sssd-client-debuginfo-2.9.4-5.el8_10.1 > 6 6_6 3!pQp)Tξ7]mtZ`ga ]mtZ`PhAˍjie `jqEC ~R|-8* 3딠iG5%nzϫi%w?N0~$@o0WS2 MIƁN`4VU:B!$)B SXy`kݛ$򇲔b Ct*;L;b]s!{Ɛ it2$szAΕ - s8LH?)>Yٕ_hx t>LP1F+~ 1nTx|e=]Ji 83T/iC|]=Rٛ̍\`||"h}f yO}UP?;2ֹ7θX%W ~0p <WOVGGCCPKt;> Hd*|SB}|r)wGl^KwI8 c99_&X1W0e758ddac3492c3c392fe646595ef0b0b47fd94b77070cd9d94eb5cbbf159ca85027e1c0d266d7c4459c291ed7c59c6685bb6ff2k3!pQp)Tξ7]mtZ`ga ]mtZ`Sp}'wهYЫoЖl߾Ԋ njԽAlBHv6GK>KteL6Px%j#OvCM D1VG]BIfA-Ŝh>Yӎr^sٯWWe:DEGBaxPC#6U 5PTȪs?pyOr`AHz:gIWIp2vޙVjeَezL/N*xVHq=0ch?W\4RIH?&3kcB\C WhU7XL4}& U 6ix$kQW^or yC|7 H>p>? ' Q8<AGO m*P* * * * *  * l* >*  0* :(g8p9P:j~G*Hh*I*X< Yd \*]x*^bedeflt*u*vP w*x<*y!48>sssd-client-debuginfo2.9.45.el8_10.1Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.gaeord1-prod-x86build002.svc.aws.rockylinux.org 'dKojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<P<k<P<]<i<q<X<T_G0, PAAAAAAAAAAA큤AAA큤A큤A큤AA큤ga[ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga_ga/ga0ga0ga0ga/ga/ga0ga0ga0ga0ga0ga0ga0ga0ga0ga0ga0ga016765b43b89c3a375b1c6c66c27ffd786182f640abd32260cec3a3218efdb106387d0c70770159a7958b1c9506c23e8471917f5c725f1eb657534113db317e7739b1cc35bab05653df507a0aafaa2dd3b8cb4221e9a5385f18dae0947d02865565b91389d63af8f212c1e6868a1b2c801bfbfbb4b38a10cc571b1e2affa2ee04e6e36deb659de723e9932efcc3d2f3a4469f165045c4ae41110fb1c0b997d88f8b2815b642a0df4ecfaf3d777a4da51ad412aa6b60141574c255bbdf1e625141b725a3f74241819d39e73d6b435e4bea26e795837b7b58fe95cf79da6afd478cd4d449a21989ec889e67ebd72e29b28ed184633463e443cc6f672c4ccb9e67c8../../../.build-id/1b/b3cd312c98158488780a2ae75da8d16d4ff8ad../../../../../usr/lib/debug/usr/lib/libnss_sss.so.2-2.9.4-5.el8_10.1.i386.debug../../../.build-id/1c/6856e0b5f629b4a67570bf825d398c063cebea../../../../../usr/lib/debug/usr/lib/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/3c/c531eed5c65b4c33db07ea504c27af57b07e4b../../../../../usr/lib/debug/usr/lib/libsubid_sss.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/6f/599d3df57293a00b451e76613d7c54f9c590ee../../../../../usr/lib/debug/usr/lib/cifs-utils/cifs_idmap_sss.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/b1/f7b13412518a3c7539d8bab2b5088041fcb11e../../../../../usr/lib/debug/usr/lib/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/d2/3c210547d406b644cc35d38404b2b43b1eaf19../../../../../usr/lib/debug/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/e0/542eca4e595ecc8ec2aa05efc0c156cd552362../../../../../usr/lib/debug/usr/lib/security/pam_sss_gss.so-2.9.4-5.el8_10.1.i386.debug../../../.build-id/f6/38f1887c303f7ce505d688bd6cd6a26796d002../../../../../usr/lib/debug/usr/lib/security/pam_sss.so-2.9.4-5.el8_10.1.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-5.el8_10.1.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-5.el8_10.14.14.3g@r@f@fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-5.1Anuar Beisembayev - 2.9.4-5Arun Bansal - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-67671 - Label DP_OPT_DYNDNS_REFRESH_OFFSET has no corresponding option [rhel-8.10.z] - Resolves: RHEL-68507 - sssd backend process segfaults when krb5.conf is invalid [rhel-8.10.z] - Resolves: RHEL-66267 - SSSD needs an option to indicate if the LDAP server can run the exop with an anonymous bind or not [rhel-8.10.z] - Resolves: RHEL-67128 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest [rhel-8.10.z] - Resolves: RHEL-66272 - sssd is skipping GPO evaluation with auto_private_groups [rhel-8.10.z] - Resolves: RHEL-66277 - possible regression of rhbz#2196521 [rhel-8.10.z]- Resolves: RHEL-39085 - [RfE] SSSD Failover Enhancements- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*1bb3cd312c98158488780a2ae75da8d16d4ff8ad1c6856e0b5f629b4a67570bf825d398c063cebea3cc531eed5c65b4c33db07ea504c27af57b07e4b6f599d3df57293a00b451e76613d7c54f9c590eeb1f7b13412518a3c7539d8bab2b5088041fcb11ed23c210547d406b644cc35d38404b2b43b1eaf19e0542eca4e595ecc8ec2aa05efc0c156cd552362f638f1887c303f7ce505d688bd6cd6a26796d0022.9.4-5.el8_10.12.9.4-5.el8_10.1     debug.build-id1bb3cd312c98158488780a2ae75da8d16d4ff8adb3cd312c98158488780a2ae75da8d16d4ff8ad.debug1c6856e0b5f629b4a67570bf825d398c063cebea6856e0b5f629b4a67570bf825d398c063cebea.debugc531eed5c65b4c33db07ea504c27af57b07e4bc531eed5c65b4c33db07ea504c27af57b07e4b.debug599d3df57293a00b451e76613d7c54f9c590ee599d3df57293a00b451e76613d7c54f9c590ee.debugb1f7b13412518a3c7539d8bab2b5088041fcb11ef7b13412518a3c7539d8bab2b5088041fcb11e.debugd23c210547d406b644cc35d38404b2b43b1eaf193c210547d406b644cc35d38404b2b43b1eaf19.debuge0542eca4e595ecc8ec2aa05efc0c156cd552362542eca4e595ecc8ec2aa05efc0c156cd552362.debugf638f1887c303f7ce505d688bd6cd6a26796d00238f1887c303f7ce505d688bd6cd6a26796d002.debugusrlibcifs-utilscifs_idmap_sss.so-2.9.4-5.el8_10.1.i386.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-5.el8_10.1.i386.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-5.el8_10.1.i386.debuglibnss_sss.so.2-2.9.4-5.el8_10.1.i386.debuglibsubid_sss.so-2.9.4-5.el8_10.1.i386.debugsecuritypam_sss.so-2.9.4-5.el8_10.1.i386.debugpam_sss_gss.so-2.9.4-5.el8_10.1.i386.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-5.el8_10.1.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/1b//usr/lib/debug/.build-id/1c//usr/lib/debug/.build-id/3c//usr/lib/debug/.build-id/6f//usr/lib/debug/.build-id/b1//usr/lib/debug/.build-id/d2//usr/lib/debug/.build-id/e0//usr/lib/debug/.build-id/f6//usr/lib/debug/usr//usr/lib/debug/usr/lib//usr/lib/debug/usr/lib/cifs-utils//usr/lib/debug/usr/lib/krb5//usr/lib/debug/usr/lib/krb5/plugins//usr/lib/debug/usr/lib/krb5/plugins/authdata//usr/lib/debug/usr/lib/krb5/plugins/libkrb5//usr/lib/debug/usr/lib/security//usr/lib/debug/usr/lib/sssd//usr/lib/debug/usr/lib/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnu directoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=6f599d3df57293a00b451e76613d7c54f9c590ee, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=b1f7b13412518a3c7539d8bab2b5088041fcb11e, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=d23c210547d406b644cc35d38404b2b43b1eaf19, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1bb3cd312c98158488780a2ae75da8d16d4ff8ad, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3cc531eed5c65b4c33db07ea504c27af57b07e4b, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=f638f1887c303f7ce505d688bd6cd6a26796d002, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=e0542eca4e595ecc8ec2aa05efc0c156cd552362, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1c6856e0b5f629b4a67570bf825d398c063cebea, with debug_info, not strippedPPPPPPPPsssd-debugsource(x86-32)2.9.4-5.el8_10.1utf-83fffe71d75d693057f297c8ebb2b1554c2a74bb38da56eb8e35ee9b21e86eb22? 7zXZ !#,K] b2u jӫ`(y1pyI1[ 5X{tt>G!w6Ж0t]Y([9{i7CchS 'Ť&#IuJ |O ls|AdiRfD=\ErU EޕWoר =1XD.j0n׼(=@7vX4SÛq)h|l䟚3QicΊ ]_ұ5_5G8Ѫ0TfmК]APu&S(hWA'y7R(u#ވ 1l{iِ3IZ uU.ZfT/ e:eL]d)LlUm{o f5@eR|AXZ@ף~ZQbɖ߫A6ABPryuXAEهPDt28@ $ <kLA^GΗ5`-kb>+bMSWr(8^& qz҈_5b`v%@*i-}IrX\D!'^6Ej :yՍ Q/E gݠ?af[V[K>UEL,{`o6ɯ8ig&[iWxGhr:! YJu$ fZ ğ@pYڦ~!&H^OuhFXj1ij>gFX`vI/=R?D5탅lSf=..Kkr/y^\u8V4螥<1oGtuaca)fU@*`-GLH͜WqeGb}Uө֥ /{sv5N}%w:Ob'b EJxOֈKKȁNv$kw/@_#9pՂ }F 3 3T{0 S3(4=v\g4d<3Evġ _3jۄ=F&4:)Ͼ3=(U-gSm}oh}lsJcz/IfJ\O*cw:2n9:,[x񍷎1rE$=5&S){ꛗu[*P]ΚS.Վ,,ch5éH1?1qG0wiC"ď,˘P>ڀud|p`$7{тym8:!,3:s2fT8f!3K"NJtڐY@i41_7KA+_} o_Bɠo홂l"=Uw鸀f10u: 6Yzolk;$mo Iǐf YB&#_LI(K,.Ʃ}gdR3tvP%uN}fcKmշkoy#k@.RyPy#ϯSЋd՛'f)F"ƍ6xE礀VNכr.!!2i\* Nbj,?e"?'f۽. ,N<0'VjaH%˳k$atkۃb;"K\V@SFr--\F(0UrSDA2ݵV!>/mqr,!1ɧ6KPTyu+pMgQ&JRNl&MB@m^wTMfDRfTU\UUE¤@˛Dfq8`7ʘL ҲՐsГp$ #=a׿rWxaf޻1䯑?wǃ*Pss 2 oc+nƳŃvOugL?Cɗt:K&|$,K};EeGg "N!s^}$|5x,G㎜դK-k_ߦ P$՟A).a`g/"j쭤.%>'~Z8Ҡ$$NJw[V0M0p0't0E| ʅ`q\,#NaXx駜,;zPŵ$=q^-{ Q2厸4>)¹sS`O+xMD%T r,A{)BJ<ՄX% 1 t,x?͉NBh2'D͈C"2dP">gR6|y4<`;\u]v? d6eю}ť%0fO3`f(#CtD9ALTOCѓF.n>M mAdϠٚ7cfD7W|P`v~)7!+P֕~rciHy]BZl*n]VbڕM̕wڱoHr*%>=@45nB1#-a۴l<܍7-GFs- eo&K$ }8O+܆EU?l\etb>>E+o̗Dr(1$r8ZN9 2զ5!nc.adpT-Dr;$V0h-R uѫp^=죿aom}ZJ~OKh^J=ίy xjE:Ϡ!|nv3Xg%8ZU7u!B*`#3;3vݢPڄMy4p UY /|n|7# IJBEXؽIxrO=ezMm)~-%CE)HEJ|/){u0;P(6 hs[RɿKj(hawsק(r w.ćxqtr7EC')'f椧+zGrVs ^%j&A) "3QwZ|BBF` =/1"Sⅸ!5ErJa+Ssc勘tc "x?w:RqR0F*Ya~#}1mELC1DAlXc-dؾ2 DlXcW8ww4{+8ከFHtx{Ii?θ"VgP$Q9W&֩$t76idrO?f_̕Rg6SX~8bh*@\Ai쩊|kpƈ lW#瓥а+c%eWm%fIƽ_V8Kf<9¼Ўb&0t#r{* p,mZ.~ńH]ݮQW' !Z,M⧻cG,k\>F={n(VqfH *EgqZ\dPMa貭DȰNh~kJ6ObCq]XY(m cB\gU̍g9؂l(kWg嗤Ify]GlXl24/wi:/泌DV,y *U_+^bS x乀1<'~v hpx ⵊ#Y-ʈ'a#BT'@]QYjԍRv2`y(3t~V7E d]MWW`3OjQ#"~`Z;&qѕ2S%=u%G3ݘ+Lj"q" GTT $AHCg:y CBA xV7"}CM=U Hr(p޵wu)Ă)b^9LTA |XV1Ԣ2: Q+!kE"z]EJiA$P„F_>/rJBneL6RZJ&iϷT[b?©fHqPn9|3[Nu3 ur-N Q$|CO)fP֐#,~~!BjnߩcLmX,h.ˊnȣ =g~Q㟜RMMpOɈŧSALA+ZEz![荙ڢ6B![0]g#J :c> $.4t49n98A/9i,V4e<~jT"`kg2m/_M ;b҆59mj: 01tMPcSx # 6dj2M Nr-rKI3.(a1F׏ P&qVtڔpGGb*q-,BV xĤ~Bs8<c@ꊖiNOAСt<иYF Q1+SK3|8iSjԋ|DU|ᮙAT:ͅEURbnn $I9 4ٹ RޠڿނʬVA˾4ȇߠjl=$4TdRA՘]~)gSͫe5aśd 7$7\hHp}l蝴Ƙusy\|)@=&o%~ 6<.H&K:KXNsAV mMfnZuI/+rGVl8xhƵA⿎EmIB{,@1l-OSyڢA">6#b?#T]AOz,Hcy-4w'$ę `IWWDr0§ _tw]Y>L ̩k?, ^$ BviӼ(EPeiG.[&vTcwad,&8ުVK=Ni3)i3Ag9UJ8bs6$hJE홻fߑ6ineX8 bͩJmBQ$F->|y`#JQ`E8_lz}sOΥ\r>{~t.d1tb#3 &=l&@gnVHzSz =a>".kot)٩wʩ Ͽlm)΀?})Yd' k ᖝc> Mhp"zo~oUAWaEU|b0"yPH'K1NaMM0_Q@_ '\ ֮u*f>`7#Lΰx$-:"dDcltWXFOh= ʘ ж`FUԄތX:Bx'Ns|$ S㱙CȼUz?\vQx1IZ BiٵT}w /*H$س܀'P9}LhE<5WlPp*!-܏R7nݯBTJn~2<<8)r@ML^+Q/Q09_.P9ayϝn&޴?mt|Tv9t0oRC-3秭j$rm lVt;SEBx?<* GSV >ZM RMZ9Z˔}Y p,[3 vIVN+bW`{<R fj+"3^2ZTcX{ykDw 3Ρ)_{sNѫalv[W_]5`ʿ0ހ9ʼnez8/N#>7<̟`>j e櫧D bC4`Oo+ 'libX,^h}O"ӗ1Pk j7>JnNSLĪun kvae4uQhi8_2V&{sLSc N٠n?F@E-tnmmp Rʉ~)7_ I2͝G5rS$mr{ `-#O5KPWoh%j(u[Owt*Ço&26}"-+ ǯZ&Dyʨ_ǭ O.ZzweQG䮁p``r3B&d&6Lp*ϋK"{`k$~41Kd8ϕ2c. #vYBL,~9+mEfF@/$x; 2=HyyvV2._!4޷p{9Ttm;:žʹӕ, ,6;=5dê&%T|}w\`m9UhUЭb4P)Jx;ۖM<;" /_v 4VfYJ}jJ|ʼnre9k_JJ-I _ ա&{/BA~}ٟLlG0+X>tr`M uQGfwϽ.A'9-r?64;[J?E)?JM#e=G-v#'wTjUw?Na+)-JHh4> w ,k}8`98LqXB34mRf4wSuƽg=OiN/IEit=)8BaR-c;cٙJ-|{:ml3J%iL5^o%,Kxt\7A؜ʖ0,懔 =ӓ>]Tv ^siT|R$2|9ueBthofCvSHXj[u5=11q;2\>8W'v S٘[. 7 _.[Ҧ. &1늺!}`Uy#^g6(ogA T>ek-IIf+%(Bʵn,0tb9ɣ,?OJə\M̹Y*1:}R^MayҚ@a!5J:d]{5B:`hj.|ѰN̻(ONbma[G0]YRw2hNz6oQ|?Q v`չnzL"wШإXq7QgK&}JQF<̑gYS1}v]}ȶctQj{aPV t0wG(擣U@,.jz-d3;hAPU!C?Rcs~&f8/Eq8R;Α5`i&No1Xk/FHS6fwVf/蝓z 2Y"չ?2-,IeP)5Ӣqܜ`uZ lVtznM0v6ac ̑}nb~,ݍi)*x9 <:wv? AqR)A ;6B Wq S_o<ӗĄ-% fz7i#5zQ Fjp+[bA{jkܴCA0)_bF3LD΋6mH3e\K s lkdRM $YH`/Ô2 `ݶy {PDCˆ V%ًhF06 %?WSL ]TvkL,2A蝻TbGsasmbwH%z%&׫w)H# A{@h~"<"WM!8̸&U{ W>+5R"ڝ=49k/Bٸ?ZRP0R~Va}{K phqkPf  v}hveIlq|{L{7BGJME'Z=Y',2飆E0o{B{Egx!,6߸;JؐphlUg+=ТK*)"j~>f*M2s)J]N>o6r+j(aOP0p*" z2yXb<  qfHCwDf\-2Debհvj,bhZBoNJCdG=:Է&GUKkvΝ`!T{q?x2A,M;)Lpt[I! 4F" }eWJnnѢER #RovO,<#1:ܱ'4(_Tn$p\DK/mc?ҽp34bO3R. Cn+<k=w0KVcJǻv,}˱$s۳Lkq&kgA/PP%kT8M= L{FciZJL}TA B78rD!?ܱB!&R`;uc4Dz(#YMw;؝73H_F&7]GQqԩԟjw_ଊ\^\MD~M#pS:Y{SȸxgA3'k?æ&fV/H rOP˳Xza"'݃n݌!\ uFG蜲g >$ޓ[# ޡj xJ˨[ې v;6^ͺWJYt:ŏ4źcqn譡 Q>`;(Y}vP=_E:4g^G/e%]?`1O&*w@֍ *k0`k^~.Yn6%hOatWcǜqĄuiW*|]:Ty%;Be9?"7jn <8a\~] 7o]7OW/W8/,SFcGB,4 XͯǗ~OXi<u&wLPjpha{!XлfT̍9[eک)bرns:B*K<)}x SlC eC(o6MƣYDi5ÊLZ{}|cE6Go; ;-Rxb4JQ]P\؅F5R#ɤtQSS]`԰Ia{8C_V ܩu^ݔqmZ+#Yzp tv̗6Tqҿ%:-J\?E6 \1{Q>{S}!3+xqMe&X> 4 .Mv c 7f3V~6tzu%{~O|fsc1(F$?f,u1ad lԽY@W‹`7bϩ$"&/t;0snh]d[7F ,lKfx"~'7SGQ#”F-ON9(Pm#̧/޻&ԇ FS2:dE6F#MWu!7v'apvfÓe=p /}֮r|]^e$/U}Y`gss#1OMh/ #:'% lDmohd;;5Qv|X#}!HC7/ h4C sEڀ{$AK!knkz0?zb^@E[XÏ$Wd0:9Nd8rKLn֕nX^`' nlL K%alᝃ.5tO&WI6`NIcmo,!2ҿ»(TZY VN{暝l/:v7Db)UaߦkHk-l}ң3-˘;i4-K}ag' o6 `cFX́s(\3}BJJ"ΛZ|]tImDr`*Kx= YX{sQk5J|;8PH&-OzÓ 0My,=~:G/پAcZr 9ԎF-2=^xGNsf HP> imMPA#qK(U"%/AދR )QPMlask,h:lt(oĊ#xɬNg{_,UK #ye?c]Hl {k{æ(UcPG$,bV.CSF`Mӣ!k*|a;}5"'DF;.pkBrG.5˜[-@dfPQ.5(eBt nv\P+D-jATQHD- ͥ`D JS9](3qm/CSzc0 Ǹ #懜(=EžpSivfm9TߜUyc ] sx{nR$xـ7zḠ~Eܫŵt"]VͦTqb/' ҆!LbBӕ} fƝSݥY_4 T7*x!?ǻ~ﲳ`LcЮ)/AP5_96b7qaj%b}nNc\mj5/u~Sr5 {[l3Yrr#Qp~vMH4s{!"';^evƔRM;øǾz PV1As(lѿ]/<]T2æ-RZt73tlh>rτ@lǮ'7سNfOcvk}{ZPր$!,w੐7F,h ?mλX+̡JDO*ȻuڥV9} 6^j`Ցx8ȭȋLf=}DB6/ڃdO1љT_(Duh\YCanNp<2 =cy1F nUF#☆эt}33ݨWC(Xy~^A5s%ENj#'x(_dHa#_y vЦٞof,k$ ܯ4Pu"-M^;:4[4ų]T@{/?|e )W $eΕ\W5#4^͝J:8t;d0E݇5b|WUK8hәRd~=3 X>{W1|sQX>Hx@u  s-[u6|&]ӗ'66M(*Z7ჯo93 YY1rsI_fȆ۱ 7O YUxEHpWeovC̓cMA7ǟ eIL0=v@df͜W)aM#̆r7IwIvd[k>qQHBr19Ɯ5? LoG)Ό![9vLH֟&D7h=rn}(0ׂE<|{B|& vb_:'89ƓPKݡpXKc ϬRAj63Wru 1Uh$zVЗԳhb bF0/ c GOϯiFM#B<ԆZrq?(Sr%UTQNHwJVPmEsP0Jg6]zZwDx]񍥅qlBd`_uΡx5i WTVSs+u6f\YK6k*Oo՝<29jͽ'У T}鑎ŧ|e0&uڣk(.Uݣ :8GgDN\+T\lRS] 0IutnO!|w4S^IcO͹Q-=, z eU[}]FG]Tn'! 2,bWOآJx7ݧsc/ȮAJgG'x*M${u oP@.GUn2-bW]{#Fx/Q(LkpqNdLå?R.;%3VVxM\|}& 밴1 ʆk1EqW)˙R\;B/ _w g%e0 0 pk1:VX@jH ~=CSYn;A*NZrh7<=UBA!Ȃ? 쌜ku!s}h]34ֺ +;;7gx(LDrn[  Т$ V fҰ& 6{w6jṕuC皌[ ^AArwfBE:vN;]@c3!a7u3ѐ_Wtk8##dA&M2k[LSF_ɹ:TӉS#IإH^1؞i$1LJz zya]Q;6ާRQ,;$ia__-_TL hzۻ.L&1D駦Au& F7K$zS_.OpKmcݡ'mJvٮ}a;M.$^ fzGce\ʿ^\41[rPT!.Ps^4b-MNC苿eRgz/idǃ&*J |`kaw3$:tz͢{*Ft7\&Ch:C Sҹ`o2&\>:PrI RJqA!̭sAGPyG _ C&h/5C͛ :OVCnt">~67G,:fC0$R6蘮_l{փ8sՕ7\AgŌy2Tw^ )7W)9:c9sNO;pagݚQ-%ٍ[־DwDզW3+#jP-~O%8g\SU޹b} BAE> c4vI>NC0_aYF  g[l3W#2c;5.wQ7Av ܵ3z 3dTJXx4Mn l'qqS.E=`WgPtUzDjZ-z1=SnAWbƢ{@ w[,ۻC )WپO+:]%)9>v b8+[t5Ǖf-l xP9k2{@!qDx&<ѻrܻPl].Z8.td.X|iPVPxKGюMRPPQxS WD)]EZZ ė6( @]XYm(K çX%ANs)5,&kfb'Wɯ ='woWN Ho :7'pIٳ3suzHZ>G5ӋH`D罡s]$~ ~3خdD=CqNѼ&fڔn*}uզla}=y{=D1qROSӂ|+p͝u J&`yXl1[c$+.[A:aQSTpGB&?$FkV&6\R? yԞZ{G@p'OhFƈO]3A.[ U!UO~2fO.VeKx}5d"\KA\od\3ɣJ6 0ną%,4nJLcbFO[^^ @Oh{N7殇D +>s' ŚdȗF@MSLK菙f;yBu;LX#Aó_:p3g:_&/b?S-HᮞHL*.b5t?vQ2k(CoA͎:~xu^ӚW-O%ọݺv,mSaf[!ϨW2Ez/һڥU:!-֓%1D~AH_|MdNS*hV{E]P/催/r<=\վ<ܥ1pN{3=*P80]WYuqc|+PDn]ݏh=N?3PM Y\A6/;O;͗ ,Ni?Wcq,MnC\xLc+*WXUN2-O3ֱf+ N獺*14Xbqs.")06zk%fUPu$]*fӃP$g3ǟT9Dtw swa*'ኢh i+Y>TĂΙʷYN}NX zwbz2kHyZ^Ǧo`LaP W,# zp9ƉM'lpxHȽ!|pYG [O{u-䤆YU;SnN߸J;Y󅗲L\lOl fqӂBr4y's%xHT c"xo|_eG P5sȱT'?q+HxEoЈ4ᕞ;b]eۅq%s oP/6xmYBQyN)a$(m4$ˎWbR@yS;7"7gqCѰı&qD_%n\Pb.6_gFF 2 qWGnq6oA=:]$Gu-4 dM Vtn pLlIV&-QAa- RLqEAQT6Br^tNx>t,SJ_fMNC:Lm5&ݶ9)>i8x:nͺT}`1%~$J0'rFY밄ڮl_i˗r2 ~t9̵.>|U ' }c{Yqw &W@1s!r)dѾc;JJ3Jz;is#(72fZ],,!sȊ0wuoգŊ cI} [0o~Vl7wPaU 8DT;56s"vHV ;biq`E)C75MS:RڪkD"*),w|^t2X^/B>+Wf qwkر|!7q s$r_B%v*x8n#agp49vES?쿨2>W>@$WxsT8$vYgFGt+{pa,5/B3PtwwEP6r15K6#gC[N8^e:Ѭ¬ㅈ&3 3S$7kpI `rl4T O,\gKz+P6iDžػ#qjrH!"z9C8eܦ1BugDz$N\8%l;/# %x,OVOUvXxؿG%qlDEDzEH1IX*J+`nR%>L!־/RdTN<"^$3D sf<0Lט]>_}>p$'9褖Xp|Y 2F Cp}I,~98zеt\nQ,=8S^|qiu[?j٘S;);Kw}iobyBL{ 17]Jsq+*pc%)hOcY+Ei>_6AA g-AcРz?lhŇR"{/RO1K ƏxT->&*Qt6w\n4}۬kk6F׸,8=8P=g`b!6b>븰۟%3zFL] _E2ʠ?ٺf0UHRa3&͸{6I@n<PiLHA,;-,vfeQLuQ/iKԵ{$1,EKLF'^TH31 A/]*O/sx'P@F*NÙ4XGR N+uqR Sqwp Qdz,ĎF\ `8\$,cE.X,!dEl"-v}QN ^|t?i, ,Ƣ>Z`7 )^W&E_&v@_,+X;k{%n0x֙0Vxϡ(*iOSl߹'zTת$@ycW4~ I2/޾jHx93k wG!4ܻJ_o ێB)ֈTߌlffz7$]撤>`/۝ 󫯅0û>tp&i8}&o=eLZԧ+ͽ ri߶xvHx,JkVvx86|QX|q?C /O7 hZwR7ϾR/ld>v@Ufo_ۢ"= .GsR]2To1xTqd) ݏСϓ>▢뢳c e19g1O",V,T@K );DDv]ThtMXAxveYpp+_ڢk;Vf-W}"xq4H`p氬 {WLROwko'o eܦĈ?jc6O[ot+>dwrTu"]"oiTxп,ߴ&}F]8&+i`1՛m=(%Z(-K~',far=O{}JqgQRCm^y~6ђ1Aucm%;;w&&=$vj7AOs@_͆{owVWOg1a>ݲu[kgF?+81"n}:$+ 렋G+AN]5Lw[8RCr{u0 Ӏ:;bB 'd(  0,>Ej564QkS'ğ1>!rWX;m3hR~7-&\]vul|j䔵&vtڴC̄%V|VPgM&U2zqIxK&wkUc ͅSdyyؿb~pH{sRDN Zt >$9p?Cp+VyԦ u8LBS~I9)z! h%G FCe35y/dB#4Htb"R( >=iŭǐOQƱAE6JkEJ==<r[_yN;y䅾אG4[w8<#=J[m!I`"~3Ww kFֵ:_B<kV%zAx^e1z :xU7 iZ|mqy9[y@ؾ?|J뒄~~IQsŽ:hSX ˼v`b9Xƌ0š)RfOЈ_;Y9w+W6<ܡy&䃲 83hrA흏K5^T{ֿ8PTOnB~Ku/#q|vSs<ַ膢;p\@|{MPCǪ6;QEp{VOBn$tF=ߋ#^OBp\vYRڲio{8Oh4ƎT(3ؐ?slsY֯:Zp4YOm\+_B ;F`#;ce ~\)p*Zf_:-4.G$=+GBS#ht'Kq#o 8%W)4~ڵ$dkWKtءXdRhv+C-R[zև`5P̭I tRс*d$vگnJُoG=a_3~5+$n`4F|+/U`$ gw K|qˑ^c9=OYFHx}edpn5d $:UEm  x>>M@3v{c0Zo"QܨQLOاo/Q+(N XԲhꏐzzCRD$4sOne-!D0qKh t5'}θN&:սA pd}6v?<}L(rTF 9vP{\''z dz 2*oVޖ0Z=.;&]d֦-]+XTf"dy%aviBgxIM(H'ohe7&2p2U&~8Z!ڵ֟To< 7SmG Pn%lKsP^S}R|‹/Z`SnM%;5K! gj9[b?KW'Kj/1'4%R1OS /KﵘG6h)jj[iEܢR | ϐ٤=C(i"X&$ж dDSn8(ރ60ĪMjEkپ*&'HQfT7' 6i*80 ۤS`Z(d61f⺹I&2{T%wo?ϕ9>/n;ݍA8B؃$Zj}b  zq9a2A6Y27^VøHl/]:zM M:H 殕jjiu # S׭횪htÙuP;UE5.ƪcQ5N(m5NdGt| eR+0LE{Z̽JO@6_˯{LMfg?o{+5x wEx[N{Mc?}}}AzQ1&`(܀ʥwBQJӗ 8r+j@eƆq# 5kP_ N2 BP}SvH3k~ ,ؽ?)X:f CV3Rq6Fҹ[э)>8RKLAo<|?_S0̃LxMtOOc0:&:4`G_u˲.kO΍g3lB!꽇oN@AJ1ua0G!Վ.JkܤPSa 3vVRoD\]5:fJI;>i)KʄI­ n%lz`_uƔ(W?o*e4'S?LƮI,i`ߖF4s#X똵j.QFxw6^y*~.Gl 5Qq^ Oz#zx3Ǝ! QrfW֢$uoXr'{.^*\n6yJ5-@Y.7pk[y5xYw9*` ?y{͛ 9XYaK~x y#"(*[*yjx"u6{~wSx?ʾt kD&֢DEG=i|OcYԖ/Q\;˳-} i T Xu}T~x^\!5 %5ǥ\i# [˜NK{yNfCp-(i$i$9hR~'*jty'W~s(/ YǙdBOU, >]M:Rh$= E~QZ%3|&M'o`=`$։ޢ#}K/Ƿɏ3)yê5aW)< !k36b`6ĕt$?[߿W]VuZOɸ0.> œ:#ɼCR+n!SF˺XLbhkbkV}h!4XglOE9b*:ޥKlʨ8+' +Øib?qc\e؆-jE  2jr~E [&mRu2&>ٴ¤J_ *3dX<+hE&|\"'2^x Q q.ouEÞB~"= C#6&ŠF"{o.1fl;5b~kJ g' =3*hEXih|ysk\7$9QymL;ۊu~[ad5V8g:#C[bL"Jomu;? *hk!Kl wRX5dy=]m (>^63 MLz!&dzTT @QT@%;vL2 ͂Բ'e(,5i;K^ P%L'rVTOVUԷv!inNz+%Ԫ1:vX z 7'SGw mV"Q ,>:jrܭdޭ]UՄi(>pV _yN\7ft/(aƭjʯoR(Q-2<*yD]I()L!]fNt^1pg8Q-_ذ<L\G<QF;"f@oZ2zsi}Ԩ) m8#NM}0 >@F:^pz ^I8YBk)YY9S7iPzm5\P!|;/!^tN ^XSJyv40OjD_ٕY%^05AKqk9?xc-ŧ 3XnΙ#1Ŝ?tb$J:dcxf(OȐ^@h@>籿'A yE]Qr1XҰkƆ=\ׁľ+U[=d+Z\oW`_ŋ ^M3&|&)\_t1XxQ|fդ{Ӵ ,GFL˩Aɍu,GZOk=gNYpbO5JŃoN ɽ^X]h;?)I$%קֶ1ӌ`dJKaK%6\yU دO]""Jo=fxc{[.q,t9Ŏ~EbpDž+DH8T"ɇ@R@@g{@ً^:=J' Gjm0 Li;T]4V:4 &420H#ܽHa q/sOcQڨOROCOIC05}gf蛱N|݂V_Gi2|2`9C2i D<5.8ԊLJ ĬOuXxfzT6Μ];#JF|_m>!,˜Scgpet?q]PoPʗ=e^`ďiVtGW^hD\rJA.@,aTS'#sۡ[&v BSHblΦ;fq-ey7^de6\k?\UDUt&kQ櫕Y㈴*^j.NC{]5HR|vHSnqeɊEաvpSq1mZ3Rdv!k+  v1g&e˩?,4O e[# t|}3Xi/FH+ccX&izC׳R8~S L\^8k2WHqjӐ#V|UƩ1*Sd(K}֌cԯ¿,D'ԕEMЩ0@:c4s9Ү2j< |8fDp_6m0|Zr~4Ԫ=K+bg~ sdq?T1kg&{XH*VvmCXJ2dL#gA Ht~KMpdoUFz 881?),lKώG|_#"V 0޿=Ed!F>@ `z: y{LYYs]cei,덟g_VV3V_ͦE𻱻<^JcKd~]y;T(wQV9m>e|ڛh92Yۃl]ӞQv{bE95%3\KtRMɱbr@B G'CDD)`(WӉ:U]ut*W5Tao.+0=4,SFE?R4=>Lh~^J g1Ի4G0j2-J~.*aeh#@\|r]![MZAZ培0]| SQm@}$hY5ؙ̩JxܠG+$$"-pWe*`߈X΃ڥn%$NY]xg?y'0ВvtTbo)s/>I >,н|ւD`汩e)ڌ9`mɖ׵_% JufDžu|]G)wwzhձւڞi6S?bn(.[ڝB1mdi3 _ UU0 ͹fv^|eɉYxf\r̾T'?<1*f]#m->$9+ɢ-,&S޹%'yp<_W.HK4<›4*-0{@A{sTլ7\~쯊y,@{!3Bּ02\? :`gUgӠ*&jHPI +l?kZܖ0GtYoܞ&OpWTKޓb^6I" HvB&& g)*~K}I$Nh-n)H.8a+V٦`*br5c֌^o'N~N^(6#jf y:8yT9NpEpI-x5"ǠdX1 ճU7tJC@Thۇsl}B^Ճj6B[xr/ݴ k#cnk#|9i4}$UCX+'=,w$B/*<.D!^=z&yϰ1-J@~͔p^ o]hqd?5=*oNyē^^:A~o }Nʺ4M-w6  , X:!p>c 2m >JC㮟R-RW=^-^N4sAފ2^;c5.Qf>mIf9F_~SN+a9c! A-p</]+5[?|qh 킦4Wy60LE-.PSn[FjZ15zUV78u{>b&~W0aGn,ᖱg #Ԇ88A{('&lDiM/==OFY3|q}ϭw-v|d$\K˴JQW;2X+#z*TSuS4d,ai F!5%>cmG~ʡ:f\OXo2fq{R2HPj2ċ{F/'&Zfi^(0l=745-% Q\fSc6=ېm %v=(Cʪ(LN/ˑ'nl c6\BFmW!Դ넬A7K˂T -gng=x#:`U}& `[:`,YMB{Rf_*R<󾚤ݡKϭY)]̏!GHXyW ;HRms"׿͛ lpimv.RiT{p^elqIwUl~4;+Թz& tY^~yNḀ8-oMu=&唒n̔jd VJ[ SůsqyNt+kخRNJϖFh`e ͂'cۛ(G *+dX,O MZY2`g9Le 9g^v!K}iɘ%&Į-;h%B서ɓ+wK/]zrxVTK3{- usX1 $V$ ʏلkfVkse-֞7$ G\x23 6y p\*ަXec0f`11+0V|W]&RGbV5{ Á2 F(k&$*8i?(l&uݓYyw|JXW2Ĕ'\L4-g]sc\U y5U"WR`'h+ i֧""8‰ 7+M2b0+)?#׌Pgŋ#$@cYK]~ps;[|mۘSor~R+dj}l`=ы3"rCm;raU'YymQ (KNj`l2e+zwzTg':r9LBЫHL&kt5¸3ifo 1%#W#;D'+-gs*5bII#GxdgAfot[-Vt8-|;b;RRMx%zw&яp *@B?gnSbdn4A Źql.+֎ŃA"8 *Q]`<*w8[gv+K`3f?U!ЋD thj @8‰FI..Cw=1MIq)M4@?@!~Wp>/@e`c4l166eItXu'C̱PVP5[aڰB: ry|r4\ɟX^XTxu !h*DA:Utצv v'ެ@ö$oET8r_gXfGC ”}cݞ8|8K 9@}i{M/{.Ea͍ 1ψv́Rm?߿MSAcoy˃Gn>r{ŕ'uZm-3^$ \~z(re4s&" +6FAVVa"xV#ToQ; -0\SQBGꦺr)iK Zq﮽E[0&41cJ&(ԲQQs~gZ)m12e@x 3u#$U]{++cU8mKtϴPsP(}NGm)t- Z)ꏖea!$`bl[1]90oqzBx|ȤJMoQsJq F2ȣ y);vAOјo|%Y -xLqàGVi2l8cIQwXn+˂<?gHkx`87m^'l oraU T$B5(5-Kqoe3n55B('jKZ7hEzjtL4F_w|.%<q̨͙Nne:n<2PF'\W.Rl?k;:(e-kq乹,~oyAAC/ɛ=>1D:]HÊhPf 'RaBRf*2.+[ۆ@mHc mJGV R_cաڽA-Ϲ @*ɰfr^TqS(;8tnF)Sn0d kS#c"0Z~Œ>e )!qf{ /sFE`jo}h \]h어ד)uW{I84Zi 񒗸u\UQ.&^Svhe*yk6r`.c*,6& 7-r>vxzLT<cC^k$u]ӿW~zhI)QN qCIiŀv2[k=?6'5N>LNlQL,%y3z(̯>&k8N*ta.pF}gJFNie w{lw޹ްQ79*y-&^Gl9Sޟxx"SS{H2=NqdVܿ|ĜA# "vW#z ^idʏLv╚%ZuVj րP";Z>\JN5вȻ xrhF̀ 竫m􎏒Ș':\t4+/CIes|~oǏ_q{{ aAό>y{rjܠ'zd?~egR{Xxxp<,klk _wԿ% mchT=(X+.4V$jYۋľY>zCf!{w>4kN¢E.9ףd`Dx/w;#wތ䷟j*y;'?;'SEC4Py pseluh~$n9-PF ϟ}_6jLF2q=_MZ<Ƈ?ib_dpP`t#Ƒu[αtRG1@zݠ͗e'%X=ZApM6KW ) B):lhۡQ!Ve!]YTm{l( ,TzSCJ*世X1>)(O%G_DdYTg(Ɠ;sXЀ7:\jl5h'3*j[O(M{W‚$Lse=:@o{wTstT/hU6B|ح+6n m Zk&ps; 4OvR$1 44JsTU3ʒS=wbA"m}8; 7G/z-S*_ye$jWv ^+CCnrcix*WQuV?ӃYK ь7Q!qo`*bMWJI2|,%#9zjm6P 4mU n[Y`^2Vr"q2I$zX騪(3)&dMfʢ8bHMSs]җ?ֶ;qK j,*?-P( w].)LwFⷷyX0fÒVVF5]hLQG{ ^pv:"\_E*4'0T8bz'=D}tmx'Y Lp]\r!c*Eѐ?eF-[-tQJU_@LH#NŚhӧUSu ,q~k zҢ^[^ AA^ٖʪnWɪP5?[8"=\t 7P5wzB0^7'v[׸yOilk;G[Y r=o[L (I!kM,ti?P` |dFsܵf*3D -+mډЀF֛ܵ Ⱥ{x@%̖su|Qz5IW/~=؊hZujr[P{D Jtql1] 4P {%%`Eҵʄ^;pky؈HkHYp bJ%FG$T'^~)jZ9PSLT о>UژvahgdK,E`{&}_l7sg.͊WvXy/KCD}8@{֑CS8ЭZڗJQTchIBsj,3Ň2`Dg~ۢL6OS׶Mh"kEPZ ᄗ&+[cs9$l;|~>Eqa@UJ`d~6y[ ޝXe ?{!ǷlՅ.d^} yYѦNa(UjIG1A8VL9ӯn,9ER&O;,|_4|.FI8͛ɴN9kKr;pLCZVF n!^r]VE|(RZ. jc]֥{O0=[p0\VB6GTldw >ޜ[]Ūlnl4 x璆|D~~qgۇEs^n'TCaHm8 Z9кd/VNGx7F!X84JOo#b ̈'W>j 8@1k5*_^/Q)&6\\&|7*꙱]6X72GyS"]˽VQX * tPX0.z4"/P%-o%PxH$):W]F8R:~AĔWg ؓȾ:&Ma`W橏w.2ٓ<n/M{AkU&U%%-I;;"3Bm"խbp.}Fp5$j)N?A@7x_߁=%&~4xǖZ&i':h;0Y*f6fH$I҉×?@X `U+'GoCܪJ8}]LEXeH KTb]`IUtYk51''Rcjz]2KN4C"uB[6;I=GH37dz 2Q3w0GF6g\ HT%W^k&P7n|&Nhlq"ETA ˹Ç켕o(1.ت%N[agM3͹:ʀJ 0NS]ɻ#UDfRvﷻbsq D9;~'qǹLZ&ƞ ZJc=7=̥Z/Uu@" "q.b{g߰Zћ/"H9z2ګ{τMaobnj`VTkxVF PTBFrqN5D&%TaDo@4Kl(**X'--JM~, u*8/"r z0`yKp{iE5Dr\RRE-.qru@7Z*~)k.s}Qikxt`(ADBcJA|smjFȵ q|$>ө8'=~oų Fh僝Jcr5 ez rF!5B?!wkU.f]s^_g!R'5Z1i;5Dِ?,ar,"G$3VZꋘ_owM=&u5v;8YdK@4PN|or}t̎"< M:G돮џr hRa+BY@QIFkdJ ,MC .|n?KxDI~Z0:3lړ=q|Ktɥ-ڼ 6}&zu^x'|`~s- <4u۽Br\ZdX%Ҹ@)`퓳&YԸb W 6Kf P8u lݘ~DrG\kl}:ѱv*i-ȱkT\:QNc<'C>N1{?| I?t1:mejxHĪﺽ| *AWSo#h@Nn4㍘iC /tTw_k8#Z̄=Qd^廑ps?Y<9 %(waDsrՈR8CՌ +>jjIlL4QaC<ժ~8nTw/p`bIK.dVr*.!W&v~- THWY mB5BR{nYW+@8Yw &yܫ\ie̐7 . xݤĜgrVBw \۹LjLpx_*h!r8爈EDvP!R?BCZ7_q?R R8P0ןf`LA@+3.ʎ"rLK85ތx" %Ut= qxu}2-q/8 W^ʛ]@n)gDɞC%O!$& Ļ^mY+3L$v'^*A_(a4ڞYTL՛s!Ruγ]'DD]aBد/fwJz5:%%jW 8t0ʎ7ڭp|ctz{ב]p->t [j>`Gɀ 5ϟ FpԢ&O s0zW0m1P늹0TO iY.ʹ7DbCI{bO$x9wF2xBw/39ƹm]3ψrbu2?4^,s>7R7*>=5,pkŷlNnkT#mHrge iЖήU911PUys1lp`w h\5;: 6$ac@Sn&,f})昳!61zRPF⁃P8p"(P!^(FРuO@MmEجE o+)/b1MIa~"̣C]"5J > Ns.XyL[n6a',ngg^HtWѸJ#mv&t.]('.1а$S.()U]Æ@(WzGFnQSOӁ`6N!GI}dD̜{Y3_IqpG1,-ATP@WUK!i:D o EBXw֥"N{sI0L2ORx*74T~":Lg#[v.ĈdP7IwN/*k K3Ku7ަ&*td?X"ŬҴ(W?ErhB w 0*34T狗D2=@B!:j W $1LO/LE&Gb$pd7Ob۵ "(uV;UIts3zxn{(WoNxń*ߣ`RKm;nc<7S:it*]^m0#&CBbuVez_!gA75dc)m\ nޚ3:f?7~iU=h@-mczS6t}n3ާCKjc6ڟٻ^YѾvUyKq_wu *bEzPI%ÖHm0iuʿjQX|uHOPѩ4*2a*?$ih+BӝZpJa[^w/DʫGB,u?p_Nٙ5KL)`Q|a БzOnStɾLQm5ĕ'V/W!.82ssjBo`b<&;ߎy̻*r6lMUagZm㦯5!ҎM9q&I?EԼ. ) [78)ISp~{zmȻq1_urh+pu 5#T,FrO13XH VUS[ke%ۢD򝑦5cP2i,vy !8j],u|{hՐ&#{tkH8x|0fnYN` kSKw͋bF{X-p%, D]3RR&Qn,_kbhV39yXP5 w wxȩis\>  m bPY5ahtŬa#8ØyxfF5 BB|(&K;:?eT)p~9Z ‹^- QM3C p?0SRL_/LPq[Rpdtt5Xgp&PȯP8=(01j3s #; C68A9j cW ~|V"\]#8J 1%ܔ=bo񂿉.Hwdf#ףs7(&VF 326H}%:23V)yB ePlDC3T_+}0zAuI;<&KZ_fJ [㒥Vr-3s]Zh2 slc^6)+tsXFl<+]_B7%8աEaDW@cvHw,Y4MH u\t]bv Tn;Do[d`K|&jh1vk`y~S6^Z41 e_|7ݛbŬGz<&ॗ [Fy$rnNi*.*'0‚#q=YVj.ָ֛0V,xhq5lQn-wI)j6Udy8>߉n1Q+77c(Bg6-1\g0$dJ:@@.a '~edIuӭRocd;z[.MyI)']_IƮj"ŌfQ}:]lWC  L2^L NtbuN&wwKKofahadž[5eWtrdR886U Fb얘MX^ڸ%AF^.h/QNv]X´AIh븸AAw\gm^OaFd p4S߶S8d R`{38qݩ mJlwG0%`q]U9C&RxodUvBwÖbζFfB:pIbT^|/NQs_}.k 玁[Eum5r }|L_QD2rҭ."ִGO"@A*s| ׅR1)OAcS_FY1f W%hDKv"6s}c'`BsA&}%2A5KũxO8D_ 4Ѻ`uLyEm4YzORj+gee!(%# 8(9i-^ lwx%" R O;@uu+h'@=+~l1Q[ҚK]T4)#Behԭ}.&mN3íKei;3ΓC|Lw DxRSMX5b9Vjk1ص\) yZ8fVϥ44}8kPIٳMOTj;$YKNdMݰXX3\y!͆ [wk)ym ?JZ-za{Eُd~V/¬h%S %6X6@t&-Z}X0NA]Q-!'6i@bHMxQc2Rl)R ./Hd؉C-\+prNÀF= >&_G(q#(ws;ԡ*\8s?^$e&mӷq)'W\8 Œ,vNosο_fW)|Lrbq>".jlU++7׋fr>x#'[rt˕;56i2:g۪5FoȦH "=XW_[$toC5y%n)B~ǐB//'Lc=&?8du(ġf!' uZԂ*P }N;'OJl;X$6gbXX@zMBQ| Mh]hʝ`a ܚY$4x.nC5W4JƿW8wA;keN肙ͷ&ivK!|#.v8@!TUs" "wƸvEI(qi}~'$YE8mZ; m2EôF |# : RQMp YXy5R咸CׯFt c)%rXRmT`byNC#w s1rn .hccu.?_Wy3M@ItIoi2G<~\.pßT(5IQm`}Ā3)ڼ69~/>]q(@NA}Mb A7 97QguS;Af5k^ Hpߒ?8⟥Eh -Sv|riw|Kg^]nw>Wx .]X݈;M9RmhV: 'Jh>n}u#dQT R7"^8Dj4+C %.h{z?>ᝰaI^w+LqRxƍծx~+Xp׸v~Z=Q>G$p 2_jl8$bv :*q-d*OI\(JG]Y/ op3{yEsle\b+<+G^/^DWlA] n@-Z8@uql~:ns3vɈ)&8T Y)KrIAihϋ \t7A5Qtt_8ףIl҆,u{}raj) jP4-*8?xꆜ#L"G^&Ub%e<$Z6';8\l (km 7>Xzかy`҅Di"&vsUQd|SoFVЋ_q4UqDzbe z1_ҝvVۛ+c(̢%۞5 bMJK?Wr󹪸 PRJR{3~8 /er.bbKk+owȽݺi +ּz4:<tr?:(eoWGJ ѳ3ݟv0|FlyO),\#)'y{a(ZG-<.0X( +_uj3oF$-T;RxxTJ&@4_os(묉7Ӫ 6h'<ubmVd1*!l)胥M{[m GcJwB `$΢u6:[kV3"jZy^;JޙPa呖ŧPkJu%:i7hbDV!>?*z 9d4S 8d{XQ@

\f)t=1U1Kz M9Z{ێjj1`fyYBQVG7hRc O="‘_-OÜ o*aP̄+nW,vqn/  .4lUOJneF4U* UO5m"ć=`nٲ/u'ma{N\tH~1eúO>t'~Vnc>d3Dio)L.%r`&qkڻ˨֧j=}Rj^TҍhIVk͘as65d 绳>G$w.Jѧj;9uYlƀ,&FR:%IhDHlc[[-Q%VcIt"؜4󙽊fQxk?`B^vy-4ZgG{8^=-BBGMUۼÑCKG< pl"B<! %P j41Pdy04 _G|md3NϬ itfh?RΒ L 4Z+N::r<)rB]y,>'R\{M.;so9wKtTww߫C7:Kvb$۱(X(qQx9N~Q$lU#݃Y34I y ƍꌨ4yEl¿b-\Rr1)#tVX0 dӟ}ƾ%7TTpF#%f&(xTT'c1PBG^~=iWp^-{A_6g誕8NNSM h{mB3m1 #9x"`$Ħʙ(mۍ5Xl6]4Yw;lx$_9*"KR;@slP%I\!kiXMAWTY٠b@T;, i2 AIh]7YWclCD$aw `07zvWG`0LwXqrdv>yƏuobP>;ӗS G!<bo*C8ؤ&5X? O7[ta'+7HȞie@7NeN?;JA{\ޮU|WYx1M~RjuxjeهVM{c/l OR}_7/\3]s[\و ']LeOoMV@;I\e}ɝq=đI;[l<(Doޡ V lt*8 c4`PiMq@zJ;x-)fU9[q$c{|sڨ "z9;m  8|ӳ񃇃@Q’#~ ֵbm R{]'u]0K| xW<pB;Q&0C(#֤՚ܜ1/L'\qk{gAr,)R`A+JEXٹJ'PxޠvD0ZY˺b27n 5ޥV6 VC惥ն 3׭U[Z %|?K0;KvCUvè&&lN]K$vWko8`jV 4WõSExp]\ _`4CۂBEQE|Ծ9HĔ!9{=5DMdj[TPmhԹZ|YJQ 2wl`>jK*Q2NAi+DC!!Qj_3չrQX(B#sKA9#r[n00V/Ӥ+.gź_dcW 9&AԌUI콖mtjxU s_Q'WMlu.^M2td`QFt? \[Ksx,R?t;s*Pk{(>˔PLn>l44?$O ^vdPA , 0Q٢Y;Pe>L'>w ېc5]4ypM S%F|rS%k$ǒ2]*Y ]eWiFyd#/^&Tj\RB[4`8YzVy^B>?ʈU>{Ofx6*/(:V 9n hw a:P)ejmƉ.i*n{eK{"L+_ߖ$YCN0en##؂J’܊D3$ RLB!@$ V%TRIG7No$쇍1 ]7[;i]*Pn&+|:cAo YYuS gMĿ0{4ƣiK-B_7_TlZ}a,UXRd"  _83< VIixq&짮h zgȋd=6a)0|ǦW?0W0wȡi%|![z< |B)^ekvW6waԨ qh_mUJ^}JmF|8ՒjE•[cS\ٝ[5ݍɫ:6 .Q:/pl-:t"z(|^+oȱ" . ^uxSaKo6ZW[qʺ.P!!#uQHƪwr$Q~T")}S!1 '!"T%1lܐ#ѱdV0h+<6k۶vW0IY!/jdNAuc hrAHUnhbyϺTuZS;iRntdxER>0u eu: p5 Zi2i_5'?V\u23 ƥn2/nz;~\Mz+kz^/߆OTvuÞ`K9'إw@4={_xȄDCynRq&eL0!o20=Pyxtb ⽇UKJGn~䤣`oVIM]ȥ.0yvj{Bmկ.A`{#zs֐RJRf S!Mrp{-Ƅt/E fFp K? ębvRRit.q^T)x+ y x u܏^cȇG9gѽF$,ݪdKRLͼE8b=9 t*[cbH7aaLPN'05 ɞ7p3j4> qfNb5&RϹ#DF!yhf'sSPjX8^|P!-m Ӕ "y+$c_VguaK,5ƤnбL͊ `0 9 x xU#R5oS k ͻht7`Į:R _dq\݁1 l߶K CW35?\*7ײdO)K&ےSn@COR%P" UecSH%iL˞#dCV]It٩Ϝs;s9[y@Ìg\g)֥7 `W&^;s|cI%~*6V+S !Ol"X!KBpҌ C ( PA\ }&=ezk d=5..2( >mh4"N+Gse8/KA@%x-AR#GvwU>q: RcY,޴JQrS7\W;V|O|DoEXPɌ{kT- gOp95zF#(m@aoD4fͅ2||w?" 4`yr1V5[ʥt _o3&+`z8B}sUr8e[Hngr0!S,R+5'yXzT(=F Y^UDyeXNN.:qƒ_ PA/b8=\$愞t"(H@1"]#QUv1*g6/O kXxN7je3[nRB%:B0m֘8KJ^i b(T :т{L`|S6kpbۥzHͤw!t#bPW;ǮΉO4 ;N^<"RK)fUJNf7dH6]c%ӂ6k)L4Iy)^Dxxs=Ɓm‹ގ?vZ V{,dTG3foQ/^FGAOj 8>.*wN75z8(W%KzEwI_28tajfS"o+T"LE>}#O^b>X&Z] |Ն3ulS$<L˅1 Ӟ /,Ba*[a(Ȉc;/`daO-w"--&1U irRT==9mBdSHECk$XΚ W$:."swt~Jt#cQ*P\g G#_fg1U`j:…E'15b8e AMiKʣuӄĝ K=_PfvR=NEoC]fF 6!.Ycoq^:z/v,TGOi" q(x! Ċ=.)JL8$=5Wθ*SXD#ݎMBػYg#Ud$]sHEV)e%㆝B^sX3wJGwx0>UpC1\qLD=sm]Úf6+ 5(z4ǜ8W_!(^U {cjnxk R^E_\e+Y5W`"ECbKb/#{P/T?GQR/;|K[4Ge^^RWQnf eQ\THINrBIPWq8ӛ4??aiD (K͞^ȼokS~g˝ pܛЧSq#.'!}f iSy_X]]Hc3B?^`cy ,âӹ:*dnԩ-{tQ. Ɏ4vm*(ԖOD|ްYaKO9$yvz$*`ĉDFsS 7jK[ff5L¹:F%x'û?^&wI{a25c'mO-*/+v.6 9@S t }4.W} ӯNZ+:3!-L@9tP?mOpU8Ei{#D0mT< :`«'7(xS^WH5 (fMio^:#ؤ "k =;|MƯ<%n^ vn/ g׌kʛL>6$n@LJ(Zl/䭍NStzg,.Q<ܑE/xB֎BCœHeEZ99_O/wV!%׉1w{6[bE1JX9<Q|b7T4#-!3]VUo}8J6vY!+":"pN9౶N%F÷tA_?vʼh%1e̤G|$תs0H, tbǡgQAPg.+?K)MְZnޞxٳ e`u-Iܹx[!6GHj NHyB/pm X+);%?{?2f~r Q?)yx $L5 cs.5ujtq=5D@\ؒxڭxs):y*rwBXkC_6 e ,ߚ:1Cٖ7q=e!^Q4&6A.vYb{۠-):ېc*@>bߌ6M Bgڎ]q+a D *Bs+էٶd - tQy븷aĻl2;ގ{bzw֢2,D+*E#qh%'ҴSK"WSaញ3LcB2&d=^WԻprjUuA1}vШȵS Dc~O;km> hsY({[cO'FOcB*FriyȆ\QTۿDb-P$~&sh `v*vJnz˶7er1/q;`zxvc.gJ&fcd/9UKKx0=2"M_׽Q~ _#fo#8gX8˜WŢ+Z@pX7Jb"H>[Y38DȲ(tlpImA*bր5%j.l\ԨH.Sk6,*o aH񗃛 ,{隨f|ԏo kFԣ=Aik\Ѯ~2c݌:8qyΙ jC.1nIUws۝N@Y<ݾJ!,гQM1u?~yD-q[AC:WbV'Ў)whס+||\xxB? 6_H4=P_%WUtv?yK)kџpw" YZ.@ӲWY4~z9jҼ:MBw-eMI=E.$LWa+hCyz&tg{_Eu~ {U]45x~ٟdDͷ9BAӢQӭt):H&g!-L#UkfܞKX 3#'.7Mt}1\Pg]fWEBEݑ7ǛqW6| g޽t}oN]^%L:ݍ4e`ɤ_q0<j!=kR3 MA9J-(&Dku`$nNa鯀EˣZvDF*08N'`cF/xr|Ni(gHJ?Ʋz |"XɹҮ j6C!oİv T؟%mp uHmu w L>?i5V[%ڨпG~pwqg)n轞^ۓ솛PVGoBK{XD0B2ʳǾ ;4S=`i!l! }M _1wbO&|h u'PKLwB Zw`/^"҅M=y]Du/%eǥ iXR[\{2~g_ȇ̿Tmǔz}szd7{W&h3"Bj>m$ tvAyZXDVg$Dz868s xJ.'U,C8m!;RW>J oU)^ 1¾s`2d; [Mh׽ ȡe!\YmxM'0#s ð5'Br|R,{t ӧV:o4ss.JDlyhã 7*.twv  r3hJTdmFId%}a̒>9j}}L9> "v63xKq2ƮQP#O2$@)Ui_&_ y7s-*+qQм=I09V+gڽ|PRgL%mI ! %bBITu޻XSLu_]8Ҏc* wc2+:MG$U׮my4yd.,rHzP WoLAх^:,y|ܰ4& 'Ɏf 5S(QT4 S1P&K 6OuDH^"|\-}Tb@ ?6;?4c6IT2lEH)ciVlݩUq g'q2_GѪ##qf}``zn\A@٨uX5]q !%߶,X22"}F![=rA!c:PLT {k. M,Zۤ bGB~\]Q4 |sh 6p ЊHoQ+3T-P\clB;SC/^^Pmw9t\x8Bj,IaT`a+ZK;%z? (+O%nRl"`LCZhۑXy``tJSz)f?&C)IEc"1l69T9y}E=PYt7\iڈ'sC- dW> tӟF2f1MͤWC!vQtB/UKV6pqV?py/"*AJz1"F*U}yQ`wja9^4jAYoHi:ttoyW'}=EOi1%Fz:4Mµr (nP7DQKWZ$o.0 Ʒ":mQC2EKAX.M/̣j*$L SYg76jRCn7bz $eM|b]gttCtgSqjn 釂 rRZۭ~Gcw@@@1:T3ᒌw]@WH0-fQ?ʝ GT ʳOFZ9zn]x"dWÒx¿Gk{yJ(;P~bf}. m4%r5%+xt+ZQCdn4x'[bdD5|cY#UU$W"{?9N5x2;Paxubgߘ?=6_hr!6lIV]/N:.N@RpfKR#2ߛa]eM[7-E16}ֆEIWɨT$WiԛZR̸2臱꿹]&C"QZMldv|\p-QP_l Hk@WP4Es sy?#Ro4{VJjnre';rt =z%>pμuЍ\&_`Tw6.B^Ha4^)_h=W OEHF,lnQ N3k\U؆ =˄Un)=|F즺WGV˱ZR|y+ 6oI;~JE fiTB/2b [DRTma4l&57?ʏ3+*n:T]qnכ.0*OFT@J$5zY-a e[tH61dzkt!_-[{tYj/ O0kKĨ0$v&uU qF6'vzxvFS:5=ŊuiV<~!Vď wx@( !4) 'cO[ȑ%Z>Y7sz&t븉'(xHiPHgkܼzmL"KRou%Ue߈3qYg=\E@P*U1 T 980XA'*fCtH~ѣ\faY+g &Eplco1[U}:qazIs_Sn9, 6'vk,fx~ZLW,Tr̢=r]bVyr 1w LL+<_f]mwck)@mVzc0(8Z?]ג+vʏt:,p jŸc]*t`_[jfrut+/ѭe9T}#i UsSļދ|=746)ՀqLy2`eS~jn͵FJPTMKeן5hC`=)s>"H4ൺj]:N\*jE]e6uz[iiɋk`ȖPHA"!}w r7vA, 5=Z~Ew?Yǝ#R(Oj!Hrdv"<\rY0?j"9""y`21Jމ[c3~wGEEC8;! &^N醙Is O&|AiS"V_kgXx.f=^U6TKζư6CNL tUC;\_A[VVkuA*?[C l)mM(&G@`oPKճ\nE?OcD/yWMz:x2¹s..Hq7a. e'x6 >b觗5"%x/:ߐ\N ݼqfA: 'iI#+X t/|D#Lr, gu:v \g#]TE6awxI֢W ;B0͗(4PA-s(7$UǼ;vn\F |IP `&'C:HP8 Sm^EaΟY" R6gRߴrrXۜ$$ `W̟a&\?U1 ,`Q&^@#;HR9$t*z9fPf@)e9-iq %GL \ƠNaY=^ tWIq-C.Yd N =`tvyz'*-`BQf1 ?wUCD/%$ltMcLaOw&r?(Fe8 / g+Um#n+*m55NIgDC}eB#m2*pN;AM%yVAµƒ! xB^$a垖rȴh[\:uLpIܛZA)7Ѽp`i6p7$D=9Bh)ۧfGpGN&gH"H϶$ ťJXx1 ӟZ# +"fv; ;*%A |m[8EbKYJB-#dO2@b^W"8-#ཛwbuB@,&75[ʪ~|qmBӐ4u~6R_'ZK)DY9 h-{>KO tMNzvp)TudU \?EһtEӽ X)@)hfy@F nbHR)fƩx`AF&A-dUY0@F%',|=c3nJ6?I.>BV )ȅ+(*|:+[Ig( ^.`6Il0okф. M1p"q~gf[Dw:nHv}q:{z}&+NOH_ye*AfPz%2vQ2L'R^'ڈTl)#.Mږr#X+^q3ULRe~qjn O;٣3]OeRGԐG)ȏ]/sV>;ɯ(/ ꯈ%EuJܽ1ߩY=5K*}1v4^QUECEfv }M Mv'ՃL.YKgBcAbt'l~Zjg+yFIĔ%bݪںvd2keNˉu9'ma!YXdEBFȤ,r- S5Xzc JYXߘ" 4ֵȰ$OB si\M/=N~c['[cvo {?? 3E&$? K~)nz2>*`i>,)Y ٵz>=f;X=([G 7/#ШemV!_rR~nVQ2H??(]|<w% bz˼ _quy` f?GP9̨}|wL,1>֤s7].p:N屓͝r30PUV,eܼEiBuLD%MT7tG2˪8|ip TH{z# WAQ [3or;Np>9cK(.EdWNEDh#_Bm7N`쀆RfIn@SUe@d_Hacs^᪳; l_'*x5 mݵ wz¯^D7Y* %B ߢ̈Ɗ'<#`""."UlTُT2Xc4j7/ŢhS=G`esa5EŨ,3_EvE:PT:0&=C7p/㷺iڑ!QZ]0C~rI"wdIedaQ,CL3gz&m+z {(໵b˥p4}LYJ*uXD9ؤ*<ݥ2+)qc%|27xȎWҘi0 pHli`*cyc!]G-_`*] J7~r:sxdę)œ |oR@Bs DdvػvH%#1[0d8y+ύ_ڳ %^8>C[\1$]r(6 U/q=l(5`?FoH ҵGҽ'hl"n`-J!ؗ>ۂ>V%%=Kj%x_.Qȏ%S~εWt,4T1>ls`Hy"z*AVsQ"cUOCS;INpF2aA|_GJ+>v\p;ee v %+Ԑ6y1G>QmEân,s#䜌%oe{z5kK1ZkYCDz{%IyK׭0q#ΣIF]Gn];'JOG(?Eᝑd~$KTk3"VEoCS/]1q׹"|pؒ&xtiwΔyVMY[J}!\WfYZ:\ ܶ] G1j m*4ѺNT<6԰uUSüid^1o,[h(.~#A#Ip8zd^"z֏Ng!銪6VىYU .)d5Ȟ~)o$[盥'\P?О@M*e.M;k0K]bk;] jrUe|~YU<e~D? GnvE,P> 8&<1<0{ /Z)}5q&>:mC#f9{*k>DY^GS3 +eݬs}Ydܝc@"xjhD0;בbddPZ =\ҊRCǃAȶW+cK2l;F)g1[to>IӅZq&Jx4C$ǰbVtH2ke](Ddߦ )K#+rMVx*xgm<]`Of&&e.xjoc]=֧5Vݝg|qD7;;A¨;/oI0:NCwQẒ j$3OOM}wJ-vUe+6BԚѣXǗ`~hm1 9 hB6]&K]9&!2+:cGcTCPME="F dP.&K۩]͍D,#K=.yPv t,;"$ʊ!Ӕb6]ޫlt]+ 5*h 㮥10·` 9^aLc02)Gܢ8DX45p> :BhXџ ZP+PhQrWnzPG1j$⇐0r񜅖}M+"BF/^HNt-MB2XHaTE;{qw 6 bsb"MqP` Y)^xw΁-7߅sO>}y*gTUޑ_b=P,GA@L%hz{os[U_.oyj()Ck()ujs![(0$>ܒ`lաjmK IK`M d[U0!+p;QDWLw> ZWnuýG.$!Ɔ@ʇTev7< R4Rnw[elH3$U:runSla?!Gjs4) ,fwY B*?ZτzHPax8W1͑ugކ'ң? ??-b `U4DwyzaՎ򢽧EpPRfuӳb1-19~ͧtˈ7| ᾆ`Z)UU, EϸiyciĘz32WŸb>5즣戳Ͻ @sSư/a#pŒpj%K>\_YfjP}EU -2]S:\3HD&[𝜻gsItI3zSӋ&Ts`Ŝ^Zd^| ^=IRig믟ntO-a5g&> GTx!|/Djy.j@S'i[V:թLl_KZ~/*B>sIQrҊuC78E鶂O>Jz%FPrlPۻ`O;1|ٞ)RQ+1!1[|2eW~=AO]@ҸlWr-2Ø<X]Nq1m1v8 ;LApNNzmڡ#@3>crc!Vɘ+owEUS)>3v"w\qZ'!'CE 0kU:%s!̊4A-TGKۨw͚m3ZsN#V\)hM@<`(1aB Ĝc}'lWn/B؀ݥF `WFTmڼu蔕ٵZTDڴah{בiƠM6#^`pH[﫛i=9?9@䭻c뙍KkWƝ]1Gjt[]gJ!;+q35qeO㆒ tٗtHLh/%cT{XC ,?^yD\g^F#Nvoq!у/ԟ#Y@!IJ,veimF+ -r=E>=@SN-6ddK6Y4 Wwf0zt &ep1qc@G[)bVc~0㓕SQmݾ-"obw Rᶤ]M8Ela9Geu휀)lkEpp#!E |K=S$N '-$ z׏"cr!BZ]i۰޳nȋ is96Hk.)"P]ˣb~Vǂ}|wDځDGT/15K}=OF"]wMO0Z=xɿ)Âr-*a4j{)yju93a"7L\>ϳ#Lxԫy^8EYa{ą[D[E &IS>IgO3}Q@4m9˦qM)A(-W9j&¶(&(!95)NW抳ve˯`Ym5̍`[ 605qNPvͮK6@5 eYPH[]8`E7z,xYц7ȸNreA1bQΈUJL&=Ŷ%cy-2:wRtw~ro^ zMfcdHmG CęuC[:R;5MȦHO}_ 1{JGl)걭$ cڈ%m6.d#>7ʉN3#O :|q..E29jӛnO#vQ'dtKM-~J.uk,'niScACpJ(74XpD[sX'w%^p+~严2OP1 AքA-W|ca4 NBdqhkQ |DlO5v9 h2S&IY$blk*|' *mȊ#<8^1̕:&9[)D-iXw=apYth{h-$R¨Fg3''@ԣ dI@V 'dFz44C( $KpGMw|גLF*TQ1z2ٺb2Ӯ%Fۅzi%e/e7u^`Mv?% gNxwZbn8B A$>?;*CĎ^iEg ճ sCCi Qx[N}Aw;U`YQ1.@&dOT@GG>|ޑL8Xjg%ǹa~|[Kњ2,|HWjj[MfxHZy91=[U;9S B" IKLc;]&߱4q)|ih3hw~ sI^,WOPkBd6=6,'W Lt}Cx^*C*:+].{C*kIj^ H@>xnprQDJĽ;P(+0 oSy_=gE$.8i q5G~S要`:~\uvFLg~|DV)-K9;v?"(J4{gcJ!nW/5n_D"Yk}ƲobQQ!7ȼU%\",)nŸdIcJg+uֲvC 8SJ0Hpe'a1;2h¡"F$rE$ DiGD%V+Qe@%(ӛ#ɬ,'?~ce<3.Jfad.Nx>I6Px5iUs8C(9ZW*f_qvN)>%)I C72ݚέ0 J&P%]>icBuj BL\%Nb}挗|zkۋo5~db82du.( ~zaֆu xB27:Ǩ9Fpn^̳3?EgU + nxIJDm+N÷J7kqgFA)wԏp(]azhTs6&Z2An>'9C6Y01yٜ$2ǩSv hHckg iJٻ|U'ar8V o΍38bTo3!x|}:(^ JS?)s-]z:Vs?]5g飌۔c;vA_s2͙ c|$gh8 4u4D+F00$:G&`zAHd~8"}QyLm3K0MND#}`UFwZ9x/ZĿcz 6v_=uR7lf :Xa#wl8K4>"bSNC!iX?UɁE^[ˠB*@S}].(cIО(UaCШ_Z稡葧l^LyAcߥ_/,JR(8NmS`YA)Sӣ)Eͥa?͎-%",>$;my/H â~&ZAC%#'(C y%颦ȝHgа~vUcl 'g@k!In~ V`/W-te#nZQ酸sw0+kζŤ5b ?X,E|OG)HT"× v˩~۾wjeY$|ʓxcpJP ToCe  Vpܱ{m0ϵNeXq*o=*2 zh7n!),MKC]C8 BxHhjjb$`|@\nC`utJΟRmX[L50 Vk5M64H_VD 4@AR$+x,b(Q쏙T%͍@4[:3޿m=og%?x#.au_jG6tR"bB{i:ھsU?%~FdddW"X6"#L͑[M6ïIs>mxŸwx`lɉT!xw;AS!wG=eub/%W  vB"P/ #׿a`)(i P3[8qX#fdn+xPc"hޒ%X2RW#3,*?PobICI,T>&10e 7ewΔDCDXavuX:okoY+SفjKoĞLȷJı2ONާ႗LJ~>-ϳs- Kk4DC؃-ЉM|fSIJ9`1((8D@ [PG\C+nsdGm=uSi=;i?Z82i0X%LΟc1>*V5'5uGfWvsNuNۥ B9 /,2<@bE¿P1y(d$ͧ&ڠ! /uWoB fbwWuM" Yaޢ& [~F|ID.ɍp 1/#)ߠ%A[NQ2tCI@$aclyѡz5?YEzw;7Hnwi0W(+ ίL6 b`JAy4?i%nk ecHN{u{"cb4P=o -gXVtF^ _:>kuu9F%B-r_z2B$,!G6諻ֿ'F&p̳ާf,=n+i_TM @ G2IH[jfblÙ/;6M`O[ώjN-X4gOYnv" Gl.;-!'rQ7T "M٫'砪t%e/ /L'&ƻNԋ]%9- =)f}2$Z*Xhj|(a30; W$B M

c v%$.iC\v PmYc qw}*H4lSq ~h_dJh#Q8ɢ g-YO~.!~OP,$H`#H7P 3͠'Cu$?YE?nRw[T= HF>jA`}qY,DH< wEj?YUQ2gǒ\~(V5kH9כs:kd^%2Hj+jJ+*"; ^'#n(rKSaA(E8a,"^cXN&HH/_;$h㣠5jqɹ ~ķ F%\(w B~09ڌ " "UӥRqɃN*,ZK(~-\/=1!Eӓ!o-=P $n6X:F,Vjy[:QI."لW$f 11?k2xe㤗߹_(Wٴ鰆wŐ}DRS2NQ.buyF;=q Q  N^p6moVu..&0puLs͌VTu No@BYD:}<*^iٲd2NGV}>+E4}H 0ۋ_OD7"(l87/Gmn7wT-DDS@.\!KgZjFLOMBe._qobYIu}#חx"#L 1M~;iʫ$> x ,YxOuVm»V'V! @Oz \⵱]3U p-)WQZ2OvɁ&Dm{0sƉƕ˞`ɧ~gV[S4q4=P *tm ?K](ޱW1۞V+5{_<&Ԯ8Sæ^[nrnu1x3)i7YTdyI.ݠYvu_st.[s7DiMi2a2=K?,W$QV!9.7A~-cWom4 @qң$eߤ)1)YFg'nG~PaM5,OMKʧ.τ &80⛨Y{VXd m\gMRM:l&n8|)|~0(bC"4;c>wV6%+f*lo2/{fKc*_Ka.$dV7K C{fe=s7~6m9ƵUY,c&ʮm٢2l&]D?ʞ=ࣱкaʸF?dYRwğŷy݊$qeŠߵ,2%*LJt,Z$Tq-&J TA#"LWq,B: O^j&4Ѕ`v0z,v Ys42.f {Z^&ֱm*/p?itflbEIV}Lr2&O3.{˜4^: cM>J\./Z`"}#86[K_huZПq1g 6J֣֕DwRKBoT|5eo-J֊-1þ 2"C7j;Ojnl ʋtmv1on'XdD⌮-T6i`ĉ*'Fd1T(:\9Wr"F+(RvCϹ>>0 z%^ ףV'-=1}{VC?q%Dg~U_Wњ*CA5zo>aE wrTыd8L]@}(U'+>F"c{ucȷ.,ʓk4WOpe ZyF+ #ϊ[".4tR"[O#`G9&m҉IڏsD` NGP7p-4p>rϼ\9Ilb&ZHUdYC[6^/6= DGg'7`] \oD M¤EO,me$'%`Tu꿕j_#R!/jLor2 O1vE?/8jȣ)"!KW逐&9$"} %{RdnrRy'Ut c2=GgWG@b+%yi7d41?+4m,WUr2PvkB uÖi"%R7ٳ5l^hBݻEXgt@ מ(W2<- E޻n<*1fr3,7bxtz:Mo-!a듼tNrs5ώ" &s\lJv??b+M9|o3čϓ3zIK)k-˃U,5Y &oH5HaI"9B >IOl{10(y0NԌ@( @WAóĕ 6_Zؐ@3C2g=@0W@V o}6{zӥhr#"̿og=5S[f @O|2{ܜaYG8_f'ly%}.yl"ٜ͓H R3s`W0( Q;G5>ew yN^FVugF0Z E9tZYDduzn`_nkD8diQW/XYHBY9.Igng7`eβʅЯ,=mэ\.c[֋=2J8+RG̤!#í#[ gjN7(,#27.rxTk\v(+ncqOKJxw3+D[f'8up2p&QzMbAi*oQ rB}!$-Xd 37n ]Q]h}\xSKw!/uy즇jݜRC5APf*G!%|42zYUיr$#Xw%j%!?ֈr9843k/wHFv]KERMo.͋ }jhd_/TUmSʒ;!G0C Q-*5t*Ҩ8dC"ctvZ/Sduŭ큅y4<j=aKo%*lx)leQ/'uBJ&ru'9'o$oj1ն 3T5Y^YA;JTÏZxV!R*^ ԣN M0V;Ԑ>1!18I 3C2GG~?7>ܒ"3 `:h+VMhH^f|nvT[9Wȫ@c[cV4hC֐XetYj99`f HxC 0cɇв/- S)num*X,]Ȭr4=pm0Rչ]"paϴ#T.q(ޓ$f[W"^X..Q׷Iằ'䛚+ߎ )GO M֠V [Ev\X1&rj 1ٓFzFX3 @OԿ*͋Sp{0 "(ak &4xzG? &m:$j|9v o c/0+ Z7IFlM@{ #X0*oT-|vL]c P~ZĔ+o}R˥TmcVքSxU`7ez#4pqX\cI0H5Y`y3u_E{i=KJsuNGOZM-YeM`m$otFif[ojtX z_=b $6Gh$+[e邘% tjѠMo+-uap ;B N8RdqʩkF`a nLa>/A1y]`!«[%zl5]8%^%3l_S6qt,QjfUBA&D|AS}p<᫰(cY||+ԿnlŠ!$"U4rڳA_rR\XwmPL]Xf2R'CD8 p/-WCH']qRcK'ԆlQg(N׫A\=~y 3q}m[)mFRҩX I% 쀣>rZ@~}'ezt9ܼ_k!jNd - ?uciFQ !:ֹ4 OUc%o4|͉\;J k[UJ8퀠] >k+͙F>5zgiK(9>t/94*n\-x߼ͬ4N$b6"M88{sf-Fzޏ7g- ,yI2Q T(o\ڦyI^s[ypA.XLL̾YsIU]Y7XT,&ayD;&A>eF 5c8}21l".HȦFe~ynQ_ǖv`8x89;gmg;{<3 ֜(+k}̼DJɸ!(\G.h"sA >쭫!H k gS?Uɻ˵[+3PY6a>' W!{z^r/>Š 5zFniF0lPA/zƵe8]SF:r8# YVx Wae1E{G 8APx.g1_I@h.-ȈP{$H\b[I[ǽx#u(cpЭbm!&FaX4`tS"5It0y8p^DpOH3+<1P֍f#s?>ciG*,%`N'Ji-u%o\0M iUt + EP[]Eq|~S1-R^2@Xi1i1T;7V:4=htQ*'e/L% 'I*;A=KuOFkHPj8 a*"bmQQH ?Ws"|[fSϙ= $p2ǵ ŷ3g8?/_A0 KqsKŹp)xe3k9G4ٛB;i*,ܾ/n?~-biˍ4`qxHl!ԯS'}Fwڦk S$#ج/x!X{Ae·УkW,*D+^?+-} M݈79Ie1GrN곷<$u]Z#qf}0Q/f}{>nm+uxi?awIk31GJȌ?eD6lj4o/|M")HZ8IqXb3Oz;) aA>aEw1f8M#\ZyPBE qC43}im7Gҹ`]!fO%:"C4m ) 3F9R+eMCL_7Qq$D&qkW2Ԟ&tbUΥ9w;I&l]J23J`'QƼ{y*nk ś@kU~';.HV KMRܳ7٥^*vh*}J}N`yQG]2@,;Wpa^"+޷J{&P8 `:XqRn{BmY,m%aW@.КTK ̠~W(%=kȓ~ լzXj&m`uSF2⻝"Dq>rcB=YіC5 q^gp tן{jczÚ:+9ݒ>{ʓiFІ!ݎsm^;ؑ}3H?F'^)jh#ʸr3a˿)Ԇf noyR~hqZ#ݬEq1?שWSo7e|ݾ8)y,]vK.bK Edrڇ5`O)x 9x# G:r!p6uAG?n9%zd`ށ$kGNmw;6K@@6_!O 6#pI~Mvx)hzT--@Y2V`q${ax&Pxbl5&ξ(rR#0n.G=] x!\ʹ?\o)ȄQ%B[zR ĐE ek0BU?$Ko^lܢD*0X9J}祝{ ,V*e%ao6 RGBţ!<[ߤbK|4IʕVz0F-bY]ZV> ;nYOҐR/E_}@_ iJ&7mOh߱/c&C;GoE$V Iª*'DusT*#Fd,Ih2N'VKLVH1b:o͞w"FJ8uC@92_a@"zs8K1(VGIO%va*Ǯ|WIMOǒLyڌ zp @,8R$Sg6u& Di`3c$ޫU$6GB~NHy!wj)i"9Z?YRr)VAx !̑~kpJ`y ӧW}}0I(t(=/1nfYu 2;GK=0#MnzO y,A=uQQr-_S"7I3&LIݙNQVʖ֚#IF>D*/Qx4磯Z׶ PA LmҢpW@kxcdw@R5sOۊۭgr lxɆ?ƺ!PzY XXс]էG_|dϠXLkH4(z43~>]aR=/Fǃ!ҋ>oЪ;' [0܇%Gz{ESPz]㠲*5[_/e< !yHpi-R qe_Q4.A:Q0] }]>h 詧0S)ekơT lSs!V*D>!mV>9aHK` u! fd55éΒݓ+|Pl|J[MMP3^S@v+\Pa 8 Sir??YSz~>VUYǐpt}=r/as̼P܄^O t*|[)v22/ h\/$n`:B“a> DHcr\icB& Sf7b=*+jD5U [N;%0OP/KPܵƕDyf_kL4Hk06> *wܰZz.&"cD@#gJmQkTM^ &М"<}A6I8EK%̈́/5Hڡ*t[omM䷝ERW`*c2EdDSDi闧 ʞ\cC[װCSX1G +yGI` Yp+,xJhY4kKiC׷o K}!^X=ݢK.yA`BV톩.H[eg4'#e_UBX4DJez(?0H Hh!X7;5Kv B GȘ}*ޙ#2S  sW+ P<E/r%$cFA޹/Y{c,]SUu5C!J Wlju(#}չ ER`4a>w6_-N* I}G2 `Yr%]JˏW`b|"Ԡx:;6d6l4?UZG!j@-)YxjȯtmN!1Wq$&za}kMmlt[ZoH@'o"_4H"O>+HurfQ hZ'Qc=Ŝ|;ɢ.ղXCZ.UQ$ qb9c ۮ^tb'2MO_? fIůtZ4َ7BoQy>}}wR ؿa[^fXro3Cd-!-K͕[_7&f6k^+E|]}J0t *LLYq &r_{q_gvk,CJJA8h«aKVf?.]k?PYM5#dh 1ȗNpϤX/yt`L$鋦n'o#ȟ*3sٕV0a3U eypLR8_N0f=[).8.ی*qdlDh*m y+ ==7֭ BzE#8wU069L1'7  IW@]w8?n_&7- HYlRdwjrއbiS2vV%a>^&G K"tG>~T@+Zlzi2!|åkzshǙ[Gccjs/N#]S6!ꇘ/CA_?EBboF!Y>6LIYuHzkBuR}ܴ2Qd,5ϯsœɤvjHnlOR\x󀑪 Մwjstn0ωN&neDNi*|۟@iwH߭bH!.=oGMkQLjxh~.@ Uj%1me{`1/\ʺӔ%^{p)%Oʼ>!lazeE)U4#[fh45.* їBy8qGhH{٦jQ pdJe%+Ӱ}96|; Q m4tuq]7.ɱda]5]Riy6@50bb |143hmE!Z&c1KLrE`!vKְoni0<3wIN(Ɉn>j, j!>nJ.YEA o GwVlOڑGړ5.?mdR.;=Rβp)ebuO)dT~[}OV>b0W,p\#ɲ+&kHB/ݘ3;K"sQsh蝉g{X [0Ev|kC!:Fb>j9R.D19$;v~*{j9(;8AENXܟÿl}Xsc ;UZr-ZO> ^ 4S)%886DI"-o@Jg[;7):]}^'^z30H~[ & oFŽ©?jbbTEp+-yjHы]Kdn4~\JŸpm=a*VG}*-: ABF(Yhxg SV '9be/TIcNV .Y AqG6 \MzAփzzt8?tRS#,,w`x3AnrGXT ?m7Oշ|+PEq=^;ls*?}%!(Syh,jpZ)m|U=&L,S' e[B{"k1Ia?;s=bK= EAu356Acpm덷-/*OgUmqpxCjץaX&RWz՚kj<.!17BJYj*8^G U`cVX-ͿN Wdx][r+qfr UE}.-;706F#NB6KJ]l%m(ҳk xl?(ϳ? Fm\gMYΞG^^5Q`54cـV_ |WNtQ_.HZ #Ƒ;15Ah 2n:>(QިbP4BӤGwՇN$x{dzdI%/dAT`39o'VwV1+w i17#>ne'2&F+zW;`U%%Cٛ,~yi(u6Ik$'e\ 3LQ_TԻ(U$$G2a1#6tIpqaEs>槬JIEgrhS 2MvH@h4Ưm2Wv7F/Gl<',0yj_|G&eh"ɵ-CNgՈ%ύR<) }sveao3x!CBwt  EQ]& ss7|㪲ٻ蹈ӽ%E s 3 zsmyIuÒ~s`+sZKvv ٥+= ,.l5`:\R#Gjcc,'9Z^X+g3B1Ѳo_ #N{ 橊rg,?/(rF(hUnej[,>{E! BIsJoF&Nٕ׷ھơz UNzh/Ϥ إ!| xaheC 4ԢI]'<3N6#ܡ=p1߭I.ݦt<oemGl0U5Ԋ3&X砚h-=!x?)p|w2:/KrvM cGrAP`,\];.!Ž~(H:#fitpw SU[8uYBޖo9:^INϦgyBhi W*&;XwJ A8˼r>*CQ_b%5o=VE54\?OŰWWVfqhI,YE=Uq!dxHsQ-Z[jN 67)y9Z:'Sь"02;^p8, ZW_=fL ]\bo/ix ~ӥ$x1r'-h~{Sb7i8+唘;LSJս1ca$ m;/n= y>V-'ղa| `!vIѩ["%1$NΆ{!T9>ӥ֌onAܒ6 Ms(6[/;_*0Ҳ ߮}ؕYB&J^J_ӗ])OM^[_$ c\矢هP<XB<#gC2K" KS\4?U҅xJrkH{*W'/ίa )t]y=JBݷrF-878)" 0MF\NMkip~4g1XK.j-9(u kRg-ASK>}DjDtyPΔvNsoTK{-a3ApYF5 AmpkX 5, IžXMy0p5PXb7eRԉUa-OAS3x)xDҹF4ˁ|~׮ H8fD||wϜZvsyFH&Oq5zB:7ӊbݟa"=*r Bro^2mvD7SU\B *g5_Qg))Mrآ¦We3ׇ|.6I,}Yʛxb5raBv!˺x 2H7BeuJȆ'RUT&NlL#LL,KC}̓\P6aKλTU@H(`|grޯҸίWƆ'OEr(nD$Gy3Q nx6z@wڨ"}+z}bb~sFIP ?2۾GJ7qRL-RK>Eқk7CGTi xˆ9MJ3I UGg,?-&TwQ: 8$; {Bp--F1 YOØ,sXoCL|,B1e1mߠo||%;g3f RČ o /blaՆ }8ZmIֱnK|:g_Ǎ4ͥkpDGtgym<*~vY6 :GK3TƁam$-QK9fO=h_h=Kpڱ9JA9*b׃lӻYisa5-y-Na{°me"oEo{&ƭ]/bvWyjȒ0מc) ի`I3”I 9\bo/u 5H1ԀRdqֳ6.No= +6$m2tVl/кm"!.}20JS GߞT8 v 'h5^חC_9?iI>Ҩu⃪筺7- ,8IB]+֓Oy٤1ڣG5xDZy܂?B;uK=CR+ B <ʫ"D QhF6b=SKql,w8]֧=<='6#)SUM NCQH[MVmr;m0p`U<1?/k8/dL]EaP/kQK79T|d1'dRvɽJ&WGϦYm+рNa]7hAm\5XtJ\%֊irSȹTI#d.KxT4#ːKńM&Mu0ݼhk4~5V9Kt[@vy8,"fa\Cn|rn g~i~- (tH^@5 QA.5 2ScwwTlցNjI<#˶N\!NW2Wh+RԸ=F5*2Lj}^0۵Fnd`Ѹ]BgF 3:s-#~~+ܝ9q@ZUY,t¿KV%}J>q-t:>@.غ@LL}8GH͓T9Ahb:\7pX| hhV>%B, Nk\k٤ҧ*sL!@A9Y!T8F@%r=խn̵ 27{I$w7> p.k=􌇀<Āx7_1!9xE3ͫ0#<b!8 w?2{VG$EvJ2E~b#dFKL$i|檾Prky~Œ ӰvYW+~_°tʢ;pˬMeDm%IQ柳5T6Pv! pwGֺt>,:]Vv[[xSP" [&Ɋ.dn_ZwSPvxg5#&.GxZۭ<0D< o'}hA i-cmC'Ԙ(ȃDlR=wj-jb(ȷɊ&;+@+􄆻Ihf<#bL:l!ԍ0Z7dio+:iQ+DIgQze|g M"c6ÑN>pAwvt vHn w,aDU# dO[ҍDߢE2RzfߥLD ! ]+& f]:Jox&ȸ_I; fY^YHb${߼4}B%N6Y-K<ܯ8X]%7Ӡ" oE Z~z"qFVSlP6;KL_a= @xvy(Q%QIۓTwr'4hfqU⹙ܸ°g52z o<'>A[PքKr *)K H>XsVo*8sZU$"3Vf!Zr0VLb߁14Kf8fQRHu!%Jٿ77f" 15b̗\B_IQNy',bI^WV8|K7_tȂdrwA²8CO.$"0%*jvx /H31Cq͑;P`丶!B%_(ְ_d`rKj^ZnTy?dam+&cs%!On]0A/k2/ }gY]X0g.3wgs]XqܛUCR[Q!\fkXk7z3SQI]c/d"E!8w IMlRaO6@ "g#4N$Pf(MHvj('ƓQDwrvmHpY0fEȖ#v{DY0J*X"Ҙ9@xhK|z|2=(GA yEfJml$CfJ=$V=Astv&̝ 7{i)zt7.c4 ` ػN4+fu6N[ÿnϸSPmjr٨m4N>JۮcQU'xh I]k6$.|ŅZ4o7hjJ53o?2x7=3 *NT !iݠ]SՖL}rX \ҁyP r{%Pؾڈfh^l"5tS:]C#t̎i6W WRÄ-.FR!BF~N1=\< ۇ+ǧK=v Y NL, TvO0sˤzʽtR_YLoP0H`ό`^w \${?~:9` n累 =nꩾS:g=04(mݏa-OsNJ ʺ/.a-"z }mKsށ-ɀ cژo ř~qhK7(:ssE8X?>+2}sl4ȹʁu[[d)@&X )u0W,Q>'rfxJ]E [oѱNp5mfwNU\"2^+*=nV]ĔXOJB^41~ܦ٫rH5K-y;+],U_i{j|O'?gԎ`E M{:Ҵy5VU$%0A0YXsɌ˿,/CHM%@™uHBuF X\[i1a_sD+I$Z#ΐ҂~8B-N_ @DuA4o{j6pd{9 m+ ALD?%-^6 #s^?Bsoxg {+O"0)UX@regQ`bW%vKصW JɚWe WCOpIёDi@93O9m_ tbWw&Nj|l#ڄg3Y7#Hzx1g?5}-Urtre@s~ w͓R 7GeØvkZV;β &7_kݝ !-*$ {8c+JҾjJX]!dA-D]33ފD!b\N6zfK[8ӌd' g݆oOϖVFz3/F ޽]Yy'C%]xq쉐KHc t$򊣝.@1~rq*^͟=!' 'ĥ5XNg` >Ć&u*],IBrA ut0xłND! L~^D)7)HNOyK-֕Gy8FkoYL0,V`"HL+px|`ݜ<"X"Xc|v2kX:seėt,v\DJ/ TWxdకAyB@r:-(Ut5p&mK[E@ӯj)!,kSC5iD6}+V-V'deKMECi\;ǒZ0V ly@b*mW mUB”)NEs'־ݭ&kz~+B1?V48 !)қDhLzԋВ{a=iVd oq'{`t[kVq\b"*˝̀B[vd1㐚|kEnFFlO;mol<϶*濟(NfA]FR)2 GwqyX 0< fA_\n=jle+Ӈb35ṅs#$q(6sU!M;L>bR>aҖaѢ3':Ղ܊d{kYңcYa;PݭEm5's}WZ2eaaHаɁ]#BAu-&s^55Ӯ.nK=_-=ெ?r],+'BŹ&әp)8F- k`W {BφUTH[=e/Sv~9n ][J)BCV9daZZ|Y2ZxW-N,rnh" FGQ*<9]3<wxj_zaZ[B%cS'B07 >ioMSi4s"H2&(ؓՕ>P{CH䬨m>ȳ}LLFjT=B |;@31ևbP5 ):ns>ni'\h~~peOE>W 9q[CϠt-n2-VKP`&_ByCR4G2$IO? CW/yRf̣9GwL]<2nBDSdeij@^ [CxˬѪ]Ћ[=|%_g9=AN/Kƣ;yʓg|NǼ1DȔFAfiZD,쪄mqvª|ŀGJa1-to{ԁVruL >j'./H=v&o59:Ťزq@%@1CNpDř1{=\V@~9}椈!1d66hL+fN(7/1߅JaO$mB2'dhJTxj$XS-SG,JVα.9px.I> F (, ԞZ7k^I&Lq38"[8%c] ` ±;a#:( BJ1W[%I̡m`Io臜FG^1C&q9U3D.Bvuqu8AѶNnLr4]/ 齪ٯ&ޣt;Y-_Rx(\X}PwCw#6G}]J5 4:fײ%t!)/C>n_N5mze'X׶g'֕`pZ[xɈѫA$Nd/gx-VػV@';D &aZ<͙u*A4' $!cZ* Qn^zO_؈DÊs^<]ҹMNՑRKpzAr~'*+(p["inTZFZC|Xh-*rM$S$Zcw߄qF6v4D+_8<< HMLw95; F,y{x΍f?4D'fmFubW8X舔U$liڿ1{n,hQ&ǹvqj8q]B]Io6 HgteBcK]Σv*SHfY>du3نP!H- %ymM2]e73BK!.Qp]8 Q`PF fgnznkHGĘSWZF+qЂN5V=GHJ_6tCG%[}{@k˄쬣EG/HYZij( 5IR1qnTm'-c}΁D1$WR,%Uysg m(pNBr;yF!٢ SѸA=P$8gn )v;1$Um+炕~)!.6#^%t|U5>q0/WX XR{Zjp>İ6d',OD}$!7JBkb'`TP`\?^0i,$guUċ*ui=:w[Uy>]Uv rRKnRmV#ٲ$FՠmWy>hz=š_{ͤRAҪaQ]i1a?V|f;/Ժm*&Tߦ0+oK_GWUQe>~IxPwShdJGʋm.Ji[z/A0VJ_&/1M*bnSy+C?#$?nS.mJB[bJB3m|b~厈@F.Ho-Oz|_v![6(re^ #շ)c80uu^f 兽qmR- N/oַtǮ@~ zjDj|2atoQ>=7 Ig.+E+bąjʫߥĔ( fVTvT6B||5-I݆k.z޴x5O}c$3ubr,2tJnKj ӊ(|i-:/&W纕L8)"pvOv:]&v *!yvuM< dK)'W3]au |RK 2KPgU6g9<Csi5pLY M2*JuWvÈ=v-tA4 y/11ZՆꮱaāJdn[X"e4~Cѐu3A{wx9y擔c`؇2[5"R8YiK9n;f"Ϟta%@Z&JQs˯ 7tY^CBTwZ\~ دOÁ%Ii/=WBYx6s'_yz66C4ʼ[jh G^K'sa4.<t&-]<7)Cf F ڊ+ *!ʺxġT,n;E\_deu0zMb>|fXD Ά9 *) Ry){6&WO^\M`Ț湏c +KW6/zZ1 Y`nN/q׫}C+yoCĘT6V~jx#Z 3gaX>lF6̮$|LY mF4׽OcQ$1 ,D&gݼ qJ9/PBP<7Gpog&& .qj9 5b$wX[ޯ£ۏRt>❅U1'I-mV tvĭljOBd'5(7R|ժ)0јq4%RqhLj@xdN]ڮz7\ SݰR bw`ߨoFSu6}ɍr]tp1_Ki<hG"몷u;L5<$T K/_YoWwO7T͈}m}bꝒh/xBuZ-9D6OH?A /1x_i򃬓`޸PHF3p?Y~҈Y ^ElYpثQ ڈVX5ԥPy;L_Q@?=3 ßGNp65=IY=WY0ac7zrfӇb˼]AMzW[D]y+|ťPOW'V U@MAџv *kVaWہ$u2 +a =IK jofs%c.NvَM4\1? =I.D" 4l~o {@%jwkQB{xmxM7<ϞWwhn>V;8K)S~] Ƈ0G~ o/禜 `ď?{ĝ JkkID֎,[Ė))Ԝi]%Lٚ?9$gxHgn ZsQٱ$q9_M q?W%QڔX\X{N8c+>[&AE][;+rN\c./xM'M;XbGBy|LX]JKسg=p|Ih#:xLʕ, c̗gC ]2IEk>㰦 $'Yr%\EkKù;`d'4aP-̒#nlj&;]j.u&wYW>)b{Ζ³#goVqvt,>(`3y*< _]~>yyZbl+|L u\~AZh7 }VNz9?ΌSC ȡX5/o{<4"Y[tהL'̶ + ^QH+drZ(c3c@Kt!4`PLzH2+T+dD:ٞYU>uv_Z/5}zFL7-i]Qd ܠFbI{S lƎ]ż "o3+2[' E8cnTKjdnҘþ `W d}&]o:Iˢ\}Ǟ {5% -b+~Cx7ҧPu^Ħٝx8:z8/mV?t B+fBfQLV J0FYe)K1dc?ܚ_T7Kn:N?jdXy[(?+i_2]_YT[gTam-˗BD\ݔ}ҧ̹Wx QUi(&.gg']\'h:iWMkqT w£2`y+2?Z8 &Uw?a 天K8Ìqv9TSF^p\m|aWc2i"EB7H)95U Gp¹:p==|p ΢ח`r^_5t<ұjK`8 @,& \wͫhu!'@f7#ÏUN7&4rRRoMB^1<ڼKQLE{%'`/#:x}4 YP,gwJVIGV h,O nZ"?3 ؋e E_şכpevŴk=ߐ1EV9t6%Bs`{8Ic !aa1S`*B6*p?jXt1![m7+}vܹ.Emӟ,^׮w ߊg|ߡ?_p׻'cxX';{|TZ/3 jrhB:D Hd$֩8#c"ӑ.GBJ+Xhx!T^a227Klb;~Ö#ۺ5*˘zЀŨAy=72ZIH|B0'Ca̋i,2 Yr]2~ǼB؅2Vo݋WuY^B~gmq<u<{V-}GYu7Q)^"߈`ʋ[ݏK~!m4v%.8*ކ!wFi&R;.FOGpHtbKE(I7$FfA[0v2YRPXL˟:X[ }x,S>f9=c"5uHly.r}.4/)෽\}MAC?~#Afy|i1+ Uf6!Xݬ%qv=P8 {{bd#{*,~aWԠB[ITbgv( <-$ U^.VK<+@@u\5(̵OX؄1fmG -( L`i %F~DGjK ?.voDLB˧_B󲰃?Hzgl<΂t?"wyTIibm4|59+q-¦>1g#bAIB3u8F4 2iZ1jte7 ㍿w Vnt)4\HMd7hY& kJܨS,_:Rt4p\/K i0#1zc8K:,`׆42>Q/*Ms!?WT(7'SIad.L|v҃;MgZ!D^"xndhR Z wV%Y|'GadkrӾ4AQU.)Тb/ER\$9 ǺlKuJ_u>3>פ?1JNA?1 gRwbtPL/5ԿoV[i#樓߸4m= DyL|"S~.uZCah8WlIO)& ^bmZ | ݢv޸=R8;|rugvBLMھĢ:9V< &E.&LF$ !ffW?D=uG=/^ΌXYƘZc. ΓhsU $0qxST3Ec]" 5)n 1ٟ d팢ZFwC\W,ܓHl}nf%ZЊFt3> OM49,)&+mcS~ec\ڋèOUѣ֖ic;f_xT!BPݑ,K˞fgǪo1CV#65n(vPV99lC՗c VH98zKf>?wcPWY&Tn 7Hn}MX|(T\z_QUY\eeJ"s/RݚV[恛A jIvDGNRwzֺЖ ֏yACxORgV;uU QO;q5gC<9m 4%H:I݌ \ojaR9ET-iţlBlP6C"̓tG+>@|2υn7=.m!IiA(3Cs@)lF3cR H4"X uBdPq3 Ȁ䋶$l|걥DbOFs"8jBӽ+EF3oA3?ESCGD)XuM1^{9 ,8W6 08i]DhЕS)T_UFS j [.4Qe&?_|KqrcP#ꅴA؞-`ĐD҃#2p_7HSmxvE~6o0 it̴Ʒ (;I7`eF5} suak'}Qnoġcȱ@&jTa n4pO%xY w#dm9WGuMŕ*UKsg[O8"dF)J P>["-~qZ jQ|̻?bѓ0@{kU܁\.c_w ?93Ͻ`(~&H>ElG5&3eB~X {rh‹ #5;*0G>A'jՉHP:@VXsoe5]C6Rqʌ< E iQ-s ΚDDqQGжEIIQQ?^lT")C#/D;O"b1Sev G>()eEb""$1;A90Zx8s aMo۴.Mt#<׿٨tKy-bO#P,{qlߋ2r<"eAUG%|# ,2 ƻ9f[3eNDT6oi<9 s0X~=LD*1H1|j,%iH!|wgqN\@ǹ l48Ag6#`67X􉃅k(ϑ=AgR>Wx h-I%S2$W'x=i7ݼ=Wa^P| QFA2C zsa_&֥hm"z% 9,ox됏e=i79Lz| *0ſ⽜A]c@\t{Fs;*z,G1X$f )D<l@N@lCn"3gILu"fx|)r\tg,h#;iy.z *2}A; F7L-y5яm92u}3otivHtJݔyhW!U T*֒5$OqE'Y>{v8AJev0GDaycqJGJVA(k?Ժ@0K$mTi#$PcQx&/W1@%,\3G[Y%osPϱc(*|P+~{ @4ᝡ3T#L C\B &e]i;hDGvZŗZ)Q, Y"V-r[ziVqwwmKQru[C]{3qЈ.Mp$J5uRyDt!V ag@k:%6V-wK>XA׾c^Ya:K,u,%(;'qEh( ):řK~ amb>{>P+"IJ~Hu3gVj{!ުU0کHvS-JV@ d( <:< %FW1wt|sRHE'?+E]^?X1,4ٖPVHfv"cA"3R}Էeb|:|ʧOs'Db?"i*鼰@%7pI*E?@~h{*b3 #:Q,HeLy&ӋˆȶU U X +Lj`3hkl5Q~,u0=?P<\R_ gLE$XquP][#'\yF)2j[tmi-gNACyNC0D=ޠ;O q iCvdy%-;Kur뮡y1T"ću(<i"B]\1~Fb=X?|Ar T\Υ`aq܈4 QWJ.{¢o ]U)nYضndcF~YXM믅5}e!@, %E{+R r?T#`O2 RF2CZGX{5+ KLvNSz[n&`N $"zJ7dO5$!IYwj>fY?^YKAe98EE_80nqYKH-K*uv͌|$E7^Druw{v{^H\73˞  if2G;rh)UԩG5x(-薄tveeZSsVb@m]d! @hBlX_hGD䝦μIn_$+tҫW\Bߌ/aHwNqik%P_&v%6'Z[|H&kz#WY}lA Niy2ᑰn-4f Hx4m^Ь&Q7s7#?ilJo(ŠnFٯ"{0Ȇg[xaK_!9/}ZK Y/UEv5vPd49^$j}L5Kǒz09v?@o,:=ѠuNsW#!uRw3{LEkj1u=2ʭz%ףI "Ęnĵ-.̲2NAXLL^A[ZZ2א)q0Ih>,@vz?nR dFNj(_8 ȾP,M4,]ayK5B(\T0FɈd7)igjJbf&WF@g+1ëtoNKC"xy1/?gYTVIn_w'o~ _TN$WPf@q\Wt-n[ wGL~|.9zY82rT'zy hSZOD!LdO/Bw%>E%Y,e6zuڞO S {wq@?M5wx]bCLFۂa(Q! . GFcd0. ު~Mĉ{7\IMN]K8BhXd{uZv BO 6E{?Ab[ ef\۟dڱ&lALUM5{P? u({gDw *4@R&Ck.B#" QeE7\e#4Y#ȘdC YwZ=v|&"vPg=>-/3y: d^Gzrvji#EQL9‹]avJE9xdB` %fEbCOjIvVzsA3mA̜[Fu3PJc̲.X# Q !nVQ7*g(ݦ%D"˦AAX|#_oڬ;ܽY>G7zJP(_PAm(TnLVBD&1J:Dp6x)U'k~-̴n&ɤ}mƨ۳&LuN^d2Q&E` ?ks0E/pY{21Un* .1~w' T-1,̹M;/}X 1bUl.sF(Ta*ZUꀰ挋gWcI ْiYeߴXZOteYqq%YM$a Zί svH$VՏn%y?Q uTJV( KfGiki#rtuxP ] !K+"~9 /H΅q czevި @ (t4g/sm_p <IP]].ѧ|ܡ1,}M +v*H'qXB-Ff/zW]y90N C/`k_K?<8͊3^>Yf~X}u~郓\Gڿ@6,#1u 6)IC~D&Ŝ8Dۈ\Wkpܙ0nFpuߔJ8QvUe-OB\ή*pXJ}B!}0/j|gd# fBxEX ӛn'ۑHTU1x*"Q\DRWdNAȻ fKM况Fp>x7:D7Z~:c>N\TjL5oT ]8w$^_L'ݵ>!`gY"cc^( NY1Yڒp؅S=/NT!ۨI޵jM o62d Ys]HַV%;kƕN),ƲJTWbF(E8>{q-F֧3 2RJϲw0tjXbl217S FMV̢*,jU#B4>YFHTop<*C텂bqEH4>.=p̓lqRV"1$S#,\>cFZwZyU|kKZW{?tzBv)%}h8>ax Q`uΚZI"l"8hfw3U-kW<ٲ>nX#3"Jףj~9Vm TQt{d [Q_z>^>u[s*G;MNpHo-V>akC; fmp[Q,17fkХԐ=Xghj3B!Ȳ`~TۛeFq`o aǡhb$o* k+~s:;}=T Տ2Ξ']5~79u+*tO=LIu٫0aUkiďgݹI 0sgِƶݨ=!֡%o7BWW>+Ѡت~.tȨ'{UU%eVϽ)0o&D 9)͆z]X"cTsnގqA3:-LE;e_#AIo-x3:\ _>dž1䙂ui)S–!Հ34PzDc߳#Y{7){ONi j\_ RKzGUT &؊\'1;L؊y7pq] +Czb%Z\Tx 5~~0- |Y ΉGRpe;c`̾tP9T_QV&ǍE[ ŽAz +[N L%WO nI3X"F=lAj8Ĭ.sy4&^Y\ 4w-I%#m}3zm0:bz ^h-sV:P&5gp| ϋ }2}'}׍C+Bw=PHյAmY24nSfئw-~'u`:#<20ԠrY' Domd WnگivH'>x=ny\3y{$0\un*WHQKND5PC0PB]}`<^|Poԥ;pyťR> ~'1wcZYwr<ګRۍ W)0%d^Sv Pzrѓz27 .59geWu˿[Ȩ6OanJ n'+>+ku\[7xc I<ΫߵemQRJU 'CM$?u&KgʌyΖN~cC;tX|hh1 #,qoi /z%y;g&ǁUkcV{{%Mfy\b+K  2=)|/bv ?HJ*L0|Ƿ|ޠ#zd^7U[Ѽ/Br U`]0G^˸ ,<C݌{聅`A929Pa }@Wz<̓` (|%a%2#c=.<ʍ6]Нz0 h{ׯuDhĿCô࡙$0!OÀ9X]]t9uVCPX vrs;g.x7S?WNjtIʑh`UjP'N/LjaW [ݫ0Rv!  h|:TriĔ/N1.K!:2|kÌzIhER#Y K$p2o;;9hrUZO*([sy9鑟-?y}=?g}^2@CTCƇ3/Ҩi[QeT#PC^zJř`TچJ$C̒I&33ev_F'dJX(KV"ΎNCNYpx;u] ̡kKQK 7qoĀKb;b e`$j~~CkpFe('7@O7K~%8NUwQ\p :0&.toȜWd?3VU u$#jҨtgib ěy$'_:z_Et 5_{KuPǨuS*n8I7,M[4*aeVӨkFgSv rZSx܍M%+(SHD_׾oZٔ 6Xp@j?NUwDrb?|`#Mj'BFKUK5rw˟`tVA+[2S1Ll]I^Bd\$i?_pX42Q;: |*Bʡ \ǐل1VRb_%voOd}%/H4Vϝ[8xA' ع,ehBy}W,Fq:QdE-"Le@_py=Bp[fr'a"jl1'MԜ 5XGFh78+K*MiDJy~*v.ݻA|ʥ}R(P/i "TV܁@M8BAMzn,P%j1dY!OX'zo 6cҲӭ%W[K뛣#,Tx1!OEq_/FϨQ`PtCi/Vu'\ yh'bXs; z7a858"ݔi0i2EI`7#!b)Ks=љm;`- &-3GҦ9x^rl/Ӕbkd#1M1@NO+'R WHUm{҇]BzHX䈮ao0MK`IkaV8tg>Fs+w*=8Z >4|xiQZ6 b8㐲VɕYә5eh[H"+vMuV6FՀB6|fGU޹<wi;ݶO?}_QhskB"M'*IK5s0LMJ0t9y%tz;>׻#b鼗,ϝW_W*[>Nc0_B/EMת+*M%+Fۅ\N៉s>"icc>.5ZyNgMhE,_VBX[s. 8yeVMe{8 _\DI(s8i0h?_bU*ݸD [ĵˌRqz:o7D4mT VS5EP8,SCa]u[p"sI}hv*f>4(8GY&n!ock@ 8?_,ywR7ni$Њvau{ o2Z+qJOYQ!6:"t3Mf,A*6/DQIVf60`X!Ȋg(ϗ{ƥ1bv;7Lv9*V!ÄkV1&.J:Rki&.5<<=NJD)F$\2L4yҖZf#J6~#[W>1ؽ}Vgبs{CZD|/{ʎ$gA+#rfc3Eƭd HQO*?"saIQz;_c?ω<{*Ⅳa\% rUs-=S#MnBe55̓\.A'^, 1-b߮% /ߓRmKn;}Z3fp`ʇrwyKآC>=y)I*jK uueH˗(U.(C1C}ı7wx+hL̅=zW~`e{]97),v TSVOE ;4\&ѼG<@,лOGiNcY'*T;'@=|[\w cه^ -R@/yl0w_f(dO<5weP?%9cbj'n\Ҟtvo6M1`O\^ZT;$ǛSy3dJ5HV.~lr=W[:3˺ R1|EMOL#Ou?R>y:6up:L-xSץ6k2VW,حujX4{Q&Z6I)+TW  _hX'!V:#[9^n%x,2:k}om"IN)ano̓c-l98Ȼd[$ciμ)1:2Ê`B3 uuD6{Qˡ1xhĮy8tze<Ҿlth1炙#&PvPʐKD@4Q ޷\HA2Ӣt{|nK4A-=eYv`\mcD[qK۳wUQbʹفdY:N#㑌۞?*[؝ʃA8.߁\ cYٖ(W_?F4+6BW~ڋrS/f{j"qDzB0sfLT7G'5N0ǔl%9 Gbkt=v Ż0^:VfM1]u\U6T;HG/8ӻl715i]>?ȾX&Wџ=c{|xuX8n K^J H`TbCf 6#N:-|az} k7b;wo!j(4dNa`Y&0U_bj5qwܰp2V>B\)` N;ב2|H#J(iIr2| vϰ,S:.)m)RH6ǧY>\88sFӊ\}q9#Y vWC &ZRv.5 ^ VM=diVHzZmuK)u9C7 S2KR';0nTi7Aֺ,gxqd)MqJ;W`q,ꇕ-g%0H R{[N%-pC@| R3p%.2ِ/ÏH_+ᛂX2u"`,٪K7>k oMB^O a ZWs%6-)xS!@I&Iks^ /kVO{ZwC9lL <[F#!H<Tsǣ抃&buʈ?chMk }37|G?'CPt{fv?@%:^ ,ChyWXt7x C%V3ao ?O3o+x!QNq mwq5fNgxEiʠpVaa|.= @)uÛX^O"Lc]EPy)k#fQim'3:Jc9 O#ԫثx/v7/H`XΝ**њqrܰ2ם9v$3Ẇ{#N\(zi#yrYܰq~\zNkO0Hvwt,'=/'35G 2qub(%8?8@"!}ЬED׵TYя%=" cؾǶw)*g=F :1)89#~\=PBB CD=N,u%h\~%);:%I>"Rt &VKYV, =%)NVAJ x%/4L1tAW8jN:% +3yh>$kjU#xh k{>aQ}.B{}a'tHc+7'^ @skPl-P*Mkwe_q@8p8F^-k ۥ3)KߓӇa. ZKwNj7bzŽD3BI1 i!u\uE qwQJA?un:-G9زUEKt,a5OLJt&@o늘z[Áem>v)=na#0s@."ևL5aQ?"W kؼ=1[_Sk)}3Y<=.0¨S̓ձƝ\۸[4܌\B1|fi^]xPdO4 :_m rwb=ȘBfئ MLjXz{(,~icfDn4"J2π+ɷeW=#`]BVO88J8ŧH˾ 8?eŃ$3R᪸˽ɢqBtrK7MÑQۍ3mLZOVz)2x{(NQfFƏbmBRJrNt̨jx򻙯# ׺D\ t%T $ў\,|ߐަRhe왕 *2j2z$݃sgq't^soKd`i'(rtTTN/P~@!bx#ɜ1ooZQ9SUuw Y"Zw[BGPPv?2*j_Yq0?oIW#d u79ِAUUcFmX;!lpֿРi; 9 c`.8*N/Կ!-hiTTO}86MA2Ou1$?Fcc`/IF (M41'}W*#OT.Pw;He80<0TsۜhTNCf^DezIG1'V ]VWkv,bYʰxe֖wlZ 5檇xFƁYvxo&`MnI[j& <6L|&`Tn[ V=b{xAj:oΑLK_R|U `G Y@w@mkVcS vߐƙ9$W l 1"t\@RTUdpq+t6%m{ZM njAіɽ="R2Q̶QaWi('lPv.WB:^&yQFi{JP^O-Pe^zə7$_ 1åQK(q[_;r yѲ&4y=iRQP |Mu6a qsywXUiS^\#S^浀evYװj,YR%Aܝ=\vzlMnI19QV-j TNE5.|z*T;ձg>:TKuƌۭ-<n I/}0M*%&D<!@/ss9 V|ޓ6J|CD#,z]-=4F9sȣMyh/l~W8ҏh~zID$;֡j 0&TUcZ;dѹ&>K?>B"-`#;Z>Fgݰ=#RNr&YSO; Gޗ Ǻʄ B]i(R-Qܶh/M0k2!HabE!z۹|+PƖRrjv 瞏/Zk7L>-]ŀiHBW2S@S4#Sp^-|\j^gF~ 6aܒ$_IwV5 ATL6,aGhO֛h&܊&ϧʚ}0||A/G^>!=0 )z9a%'Lc);_F]0]W ݘ&ysUPesf9 |љ|K6Hbg6p490q 2_#u%Pso65u X5|Q eʄ_{oPS#SB|xti)W{#\dZBa eEy"D/gΘ2*?~ r+\ԷVGt5&~/ 41:N E7O᫽*悟`~Oky8T>TP_9Sܯ~2Ke ,hz>9*Xsb==QO֛so麫 ~G؇xzaC(m"s9|+dzQCQ[se^waX7ҏ6$j2rʧFX} yTeqOjZk K2/"lIpBdߡ51yU*2f Mڃ6\˕o8w"2Qp勞HqVIgݲȵ=I8@MZCA{%w>[ Y^  bƇ)ձY!jIP!YR (AIS$m,EՒh-~!7$6z$t, aX~~$3xʿzES%]g"+9A~zhxS/87![h<:;%RFN%l*9 pnCf x`R^PQGfU9>+NO0~ ǿjDk#iKDHylSŊbt[n!~ Zi0dj3TN9cX;؇8 ha?į[$7sl$8RQ}i?|U؄|t_%"M .&t@HmODaGcpPoU$@c n{C;?VEhWϦϳ' Gp}}ȼQdGwzWǼD_uNnm:I[uGf1Cp|5U 2؞E KuBI[4^̳.,˚.:D8#"3%x]4SlbHW 30W1:akүamilcamYB8הcFy;Go%v qh,:6&v%7E5:y(BX>2-bccܷJ VC;^B_ꤝ$$u`n7cȆZEeƜҖ2f񳸺р6Zb/Tq^Lᰉ|1٬Ӗ{A_S=P^ٴ.)e@uvKaQ"+S ``UnZ7†@{k4J1|:Q!&rK( 3fft}+e+e[xR?dݟڟPYi9Η 3=97xTz[`D2wdUb˭a^8g2ldG\LFW2Яo:?#9-U}9&j"TQcP6TSxĹ mWJKX '`kK hkz2 G<&@A=[SSucꪫB|c%:ɾͮP @}M?Bf6_(yU;[+J,ɫ^?A ݙ"-LK!ͮcfc*)-os}ǔpįA%f]|JnlV< Z̦CKt2ι? ;rڟ9L?b6 "IbciRƺ ~+)^ǚ}Y˖,v2&f*]Wnp`̠.9* ሺ?^ *+ֱR%N =a9a_5(ۣX#Z}!:DWcniFAE[l%Zee9N](Ӡ BMd>vpk$0b$ǭt[8EctZ?V\ՍgX;1}=Eaz79>Id (lCc5)L3 UuRgu@p,bʙ|J) ʥRܕ96sS ۆ|R{xJfTX oC7>WVo;Ad$``\-{2,,T *4ơ#`;|m_3R] Nf<}?47b 0>HD;^rdќH8J\_-n^a:dՒjN?8jN,T7C2쉢qf^g`-N!O V,#B(7:eJ%\%lo ܆ے;24nM` /4}2SBNk:~6)\pt* $Q5w>:y`:r%ڝ%x|(# qC5Q+tS6 Ѭ%V!P^?P^8#pwy# FL6٘g3հy?h)k0@Bۢ6EV^B@\˾}q?~f-ӯ_=AaG\ Z ێ ~y`.9g%(B?*eG+rsYE'":,'sOX (~PcN1nF5$xES3faш6|6(#vS dGd +,2)@ȯJ0p+ Bd3q4xc%qY0p@L.O3c(b_WC&H3¼p^]BE:{iD-#kuG.(V~ :EE V%'q5lP*x(X1aH(&ޕmZwVo /Ng'FbXB`Q}8I1DZ,i֭iṈ2QlEmݳ6=,fGZQTvyhz*&Նfz?]籇#WhD*hv$zŒBI54Bb#… WP}6k S"^ +rTAd*T \'/ ) x%+ ߪ5ف-4':b[6bEhpHwUm?Ƴuc`[.f0 3!6v>q40X1WcXe`^gO?'V]AÐ}:nKh7ԛhh=pR$-80!lѾ]CN0TȲn$ دޠ[&x@+#QCz o$l/Au>qe)‚=ƭזR?&6إ\hFn*Gturf8¯.B"/SОrQAtq@oΔ4rNEYdB.Ʌ24NU)6~N'jsmNhhu*A &;]O%#y[ 12UչQxDR,%X:>(r(yu[${*X4[YKZOIQ253#TM54</h;W߽:}% .Cr t` 'ttIxFɎs3b>`/wh$>zkEtVv:9]QD2oE8+v@1})Т5YY+|C]*<`ܔ>h2:tgY'9ÄJ*"Vr"u\LG,` D|7{򇌸Xg2qA,4N"[`?/PPHB*`wc1;~@ NRCU ( ,Z5zLWc[(,Ky~͠i|;H]r8ӍFmOqI'f iUǦni8)zvHS4{f$-Y"yFi]M‰@jb՗hJz=_#̫uKH T}MIU_PpF}=tvq8?=P6hEnPa="#baUaa+QVd>6eQĹSK.m)sY1 +KD3p7p&8HX618Ii׉ s: ]T|g\0t9^ԖtQZFa 0.ܔvz*VTBUbF:dy.,hY.uVܬBM7T49pk 3ڗX>[ ;}OVUaL0yW~f13$РMOqms SR38MQN|t# VR;֖tw'}׶[[~>h̕1=H@SnH`LCz#$+lRX(Ӈ ED510 <(ZEVVΗi !͙U*J19TwL0cn K}%?}l("U>Cj7_*s7ݱjQ35 Z3Zcja)W`oɦ?##in pCylbj.+0+cb먪DGHMAr'HӡqZul*n+}JϺl V ㆦ}6~.4ܵxZh_'ǵ0҉b6v>872[%mϿYCM:~w@XQ~+QDbv`)гHnN6b(M{ c ANhBj@eZθS%ߤYM#;zĐzrEb_ls;;>0y"z0lqiC1'o AaF|)*þkeO(yuq &ܖ$agGuQ|w x"m &3a6 Sno@f&13'|eu w jt ։gFHPjc^T]Wj0 R0۔X6~L10I>7U@:ع #XSVMڛaPoT纚vb=oN"PP) rf/|uk}xF{ 4b"4kl AwI{t3Y@v+_ Jn! O~?MV5nAqOOj:VR#țCGe'xG2h*q} (xn+)/OSi< ;GiB2sE Cfr=To`8Sw i\pd195s h1qU>n6LVı`Es3! )!G׈r7>&2aH=X^ݙq)r|Ojx;*pd#%Hz_9[ Q̕U&gvg)NpXA/2 cݎ;u*pJ!jإo*^+ɧ߶j}] <1x@-gv0Qv\4ݙf(0} ~fEV Hz<ؘ:.g`?2D\˽_ Ϧw `$Qs5د;r쎟ޚZoהk>%K;Z)XB[TmP-uź: <s=4WRc\Ȩұ(V<&.$2X]&]4rj,`M+h'Nov` x.BMyYȶ;VxsaPqAjE\Q3\ʩ1V7<.}2^ _ ˠ/ ]U.O2 fY,aKz7-8iT \au\&Jf~\w)L=By4EZy? ^; #\[*IЀM8!ֲUR̊OPDkg?tWI|OG!BtW+3'C "Rd;@03=`|+??3KQ}>{#*݉dt8v56*Ž1}j 4 /Di> y}b\:XkTT +bQҨq%wb#)4ƀ ^'oyp.ÿ+u3,<ٔ)n1)e"9Q*$ :j/h ,H"!$bN9Vn*x?:A>{/xD bssc\FC8Ӌߥ@YyCu/oUɌY㑹nwOe]qr8NxLe#mJdߨuQR&~Ave{x6/+uя{m6zeϞ}-eApUӏd4ͦ'{4W`AxK}VG qf,8iawILo3ILfLb{2.PDӪ4)I@D3S/>P{:7>jчGSWNIOe:S~#.]/n$N_ )fYJhTkֱna-w|WDsP.ֈwi¾0?\WpH-:g=)#÷v hFx~yHoCJt!]L a2Y9-m5?ȊW*1аj]-9Z?!:'O4a{2?-M<id} |g"Mc4,T B0q`q ^qa$+hRiDx(qJl0 Ws 1??~S-x -Wu1U]'V(8c lu_;f_D ~IP9 ==2fRӠ2<$"OAcJǞ^"l!jUu̺r-eYfLbW>IϸYP0PH[ ʑ%}Bj$ Hm[K"k< [<}bA^ 1S)5{F0lM"4OF P{2B,j>+b`82TQQm}ϓJR}&])5gNJ8ב @ 6xh(bO_@ XC k4v4OQTN/ Y 5~8{У+F/h^2!2P:sȣotJ@T_+{D; MR$JpM>Σ? ~iѢzoJ{Zψ,aߛA*4y&DVNsdXbYqud* 3(@(2xBQ/s.:گ8ya) qz:ԗ̳ Ƴ輐q=BĢ1rGg^bȕJ^u|@ h6OSZ4 phsh|dZ3 pUGT{"WPӏِB)Kf?^(,azvr@}{;%O7 H4MMmf쮖7ݘiwb?[jf+ lܫt'\(̊zZgCO$2}x[_3"⤴8.PbY>:orp_eM|sNJB^,pB2w;֪H$Lʖ][jǤ5k^Ed# Sy{RRn&DUvCgqTwPûN_bkZa) [h n<+zOYu|r5]/ dk?r:+dEI"ѱ8'`Fy#NGjoLp(ׯ/&йY_>I-[Jbi;A- -F.6tQU{@F(Ջ{,I9>%Q ĴT+FL,E"%bz~b nqA&֝+8j( \GY1ȧ13YfL$l-b} %Fn}S՛h:z:5{|A?, SJYTmx71ֹ2-Ao}ё4ټm&D.ۿOcxy\}룘 ^-%CcC؞nt=WuUš'Jѻw7 3I Z>=E䷺r9!Eb鋱ANSf)(F]flCp؈ ((4+R^lt( D LY3@7L:o7)|+hԶ޳@J O]"jLKXTXVf¨ Av!q6|UoRSazi](`7W$`؈PY{YoI{BR *|3ĸ{D&5L7kO) B\&~ }TŦדvRP.4m O9ľG/QWj]jS<f&¶Z|UaY?p }рB8m*(G(ZHob{*=/yrH!_3vFr]xU9㼨 # rC B i}:S R@p8Ch:d]ne`EyPq-Zڝ]U-H^1% ιJ8 S1ش)Bj^{@ JWxką\X Ë$*_ ٵIaUOKDfFK#uraQ` VS*&dWw=_|'Pz\<ZZ*p@*QhԶ41|=u1DJ ![O.r7WF>ZA(D׉MJb(]ᮛ4([}^RdݪEכc5,]oo)o, X:%-17rc؁IM {bc, pL:`HTLSK1ǘ"*&y;v/#=,zNBtrWI: }- 3fVYh4Ԃ 5vyx1[L"% 0?B X`y~ 6KZ])U> &~f3t$SwJ$aFB. 3}s\B$W#3O)Vu!\ʏݿIh^m׹&gvTuA4H.90B𳛢APK1iDT$PͦMGZ4` {VE0cQɠ4o'U㢕G7/&Q~#FEL/Ob+F5ۃNwS +n|sD4%%C~~LH TPHHccm 5GTwMZ=/,8DAo£m`_mQu3޳ۉM4PN&=FFYs^UXQݷpC2;}#%eo\|Qr7¢2wZi~gAB@ihܔ gnl ,LַU\\?x)Aa>;x,Pt1?AȠ*>%?.^Þpۍ5kw }q-qyQf& [_hvM6Y%:['gްٽWtZ9찏L"Li)nvn&PSdBU1勓\\&8 9.ǥftg̴78b rA"a6m68aϘǓ' g;Nn?*%4Q}u ~1~.TA̪_0~^ahKd0*T^h"$I ~!1sz3wu撒2^$oh[𮓲)6Dyfnp$Xvupˇ|,Ng~3'5urq \}J}2} B90\ÜJz ;OýPL#+xtZɝoV"z m5fm YGlR^_M#_LMSOqZ&m@Xc*S=?M](C6w.L^DlrL}% 2QtgԊtZ@DqF`;s䎊H!U%o>]d)b"vi|8ǿzDv!7F! 1S3_E.S M,;k9׬&e 5 ,6#Fۜ@T(J_(;B<d5bʝTF'eP;7:^9LXk_9HjĎQ 粎u`ѰoL(-FUB]$DYߓ6L2_~@URѺ8U:=-`]!pPjzeUhUZ^yDPK)ћ0X὏F6>a)W%: mrYX}~# ]5.VT1A%u-)VZU{"6nlS#wzw#Z #zӒ*ZhFrn)rms3$UĴ$Fa8twb| M Lf1Rq<)YԻcץ$%[S9.Q/r=k_IɜeUnZ2ze\P[z! ^HKņ L0FQ6P#U60IPbH?_`nSI$Ruكl x)%WZomi_A:$rk= /&SdA[ikK@N&IޖdОVrӸyWe{dL$G}(rA.w-?' ]5?u`D۱t+}Q&n7q|=WV}%v85dX'v?v.Խ"mfxC/߬Xb,FE>9rPEu1PtLa:TC_ c)bˮR8c䵹l"`msRK 5^K*A < [FJW2-^ިʸ9Syȣ2zU!7΅Km\3^Spq&X8c技M ڮ"v9s N+]"g+׭N:ࠨaԒ6'/fIb9}Jc8|G>&ʒ8>3W\`}kEoN?oVJ_hN3ޟ~ 5Umuf!]^}Uq?%ؐRazdn(G8}l 1cŽaYZs_QʌKS,?|_\l4H' 9ǧeN#O]RI7vu%E7f?%G#]2qO>G%G'ZNo#Up ŠQ~X,YV'П!܆IwUQt*s8^j xU Q u%54S9 YRE޶3)=ZG4 z&B &}Ɲ ;'p!~}z/V#{T˭^7;HGk.bkU:QcĤsՙ)A05`c,U֪3]-5gyEG]5W|M6$wY?pA}ãQ -'xTl%Q7'k v * ; @՗X apfjcWxe-f 2*P!>ҡxITM$X+"p=ٛwz=weG{}1p3ܵ9Gl".\svbo<2Hq%B~bn?^e]m[/OMd][1[fI Y'Dһoh<P`;!?m0Ю!guSP-bՋ"frb'TZ5tn'iUK:XD,/]G%5)MJh*9=z7=;>|}q!6*ݠQ軪D |"e&E.Xr`#'Dg(u?D0*~)ahʬ;xzz]n[џARVJg±5 w-c`'m_3*7׭:E1rmfTSp[#7[4qD Wo>q.Ơ6_ 9uZ .i\^^;Xᑾߣ(GH~P=DY+ãfԺyU[%\WjXe׿7k3-eV4;5r-}sqfe+F z4 hTд+y>%_>V6Wq1 X| E">TE7lu 7^:m8bwLCWյcyzF[ڦRZ-Җ3(4?1xiO}g+.Y;kyd^t7ڇl?g|CBc;Scq#J0u*`pv7PĚX[VԈ$\Ia/m_:%Ro5h4a}SŻV:țxU%"D^͂qwC8Ԝ׵#P|VQ8%~"j ރg䅑[UzrVLfk A8o] }ɹA=oPT gxx roS tVu2 lnvsWcQLFR>[`^R)(AӑGP(IW58Ynwci 7ynnIִɐ VΐT.*0~u>oAudO8$T%fG_ ʽ͖AkїE#kHf+&3opjӬ'/< aDZV8"%ӉmƓ|wj薏/"*)ei[6(m,>N&H:ݞ!8Gǯݐ"& {" umEzav |˹6_Sz/q'6Op/`;_^^|l?yq0W/#QG̱?kxŜ:lv RJ m ˹nyb ]aZq;fg) !ˋL0`؅ Grv7Sd(U.|1NQyҕcABF{̘;ARw1ǧTtTbӟ<3=3$➎&l?}v=o?qD-T :|'nMаsOGN=~2,d6)nMKw 04\r)[&(%[@C/ZDՁaV铻Ӱ! 81XֲQ)lubkCW4QA2`a =xQGߧi` mEM}0'vWUk l, '<#*ۜ.ՙ"q{w{p/kca>8CAغ첝@0 Ti+*F8s7R7O ?֖Ô!oLAuHe0W>Geܵ9Æӛ`iX:+TrbsmIH݃W͙?dw!B9)V^cbKR`G R8 & `(Ԅ[pRoTe88bhKQOӁlC5c{<8kȼrɽ庍(54D-𐆄.xO "㞯 q+v)d_8KRsO9mD '`)e0یFidkn`!.EݺH޼ѽMoNWb ɾgZSW.Cz32.W+wZ" ;'-zÔU3v Ny&ZӼԢSڇ:㲧R'\ohE n&\+/5i^EzK`<on?3?cY@lMxCW^IX=3(4J~xv:֗p߸)y݆qgXW C\6Q:{)`>wXT<%p:H$#;:uhzm#R܀^`1i 48y3Zgn-JumVgY{r;0<€+I;Aل8\~JⰄQiKIl !wla ВxcN}r^:)߿a:TeЅ.${xPi1·9{c0G>Me*UDIsΜt\(*z̽n:ϟԅyȵK~H/欔$hm~jQ7.[,=8kvwZ8g[)Q>8&mG4("#XèpQmĢKc3,0$0LW((vQӵ1FqO'aOKH(ygGD杨{)Rl_Kf_ZZ5}y!žiG"p&_kHtW?C18uc(1V|!MM5 !ڽD.ZT$vM0X?b_XlӃI &%Kq[jGJ $VLfQfpBz{iKjaVF pU)h=u@M7D  nCmǚb_8@M/Mq?0EX N RrSKf~T;F,6 J rF]~l\ ]5W0-6pU.םEԀt"X g>.qvH @nS m$exRr1X:vos-=nm,JGfJnnn+6[F4Ucaϫ ޜzRtaizI`;6h2khD5Q*cl؍Ȑ"[4=cZc: `31J[yJ9;\k &% > uiYwڮNEp^B[}=4t}`LDQ g襬եFZqp}߽ʸdi_͙C^`o~rK-o?e #|nY8CVq0V0 uM<6E&Įͭڲg6v4Agb_$t!y.AeN_ӿl bk%U hm YZxN{bԑ?P7)M<AM!draڈGhyܕ+`ef]8qhL @ߵl~OyGĕ##y7}wXJKTLѕ녵eMYeSq P3W)h:RI{H"Nw 51EUŊ4fY 9fk"]dp,%@R}2; aJocy%v} =[r|u-1'# rh(wHX_-%3cv"jo 0SHMt+pE\'# D\;dC~C]CHSFd }'_~qs-gvy L.;>ږtV881BhI;OﴹY"|.3 *LI#{'W}>q/S?yl'sXjޮCbĻGL%FENFĭA~wb9eZy L (&BB;w+K&F"!栣2J55/X֭z}}[qiؚC>,ڊ>X> 9|7???2.m-CJǯ +Lה+Nn~ '/ht,_?sޤ,kƨ$!Z]H0RGݮaE~_H=nOfӞ-0 ?>/y8JLe +^#:Sp`gjpnŌ -\zm=BJ6Qz (?s9G۷j۹+Mv{Rv,u IQF)~&:GD: ɦ(ܢ]MB7HZN@-`=7n;uYL)w1cyx@Տ6>[bxr՗w ZSx(Z2;6Ka4sJ@QCP7d Xwu*q$3!뿜M\sƃB/ѻ7T.&--&P@TʀjC&Xz2|d Gl,ٿ;:,i3Y]/s|*lG^Tӑ Z@ɦ/V .8 `s+UWFL4ԃ tNt`pҷ$Pl]03S$rDB)Hx/O/omumhpƝ6j `*̗iӤtgRKw͔eklx僞o1'CNe5˫Lz lr5#-%Vtu}YB=m,#sk qs z,Vj8- )HMP YZ