sssd-ad-1.13.0-40.el7_2.12$><amk!%>;H8?H(d   9 &:X^h    C Lh8ELE 5E   ( 8 }9}:Y}G@HAIA,XA8YAH\Ap]A^AbBhdC-eC2fC5lC7tCPuClvCwFhxFyFaH$Csssd-ad1.13.040.el7_2.12The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.W5worker1.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_640K%3A큤W$W$W$W4UӏWW3e996975fbbacef986bd76bc63247d7dfa32e47bd71b5794c1994b7d4e6cbaa1dcafecac1eecf378c35aa3c55d13aa2309ec7ba7dca0d79a721fd0366e0c4dd50f3186acd70db99ddfacd422a0fc7fdf22a2462be5b7635599c5e6163ba711f68ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903cca607d527cbe0997140cb91c635efa14740b1df571957bec9ee4170a46b61484b276dd9126acac814f88ecd42b1f6fa40568ff5322b55d7505116c76951a601rootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.0-40.el7_2.12.src.rpmlibsss_ad.so()(64bit)libsss_ad_common.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ bind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libini_config.so.3(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libwbclientrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)4.2.3-13.0.4-14.6.0-14.0-11.13.0-40.el7_2.121.13.0-40.el7_2.121.13.0-40.el7_2.125.2-1sssd1.10.0-8.beta24.11.3W~WWi,@WDB@WDB@WDB@W=W;W@W@V͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.13.0-40.12Jakub Hrozek - 1.13.0-40.11Jakub Hrozek - 1.13.0-40.10Jakub Hrozek - 1.13.0-40.9Jakub Hrozek - 1.13.0-40.8Jakub Hrozek - 1.13.0-40.7Jakub Hrozek - 1.13.0-40.6Jakub Hrozek - 1.13.0-40.5Jakub Hrozek - 1.13.0-40.4Jakub Hrozek - 1.13.0-40.3Jakub Hrozek - 1.13.0-40.2Jakub Hrozek - 1.13.0-40.1Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1356433 - ldap_group_external_member is no set for the IPA provider- Resolves: rhbz#1353605 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Resolves: rhbz#1347723 - sssd is not closing sockets properly- Resolves: rhbz#1339509 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1339258 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1339207 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1337292 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336836 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1324442 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1324442 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1311569 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.0-40.el7_2.121.13.0-40.el7_2.12libsss_ad.solibsss_ad_common.sogpo_childsssd-ad-1.13.0COPYINGsssd-ad.5.gzsssd-ad.5.gz/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ad-1.13.0//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fdc14b49f2dbf6c0cf4a0eedbe169a92ea0edbe4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e55d81be00be98a82b3f80e2a866865f9005253, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=663e05e80f00a72178e4683a27e25a2cfa751ffe, strippeddirectoryPascal source, ASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)9J9PRR R;R8R%RRRRRRR2R(RRR'R)R4R5R"RR RRRR&RRRR9RR.R:R-R/R,R+RRR!R RR$R7R0R6R3RR RRR R1R RR@PRR;R8RRRRRRR'R:R7R)R RR@R#RR RRRRRR8R*R0R6R7R"R RRR&RR)R RR@?P7zXZ !PH6ም]"k%w+p}zK抯ütkUMAO[RV_uno3} lr!ƴ ~K{Y)k1Ÿjmpa#1cle8 ("<:d>7&RR2 ,:S#&XaTQ\TSVѼ1x[hm]z챧ӘϛaPL2@~H+ uu ,Py%$ԧRuET=&U6}9xfz 7'䨌xrͤh'Ա.Nu=|C N?nlw=ɏr ЖytIWO'|RgC E~)sl%Qc,ׁ6d7\~z*t--%6%2]MJ.3fOP*)p}ZZ0e^2]F 0O' C?JI{u K[;Ixn蝚C(Aqgi%UcI4nnwY4:nܴ8ۧ =}vtA"d5y=*FUsuƎ?;j; z<gU, giOTfڏg,RgA Yb-uSʵ:M^W,z썈eILQ<(6OM~ LW1RGڟGEcq;]ۙr/ _1@'M˽#b84?X71LRO'3iû|x5Pkhy҉{Ven$`r`3>W8[Ԛm:5@Of[HרBRH7)dv9?]~ۙ!3(3hP(@xO:܈}V@W$>z,m sYqer`,^s4%)eZz#Q˿D]K2b:&Z敨$[@+̭= b'8ވs+[6NL%j;sKvtGȫyU/VV=XœikJjI6ĥT_E3{7:"'`R$W@J|am̬ 'yt#+O=PDp?` ErƼLJ3s,jl5.m~ ׬x?ML=]_EWSBzm r4 /i(n;_{ǿ, zwXWI[sS}G,N$]Urz 1[3~'U 񤡉&UHu)솀Rnݠĩ1UbBM,]A@K<tՔ ?hЙͭK5N xg1"I%ߚ -I릔әLzGFUmRk7P:'i. KHv˦>Џ4\h=XS+h{*v<Xl+6 ^viyË Y/ vYe,SQx=XӓEQ7~ /1lUY%Y`y hHT g#5r%CҘNfu|Wz+(xϢ9; ={-e03Cooz͸>@rrB}p)KVP9`l~ FGU^yhD=f mzF^1csOx<$I@*L(w[EOn1R$)W|mA&_y~ qR'"2rږ$m>/ R|#h$|@Q*9z!M)kuoo# tfN0G+`J 'KdʆᑋKOku% qjB[UC!C移v \& -rĢtZvMVH'؈ZS2"T9=uyϖM<>Mj[͑%p!끘K bH"N쓄 2*px }wX\Eu2!;ΒNIGEOv"}<'-Ռ4jtE1<-ȓSIk i^)N`(PRq JyڅF"3S{9M6V݁ P$TmUcK.| 5^9MD@> ̇*Jar2{#Xk0jbK chl!{fE%&IeÈuhmwwdM=@uMJ[T @>3E!eFYN EwYm}5-tx8B=2i-ZbQ"ͯ_߆ʈ !jMiH d.}=ob2-X>7(&b[R`DW8p[*ˍ{kEk!'zQLɩWzrStޠ'vĵֿw2٢nvBebwAKZ-p#h9Ż*?" ghuUT[(T+͉d+3!nVo v?~cڻ eFM֑#,τ߯I6.ˌgҳy)L;x@xbJ~iJBD1U|Qۮ/H(pJ_II`緊\({}r XظPkE˕$(&gNwZmizϋx[-@yBB}jw"84FirvR{QaI8Ky>d@B G 'X9uŗV i2jf{-u;++*: XZXez롋Wl>zC: tI'M *;uO68L+u72y ܱz|X ~[}4ʖݛ|] db3/.)C&Z:oPgJ_]#Z>H4k[ά]@^l-H&mΖd'h33Fs.~GY`QǸ |lǚlE.C\/(V&X I;GuXbQ5> F&|gf %e%wj9LJT\e $RG,5,^Ӛy|B m&lU [`ИW]9)k,8oⷂB:+opo:o~61B(?f2s1 qx1. lmC_NE3X/cs& @ -=ﭪX`5J&zv}ƞ~%:"L񪃀Yn'˟R% Ӧ*{,,LB \/RƋhA3;|@Nþslp^sV8:vG{a@ {䊙!( hpT8"㶒&xʟnC,C|o:z̕>v Y1[L6aI$a|bQdB>W$b4*>k>8!%`{D'@P@=uzcqVMYcy@ߤ֫ uHLgET.FQBIr4rc}ᅯ#Y0;|ЩjOډ]dg&WQ:ۧ.)ϧڐ16j7=O^ ixIF~ QڟP IPQNO"DkN4L"?Ԗ@GBV0t-Oğ5#$>MV ÓfeW#a]ݺ?#SGi/ Fӟh2KF~\-2`R7hy1^I d[piX7(PՑn_'QRDsmɒ~p) : ]; JZ{!v8d.BSv)q@5ph@rJmB6H$ tl*3*+c+ @{\HLJ "c/ Oϼ820d^L"`Ǯw<)iM/]9~}w'? /Y|W4 -AZE Wv৞#;E.Stwv_.o_hiT?:(_َi\b?&,"uoe)T'UUk?i5w9v jUAIi)iMCsBHW9 V܇]z ˩:}9s硽X0V!&gZQ1+h XSk7r{hfŵAn3gNF؄1+c7H'gKqFTEJ[Gq4We{KgrD{b̶tPdŢe=:?YB9PFߣqM>־Rt̟r$#0&hUV+:FA_׊¡_`S&dy<5 M ./YfK[0$KIMV#J`mQwmy.f/=A e)OQ׈Ge^v,WMtIӻO: y'´QvAJe!aL,FV( Ӓ7W|'YM~,2nW#( E إ@f-BF}PWp1ZOT"tt\85n:1K±mu4,gmo} bF<3n= (h@ g`7l@33,&mպZG,_ ?`;jF(>w5㉴{%)E2O EЬwa@#Ҳ\.( l vHF:fY[Ԁb `f= h>=&H ,LR@~+pڝQ(8toHװ1B)t!(ϳY@~G<%@J }6<̇trHS^xЍs.c z~t&z[ލڃD u@zDC5̐7݉ LBE>e5}]pbih+ Am0A{̰/˃} `Փ F sB.%U!v=xOMqԧ>֔;auZSp44g9_{,bCв/@nߕ`T'1oW\[qsE%#;v>gRYpB[臈S۩> V[`AeZ}2F5/+@TFoCv7 Is@CNA<%S N}H0KA!/d& <7*=tYDi+l(2Cb 3V>m dɆQ]#ծnjg %\m$_{bfT[uD;ʑ\E x3?qT#tr̰ȯ.cW!qy¯Lܮd{{ ejɨU~BV,wTH(boh_)lCx84wv3Oyӎ0B2yiS "M+s  jBJ$A7"F79y R$jE`lƓm> CZԈI >ʓ+iS+g^RMӨXljP<]M4ȍ,"ݥ_58^/vO)'JT <ţy\t7Z1(Ct}PRqiC\!<=#Ο-vX_Fǂc*@.MɬS,J M_i1Y Tp.<riVH3Q󼣌>k$=,17y ri1MWoi㱸Doz#5RT6}_t1_P*$x%3&{׏H,Ʀr~ "0{]9`ퟹs&|Tcm{3ӰENcX8g6XB;$3, u>$ OnLJ]M9 zg*NX6iI L|^b$mږ6 II$44)-@RSdyepL8=_N!p^њ^a%``u?'rsA;b2-7OWWvv X3K}UYG?8=o$3l"r*ߝ]ފ! (ͤ<_7/gUx.|D/2p«#AmASٙ6al̚fUܒB_h'vv I&̉R#{{p]`PpTI)<x̙XgjBhWsPRR܊[*j *B|Dp421+tnhW#_ (qwSLjnݣl x&pަk$SËB8y|:z@fY䕷Uv @k2Jߺ)2WlHy~ wP9\/Gn-Q&, TQDu,Y^yD`.Z4DMb=I 5̱hF+a-ǧfT`̇v^j4;l>h?ݭTgh*8Q)kA(JvJOئ(X4B4u&1y4+DqDநA~޹.X燜MR_s**zyj2n!N9&`x 0[>R!iIıZs;=зl 0_]I1X.Jac Ǝސho_iwE9ǰFζM0eg$[qF:OC%fUz0uA]\,+FbHѦ@sc&*sM ;&l *dr=<$_ܣ+#Lel!U[G|߫Rtƽ4aSc`EJ)$>x4AARH+ @Ùhqz:VQ9[X eV֯Tg;Bc~ؕ'3V'@V묀]ku.JD2Ч0vO(wK>K(;_Y n(~R}6<*ڞ9v8qӄa$r~C@7]Ɋz׾77 Б3%4_n HCR Q!bytjt~S^,ʔ&FڍGtƅo1<5=*}`tus`q6eџ 0~Gml y^`WSKɻ˴n4BmS#b󽛧7[b~LC=$\Ho>"Qo̞z GܸB b+dfIVJL/c^5t""%p"^)ve" 7zd^81XN $?),4Fmp%ƺ߀))# N<|XزӹU4@tY>KWĀ m^8n!dgC']aS9Ё\/#c5Hu YF ?I!lSPZB_^<mR%ʀ۲>-*/i!:꬘O'_%:lPÇВҥ-]!$v >JrNt&D~w9e+Jb}ڀֶՍIO$N:8q`:^srY0EѰBpȷ;NREԜ _J_=U!vC\՗HP$|ȣ1be#VRm05_w<>H%fv(ӝ`Gy$eW[`1\s=H{d"+c_Ex:Q-&(5P~q)ߛ \]($#:#4Z0kxKĐ'8.'*JE6 9v#*C% 7LI21Čc vPuDeZqQLkXaٵ㳴'\Z{x>ɛUlDgpPD'Ȃ"KιGY ks!7.~L;9EW 9Bٴj&%Q_FPGb< /eaw+8~<ҕ՝9L/J?9L P#gOL$qD4g `>Ǖ]UG y캨(5Cz?(h{d[aUЩtvVyaʟ'#֫6K'9gӬ4 紘s~s]̈́X]ւD] Zƚљ{@.`AxM?h=Lc8`bXq-];Es\̜2N.MȪtX]'vќ\ž(*5LyxwRdlg)WO= [=߳\ҶC_G:8RtT%֣UR@1sw%j;', ίbЉQƒjy:Xjw:\-F"+WM_mvkPٰ,HQ@9SHoilVBoYc {)|c[C}nISPp#()S+`~[DH;><@{1}Kud]NejxQ vgɺ*/ڑ-àZnTC;!Y2W& f^}uJ?Fu5.U!d*#<@aS#oD Z@!ѣx@h@]GazpCïYFH\WĠ+ПwC2nmq~ Ο;w\~LPЖ&wv ZM=>BٍMo VٟwIS',XrJB-FH)mY!Ȕ{]o|Xg*'}c6q[kNj5/?ɕQSG7 1mj#XHbpžA98sRN܋!MN:ܿCtduXy񋏖p做k,],: ᅼ*dteBE܍j2e_)X)w6fY%8+|˭t&꣄/`LEcG~zBe3n;0Yk^9s,un&iB;)KGGת{u5f9p^R`} y1pz3鎪كO7Q>0=gE^!$ť(ʫQ\eV|lq-2?cj|U|jLǒ2/ĩF=ٞI.!.(dfQ\ʍ9WqD*ѴFNGziu|#dZ7\I\˪f`J!ծ_)jwDy+c/7 RW hF1l~{˿ǻsɇ"ɫ\Ӯ#^M兰J^g~FBFBYD#tkRyh_5(ქ󚘷kdkduB`}fp /cxUFv]RL}Nkh3;c&h\ʪj47mC-N&l$@&DXmw؈؋(v)UMH_S~{N;ӯ"mԃSؤPEHO{EHz宓Pu0.>::X aYO{mzì^D]71N4ҵq6xhfdӢ+>(7<9 &Op1P O;wkadH'<&1{G^'3_NJ,@/-;n38A:/5g''hǜg5D ƲM-v:Mv۴FM(.# =cfkRg Ϭ _crCP̠_=MՎ#UܽA 7ffx$PNI'XW>*TG/exy 5z2EP! zx(ſ^/-9Jq|B G8lLcu4 :}7hrp#a/Q !u1ߡs+8ѴDigqQU? ӫJ7m $B}T#Mʟwə$]l })T,/R4'ŲPwb"ߝ uvY n'A(!w\9KH"a"?(lG.Fؕ}Db ؽy͠fw5ҋU/#Cwnд"?j?s0rc٨/þQ8t.Eu!8AŤ]1qʞ^0Ek۾¡\Y#D.+<_5?D7B]CiCL|*\!dv qB&W '@7-Y, {1e޻j&Ƃg6Azb̉OZ,o\"n*al{sG[ϣ7iiEN~ v]ݚI|^>G5N2#K3lUyQo*34fF)z |x n1QdeL,WlS&vrՋW Mď8Q63:SLGإU8YQlTe]U}"_!CbC <r9m?O(;&oH1,9b ybTIO!?jH,;i2+{ZH{b_VCMzs|Lg0j![8Y7QCpS8 24SnVU1>Z$/q^˫U|\㴊7xZkM)iĻ4颢ݸ 0wW93)s59!,"y2 6D5.$)JOȌIJuza΂3Â:zE鿵)*G~:Y10ŬyU&4ı_eQP-i]4+@&I*Mا`Nn|\{[JڀQk:RdJzʕ%:Vf܇iB`yM'N\=4βJzoA '~} YJ@^K~̏2<~Ex/`t<, 1!{xu{~w4֪%WyqI$eeXO4h|nWߖE`ڻs}f@h"4Bz8Ph# mn"lك3[e`EyE!4ft'({Ӱ4xԋP!kl"L,@С?7Cm43.c;]zП y]f IL\ڦr 5W@ϻE-ͣw@xPck> TǍ6K5iYGFzY 72ϐ>Os5bkq69}`v;eVNax5f uS,i 7C Nr,2j3B.Q6"j&L9n\Wd,Ca _hvUViZ>{zȽ zl {lמyC ⩴lr׾It ar\_QPh(QDCd*߽} L С=^ΡQVkZشOQu<\[*P/ޜ O414"O*xfQ继ݖț!qq@zeLi|7*,}TfBPp4Wxxt=y4T`3YCz>HƣBb8p7&D}476hѪKxHkUѲl"+FQ+r0Pq |06zn&6"&D>3B+8>iTX|Ю)q/?oW0,klbKn } 'FfjNrĢΏ).W%MZ8a]KƁᝇdNn9kP}0G 82KRrG9nE@NqC0o^ Qm ڪnl]ЇHUV/]ǧL.wv5.$c)(.;T/'hv-;ᖼV4%HM,A,H~pJ$[j)&*CJa6$(L`q5ܮ"[?;&ڕbǓC?Z2h I]w}pѮy>Ž.ţѝVʲRmK||ם;c9İ?<;APCܘbәqe$7M?/cHzh'׳21?"½NyRk0I kU?GN&uk2c23.d/dYObDKBӚnJ5r7[Z9[ytcf y1t{Ӓ7|첎zY(nǕ J\E5,5}P F$UfQ?1Y {z`GRM5k3x}j Ҽ,puΡ{gGk uo:$*R<8n+`d̹t'4͊23yS!}MLR^w93\gp-:bT(LIE(50a iOAWě>So W%H\lE#ԸT]\ЊHn6E[3z4omtJQifv/Rv]90+}]7[9%'>y 6aF(CQ $oz?ܛ o9[dv+L_?ƚYc]u#q-M^8( g!lO>yWY-zO.1R#qy]K t5Zw.K]:Lcb%F ~Yab: 'K1ѥ&}=S|E4vCxMvu/"x㵪V 6 Ѯu'l_5wdfe+zcr^@ =遴U .+L.Rɝ/1‹BowRYE<\CgX nNv IQs~u܌.D+R8{h|㧩?~(x@)`#ܚIOQdhij䱻,qZtAku{zw MSS,{ovCp0שCh:T^{<עUa TrM۱]9dHefHC|×pBT1%gﴯ8:DЬuc>ʘ^B=8>q*(.@垤ۖE!zE6n 4&,~bnt2'x lYhOAET>-?~׌ڨ+`|Qb_Xܥco,"0=*qW^TΦ崡71lGBWJy_Y.T7I#c:H¢ᗱ|#EZ#)79\DFEA/rG)y{H25<'$dhf\ 0Ol9憾6ʵ1+"66c+Ʈ ttY9yp*BbLUK@jlDꮾ?NϙQ0֧0k7`u9=ao .T @ Vv9P :ee׍݌b W|U,%E;{.4#iPsF$n7m^o\X~R VU!NncDےBĘT9 'k9 T:Ynf|! J=m x"YNG$B-+wg} 7}4*tZK퀓B&LK+<|$77~U׻KF V y #)ƨj\jnWeJST9PoAQŕq5xgUE, ;v&0y9vɤ\Ѻ9G#W(}`&2B}SM0bvdIy!OUZ3 (1Zu^E籛8oX!z\dVhO-hW# y}˗U1eFg=JrjC<_ZEMwީ`Ye6V|\oBL2]B_=u4^㔿uj 1$,={PYȄ:ebYRQr0Y>Jn7p\^B4ոA|~$fN[ $UcjoG#xe̅0#Ry91'Ϡo\SUon_>p; &#Jˏ31ΣOTX{CҺ+5_0ߦ=P0׊<%IYV0]:KҧYu`hO},d'Mc{@ox//.3t9C$[Z%'7=?@;V rk^&_UT#Ȫ!W=T X|vÚ1-_+ǃufnFGS~qO֣* r_^Vv}n39 R(󃦌 {C|K\rcYaP9/QD`ۦ"Ҽq4Ktۗی >`!FZ  n ^9ze*}J )= *4e5NJݸ'5C MNA ?#I([=>(B,q$hx0[p ccbG# ƲK;bdmb=W>&%BH"88#$tS D> phonNZX::XP cy&'i~R ʹc WČ O(H@TJM r[N_i&}  !D!v:uR4nj]a8"X2%յ"  6JH^7* ()|VS`,e[Fm@N-ᔒ`#5$d^dľ#$Gܛv3LY Z=%m_N0J!lvbݑm!guҍ@׆ 3cϛ;8\WSʁܨ#ZNa}4~ }m.c7r9DMDr^+Џb~K͛ {xԈ3<;k =) @(BG;Rn% *-uy=R\2X)-s/z+_.m/0җ3xtKϗi :sE ,_L//a,21^{Bl K$B V/mraD&f+)[3J/7 ≌%})Z!viAw]me&RT M{;8kTx.IqD.1MuH3L 9՗^tb7Jׯ{>VP7),(oK(͉uȝ,'Tk#:#Hdk}^ᒯ&32;5{A҈ S&>F;XD ˪ x>P+t;-I#7oq}R*9,qʁҒJˀչ]-] /׺K +`6VWJ~-6چ_a1Ӫ]}Z\#%,u op~1@/3aV #[7*r?b =) ]"c?a$AC|kIjTud7&=cp}%at$^HHDS\gOM+U5GZu\'-Ңԏ_[K@HXh"12,+&Gxu DWs?O̕?}e؏9S}M##l)K|bKR7٤-4ANwGJ>=m5_* }ZF$eM}YE#R/qEsFeZaX˯7EJ ,;cDSrK K`N1m%z[Y!PhԿՎpQJZZ>nHN :P!>MDm"Ʒ<̀I}ݡzo` yX)F]>aђuޱU_YlSAd$].ٶA&O~7Ғ!NTwz^JczC5v bE꺑mQO]<6!xP69x)mw ޮ0^xPK~&Ч RPj{#LTBf.W?`I1O6wΔ)m/O6Y|KkHƈuJdWΙdeg JOwm*Ds7(~+9/">9ND"Jk̄ś}pC#H=!vjcyօqP]LȜv1C >lOJ? O2|fuS5.) u-+|.bƫbo;%e:bS\{s7 Jm?Gl[\(:׎ /0ZAb8s>+qV\S"`o_UE5fB+ ]|9r-i6Lj0!}5ngݾ~GՌ*FmUT8_=^CwޯA3t%;<9 7;P~tmq+*k/+tC*: I7g泓xB'T4Rg*s}5az~P Jjc61oĮN'"g?,=_E>T+ا~{RL-=N'd I,N5Y81b2ìUZѴ  dLQ;j 7;WB7rT7Ж2%-&7W#3>Cr_щ|~^#Jj!ZrR˙cP(\Ƕ$PıVh_ƱNlǶaףγ\Jba0L`MkUUj&d }eY{+x+ )wfGf{( T׹wpaO "9j\WUSeUTBG^i|Wla(ܮ ~G.k=ST(iy[&-TD\mCp'r>hpl2 TubZs%t4U l(MMm'/߼Sb_&w^O^vR*Jfh$}`)=I _ZVI@n{zTXU@g^9nI])[Ô(ԝ >VmoM)(xUx2: ftƯ%ȧTE=ᩚKlm!>S= 8 IC kE!.% K5AO_kȯp2%e)U6 ?+H@a3SL8  4&V5S2mwܫC_Q-7Fl#/ z0z]8;s8IC RVNPˎ[`K}M]0E٩G7$4 W3_=y: kj><&EW]3jM_]iMl~1B[.)fPdS-Ϫlg,_kLx1{ʔSo^1V9},]=Bo?]&Td4MdgN [GE.{Nb/͈}]kH=o@HF3,څ]FZ5C+?4f[GNDԯX.Nyc{"X,nOk䗋`^[-U;RAU>< <`ə)%)~-aw烑(0R-G9!.$ F; %pFKm-DG*+vO[jupi_C1hQ}T \@YY s(J)w78G+L5kjw!4 <.Isua_萱4䷰a&Arj!3M4Ht}Ac(Vtt-CW#MI7ΞT' T>o8[OLk7#.l`&d2ѭ`V4cSy$J͡@Ljjl_HF'8xb,>edi"4|i 351\}Ps3[EPWBou N=^U`6?gln,TY5aʆu5yeL>+E[Jo]A=&J f<3ac;#Nֹ!% Ro  ψbF>[Ķ ,jammmtyJy&6Ah 7"odt43D)<#7ŞׂRֳÒ B%LX Vv#ٮ'0 \y9]Luh/zbsn]6&ND빑 w䮨3D#*Mڛyq?'(!"[s:U7Nf\/ #u'IRLI]GauAES I*{Y|`!#b hK%z7? $Z*G94>5437"Nv׳]fqFXh5v9`bB% '"-7pfeH6λmbjuT]9 l90w ZfO691J5˷ie"#veqh9vStqa8,h,B(fm[)]-i ljt:o@CΌa@-*:zA'Xs5J'15 h nWp@ء-~nyB|܋u<mT=Q"h'%"/x v\v;5,'1/h#eEɣ σ"ȃSҐe^'bkXAJ6p\&dCχn7cۺ}pktN9R?)0"S}"wqYkqv5zWC<Ң]Cw3fa3yL@lCe_W=Zqp/H Ap(Uh+-n8'fA(#BXl^qInnI}BB&5 SwZUüxלt4+_2up]'|Q 65sMQb(L"KR|"IBv)/t;YaIm#ݶ. z+kn򡬈JQN0۸q1Y'`IZgG~k&+5~wo֧pE|b*0P>.Hkwy{'(ȅ7?\`"Sms1L&T NŒ+U-|o`w xosQz/ p'̓؍8_o:f6`V<$NyWyv8/NA G%Cz~L90/;;n,2%=CiY]MN6k  ,f,ƼlWԁ:,+Jbz(Ih3K|N $6Ą߿*m?r2*@8DkH(Il7 RFESnD6c?nbDT 2U6\JDBO~ag)yҔVͪg{M<̵(`mDɧiNjڊV\ v-zs@{Z)("z^3: ә2u^Xn +ZbEcOu\ZRM#ljc3Y ^Io|2 eLZ[_Ú1ncw]b7!YCY; [} (!yw:J,PJ'Nu9P܁NF^2x̧UWsSz lچ} s4#(y9pJ~PD"7<|A 8֐#2v:5wDP|d#v{=ė.8"j[{J:nO=j;KV1Jiu`%j#e]7bZW`ײ)I(=!}x6ƈ&Vqjugng 16)q߬kYסH?-|SIʝuG3v iǖy0NCsk^RM*G``D@V:5y:믇ZS-Qާ (9~nb rQ hbWC_SfZ=%OB VϢs|F}hC[ܵOp.cf/sx&P4DM>n9U{*ЪF.bܴ%R!j]98q}'εNb6yω7,?w Mz)+a1}3u4|&AVK_ džBvlR=)h;*"ǣiyO`*WgcXܳjn\j8#S!WS6x:q{_àI hcx偏V--i2uqCfI4@-3oO5131 o 1m 9~E~l[U v:V9fs0aSCRn,rZ:؍{3W;P/&e; % W+2% }DDK4OtPz| ~; 9ZhY`]e <~.PC<2=j @dMBȧf8O{#rB oCs_{S_^k xp=n T06 mv3-MsQ?hpkq& w8VƟϗ$}R΄wvC|ϙ) <՗oq,_HJ=x;l+"4Wt(l_wL%%ٕ~HoP˫cS LI+9os3# (n@#+ Qp^ELiT$KQL| /Pxm2 kG;@fŨv*vnڜ" .~U3!fo#VrQ8 ȯAKvm"jpX5Y^10ʪiʭK@a PsF"R+!=t\EfEITDD%:3GUv # p8J)8pmyW͊<)S8th׶2גK#8j{{wK3dHi/ %g⟥\ *S+m ՗@@J q zL7S fG u+n\'P^=-ĊGiHRF,t黙 z,upV}LJr/zC*BDʉ#OhO:F !u\=Q*lrH톱2W,1ȯ`Y ^Yi"X"O@zP m3nIb B6w<sO\F dVWbYeF $D!a5t`KA#F$-4γalj# PG&ߢzd8 }V1StZYzaa^vhv:V~mp%]PZ[᧟%A#aUt&gsLp]\6<6c΀M l<`<6ʭ-4;)O0~T@ی!1]DW1KIT\Y֭a r#+kyrH?x?;t ,2c\' v}E4'B *r*{2šHbӐl)Lq縗t:":$xz6,eYyֆM7.d}nZK{_LrVOtBaUB/J*C UbU"E2Yܼ8@2J3;A,zz{ŝkɘyQγqbLq oA5f!:@ bҜY]QPqPvzBWdc܆VT9s_9 a)eWGSGS@P 0Sdh9TLojg$@jɉ9|ы_w7(};"FVbHEqqiRώ3x`mؓzX$> ~Sͯ _]ys l8a7D~x_sp{h;/zyO:̄ŏxgyஊeʌqx8k8,[@`5&>|FA/KCAawK@r&Q/iV`sQ9 )) ;]KZq/([be7C=PgIK&3I*tCie$$/uZԓ-JdZl5|MMaQ3}Llh)UFAը. kc_t NPz9#~\8#YnzuRt~u"xpȽ,uB` Sܠ%ͽ{R-la-z~)KjVp82\L7CqemzUV2= y؄W@)DBCm G9IIҿ_9QokUd* ;H=;Tkro_*4Vwp_x/rfю.{ ]c3/6=?԰ Y zu^4u_CIq? _ -[r_B+eM;N/DͪWk/ x Œ49x),$6RZ%Vb4:=#=Y1C gLKX)CQHKL m - FQ(2)0eiٛuLe)] Q+#hCEWJC}L&ηK{BU`kPM.8QB de>3L+XHE;(5|)±R*n[lڶS(3.Fe쭳=xS:&!7Jb.wN67@ #[8yㄙ{K<0I;XmxŸDT!軳\K|}>I TfrΎu7 hxe2fIG뼍"g֢^[NιkF;8KըNCD)ҘA882h63jFM1q^`tQ1* ѣAdXeuw[=q%"dKZ2)ӸV`S]TjQ5|kS3L}ˋzia/KnՏ3L\)6[ 4aUGpiIQו$y<&7t$:ы^:EX Ԕ4kC2U"ƽs\.!nbK󁦑 ~ ᲆ':=*aA5lN B#cV5JhFƟrjF]!jh[Ma3Z6 ~q3Z] cV'\"s`B[enBY Ƚd.DĤ|cǂM^ \o jzx2WNh/a(T@9} ʿ47AE ea1'19PæG 8VngjdGb_USޔKZ"tQ qyYdw*; )> #x&(2Z,ToI'Ft͂ `Ҋ> 2g3Z0 `2GSh,WΤٝ*U>ycH,& [r! h5`{꡿:8?hPSes^[8uL&XU-E$z\~3t 猽-2;3NCYm~vf,P[Z+4vNY$˿4O/GI%OeNw:n`#wJ}d: ӷ-{v ZϢ7si )wlϳ&cm1,:p|59mAǛӭj@ .*MuQGt)P潟9 *-st&C8{_rz}5$/ J?? ޓ%f- fUl¼z8. ݮV$)3a'r)u@-n5ʲxQVm˜~_L~!6|Oµqk]M p֯.fPBA™I3nS)1 B]ٻS i|я+mG7pRX d^ĩ)(aAtE=Tv`DeSSz`a˔[ZzW XϤ<^J7 #nAJ[_j屡GT](9` lO.wOM2uԡ-m(7 ãZ2eUJfNpŘNu91"f0S׊~8‰u5Q a}=EBZL0sZ6Z7s`M{PYio^(},4J3s`IC$:ڍԸ}Z9<%.1ڬc"l7ǯȭyDM,WM%wW=J2ķ79+f\(wQZB^g3'R$D{5tST{lFApJ#hIf`pBY#dX!}' U <zg`ζա| YaR\&S@%ٜVv,yt7S&4{By=ޣ ʤB |&]S+n)\x}M72sW) zvC^˷{?!PEE )@ [[vttת]d2ZyGvx2"x*3h3iH:G0aNޢTuUS$"uzR6]Lp\#'׺glB"l 5!}`|-7_7^FƳ]QжC*(6ULl.*@˓ h96St6B5p2ycHxenfʘ Y+O ڐgu chqP %agQR2fpF]V2+qxʳNjbhmhx@LIxWD2iʲI׺*!EF$qPnJ(nC-n_FԚr*K):)=PJ&n?[bV&:zަcP%8Sre P,Z\XJe0.I*vt'fFf1IFraAFTK :z<rn^]ჽM%lQ#{=Mm޲뉹lp>&PIR֯y݀.|s]rۇX Ѯfw[x󼒆S-< 9H{d-@xh{Rվ@N kq x4la?>;MV1gkޖ-w|B6/~1O{񔄟|f&n)ec5w[i]Fyvg*O/B(!l=.RէjST'x XjE ;寣6IgH B c7*|Zs&=1b=ȆsJ0h" jK}4to=[2m Yw%B郌g&ڋ\ 8<^3s-ɿF7V3[]@c iX^ VO@eD/iڤeƍ/e/kr9m ܀Jcx Է%fL@7%:ʖ]hqڢax>>Mi(YS̽暕L+PΏ?σՃXx/Akl- |L1,~_' :`jcL ׾T~FNrͰ^,BX=v(Tv]%ay;qACk#}Z@i.RZ |F{|!FxFLkh z h-jF&]Z)7|e׶1%[GLk, U2l ԗqKSuGucYz ~3~EA[X-4l;ĴjrŐnˈ* PdEfiilM"kк"`걐z ^|Og2X=<#[;AJQGOi1"xxCbgp* DijfJ$ 䣨d࿢zBp{V Ҩ7G_{M |`58Uܕ i{|zM39ok 0/BϣZ`uyG˱EdDcQL4kN3Rr~ ;*I\5#~[mL0K.d}'AecY0v$$ mT*@rQj"fhw:Ҿ(!H۷DJ!V Q͋WbI{P]_c3hc!% a+fw4]y]Bۛ6O^VL)>x$<)=h]5`kMy~*' i镯$>kYޡOi 9쁯tJ9W_hHN8 *JneC\yV[9gLmP9z"uv !i\ԫ]'kg84qИ.QUT& u^lݜh-a*[%:~1v;۶ O^MrhtޱxP7;BǏ= ĩ-u+XZ`e9Zb]B)a)e遷<1}F 2mWʭ2}=WBO;"vh:-ST ǏS8i;5$)ml~0g dx.Z᠎]TħRKcs*516?Kԅ&iE] [bA#ʎR/k~TVLF"AgoI _>#G }4f!x8掕ġwnȘ>LUĘ[Z<:rVkLC[,OTTI+ & ec/Gy:IJ7R3_jHT7?FƯ5[:΢aKN'OHL8ǟQǑ0%qz\l+p S+^,ա1(rmT'1jM=\,jsx])@=Y?TTzĘ/lUof`0n>PnE R !@Ts9C]mDp%_M]5 x8'XiEޕsVF {Q[U+!" ,5!!$ㅷYsG[/}̇nc1j+!BEFX5q );oDH~wN(>[ޞO(IT/)Ts]<'TTΚ3>E0<3 A{^(?gF HuLr>|V;ILC:i.iZZYaNAqb)7ȭ[{ AW!->О_L^f,u$%V29 Uבuي"/n?2^R:}r\P ue<ɑ ceA4ma#1g'zx.{2.KzX@)IhP@B&U' \tƃOR >P%ce7,X=HNr7lgGmTˮDV/-_//6-]*v 0۱ˬ`kr ZgR5KT$L|md\/)SɩJ*=m!So5M}]QkQ 8ߥcvnuʧ@zObHpvě12 iGwhzZ']ifE,%fY.^ٽtD} [)N5Hr̅^P(u1S Dh#$"!LŴ&8(W]Q%mbyQ,s})ʮIJY6L؜z{&^zz5V_)  z$& ;xiWVF{ō6 DQAPx"sQ(]jY yz>&>1%b>\aR/Cߊ[~TKڎ|f\XsNИI$|e".㞓#81!Fyٖ ϜpUGǙ%ϲ VYY%F/X;GNJ?j᝔a~CWH} Fb K]<~g?tݑ3޹r7]6ri n ]C@7fJt2jZa *ph'l&'zdr\Rx^L'%L)SDY#e)X&7>arj4=7` 3 7PAՠbk ZV !@&u5 UNũ>)oP9BT1VJ?a\@ԡo C0x 뢝he) .oZf5,s~HN1ay)?>t͝{:Γ45)g'%wVv]BK(oiT$O4.`fƅ)a J TooSo?Ցll N9(K7,OėDa-bX,j߃`m{B.AU=EOSKc4pK@Qq[<E.-MlRicX+]gzQ?li^0nlWP?P{&Fi+'2A?Vs6NPQa_#>NH:kK/$ S~ a^_ժBI2G^v(CDGgr>]N}7Z.2jg ۏ$OYi|?gPEEGT(ͅgM+Z-WO :nd)C`((1A8y^5qLg֠~̴&EVpf^r @6pX`!(嬢p0 AYGV\L$*ϔQb _&h OUod 6 wݬU=_9 EhV*fr\ Gg)]w,L͟ MC08>EUeD² "#HԅSٙB3c93.sa]ߎdQ}MƩe-Z~6 TQ8fA1nEUFZycdۦz8'ɘY |(#܋ h6}9ੑ^kzv p RqO_?"+ $EϠ(&=_w8FZnXݳ{X?. u4mR[yS_CԎkf۞GvPS 8RK00!ZXd2xiM r8%ͻ/1PCnfdڈJn ~wCJ$`t~)O3qIڻ9y?4^{ 0blu%Fֳe,JJ<ʨau*}EQ5<T鯭 WEq9jбws"oBN`dv^5='M5O#&qtVx篹Ю ]ߪۥSM{\!Gϫcj33Рm<"$NNB*'o?m!O·$nDۣ—|k7&WmrVi=E/'aD 7{D}zaKi)@{-;d{Q3ٚS)(Kx ҃My 2$҃s:-X?t}Ԇl=^w1f»6B;BDqGG%- 5D6<C8,1BZE}*ϛFyQP\u`aX?n9%QWb~->GDK3/0xDzH8#ʐ?᧾砾R1Pݛ!관i `٠t%_MaS>'7׬vSCQgGXsoAmpm6Z", kzY]F}er:tbx=BAsW<%tj,Sq~o{ِ| ־O[..FH[ZDU$ u0@D9:n{I!ز0fۓF4zGQ $ŠǿU(whj."94d\E7HSEucw}?<B p)gq~wAФ%Dv*iSCb2gne;5äi5M,H%,1e,Ti,75GvNm¸h"zˌ|q.lu35 c7:ii0(#/Pi3Lb:9PkRiC.OXmwB+`#6B8p 0+x ߂6e?nDvL_kh-2*t';=&ϱl@Ό{1PB\/Jk'ޑW+\:=K%Vp.Tm3aT`>h0>?XeiAU !vJ9l[0uT؞<-^:tDe  %r9;rEMTk#$Uq }03ƹ _њg4(Ud0x|u]P1_:1d1hJ,XK5).5'BH2YC$A;ц8FPoeAeZsh6'7wN"0V,,mf :8ZT{?y@(a=O%Wn8ZN$mIj=uӻ)yPqw#d~eJ痳 ـxSQfuW`KCq_Z.3ќ( qzjv%pFj*܋"6&,e iD`Xl-'.v(ì). 9=K. 2{2E$Pqe.{w;(.Cz7߄c.s n'HsLHf9pN~*څqibN,pI?5tY'A\v70 }^UP2%FfAd-AOݰ! ! ~NPiupX%沈"2)DcSG! A1vɐ<$,k-y'/52XG Q8 H}BѬfE"o)fuAO[ʉ@n*N7 ~]-'UC&@׎\Q$Svi(7` dp yͦc:-,K"qʊ(jշ׀J] _?f % P[X|t4ip HM tzmZ.PC'$~Lh=/m|gf~G QtwU=l'zLLKhΩ\c*0"Z'/?:vނ{FF/O)KBπ.`auЂlFr^~kEd³X$=nO%޹@r[^`5h/"irc^g(æh<4Ha+L(,%BslBG8l2א U]֍⡼UR2(.}n3W.#~f'GlbsX>܏'sHp$56K@$9xkLb~lZ9oQh=۬n2q~/M8`/Di[R|ﹾҲos9x_8}\<>Ul:9%D1w;Sqd2gQMp3UcfFBK`f,X}Ŷ/ʄԣ\ް:i gj O|:9d߸.3l6 v4{쒍jϜEvoV*pqm!{/Rdެ*V V~(șw {l"& i,%sHI8)^îF}ex+!qA+GwJ]m]\V̖Ш&K {_FSbu^_{০K c}xG%tZD ƒ+E7meL/_Դ:?r:k@;nW߬D1PM[Vzᤦ=!?BdTn-rk$\КDx-<٨&Jp*?,ٽn8z^F@쌠2-IG F|^[Cb5 q& "vH,C$_].7}"aZT`JTb%a,~ZkT|4:OwY7ұ/kYnN9$%rqofuf"@Ʊ߻^Ę{<47ia/)ѕN/rG9?;ε;1Xy+RDK3\f?ƷQh뉩 MZGSKqU_Nx'pݺ71Ls܀tm'tiaoOsi6FYn~b(himž(H"_E^ sЧwqpkd(;@:Y~4uY`tŅR{W{kmHՄR̫6&lK( CBOJKډ\߀ab!ӶuYbOL{o :57\<;=x_S&<(f\G6m\4Wyf&\q`/m'SGbC4ab]@,ZFA Y|ѷ04uaddƦk3!⺨@ T\1`8?( Wm﫞NڠKEytΗ:{J*`p. q9)E+|bt`9R\ڄs*l2R=ݑjmfbwCp@*x(76(3Hqh- ̹БnhOPe֠TE7aKu-;"1OG.L vMz$@kUq"1 #\I7ivg=ۼh%=,2oMbé&2ۃ]C,X5#ك6bNis#z',{2QK^jMfFa_KՏAvT6_{UWl3R$PGyQaG a6,IECۿYlXy͆9HuMÝrXx7g$ke>9Xf~ ӒjA.T‡H JK|6X+xdMÊ,;́h!| .jo9[xɌJr,l|AzD@^E}՘u6kEEq0-o ' RP6f+0iZR>܉n@BkAEtR> kLب:I[DMʽM}"R ?9!Dne񢝀Q tR} 1wT72e򽼥-A_.;ئ^3iD"^^O'dD˧uܓc֚%)` cw9-8& M"qs>oŰ &`V/LT~eMGF*J0vCCV'1հ;?je!$}b3 Zrq7m⊢Q%7H G43҄l:I?rȀ9VI"U5$}ji5xtpH|yфFL|*i16JRO cnu s;qi0kfHZ#6td'Q; ٛo]g0Rǡf@WaxhH+"hK#Md C[$EDIrq9<Y@9مY tIqrԨer+d*I~wҳK J?q+<պFͨ¢lu轣wC==MߞW]1DVϔ6s-3w+P]"ޛPWXG5G'}Ӊ`+Kml2*`ւ/ӧ&NL jXe0|skxtZeXBjwZ1{NCJ{?Uk&;qkVNT;0~*,EZ׷4Fs&{ھZ%nBڣEЬ閟=S1Hr u|,7$ ɗ| -!]d,Vƿ0(؛H{ [QX|3o[z75P3Mo;tjo{ *F?eS 3A0Xԅk!.[N`Ne.`ӸVU7B8J4]Lﮤ68=.V4b8m8E]Il܈}LKS`Kȫ4WwspGYQv2iM !FԾ4l-Aokzܓ!|I2uŨ9BL3b7ϔO@ _&U3=d:N^EHfLc?r>y*4k!j6*>Nuؐsx+^VϏ[j־Ҽt̾׈e% Q7Cq{j"̾ AU& J.ο󘙤ZH;V,?UހntqW\xrwwyzrNCR[yo I!L?ܨP0N%8&)Ԧ}J/5MYO]XfP'8q̬))ek_ƬѶH<XLHKyꇜwWV]s eV#lQP_c}>p|cm?۴oprǰ pxv>tAݷqa°**wV#]*6Ûp'ÜvqƢnaױ*ُtDhXX wa{H>eI_8h<[xaTCw|0B-"ځ;巀M iSڼPʭ٣ol`#k 5<` 'a46ڍ5?!+,+d5KK{ov@>!xr'"=ߨ+Umɫ~nIV*=12 MqZ'St5RNh2\Wާt |~#6l#}?FNq5^{,Ta{]5 ˭-9#$woW|ܵPV$?Y\ƔVA)"Ox.v #?ۚ"LKaڡ``e{<꺜xK65 sZ $- 6x%H?q?O؁f2OE8n"~$F1UQbUPpuk4l=wy $&=݊@uH;{{i[Tma/Mh%Aה6{f .%d67QG^Fx[?;rT?BPG{`w)و4$[0L$N3~TPs8q%8wLJ0,LlL F]萳tFQvh?/=jJ)C#uIHa},.Gq`,԰ɒCiHʓvIQF9&~~"\4"AXe^8MyWT>&愃K]1T~? bŔӬƆi4_`5(ʢ  9e͙ u? s ,SBD kj D1 N@()&c_+c41[;S5;vsj[zM~I5$ Y|LTZa5f[I 6wAZf3TmzrDSZR]_\zuQv\DCo##J 6}촶SɛL~Ԋ%c^P2gtQl9Lf9<_Ԇ5=S.d[l Ok]o..Y-I+ V!Js(!GOUS5%iDA2& /i"W3c5V1]Ģ^ Y&R~#U#t_1|TFCϯ% 0}EMUwt\\6W1XٽO4~WtRɾU;Z$=`;$R5ŶNy5Ejne ->h)J >o`w_~0 |Hԃӄoͅ!(Qh%14 u1HXpLeh1Bꌈ,wKNe(wkD.R橦*QH\lw8a11%kONoXy7NDcqMT86b[t箊\N*|/tDE9?2KJs V%Uc:5( e]% ®v78+g0B .E2a<5'īÁ bN/^+wNȷdMٶgaM$T#!޺Y}ެ;| uoE eXZKS&oU•GqNj4ʛ*^0=&g\ mZM쳣~~}mSCѳF;c3|MY`REMs+'ajcyp҃)6RJ)(hmSŬO)ZdYгu2]X&L)C;-)FC #L܂3EW0b~(5@wɲp9ht%ebxw`'oX1VԋoAGkI\'ϫZd5 x`bU 6<ԷU/"֓J%(>`]Qo߸(L+Vzr2@+##C[G8%TI !r 3k uoqBt t Kq\DO.Jr߹̬> Rp$JOMާM~ӧXv4l([w}!bKV,B \&ү~A6GMGɋ,u yI)Ǿy~OS0 < gY%U^A5}Zq/.x&VöH$+Wv2ll# 1|ޜD A;f+nj+WM[o}\ Wq 'UڑnRݛ w )3F k{*lRfDݴ\ ؝CD})E &SǀL>%F 4ߣ{65tOY=(Lð$0uIr3K0e욭f4} &ceXړuUtF~t sr@S;Jzl8Y-i]%1R8X!;)Ɍ쟌(bL Gl,(RՅH,cV3噥_3=1ured}aL{{|b/QǂȦ;!Q=>7uD?Z%/NV@~qqe19i9&k>̤;?U8Yl8~P9 P 0&]?=車 )P`gz iv-_\dGʤÞ%LR?ѶZEMV-4Y$;6Z2Y[}&kC8B#]G^ q !u'γȢld'G|Y]iAצX0S6W\&[FjL‹Ŗ T&WB,TgtF\+x! \0v]k\T҇{"n$gWߐ{bqQm=M- l AWvX*]~6xT`qi;|>[2iR8ݩѴ2}qNn@ߤ"ScMAfmi, *WtQՐC /^+sTvH\t\:nуf22IiU6F5B!Ð)9~1gBc !=.C.]XPHۤYd~rT 1ڻ,_n`T`؝!9eO?m"B2}e<#-wETw'@6k]!LsI+] h($Q FLH$H\\sc"x|gDz~Pn':\^VX9!<}Cj<9L$^HkCrvp3 idUy84~ߟgV┇T#Z;Q[Ny2$sy"9He#ke\Uo,W"&v|{ jc6HpPՅD_6c?@ʥ2~)l 9wr)z@{t8W%.uDbÆ9*E7$p iqQPpiH|g T2?N._2L"忽v=L?] EZ {1m(=7bQ%.]5*xQ2emO`?i @[% QX;?LW{USqhS~Xf]E.sƉ֭9#{7M꬚s+|/fՕ !RnҷΙ? )v=e[&R\zQd߰Gb?=G¶&#Nt}NmomoaUU;|-RTQ:̱(GZwOz8^gĄX6I-W ڽY~ڻ]U}LpnvO8ΜB`wU{8A&Pa\S?{i]iŔR@i=PL_Q9׹Wfbn {Sy"[+Fu16+yd)ĞNVUl}OgbM g/fIc8\x8fѲI|[zhY~39FeKYS Ml9ONV z~.6t >V-DK˨ Qqc$USfOpjo[{ C!yCxs0x9L G. Ӯ)AÇV ϩ2\L+ PI=vu !n!H> F{DƩ ~ħawC~@{;>m-uf,|&МjhvY-9{ØiE ON>)P/T\Ȋv< F.D_flqW`:|sեXy܂f5 `[ҝϥ zE( _YHoՏʘtI_$B`mK$X|ڣ}{$(uj/<"֚Щ&;3rKwAuڏl69'quu]Û>Kr9FmʊEڥ!7~G(Meی8$qs;3ƔR/MR70 @yn*11s 8_ۍ_mKSG~kDf);mcpk,VdNqy=0Ȅ1=ڄvKݠyM%Z]\,Y6 '3 ]Y[3=YۥZw߅cKY 1Վ5·r:k*H />,Z9]ϖGTІB9)La[eʹd gymtg*^ L'EЦGl}u;[#H& '=?ua֘6e5MK`~T#k5嶇u"G+;dꅼybm*rUNATV"Jk7H{ihJȺX]5v s3Vsws GjjX>}MrSW WwFGˎQt ;@MiNC.fvCm"EnfL!&Clvr5 PČ}6=&2ܤdK_~{5j_l4Fi`a8qXxQHybg a%=D}eK3=j w~Nx'X+D#_]/p5 '@ ̜3o&wɋe?:P1&r%\!^%4T8EӸQaʇNcc*t+Բ.}Z7$帺?sd Ū._ΧlMm=S6w ' 5aV wPik|[li(df6#!dtWƂ+<4]>MGӖwsqݔ]bP}'H qPŶ9.O,9lZX+Z_/y :Do#f=?fP0FF =?PY^e֬+X Q87wØ!X򜯖\%ILߖIbR 5@7RjKv E[{I- Kb?,Gt/U1˷ަ o|fv77 iMbohUwU&P +ϮlH3)A,ܜF~- X BihIsnJWGRuTz`V00́n,FX{d~C5<20]oFS"]`Ŝ&lo~b;gt8Z2w kLV ~+)0VPW?0 yw{AaVrS[kmۥ\(ƕp^3\2~ev?Ei|@쎮 ްsF[n[bSbE>8q? &< TjT-xX{~+T5z@=$S#jb[Oa|h 4%Rro8;i:{^T#C\D N`BWfT@&d @;G ֬崛vn5[꫍.Z5:7.N #L M# ϟs\ɨ՚ 7;b|` ZǦyѰ5V;ħ9fvpo*%x])BRRB~Qo|2),k"܋ r#-ΰ^d;+.fpshomm>dBřx;›uvWuk;H8 7M,"pָ8v"=jk$6@.c/jF6f[o0.Ao+9ّ;E-JA0_׋Uf غac6dj`2= JHq2A>\a:keImaJX85,Ev6鄯\B |k̫]|XՒmn ؞ J-8յ~Өte~ZcP3TIutNh ^BYL+γ,Z!Io#Opgl<$C`N2X *ߛ܎{/2y|KRyD+\0K\.gV%~x :aѽ۠&]Q [|h]X:^Zq]1~n1.# g]$p_ +3k4^#wkbᕩu!svbHgM?I"xRKenrHs(mU'걊F)1֜%*tfkW͢Vy>/GC{S̼咱0G!5kwQF4a fmڼExک8*X ר!(x\"k*Bo|*mَGMn*7"UI)Yj1?w- Bg%Է ]D9(Y=rz\H`y]=Y^xVBGiR$6= tJs.Fcb彅 ^ӀGi9?2pHeI$(qDz[z8X_nǝ_w3Ѓcx'ŠMz- ^>~'MXL)5aEޥQ_c,JC( ztј;Ě<@L)#wI FQm%5D n _.\r]dyZXd w [PO|}`fvaJ29G'cDgJ~BTdR:O!) ѵ35?2?eIa==m[K֤j4-\݁ⲧFh aFvGf1t/9{yc:M߭FcC3DZߋ3}&[zc/RLSz{2C_ZPV]F~}Ulp~)mmwC@{?0Fi ?/Z=Dku ݭL'mJohQØ$^ziWNZ/3gMuo0)ѰSyCl &#'Ű+똲x챕6 %X'f.V4Q~Q Q^Ғɥ\Wlڸ]&)$!^{S1dݩ> ~qoN #KE C}5w>xhu6EADOM7Z x+z1:'0>̪`5]!i]7ė-wʼn({Jy ,u:aER0 FmSa&JI>MdNd*a4=\޿<bbq[LE']`+bom'Q:Ӑt4 2hAG`z=Y.?+Nj. Ɲ =s Hd)ƖΑ-l)27QR sa!iW$"?M~P,uWHRULˁO)rL Z"r@ #D/Xrc,6*/jRjOlF"]mM=PV)hPH akB˸YWiqV~pU7)> ^Wȁ.ACrAe[%i^~$`@ {F@u>f2*irk08-EoNݸDW }CauV[`jܦlWE::ڒ,dxf,ն,ѕW6.G{2o~$frn*C(sLR&Fr]` 4\LD"y@ZS@KF-@a^ -%S%f.魳7x7½~_ݾjt6ڼPjm-m :c9"}d}qӄ22Va_߹]C~ Uq]:h3d0I;|X9`gmZ!cL&i^؆HRE Qe&!7UIC8X5!3E77!W1}6|C ToG+24n-1'8|Z?xwmKeS,PH!6R{Uqٹ`EOUM\q:i*`)hi]c:xKnޒU&}q#,.},Nz N4Ծe<0 DZ\; EPT/YWw"6zX(}D Ocfk:tĉGCwL|e!oAlL:fhI۳CrKP<,~ͲAXQn6vKXb# 歟@zLwIRfݧA .n |qY /c)8I'Ʈı>mKԄ(x& `EUo .14ab*[69qؕ¹h=8md_Sg "s:qsoM&?+ڏ3G  GJ^$2Uf|!sѻ{ͧy@NvMʿ#7ÈYCazA<\J(~S/Ш8:B^ul~q^ ;?*A*ouDq&س߼RvGJmt"..?K9 vD`fe]z!,~n4i;׿wU0RgϏT a$GJXij#̈Vݍ )*҃-ŸrKY;zG7.Z(ӇW+YLD/%'7:(WLkbq7ا3|Ʒ*zd۱Q}M*X{=\vQ$&|p8j *+Dr 崬ч1ٲ3kZTY#\u==Uz=gC|&66dD%ja&WQۏ+r={ TX6k̒G=k]-Rh\B|N% gHNDL@_G5M9v Ԍy9!+Nob[/o'4GD^?uƒt/>]m:*c/ T79q7n҈}x?8a80W?Ӏ~*Nώj .>``2'퉆]J{Q*:ή"Kԅ5M=l X=F)B8g;DRtC`K?3ile/4:U2d0$$|3З!`n`Ӛe:ZI?ߛVic蚀VMXWp,(Xwp9\nD79ڲ! D+]qaqMG[ x OSFAVQzc=s}dHh{fomeIÖw/Oje !ICJ~kXjb$EΞpNRl`'@P'a7Fm&)P:SGIRfw>>]ߎkXB g1K|pĎ }M/OWLM5D4,9zvQS%vMwhG>X@cV[Yԫ?W4tQ 9 ^%NWx@}Yς,Ry/@}Z>qg\w?R^nR.fcvbF`~ZO昀NO韐e)_+|w~\PԚ"Kz[;Y" ?a.*#d9wA;DJŗXSGEh\kR ݐ1v2K[[0u8?hMB#cn7o!h%~ Ϣ }~ֱd$n40m~ ))eHbr 5u/UZeJ22?WpUZ]`l\ttk9!G{,Dߍbj4å)]r!3oOa݊Oo!E|::5;Q>~=ƒz3b'AۀcW({ߚdtVxAҍeSx߼&3FoK]DŽ\s)u_N6+bOFtzL ;(o":#TknR9d }loR `4y Op`Kc^QO-蛰tB8! ~lDŽB 2L+140N+Ċ=z3ˌ442*=2'X{HX)kAӋJX\'"gMj:kܙaN@<幫FV~ 5u|X^tw#=%@]ŁLeW92sis e4W /mt,s˰t5y-t;b3ʭ  -|cԔ%S]r¿Ɋ+ TIE5#GX4%BCL +^ 2%eܱ'3<*a gSI/YS!*s7:PT$u6:$B=ca5џn+hX,V~]O˦cF(>< .: V%zVsYؙNkm{;Kys\:Q~lvy n4 VY3zߌ-,0._gs‚3Y.h*T2ôom+WXxr}vBJ3qW'L\R"a2sQfi2=+t  AXXr C-'*\Bܛ\ϙ! [`R]b.8+ipN 13'.@C@FӖ򅓸g⏀qJa˦ns1C0 H1`ueΡfMqua$^bo/a X|Цl@x.GT$~ͳשZc\Ciyca@ը_rZMsF2\ޚkvJp;~Tobq/:<<eZ1k7vʶW >'j!)!{I0ӟT6EM>.OE 6x(]G ׏6<2>bhve{pA^5}U'ToG|霠e[$C~[FS8|:$4i{dÜ"ZruX,ADeM.g\ll4U,!8f`:u9 ":}NG @mFegAg.\Esʆ+nG]%||jǃЫ95d6m d1A:7CiQA6#~??鈜.OmkuPlceZŦy|5G;Wm52jGgwl߁&ehq8.t &zX0WJȃ%4fts'FeQ58Bqp$UZl?QD|YkJBJ%fm!Bkw4 $_gT-nƼB;Og >Αb3U;.D[}|"R)I'CŲW ~X_#mϪf$#Ȱ []\&B&E ..R&I\,7 ,fn{&mðe?z*##.Y 9Fi~&e+ELnf3Xg9eDt{/M/W5#G׸, r0A#(Qo /֫y3Vki G5 qaKwo,B,@R"ԛ/dzlDD.hCxූ!Ų?HVvەBk(&]ye^l!طrIZ^t-Kf(Vz z#R1[B?ZЅ1_.x)QNINu?*[Crٹd- "Oj&>p}޲]ސICiDe?f.`~0yӬ}"LME椬4|亡ͣ)̗j3pr(V dڷ5֩2(| %#L!$aЕ96c8 9V^Sc aࣱ^koGVUYIp`uHٷU, 2-{/Fը!NgT=(DCw1d=/?DEwI kuE~x%Ԅ(U\T.J$jI-UP1  &u+X>~A6l:{,аoz2Ah42BZ@ZQ/Fŕ"}(Wh'#%~y>'ri|0vuTk s2I^1^_>J*ϛD\%7@MR7@\QAl@;RRE6LD$v*Θ ^S d8Upr'2]`šv,EOO/ְZ:A,A}|g(o M)MRwK!+ 'tQyh޲Rs yD`.u?0Dm"2 c3<\|*'7޴~g/p>QC5lfJACu QPQc#ԣա'DsE@0ByB͘jWh |F_}6 uQ32%[OL^8s1C+Ӕ3jnQ^dѺ}TZ6jX݊F;9|QNvfe,%)B'ںw6̀&qZj_C[fK|[;&lVWߟrrO!skIeP-Nd@5aL6C}sVX IiϺV|è ge:%5_Jق:bneWW|d\f6_oL?O4⻭I/v!~^WF]ʂaLΘYWlBFI).T3&R)0 ܬas0@]GQAisT@mkӑٰ;4 pR6ΕA,_ݔLjZ%^LۭPqQB-!LQՔk Z0мGQȝ?5-&H>(Y"XaPɵ{Lntle+D侰O4-]Qn\`bBf(&Bp#>O`]0z!SI:v%!g6wi{vNi~Wna75̻Ì"16Mu;>3hպN}+uS#MDxJXC{H}̱w8O\ZcِZNLʹ]P *J*rm#Jۭ#+&Z"SN2RBx[54wK YgE &ih2ݖAg%nب4(t͊KqL[ zDQ*Ůo.7\@>sEr:# ŭ p(]>!5Y  vZÖPb#҂N EY6;r#; 8!2raP[T!t dՕ~A8+`}m1 :5; 9 A7 aov֏89Ċ;fsG]Z`D'$ rKv\"ػVᥢ-͸ƪe)c $$*cAW~Nf|?F8ғ ~ʯ4J_x`N/vLqcYf-܍h}10ZiMi)#^Anzd~Nz!#nebA5f߸ˌnu܎ʇ817TrtZ"BO*Q&Ѱ$ ߄107{r_kjڽ0"N<ѬXn~FoWc@'9F\i3BT٪3ajVpZQb+KkM߾H>!s| dpG*x,Y^`at= Q6E G WAhbl*Yg} C>g%uRc+wzܞ@-=WO-{@9ɗvvv]Z`"`6jَS c-4*C%N6<\%o/o kj77Y0ve:QbsJdFI{WRmLY+&;MgqG_bՑF-r: W߷x x#!nBP}XYg)U3{TuRh3T~i^ʯOVj1oNv<|^:X&ScNV6w]( L@8KzϳS: t8xqf=Oq;ْZ#8lo*mC{ğ/@S1qmQ{iCHwOAluyF~.VYZ.8';EŠ1Ґ "VxRHMJaoDm`>x{{IV,hۡ ۺ0pFLj!6_?uV^q0dkWK DkXg\]ȪU>Eؘa}yٟ|ܐzM^ s-Wx³q&zܒ^cں(΢,gےsQo [dLa/uƙCu{z#\ng8 ^X79~h*'2L,%N/0LA0 &:)+P C~*|#Nk{du&K0l[sjs_J5x\,kHGQά+ĸy2hH Gᨌ{'WيOaPK>z qTC8x-$=Z+`*Y 1TjB&ɓً[F2'(~ZQUBTP/E Jn!"~9Yݙ!!*TBI].fRd ypCɼ:Bd]yA/E/i 10E e3T}q~y%[JyFnkK#Wn5%@Gj~no=373k[ZHAZ1Ѐb 4=9r E Աh *Xأ"skQj>x],$.Q6RĖ"誗Gc"\D!%~Қ!]>R" ISF OBf3)2&\D}۶Pi*^~ 3YpÜ#bJEEhƢm',9Ɗɏ%>S3)-~ \q7OФ|Y Q_vh11 :'S ՂI&%2wK)Qb}0XV?/s&I" 붔\{:\IY (V~:µ1zG>#%"H^ A)$99&SK<]R| qGU/"ÑD{ظtv ^oa4QE>zPMfAFE9D=vFCm_lBbxJ~=UtH+6_=s*B1|Hw#ErE{vۖ9hbY|nYPBIW60I抛em}Si42h&k֑]>ȟKs[c2oBlb hld|H[@,I=j>J8?!e(axy泣Xվǖ.,BЫ-DHO:ыKm2ByGsM Zhˇ#4`f}X!RR%e('87~`:rKE\P-]^JE`#n/wL]x$5>W]F8YhU| f$ў7mqr0#` 5'|"c&~$@(#2 )(;/`#h%CŅ]8R'IҌkڃ*  w1ei78g~‹0719=s12huk Y)Oj=U<, QK:ϝc}Wk(>VX!Guڣ8zs&ǧ ͬ Xn4hQj€t H^D;2o` 6H̜նޱ04AP, 0P㭮 HX@n+j 򋞭_P>h_ ؄2@w-kug)נӜv>KwD8Dt_]Gz>UR  ~.(W~O2>$h$aB> n!B2E*XxSVPGH) =jۅ;,-R) ~{RE !rQ^=uxrB-TS#;҃nv?r]JUZsD2U*d9d0U-Πк٬? xv _%Ijeubl:fۻ?[N/+.̏ΝPw{wiD 7n'O!&l4qHܫ+fC[ PPֹQ+Zh}몾uYy;1\z׮7xT?[ƖyƱ\w 7 v| b;3  $ @jv2<я+dt"sO՜*{%.\f1y"E 7@9!qVk|_>SmX?DŽ_\Ь/0vg1{ BduՑ. $i9l>yQ=*nIʨ ^ :C~vzNLiw2siփBc"ú\/ O7k]BilB\ {f( fV LM3Ȥhڧ/Yt .=%(.}p ( ͤBtTv0%sa^V̞FHX@U^}eBRl E{I##?ؒIrarP p(vCr#OwۙU5Á7f›s ϟlwvhټI*1YIiṉvyfn":H^[aRRq /QQѿ{XYqm6D6}:G$E-:)|MG%{ӳR:Hbɡ->9,YVt}1kq |~TD\/UB-}΢#c'B#9L=GuǷCa|(Π匳>B"򓮃p8CzS\^vRz'yTI7LѪ]VTC,[w⟬ ^gŖifFĴ:s"F|!;>_F-pŽ@ޕu~@ue߆`RGWe;ڗشwH<Rxz۸ @X|"jNOh|'<$eԂT%\WaX_~%efCI#GJ`ءū(u^ݲ8fʦ .#^a*==/^`na}XSCt `yC\CXzK4G4.p=murzL&{jygg+՘֙/uDi\KO,vs1K+@ PX:e|2XO%:4PCe&z'}QA*mi<1wDL^Y揥^fǯ :1RH:6κާ tXViѰb:.@[Hf+`ٶfS{\| ]k>Qy((gDQ4|,D: Ň8ㄧAĕ^Y*MK ʡ+Gw58:UcU/cPҋ|"lY #5\`ҲdӉլ'fy tRE H doMY"3u7D{m.|l{[r3i'/g \܏5C)XhObq@бS C]Rah/Nq^EM}̡UʀYN):v*Uc,G\O6Yv b*\7,,NCǼBϻs(yEDU<\()l{L?N*>n~9>LHچ7_dW[2sЪ$+2-Nj2hfr? Cύ 5u|L=3v(u(!x\X"#@Fs,O6έ vȇ5kV.K1wu^+ζYIaaazK01=xP^ډ#,;"@Po({x)w$^AE$ M&9By~M'4޲+O;04 [ JR2Ȏ+ҿ\C6.W7oܖ~}kM됅ݥ X' |j L-U/f)ڿ/Us-]"|K^0=LycJ8cʠÆKg,16o=ƞ.",S/=u5Ӧh.f*(C7ͥS((u{wt;y/(qY}DZq)1v|l+օfMԜjۨ,X0׊~u{{)^*T\hB_sԀtz Rm=yOCukUy_(giui-֋=[% dhO쬙Xiۈpgϟ9}$hTZh#8\~0l5 ,`y-U52rp!x'@S΂"柾-u>³S;2BZ\MjO(wqKh(ǚNa>>&gM=5l-_3k2AzDB{~M9dnk#܌}o)R\/:rѕ6 ;,5%E~A)@no4حo>͙\PN4h?!idnj'I ,aOG0{t>ݸVȅBpydUGGw/x ŭ Ϯ[lNA 4My*T#Nl2>fXo6&/{xi&Mt(SU-&2aś2Z y(RIxyƋ8%gmd }R,c}B-n(乶}g ĕ8I'U L*D>=h\ ? b@4|;gKuNefd%N/Hz(뫇^ѴvPbu\?Tz. ~@]B6Q@J]6^Kk|mh`5(jv]UnEژ*.$z,dc.U\XcO2YNM^OΆs;'VT޵ց~_\_?|o?I;ߙ ;:Az:'RMKU"E(-Ou9T u $%1* F!Ith4>pDC5AW%nkԉ ԡ9]kz͘pemHSM] NOadKc"&&>Ǣh>tz2+;TEG'MJ4vH3u6Ibl"Y'ܻb~Eސ0TD0B%B T칧 KUp7/ bb1Y1cs$$~ n.,z(Yi#lG 'S' ǝJg_^ĔiΕܡlq,|7vwRs! jV g>>U Ե[3Ҍb_{-7FB&$@*rh/V&{"O̕'hQ OQ bjX`_nAރHZ։Y eH#TV"`q& ({ !7w#Z8(:^ 7káK}~|jsܻfkzۘĘYN=pȠۑ4 s;v0! 0ՊN g8wt(`Y;SL12; SEkP̲t̉c`(N*ڛK@<u'.%)mk<BFI#*yDD!Gnϛ1Xk&6&ԪٵX#; poe,ՂeNq^;z4xL\[!]6'P~++KqC7_~ kPPD*/ܔ?~b`xr9x%J `+>7hQ/}#HբDYXLXIdv50ޯImp-5ѵh"䎏VKZTf\`8XTx gb,X{ag}`mT௅M:I=ReTdJ!b-ȯ7 P#F+޲7!/f GqN͊L,Z&-P_nx떾$CBs NN L XaBZ{A7U΀(1݄X7ɥyUtHe <}Cߞ)=T *s=CF 1{1'EKk.<}گcTBxIC҇ULNWmk] :f B툀h3Lն= $OF {'7p~@pB4݅3\k`(h^SbLoV7_;HvnPA jך6,+/7E?>L*OX8 Avrrl-'Iyr1av _։KF^A`\ N{WRW@Ogk !WaӨp*zf5)$ZRya١%NL!v99|p,Ht9MȌ߸Qw&=$(-MǓONcz B65諏7Q?{Q̪i߷s.:z4SmʲN'6G @*0 jFVI n@uQжuݭg, s f2wM韠]AʑW4o ΟA !iդ2:^Tn~I 9Ci:> aK[jP%W_kh깡"!@|3l} MzOzH.b+j{l޾ 1PsO?eyjgPMÜR7e~a4a:57dBCGC]̤#33Y},&hbv:*#EƝ9yė!P&"Mf_e)ƽSرny^Vv:3ҁ`km&mLZ[~q>:j8o iH=RoMV#$S$5Bbe&stɇԼv"JZ܃/USr!Ew&ݥ۽m檉ad7'eYta!R|~u/q+1B<1S4}xb\AlIr} ܚ4JbXWHJr~.n7^iNd?M~F& 9 p=QF{JW8"{=򦚳F XI}UZ+m_<$|Ÿ^`L&>V֛V6ox}7Oxܙ9}hx*qʹ.?v @S_=9uU[&,lVw(bd?0r%D27ސDgB=!ML&5lI4.,T`<*.Ufy E2jsj.HFnuo:{G|J[4vy5ucy W6@C1NS4l:%kg4 H9coY7561RXv:9B&UݲG9aEG_,+t]ٵGMg њ%R5BQK#VX }^p#R'-0qra"f \ l["y اƪn \ƌWZO%"Y.[J @wZDVNfW7Er,JSE *$dIqE}5Zarɏ6❰wl% Vc?V[O[zf??&Kmovxq,*80zbWEpY d3 PUL*<ףi^oj 76rn~tcȋqsIJL,FjÐ[8"p`4H=,L;ۢ=tڶ,b$.PVFlHIe8RkqjZa/* 8 )N TYSl }MM)gkf7YZReѕ\(9àk#a+ s9IUs<䀘@B=`pCå2sX$2R6rtz6A( \V0A`yB8Nu]!NƏrV_PCfăX7/', (7]S-?EȸI1هW7pnCw!bpBM4{b.~KBs&*ZIaW]J^ Ȇl-&Z8 sQ|d91aq(yG﬷YZk3j-bqLc.ZwK:I꼜Kwtokfv}NI[$3RM1Y'QNPrT^;oEG/qS<|bUd1ڎn %ʂ9=_F{ax֙|R|thE؀h/4xM \+;詵C-a _]S\M{EDf)'eYam)C,t@C˔UCSUIۈjtJFrAx)nAΐd\(v{4.'n~{Wc{ʈ \[WĶl fv`ۮӃ{ ]x=Nx #ԩ}r^Za .u3 yzb0'' dL5 \ت-N@Bk 騩ԵwQ;.oÃ>=\Xz8Sq@-f rꮁ&ҿY)`-)R(kaù?T'jP\+ONB.㏧|;'b,B#W3oW-Ta7<.%Lj!G-MmjFPWpD4]m2Y=X3~a8W^ k@`_U4K|WX6\{ 9 wc:͞ #2d+=DȠjM8%);{>7l26Cohۢ<Q5J/qDi]":#tzWȁVFHh}<04VbU>dzUyU(!piHDz敁L[']>;"8jHbxHQ?,VNE .oymа>ָL4y$o&LjtƮɗwT^4y𣊍jV1a1kRY~(?A 6慒gHepJN=@:4om"`_It(H˿yW}dTZ8J)r8xj` GUЎQxYaDμ\ DX8σJ>L f]VQwCG<=E٥e%l8*;̀~ n:0|]'d> s mU',T64OuIJ鶄*-:CwD}9?U$WSJZ6BO wWY^]֌EU$?(O bPcݚ2MiaŻ^}[q3sл YZt3xrh2& kW=JxB6kʊ 'e8[.^|sR*lFSTCE5r8r,mT{V6E*&rJQyDJZTI5WsjXZI\^ -coXz (Zd DەxOdы:|4DF->qmH2Hܡkk6-&rkjh8? E,:^4ɍ=g@˧rIԴR;H4S=̮d^wbD,6M }Dh<4swĸhUvJ+e~0\!J/ȿs&PP<{+nOSzC>2[b5J|^lU|:EbHP[1x!7(^:֊Fq ?qt,۰(u0Cx dO}#ԘfW!{7 }V= yo}񩵯odDhMvtrCU"\7C, v:cCh (fw 믓Ij! pJ>Sixì1qcW.yamxc{+XM !Y+¬`kTJ.s,>LSbh@Y㷋pKܛ&'&gW i<6 <6i O n Tm$m:ܬ?^X tj mgtQ4NHufP+QrUp };W& 7[,r92o8o$Yp!WDžklLx.8ShaPe!' Ʌ?(M/4Aj(097ri<ﳍ+z5C(xRS "2[]B 8ޮ::)v'FE=TLQה(՜ )slTI M %6[f=~0ǐ˕>quP>4~(>BF6I|T5<]t{-z!EWv4q,ȅFu~Qnk4BO`ę_WW?,j YO͗F]@1|f8S|| ^]VM__-[}WRa`9d[Py ~jc j Ms|@u_h0~e4&E~hQYSq" T'ȃv=<@U 퇖ȌI dRc\iB7i$,.X ԙM6?d#SȘ04TU2L.ñ$Rx? 5oo2j60L` a灝wQ?G*D:N/\q@[f7~S)gμ Vǹ "$6ϽN 73HeU+^~$Mu%&v4DQ3.p}e^p$-[5Z*){aD:Pja\pChzW_l޼Vo+#tt.ŕs?0`%CY‚s<{J+F ƾ#XY/A(z^W(]-]}:ZdC%G8/؋unl+wPm!1"].YtXr< maא@[ƶB$Z0_o?Kyzs}HAeE!6Ր!>;4(k(K$C]ϓKB@nc-ьeǕ ^xk F|~/77 ќJSoPlZ.e{> ,bK'ZkQՈjIX iK#Q.'_ ?2 SК'-^PzįnP/nqg\oM1fVF:X6iv'F2x#5+3 l+:.Eiإ$_ݧ~nۿPҒe_4 _Eu ȲB]bp|W9S)vقQRxW'k/)R=x¾ڼPv5nc-a?7x\\1g6ͳr)Kƒ[[Io=ZV0U]|+$~O*٬fR.6lu!㣆a"X?}6& 4_ zJϑ \. ,QEUM&tL{Hd$y%Qݼr}z/%`8-H NwwLԀ 8]΀alHIi$g[<[m&Y( NCϚ&lpjZ!iu\Lb&c6&x7&CAnzx3C\dhZ*FbU;|SU{;xOlsZ#"LWT/Tid(7y:A~ڢ?/3Lv"FRD8u_*ZY47!LُJK*3OA۹CޙwrJ&tjz.~8QTP^fIsavwZ51^bULSNO~;ލ!#Rl6Ho6AQwEwLkddR7$sQ;'xBòS9ʩa]pgIzVtd緵 ,' }L54$eB ʰ65pp&$Φe.!VB@D Cs"t.M QP6JJr.:Wbg3ocugΜK>4Sq$N$6\k`0\l4~K]a^+hKhB%Z5 4JCTIaSOUuZk?O? Xk#v{~ 4qq!C`UHRTJ,Yf5@pϵ};d0%Qr(H(>6ɂd]@!dlJNbD*œGvr2#үLJ4>'K"r%A ' [g8 b5s,^$_ax^ @89n>&N (NxUb:.fk\}k++>9E{LIdU}f#rgSi ꣨hT01AL|.yɣ%XHGm>&$W B$gѾ vZ'F+7LB]SjF1gTWbH7w29]W{ I >3oΐ6AV!T,3}- YwOtssY ,i@~՞^b&eaýr4@AqBbNn /!%aO\Y\QWb/,)Ch*:Erzp#+oz0w tJ]W酣km{` v{:A4GlAEa`>Bq'6Z(f 혻m\d,uЁ ~;ϗ"}%hٶ:'>>絲h BZdlCЛE/ypרUDi=F cNZ[ZR}DtDGEd ~4;oL"ӋտQ5J?3Sː.'dpGẂ);]W%& pM!J^(7O/5_o*DQkPQn1W1w2<:vkFN $@ Tn|z9Oz^tE8*15I*qzA"V+tjn>)-3[`&2c+JmZ3fʏDM+-ȽèȐ3؂`|g]^ڦ|f;9~T+7.Xؼ/@&9H]b Kx KHt-9W,x}AdIb:9W%ac*_o3j=. <ъ{*c@oӱE*/ts`{ȍP1otYXemv"پaPAt3@myfɽCjM0x2!|-ڔ buh]l[)W0|Cc, Ml$| BIsp ^J.X zy $CVWOOsҔ&Bx^sW`^xdf]5sC|jT# RFyrnC\=@8$X{}0[`&&nXcG'MY$T˥PC0YGRpLA~;&<0S\FnNiVβͬîtWGx~3ipH5h5q>-u9y]2bw^bC zXJEbK9}fbZqnd)ڶ쇮[s:q3Cs~iѬ|h4g!J'9}eQKko N+ZyFh]˜`nViIuŕ5\ CsX7]3qK-^hi9tIǷxN\%v1˷] mv:/xhg c/JT&d>H_A|1@ DFgZt ڜK~`NBH3/坂ϯ7.Y~Yt\.G W-KFh&z~t$oDӌtZ#rNY[ZOctfE0 D􅛖Q&>ߚDdA3i$Wcժ^LdI'+MN*QcF"2j^*땈qp+pCmNl+YAM:{ܙF΍;~aNvQPMN.ްc;$WJPw?_Eh"Vn+~EE~/}|F3ɢ>n‡qq=Z]2IBLJhe#/ttXK kC}y*lh_Lk *S|Ew@ w NwǪ3fwԾxɴ7;9eKS4qK}lqb,ē;'V2Pqg~J"`X/:D`ͫ Ĝ]1;T\Jf'&kwYLwv.H\r ?@/ݩh31nAW,r-ޯYU5v%}}% ,e8LJ#fSy-ҀhtW՜'"Y"$ltHm?Zxn{+@Zԏd<['ꍠ%m07H=YA=]%Zp&`t9r+BoɴK b*U;M5"8'{xȫ^]O2H]X@Wp)c <AWw%L΅*5b8oiQʶXGvY9\<_55\2y:I%_&1I9ENjVFB"˾_1zD°`}>&g̒᷆ m~62h8hTyiSLǾzZ~EgT${0t65Yb=׷vYFyO%ٲՊ yYfAc1̉6o.t+&eZQBP>Y!+s㭙@ӟ8 <Mm8 8N[u݃;Iqf3DZo=Q@;[Sa9g KFI9g]I$"3 vp?t/ ֌adFP+ }f ˇ(exRZ'qg7yMHO`|&4fmTR̮및 au{#J 'HCZ*Uvb~.Q4ڡ6.}TsʐM5rx)Ŵb]x8U/\ȃ k 4d YZ