sssd-client-debuginfo-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!M ]mtZ`Y.Z6Vp?ɏrH@*]d>O''. #mX沚z϶}dqI#D /̡`MbvL׀O4R RQz kk#ɓ= XA,ݯ}ÆUW&ʴ{F1I={o#x47Q4781_i/TCc;4$-ƕ;#8QBV%|ojOEDD8H}ez`\%v{T^4)E(xJ0e YKmfdZ5kA=L-'Gb#ڍ˸/Z[[)Ie+ogowT*VYEa | ;) lzte  z"v'/] eUJ H ~)gIݱ2]Gv*tbT$ƛ?a8b̀LZ}J^abe755da673ef3a458bcd7b90a7c0aa845813bbcf2edf99d4df21dd3d03b6235b0dde07eba320adeab18d94a28b7a7f3207bc822hH3!pQp)Tξ7]mtZ`f!M ]mtZ`jtDW/j{asODٴV#Ze|XD qȩ@RLOT kohnզȂ!y'6ImJ"Fk\8_P␁JϬ{xVYRgƴp,:RnȒ=V%KY~ )N~Ƈz90L 6vpj \+5/ջދ; Ah״{, 3D)Co-dti@v1+q]"e}d)ni8b,HUhОГCB#$im#zVoPNF4,6c@  tVa)*K A39 @8}ȱR@8F(V H>p>H?8 % O48=CK i{,T, , , , ,  , |, X, 4 P, b(89h:jGL,H,I,X Y \h,],^bduezf}lt,uH,v w<,x,y4sssd-client-debuginfo2.9.43.el8_10Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.f!<ord1-prod-x86build002.svc.aws.rockylinux.org 'DKojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<o<N<i<[<V<N<R<g_G|,,PAAAAAAAAAAAAA큤AAA큤A큤A큤AA큤f!;f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!<f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;f!;c5e75c0665762457a9497014c4c20e46d6a5975b8b67612b1e7080f7d60cdb212afd7a878c4c7585974e03bbebdc80c830ec3684dabb0d0cdea1d6101e8596f92721e0f3e2976eaad01689b837393f4c591191022410b49ca315d2992f2a9082c6e132fb4627847baf76d9409ebe4edeaf6af34bc916741ad8fd6281cd97b49aaba19835cdb5d9367e5318d7181a959479b76c1f50a9e6a5f5a75481cc91a741534a5bfcdc62a65d46cbd684d7e7fc05963ba834dbf282745ee64c303f19046d20cb8950f85bd0427886de37c81fca415cddbec76c62407fccb0281b8704ed693e310b55d99dfc7535ceb8d4ec11c89bdad8894a461c1294f4e1ae57148cfe38../../../.build-id/23/42ef03f5df94c351cc0d0f85cbf0f0a47d7f0f../../../../../usr/lib/debug/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-3.el8_10.i386.debug../../../.build-id/39/b3c9b50933ade288115963156ec8d606bd72d1../../../../../usr/lib/debug/usr/lib/libsubid_sss.so-2.9.4-3.el8_10.i386.debug../../../.build-id/7c/29b92f12a8137cc633d80d4fc4aa75ff365b13../../../../../usr/lib/debug/usr/lib/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-3.el8_10.i386.debug../../../.build-id/a9/4fa9dd8da445610eab25b98279e187835586f2../../../../../usr/lib/debug/usr/lib/cifs-utils/cifs_idmap_sss.so-2.9.4-3.el8_10.i386.debug../../../.build-id/ad/4f2ad241e40e67125ca1bfe4acc89b319fd7b4../../../../../usr/lib/debug/usr/lib/security/pam_sss_gss.so-2.9.4-3.el8_10.i386.debug../../../.build-id/b9/add459334ff4961c14c772b7a75a0ac9179e48../../../../../usr/lib/debug/usr/lib/libnss_sss.so.2-2.9.4-3.el8_10.i386.debug../../../.build-id/da/3fb40e202b4a528ff981dc857ebd0f7395a225../../../../../usr/lib/debug/usr/lib/security/pam_sss.so-2.9.4-3.el8_10.i386.debug../../../.build-id/ea/bf57b8c54956a4bcb262fbd88227a0dad48faa../../../../../usr/lib/debug/usr/lib/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-3.el8_10.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-3.el8_104.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,2342ef03f5df94c351cc0d0f85cbf0f0a47d7f0f39b3c9b50933ade288115963156ec8d606bd72d17c29b92f12a8137cc633d80d4fc4aa75ff365b13a94fa9dd8da445610eab25b98279e187835586f2ad4f2ad241e40e67125ca1bfe4acc89b319fd7b4b9add459334ff4961c14c772b7a75a0ac9179e48da3fb40e202b4a528ff981dc857ebd0f7395a225eabf57b8c54956a4bcb262fbd88227a0dad48faa2.9.4-3.el8_102.9.4-3.el8_10     debug.build-id2342ef03f5df94c351cc0d0f85cbf0f0a47d7f0f42ef03f5df94c351cc0d0f85cbf0f0a47d7f0f.debug39b3c9b50933ade288115963156ec8d606bd72d1b3c9b50933ade288115963156ec8d606bd72d1.debug7c29b92f12a8137cc633d80d4fc4aa75ff365b1329b92f12a8137cc633d80d4fc4aa75ff365b13.debuga94fa9dd8da445610eab25b98279e187835586f24fa9dd8da445610eab25b98279e187835586f2.debugad4f2ad241e40e67125ca1bfe4acc89b319fd7b44f2ad241e40e67125ca1bfe4acc89b319fd7b4.debugb9add459334ff4961c14c772b7a75a0ac9179e48add459334ff4961c14c772b7a75a0ac9179e48.debugda3fb40e202b4a528ff981dc857ebd0f7395a2253fb40e202b4a528ff981dc857ebd0f7395a225.debugeabf57b8c54956a4bcb262fbd88227a0dad48faabf57b8c54956a4bcb262fbd88227a0dad48faa.debugusrlibcifs-utilscifs_idmap_sss.so-2.9.4-3.el8_10.i386.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-3.el8_10.i386.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-3.el8_10.i386.debuglibnss_sss.so.2-2.9.4-3.el8_10.i386.debuglibsubid_sss.so-2.9.4-3.el8_10.i386.debugsecuritypam_sss.so-2.9.4-3.el8_10.i386.debugpam_sss_gss.so-2.9.4-3.el8_10.i386.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-3.el8_10.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/23//usr/lib/debug/.build-id/39//usr/lib/debug/.build-id/7c//usr/lib/debug/.build-id/a9//usr/lib/debug/.build-id/ad//usr/lib/debug/.build-id/b9//usr/lib/debug/.build-id/da//usr/lib/debug/.build-id/ea//usr/lib/debug/usr//usr/lib/debug/usr/lib//usr/lib/debug/usr/lib/cifs-utils//usr/lib/debug/usr/lib/krb5//usr/lib/debug/usr/lib/krb5/plugins//usr/lib/debug/usr/lib/krb5/plugins/authdata//usr/lib/debug/usr/lib/krb5/plugins/libkrb5//usr/lib/debug/usr/lib/security//usr/lib/debug/usr/lib/sssd//usr/lib/debug/usr/lib/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnu directoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a94fa9dd8da445610eab25b98279e187835586f2, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=eabf57b8c54956a4bcb262fbd88227a0dad48faa, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2342ef03f5df94c351cc0d0f85cbf0f0a47d7f0f, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=b9add459334ff4961c14c772b7a75a0ac9179e48, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=39b3c9b50933ade288115963156ec8d606bd72d1, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=da3fb40e202b4a528ff981dc857ebd0f7395a225, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ad4f2ad241e40e67125ca1bfe4acc89b319fd7b4, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=7c29b92f12a8137cc633d80d4fc4aa75ff365b13, with debug_info, not strippedPPPPPPPPsssd-debugsource(x86-32)2.9.4-3.el8_10utf-86c2e361cb98bf11716dea0b535d0ed4c66e82312f6f4d85f639e0cb0b5b9615c? 7zXZ !#,h] b2u jӫ`(y0@o&yC[k ʺହGꯉEC-PB\*Vxc*#y GKrZfb >! }1o#IDŽBp%mzjhi~6quװN$d6|vv t?y~LVվy9pV,pe .#uWe~ ;4s#}eK>8} Uq,X|,F n˦vTcf3ENWP!yD^A6R5pQmdw=p~.P*{#aUiX]Wnd)IҰ]cxߘcY%'IdF@"] QXMPzݫ~vʌf f|ޭ3CAnZ)bVYzaX&G(MNw&FfiѳCrFeoߔ33Sbf @5M/֒t=]hq+oSJO ӗ0 iqT ,_F4 'k *4;M\R[֪-Ad B~3 yKVı9*cQ!Srٟk W xe$)2c3fhu0"7VPE.0LʌDZEbz]l i}ڹJ6Sfb9(#cByǂ$}xvfadf4J;CNv`̕_Y?CTFPv obLfw&O/=@0괧2 M3x` 2C3 %wqߣt\/QSܢyCϩGu}۠D=N, $z{ٖzuuƽ!:]Tcc ;aC?Q~Ej=6.k|O> )L8T-EX$]Q)$5Ps\(Il ~KF;XR `ۭ,R;ԣdΓGy@ eOxXHJ5G~RH8j$ އLs.&|:&?R oWމ ["R9Pmnj't>ĢefJ$z# 6⾳ 3^Ns _N%Ah~nХ_bLD1 /IP}=ʅuXQS`=?{jK5>-s(u5H畞FĭWWntШGT=ISVøcG鍳0`AZc)m]pV6M<45,(ۡҬ@3pz=@ fЪtG9DxO_v iymL1C ى!6xDgV"$V09§Zʧ:= %W%z^z=iҍnd+SO$CfF$u)VP황Q&W掙p+#iOEY)Pqr䨨5ܴNn*|O+}euׄ È\o*9K*\K"cH>8995 }F-5,p crf#yFijJ@*dgUǙ"[>]2\Bl<?W!,%He{#'Am/#*Cyٞ0*&h'X06lCB.ɃD`7r !{U!|5 ~~]1f!hiDC^*a+RƉw(t`+@1^4$ɻVPwx-cBߎʭڞ@ɠZ웺ŭ`H7<Zl}{pE1z׭ ,uD^РA%0uA W4)&E^@/I_-w0Mkbvv/[,Lj2Gů)h8ʆڊq@#}UV^i hw\H9T3D߭f Y P xv| tXmMje%.aŊ"Vz RWLٯԡQ;8$0xCBƧeOf?]Mb)8ЊqZs k.:K BN*Xeںe2\7ۗg7T$,Fw.)ħ w}K08E&̖㠆B WywV /$f+?ESK=W.})N ~Aid:e2CP{)E]އK)"r `! qwsdiڿkr5oc](Ie8svJ+X|Hk+d_h(V9RqܯH(VR%c?k=r)Hȍ9 >+@ (d?F-9R:? Bx};Tu05Ƚ>ZB #QGjЬ=ۢW|׺*1I{Vkbq =_&W/_+xG3tΔ)L0Jo&PkS0}ّD'^2YKXڃa plC= {|0{U;ݰ')K ЛrUd` ۞t Bu)ơNfjڅ׸~LqNf*I8.-@ 0lRse/%?c>F_{f0_-T;sz|#a 撓 wskeZ^8^_o|vȝi,iDV brpG~gbysq'S}nRu}#" %[ӏ4[EfTjt4s#aQ?15[Mͧe>=%Qx22_E/=Bn;INY.tƷY5`s[8x[< n:E](J ͛ELȜQgƪIST9~]ٰԎ NPj#KZۍ5c @#JIʓ,>?WnTd]ߏFA>׺B?Q |C-)o`1['G[tMRɃsǯLB6AvrEmET#7oW^a7͞Xٴoc%^0Wk)v9D{GsYfI*i$'>m?sػ'1RL/s+F _2 >g6|&'?"/ ˪cHd1+3樔lo-u7Hd2tޅld{$p \?{)^{QlL~>t 1`Lyo1L!2}y)E=۸-}Maԅ&)4O><5PM;S٫QZJnhiGm9.B.3ܮ.V](=H<GR!Ir$~u#H>$&98hݷ^>7qZIga#Iq ڐLFΏf"8!2Joˤb?J@QmX\לQI_ Eb 쯌?3qM66r{+RXfd7袅Yc3CO8=Zʋ[ E<}5:xZ;.?=i~^Q\Rz5B\rnڢb\/OJUqN"`#ƾ)ź$tčzʏ9˩q kQςevAp҂Mk }E O-v}^7?[U^F "e9*u]WmmKكqmH/hБ&p1-fA m\9_̼ [lS"u&R* oM*n;k.v"V*p dC$#}˛Bzi$R^F\e5d 8UHȲ9 _rFh_{[&citC5Dޏ:]D kXװO_R7ȊE7zw9P19<|,18y'.cx>OOޯxW y\˟,w PXr)+Fqe7uѢ|ڝ$v?mGsg\L &*㵡G#Ts?-@$apʮNToc_)>B}?B w"͸a!V5mZV+[YJ00/.wB cg"o #Q}}n s S"G>GYߛLQTuq#Qzू 2y/F|juڢ(/ ZU蹱f97M?yy*ToKkz`(}"?yWhoQD@DJXi-< J@>>^1Pܒse ܈&OJ`tمD8w_ \Q6%okkj蝛:uEܵ_=xC0EŶkڝ/Vsh'+fU],:&}k50 &F[Tt3ΆS Tk"Tyz̉@WTk?Q_#&z⑴fxnm?˘"!~ ৿8בmSa %[~Jr >$FU4n@{j\ d ?ɢOIQ?V4\8I>PBuѦɇJo"&;IuUKCONf 6uÚ$+Bv3jX֋7@hH,VNNUfIB z &@53r+|途#x xAzğkXDR~Um07rcp7$fLA eM~)+3O`8K&m_)uTT " YD霒LFK5}C.}RsQ(eɢ=PVrX#}~ G͟@ry:s!ͬyh0ߎkofP +wRYGbz0Ga裫#.1򑡺dhW Z ;q!9xD~=~R iٙDLS0OP] [%MR ^ _i+~ B$1G@/ý^9.Z-֣j8juc* &CDr\ps n'vDژ+0̒TIiZ681c,nMwTw<J͹]s4S|p[gn| [NG n^%PmץWNЎkY=3`A1@RɣVw{{)h y#3-Y`r [5)u2Ǯh!ȐxGXNK_5*ӓ3$2O cz ĀgwDi-~Tn$[+bohR.Y^" "ыa@-Իr)^tq(5 X[Otlk,T5x`"qْ4c$dծ0Hn|*يV$=IWbW/t9DըHY`osu8;X}Zf 0b ʋBhQ*Ŝy>>/#˄X(\qJ_6oG40V '˾hRa<)NNMhSߘM3{\$˨CG͇;j6" ?n D-UkZqt-ͅv;ob%' DKp%"DH= ;y\xb\->:@:SF<^򛶘jtx)c+@U#"5Q(DPzr>'ݽuUNvBRWS--T?q'k k=RDިY IHُI8TWw>O#J #1W. GJ3Џo`BN@suGt=L]\,yZ0 aH1wyK6i"(􄒢7Yu[|}#r2E[ЗNZ UTۻYEXOΒ@=wOV%`A71@i)9:Z,fEmoe ٫gEܝ乱Zb1ۡ闓vCAbϹ}u-lQj.dC%⚛]kw o\oIzh(ng#a5p󙗟Tqd6l d2Vg%yʂ4)/Rswo#3R5{ЌE2_ rs(DS~̙[+F ĝm ;6!JI{"BT2JZ6  }n?v@=hJJTNLGDGáP=be٠`7RUs{)wԬ]2}M'fRH܋xP#1lGDG>[V6yHKTGh" R~=Hh3hEZǐ ζ02$heOיnTh<9EcӉ<^5{HgeįW7#1xV$`XÀU6 wYˠ,PtPmXi"2eKh!,q3׸U>AEJ8 %@D<}4FqK32i;d_Lz~eM &t6'Y5NỪaz2#1ωjVR2ٞߚ7&)mBV)*~ǔF U6,Z!2=aZܠ:B|`-;0yb7;HKVH@r6+n 8jf\FX2xu 2tr^zDp A"9답ÑJ11~]4#S=I F)@- z#ŷ&F=`< /W۳Z'W( h1%'{֕vLx|{ M&#˗.u˥F/5۞&T qMm:GB^{n0CRE/b.PDfnGbEPfx'cǚ[KfW{*EU ߶a!PĒ՞`quzǫKU7̓|Qdwy2R z'ڃ_^ː-ʎSrHrhT2X6  _i*ILbӧLpTrpm_̥Ǡc.Ҍ}7 +0qVy  x#EI+Q7[P&}< %,Wj hU->tvarUKl UgcnO( \a0rL8m sq8ΌxS#H(Iy,W|ˀDtä¸>HQ[Q-Lo)T:@0:ČBڼc9 n{ݑچqL qj2T ҵW)KGNsJk4s~?G%sݝLL~jMɔ$D#̄N)k4 UH*EՓRIJ[W9G:V+@{4-1ĩ #gQpsNɼh @Bm=` 1 S͓^zFVoL:.@'vyi3#ueÿ]A{VSְ7;^JfE :rGh^7'p[#(zJsv(+Mtn "-JCUB!KS0q!<)I2}?P%1zҵ4_{AŨ+8*gІ-:Tʘa 4s&AJw\\l+xGO\z-Ox>x2|JڸI(AM[5YT)y]BjM`D~ &adI%^d UyVˠlS ~.ЙmiC.rrtc“梠{"G"X>J*"%1j&0)9_ TX jPu6!>zJ#z c5 {uܨ8Y8 /ضCrK.=O޴[ F!E;)5h{lKW@%WҠ DzJ GO أpHI \ a#qdZ8ר"˘= P>1ԪtBo6]{X=T{"U8^i1.B~$:]$K! vu%݆>=MVQ.wxZ,Mm[,-}"L@Go~ #ܜX x! _YQ2SCe- *1cbQ{ l<ߢW  Uuj(+ߠ]QOR:Ov٩7/A`yQ0wJt~TBmΊ *d=K2 w80475,Gꬲ,s`Yú#AIvFɟߎ+ LfuI)*fxb"f&jf?ÄզEZ?w^X(=L*L u@5ڌ A]s@ױ^ӿ<#r 1V@gW'08`jWveI$ /j %G.EiIJ2KPzUGpPKyK7k \ GP>ɚ\C@ul6o!O]&59a8ʪ_l1N1=|K<cs;&.AEbqsZ~EFH&<7]-1 YQsɽxvlbe;iptc¸0ZE!L0)q2}Ԋ-b: lo%sq/ +|Ex,t,;Mf>]FQ5OԆD}o}!wUE\,`T& /<|I2oYx0\Q\ȹ[SꈎD2M+sC"!~gց5ϑ9KIĥf;G@2FtˋTWr<%})$g^=Y8bMw'\(mA^_3jY%0}jY 38,䝛ؕ;/"S6ׇt1k|WO?Bڵ LKm@MtY}Ux E8cXlZ9#by:Ї=[,*pX|1512GN,e.yzm"[[&iI d $3 WWI-l=LvX0P X+52~Y霬֔8{-BNx,lfiǑ$&g3djαrp.0a ч814IUxD4jyM 6B;Xz~#&{{c.궘#|[1& My!(CSju.j<țgnIБIyj;=OҼF6-nU\L|izG_Y^q2o}?ںq|yB$NC1^ϢRAt5Z&^b~ x2l tTF™<).6v32*X,`?]V52-;!Z Y1VFv9&Ǝ4E)/J662QXIDxk]Ms?0@a]엇7;;e=i*zF>So(1hG *FWkק&Os(>j ߬X1io*'wS_S=yI` Euڄ ~Bln;%ZA kT1+~zChtTG]=%hyDwI/ \*y.[J+U +Oi`U)9駿)FEb1MSv=oQɗx֩|\ienFE:*Қc̺u<4X@ߩD"OϸyxC?hu>3rA?3v{}xMT#-j$.uMG}Fȿsؚ5)-QbklVݓݼ~E?7տW0.Ï)7]v6vZAăM@ P$ŭn4D$:2e0&l`^ h$㡂v.\ ؆cfiĺ|Lfy/X?^|~[jM&?1w(:TW41prY""n-AP<V>|b';Un iDC|-J 2R޳کRC09q8/Oݢ^Ӭ7esLsbLM 9* YtL[`=Fy}u\4f fٙ*XZ2.'@+7yfDN椅vp~FI8YУb>&;M1gMu5#vϒHI<<2بQ-~OZvxp$]AJ+[vguZ`$ڕqNZoCv^썂 A*r6ց`}< L#5$M7Aq Icv@:n taUYM~Zy| Wwa%NmMes;Gv[{S:B$/vF\8kV|e@;V[[V+=pr&.t04oa\urǺ] {sq>xX/gV Eс6A韣K5sF ʑB1,} dk}Ny*jh*~NPlniEQa}eԗɑMu aچciQ)[soNc}i9ץ"ǂZ9ͼF,` 6rʡS0'bn9ZPx&1><9 Xd5Z-bhcS@4py ] 2iD>XFWpql #??p ٱ1^9hK3\+|3-ΐjs]Us 1"0rrX<6ojw4K0n%7O AI'ʇ" ]4-yAWKrDn JT_ e*/#o}sӐ֝4p{pBC_XN2+!f_Ȋxhsez'[*,4KiAp"o^/ Q {ˊX aVpE{/?[])9њVzX4TYӐa Z91!\zjǝrLNf}ԛFw\k}{,q~pXL/J.B.b_3?ZhZXT \T&cĐ@]5+a7]ZoD m`\[hc ; N(q\3:A_*.iEMs; cQn }zI#.,]TB>iH tC&_l;O+QmL{{42!>Dv8Y^Ŝ oK-=:Vi,aj]hmCϻ\߸D,h]b\E,{Nǩ "م8~B|(06oNX~=h/&4 CIZXSTє# y%O Kn}fZ Knmq' )#A NJ*`ƿl]T2TpqCMvU>`$Ho*YPnü?P!Ge@sB`061YaZ4Df`d$`eJ鹓$\TUa66c}x%I8#Yʒ`D0*mSΡ4m(9Me|)Iq¼۸L#J|IVGl13v:ݫWMH%3Isܾ@b6:s !)h XnI:C83Ot k||%KTIn H_r).=;}wi<.j9=k8ݑ/i1&cGw;o"1Gn XF MɟLZX l}۞g~3DLl[뵋WM rq[PmoT"LúPe ;T#Z#DRґw@mZ n2!λvi*juX`bBޛTOA{hcg*"4#;{rj97syAl25}ҏ<8mԝoW*t-p=$- U,Ҫ$jV=Lt2þ]jB[02hDAOH @sAF"wGL=O5z ީ@I{ ä́FH mL c UV5*\!ۓni|G,%g}Wޡ ']ǂOlھdFU,\1+4 q/Ky E x; ,^G\}&baܪ G(A ϔS-1͛Px?[@߾$_iTb F+LjI<~9I;]dW5:Re`XbrBAQPf]dMŜ{:n;ȼ[ &jW`>0N 9Ů'&yg?jRYq?o11'ݨy5M9~rb{֚ɔcҍHuUOW9ϭ۞v;0s)]4?b 4ċan?ۜh!!+ޭfD*3{4ޟk7`,SGR*@oB;gAnh񳫖qnD RG1MO:7k# Rk&T@1bF_ج; t";((K(O[R["4]ɂ@&_Ks:gʚ'"tep*T5'Uߕz1s(ILqUVƜdDl#ͮRMW&;[Mw1Z$4 1 aӝQRӸըf:2A5t3f' I` HL,.&jD殴ϼKF5 ȚqцvD-d~:cFaM \6Y%q?I:< qͯ"G tJz~_"&8܎z 1l뵠H%65/=!j V Dc;)j(G"甏:Vv# O/=1eĨ6b}EJƑG*j<Gl8W~腎Ү76$vsk% m h> "C*yuB!L,4u|˅m;qkd2/4z w񽥡߄Ypb<_&ty ,| Q`Hea-e"Q {ɣO!)t].$='Luķ5 }"h1H|St~C贡~(+yt/% ">JW~{1k@_ aǛfa (l9រN Hޒ/>|lܩKY?õ 5X|~9#)oZN5.n,l[vskTcU~#vjE!1FAh M-994/B9s0CQ-ᄤP}ՆT\./c^49e(_0u_.YlEv/x >ƈrT,SIN , `eIѣu83bI0Wt}wQ{zƭ _?CaNuۘy*d+YW\8F1bNf ܦ~t>ȹkMdyxʓb6X(\l).<-5gJ=>̰(y BccE!t{[垔jOR#&=>OcBTb_egyp}ٵ'A5?P-/T52,w zYjw#@-:1RNLԧ'VnZPNz+~W:5ϴ1C=:evY$-.~IˍW~3ngEQz^ 76+#,DS 7nT $cò]ԴiX1l잜)]2HK~08Ћg-͝Kz%L3oo$r)4|Ã?u"O^iꤘΊmug.i YiAQt6۷~:\# nl͍K##3`C ( \3|8GFf) r6V(*6#>au勒WHO>̓0Kf6;t}4Bg (dPmE:oE:2 %>5 Q Eʛ4AL]h-.$fƗSmupM[K/|1^қPV˷5z\C4fRNWP$Xa:ӑcz>dFb>df'rMi=ߗr EկテO3":+[v;02sj=ړƌ3˲o ˙Yjp MYs{VqTC")@g vOާ'ܟȁv3GIjR|1=«QmoX'96PƃŁ˙A־pU@iWa1b&9t*_At_Tw ̓εqoKE`;O H&.ej>qF dBhǼInhӱ)x\ReI3ut6⓺ T~* ]䒪n^T Ě cilxC'̋τĎ ѳ00xU9Jr%"ΛAqnzu'}/q!`~My&:މ`6 m.^8ׯ|36OS~ ؍O|9ؑl0 9E ~o?_(OPYZ[qnN&HIyn3 +\F>EE=l4Kd) RXe: S+kcjϢR0\X%zgM[T{U+ ?l~8Xi?"ba=u+g%u%*bi1T[<,¤p@:#xDa|~t|.\ѳI6Y:p¾x(gZ8$\<8l{^®o.;S. Q~DK %L^ )(zɹGz0*uG8 chkOPH֕cyq'I,\M7rk>GŞpEWy1.gGfڍ?sRm06-u~V/9NǶPURkzF@Zf!1Wf 8exl ӕL;t_3mb;H3% oR(٩1?F"ϋ3](.qRu^_"Q)JjmZ_+7bR<ײ_`Y5ZOd;bv  EW6}ƓX٧Nvf4 poG@ 'P9{ u#Sl,&ڶL{6'n$i,#>%j6j86 0p:T@0dȊP{|UT䒘/\3=~R썦J1wRp ſHL=ΕJV5#E5F!gi+zVtP%e\7$Y岩)S\:J]*( ^vϫ DX/6]:{LYCa}4\,)$|1/FBB<#Li\YGwvsg9똍fbK5Uqq!!\~'68+u '_p.E~ j_Q{iHK+#pᨬW)*z+j,q ӠX8gmC'D 8ިf jWp]a([0Pypl:f;BYpWFGds#T ϘωcI:ȹJawL# iӜ܈kQf@q<3qnnlK?cGao=A"o9$Ymv ^K F$`zTͅaı-(;%B(Dw‚9)<'kYj~&9n2V5^],r d(=wKS#rR6=WHQd2'SBf0;sz{d}J^<߷>С5,7s"J2H|JoەkO*lGЀ=W%"h4{onJ{R!0K+5;A T^m {ԗ'L.^Ta#wxQ" cS B{\y9ȪAz}boDn$yEzy`8.&@:Au5hynlL{R"X>UPn/VZܒ>f4G3tzZ$` !gy,ԧOEŵcl&]%7Z7R_|se"{0DuPP|[7o;f:W{wV4.y^!*b N# uoN=!hQ? Zɍdew"'f*^h >0w5:籨 ^= ITw.} r5txecP \X]"k\dn'lJod~9Nqnw!iIs~JqLiN?i-|^/^)JD ,&ĸ=k;" }$\RPkcK rSy0d46LxD=): NT _`qR+utUj"5r_~u!>Ë!OÑD my;"GyIek'|tRvFWH=|ic: 厕 bњ#r_;U cMrAޣ9$ȼb$%~%⎏ B-D?F.i߀N=>XrW=+#֑i d3 mkrZ`\ E糳Im<^3@!4jG:F|8kSi \M(aHt@A2g#R;SHfNH.U lR=¸+hMq"ý k'^ST8+! J?z{0( Tњ~`+aD D?>hRԁ2TyuVɣ^=.gc:cH>5{r}W(;{!Z?S96@%bEFo2_6=IsH[ߩ~.(L0zK)%̤/P3wPw1 ecSe>5XOBK$3GrrpTlCzwR&8_ \ kqK;ÛrrЛmJCuAشdGKMISTP{!9p?^!sFvaJN&ԂQ^U(|#y,hi%*';TU#͘62BLh Ecm)RoKV掩y#г39{\z8j]4${!WHxnQ= ^ؗRǧ<>|#izVٚMJtd@5ҩ(Gn\ST-ݼT\sr,^vay 68;1L1=2d lesYՉ7-U$bR? %&,h.((c8 [J*.an~(?N+|bF("xR3${|c@ĚtH vF{˟Bd`ŚO &2R n-6M2#OG))#.v 6:@,DWpj`H$A[q%R 8M"  7(T'_ֈ&LoDr[{4*CLNړ0N]WPeO,p@z"~> шQ-ms8#ĠN& *tД~x R:*ւ-3 ̙ 6g *_OQhJWH`Oap YZA ɵ.`JQa5nhsyx |xQ 1E-h4Vq!GDc%aȡp+k&֛"YU|CΡ6)K$VZ2XwI7EM8āU"9cnnƘ0 ۏ#ETSA|2n{(Z~B;e[K}B7в&$DuFrXۋP e E>.2z 4~*wuJ.ؐ3j0D,Vsό*r$.#WCe<&13:4-S55(qfhhDma z:+urJt&&7[:uC3ܹMmJX.O;4~'(3BQ`"]KrE|cX,aSӡ`>/$^3d7kH,@,5 Z,qK*mt5J۵! J!Aq9Ґp%{D&%+ dTۭ fkς!}ҋLr, =̓/dQrH Z=MX(|cӯN \%Ss Ap']RMhBa<.itɤ&dV/i3Wl+#fN"CIÖ Fe5229}g^O e!<.zi>0[CLCp5Pn:+w){znpfss;(:K&.b/4{|w4u],a @7GK[5>>(a= RQ-1s 3 $k^;بFͯ <50pCS׌v$1Ha%3+yzTp/W"#w2҉yE%^v. .N&E'u#U24iCf*]~> #183{;q"醚ѫ 8ibZw5h|.Nz 5_O.j+47zC7k8<T2QqM_J$Qƹ_(7F:;jGӷ2 HW W\`{{-NǟX[Pgbg^CFC/ij'!*СBlUx?qXQ{%''O/I2yFQ[.H^%x^w{/E򩸦7 _&c,l?D0 & 0YUzv^G "NL5dvۿ3.[}4c<F66S>S:^!KUʖ홭.[r)L0H;[w5NbLĢl]]vm*$뺨PlhV?59utH H>^V.TaXHd`X' ,d{+ &s%Wh:5/Eoγ {>*}4A* ,qMIVtRkq騙B.Y/}ϔ1ʘUrB뢏s,()3qgz/P?&wV@c>hB3 ?>j\:f^*sAa4iK&HQ93u)L}P#,Wl)v=u}_1V2@OjED:SHbgCP O-kƅ1 p7p4a/-#aq[@n?QE< 9 2Ndӏ`1\Jxp{h[MKT1 6Hf2U+[T<,1zDIy?S9M p]~//s 6uuB*m /p:[at Q8/ 7D ep9\u DzQ>]mlW`73j5' K)ZWB!KCm Z`` eM,f}ĥ|V.C:qX'"=4Ors|կibOr~3@&(1˃F%!鿏X'3titx_^LKly$6Dv3KGgPAI5m^0( MI3¥NO`9d/ri$9܉ahF4/srt QIS?ڄ27&* ,TzNO}ױ*uyon*iN#jHk׿wxoXhk+~z[Ɯj$=q&pޔZWiG ;4nlyM }Z_;OžK"AĤ2I]Ϋx}6A{fCT7jT)}1#:D'%|XN7=(Y1Bh}۔YL7}uxe?@.b}ɩCw#M "/w"55T35G0$I#:R;k 61K@H[@pcMW(b߼Np;_ᕖe,"#ِK,-++cQpFVe aF^3j1]<`;ff~9 D0,B뵩|!g !8yq7Ǡ$ <*v"T' Xg YT t"ϳ+nuQ_;] gf~ 1n f Lr'--3/>+r 8h׶4W7;A~l%vsnŶD3Xm#ظ4,7wPF]a g!g BQ j{[B,#l6ӭ@s&qN~o@,7a~Fjm3~nW,idv-H&g֡MB<4_؊H2TO9:w]nŲxN]kr٘slvrv,"7wӈʐm6寧%ȡr 8 FxWEVfcDMpePԝ2GllPvWn`ԡR{tg#Ǧ M:h|'BC%npWYҹ7P x(4Iw!v.nAG;To#.~S`c ^-yjt8/Mo;s{zx?!׿Ne`[/zn\5Uh]|."˹)oF5C qcLCl-v}1] Al++j" U:XƟ@x`;o>_tk;= <%4ģ[g2[_C\rш1gM{5d;d5~[ceʃcRh:ՆǠ2d˴r&Zl&Btq`rmN%Řh) 9XIQi~/K`!YF& WccƖz<4u\NIOŞ+=r˚lAKx!Lց ZR{RW!f~w=][n+ /_.Ho?Ba%+H3Z46>_eLe'feGm=aܓ0:T]%ȓo^w] (uM2Ex޻-4)7 ƺzAHr˸ޱ*Je2&?mO;}/nk s"St&.-]YmW Ǎh#ظB,~+ǖlnR4^?OFКԹt2 h!84{sXV*x c7:V\E.:U W84A9eQ hSʏ2!RLW=%!SKfv6fD@AT`y5L"}OCY \,Pi-aR3'H4Lh4pJLD~MquZ;}9PܰwP#զ2=wzOw%?ֵ M2wB])A\]) QwSiMŠ!CNɜб?@L!N6\՘D06l]U:z13uSCc9r6\1M4d x" .7id٢s_BO^Re$E9Yp.[>aF8?ԛ؃AidE"S)~:w4}cYDZU Ħw@ յ:R{% IA?s=y19 S |DU `SH9'nOfʢ)o0vP>|`Yů(#6d=ڰ`,!!6EYlEZf*af[m7*(::h_Gxo\`` 12Vbe')볘u2zqDfiH;iX)2No~nyхߑ<[Gmi}Tߔt 8=$#,{|&{W=n*z)K209ePNs\ba*w;޵óu|$ڕi LsS.3HCXr}VFǫz^њijI ^FIh#W/W_U dTθP!+R)n0G،/`v4O#XkO78 M5VmO5A]ӻKi }M76ozR8Qru^Ci^Iڱִ2DQJ"v7}F ŵ_acR9i.E[Ԣjue'B01ivD kۚ_J<\9YX ȷ{֗b=\Yf]~_%1SLޖշ6d-Ep J,d0Cz㓏ZEE&=הppvPd^)wՀwNlXSH%џF_={+Ig |o2T|7:xFgUn:ܽI#kb,:1iwGvDn]2[&Ib5յIXCoptq쏣S4ТYF{LYq@+a7 hK:Ր'mt9 911RĆ09wQfc̦;T9k),j2ZkKK7^꣬1h3q1յ <]>$z*MkRLGV< %d@y֡'%V\hQT"- ;Ao/™4IOHOzjjǦI߈V%t;YbT%+U3Š{hYUaHYU"2kqv5ՅD 2sT} /B]M|cnkHKw\i6"$~8ّf\l47wQp~O^CCK~l9xp=> 5b𗭿&z`Ϲ}6{K5yJC^V@ST5͔V&DH3DNKfR%,R=BHFv}:4.M4,3eir)ħn;7-YH`z.o.%6o3D1<գո]'k 56TeiD0c"P-f!{`U Suw k(O(]PֺI.} o0ZA24^*=rm 6cx=D̴8酢C< Ea΁_& !FoY3DkX9r12"Н;lo"9: F}c1?A,T_m2 7_sIEJ yi ^o<<ȑ-Nx[ʧ `0Df|} i8e""z JFb[kԫ9 4Yx: VY2_ 2DW{t0)cXc_iͭluXVh<јG(}RDM `_ȍc 8V"%w5A_Â4ɿ zɵ(K ^=(wDIT-!7=IϙUjk5 K2M1{]RHuXSQ}o5yz* :Y5f-Q#Om^'FD%IZV0eH2x}rPJVs RinM`y}/Au@Sm >)GLi??De>Ù57QP3vB_qU Ll{1ѼbιOg It҉׹k&bq7bg-'mLn84X(O>6v/ɺ˄7u*/]#_Αlo^#ǶZ,*b˳_%αT@+##mJHzE \,+(磧׀ m7-p7C@F蟕LYMK ]-ᥡ Yc֔~]U*}B_d2;m3̱G)C- ./ƎP] BdZeDap0_8S,Y XHS;Pd)e5}*  & et ;o3` N~-!x^Qo`v-pcZ/Au!K6f 哤^AvutџڝK"l%S)%hyvc5=ƧtwkO[|Ԧ_o`n[۲^'lᙘTD||+K_9[䚕4Rˆ3zcܧγpqy#?Â/iz_yRCl"p3H(*WsQWfww^6t|VnOKDgg}>!$.كQ=7Kj(AIyYH&Et>VxiVS#޲VmҨ;}AWm\':@7(a7`oP[ZD!" PqIb^ 9ٹ}6(!8-Az"9Rg#f<^e/ !˯@HRaJo4?EidwfyIw8HH _M<5&> $.]ش6wnAAJV~H?NF_~2J0h Hv4AQ&)5iL[_ Ck4RO#A^rK\7LQ٭w"ِlZVIv(eŹ @|ir - K%*R ;ᮢp$S;%p59_7'OMg;11 wוOˇ7jwddSj m]wM%M'@"i:`taRsaY(B44q{lfQ.*jsu7OQ7Y`hy0%CtӪJ5 6 jzp 8xgF1Th$QcB(R45%W7rs]eSbҪ o7csfq9%-{Yװs.D/cvBBn_yGkeS람LtksNn!<8o<l[ĻMdr\[dʃ)|+϶+yõfk$ZS)D Hڬ㌝AE(, ׫o+qCTsBTDi3̇,FHckavA:۠T4Xm/C-Pкoc% 9acx4;^ӾCbϯpVAiE,􏲵?,&x.NZob!D-|׫ҽZhl]^^Ol*fY/Z gRuگXY+GwJo7t3!O:H z D^ߴx}dYaQ ~v/}oƐL6}𨀊ض)qJ5MqWrȘ۔CJ Hc`hR N?1!΄ӨIJ5ۤ[xtR'CO{ݱ0ŒCkCI\ 0\ŊhI s)(aJnG'Y<.R\vc(>CXT?}Z/$k$ g\WIi_,ϷeRem?]Q늅hE7z:gt SAJaWo]X/rZf-KqbeZ'ktwԘ2dNhn9,X3kR1N\ ,2Z(-'4'Oy#]+zC+)U zӫf(yƇP?o)SLp Z$80!tuxTn3+I1%Sf$C]9Ippf/RR BXt3 [A m5v^zM>(+`*4q:4n]՜$r+ْ@n!cä:CJƭ2uU:j&htB']RF"PuI@A݆΅ѻe2@͔XF)Ę%ک\8(2:yW ͊sPQ\v" ck6hOևٹsnT =݀Nj\lt_ӊC)u# Q˻K)rPr+<%uoЁlinSb^cTkǎ'|פ0A_`#(T{ +i% rဳG\c#aHRw/u4v``&.*naVx\}N:$ R4,X]'~̢,p:/6jN1#kjMZR/RH ]FCRtSUA=E4$;TlIX24 Q_d:9*!޼B}}2{N?x}\ΓdxO#>jHJx4&JR.Qq:wt\^E~ Z2 Cys"6:ݢ)fחs5qDSwqЉr3'SI{%37YxJ̆V!.=,Z]4r`y#"=S}ӿgվ^j)CLMf?jcf 3&~`෼ztBxJ ƴ 6a`t=M*ՙj*PV2%2h *aM(Gsր 1A}J&'-{\_vX?3q"l.YO4QagAQ> "Mlahsvȧ[H+QfeizN봞jW;Sjv QY@Y8f.D='!:%o4( ػ*5LA*2+W^zzʑjuZ⹜#%cԴ̽p.^3ٲ /kUQk`~F<֡:\E z|{caڙ!dG]B. +Sl[n)]؂K84}R ZKBܬƒTaoϔPf+6suz"KTʧrXU kգܰ؇OX7gE! Mр} *9~D^[IƏ`L_ltL= Sg31}~vU8e8Ԙ0lQ3Fp0vUOqQM^h$Nǩ/kw˼ $!3Ɣ6:%]e7]y4V!anhmÀ/o.STT^VDXQx~u$rTH 믡Ufؘ.kw>^?cum̈́H. ?-l0&[76f^d9 ^4 py9E19CHZBٴU;%WԑWeDt1e ,ޜ(-6 ʛarHv"w)Fr"'hNbH۽(]aMI3#x:*k8)vvKAn;u0Kz):Dܐ-4p#_.f*dC8v23!{#?˖֦ΆMݢXU_&+g=Ѓj~j:G/4`GB٩h6Jv%L?I^{nƙ஗*qP/V 'zGD,)OLFmEͰ= E hbl?>R 7']^F ]%ÔNd71؃^ѾZN_͕}zGװ G`f2po4@|H|EB/O"^G1)/{: :eRSeYJۅMŽ)ÙȂҙ T@ę<~źd>AwJs04z,͋uJE5_Xq^ =&s۱6<\>j=+mOq˒ 8Ȃpk?^f3(02w/,@I(Ӵ;/ƨے Aae֨uDP'҂{:nXPBn݉O?b׳%&aiJ \c&ᥞzHiN+8byđ*U#zE.T-M4ĉ6ĞMWpcIw(/^LHR Ks4ZΟ1 c#}n*Z88*XXs_ZUԕ6S& (sow3V"Հ):YJ:P)Q9"p#4J21UAIzd'iB%D  " Y-LR۱[̓+ S:6[Ք0M^K8Jqq%vʖ9ڏ}q'n7ZıKc& ubXߑpё6Fma,]|TLmW1{buiN`I?iCSmEǰYi# _Lb*"i0~x; '$p1t|0~l񤳂)c92h}^5O2 V55fY29rrZh}kРdFT ~')_"{E ^i*_q Q,TF#[_#E*|'1DR|ah;QVpJ:]e62GK-|jA F!_Ba _ΒQ'Sv)5cb<͌jAsgR ˨}::rjD oOEiq}>[}ʃhZKP2׬e!Tџ[h Anmòsz |[᷁@"rB*s;33_;V{]BD5i Тj3Lشt"^ [m//1[|0lk)tG6 $>v6'Nc2ȩ+V@\uC'KkF) 3 - @E & JF$"LnZXϩx ,a|;S-*sM|l{l(iݕODηY'HQrQ{{; 1.ƋeNb[?/tmG2QfOU6 49q"H||4 wPi隰_DlU *!S5rS}CTQ/n Wdy+W`U-N NpeŁN:>)2mH&|ʞy,HY:HZ1?y5 =wXIF[y9eca"4"E{ KU=n'PˁM/ t V ۂU.4LtWBD a2SvY:4ix:3^#O)F( #]naQ{^ C"1 tR 3/e+ŠjA |Pa>4SC1*? ޶)~<熆#&L ̢V=O(޽y mBS-ᯘ9+. EþƁ^fḦ́р2 X+BHdLSH ݬ\ډyrA~o؞mI|Ծ$cFt-;O.,D2Gz;gY! }+my> MimGsZU&J,5YuK/]du|A"lh&3.w\1Wlߤ1"d[D˗*ävFm{ GeS-Qۋ4~Wp -/y%x,%aNt 8Sv-xڌ_SCO4JQL>Qo#8v>h9w0*yxD/(pj+X.P%/D{a%Xӧ&ڃzRLiR`O*8zC74%~˞O`kkWϼ-oL7(SIOS]A<4HȋY'hg!S# \)!Jնj)\K$t>kuv"?"^AAY95i탬 {4@~,sKxG!nIl \Oo0!tIhXi!6Ae4 cm6k!bHo/b1 =sbe\Bh;EB6qlQ0kLٝG$׼exl_h/10-AfP< gQG dM{߁Yk~13ة6| p`Hhq3.;[XѨ{,:KC2ٝG|xVŴ0¢-1SBB^Tx8{4t^< L `88y/X&w;5Pe Kz#,L~ٲ0(Tw{ΣDgf>W7-4\A} D"/ڦ<M <)i&IZwoBJKި:@$0?ffu@L2yx*Oտ}&(s <SvgCd#$Hg- ÎղCu@(WWD; 7%-% -@OuL,C^vP$ێNю&rUvMQc@(ėZ3#U\n?ݎ\vNll";>0 [-2&; U6%~V Pb&T~ :(\Կ#D FBv#Q wV1mQ TO㝤Xh? X+c)Hƞog}pxяpBqH&9x!KOc$ok5-LRYӯW Xubz4ǁ9[ddVC <ʐ-E Pz$Qj$ ʒVAo{6 x{Z>>FqwLu - !hESDup]߅)4ޚ hp H&;;_Tغ >W}[i&ڐ,͵*l3ʡE?fyLi&f[,\_WWr][\3rL}EL7bRڻ(aId~q i^ o.FpVyFʴzC5zX|q_%b;>]:cxbZhv,~SՅn>0*Y s[^5tZ;|L?y{4QS3*Ary[ɵy&U#M_1Kθ eҵ./=syQy"(]xM?ܒ7L64Xjʗ{'r*2 bx AꉖZXV/3Q kl7)&\} 8lGELxvƓ`0\ɧgס}ZV$' i.޽={5+^S. }0aϊ8QL\@_ZV ӳ)p0[f"SrEF oYqyP\@z/՝/>-rnX4~i pBE=)w=EĖr_DL0^bʔKl_HoMÈ9g +- ^d7i_Ϲ| w_Zh1N;tFH1"x@M D!zZoO/.V so|,IZ~4^]q9-zu ö34[=ӎL5 cM U73갣a8ōnYjë:Cm;ߪUcX!o],BЬՈgƓrm\/H(ż dI[''Q4LPeЗn")*T}\|ByuwqD 9 sB@ɂ9$[P5bVCpΈ5P Z.TOm]{X07@lFLʏ<`niV}q`LA>49"Ps~W߈_}NvZ6C!˱X.a$ W{ցxh[ s"0 {l%Ϟ%@kah0A^X(x&ПAD>< +8IkV_Tv&D0ș$E%fcz0()9͍U}.+ccթl2i?9W;hdKQ#7Q!=4N^ɢbClvQ iEV[5š罁:+ʟ39Y, m'DG;rt,IPT~t1^ԓy-jPى WXz)׻cJQ%lZUX'`.d|x{g}<6iM=x߀` |,f5^LkĞ)J%ѳ'ݤHi̱<`(4i9 7PmzѬtc'5rz G0Kr4ۑ߲MuSo[6YȽ"͵Q4O,w~+v@<Nnг\c;`s3Y{k`tso]d}r(cp%#.m6sdlbEnL2A5BABO;0;UM1`e~obk0z3A~Rr4NX Z)E?*偣goEaƞ7 O; {|H.F/n.q1?)^gk*Z*wA|IMOvPyO.zs AN;e*o|RP Dd.TXJQێq(z|nvl #nEpYSľh(ڹeIO$`e1)Do٤݉DQm{rt*Θa8D>‰g?|Z rq(K nnIP YKUcjٔAuXJ-ҶP5;2˰(tBxPFWـM+'$Ox_`OVD]A"z+*)op$/)`g] e1 ̓]S$_mFz7˘%3}vöV-\hK3 T;X:֤ %* 7}j8Q!Hۀ41 mtyrs'eKp+9MIVҳ4:$O15؏H]>x 0WKO} 18St?5;S:h?Rٷ|b5\A9$e1ni0rl~e ~Rʲ]/(i >N{è/x '|x4qtrӂR>928M R3c!@I@ޖ4jwLgIl4*|{%y X+ܐd w8 1-d=u_ <^'eCO9Y53g=^#D16ߡD_׬.ZVTxDKB$vy8I w[q4z Cp={(49[!GycS?ܘ\Л'SǡɄgvj'tw(]U5~8K X;[\GgEɚ*dC隶1kI1a-Sd&)>|O2VT54O^>Ϛky+g(d^˪+MqZV8\rEu?^=Y. "v@hn73*O||4dd  ೤cW}LsQLn~X'F zľƹAF| )=>`F ǀYfse>UW|DAm1 6,M6k=:vN wGy=񉤈W7Wei>1KDmś>MPX_y܁{_ZRgE[ٓ1VT^ ' 2ʵi *Ӡ2^\>v #,JA3j) V؀SuQYr!Π<ڶ-r&3xeص!nQl356}hmq+L~[ְЂ2Plȇe{C"./NBQ]`a}b-R˂ sc1"o~/g){(郁c>/_ %Ӥsq;JNzЃ/57qtnZ27fvC;2#$)`ow>B LD$G&ǁRC-IFQ ""[Ùˀ !Vi[V&rՉPw摯j{=[.Gzܤ ,l5l-qydkwo7HLBF7B)^ o`MۚfG ^WwEP$ 6;І{|,.:dŌݜ7.=!YG/_}%HMf?!dzҞm570e gMycO=M 65]kM.,0,Cܳ[fCT9/GX_H٬+4\o*(Z&%Uo\B7Z DI)S9*He/3#[Fu>2L;ҕ~b.eS̷Les|$u $>Ί}{8#]5 w8@ e+vHLSgԄy>xblj}S=s@(x(jrR 9فATE8b 2,~ Y@BëL={abb&IŎo9KtiV`6B`SΨ 6 ,;y{!4ē1D\7{MJ&bkqM˂Lki@SbFD8ǥM?0R CB1쒷!EtF7EaB>a Y 3'4eὡ-#Q(3}9'Zz]˛6ݼ餀 4zC+Dn_wHtRBI1߫1兢am"RĒI}=M#Z8ғfeDCNaЛ6ꓽތ &t˞I㮝]5[ȗO}#AYfNs i@OFϻ*w,@M%E ,3Zw<umsN\-*PW(4NGw> 'C UJ$`OΜ`iF'FW{2v;ޥN-O!vGόф?,QBfB[)L:{8/$P{iEQKV#JZ$oLW$Eqq ZUJa<?Q<:jBT0 WYvU_0pM>2X_ČJdۼ%_N=rʿkI0 5+@UW&![k:Vlڸq&6:}m0@& +fc>h;7>]vz[)g% PP%BKꂳWY;i3bi{ho D`v073H]lji  qC0FШmŊOyqrx. hj,NV5_ +alF)ҵ"d҄R|{GI8)t\]ߘ]$ʾ TG ,&X$ok9. u: StLuN@ `OSJM?Y5],fO!DZP|_f)ߋY i(4?VEr Q7ww1A&ji#:%ܝefgkɆuӘWeDb(l[= h?3\F̛(j"}`-~G>Y)ht3蚠0msyU "\n0L S9Lⳏ3o ĭr[}` ϶w]m?CհN~A0wrT^㘝BLۇ|RL"m/<2;L ~cϮY(en$xw[H,3%Q5 8':Cūx$x5g9D 2 sckijDHQ¹WD.Ƒ-~3B}B+p۫TbHHؔ/RS-u!{K=(EBSN66+kh#XP,_,4M@3ډ?UYh)$7 Fg>II65<GSwR 6IFˊH(ۍyqiguw3lv:j58+wʱiPgOnxqY.ƣL&M]{x,SDC$r$k D=Bjjܢ ;=Pq+v4aCmԍaFhU8AD-5 VT٥2;청x1sncs͝TbC8QF)[IL[Q%g_jx: [2iE=x2 d4g`ܮw6w@%wTb|EPI!:YQ:[$=9ֽ.Y~TgFGX\M#U3_(*H!.P^#Ԏȡ#n/e`r^&^o5iU1j2%V9.Xk8 fuFB~k]g̈́Ŕl"F!ٷn `jNovL NrLwj𹡞-4Q[ -RKdMŮ+Eu]Y}ץv&bf&Âܾ(%YZda=>vԻDQ^sCM6=ǒ]:d{CDHݾQҲp5|{I9vd1E;BR@]`L^e= > %²TjRzѼcC?~x2՝ -޷YiyG1?5׫u?tL9lnt%;R+B/^oY>䕒 />ۡ*hkuzgmNc[E.~.FyAGvw(/c::.@j4vgVuXш ;s,Gpy_CiApgrWATzuj 6pnoGH5\n]Yz=n?wAqc#nkaӔ8WIlRLVϮ^>@2yF1 s>IiMWKh\k+X ,!Mq)0Q;<Ix5?t" l jjy I_Rknw)՜uU3VHw;"EGdI+!޲!Cʹ.dz*T#:D)q+r34Md{[hoKp%(oxeYc|%ν $jLW6_oHِ%G[?2VHMV}]Dx[I|>F{x>Bc#ą행g2#OMtlV/(#iMa+sCzYwC#@ +ek}O?]dQa^Yzay>Y8s{hnP,3dr`͚l<RCS$.( HCe.,tdB=Őڴz^L%Ŏx3M+:ʻE?"%E/WG2^YiaE*ceu|RE$lsBؠʞA=De!`WU)(ulJ6@dXJFkv<~wyFvu1u|* k,Yh +8wMRJ"53$ǣ hUG檿޽vaߊ-SG9 {SW/W|)Z}&H2~濪Ar0F2z$0Fnxj`'nԳpC~*r7ŎdH JH4i07zT-z4Af_pGLt m~_VnHP}o FRSKXh zgyY`ݵ\/htKרy+u_Ad Uj7(@M+֎!>n ͱ:AfJkNֿϠF V X8OTߌw^I$~r1Ĝ nWk}܋^6NNq`y*5R~DHwycǗ}P1](5`ufBg7ˌ({ZiAN9Acy'n4.vt/qug٢$:,a9lӨ<{Xڄ?!?:F]wK6k~F;{t Hxq_"Zr%2:ʳBIe9Y1e'4$+x$Ш_u&~  `mflҢX),/\ T MbdDkL)}exd$E&VNҷի/熳2H0*o)ՒCDor_\WF,Xa-瘵<fVtuj;XQP(7Ry|=&RAǒo&@\:X7INUӵue w \Db|\) fv53~Tj~OQ'+P~e4dkr6nk38 J5^†|; O& fRuZnא*_]<(A&*ˤ 3MsDLwH 5>u@ o*SW8K#~,##k'E}μ/$ȣ*s Yo/7^HP Y MW trrVew+1 AB>KU0 x ìrN ^.*Ӭ Sxm 'j5*'XRGʮ~uAN:3^DЅOeꑣ[fw*(;spN7Um;^\' >d99ktw5}s%<U'oU8PaJ]&VSTJyS4j.D"Ϥi3G󱛵hn `dW&J5X? ƃ曎ʶfx XKkC5&YQ#c#Oj3mm$nEBW"|(lH(%wjQ(tj|i/)rVLK[M)֠IX23!sPYU/ Nc|zS>8:sFiDLU,~:[ESդ>A%pVܴa~.ԶsOKլؑǹG1=k`.6Yw.dk%q:*jܜd"Am܉0kukrpCbdyğx[W;gODt*?dn=Kmף;!]7W\%vXQe:4]hv۟-3ͫ 2UIjkJ NUǝQVSy2?SC ~9J t4vZ~8x>%߸Փ!?:d"C-<rnjvlU _Aޚ.šfm[{8(0E,,kyR6D&.~\SF\5F\_D7َXf5"03&Wo w,yz*T%š?Et8@VG_&#jn)'l&xxtomP-4T>0EDA{@1Q wgxg;5ÒRKO+|IAk.d} la:;@f.AqUJL3.ې%?,d.,6L# A؈dVFA &= l8y|](z H$3=Y\M ε [, o4}Vٕw'1Upa{A1I0&06r꩟Ҳ{:*w߲f)OHW2cGcE3-FCxc]WP6+^zݹ#KɨAm0bqWK Ƞ頖F2]V"<ӝ#8|v!D>ӗֳM){{z|g |#QF_2,|N|w7~^@IQGUnhr$Sd>XzGWb|wt Nx {28#)CH/ƞۖoOr-Ex*LTtx;t[[d]FSw_~Y2uaSB@%u~2T"iZrdJ\IPmF qB#&=[ y.z2dԊ@ϏnkŭZБ hWV^생V3C~9MfN`[a [! =Ym''ش0TAڥ e4pPKšjU/h'ZG)aVaR:eA>/I'vDX*u m2&tp;Yêdi)tOB2Wf:ټ4oDc|<'H/ƚVмct[zt M3qa iL;n Ogɖq.o3z##x\4ܔu/^7b7]/XPgs:h=(|.|ЫtCA ULZ*[sX0\v \23/q+gvq?dV} r.- 4mcʧkUa{OCT˼'H ުİڒ -׿jjxߣmܠrGAr<1~ ƭc O7:[(==[$n>Kyv~aB=UDo9zY]xf~;o3:[p\Xe.yfu%3K^2 Ml)} }|9/vWt&+U580"ýc{ qI7TU[i vrX˜yTtO4MHz 31xȜ9b;@>{7:xl_X,ڵuگatPN?Ͼv*hO f$7mz)D j {?o.U5zL&;-,q= Rtm< XŐ 6xv]1qI+urؑ_^(87,55N5ԊZ%|W qO.OE0lZ24䩤f=G'E.n sa%(/w}F+1B{wrOaa_oSi:iR"2 GV6SI-Mj eT+qFDF&VWy@7|gQWHy?ؤ =ɢ)q'x셟'm\i0I845wP4q*$uPDR9h,V3[RMKRl74;ElƥDCѰi}&~LOkrnG۫9bR VSæ9:|ӯ(DdLW[vo93s%0]ŭq ]9ծy .mt @D+ȇ63ҒƐ|rBh9muO_Rʯ`H߫RiB hgIنfx l/J>yPNT)3NUf+<8#J5c/ek>4ZntV]{y,n]_PW⁤>JK|AldͤzhQ`]9#Bڗ.(hy{q. :SF, }D7aPegd9Iֱ4 A1#e5yhz%lꐟaH?ioIk΁H W`{?pA@)׍/.&]/rԚ0$P=aX]_u3gA!05L䣹8Q HrwN{^s1:=b\,uqkowOʮPύдjHrjKsm"1nnJ ZXYx,1filVxur,%wC{/'1!@\ a{;þU[k ^gc).\TŊiP@)\ԩIiՈAAr{'@[GU3%>=Gj+**/=5ؔK(n$LsX)di ]X*P5CU~e𑢨 $*~h܇ѻ]93bz}~R7Hv҇ e['__/Fl3.TlV4.uԷZhI9՝\IJCjB,WVtCrm&yhXmÊ?;(Iy@^)TNXIq_|X=[OӬngƩN+n_i sڡ.>P˸i0&%^/'YiRZc\/[JYڿy4}h|ñGhӇo=c2hY yl,_^!%]#;P SҒgNoքU[: ǬVi MJQH?j+0 =OOS`cv>k{ɓdAڤv ߩWUMm RO0FƵ ^9ɬb e\ԏW]$-|PI+Q͗^okCն%_@& ڊwrLK,V#640tJs5"MgeJ71f QP㝤qcD Їkb?,'b9M I2"͐sۦl(a rJ 4V-] b\u *z8)| ` U` z_|F8õ4h9RCI$YՏ~.61)_պ!Iۍa%囟8P&6;T^[5U5nX,NI[24 08jb.@OOHNJYQ0Ö<J֒Q<gtCf\w6v$T)Iґ)ҫx ɱWTZ[J^I WъNK ]ֆM: \4~-#+E%ŒJyk!4֓KN80̢hC%^"şy$"~)l?T$ӖuOؔ:!կĄХՠ!}A[CvҔ+c}=|0~ކ[/~j.\Pz"5{}p[GCCɌ~?=:3S1HӖU+*B5վ-Sq`I;>ycq?B}G01y+\oGz[DTMTzL:ANX+S-"[0{@\!*u,CM I"@*&LɄ&JI '?pJ $FHɏ+R PR"^zKJ;jo } z OABBo\ڭkI{vP[td409V+G`SC榺F^w i|N"@ .ؤ0_-pn-7W,ns]Z&qY<&NLI/3Z7Wn '5n-0#B9⍾[P {lTvcZX ʆ 屓U+s1X= 8b/^s,+7GChF7=e71ئs(J Ds #%^ REr_&?/_!eq-ZO,(wCom~^V;ǶyVe"'(GƂ&>Ӄ%䔦Iןv|ڙY_jqۚ]fʰWPO{BY(|t P7;ot-I)cy0SNlx$cőYZ?ѓBY6Ӯ.Ai,uY"cM bqf$@Mjԙ>[|YNR0",Zxd܃K%2!^S?lF傁$9\;g摳f LG[?%.#$1%%Vpc3חh\"wtt eς#2,IIW4@ߤ$;S>7#S(m+ 4um̞=t33ߙԟLf f0 Gve[wmUAMQ4h7.;^3E c~'6ϬAN<\Д<R8$wmI'_ܜeP{NePm{x'.1D`BPy(y =}2Va#яT&VihVqAz C2Q2֞c \pQr8 g%jN:WF/ŰѰv42>s^ݔQ{S绺a-f|s2?G@ǢǧئLHџ-Ե0-T"GWcm;IR(d.iVaӦ`־~fd9CE849Tr%]3<̹A\ޓwlW77BMqL;ޅP˰ImAZ#cU5+ 8a(g!iBi= ,-`c|+]@;`U%ӖG%Qd}*g2͠2guvT/VB tUl#!Fℵ;n*ybrNiuL7 |UӣS%jqh"UXP2 WvEW}7ZA^ܖ@0iwQn@0@NVVԷ4hkZGPF^[vs8GV1ӚjƇ 1,׌*`.EWq}[i6Щ=_q.:jŋ(ۮ X2HnT‡bi~?[>q-S90{ع^a=Ѥ9cv^Tqu_oPnG_:-6qUJ;CW]ɨRz+usF"wƠ1rSy.āZ? b-LfWضLl|I..u )O (xGT&pJ\$&I3 Zsg{!r<@ۈ؈ez&W{N]@ _7ZL>Wذ"əb?z.pOvf}ŎqiTL0Wf%|ɍ2I ޿*P(sl~hSO%s9er [ ;*+Q$!ԙ-5񄎙mNMBܯb[AwEyFR_3a4F [$TxuLV;Aa.oFȕ鄼_*;H5U&6?S6l7Q1"ƛn@9gA 5m*f`?1JOtǨKm!{avږIe,DTkw4L+(?h`x?tʔu?Hq~7 YMug֠ڣH=1oN_xESQP[!zOyB1Mk$P)( bµ7dCY1Twm^j%T"z 䫝 {n,8<+gw?4+lM/b\(aꤏ:luuݑ9˒+8vU[#f?"I[\ւY6k΀!5۾,p۽  q_FeVZDd? Cg)ILuQZI+Zf#Gw^s{N_C)nP$yXm ]5)"^㯧qC#}l\xב4&Dвwr;aWy56~Ep dYS4$\w<@*Y UN#baJϫGS١g߅͋q,;ipUJl#Mu+flV u;##ۦ6"HqLJ/UIxAh1iޠM w}tuv14So; ˤʆ.S%hyRkShnA8ȖRG~="cui j<hf/q& ~?ٿ&_P!'@Hs-@FȽaҀXH;P!sx%o٩H}H!b2tYm$N[wa9%A`TN1Yc9jo% be2G62C\K$ތ}T)kjݎur !zv۹6N,qgi`\9LmFiStO6hpPtxcuLMn7An)F P kr u~j* _ Xh4wZ#sЛ2ziI츟qHG.Xk8pGpS@n0U[Z^5PØke7 nb,^:tcZMUl\bʜ>}Y1:=}Dd[4B$ Q ?(M1jL< AU νbaZ,q=6|ȫQ Ync< S Vz>\iX >)gF vϗfރwuB?zԒѻ 1{1R_62N&?,꼩b]}i׳C$Z:jrI7(y:߾ 09KPx@VF},M;-b^mvea;7/!eiD)cj)+uX+!G$^Ye`w,P\¯1w=m_#~H2 0tq$eG~?*ӮSss\?ïPl)) -=zFsnu4FlKj޴i^Db ` Gr&r(lUQ VV>{ *)R*4̨:S= e`²,w h{tcgsZe ʂD֜dpl s-lUfoa[S ?9sToH)DƲ5Q"G!-~B#pfGx"@;<|aJ PBEg3s/o> m"(x"<*iű,Gw\j`"!RG?~9EH4u&ۊJӯA͐#*IL0*%67 +BVqK82&BVxscկJ6npڒ&rA@b/mw" h- a;zҁ*R#g,6H^SDڔMHBL'J^{hkE_*1ԻbK:!҄MQ<6uzɎ ,ٿʷEeYQϞȹrDC>4IQիl nA~pļV__tiX.}@ntle׋h^sqz~ݩ^hٜrN-~ϼ9k؁C^lD܄D.P=,Np NJ`+TXGP% Baktę6°)z9U";5N0^*viߔ]? ge0kJu; .~G8$+wha־t"HƖT$.f|րʋrx5KH탎#S)4yEAF;&smuChqcȒbZÜx٨6Kd"g0&bk46;ͷHN 8{cx]=hHyOeQ5Q ̙* #8=w,=d! UZ7MEM9g4\1DABn90m`D;$Oo͋Nz~CYXTA<@+O|?ݴ.!F3")7Th=5˩հ\5{7 nȭ^~/lpx-KBEV%pbBK$6zmljR|Y(AZBRy fKeee{` b"E:Pw &G2 /l[wxQ^0Jw˩j6GJ5N\,`q%4W8OR6yKZԥ(u9j$Jp~7睒&,+HT uDn(="8r+ۧݍQdS ` )o`Dӆ0X(X0W߇h3Jҗ !Hh!݊U?Qhֻk_ȹ2W+DV}Q6V. >72 }p&E"lwTOb#@*J َINb|(;dV F|1ѵ<^M5BGCPms"NKY3 aR!*b}H* t࠳Ƣ;&}:V7*P![*Bxq7Ő kCg@Rg7a3-Gicnl&grYD%$Rq>~F_t]# սk\w 1``rXQBLO3>jaRLyÃVWtTCE ieVɞ]f&7t雂L"5uq6td5y:Bd=7(qST rt-e xBbi oh7TNKoQlr:&A6IgԂom27SBT4] =įi]&."wKU?` 1)XAevq<n߮s D}}\6>D9FKˆM c3?-Vӕpc犼D1b.Nl!O z Щ‹r~rIWEzRR `j^ġ<xdG v:XaUḛ[kʉr&/n CGFQ؝5\Ә !EAUAV>&w\lA©XfxxW^"jDeE|ogQY[6 0?NvHzU̽̊R=YBSN>CeR9}޵؊39f*eW|VjZU;V3FXٳ \5($k= G UR񉏖[5M:D ~q“;k &b0G 8WBx'Q/_ PAh+[3%$)wJL뱙ʍͫ%)aB7,eBNr:c #%GC5 ٨SW\a7[ %| L/6d}IRtu 5Q-S橿ĚIGh,IE,#c]U²܎W:;Ѭ><7`E'>0IC:,B|"[w;ׇ\VwE5S _BCdc~,SRSW"O:-ϳfՆ&> 'c1h<3 /)お}sKO_c<*|Fß92mZCVHAwDXg rwMOԹ8V+_W=s0@='w, XeZe5o֪ֈ LRmz7&1z*rg Y|O|Bٿ55MN^ t`u%l] bL2q(5chR&-Z>S04P5}c[B@ #|V l-- 魉c<\[a,䒇DHXzgT:b#\;DYA y %0Zh"P$ t!^}s$Ϡ4# ;K?x0+ 1}p u\;쇰llGJB&Y-䘍Z -Um!JGt2uic3;[Y7&"ljʱ.b<l.LXdd@_C"C pG?G"ݽlzN"C%̀6B8)%Or# &G~h2rGڦq“&2 pd!&g.k#LJ㸏 (cU oOUOwCt V#6VU6oW< aV|r)Q N㕫c^Yo.QZcU_ChBlQ?30N]Z9I-T(۠A> )ρԸ \CZ@|pT`@AȓgFgf' =lX KrP08.^<K"z`7Q>܉E pϪ&^-NTsLp?gi|}Ҋ1iHgvu[GnJ'd/UJ/k-,o'cOVy BҌFVFca:& /Όټ*SR6fsV׮|0&#@غHf7nhX\irH8<wjnBlhV}\vfcs2XEƞ\m6r?fF[@@mP3dABr3a;K5$Y`K&f4YN(/&b5H$t~\_-ðCMXS.g%WAx}֔U3ǜRu+ ގ|2eiRU,ZF6n @J{TBb??PQܰeڇ7 k2s_ sш0/:|7|K[y94y)Obwh}yQ~ϋg@JTlSrz0畑P#s1浗Flud܇xdU ö@.f5kME_S!K![}gX4xz{2(!MT*t-KUZD%&k~j+QȥϪ П-V=jOQ~~ +QzR)"E oƒىD[늕qsXE[3'SZ(ƕ-u39n&鮾Ar!}-j p%NϞdڑ%T|2pem(TGw~μ%"fs?`:O7?#V>Jt?>IR*wImΝp,o `4S52…xbRyIOwgd¿C ,DE-s6r?;D$(!,kaFWCd ̂bSڜ"y~ P~ruriL :$u _ഊOBAvF̀EWT+^f)e.퓦K_KɿgvGbnAX;'p"sw8͢>AbpC$> \sDmGiGd ܶʼ`pA4_(&h#ynmMc$%\߈z#bC3 CnMOK,jDޗA*Lb.Di~x K0-%+;=HI1/̌ B+q͕- -SƾGfWNsKf,<.1eêP6ti|ڈ"q6]IM+4h@k= ^XRތߟz׎$UT3bo8V]̮XPZ!3u]HTzMsOT)R10(ּO,ӧz db%@kaȰ҂Vm }u`H)g\EGzjr6]E`+;>*a=Ę9%Q~,q8 =Z͗kqg_i<^£Ɓ¤ P$Q %>xRE#7k`Dߺ#%5ߦ/ (_Ӕ\(7ԕ;m$s-hr.zULnyFt5E|sҷo\M)Fk7u$p.O'%>&$+Vdj;pv[wyţVC٦N[BW֠=Hdˀ5;$56twGNHU/`ю S^{ CvԙזXqa2dT;2d^8e̔Ev󧁳F@IW(VzQD~3sy~XztN ,4{P0$'J,[ /iCc=)I˗$GE * /UHu[)%E|ӬB.)OB}J%jE <[=Qa8=FŨW5@>6 ~tdd6FTLdd <$*$. )/ 2:’H/$DSy%0xu4013Î5z|W`>\qd$d} >~{6+AfP֦>,I|Hqʃ3\JAd]=:#o4:0CFZ}c|Ǣ^8`˛*ew! =ZTDRSQI;`c/PĝH*M/'-RQ}<1mkYTtvJ:~I?3[OBIyU]t%i6'8+ dcĺA]c~E*+|(ռfhJ$}"r1$??FLC.$ (Ki{-`SvN&o5CD[/xO\h̝+W*Ό0ԹH:9|JHìHh`Ր=!N.=TzZ*ؼT539y"~fuhOBqU_f @CAr #?'G vkŭJ&vjHtAʃ?[3E$k+RbFhc'ph@VehmlF鬼nƴ0+8Il^Ap`mVVqH/؋sE+h#f^yռrS*p$a'~Y`@|xiV]Y/{ k3Y "}.lAPoF>wr P ǘ) [03BtvC {|i*gv?qJŃ[Y}h7_UeMkz 4VeI]>Ѻ i[L\_.:&ȶDyMh?GcҌ\9}lo52_ةsKE I4"B\KS/Ǽ‚mN0$i혉̨op.>84jc<-Q9vX.ɷ,%!U"' [@nǑo|p89 RMQ74h DJIҤY>A͝w\⡈X~3o'W-C&{ 3wv3i]V!:_ҠO* IjbRӈ&$Mr5Þ9x2T"Żt}ӏ\s&YFt1Clo?~>-(@lRl,>06mҝ.ֱ(2Ƭ;W@VUN|'i2|:gPE3&V-p\6W i* -Md_rڹB7}3m|*oa5zc=#dzZKTO:J[Ī<!GR(LUF I#aS/U|ls jfx W)7*% POƼ0>h$!*5vhܭ%|:$Wn+XY<7>©_gq4[VuMF7AnbEG8MlC;`:!ƮVEvmҍkɭwR78rlٝ$:5c3ɸ~p6cCpF6xe>nuk)5EʜO /"-!sMe4Z^ײWJ#@?|c; N 3gwu\ +HfBD7\5zwq4.QnrU h, Y'|"dO,CĘͧД1 r vPH v:*j^w2;":R$= LC+<Xzio&ƛ:غV-db_qTKɄ;sNv4d͋[ܭ-ٮ(l:r^3B߀! ))>lo:Zx^lW]Ȗ~U wSb<ȭInaŠ˓0,_~O_ʓ $f^;Uj$*1NCX DA%<{|xn/\*p|:NprNrYCC2u=fjڗ4jSƲJ6#a)v 5}&<;oH3Τ{@#>O4C oINglgFuN]ZE+iHufWSOQM(s[aEL)&ܾj v JR lJ&ZNk(bRFV%,iJ#QsSHHt ^? n_8d">ތ c?Zw,MC27x:˘9jN+?|[m} 61{26i"7~%*DwY&/XVC^dXTvSK/,ac2N¢݄دAUu-hSUV$R 9U!~7Vk6'Bdjԓ֦$Pբ:iXFr˩ acSHlxٕqTt_M9~fPڔG-p ;fOPL@p"M^EqįL&³ZMU~;Dݴ_X*t5oQ9yD4uQeTYLC]IyguX8k!SŜ8qJ,: P}z<c7X?r? %3to%>QZ)Y~wٷpæG_3ڬƖ(2Uμf6E!Ǎ}*%vffsA!݈e"{$P9#c5iid=ߛKl}ob;qzjW)|0@gL 3hJXC-n<DvUTLN`Z@t* ZQ$u8)%a[ PJ1I:?@(zfްVpU[0ݢXeu>W$mB72 zSY]ӝ]~:'I)WtxC-<pzOY3<ӼNg r(˫۬O4wYZ4l]DA3zֲqn%w=8MqJ*9mnG"K;snHǴJ0up*쪄&FR ZݯMA` K_$3ZIVtIo(c@M7_0q"yEki-ưmiyIzy 'i{7r-(Ĵtm7B)"`K9UՑs8w wLo>Y;TbY2h8?ޏµ͖L!cT`E C$J2K^z&Rw+nwnz恓e"RR].Y+,iכly4.tK_6vPn|82½ڿ84INCRJi_:2.>HdשTX~[~(qpeN6|F UoJ둺 L˳j!^%WK +t?)xc 5XG.s;=l(LNk SWN.lbong Vs54qQ WP_?Μ JQ54m*C~*h M\NUu?dbdh\q(5o Jxw 2mx /*H{)w|@o+N0z\喝\9N-7oCH67p(\ a0p%Zڥw[uU6/1@CH% G_cg2 i=q1w=zI!:c':tpDco⻪<^{w#pmt ]X|o:n ? Pb&u-\PX~ѧ5ZT/\%8ޑ8t4}2vvjJAH*vO l*wxq>uPzw@`h˅}d~?Q}lVii1.#~2z0…,>h(v_"2o;%(wdzZ^E=4j'э4puuJ`Dʀ\Qz_5ߚZm@[*HƪU\;cO=Dy!*'Āi>,lRf`qJ@3TPVkAie-2:WH RejWY0 "Rc #O8PYv9 zBn+Ls'ipNq#a 6*a.+pOX=&i*l[tgHL/,:n ܱwQ]Ȋre YYtJ.01E D]WaޤBZuWp)#IR Q~H(12 aj˰ lBY$ }+پ~HǺ\6<2kx$n eڋ.1%uYgumZ3so%"/U+aGS>ktz(ěwp9`x1-p.VHTK GUc-;ttPc^) P 6D:2]/* 44^(K1]gV ~*V4txC^pEnz=GgK)8Fn@x,ĊFqdÝ0\8".,M%_^f>H2m;3vPQ  Cw\d]w-b 6N4O5:|;JbRs=rjۮ]Tn)9E˖p2(+A`:Uh'fb}N Q2!n*\x+[Pִ8D7ZoFfQ4X}ĿOqld:S7R(D/ +L2|{N1 Bx."}*.ϡتJеkxH؞#'bra(hS" $rA[6q(#2 J=]'8mhU6ZeҞ;<3ڟ/*4Pg7]W~p>12)j?O1yr'eVmt`=ND EmpU0 eqdQxÔ(tO;_:ppUw  U4h؏D&L2@lE V)5Oℴޕ_..?ВDċ/Ŏqظ'+/VcGn{xcްXIwÑPKfCRIW {LޑLXНPI+)Вr"5Rj1Am [+?E0od#^Ċ.s/;\Z@ՑC ĥErm{'`o8Rt#/(- ȯȴh>`V? ehAI)D^Rvz} 6_pDf UYJH;37nmkC?HBMԕZi[n sq'B EDS5tY}OMI)mOq'U^JbuF6ΏT5f n9ZXe" `WB늴рҖ\/sG\KJMF%p4Ϸ?5! 2 NChVpk1,@R{ r~VTنފa,%1>*an1YW8%`#!jI2=MEOJ1{gٰNA)1R*,:EEp l =C|?{,J; pʼ)Ӯ׹kĪU$|XqjGtEtn'8"i v<|<$ye"$fIΞwSDL1)LJu= v',I>@ۍ}cYt_g+ՠ奻%-!q 4"al0P$ 75LL soCܫ9LB3 /Cgk@ :yp OTV\b-v͘~a%dwȣT7MTKnD ,4f| JLvḾ+pMp򺵟dT> ,׏|O(mSàT9^AD(!_zhB›1xG5\a3:PhgEz!`)cv@|cph{ꓶMƾBҢ@ ۻ6B̎\KhZY [()^cZ^쯀ݬNc$e^Hܴ4G V(`_YZD*#5Ĕ|2樑y "VoQ  qϮ.~l1a2^Zd9bP6P$( oiTO'$x;؟({ey=2+w?2*1jo@C"3#Q+{:y.Xeh?؛y(I,jZmX.LZ g7IsҨhpB]૽#!&$zձd) a섟@ƫ2TPSSO'W 6@퉾5x>GUZqjU$6i+"l()^XN ׇ}wk8=dAn|Ͱ}ChQ1: obh'hR$qce4/l9+HK3o˴gG \ٝ_B͟{LMmWJ@ qp,='~}TwA|5l4챗c8TTg{;:M!Izs mTga] N6, r2m[xr?0 T?p m1ۈͱ\X7x\% ˔-+H[B=w{ GPuxرY4X_̀~?o#._\aT6BDN3NJ_JV~ r} Qob`6OJ@*A%d%"fYxtNG+Sw%A}z ѾEaۃnr7q`X~CDnNɲS5 Ėq CqH h(Ҧ5߾\ 3es-IJ7mI %n蝔N`l{X{dЌL-xޙRqOsQ¿?L̎’pAl٨ 0_fOy mex==ovecɊS Ӫ Rɏ{|& #pI=xRUws㻫8Q<hOMUmDw]d(B'Cl\tntvU7vuyLkXD/4^>s __mq)DEjC%Rr_^g˴@] |~$OZGK]`CS>LK&-3|O.OFѬW.  .!~ܾ-̛ ":ꂛgCgyAz3=$}LU):.[6Q[S[L+ٿQ~sR Մ[3]kGH¾ƽ*fn$`+)BBLox p1-.I4y4roo~in(Tw(RNga%\6"(JcϴXvAK0XA3 Ci(VSq'X\lua,  cT1 &jFr{(jAv> qRTJ+SOo2@Z<7L<gGqwWF(N"j\!TM[R@[7GMB rKL!BӠMhS LQi1"Q+O^]b_z$uΊ-Huaڴwlo3zdؽfbpNҎؕZ-aT+XD(]޴/sv|G*4qvȣ}.QnVe/esU ;fT63%ӻ̆@GD i&"2E$ =֔51g@ ƺ)3sfQo"ߙG`L9ItPI q'>&>) ;ס AxP?Z gcތ!|o/þD0E>/˰jѯȇQĴ φ)`źmo .zu!*7m#H[-2;emh^v}>wj׽d?_DDp u;+#l+׽%yA(.ԄMȖ) .Z[\ 8MFp̬%+P½V^< 5%:"2]oquU!ҒľjE:(JIeN3HzM?o&-k$Y y5EhYiL\>D`'8.[?+e7ؐ*"Iz)I#8/IO>IkTshx1vᦰ\#<8sWm"iK> edL3}ci⡳7{r LTpOA*VV ڎ\iK>5{0X Me&KNtBR&Kh@aT,)ނfLصQkG3YwtzÊnEVlZWk:+Ěpqػt@:UXyIu~@|4dD tu.uf?DԼTۢMy*SC#h8B ځxS;DC *H~dBꞺemqd]YeBD ssY1sG5,gHG]Vr=2??7NaW#X5}ӋLvi< {R?8i'o|x ϑ[ep8Bm7d9磱(H<"6Gϳ!e?+<5 EMNa.UqFވf_kbȎ#Z6TD.}yq/:2U׈\3`Mؿ8.1aC"V#Rf5Aq`xμUknFBџQ+[uGYKr K֔ KU%'2 Py.5ыr8nfhz#)?((OΝNIko(s!T:0M9K-9&xn0=q1ar Y z]14T/Kf<2ey\W|wJɆKQT7ɉ5IC@ *DLogiɪÑ/\%xqM]6JjP 'y!Mg#>ДSa@ jM Xg0i6XsE)vLK-9!a,;y"@w{\ԣFkp($MFiU=E"& tabsd?|mK~LV;}NԙmH*1#3P"FabU gˏfFFʭIR)+bk;d+^KUYD` LC!q #\ohK{aYT Mw0;7"t*RGKxGљzC0x3+"t)@ F?(_48>QMx_ܪ1[Ό^+XZ%,pdqfѦDa&·9ުXhۃ4X.Y ߑ68t"OqB*-vj& ή`Sfq0"pC?BU +"QE,gaURD% EԻS3i1|xAk{VC@U8XH.|)K`2inIx _i07F< +XYuةg\.T)QU=!˪ {1]#KXӺ?Gx ]̿+[6D(*+9l| )D->p2B49p2OOzB(m1== Q֢ˍJb(LG#IOȬa+P-hGԛ6,#%ZaPLUG:*Y,Ƣr[6: 9W ,!m sΥ3`A|wD&>$S+g8e[6a[ڈ(;eETz?oS<%&{86.A]5@DYe&|ҍHm GA_iC/̈[,:KX/UL _Dc" nZ+ "xjdF~RgR innjC,X<$+e̖tBU!Wܒ,JAè3y_$@~mG1~j%52‰dBcl^Y_lolXX$Yjܽb".p)C#NFzFqHO`H*!n* )^N N>:ǨAE|uOX^Eޘ~W˥ kXa`E=0r &m6bBw&p$#0DE0`#;q1_[J za3NRF\ dʿ[DH.5Nߎ;)O ,(>ۖ{}{tBthkqs7Cqp˧RbM_6&<*dn~!wyRdB1Nw.;e96cwK ITsvBZuhkH5aP2̗)Ǧ&8t2n̴6#e,昄Ng N &]%lpaj+xt(Nyߧh\Q@謽]Ҏ5lnsø]b>X++%Loֳ'")$Ԕ`m 0tӓ*Uݺ}QXE9֬zZmhkX͓Af27u*֖6 )pE1e@.\^{|X9C2sYⲀ"K$EB?ol!R/Hh?7_ &m`:NPq+7:KCUo-},} `Mۂ!]3t(~yo1L \lT~(0Ij}է)%QD[fդ+.y#~UHƊCRo2>5DsL$سf4u׼/|<ճCzX1ޒ?p̘qUr+2RhOt5a$ zPK,`;wy .p?i됛4?-)h։šZ$5E]6U.eXdz~kk7k Dh3ags=%l#1B9sx`,@5QLxAmh|I0n=kgWcxWê9Ѩj6i_ݳs Fs=M7&=$HY}sPh'Dt^o HqT|3}6v ֯iCc´V$muμ[~?ywgHZd`ܻe y?F)4fp% !9ni 1L_Y"JCO,h Oosߟ:nMr=F ')JY,+pmW'ݓ)X9chq~^6Ќ^s[zt!"7&jI;1g04r?옝/lIP=KI4/9KAe)09f%wtscdQIJ\ U|؆*_R"뻺#!nwPp 2> P?YM0feCz}YA.7ոvjuS閏ל=)N+DGK$Zv\zNV= vL:gtEǴ|jTOKtױj>s]cK%fD,+7==dul*xw#\Otћu(egM80BL+πqack(Yr) G&e;x{+˼jQ6@ۗDgdP*%&zJJ@v'&>_`+$7JBÓd4[n#N;- _BӢ.3\j#EN8^e6@x. =eW jq.f-įMaF@H~æ>,d-ѫtQ.?Gx@g= {*x~R6<Ӻ7i]np3֥fƶy;^ףф7_hm=|aۺmyQةXP[j"Qءl_=wU ߑ},ەb{9aJ]EWiMPE}e{_:i >&%|Qk"!w\VT4NFPHv8bqJ";ţyA_Ii䇁aiʆ]? U~jw)G2@+6-Cw A~$*AQUw\5mGFIk3;) 0A[ZzbX7Ajs/Ѝ%<bvu)MGΖPY3e+y?CfCX,\F!P{k`ĩ-KZHϨ4quIJ A=yEs_Rh{RJ̶y7t! ڪob2"bn\tAt. XltXbW1׵ުNi &ְ oO ] @I㑼ZeΆOW"2U>eya_""WߒxBf!rV"IGrE&͘4Iqu&uŦn6Ȭb1^}WEI[.ȱ$KBh~E_dE;U<ڙ;X=oSr0ꤌ*tx eͥ(/eVl(\֡=`lgY+;dn;L ̷LNr%X1! @Q͋qѩn>~pZJ2lgWW (#WTA< GzrfBKҪQ؇c`9Qew^)7B딚 |sW2H){'_ogI`Mi{"N6 l gzN '}r+Nx4TqSjqGm3 5:(fhc,nՑᔶ%ldK ZHL\A!)`2zIh}7:TSR݂.HՑ)6 RhozitLky3/iWжjFYلEa46}m[#ȇ-FEfOutS'jZ(])ⶴT^U GW0̏F҈ u, e%m`se`~o^j>"/e&>ߠD$̨ @'F'qsmT/$d_r!Sv6B\iwŵ3o/h9sθbE31(o̼'Sע"?tgdXaǨ9DnN0" _AM49cWQ.˨Ryk%;Ɨx .sI=TLyh_iaɷ]]H;/a䫐H]JeYeOĥTf8# 4wjjϾ9 I{^S6`f-4opN;4h'6 l*&~t}=y !"{->ܽȴK>_nV,Y֐?)^>T]kbӣL8Tu0AţqG<-(lE>Ev4د%HYMFzytip`> k}\o?,-(*,,B->Ưׇۇ(>(k7LEb!%>_Iokdd b -8^XĕhF ,;$_K`)xZPLġ9B*=Ȳ(@el B;O=C#(L-־zܭU' ٺ25a'4V̦ GQg3iER*6Wy{S 9 &kJ$@Yq_ ;#T&.ƚnn)'p_Yh 384_c='%:H*b`˭# (vpF+\iչB!Esd=3볥t"j2C^nhwӎ*eu+4{-_zIYyҊQeL! L}~ycU3=aY&/ZUJ Q"m xz/Jx0@Q|-c?wO֐_+¤oա޲ W9Dϰ5k0`.e^'x{[UcRW &3P'x,H<{=dŇ-hf#uV/o{q6NNR9gZӥ)&SmEm`? Ox1 's):Ӹ!f, Ok CbzoMM?[,F F FM3^;*8~\|4(P\_Ne?")a%dҌZH?C_WO j aBC}.BN=UMBzcYDj%;Cֿ9Mp9 B!P_\X0{vC B@XFȘ\mApGtU2׫{;+7F: =u>+A5= }aa5<&qin9|Y! nU-tV+dăG 1˛vn<  f{UN33ݓFdcs}eLԸm Oar5vhƵ& >o*zڙk+yC|2!s2:Z.n'-W RL^'*B'aL1".7Fjb\|{н硷Aʞ hxe W֬@fxlGo {1|gav`={C7y*8g l{o X[lN frt9.F6")$xսK | $9+=.rKpyoFAeD-OzX.4W%l\(Pj5?4v׺dǻX95 a}9yJTp&P4?,y'q۾񔈽pɜ͓ٽs.@apDGH,OMs">!薓%Œe,JbGWywCv2E}~_Rg#A]igdKU`s7mٱ'm $Ǯe޲$BΠTNhvү^ 7o;c-'m|yL!sPc  H>XMiOTժ3COwv&dAqg K?^d[Q$}~ |jh  2:Y @~buczrSƱHe**jzvfWPYWFv4soQ1 (QA^^@kD?n+j_ܬHr4N7̵W T8vuKz:B>f-_=`>=Ab䈒Sc1\S/@+ED]nZ"ҖOEmM(Kp<7iz(Fv<3Dxm8SPީ8,ANK4(WCʇӥ,'NC1tO(Sdxu tW1W`)0*RP 9[BX+FVC;ßڰE+8Q_~2Gl Œ^xsc@n\􈺝r5`'%>\U747հ}>Yey;WIE|WtX617 L ]28 O"a>#5VE9>MjcSX\gT"ͬ}{xoWTdmZ.?7u eeu_HE}(-n>=@Qw K+JǍRLkZkbҠxq7jB҉h }eAA {ldvr.㲗ñgt{X$ܞ!3^& m3HZrsG܅&2RW# _Ǣ,я](vk$~T$ mT#)hh S~>$D#sx':+=6xM2;LXW5" O~)iIcV[_۔,߱w;k*= "-kϪ$fЧtkD;1oOi8ގ΀ԂylN_$(*.9ncn^cCX7ٶVm2 Zr]p4}1"ۉϙ׏l^VmTFUWG- fp@kѧ7AMN _MMg#1ˉ>FK$`>%T"72Qiub*u׮|/ģ8%c%ֱDXSt^îHUVNr?D|5Z8k ˕sFӧܺ[+К_H'A"hU;ݣ}<Jf z׀<^'GoE ٷj=D\=-ɠBsԓijwi0^ (&\|>jf.cS7~L Uj~j8jI&)2fݙ^DiQyyWPe" ፸ti# f9.E QkhV.:\y;' c5SƏA7dw=P5*\7mÓno9sfU>haMR@a;9_^43sRAB{* * iv Dq_7 "rf¼ö@'KmCͥYd*|9+S݊!ES9{WWÐ: Q7c+L`hzI_1w[w0# .6֦$6!ٖuZ`UN7EGw`9 : ?؄Mc`ZEE5YPC5gs W\@0 &jotra_'R}/ۖo!Z"U,ooh`}_g>辉տ>:ģsUWs=Ͱ\Sp6k$)kŮ(`gNqir3(Q/#XZ0LBʔ%M[H߄5b LaL?SB(_z+]PpzC5`UZ .; 2Kb!3D޻A @܎ǩ*W]Pm݅{l`,`Jl4Z}S2YY$ 滄ey *<k~wN P^$c7}=Jn;iM'WwjEӿ#0: GSH x}{#WR7JXn Թji^c]paXmgަHFZx-u[kU|3I|%<=;2^8Nѡ(^3Wh?أ6t(A1NN҉]g ^5c#<fcBs@V/w]D.Gj)8XA}r[ #31"Tyу^#C HL!4h/J`z)e܍PXQu@uƗ3PvaRX]V9p|NֿcjO9p@~jhTt|Zg>0JXB2Wpz{`[VYX H${IPOqPg?!y<xQ8?CUzGVpzƘʒֵxefPV~"I]'&UYHKxYmg\_4~MY[Q4>{.S_n"Wr)2VUci5qJvX8MLƣet؃&I(HŸeCI VT:DѮ2iY~r'b"*S2,LT,Lpq?aM|nUI !Zъ}fxt:EW֤ScC>h&P˧A/o^TRv E;$ mH]M |ʣs4uZckԖ"E+wbZU:·`0D ݥ3SmUL_ŕ2k-Ktp {Wˇk[1!4_#DW{{~ Zf_5g8\ Xd~cQ:h˔soL\\V0H4WɕuB@*i_]ȳV! jl4O`ǩM&)K 3̓]()D\bY$zK ͵]М/DTUm(s^8ۤa0MB8jE,X8?>;F5gN~qYnQ.Q긐aNϨ.Un@3m^Hwoe1W\#QF̳ v5utR?|xzRSB0=:0wڳwqCr*AĉQ Eo5Jfu`yJ)/t9e_qtQ4Ab4.aEqC=o6kc\& w3M<ByQ+ *$>>KAV}ȟ"*Ϳlhkf%BSuLͺm>%B }`[$U-r6)a4ÌZZ_ں"!'(zZeQcv#=PU"g=%r=wP,jۅ:ǦRs&5TqHqMDH'!R|~Y5khzWT} +-b_.qht/Nޮ >0e >rz*J!UTgINR)4(=}s0 4mFDHeSqWr}j\^as3V97y:1?ЕϬ/C8qDOH^R6P;6gQ[8T7{9o50"4EД7wE36e|d#Pq٩C'^] }T* B(l]RmheLAQv`ÎnCn[ay h휸U3^u+wTG15O=ԦJc`ϰ']&q`|[QȌIW(+av]JcyIB5 sdQT&h$LABPIV7$uVD={g݆^ 0!i 8K$S&'B7OˇD>qvQWəU7{Yc N/!bbv>@ Ƞ?'DQ 3Kb>Vxe*tD:m}޾`d#-8+1O $L}=?k:nD-JQVJ!uew"OfR>рV_C/1&3t\r*h1cfH@py < ^&I JvDRU|]aGH+o,{WXR͘ڢuZ[c/$t:i\خ^ɺCx\w8TЮ";&nRwU6-[ w0jU7 W2¯Þ8]C-@i]PM,3q@2oCT-'@ش?:;zl/*y TݘNWvTw9dxN뇪hWOseEnb?3$P X^H[u,/t=}ai 2NZ?TůSJ oJK%ȱ9G7]Ȋ'W /PZNM'R.&Xq@4p ?I@ɉʕl |c`5a젎tZ{ L"RO#ZL?K3@%棢13-sȽd\d/ 3Cgju|Sָ1AXvKnKDz_Y-ݛ iZa < ac4;d8!;v |-20WfZ_PCQTe;L|Edc':D^"7nÉL85a-Zo!ddīxEџ4]\:3eA3QOԯxݨamvƧ9E>Z}[KjaH4aFExyfTjUG5|m*㝜%(rUثE8zM-HHXޚûNP~dB&Vx$b8Qjgeh*iZ_0y2K߂J@/x*Sї|G{~@~K˜s%! ,Tx6t2Moώ p?4NRK.$2RL=R(K3G?RF }`Z&*朜D0]A"!B߸r!PS.?AJ71' yrd7=:!9JTp𡤾2b}KXuoI3R+$B7(Q ls&}Vi/(7)Dr|m{5iJK)n)|elh)зBm7=S(3Y9`ӺGu\/tL ZX?3!߫6GUBc6> vO s^v.P :*?eP}zjadNJWu\gips9R]B\dɊ~ފMoS\<NP3SLNܓ!SUGu/7{<鏆Dj[t04ʭ) iZ0 Cr5J@N3tDAT5hx4'Z}u cҸ ]!Gm Igaf Z 40S(U>])ݑ6Iݣpnv yP`qyv|l-zD`m¢W͢UQ⇶yh'[r7Ӭq{bKqjl6lF0"c(s@ qt.ru=nR P!,3Sll{kU➘ )=b[{Pu&`F(8D1-J~q8yWr ]Tu39f8u`|tv7K8}ۼSAMp2zo T} i-l*dc`# !MOwILX)IzO2؃r$ Jiht XAQ 9MlQ Pxі"[.gAKgVIg ؁)$K`4Ro?Lr(ߢPv>C?9 }@Tc^\p 0Azn=rE# ;Mj*B!NC!( i(>Yz<:\b6ހ [Y`vnөwv# Ĺ{VUG*\45|ICm#1΁ϟ+fHՒ陼<4Er'y.Wqf l1?AլyfL:2 D1pt|0ah 08lH!DW(%4b@}ۜhe%'h ??XZqܱ1Fcڸ 0C/sK:A{`BLo"@` ms_ďKOrG x-6~ҷbVmTOkq6KWK{|GAZYe͏.|v2eE4/Q&H-c˒ p:, 9DZٶc(_#*XiOu}tJ0sfKt='5 "EPU'oV''U}\Hӫ?'{/ahя['^V2HCb,ZM?,R7 @g/rFק)O-4hrOd 'G̷E>w%Gr Qy[]w趯2^aDJlx@&q H$3hvtJ8gQΞcvlFёN3z}w~xzg%7h\-]eU=h}}qF ófq ]&J”%m߶oazPy-̴< v+PUĞl骨X+!47)uy1^,+͘.rw) MrMN+NǣÉ(pUq:c\urP_V(Z߰:|"$%P(gS`XÝ]#8rcǷO6[`"i!$tu}̃eHݙɄ m>\ن'Q9f+#yЇ(f Fz$RUV`5aN^rVh{C2pdtd7TsY:A+)X͗KSjn_|8)&0C-?=դ=!4HˣdY^TӴgJ e\˰u+Ҷ3'xvE]zL[ҝ9ȅ#ES;1h_b@}_!<{ u^_KMqbd%~'m],Z&~1j]K 3)T.=Ugl3ۚ8ʻ 7kc,I ckPʧDvhm5P,V#׿T3QeQA<97JP3|pʎ/GPߵٶG`$3I^; կYf^Ptʁ)KʵJ`N$7Dv%^G uzoE/3&`>yuϭp5( L8~i;wYhz 7R*v}"5J'p -R8yQd5w2a$”.tb&,QcׯEz'ێziNv[kG4П>X<VV f7wT]0rȪak#wX:߿f/󾔥2u͊|_dH㧟CLSlj)N&fGrDx~ET8s 70*#.[GG)^[RŔ|cB$2!JV8k H ߹6E6)\7tCT]K,xf1eXJWa =Vts a+ϕ=)]aF]4ДS(>u=7Zlx 1. دB%ၤ*/vH+̒RxUW0e\8#K?'P#6!ÿDp(r aw >[E+LM>/a~΍RJ;y0 f ˄Q55RokmW2A!:Ӕw 8˻HZ7zMimhg:HUJE̵x`Ei=&ْtD`4(;cW=*TUY@jr³wfg $ !Y[0D7c};IA`0OMky¹e)cSb++=nFnȴC}< aV{>>d:+$bF d85()շV7tu6^JNȃ1ZGWO$q8;26Q[nvMVu= ŰL橞LUXRbO1_jLTM*gZ?K5bH*]6*xy .C=oKb%@!{[{=#t2BU"ZK`~>}`* ӑVnf [ٽqiI@ؐ/BԜQEݔVsqރ:/b?#SR陗8kgыX]ޔo?1IwߑjاPp9'i:odK.`. $*T@h_E1TKAϻ ֍n{wFW~ P?،ʏkiI,KKry j]JEdy֊ӦexDs!P-ϙw#}Xu4uC-v*NqWw#ApKv[CܣEY i|*{mb< >Q6.GRio,+ƣecZ ޛ*rA6޴ G #ϰMAb\Ȅ_J!Q#atL18@D@ӛ"Ez?rDUC4N$\+R$֔mFnڪܾKfTvs[-_eyilMdU<9ɣkL/w42:e;sQvhL_壳Űh`TM}6u@Uv#nsv;?;h笫eZu޴29.n~&BpLA(G]]bha܆zr fm+WD(Ȼ ߹Iݴvu&U @].͖"X=z/ ZѓkpSkbYK(AmL~P9Hњ馻!6t-؉o;  ߞl $)dmJ޻a&K7'hlHɱ'-RwX\,;i\lW> &2 KT7A@M/E+ӉGq.)f{vZI'|)^qå 5~]Vʕ&ZmJ~>M]QeMHb{_nщ~ЍhUZ>vD^ t8MHO'Gv-I&% ~bթ|n/X?<|$w`qx=%zUw+;xS"/KWpGMQ]rpb}jQ<7owdUy,=%T>ξ1̰ \bj86MH&nrzSNK,>hTөg0bo<0^?ȘQKgMF ì,`=F3wRYqI٪[[ےm8wf<4r"G#qSNtJͼ$6VmZTF,$x3Wi%%+31;S}V#~A9K(YP:D8cWCRJx}Q~I("nZ8g" T i{sQR斃 7|G кwf:Zή7ߘ{'?" )F7<;?î`saAպ K\M!5Z82Yݠ]4JEbxeNwBQ,G*8=[ꃞqk0b_ƀJTcHe9]D#@{/Csa.fU;NCAkVrw-bs;x,ş[cR-#_ցb7R }tNXvUp3B.lE3_ΩU>ʉF?# \KWI8hHN#gf )=J7Pk8>e ô~ njSWՓs'{Z|@PuL@*_x7?0/uPm,; Y}]U1zC@,SK|3O75Do+vWz UX.oA pRC`*lYl.SWaw[ cP'^j/I5,? 4F஖U0PN&t_j:BxP~'k0za"~FO~8@Ng55}\Z`}d",|TtŽEpWKlx Jpc}wps$nt0 b(%Yߐ Dw|>LAŗhϋJ ;75R?s*j;brT<-_ $o?XD:P[ aL4xIeV(SwAYtqrٝ ۯ75Ĺr9((XWpnauQoO[{S.g9վc9ҟ&/tAR'SP1fGO3\ZPd!G^lO {/4& HK;w4}GjWzEZ֦fGq$R/TV ,U5SgPy:nF="a1zSSS 1sf_ ;(J}Js=YiQ\~R6p{j$ Э}5Y-~Ĝ_t35l.o̍Ґ0TΘΰ] AH.K)JG(MC^wULn&K }q|ifđw i8MRc?C^bBSLD >dT,0`cl8 |7)̩:x4*^qg~u:58$Sg|uӫ7+M@r)${I]G 7 =t천ý0n묮^6)M =8#ܧvnI/-l)Z"amPD6w/:ghhujfm%!N8og~>}^rm%@KyQ<Џմ)^)Z~DrƬ88'4,[qMdn qAcOlYO1bQ Gt_v>e!KiK RKjjgb;3 z( xp=9q܄v'D^lH,c.-')J:UZt7€KtC&nST\I()iЙ sgm!NjQkkBcsب3y|@ǷMUXс)WP jg WEܑzWp< 76i: >mʚL:3IQQL)Pm}uQ&b .CF Nջb¦mk8 Ӊ^C{>k-M[[3c0EW;׭^~_@o(&Ep7?Z-*C.C}$r~jld:eSY}Wp7;4x!tYGȼ [:M)DE/x:G+yAR,Ib oڿNS"%1 z嗐2*cz>!/MZ6eo0?Zjz C/V^8?&1'z)1QOgO HA1ܴ*<'㎁F44?YI'Xpr!ِ4).o)MY킽#qGd,H飙>Cc-d'jF;[}M| *LH`U7s-1fu!ACgN@ lf%A3 96=v>}37<= G9:m8Ԝ jAЎ~mIWC ߤ yE j[ iN,phzS%2iѵo|./zcM ?9Ibq j´kb¦lmng)^XJkC]|IXJOH RB`}^)B2fG-mo(:펑$ p(B=ԢF;h\ռ6>cx"ov_"!PN~Z3C}T /ID% 4d6QEW<4mᬇ7Hō$Tq!uxh;x~*YATw6UJGh>*1-;%xX^cvC珪[-ߍH.C#}iqQdvp8?Iؒ%bUm':P؉U82S} 5̎|maN.޺gV"6:X6OW!u謽ܭ([{xz[2X>VADם_EDvG4SqyѧqU6(DQ+^)r?}i_5C˫߹"*<۝вs!5ΐPC,sQΚjU!EAP3&Pgp]3I^zmӑy^k hH@5<9G~/Κ\4?} Cx>t`//Ge8?dV!*h; auv Ҧ_fZ#WppeԲ|[׽g㭬|m~-feUpg$L%\!NTS>nCĨ +"&LWs3K@/>iN]ڰfIX5$Pם:._pu^FGWaA$9i Jd∮u.g< "kȠR@I%Ie2kOъϗדNaKϊBRV- ?C$}}*c*/  :d _QS|BښFEU1Y_uwqX 9̬U*$i5#q}{ƸYD+7&oG+>agE(ÅqQW&kV0ZB>ťK[tm+I# #o33If7*ɠpIEgcމ6(^"3;l>0ڠPԄО+Z1sZ%)"ac*7 "S%#`|06[DN WZW$@dz[˼Z;~ w*=CۿKee6LDS=µ: 舑*AGOr? DS1{Jo0D'~l6qp]/:Jj:Z' -L.մ;n0[,H8Mm\5L 3hݭd8N'E~FUN6>`8UQ_vA_$YeW[^ FX/TSe{f/`WIR1L ?ckd(jpWd5fD_ۖ뉜=3Iqk$KP &/2yT(m(T_H {[6we硅߿LpO?YxI'1\/9ϛ&z|7>/vzoesp`xy> *"褅"$tt)mxkRx0n7UPm;@ʘ #ITC#DϤ H 'g7VlSK?z_GiTT3x!rbe{ 4Tcv 8ݴzùa\qn拽6 B7OY=d0.hF~!-f=b|í؟)1s/d|` Ly!@>+ƄrϦ΅ <"BגﺢꨢAfY0G*U";lJ0vn5_" ĊX߱;ܠ.nnz/B?OHM$\'!#f5NVQH.KC\ܻ+UAhmԋ"!R]!TI[L+O@M/JK 8X ׬-~_ B;-=59!ƞj,cܹ.Xc$[S;xcK ^34ۖLK,kq}l(Xd+4g]hB߈m̹sREp F: *½%Dƙ{,}*9 Gct@MnahҖBgJ9f:O" D }T??f>b 4vxd*r)beu$紿󌶫+Uߗc&VS'y,Mِ)%JP;r^m0ҢiGxӷp4^8٪-N~^kdb|($JVOG4*Lnhx7'pq.6'^oY–vJ½Ļu41$1!bbz292Nd76bvw:h?ioCͿZ b)t$4|N~4q9Ni޻e$q*b/`Bc>gMw6E"d\Ƚt7sqFifEe j ઩砭jCR GsLpE# r ‰L 6xJaWwxXt;v˰,244=?%CEЉ;0E,J.:)Fnl)U#,3!j)VT}(!Xz6#n9l| m\L]0-p8g-36%.q{b^J cO%!5wv>2CEy<*5sϲ'cAE.|D-ə.g? ~E촋R{KHw[ z࿩z/LpLZXSk"_}W}oZ >MBhva-?M ^q]+e3 jct}ѯ!xϝz'V1#` {8 :P)6h0o;OXs<D2:_aӣ. V ,RJ#ϾaFAZhc BC`D6'G8S;z6TBK=&7xq,^) V7qyK-0K٘L#6`3@(E EvzC{.*QM(p^LB._1[5 N%я g8g'0Yܠ6X#d>~&?DE⼽C0xz# k!XAx +jGjk'_dnYHe`Rv>nRI!6PXҜH&..;289fӵS.:! 9'jrʷlR17ze08PO?3`FEW`/o '0 tY':¬ n}BUѵ--e 5f1?(j!4kF4WYKei~\nJqũҶ<`" w&z5em2k)3dW⢇3A%[]}hG̐Q/tҔ-R ŠnqpTp"R+N cT}#M^%?y\ ]t#g6-k0w!`-OW2/z.tV N=ipoӮ[wudKE]~%$a%7 c})NA5Õg1#La>jZu;5xSoWYYtqI@zOCNHʦߗOj0 Y9,HW -M?*F9 ;E,=2 ' ?}t DJQqF6l'*X͢0~]B-TJOTN[51ıA+S^O>u3XUCkR-3QhT׶T|ZZSgfJBtH{shV8?ߖ>$@gd-x trsJжIB@TcN22Apۄ`KfC%tCB|$AKpwn9GScJ$lF107)zhD`ϝ.7qX?TRW@8NfPہT- I!)Mw&GiNj[ÇˤdG/+0MN)~*ɴI9ѕߺzRW.Qrћ챗ssp:)}Z@ ҇a>Grz U"BAşJe$EY N_E8sQ/ԖH!sPAiU[ vɨ7B|OEvfA89dU$rm9TB )9n )F)(ұ͵EEr*zDf7_~iϱ3v3qn<ÌCX~ _5Ɩ]ِ 8M#u'`C^p&: 2D)ZK!ᘮ3aע Fs('igu=>s7H6r˾P2[oX*8aFK~I33D{BG3u!}H6#wl|\L Asz܊ URm-m@'jxtFg)13#2++(&0ӾJR.͘7 {<2,w*A+R>78ͷ· ȡpO{GƑ=AoVyc\@2;|)%D|H8rKmu0 56XuA T7ܡ/j"|jTieeIw"B[*Ƕt,ʕsjR [1Jhs-oX#2B O uUdu.qA_ث+c],M.T6_[8ߔ[<˄E &weߍGH >ҟ3:{ qq&7ڌw-9\Y(laM*9AMK| E3oqco61Rq2 hTRH)J^aN 0n-&>X]hΒeortD*uT?;AʘPW0 mG#!`&=}1 <"եq΀=`(QGmfbb(ԋ2(6BR|B\jwUu2 |k .ndr<$I38ܲ54^/SFP i%Cw&NZ{_!;mǵOwbvsKPv ϖTgPGW{OTm;aGºk6ɆeX֟^\n%\ d)LF -6̐g*2iCLM_5}9r믦-86I'Mcn:ԿGν]\2q~sN3cTŊcFKi *]HV_HVvB+HeZ}|:Lԡp#l._{뀤yovS9ع DCsa("$J\5|;f:uK5vGCЬcj#XVjp70L)+֢+GVo>Gٯ[pmz#Ղ%;O0b҆ g]Ggͬ+cIa4{%0vǽ`7JYNŷHiit6: ?wZ:;Z'ı:l0 =~V%&jM՗b >CZAb1;qN}g'N?oYkj=-՜#z= װULb&9i'^##pWs,\Rk2 McJb3cƲLzDr r.w8lQ'Ju l$XHN-f-9/br~xn {8<@2?U cP7{ XZPח<2V5aL[ ̉N9q]sAE}Hz~&#Sc?(ţA@܆f=ZΙlb,wg./+{ LGl.};Nxeª {iu8$EԳϾT  (ՠھahמ:9I3Q.yuhs㊨#@Kbm A\߿ !EB. l6_!~W BjGWt=$W&R o/HOiٻ!ZB6<LX6l䆤3jw]Yrǰsj[myvF GR֠gS‚SoL ĬD$=3_gkrmL-ؗ&_0SUǴ)I3S=&ʨeFT  a\WƄH3_Φ) V?p6 ljR:^m?Tě@Jh̋1:ך?8Yâ0:Ω+STve::.p0a ц9l yt.95&FF*\(ԌTꮁ^[-:MLj$B?A:‹]W hz )XUBSc]~Sd(fx \v_T]|YV9ۈK(cX,Vkb%e*c=0&*uQ}GbUL_evndJ <ώ49V[Q$ݡġ"'PK-=e1oȴxew_5|j&p>0nt-C7u66ܕwAe;ӗ V;`vx5X;Px"L'䟷(J A,eį鰡ʬxti]n3`5lK.$?:HƤQZKmLht5MZ5V ٴqͶAEXɵ5 l5,wFrm4*nWOΜ'7S~F?zMeAg=@.-guBp_Pd#$iU|VFM/3Jd5xT0)YdfIRp췂Lxfxy@o0}1Nx.a顒'/}6)OM3گ\BM||MO оvJfaVnwOa( rG!AmT, 0cxvVrǠj`ժ-$G1nUI Gi/.۱wn)ܭa᪑%{'#jg.SbF/2YJZTRT0*QNGdƬ#. 4 V 8l+FV!{1fc(0˚fw`p {LrH33tQe/*A!M> ɸ +[R:`;"%݇d' ltA=}T'q#3`ל~"-jjUV.7%kbГ*2_{:*d pC[9zQG84'Tz\~ RL )I=ctC홹N!aո(#a6,Waɷ7*! ^|ڽ)+FR&=2GƯYÏ=tx2u{yvU u@?: |sj,e PcgP ~{9[&d1C(Q]4I+gVJ8Wӣ"l>оrw Dؕ#m^Ί# S}Rƒ<00.$|„I̻`ƃͮa0&DyއquAp$ZLJj K\U{ /DJÊC2CCGI])uvkfMC[Q !]մ攲FN4׆Yh4(k<"$Q(&JM腜jXzu`^/YgL)bu#k.<ws-hpqo\0nF.<#ցML1>>1ξk ދ6=,=5G 8OLc| ޫijHV}d6rf 8NLW-][FI3-£/6$Ы/ FIr|.LӯzUdm^yP(ʮ_Xd ϝ[fdu`wpa&{ %#or=+3?87Z>wXuS<3)NcO$'G3@ t^zɼ'l D̷xD>qF,\/lT0  oKm`89߶ b@GsBҿQmt+lL$MtHaKU ou][MMŧ?}~C6#0 KNvey3!i鵴֓~\޷0H??Isd]n,BbhDTEiIӣvD8"H>X #hfC꺶(&8de=&fZ''}j bimy's [>,T`pׅY$@[ov} Ҁ,cyBo; A./&熿g@ݤDd5B?F%ůyF_\kdZ浑Dcʔ'Ǫ]1x:S컡U(K&'rap ׇ1E8(RʩC]n'DwU uP#Ø,+ZRG%j\Mz釅6N|'6f&~Ns=:ȳ;j!ݡ}зch ӳdqI0As*L`R\ G"+! xDZ =CϺ)2bZ8aRyV@٨u@j-P⶗\᣻gI#tHo{0@Qϊ9_2'YVzS@wv txΠ꺳!FeX΀[mNB:P9z =}u(#2]q:*w`蒽qXxNXwR]`SH{ѲI2?zRH`ߎ{;)M~ x`Ȣ_Nft_b F %=:6øޱ5n#:"{aӛhR΢Yi'g%=?/8 O|>nOq.ul%HS "" !$Y|SEDl[$fNxvM8qa(OlAROfd9,G(@?97&)`u7.,8]dw5ܕQ9;q pkFAc0D֣gg讐f牑 =ÐX󫳓]٠Da/2Pj8 ook–־|?xm_8"-M<Ѱ }/ mF=Q3WMYG ꖗJ>P"|6PZ(R`{34t_ ,k 8ootRj΍:r"*1ʌiP M`;%1ͨ)~gZ51 H-G;S_&]tMu \ioagw%_?WBp2:E@ugDߘX4xDh~&A[?A{?2)Bm $X9P'Vc@CzLpD?XS+PIh5FCP;j,#EGB'òE4xז `Y\hdC- D/J6}9GBw>:WFp6|dg^5м3s* ,̲$UA]&BX7pA.z%E[  } )Fr orkE )!莱uu־ Fx˵$=fJiP5 5dYd7hlz&8yBI~@*vB786,(a5mNB߮VT]Ou"{;[{@1>< rΆ & d6HFcS oYVmW'f0ͿdNnC獡f eDG t-!{`ldXxWQu˼ 5I8l;0pCI7;hM`'ت{ēSs[$Q6Od{+HReЏ:1 y_3-WzCH5?|z8o}h4mEZ@2DV##p݈8T؊8Y5 ?!ƙT hlz-k0i /㘍fzhs;u$b[yfF"j/!@SW) ;B˰;WvR5Չ%`P h69s+s2b#ohivnZ0p( ڃ,)F揸>W cozNq湐 "qqMq"خ48k5f ۰hCp߰| ) Nqfi! ::\3R k^W+F=yQYI"c.;m,aY ?|ۓѥ8P띊xH@{cAǥ%dmYȉg 0}|4ցOS|cdHiJa3Y:[4,q;++s8M|i'4 w|9'Н hyYdrBv#A4Rխ`/ߡ ]$X~5mY>u_pq_Grr  Ϛu)~,LzT5^OPϹ*G M]XKV[w!HLaB],k`n`-Y9mp/qr\+\!:-Va<ƶc5Y[:LP'zbͷ?#llM/X[t90KXjrlnh32i5xyH ϒ3k%wu6Dg dS!W/EBB%gR2ƪyPDF #~@nB/+Ɖ/ue8աFz4p,NVZ*Jf֕cmo:^sn*"*# |[]_{8 G#)d84ִXx ƒ͜}w9Ӱ{1*li ]D&_'"ǐ?{5ZwwUL1~*\k IЫt4ȭY< @3~r7K <2;cJt :<)=zpf0my]u)%!F`OX8vntaԯ¶D߸DI' V=nZiYj}GU!{Z;eƔ+УdtT?BmQ>oo/%Yt9 >9\ˆ 26ix[ѭUw.#/j٬EWmU N"!a-|Y*t,n'p<̗qڭQ&=<18gfo=Zfh>+Pby 5>4~?K샶M=Í\tH6CC/e dKhi9$A=${j@Ox":PfDyh wݓ8Ώw@;uhe>MZX=jze |C45ǯYg!%uΣN.av`PP_e>q'~$Z*;a5%u/ mt) <+Fq(w[Ge]|kq"YhC@W:6n[`20sJdTzȿH'Pz Ity&f:l_N8(3nZm.ܲ!a3lw|l%îN}c:bi0-A gՐ_ *uЉj;ɨ1RS~,!;8Yy?ޞ\?Z;YV6%BA-6$RcYA+5^C;JT(zZ6iDh*Q#J[H.5Ph:e}Fڰg0Ae|8J,:bFĜM1_Fihj񋩎bkh$!v!Rȳ̖xKT9GyLu9Qp6D_ز6Q`"a_f萤!&O<ػZiyeJVrotu/t+;o/ɌB$Fi:'t0I8^(3{9)v{ O(h vެf3-ʼ韅] ąv1ݬOkIE3@ gM/uss)GB=UJѕ=uPmgk#qQ5#G@.^%Oة {U%xyPF^'E.ˑ JP@)@8GjQGrWfe(N?^WrIn)F SV7k4pbW< صXl6a%p!#F(g'3m+TH)B00)S'"^y~u;BM0RƈR]`rY2~7~A1| [E zP ْ6Eu;wgBg&I͊Vl~Gfa|1 I"QRR!0.]$L\ш aCoF^|;6m%Ǯ}A*vANAy$!it>_(>5hKrLn[ QoDdX-7ޢ\^GoBf7.KCЉ fnz+#4jfֲ?pM$=Sx{qf(f a-}+Go8XIsLrРJ:f>.d**zb6e7bZ?CM :R>~ݣeW,SvF.={YYNw^hY6t9RtZbER} ~H\*l9pmlM&Vu/hjo8- K7{,|ǐC>mCh-0qIVF%锜exs JݴL_HhePv@.s^^[ `W?e5@Ψ@ySo* Ԁi0I!GȻڱ'5{be|Jwݦؓ<|/Ol۵p༒L;,lXIqZGϤv~ g2~Fze/0.w~[e@ w'S9ig'XQ_hʼEB3lRQ%` ExMTW) Ot]t`j~6_Èqs`bDxEefQWRʾ.iZ5+4^/|jR]vw44/"' Y {SݿRгts?rf9wW+H*>l]shGݰJXy^!C X2q;gԵ38ܹHPʳ۹!#̰v%D ^url]9zUN5D^ 0cpN袺y14݉ɏSMEX<TگTm#?'jCp9j(c_]֚SQSl.4D=nWp)JPLG݅}2 IS̾';&AV,~:rWK{-CU>Z?l4>q |X 9!` N^ 9 s+cԿR-z֩ԕh_eXd+|6kB9 p zOA ;$s5\d_MM!7ABvv~ǃ/OhlB 5zѴ~! ̳9y 1 }BW 4СEfݛ&&[鷅H(,lu,zDܔ?~pm9 U67l>Ins@Gok)mbA7Nk8Szz,lx-ȟu:fʀWMȽ藬*GCg◳C'醙Ig,}u9k CഝvW46i6y}Dn]TIUHԔ<"HE.m=>DF Fݠw!9q/xW-?${~#tRHkU0+^[ֶLC׻mP2ؑ!l+f1r\0gw}bؕx {. X]vݝqpߙ,7wgK"0-_kl`R LgdY|:å8"z5u#Avp,eMXY%dTc JdX]rJU^)BO9fPs7"HY )t l%U V(W - (\͘0-ߘv{T,ҘCa>>sD.1q}$)#ǦB[TVNB`c]I /Vd*P2+8axZge<+f-^=5\"zf¼G4 0" Z(yybCW!@FZ=00S kɘ$6RS6 I1ރMϼ\X^#D ȥz;ߩ}B|K MdֽC2jz Uy064 ;pk1dž#7f*7yS[^: lx=}n|N;r҂֫m犫e nOעWw,ph\ Fh~DaTOp'څJS ]YlgܞFK}(K@? Zs{E Iqp S?a袻H"R;=aK mr n Rm&@S7|tɍB?~.L:m}W꓌<ޔ|u Y\񨓁BsqN|N*3\董~d dE߸*U8CRgʷֈe36zTcOF"$([Ctp˕fkGf񢝣d Jgӛ<uj#rh2AH;י|xhv 8"UM0[wLo,2q̝::v}\`Af|̉CGU%u.-1%X!ө~-*xa5Bi8- l[=!r E~ͤE{D6t$^eW0`q(SaY1 x7("𫔸~&9u-ª (w0uxU@ ŭ9V/6yrQ}Lz$LJ|f-EB\η8I=2 oIbCR37avE8_SS"zK~7M>'kb[^ƺfhi |V -SKj+@Ro"Yp,0!5X/xD/! 5IP;w;xS0Psv'zR*2CI&ᇲ귍Z  j)GmJ%_ EO;s%~oX+ ";kL}JDU畩ƩddeV6χ.Uk\Qޠy5 )#0YJ%3eR$Dron u& w{fuito}_t'J/lH~o=3l͵o,𶦸mASZ&iD,Gu ˵<>PDcU?\"a'޵¹~HB~ؐ b"maY.O $4J$3^PyJ5K|s+\DMVGWԷU^tCc;-fܧkfa$2Vvg,ahkgXԺ{1i˻@\.wMnf-Bm aVLmʤT'mP;XFw‘]\Nk2j<܇+`tg0/7i⵻7~> h =J I%{;p;BRg@qa+9/.9fɷ/?UM$sI3Kw<^EfPZ`!bb1z2)ر$x1^ZA1O0 ܔOЗv wf}?~H.z\ Qu~Vo! }A>/໠m  ,99\־l(no3ݼo#PHW(@CLiAaFإ1/Zw葺e Y̙aBZOk(=@b:)=Yp_K~$Ayp~{CJ]%M:9NG{>IJNXt\5OsYU#[kKWFbK5/Kc] wڿt}6Q$!ʦ'*"? _U Ce>9SWUy9!P%AnpAbD EgAhhQyt.%?,mՀ~ZkO A&*`"v#f7r[} ;toҤ-uԸ%RD]StZC Is9)hq.tLy.j޽cd hAo~tĬYsrof\ͥJn&F+GeOi v&v)ܯ&D.^VUԥCJшKVoyHC,QJj8u7$67XȞ˓~M΁yuܭi 6PxSYKᚪ $l.ORb|< $N9u?m߂UYNsy'n{__gTA [Dm6@CG[0($nK?Bd tzK`,df7ޔ)QU3_IkeG+c;,x"he&:xU 0][Ev]5KoÿEd}T~GZ :sv8Lc(;`̃ε`ԧCk WKYv潔 iϚǺRcYq@K  <Btc66&.ߜTd Q= f9ag~¾r֢ $^ 3N%;1We@GRl~O" Ssz)1+CAT-d$]+:UpS1}B {w]xI}Xyz^Q8λ'Yh']6Y!Lx;|Om;d1?|lRJ[;(gJ0swFiS Ԉ">thrS;Ur(kӐe!{ė2h݆7׃[cۥ|.lο+Z(ljzտ#q uɨ:`:;$ ~5cG )'i&=/"M_dF`Y`ƴ8 `$)mb2X:Rc]=NAgF1$VfOTeD~rsk-Ҭԥl#nxAea÷D![$ Wc\!gm/d1釳0a NP=V Q#'l:vl.oIg+2wUYQ?`^C:d+xF}0lGG`<=y3$Qc̄ 50 +&ƹ $XkҸTI~R7$AjGhO^)=mabT )24ol_$uܛ}ȼ-a >M0J('Yiv#C3,`T#Ie|_6<d=wPvq uc˲< "GPd=+ηy{w58 wl׻Sl3mq1Zf7U]ʭ{[ʵ;wyVjM.[܎vfdkEYA.HZzE=h J-;?.&r=- #L3Aiw"VLd";)F4l<4':$_5|ŒM숧6K|e 7&^H$2C'r5X89uݼY7𥝏5R#M#7O**A,=qf'8Y5-lTo-gpڸCZ3^эXB~Q@S,To ;p~ikslhK[C:v!bZ9PVsXYsb_ F`-+EFWRxO 'g1f1ݽd} Omk0v p,C{A左G*qyr4RԲǩ/1BMS|it+ЂI$(}.|&P{<$йpB@@yE&b0Y]EH9Gqy$⒆az,&@@ żQ4doelLRb6bco Q5r^ %a\~/&aT ~ͱɔm0>xj"G&?isOhNuDK;)8  %6õYjMo?@Xbb:ofTƥK`W3Б`[ux˿sTa1n58>#Š+H*k>өȆCSY 1~t5D:Z=}| duHf<.7|.=HJӟU~Hxi qe)jU]? {'&DlN)"lRA]V.;@t>PHQ`MFwIb+z#W[A\\:j:K#6rWD] 2H"Xӳ9u2Z+ tn2eR ;[omm=-Gc4kS\Ce80~xV H;kC+~Im]\ɖA\9)~2ޥ i> C^dv8y=vz^_3\P)m[-}ߗ40 $oAPy:u~ߜ| <]vX}e5\Kt-:UҲ(8^k n~N^aҨΨsOwX}ԇJ1uFgյ F^YSu ځA+w9 (ŀe`p`5ZT'bv^B0k_[r. =O R-{<4,.ӧL#H)nG &J2֋%3C20g*Fs9nh#~3 ~%QH]-×vj EZ=\B h^4xA~1]M)}<&O @׾/ʏ5x&C'CS}wȌ$J g}gRˇCOhOs5;Sm͔85[%jvWU-'MV)6]ZM÷9F)KFJ{;N:Y 堟vٙnI㮤B=[˛S[TΩ yU ɽ,ᮻ''4oXfL֨eMUt) -EɒG\(X?`p`kr Du1|ҠH1s7+!,wYmp6f]+^ZQ\`s&d0RIֽRq34E dg(V?Z)'wmhm)e(}dr,S69Zn6_"&Z׃fll87N%3vcdׅNGq"2Ü *ӪnrZ('ឥ2vĆwxV2 &f)]T8^KH̋:CNId&D ВҊ^1A$GerQهrQ{.JDխ|Y,JgR3 =5 30D+]pm8eKGsX;JݯNL٢ϻKYXu\PEEX]JteZG ѫ< E𦹓72Fkdd3h>Ӕ aWޫAp+TuN* z>G`ť؇m93n8pdv_JG̗*# Mh8M{ZV?4qb辣jSLD讣$IP#i}m v_l ˭N[!zՀ[p)^W'AfmE۬}kVZd̀Џf%nX䃢dZG!vi_z4;JAOk5sƟ.t/iDg~< >\l=UfX Zog[T'O+du{e7gy(gkZA&zGTI1mg8kZ#X r׃>1TE+wئ E7M3> e;@WfAH$"h^Ggs3YɏGwwk#tm2&+B)ER_ßj!֐07db%o5X|m} ܫb[GH=iMt倳H]|•Vj2$!C+{GEƇQJޞomܵ=7HMs< ϲ<=ڍd:/8if!Sxhc?MIOJ3Wi2 Qv"-3PLo # jiSơZ3.vxFN_d9鼮|Y,Jz~G _ݠ"碛6"X7> bSuh맋Qr)Sy\WшdE,7o0 bubF.ă*ݙo'cW?)f'%r _{S}>ɭv"*a;7֢PT՟ð"J{4m19f0cZ$:(y{ጒue*>sr:M6'!7PнHѨ7Jox_H}1wY⢲,HrF'ZVC O*Gqց,ؗtuivNZMb>+Ol XSv]e< 3&80 26I;SRIr>a7t9e4dXQ0z;,Zl^e i.N3mbn"\%!\Piv$Ezj4O[x*5zg+d 8I!~rgXyIjged} ̜$6gFRj- ף۠of1Q0Y|о|H)\؋8bU2{H fS$fyY7{ [[KxǸܕD'>G,w'J`* ~|̅@H㡝/;ҋ{]*K=p۠ $MxAkbJy0uL;49Oq/QZy nHM?uGq&Ft;q7g; rңB71@Yyip/bLzX|" yU}BV} e. !m˻{$gAX]ɝeoLV&`QG3LJ]p^tm=?QE ?#MCzgR隽Gm})ūDMi<[>8]|'ljEzU.W7QI|weyD:㪈T|/Q%y9pu- 2aSV_;3%E}TY [8z/ vbɮ $w<^Ge6` 4e`8z] #<^P+ʏjJXBԍJs۴@=(ռuC3dϿ#6Jq\eU sco殹IEy@Ceڃ\2ݖ k '}ӓ.}KGx`1][fq)Y^XQC]e!'uJ+`d`Q:ҖSݒ`szݜ@rYSkmۊ8z+X!Yo$!'Y'B"42;8_iZ. %|/qL-E}{[/Goi :cy4Qb-hl $e%.o. H0gR=K.cK28/PU :& ${D߇\5Hs,5YUy__+o-^QLWq4pD#\*nUff.6VßVL4 =C~mq1΅" 'Cл לj7rv s'EZn 4q7[Lcrlva\8a#A0\FfDNe)mտQ)e@oP"ujGn9w1Ni*e(@C+ ӸA6PRlJ~ An6:,cølKqN$ch{N Wf(!$ng\ڠݬEn\@0RO*pd 6myî-㷊f!,WIg^i#3fͬ?[D˶gŏ7I<@0J.mų0$R9_&x]4{Z- C[puFIni*ΉlvGoi lOV&5:jemM4bYL%lO5BM$O~ÏY&iZ^Гʶxc }*#q-! ?yvjc2o+/9J6g.o oV_႞Y]g|5c5Χ}ˏt~NbܨBķYWJS ӾN_R1k]baQ@_ǫѨsL&uFJ]tn%n 'Q*`ʿ·q cM$t~Vohanemp`CRT AZ&X?p$$*r6\>9o8{SaAsTKØjUn:sKjq2ft'[ޗ\7{׮!_LʅqOmF{8n'ؼNU]Ya)"rɻ d`BctoX`9Q U;PoSH.gDA>]>x~bR&N.23/tȨQ΋:;@p:qvxx([ݣHGP5]pHΫ$=FT JkN8q_3p*I6YgqGՔZtwgs(*'/BړIP9qbm'}(p+)2PZ@\HPfPPٕf:aX EdC2S B~r,sJ!78q Zq8ʶҭ aɵ?,!,#/^" W 8OT)xִ#_%A}Ys4eqvbxA4ҳ(`sQF*̻5-( {EYT*Ǹ%Ur cAI/)N'phsdqyS,<\m Ҽ5xWf39PCP8A/1x.+2Jc?4qbp[%iSgKR@ҥIʫn8`9%mE=MQ]Lɛxj Ds!}_+9K6ȗ*8t3"P]mCE(DHn IѺ]oԃyFÚBS 9|[&,ˌԉo݆3H UjL5>t>eo"BSj䖏~1 =tlh;XϰzzE7SĽX;K٩fc9,PR^͚h1# zYAUzP ,Mfp1upR}Zy3:C0DKy٪vT+g `NSY︨ߍP.!mt*k+x  h^41K86iU[x[#2s4ڞ [ ^O9L~fÄm jjQ:1^JݑO*ܐ(}"l#Յ,#$ CWkŶk1AZ~.p˗SQ4*@-qV&Z9M/1 Is\GԴ_͚G?:#YD~9 ;SÂo'liMa('$" Rv8fp>wgGaкjU}ܔ7}{]*H$ϗ|萎n"OߧdU\$S[=!S(2D%!b@=pm죽p}7CNNepװ2Bi`n ̸zȍUZb.4\Ԁ71,^$e!H[b9Pk; {#ІDFL <BS>hWⰁQoy H?۾#`ͻUD"r|ۃȓtW 2򴒆^N@XA) m,T<&2n)յnر?k*X0t ~{!ɲGҲjT%O9.lӓ'kX̉N'l3?Ă-J9o$=whNjh. 0ݶ-,>|D\gc[`rR\'[+^90ȸ̀{>rh(d|LwKwGm4O,Zr# 0zsG^R² -{ $;P)1!Vf˅/ĖueF,Uod4e`FA``EqZԙ ~r9JJҀʥ U1%gjFc=Tbn 5?T=U9K{V=8p_zmcֳ0J08J:0$ ! "y-Jc4⤥Nzu]dB}^ VjT%'T̔r%0R~bQʃi *鴮gD_q)+ݻUx&'ÑLG]f>뙑nX2\HQ7jȤSyU2; <߆F{z?dR5NF| 鈄5.'}'4Ɣ܆D52#ag4Dꧥ{Ib燲6س3^"Byׁ ZIzؕST[臹Ε@_ 3y+k.LXG}+(G8'Hzش_= {PGBѱ%x,S{dGN,a!j!u6qs; 0U۵7;s{.t$#F3&]p,g1@ز!MdF_f y΂ȒX&6gɘEKp ;!bHUŧ3`lKG/L~dZE*i^*G 05VRHjSSߖ_d }zӪ'}\#Y|wKEp*2a̳ *07H_Kujws,0I 2߾36lS" =tRzkä8 .¬fx=$"fM{b l¾e%/jR5< CJ5R#ӹGكxQhE75Q¹=V$ޛ~T:m]g$xSQSZp^-"E(峓lZ$Ix1UL:gh4 XᷱyUޔ7rQ,W1<Qv(e9ɵdN* 8~ɱN2f; x dRkcPÌ|VZUfej.e(U>セr ;PYxG5'OӶGAO֛L;V{c~ktA埁+[lxDƙPQ*GY'!JMI@mP%D)> 0:oPkQE[_U"{I ~434+D(s|MxX#>sGrEčFCwio.sMXVJ]< ѣF/x ߙdk@)w5SAo! =F4d̟"}qlWii9Et͗E 1_e%7#!3b޴ u>Gb)jtg\ }4k "fy҇U PQUbZzKsO!~x{]' sY =鎺PGpJ}P==9\o=EHU.VHYb"odWU2Vo$, LOn bǷ C2?EABߪC`|V}uއ\fPE(/ڛ m=:n"%%`;5-q,LX~^]zZsD9!:՟FDw\![կ.J Ɩ Ƨu :H!v[Vy$*'źY*?P cE6$ڱN [}mBw |&*Ω*YJb*Qˮ'wmX;Auǧ1~Z6 ^b['?SgEWǣ =h14d̘5r;:?zL:A,S-/T: 2-@B"ʶՕ[B$_);^LQ4HB}?-e762o/ @.XN[8V(C.*| Qsd6XV PU0Zh'*ҮOC neC:LMtDkGυe1b`;Z]xevDKE7/vFiIC7w,/o^>9tVf HМ’k2N/?ylQŽY96XrU ԋo?/-fL=H+y坢]gSG=OW7Q&P(H*Ӄἃk1 %8[lj^Ύ4#v9at߆,UJP66W< ӠDZȣuMuIv9u,x<2ʬGFuɳgxOh@T_xAa(<"\fg%1 d ɴ&dږa]AԲ<-Jf AxzSfl TE\bTc%tWsu\Փoj#8~E)bjzj}it%|CFnH%3C~(㠝=Jtd'% e;Ly6 i>HIB^Li%Bٿ8"&6&+o% 8^$q>V3m+YL;jD0}*5Xo|.p'Gب>ScgvXİd7'i.` ~ZZhmR_o NĈ!rM$T,ܡ.U% 3>cåP&Dq'3FFE>h;JӈP>\E2Uy-k 5o/%(ھRnp j {fhcCޱhxavf^iw* &KT9=chY/-ـX5/7schPcRO+XDM "5F N4`WնWO𪧉Z0D {M.NYVhoo+Чn_ ufnl, Cn))8`˘bĮ6aw3DeYҤԦ].@ƸFqL Ɛ&֒+q d=@LgX9efI~+ڪic0E;0;Oxj:7Ȍ_1W^+},E2gGj[lbϖ,%<%FNuUqc@-j20 'U&I阍憣.fC)j?wo |z -/%Ȝ9f.]uh;VAfڈV#AWobzJl;.aWh57`m+cjB&(Ggc^Gm"H{VIF(߇}e|u}w+f&̑vʹˤVVj=nL Ns'MTa/_x,cLe:}n%^Pϟ+%ZTv @'SN4ăm<2!Qݬy~;n~%AIf|>u҇ j7h:j>ŕ >;mH3 BV;wa̽4+=G܌Vd铚6Dk6&2e?kp[T EFS6FB8N߮`,l_5#;M TWzseTU1m UbӂLml^@Y?QfD#MBL?dK£QGLNy+߆|u]%p[>,ɝZޒ;9/J ,8xTD3zh0IҝJSIrY^S`;/W,v!t%@.]_0#kyƖ"+0#?Ǣ#|Zc#-tDiAFv([ 0-uY dUW\ֆwhJq\,K2EPJVIc~sm/qøߓ\Cs?bUd+Ф':hCњ y r?"d@ЅZ2$PU@-A$3T8 m%`Hk%zd7@=?ʛ)v\5"~[Uдcx9(ר)#Ayڠ"-XK T KD/U%tk>=pXCv Hעl^A"YjP.cK2gA_ ږB"~:1 +yb믹JC,9x^3TYLl r}lإa3[ݧemYf9\*UcO R8Ϯ2 !dHG-G{lh|/LKE$00aev QbCFBNqlzR΍ɯqP \"K%p_\~usKtZ/ Vfgap$ycG15RR|3lE_Vhpi4&-53XuP7n+Os_R ?*yJ ƦhiP:$/s "n+# 3~65Byi=G#&@x,0φpUl3DL&}h 'eO)1CK Ea*@~#-Z'`@j+F+7u.MiT=CrۥPSM$z<CJDȭʗ5C]u5cb|{ 䟿m^QMl^G%$s2p7 i"U,Q5hO>k%4SxT|[{i>-aDWXbWʫr%0p8Vؗ$u*jS5A^}c?|qA=n".x:g, ]A'18J _@ֻO%DlwMw(,XnjFwQ˚":¥g}lw2 q0#9YUY+TqxU + lD%Q BńdYd\g*=W˻; bonz=o}d|G*9<~$?" T~Cl6:ĵfK R]18c<-j'? C=m$ʇ/Gofԧ!j9ZHJŻ',&ta&l:e)2e )7Mz|F>h߻҉j*;'Ė `8>utskd3ӹ07 vC͎a`V8Yn@c~Z> 赵NE@ Vzw?o,QG&$tXPS=ڒq:|BZo!Ki8?a^'{_E ऊ5**їo ʧMi" b'%Mmʇ ٵVXp%$<wftfr*CGdTx_C/w:qǿ1g֔-F< e[nbhf6qH)Z}=xnGڏ 2jwn|3⼾To6zAݘBhV t,HSt'ec ^ʹ`< :Rd s3 pJwT]gxtncG48[Wq,y?!ˋ_ ǁTpS|]⺇tTDib99a.G}j YH\9l)/lnf&]!>`]RVhxlܺl>#* c3i$kȻۚvj=+@Yz̒{/z-4;$O}feF;$GlնZfWwKV o%ȷ aw=edm/04.-T5?6*q1}i:0NZ..2O@-"J>Qlƿ4i/bۃ<袴a73ڋ4FT1nih@g;~\+t Fq ' bSE0Onڽ,ERIC6:ɓku;} 6[CoKeMQ/ϓRH8_W^zZgw_{/X~)9̹Q|` H/z 46dj!(>CX.Z:ZDZc0'ekڸH臚T=է4awɚ( %$j8Dt0Ծ K!o=xwҴ,."?ҢB>eK7u\sw}3l^I׋x ٥Fl렦 Z g؏8R[6{8ph1AMDrF.>4ؚvT$.ҿU|/3,l"sd8Y2:u/{|{Vm@cƉpX])д uMY.󢥕jI9b4H]2_ɟP`sIBцM8̂}z SX(tfz{ o c3z Fd k<Βm63SPtjSW(3N[NsyŦ)N? `Jwߥ4{|vw(QYn:[D X"{A']4XX-Z8ˆ;$VKܗ0qU~nC=n*FhBip2L򧶷I+sɘ $}wfb9 `>71LG9m/>0xAaGKC >,uԫLPZ{V N3Աа>w҂ Hl%6z$jG:{#^BӲq<Ό¿RdͩEJRBb0&GLRWD IX$/0"3[J/&3s [y%_p>BVE1Ys>'fUG`AHgm4W_Hm0#s\%y΄FW_< 4P'_bDسmidO?zE-'q@A`9azhI<2k)m@TPrU{> vMufȀ(b+suLWsd8" qeSo=>%VՙG|u04O`r̥k[慅E$GE{ 0KccTHEr1o_ߜqslPJftK@~"mShBOBs÷k!Qcٷ2ـez)D7J1ae|`uq$uH= DRFFR/Xp?!$IW@Kȟ<8[pjez:Ȃm1f"^CN%l4|bݴC0eEP%[^]lk'&$,wdKZdBJ~__^g~Ky|à`"BDP>WSx8R;;-B?i*K^-(*Ďj}~)tB{~a&ÔLO|Kq&={5@) z;peɳ0L5F=?B+ "cߒkL1(&\$KKN:#2B_YrS_zrhe`37` F [9rLed ,zP!s#tx懍: XQǖ: PfA0ū!,hԷ2:L*/ s=u+7 TĮ$ݨ%6 2AhXa>ϟk["VEwV⟾ӐA__L 'eduh .G "{yTKA;qע9?^(2t^pui&wsF@d.mtt !Q;ni#51'\HZ̾G8l֨ցL~1/t]~9g@:S.k<&}/WS;LCiDPMP'ƔSa[쀵$>^y{\D__5T)_hXYkP?/nDXSpi2AƴܑW<^M75?Yl! r݋\NGPnflhԞKoWY뱲q?V!+4S-$A^v=fD8vޥ9GT]lq%'MLEͼԾ]ڒưG>͓WN!0ktyZ0X%>˧Y)z5MQ;eR3 TK7T% 6j$,RLM$隮ѡQ~15n [d/oGEN-3SVvnqP!;mn%C[l]ZtԈl.aFEt>KHcһ1$Q ~&t=ZC淽U[5*\O*|$sUoشmZuh@H8\V@6f J@>'9 kB4Km$P3&neȕ)ad#iGZiEֆ<ډټ]〉wXyȺf҅$P-I^#h͸ ȄQ{ ,a@/ߕZ8LHW;Z>?~ӣ8<pDN5h+(L7V Ut4=Y_,$#ht.)}74Gw}zSɾ^O$zl/K3{۹598I^PvWboG{GR`> qȖrM拑P1Obܗoܗ 7YpvxGx" [ 3Ѯ*ڸ@lp> 1|O& ^L l(J9M"t,I]DkՂeL!8Ԕ9 vgU(wmc2fN& 9PJ O,xC;ݵcDPf3M{XH쇛[$[$2t ˆ|hL$:c o{w[\io C#OP&mcl~Fzri k!aJ0Q=LQlCn݇8RLJJ9!bPj6Na}av Mߑ&:ĦWt|m6u8 K~0&a6"?Vw[&ؖd8NUK3?#gq\zuK"j3mVafX @Q@v%gh/~gWӠho\># Ky}my|Wb5[Ldٚ+Q_X:%u-x`nw[u&.<"6Rd?xI`r tcW*qUX-"4ݕ7p61`J(WɮO\Ĵr 4"uYxs)o9ػg^cB(c h_z]ӸٱcLV=BIpŽNlri%g;:/7CdoBp ci8X";t'\NF4D4;(H+yuA`~X~&H ~+}g-Y2'k6,T@U5' pPY&K8X׏JV,7Z2{41ޕQl{`e&L 3tV-700D[7_NUO0ƍj9=F~j+ S Oh .8ߩyTiR.T+ķO7+K~$_zY}կL}|O+Nx*VYu4K+xjŋVH7'BHT:|%ӄV_j?ŖFI|غ0/B8v@2t쌁 \"Ǚ^k6JD>ʱ^ \zգkJ[$dau~<&ԠT43ITĴM9Q/&.nvv,ϙY,F?2hYYd:VnzSҠKcVeBҖ|H7 PERkej7JG͛w;w, CgxzRBDW 3 5:gde"aL\j'/gEů*qoҨԟW9 g٫aeKU*nG7/ rԊۚ w|#`}>ve}xG_yh"&Fw+|v(g;N©mDt-p5kQdk% >A ႏS O9@ 9̠D:CLye:Z%ZBc@ B$.n+"+ob>4n{`$KȆ%PFG;7GZ>6z]L`ڇ8#nIa Z$ ]p[ ӁW{d0:aR\(t{Hf}Ά\:x?m۰"MdvL gF:FÝ:Gn{&M 8`̿{嶶p/`(k)McqY!mqOPz'|S*VEۍG|99ÅO-DԺ淀%hZvOwl`]&PutiwBxe&= ⽉rO=1T5zSa#=p2ݓ[6Y4;M/%)|7I;t,Sqy{`f5Q@jm#sHfᬈIQwHw;IWSs ďN˿'Xb O}l:XEF(ZB\_#,:GzrL yrz*OTN