_UR{5lA 2?Zg9<^qΪ'~&nwEmQ21 Va9-ɨySohYzeփ7o+c2Ϙh?1k*G"L@sc5GwvUXsg+k)j֪huaF8f207XΣ=&E?*.Z,_q9XމY@vnZ֭VdžTxajEyݱfO_:du ōg zs2]\|z~M kycnlwV&%iu*_>Rc,ʯ OOUȊaE3ENguB;mq@[kq/gdnK(3mD(+(ؗHu|zrT<@&[ Z"v!0FH V |vV糏cJW; oHƤF\NMH2$X\{ yvҨ]e]0Pez4c]=i&US]Mb/(Aٯ癌KA1ʝfZ%K=Wr{voݨHet-TfǓ<$#Ĭh" 3CQ R,_o>,ƮbE9@1(3$RmO)&|8#WDj-MUH?"8;,'ksNEHݞZ&:O=D)8X.SZye5"mx#^&zQ!H:~~ÚW8us埪0ß%K8rʑfQʛ2.%o^p v0Ľ#p\&A+󪻣c&=Acqv\w%kufDNHzI _P fw ahbO`jNOxLݹ#zk-u}ypfRB(M@\j30fޕ9 { ZWvJ/I]ˌ PtN9F 1܂o0%F!FW"LhHC^9885( #?NbՕ'yf &q9/[ |miRN.0Mɱ浟{B_ڐ5gtW%„1>|ʹZL䪢0,pz56*cp>UV4µ2׾[fET`t{w_; "s(- Ndp kK6BC$mdV }kZ)h+'>G-13""6gZ8."DXЫW}F1 6b\"7.?D6$73,> n|zai4ihTMIKzK/5W0afգa'T$4 Z6/v˗+ΨS`n"W } (75B6*ϱѕ /Jay>y3%:HZ|u186?BU{FIVM56dT4$rqLk^yLص↾oz/tyޔ5qQLZEƴJsVSc<oY=")eFFοd$ ҕ*c: GQ|UeFeR"l<ΐ۹dGKgNe,}vJwFB*4{p%f ): u=;twn\\yOeA$$ kK%@B(Bc,V8) }ۆ(P?|/\*ǧzfT>0r$,߿{-!r!@4Uj1wV޽Dj ZC7WAQT'#E[$i[d<,ް9sHϜ~TL )t_mۥ`ue)-&5Սdž-/<}عe|ӫ3 V9e;7gF@2킚 x%o]ERcDv"w"$H<G{>WY]U.$ȡW:=My/~;%p5W [QĶp)3a5K>R/tbC&TX>lf;^YގDXd%gB.h˜N%Xzt|J,BWާ)4#xڒ$cɖ+t _v Dh|㙹9`̃}Ry\dd;eMմ#uḐOfo z^W!!'\>yL^[\ɐhd+wҴ6/)VՎ 8M`3J}3Niq ۴uݨƎܕӳA~%v 4K^E@ACgDn$ҹ펳{76 U%8P8 6f"Pn_?IJЦ>7}mS PqQ3'Z!\NrP b9/hUywcecL%Hr;'w6fuJtbF ~ςyGUGoY/t¬2.ۛ"&q'NQ%~9]7#@Z@;PS55,z:G<"se e kN5?2w]mtpC 6/2X@[ 膨;{5IiD #uRBr -dyQn mhrGuZ筂2㌱a믛x?7hܔ5)tl늈Jnߔx SAcW]V-$LcٷIMUi|`3Õ ]D +^Ƴ#T%Sp^3tƨ&\ϓRi'ji+eB Yl]&)4pܻzH^Vn|\B|J nH/zt&P|uY[@ 5ZQ[5H>Hsr)(`ZmZi:>-bjw lB 5(ä7Is1; )쒧r̕zBbkټoZ t;Vĕ@dBAODsb {br*ÜË"z^ aN>kƧuQ- VG nXyy[|v?ń c'oW\ì:;аZ,+΋sdQ^3!\߃u6M.Xs=xE07}74YtmsL]_$=֤F^,ޯz⣝6@Ɨg%ߧ* n*AuUaP2() f/#\6j[aгR#IǝƝOPh1T.'юhPE=j*Z;-wKg}Yc-HI;.pmh=6-?ޔ+I3G>9ө+p)av &D"AH,J@UksFCpdy~L7ۛr|s.Mx1ngy!⦊w|zA(߾U_z T0nby&W22J^fR`廙k& (}Bܘ/&igyܧE !E~q88 OҮ" VQt(Meh%cjAmʛ8*-TC\tL8JȔnoI|ȠZHL q?f̽$ D7\\o?/ϭ`zq3s3vZ,X{&1U6ׄ&'=]#}BFӴ>ɕXyFp%x"a/*l=,&!\];Jٮ$6@FL,rAle) ϰr9]DifoASA]]DZ$9 +}xj8nBx|spok5`pC 8 H\3y:qFNV.>qR@ >fڻFMF-M[F\88SV]lS9y '\!%kf%4#?*Xf@ G1\:ɢZkªA`1Hagilc$Hvi;~Yqi١9@^1i`6:rpi d1gxa_dJTJpj}^i>J5-um*WWZ7 =l'Z:bU^eK\C581PUI\~ ZɝX&$ s`|+}r'9vb,.Ful^֔{\ɱx˄TR:bc~(مI-Xz-.\ryt^|s._<\Y= h<},h}bK0-PSx=KL.݀?NvF3#1lu'8+ni̗5) |b=IN[=NSR.t0&zO74WbÑKpTͱTY/c㛊p;H q`bL uGDd0FZ%yy)' $pMn \Z(-M&VPl5w?Yu6妱 O @ 0L;=FN79XQ)P ]f<^C;~7[y@ cim5]3Y]τQئpN _D`S_E,i<$ɥ:&ĮL24{٬sdz [풗f_ꕬS,$&i@rѢF /< vZ 6e|H 53vq7T$@)-I'OmBMc0R{XGʯ:)S,IS{)eb9~vTA (/_9ϬM?Ju+OR_!wc`? ur簔CV,a kHn@yw\'4?W %ZRDU.gX |*2+R]?;डdT3{)Z}TN>8 xLQA :I*(X@m_EZGjEf( `A3JUm13g_;>V)8W_81sbTz~qո%}L=pmwVI`bcJtr[0Qb3 Y.e_iRCk;@Bԛp 31۽ ůb$)[j|GͦJAQl&)SrB'GRȈatR`un X_ 9NUU墳2X7hL sGڳj؄+g`N.I|[69h"iw=4 ^9oG+gM̬ʐô"+vOo#s~9cY̋JEc{nK-}Y[ 8raEFƱ1G³.E]7Sz7j5ۀ@+}l/H5 rhn~M ŶЫr'.uk6):\06k6\_=Ll1BYApRg:@s\UM,XGP`B\2)e5w9yz41Xa @֨.@1+#Z͚sǗm);7Ht:XGqǿʂQg"ϰ61o,}^xEJkɿκC\@z' XNu`gV^V Y˟ej6#r+;v7hC\k7\ PHGYs %K(zEut/ ۙo4>jiCLA:=[<]+_"IH&ג̊ G#f_LPaj}zmdAdag%kob=hBjtm +Q<ۿL}q$G 8)yƦe$#v\vH!C2s&_(}WT┒D%l8OҀ2AYھO|-T%=P.pmŨU@pj+-r"å@i$׬\3Ft(2ZL ۵ecP GkEstϫ ;Fr%C)9~-!hf Bg/~g%tlmInu4(i_>vZ׷jq,3mo}{}ɁraaXiYW+E_ံn v}&`b_ƍ KԑZ:ZV9.snĪ}iW3ܩKaf#De&(J$>7 P׀};o8I_!ܞx ~$vf͙#90F^2A,ċ:کx{β&r'[ Ϛ&oQ@^ñ=!>=ze̞17񉳝#흸PYO,3[gK~p(ik:q lW"onxK%s^~8aV%a}"C=AEmTHNswrH%=hߡ@w2Z:NevH~aG>}_?A+cw nzt@Tgtw%z7¦-y&n<K9"w,@tDPA+d[֪RN4r뎠%wEl|X:15/F㧶Qs$|c|*Ftt 4u0x{_a-hpJ%<u CIqg3kht4ehsa}2;J*ë́CZ67RUF{QNzK@C/ġon+S\֤Nfl'9ڦ]7݁՘&ZEp;--/_|kcljb>hNLTC͌**>Ðqw IjHUˆ V[BK QO#w ١NΞ~> nDLęD L75\ivafmLaB^J7r*s8êȍ9v j$=a92}^6bkqmX2L2gySr_(2*DG}hx&;wU~@d0DT+:5~85|@jj9#}F|an @;3<5jE%gg\2_\F_Sx2(M7u t܊qC`j~9 ,l (+ 9)q]JՏI8m+m[DҢhb2;A}bCT2Vvgbɉя-şp9u K-ZiVWۑybx~pcfedGS== 3fVyV<1y""S$,e r~S&-*@-AugVJ pDa"<dKOQT{FP (.[k\\ a՟D,A)ܨ0RsqdL5FV/VSDkgme:BJb\l6⎧e$ebxJ](n.> VֳE&|7pL RЊ;Y&#9' Mmkِq/M|#+XDBu&bnb噡xeV#vMcho~~ YBVH_-MGu|@Q(Mi?ɑϯZuY$m_!yEL\ah#wU'ծgP9wXLHU(w51ڤn*3?=LHґ98ẂpW ,U/gl{ / 0סj0{yW h?/0l 1Fk Fs"gb[{;EYW]}%q&,/}d%ӏG!ƭNJpT= $z PGiշ$i긘ZX@P9x {`3k?;fOpD46+쳝CA%_}/[291YUWndؙ9̗N01WIY-'~ W0y Ĥ# b8/KENp3ߖ_ԕ! WZRWZC6%b6/L~ORK 3o{R7d8zs=ɤb*b3e jFp/(q#'h\JYbNO{hMKU=3Dmi3X&w4ԇzf+K]Tݢoxg eS4 *p3aL`t5XWJc;I 咪jVD,spwq8>: k_dBN62஽#VȨ읮iG|&.8}E+h72v](*/$@=/ZV_g%6:&YIB>{{څH][&?D(`fvV8pTmJu$]pe 8q-XZEG㹚P[ 9ŖE+8&\MJ!h!|JsshH}0(Ν+-nŴd'/b¿ 2~s{J3FW>׎QtWI FQ 5&b?%ed;Bx dfu=D:U|ROqmnL9kHZGPXt(+9kP{?ga0m}B5sphM ] qNyTt60"T:6f;'[&ڡΐ6*^Y<bwz`f$ic?6/ީobsrx,WL9{"fT=XfrUp콝J!~F"A >BNa~No}0};=[ mʂ ˜"g(@ljcjdD ĀZm1/ _xYύ5e > UdyߦI*-WsGc( 5c$h{+gu+Y8l$OU'=C->8v0@Wo[T2{a%庳2|k:}o zK,|%aT"Ȱ@ S։g~Vqbjq'؝kMi%rqn>Mg$GD%) kCa4=iGAaN((I,wp-B;m?l #qe;:+)q2a8'F`?ӾlLPȈ Oin/$]ެ{1=6^ٜt}_/;# 7vG7_g$`g!DjBͿEܵ)W+ժwsq/LBq ~MogDJ!_Iky4"}=. YO/z|{WħH>^ _Bx 3OT\D}[L=5c ~RJ;jnueQ UTʂsd0|1/ǡ_8mҀ$Ќ#QТ㿶 yH3)Ze*3̙PrFLwM{~\ QѤ}͉ܝs8F`/?'A vgu: L6Pϒ(yB0?ge03uf?[cҼ~gQ) nk9f⚡ o@7bXbvU+%%*$􅊆8ֶ]XUJa<a'9DkC]`say>Ƈ,P+(5`w -cʙcCќM$s AK|0?a${Կ2MSv&$9?ҹ iLq6-YTHԆu27qW̝7pYPU5iS?6Kv}o+&k[h QۅmH+=RPT<`j; IZb-\fn'nq2,gIi_f], ~J+,>0zKP;mE ?"%jc2LEy\J:=}< F7Vbdi?(Ta0PH LM"KG_5kkG: =R` )n*7@h(Cii`;a+7w5[ܫ{aLvE/Gc?yб;;ҦMP|u85^gvp-As7(wZ)\pI1`hәg5> ʜF.l[ڣ<ڨO"EH:ܶ:q!! ksDᴢ64?b>@M1I2n8J?_ (fG kR XfѮuO b%#MgVud3a0n_2c#heK :9Xa7gGLG_uCEc)_6}M2+`$FR4)``2deS1?FlkKj5M7}@ JWް'4LkAƊaX(i`1} W 5+zڛN 3nU 5툲v?̄N]8}սZFywщ =Qo5E|Ú<*k(\oh b t6f`ZLZ7Yr!L{u)P<];F>4|> ,5M /C 6T]?KTZb09_`,պ,ZO6ݪNhDa#M NP_'A?:ߒ==#9[2PyUlCPгt?3;%^4tC5cxcϜ n5񔧓^/3Ik^#P*O4:?ibI@`umo"\HG݌w$YM-O)0jXL[m@P.iuaچk$'%m܃~K3QpQ]SdݿK~_A~rT {Lk."}2 iOveFA _6 yk8 JD=c ;#ȧH-Bo|4J4t#2]= }L@lzƾ7ωRdoh哻n0~ qS!?hxsỒoIaJHV[q02)sEPNnˈ+癙EA0&ˆyYU2KiL꼱#3lԆظnDZۧ!f׷_{?^o?"pɶ % !*1[&]{dw1ό.0t4Jm}5  +3;rP60 e|R:GȀT(ظ  smu^&$??>bn;+PQ=pHL!hq<2_}kD2+M@j;aLqؠ> t>#Xn0Rԉ+q!0mQޑxZͩmV>BpQW]w7Qq~wݳ>̥HBCƥM}l(;O$9E9폈kXs%!QEt*t˥ 7Còi #4,2ŋfU3Ms1sjo##,ϙ]+D11֧n3 U[MiuMfTlZ&?,ȇPɐ?5n-Jy-݋5ZX ;hƙ[!YDV6Bxͅx ~OjYnw33kLr!t$q+Α3wO$M헢[Rkm:u!ZP2GrMnh|!Cq 4磼`MRCH@޷ XMgT ֿN@`Nb ѥ t]{b(&2Qy*d ( (?1P( 8_OeKB-]+,rk\꫊½$u׍Lk/[Uц_ $u9SՇ\NFLXȰ$]O7ЋQROa@PPXqRKkRvhQ9S㱂0V95ZW|4r[ b6 mhA}džMԧ<߶&N0L*)Xf(6 ^q^`AjsmFG?v0mO+l >?#byBA5#XP LH|0kVI#Sn!alT6|K]!! 5m JE wmZoCO+7yA,!pDT?tQ;'|n~,5іscl J΅,μ\gp0Z,ZN+SJ9?=RXWfzOR demb_?aĭ8 ˊ; FݝY(dYǧ5 +b ιDugBSBXP^y$3{ڷ(QItq7EhᝅȌq4Ʀ߻. ysG]5)Ӏ; wፈK'U~xpDȪz09=MOTWRpXNtv!4D\[/f@ ڀ6aeÐWr~j"ZrqE\QUm~GoPa{ThZxp x:32xHwʭih^vb*+ feڦ:RxU2h+65MWp6_В0sxYyjdS b"欴~8/`Ftgzo CR3! G;Wje+=l+v_+9QoP[kϞJhԜ36q ,5\$D| Fj2x@xOq.`b9<5~k1$t9ˀKV%qfbH[D(?]1<h:2Ķ-d`Ju$oHʪE0ÿWXx^AR]\a3." OxgٺNY "rIUcXjH0.FYHDg;jZUkC>vth*ӠiꞼfq 3)D >{D:sܟSӸv%\ԌI྘Їik:Qo*YLv?haTf"U [0l laDƷB4n[܇yG/n?1>p)nF>e8|WaA;ӕ|p,tc\ϋ3 0lj1=XF C{A1 wMa8Ùyo"dw/ YܑDh©FZ3$ڪp까{M]3>@zȚw2L/q7jŋSH|BپisJZ*vgE!X{pOhgaAu'NO>Gf )WR!x{cTE*,LA-`hm\tu5Lէuu' Cimcz*ZDv2\j>quDBnS;ĖhĿQ\,7FW8U+X7I=l7KRgHOي[^Wi3FqyLHwbiUIxzR _?hWwJ5q.*y IdVk縗#n 21rbcGFdeAaZ8_eLzn3DXcP@^KeӨaK1po!(3\-$}"ZU^ 0J"eʐC(hܘ+KOKqs=.H&5O- 6 X{_mZΕ`6%fVB{Ok컦UURC⢮]C0?yJ5fFg``=S2eORÝP,Z IG!qDFX;E7yQgMsʼR4wm쌱N4}V͒~ n%9T`hdͶ)ۘIFK [1>3_%=h-ǒM8;c%].M.TDʹw=Ӹ$/g6*CRTbO\t %. /@l1GڼEs7[-_I=-f=awYbS$z1H %:Cz 3mN"=S_T~›]g\;c<ǂhbch[t/:\ǚ2'ÀW[lQ`3!=n_=ӛ|)pb+:`FH ;Yo'WQ@` ; 5^XΊ̰OW\b'[6v(Ù5gM2\lX;aR qA޻UwLʼn>C0RQQѡC. r&lL7+Ju.7<QREdzOݻ'6;Jj)nc5.JpPa ><d{2Jr{~ ؊Uu|;UT7RD @sw 4:_uIJ8%Wg+iPb=kؘQuM ts}F' \`]؇C&Cs}*'S:ZT<C vl}uJr0ߴ2=5 ^ݫg7<9Bl҇=AG{{DpMIP?ʞьV=`DlVvard w;#R iV)˴S,+orr%%E} nй,LL*5O頁 kr@Ԭj);+Vhc vv2K0ܗki1F65mȱAԙ:>RI@g'h j#dC S'DdJ[BR{ m |c> w["6PK9s24:FC^>t4ͯ''Uµį[VvWjh% a,w0A_*^.R ·u ׯu߉ ivA /¶P>fbA<%VC1&|QtN|$WƆgR?Mݑ%;vVH3 ]/VN0q1!Vj(Yl}յ8YrLz()Y?ҲIC\+un\?%&|0wa- -4r5"XG:>wmK| 0\h$lqhŋX=D@rb93ߺl34w)3dP IF~0*K>yQgdj6'K?[3h !'H,V]>pj~9.NhV(g3N Ҳ.+`~'Ĉ"W'CTW52/7'fu8nÇD@nrA\ g'`RN 4D^(=J8 &2;AڗuzHJhۋoޖo|?T /&Z&ɐ"ʮK{]6q$ԽkTD6K+m*)}pi.C%`(XjTazDMg1`=9P;ӕS*Q78-;ZeO@ueNs8=as}%]",rd&R-gUwf F> qrЃsK4e]9wh(’Uΰ۠Ww{d lo&ObFʀfK~ v"SQ?=3+# ˺$fyVW ’˛00$6G嶪`m bc[(KVB&|I3Bx@5 Gʦxn9IqG \I4oh,CDb뭡F #g PlfwH>C>nȷɨJ$@][)^"@"\%݋ڢZ70ʵ :+2*Px\:nlimAvJJFǍPDY9h $B?0"7H ZSLIjZ 9ʼ=KeġZ5d K믊sPTHd{A@H1׹g%6HMֽ U+iQp`XWvYe PB_Cb)r!+HT``Х8ɻ\ʵeϔ ADKπ>*DVILg`8s@ uHۛ%؉C5+S]7NFQ"6U @Y #;ϱoONYC<VGI[XNFEa8| '%Ǐ >BRCz)1RUEx(^ QHw+cVC!` JI(7lj^8Aj!UG g>0^MM$ڞt!B@_ig/;d|޻Ym+eJBB<[8ګn X^f=-ҭv"8%P*M)Mq# Kď(͇ۡ|A8~>:E h`NxxH@VSG;{/14sumkek\VDT%|m`9:9F®V]`z >JIS bJrKD݋C朲"x%8`n |9P$B2Qp!a-2Qp:~Aut3=:th)Z9ymѨUE^" N ҝpKnY($Bn0(7x{^ϻr ^2$b v(#i% po2n􇽕܂ŀϿ3?d͜ݾ 1)@w\&LC8i=Ĝ~8N(ʴ.Gmѩֹ}$QpXʼn.ŎrhY:̄X׬QDn+S'Y˩  }7Mbt)[ф y\INtHۡ_{Jodz)6)x{cw,/BRQ/^՛Iҝ*/YV{ }NPDŽNuM)L @`&.Hc䳻vD)NjnpH-[ZV-`;%X"p]0w>'D 0Nd3!NOhШnX.x$B DC15i5 >-An+l\.τO0Hdwrt'fDpe#k=pҖ!sM/ $ Y8;&/1h ~Bv^MQx0Q xC: ē "PF#ـ]:M8,ؔauծCheL1gW3*01x63v(l/ZG]/爡L@TvRLGێJ$-Ez6k\fH {* SB~mb"$8wYD`qѓy=. ȄwbF0f39*.L½YZvrzo iN[>p\Y!n v~`sխ38dx]7e. 4dai0Xj~zj+fo*t<&^ &s(Bh~ qccYoPn;-4Wlip4mtBc^[צOc小uUC ЀSpbvFD{qoqJS;kI$HƞmLX\1AX>wP `{oijeb&;lRo ߃:b:Ϛ/x;&_?֯n `vw#<ؠeҴӡmpߚ$Hxgsl`x>fd較Rߜ-]}cϊ6zW Hp$D F Io:ؘZTVjGI>=EHM t( MMc~/ʁЈ-Xv(`O:$dGA7ڏh5'*nkNz ..;E4mvta!x18nϨ/ZuBǼ{vyu~ -Qґum@=4k]*lƒۇ[ |;\> -X@P %.,=VŮxi[In{Pe%Y'8wP1$Tjҙϴƈ*D8Wstt12 Y]:Эg* 1cnE86^ (^|;. (ηE+8L$ZĄ=~ۇ3Y.Yƶm:߈:`d^mqM`U=Z Dd^pkTm\p;7d b$ t[iQbbmR[Pgu$[q تU)ܚꉬ2"q()lda6uB_(Q]TYgx +Iڭ -5e%E#C*7BNs_jI!omT\[t<[q>'#Ee'=Sh(3x2׌NwϠv `5O}nhW&$i '~bCb㆑\O0ǽ3c9X;u),88j*Dc"é+Eg)=kyE^f!<`g~M%n?=hBTx2<ͧ 47P?VtP"`a&(Gҵ)a2 .ΑǦ.*Mn_0'13;\fos*a$?pJ}sWv6;YRu:3VKQ}pbOi \/c%qtS|'|7ͬ $U[Zgy+5j? ϦW;!cV00\(f~Yq^9F=GcST `R~tc;7u!E{s”*,|+-b :⩓<&>knpTVmTTWoF=jnw% 2Lm>< Vӌp$HƾB~- Rq_8089BWvO s#a<ӛ{N]DV*Pz/aGd=`z_\sd 28.0ؑ>5mJ<KrXcX DDU'{hc.PL[&%XiE@;_L`֎TS"]ͳ33-W%K϶da.S%SM85tSdW$ XH٩< ɬF_[ 1.(7AC-eS _,# UvY[C(Y%& ofd95i5M ҈S̄ 2V6?XP ǫqitl[*qȹ6~\_Щqzmi/ڄѸPd³3b*<Ǧ\a%R1D[z<-T I`B h*:sl.Y#,4NIg:? d@_(J3dw0(I L j˴t)}g<f8 h5 ~ixO, XAH$Hla,lȾu ?D3:r"kaS>jL%\c.)}lW|IGV (ő䠮Ig禬^6$h = N2FCă(U{0U!j,JV1qD1k>J)6:`\;T0T)$xLӡXn ORpIʩ}/~0_!o~hc}gOXF4>KH'+;oPFh!XhsX4I=ӑrQ$#v^>1~̝9̙8Roݍ+R(]x^ jV+E=G ü(S3Gv'T3ѬµfBC5uz2Hf1\=ɣ6˜ھkkkZֹf|ѡg-*C-&wy^+?7^dڂp'h>Fu΍cUo'C1Oz)!,jAZ`8yS'?AS9F@z; G$i )jM#O6ű/&DQ)ՒZ xE`Xmh{$)Z~ڇXv*v校x,. !1Vuߴ` ;?u88ZqNJ/' _tq`fbћ#0]NG7ea?R%lDS1'D쑊erh}i6E94pm n[q(2S& YPM} Ċ2~Ms> $d:MJ:;t3Ĭ,fL2w| -d1Xg_-3z.ָ?b'[\%!&*EzP4o}'WrBmTd}^wuuR?8Q ށIb3x9n;q/̟]odAM*%W\Ncu\׈=׉ED yΰ4@TAB æe~ IG›80%1{Fc_V-86yQ^ WKUlFT86$e >jӛnw_ІJ#u/56ZTC[U][:$6\YVqesDdqM㳅݅ZLGTl*m8mK~U ^7OM̎Q/"U l&AG&de.?oqh 1+&IE576:6b أR(e)"+>Q4B67}="qiM0O!\mE񑰣=!% PmV;q Ѳz7X?OP7U%îLX4SI4jyX2sFf=&\*[yjQsmD]wn 0t8V86*vG`nuϮwQbi =&T-GcS,VRcT*Zkb:Qi#*>iȀX3lz<,\[$ri9eFn4,Q5l-eyTChPFಡK:z̚cP lo-knj)@WJE,PX`۵zܔA+#9ʾS=5ؤ7!-t}+K*M+h#iq*Z 9}e4hD"|yo,é,p- uy8_SI 9Zz_o.~AB08*m9,bOC?&awbǯ'rVY?EY;Ww38T\hpt̀3HdGCyJ LOE=Į\ _FBE=N}"Ѿ /-g|4o{_U9irR?9YD>OIg/s#aZjr3ͣyf IA97?(rK1cX%b̆Z_-W^'YQPnW4?X+#w"Q=;4g[9ꏰjTa`2~1'|*uZok hA/χrCfʡ6D4_3?akv~SZ&- Xd'! WFS? SjN6Tw'U3+ˁJσvVkʐyOw '*x.W=m.f;lࠠ} gAށ(LXRTq-Γ?>l߰x#9d^rڽnTr;~R`[ZOMex% X9?1ov0 Z/]uNlv:4Gh04h8?82RyBpWynʧgJ3;"5h# *ЅD 9oĠF{ 6s}/7; u/+%$C.]SOLV5ĀhRd/Nnjša.pz\99\ ~ҸdF&T+ L)\4Dۈ$JpUUҐ['%jS!)0TLŜS#SM9xMtoo1)iTjYT8Ƈ_Br g=1M~PnkSof}Pb$ Ĉ_ŭ1q`xEbR( ~:fXIu;MߪmoD6CԌնj*L֨z+JOUֺ.0;KOcE;O;xQ`tw7)6z?*E:ʲ~m:( {/P3(&)g,^MfXGƨPEM B15lx:+&oa$\Ew0}u IJ ߘ@U9.G1yK/ֈac5 Ah*X]pFqFj8$US-+t\b( ǩ!4$$w,6'(fx~8y +auyesKZGծig '&?I?UwZci<34,A,FJ!#6l^ cxkX Dlɐ ،CO {$mwv1H:Onoio2TC!s.UUiKVU==I a#hN'X5̺ Jj]QZ| au8k.#_[ +0*^dFhZOmA*f2GZ.}㘜Jq%/nUtN΁FXwߎ*D>ȺMBP,!nQWa!rM @6GBkdn9PqIՔFYjߺՔfV ,N34AD8NG ۟I3vLL٩pOt+فe(<_XCS˥n3s5e'egŠͳ*Ym#|ԣu7}_}2x<8u;x7C|GKȶ"p6 4dsr;0+ _B-rg%nvww}""KWH5Byι$7yv ؾj;mjIR$I٠Tkl yCaڶ?MAԝHQ 8oGUG}o?T]Y bASOHw<^Y0!k2-*v9Z\ ط@ k!ei|<00$jR׀v||ge{>an;._Ez_,tbU#Ʃ amN;$?Tp|`+ǩCۡ:g3uQNmW("o /ܷ$'v$w4y qEDbɝ^duz~4b/W?Yo/.?R=@HiETϵUHҜ) fdxFP{Ȁ+k˄vvzhCwH]AGݾ34(*kd DFƯ;Urh=>XQcra#ֵ)|WgH ֍:MRLV$+ d;;CsƏCyI{~]eۋ@`r$p^?V~2wGQ%,ZJ/89Y '@5hd 851v]|xNZWLES׉f`yʼr( Ri}W?d/HǭUgFgq#GD[uF,x]k''oG렘- i_ ^V᩿grּTdešon="PM'F[a"2mfBiDl#2](%p'j&iXۏ}/܇}uLui_Y#3=xeyͳxB6P&S:$?qu  >1!̩)TH}$L/4k * rQs3 dղ]d&u2SZQ'2ڤ .iP]"0Ce"J!f3t9\і(#t]ǔR*yþRDRiTnR2z.buffg9V3+]7J-cDp,QqN<|Ty򆚈f~ }ՠUsCu_Һ/ vl@Ed,xE1sռzBcaƺU6[ n"^=O`(Xk=7N/:^P'\34=dnV24EB L#{ܒANUi'жlζ4$_mSQBΜ RF$^|qr}U;`9m +oJXR:ǁvdb5 Geb簍-rGU "̜ق. ®Ty=%ôz2^Â; E"5JpSt>EHcΈ| "SBM%n#&Y@jpO=E /O䕇A푪l7EFE-bzͨ{#I*X= )cͅouFeeFY])'jǙ#ta+Np$I0F! 9Kڥr 䅐8Lpv>{U@vSDwq1K ,13optq=yBt4S>Ìgknv<`N;zkŦȵ߹6 &-{+\!Qx]XcMUp}wԚ"R 6eH$SJi !Z Ҟ qH=Hmz=^T"4 DTL0 `XNe<zd8'KM`s;mb*4is6jVWV:#)t}%D>1EV!tCm/we)2^0O 4}o?a{H}o5&bFbd?J%sF 2wL^je*GjX#PnΨb}!ٖ3QHA!K-ZAy(zIOl.0R1,sdYo5ILI yD#Gcu"`o9Ui0•_.r5e@әu2{VŎ}=ZE (YW6>3F {t+o}.#*gQ6ɡj+TB5ޑ6"x*5h)1\`%E]ԚMd"U}½a¸F t$;IUs/ ݞ9y"5]k@I/IWGr7D.9G&3@UUA#c_F7s^!"$X_k9_t`F9pk6gsڕVh@o,҅ XzUDbR;|E5 3]u+xeIi;QmLq ,8g[2G &Kj**ͫ >Z] ^(ޥU05k ^X L7bYE1}ebZEn:%x:W#S:`y^ 3J@764Fh}&b׬.D(3P3ENmNϽ3t^ l2r,Glz3ެu0Gf^s$aqęz;1!izp=y(b se46HTCt-H/\mP矘;y8nz.FmEaU["3OyobN8."e)i9-dKZz^%҂UPM2LIl>B85BJ!Gfii$J+:A\g/ltdBiE8diݪ:܌ABg.ʔYoc^a&nӫ㸴L6ӵ+4% ΧEc0f-Apf>A(zK'|(u*B6%2lhinC[$ #)W"go?Gklfm3ҭܻFZX[=Z8Zj2^EziXUSlp8:J^+)e >To1<ˆ >uX &3Jj`ɬ(T`H^V"!zM`}OIVnӧ/F҆PHp/,;R/ ݠ%dIwp:d1\bi`=w Ӻ1rtoUnIM> PT@| UG(ix  s>l")mGM ֯S7[W[Rϟ{6ss! ۜv;oOڎ}=4<l8 :P;v";oܓϏ@y& !E,Q\{on0ȨCy܄?#5آlś~1#%_  6$l_hFX`M ]}h>DޑoqpprmqS}X'+yUAufCGOMO,bғCJ:dQܔ)/h) lR! UPr^w (m%eʑpJwe_Q &͝Χm -K1I֚EZ|y:<˦N W(I1$bWxMXXa$Ŭ/ @9iy{##! (-kC~dX,C Õ_U ZqV^5~~k.}[̷t;ng$˄UȄ.iMNhp\WhDAwB[i oʼnB:X.YHgrV?$(Fo#yZJ lyU G$rnokqDexY T PjMGAIj8y-XF<٩"GlE),l$[PhY,nŝU\C͂9*rw̝l/dHJy.E V3dN$}W/}lk3fa5 / ol?EAG_$R C aMo{ہ) $zچٳSݫ ezTQlWZ602{0oURo ` c+a׬'VQ=NgHxYDmf:tŪaA5R k:f8 :lj˫z(yW|.38͠S<(ML'=bʎչILWȿ^>ҨieК5hҗ$b+oWvor@N>,#0#@=x ~A`{ ܙ; ;lHI~Nbi5{lQqpH'KGEq;脪?t49&T/'KsKt .;j^L8M5غyFG)lHd1 %PnyTp Bf ƸWO"볕B]^2xcc$RD0-0lP|)~YcwbmfZf٠$%KԹۮu|X.~?B5C{?KvL呥Ʌ^4X0?辙tDMn)ә_Ȭj0|*D -!W9cfZ~DhD/dy%6ᛐ_ 8RhԂ6;%dxVZbJUYvN@a5 XAp9[h(stB/tc (o 'xDʇ{F YC\އڏ~^3dܴ1L YY,{3ֹ;óiyⳅX  M<ȸWIF@݊çSx.g s6,*Qq$ wbk){5x΅kZ-Y)+e`BF`r9L;~*"84zAi>\>s$mjעكMR4޶ F]eG&((o@_u\ DIVۋT}Y_0Aٌd#DE9P3ǒAQBZAf%-n /Kʣ.tp%jWN^sru9o@ ΍c3 QW_.n 㰏*0k+*2SA,:2[' c<8]~,KVI=?R^h𴕜mс.ynXUcrTY$瘝ᰭhtZNs;?}!;R}rA :|. t7e5F-.[ ,P?f ϯ#JXP#bSUL[x.a+~ߐ3!xL gA?a\ŵd }J.d|_ۆԍ /'Ѷc]Q3תbPKO3[suߏ&tRhL@+<@ڽE^<(kQQ?)S"Z 5puoV/bu=;>F2RQӉ i.<Tr9f-c$Ed yr3xOؕ3K81 Ԃ)karEEX,yE5Gpk|6O@+ `{j_`2FΙED%PN6(A %fwK|l2*qEÝqcLmԚeNϴH-f0z#MWe+y=qTeYw.MX!r|L\m,w:qꪨ0n>鹡5 L aU_>bWїo#=RiZˠ EYKh,Ni!krα>Nظ>(G M]rK@M'G[GPlv'PH,׀W|h.N_?" 頀 "uzTݒFݿ0>-+ZD,~^Bz?,QlƔ!- JnhЧ:4mNof -% npr~7")V~^7FR -x9%ʼ%`xY!CC6)Znd/K+ARgW˭\twXs)ӊXHk$e93w)XUKi,-@xS]~Yij`g8Gv/_P uqOrj )r± v/ ,dot5qj0U1$:EB]1Q*KWdb0N{*(73OgT=uTDMCVoM&R6yw~lB`cʰPu? U "m&ܵMu{mlBwgc>=ߴYr v |B-:\~(3[Y MvowXNƁod)RR_ b?3~ UzT1jh `4Go)=@busIQ.CAcPy8ɬFOXY-p-FjY);/:&ܣ"JɉzA*9`p2з]r8O/3c9$W4F?|:Y>j[E)%}C;.J̮?0|B?AyT*%z~R5ʉQ0X+UjoF3Hp0NևWWW84'M-&RˉQAT:4:2گJmټO}b9wU&ĀIx/Ie[ p}5 RJ:;$~3l[~0QU$څ5jL1˧2#d6["@1hsaVOқ B/G7Ԋ Y {o0m4?z3\CWʂ7qw*?u%P O,(8Y{8VTO>UW*oH(DEN8emRz3U4}24ޕFZ8ҒJR8O2]~gS4aЉQe([ҫ6tnݯ^iTik_؈K~2K >X4 PP Dmzx1\hR)݊AWtG'i1ج&%=)&W谉]0Ǹ~7]Cm[I0-~3=PTTa lN. 7\< RnDT\ʭuܵ= Q]i2pIfwDJW_0JWp֚BŸ4o$k]D$e=smy$dг|*O3#JNGP>Ue">%G6WϰYYI KFd G;_BTn6 K׎}uvW%D;o(X&P:Lֹ6ޮ6'F'iCck5 `or>9`Vm2ɧD.rE%$յXsQKKDJ P5M!6Ĝ%,N~ ,k`)4ː@/ ݠ xISCl /7ҫZnU-?!ƫN g= 0q+GTabW܊'oj90ԅ+ί}]m\(VwSMdcUtLܡq:&b5gE7&ߚ3'y7%sЖ7t30]Trݼ1/Y<9 7O-Š(vG00UKcPk[ V8]xzqqKbZ#7g{:+^."-5i Wqtm^6o=[@ rؘJB= C 6Q[{g>e6j'nu\.i 1h7$z d"%="DC6_mB۫/xe1:؅K ܭ"D*AVU$X_fIOa"7ڐD Hm&'r <0DL*P TA3Q]0&/M;mvX6G !7X$ިg =n4<|c 32pk4OݢGD[R_k6TG똤uBҌ̌%|aq}9X U"]"Vv×5 |ި$VD =f ': _VBvܢr.JS7KYp 4)UۍVj>rFGwxm2+ZYtHIr +Gҽ=%[C*[-yM4ɩ=oUB"Pq,JyyK)x@hhG}8S.0/Q:|Җ՘O 23zA)?-\~Qe=kxu^Dޜp:~ ׺NO ~NܴʱpEO84(-jlN+oE ] V =q>kϕ:@p\:9l8_&SUXo륄azE~"ui&1>$9|B:҉?ԥ5PiռXkR`ŀz3sΦ-\f_khA.;X/itՌr%Z9AIKPKP=B>X1=;+}riQt& v|f9!ɰkEc/K 1R·IsC@ڌS;gOLOQӫ4gQ^N֙vti;R 4IJf|xTOK0'0CˀT߈*fiܠt䒒 6yRw8:n?yib?iIK+:utAT{  6(^I!#¼u $Z2W GU`T` 41 n]j!R-k+Ҟ 9oD ժ~ $~bSMwΨIq;)Q.z$hc$dO^ +`:Z؛kS>Sn+ "qڍ>BMQdjWJϖ'S i+ZdYרu "UUfkMכE΋ fcB),чbrio [q@<:*N "̗Nw ~yu#Y[5q陚zie~X6rn#uBй|"I.zGPUU6E=[@&"Jm:74n0("lWiZւaIbwhǂhGR oUZf IvAM38<=(dR(,[`jAP̗s&bpcxJ.?4k‹Lw+Jy>бl<:mlqO܊"7,6> LX<ȴhDkEہT[̙wgirnL,DRîW,7ĭ%rGzt~DTԛ$RqP\p:%bD=m Ӣ*Õ-:,=Y3𝢢W3͎tyNx9\p 2M)qc~r[ΪU Cb`N'R@фJ-Rߡutdz_|3|$IyZsu{9:M_qO'S|tpu;ÜZ18}LY#Ͼ?."ėÓ- 5t%q 响?}JPD%TO^m4fBzՃg$|^/K>E鬓H auo3_*؝z`u0H,51nZLZ KyJmFAd(2ˆ"EeSm'k^s[ҰVzEGh& p> YܒCi ,Ryzub3e*T1gSϜbn$!3|hUT5*87hHh;`c~P61|!)/AM'Xp7 VU61h$0gF5`AHsk88V&*<Vשr"eMx8 FK pbC)b̧TbhM˾M!{2HKdeyg$w}z?cY)ZR f#@aIvs0;:ZؖPZ 8K˵S8 ՓSΌV3UMiWxl'] IPi$HtnÒ$i4CrF`6ʊ9ޞ"|w dϾ &dj;P70ro?HzY_x<&zJiZ(@;s 0A ѓ^0J`h);؁՚;O yd)N}suJzD3kBƀ`F7\e]uz55*)1/wܻeۨ,e6%s;D݅/qG4:EKt[gIl<$yKόiڿWrR"])D Ưc 5wNJ1 jҹ'~Jqgr~cذ#֋gqdzIݒ0b )FfN9;4ek.`W1 최!(;&L1~}u[AT_>u)+6"61ϡja 4~NfQj%ԡ6VI^T,}5LEbuw˯vʩj-Qf _h_’ BSI{diJҎ ^BRib} + & gu[]Aڃ(MG7]#uY$\ &mؾPNU4lqw*CpcyRx^y3 sa֬;10h+/G-9{OSNd :ͭ 2Fxi/73$Uڅ6U0} ÇBz*Hl%|pSPleb'T(w{i^KArsr X4V'7Tv GKj@XQ@F=]RGFVb(:?pnfa){WYUv0&^%ڝll,]ALM Tmsb/b1eų#x{:'N&$N}!%d{StJ_|I&A.Bbh@PT0"{HkPU=1սOM߬N nH†'͉a8PKL('zø퇚E C+e>N_/5=x}"3N2:ȿO,MA5vZ;o9dhxBVWҺ=k"e|2H:fzM adKH#ґ]{.# 'Gb+ʞ#eT|wMmm@3H{֚ $!|ƓnXVp3iKLf Yw[ЙJYD:w٪K7YiMM%}V'u]"#Z-.d& PXk2gQ˯$[vŇqyIes1j25ҟ!*M$u[} $p㗪pgUϡxz)B~$hZWv\XgAz[yjǼqsT͍?]?qJA㵵U0’ʸx 8 f@<+  ݟyG+$DT+kh*~L%ggdG EJIS$ ߔį"lR#'I?p :vw㤍 @5[~I|~{ǝ0ض"ᴁb4Ҡيl˝A f)U `96*?.vUZ7 oxJOPc|o򵺌J7iܜFM m |YapeF.ħUX#!oRF3ʼn-P8F7lYK@IIel߷+l)t5bKwmrCh!.J+EsseiKGU!e38Yz~"kow~_?>xc#9ihuk&1Xw=o!g%|D &TRz=d*`ռۗɗ6ξ-$*Dp:|KV/=Zt钱ߐw"WJ+5 +4LY!_Dq~,UyR\a#֘` /cAtSM[JG|Ɋrǵ,cB}wz^e6cp [3HBb#.ҩM?1B`{|•@;K l׸$ND[WJwNtb$oIެ Lf41$tѶ_Q+ޓߓ.ui4NNCFi77j,*@VNuR0y..M&@B``lF"-A>0tٴpˤ䟻&ͦ:'cC( _)s+>鵍V~m,N(G Α;߈vHwq\`Wqz.݊1iF܂R$%=Zz.[\l6ɐHw-ŪW(He(%WQ0 ﺨFE*4w;>T f=ݎ؋;wX?Wڹ]]/( ^Ľ5kĨ(9WMCΚݘ O=Y#;wFnk/ R Mټ' `yꗫSx20*N^u`&Bq,fٕ_4^|A\_=3SMtB?C&)O[GW̎>j6nkONΘk^Ӵ8IMӧϑYɨ{U ͞VMuO4dT_u^z J4@hJv!@m<@A_wShJ_ n༺ɦBGTdU`:Bʄ%& 5vuOl\\ װ^ЕRu1h/aکZl)&!EP`EނZ |2^Ḥ:9{0?&g:ΫqM%X-+7J />MV9j1*?}RWG\a|nF_V}u1SxKP(U )2ZtPlgq^R|!r݋ @+< ?TSʦv$Xj ^ (ebAI[R6}KZFt+Ặ6IgseOlX8I"btޫӖZi[}naX8 #|I VL'G]܍q4Iȟۗ&cauBњn.DeIĖ%-)j;w/tN"4w゙݃\b3Q#g%ޟSM7y%#hHt,mƊ~C8_X24NmC +(VIqVs2wQۢ4WZ 66"(dpVJA%75}Q8; ]q /kVK`nq7=hwUJo\Sz?ljc8DgɥC,N^չœ=}F#мh[YKGGգZe/QR6ȩB~#vuBDDC,mfccfEslOڦ4?}x% ҄ilXp`>IV|v.>mw2,e>[PE/cA#7[W{Ʒ~CM[d(YdE{`9L郤7Rxt2GB!XSD/*EWcޓǭǙ*G搟>bҩjF9^E.\9U(Yۘ֩:'o\3z" JnAT^1  ૣ HVwnέ ?H ($$L ͳ-T45 ť8&ήhZo9"|lE #'C8V v݃y}?wqQ'_H-)`,*Acv`U6c||?TBH=PjwO$ty(kl^u1Rb7c0&7AwanSڭԆw$(LQ]Sn'%rVWRĵ3/yY׊b'^2u8QtXf&DdAR132bjVsQx_ $6a2;y/ڵg Ş])Q#XDD>%KWͨ9DZƽ:L68{0DEF +1\PtN͝> Er"3*td>A KV2 Om7X H!={J>^cA.dd02;K. 疊|.NKJ49,-3tu{nϨp)烱M' VI>9Sj~[xyp"9z΀kOڦ^=k zpFױq^9H=&#4qY,qßw+&t:oH:ZZIMgWHv7sѳ&nd!n*?G|J# IhBܨ0֯շp-6W@cI:gL;!VnJ}}5f3Lf796f|>IA.*@NJx0TO_K1"P(^GjRCa . 5ԾgCf:H<@XUV^j{c'A4G?R$OiFy쌆7_cŽk̇ u:r^=Wٶ/Yˊ!1=&z[yJb%<3#> P Gȁ0837}P+ӋNRwA&6RO NS~)O@)&> WC؊#> Y7%(G7Z;i,3`ILFME^-f|(wWDd~nRRl$Kءp'aU+~euN]*c=ܶ[ܩcc@_PW(<+p?"}s1jrӰ;7a߬uB)9tS-&NIemӫ>ږfoK>:v`$s8o¹[$6^%$ddJfKu!!Zq1k~_ pi"/f^<_XA*>`S.}P ,><^ە9:b #}"M"lP*t>Y7p˂[H 78.Ud8q 7/-wb\Dጁ(WiQ+ƢB0'oP攲 p5ЮhZG%Ֆ9ٍ&q>a/:(+X?醢V+EDh;,ϡV)) gNCquw"?(36m8FQzWdD;ߋnӠ_U@@Sиe[K"n^LS\% |H`7n6.mӎ Uz'XBK7RӁQq1[D6`a 21&,݃d^[{T!aϔFl/fg#H4Ѥ_ lS]}NE뿿}{Pd$^T O~S7E3;oZxE~X_菥Mbd4{0 4~HH_L\[؍wrb6 +ȑh#T% epD>BԷc" wg%9NizxU:면ORjswpvC[k8j `J gF\R4y (h k-.n3jLr((X{*qw[PO&P7Vmjt&/NMYƈ:j:94&a7=0QÝ^6l)UvpT2PgD7j4D 힡^@aж05רQ-1* )jqW!= \{xS햠k( ?3 >p$-8ҔS^a ⨊=(;Ҙ_ n6 Wb«[HEAscQXRv j@i}swϏS#8aɡg"آ;N%FD-R2FTb^ ,4~
d)ِ]'0OLKׁ;\GI V޲Pa<9wQ `8⤼Rv4I:zHZʳv(Wp!%Dxr J值?CWr ӻU)TU(=w0ЊmT&K?7,Or;E+S^WIjvCA(ZhdNoDFy }^gpܺ)YYk_>L~?NB9niSkN8gaC5o mlnoN~5p HB*gv<8M?E.p -+/Y z,@ fo,? of@(u8T_VBF' U _<&/A7ʥ}_foܾ0;;x=T-o1ٚn[>Q8 ~qZ(nIz~mӠժ N5S6MB9%+|a5{0k?:TTU9Hlbe(q9)ϘYIS1 j(=jMFZ&i#7K`-7#%ʉ9 ũUeR3>@}QSno\Jj5NN=K~!D2zȩ*{ަ=D C Ĕ2!V~oJ-heZ҄iǩ NFS#\Ylg'vE0ҷFQjYKmE!pBϱ"WdFN^Lra Ċ k·"%ͫ3IcρTԾQo{uGsxR!W1 D.F3'a#WLC72|)ҠX>zQD+`p6@&p0qY$0 Y\!ᩮ#!]Wzc[ruLwCOB+!'Ec6ٛVz?L E $KI٠6֦e15o.@#<̋)9m5!:=]" ak|urV@A >3t5m[`?iUԡ\E#;Y$A*9CRo%EO ұ$Ī.Rg!u.ޒcaպ5d1?|lݖqwċɩ̎?Khe+yN5I2zazK!GPȔ{L~.ffVc"d~u .gڤX#θ^?YKRx|L#'{VQ=#GYxQ @1+Ld@*|J ]/xh!$7 +ﳋ]<깤g (Y J ά. \Jc]:Po׿G﹨Uc5@uW y Cذ7͛jLwg>/i6_N{=E x%P/H+nnv!-TBwgj?b#\|pzXJ]\-0ǣӿF@ѓ= /T3/B*ͫY*gbevq)/1|k_8 R}JCްa(gJ b) ń]iryĈO76@>?OMl`ąw=:9k=e=B S[!, 4tł{{*@ IF:[1:I WbRɂ%$Ks-u2W\2 M;.ȐC`h象W d`$'B87=:-ƌN0uQNU+(rzz4.3Rvp's)*HR>meK<+kaFN'Лx- + _(g󜶙62NtfMdAL zYޝ` bأ* cR3H2l]۴xoIJ>-~iO]aKe[Lvʦ'f]\ޅ;ʱCBtG~J<0Z8팂dcSn{K54EtjYv@ɑpǰXӮN'J9d5H1Mrw-:ynm)bXͪw}5O CIASz.$5%Vu!˩!?PW@*/X;$9-^s!1wEӖRo1rru:F,ENXgc^9 Sj,xTЅ8k͉mЇVuhB'"۽ΊyXIBLʿ$րLhTFy?Av0Hdi>Ng)tmX9=N"F'3bXú?7>> cr1Qn!^GK )NP+'z#sg!V) -5Í]mhܷ`3Æ3'RThI`Aۭ@a8>KΌx)0t(90+ˁEC$!G },[WΆȆ/yUXeVw=2D\/|^iL 5#_kIZ评po$6whl6٘R }aZ/_FZ>5 Z!f8M Y;8Z)yn3OBk u`1oCO&(qB; h{؜df|VjF9q]G %cXۖ=,uH~cp" pB,vhCFw]Z|`6d3n*-3y(l~%,ub?T`Mx6'.vh $Z5.P b ah:,wbd\w`.,oSZȦ+}p/eVPmMQ詌$4,,VRߋ3 )%ۍ~wmXTE"~\+|6h01 &c>J5g~@<[GarfB?[J\E/M }c '1(AcuM_aFH$$DD7h~j?>%ASҢz=#_O y?0Q7UgsfVOf0-Sޯƹ׀ &<. YZ