sssd-tools-1.13.3-60.el6_10.2$>=2{)DhYk>2?d   F .LR\bb b lb b b b!b#jb%T%tb&'6'6- 6(-8-94:GbHHbIbXY\b]b^pbBdźeſflCsssd-tools1.13.360.el6_10.2Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password\>x86-01.bsys.centos.org PCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64P02H0KS@ |5q#0EQ;ao3] 10m:*|MHOr ?sH dC A큤\>d\>d\>d\>d\>d\>^\>d\>d\>d\>d\>d\>Vpn\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[f5c397f38b0775d0cc31c67a713b30ac4c3e8fa5aa1bcb2b98a925080546fa83b94df0ad7e7e6f501583bcaf112d7f37d9a581e72ac22d193501a1f0cbe8b4434875ce29300797ea14c61a6f5396f574330416512a85246c7e01981a4197413242b03063b61c696a558cda4617e82a7c02b5e13948dc9edce397d1a7491e8fcc1d2010459a97c7ad5bbb048b86030355c73e0235c8baca4121f7841274c5bdc7074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45eb180ba6d581afaf319858c367b19f92a887d40697918e6e10cfb37fb4d3d5f69650d72d90ca2e9d64239f9e5500b2ab18a9fc9bdb32fc4d187140ddba6a6f56156350db3af3415feb9708cdeb7b07beaa673c8454aa23a6d9e27264c5fc18a308af39eecb3b573cb1261d1d1ff797e5fb5c461f7fa6566c2f2c9588ed52a215a2044d8ee186fa8e993fb3407381b7d1781e764b0aeb22c6a8e9fc193fbb030da8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90310e7998fa63a7c5fa94fe61532f72c8f103f6563c4f6881aff04fc12c72a2005ffe255bd2d32476ca4c1799d2f0880dff0d56c9346263c9b9166d402797a9597ac16cc6ef9e7cbce3b59721c89187acaf2bf74ee83b4ee16a72939baf79d1c994987c56756375b9c6ccfc6fdd8f141087f1de1a53e2cc7f9c1b8a64812a99c30c3a967ee8747393b7634a732da977cae90cc423f89519e1308b2ffd9d6500d3bce19c9a1c8d59d4467007dfa33a13148574c3b3a56d1f7bd0a5ea4d22a294cba70ab8ee6be09e55ef55d4df5462bb87d9171bb88c9255cdbff05ad1b665ae31cad39da900dd517559c2dfb31180acbf6dbf8c44cca601699638ee846f730575edb3bc87a2ed41ad0b33f8a7ddb198baf564ee3d5f73eed3645c35397882ce809f2b218af5f82c9eebbf77d4cf98c4ddf70d6c5def9fda0c42f60632f639f43d86e3546ea13860efbf7a889f672d22308aeab4854e590a851bb4fa24fc97700e90d2fac6d79054ae2e369e04a4c073e92d8225e8ab05a30acaf0b3abe8dda766545890f5aac5c6199f40080a7eeb9854fc19219f3c01f77ed18a2634b0612ab24e86b6654a933b196c491ffe8e198007de7b7fda4ccb537c9b80b72fefb55ad1535f17778e6082028bdc12926753802980c0dcf57be393e62848a083dc42727874608858fe68353c01c6d95a9faed0a088f539d649702f6a8767cae6050cf898dcaf95c6019e6d32722fd00035cea740bc4ce41bb19bb6ca38c4cfe2e0f4a0d3f33dad94c2a3f116dee94fb53ba321249f03d4cec1bcf19b73f7c078f7d1c466adcfe632e17455f2204564fc7999edcba0264521556b2977eaf32a175e8cbd234295369b56555fa293ee5e0b19d498798c7501cb0d7d6319e225eb1716ec9fc0edfaa451fcae313edcf7e91eaef9fdccdd4bf678e2d0f6641b96cc6efab26c1eea4aef71794a708908f80b961c82161717ec4d38e1071057c37899b4b3abb27f3398af40eafe3262aa2ab33feecf21cd2a580e50c3b041985d2bc82205d9274edf5abf7a81ed70904be6633dc26d7b97f4a822b314b80fc96da3397ef3dc20c0008a9232f1f1efa992089761253a0a8f95c22b77c5c08e61bb610c280853be10623c3aeb7d99a9387a928f8ab52135d04d087a014eabdb31485a16ed13014b2be0178b0c3dbda640d4d716bef05563415f80fe1b1c7e72c16cf8229195371c25b3071b8c84ded1e4e764264645e01c79ca04e28d35ec8d8a4cfe8fae48e131b2ab89b6d644af0d752da4bc9d07c7d932dcf2935dfdd1e96060a0e918db3fe6f7d997fd8dfaa45b2461800d9ad9150efca9c49abdfe42d405cff4649794bd79172b159e6d3e5c8994924c73393b0e032e3f7483f6e2e7a73dfa0d3313996e76fef64c49f786b3c1a5c4815f6067409536b15741536bc49072fc5e4e1c4619e9d46909077a1bc9e7c4fe450efdf4ed0a2dad8b909ef1d21df0d5e88eac935c9e722983bb0ff8cbf948c85031d641cad04ab8c7a4c6bbeee8fc8b54bb9da6b4c3c5046ab861e93605476aa9eaf25d4fb1ea3afdee0006ae36b8b18a3fcb1a6c5c4394e772ebf011b7c016464839f3eab352303c22eb45cceca781af6fa1b1be86f038ee0a1551c458c692a176cfb1ac6fd31854b06abb30f989f3c0c08e4efa80499446766a5877bbd79eb8364840c8d757b54fbbd6c786e22f3a892c1634f79e6161c20bd8eb2ea1815f37dc4a1a4e25d5b1895e8d1e0deb757aac8c898c2d91ae320fd5f44fe907ca0699f8b5273f5db15caabdd336024c509aaad69c18fb7b0a625e6440a939d5b597e5651b5e352d02bdae191c9386e3b979ebb52ab2c19c8ddbb9e1c70b639bee076b4cae6e33a9364ce730a767bd5ea602bf16ea511158759fe440ccd63126c792da795853c00cff6df61b615f3637088e9b73967873aee8136a57029a66ba7707710a6159290b724004daac15e5d12eb34b4354093ebe1b473de61f66330ffa712bee030d86e74250e1d8bb7209d11714bd90c6ba4bb6bafbee663c92ace0d73520617661242ceb9a20f3fb749d86862d8cc834a75d84eec2dcec4e21c1f5df89d94cc5cfca9a5ee641b444b39f437ec81a61e404175cc65bc2d095244b677dd868c382729beb40c65b39675056c207bbcc628a6f174bad6a2d8fab7af4bb505cfee2e0c474c8c8a8b5b50beed5d5a3f60b1361444e0c57ba3ff50fcc864cfec5ae128ed14f4b704de0339d2d7494974747dd3f2f9e825da1113ebe1a94b1083a8cc4ef3605a8025bc7cdc82d85f1489c4aa19354380904482d94c0d736616f5d9f6cff3c187ee1267b28144103ed9697270d1342d52267e10a705c1af7ddf4227a6142374ffd9e27f4a7efd70d905fa35863b0c85b4bc1eb96bdd0fe0b7d5e56f0a45169d89a4503003da23e1189a9cfbfe2ff00f1f9425b5a8b7fc192fbc67c4c9490b7abbf1d45b13881202e6ebff2c4f9aa93abbe60858fb3d23d6ebe40c44b74b30601af44b748967e984e57abd73c5afa1bc2913d9797201403296152bc129b3cc136d547e63c56719f9e25d26656348f8e109aff3b0383ca9907ccd3feebfd2bfafac566da7c49904719a5c1d874f70dddfd278f1667c796fb3c2c00f12d9b519213db2dda1acac178392510542194166731042f5f84c967b50add087cd806f24f2ca1208c5c685d5c88cc2f85cd9b04a5b449fdd89f2fd7648d0b68c2e74d0c7429dd38191248983152bc2d0fe5fe47e9832d526afcbc27a04c903b0f7042dbb1788ac6c5bcf6160d2ebec752292fd9d01d3de34a48da39b22919284fba837857ef85854776014c87199f35518887a91de2811e390aa23569ed3cde3e6de935c6ddaf3908d5b440f791a7e4dee8f11355be78185b97c6162290cbd2b8ecbbc6b231ae4acf6a96178dd7058caefe06d7bf9e6aa87924712ec948046d1489e810ea7bd822bb3e4a8485086ffe1fe36067571b3d8557d391565fdec1a0caa066c1ac0a2b260a150fa879cf48a50f515414444b1d2bd3c6df4968007ebf4eeb61aaf955138377a5d405bff06ea88e9526cdbb100639ff5c2c85ff8ab042cc56b4ab6a25b33cda4c8d0004e180a6a129ea909f6ea9f113b24b4e7dae0cc032a140a66d4aa6226439e643cd091e108d28bc5bdd814ec4c822299ae948b0feeb977f53bd4b10410adc4b4fffb947a32c27cf6729f50e97f8c63952065889c2d74587c5baedcbeec1a368d0ddda626a449e6dbd77e8d6805535c543cd55c29e93c688709038a4571794dec220ecd95a66d394b0c1bfd354f25906f46b7593b2db24b10259acd2957bf0cd8d4c7a46fb8078d57b9c313d582d0710c33949020cd27ecbfa2e51ba767fd99e1aa8ee5d4be965a802fa7ea701d552b9e21a4f512bec4b026ca161eca3889c6c8a0e4e2f1110030b7f2e6501fee112fa99b9e14a3224f92d7666db59e9ab4d7164d1dcb3340812c411432c813c9261d14d810f44392b38b57d7478b094573aa4e97127a9247ca47b430f4255cfd4470d52f9a331cbaa98d3477f7ff3b0d4f7a87c4672f16af2533d31633840505e97a9ce9adbda59ecea7e7aae994039eebba5f6aaf933a61184141bd06a744395ba5b4fe489171633b2ac7e9b056066b82625f0818034a016da47e94706366b72ce374f23ab9433ca46a9c0b9197b9560c30d9ffe6fa0d9a12ae5f26c93cf5da6b44f2b703465fd73ac1d6d4335440c465e5f40f9b58498ae2f16dab232c61fc9b850ec99e9aa2f6d79ce0517c0665660dfcfa9c129fe3e26e8ec465ce1270bcb6a8d2f943d32ae1b38e964ac2841143d7c4c8d1fdceb412fe00b5494c0397e4rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6_10.2.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el6_10.21.13.3-60.el6_10.21.13.3-60.el6_10.24.6.0-14.0-13.0.4-15.2-14.8.0[[ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Michal Židek - 1.13.3-60.2Michal Židek - 1.13.3-60.1Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1636172 - crash in ldb_msg_find_ldb_val- Resolves: rhbz#1576852 - ABRT crash - /usr/libexec/sssd/sssd_nss- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el6_10.21.13.3-60.el6_10.2 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH62]"k%}:w{!vQ_99g/I^NԺb+lZ(evJMmoTH~1Xi*-SÔ,~8Qb< Gb-+dxXQ[[7bդ!⎇-:7)p:";MXE~~7.y5AWkH)鷔(Oz W?6X ̾Ks.CSUb3R2ug/z^1ofPy֧?$ՙ6!v}^\yf*j2W??_7;|BoBEJr41]҇>})g]}jPuXOTOOǐv=.`@%iL數@-qh~*!q|GeݝTyN$8/5d - v-{@ WnכM6zV ]} d^k,=a~;"%0sv1]Bޱ!ŇX-TI\ y es{2|K1ET,f׼5"Oaiԇm2:` X' %vf uPf7ut½GL;N&oCkTT;,{T_l^;( }w!fYPm DYO-UkL[/4Ɠݜz Xj5$[.@7&ȞGG{~݀py0'NɣŮ-?e1Jȝ곐nfeJ< ?$N=$ oQJ()JECU4p[b(8F@FCρ $B K5go EPֽ^ 53fh}ߨ/|j bw_` _Srtt.MH%?=ݦb}^Z}G;km웞I":T ѓkɗ2u4:VKWy8Sh!B^Vq^C~?9)ŭ@FPƈTsn $4˩ ]aeY$ Ї e5;P;hwH0Wϱ W& B0,vqsO370۩qge'( z7Gڄ~]2C, \[Ibh$~rIq*;R~k (x Cl_UGx ܼy?]%փ1"`8 fޏIV_!frf'F"`uNj/Wb;ZIFĴm[ -ka]F]pqHI]giFKܱQRYr~[{Hd?V^.e{24@L'IEzW:M|@y>VEȍ l wؙqM!ir"B|cT Cxi:8b1,μ)g52_{4TJ[9Ī)W *\H/kӒ50:\20]v>F-Y43f]5<JcwN &1ȡl6; -YŲj+.N1y]btR[{5e݁"w1эi:Hv$& 5Q $}9t F>tsw܇rQ[x(~„^4˞d1U`|Ԁ:W6;l A<*S3C]FQl_A TB'鬮0(| PXB5ϓ8ܛfEz|޽q1yܻ&;'Y->vlO\JzR\5LZnt  ZDQl_V&/튜uZ xJjkܰ5ϴg3JV+B`=%mǹ%DY m j huQslܜ1*1gs vMV 4qF{͔2n2$䂃n]׿=w`͹-XBUޟw)!4 b)dyu"G>><X1~WAثwpI kĮTM ϟ4^D}"7˸]*Z#=מc'% nzvbpp~~?KՈ#/3UjV5]Ύ48fݨbj"\~p̩ ('E\C x.QʂIj>S+kJsp[GZNX{-^ם~]ZpBm oS\ɤPPT#,kMrk(RD݅c{IR&*XSN!em͗<#y5P8tuc2ې:_{S0htjC295aQc5verhWj]o@Wq=?yMRJsAű7oOJAQ+&=IeLPPBWWкtd+{ABra$j?:1;weK7坔XѡԶwk 0@ΡHNZ p;->b*rP&XWY[YO&;j-P9~6g,)Gԅ&s<#Ze;$s+y+t F쏱7|4n{m8O;Τu Pe%sBM4)*K{C4_H]gЈDS͚"xsL$FcN;C@{V)~ɬe;>:P2I$hӌXN* XT_RJf7rEw`P^2is$6u'^Z*"i)g b-3>%Y&J'ƬW.="6Gc8iwkT,{v T}P-ܷjZ|LW ˣ,EBcDPEn/ۚ 7H}Nr|q::D8җ/J7E[ZSQʖnq .Q01 gQ\֌M'^I70]3(%ؿ!}d$|hwǗ={Ch:@ [ w@"<;K[:T3g";b}nD׾'Qʿ6<>%mb/)6NU2I;\ݶl"p_EoON'3iJ} _(h`;2Qa ё"akM9 Abv0!>ѹ8zfpɉ/wK9 C,?'A7PXƢgrfh#:uy Y3@)vR)$K{X^'"AZŸݸ»$j_;7rmQbE[p#2H:꽒ƭGO=8%qDT ?.A `qBA/|d-C|W??Xn%Y_p)}ySV]RY3<Y_3_kf8p9 + V- sPc3 f/t\HasJc('Q%ٴ ƒi =5mo}Z*ژq+l)C Tp>\:a%&OŨNZE$U$Od9^^jހU3;9h DUƅ> !fJ_pǝ! \MMݳq7N ѿDv0lK,f4:T)8E0 h%wKYKe|rp2H)O#9U(aC6hɈert/D/&yx{L8W F;P:zٟÚJ]'aUmo0*n y҂_[s(5~@l\_צU)yv4L=1M'@KڨnN_0^ϙKk |o\m(߱ 5+"4K<\BEwې!qw B\T|jɿ9žT|2yPL7ͅv_su+ fx4O[0&Hyi8 >Հ^xhf?`/aj4aəf\^tI`9C-g#G2'Nnmu`6ʴ1b0lڄ4kc\f7h\L|s@[@$J404esb!5p5$-窳s H`&POkr.s1XpD٤$(Keqah)_$ Ceiu%lDjxf=fm9AGNzP䳭PWHn)"]# bvId /1/E5 8W!bru٘f G=7VC$^ȕ K-E%s_ '& /r;S'j |iDbn{ӟbP",_nȌI9CnE^y)ZDڈvAQ#S,6&I}υ(TΜHZfIyX7 KH@M&Tej`T[bcinBXQI2y0Cǃ Ҟ8'\ =ߘ# B@ulZ+>^Ln3Ҫ,WQyKxg)r9N8؋K[I&~~fI[x ]Z]cMa G^Ӆ@PM}Uw**Ӵ 7/i[$ gOdc!?,<7?uumkCIQ\_؎2fҊB sm=bމsƾZߥ 7v<}ւAYM5,xo%JT{ZiG2}v &Ë \wbP"ڍ%s8*\H5c |>.!AYV.ùAdՔvt9ct?RQ9^Ա[Zr`WpԎҲi}ٍ4:Z~7zɰ& a0d8CNGeH)#!p.Q) B6ٱfu`zCĽJ^P6m]g%kM`VjM_ÌT"n߀ඎW͒0c!w|߫LGCz1Kg5Q2|AT勔w^6 UD (,X_^{)-z6`>MпQFb(y"[mM q]f3k<<Ƨz ,RRm<.|oCyD\9ʆ~ҷK< IwnWto~ߑt6 e;C+wV&~Ǥ'@2EGq-9lq$҄d"ʭYnKa Il0^4${g&~Ν) W5_;hX )oյ O_@-߃Z@S_&%t >e8͐hfQ?%󒩔/QLVcLas DQC0h?zY 5 bm1 K 2(SBrU<6NJΡ h$#JH q7_|pg{ݼqi)[|pVf4,o>_/AgrBzҩ;˦0N2k"v; Ggʴi{7{R`Aig` weB(N-Ġ^JPS0Nc@կ=3=l"0jQh>T"()N~1\oO+"~Y F^4=ȋi<߁H΂m7hH֑}),EzW h_ ̠[}$窓Ťu yc. f@(;HMIXjeq3d+}]),acGwk3BеeAz$i~ QG&`=~i.2h.0JC9Ms47ѝ0 (+F@̷68Q(g9fZ (8\\Dڱ"{"} G*Tخɶ%*pMbi;Du$Er$3tqi ?(9v;#, TSR;2jFI@cOCԳzH $۶kj=dE֭?N?7GG<ќ?tG8vTjºW/{;e)uDbL 4Hsn;iΌA1`NO`T';ծHKN7O4!mRirUďUoDVH^Ծ.$؏ĉ{SǑ!XhR+`N9!]:rh !\Fbѓ*6+;`0'0~NR׳6S߸R9wt[Wr{qڵ)۞D̺cڗdgD,H}[5b<L_0$2}K. Jg0'v)8S-C6!RxT?5%:ۓ7 CE/9Xyq챂爤e%KX~Sy >յO}r^wFq8BB^lb}#c#i4P26\=n4) E3C!V)K$Ҝ4د9el[ݜvPpOYCp-9w0{"6$B078)mV4m l~k{ŋad`b DPLsXHg~< i},Avp׽B|lGR]ӹ+(>Pɻs\CI>tJ½ɒn'C; &?gZp`f-sh!oe UUpSWe 8 `;𼬻 EbH#DL)V:Vě^%(Luf)ŕdXArg8=y.rts(r/R[hJx?98gz7W. ,;Re#+n5b%TZ^-N$08L׸\JO-)}F@Annj:au/b^?BD/q+ox4gt[f|YAhyp>k]bqu\CXx(>fP+WgCMa{"DFm}wB}ޏO R䚢kt uQkd; @$"S U}DXQdYBf-hNp~Z8dɫXK/$)7tsV F{>/:gQ*58u, DfWfX0@1">7^G3&>6>DLi(=! nHNTFFhRaNΈMSVRP+Z~:diE)$%Fr2NrBf5͸ĵZ0~ _~V\sxpgٳlvKaR%fޮLƏPMpsV,Pn)P%l>'C槉yLƥ)Jkc`l*-(ƪR)ŘڻMᘁzEukT։#=|<2.͵`K܇-%;tP,;Mn,&+-k)W*zm㡽xj\Ć!I{pA5w9^ARHE7Y@ GTۿ5=3=[^xޯmSq\4 l=H|D1&SSw -yzСA-YBۯXab/ _۔\1dl[uY_"ХHEEXHjhL  {^-;E; 0R}#JsÚ7纂ʺ]Ρ/ eHq.jM/XJ k%(eAۊx3=:VX@ *hO6Eq?"XR Eyex#h(j^QqN|9z*ɑ>:pUKg)W_P FymyML;ÕKK8XnZc)ӷtded$a2.7bOG/*Ey،hmO5[W̶- Du|w:VPPwE4r. !^DxrRGl3dAl3^rFNnI.ftfס=Ј S6@ՆQDcXS)7(eX/TGCmh?O^g#AZUԻ?pR{2;upx褏 @[\S1H(߮w|%jrDuzߞ mVF \K˸ .sk \~P7A1"z`:ըlOe׍kitPr&5P%'ȗDۄ"[F 27bI")RHf@'ZSCpL`ͯȁf ۫r)w9r.AB0\('ްWw}_te\K]ATew% `n4֫`OK<νxɟ$fJ-A^g&F\e 7vNJ0u3$)L&&oLx1ĄA?AlPs- 1nERD_L3ft ]껑Vb^=3>V=z̵8f=cg0Iح4]DGJqd€{^A68IrlZok~o *Vi/` ܉G̦c߮7]Rr3$vG3OBǸ3urNuQAOUPN) W"ͻc699ZWa:3gsJ~JET>i_^ z{-knP<RݯBTt/@f:rqPLK`芒0*aGCNHL>K K`v#%07,=-[SY 3s Ж!IG+ ú px"+D{G}J h~\ !XcC5SWzpqw>ya`!2(wwR7^ww_')ď=%i[Q.{Hy*p3m<ڲYdbOB6辉(ٯj,LԴܳkB,d.aXhzatԢߝ%~J @vhO%aF7O&;8MH 5`~ 8-q;4̾+&c>HbJ Gyf!*i{wJY۹̼][  X؊F_,m 񔀰PH仺ȫ=KmP=DRe )[ᴶFtdX&oQӡ9?D_ (LrI!.:m]|so„2_ 4Ѱd<,wx[Dj \6E"< 7Ԙ?bTyr v.o#Jf\doWЕkv㶠zޥGɌ.O =RpߚDF<$lS{KxSJZ_XXٶBz2^W:_HK"H<ګ!"+R2d<5E'q7f@4;xm@s{W5uG)yaYiKYPkya2o6 KDo'??V_pdF?%Px/%jZ^RZ8x4 {@ЉjbdVF.#>#am$@}? ~hڄiH.f:sdFZx\LO*o@>n8<*ZGKT@%2w)2`Sf2[(ڑPfKe$m=H#ʍF8HacوI#)MS׻ GuKcj\T;@٪5slu)} ?K;2Rr}h4><^EҰ&⸝Cr&k=2!MXNiAMEY=*2w E?+z!*h8dJطތ؆"31v蔨i.?tPT$,(_J teqd)_4t  eYkֽu JaV8䅔).z.<=%n8?y?‘fƲ>PR,aY]A0ύK. Ũ] 'a̘<@'GWpLFmkdQV*@)GR60i{d{>mYcNmd<'J85/wڮi០ƻ 17?zW~*c]_s-L%΄XoxQ~z䶾s n4dP!`?#&ͱ0!,åڭ]-bP'z;1Ei]R _h@yߋu=`I O>g-1鯏 k_ŷ5̔:zyi⾒4lQB94Ǭ1W80t~g gVA{Qo 8m֐ hhJ~vA?%~A`Ej AHF^Th4>8 .( ?y2{yGKK>vh%ZWE̟V6Y ui[]RC%R"!٫_yt2?s6O_;[MC qCֳ,H?U,0Q^k_ |]X9x(5TJ}Ƿ6WM(V$4i*ȩj! /T*8GuUBfBK>G?&Wz0ޅPFdc)h Y:APΩn;]ÃBhG6|J W꿖$vjoVݼ~/ E`pHArUS%75vZb,H<;E\C =Ho &8q' uϬzVKD*;z2T%Qfeh?ԃ[d nGPܻnn(.rBMaz8tʠH:bԞo/\SآixK1RBD=mJ SC[vj:BX2vuei2Nb`}P)j}Z㸫b0dP: lgq [S UXtpŷD?]MnLkGڬ$;zqfu)!S̒:8?7:>crX",SI{=ꩱ,cja l_4\8bYrJfPl3np\ZMuRЅ׿"R0+?}0y$|zi~*ԝ`E=ZHl畎 6*=ZTHRZ8Ƶ-7FP!9 Yv' fܒYUgwa%,^8#A" P> A:Ҿ pO/Kɝٿ/Y[BUXfqEߟyZejU ePoZ6;S>$6r[t Ԗ] +g!36gsd U$Bv`t DTЭbG wg5zz$voZeO<.ɘz *gD܁(g%kqLb x=*d "F'~CgHMnp6M1^4zAS4hx ^OP(0;/5%1 E܋D׵^^a`oQP$PRe Үz,O|tTe.J촰wP3?7$nM G Ʒ-ɌdL*ρ'l31y%䭽=~g֥hX7Duǎy7s"L$!;yJ)95JrZtLi4@.Ycg͇D_7#c5Z6,0-UسFI;=""Kciz#q#l4p&7 IOI85!n,/4g6|mbӦMdwZkPӍ:<Wt?}cЖ\os 4zO'KDҧ_~+GœW!㮪m%b{)i3+X%R-X74.K Z{Єx` gU)[i|}9}2A3\Q2ċ9tt݅hDƩ!8㚂]ηxfW'Wpty򙰽 Ll x9!e"]oơffi (cb`tշˡE'/V=vz-I^noH-xǞs@QGSv^S!h~WhYm |MV;v1,*ȁwCgR3=#Yk> m>~F y\kVV1otKpƪGt!h8E8bwDl`ڌ St;jk,dֹ.عJ*1o2G5א5͉RѬI^z&U\ɸxJ )t Q_~ɝ+V8Hɯd:(3@.)jOunQDT>e#2pgɰNLɀqox*23vYP艱I$T;´:!sXppkг7H2_…zaadhtOMY9.EW5[T%5%%skIۉFvB)!*׳`#nbG1GVF5q`2eӅm6m0x̏٘aޛ9N`Uxbc ?hTț~z^Ւ޺*܄kF7yy&Ef>-[ƙB& D߶eO "Ts:WޘRR)<>c +OF/Ί4gB |Ϊk~4 r0ZR]0Y |ixUS_{Vt ވ޳2hFӳhp_*,XnTo;DluQ奎clhc]gZG7KܷA֜ 00=|:)겳P bA}՚±/bijt4Jz1^n'= I4Ɵ~Y%䈄eOԳfnU_DӤ0˻&'!C&tgw|x=3b]| Q:kpծO< %}ۄ0!6ev+skr B3hd%aL}M/HvZ~'t?@g` RMQ&r)^ ?` NUEBq9,M8Ƅ,`@GOQGÝbQaX8PYj,iQ>!_WA|_W53AYqp#>j~%y}@H51U{rFhB@B+@>J9ќ+ s(zcױ "^vT\$Gĥ.Eo]cЌԩI`e:}/]Lҝɣ}-Dnqg~|XVTI ɣ Ya0yڪQ ؛[?q>hx.̢v: ׈@Mv3F|jʽ]͆ՠgƘ S Re-XFXh4zH_۔-y/k&A=x=m"은4%Omu753SY fF 8AOUeKC~%*F,íĘ0RV:Ę HPȚJה@@D7s\Ҁ!c?::#fh$8o C3|`aYٝ}}q**$=B>(_'c.z/fd5[X;K2g%j/crcjlL) Ϸ4uFxC6Ddk\ך 6h&B(]׺;ȃi?q 8H\h~@螖L21n 4Dc *M+!gQWj~eL)lz:*}ĈǼ EֶsqJ%T@skD$l#ʋ_ #M(GaǢZ-!W6s =K+9ʤg3-K揷*P\qSB  1ٚKme"PqV1<ߋ08|fw5hf.e۸IeEI&W;fQ߁m.g\.j#mB6sjSiN5[5Y7-yR않Zv0fT ӇG .`ܒ˘c8IήWy6!+mH?6`~&i_d4]J9Hi/K6Q{P=ɎJsG߫O}!Di2lJ.Wf5Ozt:GKHJjh5c7aOW\;HKr=] 0MZJa\:7ǘ\3*:;x' 5v֭S[#b+G'ђT*C y.࿌6Lk9fd3Ƨij=H`(voQ+-]}E;ኴGn@1L.עY>Ӊ<>tI\qK3glQfm>jJ9n2jڔ (kYmDx!Qǎce(h(BNhN.F`޷Y`GQe?G=#A8qL@.%owu};wh諒\/kZ| k^!h-α%hcv fy`S5la!Q@9ASͤ1r%;(t<༨q>c |uoqT{e,C`4iAD$@\8ϵBTj9㼖\A41sZ$WVnj+ Z|oNn8Ըۖ\/,SK)yk;_DNq+s1:sٙ$nɮBwXEtlmexHoS#Z%Y~W?,ind$Vdi׹ KVLpKqP5,|%ƄQ ZXO< 6C$7>65؎y[{(Jgly,4ٝhqK=% #im]uGLoۼa3,P[ퟺ`_/!VtX.v,Fy1 .~!#euObFP XʇV/G IUATܦ4ٷhXЄUO"Kl|v3j k/T'VѠ64@P.<d>S4M &QZOzaٗ@k~g/('Iurt@խM2gdH[3WYiY!ADg 9Hc z {8g:pQ 4Ǭ;i=$zp= [BsfcAP<? ےڤg6Cv-pk IoJ4k$ϳ/;`/Lԑ(b^V/ujZ_׫n 8Ś; 5S7Q,|K3vnҲA:)LB E!F`æܤ*v.6G_v;#>z8EyHp^ِErZPD?hTFoWa@jO%q1rfe "B-֭v }[Zvjs⶚A}i2.FdC1,j1T|uCl<*Qt?)>w&t([ WgaK2^ ddB{ݷ LX4sc@s-z,w[̃@q!?v6m` ż=3j<>=W!U:FwV'nyDM3=c8΋𼏃ܠ2ޑ{tXHqu պURۋL4IAF4>HOgw pe~ѡ۳]EI4?qRޅ$(G}N)Б?.'pGN%R}HJRt,ȯY kਕ|;(Y:E 3jNdgPm=[r ?y32 t*P:` 4*0k! $Z[~׳rGYk߂ SJcw/20ڴ@t<$y{7K<0EwNC­}CҜmv&Ny(cn[ 0!TYArubn\6s\ ,>7! &yxC򲏶8YEvIJp8:.9MN=~Y/U*|I v+ M{-b.ZQ|d?@[#˭/Xk.,Q\rHHg:4M>iO6ljJwhƑӿjKouR oi#n'-o4 I=ۣ1aǸ `ӓw|W3"a<:w}[x -gƺ?=d`cqxB~k(RErgUVh:dBsd/sb[le1l8*#4(X3GXf)~r B!fGh~49@jľԗ?cy̻; Ta6UxsAONC#$ɯY(8xMs`EgO٦kZ1^YDdl֬HLQc<Ĥw QWY|Աpat3ˆ\\Oz} =,rO\j R^J56c!Jkk*Gdӹw1fD3y)IZ67M?w̟0;2q9"Nq]V2?Jp#yb77R|DY|K&G1,O4+1yt^]' ' ,HLd.8xj1xG@`Bs`0$3T+KhT L]@W[+a RN ޭf8=A?x\q jfDYN1)n) 5@p5C+<Ђ{r`I­g !3rc«pLH9 3 fc]RGL 1&P=Bbi!%-}L_ޗ֑;B.|&a;CNݨk}jS{ GG#!Ig/Wk#'g/=t=trws~% RSю?ts.XBPRK*Fg#<4Dv(~Wyt,3=Dǿ_f)Ba_Ew4gdM֦#Dw V90=G-WvW*cGhjy7tN~8h: ]YOH,kMiJ6)K&^t^4P%Yz'r9?(|B-m# f: Xu 6$OT%'%J6 9ׁLKrY'3!|C:nsMW,!?;j?Po-6*vJiВ& Z xHyMGB/`hk{c*dҫj_IX랙94GB$s4La)l ȭ& עlE噪,o ?ބO%)! )1pl0HԣP8|j]Gp=>_)7> Ʈ#GND!fp+ʍz滸l:3W$U&fwJ6.s\{S%Xa& `(!)WR@'B:א'Vfm:0OTY9)q~?(8"[[ IZLm>LJom=ξl))  foscFmR5LӫT9 i8La#p7aioWg+saw_c;2CwqZPQ䤏/'+ J</% U9V#N) bmjj1DIϐ`O 9s}p˜}EM6/rsc߅N&[(OmpfCғ7+:;{\OA).ce83f<*r4b;De44 nӥzœ5gQƴ"r9^~NVV$곶nv¡Ch)l*;t8PtWW*v5oT?M I=j^/vMX];LIm;NTQA8nm!P+_8k,7s5/-'#JI4ۍCP#Mq{my_J|0ܗjHd7(_kumv{ \ۻ<}BT'-g* jJ #?^<C, {8'Na[_Swi|I̘KIº ?s[.H5Tnw ޹qFp(o$XeفQ{qLEɛV|Oڀ C}~f&öP:-@IG)!e ھ`!^ µ''9S*Ď2'c}%q|hhQndN.[!5ņ$PUg%#'Zw!Ւg=ui-e'hBxfiWFnbQ8'WAPBaKv^o,-* _EA"\<%Wu E}nssD=7X{Q9oUR]qRgb4dw)}BnI`'LTwwBW~L鵻d^IgD4V^WwMb QrS breLJ.>pg0`]싋bu,[OoHBd1}:B5a\/<3EK:rXzuMj_ ,w=䃼n*DOAoxڷx~'/^t5:Vs>ı;(9}֎{BŶ.,Rׅ҄I6 $ ~2-y,#Ls@)"™ǖ:G}XGéPҢ 7k#QF,ryb{֯,Fr ;htg=DlR۩Fx0{gN5\k>w]$6, yND8ʫtj|#S@FTX.(e#Ex e'3*N#ex/)%y͜s1 <59 φŽk~L}Y{ oG ZOE=j>6#. |K.Q+ f/C KptC4n[a֓8? cλL׃uFNWAJvn(Tu(m,IXj7_п^2١gQbsB8Il.Hx9TL).p:Gb`bk +Qm j0Un3M*#AfqeۆCx1;1dAq8-Pߧ_\ř Sl#~\+|JܥאQ[Y>wIcqWsf|BEJ씼`EM慻NB?W(Yj 'A H`xNՉN :+6& QJM2]{WD +wgԃ"(E><"o;[VL( ffsV\Z݊WFd\X|nPT~I"gp&Oo /tBn@XY5N̨cꚚ%[T~`DbC .੺|O" -MTU.1]?M'E-Mՙ1lM>I5piI Cc^F}WSb_MLI^`WkBnC'sY_Yq$$;M݊ZSe΋| яx-&ѭ^4"֒Iwy;ƈ!Q, a.r}D>jPN;%%M wB|#nӷql(J§UnsSMR!Q)*Ɖ{V qClm6dO-`8T"El҂oBhB`ƅdfWuK/9ϕxUZO#ۡ,&EVkpM9fr]MGʃ\Q}˂-~B0oMEe3;qF8ao~L4Iv?n:L"˿6pu@nR+]FYJ㡹X9߭ĭgǸ ;b]u.XRQ:D<ƹey)PJ }O+%I[9d.ǿAK&pԿ[*aO4V=U _ ymF4-tzEOKb2Fy*:$ѽH(>b[~cjk_r0™~/t9 Z;)r}ՊQke(a?غ DR ]]O;~٘"r%cH3nqwirR{gQ@^"JХŋn nf]g5K.귂a+Sz:y :f=J)"^ǰrWE5cL1YL·د$[^ (D2JݻjZ,q UqXVk]B -0֗L:Lh!y''la!8rgfU(9U_;'kҧ\r3D_8C= jD5wv|k?S@cWH$~0mbЬ+13%E*GJ"O ʘ3U1Z[t=Qe6#$ǚleD-',Vm%m!6V-s߽ĿdECnqج^Q!ʇҪzhf^R1D{F" KXKo |p|W^Vc-ֵDVGE`hPB/Jdѫ$ ""'x`sf<1'9Z>8,>Zծ=' :+-/8:@ޮ Dhy]84^J:iE1cOJ9zmIH9ƐA|F%U*Vʷ؇fa@S1 i9ѐvP"/=|2h7wAa Ԕ|'] -08B膙KcrVs $Nb}X c=˔362(&\v[#K)_ 9Gi,}}]wٸPKg8s^BxVNg@f*=9%u;7iW&@<^5VeAؿo>ڠb]O }t:F1s~{eq)d%5^t*4Vbkαpe#'*c5|:A 9`V*[:j}QWڊoؐ%}WEpdmS @-X0$UIk~QxI Q1nডRkK͢C|v2ڶnF0d:i~w6Y4{Rv{1]$k$ ePa_*1pzTͶK]XvӢ[ӻ;$:e˜ƭ{t[`?&ǎ!_'-j}x0@Ye. %Tэ328-| bs#;dk$`vK1ڤ>6^GP\{b)[׬_wO|V'.QhrKdٶi}f{c_Y"5>ԐeF7= |@[3Ŀ^O[627GtWn:4 5ػz"oG,1`KpiJYkJct:)y$HU)\ZRz)܍tQ+uhifddV{uX(M*J㌄N탘H[0):T%vjG]C5u,I!3eBPCf?PꂑVJ%\^p\֛A%Om1`0c 2nD5̀Hm Z Y? mN6@Z.9bGouvm]_}Tw'_SгذeR>j ze<_*7n,hcDKdߥHJǥܒ@ړJ7*i5 P`=7[wj2..qiΔ2?FryRy_߳ak9qq&Zo..Cw*\e qw!6>.49Cٗyy 0x<:ɚ]{0VYUE+|$=.l8* 88U! 9VDiPGܪiSQogpV{`a]{Pnnwܞk[n3ۦfO^!G[@=OůbM%j݉ %NU\NXaGPP0qKW*|0XWBS|H<{9-F2tC`+}-}'uÑNH@Xq+>Qa4HŢ J1lnM¥ lD '#>`vshρ?0[ٷ16K4jE,ڿp1vՈbKuުC!eQu4 _]`Pk?ɧG){_͗-,!J[!W-|!*iyiB^FHLX9` $oO%dR? GY. s"?(1BR5Rr]AI饷jT_c VԻHp*;Bcݻf0y7Beb7d0L:M)~WEH}ɚ<̤e UtRVf>}`f%[ ;g?:70ڿ=BH&_65ͥ@[H z#7:|%qyL-D4e2F ;Bd_:Ym)JHY+F-VPxg\`d% &O*+].h*[/.OZY] Or3i!Ru5g7lY9r6o]PA!x)3t 5@Z!S,Y,NնqU /BAY$cl hR$!~(GdƻZq<Cnqլ]&?H${W4* !Z0:~qxQǠgS4\#|VI)UM ~%ԟԸ6 0Zmk dE0Ms92b5j=oWͰ遻:u@`nq[TH#Vt2Xr+u vzwoqb[%r6R8PiKH8xo'{7 Z<8"|>\;=D'[QE sE/,/wNO;R`Xѥ}5#q >O%~pw73O>Qn7,H~\{vEM.ƧxL-o3z+@%zJ>(%F⽰-= *mi1CI:!cŴr0@ΰ{> ԯ#"ob ``kDuV ]wfQkμ'_#iǤa{!躨8`M3&4ucT0Ʃ[Svp%R8jYHeP&ۣApv\!0T yرWȐtAwYnMJZïǾ < BD (,RP;So4Y]dm%Xx*, =4 Zn n)rgwIو٣^>6D# 9; rbFY@|>h#VވRt!I)԰pSARL[w~07?ÜPͪa)ZuЪqJa:l {39Kw۠ʍQsU5 |t{U.oO' ČÇYK ;fpҘR%ZtN]L0Qj?x+{}k'ZC/4!sFoOdw>n9ԧ>@I7V"GM@s#Ff0HŬ .E8(gs|j 1#"G~k*w=v[J7B r$S=rv ƣAKRKcUmD\w Rx\3'0/T}ͩ>Ik2X;^{}q,[X%9 o] Nڠm YdYF X'ʢ6t@ŢBP☿ I*S`avxR ]+M'" oIN`F ϑ7U L'nrnu3W=ح9h9HorELHpnF뒾@:t:)2n/Ք+\6=/jr)rAMN^AmJ!@^sA~~ZAFKd_y=f5U>/N'_4*o\?˧bLQ(ɛnf~[n>gVwK$޸W|uKB]7uj;Z tUG5oj9dlF)?Il GYh^rF-PoMs83j#dFK՝"ҋu++V 4/Ӌ\aњk'TerHGKBU!ظqP13(C՝U=ţ iX,܏Bu4ԈDgcU#. ˾/TBUS^eTy|?pRXŐCK@[Ay@.Á1)>Ww-?L%|ޫgV%]æ~gzԜ;2|$4l} `,ܼzN D@h4'P)Ķe1iRTX8-!J1> &qb">3?WFǍ/$БC"ǚ=0Nx?^Le_ ĝ)OC,їqE 0Q)I ;so9R.L`+ sZh1_X{ΫjwȄ6̃pvL @y@bHl8!e:ʩM,ema_\ 9/d;O`)ȓ4OR9oz&J0EBuM=-me"#SU`K< r<`(}m-ھ@^9F[(x%{8.ǛWr_$0oLCq{:܀K_n\Ɨ쇉Z$~Dj=F!阳xZ0%|Yf`g07W%XhIg[h]ayHko*[;.8)>@.sSvN KZhK*A/l'Vj\#$sןohϣzIG^z?T:I \\pz ;IIZu(K8yY*ր rD-Q8T5.:ك qZ4vӓr o,ICĹs1rQ=ݣa:x9pۙ*Nͳ],p("y#I9眑*6O`K}`5'Dzcg'nVla3G=*| l4t"zi0Θ5!Yȭ^dS0gUAxpif wE#'QK_H*J$6ʍnٖ]{ /xp& '&V3uyGP#'3}~=1|FS_?qqt&E(:^M{ X>Nj|JŸ×O5"vOnS0` &UMѤR2!$eW|u^i8ٺy}6;k;_hs(U7Y=`~b-M$8, |W'VWd@0nx=#k`Sõc+?"Y#Pse#" Hzq`/,+_">(ܐsG}O4dNJ]MxtdyIfˆRƜ<) f~Je6T2~eG[?^E^ڰ o2ǵL;n+m"P7~ //';gBe-'zL$u;^:%#<$qoCoT}9Ϳ XB.9+Ɩ\<?F ֟{Bڌю>Zᚫ".VvΓr%2!M);y~U*'YP`-^rrج=QQлŌz:[z9qfb`cc|{l{:vAlŞ93L}Ben&} ̺8&6b4AT"6?Iac{i19 xp&ŗ'Z_r%,W셤Oӭl5D[mг6ݾ*fa!WqOM23+f[HǕ^YE6%M󼓉>뚖 ^e'Ji6nj/\ctc3j_.֝H3bzjs)6B?pNV|bPU! y9tYrTOuh{¬TbqlNƧu ͺ镣/B!]Ot^W?MJ*,-7W~텺[%/*v%8GpnJFs_'DU`U4Mc^N߯sy*ltbօt0[wU]K: VLT?$a%qXLmI=WFt? G?ia%?H K_tX^0{ iD\gEQttR!`{#Ej><´¡1ȺI̜@%^ͫĄ>o_9.wG:/wSGű`?ܯ]K lIX~wfI7hO]N+۰Uʧ&k /,9t|ooija$:_@JmEE֫1g͍3gBPpqxߒߚ-0ۓrn5 jlD=",&e06m4pZM]j j_31 ɑ5,LD0 l]CWf{1~8F7=Q 4mS/ (ɪ86H][j"V(nLfUpӽ}A \(7Y S)xrVEOl,>lK Str^_ע~מ#9<ӝh#dÿp8цyZYCr)URM_.IF ȓfJr`4>8S1v'}j\03|2`U; :]uݯvO4.ZIdk\[v0RO9s%(hdh)q=],eX>Gvyxg<1l)Փoʛ^1MV.=Е@`o1-Oh'V}u8UCYlsYbݠsh|A@>aW!.Thb6dk~Kʑ 'J]zBFor/-uoF޸zlANh쾎@h Z}(o5Sc38B~&RU4hְ&m3ȧ!166FCf6?>Ow!~q~+k"\o$_m $2Q*=2hu,#u8d0 zWTѕDQpb2zc/ RS$#aB{L4S[jC~li||%w㝮]% T?Z;1ɹU=i-(OYn",鑠# 1<.Ǘ&nωgIsGf薂!ݽq hFAVԷ&51dur)}L6{$зqR( Qk<^Z ?m_nLGu ~s:EnXhO7Bp,co-UQHKQbd B+#,yqkD=CYF_mu,+ak?vjW'OO@p\'`Mٳ2_Ke;MJDQ2F Xr.(!ᕴnH Pje|CHMkr¦**4]->CqD :ijXo !I++d.0uf*s.=ϼN500q sy&UXUvu< +Q(qOX1g&Btec+&E+ܒ*0ңo[;ݔlSzL>x4Mn.OMfG;hy1Lȷ ӋbyT?[$b],X$bLdG) KPg;u^lh,MQϰ2ǝ-'"Htpt@O1x'iӕ6tkEQKS}| T.P1t=S3Kc[QUhJ['lΨ<8Qh-frHbNiۍFb?б\}fF`]Hp:֒]8sR"OS`/*M>@Ks)1w T]KunUrv bѬ)BRs!ޙֺ%;=lu,D29@CDu%a$N-%HMﯹ`O)XK].X35!@3pu:1Ȭ$Ƣ)T Ou@efSMJ0іQmAr 9EҨAj (?5(690/u:Q¦rNHHXlJ<1|PͯʃnK-їN!`x}NiJ0RNݗFH#ͨs3ȱ=6 i;pOሑO#OO@#ș[Ģy3*a!>5 /v#I"_pZm>r \@#18 ۴gG9k*WņË֪:%?2ą*5B"53&v]pȨo"a` x B] @) >Ê7g xhH/OmmlþAH8ի^{Y%]Jre4|0uDZ)VTC?R}F\ߥX5RC4SD*k:fϹKYa-e1nN+bE3+60duqJD\l,%Y? .EJ rVA-Me* ]\Biroe+%h9fY6VjgQϻ&@ј#5_k+@lRrHt:c#7ne,-;3I:#Wp6f);yO;.$"]q#6biN@ҎLeF=/ (e8?4SdZ(͑X̕ip_hD[Z=#抶yz<{"GKWYT#ԵފUoPx=gwL1o#N.ozF~Mfƹ0mT67fesE1lpdB~/TdWM_˪kp* ^;Qk??)+JR<x Aej."}6M)yvЄG`wH:bwW oRf@W?!Mlu#n-Xb&ky5-HsojUwRZMeBe`~ +co#l{BL &gdd/KQbjo=n6xn'g6݂V^ fdә}2MvB%OMf_^<g?{R9ܸbVi|{C*zEqn/_9qn#D8S}H8bcVq(Sg;$7  e7-ZzJ m'*a+9$vs% }StP%{p3'i?0ٴf*86 3.맲ك/CՓnk sOr=MfJHcbYnMp뚼-RTM=W& 0D(h1^2&[#[.ynLLKA1AZB:xYW/ގܙ{hf ys.p?X jLhWR_p-tbZV1ei}~߅SPf)F@DhYvgz`IE%[[ /\r /.eW_EAB$9JD(2b6v$XG%<ޟ DH_ݯXtU9ի̘S+D}"*m>O9_kJ@s$t7|:r E΂}\;M$C91T=Ӂ!-5|FETv6}ͭSrSssFR\q7pi;|ar9稞H-6w? $v42ѯb|w:)MƸ׮^3W9Hiyw(3ALk"f gűbVMj|'Z-0ڿaL5yA[ނ4u6}- +D "E$aOo gn78)=@u>M&rԦQp. )/C0#z5x ײTFR@JM#j\ze=ɈXVE-ZchjAs-5ZPov ˈaWmgppisg-L6?^;\Os ckU}&ch> ;cг!# 4f'U!_6+2 V&Qoå!ZeP]:BFfz9 G%<)Vآ>G) #X.c<H6gF4UYt|??AMJ kY q-a G7+VVJ91j/).a*)LpK꼛[@lVnVi TRP)'٦$;@rhs']4Oj2gᆲ*k2RF6x¢YFO.e؇71UUY`KPD, eƖpx+i&q3L+Z0Ť$:"y 7w7WXgxf7l0 ne il wAYzG[(NIr{0kXg Dd 􁥙֊hK[ʠE|ދ쨻YN _.-n2nﺴFxZa!og=ГIݞ0Wswn`Kfɺ~&e@[椡Jު~0z6Y-6U Cx<p#0׫Af/*ckBZvtmfK O&r&ҙ/d +6sy]7_ \TVASJ3\\oOC ;lU6̸HBmܘ dtKk.r\ qN|mgLTgi3m, I!)-{3lK27FIA =IU͓"  * >9w< W#ا -M-+#jo {1ro|F .J/]ɻ0`37y>5B2K&]4B +do?7Y.%ze߼?_nXPף+ԇBT1瞴*M)ZjOq]&W+֞ $@ފ!r{ӂ4B껌Pϗaծ*FGO7$РhоVRaΌa17=ԕ={ /fLv'&Ji zf Obr=ڄy^*~'"W7?Nw4ƌAڠy&} vCZ- lq@;WkoZc=ˆo(| 2jB9[X!q֞kUP M19#Ngi2<;2k(}Әڹek/wy ۛ@إGU{i|P-dǷE~,<b,B\}o4 9mĬ53jR&=zEQAw&3ㅷUnXpIWty6s ;oe,aA|*Dlը̬hᯮbs>ZA+WA~bLUG.{UeRkf<:4>dC^CmjMRAy6%ih$UVf+Lápu}A}RKxv0Yԑ;˂y_{أ aj*fgo- Gkf.4Gx`rX҅"~)+2|nfBp(B, b4DD}_EzDd5#_BNmwp7(8ŽŽ\ƸR&UǭƉ'Vz_p꼡%)X}%д/h|~6 @XEAJ+3 "x.IA2ᚽ;_ !(/!r j*zЦ\MGҾhџ7G$#<.!ŇSu3E+WsROx&ŻY3Row6sW ixQ ~x)ȯj\[2'<6?Ŷ~8|5B YHV^&zvu!,]WcD73xT+p(fD;q< Gm-< b*<µ[OXEy5[`dQ\ؿbضZBk})nfm (޴r 3&cfIJA>!_F_h ,H/DZ`?<;bp9C| iv: f)"xdKn h[`$,'<*baX7+xAlY Ci}l*YCi-n4ItǸ\qR'Nʸ`x:T 맶.'85nxء`{3EScQxڙj%e x,-߉Ϛp:)sơcАX൶jmRa)e'ZR WsLtZw .ز_2UiBv_g ˨.C\W ,X-p.3ZhTu~.% ӧ|uJߕ_:X^!/W &M~4~Znٮa;O#/!zcS+c'Y~Q&(6ctEzօNpy¨+1$!P9`-]XPra/61 0Qfp G'A3אtEl/y2t[,*bƂɾV NYuZ|MO6ʨ\ЧTz<z ,˳Re_hm m&Y<|$Ḫa:8 䟅T/YN^BI}/gp6eå=HS4H/]o" Y9jb8nWJM?ggf7\钱>T(+8k$9&p?il ,FBp%L93NLg8\]EaE \'R9Z>A~9_7CLcv]#uwi-1V!7ZŸ1 *P!7hlLTA( sݵZ"?u607`Cľiᰩ+&hpCRffC^&Z`M^ʶR0~0y}}AZo[oQ"%[ #֕^T҇z|k4G2@ l2j4r Lg}C$@oG`nf)2p"[?7SUƺA[,7ۢOXJעr շh2Oz')B5|B&y4Wړ"(l: !e3TCͣ 1i*ic71H^%lFuƴQ)kS7_5'q&"8,1qOQ(d"=b2xM-?EqwOrUj pu=I ӵS:s[&>9bi$C<nяh:{9R63J2A5X(Wn %M v;O} ԅ ~&L8s-xI\[RGr; ^$PBqb"궪jŕ%ƣӎׁL(]!Z@z: QVIuxlZ`j=3M!8@'VR `۔:J[R!u/~&㵤%#Q}<_)ENRwʡ"0ӄ@ Ax) ]i*>Ś,d_nqq}0meA#ڇDk; 4AufN7ϸb]iE*lDJո1g -B}((ʞ`S}y;wK7:j-C :Nذkq (y6J̮PMU6Bvt.=Zx6zF۴dCelz5 Ļ֎(;+V!Ç1RJ@_8%2- /kBA~m&8E@&1)B#9G' *k t`H30XCwoe w]/I&b:׷L1Kv}HEP-GE^3רqlia \MʦyX~OH?2{coX˲?rZXiǀ1~a}30ewRs#;jƴeb*\;H#6֖LE;\-3(V)ug|ɕ WN?uuxLW-η Igh *jN&B_>0tk( -tWI/[w$#.@yxphDͿ$ f?ϢL=ƀf™ϡ ENF)J kTF.;9ȸvY7hu9ބUh䠕 tڦjީӮ"$a2hv|hX.Nj͕5`[IPL.Z.$diM " ?70} \q2Hr$Un+űRڑ~b lXwq'՞E(^J(k8֫+k2j dJ`_|( /7|TI$ur8Cf%Bʞ8a@'-Zۭ;[6Y}fE+ifiv 0 %?|41i;0Q~L <=oq HA'}&бP%0$D-oGTՋv++6ti j7.;=/{K5r^촩]I̳Pp= B.ag9a[ۗʗpDOQjl~T-w\]v(OY}`-am|0kLu+Ip6=OGVUKioAQ㥥6sF <qKpmk=vscmfnPԔzsoW0٤ICyhk**rpt+ L \5QTrn_RX= 3TatMpYA5#T2m8e3›4W!g|Wm~uOK~@"[{S*j 8;bBB[r ܵP@x:Ъ[g2<^ Ѱ_!FyDK5PDJbn9 Ofӟ { 0K8@m,M@$DIja> VCD*:\Ele2d0l̓ހL@Dk+iټT^TVd~.8ChSt݈ƴD(%0[)u<3>B@4-KqfNI=[i/@,EyUlbG[ElL)Y{c$)T߮ 46V'l<{q ]RT5 aCYWM:&^cv\} r W׏7bx.1Ny :&ҵqXA]M%'!Lo!1P7?)+\!IP{9P`4OG2 (miQ~K 6"-$Jb,:RIFUIbĸ̶V'ͥ:OnTpvgSjYlU2$;!=@iWFV}SokAou&Ť Y<rpg@'%,VL&6W ensnD($A[~Ƒ> $51V`<`cj5X0<s@a󕀫Nο\0g`^16"%}Dgy)7IORzTQ."4B0,XOq7hҮfef 0Sns^l3~{7/dP9]ݤQ&C m̀'0 j<߸P'^)n*wƒ;h߭@]vei3q1F<\͌j_D {iy WJ&Md7q4yq[#d#*f [@=×n͏*=Z>o̺4S, Xg [w#w,[5f ?5 <ͯ1 sa;dTjEe,!b8;Lc@?{jFZR xRv~V't£baW@wTWeí]-%l]i5u|CΞ۴_'H(vo-1IIo.D5?毴q|7rġꔅPSΨ b8% oQ;KR 79m՗ʹEu, gtExSy'ňe. \B`V>(I1[QeuCb;OxHݦ3$5P> ๯0Zx Wv,JVM9 tWo/Bp@Y`u#Ǘdެ lܳON ![!G1 6V@^du5R׆Y8UН}F06+P% yV} yv Few#;AsO(CC+CmQ+Q\0^`b%/pƈ{&jĽX~t4t9ௐʅ K#]5r+\L3-?SM[%{ESjmy9-\FSskUk=; cB#&53킕9Ǎ0sw>|"f MQh YC=Jo;"Ѿg8 nΈDsTG vY}YZgs3ueȊd2 Z;7N,(U_bW&~\+]S+MfѪAw1]jDۯ`(]K"|$- eOt柷ޏ$@}DGqX%M >DJ=^BQq۞!pWs٨CoJ#C@8~@Az" Cm/3^pmf-]<"9jmNLky03(J,=1j/X폻 Ia! tiCcc}4ORLܸK^Jf#e$v&!¤bǵ[ԥHvWt}FRH>M'%ܭbƟj_6gҴjչhlZ=45%m>Hoڰ^M͢AN ﲅm(0S_of(ҙ1<8֊@1 ܺg31TrZ'Mf~S VD^t[0hPfD28qnY Z0oЊ|vv)H'\Qso-$,EwqXi86&NrUҚfkdه,Z9ӤyZz^[U6FU o<:f3 [#<wa"a?PP Iۛv퇾yRn;dвwL;䊯WVe#2zS5k cY𐽠N=PArҨׄW1V=bhk>S=1mNA?jb[0^L&p&$(?z)f{dG?WjXg<F!h0JN=:C^\%=h݁QY/H]ݭ8J.(o QR_i"R ~*d%xx  &[V߆*G+ _N@sj;XaiX||[h)!"bw:Z!θD@cn\ i:d 0f[fK7 IS`e pd'}QCė rH̳#gac>NΓi|C\?:6[Xck eq նꥆa]z*;Rfw|p& L@Raa} DjutMIYlX[u>Gt[3%;A@4*g̓6!QWr:L[|Er(!r?lW_]? U4G7V R pŜi#I%nHbghEP&ZM'$4Q{iZ+#u6  FP]a.ۓzz\ ZKK .ߙ, Z]!5s!'c}*B\,@ޚp~ Ɛy5@߸ax{pwQ%,#,YB'tm*ˆQQ "H}U*N-,l^4pyvz@]IN\`3 rzzdˣfR3. sz>O9! Ԟ?{RCtT ["AIu^l$H)+KwkҗV ֏t#wʪ'؍>MN0 yW 5SHC[rbk=5s-l'Ta[<epsQI8Ut߃.]!1.6s}8KFpKW9W7M/f>Y=p]?h'a[ߟ?*63+NMjumTd0ngSRBw7b>>i6е:('Yu"fw4^OI:]Ӭd 3ՅuEE`6>KKe69 IT4&!8(e)Iuf|&7ȩ;:Pęo߂~8-35TdeFqAŽK8n^ Lgi-t+8j}IZ$C4rۋԩvL1.s^DR\VqȻ=8?m od7ȗV҄öB=J625쫆CS^;*ATH`y\!Zc 9gϬ[-\!Cn|i3ݣ"L]e @W#Rݸ| >Mσ"NXڰ Icee?kݷ 8P%I`A~\09ܮ :LdtAI[֥sg:!b( US8]aF0q}g0hC ),zBTK#1se1Q⽁?3̽mV%LM q_Qd kYZْmAthGh}"]7Y V$ŷfLhyIrmL)gVfuf& #;rl2o7+o0ZȖM·؀{&莸 B kFdoݏRG4ScA}VXX(o[?$Ⱦ'_heګi!Xzy~ƠSM>P<ʟah]']|Q"<5^Ѡ'r"`TޡKsP\jIBu*g(~G?K2²~QBTq'`at s-5SkkC`F}f~SGuxA#_տQ l- VhӦ2اu<?7.^K0?ŲH9X ">Sc\v3Ep@ 4UMsK?bլ.as7lϐVlu.GSo藀ѫXUcD`dsz` | 'q'+@eR}r?HI<<Y$̐Q|'bwʦH ? peK }.GPZ6pQĵ=t T8"Y]ԅsj!HHx6@RB,P5MSSЎ2UNXãBpZt9%EHP8[ zQ`_g%;hH*ΈuA&T+@DdM Ƴ A'-2;DU󠟎gD&^.c[w\4hLŔ-q8U9H:K>%vNױZ.R)9{L:+u]Xrr!Dtokz "j1*a("3X-}&VX3|霋`he >ڊQ`WY&U(i؈#]JÁ|沓ڝ>P1 &W*PL?Jw*Pbs5fz]Cǒ?mhtdyOue3v*,oᓘ%ESR8?a Q+,Kj4=^"k,Te =Y} 8䗫):ir@IQVm i^5w'h9$8 ŝ8twMqp!zUs u;&' w fOWjPMv*ы+bwxdV 3 ;p"w9([5[_R牟r~Z7{`)&=lggtKn//5LgmKO&֚5nInؑ"4=xCR4 W5$9!uޏ>hnd" !%jj1Y=^Iz46-n2Oc [ [d%K.- &~Xr5i>U_*`,ޕ*{D $&%s-c#LV6)gzp36v"vkSUys}̳!r}haf'fqˉ/(ٽ m誝m926p\U7Dk`(~HzL*`%-Fð\YO uXw8/$|vcVSQںT)!gD$v˗=6½;z؞M*R[ٽ+9zgM_}|;=lmMO117&#MSx 򡭁=,zAMС 7eU69iߥD KMDMvN8?zN+j"AB6P<U~i =1%'CNK`r 즎4*hUUeGs+ ԘR6r.ua#)QÿũX.{][>_lpD9 \óQicZ%\s'kn>gD+ɱ'>vȽLaS<~Ue'zl9M=RUCh6LUV8(|zUFRʅE>5>:go+(rLBƭ?umy,|0.M3}77=mѬ%=ٸ1 nJUSQ&x~Z|3dںlUl`3'CVR*D PPtι kԫv -󼥇- w+[=~F$2dƿy`GJ`:)L} {ҁZ8r# ndNֿuII@6mn2W_xvHܘb' Qt'n؝m=uK_GWy}&B>7,h1=QVŨ)fg!Hn wj?\! "`HH:{Kf{^x|X&LFm/C:Bvl=tM8^FD {S6ۤO`Jz6qeH7_vOl9C.{KE%KE෈蘹i7ĔEc4` _Y˰5L3e_>xr]aߢQ՘|pfDT6'Q.Lx7{Qӗ'f8x}ɤ̝~]*vJcz_>~`_wqU)Ô Gf7[nq8vm%_<۶IEKׁ 8ZR/~]Q6F`B c} O圄"!iNw+}vCC9'04wv(j3j9$, Ŏ SeatN V2XƖ\\"j Wùh!%<}}Ps'IPe8f~C`}}q-X KJ +Iq#o/ʡ ΜwitJ 2'Q21yWhQq"IN ]GsڽPBR{8O"̳$),\$cTCJ9}9NgDN79_Dy1}Pؘj_?]!@i ʝZF osUwtIZm]|6j Tw KȋpV#~`M> 5!G^xr;yv)O!%@${HLlL@"UbTcbVx`X 9Nᵙ[{B,y!){tΜ-bm!ޙpH8JU !ؓ]/rfO^[;\Mt_N=-͈ic)`uL ษe>\,}{0&]<k+06iWf}d^[Sy֓A`=8_ TJ{I=̣8ad PdiuS m&ScЗ;{+Shy. ?*e UqxҦ,w6 "=\s;썚7^Rl:<` ZWf~ki @ zc7w "& Md \;B^xXfߛkݼexqX.}(1_~?e]lN{];ȒLqR֊-YcM0lY{}bAܡGM3Cs9. N/醁nɘ HURO/ d^dي}O>;`kq svU,iI󛏭$)ku4 vCEqy±"Y^ Q`ž" cvLn)>7E}U;wd>6iRW; i/Lɭ 8nFvj^)ũÝE`Y_S0ڭ# hWS*xTyC1 $L5Stw7#{RJ R򫠽 r[;O{Rߋ_R1S#߲м{и)L]= N\3SiҚdHO-OHep7n94 ,酦0V\ji'o]l(M@{xւK;xb=\FI){/=#NPq4(>VkFuX?l۞2GO$(y(s 慄RT4@9>ez/I:E""߲;Tic>NMɀ8~C0>S9))k)3(}q´8[xb [j!2,/9pz/UdυDѠxu6OA78xڻƤN{ ≍g:ViO>2EJGG ©-L5N=@s(jliFkq<tW@5S eձBM+b/S( gLoVA}+&0>FB1I I\ Os]js>,|a%uxw)w#~Kc88~+ XHIlxۗ0T|xQF{A0 GL2"-_P68vMEe[yL ǾT C76 zv Xߢ^/nZc9l/֡aK%QIfWf1mb@࿾. FŠLeFОJ9;JXM7gCZ$MSe2:KгE/8 6s_^// g0j^Ȕbr&VOli&;z ~G r{D0SVU;,i̴zZGr\NB-Fs=A+.Wjt}W/SqH9t(nS{7:H`t](nL-7@D~+a*me:DwRf®EUFjqXEs62%N|QNhg=7Z4cR>`* N4D8tW 0wG918 8jepN;cvc&\yX'WHw_'ZvM ќ:"xem=)y_T2ԿK5jgNNj)sBD?R!8 ??bF]w/]-dpakHGkMQD,+#, 5Z /P(Փ&LqQu*~h~4&[mSbYĨ33y8;ϒ3͍W|s .9K--{:~h q q|80EP1qw ḪGyhZc ).σ]x GWk2kw3NJij#y ~V~8^%y6H梨9||m#nHu&/ocyjZ`|rl6>0q\O4%?JO/E٢BX&#ۺHE]j1 #nr~uXv&)ఉ)%+69|?;1A \BHO HFo!bN9gf/әtg!n%{lĒh1$Lftv |eസAHgTqm*Eu~5?-qкbBr@=h^~GE\X@(] d*]}|tN[RKH&nT%S2/Z$dǪ=IRENIhx}z]$JL@ $Ph9x[Y $B =X2&Sc!IZOכpa9q j|7ѿ4OJ^ղ5_)R ̅OBN4"ز)A0tHx? JmF#usİvV;HuuĿ,'3}1ሌпK?L)x 7ڕAZtbxN~,_eu:tʛڽF#> |=Sn,kjӑ*^qd:7/yH r}3G[7537{WġQ~"7(}7魲aBi巄a&J[H#uG{t]h\~]oe-qj#yo d[b稙CBƮLK{̈́s$3]'KQ&@{CQ-=.nQTOhpݞ8=pn8OQhns` !jE/ʞJ@Olq?SqX 7z3ACi B+VC1,nnI8`(Z?IZ&`.Vw^SJ)3mͫoݭ Ou+z#LHe5v(Ӕ,fS!01AM̟ja *b"ϼU{ehjzC =ԓzlʈ$.'f_BfWJ S0%8gOp[[Eg(E9+ōSE>$[)tT:U,'׃ F[D8d PW.G$ib(,wɏ YMmm iuGUHK Ú@[V?cr>l_YL\Cƃ-m|+ĶͿz;  wo>g|SQO?\UƊoN9v07+̥=d:+\LM6j] Zf<(JN,*ߖ,Tz#}g1Ѫ&ȶbɅ߈U?{uq[`j ZO4Fa=lk#Fk;r P%mcp [+8@s.W Vյ':{iE$7cBW$NOy`/Fgu_Aq_щ}׳N6#"&_5 +$ A# Thz2Qwѹ&"ZCgBլ8Fe|zͷA&1>8XX$0兀9I|n Yv[|G:"fņ#^~F=mhlWFL_%fTv56s Fi1㪐'6rqB;v8SC1PUS.,Ml՚&޼~7@ s<|Xտ'[-u yzHCd#Sx cjI}c|{b O٬z>'`RHoOPDN )XtJ PkH.}QpJvs:JęwuP[ ~ a cSu$XsiJy-Y+~wTHNNUܡ2sy|PVokv] $.K-}7-,G 34z&fit1J{njcܤ/ x@oξYh;P~:=|]t$BK?mc(:Rs1T;ضb 7!wJqGoG̬p\4_ Pv|݁h y.[i#]Fh26&TM\Eq#/"#ǩ{ qCs C)"݁r1Ư0t4y=j%S \cxPabus]Ooc0hF$!@#[+bkjvPp1 #Fp;8_>L{[:rv哙8 3 ,5^*>'x0OcgT1Eu 5Zq`]gmmqj)j4\/6lW aS HX5OZ mar@qѬ7Ν|iњzcT w,XKPjzLggXlX={DP7)z `mB:7`RUTwJ̄%\l@R)㲚Yszhiws9eє O#d,cK˖;V"P>8QAX"I,[dFM`x͸6vβf/^EK/Zln &YEifxN KaVGW<8X<7J/OzB.Ґe/Z٧rm 퇊L{K7d`z[N o+EN2s*zbnބQ  褷EkBڌv @XX辸{K ۆ#7X U|7 H\nhWo[l$q<\SspЎm'tjV3-fd*7X@Qc̰W3R+VV!2JLBOf3? _ikPbDO;6Pa1=AP4KQl YW w4d=T<wh?9HlbWX0dl$Y&Ú&Rނr4iZ.b\o!N'8F5gGTU?EჁg`vZ:`E'@d(oT𬼙"&>Vf_a=s/TΪ};@: /\nY&]fj㛵_v, 6w&G@%EP᫠mhR)~~LAncg5)tRFTk)53wom9jqQ Ow,oR/IP1o,l!(x\iñ1 x_2@/wV#k.2 z#7Mqӧ_WE &˵ZF)zZ0[mK"P뽿e1g@,WS~hZMK*ԍ*-+VCϝV|YOMBXlw,;Ȱ;dCt֣1;STm kOZUIL!ް9#/ 3|~ R `'| B5D+ -juIr`)*3#^>b*' ^Ga1ޘ|Q]ݹR)UWxKzd*>þb#B[׭%ASU".РiyGܺM/Lt$.\" /։q8SL/ZS` ˪ZMkofc?UnkM&H0N2eLsK(E;a63_2u[Y[1_Fx$E {X\8C" c(N6<>$Yc8{w? ~4.w'f~e吩99C\`, * 6P: ǂ9/"4!| mBay5gߜP)e8C>YofuJ BKI8!KpXJ`TW~41MEHJ2nJ&)̩7B$]&x衆m206`>x/IR3( 0iO 42%wKɀLMƒXFfn 8-=Ct %ش&RXgE3n09:Kv"lUOM+(CY7uEq٤ݙKM#<\cׅ'->3n1GƄݶ93n KUY]us"od1Ko rj#e<,NY8 Zq͂1 vΚW]G)`(hrf[o_UGbD Ux\OGJ2$Ѐ G-n> HRd*>zhV0Pli %ոDmqu#PBkh׮zMM|CiV뒷 j迼3#]#etҩʮݴ(X %'4`eӍ.쇿 ~sj;u$ՀQҟۨqPH4Gr#ͱْA?oAO`-rOqUFlVQ3ۑ1V\P+l¯Xv/ `~غ/V$ IcOԽ{cd)y ![^gu,̕"&([jJU9+6ďa#KHkI(|UG_EMˬ>Y M'{Pb&"j? g׀}PKXeέ4_~ܫi{:RR=;rzGuw 7U;TȂ`ּb/Ay>#G""KC3?'t=\xI f ),\}Y~E^b+cG-YF'Ben@bRP MI3/݄dS6X-!`*8󂆼<%Β-h(/tۅl)K0U>xB(@S'TQ,\q0`XؾO*NҤFډT!L%v$:0J+)?*%E0q) vm yHK&mS"}`ˀ3!dv/j\V!ϭE64r {uÔt%nN.z"fZ0 Oz<) t\娱*>g ؇6S!¶:ED3/KgP|Rlb&gdGM1&5m#~@ |I--dΥ{+,42m8nPwֳB7]:5R&Y'=*j~\(`0QGf$cbIJ_Srk>pH*TJN ?GxzC`MIC2y܀-Ms\} N\%OWB] $B[W2$~Y&ʳT9p깷1I/K4n*!*~'w璗5n?T0$l{b2(AnE\]MV̜"$B^m`f- Z)i|_ {wpfjxs[IT/^[[f7V3`[9Y' @psxՃՋ8iYEc :sn bAa͒Hnb_Ƙ}-(T!\~rbMyę&QgS$۱Dj.Nq>lA(?ܬT4pN? Y t\UA:Ac2g U<3 }7#@`-$ {DU+OP(و .=zĈ2!62^B݋F%TNT uc$Lp5$_[Vt%|q(} 9t9#oՂG0h,ڹՙ|0FB," Mgѫ;q)x&B:cE\ŀ(aH?[Qq<+tz< ybVz6^l귾*4)/͂i?(ͻXfg%y0Ge=t]7 j^.UPC0Y?O}HYҵJh&U3; 9+3'; 4/AqF? 0B,V`iنrq$pwp."X?/Dr5 49!ީgP 3B$Ilt%;-U(E@-**C7Rpf Vli9oڳ6Mu9gos!__~aZ ml>0aɋO8w78p(]#q4ʪ\bhu:!L+8rwPmCy{Zq(SNz9[n>HZ%DZge]۞S͂޺28N@D44hDr3qG;kыr$x|uH^񼴝dp> 1ou '$\Z< #=V@yp_Z{+7nj _Kk2J?!]B'7l[]Os Ιrt$nX֨UǷコMPd$g~1a!FC8$ՆT˖.ISO\2;di- @wv~xJwĞt-<a ݽ9|Q (x"'!S'階gt@wBGS\&Q]C\ß23z1lCcS7z[ ؔ@t_ssV:pP/@8qŋb26,Ф2ȕ2m,6\)?wt<{ـk'\tP?X{qA=7Cozڵ2:„񙆚.u4 P7;D+[:4Yx S(B yǃT2Ԙ?;E F28ѱ&9a1f;%Iw¥KeDܽU[T qo؇ aa*a+u,b]yB.e([HV:=G)AFO ^4ʛ䃹$U-[\5s9FB29$m{'M!B]V.?I9e]gхʇR /MCaB.ޠoO`=KSlt`s| YC'1$ô,TxkŠx& >, X9j"|Ή4Q1x ba ,yX0yf7ΗZWKءC+v+>CnnK#a9Ф&Lݮ8aq{B'?6K -b2,^s.Kɉ~U ^nÖYoHaBv/ bww>H@=vʽSh@rs%QiТҐy5Zt~|5+rŌ:Cn,h12e5>"UV /vj<tjn:l YGrʊd#PG~q 2CƻȪ{ mɪDjs Sxs1jJoW[l0%ŷnt>[V#P?,O4 Я@o_d 3YI" ɸQulkLߛqxj6cvJƜH6#w_M"ˌG%M>.Tʶ7"J0ܱC{NW;/AwEVڙ,]X\P]"Z4,zgWj44XR c=z138VI1?f忓_Gx3!.\KB* =cN!A3nTkPmLYq,|elL(Bgk`JCpPKOT BCI\% ˮA*hjةj{!O5zT64/3/~7 L GQA>*E,/ V)^;kP8 lmJ@f/%2}QnZ ,Reįg{>3R8cL7A 8:AI*xe]Y͡ka(p\hz=zHT>c hWJ!RyBaoXANje|7yMqfls@'=-3*X9ͫ}|X](:n92fՁ; ?M}bt=;tft`H~dL:`h*=~9SzL7huW=l`rw[']"0*\M9An#KԸI?}vu '7"zݕɅQ[=@> (Y5wge±6G;Y}mymF%" ⋔ps?90vldWX}''Qop-_]|#{_^`ПP[>)('OV)w[y!\[8)_u*CcpהYqc cY;}*{dI{֞Z+qx=zhX@/&#Qh/B;qmt|-^3nw(9v]5MP!}fGonSuPRWhOi6qk*}b?2[v$6F!v}`h;8}kX ωW!ǣF0^P$(h_U~DKXo^e w?)yhgZ{thG暤6fʪ舶~GvW!xCX驒2PwE&pfK FvNٓEB9'f7i' %h.$0Ǖ$͇Ҿ,|hOFpxPKuWU J]+S2vm2j Z}sf5Qoj m>\ ZRA&0G&G2э}FS>1@+_;96 Z=)5?i |i$Is^oEL7{"xW2l@S==@mIY ܍FZרwSJX xew摒^6c< 8nOR}\p#F&++ulAq[tIO!W\<šp5MDŽ>PzhХ3$C||*'^5=8xAe s!4  jqcNIݜЃ&Gq(9_aLݸEԕT/6am`w D(d@9jST7k7v%cBY0_\-i$NxNsS=F[D!A -TRܤnԬ; tgO#gՙxړ]2.s6INCur_)q7H!l c6 `n^^UlP#_q)Ӑ.^,1NVU+6Vyh2ѢB,~ K6DVHZ><5h&c"bu!MOd2j^'/'Z Z.+FfdÆ@nva܍a\φ9)[1T { J*YϞ!:..z])N॔~$BqJ1YĤvjge#I:Xeb0떫|lJ /Tp5Jtu[K!`)5 "ڻ%薮Av5i- pEթ\n퍂3S1'sF ԦYd-js`c!gd3nWrM^Pr6Yyra1&ٴd?9kHL5m5C'<w޹g="...Vи6 b^ gca)߿@4\t:ͽ8n_«rҔ"UZ;Jl}DGRb't.pb|҃|7:F[ HC^PKd<|\9@X.-6٤"a={hڼkȶ9?Oѷ;O4݇2DBQ]')x+2  -{7>[e DR`Zk7<5wfoƒY C@ DJvjQ[v$9#5ꄼ6s@jz[}Z/;Җb$;-a"\iSպʣ1 `1aT"bt1k}F9MG=WޞuP @V5 Wg ӛRheևD3 D`S9+:t Wp y \}w85% 7 FTg|oD[pCFR~Dِ+Cѧܰ9)w26Ҏmvy%~cNԂaYQ NڬnZJ!j\kqPʅ}~LxV^f`+'K 9 ۳"9JuqQW l( l.J&q ک{v:k *i(G諡) sy>pnl @6ѾU2מ[N3˂.͜.PK<JPJ284(?mnȑ~P$hU&rXHeTkkma)w(Ք3,`T琦Z=(]4ǴƖ G ?N tk\VξߤsԡY%wn䎷h ,@]\/2+GU^Y"0uخ;HMp}7Z 2-by =ҍ?cC٤>"[ @ȻL@\^Y D wv;1 n?PV"x9h +4U*!)HdwS{`;ă$_TzIYD-,rUe;!W*7émb)]ޜj,s$ zkp50d[-d?:^}DR̋*I)yl.~!smT N'c^=o"N̖c&۲̀absv\3ńģ^_gc˕0vM}D>,-<9=2g|ӗds5["b@VgMG vYر՘G~Z./$M\z% 1tŞ]uIi[CT5UP\7#lhf@GC/-;D/yv}49T2`)š ݧ/i` o_:@cMkor)J:m[N򏾨t5뉏9 p\hP͕nĀFG79.9n:܍Iveuȅˑ~ W{CQ@^_{vN* |Mk>jIqo6BvFo.@ P^I4s*qۣ3wF㷌2M24L_|F׈m&U>xD4Z[9W{ 7֫u[;Ҕ3rrk!:t|r\3t2ĩXŷRe?TSWܟd6[TqБɾ(89veֿMw\K.}OF,ݥIXC䣀&Y!V; =pSC͒@+(*tW~tؠl]{9P&+P0y&tSPw:UP3oto,Tz='- Q)ɧW PιjQ=mfיEYsBX$$ÞF(f <|-P-'+PFi7bP&A4|p>u ĘHUܜõ ™IX듕 Y!CԠ)x~ܦ,_}g* Q% >7+hoPwk:k03I{oGĖK2ɨ\ 6LU/,_*);mҏ9x^. ^.Or]Ik:T:㩟`CTa3ԬǃtVK=>bLcO&OZ1V=jފu:+"Ά=s:xҞIo+6SGB-S/^\c%jHUK/ eY3lLu,GVь ?9/_#4*^D0e0j0-^+FXڿ?йSаMȹZy4dn3,l`}ߎ?!)OsJJq^CTzbr8!8``ռ(~5>DگLqP3q°/"s 9 ^_` WFѥ IЃ03q j<%W3>׆5уZTi2bduvt)3_D1rJAX@2y|ޓڿ-@bkAzzb;ֆ/B}H݉0P%BEl:&fN!폚sNcaxRkN~Ft<ՅQJ _XBz[{nW+?a|s17՜pMK}V. <~YMݢc6"!tc9I?72L%9س½TA)R 3f wPƈQES3JZ 6JWݫ9lz`izscId?^cOx4 c̹6:u@#hBќtocW(}/2-(y<؝fϷ2i2QQ; 6  ,}tH ѳC뚸C9q1ͩBn胔8\jH]mF$+cGd|_" mK\zZ@Hmu,,c8l'La y`͆c3":R1$D t$}tW>R17%I(-W32{r sRbf'+L~6:d=ᕵ| %.]Wn vGߺ^0X#@IY&wӭb,Xۇ1E^oz r/1:qX8Z$Xm? ƞv,wӊbmv$l[<~ ! ܶo_;>$*R1}esnpFTe ᣌZC NXK\+FWj/HF]Vވgn{']2Œ0VTEN:9V?l*Tm1XsoP_E`lO G"㽸 5a?SsO7͊50P`hVp-LK7a2ʵQ+N$ݝ6ݨ]I8,W*QeW?rKH)A:S/6}3ksWYmYr?2dvm2.,wJMßͤB=. ]h Q0=wlyTe7NIxIh+؅k4+#|0qwڂW,y݇G_?0g:=ڌEbKxJ VUC=JI )Z1W<\+Vv@֪YcUy/<gYlyc%g.EάN_սSKI<>zUVF _8Gתe p[-7R ߨT "dj=gMBIyQml?9twtgsy/W+*L*(?X,u|s1H.@jSiZQPYeԒ^  g˲D}xz#7͠=|Ttu>Ip֏);v|X޸-@=[q[gxQHCȾ.ϠԙU[#4ӑLf^n%ꋦ꡻ٵ<>UUwNV.E>5,AwmCpKvjuW28Ip}ꦄH/8/W הX!a3P>9^D"|e *Gw"p>|>\'BA 5z?ؗQt{ D5F1JI.{j.H؏14p'6F dHڑ/EZ%MxG~|f:Dk-kPp ~DI[ntCdc+WIb 0,x[ym;(9>Ҳ֒ @%^F^s\yDu"9 J<*9*܀vy KBaNnz2d3毥ud Q,Ud5欩rD{D Di 5#)Xu̯}(P ˮ~ C; JRKkď{Gd@ ΘL"pi,c Cǡ*dD:B.phcU\Jʥ(Ÿ֫է$ E CL_`j@7u G vfeG7w7_Idv7FTAjp/3 Ќ+kܒ! VsN(} hA*=?b Ar'jz܉UR<6c7dNi h7srSW (u$߬XIB[Qn5ޓһT ~fss:Gŧ'z{Tq0hbV'~vqsLۏ2d=AƀToFÃs.l< B3ChdY adw7' ?=0L`p7bPD1}:좕 ggFmdև>2U3Ns%TX[H㒳kLpT+ñ=ҞF#.$c[5R fvfQC A6uf Xu3wgb~hfA]\|JA_ޓ׺iùEn7ĺ25É7u[]G}PU A]$~E ոB2Nn8MvCk4P6R7L1z`38w?! |k]މF>֔ }S4Hut^oJj櫲[);QiS;}ؚUYcU#8 lNL=ҁg(c<Ǫ!1%[9E3HƅQʇ,3(YDX^KD7(U;zkFi#HBqyC>4dr(|?NHaa*8iÀ ,N$sCEMa5BдLO-/g0k9%T*NT vA;L}U&e I5 gc;,83`fNQ_m#wU  ?A~ݬRzia{6k<{G8H+\3O}U0dr#3dx6~ZV]"Su (:uIUT[]XYڌțb(vWP: Dw}؋!r .j jPc^)@PI<)R >S\r1e7ue kGq<|(mܟC VȘѤtΥh R {xDIrbr "T1Y q y!?qymQ;bXüe7j訂&`\oּAH~4s] W%uvaM1$m65u8bh=^!z1P_ʚ7 wA? PRQ!xȘe5bGn"y϶2s8S=pmV%ajh[?ngq C $p砊d(\ҏZ ̢r <&FSKKO^JX 2>g 憍E8Usc̍KYxi ӳMÝ[_YCmI[2P.猬$OzENA#tGsTcr}Gh9E`0~']aA X! ZNP_&rO*A{a\ ! F0R'EvE:FhC%fmbJ #V XK\RtxtVhM>S! ?lmݎcx0ԣjS!Dԧ3-Yo:J?qP|@G s/w>2o5#5bN :vcO/Z q&jvE1ZXg* VluG]({2;m#9-ÅCs,yk1k QtesD _@(/5uxA8]m l\{π\bєE*A>\1#v)1P ;M98C+3eѽ$](Wln]kP}$K5>Eq$Ywjb06s]IC8ò[nL|&\{9X{{a)):DZl_0hC` =qC^U^.Ni71hE;7>/+㛊a I9o_?ZEQ+kmd##=yuEinxy.XS) Dg4CEi4& |e_}aoŘg&>k(0(o214Z(!݌dFqRT,$p㍷N6"B$EsRkڌ'q>zOV̯$7;n/UzzDKUDt&qoD҅|fdtxاH.tB`1iz~(SX;ww eW;t;=pZOα+m rk~Źr4N.[=+䩐9 2iyQoa0ò|yiVUIЦ }uibqa%`?:+$jB,&Lh?Khy網IO3wMR:y /lRTۓZ^FpBe {.tSFHKQD(0J |U)H񞤌4 L{ʕGO؉ L.![*7,kU)*p+) \)o8 WV}bT8)tф)D„O%E,&]b by{̻OK\bqU㩞`ya+m :PjY'{scEQD)VEfwX&m霋߾EG.CW7|{j.vKZys@͕inBՖ}"-Rlf,uS7oK| u!@1*o*AmNsLqQ6Z)rF16 i? >o2/ 0s^MX Aa=lmIgN4쯽`D=[B@\=68`1,7CD%:˱($SƂV*ڢ6u`^gn7Is`v cG*9vG̲`°epC\ & Ăԑ$r\c9vа8}R` TS)h)IۋswWfМ75& P09zr g]}TेhÁ1!v3RVaVl1R Xnp.kSawӇMT:h Rl]mdk3l()Ax"GH$G?rT$h61.ByQ x? WAR]s:[Lu #ų01c" _q|ycMA&,=N%66|J% >w7Le݃w$C+oҔ:e/$j<=#ʒH;eݩ>㲑v>H9-HH1aũY"ъag'B`/~i ~<# 퇜@`ȃa5虾d=d)3Ok)8 tJ*O:t&z*KaI% yaqݵp7QW)Z d>iǧ gWfQP \w:&#ZW,F2UlT/$2}* ']uYBǏh¶)|s/kke|0 MA`hk kx:jpmel(鉑8J &#n?蛓V62Z#M~/FԔ Αwafӂܚ:m"Ƥ[[%c`e&i-Qc:ؙ7?"2Λ^%g"o?B=“Aբrƃd R-'GF%BkY>0٢$è`t !՛16 zy,}W̺Tl"™ Nefw†XjfPIzRxF1n&W 4JSMwJ,6afeݨVyT%eQ-4eD+@gfP0C2זo>4"7Bf@:cZv4B;bJ7d o9/CV4]ə &Of|*gTn>#Vw+l.ğ7t,]Zhڧa+^Bl4!2%:T÷? m1׋} T)G>}g1IՎ RR*'q^gHjDׂa; NV>Y;S:zUuug2cێ0? NB< \C + -q;cPq} raM]i'UULtR쪨%a>M #64OT~= /" ,=Y~q 9.CHl~ =hAO4bE®pJkfM% 2]il"زQf ObN8WgR1E>Zd.|?O#}LfXɁHC QHPUKfTbN(/Dx;ܜ i"kj x x{*ޟ ;U ctĮ!kӾf}F6WQG6#;dh_9rbu1ѧbZ|>j>>sWuJ[ߨA&0]1%=k` C̱C OWAECo[iKA? +NyR+s~ sО'GWNS1OlY*Oj@=Wt͒&ۉn*qe}oGZp%aHmnF3z:hzࣰo 8`? K~` ʻƙn)&t3E–MBf)hVvAf'NƢ(EHyUŔ]X,xNsFZ6r1f},v -oa1 _⟹ [mH.LTH\9xhkb}U𔳯{TK XF{d2w,Ȣ CY>,z8=yON3Jz/?7z;`:tDOձp$P~, G o4(W [-"80|PN V IFH|k^,SM4xj.$# jeqjf*jY3 geNiƀݻJ$ %J*&zNݾ.-_:.lW%$4Cj>4ˎR=#m|&u*2v)oxMD9y#2gdsCK$WJgH5 ^!!Muv {$>Հź^!4P٣GC0;*b^8d70$v0SQyӉ^ >dHf[AXj 81n}3 r 3ؽ%CEB#Vv:CS^Ka B!SK'ä*YFg-̼+$BU;i xЏX4ii'SCJ=)דԀ\3/¤(NK[h^BTA#N#ږ ge?- U7*cbQ\^re$Q{JrrU@Wa[ܙ x^z I=P]P$uU&& 6 z$%%@44|1j`ܫOV`O1- gF)msQRvzK" ?Z@ۄ'9 Ju`hʘ> s$|C yuF1LfWJ؀q^cWDleJ's02'[HDu s)YZV/2+Ȍu!wk) ^sV'ܻUn6YZi rj,){-l1s~,֢`B5|8z驳"B`L)8`Vb$jߛǵ?wq`O9N]c_>.I f =tڊj1,ZhZf'arMhKO4BV7&WT-6R)8=i bzЈeTIßO4-pYn_JE50f:~J}v~h]*.*+I[Eى6?e&ZKuIV~u&kCW$mk[A#.bѮdPxYbRQ`AƷ.uO@T+5[(3 (|LTŬ݋qQźT3\Impπ/yG1jMM K#u wB>fqoDS 4Tؐ⎲Sl"j躽#GY2 ˲4r@υYߏ 6XL̙u *f=jls,eYsz3#wTZamX]+Y e-Egv4odu陵AՄTܯKe6$] tS&nQyT{YqݼL#x ei%jۧ^W^%iU.89n EZ14e9^r3<}_@f9mv-nA83f(ȸ-|d=H Z]4jr, F kZTͭé6"~\L 3-#$4"LjR*"ӑZ N1u\ R?)gJ,)*F\_٫0 ,j\K]YKBA!GAwEı]ewNMΩYCtM bgW< q6C(B D4u\+C8;řE\Mw 1PÇR^Eewos9Ah3Rίk5A*NIQl<(DAөgRfCa;gY뛉-|-Z&e0 z=)u?sK{o a+'VAa؍m8sP ̾u32ӄ_83o2) *-x]1= ! NmV8zGGʓ㲄,6_;QYba!OҞ\1V0n^_{? 6rۨ~Opƻ&P)fiP]R5Ll@ü _@g G@69H"/]oAa%)**Kjt}矊t~'9E %P(H[E4V4{IrPx?98n:&a=)a VOCWpP{ZTD 6M [®Xu.O3cΜ&P.1e;t;%KyXE5m73-#MG.a 19Pws >]eLNV$VϿk;K'c /Ss:AkL gL~ԫ?hBqF}G< ^Nq N<%}/p`M7ꮠfn/pȁu"t,ǭ'Eiv|6>4@K*< 54sm-~`02jre8 M4 mCmLB^#O',5:͡8Hc$0+bD|agL>,7r۴A8Ɵ{sWl]:!)Yᚦut_ ̙%ա=Ӑ霳5f@n_Pjrֱxk/30j{a2 =Pqȿ i83PZolRaNxx|>xiXHI{cn(QZUsV~蔴PxJk#h;Gt}OB$?/Ok1.R34Kf_{B@\ 68yHc^cc{ci!1ΙZEʼaqhL#$bˤ7)N~S~8J}bGfay |`ϛsa:S'<Y cζ.G+ͮط6p7㕡 Kt$lÛ^&;v Ǥ".lJ2{ScIye(zA,& ݏ!TPf!giq$[gk,)k1[eba/C :lb 6_\8rQ ^/զf5i%Z, . mZ??sTFJgoW,(.jH (`CAq2 ph|R ^ 8S!K$&zgWKGUq ]/u5ifT:ݣx2үd i֞p!!aբ$p@+oL>=ʽVtxsg SZSoG5v ?D13,*]O6*@ԛTRu1 r"m]h@[}ҟVv4[҅75Wqjo+ WBi ro؋W:Wy9X`, 81p2R'Dy sYCgeư.EwTj\3ȞUCn_{a P4@&ꃂi=´./ Ψ:Ӈ9ޢ:OcaO79(McI4!eLXӲ3J:X #ZΛ<ڑbJla D?ʦ(koMfJ9q ;bxi`03\IaG82 Z2~>G+phĪO}X{/]T{"RO}or;NiTX"5{;qFw #7ەi3Vgq1%c?"k Ŷ׳fu#Tch'#@~tAsuviEPhQ=&? 6X Y{ xW@Ӂ2=[W@Aqd5̀@ V 2<$u]W9Go5}1@~mIVl(*9 J'(4^g]lȀQE04vu=>Lxۓ75],ӐCvlR)w][~;gYg~mR*G&.岆RyԨoE]@Pשډr&Nqk:! gK Q^tiܜQ,Z#{ug8'bj =vlUYO,/i+sWڬ!?[{0mAqtwςSّOMe7Sl>#/ ]9|[Copj譝eHz`hT`p6r/17so[̺smQoGRb{hV9s9~:њzcY3|" )O&5#bI=Bo}72|e3q#ce`9Ov}X0wlᮔe0mѳe&jY匩_uS3o+Ӧ5{4M+{\3$ul{c^ǏB\rfz]6盖P/őaL /j>Q)U xi;OX}OV'-[vӓ<<:Eq$w,tE$=cL аAIoz2Xh]87[ɘ M譶DELx34Ymm1h-!Ùj&Yŀ˫Grö{YҎROvn@z3m:Bm1[i*5ͼp: my`m`CLf"KX~ @-IϴGzUv ^"h՜_W.{L^??cY5 zkBnJqrL@H36FOK1=@xB4vbh n.jƮy(RZF/UEM$3ڋC%sw9{̖͡*hQ &B)]]IffbPs*GNwb^(voG'\qVgT.͒VE" 3Ob4,~MD0Q1vMEi~Իv\4~Ul D\g1DCVgo~Lp33{XЖI={Wuo7ۛlxJP[7ffoZ X6zBhkL X  LA !8*:eN]Ψ kpx~ E9BCÌxȱC'g4j@?SƘoY[{8BE韉גCЀ5_iw7 ^ fyg\mkڢ!$yk|p"X1艆j\jrBm۳EK/՛a U,T Z/4%b)M&C™rwQoApW|9hq@jY~QXjb'jqb)Y[H{p^[e5djaiԨN?4qAIu6۳բ8pOm'R!{%X|drH,H\!GjmV\7 1<_1l apl2;fd̦ӭ*H!Y3AHn|1fX c0ZaI[!H{KڒmOM=3o2e8WK%<5/v++Y,GcKVpj¡:zFJ\tPò6M#bG`B6=#TVPPf9γ$ʖ =+DB pM_rHhg+tߑ /[x^@}0u3eoК|F(i >UZRSw8dvHjoC󊩚#G/xOGJn^V P'sycd@N8Àˇ۵CBNEUp'dNWe пJʆ6۔')>21_?)Αʌ ž9!\=|LQCo<e}8 @.a-ߡpjCurLejsrh~hM5nG>)u$`rUD$4<;@ ܅9`8ѵ;9o˲j2 B#4Mf0*QKy*|!,B؆v hx{_z͇*l0 TEZne ~+?a<+ۃ-N3zgFT/ryDОT(2eƻkv>C($)<ڈ. g(<+G1bPD@sphc]:~wWXe;"9ژ@3*ꭟ1v3y(Wc!iAMy̑r3ap#ew~QT6C #EU55.y[RCB 0lsG1n.)HkI!?>7` ='^b G)FEVB`0X:~Bj&sŽ¼KflB.\\~?_h 8eyF^#BЗ;FG[/=LTgaxN(K~9ۢ-q8Ǖ!Dgn#W$#WcrV8%Ɠf@.M4.愌4TD~eWi//@٤<_HX3Qa0&[zpiVߦPMs wolzB5)q@}XO .1>9|{kI͛)fLݚb?'$FA=^9Y(rs7;@#zliAFU> ֟+ OI cYqj?ݥ͍ ˝V[M.PC")S_u1.(E(E]s.+\ݹ i_$%r[ " 頟IR գQIb L^%`ʥ nx2NHM=Ay# F*_Vx!)UyJ_IHUN.>~R Ƈ&C-~ez/zq4U,H\S ^?;SU 2D~)Q~F =$U|{vӏ\:$,oS,k,\9OJ#?~?-" "6c0S -Hq-YpM{гdzgP3(D ?bUwf1ه`Tqci4:^5i9Sv99idYݒB alUM:3ϗ8{|Z8G um7ER* IIprO[BaЧf3" ,^9-^3z٦&$ۢug)X)$ώT""]C^jhbTOCƯEBs!^V)mcp߻v{Q C=% <3?S6Vu2sZ_}[B%S$gh[Ƣ&WlSs uJsճ0Ixah@SXAwA}YсDpa !db4y6C 1'nʿ)ʭHEXLF]bi%3#`:+iz=fmn6d ^_Ttl] ; x+aIu ̈ɹ5?p;':n)k"уU*@KL+yz%<,cJ/ xUP<-i%[IcLG15c)8Yo1*{${oז1[֠UQHS>0_ EX\E02'3AD#ݟ7|q,bG7' zGF0nsF/}!ʼnp3}:Zi>:ތ̩B;+䕌5+Wŧ6Rw*oQ̅qHP|R!;4>{9~0HfR'/=v^KAv)TK_9]`'Te`011Ы I Q|hvz~PxВ3L*Sa=DSxف^ YTa gI'jzIIl~uHIC0dKv9ݳ]=]5iRQ֫Ninu+~fxfủ?8TѠ -{x xaOX;+NԬ &wMgN=.o'#;wo؅j!BR:q/v}^9􃴙EqqU5B1i.6 /9Je+I5UQ_hjh2eqp?4FAF°;jew@8ənmvCΓBb\Z w~|B6n0R-@Rf ' {^ @n7ZԎoɭ.Sn,=ijPg4 8)k/zG 29#Ng"scZiډ!A?yAgQ Ry-{~GT|:;XS„@Q.\.5#2?mw Zs9xޝ5َ`GE3 J67R)6m !EPu|n\QO^4CVJ5qh>9[^+?aOK{muU>_"c. ƵCUj9)$YUX[w1*?5@Ymܺↇ *[ڶdsS+!>4ix@3loa߀%3)q͹ DJfY`@3g\jqS_SƆpak( 'equTA)^l4|T.B˃Ю.36096zs= 9̬"G2;` I銪n;J;ڒGDz̠2K{B`"\oH !rꠓ3Dl,+򖱩߿iFDM! -g6V]o%%ͤݩcQ^g $^Ji@ψSƆQ't~-%qFho[Y䫬M!/0]w4y?ER*0JY XHno:*ӧCnϒ5D]jOi<,j>$ڪjDnD.7Ӯi9XUdl!&,klCbD][[8jq [_/ZeI.1'a%-UőqEql_ݬ16W y~N*۲O*Vo`*hX=۟N;ME$g wW {*i? 3Ut>/ZlQgPXv;YQi rAxtJ):y)cݼ^H)}df oXM_r, Iuq3v l+YIhVU); xӪF]0P?b%4 )Bq^&H2 >/4,a‘Tm9&~e4( WdUMv^C^_^,f /IRXHEUsy1DAuAe z( mϨ(" *k߽0NtCV'z28G$RvȎ~c?Q&}rreKUĸxͣALhn!MCۖF;lr$0"laMޓq%d9uь:Nso;FSAq:ؗŭݱ?-u9VV&:t ,GFU˔tǜy>yX)k$5܍K<[N6qx,b Ch-H[erT C&B[v(b/PJEl\"k-,&t;%JMY_hrJoi(j΂\+}¾3+\C!DL$J_ɼn4-ywA, _ʀ$':Eа2d'炿X@^IȌq+Һ5eɬ`-'CV10~l Mp6mJah$\UrM=UԖFVSAF7VюP0gR.M~d|O-gQwtIzNs,rzu[䛥[,H+ƉtõKq=̀;b(D3IPQ1߮ +R\Kd 1uJ6Ǜy!7X1MfQ6n'T"qTtt5 u¾7ؠp1:qn7q}trS(*Yo6 \IU;<(g?5}.Sk<0l JK犝č=Uv@z+3LI7Y;ELma>7 T霮(y6h.c!3eE%gcA=V20_}D8GH֒kƽYƈ'Inf"lOR|c)$-_=Z,^P%y>g 6u)GKaimwcaH:2%q) }) EMK pĻH!m׻9Y5gÅ:S@ o"w{9bg1lW婫A,y:)/É5&IJT#ܖjrh[E7z;?7.!TH  sYl^ KYA(-73 VS3"C/ӣSVoD \ %Xa&rF,^rP><]2j W``4 7df)ϋPev\0$ϘѤ?"E N$m6nJ\e3:ȶV|T Ц52*D~Y5) x˰E\Q6)i!˩4>0Vt/)Xjj6k$,\}0>d‘Cc\{fL)c[w-ܘNEhY0cufBMYA]?SҦ`JbKLw#Mf#&Kaq6X:ۑ[XJ+=PRu\$W̉Xa~Ӥ0ոXْ|a\M#ʛu[B: TЌbu4pC@1<+GV``"{\y-ߧ[t5$A:'Bn?+Rmp9C -rfN\vjg.ljCe 12˖EH?^-m.3~7. 2{9BGqM@29y \oܻ(˨~< -u~В: Qm·u Y2#܃E.bLSl݈ϐJczx"K_ETvO59jTc+މ0u;.TIby-v_p%vؽ+B 'Zt _ST lJqwVҘ 㹑ٚG])^e#RF{\7-:kaފtPCXLe'EKۨk%]yw}r–VxiB?XV15jUZN%} *2ZɬP)m}:F ]obC5@k7R<e}R |p2铸qzAla:A2 u8si| aK&j^ լ; DV"y<\؏YJQJR_C25Սw(-Νc ?ìRQ.~$+rzRVNZ Ge)]1>ѨJ"r ޣq nfHAƝapem9%ӀmXZ.`)\n%fz;7QG*+Mو0. 3;Qr*h3ȱE6@j[(ztM-{ęUǝĩ҅]ks^qE_A0 G-ftr]AQ)fc91rς6 ʋY(cP,pT+fE)@_Øo,l~-b2kCE:[? Rx".SV,w\X}i$LOyH/ӧQޛECMQ_`@p"\zy*7hM.XP ~:`q嵔 6Ej5_ v!~=8u= C#VZ@Q|.=kIzVu%v|m +U=\f [ydQF <_ءs*?p=㨱/%n4>t:?K@aGEN-mN<=<T[` "+v( rX̍,Mzb]qDuSA:tq.y w+HTZR7=e\Ͼ:?H7 G~ϻgYV#Q9P`M Kl@[ /rV\p K7sph텲޵yp@h2ov#~Rrι_g:;ؾ%\彟#Ԣ݋,HǑL[5ƹA`WEfw(5d0rUMgj8N:v-,%-\4%+/w4"$?BM>pfYFEHvs0DB 0J=o +9-y:rtA}b)GA9bES|b3%rDN8!8;wNnyX$n}Gw F>Q2JnDY)*-tHe+,؃t*2#US{:)aail9Qk\"]4' ~Ζ[=#VWTE֊^.G<&s HXvDuDÅ-')PS{S,va@ɼtܼ2q*)Rd`uhG ;i9>ף/[_TWmɹt;XE- >OœJrLHv9)w2SX؅2O}e5b %8Y3eD>Q])G|OaQ?;Dɏ$qtKoHeP)g7wu5?pW> k8n7+;,$S vJA '9tUΰ0ÀxBBQP"z>MܻLxđ>TPW(.wC8{RJ kd =s8,_Nn2W>o? `j}QZ{&)WA&CK6xVh^10ScZuM*  pv0[4=fT5 ;# +5dو6϶\'_PQk?ܓMi.c iwG@FyO8hxԔ&;Ug&a#;xm9U1b|Y8,"Hjfg"K,55V,E+di`~U W}ޮdfQG%P#gι\mY5^mwc\C2-j{s좇D F`2z[~=ݴd+&ERH; C-g/mlpIծp*o软&eOHKw7ãwJAJknב*l[EՏxYE  lvK6I:]1l:EDَ Lt{(@(nbU/"R ~[|#,d!< ޤkiɟLo10cjsC~lr:]Q`84ԬdA z .u:2b=Ha!U>99!poyJ ա\3RƦbޟ̄ J@ >޸-oI[~}y=+[ *V{M$4"v$0VAXX G$!:K㙼ǭ,7 ? Ux?WF{T"x^#7} ~#.lcދw`t+wAxe;gg{֍!un%ۣ/#\"7az+9/Y>f!bKy}] L?QX5.6xXQS΅Z k?~ܳ^2* {dʎ/Epc%DONrHzrɭĚ{{vt1i<\Ǹk::_E,$]~M2-rjI;c<4L$id9ڋ'2]xf[ir<l4IZWI";O|!vd\Qr%k'xBDcp1zЗ1@& Fd#|弁-11p̀<p^ CUjnvظ%ngҁww.t!^8\/[|Y>ztB+JY>;mnjQ9ok0ie?:M]|buk ZUnvъ09ǃ_Fu c24% QT [(2UYKpO VbRHXOe\ ۖbcY4̲VPGFdƔN̯ TLj pm}P-HW^MB©ƌ:R5ͅWѻ7er30d3jkTi|Ԩv3V[4F{)JH+ršϐ6S\OCͣbUfVRM|#F5쮑dMMk[.DW"X/t(Ou܇T޻h")nV WB<²촒S\ndT[ O@BA,{&δP%8K1¥T;wut`6 A;_k==eyޠ:!`R@p݃}zq X,o%F]Rg"?̽T]i-#lB@6W쓡Qtv!r"a6(WZǶcĂn`Yb.^k`a$Cgf*_s!Pvp '5Skb%N/&;v%Ȉ=UծG/3-w[v&]T_Я "c-d>2;taO/0[. S54 KG2R>FRf/0:L;*2>.?r)I:d*J[_7z=ցm,] Fh4#С؈[ ª޳Y}@CO}4-7o˼Ih4! Yo*X( G-=>HU}sKΣa+a[(DasE˥rB%"boW[Jo%3032sj$D3v%jS4=Mjϻq3bJPQ;7kEP]6 5"T56R/K5x$V>O<+t )9/1 ˯!'ˆ엚Zі !|+e)ޱ%ܦ!\IQe6 lP\-&ֽC3\ix/ƿMm>M.z 3ׇj#LGn"~7A#;ǡd_h.m왲YD(XIya_ p*55.KXVLt;o ȣ̿pXjw`5)hJ˕ne 2LfX0k0s7~ f:=.yNȜD"yPa'Yx|]4Zky}uB@u[{(1de[tNPj.-Şav-J 6DӉp1wi۫/fLg疘^* pOdx:ex; lShv~&-R&ʼ3'SDtkm#tji+!YlZZdzXb'0dɷRsUQ}d3Er$+O'ӄ] ~A=Oz_&|Ue||̷D]4g 3T`=~g9 ]􁸹0fQ='Ћ?|go `RMգ_/pjnI4t$6Xfpl֑-WJꀨ_m%[\Th$OEpL_pVbBi(W/cKI螪JĿ¸WbQS~\~l(%+yuJW}ڣa %R#T-ml> EZ261?aMמ)vY~y&[' AqZkܶ 5yNs~"DM^Dصb4 RH=fL ?Bv.!By1H ֨J~ضO{*QvL[d ` ; TaқWYvnqPQ&cDk׼zk8b{hoUsM &XB|>6Y "~_q1q>_'4Gϓ7Ś {P҅]3If43qVkgʜhsFA5nݐ3vf귧$G7a]U֤^Ty\%-m>4hBBCuz4\2iUNr6K7]p o/NOԜ'&O{nvPݭ 3CD?0%I d0yq>2bppզvVjvaCnrG51~xcAclZyT6qt`,JRh_33):pҨ̣ OP;< {4/{G_$[Y6HO4Ϸ*QD5'0?E^P")WRd0M)3SjZPKPia_C8xSro/tI%/bfm>yPHqfX1<#Ě&|9>ՏO9c25% _<t> W/փS oj`CuIMϷ˵-bp kf! 3E+wB0K??0ks'ɁɳQ9۹ڪicr`l&dTɮZFS,GӰ߁$H{lؿ$G,mS1nBpFON'Z'z'Vzzʼ r5U4?#{ʎ*˧ 9S/ rNyQ9۪?x?a,$}m ]I]5cr,B{Vl fVVhu$+Z=MLb{( K}+JzzsG)F? =s;R&5-Z6RHjs_h|cFMW"+"P]V%*WDr,8U ?jX*]7Wo%WvY6' .(@oqx]531(uEߠYXp.R#r]\n^J[Aa~M$܆>*^\R#~gW㲲۞Sq9$b'Ē-rt\)sQI}.OoDgТP @Ʀ4h9)dLE5d~q]itk~`rWhN4C+"QY՝PͱLyCi@! ʶ?"SԚjk}z\ωh!*J%1rJݙ@ 7i7@Oe{?2h\SX Y"& Qo]6$/yS Q &v P]*Q*u²"=̦/;ZP:5gw3p(k:c96cZ7my|G/-<8B\2ݛah$1&)̫֘㑪UvczO]](FIOM|O$al2SkKvlqm$'od@Wޓh RʭB.I Ltq[a'C!YTJ(*8ya8 MKx0Աf~pIL4~<ET7#K(`[+?tKK#cU@0OVs$}qMnX޾ 8=-L} 4m1  kAu$pa_NbpES_ tN1hT*_!C𯃠!%2"`.ϳgM?D^K>e"w>c<\͍L^D1/-A[03'pJ\qrA8.yjfPmxE T6,DYp"<"0\ZgHl+䓡~P0|_FSElGI`<[={i2D'+ ShvJE Os9y 3®5&,[CøXtoG\]vDJLT\u[aDG[[CN?>^MV5[¶hDV΁\<׍Ext햵~7fFդnY6xJ/Gqւa_ +[ݑ ]w'/Ru߳jxɪA=UVzkg0RPdi U6<en(rR>cYwz*0]d(i ^.|]$rJ1-!3qO)PE:DXk2oyi> uF+擄&7ˉ?zAw7Ceh֝I,zͱZbni ;"{P +:ת~3t(gi\pHjc˜Pvak?yŪ )rN$lԜŠtZS> I2l fyXrk׫NA-2ϏO2sZ'7D3W[g@NDR^G\ƾs {$>Th1rj>CtYXUNC Wr|}=:;(g6E{7?$TlSK3|3!D}}BC/щ\yM/n2q4Z+rx9x] f;l<^eۦ7N7ŏνj;E N~~ H~%D)3u~`=]m'Ĕ7~o3w9y,Kb6wq!lo!azSUF'+Ǹ@W 8Uj{)3uel},m(tEj.JxF9Ye٦c{5s& PYBzP+VF qE-{ݘf|p=x eLC5.tqx ̜ex|!=4u@ߨx"{.(J>V!)X%Rӑbu|j#~!d#Շu/E4*ro,T77 }[j˴{R`A*EAZ/SKۣgNF)Vk˓,@f_VQ+X8DLEU5q8-?|N7Fr.MV(dC-g[-Pw#´-iVZǜǘ4<[\̵p:&ŇA;sw-u0N (0U&5\ xYVq%F5G c4$2mZk/|,_+"?:OB4<1kYF톰şԚT^t30[p 2 L'׽BA W;:/;5?",u٫i*w&+;ji>͔4.ʮKV"w;~@?F,˫IHHu^ Jzo8!, >yVccGhdêv7d+ cs$wcA>>t4u#?@,,%j<ί5#u 8TU7įa<븩2 zU%wv_6~FNN 9w]1` %yTZB8$kO%5g_נ/u*h0xn :UewsvP;0C>y[C(4>j,Q0Xc:|i]] j%t9,Yn1e%}B<&)zzqG(CfぇҖР)2\NFhFBpc,l73y{8F//pTѮlHuhYr'r g Q CH:l:m=`%H4 j8\oOX)+J:a[xzixu2Z8 ~x<Ը* i!t rե.qh6:|W3{C4اlU"=QMUk^ ^ӿc?I\3 ٱxՖ:|#1ZFy.^-PvQ-|L>l͉Tm ~D_e%2?by}Ҏ73΃EoL#zY+ѡ]qV0)8 GlD!_DQ]-Yy/kBv*?.jR-/ suчKʕ!DEnj-U19rvB)*zaA!9g8 K #B.ԤݮcZxET?e ; \D҈y uM;nsWrzD VKLUVL 9%ΝD hgݘe)FA^zm_)W[A6BLhwN chI}F%?h/(fmh "a{{ّ+-FV:"asXq?֎wK9D?M.xQ;<$60zYVO b$!Ck$[ZUz0$u~ʀ#|!׻BژXy5yʐ<5f]#Eoz5n7 ţ?L"6 羽 ׃'w YGvNn݈9X|{ac Ga ٧1e_n̜曰 *bL\}kFsZ{tcFJNtqeMطjpyH3seOyT\3x٘kp0[A5V89W& Ԣ3<מٵp=R,ɤl GњswNu~cRt!y39eݤLXk3nP|c_\j,Dn0ۇ]ʄ)˿p=P9:R"֕#W?z$B*N:raQ-Dfefءx+>_egt35|Ź̀pc_uQl b.#p +D727 1ö ;*y6B"AHޡ%.æc:䵙\\H.V&̆EY"I.үirMJ&g4a{yxDXXჀU$$%}WVEq;&sV -0< I #qL ^Ӣ1_aCqS6“|Wכ0ܟ uqW[hR:u#\Y?杭t,S{3Ch /zk@,-X=+l[r0NY>/I҉j/}bab 1][BzoӻzI&W!\Wc}2-ɶ25TBPIm;nN#-m+Qݧ@vsw!<_t]C,$cgܨ*8i(þ$8G"(&~陘vϓѬ/Ng#Sdzܳ33eY{~"*جDZ+ 4L*i‹Ci Z`\pX3ps<$ vm|_l {4sXM+[JJK}* ev`듗h?%Ew#dm۽FaLh6pGa%aHfmH1N+%(~j!w G;xlR,˵*xevsڮ4(i[֘;֦_XMLU&AFJbdrvqy.o< k{T wl' D'MD'P5A'H+K[d>xvQ]Zz($*NmG[i־fz"FN<K"o ̘_ΈS( =w' 뎫9Hz4ē,"#ڨс^%¸ݳ._ V! m`ih{]\J7ڜq+YR<ޗX-?~0o?BAϽj:r4- xV5fQԝb5[1fO*=a :(D6AEX(sI|8h76rrR֨5p-ccнd^1,tUQ2eF'$^- 5hiO["|u!Ů4e L1xQf WjWc2H@8p(ٗ[}e;ťP\;U`LHBn  nT(L!֩>:: g[ co)Ò Ez1bEL_*#mmJ5?i{O5kۡ\V= fv6@5'ib̽/?MDBU-k dP{:8jQuH-7W(u;1u4N<\_w%:ȫ>VXZuuL7V ſ?x\/uQLׅqY8:d/MJLe_eؼo T2geq+^ka\x^Qޘ1X0$:p,@L+&H/;rlqI?z ĭ]!70:w&x710[I+!)DYFYk?.\/|<$/3 kx0.?tV $该`~ȁ~eO3ri16ZU˻q:#u-,0WwF'dRR~"C#Ad./u*n^C~r4)}>l@Uvy-wLFT#|lW?s+)0DKJߨ^$Xg@\gn0C#M?r'h}OٽDNz5 7['B БUԓ!l?&Ef(Nj㕀,&>.J@N4*;F,ƺi7ESYjbUTN5 HtOUZ$I{d1` wnu+@Ln-DU?fCdR+} t˥:#/(D\wlvRJbXɒLLro3,VMP~ Ms=M)H'dmz`HB ,1$':򫼡9@@X@fg{Fuϯ-ծN;xK%M#@-MmZk0~A}9"wWBjodBCQ5k$ 6"y,@<}A][ Wagਛն#Gs@Tѳ_ͱɭ(Z?,v"Ӛ$NykE])BEYhAC>B;*#wE%CetZ$H=R*>.ͩޫCf=+q3 @0|eJL'tu 5kY<$>ȕ1]DBw6[pQ`­3&IAn`ڒ= wf4ڴ*3k؏-y9xރ(cSA/MO5 {g%%UlvCªT\q{XVQ |$oG>B3RP,`0V6t1ջTQt] vUd8%ґs7g)UVQpPvސg7>`&c^7ңQfSOhKeJ*;D?L8 XhkV>,0]3 csrjP`m("KOf/BX +Q q/J4GN #0Rզ y|,ˑ{{f bSك-;C@dž*BaW06WcYCYxhT6 d5w:N!Z"$"4Ømh)0{$)/S-ҥ*A ({ OB2vr ,v\ܺ\ in>H/Mp0}e τ/6ÑJ6H2FςخD @uGj !c5ՍEaϵ<]9g @ hs yۇQ"#f:c> ;| {h_S'$Κ/͈q" øf\9'ISa*!4RҔQHyC9>,M,ğw`Z)P)v=9N ԭįV65m@@G'rI܎iޛL*!E;7,JA_ ^vy|6,]TG`']XbXyZa 8+R9M6~I+`;26`4n!Kr2+qtfdF"MLٚ{@[l!T<x"uqÛ?91&Yq]ʴ<2y6a 튚vҹ˰& \]%VdTB"ۡ*e͘ ](-!&DUU| IP5,JZABN[ CĶ:qg[|Rj &['U/F`U"Sh`n\^S= x[XھĖXGvu9KH+&Zw3c%"N9̂,63~aAZo]MB[~[ڸ >hVGaUw/?Q';hغVIm=[ezkg/=paCA\z1yK$ XEX x|8Yx+3H3 YAέU)=]*Q 2<|O(&v {KB>N)潉XˍesžgqiC<˸ا%~ЉP'Uf~3Ʃ/u+0ں \˜·r#ydcO(GYglixzv"9J0w̡Fr ڙWɋZjݾ&&WBqTc]1@C.=Rlxjˀ7>Df̼ l!*A;{P Xa:GP귁lRŖYu /@jr)ؕ mi BJ5m3_ 8 O0,847 \W@7z&}?>|Yh.h -[$牏f'ϾRy. $?@xҧ# g% (8L Ԃ^^$E}h Zyq?5| =8xCgs|#h:p &aE2Z!7S-4*U#ԵYs׊ mI_$% נȮ!] 2$suIBvB<@3N 0*vZL("o $7:gו)+Xʍck=Uyv p#̠-c9wQ|Vy*c~Jύ'5PQbhḻ1dcmT8zsmױ,wWsy&0y͋4b|{%]!/VL ԽiIл*:y*+I]RM bimk']SOHځw*x?sGUY(Z(eΑ{xQty~s I-mMp \[ڠPs`'B&% bY+CH>PC^+Ua\l+x;fw?HIqA yqk+bb'xo_\5Pq_ PaB*xn{~JerW W]ƎDۤ0mrLa|}·Q;~ۜ1䘇z׀"9-GFVnVNPC*܏wS+Y> `sb в*>-OUhx';ZbxjDU0$OT* ylǪ(s, xlʮ¹`ݸ c8:j-F ?o\gA~֕@"'C00QveQ=#ر}7ox/B=" &/Q༱NU:t6OS͏%4 ;_&&R $ZHG +z=n^#U -"6g~c ĀC5LJ[B;a27tTW68TD1fBlMP)ꋍ#Hl{//a#N?7 \)Ckq:1 &DiK7#Gz9vYbr(ȑYkYlի!%3N52Wdں ͋ܪ83 oEާvFg͚@i6S#f6O&jc x6uOTmL[)3.0E_yCp w7(Wǟs*:.4r3MmS&$¯!&6a7Qg+ T4Gqc(jP*J4:IBtl_ u-VBd8yfhq!j,$|ydiXҠݣ{Ň* N` SYul~4eOJک OϢ :ѧOv\i& 9(P:|tUYEy|z1j7g{t{W._bekz;.  \XGjP,M6܉X0붥( ?atL96Dٷyߴ-ݩ\?px$i֡?l|K:U52$c!XS/rȰθSj.?E -ϾfRu[!L[I+)ܞmRS^޾JDˊ/ ï&&EX@{W(oh.DY f6+2nyA䠑?c6hjRE&P;?rDpuv'E3]HL<$(׾:z%=Ūs;`KA˲;<9,#Tr󙚇gM\/{ e%&!sTK9`T5 KpheX[}Δ 4KèVa Ro.i;BI&'d5Xf :41 Mv8SQ0 (4ENlAؚ7>($k %&Vx]@SJiXoKرf.j{\b~;RKxkDqhJJfZ ;GѺÍ-z㏎EIXY&`1$m/zq t\ٗH_890d3G +Y1bRNi=soe/`a &ء|< vuE+Z?kn) }@.? Ȏ_:s{!&dOwہ`ƦR}YxගdM( Z>d5)y)2Gj}!9:P&eWág5KeoG&#DWӰGӂR'+]%{O£!J:!TE=~( ǩzcQgt`g TqgE{DOwzm) I0'w[N{2BؓUk[v_8!Pp^A{=%rBn}*s=Ey&k14%異v+"7K6ax} ۝ލSfR+ZTP7~a QvSf% a0*<}i^yscV~dDP3qr.U }};.P~X.(Lo >7?uYeذutM߳oQb *4vW1xtsp\ༀ [CbPeTV -+A7VպEX Sl퐫Ӆ+7&eM2d\a;.Gϲ'vݗn6}HSu "F`^/,gߧ" \`tɮ{TA >4U2s!)r@=d \iߔ<ΙnR.CKjP5eJ|,A'O3RjJY#-/]KgvpB<크|`\x#z 3]a*~N?_d?L`O~Z'KI݉gfRwKC!Qo9,SpV?$3[tfv,v[y^gV!e3Tؽ ڳylִ6JΐtBX x%][;N2q<]"h8a3T U4 ac{T\pUbؾ 14aHf&im&j̋`RVq>F'yS1҉̛(?\rsWo]tc==iLT@]6*tݚd˺Z2(xݠX@tzOj;;v~jђYH@ .T7,L[TLIC[Ӗ%\ ڙAWs/\QsZ6[7j []\yڄ~~RA?ݛExpO6IY~l~쀐woQOxi!r\[eG-*&EyG?5./U]Z@ V|^7'2:jzP~G5 :vcM׃’>]4NkTӢqE'cY[fuqI[p5i,>5/53L  Ȉ@ j &;ᓩNfuMޏG}goGU3ˋ5FIꅃ`-vh jn_Ķf%߫+ 7T_~م}}LkD.#-"pv/^'<3E,EYя8N߿%Tg@ĹW嘹D|zXlEe>7NoM w;.! `'ԈTt@ +PmFtK'?s,'-U0n=j?ZRE{Vok7BȖw%ĭ1b3%-F?;/%$36RQP[BZ^Gx4%ͤko+jI $OVfA @%eImEwgz͓MM?+8.扑 DWpR8?&7[S3%6/# Dp,ɗ]uޞOgc՜X+mԀY7f3sDCxD-| 4gLsD(NQ_?kN؛лއXY\H$EIP(o)Mь˺S,x` Hh^wb9NX?"T^ zcy2Jˬs:c՘4Ԋf[!XAMiUv]⮅7y)䌯u>iIxKbJg@23ڔ:ͬ,rt »SLaHˎJa ^*oմ=Qz 2 @U*>8( >~r/I *+,{ZY$v?7hb;T-+3t2 -=)9>:ج}Ɔk+`cJ13PZQܣT.BGMj#  qm?2?u=trR ~"Zh)PJ%ȏOs{l8)>A"d&M X^rX38?횁䡃>08AR m'FaFAaI-~{.^ QxCCcm{6TNu!;.X: s : )! ހr2]M@V9 PxcI^m'cE@y5$PVū%{"ủ,h.Mp. "Vh˹"ngdPH]YYۨƢcNN9aH5OJ* iq*#01^FfS #fNc@]Ð׃i'x 8;S j96#ې8ߺ|`_]ơ+hWͱj `]U&GJ y+=Dk(N펊5 C+bU NA@4.iŹN(@x#;ָa$7U?ʘ.؈N<@/nMҙkL$\r(?Uл d^R6F9T8yhrpkr$fHZ >(pt]>VzO%x۷Ou{&M%]aɵ[v5G`TeZX?T+w#0cTgj]=ҋoY-!ocw2mpua)' ,lnS9#-ZbI0C5IU1P8p:::^@@wRqMP:0׹3^+Cj;@`^ѻ&j< Ώ}bJq}jw_nK<ץPɆ76=UBqFMٷPا9o?叹0[rS:EirtWR2q&V< 0,1DWc=pz-# Ӛs⟃{^PWQOqXŜb9$- eOMJT^f (KY|nչrTP$Mfc Z?+)׳Y;wVEuA8=&M*OhV鼺A̺ ~DT%MR Br&)&ƩGFe9B>:chB`g~(JjsPnv(OCM| g!5=sP8%Ɛ(׾v4# "?ץB`V_DN%|ydm,6Ǜ}8\Mou_#6_fR.HŪ\H?jJbQ]&w9) n\I-N]Q8$e'ĘXJ) Y-RU'-nZ]WKUXV_"òH|$%QGFlJt٩${Z.8n&s91CSoI#49jXh?~jr:3֗=rx?:yݤh\C"fo6Rj%#mzzl}EF6PJJkA ōe\'enb奖HeCEV~co دUVTBؕM;YRBgœ#e's UVVcɘHi/:z?EM&`u")7!vhJ#MN+~,2bIY Ş0x WZU,ÙPrưQqnKMfw;Ck-%̜:[[ď}}@~̗:ٌ}`&l\GbI5\eyO|%,HRq Q~ш}"+G+Pk}VTsA:ؽެq$IH4݊,iY#A7?(T ?Ȳs:Ͽ55( P:ɲC %)eolob |*0l=LYÚYcu-۽ 5W0`*ޅൎ1|ԛϙˬ CAsa$'LP\ |ZI] f3z(o3,PPM"bdnOF{j`e2 EIc]&n ,.A h1#۳zkos H*p_T WCFF6q< -0 ?Fh`C91u] c NsXͺQܫ.bܻYz}lx :CJ]W8"P _ieD NoV}{Ip<`Rf'F \*.z[[K(=#4$,[GӍyj3xs"CĚ ^d6OZsV*wmҊU6Pۄ6 ;:,k4q;hQCԗfucWa[4qk)Z`!+y%)#` &nM,H)6|eEW(S5±z3]~RUxlϾL6I~*:1sh,ycj_ZEyxܪlu!2H9YA6n\mEDY `&>|_zM9.ݫ]77 e\ ^Vwqyu[csYJkJx|(_|h6pUAfznc+%txv^ޠ%5x0L욦GYQYhb:T;tg}aRvF&IR?}t+GWJi&x@YJr?NIO췚OOs_ԑ2.pC[ɭ`OR<XC<)~\r/M'6P[ WMŎ:*:bC #!2S-boqaC (!KQ+! kKYM]'H(oC Byoq[X#dzŒ% ,$V<ՄLXG7: ''Wү}x:C8rA3-_rTc7 Ki95dG2ᏢW_F3jRAbmDũf(SGFm6 th[.!;'_Ljv&'{>Qi?_|ǥXqԒ '~B lR *\șAN觭^j:PkkaMlCMtkAz^n$+$3Xd]eћ Ge{Ͽe`5I1@KѩQCBs֦fuX䢩nƙNWnIhǨX31 (ɘFmKl[s%MrXA)<>&ٖo^T_-5X\0O1l_] ωaQY?q,1=ca d̗w[bH2??h//DJgܽ:9"^#;){Q]Rzդ5{M|<"0C _9%4EP7ui)o"C3Mk[4axڨ{Wq]#.L8ŒTl Neg71!OOj|?#6{ .;./3W?{ehQ^堅[gP RH=V2W'SIao1c٠b/a TIA ӭa k nb&4Sd=GNP-(瀴- ):󧇚UwIxlf]?5q္`HZgتLT O?BW[)n b㢲!.w͠|mR>c.}淐iB A9OțN>$־ |oThv{qqxI]xyxJZZy·wM;%#fg]alOFlHcLݦЛ5=xYkB\ e!Is!fVb"X/] zVjSL䯇W9;(f%̏]*K;,kQ8[z&y;3b)%n&VBO$Y,0;6q#R0j<ꄀ˪ UVlaȀbXFgan.KchqX%?Mr/AIȃHI\U9i5dh_({AGz=ME*}z=!s%= w ODȚ-onl"5B: Sl^P0r͓Dw hg]8 as'}si-ŅZ&< fdt5OeUjJi;t{O?vE`g雡CORwq[]~"1W]oSmTTŘz #d,Y3vrR v`yT9j5j%M)tOZXi[) O{FKtV={eZͥNV;͞i7 z2o{ݓ'vv~hi[mZ*L$5snk f`>[E )E^U3S 5ztDD =H%k[W>a;5{\Z$e\$m'خD2uD's.(㕒5~ÏP/\;[2/Կ?n#hjp<#0W\vJuhY.QqeQh*3viOi$3/,l?@oD>cN2?he+`φpU &pdp?k d4'UF1X<<-32̱ J:8 Fj" V~*'Ȣ)m Z'Q/M{j LA@ʴuxC-"E%u&?e,褮/O^u; ڭuU6Lp[mCGs`P=/i+x?gk&쟲M©8Ȕ[ 1ZFCU0'շ%|49$6dg4?-d `>-,= P@fu!ׇ#TNCLrh@XH 21~θKy0 ?~lP@OIPs3`~@O2ܴ.hIhW#p5dQ--Uc4B=@-2Q/LZus&kcKI?ہѫ:oʻZ*K89FVN1%)X@ 6c5Q&FlG_>:wbTK`,ف^5. ;_ j^S~~nJ!-'Qzx;vD {NSU}Mox-Bc$Gv V>׍QaE+FYXl;tRTj0uKaՆO- e)(R¾4D|1%\7UNuFJ'@~b :f[BaMmgF)7ck Bw;sXWP g9:$u(VxX/'V K%7X:dȰgz7 Qj%T1g.7?IW ~HJu~z$D 2yɭBxN;+% t\dfUR%Ҋ֤@dHA)[D UN@!.Op lIphխttI>$`e+tB7 m6352/C_M;"}* :L'ۘ?:CA]STRQ)Iؘ֑.xO[vVYmr,[/Vk9ʮ2laVGÏ^5xslbJ̑_?uQȚiU:b(wC=C軶Dw6.TcHw|LyO-K&$nQ:.n#f߱ m+a*OK>!W7`˖S:.oJ;*DG "1$8HRL&hr$Eg8OZup6 -RAHxgudţP 3Q`VsF 6-Q;%vRq^/K)Ĕ4\a$K DزM*zJ$K@Zʯ·hǖ&Bt(B. r9_HۘWnQ(ZT?m1{4O]iidy4WkK4?_yS`%JW{P!+.:K!U}-jӮT[ODZҏF}a!ҼWoyKO i$1̗v>fMj/qPC"<>urf&X\gL'1n~^$u'7Ls US^۞٨[V 'Ckbxp'"Xcn͛?]! L>QgPc%([Z}T?{{稸> YR,Em(dy?@!ˡ!,Pp>~8{̈́B(IKJvXML/KG߳ }@Ԝ sWwnKUaRn+_KYG+M4}ūȷ6FN9;GA d˳"~PoNQ6xY\*e8cmi%ז{78vڷo_THV9U)#ƹg^Y#jҫplRVc8HJ x! V*!SE4%!sf}׵l,p" ٣e*Ҙ CCU\"Ds4G߆D0.RUI|4dPs1GGHL `X1m0+7hq!7ǀ;$, + ʌ3w0B ƓH]'k&j7;e.(De<H_ͽro4ѶV_Zr8w@ ^±.eqrݪ˜ R,]Y twHYX>;ε&"kC«;bUob6.u<3U̒R=8.t`&RbiYEXf7/b7+fk@%Nkj(H˸r7supiSUp-@w ,$&"ʻ0Q@)#s JPw쵳F&mw_LϒPt)(mz몤f+DmMnӨڄ0 Kȷs. z~d\ѪHNQ(q%񁺐(Tj̳hmak: )&w;E^G c# aɃn0԰i}VfVO\ g֍VZ[m9s06V]^''sL!&ŇV7a73W:91A$ѱf&SIsp&-+C)DNw?}l$L칞\1ͬكUݹm*5ۤ A8 xiEܦy S2X #&G p=8"edD>Dp0a?cKQ5$mʟ$#cJA~L -9*9tNO)ٞlIu!%qǖ4KCֳSUg3^ n^w dKunH"@/x"D QXötܞxOuDs2cDUy6#(_qooN |Q˯-Wh>mmhZ9xHqg>eDi1K~^*Û{BԥM\ ӵ [<&ޮCzٺ&\]ؾxw0rxa!*~|6cm ѵޭn8$4L$_[X o}F'$ &2b$  (d2%bihkP0< t|+k*+@(CVT fj)8voҮIHqnW+=k ēx*QҵwJYJWGnBMDmG{`PYGh4zwJ %D(Dw=`˼Jj$I]/X{3 O+;A Wh% ?A!n,=NEK˧ki ga4NëxF™ T#łsB -ヒ?. &[5涍ЉnοzSb|qv a4}7*>ά=Ԇ q||EM;]`僪c' 觶J FV 9VGc(H-irk,t]QÄ ZҊSR'J'ߣ,,!r|@IDPr"-D~qCc@~>[ MǤZ|Gego=;u_ʼحm*}v%'~IGߊj;5y|h lFo|p{]Hr5GfvըQjJXw іd^jt c#I4͈"ϲ=d-LY*W^iNܛ:Z-b?@! wKhJȂvo5eAKtCj.,<NA-33F=xE9x5ºn-@f|4`_vھXQӂ(So nuvs[*ls ʴqp>8d4J{uf`n4n\q;a e;䱦|r8FS*h`C_Uʵ>3DH`ZtKEU1'f8iI+@Gm uGJ2ұϞNRQ|X~# μkpD ==f|[?6R!@IJt 61VCOB< Cܩ pX(";Wv*D8T,d٘=){2 ) #lM"}DYĎ7P(i ?9/QL\{qGhҒn@\ Xť)Yᖱ 4|a-ݐ|$~mN C؛ {J/K뗕E#x?kuM.ft o*U L[Sa7l3}!ҫ4Y ݀5Ixϟ~ ǚ-~[ňt58b=623 uy' KkH¤Dχ(|N Lu@a џVů^C_.8{2Ogm pZQ3޷ra7n1:˸̙!%TC9ȑAj#8)PMD e8oux ;U%i;B ]σxr|l'zN_PԽB{mkb)ư b.tx(|DTDHySFRPB Xy Qa~=^`<ݞ0xsg[gJs+:5NK#G'beK* fm-o_Z M?@ד-}G۾1*Kyq۔٦m룴Xo6DIocqJ[``.x ~]m" 9pg1f}M V*Ja3VK([X{ru!BpK;s\.KHҰ4?;&6b=7z\6ret--6ƀv80 *3l5]z{8r. Ag b`xP<-: zn`]Kz 08 )@[M~vuޤA_N *IqPCgX "*ѭ5qQ8z<)ߤzŬnGⳢweL%7>@K>z#d.HA}^f)wGԝn5^e3?)hX4A;j^YIE 90'ZX4&ѥٗHz#x<[$Kl$ YUʶt   ɫ~ll C}l ;~!#j`s`:3VFRuF}=j#H2^M #CT.>P}DLvoխIH2HNnpzI!=rBq6;><06 \+\`g@>>IwCLJ km _e7KHw/RzhщBK R~X-_fs=scb|'=A>$lrfrQZN7N%BH #"8 1~-?K5[)Oi a,HD.b8MوH+b$)R;hd K!2x+pWQ8(y((ﺹ7#!wu¾t'FNr1vr^#]ᴬwot+СistP[S-fJ?ZDR *[@gDm֎Z /7@MY xz/lš$+WYm#eǍzMY#(p'V>";pڣ7Px59}gǦ~<$Cy(LoM;\wʧoH~H>|.H ml#-|8N~^5{ٔv#= ex {3@Cs7`n9VK% %Q#fL=voB,u:VXyz3.!5<|:rF_fظT$ؽCF^9[} UG߃{jr92_p