sssd-tools-1.13.3-60.el6_10.2$>/qLcS)Hs#>2?d   F .LRXbb b hb b b b!|b#fb%P%pb&'9'9+9(,q8,x93:GbHbIbXY\b]Lb^<bdĬeıfĴlĶCsssd-tools1.13.360.el6_10.2Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password\>x86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686+ɤKS@ |5q#0EQ;ao3] 10m:*|MHOr ?sH dC A큤\>S\>S\>S\>S\>S\>J\>S\>S\>S\>S\>S\>Vpn\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F6e0820314ea3ec7bc18b1a02ec3301dcb834a52ca671d60e8bbd6e8dda29149e10acab9502ce2e73014692130c887714ab86d0c8455e3ca3c60654dd1eb87dfbcbe626e51dc7fdf478397557ae7adf0452f253bc11ddad6cb89d4d5fa8fa20087f9c819356c2781dd47f9abe0138a5b58c00d63fba576d13b27ca1040181516e865c4f8b05fae82b77e7c3d36a6b73bd717a761d707845344c65ad8b31ac2846074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e4b5ce8776a762c744f1a6baae5545d31d9d4bdcfd2db99a12ee83cd804192a1a38a9daf34044a114e85b3ee4965a4712cadb8857e38b24ca88328bcdd9c8941958dbe4f10a9270f7343dd9d7f90bb6ad02b51363ea969a23b8c4282e241ea075d09230a51dde5dac102de3ec991294200bd38d2e9a330a9bf9d551d987b0697948f560a1d2c5b425b6bc3cdfb439f6ba3335a7210d772475b29fff80ad4dc2848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90310e7998fa63a7c5fa94fe61532f72c8f103f6563c4f6881aff04fc12c72a2005ffe255bd2d32476ca4c1799d2f0880dff0d56c9346263c9b9166d402797a9597ac16cc6ef9e7cbce3b59721c89187acaf2bf74ee83b4ee16a72939baf79d1c994987c56756375b9c6ccfc6fdd8f141087f1de1a53e2cc7f9c1b8a64812a99c30c3a967ee8747393b7634a732da977cae90cc423f89519e1308b2ffd9d6500d3bce19c9a1c8d59d4467007dfa33a13148574c3b3a56d1f7bd0a5ea4d22a294cba70ab8ee6be09e55ef55d4df5462bb87d9171bb88c9255cdbff05ad1b665ae31cad39da900dd517559c2dfb31180acbf6dbf8c44cca601699638ee846f730575edb3bc87a2ed41ad0b33f8a7ddb198baf564ee3d5f73eed3645c35397882ce809f2b218af5f82c9eebbf77d4cf98c4ddf70d6c5def9fda0c42f60632f639f43d86e3546ea13860efbf7a889f672d22308aeab4854e590a851bb4fa24fc97700e90d2fac6d79054ae2e369e04a4c073e92d8225e8ab05a30acaf0b3abe8dda766545890f5aac5c6199f40080a7eeb9854fc19219f3c01f77ed18a2634b0612ab24e86b6654a933b196c491ffe8e198007de7b7fda4ccb537c9b80b72fefb55ad1535f17778e6082028bdc12926753802980c0dcf57be393e62848a083dc42727874608858fe68353c01c6d95a9faed0a088f539d649702f6a8767cae6050cf898dcaf95c6019e6d32722fd00035cea740bc4ce41bb19bb6ca38c4cfe2e0f4a0d3f33dad94c2a3f116dee94fb53ba321249f03d4cec1bcf19b73f7c078f7d1c466adcfe632e17455f2204564fc7999edcba0264521556b2977eaf32a175e8cbd234295369b56555fa293ee5e0b19d498798c7501cb0d7d6319e225eb1716ec9fc0edfaa451fcae313edcf7e91eaef9fdccdd4bf678e2d0f6641b96cc6efab26c1eea4aef71794a708908f80b961c82161717ec4d38e1071057c37899b4b3abb27f3398af40eafe3262aa2ab33feecf21cd2a580e50c3b041985d2bc82205d9274edf5abf7a81ed70904be6633dc26d7b97f4a822b314b80fc96da3397ef3dc20c0008a9232f1f1efa992089761253a0a8f95c22b77c5c08e61bb610c280853be10623c3aeb7d99a9387a928f8ab52135d04d087a014eabdb31485a16ed13014b2be0178b0c3dbda640d4d716bef05563415f80fe1b1c7e72c16cf8229195371c25b3071b8c84ded1e4e764264645e01c79ca04e28d35ec8d8a4cfe8fae48e131b2ab89b6d644af0d752da4bc9d07c7d932dcf2935dfdd1e96060a0e918db3fe6f7d997fd8dfaa45b2461800d9ad9150efca9c49abdfe42d405cff4649794bd79172b159e6d3e5c8994924c73393b0e032e3f7483f6e2e7a73dfa0d3313996e76fef64c49f786b3c1a5c4815f6067409536b15741536bc49072fc5e4e1c4619e9d46909077a1bc9e7c4fe450efdf4ed0a2dad8b909ef1d21df0d5e88eac935c9e722983bb0ff8cbf948c85031d641cad04ab8c7a4c6bbeee8fc8b54bb9da6b4c3c5046ab861e93605476aa9eaf25d4fb1ea3afdee0006ae36b8b18a3fcb1a6c5c4394e772ebf011b7c016464839f3eab352303c22eb45cceca781af6fa1b1be86f038ee0a1551c458c692a176cfb1ac6fd31854b06abb30f989f3c0c08e4efa80499446766a5877bbd79eb8364840c8d757b54fbbd6c786e22f3a892c1634f79e6161c20bd8eb2ea1815f37dc4a1a4e25d5b1895e8d1e0deb757aac8c898c2d91ae320fd5f44fe907ca0699f8b5273f5db15caabdd336024c509aaad69c18fb7b0a625e6440a939d5b597e5651b5e352d02bdae191c9386e3b979ebb52ab2c19c8ddbb9e1c70b639bee076b4cae6e33a9364ce730a767bd5ea602bf16ea511158759fe440ccd63126c792da795853c00cff6df61b615f3637088e9b73967873aee8136a57029a66ba7707710a6159290b724004daac15e5d12eb34b4354093ebe1b473de61f66330ffa712bee030d86e74250e1d8bb7209d11714bd90c6ba4bb6bafbee663c92ace0d73520617661242ceb9a20f3fb749d86862d8cc834a75d84eec2dcec4e21c1f5df89d94cc5cfca9a5ee641b444b39f437ec81a61e404175cc65bc2d095244b677dd868c382729beb40c65b39675056c207bbcc628a6f174bad6a2d8fab7af4bb505cfee2e0c474c8c8a8b5b50beed5d5a3f60b1361444e0c57ba3ff50fcc864cfec5ae128ed14f4b704de0339d2d7494974747dd3f2f9e825da1113ebe1a94b1083a8cc4ef3605a8025bc7cdc82d85f1489c4aa19354380904482d94c0d736616f5d9f6cff3c187ee1267b28144103ed9697270d1342d52267e10a705c1af7ddf4227a6142374ffd9e27f4a7efd70d905fa35863b0c85b4bc1eb96bdd0fe0b7d5e56f0a45169d89a4503003da23e1189a9cfbfe2ff00f1f9425b5a8b7fc192fbc67c4c9490b7abbf1d45b13881202e6ebff2c4f9aa93abbe60858fb3d23d6ebe40c44b74b30601af44b748967e984e57abd73c5afa1bc2913d9797201403296152bc129b3cc136d547e63c56719f9e25d26656348f8e109aff3b0383ca9907ccd3feebfd2bfafac566da7c49904719a5c1d874f70dddfd278f1667c796fb3c2c00f12d9b519213db2dda1acac178392510542194166731042f5f84c967b50add087cd806f24f2ca1208c5c685d5c88cc2f85cd9b04a5b449fdd89f2fd7648d0b68c2e74d0c7429dd38191248983152bc2d0fe5fe47e9832d526afcbc27a04c903b0f7042dbb1788ac6c5bcf6160d2ebec752292fd9d01d3de34a48da39b22919284fba837857ef85854776014c87199f35518887a91de2811e390aa23569ed3cde3e6de935c6ddaf3908d5b440f791a7e4dee8f11355be78185b97c6162290cbd2b8ecbbc6b231ae4acf6a96178dd7058caefe06d7bf9e6aa87924712ec948046d1489e810ea7bd822bb3e4a8485086ffe1fe36067571b3d8557d391565fdec1a0caa066c1ac0a2b260a150fa879cf48a50f515414444b1d2bd3c6df4968007ebf4eeb61aaf955138377a5d405bff06ea88e9526cdbb100639ff5c2c85ff8ab042cc56b4ab6a25b33cda4c8d0004e180a6a129ea909f6ea9f113b24b4e7dae0cc032a140a66d4aa6226439e643cd091e108d28bc5bdd814ec4c822299ae948b0feeb977f53bd4b10410adc4b4fffb947a32c27cf6729f50e97f8c63952065889c2d74587c5baedcbeec1a368d0ddda626a449e6dbd77e8d6805535c543cd55c29e93c688709038a4571794dec220ecd95a66d394b0c1bfd354f25906f46b7593b2db24b10259acd2957bf0cd8d4c7a46fb8078d57b9c313d582d0710c33949020cd27ecbfa2e51ba767fd99e1aa8ee5d4be965a802fa7ea701d552b9e21a4f512bec4b026ca161eca3889c6c8a0e4e2f1110030b7f2e6501fee112fa99b9e14a3224f92d7666db59e9ab4d7164d1dcb3340812c411432c813c9261d14d810f44392b38b57d7478b094573aa4e97127a9247ca47b430f4255cfd4470d52f9a331cbaa98d3477f7ff3b0d4f7a87c4672f16af2533d31633840505e97a9ce9adbda59ecea7e7aae994039eebba5f6aaf933a61184141bd06a744395ba5b4fe489171633b2ac7e9b056066b82625f0818034a016da47e94706366b72ce374f23ab9433ca46a9c0b9197b9560c30d9ffe6fa0d9a12ae5f26c93cf5da6b44f2b703465fd73ac1d6d4335440c465e5f40f9b58498ae2f16dab232c61fc9b850ec99e9aa2f6d79ce0517c0665660dfcfa9c129fe3e26e8ec465ce1270bcb6a8d2f943d32ae1b38e964ac2841143d7c4c8d1fdceb412fe00b5494c0397e4rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6_10.2.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el6_10.21.13.3-60.el6_10.21.13.3-60.el6_10.24.6.0-14.0-13.0.4-15.2-14.8.0[[ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Michal Židek - 1.13.3-60.2Michal Židek - 1.13.3-60.1Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1636172 - crash in ldb_msg_find_ldb_val- Resolves: rhbz#1576852 - ABRT crash - /usr/libexec/sssd/sssd_nss- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el6_10.21.13.3-60.el6_10.2 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6H]"k%}:w{!vQ_99e[7h  YCu.骵D]HJZ-/ıt-NF'<n:C1I’=VFR igbx|*H+6TUI_4E\ʀ4~X6БWƫc(މH<:n/~x!X8 篸XV٪jfߋNK:cX;&x=O.p:.N%H.݃N鯣h-R â8gXǁ"=@Bd"Rxy$u3mނ/H&U,K'mU,i`pݍZ9؟Բ:-IOUD7C} 'Ct?dX6iRX8&*OFe mSn9Y|nuvuw1fJ;љ6´WCO"X#Ob{M[ !*+`W%XV|R{; ,e[eh^S= 476bԵ{uyV4f.1jB oH^O0~8+(ǁu&R3gSn0㎜mq)LXL#Gy;TmGyy]^w*#9{e,Cψdr Ο/T x2If:rw}&-PZhf 9iX f 3Qҙ%nU?+cC".K. .֎7Zl6AՀ')eQ1uj2Y7 _Lam BuJΌDr WYVW*TBcի(S640kn JNΛIBJ/~9~}}T %yq˽$vtVn\j@2 w/NI0{b1^)I,My Ydϕܡ;;@8.I OtTf na4hUzn+m@z8yGS ɚah1[i0|ӂRJVoBޞ WC}I1z%V:wLELj-_ qxQ|1ދ4E~y4ce#T&"AQ~^}H5w}:&Oki?lП#Yto˵pY)?Yo B9RBB&ɩ _ ٘o=MX)NmCx9/yNe(j_^*[5p8q,qΆװkĚÏ3J*M?p:սKg-+89/IϫXGY#V}U&*BVuL -546vVpa61,0;o $:O77P ;p(Tͭt8 XtɝA"rbU\N0t~~CZT)G!s'CZyË9[!"=Sͦ ߤp*C7˙pak\/*Vk])qoΝ &[=?ucy"\Ip7N`c>NpJTOL{v >FiIgl3H;Ȥ\9 ;@LIq)U"=o缹 H쬯qLmщ/כ1WtJ:J8ɘ,ieҏ6F9gQt"7dxyیq͊gȰGrɡiML'[:5LjT A8Լbnqq8kB"KAm|ڰ u5~l8ų( w|l=L ԃ3DyY}Tbj7(82hh^*];sJSyBc~# W "ț2Z˾FQsa >Xg+t̛ݢE`o`85wr$0 ^~)ڗߡIΈB3@` LQ[҉L.X0_A +O1<#aϺߎOD; 3uLrBkғUYry!l [*r:Zx#3S@-iȸ؄׭6ܷ*F}zY}"B.< ;,}Eunτ,{d_U;ZTj.[^F{>TAcet& RWTlg9џmn7:[c}EpeԵv;Ϯ=p,ګ V[` },gZe ѐ;fp)貝Y5nnANĝ3S]ioD 9~Z ;EEE$NĂitE7Wp,kS|ؾ&P 6|Rɤ4م:|e(-@c /9.hQPNi9 V(woA7mf BLj.ao9eR8d.Ӥ&|&Vü0mh,ҬErK~i~/5lYqLW̫2ꧦ®b"HW$ZEP5dÙbg;[#S9ztnI'l}ԇ=-{jǰϥb;˞HUK|hb쀗H8S`)U;?vNT00ÏFV$T39{kصjJנ2>%:CddST4ϱ8 xX, an"_[((MJ.ʵ?* p2~ 󂷢2‰' 3;NgAҁI7-`4M#D杝Q ),y7"+c5;@]Ʀ2,)04}U`L~{.$Bg]ZA9i/5vv?`B3KQ?쁙d]H>#IQz[~~~xSrF M$QԿ==Mru?{S t[I1H1%lɍNԹeFO6hmt:3P KSI=q=~8acܲJvGbC iv#8^.te+e/XGcNDн.B Gr*N/!o`L) >@|ʻ s{&|[i_\6/ P`MN"v6#|015{nnBf"I n {0'q ͘ӋS> !D )uxEđcPߤ'3( *> 1|g>tԸN&6XpQ?]8-x>^̆눼2l툞Us>h} L?F 1g<* ~3\dsA;-є4iht{IC{ ԩi=!j41&s嫷SRfG(HK2v_{%пy:b Jhdႇt֘RU'sҋuz-bP^yY?˙|G .vJvGewX^!V]9$q6 vt$4m_-k6l@^47~.TTyB$ yP)7X!H': $f#Jw|3kL66}nޕ0.X\yk݉2q= Ni듕tTŇ-q?7cdowgLsJ[\7Ys)kmm#B)Z4DJLP"%H_<@AS;ӢsoX>#_6pra _,=zuKϒe5g|E~m0nbNR\%8JB͎V7Q`Jvf>v\h7zDC $^ogU'`ŭO Fg f5j% Gf79f%Rl}e>0sO%(h5#X7[ry+_fj#]\iDKg{SOsE9+c8𢏎Э0+a[2%+Ɏ3;ViYC=C 3*$&d LTF\W:e| {9Q.l:&)WbT%%{`.g 05k12s`Iby* v=0 \Wc^ḾUmGD2\{ߪN )rbXg4 0;: *$R<UB)kAkAf^sG#nbs.F.E=Zto ZќƲ16|Z0KUiz9_:? ЫDMoOB˗7Dq@YXXtA7{@6 N_6ԍm;O;V6ר H wK/lHw"b1$ؚTr!˚YxގD,?m7  AD~OfmQQ@;g'V5Ȫi;2\֨=;6ra@j{MF.YmS `[.sR_`u(\'`jeVmfQ]I}c5d?5L!N6 t_+&|n٬I~/F'v}2CEp =g5ú`zɇr{(WZïCE$3_JldF4F(+";1aVNr!-Tjf8{ɐSOubj8$ J>7]vNg 6URgcYn wbi&,rcNFaq0=e>_Z0 Vӡ*B[\xf-WDpg}Ef [J8ߒ!0*;ΪxD蔝fBP`[@E$zܒHp`W . G(\ 4YS¨*!TQDU"gEMlʭUDv[DDrWs*b_?#CdQ:XG';w,NOYԸDY h!'GK7bvv"'&a|e+P%5aC$~C)ùﰢ06 ń/&u)rEN"@&a:}d2n v*ioE[B1_w;)&)3O¹f}|54xo 7[lw} 2- B)RTsBKF_T:1gv )Z$Jb|@o&)iÝ ᜀ_벌0;WjӈOLb;a۬~b~AnyWq,p=Ѵ^!6%!%u"76PL PPCj{y֗RƎ)*BFsQm@R{t ByǛcI^CZzXfRB9Q|mBOTՓM8Y/>A0mc pF MT$='SXA Ouɗqt ]7Wi)Aˁϖo4%\ĥ SCv{{';ȋ('g[i3n̓N[/XY ' ֎rQ ] )'D?XXiC4+SAL}<+w?>O Gƒ`5 nyn~'+ Px!ah3!L.Nޮw"0qtɬwqH!;wW&ѝJvʓĖ=cKҹdRv64ȧ^4qq GkCZRdyݖtTо~!}%#+4ee8jN4KB+Ya`Ez>6 嬢;tfV\16%ױ1b:t>B,&m1\Ƽ+ԯρrtŽ|ae$ +,G8=Xc-g6II}~NnǗNLeues/[W{lwN6] Y7pu*R1 }P)|T m)ez̰RklG0X'#5ϗOչiKȈIzSv(Jy'YґI%'L :?W :2FQ`T$HXP͚,vlC7Z2R%8xn5Dh?86@.~8%470'* S7fZ5A>Q@)tLǟ <{^%s҄n1{׀5FM‒,rLWd])>Ѝtӄ0 Mf~sY~?G"AO`P4hQV\oOfi*<edQ%M{ɥ[ YCaM_;;i#P,~\{wdwGɳy^NFׇ<keKDU:=ejo6RWlgWw81_RhJ5m1U+23A~Ʉ#a0`LP-gPdS[s01R&&np~@lE 9;ɂ~/>"bґD}C}1nf~N=W֫ԸjsoH Jl-07 8^{ctxN.xS2OrB؝J<9 2U'*\bL+vhB[+.HxеXaʺf8E 頜ܤMB0`P̨GToW^`r`zXNh(M(yDiW1P:Fga.BS#@jXm4J8巻mnqtqoL_qh%- vh&c'Eў@|겙|pzԠ<;;0,2ah8 X#RaK\,;#4~? ^S]vCOH!Ek4rEpH>ԯ~H!#x!TܲRgJ_xYO'u1_K_ږ?O|JgPKl,8xp H<;ލmYn/f~nP&<}-psTt`J Djg;^xJz%(\@yjpXb/ U!Šk3=J>k 00TbgaL dYmS Ł*s߬PyxŠ؞g>bS7?̪/zS3V~A~9/բIx;S-Ë'[ L@Qž%tsEVȊƁ z[L.ݚi U>eu~ D. ӑ"W5ߌ23oD̏}yR/Cs[й酓5d+jۍ!b))aL9eYhvAfzI!°{Gm{hyyț#@Z` y9dB5x i >GSus.Y(Y _E(`KXNʫ٘djwRG}+ @-x#~ɹ9~'g8\m)Qd~{p)#W273hG+͜ {d4֕ǁ[9(e>vŸ@mLE\էxcx @[Į8v\OH("f[3Am!b< Ksn5kYZ4%e8O|HkDZr}gSlڀΣNM7*od"T74 '[TwKD"`nN Tnؕ$dGԩ5KGgr::6f9Tĺҹy1Oɭ .o9Y;H%rM$齪ݨ C2]lT*1f#yAdIpO [ :R ,':k s"*4msN+,SCa2h5螚z)mvRSgo)49ŜA ޓZ@ݜRO/q8Iq#k0'6C.&= Ӌy3:##q[Ӷ%2ۜkpqNIp!dPp_ۦM4IP+XdDo J=<SATj##t<6Hԡ"s&ZMoZ$$H\o43B~Crn h )&,E;8tɽ(l5+ns:c&-L\6&x[֖Rw5c 'R]5+elzQcUX13b2b4%'Z(Ro:0%-j@2r~RҀSCj :l^B4Bg{QFO3 xmO8xYH"!`LT5++9c4l^O?Z?.31Nͨv=$rdB%B!5v'2εHWK˥ t@ɽGF QWVy8 G lLu_|٩5lصr M1|xW^Z0&ԶalTf @|>q =S׸y=i)72ѭWj ,8?T-]cwXZA Hs)gq9˨7~yz]o>u-{$# ҏ8|hJ I>6%ek`>ԩzj8I ڪdu^1:Vw>P*Uu2dL4\DjPvT u.EPYhJgR;d'j{P쎴f| aB3p W8$Ֆ_ `d/:Pxk8N{ק7G_@67EENk^ mCES|"G )Hc;&b۾H V^6w1exʀӃy$;}i{7Fũ5 aq'kbR XN$ GgtYg3#(#7CݛH-IF,l?4Z=jMG$>lyp=FHS';='# 8vBp/;E #D Ba+z)ЧZ$W[S,pw5;7  =?z_~G\ӳ1YʤFnJ Eo;<U? ~ &XXIR΀A`>0sOk|8)NPyFfl!N0X؁b\&f*0 93k*2ĀB i+}9S?rABѠds ~ش@s"VDΊaNa_0*Fa> i (KB{pAc,tؕ,ՐR>6oxmg<)mܸфc l)nO6HnbԲ(\P')'";OVر׉z+t˱_9Ly2z`X`"&g#?[P7DgǨٳiYjfJW>#m#H nSfˊpv-~Μ;inR՜IkLQ:tlY4 46s6}nx eUMZłlut>K$kkseQIAmZc[u`B]IziO7ٱήSYf]3Q*}l^%*%b˜z}^cZcL QR0^#ʘ_$?X="PPjM; dP;>Jy3x7U]X: >AOYBV)h$ї]1,2ᣯђcJ[;I_Fv6:$3JpD\ ߸歟 YCatf\mwFźB"QQ>FRi8^⊤Y<*)Jfb3Ҡ>:ZcS|TAfI t%?#.qNn1Rۯ`.z, *y.dʨuxK*_3_7V1P1jס1W} C)w7ƅ#S>@٣w ߙAbWId,hӳ~A/o]ľ׆cE.hKZD=qR P$K8+˞B'$S,0^0i n3[*#$sZtIѨ]RJ U~_N xV} v20  SBY:AX_*3w:K2%  !Ys| y*/DNith^$鄂IݬCH\j@V6 tK%&yl}1;Jngt'_ IG'E``4>LXB Fǩ_C]o7_w~lst *Mer|^/^YNH]u;mAt-&upN{"_^q>0GdߺV,<iw|G֠^VF K'.{N xBB b$Ȧ5lz9{7;O~bN@ӂiߚ7$Abݣ{3+(GTXI5@2 9~R.oGd+.:Vs3Y4 hx۷ޜ*n.C.qC%Bٜ2A"7rmތ-!4S;؍J[k?xPSEO88J*5t)oqa'Weg`-+::nmy}}ב>Q'ZR\:e) ;~^Z <"wYqCYpԡV(-\冼7@Ëo.m2X_9 @F+"Zx.W.nA}}k_MC%ՖEU A] ?+:dP JwH6W &G!q[{'~;s䜟4?">8zb 9Bq'j}@T !貣P:r[=A~)x`bEI\=u )ểr0>Zj6V; U*.*Mk~_dƍ@0-2Yikbd`=0`{xy-Q6C%QOڷ)MkŻɷ`ᣛuv Q[vqQW]C.É␎ONiw͛kP6.tTBp' 3Ӹe}w^8_FNOj s~Ղ%TDA.@7.QXڣRxm8]b5T9}/n:,HW$֌ ) 5N[ae L&hQ$]T3I6D[K O.ZʈrCu.Oߧ=^CR}&,"RR(9EH9T me}&:R nZRQ}F/c }6/(jtuCWq) uW< I0ޫk(:B>>j#F hseG[n>$N7"N^hTb{2X~}_]+_řy)tl+|E|N8-J'KqV. S*W0UbH |&ӛde@rINTd"1ħN7-kCy ba $mS1CvګDWL4 Oۭ_ eRᇡ$x?Ҷn툌 O+t,$E2Ɛ~͝eB)kɗ[˧^C4~$%&0cY\\Tti,(юM)H|+tw,gnW)ĚPɿtV2㥎{N1PۉZݸo uiȀF`35MM;Mbe#t6nzSbbX3r P IbEk[`歯 ZɺuV 󭻺rGVR*ʾU.d53&}8u/U006BLkd'6@28,* A8ÞBk躰>OR TZZ\j|ɨiJK-Jf4Anp,!):xm<}m][ [sت-G@8y*FS6cۉxYx|O9pD_$p, W Xw{n2g,w.,^O} D"'X}zL}WY $nLgNۇ P:}U1Ժ~ME_X[8Cwϑ2կ.ieϊB 3# ,-oqK [y%!T[R߭Dqɖ"{:sCvڅx~=E'z.%(W#xOsmW,9r*\Xh]y}@E]*-V?7Y*4b ҂`9|K&(~ H\ L^kA;?so},Q ;Noe&|T{D~ "W鬕'&nTj`+VГΡU/bL{u5 k!5 VWv^;\ ']+HPB?~RB^[ Q߮a;rS_u_J֖Nqݫ?"m1qt}SL1p?` эb&`uk5[=,͵(P7p-4Ԏra)A*Bb`R @f.)B'G{ԟ@Ă(ynIÜҋ1@z9wstn̼% uG~ƢϨ2>wbCnK;{mwɶuTTLegg=(CzBaO)~>+QJ{&=FX'T+"'oصI$yIzZh]z'W*Nq) dH-`mPpXMU@H2/qU$CK I?e 1 ;~J*UASE;uF.U⫆s/#!Fid:n CYV赍5hB'ɒ*E]]@ (ccCWE̓Uc:p;'2Oh=!Z26?̧Ŗ#A -^j]!gC :/J1`7~<қ4rHrsAnbO Dv9N, yNZH_voԨz-pO+ EyB5*\:GH0)$717Ժőϒ+uAEjp( $7m-֢2.+7w6!~8à.ʗ0'T7g y`“4EωRDՊƴO@@|;rЌi &;OMߛg:%YHe+BR\9ya R(+Mdv'@|q7 ExD>@F^zEMLX`0G| kd`O#KAYHi"/+R^NFn2van kzKf_*7A 0,7 JV0~Bil؀aѯ`Տmgwۋ 8գF QpBH|?[ =@n5e{lDYKvf@a) JAIH:q#!_,T[ٙiH4 ]"3^aW\_QtզS=.S& Ȯ߶Ee{u 8 Lyj7re=.͢1ߣ2ֻ+4@ŋ8QGJ*-W7TH II4Z~/U~Я2FϽAc+ę e`O(폹]dCzyl'xs#[ś-Nr1 W~+"RI@g)^ B _zs]"=^i^^8Lf3\Rc$H4}}ڃC( pAkW݃eUWDG ,wz͎ocKi'@VNVgU;^1m4W*ߟt 3&=tpj{~Gx]6fDï*Z砱YmC) ̎QujGu&]Fbt ؼӅV也KćO–Ep#}D]n=sQRj:(fARrl68?/5i \038D#-^- 7?suRT~H(  fc&LU{̹N691 [y>Sv|v|1cp}(凵*K8U[ؒlJ_R=L?"\̣f.S h#Vᵼ݇!$2pπC4"̼y{9"0r3+Q;H-7xы'+m&pm g+apd,=_Ad@E6RyHyJ&P+f,g[leA˾wٞܩLzwPkqDv࿃'D,ʁ-*.!3wFj67r~aO\9h®cM#qWoLq,WgVF TH".)<:t$Msgv/>[<~ +?)ʨarXzpE,ϡUY!3bx OG?Ҝ3{!xiP mKH vU{"CĝF 3Ow Q| :!xLV֛ƿk6(%=RdIp3!A[X@W!)hq;PfډXAr8+{¸/E!K]Fz_KĠXϔ|W<k(>nӤ0cu5HU#YGҒ"bx8JSP>-zrO:Dzt9u3[^m |\84v //}NNtږֆ,UUCju~]JG|JKṚaUμ39br'ZTQ*|_+b'H6/!y0ϏDaN,G%LPXˣIJXi$~hG-k.MEBS˳-x_LWg.k]ٍM? fwp R!m%NۦfUv~AD6R0x ʇ cL.b+poʵ ,㧋ʵ8c}d^4V6mc6g"%7#  ]y\hFM5T)@WluO!;&}p}y$\\vf-~җ6#AaTyoz: D~.T)ΤekJc\ 2~PMSSlqtژx{EK;u-ްXʚ{^BrxCq;H+CF&& < ڪy%k f4ө^ͰH0!OFp韛EYS!Ay[DNל&XCCbInQ9 J}@Zc+U#p9JK|?s$RȔTKC>K]{T$^V> }W(xRԬbPP:~/]CYݳ){+SSUb2 6Mjs8_(?ECB'\>Φᓱ Գ\hKK+锇BAxp$ hs<)ޯxۻTc4*B-d:GwB[ IJƖ%Q˕md쵩`Q 9zғôJEڨcYfR/# )B٥v;0PS Z_=w6U_@Qv# *9ͥ䨬)ƥI-]S[<Xe!Ws1 w߆tt;*hr'{WL VroUIk^˼( GY˲dO+7N~UߣW<@95yNA҆/MNk`Fa% 9 r:YabXluB7#삁l8L.(4&g[-d Z?ɕŪ٠?IJjxzW O=.2O3l!9=L(qem՜aHdYb5EG{,`INq; l Hfԗ~3e| ץP^A!=)&\[iH1&hYG |Ԏ *hY1_E6˞{G)m<:]%NsNGXJWhwRu䙠ihgpګYZЕh6qX!ڗHґf̉4([xB KwbB@Z,&!|=C!jZ]_5+VWkt!vS`ނ Xu+W xY'' +;:sC`G>hoT6d;|Wn6݀e^d[:6 qP<#}aNK$&_ާy"tF3$A/$$i6n [2VIPW÷P~ᛡ8!3⌇h =jCAy)N @;+s ܜ,֒vJH{\UC Dhjڑf53@'l7'hߪ>M}';)fds k6[X*G[o$> />_fQ}; Wg(g?_E eJBM|g]kX H*dv(yXGF5*E#6oF%\q aRE@س|ؑZsM7᳭Ś=?y>cpwxL*UQ~F%r]AgjmTdNkj (v¸ORT/shW`#zԋ|S\ )@0d3v4ANz_?XMɲVx=QѭuRgzX1 Zbwk!ݫȚx]DkϷraslkpb "A6 R;Y\Ƥ6q:U"]:!O*+`d沱絠5ꔏc((49ej@ O-) ;1ڲ(nPJ9w8 jnk Ѹk@Q5`mL űj6K(7f$DK5Ew?VH}j!ATeTVl[+/N ;V/)|.AGBP62C(<Zd_xޣZɅD/IbE#✘J/ej(w&r6NwN!XΈ蘨L\ +'4J+SϥvSVI4ƍr`Y bXΐStk*j'}mQ1.,|H-G*魧sȁ\G00 pAIk(U桸 QwN\zz;A6|^aAYC 3=j%ȉSQV5pDTe,˜zF36ёAŗ7oavejNMI6QPSkQƦ Spi[2ATϻGLoTU8J¨\*^RnlR!g$Jۨ)T$:FV\K .'m˫*H,<[)oJ<*Ɂkv:_L@W8gw{)ϩHYUӶONٝ8/#fR%rlYAW0p#jac҉ĮVҼݗvmTqdeFx^}ctgkQg!b]<>إC҇{w|bq8}P #ҏŢWJT6)J[)nJ] i߫k}yœ-^%V@tD:~|`qq啗)1Gbʐ &XYq[xZѨ`qUQMJHv\b%w]υ-1|W[v92 F|L=?ŭBnRi=]&)$gWڴb_(;ZO~~+}ߒ Wf!~kG76Gkr=v ] ]+Vۨben%TyM?kn~CnAcv^omrb8n=$QD }iWD*k.JG?ߓrdFV5>I߰xq`EDq97 Zfft6f]gϵFx^ҕG%a/%M*McIgG 8e0׺tnHd}%GL?ĂoyGM1\^!zPc=C*@XÈ?NEN 3DıB ~ ͙*1_~3#mșYùdUggR^:.{l`$q7-v^RA5.|š߷vђWV.>9Z*dzsQX5(Ų <GC<P99o`Ǚi3$۬Cz"hu,qr͙ƱIh[} ,OyGE 8 zHm.MHi:/eZlr6Qb= D 1 A57ݘz \U΅VҾMXP*Z鐮M'kVOW;X~ǰ i1ouٕPi;m׮%{:Myetx͝)J F@JڽF]f+GB~jtToyYZ=Y 鸳 I9ٳz1 YiʉG >^LoxB0hmz|*<s7rp?WG;u7f~l|Vvj:쨛$/OBtlQb!X"#n^N%JXg. 'A']MEEkt6oY}gCrP`v_#,ܱmK㸙gϴrRH9202pT@;z| 470 7l ?t!bno7Tfd:?d79C;-x.٢GG Vј5KOBnB/I|D %2g{flV%bbDEST8D1E,´2TΘ*.o׸[rzmjN\x  DKRY|U\@^\V0k&B$os8w@qzJ GAbP+gkO;U7<˂2dY_\y#~aLqV,ZtK+I8DLUSB h*hBU9{L729/&U{"bhTOJvI#Hō&THCxܝ+?ԡ}ScKxϹSBSj{@9hUC,9j\ ^SH%{y]q!娓Fp$+A JT6#v@kuBԩYRXuCA;Ъak}:%V"ai˗=\; ޟGo:BGS0 #,0Flڦba$u| jZodvœp]ӷ7YkX;Q;[k42I.h8_naQ ih |޹Tg reʭBbTv8w _&5T_M6ii`r 5b1YVE`\g)3΃_pz{LLH+#Ð 'mz!H%ֶ;-+a`d,aft*h(g*UMo#d?&oK@hlҌb EQbmoMDc~X E)Cz:4 J :XVO}C'rb.~0*I67A=gN$:+)&2jRRYu_O5VhEi6?P~MC]yGD:%`c^WmD>q׍pgQ8 bCju Pa ('؛IbT= 077aSU)H__d9}mzLj4Cy@2Q֣3- bYBmb!ƚa|h.PC ˘}d06t{*7ەcttnS[6RX s| T=_9lPx…LlL #feyR8jؚT1`mJ:٢>:Cl^!9v^!Jn]WK3u#,>N1H:;z2 ?Q;q`$#v㗷)H8R\#_͊'0|sꪳSd0UXS}~Cܐ۾K, pi3{sANj &`~  uY|+Je% Nȴ6ȹjzuR%^=$Hi&ʄ@S:V.-KGPI`/NM: `|\޼K5̟w{{'96tX"L]1~me.;Fτmvǭ Ə[t>fmXi\deա,~HfM(Ý떥i9^ .!IOB0yP!S/v,6-;J ZHA>{Ui{g$tjjN cz=B20R2ŏ0XCLE3x.dRkKD!ݣ}e*o06E9e/z2 H hXH~'y%FbkXe(&"A J PvrcP/!N9^X:Fy3\lA6RYLO^:]"C^2) ?lk$p_Q=G:9?Y~UJCBD2Q"WEY۴pmcmJ,hSr3ɌYQ8'[3]9! ˬRR  } ,hB")M%)ܱ^Q yD#[s|IplfЩ/Pa7O^Φl~ICYǯoU{D0-Se1Y)@>W%0륞}+ q﫣AtF0Ɠ+lנ9[k)0qq@1 f>X,;&#* h2RBz d$E:F Ƥ˵ Y=4aF.FH ~&y-m^k FY3p=pI>J,%33{g1'; . yS> }cqV`RuOo;#DQ`S1!#λAK(w hb7(K?PL@4e9.>PwI%{q&&4p*7^/y)b3W^#k ,tHP_KFj)/@5A; $)SAH羏Qs&> Y6}9[&USwu>@Y&Xdd7ىzjý'Ѣ XE=#YT1YdǷg\/y9UrIY JS(~?P+Q7pseO0 8=&?nFMnRSIҧܞzZk\O=t^Qi/Zl o_6xLKPlB q_X1]%bi8@=S?}gE\s芓NpqQϋ#U{|fưh<4%[h&5d#ppkؐOlPa=ɞy} AlBă/"f tDx JδةWc"q`_?J^=7@RѸY*t5dn{Epٛkz#x->܌G.+uCA~x+qg . M nKo5d Z@_+`eId*"J:csMa4,@8TӍ?bNU=܂,Sj7^;;!#s= ꥧ UE ?x x-la^;/'o!h{'jŁ nu#-8ơZU_ "5vjpuCn&wPMSUƼ)>:Qbٚr{G+G']e&l;y{&9 0W4I yl5(4H)q04RMRϣj~Ŧ6B?`8胃2ak]XGog~wl[oxZt"$je}PQU0$Ru.~6,Oꊖr;3[139wfܿ=1CE fVYK톘vƩ"x59z+L%N C~-s}|ku@`op)]H(}JJm^M1uA(Ү9oM±[=Q}N$OOZ-Mou rf[BXa1&zj|bW5镲r޳B?WT+.LD͗wnKpYJU16g2٢ҰL1v 7Ϧ XM\K;O)]`'f)ž^uum-Bi/ ]lH@oWXKWܚpnݐFl40`X6REl /Dd;NWZI>Ej!7׍7"c1[b2es;^~afW5nXnhK &k s~z\GaLL@b'hW: 5晷%@F4;C9=Ěo/Jp`/v{S@ ¤L,YV?>% }wy|ج{[nfxтBūC$u]"z@wL?l׻;1{ꙛ]ĺ?Ki>^)D7ykC~Tm:ǣ}9N`rjRחyg6dW=/ z-R_^K?8`0C:RFaFZpP_MT ͍ǝCkNJCvՐ׾BeS?,NY@mDt .gr}hgFsmdJ[)k* pɬG:!lW?-ao{Iea UMagrtCw@w y̛g]ϸ GO:u@P1@NH'2 OVI+tV}NgRr-t뭪Mm՞,d|=_gVufhWZ48Rs4 r#'J2m{=9->-lU- !d+|nXʊeX&/C@'|CD|/co0A70tPfhq==W;=k"sCzoa˳IAl*[62}*1Vqj(۞4eX$ 8{V0dRL$ΙB/C7JTL{Ȣ5P/-#@{lY#bg1Utl\q<]Hz0sD,صuBQݖBV̽YF*<ZLgU./7o_h,G07vz8u4i+)=\h Fݸd+f~97DzXyTQ)k?RLR\jMt{.v_&#hVZ2 "no.WĢuu=UL!>62s0EoŴ,5V[P.3&Tz`Shdzt/#-l5R{v4.Ivw%[Aͽ"3Y<?VLAQ-aj+߾cYgJ(룃ցFt2SG}_C5ԛ 2}(R:Ь6#Ó;+^nm? ߞT0pr}\8o]oTцkT,ɽcgO91) "y)B\@ynlZ]hr:㬚L\C1+gt'Ǟf6ZBn 0Z z1%8_Sv ٫jkfXM鉪~pSOJ蚪ENjeƯX9C)pAld8e1|֪ nﰴ0%9܍OwF-R6ЎݽXݒbu햒Q7 Φ/uz;S?"cQNƌ'[u.,g*b,M\esKPQHў3GlˠKY5㱶؀VŅWh0{@wջF0֫!t p~E4k[I nPGHDi%©XR` GfEURٽ0s+U ygGX_Ė6K7h5QO :$K8欟e^Y#LRJ;v zQmVں LQg$^.UG#U?T؆4\zqFѯw,Egc.>7J GÝR刺E' kHXڠ!raUg&W⠁鋇o)AaOFxykQUI×U&XCc霌y5M\<.PaMX.k.543C>@O`%@{]%a?72 vÕt nnLn`84E+L"y6 uU'#]~zQUodB .% ZZ&sq׀8cYwFl~Xᱺ0h(^v)+Or˪T^V(c>ͮopËe>l[-~lmB:-kbvHvI1@P5~{`+| ϣ}?й?/ua?kU;l\B?#}n?d7'n0_ ~!׊9`ou8V>7)P:1SY9׃05{6eIMޙjH]|$sO}:GpM~:4W?Aд~;?a ɛH-7dQEUYZg+VUo?j`5p"b9t-]-biX.!WnE)OG@9J4`{OZz۟`{sazhFp̮+@%vG⥚ aD"4l@=E4ک;,*M(S5@ޜѸ{zCiurQsUEW Ŕ=?1L~!ۊ-V[ŝg #q?6ЖZ7t )80;cov_}b,v6S8*Q{!Bg p `zaw<2}P&Q=m@2{cxZ<{:ULo{1QR*+դ'Xw@<*4 k*C_PE/ #Vc7J,K<~-e%\,Sh/Ry ![iJ*DVHbdFd=nX3 ehuZ9 ذ $?mnY;- n U ĥ^sH - F,|EY <=[}5XS \YRC4NtZ!OwHsf4X S)I{er ; Ao4\0,tϖ_cӄ|N$ iDF~ZFt;9qfXrQD.TvS$)g- >܇b=]i|aCDHU vt~~F}?;`~BՎ[5k6sA}Ė1(TH,/,aH{k频hjSxro4bY1rzxb6 Wm1kuFsZUjc  R7HHЉ$VWoGT{s_9>J:H Krz uojå̈́/=}oH3O#2FȯA⭰oc.21ଷtNs$,?]mHEQŤMɱTXiĤj*h_ĿF?B,tU0YLb95UCUQO$=x@Qk)/t)դy, qb=;2PJeSN01eH)=k5^дfwBqDpW!|_! "EmQemz,WIa67@WBtsؔp)wq|D`UJN '5PZli@?fCP nIE0]:*a(ͮ Ct>'ִBD\^<+mY~'-)\G;HȔIL HRHO= cxǶE%g!ڻi2- ȧ2ba7;z oռ !M_Mڪ9@=Meѣh@ eY2bw^,(F9],nrdpjZR$Z 27S ToӮjTpURYobg~ܶ:4gv/J[5k :s~kZ<9 rC #; ${G.xR-UmhtL]H2Ec0jN7'6"=xxD]U`Dt<ւ`ãHtީzG) 4TP ~R2ZfgY|A7"xF'1֥'g޴_2z=si-m㫒eZL~ DTT%Gh2ʑvEU'( DxW2;*t c,]oEtJrm)Ղz{z:U;+Ab>LÓclӓKӖP>W jK5eph93T'ĸOɞu?+(sP\?C_y%p$!52{G3``;0"oVGqG^eOBceE:aBPyVA͈݆.hϤآ LXyZS }|gUPr/8Ѭvb@Mz>x+.?;CQ-Ɇ.gv;U֤ "-?_|hV.`Eł:!臭N^''MEev".bXJ<[Ud \Q'j ܌o797[&/ti-^$b2Y'`u [qM1&@aG-3̂\g[mۭCE{ M( vxs:Q1f|NjVhdRT 96L:1@u4%^->Hxظ; ա+|L`m6}<]lGv'.Îx41o.l4MK &]h/GQ't㈲ 5L 2IK${F7JTc6wYg]l.sAg.R,.9#<uz15|saIqI@~vcܓg<೴[Ǥ*c M۟ 69Эg9SY6=26LV&mF%Ѕ$,:24UgzVEo g=@LAmeX7WI-Eď]݊ASr9JeN$~ 8uGGIH*8 ~:$[qC{}=ʳrIj M+ve,ף~LlܟȜhoKazr6i O4a0X'gK'].;jfܳX Ü՛ei9VL1E4n"N1),t9]k1r+ǝ3.00$qD}Mq%Ʀ[EC0kA٥]m`\7{R /~35g;#>Nd,xz%۝@kƏ7M{A<9vĮK\]k2Zsb2HK%󰌥ez*@J CT]5: %[UVW+2Rt(/y?,;9{_^6˰&T }?͡ ۼȺ U.{"j4OoϿjdgJhxP*q/Vk{24sI NSQ4b]StE'D dY'k C,ZXuge;PXd;`/J A'QQ? :gUqJh_qr;7z{O:NmtjY!,]F|y=\O }˛|r_"suLXj `X8ÁGuԳ5%@O`Ĩ,6H}t*^D b#,pfܮdy]׌:x`3Y Dzf+ Υ`27?=E`;a%i6)pD3b Jg׹Bf~XLuOF2'r>c{o#3*œ̸A./ /cI,|vE/:{e//|T[tV7`eQ TcLV9 & g(PqRhb~Rf\1_FI4H$Yh,]PgB"T7Bl\L5L ,(쑬\UDH>E%tMwR=1P jV0UFi$T0Jc]E^UMr{ yY(jӣl [ȁW}Z\UJx9m |||ۜkI69fj2ӡNB#*f݈!Foވrdp4Bi I#RF`3$ ,f5W}҆;(f&1WjШ 1d0\Dbqkgg9NݼR\C#?̞޿㒑l^DFbL=Ȯ5w<+{x,r#>ouT6]䍍Z@ =}+P۩>YCW&qo!ч3L?CJR 1eFb@F2 BHFB & 䱎0΃rM6K\giOGň7RD~fio[GSSP!.cEJ"7&jNq`3#ui+<ۘ+`'zRIu: &N7>b^2(5E$v$%a#ϸ"tOߨcF,VUw#yimoz?Pa~1J4^gj{(Q$35r3w-ϓ\/%'7j*@_Hy"Z<‹(ޛ>^Ȫ3U;??yL=5 [36I]wߑȔNȦCKp[DzMW6qaw/P*6^PDZ?7  i ,fos#D 3s4dr"`!k)2I/S{qKFϢ…Y "/ڗ(1g!c\ZĄ}®!`Zcj/ի2R-2,0ecsw^+||v}P_mlSOwlu(-zshv *yŗQ*lYx 02bdP?)f}~Mv? !CgVp|1.p i_?`R|]-S; 䮎3mMfލ-p>t >~f`l_,S 3 cqBy)S b9x6"!A,Ж3邗Y ˄UONuEu󁥟Rd# u~bfŬ+:w&O úX6{OO? eLoSˤezdZC]sC4쌧 b1>7ȩltS;>a{9f24Km] T0hՄoQcȺuPfnҳu_h0 . tpA9 a0sUl ~\^IV=UK:N]JzX~ɉe]a&FlpqGLITDž,_jMԨTll:S"J(.B1=`<@ tHjiyֱךљeٗD98 6Ҷ&O79>es`K:Ӥ tp,I eU ;{n][F-<Řf du5׬Pׄ1!hebjt%HY$d< _`N(Z`b\]=@YkxSwa#&h!\ξ9bVLpmo}~AL `cZA$-#_AԂ%,Gpث9gEf6xZخc8K}~9{_woo0P_p<ƽ<qd.ȴyXS zbVǜ% ?@Ds|(LUzzÏޓb S'<`t1|X'ɓ3?7>*s|6鈿m|۠=g(GpI1$ۀkqs_Ww(mLϘ3pgTG$Y%[@!t`v$ih oL'85lQL iݙnU]3йûRi˓=f|) S1`'Jz#]0`p mt HԐԿ{A'Zz%cn&VP q`ǯȜqمM(KLɕ*'|^KdT3/̈́5sRLu;6"7tzy&!O=nFe\jS>ML6* LxB,c '1llz2 } m֦1Kf=!}e6JzLY͇tٟy.=X< +OkϦud&l⢳@NgOxJM*-->#d?N{)Ud&=(z&k]ԇ]NF) (1O;:嫲8A2|ڻ5W"b8-@ ;4ү:Z#14-LTqjvI;na&gʹ{c[T)xXn5ɧ LFa[~. ae2J+'E^H>2%9(Ϩm j0c)mE&050?8zaKNZMյzSyȪUd SHּ]MX5,a{%Y:f8 S6VpZok e}Bx~0gïjvI ̿K&p_3g>GV#zɿ-{̾1Hи%IY! 3-6T ) fqdi'^ %hgǶ-VyrɊED)|ڸjpńrథYQTg-0z#v ]tQ@e^|!>`TjEA_C^J#%=9 ^'?0]kJ!tbh© R7TRZyLmA'K"6rՋ@Q[N9nYlUͮ &8߄ DEkq@2SRL-콿yI==W&D(~ApTfƺ=h Es٪DjEQwtż9f4-C1=zZF[q(\vAKF#/48CNzbt~ `>&{(%%*\óY.Tyx wqR*|y+wSPԱNxJ-'N!;X AOl$14;j3'q#^rY3|3g楴~&tB'4u3ʢ#Lj)\SR;& PB˿H%:+R aV m-gRgٯ`<ӹ}LO8y)͟E4e!F_c=I&mchUs̴Pm8p{Sjurud8_KE s""C $%%; t&7`Ej3{ONJk*W? [;GtN Oa\Ml#,YݎXl},w ؐeضK5 `@˄2ӛ)/NnW7Ћ Gs#+, K71EmD'5yw*;Y!1P\krud fGީ"I'JzGf8)ᠠM~uHQ Dup*w E/OgrNyC*%IbːjJ[ބE2S>4߱A%B( ?0ILy@1^L8H(LQ:oRQ\vպxy[dQ Y5,|9p$;A+9.%&>عDJY8s҅ 7aOmZ`jiQ}t,_>gW>S"շf9p1>Pߧ@X|=$CcTC =zR .QUS! ".osjf!Z#l*p=e UhBg:{W?*eFrpxHO!?:5#{GS'e0:z}QҟgذWO졽f4  O p˕#I\T i~]hEg|u;"d`P`DeЈYpbLҤH [Q0\Oxm+$wDM5O)iY3;546XfDgJɮG 82PuO]g3"*Q%3fJse +7a) ")u&Wbk.<>VBYۻ!G\ \ ¿{P{5Qr{x'1YѬ焝*F"X6*%Xk)eʭQ7ڋ-\5& 0 WK)GZ[klʂ]6: d?c:7DA֘7d.J -OӚau/s ?Z I%Tn!W~,a&P)\0z=& @QQI){[o e $Qbr~2VC>n%˰;Iw.2^bz]xWg]!:l!Ugyk; k6,x#'u "1,:"&*nlHT'bd6 ޮ>1ѝ gZ,>]:U P C[oҀdǂ'ƚYz yŤisb&8Gk2 u8p4qjPDW>'I6![Ni#h&~-5BZ;G;`irI }ݛ [~.h/+`,%QN P\mM $18 ךHp@1BTF`o–X.,PB:gH_YY&C\ Б^aItrj-lq8q%f8 ognwgBB(+*4n;WC .o2ztzLa\LG;rwk.c$@2tLwa@"-/{jPl ""|/|@QZ|0h7(@L>s?'Xō.JBbj:Q$ajfdbZpOj4fy^,7:zB]7{ƃdIVAF1POĦ "tѤ+cu,kl1c\+^x ]dO^\ûݍ᥄d :Q dGr'-fZOeXQ@̦9٠mjN' ކE*1j#L_`Et>LIQOcz7 HH&Yߓjq-{d L&s͓##Xڬ?Ӗbt !X͞'9;f#CB 4UlL$  ^Ӡ4BYӣ?/[>{/v(OY"WLYcܵ:+bgvYnUƕZ@M i7^S 0'yg_Jt."< o+ˁ16e).o4@ 3pA9*ӲN @pADx|E"Ʒh 'ɤ(΋Oo ek;[~M`ʙwf5`,K5g5 b+2 dI*8\y77yYж&Vׁ'\Wkrzړj}n?* cClvqh,@839$ٟO:k]fm  v5}G9L0?&vS"޵p͞N*M/M'X&f'"фJٍLjyqSfBpV<۠,o Aӳw*:ױ=q ow #;c![qPr=3gb0ز$[k6yegekw,=>\z&E@o] C1lq38hmK/q~U땇'Y6Sp0AnV)*Xk% oNo\£2Lٔ\ %,҉&~40f"GjsGAf#`Z*V\ӟ3\EAvr4 #k|A`w 2 : "@Z `@7|,&-ʤ17&S|CCʕI׌6f=%b" >+[aojECfnmU)](dK ”oa" 9P /%!Ů+_QYIs66vR%$f 鞻Χ:G]]h?&lE|?tVE7Ipe-h[Т6vPlA*!#*3?,b/@OJkEaܥɻ L|ak%!w-U. k˪}1QƮ.;92!YO!FKjd03s[_.qPF!B,[G[F/,(]alՋgEg4'C}.6\W.n\dgluL|)z?vXh#=9 ~EOnC&`v  Ԝ4N/p_#h/^qL.O0򃏑Lŋ  c4Hh?#nop掳ύa)J8$; |kflCFݽ)Ҥ2|MrbJQdx"OI":g.#Q#g7%ýw.P%5O¨3fdHH}T @Om]釪ZE7@`X8xE+ٗ I9ǎߔ8ain"p6 {yqXǕ -ֵp?3UuxM8pLKqsD^AC+40p˳ ˆQPg?ZvB4՛'S<­wH^fb$?ט (z<(&0iKN݄!ӗ"j&SOc'e5~IeexJca[k8M$PcD+O᧬Yꤤ鮑C|U9ϨǂmUvD=_RJw|%Ɇ@^{5WQw7]a0Fdxu/J$vN3wn TSA ./k6ίck˂&ZVbae5w:+s{Z[zh ' 5f /c@SK-.”}jUw" Yv5MZdpZ\a]@zVoB+K{$V&T3Q= ZcT!)m|Q6#ڇ ~Hѭ}Ppp8bL.вU*RVN̈1#<$m@/4 ׾GGØ sL%߆=^tV=t?=rl[&xΝmt'Ѓ|i֠h( S_ Ά0q!JNӋ'ҾR4ÓuRP9\)! IutFIBoqgw`=P'KmwO7{GMB.7REuuWn3J/ !Bt̠b4!.2Dtsb;1`$rǗͦJfK=T*W*ec+)!pDV+qj7fKRIO?.ITSib5`ШĆxs(_CxؙQu󧡕NJ` ٯJ^.mV3Ca$S.k9A-Ĕ_c$/ DP0~rP=~ BC Yhg6myy5y(NWO~ylL`VՄq+Sk65$.!ECz@IOH@3ܦ-0{qEr1ԻtGl(iF,lmecQ7;U[-z讷{4F8Z9bZ%Iv聟֤*7tz80eK@Urr8FI:6ͨsFxT ncz,'޾ۋE\Ξj$CLrNjq\͋3"P,dq6Kë|)$)^[Q3 [{bG#vהT#ED:bLKNٙB!#!릠s֞/T3HHUCr22%7dIq??.ZoAuW`{qwJn(rAd%= F|3f*0_~2OB:szzi>Ec#Ap/Vi\;kmK2L}.zOHa8*v;sLL-D3 L)>ki0TcRC]7%4c_C[ܕk oMzp3ZG:u2.űgq[ʘܷa(3N)7khBɝ&Ӷtqa6tpVp D/v..ĈOeb}0JV Y(oq^@lA1Y^=*;24g? &/d|Lj0O۱mȡF~WbUjO6oxSf:#oζ_Zfr?Vz7厇!rf`9ï5GgY_duYIdlc)U0*ᅳ>tϊ =i  ; %̩T ]^` vheUʔ2S[U[.MLNCaK)T[9޺: 'm*|2 W1ݩRp58>^z v nIu.R*d=^q6mp^4sO=s?W-#I6k Q}pp%,ى0GY]y}]'cyw?\XamhQ';-m?^ 17`#UP&ዜF"ûIŬvڒ"Pz-%A/_?&oj?나Ws5H"/ Q\RWDc&9Qt&zGqXm@^ rhh`"۱մgTe t'Լ(ZƲuG}S~I@n!UImmԜ i1]zkn_>.1_31`P풧CS S{EuUu .5{ɺo(V8kyPK;sb%|^"삸r|\Sj"D3sH)'W4|fln4!Q>, $zd!χ4I>4_BEݒ"7YYLߢZV(s}gUOPFCVmI"$+@X1eWҞż6A;ơ)׬QJ"<ˇ6= qmU8gz۲q$MFƯamqk{k̤z1bf7N5[RR鎚+\21˜zTSy>yP҂cm+^REUurX054ʺN<& ozd!ei5id "M,u~{d/)ϩv dGl]>wN8ȴU&IWV!^Li94W<ͷ%gA_̨Hdc_1W+_&ʐ%_U}lCb>#/=Н^c$utXcSbçsQFXPg8wk-Zk@ڞd[d~m=;:zi^-;P Ǎ_z՝ǟ<.՞/YR8e`4Ct40: `rj~xAA;?Cy*$jk#.8@v}1]Kد [JZ# #D2>&Nˤ(оÖx&ɀЧ@rknGء1zB|Nc;ES ؛w<3y펎/ZKx $Ϻ4 ƒ>Moac3n F~S/3AfUbꅃ-ڸŗGoj^F\[Rp#>L :i},Jb+pp/O?ʔ*Izz(`w9u[ sJaуG?f|' 'N UB\RY[;Fb-(j(Ig`צUfs9mj@|`;Ә`lrrhel#]CQpCWHNl< q,N'{$6ybdTnx^l,(d&b?VzCBT7 Iw*Ao"NXjh]g ,L;ql^sLڡ; ϛY&/>чNX1 +t+I/,-W}T_W4F ih3}3h:T U\^_}I> 7ۉӣԭFoG'8s vsE3Hg{,:6Thi.{豍 Q%o;I%\u2y,挔Md/jPW|3Owz$R +@>z`FH7UĕUuӜcܖ-,5H8`;ih C LIħGם='P)g}Oe%sݎ1.M=bF?O (í:8)&n?\UGXBis]p368f1u4낛heU75.Ax[cn}iG;ԩ~YF{g}BFQvqԸ4Lsfcw-0Lń|vun-_ۏCil 7AMFS퀤|&qjpg=ƹnv %eD;A$.5QZPziy<-:*iH _IqЗM,C% p; e[|%&OVXN:p/ 1s2Pl ʺtbՀ. RJ^ý ]|N0NӇWp:ra#ȡr4Dz HϬz 4/('p\ڠoQ xi޿7VdPoD}WA)7/g[3Q@z=='s)5|.yr)bfG{$tZH;TsMŽ)eR夆͠rp,ZE<UNX %bJk%,0EYڵ]} 'P7b: Rer!0Es1nbq B"&u>As? vpS'0ҴbG~оPeiP>*A-BUi oq㝠Mf^Ә{lBgbZ|P&FDf. v N8R[WKΧz cӺj3"Nu陂f)i>Pb֦1. A0p>R1>=VUa J 00] $%$շgݾPĶࠢk6MkM#[ы65йK;ʉ`q, 3n`2u vV412}+7=Lx {O!J߃޶e>0y׆7X$wP\[Q֔f,A6KJ']ߧP/"d8?aZ,]ƌo<*{4` ;=1+$uaur|ke8ܞd=2o ZJs>PR_>N.D }njݫ"{5J+ԣŧ19;{NU%U`b÷oEW,;;%&·>=d=v@.| #c l u'O(izo|ZCl,lͯڡ8O6a.{8<`z&`)!]b"o}CŠ,̗ye}zgq *ᇾi;F_+9x44!bX})W.зh њ:liŁY4kq!Qhm瀞g:H%E58@ w̭Y Ŗ=4J"Q}Ti-vvcKX"7j UIӊ %nH6~5& vx`ӹg !Ec c# "A򄫿 )g@$ClGcޞc9l1u#uv'$_0HGqSng262vQ3<Uso5; UTnL̂ؼ"uĊ@ }p ؈#5)75{!V!x~`G#.ə, +">c;$MGeU ]TOR]CƩV9b!.ݦ7I.[ W><ފmv1tX էDP) ʧUvJ!X|L=ba4Vo`u܄iwP)}UYCJ(a ,M~gdqc/w<瀿ZI~],[6)FǦ`b ~y)mpBG>[‹ús1asG(\gu:|gVApB0"d)-V ^P-d(9P8 $:Pg郗|\|JͶLSU6F~_No=]sJ=桼9=:(9xwn$h6z]RvvѸL\Iٓ;`ġeaȋ ޣ4}Yp6 !3s#"'һdyŮA4Z*<=X `(2}{i Rime _ +C/F1BjX%5 yMvPL9\}:N$lQkK$<3^7ܳ2Ubl7*PM;SuCI-HgҔGrkʨ;uzIOŊdd7W<ZƑݳdy76Nt"3L$(zEQA}tuo_0a@OJ3g3 ݥY8f 74Q>5FUνhpHIbKTqXq6ꆁ rQya#iMw㎋Ÿ&%3B=y~ӿ dT4' 8*^+%,_BufnEnߍwR8?g(-~7nk4ulVhn]Ճ~ɦD㻫vb)qf9On}[Q([ ;vD  ^6NR.]NT?yK˭;/}PX[cpS1Ūe*$^ 3.7>U(J@y'!հebu`&گKr٫rLFh=!^: ,v 9Ȯb咧/-#K2޶Uv_[vC35*t Dt8yi& ES/M9E' ؉Dڷ 5̏6ǣ *=a&(ڛmI@4ڳ#JnydD {ޮ0`:}$ķ[IL~ڲucw|} 1#zGkŶG>;6φooO$ MXMO`# eip|Mxt6$I+|]vbjD[Py6h5agȇ(&2Ls:l(2eUɞ-IڝK?ÿrgBK~q}C,>/)iySrC=v1Xn6V5QdYtq Պn9X/%~1^-n:908B7b)|7xJZubr6k( / *VZyBd{zOrA,^dv >c X W^$s8ZHT0xO _;9zhc),rr)zZmȿwf:(V|[{> 9\FR{I TGPV0Qٌ5P&|`oLcQ^RV/B-{*jLJ;,a+ 8{ `_2GwX^n˝tR<؊ /-#/rKog4YI;Rh }B\K ]S7@Ԫn#6I'L>ע.98mۣ V4vyJߎ.]{qI^uۘlإR|3/3O 2WqFq ~#S) jf"<5 ,J88,v s}u>rɌ#4fãٔ #x94HvNakمn0wE{u(sgˮKkLk2#׌ nBiSzOaq ǷT;QXzS95ۓ竓E[^oHv|}{10ج/#s.,ӄmPwkn/ؓ 5$|t?VpM0@~P,Y7{OtC;4PRW._ QiO>pԠK6Fo*/ h4PDt"wŮPI& M@JQo]EKR'L7e%BNw |98<$-`tp@$Zc3ZYtݚm jMe8mM&_N(& dx,(#`p){XcEp9Ti$W)XNV! D` ~+EPhYWdZtJsov sf ,->bQ:L^5 +(˚~/nT9|_wwaWR@-Ąx~ŅSG+4 |&?fԳ}ᜢ < iDW/D ]wv TMy#~!u8^r_ ) sD 3m%lavPȰ|#<س wֺU&a8އ >ڲ+R@/0:@]G"!&6Zkk1[kѳBybo*ߌUļOlSjvHhi|ԴfEq1,꼰0kJ$YϭTXakOB]k˹`ccvcJL+eo+s,2CQn$XϮoӏ=\^u"6QǨм⍒LEˆ IDv}މCQr7dF4#ٟ5?kn~G:G!%$'-7bS-c.tɶLDҞgn1s0>|S16f\FۚE[O{ǕuQ&}d~° oOlԸ R6OVM-1(m㴞\~jT!ը_*HoE4p=eIeCD,tG],- 1"[Mspcq6Fn=)06L ]N(Iϐ̼) Ա O~e7R9zYdZ`(j^j6B\+JSogG))Kt;6:}ޖ @rwO0`:S]"8]k7-B,iar#U,";m_W\[/O0Wt׉uωcoE\xEܣ%!"9UU74|brZ=['V`[u̖҇R a2 aWt|>9𴋴To">VOZ&#Q7<!IQeE ,d?t;i,kIGk[ R$;AkdB;EnUU2}96Sqx㊄TJF5X!#u RQ9*5g)`izؗN|fא`yX&8) /" R FhG\\jtkA4Aio;Ȋi]iXT9._vXΗ]h-OG%"z+pALi=NyuI\}}&_0(<ڨ͂7]nz."s[jT M)Y:Qžʬx\se٨J5 YAm{m4MS?B]4\Bd(Jc ʇU~_5,+{ ]{)\rF0+KV1tMrk$.~@nh]{Fy&.LL'6s}!&>xoC4w$%{zZeڥإpM'[* CnfjPB@3ֵz*Eۅ}ʷx޿.hpѻ\:t m];W:=ok lybo=gL7yV[L1H??@L^_TMך]} micVBuisI-HY}d9H6 ٨7`uܱoa 6ٳM"XC\S_@9p t/ 8`6 e߾W,~H?-1wXznTPֱi͌9 2k{p,Cނ^rjPoP&pnIBaqj*̇RnXk5Ӏ"#VRƦ5 {^Rp$ e1LB4gN,FO)(,xaiLL8U%[6eոvG8K T|9wk#4BZ)v6bOyR/dP"^X=! TgZN TxdcQpd ^ Ȋvm}6sL{Ј@t˝`6᭐3Q LxhaiL'V3[g)x@O:ECHG ,_/m'EXRֽd^/xGjɣs`BoT+V o\  Yᄧ"G$ •SD~ >B7װׂzӳa!ouL d >,=ẙp/9)2D"/<ҀfYHII?#IX"N R1j˧}\p7ǂ%VͫT4f}N}-gc0؁rN8hX0zlND^`5~rDpE_d+2+čIu6 ?^ #K=YGH*uݴE&8q^ˌĿlzF"2:=?jbN|M4>ZPFv K9Fs)/ o9Zj`QgjXܫ ieLT+3S<2N/A/I; ,\s [Γ^y|g~h|EQe #gX-[m]3wFr7,:9[ Gl{~'X#%Z 8?Epϳj v\Gi{.G)zD)a  zb,%_\D@#c}K}oNwڄ~xCU] 3o{¬pZ܋ؐ=j&oS/Ѩǟw 'c^l}7yO(!5=ܝ \/[cD(4m箴!uP :ӻ}akRS/QT"M`  @EuvUD?fxxf ʗپ&aJjs(4Aԩc nwH!%t}smad1@Яuhr' gJp |fpiAIPۻ+%[=09Rp}LV̔7/((eHܝ $I b'縰pp!Fw<Ɗ%f`BF@ihtQ0@kPzdJo+f-=C8 3.`<nԒk B.mP #>?&+>,dڻ2g)V9cdgO-<6?ޠ+:x!ͥۍ-c(1{|[hMď 3h*:'eEԝm[)ASr z>u)$y>h$h:4LKl}Vc=8(ny5R]_=3t[[MZW[h%<8/1KdgH;")LSDVv\#oֳC C2.f~n55l\:su]961VI'/#cΤ+xRZ* 68?fMA "T޸6ijDdM<dy`7,N!" G%zj@l#6L-.YGJyAr(!R9ŅCHM W--H;LI\^u17MT pZ޼1\Y{i"P&&dF`%,HeÉFƇm[{K_"ԅXkW__ؠq r7t@CW bM 8- bkogђ; `iTFDQAu?AI<" *sO)̿feL,3;)@Rp[gg8ѻ]v/1!(etxXa] !)>_[x@K8S9fUV0(I5ǶKIzZ`UE8x) FsнZb"]'\ucG?IN n9̻'SM*TxKjŁ# P ^8?}5B88'qRCooxZy< v^ ya9BP(<fbQ8Renj :@4L4M[s)\M;?Q3% NJЪ~VvƏt z>F[]r{GJ@y( l!g2 rS<{Evtn:ie9Mقrh{J̉NMqQ5zPĈ8M" KɹB:u#EhL(!]´$Q>(QetT!*B@MiE }u]rvUcqR/ueQrk*_8\WS>8z $fXޕ3YeRK)M1eL>McXfxN˷ M0$'m_)dsMDS!Vh!B|ffzcK2fқ~QPΐ#.x\f" oIvYVQ ?6(Xh~ѧ_Z#3MWI= j-hfֱ*6 gKq)<%@idT;^ $;r~s 7ahGB@ԉ&\1atvd/y%6[wq%O_tmn@JhƐ '>Xz7E:$k!=W<T}v$> 'KI>kIMD\0ڐwaJ78TGP,;!?2 0B^%@ԤwF2؎tC|O|¬0:WhkZPg[5HlOC[k4ﰠa鈹>B`ľ8~Ǐ5YHL(f{ U8 o6s"d 1,{]h]yH#奠8FВljLeA[IM/5WUʵ['cR6cnvtp ;VnYFg ,iߛJ},$<şM+Bi0pE5z-'SẂ@ߛI?PQ[Y8 m$FQF&nEf߸.g (MA!E*f-IOdǢ# jl N z吔ZOmz}xEQBڏtW0z{fI}?) m~KjY,e1U6(G C*"7ř >|}nHM4:$0`Ә{ 34$>w>A0#y".;mQ@Ė $CkY2h3~в7V_H!6bJ/"fmB2M*4³0n<u4KKU+`L5liZxJ'44U ?6-Zr^f-}1W#`_(:$ԝ|F?oslHE)I=/U.'R&&o EܸˁLT!Ͱ2W_rDׯ~16U]I)~`Ӫz'q8(.3<JU/e!ÞGWmV\ޟ<舃i1ޤ('zYb$ajdi9{ȼ v Lش?- 2XNMpb6vgY-@T+|xY}0*Z/  X&KxZ$RJFytqmN&ǯUn$Iv & D!(Ƃ||PS6 BsƢ.UY ېv@zq|N3 R3zπIs0̽AF4eXGm, 11+ʝ1DmN{)A4/Xڼ]{=_mr~݁vNEޑ~Y ?(4E\ Q24HhwC*{!kDi s5XpU _%|aTm.G80 /*5Eu;F<G/zxl7çbtWB1-Sr{ 8zTWZ>?5kޛ^w7>!tŔ(1Ϊ}fexi@ouPFJ6CmȣhqȒ}&9JmPAlIfbg'a{ ;["TW <YMH/iCvwr_Fa &1PW&Tp0D@Equmwe6P]d|goix 3~iLYh{7=O^XH frprbEWБrZ^WOKϹPL#Lf| !Ƽ6P(F @(붓$)k 5|d'~蔘 qڨ*Qr,G6cicYWdǥ"dDžj mbњdj/.ɘ{D՞R/} >ǞCV Z҈۲.s]L LX5ڙ8 ;zr#{Mւ:Ñ/y]*|Q-@ÃDz'*yChUʋKW0 )=8FJ4QFYbfx1(uU4(cBVo䌞Ul)-L7?XÕ )˂SBTCA?:_x×W f}@xj+in* qX˧M*\щ^byInte@d%;}̀I:G6$Պv(.눪I礠Rfűv ``UyfJL 1RCCr#д<[79&# .BO})v7Xt`,/Hi#e^8mLpbw̧3W_W-:ۣ7-mmqErhlc&'$*}Q˽wX7~$tijQKHX隡JNcFZrLݚ@Cj *k*(h:.c>aϻYb!vүqp3$oF\!64oΐY]f _n3woJ`@2Щ@U[A 7KpA2]1<OF(t ?$_vxO_̞Xg-Ev&S"ohVVJjH6ce$kgzsˤ7m4&Ajiҙ<[ K탬"ٽ7,67q Dxf҇dx"NT'tlH@L<&(xøA9.+wEsO|i!9!oE@+ @Il[k |Vg<:BTǹ zye<7; gZ5kOƕϜj[vC bFj'`nQ4JkmVU@BZm@^VEsAФE3n8zJt=Eb^UFkKC먃0yMDKF7C 6IԾDcWoٻȧQf1 d4jf'pv~ZO(R wڬUC, Y꼌:؋ lj[!8|VK6Lf57jQj$;GҚ-FS7Pjy\azico 9c ~$VIƤ%ɝнёL6lЕ0]lI ]x#XիL4=h^=-`7UL9Ol.\(AF. a<c8gDoCs_bK=!tN#(R.Ps%L!x3Vơq^2LK80JS ea~j]nDKs0N`A@Bjt]d"S{oE6(>ÞRoG,J?&q:ʹ0eMPqz|#[z[u47Uht2"`kQ3E!JUPјzƫ>Clu;ӛV5{VHQL]O Kǥ$ (><T* 8BԣNkl]}雞0 sruKI4`9euxs4KU6cmHx2Q5Uw N꥘WsAastG'po%i^f0/RH5d\"헋_pȜh$=ޔqEFI>ou`YnגuNr#H6}4GO`)c(R} | ucfOo2Y) WꀭTFuM>쬴}ۚ|V|*X]XH-esG3Z"+en]@ߕ t~Bs4ޱC5n&Z$07SQ )_z|;2aE 5 ]7tR*\ D-AAAq )A-Fp+<-gFB1B.bDue}`H2Wc *)f²G7X`+so'Mvڝ{zqv|ʔӽn(f5V7急7Dx7/~Z>\}. f:“i?;{bHoԡ{`No'5T@.Z7gqc{օǡ7ڸ-'a| xUɟӓvjӮ#LO0zH[p!DhZrvd3qO#26vR3#=LL۷,D7D;&:*!.pI'%RGQ,5XiA#GX6AMd9$'X4Pm\2_1mS^yB[ZƤ|袺w"H'~# ahJ<3-XXA#-X0S4H1ugiRp8iҁ tj["}ڗj6ujM@sШ1woE{9UX+ۑ2hn::>L<5IV DډGo n ^0g5Ӥy;+n<0Ks4>X@}_-ڶ aˢ2Wfa?I`,w\YtAJgϝu='S NDk9 ϚրO+ߌa^,t:ϑy;!&>/ʈT c/'p6f8~(TC$BNڑnD Zt'.\)-Vw]i E+ٰƩG{aGpD?jPu_ ( (b21G}#jȪ.>/TN>iA;a zLnlxbEdPbů9 iy* ClnQl9= y*b5Cg f*yȄ6"Uƪ4Om27uL>̈ØЛ-(K^>LC `J e>Kx 4p,,$D1#k]6LLJdRl|-7Egx0'i{vA(*Y\\R㴭!B/{zea vvrros?Ϯ@\Ӡ47RƞO͝ηf2۝JSvND,a\Ho9s鈌o ;  ;f&]5#jJԞbYih, V+cmmǬDeGfZTbҠ]m0#WTTnc9P0;) &ρ\ExĘ^XgD(Hjqa\_2@j[mjUW/TZ%wNj51V L3kHt @vZFD\nYI.VcN)%+k>[`8UW ='fI]X綒Vy\7lMaiܿr <~oKhl#mAPM*3iǥajL!!ZoLwg^+Η:QGzWRNc՟6\g(q_(闖,#/T c_n' >f*9yn|":O"&a5kP?M@ɾE'ݾxt,jS׏7Uĺ|7nhQ#޷ b-$r6]lkJ'+*ʾ!߆]ckkVO._`L,7tc+vYZA:3ho:A6|q Gqtx,Dqi3l$ClRU^͆\>v@$舴MC:u{:T } Dπ[Fԕ*I}tB t޼\QaſL #Fa)DRс@Xd4[KKB 9;ܔ}`9 -) M )C~Y*,[."yknN̩O(q9DL/ L#/VsR0Wr ոO49Fē:s$ʏ:I=qCO71Tr,ұnXD|=$7t3so\PSxJk)>1g P栽)u<6|@Oe9>7^#k7Ij1hx?\]48r )aQU^丼 cEb/& n h&1^{ 5 `eq.)2]UQU9Q#P.E??RD5ڦcz['.@;bY G`s`VkK 2E3 Г;-Wɦe"!AF P~8C@u֖YSݖ=.NctP.\j1ݺ ; fj񓞚K,Ay)BGWS͋rHчÝzjӂxH=\8D؋,؏LJN+NH&sK<[Hb٩CGf 9T>Dgu ZM`Npy]sI17k 9k(ʞMF#o޵Drjm2_{dk- ,h@=\RZo <1Q\LOgFJi-F*RݡCƦ/+ qQ^<7y#+n>ʜZbk!7rf[ϊ0Ls#SE9 hĢ6r'UFϸU.hc~W6>S] (mӕo2o.~Sb\a*"#ohY k촯KrYcXI P99t5xk`fz!~*r d]e?2Ӛ˝(ĽF 5fѤτ?\kֺf̳Af]27/kzK/C`y<:<bg5SH9uX7{)djpL.F(‡OivC㷮݌!yT&i:(:-]ƐjMh>R9Ŋ eC^|7ܷfq+hЅ$\Vl>o߾ػ7}x|a0mJ/)}e#k岇t`Zߢ+ʱV}=Fo~G Fr4b#?)|;V@,VΕD,ggkR+lfׄ@QbxΡU2j>8O\ưٍ",^}O-ʱ²e}nF2nI{]q}'O^bu&ZBeM F݅cz.ۓ@,2̋SJUaƏC WQwzev/!j}C++]-mc>َ1TGHh?lՊcBW8.uA,0{wV6\$%[j |pyu>W;3=LnKR)1df8A?kNT8錝}6y8\8E9(;?>8NvҰj?No \k1j>^\Ixr$B$L^- H'CZ# w 25"г/!\nSXj=-7L!S+E'QY$Nލ2pK_J˭=]&mE.>9@KH o\KxHQ"#v/rN.u3.rMY}TEhl*!Λf~1Luoa,lfQl4cڗ $^I*B81AECCM{tJJ}1b}=RsQ4o 3nVU2 y8wk``ڻB.ia4.z>M,ҠEV^[>hg,NqbC#z5ۣ apbbsT:VMkC7JѡHDM7b%- FNmy?H0x%'-3dû1h)q+[[ud[H'q˥'0aKq t}a;H{&UqTrͻ`f{ rMKOSSE2}fp:2Ģ 24Mg%~N:[Gľ5Xdc?} lUDp_ z6p 5n9wG|`ph.f;X_ nH-o5;7|j5Iʅ뵒ԇ OH"|E0T[k0P^1l٢mhߏz 9%^^`G H/T7?{lʷZ\Do3= R[3VkAP<2G/ԃonqO!OJ;ۜ9? f8Ĩb29ᦵ3J$6* TϺIIJzqMqAJ2'EvN;*?PI"fK?Ff.[ ]6W@ʷ5WEO10jˈ^1ƳryW\8Fx *fA Dӫic fH/+%>zj('K|=.,Cbǜ}%P/6ԍbzт>2Q|5- 9>Y$@e"zo3/'շJww)䆈Cb@]ϰIuJM'B$E^Z ՙ+ɕjWa&Kh\)($ʦNݞ4:/L«QnOf._/}g+ևߕSa i7)F1:!EP y&24O">·ڱ<&>ZH`Fr`H"4v(dv a2C!2ۣl$^iO eT [3 *f({ N_'"4(אּ*n껇aD<^u `3X᪽'VBn0ɰȅ"dyyH0<';n2{DiP"WA/ܚ,Z?(VGtor:ݝu+6" 3{j(zZD3 i&i[tïld1Q{~@ w2>56<1m;q4F)zJb':KDwy0Uz6"z3ܔY5c_*BW5Fi*ތFg;#m6Fo&X U;Aq LDBi" $%DtX#t@ৰR֚oI Ic6p] _sxM18Zթrx*lݝGAA jnJ F= R$3Fkƶ[*:.o?ZF괸ԴB#@>` ^H;Yz.T_5ZӝwIgg!Sm-*M{A 5DL# tO;kAgIi;CgZUK±mb?|JlmC$Az/N# B9+z#E}fʉu:I۲PGɗ٧6`uuqtSE"H~i(Jd$TMuZtǩx}y84]_pՊDD"V{"㤦0LV#^p*ϙE4*јt] NyCɇLo=s, y]lF G.zE_ڊ3**Zu.z$7UQF?2t+y.0 D5B7E)vP{\S;bz*@'K>%jrj0(d[񅠷R|x n:c%P}Z^Uծ'P5Rκm̵G4ˀPw!7 +68OiG;2lmfƌMasNURN*ZFPQ UNW'q0̣8kg \]Fm8ߍ?c cfz~s[ZQl&@ܓ;jk/fk,n3y~FvXYWVѼ)=9\"z|nw%VQ^#ι[th< Ȗp|dc8B ŜQ3J}F6lAdt̬eмTW bـ>WR;~b0zOfȂ2uy̎ PZ,/V8A5$7V@oX(߯8csamJ9xJA&>&종ca&z 3]C?8f.w먈O[]Sy돗U▮6I_'wsTkb)j8{ %{+d_T:kWBai29!. z;`nPBA:OTd ]SUaLU/tbҔ #AkzK^Gv'<\U"o&U~8ǙPp'Uk_رܪtO=/ޏ(5ק- # ϑPt#^h͕R$A >#Lxg,`{\0Н=9PqlnXbMo`#1Z^Zms%y= p%:?v:OAy77nGxKڂ>4ĔocE5<͇M/vW~}6Elz ƪwhRABu JW!cK֯j#KpweS ̥ MeZS cr,wYXW}Z; קm7Aid1N44?iy>$H7)qImbmz4M]$ukQXyޜbݗ ` ҐMZ ˧؋ڸdSj"#id_ ;lM\49fdthC+b4&סWCeby &wk.C˼ELz?e#並ۮ=HxNH]7ֹS7z|%f&^o>L̳xSxwCK;K kDyRKb}{A|:Wd dahCPx";q}W+МD2;o Jֳo8k L+ yO FNC}SXW9GD9U4DC N⩹k3WhlH_1MYfb`Y&⊥y}>UW+%3Z"Ǐrznhwwe=Mr@WGuLֵe FvECSRbk>I'=|kVdeFjD}d?"X(Qz`  ^AxIQ:n:@d٘w%CH7P]Uz`TZ ̓' {= Wl[R)걢RsdGCɸ~X#Ȁ_~n uRg2:u3%(K NvM(`SUfDmhn9Th<]_%#$OʿdɌCDWz~5v33{^o/)l48KmA$FlFmf z)-sr ̠zYDc8p5 *J tlxT~8 [d;n G3Qxi2E161ri23!)W1x n8Rͨ޳/^|(>Qj͒z,{l SQwpb@&-99`ꛐYm5;0^e($=kf '[9~/\8ݦ T#JPx,*zɆ>Xb=͒W]E'ωH;Mi3UuҾoueNoH'+s|Q gX Xܼ̉cHu(BLV }uͯEYEŵjNr8eh i7?`3˶Ulٶ2_GVɾ{M~i":#s4TwK[xf9Vr%">T, D`WC7sMkh."qQϺjBX/AFWy ܷh~+klOhf["-@|^|*MMsLY uo%wnjx(jbn~Q ]}.0JGVxP]},,su;#Z|;VHZӿX]oZ>!m(h~"?N阁Ⱦ=Ğ6;'C mܦ%VkZhlCnb&N/-&>pLdU0%h3cHy7)%A&rAp"UDya(g@!n{ؕVhVe$b%0)n*- 0ϼs&(;o+ LYn{rlY7x,0[: <XzTbX6 ]:O=$,.JHQ+s{&'T_ǒı\ɵ ErN,r.oM?%!Ӝaw@ wZJ%Zl2H|/;[:4gZ$B XXxJfIk8$ۅdĒSo6|bUXdwY)ZlxVz[~/m`!׭ UE.|-mtYeDA|pk?"!D { 97tJ&' Rs'rGC*w;8Ŭ!ѰpTcF&a*+w6h;Rva=O_?> @ij)YW-4΂ :eJA3SYBs7?Es0}#af%7W =~8(Z|ar˄ֱ@oR (F]nS)S9S3|^x)ya(2,9U(!1&t iS0tY||c_72 k$W_yvClP^̜aBW;Xӝ^R6zzZɅ<)iAk6~n`5Ӭ A/12N*>0n%k%I*9)7ǻ=JH:/{U_˫%xeFug4-GL^N^ ƲheHd)r:_-~WA~ڊIA>n8ݖe_Hh  "1UP`4jֿ=Mmi㗇:Q%=jDSB.Uʱ*UP ZYЬ4zlo{ LlCA]ͻ2!dOj^ƺ~t-|DpHʿxi`şg`ZPX6]C[#mt@Zt0 M8g0k6̋5_xXLΦOpe=HFU"QK`;yuTw&N -S0S2̬TAL'm@H]}b A,][ͯ'_%[|~\K\Cwv!gnǜyr߈3t\V tKk{g^)z|Xi-,69/]!(*&g\VІS=şz8uGQ+9ʓ2PƷƃz_\zw } K %Q2c@;;E]_Q+/E)vG '#E[CV}i2UwqQm QO`]t6>s?x'vEQ 8 v%7q GL# uϣ]`f '^9|97^ܢV?,92"nA8aڱ8TZ|BhKJ ,yU-|AYqlplr6oN vv;OJQXB`+3pߔ] /XJ:>,6cc'υ#!2 OTPF!i ,#>ސ3v':~6>j$Gq8[" α6œ lMp='fْ^qs qX#8+eyxaAV|-ho^:&抚3pR;\ԷecaD}9)*@CٷG}D1wS"HdQr?}1;dydR,DžuAX]Y1} !/̅N;)C 46íIz?6i0 ᮁbTbr@:p @f׭Ia^3Y·ǥs}X9Έ{GPq?4bĻ.?ZgJ_Q$DVJ1%0cz$$gGc6cF.ß*ݝ%[8$<]pD鬲[EJWLja4 אLB7꺱&yL+G1FHrV{_6HexN \Sk5`fd;(YY4y{nl_n?rHg +ڔozVQ|1λ7ݚ '.Nb5(E .))Eb@N~p8zں)qMˋ&Sުv~\E:W_/oˇ4AyU2R-7kݔp5l1w?оjdQ>e%C-wqU19:sQ E -6d=$ӬV4 -dK̜Oݨ0@ΰΊU9q|ν`쨂aJ,UK-0@B.p AQܩdu*P҇s8AOv F/}8S;d̟ =&=pR"r?<,n,}ddpm +Jz',n-.Oa´%~jg򭞠swtʅZ#0v֥C"#Ԓ 6ᡣ%6cu46eOfp9e_C=q2%Zm7%?dAk;4 _4r=q[D(_| wz:5^(8Z|+PmЈBYũplN|,w5İ+C=>?50+lJ%\F"Z{T~Z7 !Z 4 ޳ryhL;pNȞ^*!7(qZ5!: &ۑx'D I f/m|iwu2PgD qC~  `,(>M^&uo \nTsQt˃9%} -^Uެ/h^Td|V!F$T*:?~0.ϝzaWAMxxQkj}r7 .MKuhyhvMxy{]'BVHxkِ[袬Y ?CltS hgzdA郰[8UVCeq\ց5T>qg&/n 0I;/S  ڄ2঑90y۳w"HxdΦ.!s&Z e"RxSn2'[-U;'-wed ߜ'lU+,Lr?pd٪盯:xȿ=Cךݏ<H W% k "g jG= Djg#%$q"svk eJ im/:Ac0Vn/v#u-,8M7"-߲ ,/Ip/)BpE3w?dg1""Oq(::vERDJNeͭ\s `-ݎ-x~_6NUx[x<\Y؛*T^zv)ưE3x%5_y2Zn(],[ TQ];8^V`q<: 85OޝLYSK&]9f]);Nף${E ,4.RXaZwxkN>mMmhm]F kJGDͺ F @:٭<_iSS n"h|82 ?$d2dL&'%8{CX\jnk^Ũ9!*}oy\PġL8_8v]DߞƁ)c6 HS:lUY.Kh޷ X%f.wx1 E 7 G&VE0bDR CFRp8f:^QQJQC_4zRT!T7@)჻}ECdɆ ^r992O1~|'O%Ma(_+g}}hmhwNd/{be9Ozg&-6!@LɱHOƿ41?+[S%"< (Ae`M;jЭJAJ^SFS4@m~gQV fdKi ̀ǽ>(F>@oLM702XqW$r)`c2((f!ĮR)`ބ# cbᳺ2<=q4kB d[4}+|͐2kt/ ?9E danm!R\*NjU 芩W杌 Tp3 C&a#rUg"n{π)KWF6D ,"c<-q }I8ƄxCJgUu޲Y@p/(i5ŗ1$mCWl=~dC" nSrKt#8]P,P3燉gU~U6GTY\a^ρKemԵ c+PztB|Úrm*}&Q'QBWR ZIPRR :saZY: TU$< x a˳􃦌w 5aA?}M5Z, !W CN9#Ӊ6Y#蔂}TqB1UW8}w;xC1yED|=%#ZWh:Jٟڵۇf8ϛ}\[]@"qhrA>Vc`TQ_Gz-E8jFx!v{WhH%]֏a{䩶}4_CPOJg^(;4 3GS"N2mqj )0k>T+9*|7`+TTYe6PtЧ^Ѷ%w^iۿĶ@ؼt!bmyӈƫ>PfcXk`ɹ?I0d/2zOr|/ yk3Ӟ՛vѦ3:7׿DN2Pt _(,3+ZgVnGVlm;Q2@<=ʡMEml͋@LKBt 1C,]K8cMA^`0nuvsY ~6y):hE_1mk}44ˢVuk4ҕȬͻ݇D8G{ѫqa'C_tPnЦ ОԡVbӎ'ՙdGpvN2.NR>]rt@c 4qŠQ_aԵ]/Z;¶H.ۗ;8'.֎5̒Z,W祎 ~[_n} &#]XNJqMq:Ӡjg\YL38p+Qo$(zЈcoz yyx=KVi9?^`2QJMv?󣊚iXFY)_}z7AB6W&z~F1R!@9 (rYUqOѰT 4&9@GFtZ}w;~~Y'r [1͜-:O;P&6v{8k6O KM&*(SJK=J1P DxTA7jBYEKCZ]zE8rlT3`ˇ!&jCF7G~#x' \`\;KbNٻ`Bn8bKҚnW[i'1Ns<hm*^ b.c>_{ )4k`bCչV5J_MejZ 0*YݗjaWJak^䢩C`A9w0n h EYP5|OfJq;v %@| “C=V\Gx#RIO +0it@1VK8Y,$U 18;QڍcFFk<4Un`!Ӟ·\ͣ.KWI}sWUR ⍚{>^.qupt ؼRh %& I= I,A[''#5g<Җ[ZNb߸{"L,Vb6g*5NaԴNgx,H/,c!鄟Ў,igln/pzG JvOY2(,N?5?Rk61c17IEd2a<- B % |6~qlQNӤOYr Y۱pȰ 'cuLW{}t;ӹ6^%Soj-{LD8ekdICx ϗ(+4PA&D=@dV#Ywz'$n.2,qCjqQ' t̫roƲ D~MOPtdAɴQnӝ ǀLmb.Lno<^^*m1l֕WR3t&B9} V'a2˟n:iau):9NPNJXvHSx'8 AT'a *U*z͋=B5fz%?z|Q\K$q-f/'Ny5:*[GnѼwp*DG_~!'q Wd@cY ">Q#bsZrRE:$&}ڹ{LA11J]D ]wW:]Fu1c0?{.Kv|Nc 8Qx/QJ6_:b:H<(B(ίsT21]?v|#D,ǝp8/ES6R Xj?ܑ Xn¨q2/킇M p~P#MP4θ§^B$!σreeZ dBle2H߿I{ *nV9o~3C7E+pzగ;3P`MMw: JjCd ؕ*<>Һ&aoS5+8pX{^/]!n?lYPPJU :,}4H$Sb䡣&1e5wG|'$NEؾ$XTm,km&XXNokb pf ͩ1|uu,a]k0Ft=j ;MRG/`:X)>@@86/M&kE YSv]c)#Ҷj} 7L[Xg%64I+h,D\0[LZX7ԇ/35~ 9+4S;hMvPTZU8ٲlc-_u)7 }ƗA)CȝU_X: Wn}kp)Eɟc!V(&.Bn5Զ7DOʚv#d; k|KQ6L:aLk!v/;,W=lq%(H d(=||@նQ;lr<۩:] @"XK{C~NļӶ衟]גj-0 tAثL̾{cTmΏ:^4yߊ ഌy~̇Um|@@Y4<{;f_( 85auwr眫gӣ%u@ Σ벙MN6h&catwhnIeg|5.V| `% ,܂Ie@ zx``H LJ4;(/>$O fT>sL7_2w&&͓*pk_Icƥ;JAlٽA8>ndӶGEb~7rr?Cv6N|f4N 1"R_ K+LN8 k55"h\N?~hB?{I qyt}q9_PiէT -6Va`|CMTc|A|D 4nE9.14:~7̕Q\ $&_xby zZr$֍1׬j(wfĤ|}w|)lwɈ* y%Q|BS_Qn,9DmŴ.s,DUwU'&MV"+PJ K/DIV}Rp䀈VOi@iHsg*Xnb`A^^plAFE&QrHzf1}K}GQ pvؼbC6pyBR-*f> 3t 5R UZ1XquaC -0'zeªp׫EHU[Y;['AD/;vD\y XB +< TIJ2@CmތcVif2!,vgđgJt#TozEj2q\rKGӸG.E)]xw>^bߗQ{L}BG o(8%[}xoM8=GܪiLMiRq]|zP /Xz_>t@*NlP>-R` \ɦ39ƒ;PE7H F8FdvfL'3NШ; Uxb[ڀ| OuzGL0].$FNt)¼x j6Ǟo?]u(e)9\]ZŎoJv 0YYŵ|gy1qpjϗ:|j5g X+Gh HdI39=)6FQI"RQNSKSU@ RZ+'c`>73.U\-GEp(C&1 G`p)#Ňg#Ăzxu K5ˡku**GOU,.M8ZΌd41+7hAv@(H65[q}}~UM``Z^C㏩n%?.fx!s_Ź8ɽuX-l ݴ2Aȓ|K2% 6'I"Ěّ;CVu@T{#>O*a`-#mr? jdn:ZO9! rF..9+kxqvS^sE#o(yX,ѕcgfc~յ3 ک^ﰄ0s}Jo-P0+a`k\g\(̵)oKٖ?; ےe Yzt`#{-Gc͸I]0R18x+=)#z\֒S&}KEO>H90UmX}e 0zxA@7 FSw鼥/"Ht']77=n'EhNkBx+6Km*3L򞙈a-nڐn\iG:29+/\E݊YrD6Sd}>uڱ(u?VcFkȇN"a3])Y2;p`r2;kk;UǮ)䄄o PYKmKsKzQP`GpKFz^-^nEh $`fzTcr@eV-zs(N犬w(Co%!#4E 9\hs|GnJRt$zuX.p{]u(AJ~wHRR78w9{%~rhBz |bG7O\_i ;}=o؂p!Љ ];+3 ͗coZb}2Ou| W8·\= #7kalgXn!iwЎ39tR֬6 ar:NUA*g~@1s?8l`+@qv3s=\c8Y2`(ʽJi1{ ajЫ>j{esgE+\ynG[Q? M6-Xa6{au\ʂ:g.U!>T~R%=l޽;A9#V)U/%S'6ߨnFQ1E R!u1եՓC\jPbZĸKq&ϱ@oM=`K<͵?9ߞ,P3_ًO,,I {v?&V)-/%'gj,ife>CjBI\}ENփpOx &h*pj3ⷍ,1CQl F=F8Oďu<(۬j{$ec e#mA593dLTDT_k}3H7Y%k=ռ#0,*)!Lba厶P=v',-ވ1+{$~ov&Mv(3Wѓ(ʋ.Q3 ^h媁0ݑ=SH֍QyUi <3`(Uo<p jG|@"qmŌ4cZXOIR7D8C80UipSݴ:'laS7ϴA2٤Gl/a Ky{'tt`u8iɾ{Z]7@\W|)ܹD^cAFSM:ׂX)9눑Þ]g|,9Vz^A\:kdS۲5Yxyrep*ALZR!^.!ZZ\g7N,Fo 8y];dȘKGqfn;#Ÿ!ԙLlG:*t2,.cQ~Kuĉ/:jGVB7-XMÁjaw&4W%!m]rrRV AWC?ShgPϰ19ͭCw2* k9A6-"|k1VxcN-@ _Y>o<"(5"-HO:@Jv*RT9w9l:5-2#x- ?ar8ϯ)WxtBEi{VnFA'[v1&_g􍌄w"\l{$bcGvM e$h,2]Lkk1K2Wﰋl v1|Lݧ!K_ Xi/Ʀ2FJy񯴄+`RWH&S%xÀxbO}=˭P~2Һ̤hf.Dl kjTb`!~/4B.'۟Ir-ɓ.>D7ű7+x4Ll0O:e"i_16FdYۻ?<% {{W<|}a,*g '(FgOOm:/Nm$ScY#Za#:P)k`DBΙwŊhG+,gEhNY?)9Y*0Vlyhޢi! 26ᑮpve\Ɂ:Xu7nfű^>W8-|"LH|+$C`ҤO܊[S8,I2 $j,N[ՋpeqG]5% @L(:IDX!{ЃGKKqޤ|ѱqdԳu>(K@Ck9)V{M8y %Jx H41~OYձЮt\uv^q +jmnި$3mg\h*qO.Y]]mpb6fѫ6\{?lҨh+- $Z1K~]yD|/.MII&u^ $xIKRzĄ'O &y[YRUc_'qeJEOf9 ̧Uu9R/ f/ryM܄΢I\M wYYsw9,*|"#sAT9A,| 6vmo6v~7*2o"w'Zp2|+22 [580 7Ek=!e%̃3,܀H@Yl<݄uΡ H-> BEĸS]:dDH\k~bg?KZb7P:h,X&ɿDrSg聹]* IHR;jϰi^zs$mu/ k)@eI}YM+#vMߊ+¯'H|Kp)“|ښ5z|8UD,jLٝ) Q:-膁\E=-E8~A>|r9fY3irWÖE6+=1Id:$MzI_alUS﫹(:VI݌Pôgb6z*1Bh[GtqƮnB{0fZWe+P΢Z J~#V;|)'#)k` JK~ (3#{"L7VDo>͠#!(pbɣSS9a.߶Wu;|y[{! }gm"Z\zkvT t]@܆jl&0^NjH,h+~\qs}څH<Qjfk V|ʓXm; Qʥ"Q~FDMvGam&zLrST fKH͆x2D,Q~QQwZZ!unfW iӮ ֯fd@X} H਽ 2$37ncF (CqBMMZxl늕!AJCv ~ y E%r=c[(UGPZ0LO*).Х [cE$ $c~pj % VEó|?Y[DzĻ/ͼmVBh Z~*>#GDK%GH9U쒐IMrxFwRz_\Ґ/p$$d `1h;I+)}6 rAT{DM\2JK%?/S$uYb]SFb(ӗ4:gҫ?DE-I #f_p q !u 0ڟ OqLf8bu&PNgswc3?4 ݪBT-yP 9m'83 % /6t$?ϭfFRbB^'*m-2@:"54&gh2~Yhl< Y8/Fn8סb)[9Pz?>miaO9]bq LYX:;05Ζ9Nl>d86Lzt|YG $1\S|h/)n9|ZXp&FV3p\?l(G\6>?oAi3 n~D+%x;PЊ|U7PxԢy w/+ 2ƺJWZ== &K44lLPZxO.ز(N&0\IĂf%`\Mn6IO@Ԇܠ\/?}ݩ(XaNk/yؾɌNJt.[X!w@}Q1;W{)t\; A.tQM]uӫH"[)kB RԕZИ|vK/ƎNn[6O%]LULTYŌ5sc͂="; xb&[UOUAPQe\g~=?t0[?K}+rMRR%F\a Tn#9b`+2;7[0ycԙ!t,`4'9ԲUާGEPT㋨V^3LPb[dqgOt3"3C3Gvuh;^ "S' 70@f5*'(8>8^HYoy %fS2Vm81DA툝lp4oͺ#hGʞ1I#Vg%mX>HΉ,.1}־htSV:l϶<.sC6KȎ+bYܺμ@;۞OTR -!1pCKށFdh!hFﴏ^$k^3 s>SU4~S>1UO&2+Z>2W>G]>i*tD Ҡל#y@>A<aeh`$Kϕp=;kNX'-WHȢ`;t]y\nNLW: PK;@դ`,js7wꒅc-vgGŲ8kxۋG[2GvG&0sʡè/RiUZj *,`Gx0ݥ Q {k{6!pc|)c$HK1g5>;L@PɀI9W6F>2= 1jlu>-!n$3VA/T<85M<}۬4r/)(כ Gb`dAA;H!z%fOF+ ET6;pe֪q\6|tHݓU_/K:|-Jp0F2BrQr{,ILsl*Kx`=T 6?RQcvbp^ ȔU.#0qɷ: &3Z]asuRsA?”,\W` @i"AL+ (+_1 'vYl}_b!zQ[/o5p~6ByC]aMXi?@r3_tOs5L []h9U8$$#D.F+k](FTpHz~N2sQ–`V?CpOI+Yfn5qɹikjgңGNh+5>>_ +!k`62;懨)7a>rK9?bl`$ l#,G}'1 p ɴr4I..eLPI TV%љ荬?ٵڀF]37[P}#,{ywwyrfͽj9!?;Dtw hZctb1.U2ʞL 2۝"oHWc@?I/Tr[e;ՐEN"ԋ^M#|]XԹ=l E(򒺰b"&".rTbAmXMg! :Ω wR'q.Sux5'}Џc dmP!"iD$_Kz;0W*pvgNr@NNw[oq1>7SD;,1k趮ȃm[͚S۶  jlv><:1;(,4RM8_er\Y,G'g+nqLpA2㡩KpQ?YApG jn R(iM4 L7lV PyzK~ ;<+ԋ-({lIN4IS|r~٤=QsRԒSdlfpl]׫.;c SVH4:("-\=$}#Cx9n0zj y;a+|hKb_7f\a~.M_`An~)?Ų .B2j6PVyށ;gOKxU,*aߓJ q}w\Vޙ.w*r VqA_{%1aML=>M%17d^;T,KeC&BA ܆+"[*_5LopGdHGn>< =`{ܝ)lS?w_]|iڧٺih!F-iVfk߾83ۥZŔt%ZB1 ZF8I7kF0L[%vS\?X75*6KcY ̓W5,E9Ν)rUXqGfkA_@RMp<]vyҟjR ֈ )OqXnА "G#a `9>=AIX1QEZwF@]v:wrCrP) &y_島7UU e?*R%a2l;+Bl?u6}щ6ċOԀ2狯#kznY/'^Q6߳cU %*"2WϡemC] >vmj@$G]ՅnA9;qCq]ig`W||2+.?uxѨDq[7ŸCu\V6WVP3MO``413Y =Sa|bLGF2J!a!1d @<y _k&F^=`191Hd.>o !`{Ҹ(n2CR]25V1~J8Gp+Mש 2_5~@[{Wt0 {X!h~( DdX~xՕd&:ljMottax- MhqÊ)үvB5`1^ij5Ff*ä׸u+o~1m. g;q4Wr߆C|ϥB,ŵ2ޑ%ȆjKpH8ߠ~~6\}/i=6F XWʸE*j[(#N]?)'O#s2M5g-Ecb@৸6%Ɨ{ 9DTT5D0rK2>mcdӓVJK h_$r,;ƹV>$:`mjlK"| l (>dځD9Wj m5McbBZhA:..&zhYkd(}_מO8'lFцItS3 vDFe@b`:Z۔֙Z!,ja%T_o{$p rL;Գj~$$F8,M/#ϊ#i9jJ(qYٓDM~]W+6F̿ O~4Aáze JgLb,~^᭲yFӇb9qj|\0O5!ڏi?0S,7/O4#Dhxj 7Тx{(1& KbCZ;%SWThwT%#LT 86 'v3JAkõu:^A.~R5 yJ4qQ2xhg:}w\ThVZGE݌JjH0)vdS;W WkPQ22^W\ڄ*4Gݡ)UWgLN- [9gE9ܞO)&z}jfiéDjd.#3%tuDMI{>NwZOcH[-J˯VX: rw&me W9߽EA>#K <{VD=|H] +~ˑ%ZφDP;:) &Y > I(O.<ǘ|f|DL$|ևBN$3(N :.2]! w"^\p"d"nr;[緆5~gP1\FpoC$2b]zzZ<){x3=XRLճV l[(l(L6ZB chq uBaec8 ,e0w:@c?+O !8R&SWt64^ P;OG*q =)ȋ.G4C~쫯~kty;<ǩkru]dW{ ,waNbU;$TeV^fdЇToL%P^úbnH2Z 7t l'I2[`r fW1$0Y3#Q 1Xjk]0QxNV-0_͑јRvF$r#߱k [1B@6j}0:w./.ZFv_w2m3N(S9 W I ؇NO>MξHsg$lE}m]_)pѪ(;A[: Ma;˕6־t> :;ٛJSrfAH BZb{ :?߀75;t30?04RnT_%9™-haC"&?9m&/Y/(· EZ XnM]xǸU8.W5<͍M-\M'E̜ϓ|eUxtGixcg7# >^A/})&+'=7{S781cЄcrƳr^{ ّ3NN gtY)=fQ͖`O_i ޝԮdʼnu06ys>OF R7:Swoq o^vKul&@z]9ÒDFu~HASH G]hETj89.FGH#_{#[AJyJ6lLC 4!\z:ssn)cx?DbW,Lzՙ~Pċ_لW/ӣm8=rǃ,X@poކ\m߈Î&:B4-:OpH A"3@Rq AAې5 }D8'm kgIL-cE[nmO*`z܇l£u>^3:_y͆h94.pcM7a B+mnW3JMf![ sY{7R"PdϼBPii{$Fx%b nkoÌJfxDv`S1.O @S% jOEP^C<0 0+gMa̼.!E0w3 7ӕfU&9@C #.QnTdYo%# [JqR*rlYRBd!Ž8x/e(L!$^(hFZ!o: D5TV\Gc}:lDR6>-9D[j_e\^X,[3Կt)1mb?H>EJǭfǗFV^γd.Ss_a,ݒKN(]\W,'éCvl-:.DQ-+6ʌqOIA(UwFK Xo%dяm5[){nsZr_Km_=!-RJDž{X\Ξf"zj>=8$ns#Kɝ@9[Ʈl>s;? $@7]9GzۻJ%]Æ2qOr=Pue`橕^na Y4m1xl>ΧU\# _3YVBs iX]"IOv?Ӄ)YѤ=" )nr,]aZJPC_VVY@\,%A4=3m]Y2P3&FΖukvD r A6/D i 8'd0M:҃d>'Hȸ&q#X/eB+1|SnCbJE+w|552+VP2yA4<iLTM>?+eYbV6iL~z 1-DxW$&b&W%Nnm26iex"i6z\f60ķ8ӀĚi-h7h޸o.erFI[n >$4Sspa3:-x/L=M̼{}Ѐ[hСdn 'xemÙ-ohh; Ucr6--y][D*6|3a_HxN'g5xFi"b韖i %Fd]_~*Y*Ljп{xbZ R/Czwj tXPWׅḅ<Ұ$ݹ$y`qc6^CS"?ˢ,o:n9Gunv!=]_B5~PU'Llpϐ{5fɴpvYB֑UaY(5a=pM{ڏ)E$Nawrnb1|KHc]h*Q;<HVin0jpVH~(TcSB~hAMm:₈+ )o':enM˽F&:PWJաvɴƆ21Z08\&;I42sz;+g#B,'nkl V $ƛKХ~آ ̋~M+^ӎ3c qR:O\Ф~twN韛|]/#LXQ>lxx&DāPm0y^UށՒ-:ߠ|S:7 ^^Y& UBa4JWe8 >~_`Hp&r\jBtu?oWfKVSAT2)343cPUg'Nclg$Ya|W.~W:W6݌K/!w@MfźM(0\!tzz"G+;{4yJ `Llc$|Cu嫰NGr:]._;XC7 -oeNZ%wo"f dRH6.>Mb&HFXAo,>?0W OA }4G_z`2ݬoOxQ.{B9Tc¨y*~s79:6+no?Bw^ E'1 ?z#[9?N׳iXUܧX}0}地e \P4W#BYP/hOמS!,$M{foϊVZWF4c:DQrpY$St#ʱҿB\" yOPY 'ۘq>W#e9  mTAWi , RC_DL XH-,6F$c]!s鶦ņ|9ډ@I-KL+3{{FYF8q ovu.+,nUCKYdWd|`}ܞyzK-:/[&x*DwOMyYý:%B.- =Ƚ❎;=9ɥKKnG@HR)Dh!@KG_SJonǯB:7;>]H:竮+f`s g dһeVtDϧ;H!X-uqcŹxe, [Od ߿5$-9eT74jUQ9~]_[4ܩID&ՕvUU#h15y'+q/ׁrq6No'Xmx(ʰf 96Ep3[#Z(U1 Z$#ړ2xoL:=͈ J!'TAVw3`0+ fr @|l QV-+0'j\]Bp슩2j6_j#2$۰r2R) OxSkY6YIooAOYAsH=oK7fO6q >;;+|0B(,w|A?{5>ʿ޾/G:1/uubˮRTz8oӳ9[&2j Y{%F}ZQ^_uyDyW_’i;,ٟ6g[WbP3^0'BN__x.aպcv\ c;]gRxd5n0䲱€wXћ톷ng+afz_=*mhD*9=a5+erņx)nPZ>ɩOT>D8Rpςn֪gzr M%RٍPyٗ'e -<{" ^E bDSM=! JS˿gŶ* 6vvF4*:2/"5*ݡ2A:O lTf+ aHgK|֋Kd]#d^]DGi{#Aψ1\;cKhy.ߏ NȓzQQ3= E;ɰziJDYȞ|ufvx $yEȚ× 4)j`4rV[W[CTȷCf~h*p>FǺ_i1SBhὑr@rgd۰;hp.aFG ޴b&G +v򿂀HGGq]fLuoy.[@@fM=LYWich\``78"W#Q#3WЭ0x4 osGQ; m>%wãBI"cO(~ )Ge[>D:xpX1>/EDR8z̐m{?gm3aSUt b垃.XAS*@f[5m>,v!x!yLAk͛Y_S%}Qzsuxv߮t,ʛ8}=l2\N"зZ]p];qSI;[>̈JVC4i{#@ZܱaDIp?(N0 1l\K4&_}Td{Д<St>Y|M"xQ3WPRa JD⿬qs P]A(.~ &v%I\+Wr4񮉨j7tJ7>X@?U3pe$2%3ƌzIDhxiFˑ@E/>ە!fўޣUߪdqV NS<ʛۍT$|6W—ת;imfz(Ƕ_+ƈS;zb)' #4->4L4bf> /-t@F6 `!8EJb=i] V΄ v?ا!;A)&IБzT&5 1yἮ>SʌVu2BMf2m'qi@!ݠ$t{/W7"n6 Ά#F:0 AڥG [a!yE'UQ;͗cI۬<0ד5[1 >j }SFK>Vg8ͣa4y qZl#Grn#.tw]FDfVfѕB 4_NߔT0&&+XO/z@=8EB1Vq%ce?'l;Fqn]$kLAL/{Œn1]p% !8 j# h] ;kKgavPQЕ_?̖5}m$\J~ ʹ: 2,U_ SildW;d q <čFrYLpbErdtK~DfO1mi{U\AocDh_gP97A bȺ4ڣNJ!I[I#2a-nY`?p..x5 xui!jZp Jh(U~#z~Vrnr1;ҭ&k[kwZ- V8v^vM~yl`8@wB?۳;uqndɜ˃%,Zoiie괄TOa+RV=R\FUx;nU,&Lѥkb1xX%Dx6)ܘi u6[80]A=}r64gx9)ECnR[*J UfB"JDu@oc63 +&=;3֙7ԗC!,5ROI!0(|jxP:;1&jtmY\fL J1Ujb)LV9)QgnHzps$P.I /9H{V|V!s-깊q@XO`{u6J|y>P`Lz*|O Hl4 Dt='\r`8Ď68$ă/v'9ףYo*Dk(㔡(9M "cZmoDC;b)¢[Vgsa*ze m1kj2CʅfXpPkR iqLBN-Mb1@{SHl2 |K2WŖjDp7%Q>Tuf32WXḫfKkAu Ej6oym%/qF#x[:OZBç9'WA320)YN:SxŠw0kNbfk.$Ne}눃᯸P=XcIԈAɍ0K(8:O5]I5lPud**dzc4~kA{c~T,կ,i8Pz8pv& vH>WV|Dg3_{ f _oU4ͼN_@D.-OU.lf̖$y&WEM&]IY~őȠIF_)cDpx|)=^eH_Z]x' b= iI( 'R”΃1UKe)ӲdJ#FJG)q ?zCӾ0&aBJOQZ" qXtq5MU(NQuA+鹮(pnon!Mܓwc^q:ܾ " A@4鎛.]Pov`ܣNjv;nB5. \)~ÊS1Imlf(6XkӟdCs|5*l2%?앵 hZxprG/->´Žzb de8DK}Ygt6`_tb'\K/|e z[TZqf~MgzLCiRXG$;]Y 3jeI ,pӬ.u b7?%.{_?}ՄŶڛNʁqU6yz`n b6YAm۪Ra"`T6v'M☻%lؾMV/9'` R.c?U0fL? br]F+B[6Tބ0~Km68[~H)T7lw \X-dIɺEJox[Vb9 :-C7(.EkcAn(,b;Q+⥝VHr+DOJd6͛r`dώg 8RZX~˵!yyTda=oiS*BLQYl@81PsB3 5\ݎUvMOC,R\u*#L9H*GO'%ƚۋ,*ёT\P)TTek;l IЕЕP\xf F rs ^b%ڴ0{F0+Ӧ r3 wOkqie#ڇ<h8$^wL|)SK@?;mko-dY!~QX) K#7:%7I/aN˪1RrCs-;HkmYsOLg9ACEe PR)䐇\I|~B}BnNЬC{OҳIpcm3;zSJ. ah(Yt<03[sk K<92Mz1s|sj-VF/6vY.+҃j.zGtn#Jh&IX%GFj Q5~O2. p4E/OkXJߑc/`o@yD;i٘` [, B!&U|ZwƝ$`dRJS`wˍRXfM`zh^}^mKbpEжY+CN_^#{TY=4obzGZYe/8_P0 ;b>&s5cs>w@H GT㤏Lۼ8tK,MO5_=s%h&+t4ǣxB*>X5lТ6sqo eڰK[R JHh4D>PdxYyVH sEJs xXY[[|̳o- Q1\tFy7 Ho+Cwy۲T齢@85]"ʺ.ι*wP7`Ժ?Y-E{.^\x0ّ.WKkgt> 2 U >w`?4nO5$m9MK0aN6hyеҳ¼e"KmrYv.F/ XalTÍT.,OYB0!iWwy`^c2>仩I{G~8-}g3r v8.ҁcmu1B[@.Q!-h3uSC)llxh_٩g+k_r,h|f-ê[:!wNm=Ī9V2X'#Tрb:M{|VbtN5wy^d-:\Hv;^l]wDNmsyjG2~ijʶItzϢҭXGb4qF Kk#Mm8`Ņgx}t?3u݀VNCADvT,҃!*@TpP?qYciE#w~F7|>HOi0`90*0 n7Rrײ\k}e/q'/?Qn+>JejLLo{2:J94j8 Wإ1uD9NϨJiy'z)vt!ЍRa 9 sBV654#)BDPWȸws L8pHzޙw)[gjYT=?l!1 a8VDVm/^:$ʼ*ΪD[` O}Bv~ϸ-z&s)*F؍[ O/TOL͋dιEsig1g#]͛GZQaP@"2m&J ܴyLȤ xPFu>Ԉă~G @5=]<%7ois JpxV g'Of#GcݨE/!=,m2an#)Y7v2A7|p ETp9b7q|@)v@%pw֠u(wbTPD hB/P$̞'Vp*R]?]͑;%LvVm)x JBl](uR/_$%T>oS(Ƈ/Tհ[NߒV{]sb9 y*r|YH %>ĹT`;K%P'^ѡzlV~o[eR 1TaJD9Y8o*qrܪ{:b˻ ?ĮH;ifq֙/Ɂw.?ilPo$8oZO|*,٠Nyk0]΅-5[X̓Mb7`&{pY'("XIlf4!*2xt`Q_.]G.e:ALf U`wH㰙͵k廎}Qm_M}?@h9vyDѹ@h-bOB/|߃a"12|lyI z U4$eqRbvܮ PC; 4Ju!N6oiV^B{/D%y>B!?1+Te~؞F&UgBG0y8;M$v G#t[viЁ b\ztuْEL3VIOed{ǭfn2;x W=RL~ܭj؄`>ֆݓ:K/r©|q3aS[COr| 7^i ͵oܧ+7T, Of^imI$)U;0-HzHEg=4k{`J/@ _*"sEh7$+4gaAl 0`(+S_ [sL-9b\+4`LRϻ6Oju[7Ɣr ͂[A^yJѮ6CI{,cuZ*v$T?ω"=M>[ʋB2rLS }886!(TV㥞`&za sSOsDAտ+e zLa4ҕ54CBh(rgפOS\&$RdBV e2R]~#qSRnAC!d;8Y&s `%XOͫlO''G𵈇EPtdf!")(ʻ;iP40f2v &jdYk{)I~v_/-N:iJ9Ї=J0(̅:)ෳ~\+EIs( ˘EwEGԭ}Qݻne!4lq%sdlW5qH'H!::s4ίJ= G\45yMGAt|NqzmDሥrA->QZR.YXεgR Ӊ >.9VgԊUr|RX:ފg&EۄPǭ8a [EXh 5p׿ A X:T miX%*LyCsB7՛kkT3k &+JaVuȷYE'YQO| ϷⷸzZckSZԛuӸ=ݾCuiPEpm<S*]@`@l fCyFhuiSČS2b,:۬{Wv yѣ};zsd lRq&a گhсa2Ξ&C-_wU7DO$snǹBK&" 74,U;~# 0vJЭ9oo,|~:<(];?o1]\wl' ɿ:tJg̻\aJ:a<눹;_%ĖLn4FˆII'\-8s[1p L 26ՠ!amA&5*A32f0WKnBd ԰*q2覆nNh/;ʱz}n&x0g1}BVH 7NF <)'Hl"d05b{M`(pC|Z*u^19_]فZ䂸{^UklS|$SWEù8*:lp.bMK8ړe53얃vFAGpˇz?d.M=m]>ق4CgH "] &h C$  jW}ڈ A 8)mtk]ӛ @TjEy# o^bd@f8wr6H\gy IR%S BYqx$^}EDyK}'D۵=_*NWXqV vf0q[LR~S:G5qWy+mԳ= o<@"#kAPm}i7mP:hĚF}>e<'sš$ rJԶXt/@ L?)Xg>ںPܟ LR>vzĸl3|{T#8Z6ĒV-K$U+Kl#⟟X}RzEŃ$E~7s>j[ 0::^%`ru7!#&Gb;iDq_1ԶR 8Io*r$BFpcvEBhGo KHs[JT}37(@k{ 6 ;ص`4YUcooR6" /=Ac8|2h iZ 0ȐEM&g{c<fʂapNf0]\oR9Z,Y^d48ܕe xZMGd)VY+="Jڡt#|ؒ9/9R34T ʽgię81/'2ۛR~YQy؜GwrF4[7ҍ&rYG15EQteEiMt+RQ1a% c>r~=g N@}W/KH9}U@l_讈;V޻?٢{'oaL#Ǵ9Uä$9i4jMp,ǿk;{ķ 1!Ww:NJF 7i #N>qT*L$2_Ż4M5E~x!<!Xe. OϥnINF R!kwaV*#R3}+}w 5YvѢ4:%jH3a4ڤ{>&Q(V,v#fuj,Hlpb1B.tcy'ܑJA[ϬL< KW;m&@~a̩'x*޴EH&mHYZ9" (HɸR-VY04:Hټ{cp9g?k2DO]9~BUIma /z G蘖Qț\h3k2ZBx-Dck^e#m>.)Jkb w0Lj5:bd\am#DWvZhv3> vP]$`=+u؝I +K-՗6ڠ[IX 胤JHCDDqr:$GO( E`0Z{H.DXgv0tL֎g}I9h9scS_뺝`l*H{(&7>CBxc̚iĜnP IηbtqAtiUɐzs r9eԡBI݅ݶvX+J&5X,Qq|iqWEط(]J4C%+j+4J ؠ5q@4-r]r%P],"I+cBgnF_QsJePT.t0W9'ߏPc? ֛ЧZoll}ƛ؛;o-[H,2 ]L+lȽu3ar#J $>0_`dYЅX}Dւ"'a4 H8L c+W}p}+:q5yZ*ftx]-@0܋ -}3D?ҚRm|s} GMn*dk<.e+C嘕G{r0ӕ2( vyƱ* s͎9MbI&y:\ k6)ʔ=B7$ܲ[L6xc:΃0I 2fm>i2p%R?]5vܺ d82G3{y6L[K&1BiVrY~VJuԆ3z8k1b]P>Wk'ch8H?f LKZՌD(V}Rd4oP-*4a6ـSn_[n2$lOVsAy#oFA,#%SJdc5Ʃ{&Ϫ<r1a9Oģq]O)#] ^Y4  * 9#f$Uc@i2P?8Lնep񽃺hW΂\FL>֢؍6QK% !`|C|Gim+$>:$;C џ+}* gPuS2Юi9J~']Ŕ^DrME9о90lgHȁ$g l 1ـJ=Y d"U+^V Gekޤ5;uw t}DY7@rYѹ%UjwGeN/4.mi-hz_怇)fbkҽصs>1lIBV,FC\\߲Y-Im:?I}9KC}WW~6}22$I3~#[q&>ti(弸) 9\h\(ᓠ,U5I"JjYGJ){,;2 =%19Ҕ@I(%y21h}xy捳:WVƨ!MHֿ8逶a$"YnpaY;<߹LGpD{Tl=(iI2, 1lφl/lSCKXd Zek{3$\Α|לTY7>&IN7tYz᫉\NgJtT͎e]ÇEzZk\Wf>Hqs T^ (ȾdiNq$HƶG!'3}e{U-7_ BLW0|b½2U"!ۓƜN"nugY >S{Y+o qܺ{~'uБN/7wԑcLg*& [s@BMH0f`FDZ wu7 C0 jLTMcc#n,QC)^O4|qk>(cIB<}@EhU!yPvk!b[,y PՅ۹׹C(#A-fo(]a4QbuSAnE dmC'&`3?:0جkI`,=T>!敳&+ 6=1.Y{VI[`54kD}<a0̻[{ߓ]/9@MGH] I= VV H 'm;8;hp^OS_q'[?hS= Ra6 ob{H(ew踞h~>LoQE 9Q$\.u"QA7bUA}A`LwSg6lǯ~\r<" LMFSXI1} (Qjrɫm!L2<ev| $[=uG^KG&)L֙?՝:zbr3K>u6* r?/m(򥝣˸aX\Y{ pGgb62#'51C)$ [h[) TU D0@1e0ۭ9;5)GJ3֘t!R~r)>DEyfՕ#W KhT첧s/l×٫u"8QK2]70ӥG c"S#kbO]-zVA駓 wjP5 s|m`G`fjcɮUxI`%LV6cEV[(g n[/7M!jDb|ZHr[rަ %zI x6T.*Y|}c"_ɢ;7rj{~d;}U+Fy+s"(*gID2ab,Hi+6?]K?"1y/ n;>s;qQzi-}f0GIcV!ee90:o%&hjgcvB2pDp≭n#kmܑcdرWD OaZhmק+&^3>`kx%3 iLزa%b:IBdK(sE4hw/+;~B}UQ(ȹb>p0< kT=hUG2 Oen)663mfbo0-*:T!EEI){vӿIސJbQkFE`2\J*kjӀ1iIi_E' |y}cL墹;kr`` -;vk\q$nb.̼~2qkFNt^a4ck:IdKm:~ .KmVڑ-;/b3% iOfAom $O`Pɭǿ 8fAI]WfPrzx;%4媅ΖNF*&4;hm c+5n}r}ɍt,"Pג?u"sJl0PA.)\TIr_ z%g8 Sk- Xx sW A}հi|<%|E7.:hO#ݓuaY3Z|B͇ s KUiˁiTf^{n[ht1IY]XMkt;^Avdj[FaL∂[cE}2Vp,\H;hg=%p?M?UHghYaør)&?L}odS[x @xtTZH  ZnLk}O]A~eOr/ekpclBj6|hGN5go͎vJkh>~6*|ڼY/>zNxdQ#Ak,̷̙eq{ eJN?א)Z `+u2.n0hv"D3hrl5Qskx˧1GC3~ gwqƣG'k #ޥk NZ-H~$ԗӄّ<:4_OmMU9Ҏ_O+'Xsrlv}~PFORQeCItjr Z0jt2<q4jݣXY['`MlO<,g\hBމRΚiPgi>s /tg/艂x~beԍ{K|^2dQlC1$`"0'q^@PuWuuW/yX4⎫V2Nr9t8 @G2udB# ŋTز%!/ZJ4拸9o)>x {ީ##(F&zkRn`1@ZO߲R]4i`{`އ9GU5SjY]~KUV}0>)scVn`7ǕOŋc3<"6w*iyap'2ps\AIBAqB)̡;UWu yԍ~aL@oHڞ^ζ"Yw$8˹,⹷j5쪅Ϙ;H Qm(0A?c%޵067N,v`/Oˀ^\ݟ~ qfidxIJPK-`7%\=aMc$$؈>GBY{DNFSxu a4?^y㛓 O |Ǻ}YљcF߬<x3,ƚ]_OE lQ$HSx|dx&{o%~ӿ<7ޥ&GpK?6ԇPPZUpSht8c yfM'`刾4j9~MDg{t~lF3ܸ{X>ra'l~Yc3v$PڻPˑ31,ɳko󋶁E[GG6(RX.kB4λ`C\+Vz y} !W.7b2ҺA^iJ/ ` ސ0SJx%w2|T+uK^@g3a.FEуǞ5_WUNW Rpo/Sdj3J G!Jk.5L̀X?P܋茣~q 0ua&O2JqN Kd65G5wo y#Ys=+;)ELET]fTd :}RIuOymFaS7cD~ gęZxܒǻYUՏ et8PY dTkɡ @za *~I~Et*S9{'R<ľvQ9 ^}/Sp,ܹ4AB%2BŬES" ԽVFH~q0 cw4)Fk:Ѿ6<etC\0sx`Nx.W$Y7}TaȾ-Fi@՝7P>='G3q7Y]OSs(D+Ș"X~ Z^f /QN^n@nEq+ D>'TuATހw7Gyeb8+|Է}cdUO@QmtA͆E3s4ł0 C#*i3pQAB?HH2yu_lk魽< vS3 =?i)\RܕNz;|$5{u_ϹYzlZ)ǣ6mޖ$dI)z˒z1U<{TjF\-p#9= p 5 :o'94ǠW!P=*Iվx/ ϵ tQw"b_(1L(`.  RTO!w7hC\)e:~Ѝ{E&>|\ou-LY3 a<;ȬԘxA5{qyUKͯg;9?:q #2k(@ Xv=0K`joR#$^}~׹е2씲SIX(rmgBJHe-|("]\{}>PPK#bHnInh¦@ShfJDǜѵ#7'ClY侟7AѠwhCDq+ӈY.D@%k6O.zEu5If>]r2i RK\kQbjkh:e%[<F&{۳ҙ/OrzS >ma,V'9zJ3!\LB09>cv>qZD-\a'"Vy3O f5Pn Eᔔ'PکĞK>ZsH{VnDpeyB~&يs ypb6580AbLDc!h&}PSSIeQNa|)OH3Rt;͐|\7܁">SBQg$e)[TrXՉ}lU訡 enz/l|aՏrM`fv쬉νݾB-bsSCs;i^sV=u+!,he!&%,C2"3XMg"%[wnD #d.f>KQ2l_Gq3S}sRI Ƅv TܟI=_B9H }2X=cAF+[L /ϧpty7i,F%R~mr@D%gm?zoC'` # Ȍ9h:zB'oAu:杄SJx e:z hAXɖS!Soۙb|A'ɇ$2[+LwT NKX:pNLc[ƃl= bq4\;x{w^[ny񞭹> <j`Y w?0W1q `&ܘg͓ ~:}˕+mCV;W*1<y槽l'gwhjviKrּx @ uS@ Q0w@&nj/cu2ʟ2oOhRvJ&&YɵޯkT dWimqLWƇ .,uܯr'ȫQ|w1l0H9$<̷l yK3Ȟ,oA_׫nzb^1lL}3Ki_`m2?huڔژ! hAʃ!㉥1eo8z@T8Lv,'lr+g HHY?:hxŅvQ :Bİfz}p4 CsU{NGUs|tk(h}:ݲotǓ>i"wnl;M&UM`$4])&?b;ZBbEaރ XdC,RӖUdIC-'fftf(U0YG GZ:$E=X{Ɩ*́2|٦cu׎TS7uHϮUݘD[O[-e@XA AXl3O99lML-.ӕZ~\,rzIk0L,،ˁ%fD)*ےjUQڣB|[o{P[viCc꽰lcQf .&)ݤEJ7]_ǚ0!=ĥmiQGhKצ9GW)e]%H)<ѢŲK-o5K; #~FR$E(V!q%kiM z"o%{:s(@VN35ЙC T1;*>/ rY9\M࢓hӐ~vfo?Eb|CLjFGڱh:3: Yz͈:m)4isG+ؠLj 'KQfQv:.ȟVX5Oo@8skc1'aA3MjIBqU@.S6.;Yh|R&?#qt#5#/^,}i.47=6}ռ Ctj4#KҌ~)_{eC=ݭm.2 QnSYVA]f8T=sZ8Uh3Ӝ SoE`yJ߲Z!Eyx[a5o5A)W)2oDYiAԷ)23k?hVû!(s]VK:QT/ ̀<Ą$Ey !(ޔ}hۦ((pI?Ęuow" 3#4zVS ySzg#>9yNVIGW)xFK QJi <7*Xb"Lkr)GRiktǛaX^? VG6=}>׈4!4>q$7"P3{iS8zIm$YMM98\̫^H4q# N">R  CR-j ܸv8 L,r@g &GD(Ӑca^cVv ޲8LwHˠ7Cx$žt8Sǁ zz@jgۨVRB-,x`{-`#p>A'̞=iE6fACǰsr)쾒{aۉPS4VHQvcXTG3d.Ty-Np lw DY:ʼn;BRT~p>sE'˰ɨ[5{na0BSSO?< {D~Bv X)٧ QgG֩']2lf`%$ LD3\G|EZiDT SϺ&Z$q5H\}AdDv:@H&A&>T|=cj/.M}eG)+w1&2*[^Sfz) ́Sn?IA{`*`*tsc'+ :i߷ʘٳPSع?CֳER.ʘ ?ni\[z:ImC#.XGx+>f(ϗbMX=U&c,uHw*xjdtI4gKCJο~E?=xLQtȧH/ +˵uyP>0\ qG#Ha" (VGNz"Ə^ I3haM-|ǁ;Zu`sv\F+g>vThLjNK,1|-H`26<*k1US ֬.❟/wx<3%?vKqN#GGurM!麯>a6U'-. C$`= ["5o2(B[wcߍy)(@聒yu. Qk(9\N.-v[oɍzժ75ɺ om}%G]J7/`T]9Y!"zK-€#F*/@Հ җ-8i?Ibjy5LiF oX򈂹}F(ipJ%F E9\zg gͫ s˩!^t"{ #䜭 R\obp<pCe #TOM{喗2w;Z8t. z 9_ oNNj@y<VGXdhvP$8i9 AB8̲*XAzbPG.ȕD#6օQObY,_xpD3rq6ݢ-)⇡sP4B(H;R ;܎Þq|NU-;ۚŧr *Q;A(6~ħ` Z92HQftEvcMA=k2+# e*f`0|D@V M$hyk1#Y'ʡЮyRz KOjh*wz^Z|Xe&=”WF؜z]^tvMYD!!`.$(-" hCÐrzYD!Tt8I+\O={a>FOAڀ˫ڌoOw`n-"$y@tވ>PB3')Y95#eD鬿T,1"Cäy4 @EbΒ+ UWdLH[M>:~4|OE^5-G)ejv eHG۱)Q2"3s"w\l9lCyFvL]y3 FA M&r7*R6?4s#uxHϳQ#5#Wi 9cV}4MeB 4B]Oz5!aZRA#\tH74 tt@ ^ (k=3y0:.'NOf,T}.ݮ=+nJ df%_<0\O9Eq9OΞyk KtW$:mujqzs:yBTU s:ioZD*Aʿ!>@(>Su5$̞`[Xm,ڸ.b+ј^ -apf8/7|74H ᯤ+K(IlpZ^{o~-o:l"p!r r$CN$n 8=:v`jޚ1e|m8op#כɣVQ=H-3=V,$ؒG1Mdžk2HUyp=uH蓐KM"`H VLֺUpSf87HeE,uַnox.rǻzêbUpl`c.1K]V7[s?3OC=OUȭ2?KmCg~ˎˀ3p ksb"fOwb)kk ~$6>{_x N=-,݀ OV2}^荾Mqz{ʭ՟;0"7(Lȿמr)w&9pR*A) (l5d q4#Iߓmz&?x/G x꼰gi[HQ~+ 3!Kjsʍ(soVёdvT38 ,I|JŻ: vVe (^R ެ0`j'~xG!X1aFs"\sNv̂TEfڈ/uo[]Y^U AC<欇R|քD#=8rw*e `y]]o:X e YZ