sssd-tools-debuginfo-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!M ]mtZ`={߯m/}-~t lgz L^^\7.^/HwԴ!heʂ.sd|WjZ;D&ǵ1s\\A$ŋ_*<Ov &u^@}0G^rh^pd wedzL+9+cç1I> OJ4z>KWA8Gҳ_gy;G Y넒lU>y}D.ЩDNcD;p%[[`} (7q<@@i'vAv4p8 Yvcވ"xSjq+mvN)8ɥFTLe[2eȗ`7js>'"0t&2V0>)5Dx A/q_-qѥ2^؋^tA]I&;CÎ*`(KSRj_4c'VybMŞSqo*Ts.aх}yQ2a6631c77739a988d161e262a246e4fee5c0d0fbf6f7e02cbdc754cb31be6d571d09f4a08dfdb0f65ca6ac72fa42e4f873936f69p3!pQp)Tξ7]mtZ`f!M ]mtZ`lZ`B=K2.%M ? FF{+PΏKmL.(deXo\͊^^&2&"_o1,8`j&g2J9'|^=nԵ]?ⒺC Jy `Аqilu6>(wAŪUJM;(>zC3 # */Lؘl|Tw5_r y#_/|  񆸉9z"=84pGL힬ss i4^NhoM Bp6i4ЦNA/Θ53g0F 9gb[( ě_/ͥN]d"w.h2<9gی7+Nuȁnx1Q}VE.dN%vKT7~})m>p> ? $ M049?F dv   T # G\p(89 :aGHILX\Yp\ ]H^bdefl t u\vwxLy sssd-tools-debuginfo2.9.43.el8_10Debug information for package sssd-toolsThis package provides debug information for package sssd-tools. Debug information is useful when developing applications that use this package or when debugging this package.f!<ord1-prod-x86build002.svc.aws.rockylinux.orgPKojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<F<L<H|{NAAAAAA큤f!;f!<f!<f!<f!<f!<f!<f!<f!<f!<f!;f!;f!;f!;f!;6b52314a7b092cf4de83eafb64331c060da1256c37b8a8912cdd5f806ff59afedc0a2fa3b5161da596ce7c2450f9abd21332737dc32ae80fb5706c377b0d59308b511f83c5c295e46ef1628a1a7b4c59f4823b118b41c4704037ee639c6b6568../../../.build-id/2d/a9309eae0a2696a67a69051f29d1dee11f9c6d../../../../../usr/lib/debug/usr/sbin/sssctl-2.9.4-3.el8_10.i386.debug../../../.build-id/3b/86c4e562b04e0d3e77ab55386d7d3b3994cb31../../../../../usr/lib/debug/usr/sbin/sss_override-2.9.4-3.el8_10.i386.debug../../../.build-id/de/08219bee2e6c380dd8b44395b59024dd582f11../../../../../usr/lib/debug/usr/sbin/sss_seed-2.9.4-3.el8_10.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-tools-debuginfosssd-tools-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-3.el8_104.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) 2da9309eae0a2696a67a69051f29d1dee11f9c6d3b86c4e562b04e0d3e77ab55386d7d3b3994cb31de08219bee2e6c380dd8b44395b59024dd582f112.9.4-3.el8_102.9.4-3.el8_10debug.build-id2da9309eae0a2696a67a69051f29d1dee11f9c6da9309eae0a2696a67a69051f29d1dee11f9c6d.debug86c4e562b04e0d3e77ab55386d7d3b3994cb3186c4e562b04e0d3e77ab55386d7d3b3994cb31.debugde08219bee2e6c380dd8b44395b59024dd582f1108219bee2e6c380dd8b44395b59024dd582f11.debugusrsbinsss_override-2.9.4-3.el8_10.i386.debugsss_seed-2.9.4-3.el8_10.i386.debugsssctl-2.9.4-3.el8_10.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/2d//usr/lib/debug/.build-id/3b//usr/lib/debug/.build-id/de//usr/lib/debug/usr//usr/lib/debug/usr/sbin/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=3b86c4e562b04e0d3e77ab55386d7d3b3994cb31, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=de08219bee2e6c380dd8b44395b59024dd582f11, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=2da9309eae0a2696a67a69051f29d1dee11f9c6d, with debug_info, not strippedPPPsssd-debugsource(x86-32)2.9.4-3.el8_10utf-810242d26edb5a83c1a8f2f9018e5c666d09a27a66445f58ab66f4ef5919ccdfb? 7zXZ !#,] b2u jӫ`(y0@o&yC[k ʺହGꆃ<ñ[3| œьY~,* Z\K/=`=b]k$K <W;"~)R< {2-)>oB%7`{1Wl5@kcϤZ֛F'4x@.5I˥\r޶%]KKsW>W:Ij%#|zu"?+7d9Bѱ۫U@uAL >9jެRB)WN"ݠb,Ûm T,.>JVLk/nM슽ّ\.S# Tr^o/=mQL~X+P!%9zIM" kA_,]ЧAH d&nGlgw uRJF|q۾_qU!+WKt&/kJipֽKTĬ#P]_G:yT(\#L<m4PvFʄ5#eͤPDMJZ K0@>+C5.,%6ڝ-*\0!߄l٪e2v@!tl΍mղQ=&|௭v>};}5ܬ~@Du˟vYlP:`˶ aG_(ѝͪIz'[<*u6vvZa~),(Y곋+F6m<2?߁9Ϫ]i'y,桉,&d^.) =iјEIz+1ǔu&%BXG$d0x0{KB4*x\$~4]5~y0'OrY 5*i[BId,_}5?{SB~џ&1wkmoEsI/xYcė B:&jQߠ'@ͣJhz~} VMFXG~HOZL|h^Jx6(Qq e%_rN6(E-ڽbX]dO.z*uX]6 H7G7Ipd+rzxE֎E ^Ղgӳkvr{f䔷^Hzg>_x4&s E̛aG⯹~^oa9-1V ㅊE _/gnH"щ',yҊɋOԭv]쮷Bo,koR8jNmg$bRޒ[CN{t.g/ϵQ~eC'@0^C2>|McN{cX>md($&Tci\mzUTt1fPEl(+&(йחNЧ[ьhI?vԵ6a$2Z ^5Z 2sdԞu)/b- I[c0G{/bflV*۷~Am:VZg|F^#b}[)5>3E&Vfwkؒt-nP.֑RN. hXp8y|[}vb|)D -KvNc/ah?d{R+*KzFUI tÎ"e`<B5E#[¥d^atRy?ު ) ߽ ^w'w8ag8"zR} O>7&9 آCh5^?44Υ/jb* 8PPzm9g©-T_%.=b:78v'$\`J)$K}Pٖ]f68-~e3*=jȻcNS_ƥֹgYplM̟`z!;w%Ǯ– D`z'ANI$^W1Y9(s# n\Q`i;$:6}<<*n)KP 7Xz>I{YyŭZ RuVwH|kN|yD_yX2uAӫu >^OUT76e'+Q:aCPP&;G$*-{ w\ppXu <^E% y<RXf`r> G:PN}g7)[hyMmh{x2hpfC'ՔKұr7薛^x"A$GEW ^D3N9-gR%b\ \raș/8|Lc_HRI9xpw(fU㖐BM 7wa·ġ a(j|t~I݊m$Ր~i臝>l24nyY"HQsYkkX-h5'(R &(N6jl sFG=B ]vJ r.y+N\Rw/ &hټb ~CU9NQ w:`s=6=H^e&3V-Jb2}#O@FS&P5&3pgϫkA7Dڋ4T%(a G'( ?l:CX{ KNpzn 5.ǐ-&9"h;):`Aos&_U%2_!Yqr (ie@lV8_ $ H`GG1nI˚#7bd[#Iuk}N9HFAp/<:w~,X2Nn#M޼0 㡁GWr*:+" / |>} @XXq{ͥ*3<7WZ7P֐xJP+bZRG Dže1ԮH3w0Vы-a[_8- `w/QyvON,C$3$rB6};9o.HUH>=t۟?NjV |c7 $4lXo_*辀*_t*`sW< +7i!u]*X އ5/d!dPeCZ~n{㜍`ej!'2.$cuPFbr\U-{7:MnA{F|Ò) u0C gA'X:U *sK}syJ|Œ s4,eNT'1ړ@Bѿݯީ4ڌ%I)_(M&9؜SۤiT 2RhmJE"bnld"'cjS ?aO$$KtenW\=fY2^gk:#wNHJV1ͼ.̼O*lr8ietO޿,lmWΌU&8{]z(f?ŨoE+\fP[uq%mz:ƾRA{Ԡb|1*y>ܢfC<ƵFl.0l㆜!P3P$"T1W4RjVܑ[{!;DlB+ 6i ݍIy1~;N]G&E-!G{hsoY Ee%a0D1+)E3Oy P1XN)cfV*k&僥tpKg5ty19H#KojBRYпKWZUKH6VdW!w`?]LIG]ܹ㡱4.9tQ8mZ&0 jHޠl[\ !hIRDqM3DZɿ-p[S_i/mGH44 7!jM'jC6LZC`*JҺ΂F* J䋲).P:NɷVkJȯ7AI5nz)"^0mEHH c7v::[|LлL_[!88Hŝ7پu-*!,5f hJc&g&xh+UqOhg$V*CEm6 Qh  9EQe `㺀Ap sjX}+6$ w HZȡ,)LU !́4U)q@V53<2S һPĎbz3馅k/a80N0^D"~mˠ#IU/iܓBrNv<07_S3x̙` yɴkBVcMDy<؅bCr%[BwOC>qkU{_JѯK7޳"Af2?(6j.]ndGU+e ٙh6 i~ `$lVͤH@ ,"{whBtYv!3lK_կ-,fY[(3T=EESƛ- ޠ!v7bMĠ)ԄcAHܙLm4bSi[?>%jLh#1pOpMI)*co5Bnh(Ր1/Qt%mB2V'XEf)Bn7qI7@IF+ jC-Сĺէ̻-bHXrj0f:1rJ>K{~ ثA"}ȎX*Ё9l`{7` ןLAX:O⎰%r~PH=Qzk̂r,[lՂrM!|lBH A 2%㾯̣V3"[PfYf !6"5/Au%G" P3FWVKhT&mzmC4#[,?)9&qI8m冸 .բbN3v>tkE}0[ay*w~+X0 \K-F2v|tܤ5 ]_[e[QPE!b Fu ;1aҗq]6;MBA%7MY_aOL;TДX ^`(.x1$̾r1ttNBU9ͭ+q⟛Z ,99+%-f_A bfKht?[W}Map$;3(ݿez=y ݺsldig}`mli-ЄT8x( CX4;xM kb L;Vw~-MrÂS>VHDfn,l] p~V+#4<ΪDcǗth`FWz1 9pMMX}y=ZeyEVa3AQ}@8`5)`t@A {*'y:IPH9&(Γ)W8y,?==CA*Ə5}l,ȑ+kRyG됦9~ ÔjjPJd* [qkw,+]st'-vW艂LSީsv:T:"_ #a#^`2-vW׌J/҅ꡌ{4Sq:T !s^V:DR+Q#c=ʘ)֌)SA<8wE"~ i *DwңE$JlЀا$D-py_Z04&\Sm,e6X-]it蹗MRdQPvQ^)rhp7^F|90nVBYDk{!V D1i`&J$T2ff5x &" ^ .Fu1`,wW[FG_7rdt=(ɫe1-kx- 4CLӦS?df9rpVѻڷkX "IME0x &_f Z߶vY" Ic)Pl=2w`c(d 0U1CSm!s~MH TT ~+._c$ջb+  &)הࠋV⾘C،A*dG$NZgtIhi#i2Sÿ4ٙijn& uylׁH-yLXig3&xHdk__[}-{32TI'ulq4wT;z 7PtYԏ8Ju͑ݧޝwT״`e!ɟ4PiTRnن,DN,?>S$Q3|Ɉz ^q sl<P`Cv(B°AC z\*'U~2`g[x bX 'WՆl'א"dv=![KN^r ps%M8nٴyMh07"bX=t]5p^FK@V(FMa5'2]7:rIS hgS}kShaT15ERe쓯Ҳ`r?!H^tcOf'pMm@駿~z{4y^44_c4s =Av#v`S"CfQ6bHi(y缣 |!޽ lsl\f_R+xuz{nګg]uTX7j!kkS{/PNb gax&"iE%fYkwDټ@.$.?9GclEv;#Ei[b3W^&I~tBBT wev ק}_ HknMET6zo}tk)U "=}KS~ύY~eoW=1>/o(ʧ8 YǰG&ֹ4 d%ZK u%<\帼zljIR. FAf+]5nYMrV`oP5AD`wz ֔LE6{.$G qf0t9ԵFͿa=6!GV"NUQԧoh-0|>a$cFt ]\tok" 8z\kղBxR$n@!e"o̐DN;J' 21hoaDlvWޗ`wӞ_ڥ%#ᠹm%Wi쑻֕SvkQ-"pL2j$@`ә+GL^B?[9"|=93w@7!҅xJlu,lU'sHt;+ JurSkP5\вl3Z'ƒ/Fmh٧_D rwX?}rRds-YE:Z ^׍N`dm*3 45P7`v>/*r!I集\ʀI> caIEeۃ`xh.ic 4e*4QBtsyʯd%d0 Ҳ88v?yX4Be @N zSY=68VZ\;IK{Aswf9R~ѥܚ /bvK/%~@ C+ J2kt_TRD|ؘ\UכrC$]A Lw5|{2(o M'&,U*LStA糀 翕*O]F;6W.p BUBz +6%&\M@=2h)/k=@s"Tu忽j`vP5mc%g=Pޭr #8XaeN#{o pPeZ#7q amPOuOAш_ĥV΂P4"+ LT 0}7Qn;|ۚhGqٍq j.8Kކ!;A N_K5eb9 BR /TZcU/#ʯ.`j"sk`OW{Is?N+u鯝\cvGTt^Rui|T1(@0*=EuOI(]:unvМ;ί8k*&QPK7`& r 28Ru!?,cL|U֦W]!rz)TјXV#SXmX3J&gFrN0bipG/<wzM,7ix )UT8$oK!axU>Đ,ґ,qarNEő#Ⱥ Ȋ>vT8|kG̯(X]U ipJڶe E,{Lu:؂P80V)bdpB\ţa dʩUJ.m[2GHXIBkh3CmO!61JbQC:z&Ҹo33n1HQYnS)yh,%_n هB}ͽbjgSEJM\ۙdϧyᓝ73x|ō3w6һH?cЅdޣb򙯋`tluzUdϳk1Px"=n󯖊3\aC#UvU,B$IQ]3{)]P;l/iLXH@.#< {^nAܭ\:hI{#hܬG ȉo;֧0JDJ  xBq{*K.R\j\9F~p!ah$t[SCkAu}hiFo'i]/HZŇma;^"A1-Q)SLŐV냦CNnSʶ$wRZ2޲ @f Fdw?,?IRr^<` w{0{(=LXFzٹͲeSkg<꺛rZh"lClS%8Aqbg7A_}ᆍD5@#X :OJOR>YR؅Sy7=i;k7EV>% M&lq;T X+ځ7G<,זUfDs`t\/l([H'c-[HNhJ9oֈw}4|gZF=\K^ZڤE9}(҉g"SpqQ~ ߿".N.N?h?*Nb6 +(~9wI4OQ|U8 J#ku똽&D,û6%h4@>-,(PˍGs唸U߼ʐ~Oy(}=֙Gg X&Wۏ-NQX_ڎOS6:kTtV/jNi縶. *~(ވIAA9VQv|µRY {uuM5$-◸nG͂yZ}ֿ͉/zn)щMȄol43uj.όj XL3<3Zk Bt&vCEP"@`_z6ͳ( -0nNj?XnIyFNkƯkk{|0˰5²1,> YcT%A7a%~'6@5=՝'ώ(ɂ7^ɓ7: ِBEgTOR,F@&AL(tv|ŗʃ2oʝbmяPr-|Ihk49õ="0X< =xJI%-옸*Z"uH키ts#oyƣӫ8.gYܕZhobd&>Xː\)u9)Lsu-TS2FCfMCxr(s/gES7X</RJws9N**bJcfwrT-sP4laquQy!j>bZ6E9LBj7k!SҸ;Z+ɱcOaAY)ۈ]l7j_"{)y{hL\Y~~C|1z 0Z-{#M0XwIf4]3JiRM]FZq-+93h~ZHV@լ Q OK;> XJ4"TP1(9 WhNdgҹA񨝧9n gx]gUAM3gl;H;Bkm]ՖcPtD@kOV^W^Y͞US.\ZK/ja}ꯋ]ޠ z-KE N38v.AU4`[43ziTϏS{>'fos ;W;&eԼBڛR^9ף:^rptW5m" cX'|D5;,PR?K +fv4/;>gǙQf* )䫢+c!'zH($G(5&%&) L8ش.wnvnYhn-;IYKl4gS^|׺{xz0^v Da$X"QD|] edfRpl9L"xl{[b~)0eĽ pvi#&|-{s53Ke(t2%a';sYUWX VcA!iN~\έ*gj3"=i{eH&G;/ dxI/oCTT"'le߲ b}g tؿGr$^ >OAt9#&D6YvSrG,YzoDa XlVY "yxz Z{ޢ}F&9bOo3ޖOMϰ%؃XIj/t!~a6Į,dJnB2 }F;qYH @>MbF8-qeAeDhiKV#RIZSW`x=8T3SWNw ɕ&+rl F 2B  8CJX-kۯjgTSjH[]0k*Wh\ݷM؁ɊޗBGV),L70A'VzAEvn4epqpފ53|$H_I9Mtr "*me JCzp9\^`t,>oCS6mu b3&y40a ؏jB?UfV9[*$u :ʵ;ҥjh9І ݒ96 ZQ .3'Ќ݅h+@'gMc>FR!J~% ,$zw VQha>)•,{q3Y0 O:(ưʙ7R`m| !oCxո-X5q\E9=sN] K2{qRepTz[hPbx= βT,|4^ fǕk9BxJ;ꜩ =jfDNI'`Ԥ.1|>^g)83d=S͉"rsy~`]iiX[D/ 2x7cW*Y4YwlCRFi3~W%S܈] 3L]p/ig0'@i1JBod1)h](! uN栶+d}1;}h3 ڴ\-^\|. "`9q䳭ژsE=@~$-x et$irBL0q:S8 WD60|~iϼNM^J<'qշf:ƞ5˦= C>;B_D^P!6\=_SZ)$[>ϲlle;vx4u#?r }ڹ5B k/5< K]ZMN2@W`I]$D!$T 䡣zU)fZx!$:(kJMXzeKW3d} j2MfoڍCjIfx]@al\x,jݴ45牖QG֣az-Yr7XX\ICOk mM]hM]˱6``# rIMD&#OZt4F Zi7?4lmj Y/_,E" / zݺ1CGEkTz$ъY jt/]# •Shƀ[]1%RYiĿج—EBNGh<>=Г)٠Ni8&ѯfKò`́p1$P7O_y|F (Њ)𮼚Qov6p=+>Mp{'қP=9^MN:zk_d]/LZh ϓ>k؞6צsa`[<{Ǫ=^V|YQ l]Ha`TǺS] ݊h$߃GmZbƯ,A{zMZk|ޝ*G仛hݬM1{Y/B8bοT{9hx: ahCP`_ٸ%r("+̟cܜ|(FE\Fj|.^smXM) 0K })ghH93 Vf Wƅ t&(0+!fʳB'_6sr;⫝̸S,{ 2Ak!(PdGZEc(-~V!4dJFb^0OqXi[K#DΩ|P_^Cp w͔rx Ԁ"/eWOd 2ֳR8'5C/%hh&"?l I+^t;T^< ct |CmZ`cE /U47$̪4 c/nW1L{`49i P$C^`&y&yG䅨L$AXgwFw P0IO32e!:];B8Eiat_wN1z?c[e kθt_jloDtJM YƥѴY._MDUX աu00`޵R _>yqu rԧ]U+_"l決-:Ι|π`9,`Z%a|@?ㄴj3s-_&1*#=m5dUkTy$/<DY1T XnxJ?*.c-^[YmwjU)#0bP$'&92`e${JӺ;@6v'M(\E.hFGd%d-V*`<<-u)Sgg(Ք>'؃B[@󲆫!֫<#uo#Bd3 <i[1\t3iۚUϻ mfc*ɘGEC7&r6 =onϬ0^LKGW؅#3$-]gc[FwݕW:lyLW?5_t#>)±K}'R+2? 66k^DFӱ ZkaSI*JB]ށ̵d6ZFzB&׮APE/ UY"`uJ( Ia|؎raɦ1Y*%Swr`Anq *| q@Y;ȉ\c{PPtxؼk"gWa DXehwPy 6 gؽyTIx3Pk1h#&&TIX>`KHآB} S{cM_Y'ܕ9<_ 4WZL ٰ2U],N.%= *ۭ݃}/<ը8.Q1iͷ+#5Sexy-oOlpJHEd([Zͷȉ k'H޷D20QTaLKՆGx\>@_"kbɚu! )! ;u4S^#.f2Nn?F+~].uzVұNt'1|^Y0e〉sYLc=Eʩ 2v BFF|P#>8~p"bY*~IkanH}=;ϥݢѢ 1Kajw n.[U&M"H[Az`=p^r"ߣ&7c9suL[qEp+'}6l{ʌUS a@K@WPH\U"ƬΤ䂖 I†"ң/Lq!9ZH]iΤ<3ODF .Bdluhl}yI .DxMƷ>\GZP[ǒ: LaU茍}Щ KLKW@gk H|CS/R|,G"gp`n# 7|_A%#葕@Х"=;}~ѣ$3DgH%,ytd>9#Db`(۬cLQzq3Nж?Έ9z6UP6Ĕ98\VШ/yNE0+h?E||k,*\}|4~3˾7ђ|=0 yK>N_>xyeR&Y[[=mB,1Id6tf(F z=j,]Y " ?oEJ#̪=G#F X4ʌÌėI͹`?ScݯTIeuEQ] 21ӨXF^˜+UBFkJ84_\:&&8Dp޹UmJe 2bO 1-}*&I 1qYz< >h[ 91frtS}+ shN R_+Z6)4%5Zk5:~Ԗ4Z`[q\q4$؜ LVi&{B(κ4L:ffkYlYŘHِ +mѝ#;(&#]ʪIb1r B'0u=w05CҦçB] [aK^=!ݨrȒ[֩ NO;'0r4Z *ouL sk/р#tT8O+RVR>l:ݼ4>,,YxAF/3tqyv~<.ҙ7>zS !̺Ɔ)aPu݈f` /ޗY1+Hv}5d}]vŤudOvŐeQJlywծGN6A!1}/q/977*g>:+k|>AF|orYRad>"%ZJw$tARh:}h ~8\UiI26pglCj5yQJ~#ݾ`Y~ brϵ >7X $OJx'b巇%ǭ&qQZ \pzM%8k'}0Ҍ^Q{CtW tZcjM]TMC1~FEӞ40%>p/Cc'Ω|* M#{|ҮtUQKs *$a4A?kH#"Q u1ďlifiYC/ṯVNroeFopZ8鷸KHv.pv.|dK_mw+^G>PhP.{pzZԽ%WM; 8Ri [|ވZ ̾HɦT54;onV(W^9&޺__okEr>thyJ7(%Z`t^BnбH!;y`Eqf{*]<-&(P'O9iGݖ|T.:6=(!߸(-V,L=<~6"Cfo33n+2G=60=lNPw 4"q+ 7cRshf?"D "w{Vk=uҽ)M)QAla6q$v\g[@1Qu,ƋϘ4;0WS21m;fϩ/[!zQ돭A*ELkeX%fRR7$`v{G* 나zu{9RGp <8tP?Wmz)*:F$MʥPt;\;ok? `1ɘSCwE; e(!I(VHT9_a-JO_[ʯ2ɳ@?%7i&$3a:( $@u8ʧwsy^5tWD6[l/vob~ -tbjS -nr!q6X:]{=N-DS@^:# 2>,9 +o'q[i,"/#)WӠ*0eD[mBϯJЁ65w((Rf>0r-NDJtMx58N KFO͍k DޙR5\+`rWTnU6.&y(I`b ]:?scIul "'N?5!9O/n$Z25Rgi6SF{}ΧfT?T(y;2U(Ez'N%^r3 qoB{+-#X~ O+(KXE+c>i0p7x2d| @xGUn+kvHfy8{6׿) :k4*|qFq9Jm}NcNkplF[-x⏊t9hjT̠ M`Kڜ>T$:ʩȩFncXo@.w%mNvbÆB,"C{)ĩ59_:hr8ʘV72m{FC$t!vY\'[*LI5$l.b1릨9dC|9䋥 Ty(B:gYK/<8%A)KK4J/9B+/Ξ? k TNڥC֙ ?…҆o4͹PK;' Ngsϐ߲M9lރ!b&ZnR޸͗[RI|H_Bri՗v}h" ci] cَ#<%n78w#JŻ?X)V KEw{6/V*e-ķ4f6>3bPb?>D) 1Ê:pFq(@n^IxJh?LFLo?&';פּf0 댞vׁ(Rz,McmR^0#\im@aj~ ksNbpKMU*i}CГV V%ʄd$(у;TẌ́Kv3?}g9\&Xl(ڨi]B3yuЄ(XP W퇶SHYY"~{tMɪe`)[7#/]"l:M_|#n&ʚY.>dw\j-m4@C1Ӓ~+nFUu׀C0!: -dQbRC_uJ}۸%F$ahl~[>x^ `TCe^$U(?sW-N:0r¢2[wXb IsKz9'HQZRz%7/suGwYoAUl 0d#pTDY(269[9R]@} 0 [&xD~mFv?B.(>S]X#k+7馟htStkܮ17('Ȫ}?.(ψˋ3hBK U3pѼQ:~M\\A@,CWzQH큫Q^ݲD>.bǴݹ=r@o;0#ϳ.G5 er/n&'9u)O(n~]!*ͲNj ˹fW~Mtb}E%J ]ە9DWPfcbdt UŻ,B'xHKm00͐vEu{2iH'MFl~PMOаڌ {:_ YJwt!ZYaqOU_9('GE)7nk]C8ߴx J)87\ ó ;JF7CޘǧT 3Wq:a!իb__Z湵YrM:s bqm+CwU(mɋLoXbyPDWNgtq8v.Qe̯jZ@Ttd'B( vCVdNK+t:ÁQ1V?G:"QR)_,4)/f-%a9nN^G-=0(!!=|!M#Ğcʹ߿[ŏλ!دJ̕Ho \tc9*‹vr ܰ ]gڑ9Wꬩs)ڎ>o5j`нo/~d,1 Qdr뎛ԄhO}z~*T|ʯRMY콦Զf1toZZ_6_)EiwpߜƜڒSw iUX6"YkP[gm6 SQ#- unZ-ӪDˠv÷euCޫx|@H /B>9HsRE)F$Zaz/wHFƾOx)-rٹz"QZ.8 '=h/ >&"_ՓJUhj$yT@UB=s{FbVlY1X1nNkˇ&(dV]fP Ozo7XRh7T覇g" 9:~! ]UPQc8sEǮ^gl+]nٱl,.)gkr6|c ULNOA5(3ӭဆ1Ah6#~2ȃKmK =f:ڽSJkd5!V*g1(ԃoⁱf_ :HE 1h3)Q9+zj&qG T+u.9pjn̅;<}QLhT~%Ȗ:JkִRn,'Nї^f dL_8j#%ǔ Yg7|8gϠj+&&f|dIrpE]3ڬQgn$1%*~폚EE ?`Rt ̗}vE o*39Hemm4l6} !bja1uYŮo_v+`3 obɲ)RL=ǒ>_4m/ҞpQGM_h-A.>ǦvF"vq/Nos nLMB >+q A)YbA.WpMƊPt/Sz3+p~Tds3&Pt-8krCuL'Au C? e#P?ȈjzSПZ\2x0.pmVơدDF(ۇ zʚ$E򩩜nQ4Qysr -YˊH@fQhm.~\F.K j -"[ \_l~a*6a#2UKA3# eXYwz$/lz pNA fҘP:lqWXcEXs&ܳ?0Ŷ[HK_O)R7ǖ9vu8ʺ&xHEmSPJk;}gUIV r)Ԕp B,GAD}KO!]fs؈|*NY=gi{[r@inoRMIjxф( mqBlꤵHn}q`.n&uL m; nR F#R %*h׮ >B}cu7^ZDR)"Mfgv#ly#[^[{+omHQx&?{%4)tOb\ϱ}ڼޭ$+Ɗx>x]_!xFFAR}3JC>{ĩ]%<)aˁ4u[)w^D}7W4^uY9ہPڣ.*m1 :g@ps-I) 4D > mDzw)f-ua\ k+*,u 'eGF PZ+C\q,%Y:\X`+ނ.d;s 6j% <3[狠dx-LFs]`>Y xhX3t,_X#JW.3Tx破rT]̒8mZ8yTijGnGc7Դ/h,CR5؎eF[BZc:qy9~QBg)f&R +S<4%9rbw]V(~u/5~ZKU^%֪iM߇ x ׂl,QZa[3( #Уv|Dy%Z4LzM:铹q.]<ڈWR‘nJ4D ` 8i@nkUՙ%MJ㽎w*qgBqy\-h^:LwMx h+#wŜmr/厐lo ǹ̓e z<62v!FG˄ ,>+󀹪,`E>mYN,,0VR=o&HhC6'@> u*5\⢓@ɁCb|Iv\nxi7Abqs[J`Vց)F C{E$\cyp%3;;u!X7>k!XgT7P:_ ;rlUƶMx0:5r/0qo%Sms?i!?ye`͓?n-Bkp'c <ˏ%9bݿI7F5L (8T1n02"0?;X[ni~ c`w>Q\UhW4*E@=b<GC5+(^У HV4E͹ƫd-$,ɳF(TlIbBgR>DPrcp JqꊉUrbdU iQK: VK'`ZOT/h"}M͈ey/]aNdfl5ST&<:Vc400 v@gV?ل(MLԴ`)dt8#li5|{ g:"1{~_~/n~zF%tu߸ 5%El{J`d@.ߕ*qz6u/LQdUI8eϫ8KD16Q`oڷ,:t%lq+A .u@ ܂8 \(6b~rHfqxJΜ {+>)4+ȿ;;tśjt/.c9C1K@1IPƌI-G ? \<$TAᱞMk b3=:l_=U4*E⬥"Lim G Mqv×6$ r57})@speJyР!x: Glk]S%$ަ~>oe.0Cgt +Κhd=<2vv :Ճ;K:nD|w?(@'@0"!+sV=%ҽUjK |:j-.!7 B0lh_/jiJ!.I[قBO`Dו!:Ź{ &4${-$&I8{SzV3Jށ#WVCF&*\⸏[Je'ci9j$&tf6'()B<3+Zn!;dJ%EyF{aid~]5^򫒽_UQsNb7{$h覇X_SSZ"9.T()KHȊ+)/86f<[g-QAl<ӵŤDՂI/_0ֲ"FGcd1>Z4n94/-' 6k*h8Ehdh3_x#I$iS)jNu݄-bԴI:Rpka4 m g.5 ;au#-R̼@UqGwϐTV d*{c_u{%TyA0{al N,o=)yfȷ Yn5Ǩ v2$.WlX&k˔vPjJ`oV,듍$.9~; wAzTKy^Xejo~А(È<#Y KM711C݊gl+^ҕ:t5ًB#\|rUa$YjPÞL 6RqJKd̚QwB asٵCWnTIVu|iޙCyȗ3'jӱCZ3 `ǕJʚ@~V d?[o*۽=22!Lƭ}w5O A8Ga# l/v_rH!-0[pɕ`}x@"$l"k:u^ j.n z(ITZ]&LmJܤa2C\1|)&^Fi%e͜ł\3bb4<@<ឩ)vtE&]и5avz?=YsT\|T ]J@x xd@>jO2#t8*Kc@#4?9 D0+-Ks=M} 5,X|oGfE9TLzsh}ؒGkh1K(\4I;C:[xq^(%.n~C\M{,`"Z씻lxu )PL-p]Cuvb'ԑuvL筩ŦRZ `eBI6mt%Xʹf6Ia:~9,sMpbw7i5d_ pzח||H']s Ȟ#Uj'{^,0j="DWcQOiw{eQX%r/ _=BB*,1%OFK^[-/c*"|ہwj5گE8|l K-!M$j;6B2 ^PΏ9bv4!DV𫜠%&3?QE֤NKs!kydQ,=Yt/?þ[1ʱй缨h4C]OrfnyE*v[Eu*n=t~/P;P b\An?3d,)){ְ~z#litT5Fux#Q"ulC'R>`Q)@V>zK.mUfXjq/`!)Vi0ǚȠrKXN4 FP_"kN^-6O!Էg<DE\vKA88coËÅR1t}4Jhdt_HbWb%0j?ljETv~<9,r꫁/a<F t':IG>!+]fB817iUs=\ۙ>DS2^ٞ*h_֐`:`)vgN(qPBx0 }wFb< ?d ܶA#\ ,Z %u7.!TL R4]rKW/[M&( dҰ\$F8Oxzt-©#D4RBBk'J̃q@^UG`L[8[I9 1&)FnK!_El4{ir(EjI;ʚ08XMB`AEA҄]zِKDb6\} %\Zv0ii5~iѳ L4j]c_CB/o(O{Qj#ohQ[B?<)j#?MA%Vk[ʫ6;D |BQ./fW0_g7ѴjbdEɞGd{g*{_Oa{K;f)wT+pX۳'{Bay T/L8ub@A͕9DUS 4' GRBr Q һ/$QnTmf!هS. _dL֥C)C*-Yrgo&wiXbBgܪޡ;`K POn1/hWWBpF[Kb4l(YdbEA1I1 _7YUTxKş_N$횶s/5;∧b"ׄ&jV@Ep;rF``DC 9`j(DAk9 Sނ2CDH"'Aߦ"%q~LuR&y89s&oz4 6Zm{ *֠bڥcuNZ҃rI$طy2*n F bHaB: 0&~`]&&]Ra}rz/M欲+*gT#^)<<˓)6&Pl*q bgh+xVI޾;m'W dl+* g" =~|{B[H0LW5@PA+ ϑF(f_8I~a㧧 V͒ɲBQD1RM=[5ݝX"ͤKnס׊q$gK1@_ w!1F{تT!?Gq*oNoV5b9Ǘp߾35]gK*rHw^5Gn(T(K 2?f8/T4=|+D}:Nɤ]q˨JMg5L$ҨjPszߠDHl(M $J&jOBFN6buvwň#tI!X&nTҩ 6mBl(-`<Gm$iݕ/ Q)G7 ߇7`/gA ˦İT`V_&CsHxyղm8¡&T}B9b5(nVaK'F6K?{: B ^2qwјɁxCJиKɮg 4aCMfZ_f#oC*IN S כabH!TuɁc7ǃ4^ֿJ?t3R6 tI XOl<FyVe>>3.O"BQ1˸VN649-Yי҆LpA*d5%~W/5>BE /O0؂)k%b0IΧqq&<3f]尿ԗ[2YY.%(m7b-( 6.&|nTj<'Wf-:aU5_AI46T7</ sas<):IUkNm%[B|r?$%K:(6kMwc6&P73L.Y.>>@D< ƸA85_b=:>TxO&<ֶz^RjJރ̀!+W;kτrx)1SQ0S;ވpb.ũ"%ǽm|MErwUeMoȨmeP Ŭ>Mр鲑Bn^iaS~O[|gI-?q@t:puW}~QDyDvDKgGKkZHLi<.6~* ; K7 }FXFi%w4(ޭ|~ -1dn邌1d*(=뜣XaPCqTA9djO=a{ܦYuB yW4){=l ly'9JC3!yCsj0C昙[\#>qԀIdv ~ҝf(K?7#:dCϗޙxdjzmݽX :qes ԣ/H}py7 iLj;l/T[']u.]>Xÿ Lgc 2>jq85ORVt(Cc9x)K> W7ף1!~\0.jc6;ƴ,/B˻2':>͖¾>BZwwf9$0ȈY2NDG<n-R;ZI.x ?k,cGzG.23KԹ?q=Bhz&^W7﬊^k$Gg7i0`vEfM㷸k<[e@zYЏ.Xz1$Ʒa3 ;iaFT]}"gMV7N K"bN /B(QrIodIG.ݾ x+aD{T\;S`O&nY8Jq*Sy O'MGعJ f?qMƒt!$A+mTp R{o  kPD{{1`tlcWJDrhZ)=riK~ʖ4L^H-ax<m.3y% s̝N*b _dl{bp8H6N* (*1&D&Ǣ v1ɮLrrHYl~#j1 @Z.w oZ%NslJC0'LA/ 9S˩@n|c=3m_ a4c V !ǀ3.O < 'X+}Jm]ڴ {}To0Іс + &CѣYR$nɄ;j'IguAJdc:E юWSIꀈUM{ 4l.HcI8dLejSQ Ŷs,X4mu E;"#RE6mBP~f䔬fq]DɜkvYA,/11yG̕`\#ğ52~V7Mɫ[ܨ!_<.T!ՆB0GB,X w2,RoQ)-2ZnG^F܅Y? F>]>0B$JhbvTgx3ƞT3 [򘪑ڐ\m#Sk '1F0q˞bxG# S9m !mx {x# HKgcܢLC\xY]n]N))&Ťb$i'v{&UO WEX{lSt(a~ c}Ƽ$:ʊE)FEQF\hU]:+hտŭĹz\ Z7-@\ޗc2L,F=[zW nh)qt6Њ~F4W^Ǥ.XLg 9?25jَ5#)A{Ѯ㛳UE,!.Mi#B UeG(8,AE(4L_m:B9!]+|}mdibH{?b"EĆP\ٚ$reDc]NĄ udJN6$Zyʘ\f#OQ']K:̩-|a_ N ra,V)s=na+d ˴t: T%/\}PRi OTkO͓o>J4`!$ڄ" .Di? ܳ#@ʰ+/ M@QޟhȽH;fLPufjJXꓐT2|]ݛ̰.(*ڱWr"{#Kco>iX`5 й p/^a(!pEu ԐNǷE܂"q 3;Pܩݩc*LK1?_kCTm3#cܘX e֝L7k +cos?(5D~wkhd\ܚ@JrwOQLDgv4׏рL2f-k^r0 _Ib^,@-́nn8א?NE=PWk>10iupf3LGeGPjO ?r]=&'6w(ެ)*ݓbĔ)^XڕYjH&±/oKAb Qa2vrOlZ:}EZY.77cHeTIq,+*'sDʁ$WLkeE{,|eKm1̼d  LMn"Q=P&'ͻ5>;$)Q8ߑ+AXBBъ-"2vA8YȹI[(bCr>&4[.KPd wB3ւ l<${O 7ARh4x!ӆte/#!J9pubf; ]`3>` 9A-mǑq[̛W9sZPowiwW\8]+sOY@rq7붺Ԯ<]G&r{$=EU*#* gPf &?VG2.#8Ȯ2^CF "$W@|y'1?C覆UQ#p룑gӠ oVTo˲ئ#U Wa{dZV& WP"X&\ o2xZ$ѹu zpL# dhwS. %#k8P7[Gnny>BCU_2C8"QCa[F åښ9ܧP[)g2@tYri("k~}56{ pͽِ~ sVQx}P;Iʪ#I[=պiL'+3Iy'?4-)g8R@Cpdb\/gu9Q!ګ |:p@}v)Eof|N%nZhגm $0;eiTrkc!<)Oߍ~l]Ѱ쨷3{x$XO Fl<]6^2郘X86s1'Nj& LhEUz'/ Vϋ2Ag/b 1dFFz3y#HA0A;\@bX zVWYF-B5W}mZhaHnGⅎd'jo?FူޗD#|шt[z&o!,aIũ~Wz#yN&_Jp1}Y9*-w%U%ajW0b I&N\$8󝤇$ 5۰S"n6(gu+VvsK @E W Gl*¼ifҗOB<:d <mevFY]3 ^J":Ͱ*Hv_AD̘4R.5pQrl}$uNy8cy]J 搚,vOshL~"Y|+ftDǀsZ[`)s&Ց=!I6U /2iT o׼ph,؊}3"Ltl",RNWyf58[~1 8)DBb p /QA.TϘ y4uم~3 0sJ+-4po)uV=y @x0ҝ@eBxv;r:F8[AtžLj#xh݃R}5Z,_J)"( ҐѣAsShcww}e"ݻӼlmTq]LecW%,6d^DkrS퍻S@.5?DHu|ʋX ퟋ{z/hv!L !Ew-V VHM~5f H*Oώ.*Y=~H8Gy'y1A\x.JvhFI1p=(Mb BϽW_o]Q%{b6H7༢:.Wʦۚ'ht k"qV;Vg_l ձy@ޱ`,/40cQ*-Pbը7Ea5C^$ŵyǕu+hȨ^˳0cɸvF HE#@ne`4x4|f8RP;*,p`v&?< #؇NTfC˕mI:i˷X"χ 9axX/2BZ5hm)(FOn= kvej"Je}%Oym1y yF u!>k*i+|w6K,*7؃z,!]rmSx;OH ]>ޔ{=%#_=U2?x ϲ翵;̿CˑWf[t86xh؍pɚ0aVh,e>?w*S%䨞`u$"_vf ;J%_K.F^Dt'D[hivOimr~bj͉2쑔dL?B\_貘t!ÑUb&qjfp.s~&'"I%jI-D4bGgwJ/}c.-]/_yy-uK, ENkBΧl]TE!GCY7 i''2M/p#}Zm"u0hTj2[;ϼPKʋoڡ17n?C(lzڴT+BYcEΝn*Nrh{E}Nd"jG-,G><^aaFpSԊ~9qO)j+Km_`.n#T'rBwAdzcS>Q'6ڿ*M~GjՕ5#;lEydBr04` Dݟ=O4Yt# f^$uM}~*%,S$a.=2D[?N[Cɭ6lLwKL}D}1 XԢ:'$X [Өl6U3G60gJBv9線obňLum,,5̌|Tc.Gk2'91D: ǃ3ջrv4tUn½+Q)۞ВR;Ye ($WPYNS0kvB0?#x1j~b{ϫ/rl|^ǵظhMi:YnjT 6@J"#] >8Ǘ/JI*:<+'/s>L΋XaE_OL70\gl-!q[yN`Ta|3EMv?jbW5۱TI!1:z6Ԩqk+dsЙ$LAVЁ O=5XZb XgC# )CY*#(` ɛ /o8|҉|F|ks<*hںA5%@q DFII=#*?hmtV2c:3̈rjY3Af:k+zp?J% !t zJKpEP@}jvptn8X=. 9ox]#4'Xڪ2leJ^L2J<=^8y} u2yiVX|'ē}n!K•:/*"FDDBQB0\t BgĔaKH"SZ>aTm6I)lU.˛6uo`~= xD^3`1!=~6LhjA[kChT2+X=bA0x,j>Z)3 L@n7ߡGK*[$(y$ߏP*ݩ_IHYVಮ@RU;pM iyN77Pqf!jiC{R[ӣ `&@q :ӜQ+ʙcђiJcќ҅93{dl;O]MRn5YGΣ D|,Br`ȱ#SYS0 ?Zc+wcDǹ'zZ.qY3ݑԄ d{r<+yA ֮x~n u.>';ɒ'Tx`kBnWgp2;Dt. ]4ql0DJ$(d,ec6j4Y>7*bV<]24<9SRK|f6MpR$Uk 6lw)v$j|g^r_Wҹ;bHj\ՑuMHWmw_y7YƅCwE´ Œ")WOuyƒr8kZaNLYV  X3V'Lڣ"nϭDPE՗8ߺkw+5xIE:/j2"2<gQav7(gF?֥ɒ X.@ӳi$H1ߎ͋Vl_B -4UM{0=Е\B+tn;^!p?ڃz ilcqCCtL4=G(vN#՛`ݱzxjL9;UM s9:E+:?N wmtcCTe@[g "zj*6!\6=Sk2@ sribi-l7KZS 6H 3RϡxA됲釛u?Gt~މg-hO^Z|~Q=` 4HU2V?u3ۧik#j:[0I}u >!QL$%+U8Is 1ʐ)]&~p iS#=F"GWuY(=~2_qS.}][;o6֙x\l'-1=KU7,R+V-NV&'؏Qф+GȨUJfcf VNj Q`g9Dj84UM&Vx>T<3 z](c$S( ݭՓ+0' Wta\I9Mx1-s5T=O)*t7x~=DzU \HrC\)5rd3c8F5Mb]DtHd$y9v|(.7K8BW/D0h lx/klM^-jVk2I]rijFP6zuFH(3__C9WW{qbJ?BqWvC#PڲG}ShkH,t {[Khi%?*/^eSƐ&#ɪ!զ{gHY)t`si)!G@P42JLJTe:s۲$ZRkĚ~07(PVUQП0S0pX4t"b/_do $.Ē0Q'P~1&}bA,K-ݡ~cK=># p3G]`-Y;g#H[p6 Qr7(2 <lM tBEy^镃~Gϡ,s$*A,RdY\Zo[α(>5X4@˻yb"ǖ'j9#՟It ZjrP\,x +P;I8Hƶ4EtCC y JSebaadr]꫏|q;A *|xw޶dap1 ?il>u'Sths3dsY KX̢V-_KC(kY`{n/ 7w.{cZcށ7h$.7YTP.$NH hz aZܜ:?s"ӵKt %^M|TsiEP9B(+Iu\<Ї[Bvi/r&752` a5Org (uszن>{ʩ^fŨ.*=zC5V_6Aa/ȓup(3ïh y7Ö́8! bW~cZP꬟6' zw+V<~*Ys)z${f:+ hmsVіS#&$9-s)9hFȒٓ/N@('ʳ;v:2EhQ8؅TQj/%6'YVn&|<ˮkq8]m/I|Xq^F~q>ԶP3 :r-u>5yޖ8ڳJfS3mߗO5/*{[,Dă tu w4U a{]?T@D\8^I<"ɵB^/l @așE'C/T[ -(W]+I1 7o?ݫ&oA>!QFW! +39(߶PDĵ|!oPijׁ Si챆֛##ޯ';xGVرzu/Y7iQީ3 3|GA-JbB5偧@DRrbΔ$0Mu:aR[8&{EyH&8I;'Ep,Ʊ^~iMJPgR5RK,)Jߦ)㕬)x0A@|{fGmfZD@i\+Qv6޾y=?L>({J6'WMizvY$PGILt_\2}rpg._nd3HM\5 Jp?LۯnhIBa #ljp'd^,C&:%X-aI/L[&ނ&9P/Xһ%uDYĸSi,nUwNz)T{I#g7 iI 8Ii"󺜷<Ѿ)ގm ]ɂo%cT[ATWMjo *­thGJGN15 _mJUpt w2츥@DނN[]N<㥗yoB:ȇ7V h--ΛoZOJYlVHPq}gXhPiF(%{3  h"B 1j:$9b%bNj e9`;;k|X#h-'͑iaDw|{90Ht=-D KU-8 Zy罭P6R/ueSB*0{+-u“ Vi6A[livSr9EqbMXt@>/G7|珰v~s]1P?E@%&;bcgxɄ7N]rr>N$.o2^x:5S\ϛt:9 <9*sv-FP&J:V+GaÙKšN TRƤ'~87 ѫX$| ݼ:w> 3R.  H"r:41y&%$F ?շgTY]*A_8or_0v*d+guc/4YЉh]}}'22y{m$;ӴhTu ʃ8DkMHo#YN̥:fP=®9UrojJBzDask' &H w`iJY tsg}qFfk}Fp =LgZ!g{ԢFgPu:/Y-FπI+{q#q<2is۪d%p$2{4jReIB [6#HhIXP8P5r⡞9ޚaya|uxeDT7EN csyf雉&RT㊧][M7k*jPQt!C>K&?d^k!$ʕTq7}ͱx[{]Jόh Kw{1Nz}8yc%P-67h"Q@Kѓ-H4ORO Vakb:7ݓ;f<Ŏ7%ocNKT i?1Ldsrܱ SAkL(5i {;p}x-9t .b:$`$"%qͶY1p"e 3z|x+b/~ ;o?8B {^UВ t (C:Ug%3 6o4dϫPa"hSM K[plWB_/-zCJH9f~kV4bۊ%:E+cD;M&řMWIH_@'v{cN#6TaUsTͫhxojԩeOhqј^5|!# Eth0$+WJi~5Ŧa{7Ք2>q,Tk,-g3a:(!m k/!hŬv:71 7fȗ >L8e PI@z% g3j2&H#I&h4  *=|!Kǻj=lLQrQ߼0O. 8C,vHi]8ZՃjީ7pGk$n 36X$̕ TD3=cr+/I:ٮybpՄ<=6 ?S hWZHr4roJ`+L{=8#-׶3Ixw~or622 x_[Wdj;s[qap>&ݫTD/pi ߘ}8FZet_j+ d.CEמڭN-sjRRʔIG$ hkLZ*qnsһDpYY6K*MZ$pr;e+|{(/co͎ _ F,@B[dw[I@terۂ'j\9:^W~\ҫ4Y04Om/BMoؼԈh(WneK}չa&R<]hx!8> v.G_. ܦKڶd\J} *:OUV#M+ŽNPw`]U_&YV?~sea. !նb}&?"'mp[Hp[+eU b_EC7i1ax6p\^1w:xbP81 X1[u5I3!jycFuE?t>^qCwlm+"|QŋCю2hE-$_#ꎑ1򍑄~RpCϙb-b)F+sG(5+9`Pnpx*,|뭖!41?d{gC`X K]gF 3 )j{FtAdZě08(6ivdNp߮MH0rs8뉀aǬ\AgD;N1JnX}RKT=I޸@V{zC䣔))V*4@I%_7K^J!e]ve%!2. :⯭h $p໥b:6U+*c2;3+BY6oHMÖAq=eۚbșߥsMIQE4*i[Y}1)kry:Q:.WF'NOsl%w(n. <𤡊8L [Rx'$^A  YHB-h:^l5Af-vFGnI#37z8hRU-'Ᏼc-G8wFAWל u`UۨO?-ZJiuz cyE"o9o}։Hb}Bh bƩJ b_@~Zy6ޣ*8-~Ia2zR+z%H氡2,ŵ5X#[_\SR"Xa=6XG=@^; VT_~ĠfБtUq-g0+RG*}AF$X~ՎS m8A*Zrod,"5p}tߑxhB!<@ ؀IݖFwD:1 }.TSt"wphT2b`ÉEREkh:ՋB%UU>4;j|2@y_܎x.Uy1rN=*RkNYECWd!iH$ l=딖qk(@!cs%j"!kw:=_Lw[7,t! nͻ7"eq_=Ɩӓܝ(a$uE{Ž SQ\<*ZTAԼ5 C>ۯABXZV!Yzr_z Aы7R=WWh5<Zx/^{"HPj rgLhn!Dck$E ɷK&, 0LaT)4@dØo b68MFM|8 nG/ڄp:%Kz +! ~,kA}z uqk<QF$Gl92NP$Y79ZG>qZ!m)i3ie&#(G':墚ʘZPcUhJь0 w}nq3|@Wx}_ !+#pIr۵l4^,o(}>۷'c}5pB$[XʻMx6!`G>e&ZWBrJ&³O-MBM:H2\BE=ҩ }+?_/" T(BnΒ̪|_~`|K u:6⩆/&ZⴁooTYWo;/uxЌett?ҝa5&/+iO|" m6P@vB_JjBչU1y1dc[v8n.}W$!USz2{>5 h~PcE Od +U"^N@F2Ep"֠oő&CV=a=-eGϺh%m*ߡ'bT¯PcԺd:FGchyX-+m#l^SQ bC?o Ksƣj!";}\Y w^E{<5@{v *dizT *zɭb@|wDTsƢ In"f[cT΃yٳt,J-B.M`PyƇ:&m~kg m5:0>Qtde32>[zB'P>Lh{:N`*d\RZ1EжrQMaRY. 6okvD$P~7!ˀ&p#r1 [ BWm >}v K EP;jA 7h ~:OD:sywҊ/HApQvgzգUĽc-]ʘMX ϠOW JFl8.>ceTkjJPymr8ov'tXLЅ$B>h(XFP^Wd^]ke\뤿4G Ê~/6?gD ajZV\TD9 Km6Wߑэa{۾Ӫprc752\c/G|kdHA avA@$C1c稈mN%;e Q7G\DL̠)ʷ8m6RX_Eמ *G~t]IQ?Gk"[h9ߎa"~Guv٥(E {F˝Ds0`YB-6:_&[S/ w] zMCђDRr\tvVgl<[Gz &jǧnQz9l>h[$hzBZܻnaĖF liiC(EdF\+ P9Q@pGztkO;f+?E,iAMDg ;4.}#:WCyϞ2|_y}?uX"?ߣsѴ81| 7h9MZΚ/g=fxG=rr&|fӿE*k-Mkl4y[W6tI4ԉ@dXy+vjGCi8?(ܧ!=p;6w*rzT5ZcRbG\XV\SS;ⷫH̺+XNWGcI*3 9>5j 99ۘə?}[)P;)&#eI>uc/hҍ&Bzl92D[CDZa9֑KekK򠑡imP!sN C1o1b8k #۪{  kS؎..L9sa~lZjsT(pDCMK~s~4աnm~op'-! Tϋͬՙe jm>9p3 Ys9dȐ0ȇ ψM9tꦑ[EBz둶4Jx%m%R$EZ]Lؔ髒kBp_`,iR !nۈ޲>p`?? {_̦m ducHf_yO7IuHX#K$|*'sE7`A;Gc@-6?5H)TzyjMs+Ѫ?m<4VYy$NexRmUc ]L.R!bw>`82ډy/ŸGQ}&@B˻G U"DN/(|$ݽH@xF+RcE%ݣ2U؇| 52;N_<: VH+EI8(ph D% #dyP9 6׮Wnsl'p/QSF_a%WOW,~Hx}(xBi 4W%vI [,Az)\ R8٪nFiN܌bFBz߄=n]F{{itm|@\ b2z]bI]oѯye5i2~{UowZ3lF{H_tŇ c:b'}Z|5ѻ֮=s!lc侓}!-P1=mgׇ 26j61+FQE7rYc]V裨VЬ/="] c)-IJq@}3-[W&-V xvP2je1hH!`hhIώ6;7#, v77ealuhE-0nϑҽ=qV!`"O}ڍ&aEJ\JÆ0*z{-#\$5 Yl[vO̒3}\mU4mqpvA$/K,gCEGhZJ /Orʏ:I2\uJ%H]*IE;dvVM9m櫧V5\V%BBr_YxD.U3ݔukDGdʹF'J=6Yln5}($Pw"0b7YVg~T;Bpw1au&S8哑Z 8ɇB-k~H&B[ 0mZCUpN7JH,zQi3϶'N&g8[Oq90XK"e ])Tv5Ʈ'%ՉU;inGܞ%~J\8HzFp)&sm`C: 5xO;OUe1u=sjѷe|Z=avWZY⸸<$ 7e´ICs܈CG2k"/$؍O^,HlBrVMZhgoIRitq?o[_aFUD*ϙT<R̃Z zj@6Z/w"h(ސ;)X~b ܅c8(a|z/Fbwl^ [~juLz,:_91 ̠g҂$H,|L46Vh_OBGy@H_zK/Qm\ЏoP~fGNUzP—ϋ=>R8O(sVJY) tv} {읭"JG&"7EO/.D Q xGq٬b`}Ġ JeK֎8񿅂1NâÉrGiO@)m *ZI ̺I%N`F O$Li0Sd%{v oԇ*KaRS>jk9e(!:!q{t^M`ptU&.qS(-Ck8FAz@_O,2:a WW?ܱiifELo\̀r̙SXI{չ,NNc-~d6eLREDP˧1{ghm_ y +l qBIU`]-!%"` <0z_E3c;r,fOxM)o4;hFKGGZͶ qDQ1, InWuI#UWc4lմ]IM/PmmK*; z]\WǓla"A [{.5#HȉehβrQu*/>O[A(7ﱋ:=c)d|M_ Ggd %tS|geFAQwlބ5X[_7)%']nimGtZجځ7Jޯ?8XB~D{@_[Jk*@<}(1qoiX5Wݹ}G215Jq)?¾ǡ ^~ ]7WS[>&!\7s F k5БKf4lDM0 I0urCy}\]2mhknsC'jg7;?)ߥtS}ST1jjjVSL1Ȳ5 bn u)gpHyBVNүY*…:JrEwZG/2ucb^*mWp~l_kk}fCˋzXR [6&Acdx|3){qV7܏Ω$E#Y Sd A;kc< VqE. V w)LIЌ"M?aBW K0{&,x0A™19`wK2=҆Bۖ T]5%;fX "񧔳Q :JH@E?dÃW' l5WL~SIW 1LJד]fZ}TJ&ݬTFr\P?oV,[ 7; hYnvHfYb <"CS(K^"|5QTi/!S=w",s۠zA<1f[v1W?(x⊨'Jn)B ǃ2f~|~#ѭ@~:]/ TZ&lphD615qCm\$Tmc?H6V-Xd%*ɯ:-Y@ &M|92>a/) GR#*nQf?%|=Jdt IFL' 1¥Z;87쨨pL/b蠊NAЌnn^񹭭Zի|0 rXbDe^j`aR`&=^m4{qɖr"ۘC}%\.XnIUUc@|j&ڸ Jl`-BNKu0,H&0j»iljcO"7޲Y6#(+7 '缋P' *!s$*~Dbrd1m7rcFQ\~.]a՗e9k)tyX'I +C765>59by| X~FE66;m9h]Xh^,?> (`t+T-HA"gʣ8jBÄ!6#}rcH.uYZBu7 pdEU3\[`M'7} M : (@.ŝ;5y/J3jtW.2V$6V hNgU/gy3Cb+hT**,A$mB)K>v>T\_5'PY\#l. 3ԁJ},7{O#MҾ5{ގjH)J8Nv~My_ ]ET`HvmDB98*u%0hł%ҏP" Ы!nwo`?S}ѩAVM>gm7aШ02ujN,pZ_Ǔ`dgDl8-ǂe wy$~k/ƶ2H.rB7Mk)U*r1 iSwEON!Sn\|ћ5znr9۲~vsR0Y(Q2ZJ"IT;8mᡀ$ ›˘u 52Hbo5j97Ig}x)eFBŏ].Rq/ܔ:VS[e PE9` l{T8 ,ā,֕[ΞLYS8)Ќ7fS W(Nc<59!!R5_\,('AFhpt'ץKpk,iC'ю2s'YkO6gͶe/>͈/Q,I ~lۿOAp[u̳!Tqi ҧ[HS5pYemRn7?4YRn1m <3C4拗c ]tӿC8^J9N'~Hq}F@"a.1Jedcx>KS'G2hU%8Y(yY-o3Y e${L{.*RS LhÏ3Q ũYbE Q(X2]C=ĵi;$@6Q%ed `rA'裞$O"Ay |=jjN$(Tu Xmp`k-_ 9hoLDkv\55.A+8I:Eͯ`r0 f~;VA+N<["7[[ĝ|i 'gB}˅da6Q@hS *=&oaan1iczAjF*r\݅s魶3G2!D:ܹmL q!0K6Ƹ'?X9{U\!NLw&5z-~&t Pu`)'AqA;Tzt"s1`qL^o4҉Ӝ(ttΓ*` +`jV-ŕ\%1ˆf.)Ah)8&[@Ԉ!1Y@i8 >ۘ-ꧠEJV>IqX8459⒞7P`feZTJi+zx3Ȯ Sc+N"YwlHgEq4(DA1~eCZL>˔ ZnF Tև#ږ"1Es}a=LpͿ bd Ӡ bCk0l!KbS'_) 4I&fZ;`y|vf]az7hBs~2HC3Y1u1w!gM|cAPQ}v-gymBt2Zj̡k,$ kHwHP|SIϳò+S!ş8g:8%ú ,ky>~(NmF2nr:y6h! MLxe5.<=*ZHȎ.*iNN8dmgREKyi4=m:ۓI)kkΞm@ԮQh}3R p8|k.dНx_7TEO) !nN-ժMBrU璫3tvPIt!X|R7s|]o Ki /on凲|㩳}\2Н γkJ9?ٯS`jDK]w?UQ۫^jzGA[91(BlS+7E҉ : `{zdSf@,9w Duk(xB23TI*nU,7^.k~aypՃJE :a:/xc$_X8yaYϦQ0z=]Z*#shA +(8I) WYECdNVLԶ 5:ұ@RW섙uuX^`Ѝ wS8¬x: FZcK,N:$;mXL"*K7 қl/n2:?1S(sJT ЖMU/)B{oÎ8Uka{)#%n~}*eAgLx /a#rBltr>eT#Hҍ~"O%c\D(Bwp;Ѥ=q~]SJK^k 33Nxa[uQ5DI}z򑷪ӲrGDK~'DTجjT04Zd:꺤+Eq@pL̩hUh%(L6/HI8ek! ޣ JL`ܰ0B] $m$JL2C=9t UN ӼBҶ崅OAKQId<X&@gݔc[6S:\'ӲnBI%j];=]HHOHsD@ u`CFS!:zՠ\ED=a^|Ǫ2xcodW]}sDXeIrA55j)wf-noy1q^+Z,*uh16_l55)~*:OU;㵡Rq"0!QkQ ,.b=V5;Z]a;{fz/EZٲu%mJԣ3ltRP%NzA~g:`d܇auIW}L1z#gMM|a)P}ey/]| 16d(^;M (_5sĔ2A,q]t3{Ս]י卸֩YT^JUL$<|p]TIo/ 1XW/m|])#~{ N6\ TLH?9}E#;flH8=f.tkzt\* uKBPLDv?yis'?>&6ɤ})2pk.gK%Z'c٦y/)( {/qSE9#mƄI~oUQ XBw,Ysǜjd'귥*>.-D$**AQZD0?g eš0|]^#lú I3 ʬ8I "\$-!wS3PҗwHuxJW98AЧ+Az[ٱ{Klb|E%L) nng2ҭU@i$5,}h>uPCmqC(4j[%.X@p71 F;xBM>plr][,3td[2 }{[+vYUۦR@\PquK-62bMBEc6nFH8 {LRs WW:fa`) #ܒdyB9Qlb;mJS[V1Hq8+JԲ(Ԫ8]4A״cꆎʣ9/Ai!ʹ/ň#'Ǝ/?"cS tFKW6>=ץIm\_E]I;4i(ݴ ޚn7 X:Ϙ"{7 ;n0 M#.VXԦ&O4|[3bb|RhH]>j8ܳQE7{Sʝ.'qGK,r@ c/d8jt@38֢~~0*B]D* $P:"M3 ;4(50+AHhFoM 9nUFrvGoy~F1z kbvd3h9žD2WZS.+ЏJp2HW?^#t׏b#!j6}E!rO܏`U"`&yK /2Mˮ3 CNP-Gq$HhV3)śܖ;[Ùc4^צD27$SnyyIx3. T})ǖͩ at%ޥ<'!]Y^4IBd#ۥtX.,m4? Xԑk!`W)*lA1]SZXStz$bPy12z-)f~xuGXNGq1E!%MI:Z6#^ئ -u5{8KCb;`rw jp?t 4]QiFngi=D]qb7IX's5! uOnRsP#ҪnRsM$x|~}iX]ob!˧`򹂛F1t'jHDedn]]׋+N/MˤOw9ԓ r[?eov`bj&:]\׏CG;_7'E~H4馟2~6ZڒiM ?A7~bOA̤Nֶ#x,,'5VQ)T(hٍ]^M7pPp\6U]Z99TVFZR@H4#(Z ߏ=^M*A7S[`B_BAD$Q1TFOgDe@OXr$UIpsGx0{_=1^2H\G~N)uIٝA͘u+QLA N/8Qa. v bgaxi O_Q % Xm?B×=)^N7؇ b4X=‰At9$IadI6YZFQV?4*ٺןPg?Ix^0 mVa6HՇ& A -{[ό="1{[nG!EkX-#ˌC_棍bٚHAO䘊]M9ِi02G IW]C-?.{0l=v炚T)s,c?kHrKSDrR>( {H}SkWҗF?`w%BHQ"z-3N kA#ނLwצ[#wmd1*Vp MZ꼯2#cl!mKҨa?RҴk4 `Ǝ )-4!Tx뻨{\ڜiqm߬V֟ B05lqEFd3]k! 绻nQgGbowI0P%h::pfbсϭ߾_rf 7k?Qa<`%BolQ+ӧSZaB ]78N[ͧ7Iۙ{t^")> \=FWI!M̀es]{#j~vkQzZ8.DbO͊ )Uf 7 !(+NfI:4Nbqg3;ȏ"'!X'㡉cH``jߝèF9mJn2rF)27Wh3 rZMI4U=;ɺ8j`YIe ۸t6S҅{ka9*N+kQ5a>㫵;P, DҶQs`uV}6[8ƛw>^]b&Y-2zGN=L Ɇ6_DOp>f(lb6g͸P8;p^߂)99$A0wDBx{VF- MTjc:[T9"ocr|$ z̭l g \*8K=uuQqF,Bܚ $+^KL%t0[Qi㮷ҋ4N^%&̂}XͿ C7>F3/Ozmkť#q9JIf hz@V9@6wߩFߣU6 q#I}z@P[@"E{>׾78Պd9r2ɍ0ZI7:*EzrμNC|21a*:@$?I~Ы.a{g9nA:ƃ My>#x)!zU>,uL(b >?Q#gΏMdD=U:l@.Df9 .Tڿ'Dև\9*6v{!$+>]0'у#G4T{o0hS\׭ؾGX;V4)%< tBΙ昶c%PiP @z=/D"kK2jO*_ͥg=dRR?TxM!GIg56`j*%mL7M;#Ut x3 8Vw` a} &eF-Je,WOd`2V*qxflyP[TWd2@1^L%ua.⋹2qpJp$[5.4/?GpZ wق}(r~~?IVvĈ$-U廹;v6H칃XcOǤ G:5P6oI3Z..axXZ66~bL{|P{~g1)8'9FɂwMb--^^ 05ts&W+B DxPմuw0>3j>'_I@ҋȏ`N0,F3WvP=yVm̯Ka\'{ 29w+ $,8_ގ6it$=fعS"2l.8 Gy O^Gl^ž7.j{+E JqU|T_P Ӡ\$$$:Z]!<=Z ePQV-d6a*`nYm4tuxa?Hp1lXn^Zy>}Uaߠz7ңJJL*v 4Ӕ5PClt]m597&sXU݇9}q1RdՊ$gNMȳZئkf[E Pf9;睪NG 56o %9鎻|I˔8(xؔ~v78wєSMmu-e~w:9lN~7Gz: |Z>an 篎'OBoɌcJVAո1X!i\,I,x 26 w%p  ƩՉ`Bv%ZPnBEBP7[37hCҶ@EG[TfwR>`T@D([s] _-id!DJK}/1ž0!~_ v=錵`Zs;\U4zx|+{#@eJW߳25[Qv|$d&|51hI&a\DC76Wkŋqē.2 &4Ln/A(o6 T-OӤ# 6`χz SN{(,>ݛ^qŽXH,k5 :fȐgwT:ݿ9Y#R},o֔>𬗮 UiUO}3YP4B"lߧR63nVӰ0HrPqɆfY:KQ. [|F^ijbcXkUt`#Pj@~k^Z~9,-g Mۈ ~ .(UFz,rkcbKh&@CwJ☥oOm"Qɻp3 Zf|u}5ҫe4ʺAف75NfKD}(U"Ty% D}Wrf\U73q ƻ:QM*|7E´LKWcOЬ2+G/d $i_*O(cy!7%4Yv;CO7RA^ҌjCrLy_pL_A#GܒpUAR*+kf ((a#]Dg[L]k is'ɼ;/pt ޭuY_m" j8*PY|y=Z=I"E2`~nJE-{/㒞k2K..n(3i QF^,FrK/8&.\Ga?=]:ZtxiUq檭3Eu(tAp3`E1ͧ+ˡxWV3ӝl;<6^IeA'r+'ʷmDLpY-$@,,v=y%oUI_MUIZz7[mERh@ѴԳ~ a7::Sig"86N<)BMZs k^y^ c6Þh 4xUk xkN\F!=v$tvE<ɳv&v]낳P~֍`uðu/-o_tkgw8- ,"_gxŝ;}H oT5}|鄟!8Q ,T"yݬb5@P'ſt(ݨ|S^d8L"* VXez#%pK)Wa [շJOzkkTL[@~Qzt\hjBoߴ}-Wqi \Oeϲ[g{cT Xؗܩ]dTRG([5e|p;sjL(pH,w nTGYAcrKƢqePz5AleEDɔ3БHw%80 [f"7|`f3P`NPi5;#bXrM.(gob4BXɧGbI_րN_,L)G0eI?k츗odS4Ը(.?IW<'K+ߴ!>71x }rɍj?};]A$s5[έ1_އo IuT|T?/z6G{bC~y6]IPOs?+G1W4>mFE",Z U29̃*1^H›  @I ;&Q, `nX.`냯IO V;S^ WmE}mNw`?Yw%yN>_3g q1W>< "B߳lϻ#Hw# Pј~zVAb!:\0Q+:*_>Bi/c#H%KdM*AUj6W~=ׇ%XUE@AGɈ}i B+rw1 ~Cʬ=< YADKP *`XA9$rNz߃k0Fi>D5{r7 rT<#P:7ȤB\/j֜{Me{v+ 43=@cs~Gi0YԠD@b 9 ^!T!G>4RUOާ{?~hjE p9y_OdPnb X"'RY jkJ6D([`[F+pvѻrq?o#ٌw>Xm UCCD,r]^Ppnd$!P{peGeK_iFO^lLrܨb%?a8hteS qyAkOsq&]ׄv/vʠ6[eD5e4c\ثy"T4!PS}RrtX\ǍIyChFm[Ih!?ȡ%.0`ܱ0(ss)r2cSTcC`Z;.]'!&-;͈SZ|v)YAr4*s*r 37͹.KILaQuA%p3d  -ۑ<53!YQ$zݼ;F>L>6//_M1ɠ]R!&U <ҙdRLlq'BPI1yPI!*V?Qޕ5f> 6P+:4Q*C0q?+& L\>_^chd_Zng &ϵT:u1>%f ch[N9Gl*fsh {ȩ 3u*[%lwyp"ҹLi>RO\xx#8JN+1Uvȿ_qjm=*˧KHt'rd誳IBKMIr(m~4=u r/b f^2chVlu9-x״l:P% 8͢o`(M k T|xKD;:2'hO s{!P-$g@傇* tΓ6*-Nٿۺ}B0\ !=4}1j=\Lpm^r ys2l1;XT>lv h^LJnSHt&x!#W*E&D'D9``;?n^4:Օc?쭗gͮTHQyv|(_Y(nb~sS^MrA;/ tZ]*lk#}`vaA`*1tXC fr*Q5 bbi̋}>=zhi`fo~0’=j1wyionXNML7g +k_K3K %bP83Yaoo8<0M9aAļJIWM!ڍY͵gcܛrtg񋊀[io6=&JKN5JqeP B ʐU% [8=n7V88K3l7]\J?,vkDbi'[ޡ hPHn5Y@f*: lL1-R)3(Dz)pQȵ7Ywǧ&!ҁ^Nی8le ּR<`[G- 3{%?w!a{zWUWtݽ'D5 !$B_Owfx3IG _i Y-c#-NR}Qx)Nై~%+ģ`Z>jmVŐv^0t/r%!ǦkD`*UdBs42 ѥ jW@fk:7s_zl~KHw:&C<_-B-cl\S 7?f?{[_*a㌨eǓǞLO4j  F)t%2HN!cY@ h`@5ÍJQ3:4|j|G[~L'2> /L\ 9fٻq΋"fEIZ7"$h\io^(lsר1G}/%ͼ]Ri4pWsb5_ForR+oQ~|J2z5 x!SU!Y=p+E/ !g|Zi8:( DР1JA. UzDG B٤ϵFPP~H>9:OԭW=}Իw&,R=1s MA"{dkpkDﺾ6諪?'(s l"[ז}, PY&} F=s)Cf}c?-ޠbcFRtmv4*,hVԷ/R؂[ȅ |;,Vn<4[, ?zWv@r௑Gercq!t$A\G/zqуc^T 4@cc|i&HѲh_nSxX]a8*s alҫ|ՐNisnB5ΌMI)3&s̢Y\..^VKΜ!} #}T;`&7aD{洛Ԝ =|ɴ-fJw\vUo2xyja}ь/ާVo 'ANg.D=}{[I(f@-Ǚb@͈BӌbGTh, =>ot9/VEȘɉ8;;hߗŶJXf7?;]rK"ǟmWd0wV|#Y2["F}W"O&gUEP|YVӎܐ_V,BnԮ %!AVo_p3fR9q2dQ2-0#w+,$5^8ÎS7E2@h겳]4Q3azz9o‡@JJ+@zxfz<(CB>C(H1&VD6K&,nƫ~66=K]1%ܵ=ϋՈsxPKVmlh 4}p'$kb 1 WAcWqǕȀПd+e_VUKJD#o9J3)\]@w҄8ʮ.-?-6O ?_|W%y /KT F5ՈfmrwkN:+ fy 0btφ~\k:дɅe/{eEUhfVW0+M Z͆"KWrU^tL׵2lX^&-#'$=ۤԵPBy15Sp"y;^u] ԩv&F_ؙ-!W.^ u_l )jxT1YGHT%zZjZA8E#L X,ӧ"xqxajGP,'> Z[" Z)5煔;:pB,ǎf}">sjZHU*sb~5W"I}3L!+{j ga=‡1ò^$/MMڇ3ge)-.]~ 5D2=˟ .?ϐidO>923 @jEAnŒqf1_:T,yij7BT1G϶J8iE;_ʌA[V?wnZ7*t2P{fGjM5`7p+{k~Ʋˢ#.X7o5̶#2̔jC_ɦGҕb=FΘ&JFt&P'`>+ۛT#N反tY8}IJEB %|-n!m D}HqoT;F1b$6&ASȕΓ4*d^ҐmW 39]|L^qT`0Ar;m@hH*=8V %V|NJvoYԂ1 3Vó %4Tj ug%XK؋ e{*5ja5oݠ"R.9giN!L`56AM0zxG_[[) Z*Q+NFt!~iF]E=-{f*xQgPŭ`c~{EAM{Xp?\343RlZ, }|B+;&v5Kq:/׼5FKR$ Yfp-]K yYl톱/hg?Z1zʟUYH۬&5!v?`:_rZ-f[:@`HIMexGw TY.xQ,N ɈEm'bf"UbjMmW6;3><ܬc'~%74}Lg ZNmbEo[9ˠ]%$Lg$E@}yMCz9C]VS(T.VII&ÄZi[<+DD{bD* 2@P"[rr1\Z$2YEAo> %#Z甚rߵbT5\dH9)&W<⹘gM>D;?pșxZy 0+J_{zEyTr]ۇ͐zN{KJ.يwzR.:ZZBSdoj}t43~뙧v}+P#ۑ0^w-Yώz?CüuQEƠ(Cڪ[NN@~ Hf8)ĭEG\>h:q9[z^'h[!h-I#LCuD"Dcp4Ó"WNws?gšU[|%KُToNPUaDAQL눓h+08{m`dFj&M= Nyj1E}U8cH.PyZRҕ} U}VE15Ohgw`#q&pG@I2g0o|?_Ef2D{!d HxtM$N\(Cz {ic"vCKn:`F)]S vO%ԡǪ! ,H}OVSUJDSi\Ks ^Zsڶ~QN͘=^ͰX7 }1h“Q|zz˭n a7W Q'(7h8@V]^a]Ҿ=${+_@^-GTUwt{3[]EgZPÝu³@s#cC%$~i'_J6]_\.nZ|N!z_I@]v0.3 EYC: ~_Zt竿+C^wi= ȁeDžx+:*].F#/,b#8޾LeU 6}ufw3[OĆ8d`DZmo-qh[>Uzh^~$ZNF5 )~4~On`q։ȘnQmiW> &*Rڝ`k IL~=/z'%RG3[_GkG g`JK)t9R0(wq\6^3`Te^/Ϧ+GZ:PB7D,r ^hW D^fpzn͛`£XX()ȕiL B^Dz+ 4]!GtZ˟Qw' uU6/XH/^t;ɒ7浾J抟HW 1(4M]'*Cݟ>IY\^T I282@.I˚:]4Qbͫ-\Tyha1ObMolg)aj ~-J(s5)*1z6%CپX% ! WmnZet,U Wt.x:^U57ҮfhZR"- '0#e]h}H)܏Ah'J c(Rg'/+EY yy~Q^wnE qQ TxNqX1Ŋ)Z & cᵰ@ % :Zůw)Te>ko/ AISI8[8D0uQICS\,Z> P-hnGدE#RƎթ ӠbBV MTg1O` Tnoᥑ_Z@̓i{ qIVK\ۭ9zk: CP҅`pX7Z 巶Phʹ1Y(,Eyθ"[7@!6|ݵT%UM";J:b-whaG+5Cp= s oIWZtLZ(%5Q|vzeKb(/$q,'?,IJR`gպZB'z|{lgR+kuywan~]֍D1PN J,TBs#//\; 8fއ3 kV?gF  nm$ߦ2\\­牃y6XK6DRZH{c7X,^i(7mUxN_2q2$ngs>^x#7CXDS=@c>89ٯkM0 "[rJ3` h2'&1(  &ۧ 3 Ѻ! &f4@>-f0f3De- W FZKݠUkBrtU^5|y&-h£ʁt3ƎexE `jda rgX;g17_+`8T3cJ,1 ZփS12bb|5c)JAH3")AO] E=e'e:m(aT}]OۖH bMO@}$)a VobP+B⥶'sylse 1`j#j+GC1u&^:kzP4LTHIJ9TRպ }?new}-a<Ԅ_Q)71PZ`QKYGYƙx|I9KP@'jӛz:GwTkiX6>^[xnr禞\қꇎBipwyjXu^<0l/hۙ}{OJKf9,g;&#d|Gmo$@p6/$8(_ՓJ2^u=_d:.,' 䆃X‰(>,EɺqQv tfʩ?XuG.PoEz{J5pMb]cJ= lL̸Fsot/7GΝ^o/#u-yMz&.z!9ONciuֻ"!^-n/&ETC1HI=K)M0RsZcg0KJj U&E7YW!K+?0GV~lHr q,f=Ebԉ gpi0rfLJY b{?Xo)-u %ܘ7FbKF=$B:k^(d؟Q)vWM(X'zP z &uao="Df> Uh t 5Eҫ9 ?yty!PLnd*g4l,T<tKFMx *;]+x-8@ 0g:vln~;@L) {wÖL廳rԏ򽻳tG_5w,a@=bwr }CH.o,a0.J`:/uyKwn=ܮoՃxDt]E UItۇRNzyO<Ý:HۛmY  hM\T.B̵[@25a/Uv<J cg /f7Z|EM ʸwo~O^HB! #דrn̈\//Qj|*XC3:G< ׋+7ǒ212RNjѰ'KnaﳯpB? {n Uj:XjfHq,5BEnO ^p$XiLE0?"|v*"k?.Kst[Q[]A/Euoŷ؍ir('w,_Sђ, Pod.0Zxwcerv]|jJ6?BD6ase}OvP!QY^wUNPMQ\}~r< -[Q+~/Sl}SM_] gN)٬&]~p5'~-C i,n6GPϗ TݕtovWB{?w1?:F*rNgja`/Y_ zQ5M/B$n0!PKUp&M'pe3k}{?Ob.;Q@uW*ja_&;ӝ#{͘7 9}t -Hń>/AU\j+#vdVZ5hT/7"Ϣ6> >'p)d ̙TYoh(8Ĉd)ob2䇎7w1єz-|:d#|τ5>_WxljŽEbJyFxeb=M(iO;`*ؿMe[ف1}%8Ĵ띁VԈ}V"gލ9K* 0x@|2Uaˌ;IHBPPq%H›6Xpbķ$_b 5 %2lhՓ>#Xq9lO&VFQWº!g*mY~z.@8Ԗ UiZN.JN7/ PH6-h hA3ɍՎ`XOc@ TCVB=2{}`:)'i["Čz#]ggq5$fP}pDZ|fv89%RD, {#*J5">Sٍl\A_ɟm(:fEpbUAу/!ب@0%nf30NCiUԙËYnlΐ k7:q9ė`qu?gHԩဝD =bOnϑfɻ. f'vo s}N.u ɫ N3#/u@_{ . (Mp#vF2򽎈]TE@=yH47 ^9Q$WOX'C;& egmE *Ttrb\`Է^@6abtԑ,$0CY,[Th*Ƚu*a\qrz5zڳv/'-n 3H* 'i駧bE !o/eTI[Խҩpg;/T#XM[2p3œ[DۢS-_!0q/Ѕ4vZbw[)sKzo7"oARsL1Ջ<_j!H Go,>7+A~hTy>rjyez%5P0Y+|,v;T{A7|[!H$g1q}K4J_:{7WI}y:?`2ve!нO\ΟHo[kj&(rfP-;l6Aw$>8 9>ݳ:i\l"`ͮ5P5)eU tԡ**pe#16P۾z3qˆ@@L*?vZ7۱% oIYQI$] W`1ߠXʍ]Tv\Bh|T䢺6c;Uf^WX;C*;XP>pD 1WS|[CP'`M'%@J$i4 \1$ ⰝJ=FLf__GRjX?Fq\؝^5.S/9 dz4d|{ UkvP$t%feMu%P(oNdqҵ2B[Y+5ǐAOUB2=a9n3QBVth~-hAo!6] љWk|q䷡7KQF5OI|!bwstXU` $C }lK>jO[c}RdҊV'8/,Q>z3~_c\A|W[ pꇇsRljGv$X Ҵ5c$ct}0ߤO!\Jo#xKF޴u>~+z7,ٝ&xa |@i]? %UP=",sV5C:O-hqx(, TZl:Ud+$iF ZD W-^>ɾF}vq &&h̆k:s_;3(ȗɌ1\y/+6:o" ^8Ï>޼0^x:b(;E1^WMXX%P{Yƹ]O yjwMۍ܄E3Z~fթLn#翌Ys{ CM_~*eppky`)EGl&+HhZAւʼ@<\=b7oN)ԡk}S ֳ.4hm%b+>PAn qmln'N Zj HŌ[I;O4'Ē%hQߒ&Fd0]ΜDqH32-mH`Raͤc^ X3޼P`*<:c3țUO'3 [XIJuSB@67J le4ԉ6kَH[36}_zaF7Vi361 -(py'XGߏfL߮-@gѱ;7*!徇C%5zdNmv| ,$mRQh1cFojN_b lM9j PwX+:HBrRYõA5Գh$s2-yͦgJ^tMQh{`X\1dxɄ )~fiUH͸ wEoV'W"Jd.Kk8xLv(?̭K? qS*z3X\aYI*9!-f[Ă&ggۇ} Yx??L ~V¤cg^e`SM&iA$M%KAk~pyWf ~/UہM֊JH%%X`%m!ZK7c"~7q:> 7#:)^Do ^T.Hᘱ i_=ߗP~]#Ɔ@p-j[⾷wsU4:{':mbbpτ_鳨cd<y\[!GQ~ p$p#]yfXeDSO;CTb&'i&/q'g(zy޲YuOy ԡ?})@XUϡֽ}d~axɦ+2KȂp"3h @hm{kTXFmxi}PCllj>k'CQA2ӔK lcuv؎T84>sH 8{Ӳ˒aot3Q8muKɲBM@ ӰC2fe6&cRPϬ?Ec;,8jےZf/Px/I"rKRl B !$ahK{W<)}""Ḧ́ c2Gݳ\Ez|VR۳ Jlp|yۂ:"Uվ6?F&ƕb#k {3񍬚/08 8>FK+Dr"b㇢x.j$Un՘+ҰTU ķѱ7߱m }XUMUS*_BFm!I<4/g ui%ds[)n~8^5zTt^%ԭ Fw:I=JѬ[e<ڠZI,rmB }JMczUZczmqFŘ[ CX8GmQ>+xE- k?׏ ӕAh6ȑ&;n-HrӨ7[. ޷&nQtϤaf,=x^·r&KRp[4X^.lej01q䬮r:OU ZՑ@)3 HSRn=|ʕ_nՔQRڊx* T죋8s[XY`\82ʹGJ#w$b3zy^׏6QKgIn3QKlq|R5KK#~חi&;s6'G}){ƜqDQtrI0ν{DOSOl1d9S]xX^_lM95گBgy4E ɻ5WKBʱQ}df։U;On3;F(G~t1jՓ)+1.s&`+ lG2G͚pUGROUe'g1;D&^K-Exu/B2P~ϕ;] uGzl]*f}7KxCǭ/~Ddb=E(mK)$iouh(XrmF6@ē+#G;Ubs$CNGݐll)ҳ4XX`DIO1$8`vD%{@WBnTAE$ln:&xa`%pA`4irY&Ou MđkёQGg+/GHc>*±E3_xvF -BbA.eUYwd"n t~'%K*z)7`;Y!Erz͜0 XkRk!:`8h(HZ%%- _e]$e] JwXgۓB&eh֐k GT_ݵ-e֭|qNm)ZrRvk=NtilЬi|;Lvu'H >0BAb>Y~HDcu$dR4StF*rG:A0SglM)~,Jd 0cؕ%_#ZPpJ 26fO}ƞX9kep^|$=V$rJX_@*x8R:gѸc*MJl_eyH1̓|o"4Ͷ:嵰Nyɒ2pu?2mx|E_ȐFF^c1yrb6PLwdz񥭭Po8ŸEk'в_Vfw# ZZaƖũoWcx)i";ʸCo>%\,i0s+&~T9ZI'pڎG–Iϣ b"p@| x[< L! [iy)FTuox ^5iv`ae&Ӭ[63P^VvJuj 7Y"`*>PC7!~ J"$P: lls7Mnbܓ ,h`"0ӹFnxͦ[0τ|.F2'rgp(+8oy;]g{41 G[IbvO|s3Auao&Mc׍ox]e G''Aquc:!.{?zzsU  yx=齺BhLUbRz12:HWV*;qe@/'zֽB J=9%8F:~xȜ^c?3U?J6i * i4שּׂcزCBHBټo&ơ_T Hi](.H PY(⛺$>™(K,N6ەQ,>`KѲC(`ezI;0`,DFYSP";9Hݺlv#`DINbek4\8@-y;L+FS u qꨉȵQ`itğ8/<8Ch!(k#L>U]QxM;x{ D6P{%gsca=tN¥=dB+ j3a"> GG~(?V #Z,Z3bG^z:&!r1WIC/]C(u&s\qǣ"0Q4Nl=?Zq{M@pAtc7+O-r'^\:Y]O~T05, IB#X:OBoA\[9Lͱ|.B:]8r,ZĘ- hh@D+t~ vPhMRT`*r-sWڐPy1n=Kz"tzn%sʟ:tToOX:YCr#CVCrvr*GI 6U_SӿI 8$_|TH8?ܳ`(qP ~1 ) vPLS<5JJem/$H¨b)Th;8Yp\Mvb&fV|FY08JS]bg^eJލB3ٶVBӚH|KmĔ{z%j3 'ąve\rzo w.\z EI=+,*I0U=p:vJ%Bȏ ƠgMqDPl`29[juE{|O T2oF"WRp @Ōze[[hZx?-k[p>i&}oʹC3pdw{ܞ͒$Bh5q[5o7dz9Cr;]NWjxQ~M9 % +0ܳ?bx9AXɍ^MIjhifJB3k^{ڊSQ,rasjxۚ M^݃[{̌t-ꪘ/G?e3Wh3䖈'>0*wzzeB)CܜNZ :߻iF?oR >Uܳxb7cNSV:-禉¨׻gu\UoYZ(EFź ^eKGbߟBo"4*( •4 y ]u-j>"e@9nnEA녒 :3uQ<wMFVNm.Fk$#,ӌb dD@vGu ?ƝIKz4Z\+{ITp~IVu,$m 1#O!lN  yy <rR[7wϚCoIP~1 ?g Nx&C9|}Yh-;D>d'mX[?3$GCXAEp1đuvRaP ,@U 3p, 1?`!6c '4㣸B6 o+=]fEgB=ct>VԸX n<3N9}g_x WΡt(N[A%VM=[P=N{ғQEPFO -tP C5;K:`XeNնsN`zC- ں?2ċ1K1Qa/NHC1/\g|bc݋5~QP N=mLo*?!ڇ=9{qIGwюuɂ_6qDdLi넝T $.5eƀ?)zh Uux][|T2I&0$l\ƅ M$Kg:[mIyC~O'2'엪?N5ݴ#CްqJ%AIF Y -N":$ [ 3x E|9Thws <Sk#O=I"rFƢ aǮΉϳ]F 'mONi6p ORX喂{Ce`H~vڑ{CWi32tXYY-b/f"utFA۽ OqqE,EHذs&ޣ%^ĿǜW~PD=E{ttT˲>_ q3g83K+X(Q@9MЇr/mMX.8('\E:n];cnfE,étŘe?!o;{@NȖҩ(;kFnW}bDž5q-|ZgfKi3dOo8^l3HvC{ | p A~ԛ&I)QoԾ*qË25q2ǭ.IϏ\ -%<Q 롙ti J+!sӢ7WWa+q[tvK}PG6dxd*s§u%TKh`9$]JX- x7z>Gw`+?QU=x> _71s;V1l7;#똫!;=j-qB+ g1f'/wG9P-2s -|~\ L!NHs );bqJkV$y8x{!ê5I39f!tQ\#[/A+s 1Ú4*:$cVQ2oYT6'Np%qpH_. NλjJŎn T,Vz[>90ݶIi\ڤ?pVn=~,gi+BxW+ZSY Jo*#0@`-PHMzx=ͭ-? ^npՆJ I3rngDVx1%븫ruJNdzuf';ׄbՇ-A'bzBuT#O/shh6a0%ykizP,c |M#ˌ?lPJ[k!ŇPȭGj5)!>szU}K4S0~(&ๅO%) v[`tht2a;U(rS! aL?QoY, QPbVVkDkx| ]>1 SǂJg[䠗Xo^aVM#]T$ô[1={M;ab(-mxOpMu?^rolG^[NjPQ u;%؇9VDK$}p4#>`mi>ɍ#uK+J0g}v46"jJ0k5u 1UeYk)bbtG1bY~<8]qw"iG;RA!ʺFqG%dS--s7(#XjѡK*R^WCk#mc"6œ< +mAŧOtR?7`8[C~Pc9wH}p#4)Q(WWo^}FZB\n.4LT&^ ^viD?O77W8S' "˜̜("A[5ItOnV<<爪 ZRj0 (x OgBBDrGDK%;I3{1f~>߃R3Q bGT8sx8\" 8tQD釗| KB.  Ddz!K:(Ypz=Q@opE'yG.D-8-Һ7YI@ jwtsR3?)J^2eK_GZw>~9`j ~E\|T.5=oXYB x("]a`\I${W=;9H^JcP젴K.+Av)Ol,38UB38]aWO#9ےI2lGFxk?0; l"l9b.UMq;F~H ? B׋uhG)oV$ 7WryGZW q-#1Cu8۸ r2OvcuXKYh4Dw(#&Tx0zA?2~=OWA+X*7b6ƿME@}*qCeE;g9!|@cz,s oE*n Ū3e+〠u!W>]!ּhKXb/{]2La >0A%ZxxX)߿?mǝwz G[M&3ogJÒ` 9MU7kH5@}f-) $*"_;9 {-SA߽,_W TR=.k~@h$QpzqvMF GvJuߪL\}t)=ۚKHlg 5"O,O}4Z=l >}߃S)89x:KD'ⱱZ5eW 9nCON~O[ٴ`z]Ѹ1* ܉A&9b!~͍jyNeW p I]|G0~'F$5,Yv݋[mnAE?$ٗ6ڥҐ󥺇HqР>}Az-[l'HA?([%gbܩî.`+ƚ Z:)W~T30^sɼKK{> <oTgqW.`a2ƓrGPSÏMrJb/&1lhhGl,ٍC}[m"?%g X*4X<CkuHޟnϷS.ચ)]rWK#Qu X++@<2>eKHڌ; <̍SKD.ⱄzw'?jd<**mْfp2N΁ ^_@NatdDԎ QU`4*wPk6ݨg. _ .B]]y(NS !"`uZ~4.'n_!H̦΋9FcV2rhϼ8Cў Y~==vJ/G|֞>1/W?ɏ(YA9nģm?r[;{}ةd#x[¨p&GRl涗% AkX{ PO(d<&W {&.8uNkj{ NsɆvXI X??a9ޛ3o)wakAyC_aT"ͺk.,$BVwc xGA"JJI͊')r ].~ys6BCM -Ng&NTnYSٹNjچׂlQ4;KoRrˏı4U)⌬1v~o#K7O>-b2%Z EŊ`NۊVpr*Ү+샟.t_uޓ^"x@U~u$#s&'*GC !ftlI"ok5IhsfxN_ۆꄭAZޱ;E!Q4Pt(6s%6@Rr)ۨ?o?Vn4Zx8bOX Qe\ |@8l=lk櫪7|TP2_!x)pM6g5Z7wŌ?[J=엫(#GzFKt<_|iLQ1tHh<›",:i OUn"4JKj}(Fl^ 6r%Z$ɵR"fo]POESg]Uj Fc ީ ˻{BܕPh3&u9yz- 4zX(?.Ά|Sn+9=#5[zsj+[>=U LPyCqVXk8}_ekxXnaFZWxq2NʱUv??BaA:qw)oeD9|׏f4wՉ at܍2Em+ċ(u2rxU9,>775gN.9!皁/xB"i I;_!Q*(WBz] ;ֺMrD\%_66hW*&#) Id+-.' ,G|!]50^*bÞ'!qKCI? %4 أyT*%s3r;9d+DԶog16=BXx]/ a f6 _cHƸFz0Ѡn pRSS-n.4dY ^Z 40}"kbAHr\n^5/cz,Kb"hHe1v~Q.H{ m{FgD·>kpPF{)i#vvJKZCQ m/gZ8e'.z\jQܚ{|k<1Ǧy'S $EG5T&8#`a?^+vmMKi0j`'؍ň,7 LH-ȉJt?Vq~,5D@>r̽qM@4S籬Tk1܎ttZ!<>!BeJKD (bMdM@X[БfX~Ίg# nUBM(K^lժGWCF~pk,r2\d׆Y@IT{C إ6V,4^{p n?kK9pȢx9BoYtCK" N]nؗ>H aѺ:Wg (tNJ2*tՍFp^lЃorv3ޣ\' E ̥Aۄ拗+}xW Y?fveV*\QwY.]+qb ~,v^ˎAB};֞}{[:8,iy{%Z1"Ba.ߖescW#9SqG-fKH}xLKi!Ӏj8gq@.te+% p7 u2UwJrRgBhP15TjK=vlrG'K%;Ps]豕@nK\[TӺ8#L{^MEEދ귮rB-Ȉt\s#h4uu!]r݀ |YbpJtQ1 f!S}@ r72"`}Eye#j D.'f@l6h8A d~VZ!Â"AB@0X(A5*AWgCQB!Є 3|QâX>}Qzff q-g*pE1Xes;Uq~سȍf2 ڕDN_e*v_suim78ZKЄ vև}=`SD Cgt~Sn̂ =3' :Iօ6|JBj) fةڨ{ q0sծ0/}52TrvDp1h&1#+L!Z=#VfoWRKX6-3S@T \.3{UqzvZBue$zWxoC#@" U֎QF/r2=\K~W(VO`9Onf|3KRmLU,g°wB}8]_1GTDuxqŰ-D*3(,(D\_mvD[ P [:;>tmUj?\ң&. I6TV3E3luԠƝXiǯZ-V`$UsΘ}G/#L]jYm)_] PȺ.J,4 U _m(|X~di?-iQΠ#kCp!L +\Q5]~ep$L,k3>ay\/Xb>ԍtGK~;R18M$̐hR\?!c۳Y2b'W/޳% i73:L@,YG٘IWy'R<ХIJ3AA`qcUpGAvHfy*'G#66,~\$ hIN]n~M$0UY2XL j!k<h.~yw?xFf8ϑ eNuV=^<'2ran$zȘ JR䅛a8F`.$T<8PdXݷ&c/}dc=PZIk7_3%_2!;B^wcDgSbg&7:'8/u5TGnNϒ8B\h~_ќ$+I/L@q<͗Wy1 .ٹ47XpDK2{K?O 'McY~7ku8׳n=81x=ϼ rLxi[V]&( UQs+_~L7朄Yk0qg=KG92fuj#ʪ'`"߼>J!^&=[DCX~”0D2À;xO!JzĸDw aÌ1CVc/H0SWݜnӞܞU phۺt-L ?c*ق;OvjM" ܵʁ=ݧi@w.Eb-j!VZHbiw+_҂f.@M[ uS;T;4Uhxq"^X#/P2 _@X[Cu؉L,M6iU@p,ePW%yzB d@7T͒D4{ӣu܂X *ơ-MW҃.:{Ћ46>͒~[nd54&tseRsuBhq랮mz,sBzc8Xrhfl!Lgp!:1m5?s48P mκΔk-#tɭ *r1GcסAK ͟*r:SJ\0Nq?=u*C UtV:l@e؉ආi,OY;&C&>?c]޹sy=q0yɓE/pqj3*i=HR\4%nTGE ݃gp[TL&]%cׄ; [5cYMaS`3!e~ΰZJտ2܃ hYD^FŷwLʷ͍C{œΊaxFNPu6VifRԚl #2_|b[N'JbԢP>tl4A8F S "y_u> Kp@A4ST%$oHk @G*yM: Ev}.t1|.ةn;|AR;\g@s>%H*g)PQ .(lz8luȄi܂0;7lZ pi>M^$KlR(v ߼p[R`|P@vHQޔ6)u'd`Gu?#6m*G$RQ_kyX.J׊D=!JSE3f;yb-"h|gs1jl[Ik3|5Ͳ]%ڄ^)"L#{(Bďabg?ylr>#߾Tηո0\1{V>-{e[H똸<@ vFSYd zg5ത Vq=AQOlQ'M:l`INY*ó!V=Ɂiof݁v^_4 N^&К"&pDB;*1hfJNj!5 @k#Y}wA`N{M)83jϥMb_p5 Iܣ-SL[6'WxƬ+&@j *= MJ\'z Jfz-}ΝH/<5fTVEB61sF+ xׄ$Wf@ HKt'85)|͵fO[Tpe1מr ]#dSi"V~9WɌMr>sR7GDPc1moxYѨlE/P,p+lD}Btuv UY:ԹKj@J'7KLO%EGJ73+t-YSӡB| v՚%DǕ u|Rgy*0MYgB+TL}a_@WHxanl>d&cRa[]=㞃 NU;GM]Dƣ{7S0%J]rZ6fi"OPzM[tBNJ./1$ӫM;Sگv,f7p#cyeZ OJgty]8X,DN`2xv5Ivw؀pL xpp]yb5.`US$7۳+l՟ P}uqLވ 1iF`' z"`i5!έ/Ċݘ((VDqGY`:[QuC2x2l0&ڸ9E5kP[s>{~~A[0^l&FϜ-@5d.:]Z>&ɇ%8Cp#_ҋϖ0h.?`TtC7W^mC[zB.<^G vŨV\KMqۆ(Z##~y&Vl DVžT) {GXbGF*&*X$kq_;q1X RpډrQ9FBY?d쟚>F[└B +2|2Ɨ'"ma- 4uD$#FBc'ƬJٽP$Vrj ۠k2&א,KŃŵfm/!d2Cw>4#'TbkZo]} q\R)Wu- U)sNˠ>^7N 6 'ny V#5rJiaQ}$^4o{(P#&}"+KuB&MX1F6Y]:: r՘=Ϲ_챟ߗ{FD$TLs3B='HTFoonf @'+*"$Ҙ4Ŭ24#Rulw` }J|XQqcc';uRe9v@ v+e碟l/BXꙘ J`:b?={(%ċ2>aɄ8Y֎5v.wu:ѩ#E#vςg a@Pz3K(.P} g$W"(Rԯͳ5ӷ$qd*oG_iqz'+#{2SG:!1%X +Lb)?m"3ymˌ݅ˠCY) cYU7:& ”>N9si%&Y=H0H:ٓZ ]%A*S;[ʂ+=+.ԭJ![W>(PeN~b'JTxq2BK?~Ghp]AqO$#||-<:og׏vXevCP9*Z%72( pB#7J%kͮsTO"xϕ& >{ęElxG*P|haaLr^ ;A+>vr.Hbhj /gq/l}&7d\yF~53OO:@')]#8:L{֢lѾd , +r*,Op()6hbW~+(RxVϚYI'#&̬7"Iat>Ks6gnb-͝z4ER)?x!3|aAd,sB! yy=-3Z*YO|1݈'̭>5g+mǘ4s5*]ܴ<:]v]¹5({B&e>8l &2iA %:%`Vp@y˃v]-rH{_i[w!1̉S0궶 [Wa|c݆_"--P|v J(;k%&J1+4 X >} wO%ѐ8ehkzQEf|Q04%ɲ)Ws)ʳ)*_]Μ` `T'F4j('tE+L:~wZ?]ȠIOz̃_evoPZAĕDi$2{UqpO[> n.>J da1]/Q|d5` x`]G%GTu%-z13a‡%Ek$Z|p>NYB,4׉W>G!4ݠ`|m0\lx8!:sw-Cf؈(6? yT=nV |DeӆpezG9HwHuJ}.u{hk-_4[ 5G/~u6AOzdf0\;̼Y鍑%(#ކԘs w eDR' qH>FMһĒ L8[vfW.$<+h>/[2j*)0sMr 0<-[kP& yh`&!f#ZpTlk&lm4BLx-ny}9Ǒ>gҮW* 3_Ё{VUm8UвNQU\n%5T?L1c\4sOP]`ZXRӣJ"3Ao^!-I77vNmd/DQ5jՊZސ#IG` 43&:yD^zuњKS8)R,*)ZSBN5rЅ8`hu:gL2]$R[ױHVQE4 ,tV(meJhd-{,*d;(ϕ0)6zӀo!_FxCky``IvpGj&ŕ{]%{=YHmXq~D2ܑȱh[u]` Dv02|Nl]_EKV1e)pWĹ(Xr qlF|B@byw4V|^/ ݮG h3w", `SzGR^P96UYd;dxHs. (]O,VF,Z-q`屆[˛&S֪s]* @* WB !W$Ǐ(9Or}GfD=4\\g;CbhWó7+5Tp;Z"nhPӭ̑FAV!D^p^wlͩmym o yzat,]ޟ_/FL[52;zܿTY;9kiۨ3<<@ MY s4D2r_q Ffjff2|9۱[+Ft2[D< l3 /WLl){k%L[kYM/\~9q%O|| jܳCߥŠ]S5gm6Z]s 5j"c1[7"^:+ Z,͖1$pou&~Zs^c1d텈}:M:ٱa@@]0`>kFG{z/((>LL#5.έn\lGC2h64B NSױ΃DSP@kg)*q{wSЌ략mr<=вe5!9 w#y>f(Aչ}6In9%R<%(#͘%`K׏;{@>.*Bwn-G+>Lz@%$clCTLXU5EzN"{3:jeiN"O {r) eW'԰l3ƜUYtv2p+,Xr%؄ēj/cgSyx6F*4 T f7ii }fk^JKo.aUh59@'9Eў&Q" fq"~U>i|܀ WyK641G<9ֵ_>~6 >*u"y*!ҞL:^S T!ϫ {\! lmrZDƠ$'^Mŧn lIvh?%fi[L b-6hbrͭT\m_Q# ^[JzlSS4EuAAJ\M=CJON`JNJM+F cC*K Wߧm7p5S޾2$F9ѣ"L]1![nIH߶#8 DHR.l=[}yQ1# h -ͱUA#98:!˗:hɺOYhP3|N,6<%G3$gzrC= )%H~D>ν 7=?\&ӥ˰떶aX 8#lu%;bf,XDiQ xھ%dPȔ e)'9ZT)5~}6\ KKYk@S/\~^蕋(G6H\*?2'ܿ?]ڦآ3;Rk9}y3\ؠDFCVp@vt8s^Wg]>W!Y ^ .{#Ԅ6jylŒzzb&7J+-J l,+88; ;uq,շp# )zˈ6hHS:(9~P"#I[?*j"'Ci68˟-r1E(3DդX7u6Ku`NuVn Ԍ&{H_Zg_,=gJly*SNǟHn퓁i*+֛te ?Amyq/*u;d]O''Uht"X>Kޯ H]TK5\.oRs*>ʛQOI̪A.ӵ^Ѱ~|>%6?1X.%*18PäDnM++Q*@SPƱ /pPgH8?^]Oo¢^P#.e&vs]R?ZVDE  N6p"f&UIS>S, 6x ҕb$1U,k1` Of~π!0r.:v$b4 GInQ1Z·u:Do@k*lb(k&x{i=jtgM16:QHB !35Bh@<-)v.!AH~or#pY{W{F9L?|hB}W= |GN[_y?}9q)8J)c m+4%n&e[©E-/8V݂vMqkty7PB. e񶛰fҧx`+GMcq^$eS|4IlӤ,èeto="֢!rپ"?Xӳf9a!WC+plN3a 5iK񝝴B><9arK~:/'?I>Sp#W$[ g@BNcɂ˜YNLz& <iAǶH];]~W^3i#ӡ8g#H\LrZ6q$"O{|gLu]1 4ܤ+3zL8bR= W/GA?p7̡Z31S1:O {2ŎqS=И}#RvJcsbQ}Tލ$Vhȸ 6N>I[LY}ۼ;6^'ND]>n]Eu{;afmZJYvP";B~H# #0ZiJvɷ*c=U9kNS%SmL˩}~ڔ`(/,"@_w+bYBM=)Q{S陗 mG|>37ao['3V|by$q')FfQAu7L"'w*.ÄA8ه BߚMʺk FEf¦4Ukv=ՔTcF>̡&.*'JxEwDN*^fLʛ޼VSvk-ozG ߹-H(ptgq.z1fW*aJzNUIG'SEuf7[0~PvL%Bj_TpWp:Ba;ު !uSјx0/7MBog7!*:^pk]˴pZtE{XqTlRL{R'< ݕ#nRFJ)܇"` K>negm)5pzoއ SUcR?6q\T鍏Y6IG F? 7)ݲKA,G#u671ώ59Bk]}n쉒.Hki{lHfлs2&:.(X]ftK=Ub87͕D`%% '`1%k:8G;а}J1 /遏Ex^ X_z;(Ec1.)  uiE'hh 1)3Qd-R',FrRIVG 9Gpz(Uqx]"r&`?JP0Wyo)ҥXr: URi7-"Rvl%IՒ @;ZR5%7k_ӅyLX$5)i q{$~S7 ?MK : [SϩZpO:$F+vOꤨVF &o(`m':b& QY,I]u&옽9X{v^1%S`g@a {|#1F/ 5i1+ ,̩j1չR3NO)c&4.iexmGu&}>77:J_ii阪 [Sv U8y,)rhF)TX i]0 6 x\GNJB?]]JTJnk9Oz%F>@[eΑy1|dt2GM̀0 Q,jFG!s]rS!Z-*~%qlM 1R*S P뻰AeS: bzt"G A? q2Mcecx#k<~RxcZ2:ڄ̀k77)㊸aa4씀4Jhk*D8%ΎZÕNPcHVjlw[%V)hfhb:zXKe~:ZQ{u֝(ȩ\U"ʓ%w q3 <)ԃMK-垰^$I<$iaMsOZgFWa[Bnlj#׫S4ꃈ>v+'7&o01$ ǮH8M}0Fg ?nuWQ"i׵%U77fJH6sg(c 6JuTn}ԓ jR>Qޕ$HN&]f`9Vԅl*#bA&vD=>8zl(]Х YZ