sssd-ad-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`fȮ ]mtZ`={W+,|,TKGՁ` e6 m_Q+npя .b7鏮}~jp% Oo-O2o G'"P"GpB̟ !ј?PWO_ێΤB 0$%֞"FGZpic ' ^w ͈0MOUWf3Up~[,>v=:;*H N0+<[ya3C6XMq"?He<Z:o jLJ]qS 7hHPLߨ'f`w˫v')1ؕ\eҨ7u6Y&+HOESk$ NF-@b!8A-(#j[aa*QUk:u@sp*Ӟ;! ]}6 _z{>pE|?ld   5  0Dagl           0 d   8`II #I   ( 8 9:gG( H\ I XY\ ] ^ bd4e9f<l>tT u vw xL yV  &hCsssd-ad2.9.44.el8_10The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.f ord1-prod-x86build005.svc.aws.rockylinux.orgsKojiRockyGPLv3+infrastructure@rockylinux.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxi686%&PK:N>oQAAAA큤ffffffffe+ffff8952d822c6aa80de45c1b1098da094f5f513eccd6dbca0b3903788062d3d31c5e1a7f423f2f5d679487412b3d198259951d36d6d2fe6467292a280d11968a8c78ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9032dd0e1f82ce8da1ce127494e6aebcf70611f652fa11fba40d016a24c83e5cad2c4910d2fb3d7b1bfff2231e5d063de44cf1cc5cfbe974fa8d3da97e8242c33a1d49135da899fe6ce90bbf46d77c4b3f8e6b71e4480ad03ac4b3d2ca650c60cfbb763c8def7e244bf9c06e7742e4c347ccb5b1add5f96df1b7de1bf43d4a4a49c../../../../usr/lib/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmlibsss_ad.sosssd-adsssd-ad(x86-32)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.28)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcollection.so.4libcom_err.so.2libcrypto.so.1.1libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libini_config.so.5libini_config.so.5(INI_CONFIG_1.1.0)libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libldb.so.2libldb.so.2(LDB_0.9.10)libndr-krb5pac.so.0libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr-standard.so.0libndr.so.3libndr.so.3(NDR_0.0.1)libndr.so.3(NDR_0.0.6)libndr.so.3(NDR_1.0.0)libpcre2-8.so.0libpopt.so.0libpopt.so.0(LIBPOPT_0)libref_array.so.1librt.so.1libsamba-util.so.0libsasl2.so.3libselinux.so.1libsmbclient.so.0libsmbclient.so.0(SMBCLIENT_0.1.0)libsss_cert.solibsss_certmaplibsss_certmap.so.0libsss_child.solibsss_crypt.solibsss_debug.solibsss_idmaplibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_krb5_common.solibsss_ldap_common.solibsss_util.solibsystemd.so.0libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0libtevent.so.0(TEVENT_0.15.0)libtevent.so.0(TEVENT_0.9.9)libunistring.so.2rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-4.el8_102.9.4-4.el8_103.0.4-14.6.0-14.0-15.2-14.19.4-4.el8_102.9.4-4.el8_102.9.4-4.el8_102.9.4-4.el8_10sssd1.10.0-8.beta24.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-4.el8_102.9.4-4.el8_10 .build-id3b5f9fa190c868d4da44112b48cd903b8c15e646e8d9a1e61a7c8881b2415e5c6a5efc690529a991libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/3b//usr/lib/.build-id/e8//usr/lib/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3b5f9fa190c868d4da44112b48cd903b8c15e646, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=e8d9a1e61a7c8881b2415e5c6a5efc690529a991, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix);;PRRR=R>RR RRRRRR R!RRRR:R4R(RRRRR'R6RRR.R5RRRR R7R&R#RR R)R;R?R"RRR%R R,R0R R/Rsߚ*&dkz83,:MwYVOBt`dxJV?C!&֊Oa *oV-vSu*CQ?FdEsQ#XƓrDVo<0y3]{etmJVN ?[Q(3]HC$%BD920UD nmP("r;5\Zyl ky19.r Z/~R"Q7:}h,h^^,PR=_V%k~1Tcn+ {+INIçڬuz5eXֳp@* _ם_פRDᆪWו&R·GR>,cjCqM9idFAy6V(,bV%t*~Q{qYxZM}gR4vae(\\Hs SFP_3E/*U>8<_{(kGJo6-9x!߾QP ;3'~WXGW -В2Ao8`WE2gP>­sF އWu6ڃ_⇨rQ2*Ck`w2~ W-aNTb 11n*d;u~r?EXՌgŸYtr<$ ghZϵ>b2`A_8ޒUNj8/ɕGbf+:r[Jq&/^J?I~FF%}(@it~61*j=RX!4L/{nJ+luI| 3G|PLzU /ucKl)܍v%M^%4QNgP_jr]"~\cXP& OQ,YI^ [g.zb>5@/n0iyD'xFxU=0dy;! b(S.۹s8+ @2/r:y *a]CitiũG8g?\JۏyG7%ӄVeQkfPXqOcp d o p4_ &~uJD}=S(HNG+\րCtb_go $ϿhȽΪDſ!ʟM8;c^Yuӆ<58 fq<A߬E<,%=X\mYw"|n}5a34A-;FG綃7e<܌m߿^d"+#/S{#23|` KV dIU%uc,hr iPnTyUie pL):Qʬs::Lږ4@ߒ CoсF{*DO`Q#̏wdްEBnz;ԓU2>s^n!J>F&I)H޾I> qDv˦ۡ:xSֶH'CWu_CfRLzЍ~F0׫wk4޿~5Ea8]h %Z1V]n8-ckc:^5Z~ߺ6 G "Zj JB~J~c8„[Y"V0VB/%V\ [uhCy`!iUȊqvh>w*ZkV8i'>qD~~\ȕƝ)Oz؎7S H7DOY]e! P;l,|Ⱥ~Y.9e\f] WBx# >feY>IߜL׎6|*֊c7x;Α'A~]8ighMfx,\RDS dUff+wUK$@7N[Ch^se^qB vZʫ̏A#|eڲ[P?N%}U,s`,:e4ovod+,"l[Q) B֤֟,3W %HyjMUdUHNLRɴi=,}3 jpӃVYq){FEI Ol8Jr=6UP;łj /2"DJlݍ96H05pNVqBx|b7Οn[!X%v dBFel/=Adݺ,Ք>OK:*փx+̅Rl=DOR4nW.2ָzQ̓ʶ5=TȶvUՌ99>{fZ$X(S F? ㌒k*f%jiA[kC}tr>>R8;PJ2Q?pt8"l( _ݩ.qF+1]jD㨦`(xƑ5 ̻qSŏq#@{!Oࢨ` U6OK`kpH(]9srm#OWbp19":AG5hjӶBE14"c68"g#3Xl!SK=ob@xqA$x]/.FhAV>FM!}yFQ=c1@Y 7TCYVL6@ȣ| ݓ T_kn`I7 fT;#$+wo+i1XP/V4ҍ{x02lE UI_No]!Sn:V9T{ $D"Hު:) 71>qu6|C+șDC:Z8/OG4cS?ѿ7 Iuy@f#ӾgnDAܚB[_>w2TҀ6Lr^PG QA<$бg5;?l!e&BJΕӆ80Z%aX< Ӹ+SA#)K/>thDU!0Ho!Y•D*Śs5NN`$|+#pK@le~WlAՄjsS*-f޾ѩNg5$0*c$ٲ,-A $I^sʺz'T1[C-R^kdL?=W99/hy~Rnyvixi6Pl{(66ǥ1aI=j'BC'B_'❒#$>IY\.>MT&ƨVJuMا%-0 Spom}:8ZBk ),uf";>Jpyh5|0o9oydBES7A(YRedwqS639^ }V/7k-G [Q{Drݍ/AGBw#->NE=w+LL@6UW]ONiel&o_T/ogY28|H 03;S|Sj4m)th2$`_tp\3|EZ4Xr/ ѯȤ?U 9=شRj~+-20\捀3Ћ^{&b'j-(k/]"},TSEqVy&,4,G~}(s,c6.L֠h(V1w&t%34x;vHL3p!:b1z{f޼ mJ^=rpȊ~g M1X*jh\ FoVZlc2K zeF, Pπ*)G&\n /Y!*;O#r"y摛'z\39G,F5F f0tsٖHw;I\i C9f(x># rth8KA׳6ٮo_ON W?&5=hX9urpOOXJ3W<&"5!4?ܲ9BtGayl=$GΩ}Z GaO*4}b^#! \2P׿A(nD@KaEaRa)j筹r ;i^'`zjJq/0:juy͖ki%17> )єhԴJwWE'&/'kޏf!.LX~oن%rf8۹նz@W;3aN )qկ8־<хXNzCԇSK^Q2MK7Ez3$K/rc`~eѕz.Ƿ][23eCA\:35~?8A# tem!zFzjwk1o7s&| n?K4;ʮG+8VE~#bDPcVhƳ\S܌XVuB3NNjNʶܯCf!fSo(5Mj5(+u%$%?E=r* %l.Pr | 70{^1s ;T]F@hpb#~)=v%m73dỂwʦ`LF-dsrLE7|r,K܈9;hؙ .p$c\#W4%[f T1ْ3(hSO>ZgqdFe&6p!\jz[\obK08lwSbCÍ6&m2|8 ۿ'nUئ"(\@xʖSI0XF 1x!{Дt Va-e!|IK f}'SHYD:% $FOů |ֱ;gpe ,n FǵHJUeHT/LzApo@)㪳W|ޅ r*6}䜿ՌM' K} ,n*uwgq+5~5R0v{A}\]2(έU] 0m  zUW,Ih@*>ǿؒf f TYEESF5F}\-5Z9ʹC/cKs\)ɵA~\.#C`M)40CvqPQ44jAO߭r1#W̯t1R̩,_~, a;24"ڌ{椿j/yJP}v0x~fRndfK.*]{mۖ: }Q?ݸ20f1pʍ,+7rxS0Ի+c蘑,ٮ<˙R@0hWKf P1*1=IF4{3=d/[fcJ 6ze@cϥYb6A #ۿBSXfE&( ~Ö7eh\M"3/A%UkdsGuPe0Ue|8YgGsĩ#+6S8 +4 gpcYFXbCYEa9ćaR`tl4!LET>d r9P蹆-r׆xb#|xT)y MÈS}$ t92}7Ч$h=;5|NWV,#H0tz%1Of-)r:d+q. YA.\OI•9 @CEʨ<ѱtA0?Uh& J-8 8rHGxZI8Y]kd%~8#D&M#0íPEɹo'웾V`b7tͬK: UoZ>MB&f)!jxKe~?˜#[--"<<.9g6na4wF$'ôtp* RGkM"@`9h? $m g{GE,Ƀ4\OAX-9d) \\X?⏾<8E[f KVMP׌v1Rf52 l5~6WP >كR1~mA~(k 9yMRS6 ,t41'͗w)Ʋ4=6V#_9Ԍ$gpcr8u^گd :[o-ԉ㽴$RJnEӐ߻'`MLF=z=z,c {8_, J{#pmcVax&ȿENw#i.԰  ->F {cȥ''<|}DXȿ.ja\]PT@7Epy)1ju&0mb2N)~'"Kաɠ*joÞOj?TY#j$D<M-q=s&&˴*@t1rUNjFIh,Jʙy[]uR70jW[fv/!\iUnͻA=]LUA*{O# C IkK@@y D%F6xV6.'N_h滸mskճ.a]ӋOAO~%ksa9GQ `c1R+ܤ+:n]pMzC?ӞM8bYDgY"jﯷ!8zz5T1gے_9C7}efo?I5~k szZ̙ j[TC1fT0{*A2bf) C_|6(Ԗy!_U]Nu6&CEqh{(G]<{ΓZ~s!ZfXuzs,>p2m0Bfѫ~|hcSCHOuN>g Me%E^ O6HWjB7lk&;RWlk ,l%]b&{  9RQDqHNISyݤ ( $ߑ/7_Z01}8NZ2ԗm<} ݊0/FGPľFb-H;t:v,F-Q!wkxB.Zׁ,eY]]غ'4u6Y @"Ŷ)@m|=jFD,'C{%6Z2>(J\I =7lx_ܪ{^x}l&67::W:j3SL¢7Ęu!DA\74Fjl )-Dil';&ŪV[pwP 7⠱}P-)ݿ{D8N- or} އUulE`4x Ejn5H++ΐ dAzwunaQxH]/PNT~/| :*i0u*T'K];C%H9I袧n6KTB': $Sh,7Xz܂Mjca2I4k7'Ѷ^RČya+ 1e7É|g*IIL,hX#CJvfLۃFO V*bR s}OCRa,2vu(̅ثXMAdT)6P.N]C]n<ȧ%X],I릣06{>?&U^!lwsث`&a- Ls9G ֚CH<r=i /bN#BAZƀQ0[=ۯ&{U)D>J'4M%P9[Av}&$_ΝnnjDu2)כڍ M.@)bpofdYE1j>ijwzSg9p~7K8ڌ8(ULa쀍&Y zHuJul&]kF}CԖ=6" k,KYZjX,~;p9H:V6p ?f lo^d Eaۿ쎶/\7~q$(O!ʔu`9e'<>$},6Ӱ0ԭv| .a2U=»*WQUtSSU#ҡKũ"BQ'<`7z﹮UXEt6)gyzzUR_2[\Z ok/O ŴGɵ.ZW`Չs/ %ڡVX#@%R!#c}ܣDbN$h`2ʠ)7o-̫^*בڿ7sNUis^'?efoև{iG:lI`m,Yx㟌,_CZ׿Zw xѣ癿dm\S ˹ԞF53cX K/"aAmJ`fwn0ȏG)p :,^h,X+4ɭ-V`m5(+\7֘U6:),Zj1Gq_}x.~)zi(S7`4U%CDX sso- h0B80kV8m5i5^XoQ *t=,’*g 85Sl{JQm-+7'#1YkpQNzcVVQjC\˖Iz??P#f" Zuir_-dA!Wv]vdar^f]UB2VTTFi eV4 `?xYa;S:E>=% !=BWRfʬ.$0+el,'a<`,[@ ?OqTu jm״|h>؂`¬@y-3d_E|^G[D^ci卛 Y(6YJfv}K>QaʺX3j;pt rtqyD sDY<&D!Tr9yZ8 ڽZ&JoKocpxU=0 ޣkGqȼb1(m%; m#ƔX^ںnbd=qHYMDpT*woXP.d$zş,;4H NݽFIA= "ci^ڸlj&υE7KOh0k2=l堃Ve*%>F39F/5"^;t8NN}W|$n;t%XOΏ5U^GM$م%@ĊvJ5z=նf9wZyJ;DZ{`%f.Bf=48H= Xaep9LsF]j4YCEOף _+!"Q$. = |(h֞0cLu|hu/)ڢڅ\\^\yYbps#fea=??b;^i5+<.Z COA|ݢ+v_=sOnEB{]}2N>9f:?[l6 ^7-CsǷ%p(yd&k.V]{yu$6 TU)-~g`Fʊ ϼaAЪa^ 1~!xůNn{%K; HFWczv|Dj)wKs?咴ZW %c d`#\AMwqk^Lku_UM`޻Ũ#un䗤=tÝnjlbH}GDsز`Z-9~pqz,9d]6ƻ uWFц " ƏbɁxLM"#|m׃{Ӈ@i}  wh(U`14E"3901ºGrѽƿ.v,%`[~-ZNwӏ4髱zkCoysM_vmi3YS=6a!4>MV vϵ|9\.u⹮:Ui%x!vw7pqwp>{W+_Bvj,*}N/[cx-k.WPs~];+uWdv2L,{B{~6yكl /9΋UHuP%ѰҗDsy ϓ]赀R5!x3=:K\9NP'VEuY*_ dE1rW`O MM`բ/Zd^JBM%'*QdM1 pi\?;NT,HLԹRFآorTV=2O ^yӁoMq#vt}-I _>R"CE_GHLƞ9̓K3pW?C4"Y9W.i4>|gKlY#nЋO"5N5OKV47v|DZĖn|Xxf<=F]_a23)J @j8Vw%MwRƚ"퇖9k+6nhX$LWs;H1*"]yJ4#(V\ 1~RIR HyW,76Q ,mJ[-8U $yhc8k&Dm9 Hf,:Q8$QHY8v\&*&5&m mZ[]@dH_([#| Is$AyDq):?|KpY$r*L pҼ> tթĘ`9H 4rNz Ly/]nY> B 6Xz |$u["P=Xn\0F!@d4GkF-Ûrr{G=6:u5D8^Gc-ٷ/< 33Om:ќҀv#]xahE[ wVc=[*3d2|_35QֶkZn; 3ǧL) D2>w8- %=?$޴n{۫hh5"ᣗp™aL\.I4E t;HQ*=C|uK0"chϬ i(2=c]iW~HW&| hABœvӦ9e* Jv/Q@v=Pj*qW+TgNu_:G`6NMS}Ӌif#30r0FӭK2~(,nL v@R^iPbR30$N]Hgj_UB-TK)QӀ|`S):G6KQ LV23ʤБ$ n+j\wJ'; t" w ">vIZ#,Oڶ}HA\KI01DT1 LNb ȝ}wP\Uafp^̉qn+%Z0/bS3Tgؗ5VS hNP8/M{TʋӼ=pGZ?gfoCȒQ0KJ~q >q? Y{#{ZAe|Pڃt^-h!iAo:88q#_A~ y_)L #+VnɻD`$~\oChkf5y_nA*O12BqXd BP8&YpC-RL/<"Bz.<(#M@Ns{O ;p3_5'W2yp`ށ9q9*lC(fҁƘqb]@/xCEDMULIסi;9ěq$)//_XNo{qaAUxeSU-KɢM UҸ$av4 PkacO,y8?>0ڕJN qGP@Ubޘ(˜La"1 _Q^.lixIH2FP Te!N f,{ ];_h"] jdsurz,*p,Lv:kzj>S ?44c=ɟ'=pQYӀU 7F5M]ԗi餜&,Zx>D i@9FN빪-s^ Χ6LQuwҵ sP1Z6(Io=+=ޒu_Y;UM"֘CZ\R{BM6?U ȅ$x@ā;"S=, K }),8jI<T aB-\)(59*!vXȣփs*FbF ,a}$`{?L^9B({YB`pUܻRcq1= "qgnY@]8 ׵!РQb' ʸj('aQL~h |Sά Qb f>ILy/~ { w靖,G$#v+e{܅39]Yc1j20!C!fU>O>Iv$ǹ3?Ҽ4^Lie^W bt SDm`(Ǿ_~}7+6dP>3+ZlT+ >ZMPZR[ILbq;Ȅ/"Us3? v AnJ݉U&$B9g=!4+" X qzw*JR*Xvx ]COxyHn`Նg(Wwd'RL/K UDSn*:}%RPGe}6eZS&nprg zDά HMD93':]>\л%xgm~EM G_: l&{j_p]ѧ__L#X,E (IW"Z40AYD\?PU7]<55 QBA!d w{H?p@M-}OX?X/ 7t\ $8!%<٩"eav;9-/,%bn4T i!4ѥvKrD*As`W=A{-Ƈfz9׉kxnN-~fkL"I * I]ەF܍r5.kx K1=i-c)eQtYyb8̞:k_OJS#X uܠ "?("mKS|%(C>G%Te٬@pp Fn1Qz*.[9"$s*iz#?uDj؛}P(7w.Gݗ^(9ΧJQtЫLSOjpNfyħ!LeFẀ<Я͇o" Z|u_C=\@;`kG1cS6n靗*( #/4.y}87&rh,|;aSF_JOlN,y:U3[mtG[7f/NcdBJY@IavsBB<K>gt%쏎i'Sx9X(1^5WAj ZRz(R8S39@]:"T$ѧT`K<&ѭ|m >.u|p"=,ϟicici\3| 6hZcؾMl6AԲLmN\QR%D7w5 sE g]f轢U񳎭w QuX҈ċ ?f5E–HۦΑ.)n%|1" .~k&׈H|iO0{|"Ѣ~=^ Ƒs.#-ކ E\ͧӫMQF YS)`-J 0sf,$燩 'FulY"H+u0lNU\7# VT˸l)lCx/A MpV$ԢDaM(O oTջ"02 U3]boonCn$d^"ղ Ⱦ.K_yN` 7W)åa LPeeaMgMܨЖ"btPB{4jwĪ VYf CkҫK2NJrAFM<l>HXdנcl.Wk3V4& >}#P\y)"o 0`{^'LT^ǺQ"Z~њpӰ[.x0P=~)@_Y`4rrE4߻8rHKkYlsw+4#-td#k|bBM3=? m8zĄu@HbsG@svG}c6¹,IjǤu,G6Joϓ{/Q+I{Ym=Um3ex_Z5)OΌ"f kP*߷Y[}dS5ͻnۜ'kH:uZ}yiƬ}t:Ɍ^t^=Ɋky6Jis*=a '˽7a U{f_3c.Cf褸IDŽ>4AZ..@cy%r9 +t1q (TD鶚-^!bR[ѮUHrṀȝv3Z?%<kTȊ⓵pܓ&U\RBdmf~a@Ӗ8,l#wK̼G{/Q:mccb=EOtnTZy"4K*K?XOe%JZoRq]QVg2d8X,2*iet૰O`\ KhTX>l;r(vڌ Jϸh ^/E^׭mOy<:13v=Hu77P>Nq8O^y=s %Ć :z-T 6F F?݅C:2cM+߀⇿bBc'. vU50sM{"![VqE0ZS| Cl J |$oJo'+T"./Nń#Um3Phr[ C&Ni2 k,2/̜.ѳ}M %OP3ZGa 1*jTS 3[5ȃ@2(;>!\T1%6PS@O]χny,|BcX w8Y‛=i?&b;;+ZV7xSZq'Bqtoo8b8GJt?xڮJfzVV=k^JRd{4g惟4~*"CX knofATrz9HgMfx3]oU64\:HXw{z*@A<2JByȮ%0E=:$/Qá\`>/&] š Ib`5n K.zLEYݿZ9dӔMtH.p3l>Zgtm̎iTxЎsAM/ Vj.m|U&&yZg}A XbM&<=QS/4GWG!*{᷽M Px<#-xmקm~S<6:TJ7SO EͪP uD&oiF[N. %gW:9-0_Kx X^wCQ?" %qCNOr{o8jT7(᧗p20ܝN)RlΞ_Dغ{Wnα^RnX,23KlWgkfzF%{fDBыW"d%9=`F2q[[>+FqDd(CMY@ 5Iԡc@  ݥϷqa &#Rb(na/ƯHtDlNQJURJ4\608k\+.5p</c d.CX4wg}U迪F.3@G1Q s%RآBZ)P(H 5SlS*Vx!ѽv|? Fh#0G b e5wURo²$Pf2NcauUo'.PTߞgu!ګ;w<|e7<\!')3*^7+4?~E;eZXRgvE/wT߁kpRs'ʆdsTUoʔKruޮatQ\+;bq*/`CksX4!J`m LP+O5g 9`,KAsjrfA`LgEh@vwZqUBnti/ZAX]/hoct:S*n-H0-y?XvQw&Ym}}nZ?HK:*j3s~SqS"{G3Ⱦ/@m[NwQ!Vd .8l')ab `ZRtV8-o6 Q^aqlE8Low X3ڨ㟥=R1ѽ_ !xh4;> =ڎ*M8F iTH%1cώua"O~`$.>ItV;x} bVrWL!uRߴ6"ItR;&4 GMshWrr\д72iiF7u{f~; {3kQ?z ғ jaMiY Hul'oeY$80R &<ǺIAԮ;]3 Kͪs%:sYkÄ2+o>r2ؘ"S, _cWQ=E4kezWuͪZQu29=U>VNzwC 9L%MD7F \A3{ b0cwJ>Bk+ Ikwdi=/ i/_E dg5ABiAֽB{A=_HUIt]itWo Umy;LIY*0) 7P&&Pg eDτdWO^>j=Bj~2B]m=X[%ʣLλ/!]~I$Cԟ3j13mRUD-W M<iM8wSdY:~Jؽ; <j@hC5ElD7t(Bio6/5~Cr wæc(E$7H# )tM?b*}:)lY$d. Ef֋ ͧ> yXDXɯs֛'z~vu]>3/?~0*C [йJtkFQk&-:I¯zD6Q#k҂~=I/yy0!$6y 7ofž=្U4"GsFXEGPb{hؿ tG㓜m]Ckd['mEs)k } )_`b2 :>LQg" sp Ŋ2s~eU_փ}1*^=@ TzP 1[B7VecL eByǠIS{ʧ 6Θ9jKg*NPl/YaR,9̛i:f)Cs8m$Iga9y` 8pb?o, 1x 6eaj!/,kKJQ?ȧJ,ޖxOHYBho2lnrj>.Vh;5.BYSO^o.#rا@g kdK?צNXimzu8Yfa.q* , =wS v!rI^s19(_)yȧ\ ۍi{7e+  euqjҸȳAOF{[m wqBx^5~~BW/`NoqvK^n{Iaݎ‡fR~.BDpM0FsZ)>γ{niY :nF{z M--HՈo.I$^ѓ nMwإh ¹ n:@ {X3~>xu0P:CZ65fnS-^;yY6f1:>mhEE-_ pBCeA>A)"tPf :?m0yڀӔF%hl%T[ėa}ۆ,#*v+v&Żǫ̋Z+1QUG׌5>+{2 bt|Wޫ!!NIg5fy8zѡ]R(fٔ[-ul'sCA9,J xڦqp Tf>VbR 2̛jۻpLu钸;ᓬ6<^# ^,dND`#JȞVc$+o1K7Pиx~w{~_Ljx5@]7Xl2Z;}Rt7[i=ԃ֪Xcچ7(כx2 Js}"Vv܅CEMk~7o6x>6"qaxu `hGR=; ' |FJ,\̞dk]Qy &>MGK+xt0[o~( dago畦>AL=.ڝ@sIPF }g=Eyu**y/7k]*߶LF PH]cr/H# ۫@ܜ.-۽ Μb0廿*_to'RJv$P3f|D䦂>Kxx?J`E[s!w#FAv t΃W$2u`] (TAdPeXA5b?x6P>gE!?ݳu jMpm@I/uH_h]nJ/"):9pWA3SO II QaRBE>v.@^2-:C-٬{ʦ;4ye:.hJӃr\Sej/,-Xۗ_c97e~|wWZLc^cJ.uCӝ w5-3a\xmw[eub`&?DRM +>L].iG @"q)wCĔ8yٙeӠej0ʻ۽0ً]~2`3Lq.%;:&^W o6寞g J*&* ?ۖig~I"C=feZu_T,3qL@"8L#" oӢ&r]o+b[c~|ӜVj(jfBx!,_uMȒގ2>FP@~T&yda3C$ Ӎ5=uci|sp濑6X2.2;Ft/.ccђ{*|pyC.Y%47.A1tGd%9k&Â_VVWޝk疳o:q0$(ˁ;A%i-ae!ZBiC*+3,>]r4'F|K FlI2&JWD!7*\_~.kشYթiNѱ kx{pϾq%nK{km%o,hIS׍~4Ku"-L?aKn^gP6ei)-z䇯g C~ge׭|3%%tM`tѸ>fe uT&߶E6W) QSYĻ2>B:CE[[U@w !w&Miu$V|dyX_;eGv $dْ;'ptމƣJ?BFuy+%fXj>љ1It,Jh0KFןVfsvU(vMg74\F0 v6V y?!p˄;Wl5j3D{-< )D*pMҺt㯌)@݂dڶx4c,RE6z%ؗco1V)5nř xsr6-K$&7u'U|R- ۋέ{xoG-Zvfyg8  M{?}! !{E);/énȗdF`5>N*9d@m mXSpC\ >Dx7nXV[Y ɣf3G _߫I3jǎ^gK'DY</IJE(0Mut'FtA^Ng*~! `eOX׃CE7 }`a%y8N4o ϕu Yu5xjnxd刢W ;CaJzYMdQ|R2iP=VK7" koZda^*-IE6 ߽*V(]w +,u„1<n}@|ς48,*BIS*uVύ¸Y"4/>6ORjևB`5ntIo@ zZHOse@PVj負֧z! |`nUyrN92}0i/4Vv-He-ӀN>m?C+Ls5KFaY7[&VhŘ2re-gE./?RƄ?܈ [6YѠBm(a82xjYh~Ř1 N.A %V:1gڏV (baEϫEDD6A/0ֈ$ڬW1J.}F*5:1HJvaxբIs/;ڿԃWYwس`1r)NAY6נӞ6Iz0_{A`y+K WN ]"֫<tsP2:ȘXCruA ؂)x-ƖE>R 3vBBiDf> ˵1{̝02O^6g*K[j32cR^6&#P* cHyYɡ28dХl)zp2ϻ,QkK `h0Q[G6ǂkQ#(&<8зD>TC=*rʒ11-PtDbjyFt+ Q Y63 hL\q΍ۚyEsO m1؜'(趐zAU.d${ȑmo=X U*(D %S@3J6Ď r QzHZqt.&v3+0A@jM. e_YpWWN- Kw3PC%k[x\ҍmf[Mc]quKpc҉6K.W߇,{y 6V>ږ ݭ96qü+.q"fHN´/Z)AvʼnQy69[_P@o9WLI;-yY ')r"P v<^*!x0-,Ь N k !2 s4A*/2T+& w]# e&'!o>_ xB6 [Gp!hb&i?qLNW"S|IUT դHelb?ω2D4 E4ưԊ{F_!yw_?nn6MzidQoN&ñoו1\ ѱ12*L"lӳغ,ئB2\K^uOҦcA>O|\C~sSb.~ܵL/x/_5 ߑP$โ@y/Ub!? 0h?][=#u24v9յO(1H)9Érhmt7`u.3e 0 9b`da'^90Jlg'F]x%Daq1$@9H Mn LfjokOy6q`8\~O#%~sI曢7}5 x靲:hJn>{.~yqJY8؉8: e8T$ %~&]؝u3w+YMJĄֆWA""* KPJ3 d)ZD͛iVScllZf)b˼'In5+6~^%lD[N50BU(0ٞ9@̰ .+i/b-YIG){2M5G};/pf $X:h(\JH*֞.V-'PDYw-+[/YDv~3b*sK"'A$ykөTtSMvHUA|:1#wobO~-Vx)(} |@NC3Ԓ=*fQGሉb_u茻wxNA&׉4]ӖۂY&Y7T3 z;_+}PYxt-?6t=80wBVaY OX\*H^ p>KS͘t):9vZy8RsXiϦ]s-~a+.6鏊vYSwazBl$(@ .z0Yƾ%GpBT7|U!qYj;Ժ{moK8Ǵ{aov䂚}bd`UecfRȱp¹QUp:Tp4,mr&,-ϣryvdLQA| Hn%߁ hUU2=?[=)LC yDx,;BW6vA_q~w8p2g96M*j-jROZZ_eŧ\n3.l-@Zug6.n8o|=M,4Ġ3]GؒFDEʼq8,?aI~9itldr*(ϑSPu<\>(}"a35ELG~FHz?fnxf(ݧx4Gˮ=b򋩩-l\1[-~^4Y\˧srl*^.<3_}lVBpړY 3?XVn{sz]j,}PaR!o**4CEsJL%9 p*$ø3WI"[m׈pL"VL L*C;wT,`Y iŷ8SF$-y1BI?or??Ц=n \Ny {$h%tOQғ]x8Mc?>s #taV?}$ݥrZ ϖB^A"ZCW~tTvu vT{"p(l hWrV.9dzY͝`{ɰ5 >XŠ!BK"x-4Isƥt(cӑ/d8^I  `SMe5 GKt6ӡM/XFlޏ3{7Ҁw>,?(d4@^I \%sfT%}[¨od\GD뭤xozR+Ti[ S `In5Ok:&\ WǍ61t9{ƸjfZ݋.6("L5;1E"F|_UfrR=CqܥR5dPC{lr2dk L,KOtަ)xʷĻ}:iR [q?*sp822ie,pRF! 0Pdž`xr[\LK*&FeTqN\Ay>>'{O1sy98XvSYiϘzҜ4‡ʥQS=٢_(wGakii v?#^|xlUՊ@1 S~]q/K~ƻE Uf*%EyX+D"M%C>Ukڏ WH6S 1Q& Ome5}&|􃎟 jQ$ohB?wg(D%hLOvN")lCt@=H l%"]C$r_*zR:@w'tͺSe+Q;?oPi"N>=s)$^Nk % 33Iv >K퍌_'G?^d#cY@e`LD( /Y#,¨qVnu1K~mWJ~^ż~ .O &'?_"O,!SmoAsBic,mXkqQ…\f,zr$Bf-]Ud7|J~oyh01==ŭ}NjV9g\S9^[f;+L3S}UձY[g1ڛ7:G}80{F(us 5KJNYk@l'&"ډ.+T B+K(F1l;3򒏀54h*i04i~*Mй"bw. d:MZ7akHY;PE.:e;RJ!B؄ '^0%@q A؆_x63#EɦQUJ^nF}8:U)d6 w*0pex3/mNHP(5'O*Pgϼ=)_|MmN]7s p[`ŻL:4EYx&_GnD ↧&k|,{V;? =E^IE5>fÏn#p1et\,~̳ -!#ȦFb2:qF(g%<>>^6ue!޲_hc r熢UnFcb9~gv(QQ,H,~/^QB r';  HtKp2;`VF3gtژ_Z}b`o\ZyT꽧4Fk22 ZP1]쳞yx>v nsG{N0rvnŨb.M~]5']̈j2bB6A^ҩ=pTЍGzF@J/݉Yc8هRhu\H(- 'o>b~S$}xÙlL]Vj74l,L|PqXJ~]-?^ > *գW^@(o#zB<!ñL{Ð(H I%d`+)5eI8*.9T~وw 1ͺ > A6ml6)8"r*Llq]{ m(Bk4^'cX?b;~rیg}+8;eg68fD.C{rE!*qx.S>, ."*,{6Cs5kb.ɴp`)Xv} Pw+1+^Hb d[)HSU@$S E:hz]/و=Vy\r'#. rVYBSE#,MP{TFAb$,ү[WilF֧2 }O` UfB<ǘշ­weGOs*~ aƿEh$JSD61REΜ(@vSAG}I$H(ZE٩5eQ)LT=$UulcWG-(%,)8'E@:H4lxJ!ck#uO"} "J$~ϞjZ,M3vz,X 1Sz =]A .oK LeM4aϚ"oº(SC91`2Bvؒ +>>O'|CDx|d5#uk,!`[m۱#NFux.YfԈWאWᣌ*970/QDA Rj%UTEub<+}cI(L˜czz5 npB1!s,/Ӌݩsbݢj<ܥČ ͻU $+LY,Ew^#;Pīd@vaV-Q@!ѵNT`ӦC V K2vX&acӅ崖ex Jy&OBH}̀|ajJ$ Z6[Funth4[zZo&ڠjn)5Hةʜ0鿦Tmڭ;9 1uƩL'i@`A4JbmA<-#a{iFrfI*乓-B5ɖGM3H[SA1ˊgCz"i.%VbJ/"0T%Y'.\Jxu4ttY;(y?i Da&*eK2U'w3ċjUa(xMsOQu3a(J&-RӆaJJ>֐wHjЃ$7Hm6Ή-.@0aw/JdGސV沜U> |y:塷T !rY S w; |5&9 )$bc[8*Te w4?CCҦnYL8Mէ? 7'gv|dnXDz.mJx,4z8zq}w&fUj?۠jӅ.Z9aNX ^u|pliuB*h!\vL6`N%s}C0^K,]JE :hL8 b`\ Jl$$/4dMs nV6D;HmIcAF# >#;A#HɀT4Dspa۔G-_-!4Mxx }զ^5XZj'-q!hmoVܜ(+?.C.MpJPa4Tc@cp/C컵1e8ТN&|N5WkÇW#[@2yd$Ʒ40X{1Pf=€}kVòɦ6,Q0J}̦_N7QhMiBE7ϼX XW?1z#rGּ3 ,/DȌp cǰ(f T/ZiBYԅ؊{brw6n%xSR1Tzc< b5mF%իa;L@,aGḤbv9O;p( b瞬!"H H+jt;o/z=.V˰ZEt[U6d;Y׍R3玓Er,wӒEyr s:^ffcaEÊ-( sb N58h%m\M]).^F42umL -yd&R*|v'GXG!o# IWsQx嬢s*>TҪ=H}ɧx/(8+* ?| @nQw][oߧRY:g"ZՃb>?AH`F()(Okgt%3T ;/E CČeiO4ƐcAS&(TN|>(>Z^$y`! wV^Qm+3Xm i#{lD['IZ\\V/ջYKTfW|D`92ڒxf_yUT.  e^OSAȂ\+\>7{81ޚOK±FhɇAc(Ziiُv6$ީ/ 8azw9Ʈl@̎jަ00hyi6%(; 19ɄVyΕۉGՙ>/6>ؼKAX6M txhBת>@3û8YR(硼9f>"[g)ò~_ma9N`H#US|^ݚ% &1 ѵYmjrh#LTfq?Gu IG;.e65?u?@U|.+pB١Aϴ *y2%9>]Fy(6s :glK^#1z  MMz|v񜃓^I"'1`A L a1 j5R)YH`YCB-9pg"?B)s\ӷhcZ<x+"(h͌7ebk0: f*N=~4@\)fɺ"Ruɍ'̥w QY 1X٧f=d|C,Evq@>[ד=Wk=_"ӟRE8fu%ij+}! D}EzbWP+ɯUzzrh5@VK| nw#8v<ދz ~n!HžU)&OvsNE,E#)lxjs=:z6 hSԙVIwf\9 P:e9#ץE*&’?3z Z˻ ,m)JN]RTԀ}p|ɇ2-w;|tgFCj+F'J_$[^j9$漢$kk"ŠfxO@jLC\$&F(/r+ifZ(vv\ToA[=ڱ\*ze;{7:٪YjaI׌\6u Cgj&DD(gi* IWw! &n"!n7YҙzÏ5]$a8[矔EP+peYl {[`ΠA2]VwFhhٮEE.s+3$_%/ǃud34v:Z4Ha?:`mPk3%Fz:7VF O;bL3 ݮ]Msm9 -.;3GQze{>iTZv;lMzvO_ yVyz_Ͱ=&hGEx lNxE70dAғlE %oTy8(I4pm;|}!jdbvγr\Zt0yAomIz)C\: RM]|*1?7^io> nF9hGP9cIs:؜|w*ˢv^ei NKlv=G?>z}Jd00;zy8% ּle]"4[(nO Y}ә'L,mzG,- T <K+VZ{(ƚqJdA#2(A1O|KfȬ|nYn| 6Ol5D^K,v`6TbHz܂<<ªO*38{PLMX.EV0JiBQgv!5FS.SW[3pěfЈa|}|^UW`KJ "pXa+S <RiF/eUn) YIw"8X-*K= :C3]]dÛq)cM^z̝TU5_w Da[Ab fO !q*׼Bqh,G pyƹC?٤N/!Q 俩*PnEq`LGx~v+'1xU#˩OOʆW ;j>7> ײ\z:n+6KE!GnP+ێe3yjG*\Ta9'뼱؎t1h[e04E|prpe9q@-UIdOLIp}58v]@pt,IJ p3 ѻzY[ZY:CE/.U8ejo<3/n  W,4%H" çâm݀=VTd?EV|]du][,LNY 㔘尛.<'S~`kI[P mZr(Ғu"Ԭ )Yu|] ,,-H>*^3}EFP/.i|n%USgݥʟw6%S(; EQ5&DDV{BZB+=Jh_-k6SP_ f_жt&rBλV4eS6A4/ga|Y|ʑVdx^9C~_3].E/~w-Bl5^?TM2ft-PwNrD6ۤOh8 /sՄzG(pZ1ȑ[Ţ`ώ*Fv2m DzQb_Ͽ*J)|dR.b2~|<\$\V6.IDO?/Vvtk1A!t(mP;?` UMS[Ơ B l7ceC8z =Bin ~z4]f bNԃyu>ZXdzMdfsߟF]MrI5%'+ؠ Mmb+Hz>}5A(TЌX”cl\Woe0s`|xh-R*Ɨm!'BFfnNxAI~ͻ!PH?s◒ao7b@W:Cu !x~V!\ȧ| ʧ) :7f1ZF_ Kt-4SjIDզz@LfI6*b6Neku_*cUq?Ȯ>ýV54BϺlVz) " lũ/ ;|mp +M2Uϩ8>TrZ0On iiG }C/7ѷN\`hȹ{<-RU+83٪0#W'Yݠg(YE n]Q%64Pig~vE߫XF [OP 7Meqք x䖴GqMZ'b?Pɣ:e4&@;I7U[ÈsDUXsϫ#ܭ"89Dc%qZp6v'-sL9WL_4֔Ѳ¯~wU]!C93eauk=W@ (@xu[E1o l7gLzZ9f}~ef\z¨lã2a.'WH$Ӌ7+|]$Tz)flU3&a۰`06u3V ]Xemz:3oHtB㑷R];o$#uYHpQ2R>НYׁ>9h {S:#0O1Fʤc~92x2} D#+UmY֭]ű!&6L3IA^31xniWAϱq07+n>o Ȼ,H~5zp`ҳׇ?6-kp0ĠtDcLfb}gO+RGA;ad5T^V@4JY\g^ov&H0n+&d5Ttr%  QRrk[[]LUD6й QZN%@ùH=9QV̾@|7sB\ fjRjIb *CQ2ôBlDקQ\$RDl0ajXɵh8+@{ A\XR,T?ۗi ޙdc.~. Fla=ɫbXS)>tuqB2M8^甑%h|`[M/l%Iwl",CY1lgMΏŌ@9V8f_*G_Z>|NZb{Md?WXɸ3R.3p5b~DI봄 :IᎼ޲m'X~CY=m)٣UO=E{=bG{E,Ǯ;W%[p.!,*c&D*eW1P}bq'v/54cnQhzdgyZ.l>?6GJ8ɽBC^1tU5 v6 |YUfO1n*l]oy1݌*[µ #CBo#33MN ݘ-=cҾH%8C̿V5݄A 0:3b*\=Q)"Zn |[-D5롂f7OS_$Q^B~-%i@<4ӯnϡ-S~VFBeR8 fܐn|>8J( d chV%?{t}$ȼ #2HZOހ K~|yz`魰]AL ܳvgeiV~9ٱ˱|IG"/1D%ZOE%sRDdM(J S&ڡrpn,LZzX?zZ̦G'.E];I7z|M9I25fo}EF$N>#Rm!7-MnA-T;dYDG y0 Â- ݬqС۶ٸ~|/d8}ptKTL'RuiK$i9A{?O]T,OhQ˜k@ψ= sw<0Wb]bObUc!VRznh+!CA. rW9༯|_[a*#xГ ANFj0cD}tyLap^.~ueTniF܍{68+"8 ;^G$Y LjI~EQ N҂KkV';% x,ZG( I ;"F߸,XoiAgs3"NypRrk`Hq[8/G:]F5̚FP/-oVa f=٣ `ݧ=Fc l}I~tu߅n jīb'FRb؇t$/GqoP|t*Uy}NHD&2̝wk qRNcn=2^Fm: MKTT>'S7ɲFS S1ur.LQL{=^*JGg>8Ɓsާc HkQ[-Xqʔ74.#Gm51bBJi(3972fSy*zƾ13^唿/n-`G.("[l鐢!'ّ)xٗ9?us h Q~2{4߂aXu/xJ`u*D_Na0}{s\40SLӰ~Aúĥ5?F^UWQ_G6sLwX8Ӡ2Pt7yJwzBx/ԕGo#J9ޖ+$J02NZۇ@)d"6y4k)$)#u{/ʟjpV9\$'+Çdo6f,]~2kȚ,j}sلȁ+3KSz A;eցA%gCTl>t\x~^E1浽̌m^}j*Ї "y\D}RLY@ \{t8P-CD.qFfYXo]X(Mhg#8Ө;q˴1Eyyw` g7QǵspW{ca&[MqOX41I~)tؠ_ql:m$*aV<̱,%`q_ +;۔ 6q˅o:~(Hj]M ٻ~獈&д$RUjJҧ> Mۥ?bb> :y:D9H+OH,>bh19[$ j;jF9*@:V>nc(~ Tς06pF[ y 1瓪j9k4nJH"clGҼ?JuE߬%V~ $?=FvLqHahS8~y븞Pr~~&6ETUc@!dUEh 8GOY=;&@~PXoyEvBm} DŽ-+gƔ\"^Vm\)әG|J`pCD; /NwUh3 Z{tyIePGh9Qo+ ڣ?DFn:o?,I|"vȒƃ7AUjW$*)ArɾU",;ذ3 k=Kwy&K7Z,.9U$?o 8δ&hdr <_I﨤6| F!m#kE0z ߅.پ$Z. "υ,Sfg^zz$':x,Ҿ}Vv+˲M3YdN6"> %& )f@O: ]/z>{ke{AUGS 7R˟A(,= n=);U>$tc^5G˗@ki=V3˹OvmJ/A͏Lbh%Nbny&VgR@V9&ŹR4ĸF4<١hm 'UsE_j @O_^=󶖢hJxe MwDg*y0NK WAX(QEAd-}tSO pn,6ddʓjx@iiehLW RiE6t,Z>~>!*9IMۡT,V?Qc>?(>2+U)KNkǒ|-p]J NF),,@Ǜ(`0࠶HcIKT=`_6)* GlstNW޶~u}C+TP[mG#ŻH2~[ 51s14"NP]?Ӧm/dj! ګe+Lw2yu^ /fK !.9pkqt7Vy-1!ya ebU*=_&-0Q;H)AFŭ1uݣ) f:أ0.^gk(y U;lx'QA$^ I _QqԹ+wx9֏~[F|k@+D/776',2cFN%,I&;ĩe T rk">Lv ` C'Fjt-EoB.rΌ?9AkG%``"32 {>)PX]"x<0#pV|i5m`X&?@JuZKh̐V/Rs$ZJ9lSoE`'Uo 9(}16IsbvИb8t[B&` kb*,H-ô lT C0D=];M^jJ6͸@ +^"/ulZc@hݮ:<$ F v-LaYyqy>'-|sI-M 82f澛:Zi `<'NyIe%#b&a{rDxx靂gIU8 {W~9&ra8QDb!pn OEB6`نNTy$ha4Hvԫ؇ޓS̮uV|7;(zs-nf !̮k?p* ]wK2ߒF%S/0Q[i)AH\OW6]ad9g.NN %RG>ۓE(Y{hAר 4uK~-"ad\uT^(%̊ĮJڜ>P 9qވ'?ȬWE z(D~Χx[sAHKiٓbovsMUcOٌLbna|ma y`D`.ʘFڈNmU2JMy" 'w#-9~6ל7F Aġ9> 5mtRf AdJR.6e:׃8OFh{RZ!a{*[68P/ "i40byK{stS(E]^FVy GL4?Peƾ=:uU9 tpza|ǕMgzkdg(l<}vm#i7'FwGYԶbLH7/fI|]OG.V/7SZV^J(JzdEB.Ʃ+; =þvL|N/DyI%i@>XYa^ONew *lKScmK=۴E\)35ff[fYV]רKF_ R1MXPpenN$a /ðCN+kg ԉF Gs6HX֚:} j>`c%, H$BW"bU)SU)86Z.};i]_RԓpEkJ`̓ Hjrhϥ]WѸ6R'Ӧz_X6*~W(Ge\׃o~|/`oՉrC8pSiu4K>N:l/͈J ?jyܿd>!Y2vc|Ml5޺)?:k,F7:Ddsq-&%bu9R%W3s(f((Hi_K LOp "@4XHA:nb0<:xt>uXcwY!\76>ɐw4Ȍ#!{y{&:xy5kR@=- չ 3tg^bLǎEUO6vn)jBlȰ'ETK#>! ^.nƂ2loV 0,X P:xoYwT!@3dEjZVϾ_3>;ݳ ]n@xU^z)S-!QKVPnȖG.(a"RQ QP0%|HѬ[ֲ`| eq϶/MG}ur0_dOKin:\l=]lg@bд9{7r}AY`1Docb]}7YiP1>$e0ڥPzQ٬!a4S}1?HRW !rrd 56Qs "^`E)$e.|\D|^8Yk_@$dԧSr~ Q9-#4;VAm8|~bi;}LO$P+UIyf55$3AW2Ӻ0(r65k#s0i076 ?5m/z\t0su l'هk"uCXE>b6ñr^0&[: vȔl@3 Z]c..7=XU$jc5_Hdt}{ .'o|@  ߇IF!; i ULLՃh8sI!#Vj0 d4߆JO- 8=4_?.w/dNho pH_&=9$ Lr?ertwL,5\D)j9K 9 YΦօPOP`ŒĘ_(Ktm~+:n*`wZ). ĕIeK>27oiyu ;)ǸYU]ȓؚ?X9jX@'of\޲ߍlO١IPld5B 3SpV3ߖHɻbד_ݩЄk8elHT>KgT5rp{X:d%L,-Ѓ@S7JJNRYz=OX~Dw9AeFQk3 AwB{:PL~<2t&5W/ }AiOr"OQ M@p|dRi>hoJk=&#X6o[1%%/|9Sb$ =J&&Y(s:&D\ :d(HƊ=RTu1`mcQ&]yDǧtUS%7>eI0pou&p2*łK j x: & dHkSxٓ5' HE@G-遠y3Wf bX[g˘waݶ yRds'l¨cOH$]rs`ͲG'LiO/Z-k:50yO޺M2'm` .0O۠iFD.~evFa͵a<}vX yUC5}" Na%nCKkk9I!@"Sĕo#}X%P'CR/FHhِ0!ǬʰlwtD>hOY-ɐfQJTȵ6lHKθ~ \j%NY3_ 󔝕sM~zL8<^ |wBڊ\x+޴"Ff/opvg~5|qzw3!@kAMЊyq]gTW%nhh]:%ҫ\Пo|Jz mu j!*Qu9裥 !yj?uyAYsrccb]R dVi fn5^oAΛk$-z+Xqn }A=m`:U@ =7)=C}\?'?&@4H&  'Qѳi2u}Q k?.ׇưKaU;nemMAm0ZeYLT|ܹbGO2!2M :f_g}yꆠjU@e \>0DsV(O5TT؜st蒺(p/pY}Ac ƻi]g}e,n$X>l*I؜j1] Fǁ9LE]ѿdn [@@Ab7 %$ N2W<="MKl|NxW>DZNʤxTOd֬ ~j"Wv=<[I~){\!VWtb>ԵwAS spņuqdASR \r bVνN@FCQVu,]1n> GSs} z[1~141cMs%cxeU&68&E@<i -ea^Nb S:8pn [W"e KQTݘ=8׳PMʳ\i86~(߫B XvdgWۧfZj< tȂHƚiZ #Ƥe-~^YlNM@1^(H ڞ([X/Ru^ T Xx,=Df"Beav]-R<o!&T:x\\YGT CC"&,bstQaWY8oLb2 b\RvΪ6 ceYys pD8f$z˸>|}gC9(*2)2lV۟#ɱ(Y?ήI0*# c&kD0r*(W֮}t.vQ:uXֹru2v'7C4'TɃ690Yes3@xC NDb\Өt[![ƕ;>2%k{2}G K]#ܫH)}K:Z`H3|j)؎Ўf|Q4Ak]++Z2nv'rpNpil\uOA{$\`$vC<$ !GU<0uTY0zmBr@C(.ZjWǰT,SaX}%DrE[`Sjظ2, /wWj0j 8`O4bu5Q X!Љf2иr"pC3nB溰"$+//HPǿTUS] " `W!4ZB!j\2CO4LssWᗑ/,*mmYƶ?Sΐ[NzZ"vsQ83BN y?K@.'y3nnG\sT[x{#_&L7p27S±e,j "zuOFd)LtiɆtCj;UN5^h^þPND޳RXGmUtH9 ԥrDnQ7=NA\R1BW8a#@8,d91i*R*1DZh.5rJ` 'E̹ *bzŸEt[vc`'xTQxV*S4vNWcH'IHJV"ioN%W26IWEkTunJu\&BƓp_Ԙ5bYr_4')tHNqFwdfdi!We?XKa?u!Oz%( x\D0ؖ cʄ>4yh,D{Jg_E#9* ([$Tr9,^&6ekW8djS7h3Ng:6n)'gfp3c+<`[O3V,ݰH{r#T iْ83$#ZHEó/UF=dl_6V݂Pfra_}*2<a qH BNK 2kb3.e9qmXjݒ! LEr_%ɱ$4c+wVh\U6I@994Y%Yz$ ys= JiP©R$;k/m* :'AVx5#DM{܃+i:-8+pΖJO *쐍@Qϡx;ךIvs.{T[QY7J>v^a%|0@uEs A̯pI_ w'2Cf#'_G8K1\'f1,BF1>dXa}ect({4R<+[ civ- Mk$tk)ؕs4?g+.K^N&NQtLqU{_cvI@k[ܨU,inR)dI΀Qc~u .>k3#5)i3pKƱn٤89qݧθMbr›EmCe`NzיO߮Cݑ82+VK ў7/X_YkC7O?L3ɩdҥ˕!6J!ѹ_n/E%\5~.+Mzͤ1î|(p&BKr:z O[Fڐp~DCc7ũQK7 u7ѧE42Hm )p -rDP#9.D5&0hƐxH+r981ȑ4crȼw%(]LC$6V2 =Ѕ1if(,YW7INp巬jqOJ7U@ԯǞxɰ\ @^x\o ri8(*(>ȫ+4>>u H FUG;ܙlE0}Qfhz%%@~],*͗N}W3VC18*4 n H֥/Y9M$yRbO}D[]wrs?M|ycjnA&)K:z6 P vR6y-L,5e^#h(e^S% Z/ ceuG_]ˊGDx%ꓝoiYFn$Gڹ^& #cy6C4>@D7]e:CQS @I" –-.j'Fk1P[=m* ^0Nk#T jim93VPX|C'HQ, riɽK-a͢`fHgZSZ9}R^×t#fK;H+1lsvaqeY_.35_ϕRcW+Ar^#P*HMjB],e ]@-(*1XG`O߮'٣W&[^> L`l{XONǾ>}߿ |Nź~QA ЗAe//SSCa=0I|U"^/QȲ7B.TD{'I| .'Ib't_L~`=doJm\)P蜁>FZ4d"eQOVI,_]vzv ƣh !6'NT֢w\zqIÚꡯqp3.׷R? bA"^tLȈyBt |'( & Z\Mz \–CarbAhktIi[<͙^H9 F2/}+;&sgG)]C]!%^tzsУ|ᏪC]Xw[q +!fF3a`̠|00-QI%u:%N{}z{c vmq,| Qy-1+?h2QLc\x_geYƹ!Rz#n=UV'q_FJbЗʚp#w``~O*@dVmtJ/*LGs)@ AbQ>r#C>m$bŕ:oLBOމ:27b_٨?5j~| D"8b.Fq24D)g` .y&Iy_.t_r}VNؘ>>5RIuε0ڣgf11a3Ɲ7/~HoVg&65xD]ac3W00, 9~FB:Sџ.-4Ϻg^ޗwt6]jwaB 9Iy;3HH#Ig0k 9(+0E65ziMÎxOԯت8 ioR_QdHұ8i6ZROZ(U/ܿ:0[G04s넫.٭1 8}$0Rj^y5t%:u6gJ"9EEPZt KB,"÷>.dmB3b!+5ƲD?nI1afm 0f?#tm `l@moYևw3}<.6twxǥ:@% ~ !Fi %y"lUȨURz˹w@刮,=uVsJd3g nAȠ# πe 0qJb*6ξhzÑu;=kwRYzqRtt+τ&B|@G7C*fU:=dbkENG# .?r\0d)$7T>D7M*rp0dǝzZGf.\3ICoWD3ךbYXlh1DE84YR ϟ;(䇁ߎu}XuX ͤ Ʉ>̳^i^|0D)ySQG1Yȇ1gC=~Zg [=Cn/BfHv<P`92"2bvx`TaöJb S軬*eZrhD@\KQi@ʻ\VOFNpX:>ڙVzvdYpbDB{zͲN ?ѵjN@;NpmgɌaփs{7VݱdHC tB^A%HG$קH֔5 ` ز{*Ҹʬd !Φ1oB3:hU4ّOثB39֎ݚc-Ehd:H%Jʉ˳Z- LPW[,2x16q Pq/M~8iq#"zVaKB",;ē=R\hZcEMvZF,|&q#XI"|TO|m{1tȮ\'YuٔrmƐ<:l޳d1]fL^gїZ(A}Y*R8=}XD*rc$޹{n,M8)yV}7Tm;ا$:9lA0.OܙO&m0oO~ׁWv$*pC${q2o.Psm (s4q2 HiCJ339^:Jnj` 8dي (Aڵo Z@ 6tzuD)/@ONմCOyp* n%뱑,7^2gD͑2tIb2j`y7K:0!H 42EXAAt'>ʙPmǮHs*Ŗ=:ѨFRک5]fݍ͛1xulPG|{d0vb'?RY} [I+XATTj"1pIU[p|aQ6ZAjY4C#4e) jVDCÂV,T 4:6vv<[1 NnWC7Ǹ3ja,ɿ@5v+9醑DZ: OO W+ `P>5rX1."k.eo$NBVX^OήQq3VעaT6T@"U)?m ITctJdowȊy+5  A0Hr}mSnKPk@(JUG]wDQMaqR6?}?r31L}]hio27(kTV܇DMWbt H/}FJ$@ c'k?wO4عg+` FDsGoe/O~Y׭vpx'-Գ֘m_'NNN$Gi% -wcLgICRZ D?qQjNҙj8@se՚[ (Jp};OA۵E'vvHr3LX! I}4M 96$A#5LVpl5`Ǚ{Mh!4>.-a7 αޱY^I * ec_1SK*{:7Kh}ZL+0AFsT4 ӹ ؏u?HOt/mvVlQ87vKuid#LpGUw,ҺڂG|һmoVc?u4PޭK Q\5V8qo_ ,,'dhoxd76b\3MDl|LDJ>Hҋ}} OH$126Xt$ JARgMɞH҇_4 P2~rm,5"m!#bfД[2`Y \A7,ğgqםb"˝m/lkGǠs31O͉Z4-j0x˨=1^IDw? E @l_d E~1>Ƿ4sP\OJEk/CЅ$"pCN67pnv}gZdÓ!s~-Dvtњyt{ 2ؾHX~dt$ZҐ?co6 h{1rϊ桏|bѤݡlPl-DO,i dY/p@p*A-a)@AgWKKq~^wV&Zj_@R[>dL w3"w6tY-!TA`ďRRLη6xWH jݘiap̫}RF1B rF+ONK*f0^ 'ű}9^!>[g)Y[@gWr"\7f黸! ,U( uV'0I۬iqw.o-0^?6-Xr(2ESRh'2!h.?ezo 7;dL vfrY?yB(bwl L"ߤvDpWNL(AŶ1}M`*WN*m5Ѡ4tGW[X8R; *bM Jxf>.zƽE܅twz+ bf]ԗ2S%Ǣtѯ\5 |쿳9v;>!7S@jvGTKmo &za$ZQ u_,Թ^SYن%d/߆X$dwPh%ѣm0|p_R:z3b{Ij`}ڮ0 [?t]@|p%%ts,q^n˾:Cr {3w0|f08^.?دnn~G2II^ZE>q脔F/9"J4fXf@.lVyYÈe@) ?(!;hj;LiOWz'8¹ŀ͢B0!M3],r|w:,@.K2<i,O6Ung f _ YL^e*󤋦.2.x3چP'3,(wPI\@|Y[`gu&G_P՞(e6j7ҝ#JXi>_mXtލU+<ֿĺJ=Y3vt2gB CJn"#у6GwY8_ t(5vkiHKl18Ґv]y,օpIYvTH:X9ȏZJ$L"3ظvC5|pkJx>bbPƃDbRCCϷA*0(+jd 0oiB# P/@A  bwJr //"ְ0+猒;5oYw% W8wT{ǨvH( ẀPe k=w-l]u3=Y|~73"^.LMf-9b v,y7^CL!* /%hAgƿ~O*&:5)hzveNkkՑJ {g&!lѳpH~`&< C)#rT{"`Jsƈmjof%aTأ>iBI$^e!![9xwn0_ X3Ÿtz޹F}jˆ'Wx L?0}4HIZKH j̶xY3V PgH7B̔RQXu]~ȀJm($BK/3q۳_bY ? W:ZmfLu 12B `7WRs*0"۰Pd_l"isĦ\9e:U~:H`rk^@?Q&yv|SF@MMH% US 8NjVI֨hNyX3c?ss@(QvB -q?vMswH'MXTFg"PJoZZљ8:*dוVB%LU=5 ["z2^ͬ:)|EdQs06k1Oǃ;C.}s <=bI) 6!ڛ$>ұ/'LLbSUCb؍rFLJ97 rYxq ϔ:dy ;X0ћ*p; \,Ca0bBm[&`nFp6LBZ["5v̈́) 05?07tN@>G@Xвn`e=*z}-ů$۵1ǩ@bEKLivZ\FU:̛P4|/wƀ=+`}>pQ^H1~/zSlXqr];DAbt'*[ٗCD+E~  }:4Y5*:i8-  ;ID ~M@穼uSev&6Qr{+JEg]0Mb*xZWO9Ś$Ǯ(eüB]WVpJAe fX~v)THr[IM2NfplnykK$CEshsвnl`3h?X j1/A7si^Ң dzn͑nj?Ėmw4VK$'F1SFm*,m2ᡲ_5ɬƋ@eL(64">Fo3෨a'Jzan]C[pĨPOj+AP>{TM;XO=+5e21{N%JUGcID_nQ" ›!oNTI-&-8Fx?B5 _|p&$ޖ45`o,Zgp\ɾV%O`-'5/D򒖕є9'O&I c̈ "3/a<CW`|ܫ(.2A*\OO?`^ } &q6M8g,EHwf`bbGҮMfjC,6Q["n'oM5|ר{~"NU+v$eİO՗#KB-V b&.;: S0m};xl𘒷/9K } ~YZY$.ߴ=gz]). 闣qG⭙8 Jx㵭p;gLsď# vjhUW}N3|A*(E=5RФ5qB+j-d7 qh>@3 7(2[|p^`v{ !4WPzäbfӉ~) d)kkx(s\[K4mֈ7B/GUT{5$GvE2Ba_V7F$Uačۓu t':IsWxFrz>m2uSيG]tZ|ߏ2%Ά03=~B39cYl֗j8U˷nW##Pm &&YJ,3$[>y*A+~ } 71PzR͂(VQ|` :4yά+"(F6W<)1ѣͷ3^13p\m؞*4h981ƺE1KJ_MZC 4{6lYf3Tpä:h%7O[ To6w9o .Qםozc"u/ 6m+mNE&# @# .q*t'Sr{[ͥE.sګF#aMGP *t;t9m ~>f(9B]e=f~{>p>Aan\KaoJ;⾬# 5=+;Ym[W?d[4y'F5s7(muq?lo^JH \ha8#gvg)?tzfA{rnAՙi$wLQ դQ-$Y ۲O ッ]Q }e&gFض-bMtZec?i Ԍ{hDӗ "G'#"x俵6X+[vqd97dGӢv0^q~M4=Wy)HD ̶õyu&u 9-Ϛu~NĜS$^Sٵѥpڦ=fCͨ")kN-'0 liS?ک H֡DhZʮҹv#V @V{;WMTEzNĕ_"5vH1?(.3(9Ln8MWMmd5>%A] [ECQ F4FRb0+%_3҈O7v0b{% 4y61\wQic`|ZwNV0>*UyË?3Z=|F(΂6(S2Z\?!ʧd=X~-Jfi&G`E*pI8+ ̈́$ZRƃj.]M'͎jj 9[KM:V)a.ÓfԚ"7U@}Ub#İ}Shmn3H**E>s+ s ~ .ueʿ3:yfᗨaόG^x_hUާjh(-^,洅vy M]9ǐ#ěca&TۜgrGt^4]XFj!DN}) Y=90UV^h6feBD.y>9i CۉАъ\UTBVݺ8%zە*Bj hdqZ儕{l ]%LKzB9NL٘i̥-.FqȘVBfPܝڎrp7i/HK2n F{vKwbpJom*_Syedw1%s Z+.F\On6)^5{,TzD)&B S,tRG)'B [@^Yd PX`lF;Jex)Kx=? #r5%,l^HVT'L  3#Ʌ"ԑ0D]F#Ԏ[ {-nx+G dȤ(vt^^Y`x!f}a喗BG%?*;G7Ёe1Rg,Iـt%K /D}wkf[mfgYRzq|+6PGlTUc\$?SA0}M <,3B, $}h] APE/U1ϠC`##*|"@GM1Ҙ59]3"Fq*V̨a6@!Z B(ʆx|k7n[P=] 6_V@euG( ܟa~YR$i*7'OtkYE2BZ٧L.o_o Uqm҇.99'tf8IXiK.a;3u?Gء=f#J@Tx%*6l)?:Bgfۓ [t!P=)Ձօ4Gm`qZ @Zqoa!,+L W: گ_o*b^eOK{ozBӓ"56Jt:$H)T?`XV!18|Ty3 G.R~^+l!xB^ MykRG~_0RÜoͮZ-}V;7ayrGlЂ6'\;gsNi$ڂ=P~^Ӿ'!WXXhKfB!yͅ0DXtYwYly7N)z=5KꀯXt}B hSj Ɏ LwN9:Ԏk١TA^<<[>YNj!B0,i9iCg/ L:e; fmHF?W"ZU [~MނY0F<,ou_pNӕ$t4ՕU{_/Y"=? o QXC}i;-r4y{QVVjqe@S,Ű<>$Pz@I2< N8Fp cR7(v_(+5+~;pqI̶_JV@ :>o,EN7*+`[]ZgX$sYCv[Jd=C<;~{9WL=P֭Ŭ;’?re|-V`Qؖ@% 9]㷽ܮp"n6\SKS!J5?l'\}Jߞ3_Q'70?j hݕ7ga4+_b_4^)Dմ5N+|n@dVKlCmJ{x`]zu`nztu]jost9$}Y)b325wvH˵Si-V ] n[+>6뛅ka GhWD۔n|VT\>p/GՄ͟;Hĩ;nKi۽WԆqw :lc|1i[Fo3o٤GN`rhv:?=.T{0L5$o}! : Ea7w\w?2Q/`KC$Um Ҏ <* @k*l@yJ]qz기tց`HeȑM,(Cfzziv0KW@ΦrmPFǨb}˳1] &֭wCp>`G|GJ!nƘt#&/rOSI.GIEW AL*2Q ^Q#J,boeN #h.zVG$}uylH%u[C\ގ4_8וhCG8!pt,[_$QRֹN nZ{-DTWYnTg y0>rX(,[iXzJ~J\djUh-T,iB:ݖ9@3Ǫ|gjfp0~K6TD$ە~)gd6z``"M@Otznf4e>!;jfQgRagp_{\aE8yCeZ3sfUZF$͑EMf:(tu}FU3fk038 MO}-3YƝHR3;`_pPׇlFDC wE⌌eHz嬳o8qRDx(VD-eӶf}bb(,omM㌟Bɼe~P8 Jw3M+hFw| b<)¶+l26+dB8ڀì9XsiC1mY0NDӄpw=|Po)kK{;jf6*s\(5v(tx$X9'FI0!q N<32; "Vci>"j-܂nGLP{CP W#،}i5w9x6a, L.ZM@~Qou_v]c>rY׹nK>Z Umzr2u|3LzLꧩxNtӶv% \#-/0q| ^d8ռW@s(@jX~zj&H}Ȟl͸ } 6m5}1{ZSĬ%į˟IBI"n]U!kCtFY:H\:й^UA/_Q~Ѭ.tĊQ"(l #+Y[hG#UaRdA#vp&[fI/ƛK8k1d)]Vc `(!(VO_Ϛ &ۥ4 {Yg<8Od],A=ut{YC*ً:sJ,p2\D\œzEJxoE ӵ@h/Mӻ/XOo86SZ 6坵;T2).@^t u:,ݭ’h{)V.as%2HLQ E_%h9HAЅh,x,d-Z#T64â}nzuEEJW\\ۀbﴺĐ ]rסۂaN1brXo>jӯTnw#pÚ{g ˦Yd2HUEB F6DdNYiC Y=} etZC3mDⶤqϾ] pǞgd}8rij m9 `g[P|y;pÒlVJkraA94+^cɲٷ8] Q(JI(l?@'I͒_Gv<:nq}hfcM5v`H5?<ح̲ѦX]!ѮF6K3)(rDB<ή士GI+ӟVۈG^ɤv~K&m1,J*xK}|"j`ڎlSpE˴.rI$`IS}d$ G&89`X6xUsѣ,R8U@<۬HC{AqG7yvPҾKnna!;.!?mj?m1 " quH1zv뼧~5w$B,4лoX$_]}-߾߻iFG 4`J@`Z4`#iD/d~/.tǶ@M:čX5buB4N50B"a cdee"(Б4ҏ.@T8 1)$ՃIjիV%kfO Q9lXé!@boCj~'+`:ӎfi/v}X-Uwӥhy6IF8f~ 78-#%uёVrBss2h9Z-g€9oGG(|óߵyLg *+G.?N23IR97KCJ餎j5I#vG-̦`&kF9BPDUBrO׏M;%ғ(Nb\H߶$U1"ѯX̻cç`p ЗJvsdՙO yLw'zh[-;z6^<܌ X`H[_̌TF޶]dTK}f~us$ 6DpV8ϗ2髂0TZGY.+h\pLA/2э)ᬧE:K0^{;+= mm Κ{%H} GãEcg%pﲱ5M:\Pxp1X9?sBpBgx !ƣI|+ iLD"oS}YzҤ>W^늒NYڀEU:^B;^]אp _V?Fjq +=xhT91\";֒!JK`R{Oh:aklg/Vx>jrV')(c)_f$ȶV $PWHtd]uy ͡dv0/%>* Hxa10UuMaPw;~YŊxWԿy Iܖu^7QYEi4j~~4Ϥer!6[8Hdx]j جH*@N=94?MӡTG| V|T vr4ƕy[xtK Z\@rc=ļz6)} 52s7hپM"mO7.6پ|B{ ^ITE .1gm-pC!)2**\:?3ʤ iYBpdK[ qFiyGԏY/ݗ@x'Fw̻%O~_H4p2؇ؾВoEn]fk?u*α0wJ]Ha0jk׎-ϕ ke ^sY߮tC~_0ifp+ƥZ TZYޣ_!&@mAVmOT:o|n7Dkt^^2=Xm3h9Bx 6nVn@ uw!?xJ4Ez.~*;ӥ(:q.x=G}T $ʺugpU^ܜtdЅۊއi[k6>U&&@sGbpܞ OuI$8!P$ߟA4ʊj4V;$A7va9]:X֏c'/PH%ϢaZ%\߃Qtt,2LP>O8/r xJCr0Q+nb聲Ç& k<|JlˈN0e؀0;#ap‡|:Kiy '%^TG66f0*6<e;j%}CIWh^ YcQL |.h`{w e2@ݾ-rWAם, sQ|hpwu:w۱ȥe'^o!f 1?54fqMz KZp|flαh>[Ċ_K⨵Wz*yJa=7wK`kk2~>50Q}iʒ@ %f<7B~ItgCc")R|Zm@7uŅ/H~w좐%2^ٿa ?wȍ4yfOKo*h beic,9.ȊZɣk!O)s|1kNEv2f\"xf!m)>ѹ?B\LQp0¿8t\-dl{>FJXU?FM=\a뾘{7[? K^A*^Wq8I{bu.LK籼abd/ =#Ą>X*x ВzTw:Gk[;%TNk12ujC{7.LK%w!J7(ig. OU3bҴɲ96Lw})ܝ H . gF Sk67dTo {0cJLu .q{S8R"\, ޻`]ŔoUWi9:*|$I/p(67h rCKTb?JʸhX7[HD4΂U^`:Ws5))Y?}[EaLY@ۿb!+| G/:  @ ,ρ:) ts<_S+ $#fI#jـU. 3kC,WۊNj,$ZL_זA3z.uE6A[!w (aEY'!Z\(Mb5 b%A PhLbЋ1bˇn6q"ޒα|[nQդH4`GlռiM>zl:>ѲxqgOU9PR|~ƱTc-)0Nj孊th#' K6g:| 1#Mf[VS]Kʏ;|Ww&&4>kgCd {!q[J W=T "Dm{ "OuDd n;P~&L ]AM(Oɻ4/Gy<+|v8$G6s 5KЫh"5"(aځIU]ڙbǞ:a:vbMڠ_Z85\uLb|c}VIu!#"Gh~ZǭCe*.؎Q 7Or{R Br0xg/2:>ZK򁰸M q%Cw)xO4৤q;Kij}n{,; /[*"1V~uqܥioQ'k&#n5R;(2PE?T)pQ1mvM,MR8lz>)y^u19PF{ s: 9h@NFvo*~uܚ.|j`}r h7IDxF#9:EY@Ո$WKhy<3(uq]'\+Y2Rzs].~MAnp;/ _߃X̸l ~dfBan"`D7/m4qmMS4顳z~=O 2q+߃IV.lޜm(6D"՜@XMiXtm -U`U*kT^uC Ɖ$Wy3RMd};T\\)K!ݵiGm!vWXy?%=✧8?? t֔ iKhug q&hk&pذ>tLeÌ?M %GYk-vڞҚG:aSH.a"|z%l[RRDZWhqjO*95ij #˪g|Nah '5Q$dͫ\fU,g76uX`^m֣uHʬSEc/wUkL[zsSIfPF)uzyyuhjoT/ HT>?ZDDuE>9whvxUC0⸃r::Fo"U+a:_ #6VUٲjKZ"ۜ"'NE3#,G` q+nynVL"| HH߮{:"ճoJY xOnvA3n:>?n5 [v9k6aI硩纮,c_䀱F>aUoNh$󦁆Uh5H&{]cq۴Q[onב,Y2IZ} #2P쵉B/سE혗4l\ZOqc$eX߅.GNb&ԍoʼnbOt؏ 9Kc(yӇ2wВ3q B8nHǘz'N4+q< ʽxC*9R(AM Toi6ԦJtU\LמAHi/0?p ?R/,.zh @Y㐡-0Pf&<@u+˹g2+{h ~}Iu+5@Wx{ct򿅭%[!x~[1ܫS R<`v"I?_yۇK B^''d| k~bze; "aQKXzZZm@Dijdazm;'kT7[Mfh/&w(z(_<"r翚 ebjvZPbz_褙RH\JoqX -1JXX5\B661[_d›(jkYo1Zh!ojdvHcTRuW ޺s)X~GB[MK]˰4n?]s?(1Q4m LVk(ˢ>h|nV2lǡzG1J9e"Wu񙉍1%t ]}Mf4Ah n63DIbT 8 B`a62!(}4Uav~uG? ˔G"ߣ2(RtF˜~ ̨elM s%` wZubM$NX-299*ΛCP:Mj>;=ExٓKKY-JH>3RNH!26^g ѣo!gI*fc{YKsWzP/x]Vէ~o/q`8d/1-Pq 6/~ٍLp;/Z*ƻY[^Ns"-STM ۏ{T52C#G{/PPTϞٶG<$ؖ$k,Vc\EB !87ЙG7:Z }Hx^ΨгFמ; 8R=\1cˤ !K~I *Xzz} :s-T ; 瑝'u4ibo{'\-yW ԯ{I.pogTӌ.݇V%P$EJ'7m=t^_Y& %bqgp;(@ȩזGo#&pã JWuID#?ڝ?NFw"TjH: e.1dQVio$>B~ދ|:ZbZTb$(s *b܆%py"]FNc`1tXG-2?o,m#KtWlй|^TWTi@bWr1;USJּ:""NIINhZyN} H+)#f|O'R|fïnT@ nN3lZOvߖo s.z`~{v:H2/~m:o;iį+8B $?scv nA*4ţ*M1T9}*?k.{ Eih|Usj"7̔iI(tE+T7f`FfP对gjP0nLv&ְ #7(Ĺ83:C-R@9/͂-6 Eua15h5G^7{\>ڝCbɢ!Gr :0+!Y!ULi뜝iK,,:% }8u[iC٫bE)D``M5b2;\!/P/0Ai`F! o"X#aq -(Kƚ&{zQ Q,^K V: X8]]χtDEEjk|ZQ-w !gLn'|t\U':X,uOjTЎ!X&ψ@:SUl- |Q¼u'Sv1inpI†"?\rBcxljx@|*n/|=giP>EA 6<=Z<]<ӹ\3wλ>sҨ_Uo,Os>lE)ȠW5 e 'dUŸ]I6!*YMf^tu2@:O߀ݣх-sUurR[%fe zU*p:d0@,q\ѭG`>^1L!UBí(c ,I!SZl(+ dK),r5-8;֝x/> T{ZCH^73޵2H`e@R=\;.Z .JRVJ~,fenPAL~~;ehn)+ͅp7g֪kX̼9bx R׈àvu7odO h6t68M~FRΐ(یx9c|[̒nPIPw*NTUd Xr)*S%HZv%s m1 }qQ':.ĉ FFV6"o?~IrOFY$ɱL _b$A+6|Èlу&gI+I|}^RÔǧ2&Oj4fVka9*6|R(zو;xiuBuB-cm(fvmLSƜ# b% P`շp2f)h/r P}(lniVV Ua]a&:-e`J!!z~\ f&/m7 k?OxV5)->II+aNH5 v3 {[F2\|y"Ȇ> K̾\Ü `6m{`o;OG."~}$U5$N=7LrN(1[j3km.? 7ǯ8-Կh(TN[nI[k;%eQ=+ي̀7''XG䔸eJ;N:VXddS(Pg}xuh>9ݿzvet&OoW\3Yi9Vtl vT+ģиs^m.\je+|o I1wre!Ȯ瓔rFm!ӥ;m*6]!]aoI?'(>]̹0e?Ύݕ*rKT(')hX&4ڗYHe@8GX"'ſLKjB!|WN8LѪٗ&Vfk{=,9QVѓ؇ڥ6'5! -#mvzށ Є1MjgLL]Z5?w.H<;|_<9rxy>[\}[,eT-ܿAf]n*2Qo1>W԰~-{e\&#?S^$[H[O4RhhkAoW sXW kMOӝFhK7^CI4mS0lx_4d¡fgJ!(zZ6՜O< )'gu1o~lQpM?R7}/$ iՃ_K~ZՁ iRs8\ ZÏi%cz*aAD@@(Sn<)MSJzVOKe-p JBBffP#Fzj~Sz)aÃIf3D) ZD)XcFtm@́ xe`I^*{Hi7&?UUܢv w4k)C:=amKUnBKj}}7'PEPn]aT N 1V#2nq}dE~y BXVȳҚLQR-BO;?E{3hF=zuqZfT\:g3>9Ę&* qzHD-3mG9aAv20lNKBh@_-/"XFR='l P)v,8K1 >;RCa ~U6L039|q X^JCLȺ+C$Ò>+YY& rmP) c{k rB}<(vlgؾ hItF|QyZSӾhPcQu%k8q{8i?o~ѷ>yb+>Lp-Pq勒JA9x+MI=';Fy ꈚ Hsc[I3 ~59Gi_ln4oFJyښpm+vgܸ5=eYBsYbeE"=@<g:i1kP2R'"^vJmoڅ:Sq~0Gt?㶱o5QOWaZvL~"S#5VwOY>C 7cP.("Onbk EN\ãޜ!) !"'x¿2wD{'FpUEՔWk^[6dhĔɮ!X(*!,;MȻy^:iĝFfX;vrlџҚ1ժ!SN#)s$Lo8fS{, d1`! cRj*##+~ 3}< )["mN8LҶ NloLIуPnJK4%{WƋUX6`|*]'%k kK "6`r"4в%&E u.C 5$͠R$HuA(7/ө Vo~wʸ1Xn Y't(aξ_ˆb0,v'˿ jr+F.ż0?X-hizV5}N6!#qKy}}2B[O͹HmM :6d;ڕp Pm{wAuA@J *~~)5&PC/^/ }.AɃOriPn~-3[n9Bh,%82,ee+~^QrcTD$)uiQnOѢhO0z1p#>TP%K4)GU "\ b :ԐmܤpB~2WSu0eޥW4>M V rdD놻%ѳC-34#4i3ru{n o?Րw1\=^f"2٫"" v&YăcP[nH́ޓ%"e)4&Y L dÿ́4ztMaKgལ9zDDc6_KiQH$8*M3bm@lQ8[Xq%`h,c];4aH*i.cCJuLX;~fs<$u 4!쳝li sHqjċe4=|lk Zz&,̓CQ2%"yh6 J*{~5)Yسvꏜ1Rr;Vx綦a-+$/伸y[|.gUS9Ew2bϾr/TG6p$%\MzKnT_W -7bPMTA7"HgW?qqj6q=JmQӨ?q棶O2g!T3yTNlbA,TzӬKp!6$jrY씒ISoa"I<4=4e+l"KWj[KzGGA 0XEħ5(2 o Tv;P F 1]{U꾀׃ʌڗZ Ciޥ`,H)VB&+H+HT{  ba^#U q_S\]zoz^ FbZ5,Ay k ׆@ԮTwM,՚5bVޫ xA4HwB8AJX( &NO^xß\NM>z9դ \&K6P8?v WMM ZHzix)KQMqd}k1 !DB:TpTe28ད7~'Υ3 J{X>A.vRJni\{_ мU?گ_fS,S}D\Rm3y.w"K=Ge&~ m%MZku' rr[mLGde Xˇcb.~0GQpKKߴ>}53,X#,eA<%WC4k34;Va)p}*H@}KşZ}Aj*p{F?X7,}&Hr<3\1UY#HZeL*& xj6v ^uj`)ftf⡑loF>>y+%}8(پ|g̝ +TEإTX(Ῑ `{,rF'IfTK:iҭhdF˷yI*''3TFu7/+hΩp&"rf~Dwp04OA偏[GqVr6[p7|yw4ڷ> 0yT,->4`PHdۀw8@}r^1Eb݇N>D0NQ Sf:ּ;v%\sojv9;vBc Y,Ìn&Z?aǑٮu=K`+De|!UoBZ*<7m` 䳓F*q)y!@Vaz^0Nj%ȉ`Cի׺X{T+ѫ8qO6K2^mБϋކ$DKzcw)U[e!fr<$ŘC'}}} k JqQbhӈ&Yp a[0C;Ikj+a%,J;A~~Q');ggܶ6y]FkKq{oЖ|Y~Y|N|y8v2Fڞ )7j*aOJ4wJuDҘrԺĵؖeî"UOY))TM}.!>/@v)u'>TTVάc:ebpBS b'd\y\rJNPK1@T CPOF*4*fEv{\W$Fsw7MN*ZiZ/vݙaj ѦWZMEyMK:!EPiB%Jn"8ϙe)ޯ-9/0TwІph:kVoyFN},o|$*b" hR^$ 8S3i}s*?ѻR~pFħW%x5r;NsRg½ZzZ5%9)Ngy7h% IQPG!d$LI8]@\wE΍P@ R[i9;ڟ7lGRCC>RbX_!^{{h*E).)U}aN§^DXK.B=+.bk%N4;ج:3TcS]y߷?uڔ4 _>&<U}u;Q Qs[,uːf?|nݥGa&Xvf fv@@̑ёZrF>9qaٹ4CNupeO \hMBgX;-Mv Vu @U氼w5D:bw6+TfnΰnC ->s~w5Juɥ:uDoF1L/-PկGFkj7TtwߊLCPy ק]Jx VS)0ol8C!R=G4pV}z"7@|U~=N0`Rq%z]Ew#ԺiknXm? Ln`=0ϭ-X+pr-w\ c͡-lD7Y"7{aZ.ټ~сa\m}qtgG3l[= ݦQ:՜͂~.TҝDj}Zs{?G=ik];@cLJdgqBpp+q3 Lt tG~3P4Bך>VJ`x'T8"I&,Hu%ENJ%8fJ3 _ܼbčdoc] bȢ/NÈ0 >ڔwz^ҽ0y8FSsu/f$2CMYzi/m5߷}.+}ړUjוNQ[kw؍blZw^kvX o|# Clwn KS'G9Dʢ.o&Hr/JF5]_>c׋ fcY[1VG7ƗjA|Vy|tL5.ų`GA6'(gXM@b:a F1#!(:v{}RBga_#v(k=#޹U"cujV U3VAM'E[Yl D0V_ e3tWd30IM3ykGOjVB9CH0>=GJ 1#-5%#)yu4}y@ .AO# X`ɑL#'}ޯz5n:Gv5hpb $UF|ODngbAW'Dsɔ3km_pNfЀhEkb~Ys"tTmHx4e וkKRE:<MpsQQ$ 8mui7xkhC>L(ʷwՕ&w;v q)8Xg4XZ#G:r`*$ &X 8A/mmXo&X{|4C:;= ]ܸښAb@;*}uJ~T/ΠoWێSp_5g?9. ([|Wn^R")JwR,96i,Ү(^sRR nM!Gi r{hMnCC%pA NP|붬9r$Jj nڷtKq,FW!Mcݽi;&̕Kf:g˛ԳC3?P QxmDGVby2]cmqtīZJkv?-f;8Ho͕ʻQkC˺p $H~N|T^mQX4Վ!|{#&Y=/L(st~|^^ ;<{jGX|KE-` W^}eUzf'a5L;^ (?E]AbmI͘!FQ7}8Ww!/=[v:y Vxz+m 2R"LlH|hy,q Ut$R a4 A m)D6 8FCh.cK0,g7CyJSMfYal&Xx]Z,NAPǤt{:kEY]V.0jU'PN&R<Η%i,p8:GЭg񐇏se *K_nֿX*Es&{A,H FOOkȝDQuWu5X1I5'bUw~l/uY˾ˆ.$-|BR\6k; NBwp[9&KcJWF*Ovae Yxa"웚0n `5v[38s0CpI!0lWXj3R#C92Ҿdž\sq1:}E9(jD2ҟ0#f^A8ej!v@(]i,oz7VeڸIJf@xɥ5دh17?ZQ0(I2c ?Ƴ{3sR507\PDim͌h4$9{odj욂Ƹ5IK]3+:K܄=!j¡27JNmgt&ޜ;k3~s \llB4zٜ+ǦyRCI9p0Լ;ʫ\ DRGuɁb.67! SpB6Tl0rG$@e\ɢ Y ElwYiOJ l&NA)ɍ"ai!J啙~7ѻFG=a}v<3NZ^ڍ8:ߑdMom ӻ_k]ɰi6R=A#yySi ;Q1w"$dRj 1d+ 9w(l "iϢF]hGuUyYCcd IzoQia!B;+N`uԯ Xc,y4:1 R^zx#4' Qa0c:k墚(:#s55v_΃.t3cO͑Y*dPjs*_ZM P>w[)뙒]3VH]$"7 z(8=clUjz wJ>"7LS0\MҜ B2f-d&>ğ~DR6Y anJS@'6ܛ`4x$D~QNsdцMlՕ7I'q]d)4oх}20cH+ c$-O%9mfç0ᒱqN/=')y&`v1׺$MڅȻm4_?ע6'6M" 0F)3ȮQ >2TLKw3s fCtl`u_ /I$)d:%[ވ ;Ky:a~ɏ.cȒ`|!/HN<޸,Vks:C>'wm"f{z<*r^t#qf6a# xeȪDiϝxLɴ"8MuBc~(q"e'4 =g#NfۦU-V8Xيr؂fL0j ө,N< mXmV D=ȯR%tr`IRt \;G]p(PK8vM@4bf;~?W+rngfQֱ]9igb\ }akqAC؍GJT= t%K">6̒U˨p`Fadέgγ,~ `t#Ъ^4.4$[NR2]HO^Jr-Ynbt3ŧ"k) 'v P6qRy}dw7 7-Iy\_ @yZ&B* Su:Z/qֿj2;ye`[lXݠeYL{lO->X4Cp ,6JW܌s+]cI5>AQX#CTS|'̔KšLieu-mLL "ȩjdy}Fͦ3$˷ 9[YL~ 8 1&+b+[RJ,&.trѝ,hc- #{>>*бO;LTñ_o]1 O.fDm рCa&wE-m-J3l Cː+R:#(&a74RjFy?+qKVfqʦ#d24,DTnJYr) %9`LJ:)ijdXsW8.l'#>"LPq, Dh `wY.cEI'ZLlX䉢Wv hW*$r%gAfdak {-@|!_H[mĥO4;r[&ueMVSCe۽pN1]*)e{K I"QحfSϾe6")[VZz8!z7r䟆H sԠRpQ.3h+z٤V7#4P"ß1z@F %@1Ga!Ac▄1XPlnd@B0vhNmW(w9dR*w clUv6Fi']Hs33'DK w=;^54&YO$/ *tF&m Œh$؟Nυ&~ ]3IK~6^9eKjCɰ k)ƟH+ߦPw&Y?3A濛<ī?iZPЩ8jLO j~ Β26@|41$TJOLFՍ47fYVYUNwy-[([&?5֍?Ľw9!C1Cy[LY3Qr,{Pxt|Kۘ q;Ap5G|8һ PY L=$CSY 5$ByB(/p}'UF #;VI%%V7[c)VFMoNph7cd(k '1:65nǯSٿ :~UTn\n$TK ̱C-,x ?S𢂀Z󕳗"g KL$v9rni´;ZX^佢oL"$pfeKLxjIj>lP))FCT*M0 s.Y;.ΨzqQT6ZIz״H8j~>.2 ' &/_ Wuq&g.'Ч_R`W\Z|щwɲx}ĶU`f5AWN DfTǒy3VҴn_|\ lf()eMXwe?j!r;tU^oDhohLp`cXϾy/;3'12 B"Tp8gX\Q_wL` 1fj[鰈\p93~`\٧ɷ|ZU ~< qتKL-YRҦ#-.Ǣ}L(`; i~j$$P1pkyA{np"$\%6L$7&5"%0>7Xs]-?mwRNj¯x\` :uoz}2;Q+1Ha^Z+q"*l 0ʹzH&~Wr(b:cSP@#}QWT.Ihir`>/y A(b iџ\1UHDzfO*I&j@r'I~U5&Cl6y}꽤w+o GIC8=UؼbʭfYx6Ʌ@SWT^<-2.SZ>H$<3 'V4hhgݫ`> Dx;ף%RYCGV4+}ZU-s,I%MǙЉD fTG -b0*HQ]̉(J,[vd5>E\Iicϻ,}3/;kݹ4O~lUGfUhe YIf{ &Jp0CE@ ;^0lЯ=S9G`rݣn8bt2{ONdUOo4Rks^1ڀڔF-5[@O WP?gr w8 ?O,\o5yqr;(Hۆ8|p8]7 R \E\!]!SwIw|bHPđ0Eb0;66"..6RJ)ɞ}0xΛxj&l6vnsoήMj"Yv r%e&W7F :q=d]2 N4SA X >oKpL{ڋ{NQl,HZ_ OXzV\Jt1?5և6=rnt#H v;`HY!6DS(hdtJ0! {JRxpLĪXO'7s<6ܒ;iC jO_Q^g#Gʄyt7V[9p8Bc%O:mYXijB2Cʖ.0$x'8Ks{0Qv\:$imnN3*ׯF1_$<ս\ mrcpq﬌f}M*4Fx0wixC;rQmqŽDKb&qg,R!TFO4lO);wAY򁪜<:R':<'XǮ )G.MY ~/]wE'g@yAʬ R\IʟMx C ѻ.̈Y:u!zkG-DtS#r6pvNTS2g}{ @wQC9`d])b6R ۉB% 4'S(- KUDGcL:a"9 l6$/nJ -%\U_gc;?'bϲ6 wKkQ:'iT%T=8Qs[8~r g5ԢmCNjfHC@4^3q2ըl:Xӓ敓f> "XdaGDxkZwza{aO6k_3""q鳐KS? !#S u`?h8f}3gf8hFE-8mH~&'+XfbܞtzH8b,rhViN-^12M˒\7 >LN?gD a8fŵXw~< ^mn<[+oalopNهmI$ A'zY\SFI}BJ5]#k8S!{ Ey4CҘ1r9eT8y[yo( Bfk݇[pœ]kÀF_x 9XsRBWr3>XA6ȕ%BΕn; 0sLrUfR@ Cr h% ӣ8So%Q KHkˎ;[r+ 9H[&+Hz"2Kd~= d%_m*572l,l~&;Bv"WZ(M(T*v-kb3#F M;l l[EתShGpDC?VCbJl1B?{X̽1kBk33@" h]Y:Sk#`$B_`kk^l%xŃ\pa3a/W޽F58مl1D5ReBL`ߤ(؀ ݒgvcv&qwwIk J,@(@TqJ>.=gYN 5,JszU|~'Q먝VM  p0N]RhgQs{z̕u>RnÃDlTpnh漗pg'A՚y/.XxdMЩ:k`f@Kc.zkhp`_bl9L/M P>$N>wRz?*9ma2:T*D Ny@lǖGt/ѯ9F3MSr]bp ޤ[ۥ{(K{̣=Oڍ)>[6P!l68qF}>؜N ռƧI>7X,FK9'ܒTjќD `SlR} ĐA.)A`T:Gb&mMp0{*pyP]L#$WKId׃Qѐ&0]<MHu2հ*_ߐk5l-V;7h /0zLӚ}1t7(96'+5Tᄾ2i\UxlQ24|duUmKj>yu_&nv7"[0bX(/݆^k}ޛ&.N܂$.(W >;jA+yIdyCddY%t}.=cԇx|~u\?$2߰kV3 {ԃ̬D!(.yOP\_eZ*L2c&xsyFF.RZ<#@)|%R@ l-pl_# QXq):?=\8VO i ! p]twn*v-`v~̟+G>⵷~Z NObﶅ@Ƕ_2I>EudY?64O֣X9 4yZ?x5n9sf.UMuNn 3_($CEzZ5[IuB`\2 RE,U(\cgx.ߺTP](0|[K 7"E{vR +#%)j?"Ә}Ə OعBy\+E rD*4IU~ !:߳UgNmx={$ u"({}q?'/?!P[3-=RA k]IKMVjc>ԉ3LkLj&;`ZySи>QCR:nl1Z.`KmTgM?ٜW'j/`A}1>)R&yB'?1#uq&\e &PHbve@sW2],}5yg*SV0:-qO43ζ;"J[qxXX3і1 $\ϤA):OCSX5rTk7!oNs}HQeL;ON/>VM BFش?m߽CwV69܈]\ލ؉9")lq6ZxEߊNtqg-W"Ipo΂>RcP],=;S ͽ9yl|ghk2 =Z4)'C=J$[ErF- ݏӸB=UrܚވpP~nMCjԕCϧ(oL) | ʮO\Ө}dx:׏|&_N"ꍻW䟰m.`3g4G#֌- 7..(-L"j,Ud#f~ȡ5]e\7b[gho6+NP_HS<̿ ˥==VmH@l"0.M'9\G̀z7,%J25z$KHʒ"yD-gZš9V,jb>yQd?6:yJW^Q}OJ*'x$[oZAFxׁr&VЯ mn|!d`PƤ0EY.*=Y4͛.Mķ`MB}3I!{s*:1kU</b 8![llg6P3o߻Ez(} e pɊaӱ}hs5htJ?+a|}>С>X4C4"pO{T!j"[e(|Jy*+.W$ ݞ87 %5aꯟ|7Gq49N;Z^H~Iys |d&gSE?&⟍EĂ9pf޿=P.,+X̋oxz>a3@U"ԼHg_ F1IS,e^R,SCj|?㌴Mb|-l >k:?{H_V wQp3Hj9R{s@:rRj@7n;G'vUˆ,C?B!SFt tWv(Ȇ_R("Y8_վbO7t?ʶp`h?zډ\Fqo%kG&aŅ ÕB(́3KkG\XYAwi9TNNbz|E/(,TUm/f5a2nx5b1v_;3궸biϠ:F_ ($ӕI8jԔ#ӽ֪<$IYV լ' K1Gpnt*2zo]݇>qOT:~rE<\%8nE'>/(Yt |~MF0|1ي9˙ @9;ɗ{4sXp'(2a?Qv^%Ϭ{&j ;TbVFBSRz1 n.s !Kp&zVܼ~o\Ę 0Yk\? plBӆYZo}M:L+"*7={8SiOݾΑȓ.[\u(}/]_7D#gIPlp ?4cy FD7][[ul&5^c3[f΄،&gm}zi|q7i}g"dN}"!u)Nd? Z)(6>{,xכLKsoRfmW3TU@ Tn_y@;j>xw4*Q0 "AV}km`Pd=~'w&-򑷃CO7lhٍqvI3"#X~}m5h.NnA?y钑WiS g }E6# Y+lq_f4Bar vs!`n'{eIxls77pHU*ldU<HK^!W(cME`-`GP꧹es+b-xH#es:>S'@-f(xB.x32uv%|3Ca&{ɟWT.m׃m?\!ӣx_~jxZǛiZ5'@[xIf1[mQ] ]ˑru~_3cփ@#'Obd9?ś˿LոK%k apabK!mU=ieBRIhf !H?0h:,'BP\\6-Ḋ$'h![ 7PGH Уt^ _RNAcc-=Xx8Pl:g96j'B;!:8E6f 8U` [IFN4zهŐSϪK&4  BXfFCU:'wnHb8#$(Dq͹n R^nʟ-PGǮ^eeHMK_d HM9*qxIszslgOglQ[@ VTTMhD/iQBJy[15_xHiNUk"q 'aE;ArZ pf͏g FKeu!˚3Hr!ApN3P.ָ2NB*Wҕge 鬬r5p*>MO}D K Oma-,sBvۖ@LSB:]9} /M;bú~ k#`lj6V`[s;%`J7` M*VFπbysmY]cYBC%ۥ1״^>- qf1lStڴhpG:W tw3[QD='Lیo*yŗAYCog}6.㝷r9mC~Rw%5҉/#X.ȸ&ЋJIzȝc+N/^ax>;<120$ h\%7ֱLF8ݚ<$,kH}M̠1 ~oeJ.2;u'!d:Cd*l3qk#^9X"]u )렇+S笞 HgE>gVPYW aa *)2Ҁf3\bc!~ 1`5!_e˰\m vz.B~fy%i6 ({rx55=܊04X $]8t J),gY_&phg״}esbwB׶ܮiVh16L'):V)tA] AMe3/aߦ)ȝ"oG"Bw>X8.t%ͫVIs1*pÝ٢,Gn(e\S[ߩ`ZuZ0s5uIBA .1}I @8y-.Î:AankФy8db+V 1vL-OA>-ZfVmjW܌ Ag c^`xN̍;'qbM"nD*hޚI26_Asb=?cFUAnTYڶļDIm@^7=&Ghv’ާ5ٴۊ>6hFLlʛ (yӖ?WKM?yhfKKbFt8VU V7DMW;xpe"'GjoUHcŌH ΖYVL zKTWf +>5$[VgӐ YD,>Ҽ֩w̃2P 8kv ZL~ݖew9w]/mt:Zߴ?6S^@=_s(6-A tb]}ۮeg'7_^ 6wÇZfJ8G|%+p<)gѹb-u9#2k1#L)(a ,&5]Y FQnlR W#8o y2߯KD] le`Cu҇:7/(Z1 Ÿ6+SНZ2%7SHBۣ ޛحyS]$ri>ɺ"f @J_杵[Z+s}^)3N+fݘ1bUBGe>֍s[6u I9ҫ[$ MR4 A(ͪԴ?IOV?M G4N=&Us/&oOn񹍰WY}sdl^"05O^[75)2XY>ShgֵfAۙ4I0q"+DQ 'HOĒgu~$>DiaҺ%U2^L ?w< ` v6o,ږ /nR.K"hO$(M Ql7y] -m|]5 *da.n3mZBu Kk?^xRi  O]R}ɥw"dF3{)X!m4er4|dhW;ݵrPWՀ\\8a(V8rޗij`Neel*"eČCAn K/-kXDO+Q?R :CN0<}3#*U|ɾQ68"QRm/{.-D){ʅMFY)l/r~]΂R ,꽻?yžg-JmpMv%~n0 _fFe^|5.MW m%?{_gIAJmsqSҳ6=@Bw̚ *M+fW|7&] *7r)ۼdi-C] :gnp}`t [:gNaեYdn&Fhd-ndk۶٩+Je²8* L/cYp`z^Wnq/b>pQoԉ :@DPy/I4bΚ7P43?|x1{Rʌ-^<&f he_lo1gJr~[EfEnJh;!%o'ry\)-Md^;|mܜ9&N #|i 8d&9 2Vn fĺAxV2,}Aw)̅i~zBk5-t{21fg~{Z^gV+8`V1?СH&RQ_X#h#5(:DؚH!G*(Cfϥ8nylơݙ@IK.Nb[FAznEb<ӄsBtճr,Y\p.Jq-J+ׁZqH LU9KILBI[DIcia~_J'n(Y<^lC^gN437x-n|k" ɬFr]1r:}餩m$\QP bIC6cM ϫ$D^B\g7곶aL6بel%uZh)p{D47c0u5~KZ¶-s'u(yY Ef9/];¼ s!*ZF)GJz4!,)PY$xp4Jx Kg-kK7X2r!+P]?kjduJ/B1)U+L5=ɲ,  u"irhC >mZ?fr Gjp6:vpB _!` ~0c m!(!.C.KQ- 3sNx. ׋Ta/PFwWi1m 7 q3Ȟ[ ck|7b \SǨ@7G96^;3HȖ7ti㪟6E/^xΉ 5X݋'_J ?"pr UX;JP>1صc<eߝs.2y߇Q(I㗒 ɵ 3~'l`aU +,NC/ٗcWUag؜q""h垪#+GrCi'>;N_yÆ1y3d4,  G@Rr\`CS8UZoD+6|3r=3 KJ};=I")><79VYCgwDi@RdY7ԇ¬=sEB@ԫXܺ쐽ywHʌI(/TZ$ah&LI Ho]ciNU8GP'X6_F#y:N<3꾸 J/u Ns ^$kYqupbGz D f*aYo*y6L|G iò.}F@Á8].#Jw$a*u&(,TB ^}R Zqe9Y=5 S'g+F$^Ϥ"Xՠ[b^[B"rBQR&s,)-ف1w9?߾B=qPaL&$h'$S#_!n]X_)\u-тp֨p˅uQ  NU7jWK$E0v〶uC @ jVo Z\LKxںvae8@e GnFH {5 Y u#!|\j_^տĭ&}[uJUYx(tEs's [$ק͡9bS)z/͗w)սq]ϡ>[[I>((G&Ј-50diu\l)+9a x"Lމl!o2K!nV@塆u(J.{BΊy4lM_H>L(^CEUPFp`_,ߵ;]6};1LSWױ6b8׵F:ԛ{> tW$,4g?xJ 0+%~eDȦvQlzdguh!CET]}Ca F[2(䣉IoVƔ'/NgpqGDEvmY=Wuu%lb@H\_]Dc łH_ZdD܍F+4"a*IEߎ#/!a-MZbTo8û6,3cL+kѬ.YfpW1:QT%J)\i sYM\;~tۜ1-% Q6,* Q zb}`M #ۡ#M\*`KmXԤ`"b"H\rC5pu>kc:yH_9D(4CA#]N:2r|##:#] bPq"V ^-(ʢD9(}`&,v~3[sX_mm=wkKb'u4Evw K٤27zZOz!;fO<6IͼU}؃˃jI2]n')"<.ǒ͉IyBZ:сQƒ-cfe+ weog覢~Z[|)~a VD/diuؙx"*5tMoҪбE= nIi܅#'mq*o!4sGGCٝtW{^f{k er `Y:e&AX(ÿbxDBK], qc?Rw,C-1 ?I \㑲0qPDMAi8! M8y6-O3ƃȭ2ůe׏~;BJ=P\u2Eא4 VjG*@CD 6 ,/\BcD <}c0ܼ ;cuWʴuh={9U%O@h{G5ɴȃTM|Sߘ ֜gK5c\m*b- GXvßW ȕ7v * |) -.oLKC`0.ymr? `0Kw:Ysdv\L=`DvE7džP00mt* 7-4xt@b7UGvZ>%KRew8^vyAZS0 .k~3279 kD{W !e_*݄4@hwsb@1zT4ٹjlgUOīWX UlՊ22V^ Y\ՠ`#>.0\xJx4q-6Ҙ.Q#3WvPDQ(<_8-fxG9\hmȎr֨%v_ і(;5M/ktP`q4CU](cC(j+QVF. %.UQM3Şw9{iX#OdJ_̫x{A? -M{7ob=oi|>q=?!@&nTg䁫]~hj?T\#WU7Th(=>MZa8gFYNذZ([DeUh*񴪂t&E9JKB[\S,H 6Ҕo9YtcIރel:)O$mzefB)^_i" IU%L: u#a/\ڙg937bF{;"5# O+^ p͠?[&u4`WsJm;$\=b5@R7R+=bų4t1+.k%O4թu[$/rHr귁:[t,VbFY#|aEa&><ƽ0)e߶;8^8 HPM3ؓ\7^"'0jD9z"wy eYOqd^(Sb_(ƒ9󬐃YI@ER~fHhQVurԫbc/F|p~C^vgb](/+Y!le*rLX2i?sU*{/>=lk# U|[ei;^y^h$2X0۶+ Z7Ad6y:/?p?'_m " #3^= Xgbp]uyI S_TK_S @)x#j`-%/"5B_C̬Rå%3'ewyZmc^,Y׼0P6bI;.p Gj{|x"+zoZ(E}8Т%0K,,X^{3մduJh"r&A%(-83]<*dJLz)zԼyìCgȂXVl~6,sk.u>?o 2/YB'tjo']D/z2Ҥ '[x;ABD~)_$SCU+o G |c6uO#>"Ō'Rq%YNd3r׫~8A#&1?KSzM7CК [NRz>V Go1I=_: ;KшUc5 x3B5,+-FdgR v\ot; bIE.' }m:өWt'vjj -_ zRv ݜ%jDCmȧJ\i*"SmK'9-cˣ`O}۵R:8et>cHBbj8ZB4INesOWٿ5D((\40.O5U?|")F 5 da4CD(QBSB1,cU~ҥA~qkG٪azfOO" "˨Y`ϣ vg<wVd (~|CW'dtaZV:'C'=΢*ʰ5-12ʾgCr v bH:й/+Y[ Eyo Wb*S=|^ͧ38 ㊜ؿtcxh]aQ`k[·/-hrd,(Q vztjiw n7rnw#B[Ձ73\mk7 ,> S6m,h`SiۏD+C=APj L#oiԈ\Ed/U8 F N4wwL]Q;FY UHBCb]4  :.7J,%v2GSuꏡ ll="}N\/؛cN38Kj4aR6h6vS?˪,T|ʼ/hI:ʪJ9Sn'oU7t1 \ Qz{T1fJm A4}uƪEPD!gOw8z[ʭO-9}&t/t~Vueo ~ܥNN5hDzv;gZ8u!% T~_0^汗T#!Z_ `5-<E9(KF"𤦲C|oP\,JR r29TQ:}MUC" $6S 03թf6Ev2rdnW;lOj B>'I ~vٷ yxUQtj->&g`%^ ,WPv'ᬨIOq  i5 ihbLg],/1nUF!nA^5ǵI 3kQk_N7A*Ԉl0]DeԱ󫦄44upT>?< `'2~=wPsٗ.Uz|L1&Z Zx3=n) F kB*G&$YJ7aEĘQ~Tlniy@v8 @In Ԓˀ^#!FtC9Wn 6U jǼ8fxȹxWIa` Q[5m`fYC] jSuc.˟iZK/[N&C2r6zn..Eg-,#" Gcx?bfu{ZN{aR$&;4Lv)݆Il.$y"#,~8N!C-mfLbbp@ldZBj<]  @7>guN҈b9F.XG=G<#YeY ֟bNra1CqGz'3DCc9& n`x4(-B3ma M3O~_mfsXM 4}+d2!݊k96>.\HŇiRJ}x}K6AMkKcjSV6F2m]jWDZ0E#ĮtC즢(8]N\NXf:/Z*o $N<оrLI,LͫUUp~mNJ'NXۥ+ǂ>Ps8c2e':N\](ڴt7#HӓJg I HY}?Y@PC :m^jM_$ky&X̝';ԻL00xW 1ʏ ̓4Hl3G) *֟]f=\]PS|eS?&o 9ѷLzFZ%H&WN- \ J3UMoxhi.RP(nq*mٖTz&JPs_1!^&}A`+ure8 \{ٺ ibu'f$S^"L)L5o|tk.6ʥڱw5:pW' 5[RBpʲ=(UN@8JK_ŷX|EeC9r=XBzNe E _'Jec,bc篣dk&@4J(;fe4mh;V(@I4t!0\83 -ѻy'#  rH3kwvsy$ 3\/ T!j =hN}MxV>~rbw]l%A&kM5dDW5z. sxݬU-b(+0nD}2NBNŠ{ 5M$#[o᫤Q>H>z׶I UUDDHU)4;ڕ1bPCD`OR75x)<{t Fs38Mx+!|j!Ne=3c>rɮB܎5ٲ>5?}&(ޓܚ[" jتvIl@yE%,p7:D#f}Q͸G݆;3NjZɗ\iKR"|n#cF~kx-0{ ѥpKPKx5,BmVK-. R= uKNfJU8Nö4v7\A#Za[81D, b-&o*>,+d)Vjó_dѡJ]t}r-e"kr8~R;!`oAtjZّMgOω/.M\;jdt ƠF8xCQjL$8jfWqEV:jUĻr2wZT39+3<]0ra=n0iMNObT%3BUVDV2$$2? ٤#ȖF1Ft8[nJ: 9d{'Rƌ_YGkI>:ǃhdoݩ{ {+o*&_}x8hjo-?9N1: $XSZIOUeMVF fnNCνXgyt'#6zW iݛ@F @՟LɱvJG^$ޠ˹*j= \e*N]oj|cxD̝%iR 0*A @{S4Up47s ~L\_e 6eK[b]??n#[u_q+P)CN 9[L*"IɅmӡhY//U1[Ld2,qYisE̛e |Y1OxA#FʝkdI͍WR 2dm U>{COnA|5 uvZQy4{<\ *1tw{Sk0(ꤟiY|6=̭ZLPE .jJ[K߱w>w c5X5Cv _Uى*+'fMY5w4!wֻ#$>C̷0CTj =BdGWxŦkg:)ZGOu^UR_V: 6ȿƕ92(R?&ilSd:a'] A5WARpGFhM ˬ.tcϫ OCW{EzC 1px(Hb_cѭΗ.]]  %\G(M~^kJ&y&򈆹~TFs;]iR#sy"lB'UJmtd.7P“KuaĮ`K4lL,=~2!vj8g<;dhѶ97TX[xqיaIV}>bT b'IWJL J0p1sO ^lIHJg 8wFgl[)%I6^ Ք7z<70Vˌ־W}\~{P{'D% ic[sIx2AkL.{iЃRA ?j{  5A3Wyq+EQ,;o bE L',qfR_3R7 zo+Vϳ Fdo h<0#+٤{ cYhQDktk~UL&[8MImGk$;^>DY!xh_ݚhPfQрv?_eqzt~l 386K߳:ިkH;5=xV2$_bNX  ό,:K[ 3b]mTT>ZWso#i\#Kk=mop!p=dF8;01~i|/!b_3/Xm<, *m)VȕL;S\8~9K׷ `n |':3KniQ04z]sN%T!{bGhGs#[CTrЖ1Ar XO c*Vq\z 3"z (ܖ]txG.U'J8~ص]K!MAZO5B`cb$$r &>:JYOп|`Dt&1 n.P3>790ti~4ƚتܕ\o@=FԹC%>yWQLЭ7 &!|x_[WTT1sHjʉl^h\m_;c=0 wvBY2GҳxY3đnZ:W q+Pq;m ӄisxWѥ@$7T-)Ku{:8yd͏fo;%dt`W i2EQ rۋQd'IC׹r)nE:15[7[lLk])xm LkXssz\RQu͈Sw4IxQř^^>wlm6U2yE?)]Dî1_xyJ~k"Rp#Y,/ b>zBK<}- &Ř)T<`+2Y\co`}d- $2K1Y Ood? ApDL[Ƚ~'L]x!-HuWB ׼Jsǁ!P:ԅ/sǠ6r:ΞJ8 /hRNyf|P`_ZʙNT i=HhEL;ۖeG{qr)oIbB St \cax0UPcg~g8IC»lyDϞZG2,vW Wq觅%hٶ1PIYǵ*r@LyXg)$¦]jvL湱׻ojhLj4 )-*p^|M= > W h~`): _+8X?lp$aħ†DߗtJKd,]Sf ${$TŔ&}zai~-}`@mtn2NC}븡XC؆0 ' 9HjB 9|NfYLDh2ђjRh-/{駤jL+ņgQ7jfAsLs52Jy{ c'r`oK?Z̜d>,ףyFdsɕ`{ -!_aa9>_:s#zSAG0^Xy^$#:kLFR9wBCo Fq5+USEq?S(evMtMph=-&g/ۂ},IV2!Pb#:I^ۛ>(csd퓭yKh2]5}( K(ntICEG+M&cE&CI f^dʺoV R=uW5AmFW.TEKCx@Ƿ5g5ot>;7}Y>!wݩu.`mc)C'gÕbcU3%nM屭GnICXm^O22e F(7|@n{kfۜ UEFwogNы-xak_$mKg:VZ{jOa:r"ĜK?5 Eށ(6rmPB:8\ab+O֚"g?XQX܏K'lv@dODÛȸSj4U=Uj^vkB/ܟR:O4ǧW_ßl)Ko^0{o'FQ?]ǩLQ(g8oy1=D({IJ 3 (U ><ܔiSؕ`c)q$G8=>&ZyyS+3əz^{~5)A$7w A"/c䰟}4ShjǯTTg^Z-W(Ȅ1祎]\MVcq ݲ7ɛG9ck  Ug_!#\ L\:|OlVϲf $.& ]Na:{tR;-d~ܜ>A"1W`fsWm!}S;O"z T8sHE+E:@ʨ2&$aJM?:C1$Ny׿r%E6Z矚\_ VJ993 ٳR, U]IXe_D?doKf<ݭ) ><:G0I4@O=2NuZ7V!!geY0eLoFYT 7h(c%MATw\Q@(zO?,2;uJ9];o~Tv`.v %V<+ʩ_"zoG򸇛 {XKǩ̊g8Z>U>)#ד12sHA_,b?ÑdPd 4슟kt[T َqBC,{|,|UYзF:zw=j_|Bp|B(6X2gYꞓS{܏7F~$7G05kZoV^^Es>Osƫor4ߴ=<`v&70dG#KCizp,`h&D.Y1!Dͫ6nWĉdpsTCט m" ϵ׋}%Fq|D;<vSJiIHN-\Hi w޲3xG3_oY[(N]ߴ9|&`o43<=Unpi D|5mJጩKuD2sv[(/xN[aJPo3{K(v* ~BJvQ cv1C3o [a;C?=02SA:Bc%{\Cfً!HK{}n.9Ix7ٰtq)zr&e56j<~Y"̎.H!wٓrp5S;Av@+Q[GÊ!ؕ#>nrRL, Xj.Sy(ѧLL]ſ*ctE]YO۬aNnQzZ,eq)H. SYT)%ub&Y>J,:mgL͡ngQ\0wkP4u%Œ.:tTrآA+Uvs_-+Ġ2_WԸ.G: m2p?hBl AP}*>' sciՃ>o-?U*jZhZ<ӂ.G2 ϡN_hcؑ_m(!Za9G$_?Pb ~w 5ZbFa/4sofIد!r3o,U_i&wW^i"ar]@$@ܤ vXA2,=='5Q7o&; g~esdtXu ̈ZFm]U\db i!Bbo/DY_m:eyfG]yMܝؒ]ct7|d@}Q?|;շ4i mיƄ@enPJ}1wʛ*3``cYh#&!A^7B ]:&M. Y_n5H+Aq˓b4`?L7W{gǙfu C *hTܒEIhT):]rڐ?y_I*'ѝ#J*2Hd[' Z5,kU}-bguNꯩ#_¦ g@GZ0}Ĺ{@pg$#i1#:7w,3b[$,9PEՁLT ia%xeU(KAј$ݲM@8~^lߋ@ro= _|+qS!٤9Lbҩm!QL[{d6 hip|%}lA+l̖_w:6xg; 3$׭av]M1T+,-N,wwtiH(ȋcD#_`V8!" .2"5S]@G5j[XiN$ƒɽc㻆fh$uDZzPs`x`NvLkrү(D|1\TIU"9:m{}۸9&4x :{/<#s+s3^SpkU:Y[n, (y{hpq&( hot5b(!9MA2%,e?lE?אw0i w$ˈЃQ1*VWwvZP G[|CIv KO2h<ӛ?ƸGVy=I«߳& a\eb*(DNK|q%Ё|W1oY\iʾc}>7(<;bJUi l~-#ҍZx`3WB`y*Z%5Q#s%؄7_H<)Y8L-gjFoG]5chK$fONBbm=Bq%%;֋x4z/׌#uˁV))*x,fڶ*$c+M2iV匎=*򾦯JoHs=h!|*D߀@ {@saԼ.M |J :5֘A?j(rޭ&- :N"_媔[K=iS+H UesPQ5F]Jx!pѦ@ӃsCoyRt>(K? 8FfozGݦh.p{qfFj}eH ?kXhC٣tŲ76Q^.'GA<>U̮' ᠐E!¯}r>濳e^T㢝5j~F@ԥAa~X.bղ`*h$'y]-^Ӆ9F\Asgz4!US5`7DڹU4U‰ ?ŒRh`m:)&W":csϺ/9t9`!Y g]IC Œؔ:]1K1So΁D[ggt,K[\WFSJ7s鮧4Bvm"rQY߯_ΘȜV:G`HLZځ85{Ao;Mx͖M9Wk/I>C_RsRc%}#XXd>oa$-8ޮnώ̀s%" {wa^`ENe |Wk'^NlOh{}KY݂f^gPʌssb|0w1'ƻ*Ue{\.8$.0!tK./SH~Nbw3l*6Q׃fx7 Ќk:$꒹ ƁҘeB<^p&%uuc rcء3Bvd+::[5K ;s,'%W!1X~RKORy%("6pX}: Ĝm5QXF"}Zh cq&9Ǣ]9Cڰ(1>p=G9 +x(*=CotemGoakp0 +^eJC1TѓeVÒQx7\88xe4/<;رrIKN̗*0YD !}gm2Rq CMr+O΍p 6sNݵMΖ̽5xjrUcg2mx@A.EWwIn^*:X`g$2jvQR<*\<(8̤֛ۑ,U2,v9`O}Ә%,w޳}!?/*|yoaed9H2OT#eN4T7gQ-eYa/iI~ \.`*tHY08uS[˫ۧ%!bIK8ΛeVtG!g\n%cPv/@V{:j]ܟli~եBDf9셅=@lT72+ױ gZ8 9LiIߘk QE/H흓@:cWeв'/e):Oj &hzw댏Qk<Ő#Fس`K.t[ .L,G6n'1/XiP/5`V|X-B#Q% ?BKr?C%rl p)?nPedJ혖.9ھ2hasC!ګE&P4__Tůffi ! &ޛ󸜜jH -I7{52&Zn~ڹcGGƬ [D@ ZIԘ严52%)U9+EMޯxe}`h4t }B#ϣUHDv:r%+*+{-϶T >U|;y|%+Dz<%x zh%L;\esϼW:~dY /dE!9q'6!pƧRJԤk:n[#ǵv?l?TGQ Ŵ[6,VX[0, 9v]7H>y5sד:2)&+qZn* ,oK褱N+S֦+@TIM Xg ųzAt(#EKĂN5BpS46a;o!TS:+c\lO|@(#"8_]Nm]DFe%ܧ-#)V9*QId9197>J;OOmV=6'zV[x" ,]?Kv>]49J;`)l27ƋR(PnoS+tZIP=ےu6Xte $z 󃸩 *x0ry_MO[Q4If$]IU ST3&d-Zh^ȼCu{*<7c+B!WXS`BX+irsCVo77@ wr럑~Pl:ﯸB0^!w$ eqC] tFdoM3yo%3Ƹ3-׈\6fNȌ4n-jvϛu$u)6q#x|fǠQ ?GbGlݘ gRMć9+g~>e6 LްzLPĚm{{iSP2/tu3$ x$Ea*L,bITCMlPZ㚗xTw2ڬх ,@o]Rк2@8F 9U.+滓 rݖl~YO_p\&oXǜ} e>=M%V]tnG/TWLg 3i^u:ޭ*ߟnvikjhL'1.i%hbgF~b}DTr&瘳٩RJd1&³cKECآH!!蓣ɰ]N{D&^nBV6 h[`ygw]% XK]9n`D/-O'It3եFFC&!zO@iShk@7_oH0)ߔ_)]m${j>{~!8@s0p#m u=Ō⢤Ѱq;u'O l2\e 2q›1kQmg0o9KImr(R(Y E*7q1'=Nͦf#<wSb#표Ym{Nި"A W#+^YNW] [k!xOMr¾L(zw-F! c "I l^p6-#wu k܍mОҦ4(mr(?sSkuRrG ?r+'MBVR:c?$gl&y+-lf *?GT=xI-h@C>c YI/,z@.kTT2 pBv|˜OK;IjWNE_`tcNI6a, x. WirSG =W:?,-?SROnlCNåXTmdckciDTe/% I1Ĺp&&-V~1yPr} skdQ؞9jjќ^N)vNfRອ^3Ӹ}Ӊv*l<2$uWzPQP_k';U~P>WgyE]_N!"-u=ӔJAm/E.'gBWooE8r׉`Moc|~?%9y6"58IgTa RӑHؑ4"K' ^"0j鎃-?PL ;ms T'lv-Z@$VG!,T4oW{|OxhX).}dOԤPvI4!4ir<\fqk5f"W֬7ic- /[ &!ن)k,bO3; S}V21ZWh 49A3شdfz6<(Yj l}6:.bhWeiKu K' yk࿰.vHGM(m[fE`NU`Yzh:˗oS5> ,Wo7:Yn߅ $@Qn O1@Y;S gZ2 69(FTҭZYͪAzܸiGkNJ;YК̄]&GoSP}>sl~ZbRoad>̥)COsM>-%8Ǽ?o.Ly6_"Q/pVhR)9{ؠ"}~'z5dRM@f%j;FB֨eT -ynbd'LC^evS$DO V mI}4-nFTXbb0GVH,Dھ= F fvcm >|eT虲Hu/$y4f޵ %Oxud .NNw"2p(z#l8hv 98+)9*VxnO>h0/8 sU׃o?5xYXePUɋ5ܧf YV罇Gq-Tk/uSO " T1ϬN7U*7~ \~ Mxbӎv$Tl"jiL"ŗSO-kev{M Y"X#^XY=H.A,+UAYCY(#={^(Bu rHN5Uom sxrCm[2Wpۑxq}HDW$8Jÿᬑ739NLH(L)+ `n(z!^z!ldk83?)0ɏ I\L֓#|l, X7LʢB 5OU8;څAbSv5Ʋo'3ϻט&|}' I{@sŮ+UsxAs X&3*[vdsD473PYXį͸Ab2=u0 PJXPjti1{ o3]{%3nNUabz4u#Ʋ:XO#TIyZfyYφ^6qi$֡n <3Frx楟hW*(1THNtNy{}g_gndlI!rOx9;`:kN0|J`yɃa~:2Pӽ9pQs)jE$ݾa J3|LS[X_DdY [%Rj%1qR{唗pT<$eE7q;2)xnS?,ତ Ffއ3*q;:]PZlkkz̑,8g1x/!_0Nn{~>p NgsxTJvM;ۼ"#>J!#ر)u=dCvbԸXj P%6FW2ۚWg%{v؊ Z^2}!(+8.$sĕGSE:r5MVt& b:LeleOB(i{ VK6A`+]o.yK@򀔝8LDx+0^>V%I41` v߬dJ/s6ؾO\Q9[]PΙ]AeeWm$GQ/=n3ugaq$ K3ʳm$~?+HPc'm1R ^SB^ ض;,ɆЈrZo|Pȃ{vƁF 8'G"nt2w9ԪHK'a&ɩx `Vp+Q4k~z;mb;*Hg1+2 =+Sn#Tj\xjr^Ikz 5A3x@̋aB AA>47t$[?`Gw,{\/ {pʃEEM"W*2bkU策%,[oٚ5x`KYV%C}ƙ_Z:`F%1Q W .nHqrg};f.^đ_L2ĵ=nX{W/J}sLwM^€+@~ I-dk` 1ˀi[#s;'?tMU)9iQ9w8]('x?tM6m_]ܒ i'Yz9Nnٟ_^4&7w7e\ϻIWmi n HBSJov:EI Na r "M565Lj.qw;=21Woe>n$UE'y>EKO<[?%_bmԾ`y5Gr JLE%4Lu62Y&~+[:,>^ <0G.#AMpiTnXJL}X3B60ΞQ5ΐHvs^Z҆CE3A_^yn.d1UHNТ;?x!b%܁ߦi]>r\vL2'/"Z%@zDG]'7tA:(qK @ W|kbۭ]NdC(`}_TR ɟm fا.`t$rغEY V?3𿓛H o!^̲RFFdW+5H_0˘b(p͂l}vŢ^v~sbI Rͭ̿AұjT=s|LurkTȚiE%j/fp9i pPP6G7w?ן-]䳂H~5@0eDqZB}ˮ'G/LL;^,lQעzTSL9'Yb7y#> 8qUL5,ςrӂ_^xN1E QXᝃOAMj•B95 u룭GM{tߦE'@p{v`U|+ dN-ԶD.-dD8! ;ň"Ƭ2BR`-D=ܹ%8Ԅ vꐖ^˱Q;Ɨ4iH! @~ƻGHRtIՑM_UAZ;ՔB Ż{iy.OU:{6^E3>4`SXD?;?_ 1cCB\C A'ͣOgQxg6 :ZxJgr);FuRPmTѳ꥛Sd[*%L~b@suKd=7HtC߲NO>0ei1$(J7Gׅ(h, C"2C&1UxĶvUe.1%ZˁvHgp1\EoYp,ZOYILyǠςmUb>"^ĕc hD~"ʣٰT|+A@t_=Dž'lV9(\:mp , DgrvdO3^%A)SӀ[~ s|b0$E-q# ғX]5÷A1ryIbf4ȟ㴱R4r?CokA5LhV-f℘(l)$@_>*zn3(VbcЈhf |u+1 rku4+ Bh3^P%s%SSjnfS2 9 b$Hx@/dÞt$.d A_;#>A}!/o8g@=Ȧ%eīq7} w]o׷ 5IlQhK6m59]::4h*ѝpC+ pyd9y.4{8Miw"8TA[S( lɟ%j5WŃKa>7Q_6w>X_<8VМ}g$&(4`Ⱦ3C}#ti5)g3Ȧ`zvmƜĪ?X8'죖dz#)SNđ"bvGs~> o}@{%"·XLif>u()v qNBU6=[cDۚ6v !3[5H}% cyb |P{z|zJW0/0oA,PDYt˒'eyTWt'.=+XN~[)6e;[ەtv p t7BPVZ )H}:3Pbɐ.&,;znapBy:6Z{i}K7wpeZC ќcr.M{\ txƹ3 :q8Lvw~l/ވ,B1T䌡$|'rSIוaʰGhWT}l064\?;ঊyғ8U~Alcsr3s;ݔь95^Г.Gp~r@&O+RV%Az&7 ' p՘vsZϸ7qRf@0 {.뫨KScHlYx8@GMySIl1wrGDOI(Fg cgafs:Zcfv"uc$ C=<&ㄟ [ SqN4/RGTnNgbuTj0k}8emck|jèְzhBS36=. [0xPo"")E,qְ w୐j;CfFv%0Vw?8:.T'?agsDH)qlH,]{A ܣg+[f zH4?YTX gl w=h?XXT仰&ERɃ S%Y҇-D˘ٙUiQK耷xLȮeT}d 27[:`ɑGqЀA0ӧs$>p@ohS&I0sx21 c&2nwJCO?$ZLɼ7a>!NC.|Te`UL\cQeTK${жRt9M#>y\"ZMؙ> b.Y 18|S2Ow09Dw@PhrRb'^MXNq43pܐ!.v׼B|[P^KR B::L݇ug6]PJD#KK'֋dxhpېr(e͏ ]6K &$Br/!gh_X/x♪znh -Tǐb\d4xn%3`_u'Xs)K~](>mjdҰV)XsXo /ÉHe Bm9Lض:i2"`sNͧnokRkXKWDPh j;<1ׇHsE~^mD1БZPH|[G&s*DVLI+M,;Y-D\jU.zީ&0$Q2"sQV^˻s[9MMnT?$:x`l࿯9ˈ99#Zel*jiY3p$tcZ=cJY)$/[tO77V®% Uf{nW(gϪb/`SfSK6ņ}qc ox>*RCLj*5QWP^4ONb\u'meD|vԬS?Oj dTTֱ@:N/4,7p)\2BK!zf gW.#a(z?N[wrǼ f3ghSǿ% gj`aoe'|:7'X49*|tTV0LAI2`y?,\M|GiWb"rVk 9l Q!4IvԒT^Qj ScN<imOx(np&,HhWdok5ITql8)kl RkP!=`C*M -}dm(e|=ϣP6JW!1"x =A]B%.5} YźߤU`4= jW]Ըh$_ښ$Q'm+i< ƞL:O=8 xp.Q +UD5`D؇ DRJtiK zrɉ;.rҡ}{R'.TI*؋4p`x+0i-e%ٵٹSwf߯xZR) ȷڱGoTei9 vB l?L%ɇ%0+(ͿcIkk N8`>9U=Cq)u[^MS<ۤ_6v4; ѾV}MB1PEȴF>ŇxW5IȒ%I@*OAhmhzz^ SCT[ .aV[`M~-`KE \+8sĊS=ԋ1hIXlYy[K8pArV*cOLo#[K3 qLƸB28JPn?).qXlt$|_k`reØS!xѾvr<y9rX[ k_N8K=3Hh:m[ky~&: |_`O}I0PZ=`l*dF @#v6 [+  Xޠ^\0|fީL0Χ"XxNj\cdi/\.%d6` ez%uR+T =1+vڗ9Aac8v^EwD*q 5JQ}nj5z"~(`9>gZNIĵSGj`h(ajL']@Uo&cȃnBF鉏<^=QN$T~JG;g0n"U]PnGB';UvD5si hW0wÖ{a Ã28vIW046 ;)Ҋ~-ȃtohpHӦg'R(ڰ?KduzmX[lЮ<脘raΥO TިЪp 𢉨7<FbaC3`#ʳqլ՛rHVFv[Q6"ssg!VT|=h)%p\, )#\'׫vۧc4Dg~e}|\1wo No`l(U~NjRe89L:?yY 7m;K 8;D'K 7ǑUFٽd 1J} X*^}:s߫ r AMTYZs%JF|,ss24ca$!Rɼ>SW¿(ɺ $B  7S|;7Khe.4VKBY3]iJ 7%0P-F1 `!ZIU"l3s/#K @հٞVHۏxjV,n۳4+P6LӞ?سAIP>N@^[hG2:6J^")I ]| ggY+F6QAI1[%7Kxp;0q'i1 KDJt\, OH!Cs zs/S0hbvCo+ZD[}9'hH-DO&CX 9d7h sfu %ɺX$ p_r2RO9Kk >ST7$nGL 6Twn*LSx~X;,&}V G'iaG:DUee0F[z荚!>܋ukjf:Kq7@A{yT q\ŏ7X{/CQo¢_05 dX:Afs3;6Σv B1UIE@DV~* %'63qMwu87PFםwNu./Š)z6cr 591m7V^#59O&v֬E `|*I+ẑ|:q #H=Al%y )iƒKNkInc9F`ֱ´/#y2M<;%:I~9?#j$2(Ye>)HiVԤXuvzOaї_Sa]&C?[RKxz,iufF12b*7PA$% m^` DjR$X4ЩEE#H.RgSW !>s"s3իET0͝稭=&3H:fɕD]/.T<YJ)|{ tə HY-Dl[qe3n6Sjs4: E('>nVAEj s$\/KH5&tn+li&v ǡ)k銒} ݫ ="顸o >AGf$yx9PKdoKX UK{T2s1jЩڎ;_wWL#%:QfesѩQsnByq&v@#Q_06$n8dHl\zS9wCFJЫt5s,$KMʖ{“s\+HR6Hj6({ݽ@Y:N*Kijj30WE(jBt{i,IEv~ښB]1 7(K:ս2Q\b(T?k@k 2up.~xoPnp~ۘiKqMiZvX)N %zEywf.]ϼ4bxSiܤ+::X͗a~ݩ-m/p ;u,}d!kwIlbM|mM?>Zp3 &(f^(K>47-T 63##)3tA܅ֵpʯ8F%5>%n RD(M-[M{~l' K{ߦPMEO>cJ$k,xG㽦=}Je'z)}=qSIPFɩ01낍{Vd5;o$?0Ҭ\]xs߅-=rwe|?*GZF)…qlDJ!@пKuZB2F8=RױPP-okCVmCT%3QFk4̰ R^X!a2 cv\ @p<އ:cXIZVMNZ()RHY|\ݨ)"'NH~/,;+ۣjE"z?42V2׋͔jbq%}8RޝXQـV-n1. z$|\:lq`O>GL/sb,V*ׁL;8;ȻlUE^V0PL ^U(k{Z,>k`Å/5W>(]'0 kkt E{Ј֭[K/[dj7`or7}7l=k)b]ڐ #8 .LCDv?:Ȕ rex]0 %_HcAAMIa7CpX*q\ Kr<uJ#sH5ޣyFF^J5l^lc,S^PQ\Y z8!|ϩ\%gȡonA*RX>KŠkdj4ND;BmXAW~0^˞Aܿ8le*NީeYsn8W1pjhgKs1G;H//$la?U+)l7-AĺM7E7Z;{Hz=ȥJ~])*sNOڦQɧeL769+JI8MڱMxhp8L1f?'QGCTVWmrF}o="5kL^LjU zKMp]<9؛eQ;K㦧#1*m79_#3rM)Msù&1grY竰@vGK(97V R _aQO7޿ |_ԺǤG"5=-$+/(6o9::cQ\5;A+($o:`+Ty^3^k`X;9mm!=1}UDkr=4V2MEVa뺩a ;@U$t'!veT U3 nr'(c+Eoe9Fu!R41gim7_Ro}$q2;V◢,t18>VNh[WQۆp&Vn)Gu HYC'SyضP!xMGk2BzZ*{M`8+Ral1İ2ӰLφK}4"ʪ2V d⑒mm h`uvP@)d`9WOQ~g~90hBp.[c-klG :^.:I6VoL?r} HI'mE%xoIn ɖپH2Kc]ܳ[^afgkҠijF6ll>8k"50̖I8A`Zۢ1_މG".ω 6@ w: DUtN["! {vT8[&s!Fܷ|=GtLɨyGMƟZkvhvDZdH5*kP&):v;{ֲc@݀0[4{zU%wg%=ȊO«Qj |GYI Ya f >x-<"""9xߘ7tqMz̠#!խkAO֋Ilԏ{ &t_N' A{왭boc̪y̲?;Ň>͖{|W5WOۛL V}z-=3oE_db9 [M(K9,}ꠗad9+E@^_zYVv1' 2\oTi Pn(:Ξ&x*X$)=¬cG܊hƼ1V겧~\1ܕŅ=ۓOب*VZ+ $=gqkCn bT(pVvwP+C)"Ntg-܈ OY6?l]H\Ѱ1 =78DUu\lEF@:6U<QSѬ=v uRdCfDF X浿|?e899rOٛsbzd},4!I-GVߞۣ$*RlL\8b[–kN :g83uR5#EPn 0r MѥǠBG\܆i /g;J'ME$fӷ\įi;NI<"%HVB܋))ۃ?He,c^?BzCx&C|9Ԇ 0/U}9& .m1:zpk#lvi K1-4v[QZz5ׇL 'kTD-!f?/(Q(fXݴ+8i̜]V=Sp{MтF:+4FQϡ;&ë9EԠSA+{Ǝ&bS;=8 x[  >h././UdK$VtbQZTz]`tЧER±($cKD9i .1W2s^&T/SB2+-p%55RRw?t"ąT!Ot|ca[#1p{ʻjJ_m%_ kT&;)XIs*6VA+#f\Xfe-!aB1@v GX o>nԧhcվWcۯih) (-k5yc ´Y; 3{+jX);>SƐ#.u]rmgA]c*BMV\ @"jw1>5SxH6*E3.Ļcoo8Hj2h|fP,aLȀ{by̓t)4E ;wAAܝc( 7 j+QXʒ&I8MqBc,Ǹ5p #ۼ8ptfPq ,80o `IΥ7`l]F+k϶ -,f>2P׮]Rlo "# (SXCG ] #uNnxZw~#WY8ڒ-? ~eŝ?'5wMp7^h~ 2[-]0sFvSh[oN5.-kHmxPEɏѲУ>v[b5 J}w(Ufze" m}FwqۅǍpb 5pi/3), ,K`NJtđ[[I ƽC؂-d*.FIr>(VjtJ,Y\vk=?zue{N̳@#66sD3'Vc|_20N6A>Mс#Fpž:PQۣ,BSۗDJiHm'-pJ70blT*/}dz$W bjAurwvR2 WX6ڜa+zɣ`q2G/PK._g;> 0R9BY(;%̟P+yh%jmy˥vWcf֝"=z^.%"xp<6ҰXP[4EdCK c[$`N׭}Z"Ծ]2ُ2;cAMr;%`N_i K/M?,J?^sW:`NBtcts5ddehn!ҝX 3xGoSyOygM痣oaDMq1 dzqG^T=Jמ*gK{b1Ȩ&;KI-7DB/pU)ͭT0,N ։/Z~ْL"kj~0#'[LH:Rk/O2I&1):r%=-Es:{LU9MTOh5IZdg5r0,WWq"sm& sf^gfW&bKr-_2j #%8̳w^] HU摡6ϨH}a\G*cV ق.H:ik."*cQ](kf\䙒:#3IܰMq!A?VPݢER߹L0mDpҩRM~)ҩ ucQ\|L(M|G|#\oj,A e2  @>Gtc3r1g?EʬD'*&}%5XI.1)Ю˯~͖2 >1z.q7l5#L{-(rֳۓ?*xcB9i/_eدr/}Y{Z4 8yyM`uCI7̘t.I>k߭n5p70#,3k;d).KoZpe VſOhXGP3&#c8*o7uv5>&&cbbܣr¶7 JPG?|xZ4F|Cԝ9=FACrŜm)M8(duu*:},@C@KPJBpD{U& efu .~Ȇ)8EZLɳ/4M71lVI_9O,N+q~dcOGWUl $A|/320w_p;7YxlG46q1 0[:x[|g8Mpz,1mL&n(#s^o dkc{ej0o5/h4͘ JREMZ r[GeȕSӰMy.HSk3nŠP ߝ|ҿX:i5?|@>~|lZcBdaPL|gZݤu;Er֎UJ, m4 N+'28!W!tHտB̲,℩:JFH~n#X}n\vg&N]\'pr9*E-8g(Mg ]6s߳g;@k8y:\,K0x#Urteb$\-,6Z T#dYC}ov Uu,Z6ßjףBmZa|xҧ"`')!P7=҇û}3ω1!/Zn1dmmGyD1ӤJ1_7w!Mnʶ<=WaڑSd#;}[r@)pD3,,c,AT BړWgO!s Jsެwtx<:%W~1ڢ5R^iƚ^FЮ!7MC=!H[TAv. U.(6 2OzXSG~TE:nR\iھ;O;%6_y {$W4S^qcq#%C(^ ._*AϑlbE"u(WlbWg[2xfyC"ZݨF 6rWֵrxinK&i~Y,4tP-Zq *5PYGCB$P.Ɖot5'=LG+ -wʸ^ Xuv(ዀٻ.pv)"O*u͗`1q_knA6!.#(Jސ`26n"~}, n ʵ"Q0oc=Z+FkSeLcAf%@B:,5GC{q"4sdx߽ 6՟I|1"0%j(xMhk5f{⭇Mz3esYkD"\'˧4n0Q߄"aEbV)@h^QR9kMBd)s5}ֱYՆAkcaXlLa=?jȡx7_z$O|ȂzۂB9xܭYp-XG竑gV'/\m`  0Klc={:E &{ec.[ )("A^\MW*xd4z1))gb$#&uk;bQCts /B%6.+YJ:^T]Zn=5( yװUP9r!cպ'ƺ:QW(yj^CwMm49N<)M%뼍 BlR/uaǿ.Ӈ1@*CͰұ+L%ᕜ >%85MY:wb4f阑&P9>Gu";gl˦[i<7/b['$5#< ƿI!n3KJItmyYS;24ip:Eu | YhA7%հ4LⱣE0idzF,n`~=ʠ~T|m H+՝aBy=p,xid\smՁy7hP;H3d"`knyq{)vĖ,D{cZprBo9W.W/ cN @::@$'5"D.72F,4D3""O n2z)l">O/7#wCcgaD) &ɤYDO E)QK+'%tjcgqr \A^: Ł IZ$qz^Pc ` |?dI$c!`be}`tg3TϿ4MYĆƢhEF+l9,i0BBNi>P ߁ L{+폢X7|.˒=Mi'((%[UnAt4`2ξ2n& g->W@TXwU-hTC >uYwea'mF.E@QڙI'Zchs`jڻP#'؝bt`MVUߣ=d 0F]fr(,W]\yBH:xauβr]+|"I^0N4'uѐ>WH#^aIc* *s~:7:Gv32eb7jqVs+f7=bpz>1_Ҥ}?~)r|^^'mK?X$4@nPn!~◛Ig:-+uBh+-l3#T=Yoy>Zw9k }?C+e>~(+P4^` 6?`*5^p/;${S`|&>e2XWLMgmr| A0T׹fr&P"PK^DG{M{?Uq@N[W^#:g{Z\ x E vx̨Z&im1g@w Ɔ%̘hHL0\ ~7|h}M70䭗[8yl왩 H]>.Y xQơJq!uE !gg脡(Mw~O@srB\+ 3B8zN[S؊7 ~5b9?˕ YɷpAG4l,<%H̊zG`:*2͌h,3=a.vyA-2-B1l^qmh.d묄c)cd AyE*Kn E4v[[BP_|':;r9?_@2Qnp&˷>Hb9Fa P' YSTz?}Fyzȸ$ݧ%a &TD2ջ߆ۙT,*{$uP)ݾȻ7[91 X{+I/ :"1yt b/xPxo{y?~Bڇ6ެ'itimtIY F’ۗj{=Pv37 dJȗho+U:kC{"~2-e"=މ2jS3Zu#piQsQ~tZ-=v4Լ=bFYr/iPAzCQ ,Z(~A.V9">|]VݫC_*/ucsD I$zz3|UojҚO21/ċ*c'`R *c*5/ZH+5[.Vc'}S  )nwG%b64qpE7XFIIچdTc% 56 Y:O4 "ֱi-u#H쵃jYΜM)@[uQGr@kFhWw qD) ROڝ O. $MW]q A.!OTV$nAFxaß&:`6P\,caJk/h|,o|ZxΈŐ^p~پ{b׻DBծIwNGW` B{O'ÈRͅ0kHmqTNO`{&3F4Yz.chwfɏ;`ξ玭T OjۮGկ;VcBkDN9S &eP/pdv&kv0UA>4Zr3J!(:Xp~YzGٷ k6FT: TܨE./) آwJƹnc2^Wu1 ]VH~0ĚD`-9οzj92 #e;ד]x ~E'ǀ!m/R;(@Y.۰QP#k*z b4 }=>XVӗqO[!Ue7AXO@Df?hZʻվS  y -피(^Enhhյ|6ݶ J 7|w fnd a*lXI+T{( ɇhex=d&İ& x !<lXnQFHTPȏSQpYT06ۉ_: ڼkQÿfUt~&cZUDr*gWq{nL0,} 37a-6挸}$a%V杷dsÓ6̌/ZתIgmܕf XwGJk_ZF4.Yo[Kl'tzhp"*-HÂſDlcуO}=|V1&T߮tӝ)YA_ـWÉIU!Y:VHѹCd7,vuˍ {(KnpE%QkZu;yX61[)38A+?y!5Wr3o"E/;_ڢ!/?1Kz:YX48R2>\s#Ec1|_IYx(tC%Y)ɬ$#x$[N66]ni4|l}f)Va2?7I!M^_#g#yx,ʨNc*h;F|U{ۄiF2{=]޴*g ")c!+LqpL_<~8t3c`YIHTڧ }慨yOm3qlV`.2dgB@6_[ݮN0c|<>HNgY_"avVq4/rĦ@ 28Z0e,νe~z]>Lj0@>_ :@Խ{o_YCi|~5<VȤ=K)fYDs7H`iS&{6 Y ,]Bc8&ޟv$`msS5]bAOuD1t͒iAmvٽxoMl0=i|:c\䫝P!_ 0Pmo yy:_f^ :6jK(Ƽ^g-K;5C#D9}ߎ JI6GwZXL~pIUCq6bzi,BH2a=vxjmyu 4q$^;eL*YmH;4{zD+`b0"yA'}*ҊS[0j濻@XAIc!F͜x9B%އN]Dw΢9t+|U--'yr,*F&-NmSNЎ5R) %Yolt 9G':Svpdq^,YnD.P?]'E9 RlY.yZؑnq{ddjU=NZj@iH;'(LM4CM^Nd:j?"`׊!hbãz_ST ·Qn&!V†F]t.5 ING]^G>| '7 ,QF Iܢ9ܮ}ܴ&sSN$RĐ<}e|wՌ5/O_Q[+0/})jB#2g?t'ƌn=M% X\AC70Maw>nՇOnZAť|nKNoIb9J'ZwWG݆߭XWc 6=Mn V!_\-Km:$ToJ!=*mk]BOsgfeUOϳT J_rb;8 o4xI9Rc`WɦŁF} 2x\W‰HRP!(:9/*>Q투$*Al%J@W0d7 4F, &n9 Yst 8q^\L5 -8lGA0w!9L2Ibw{W5s%c:(o*E5 FZ2ȍr2x옅􋧴85Ơ|0iVk,$|GuZQaoU-`ۣNU QTƊ!;B('Z/hĢXa<QPpsKq:ӯMxZ `( 6 j +-"u",u;{Sא֛AJf46r1M,!{\AE>lFo!wnI ^*x"F)@x6QVtBP,kDCձ0,܆Lj!q9G)l@MkİъG {:LgjN >{+ ywwB͕2qPCj9qFpoQƟ ;][1Ħヲ>(nUкGx|BNl4}Ǹ1 # _R6it6lǴirz26T pp8-D4r.խz~,rzv6@F~* pj/Ps Ŵ~2#W!%+Qӏf6ʹp=C˹cϘWսنQ: R{ڰ01gi8A$Iuݽj**#p# vψo\ӵ=Btmr& YoT>l- Gn9܄! k`k*UeC,ړ5vrWh ոSK+^p1M0k&85 ̊ި ˤ^tq $Yn88 ·bNy0krse-z*A[Wq"nR\zY"s4L/mk{ٌQ,'1M8xѫaΊŲNzYbA Lo:WP2 /Uʄ0HذX+j#Ze"UEM6<\+)4\BQ?!]&T6'L“[h<‹8-YpOg0/Zm7$Qى->Z/, N` ,@EKq8pivnжڀ M 4Vk ڹDl]mw͖LKnPր/ƚׁاR.B}abcG՛V"NB' Y}~w&bp_fKjKŠbm)Bve&n~2QfWQae{ĀV#{kn6"B wA6Z$;Rúf-h_@捹T$%Zu;! e0^L)a2"/=v*hC9Xc"?sP#nJ7Xݪ6v1/.!uU'fVX6VZhS4û7 y;%PMK\ ѡs3f]IM!}҃ުʴz)ظoO-!uRцk\]zf=hnE *U~tlȊTKsTjB0SQR Y'K^Kۦ&q\zdqbaor' AhQ}8HM; +@U?~@aD<%ģ/q-HJ8ž G k=Bj#;_ARb1*0r%Xbwt;_p$@RLN^ͼ:Pper#M1xҕjv#8L%糸E- 58fM &1$$+mЯEfKdKL3nk˜?@!KvKfco3VH 꽈~twoЃP)L<~]BFLDM/hM ?*>qY.hOؖ[kB'$,zowǰxQ`!'y/c"Ma2,✙o1C;1yz`C 9χ1̸LtmkL}fZ6!Yk?&6iJ^`Țz+0xb7/Jр-UΥH;<:2W]1PpRzF*קRE- !9Cqjrr`×mqmd3SMdMU,Qij.Q=r@/mlks>iKd. /YQ{"W0nMщ;L!,,Sm{COeM0!:AukջH,Rᤥp vR!{,o| 1F N Oq6r(1bM F{gx8Z֕.ҧ7@ՄxC*)9i@)G%̊|Ba8/'ɮ:&@T,PXbE }mX%tX^oRz0\N/"JLuVY ~j FjI7h\Bd!E(}kgΑqnnGCYtH$Q7``3Y<&`d[:'|fʐQ:OU镳{z;8}{pʢ)mmuv+_Uu7cD|!aލK 5}9ϻ\Ph~[_@N*>H reʹ܂:p2JJPm_!C =˱+C\%Mԏn7'I*Ē {o;KI@!޷L~5/, j3e&ZQQ7dyǢT-Kry5l DavwF{^ʪyA!͸sl.G}\ؚx#k3r9>6tn|;S,Ci=勅^INԙ= [묷!x;82m5:qm/rkS żRH~:k䎓[)z mÛ(l7.atwfk%.׷2 & `'{z Qd58$X| ,qb^=kf~'숑M+z{N{ta뾗b 4)և-(_ XG|?7Ev8+zɸ{ QUTK!%{$9 bP/9.$ rlY‐`eTFh|ߥ q W\eRK]Ʀc6 6t"!KUX#pj8c trVB6AT Ө=L0G&->\3`\v^NrW1"eb9nrAs@)9׶\sU&iALqΦix 4_4B¬ 'E"0um,F9R%*Ți91^1R/u^٥wU7khNgw3jL4%ӵxt^#WCj7`W] lЦvw?dMg#n v/; /..PsaOYtr6D-~0mD& 7cp~ ^~ F{rSýX@}" Ȯvxv@娪ucf0 bZeAW3}zHѐA6Xp2* )f] 6eJ>XEBtPBv]G p,_z:L"M/+ TT pA<$=TW %/\ WdD@eUȯ+INg+xnuXy$MIG|/DXv(c 0x"4hVSMǚs@vYܮ$5PT<Ge}#->%RXAB*sՕ_|=nÎ~|vMc~UTئľJ”Qc4CYtT9߁Ν[3$ݎX2qbsI)*,jp)VN;|b\lOt"| %Fb-1+/hlng[ * bsKa4g8Ҷ3jD76D"wx|]-vSHFvb6qjĐ%O{gg;ww>ÿ?yhw7gGۏww>wlʲhj9>QWG^tN&{ b6m$o5w6\1yҴ/Df6􆮝!a6/n~bDiM9>o1QySr3tPl]G. VrFm.5"hwjWe92"+\cZxaI -HF6O4F$ɰG mYl1qp5@NF&<`GW1X%&dae&%Y% lhp 1DW, YYbUgzS2+ mX^1w A,g|?"rc3a0d *-YUBO@q(]{BKr`7T &Ծ1-MXx 7B[fuIq=2s~`EIdarQFN B'{0c,jIbRq iQQ&U\#NCI";u.o[vXW aJSQ/ 1*U-v\IP^WsA^A|2 L.z=P*CG]iiZW/za>H^0ʤsb `!B-V]O|(x}z;\>=onNקm?B`Qۃ֯qY~ o91LE vjwNl08"57d\q:,Ot<<_G0NQ .TrxqF~4N/sNQd[4AR|^e.-ug(Rz 93|ÇK[=+4J;dV,L#fhDA}. 2}Mt>- nH&WQEr@jgl)fpNkjecQF(#&6r;R>Ь֛e +U莉Fe1[X^ Ӓ aPe)^2HK6@f?Ћ-T^ޅDJs"EoN50ǫnc s,F%,!#nr#[}[gwD ;g 嫯lX&e}Z 7܍ B槷|$Z#$7[ƶg6 5 «dtkOY\''a#ן5057z/QY\#B&MvNVdD*d~%lck#/D x#,ƫZ/lo,G ِoYF8dt3T0Cauj(˪bo[9JcS ދvF1t8:BlfXNbhfò0ŨҼ37[<)xlIpVt:H(O.GG{0ICz~ԇCAlnnjutldzk8|pwb3>4}Q0707010000000d000081a400000000000000000000000166bbc3c4000051c9000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz{sǕ'?>Ez $EI{uB"-1" C(t5ᮆ$nH РWoYYoĺ Wh|瑙' $ m& #+'wKQgwXim8Ǘ; XFo[SwNo[xx]?R/lEd1Ztұx~Fx>୤<|F~KdZ#IFx)]huSZYSܩf qG`gGΌyYN\j7D?u{O{;j)kzE-@UkROU50L^7yڅ|.ގ^M)zc'94^g?8Ϣ\Dik1ZN<[o;ע<7wOG><%y՞97+PIO7]],t#ܜ:ѿ=3Ώ>{ ;֓h9xj>:UK_+=p*iYWz&ˍN4j/ƝN9xD זfܩ {vs* 5x!$ZQ#Dq{ތZƵSq-j63~rS.OESS&.D?;L[}y / 0oޗ߭ki,EhQtbsט{~N]Wz_+xC_%P1^: \WppO3PÛjRkv.W" 5^; Ls ~[U}J0(^;j Ӄh)u[u{~?z_n>SoVCy=SVswGK}QѩD3 6z~Im]xX(V͘65F~krrEmx^#:POӺOS=[ KRY(;`e4[5mT64D,-8=D ^|kBģ3V_E_G/9V9 q#-5 'lFX3xJ,hW##65h䑋\C %*lWV{!N oRtUTAVs i<$v;ר(̀Ϡn*X]Pب ˵;CWiͥZªMRv@EMA $qZ+V/z;_sp3~P4G jj@XRJ}Ӊj9&)+]-x d_%1z*M4WL^ee&lg[0tiT}.jFuzd>6p97LvFbToGGi2N՝.հvğp!8wQM֜Cѯ5NkRۉO8mf7b|]JN:Y`pVN 6{6'T^Fcj iԹ emd7OeOoKv-jOtJ,Ikp!wSm;‘Λ;)GW䩚۷BW_MHF[>6Z?oyzGޮ U&xHYYcCTsKۓod j\]HfҍtRdϋK{^@S=y@J~ 53 T%ub [8o]0YF !,Ώ_erYz}x#T ft<btfAm 9@˴ V=('ߥ?iN#X?9>FG%ϻxv4a#]F_ rRqߤ8=3^)>t [^YϫTP>-}ahnz#σ;Q{00r;s{,vbNxnBMgut3b |S;𝦐6UYur]E vg1*0u9W&XM&YAZCV !\2?\~kS il;g}GGccŗpE^gB9o *XEF 1'[vqA>9\}\Pm;;v}vj 5$jJqIOnjг!xN{8+?v5*}ӞsuJ+i2G9Asۨe >m~=JF{|/.!QQ#E_V{ec`g  5AjyuKby8Mp7ܥllq + `[$R2h҃q1΋jtImPx'շ(Ur**AVR}? K-,c ך1l鿅]1Iq) *;4f7e}yh]{O Xۆs\QF8Y\Lf#h={+2/c,$:P1 \F$- لྡྷ\"R߮gݕi$#xflal e!FnAIPC>B]T >[(}p(l)[VβCwISI #A§eD>Kf6pJO մ5!`#Mo8rA-Z֊|,(N|zl\Lg׫bVZ˯Ϸ[KiV}>V[C?Ό 8Sjrgurd&v\tAjr_-˽0hK%RJ-Uz)ML K)^ӳ 'V$ +™E%@BYr;d>#{[us<=ղ.Usk rc!"Cp̞4glqVB"8so5Zq#z3čKOEk 띡0Iŋ-̨#/g R9M\BYd帺tlu#bTܰl 69 nM}tQk J7;رs-_(c<zB29,(DL2/%w'M}[Ap% .Nq<װG׏?_jiz[s_G@\Lg2+c\ " hzZW+onBއ9&Z2E~32a\&f;c{ 1L `@a*p/۞4!@m^O=wtnu!븮MsiuKFqHVLRyX]6J1(@&|Ml_Q]З9S9b䠭rn3z|n$\´(1"r[L"O&Hq mQp8S]!{rzg?/

jQ^{.x /o#Psʥ7߼099dhMFǺI 4i3}B\(&#Ô $ER`/iwe DszǞF)\*my0njM̀ӜWu YGΊQv*YX8p+hQ$2 [K߁&͹VZoUJ|$|`0j` &G&t͌d~IʓM( H,_ Γ!i771"w8$>rZj(RNw 䩡yE0"}>,%EA)MtK{rY):y@+QXW_(Pd#0?sĨi|2ƞ_7HM6kk]rC3wkkқ͈5 6m&Kzw35JS~DN;guHKPtH첕C63Ge1UhnYD͔Q;g" srb9U?n!A3ťkc,*:nOpBhnچ9F 5|uO*[Ƕ|Ob'6? snGqV s2loW+{`ř{:Jû+j?W!;ݵ8'> a7nGR;٤zt"O_F!&d0# %e`;3ylNKCS)k S 2pz=cg+w?sL5ߡ<^N*;O=T"jFoKVm{~+(^q}qU nIPT U%e65 t ]zC!r$TOzQ_swh+E sUU8 iJTE&omq@qp^SB\iʸ_{*?n|!n3{jK9VkͭxI=$Zvn5^.A ? CGQ'oDi?SS5,8Z)VȧC4ˍ$U/p+,2kOM@5RCH :?p*u#uYj'ii-׋vك̣ԃzw Bx<ĭڅSSD>Am6O >/Lc٨f;kXUQz 6FwfPJ}8IEH Yg\&3-f}K=*"dG^g0k+"lٰQe8Y];Vo@DNu;ʍ " hGWEC'C^ Y2%tf!6@4튊i@" i7eћH,y"D>yJMF[D[5%.cd_G,(SSϩýI9Z aJ7;I;&LW8wRJPmqmv{n# jO\jͷJ4 ^ajbq!g儖We<7A¿\@* \Լ UzTeE(FMJ[IvQnqGZ %f3a rfe Zus/Qag He.Nҫ٭,kS3y壏xSZ/"(G?[N)?CMY &/rnqA8 ^H[?{qoDaeH0B"h3 |oњZM{ڸr+%aGWfp`~iuu<,!ة|&'tb\lQ@zbg0:3GAe=jbe8]۝j|_[>n ;$/Ķ nu|Y1_m}Ln7[n \ۜT ' -g tAȡI2W9^,(.:2BɂNk)$"-eǟd_f/~4] *o;9`؎c7OKNL:V~]b˴%Yk$ lBc#OF/}A#W.ϢdemIyʝmb 44EX ={9:CV[K´|dvjr|B#inuu- / cn&^ٸS]xacX ؐ¾8v<ˈodƣ.ǰ8ODeG8Nz^X?tz_sMKpX#N8"aϭó=SF'|av l[fw E -Y&[ ѭRHn2dPJ&%(t2 {lZ7^Ab~Cut]_JDw W -Erd9"~]QS#G 4nK~VzWs1 V3* "NH+Œ@) ^jc@TE3?tzتyFX.a'2/@BnIA[3-X;\k xqj ^#mVzgzI$1>Q'0𵴓,֦y?V%eG^ș_vTղˍLz{lEԼVN[cΫpe|1q]t/d9Gq]$aS^ϸpcƑטev]Oϐ[u;MCy( ~{٪[lb[>t+{$cÕp_S-=dϰ0En}qXskW,aN9pmP#se1{T;TPX9rE ls?x~t̺ WDzyL -<t8r 6I%ٻT_\^TVBMfgFWrܼ3]U=ʱEmb^Pw4}HedDwv c,S)QpQ-7v2 I30n̴:mXU-nf6XY{lG:ޓ+ofoYX߀)m!1HP09{sm@w")bJtKTU^[@YOZfbX`z0Yss(j.>tJ%AH1 *w%^{ѱWύFg^p-2>I [KX @v^m< Hvp/˫a myM'm3\&a,PǙE}6ئnn ;@7ól?-UбES `s47Z^nђD9W^NF-^JRߵh%ܝKz6mUv->[l܈ތ;1<Ͼr浓7Ti ^9J= PtRϘ!'\ *i ?zvH%vBε`:m&'/599~KÓW/_xJx=EuȑR!t *] iPR=5g.Pk- V4@VzT7^u+٥oƞ)#.-éN_Δ "FiY}q~UWwUk`δu6Z0jFܛUvQc^v-[p՚F@K6Kn)a touT z" J,DFF~=rɱq-tڢC]uz@w]rx@7U_B~hFD\M2HZ]Vj/ vZ4NU]Ij_ L]}}˨]힒}^N] ϑ{~>EwWvR jhn`?/Hq?sH\S#lvnsC|2%lk~=ǖ+\2yjY}\{ơ!MlMMF NfӐE۵1-~V?Wg(b|[7!XHڳIΒ WU FdEt@z?i"f9E/cLHZLO]=N sAݍ&޾p):7֡kxW65_GU/|'O!J$sj_\r7N0L55uIfs7EΞm3i i wZ;Iӵz#}ʧ܅Y!.#( 8ծ+dUPQ*b$e{}et4m?ؕaFx8.Prz/|D\~  Z~ 1Er:jeY7m)MMUsPѺFX)Q~zQ;7M5)% շv.>ヸ!9:r1uvC`YNGR(w͗#ֽrX'ΆL,۬R9yC؍`)[[cgbP"%N>N0әQUw(lcO^|mY_,R*pvY/ō2guwQ..&زt1]$ݍPw!C=d;n0kYY m wqك,Kd X fٴlpAa?ѤyW19-oᵍv?,Sl?gtt[M6}fY@3x,.B-8'rڢtr ,cXZ`el%E_"A#D3uR{*d-kLYc7y0VdUUV1Xȳ)Js+,/d0<[l cBARS0_?W}͒΃9g[Ht>\QJ"/e>w0ƹrFK GƱ? @u1QS!n 7.$U|m j\^g\5V{N>>@ =qژYLR<9ƍT=MstyRh xy?A^SJ)uE'߾21uy W֯KTsU"Iy'q@YEb٣ % #7IB]jJ1\'HW_'9n)^rȂ\r#xE%L5!UɊ4 j1Kp4{언 Kzq<"Wl7nStS qW04X3tp3JEЧGP q[ZCd!}O[CF7[[7rN'-/{#v۹á9$0eNw$oj۸sk[SQl bDHvπ 9-":'ԲӜNQu ?oFP^!O}K9?MԵY'h~dME{qNUyު|QvQ?ܲg4|ߩ?c?—=k\eJ:Qqmm 0/)db c{2FLdMXHp/.B9\mRv-sLJ*.> raC[[,62/I1/!~O0+=5A /1>;o5ZVqqw+M#0z/hлP* -&(s$%hI|Dfaq8? M*ˇͣ ̀TO[QX{\+x4=Pvz.h7оbk2y<{B[UʴΈld!M؎һR4 a+1qS5cm~N.tfd}pӾ6pc{|XXi2p!y ] ?5ӭ•#-Q\.DFx̣Z!AvDI'7'I"5{;p`Z|]".dZs3I8Z-$#h ?6cc; ppgG\I^Ck2lU[:62x.৬>&9Tc{,*; jT}fkB WN֎6 !/9&TPRIL}xjF[rURg,JVth~R+a){J[ B8)|-h9'6U<0ۺ=fu?P9 B) ɢ;S' gI&3j_(*IfӁ&.wщ"="pvۺP W jW{tȊΠP~d~>aXaX8:Y 9?.ŒYt"{`䗗N[!>xÉCJN[W>VNJ^MTdWLɁz kRG"K80q͂*Z¶k9u6=g0m#2p5,sCzIj|9tS_LZc$6mb2=ς6Iu>=̋m) &WL"0r09۔˦+CKBO=n[iNA5߭u {&}m/k8%g (>oﰿat ׳R eTΧՐh.G%˔(_Ư+~'W{:>g FIK(1g,*/&XW%sZ9jNR =玭˹^ր +{֔@mWB&nisIySET^kN(Ͷ kkF--5*LCϖxj%vWx3`Ws5\ O{S{߲іSխK*dॣP:MU'B$byGx b3q#ǝYQhY&d؝m 'PwJׇ9_T k6Yzr\/e,J\PI 13QJZWQ.( 'T!7EKa3)LQj\$H4?~6&k{yCGw؁ osШo@y E㴿#]$`ͮ-5SO/?S454z=E'W7ǖ-_c"[np۾(/]0!2z.QF/kgp M'j3!2c>A"rkp&Eh+!(0g1JMg)er{5YW{\]^^M4ykٚximv.o`Nphc*Sh Zo,g홿:dP7&mN`c+$5@܁9`*r;\0(8˹[ \r,sg_ Z<\u! NXMl 6EBa Ƨ+NS5`*TmUwS:ϲV+r^h[rfh0zoA=Lfzћ\r'(b}+OCۊ 1T}Fud41E[F2.$dTFsU{ '.S \+"⑘u9s{(c.ܴ8=vV&q&x;&2p}HTX䅃Obw L3CK]]<4oNbǶyc yC22tǥ$u ̕ێjEPֳ4;ځb8pa܍rId:75%σ Ze J]`:ܻ{l6,F*gVx>l\rd~Dh)'zoNA4_$HA5V3bt~]7̗MiҶJHǸ N\4YFh!_?rBu(2݋#yd$1^]"b WEk,%' (ۓ0h8F! xO_V*'lz.#sZSg54@"}d) jINLfEWC4#gu:toYOjQZ~5mFN=z _Uًʞw[>'gQ޷& 9xCiq g3nFe2^ڂB]H"g!}N)"9ٕkQ7CL["3[@.',C4y"yجB,u?;AJT7Dh?=:a C\3*idӢ3eqeMQЭQ2vnNgMOu^ܙcD}Y3րaB\ڞic+X:{ydztWCMX 6}&%r iw+M IbP-)k4{& )Aǯ I,kkUcy54@:w~Th/–lvOWu&b\tSTfrbE@ @ X3sAɯ(n7w_zgԪڅ_'C$;g aClp}g Wg@J u@E[066<(+K8N*C9шOG?LSs`T(쭾,"\i0۩z':N;V5s5.dxG˳$~߼68F?? /uMhQ|2XoW~Qs'g̔>>c|y!e`G3t ?-X\pp!H׺*#uy_AA߳aW"cYb7X@-iz[|e\j#=lu0Ytf7)ӝ; [L2i]fWގň_xB5.%g١⏎ ("u˰ ('\B#>\&0쉮NJx ܰA'/#?S<@ESTc5R"򋧱eݕb4o {}MoUBuqۻ3"g]a;i;FTtn!?a\7,Ŗ}]um YnKge*7a~jfv3&KcUjx[5yr/y}zUBjYc+cOQ8 8B]j(Cb Q{bWd9kv#: 7 ^^fϣCم~k{JJCm@2?k? Gݐpyǻ/4kEQ.cX;;Nl s?1DY`b%b-FP+a Ki(8P0tsP;A[S#u^!e HRdF▲t$ow?kegpNuÐlȭBe%Y/l/1-$ Ӊge,/Z1nM<?SmGMr]gg>xyY)˝Ev %'vv31KҒOxB7OɹTseQP+rDsO`n&*~yJݸ=X'ܲ \otMѶ+݊svTD\TH|ӟAjܶ5"+?5Sti oK.O]|s|ˡOӒy݋.^ImϱQgZ*[ *;/x)x%E$ŋKh1_ ۽|3}\mb$')uly͙ ˃jd_s҅굙vz-i z/UIz/V̋qkU<9 >F=ivBbaUArLt h$%aJ^"L*AKlEޏaoh]6 =V#e*wT<^QU|}(] <+g@T6ea:{6A}7G$Bc׭ؽ/F.C(U+nF.M\JڋɎ;B5 l7}ݟokы'^\ڂG Se7IԙcWw)_ap^XKápȸFE&v݀D'lqB&~晳FzNTԿW$ߝg98"*}X8繕fIL*J}U[#V՛#̥¸PCrym8Dig;I~{ZZGZ_\}F\ke^S jQlޜw?ЯՒFAh-^O߷X Z홥|+]~r-E2E$r8G׼ A,ŋK< ^nε,va&9i-2#oؓkdANg)Y!Ro#Lug]2u䗢ӧ^pM>}׋