sssd-ad-1.13.0-40.el7_2.9$>Ѱu65<>;Fl?F\d   8 &:X^h    C Lh8ELE 5E   ( 8 z9z:Y\zG?(H?DI?`X?lY?|\?]?^@b@dAaeAffAilAktAuAvAwDxDyDaFXCsssd-ad1.13.040.el7_2.9The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.Wl1[worker1.bsys.centos.orgCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_640K%3A큤Wl1IWl1IWl1IWl1ZUӏWl1M>M2@MMzMx@Mj - 1.13.0-40.9Jakub Hrozek - 1.13.0-40.8Jakub Hrozek - 1.13.0-40.7Jakub Hrozek - 1.13.0-40.6Jakub Hrozek - 1.13.0-40.5Jakub Hrozek - 1.13.0-40.4Jakub Hrozek - 1.13.0-40.3Jakub Hrozek - 1.13.0-40.2Jakub Hrozek - 1.13.0-40.1Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1339509 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1339258 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1339207 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1337292 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336836 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1324442 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1324442 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1311569 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.0-40.el7_2.91.13.0-40.el7_2.9libsss_ad.solibsss_ad_common.sogpo_childsssd-ad-1.13.0COPYINGsssd-ad.5.gzsssd-ad.5.gz/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ad-1.13.0//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fdc14b49f2dbf6c0cf4a0eedbe169a92ea0edbe4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3e55d81be00be98a82b3f80e2a866865f9005253, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=663e05e80f00a72178e4683a27e25a2cfa751ffe, strippeddirectoryPascal source, ASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)9J9PRR R;R8R%RRRRRRR2R(RRR'R)R4R5R"RR RRRR&RRRR9RR.R:R-R/R,R+RRR!R RR$R7R0R6R3RR RRR R1R RR@PRR;R8RRRRRRR'R:R7R)R RR@R#RR RRRRRR8R*R0R6R7R"R RRR&RR)R RR@?P7zXZ !PH6Q]"k%bP}zK抯ütkR5jcmH) Q]y]4`(@e\;x^7 Ƒ<y;ZZ^6Y3 ={>#z{f;~[&p/>q\eg'&{hv*Eɦ42ir n0F5@XNxs0m;BG@GzKWyod]MQzA.Kƺ/ܼԭl8x3a2WZ3~o쬭;:2CNl$.OVoY y|p0\!_cЉP@Lde/xD$p1Ax.v:qEWq=D4:saibRf{}M*p.~!]sƾGGQבDLu 3#2`L{ yd}2屭osE94'rFQjgto'<y,bykrN]?T? *Y "'=ɢՔ%sH{-mLjX(#!SpZ4jTX Ym EDؽ?@Հ"%ψawQ4Rʼ+)!,@:w [RG mlw#c^DN1D;k+ Iw<_OjK#Ц6s$I&SjWꙉ%(n&O~Cq HoY]|Ewo@iZWОP[QEk*/t}ΏՏ}%Exd|51al6ϸٵ9G+˔0mT\޿T=|"LĠ'WOLJ ’6C}rj.;]UNްo/QcT4(2—̃6.c+l:2oL8-6C>4(<WzJɧ9\AnϺ, /e51FZ:ҒgفBm۔$w6QЪhn]U}MI0֎]9 `yXv^ז>8*C1N[n !k}J(:L =! fIc~ WͳMhdKthQxL~eꐣ[A.CTDA=Wq%USG߃DR]3./y͔W ДxRQ $0^b%Аn>=iqsӭj#ѷHoH(00's`d'-WaY3ZzW XZ#s](mcQЦ#'Jkݺ&+kyR`x~>Qw!&Z*w:sXe)O@1_8*epDPrhZ,Oc ܟo?haTa;77 zQj:qݤrćXV%WU&jπw(OwPQ! pM=UZ1ιJڸ}tYHE-䢣̠-~vB{?Ne2NN:0[v&i04%jK. WAۻ8 !7Uiva $= g"#pSIܹJa\eR-rOeCE_i|%RN]2~g7/wݪ,?aC8+YT1߰U8=0PD((5C}TVr2 %BoRHge)g *'쓘t Rݨʌ H5_چ!|:fԨt Qѵfcޮ3F=ۭjȥ9k LUF9g+ORXJ8xmӕ'\@Sjj4 j?*_YoY~j#\n̙Q8&>d3OZa3WmUpv<`kN?]iЫlS%.k-/`(;/t ZkfVz8-E$)S+iur[*\f;G)4rb4\#oqJLIȲ9|rt>Nñ ׾Qfv}e2 [qZA:T~"]o ߒ آRC]˼#.nVm mG` (K>=*"jU # Vm[;yO*M:; \UNYqGvj0Z< 6ƎpDS~DRog%@@05UW< ~r\CsT5t*[:ڻZ#Fߞ q sPbeL9}Qv,;Ș6G)PwL^`9Ny>B{&/^ػ}a`r fїMņyh4EN~A ͎<?bx-<cۄ`CԎ&_El> D6;?'TI->Ӻ7̢([=H.(rƴ8{#n tJwIh7luu$щbs&'aeX i:'Ÿ$W:Bʍ[cr@qqVCb~wc(%3 hs?qӽ'1)̹!Z5 SqvkqoG NC ,:&}$}yX])rqai|KpJ!Wxj2^T޼Fhtv-90/d_K;)40 ף/dV1a69!-Y5e+4m py![݆Wc]K, ޖ|д^$-?[ YaAo-4GB}a_h潺҅D[n.WDpS!wm1>_NLg B!m-Lyͤk|~nf7C_1K"wRu3)fCX3qo绤_>^wWb_xyN$fax-t|v +}?U6{ R?M}Y~GGݮ;Go☾ 8LV+т \\"ݻ&ǥ4-|'3CYwB>Yy{B{DyaUqVw_pc?3A'N@#үǞ>V5_x.ZjA/NI+[K;{-؞$HIlϩf,$mEUbDVlK]܈XfC<|Sm*X^}~f r5/s8_QCvZc*ҵSM~6`ɵCGKzEPQ U͞j)m gKGRE y! sJ;xzka ԥwRs;h̯xsa>xbSbP$Y)|dC̟fiŽ<ʩ!?Ylװs :08m>A7@D(YєKUg20De ]|V(p!Ii+FxҊBi}]!5 M0MK ? dx0g`-yXn ൚;k;/V"h`G^Len֋֊$h ZJtР.[.?fcc_ELym[OvU86"p}5g 'RRV`V }{P7*BQ/wMD\KjZ,F[B0](&Oǭ'9\v p;*:[_鰻"2n!֫êV MzZDts`~eVfU{O(؛꩎{`2R.:v =U}yƍ0+1Uo"`Eg6ᮁsn{4gr7ugHm{D[DB`5<<`j!T'@ p-1G ~Po}H+m3ji9W$?;y1Loa6q8Tߚ˗y8i)#]y`i~=Xx!ĿyNXN':e6B&! 78pKw~Ҕ3GMÄ3ačVyIY?,E;fI7-A- H!=Bxbgfrv,aTl/"$%7SgMuV]T߾sL 0HhqtB^6JYe㡾>QOV4l3-CMx%o&E( I;^zB~ ,yh pz3F(L+ %u`d@W)6;n"^-#f[TViZrHP(^e.L?XD%>iYZU>T@-)=Z =&Mo|bXNTZχy#8eQd.~4<;4}Rv=(_TbX5o;^=&n%: F; n,^&Hem띂R~mC]SBԜl$X{XMtZn/9 jq^ !:V'؟f-$E;V~AxZG#{e4 Tr^8?tĒ>'0), z˾G۠e1d%i s#D|c8f6hP y^N/zG=zrKHQTaNGu_Zwufьh_V@>r+_&<4E6m6<{9U&;#nW7tl̷+RVQ7#߫tԤ}",'C&٥ByϷm=0̞ lHܝS\!ı9aѕpGQyrKΛ3v: F~H\as  }_9OjpȀRy^'m]W UGPFxTRlN` zm!ՓA0 fRdo(h}3 3N<=#Mg<4e;8df" S,UUsfoJjg+3P˱Mob$5--Di{Fwq "̂ydGu+뮷ˈ%F&$ݝ[&qOfOpw{qB~0@L{?amVPp O'JRFQ;A)AFI7=)fa6 G_%ytiLi9O̞ UXC+"R+f-)({HDd߿?Gݛ"١r|Jѕvq>d VxVr҂\~(XnF;9|I]h'u xH撵FY`_hvy!_u37(bǣl ~6LKg! KEe)|u_`\zVEIr.`rya"uU%RiZ~_ Q9֪Zd1q>R3坏gځ h< W7Yǖ *W_`JQj:ճhc_%nwbzY\p\.Fd['.Au^@Vu=3~,={O̼˲# , wfG檙]}e5거 ,c ,(x$ǶywfR$-y\zRҁ}帉)c5{—AoIu"XMl~6!֟s \MV A XS#i(iAW#iNݜ+S`5Uɼf'rֶ4a+Tŕv NQF4 .mI$3sh YQj&0 A,v:66ўN'tߚۃ=_n^h}6i౗UkSĮφ0R󩝚MeUrJ7KP!1CNKm`g1ADpp>H4KkXȦBQ)KVO&J  9os6B74yzg?4烒k0<i5Vo}0 -G< &99~s&MD4uуHMI&+AL%ux̻n09}car] -QDPU%P4i~Uug4>#PS~pP\W].~P@-. QGnkBO ʧ:Ž3{pW8$$n^!U#NS7v'aѷ^'0)-萜Љq(iZ i# ,)"U/GpԀpPrɶM+1* (Ck;_٥j)A< ͗f&xy*5oMN)8<4\I$YN*9=v-,g-$TޚȢ$b0+4@ (&ϝM"6=zFQ&6:0 t0 LagiWjr5֘aC|Q3Őg |_;G8>&# Lde0H!F(EbvSU,Ɵ'7tud$ΣSN-K 8 ]8#Jg< W+G-&`]WaF +gVEVoHW''@s.1v0 f=MF줧2)<{L/Rf$A#?V<MƼ+f !M[R|i|k{EW<ŋ^WDhH&4Ro3L4஁99O ԙ>q06TJpYDQܵqv m+t-tW~ˠIǒlJ>@t`bznD)$tv|s.$ ;#[C>JÃWR@jqri#|xTx;;? /sZh#yȊKh/igo>EWRTSrQi9ac6d^L~ouxYuÐq.+_xAuQ'^52+h1I?^7B7 ~> w4Sʑ,M .疱'p7EgV ،bЛ0,^³O٨͜EPv:P$a8I]`ӜO(0C+ճcd+Cك( |r>Oc\2꠵h !-WvE>Ji&5-RV; [^QGF P8S}Y3cV7ܗ`:ĭj+zvd?<ӌ vrLTcQ o05س>_:+w\b L?N3BݘEsC='$SPOښ#/6Vj-eNsb̓@M89 3Wk6KAכW 6Vd'4[|:]g&nN˭D>EIΨOI`j&!`~@wT3r4bOP/?~MjpdԤ hAEϷG:pX=sۏ9نtZN&/ "% Cd˻@E̯%c,Ѝvόq|3!Z) N<6g:jhܜ-f!77tM9@*YZqq-jL#]Sy]q졠EWX3Ʈ#խGpc OY~z^;N4H]ŷh2[@ *g}}pcBZI6aTP`*6B9N/quj26(%Wx}@_#qUۥ!Mrq(? /.SyY9WI:b+  ƃzĨ1`ڞ>C~Rsr ]WX V+\4Kp LHV+Wā"pl+7ē$Jj>A8>C i5MJկ\:cRƹ&-FuyLvP(pJBI<э\knI|ռ1 . wn)S+#492d[f69^#e )AE 7S0GAѿdV@`x*qb d nR/S5M ߡ:vb}^Nng~-]D D -/# rtCߡv Hgj}w/'ZdGhFl~!G\&2zR/JX.9ʕ]E‰ IgUVHsE4ں*obV cA,ٷ9s2hӌN+A*Öii!L>Cf,|?"">pn_h'nS5/X+`V#hqhy!!@:] jd_Xao8Pճ 3sxy'; \y@w^-=OEPU?[_J[D -1^{ƏӻE-S0i }x ܴȯ1ʻĻ.H {U 'H}]Q3:ehĮ?qnldl^ :G:pwOtH0|&b4}+>;7J?)wQ )BKC!|s@Gp {A]<{0keᡡ9/E}&ױJE3F1Az2g_@~:%Jh)p&N_+=N;_1;LzH Ӿ!eC{/0.&ɳ7!k8(#={=x@eo|k9]V4Ůk/p0q ;] b=LA59LYK7Q];MT ᙉ}ȸ KCX+& e^V(E~_ q>id9֭Nk E(GNccF%$x F.UB~1Qg X؉#$wۡ[%{2FJY7kE{5w^ɨEZljbJ )cּ%e%^vzYe/9/99,>2[bȧ<5"etQ\QR[ KXohvó-\QXME*7qz%l8qwd,N3g@pEkNׂ50Q(Q]87$2nLޛEb!8ngN,K;ξs"0jA4ٰUx帾eϘ!O.uض-:BpUjpKQ| mIr8쀨q%3*DŽɮhl|rFhʸ `Ղiv20e?ߵf B8vL8@zW8{fzI9"}QfCtݳzr},"Mf G|6+ L>}p(׬9uzn֍n.V>1%).j:Jvg7E3!Dק0n=ҟnYl.ZR _W?{!mdmSYWD9|xksZnJjRsLOI2.yA[5;؃LAcsWwt \@Ef,3XX ln!Yh)S#Ts"[o5 :0Nƈs`2 _ϝ~O 2}U48sZ49F$(Bg{;qHjiyЅ 3Ƽh|@K}Qi /?Dg@xO ӦA5#dZ1>V +ƻ_dzu ndvFJ6*N+z"uWs=(l, \_}OV)dU'cFRv<eh7L|J$bSE1d>s<Rk@ m h&dIYYfg] FU6ޔ Pa"kU\ltR-,fJ (]~ C0f8%6XZԔls] (rDlMրQ5&08u! \K(ȍOt׊f|'2U ARu&faهǸD@YbytqDOEyCC$r7h1ő4kNdd}ރLnl3RZ"_(#Kz=k\;dtniq9TP@bRlH${azӊ`@7GDi*ItZ`Эk|9ig@_dZ(|nu2C\%uMw6L=!{Y&Ž|rz3"S fOeu͊?7^MTUhE 0޵ AYMeuo] YҀ*tO}Uf1((mnON\!OAƲ!ݨ)iG1-RkP[f&h݉uɛYfDg9ΨSє>[d! t?̎레8975e_~L?.Dhy~ *j+r ! 2#A2A? >uXz"!vv~?YZ3jXx%֠]F{i׾[ƈ:{3YZ%ȫDB Ԛ9UnAȥiG8u 2DD p`ǻm=ZLY23fנq x1:bt$bfi*rsY XPYZ$Tf_}iڬRG:HcRPce'&ҲLBv\eNU_W8nUL{5*&`h80yQDhO(ACAG:l(wgx02Gj6tܿT*,NTqUl}#uGIBۢ o DVɅ3Hge;T߉IĊ6TZAGn \2jRd6ubgPV^v5ƴOr|!>y;`'R/_6(l!_ BswYtۀ̳bl>!2AAGr̆\SuMhʹ+0IhP.Չo#$" )]LR@ nHgI`uu3V`Aۋ{̼aNd :_ɢb((VM5)+ceKk3GtW3~.\ r1K/[YˬT_Cr9p]`4o[f"PWa G~Ωk# { KYN"7]abY&mvt\fGmE0r&cٯncTqe~/3%Ǡen]>9`n[[#6rǂj3iz_ȵ~o_¼ֳ ꇯ^[zZd|Jj +0OE*&ti'֞k6,kcʰ9:~zUG D8E#k:Ⱆt(srR쀳s|zM-p$W4i6jNb[E~(pTp@8?CSo&8j= !ut7<,ďƳp11ۿ&9#0uQE:Ҁ?za !`i wL:Lѿ#L`I·H@θO.]vcZu@&SLJLKNH),)JyW|4 K̬@ HXH>;c5+nF2f-Xߕ$t'KIkP5~sfZeR~6i>VttD^+ڻ@ NTm}<^hqDf)ZY˻I%+Jg͍̲oHSɆxB^7)4I GJ>`hq88$F^<'Q*՟\T1KЉ#d;TEG 9ge;#,n;ё/_>|XOVʷnǬe81@3װedt s+% }FNdp;oQ'n'R=d6Lb@9W&v'J6\Wo!mm"<ӶNALG$L4@,5oˁ/@s`i!\!3>{ ÉMUq<>aU]ptֲH|1s/_F }<2"ZCKh[0a>RHC"\>1 %w P9c9%QD_2KcbXꫨaDEF37#E|RPn4}c(o,z:ǣfJ./0-,a<5OMl4+j?k{zagN/_$&f8a&og$2EdX4Z9hK[q_(~b1gD;Dӵ^~3ք1@ 2$EB?KP wA4f6u ZIYa"%CWA9X]{&"8oŽb%w;x۴7wTm5`[? \*1/cBL]|tPTJ* VA?Iړu~fp bPӤ℮BIk3Et2N"$Q`7nRoj[]8ILiuNTo#/1+r_\IST1=0"q2jfk*Ƭ^<7(yoHaE7ENSr au͙B]q}_lrFtۀ5 AH ..P*Oɼ@ h()40"*oeiMwB*3!s߷sLiK.N8s1ѓTH2F[ 嗊K|,2!ô1ԫn4`]Mm>mww"o㇑ ^#4S$ !jt%IC GvAxR=PJ%.){{6p>4yoj "!|NJ9VOrg-ōgΥ* uU7ZE]`$;Y;2kg/%m! Abvod =G3wǩG""#TK9/eeIkKqyaVPA9WL?XTC Xp5J-<깶\ʦASuۺvhd';VMX؉Yge଻›r砗[9ګ``mN ~RPTGRjRg]rrR XG {joT8(r汸E ?%f#I]R A a̼@ Mϱަ&Ň}X[pXF3>g/. AL N%^TyBH},$`vhI1 d !_߉}{VFYn,q )"J*JB@yޞ-.;12tڢȄoT_l,/<M@w*Lo+{ Oc~N%H3x[Rdkh*˜nЫN]{R$HR@][␔{a`*"GHI`PTD|sK]6Չ՜OP:k{:AxId+4wIgT=>ys'Ʀsd==¼dyi9 Ti!+owd>)zw/V7|`ߨϲ,kѼbJBLdNP2Đ^W"%qqEMR)ASI_ef.d-EQe$bᧇr6Euudj]jرP;_gebI n ,ߘЎ(sK>Y38S*j%n; m)DhP_24 K\5K'Tm|'%α v"qXB`ijyEyzMyS;lzM^8<.v/DKT 6n,8;Wыtp=Gm=SQ^L9GaW|V4 %#8dOzM4". "1kp( q~:2V~&6<\i/LMZ26§H,`W5UZ\.@!ނ[ `vIfǗo~$ wWL3j1"lp9&ZC&3Dt:cĒÆU]"%>ĽKjLqtvx#ì0Hb IŜYcdl:&D. +80NPZ#Z*e)\_UN/=툫пeC> $)&SZO>rx (0uTA&93>[Bwz+0TM>ŸO l NRE{~SW9U8^&AeY Z<6%wW>f6#=Dβ|] Z4GNSb,5O&@*ɹƮW`~5`d wq3qtAuiIY?:6!WyHƤ$ݣ=ZBHAǙiSGM9ہ\ݷEfxqJWxb>͖m2j+%GV}(/R-#D) 8a9U#]g1zl)2dSG9M_\M.RIecʅxN.t1 _%S2.,Ts6 G:<_a=@IT…#qoJU4Xu~IGG4Rn6X@ZE+31xʯ0 )J e II;MVJ Ga PR[_o  3y+6*KΎ%&<LTUѳ&Ղd\f5=EB1`nͣ:gC4ef>-b*t\I'G516զ mTj4\KFh0ۿlHݛ쌐԰O( : ϗ(zWbR)۷I2y֙N6b 3Vodgёqюq4 xH߱DD`R7ۃ-O{&eE3RFXyȎzðV@}Ǵ# m i ՐXC϶aAT_7MB}HIu1I.:2`eI;R?)j.Lj w0T撪BGकXه%o/p;W,MСy] h`^z}]%\(ҍsOs鶡R384-D*b0 w+’`mѰ)e@;]:3IGŠ6zXѣpb p{+)#9n!jdJ }d"3 R%Kr,.Np?񭢅F{ꊬFhLvQQSU0oHa jv\ע/o"9ldFh|z2l٢}ŢܯIkS/jR%Ӂ)& @oڑzh۟C_N0vt%NzDsRiR%{4aΡV6\B iwkb]?qOEem !ka7vt~4 s[E;[b v_"PGڿBOrNx-Oy]j`d*,rM&d'Tݸ0@* cC5=6g_.۴$^h3Ub/3/ιn˻4'W]>L'dG]cDK2, %y)*,m QZk-Κ"^ڴNcA@BFiW mlqJ'\2q){ $ZF3ʦ YV.qRyqU)tDžMzKxMM2KrbYGƵݑ(ĎøQ(mv0 aKu5D w&, jp:pr5"2vJ֊D_OudA{Hr2(D⼜)'눤r߁m},bL @ko=q;D$;^`~y4̮ ^Iy!YV59(VKވ%؄߆RJԱ:=ȍvcł7r]}jK]fWZgr+|U9(V2 F("mOjk$8^Ŧe\Xp` 4/hv/N*xud7n8XJ}T]*=vn%@7«\ u? FTGzd:~Fs5A[mpIRػu .^vLN^/7̺a"#mBet^ ܣR襭IԮN[Cθ{|֑ h<?ՌǢЃ y۠(~~E0)қEt BaOQܐlIsڇn]sr\ B*#cF嘴^rRo`FU5WKp:D>WddsnEVu9-FQ+89L{ʻ/Y⟛ׂ>#;GM Et&"`Q.8Nbm!p_ ?G bȖ} X|}s-nk|+F91$։iC3J1p\ojBu+M)ۆB/exFpg pJ3;=A qI`ۆŗ4(Q f`9zg0pj&(lG;+G+}Fiԏcd1۞ CX.\(b3šZY_S30z;@&PaP7?C~+h |^o$xK`F+ժe w3(7@7ս#|V糩 1OsĻ**`b]GeYek,W"bΆr#cR;aHȰ;#/a zqp)v+gF[w䄑3׷(OԺCAkphk< krHiUV–dЁgWjY;p zՋ?m8r^@(vQ @F=`jOԜL.+af:eU EI6Opv{l-/^"؅jxtN [E$5t^C x`כ]Fw` q׳*b@ѽx4ߕLEo1ke&! LN$iEs0~QEBsxHS15\_Bgi- /||B@%%<64 HǻH0w\XBs e*e:5TB?^0(%X ߘH6{p!6jfJӎ2_\?-n>Bᖏf #LWCR)B:(V*At;fnfPP{BSxZZ>p}6:szl>,v3ou½MJ&DyW\$R/&e_8,'BRMKOMt!!4G#やz~4 {嗩q AgAŔs,I @:i:8tM;a#lv^%8$a$FT9 c\sAlX^Ԍ 6wIǃbO3)l6oS~4s0rz\;]ˑ`+J~}J9qk+dcN!V[ߗF$񼋟,RXY3q{15YJI _6i#Ի$\er}NJNͮwrرN~m]ٖP_EOОa@放+Jpl8 <1f,Q%5W%R0m .6oS:jK򊂓7n,)F  1+Y>QP1w`{͞SHa*+*_^槒e_꒞Ulg^,gԜ8`R\P@:d8xs:ptP(hq o1&GEjx7 +,25 {zcT; +,&z~եSt.zVwը0;}~K!%1^-v@ G1!1Wcck dVEVt 8.Y:¬|õN 륭 rboWϦ;neB XcNj% D04tSuBP_~wRRQ")+hw"{[0$U-g] *F嗵XԭTJc8mD$ Ux7ϬN6Qq]c'0ݥ-A|VمS7~LF7dVlh}Vi콐- #f/,ƛv0WN(6|cf<`Q_: fu2P1h긞.3~zݻ7"֎.UQ!X܅IL"UP7VЏejK2[ɸZca\-ZzgZ*_χ[UXmUضW1Nj|[(uI`Db.mMwSӭJ-&oVS4"郿=P~|/ƶȂ%"r|U~ $.W)54P)j8^nG' $XJZ;D0/ Nvr݂Q ۝{AۡN[EyZnҕsC8xe5L 11ܿӑ0FZfDFH^U3 sb}:&40uBׯW#HOiVЉ*C{.X7 @ϓ(@kf9sv)sT`KT^C:墰 >5>n|JSNnݭqt6ZD4?JT#7ս"%/>;+s"6= T&gw8|+' e:꟧J9HU[^kI$*I$M>Km_VwO,_.z_NYnjJJBr6XFZU[I#6fEdSIzYl@?>L8D&1/+|P2 <*r(v83@MӈUԞ]#p6Rl[m_Dbk4 c2r-ݫSX-&ĉ>ߔ@}/=p6־:!^pR ~fg zIQd1?UgPE)%⍌l7Yj5mRqW$bu]*yD:]SN1!DXpY$|Tv<Pes w?6 0o &:>l_ʲD|ldǺpGj 29d⦻$7NV$c%SrJ@B3Q:E|<\uޫzNOwHmV_YkhNIz(śrx4aiqvh闌>'|=B]Զ x]މݳ|-PmHoVtntXpcFL!&U/ʟ?E6c_-iGFqwN >b$%YOFK0ԚÌ%_Y .^Ykd `o]HA|:z!B*;P˪-)cS3{!I{i< Ee[;$7tdOMF^re/ q|i0ư@<`}%\]B߰Y= ޠq:n? QpN;藰$CJ Eۖ F 2TΉ921Ætdwtc3I%#P=`FwG,K#$i/z-cحU(36FzFKv8'"XiPqDLwbuD ,`A/g]j$?X4nL}HLo6ԘP| 'H+ެ8ihk@_똴 m ,GI<.fSG)(Y^%//W"vC]$^;sa@XIK6}}f/Jp[8nM%VMX >|?!Vbw+khزA>`U8-0 bP)x~87'/uE? SYVPrp3[Pב4ԩm.eBIZZD6>~5Q}:U=XywV8?}A!M1$M|``^%@nY /ȥH$C}M ȕ"z6ؖFW? _P-M5QTxBU5|EygL"^Q713eW`n ѐZcD 1P"mLjoKZHj ^:GYD9V98]Q"M &6h[D.AwA Y!lt*)| w􊤃a-Ye; >“܌/`y9E"CK!7ۿ]уŔ =RŐ-L4^`vkESifkK]8Z5 E[_*F 󱃿Y4o8ONЙ|jWL1T, py!\cj͵B5)]~9b"Q2T LIy ' NP2gjl~͕&85[_Y:1) l(8 G,-u-"W55-Aͬ[dKsuIbg:%YF5u} w >O?W%d2W2~lw0sܣN/|qYW&Ak5=f8iȏ!l水L[5dݾ^NSYKd BL,tmpM0S+oW%~խm4\ݝsu,៑mt@T #[~F/?yyÿfMPw<YɆ9V:E0C0W=,@D1ӂM.RB5/!QW_NJ aKأ]wED}N-?Lb=xz"Qwdul{9E~! 5adԺMH+`'6|vۀh(~UYg.D8,^{qQ';n]u+9*?ߥtF޼ȸSg_f)8ӻ.ל͐Hpp0irx4_Jb^޺kǑ׏;J@: jV$Gm:( q m !-.;(H)S_>'p1u C!H:p _-2![TUI~x `W/}J`A?Lbd+4".߹}`ѩ87t8!em(%uYؘccn Ƶk'òYD'̱||x܋+? 33޴:tEXZpz~hSޓjKy'@{9Ruz/`^eY&c-Pz+D%Bc&z_53D5q$Ox(sh&%_ 9k$sw  $FF4eܖIFzŻW< ZDbc`!˖LdȌ?T  ^׺i+:l]nswg6~؅ylX [ ~͈jG@UmnvK*M߮l34s¦lS73) $nz'nV{-Zx(j-`]¦غZ+(s߁=f2[F^q,ow{Oq 92CP>m]ip^n!X"?ycY(/(V2Q5q>:b O m8_$ A +Q齳UzXS/ gslFGI*ђDs ܧ꺱@BX@ANBi#CCujvKLv$SlļN%$ٖP+Iߕ DK&7趾fUө[V]CV)6mp//CWE,(=*)bOzٝU3GF[Q rsUq#f̖!Z4 Ѹw+=y;EZe+"z fAZO,CwkfQzQ\}hݠ:5 ȸWBLc9D7N{ʆnǁ|7Nf+;(Ę8kgFXD)t }|_pҌ4` *K 2eWO$[W h+'q`OBCˎ#:N60TÍ0%㳣.epF!S#ɝ:T7d# w~^d0f+ 'dg .?!AbȊfjLK0{T|a/uut6@Z2dnJHrIrE{;"ӌ/MgBZHfJ}_ |5ir> Fz_^ʼnUkHP¡}c:w[y26pbWpU,yT[=FKJOd :E n{Z4wBHp`T*2Jud֞ѝ>7rwt~6uƳƮɲ^p*x145}K6cEiUnRz8q-f_?*E?+'@I ߽eb;H;J`$,8ѩ!9StwiN[qPλCIl mzM/&r<"=;3򜑫s>a?({g6vy<*bkA+ig^SO=0|+i <1ʈPC`F6%p}cj__u bEwrczRA!Pk6A@QkPt2% w ^ECHZ#Y nW.a!\5ħhUTT78 ~/\gԾ0@{3B.*4 ^X7JU)lF$͸~M6YןS;dC J۬w#vr1vaFCZSK`* !)C)|-FlJx1#}@'(o26a˗QafZd+Rw!?@//cdLbA-.piwcalca pejc,oWgľ1 n>y,jD7OmO'< (VrUthJ%1{o鐇IT~P0o}2n1ٷeʣz S2oG@j_UҗHc En1AoarWO**YBĎVh?g`G?^QDG⨚fSVZE`Ϣ*g^8+!_^Ƞ+dޙ4&n^܌CWϜ[s R#m+tX_gB#j7ҋ؛eB@qT2u=|W+@V1,DCNk'Gp T:{ïӶ.qtZs/aBCڕܬT#s4x v0lmcɱ5ljKrc< _6OfzdҎ y2пȦ1൰L/v k=K' i ^/򦓨Gt~EkZ"mJO3(Em!@6(ypi;0d|Gm&8,/> ;rңZdoIzLL6Di"G[F=g-Hd,1eTA)r#ih76lP{[wdMqdX Wg6g#DP[ Q U8ćay+7Y%8"-,|$drwjq1T4ymW'Z;3sZh:=91Zg0̵WפSf?~Iҏ; !CyD'rS*1:+N, a.zxĦ52PPJ9V.9B,#$-~e=Y L&I-SqT*Tv`]I }C0Ց,g"^/Y0 z]kĈx$EAً2Fj8ܛBl}W ڊ@бBI'^>=K()sr¾r Q ?:1kC` 3LS1Y ][d%5kfBScߧNyAZf y>(@K@jմ W)8 g_ r2I^UFώpD lһ'x&*r)[pcg:rD0zQճ8f8v E8QjƵS0=Ɲ*elbUt-٦;>P}EcLd-}MuVrKl_-EdYV^V,ۯTun[0F@8`k*kMhSwWXHxjdnw6l\7&%GCƐYÎlHFkJO (ݏ\Vg▀uь?It'7Qw@R(rŒR8{|W.NJzldmǛYbq]]I2 VqT`m6QgNIi^MqΦo6eC߻PcAgɮ4 d7A? ~s_-U]?rv]W46Ⱦ/f5IF޶3Pr%Mc6Gg-nb=dMy]2dARx/}eZq9Od22Yȑ~F_j4]^Is-1䌳0HGIJ챦b}+d:@*gkcUdUhfJEˠEݏguxTX4Ӿ7S:n]vfӇP[d6@WSJ&bZO?Do"*YSo"Vn+L] cpр .xO27~=je+nVBdD 'gSw{[WT>{€s~چA;iw1ZU rig%'E Lv$r8dLP5"ʪO?oP'=D!еL%i^g3-GNVB9ziBzU *mOǏ,Ca ]H;-|_;&.#q1b[L, ZH}V'ƯyfFA2\K]]ϾMzĺ:d:aT,ƃ3b/RB]ċ+!hA?On,!>( -T̈ܝIT-Q -v$ُT&²&@ Od!ynh|?eGpۏ>ЭR`W I}XA-Ԅy&u ]Z ~"[Z!tX$ByЄ tRohw!#W^6KrÑgɾABVFCX Ύdi0*K:RTt烠6V5RW[7}? NJ_cS_5q#̄܉xqO%@KEZ JۋuL9 gٻc˩]D,/R}8vRJX0{|Pƥ}bg"Km<t&.XWcqc9emZ ҴTF 8cs&ˎxNǵ4WW-(`_L: Lys2ko =s;tRH\'uyN3e4<%tl;8(= QL7ǜIkVɩ~Npw$,Uk`p2!+i\5 m4V;պ[/ +OhPB"HG)1-'E̳G9WF8v#8UJ.c;/LjiIBMMG1(Um!z/,{[,sdh 469b|%Qj@'.,"s K;0\X[qJLi Kn#M R(t@bʭ!&7;"hq!un j|4OSAK,?sG&NJ>Ng}u:`.!7 X*9t)0Xα>*󆊴>n ٚܳ} Lփgн[ZӔZ䁵55#|x: ]CȘk*>JIJ˙عbpX1945=A6& 6U2К¥R?DvDZ妄WN%ZqY&3uBk?{fufCu? 'C}FfSXXYSmRer1>fJ>)C怜5_..EMB(wS͒Sn2e'NlLQIiƎW[RΚ .^(iL?T?шB>\pf |Hbntם~(êפpODS̀6>}^:cڱ>*4.xZ[__0 je?=>(^Zwe>mKrz0jw9|L=lo<7o~:]aˏ{BboALԕByPF]I|sJV WuTKTу}6D/(\xTV);aDqtƀf#sN_UVڐNyW4u/ KR*KLUb:VԪFDȗhK/ϥ/8߁!AQ{F0rKv\=eD\ V+X|O `wnFd8T8 (h:g~afӿE䆤x~T,NW& ;sx5c׮\ GPu%%1 ^a 4Q.;D?MP0=wIUI!YZӈN,R5D 3DX"YxB9/#'ݥA pT'9~ն;A2wwWԆpv&ԹYȅXPlt2[i־6 ;(2/atB|l}%Z% 6fgԚmߑt^9\ $8" ;)q,TS4ddXm ao cݏ0RXm`*OdpF#U׼C0vSECW|D%9W@"o.H=ʚڬw qަ-܁7-KA-I;_\h:VٯβOrX̶bD^QwiP)m9 8"`={uO}@qu鼎p/y7)4@@UL rP^g: Pϐe" fP{%[Xp%L=z$*ʽrj$> \a"-/t~7ULH䕨ƅeR* MJW;w{4 J d\~[]G;L˛F*^|"[Y%Bq)M'XU~,Y)MgW:X A E 2%֫"TCG%iFVņ1?Ґf7ǚ3Jol<5:/=A+EPT= c7Qʿ=X2DI9:9r\ ]h:B<AErJ| n{n|oٝ(];lbIHoK̢%Uv҈$i8͐j 8qO{-KRLfk9]ƈ&ƃn-{~S ?6ٺbul,_\TB?_GR;ݵFf"PzwirۊVgƳQy0#YQii|.f@Eq]Hf ($|.֋s5op;˾j[L,3G>P˖m1|$O8Aǔ5PQ-+fcUcEtM؏w?Fo}#"3?9nYUهHpD1l9%zvr 8Z'5584TϞZhVcE二4u9X= NlD9 O *h)t1͋@ay"YҺu8@XKιt Y2<00M.O@gN<}& WHW5_hy8j7e- b{RXRHF pR # e@ޖAIDFU(31A:vZ*Jy1feLK*9cu]=ګƖꑒKq^VrV?mjXTppᥦ]Tf1(~`fj&ḁͬ'ߏhlh 4$:čYJ ļzOŒ.VrYa)+YERBJ/ʶOXdJJ ;,2k4Ѓ a"Ձ > 3oM\[ /Ja/Rp HxVƜ(LԐʽ@P1Nk=gtNpț{ 3\z(Q/<==EL;AL˝L8/ҹNexv> }HYd;Zb!f3=TEV%@*7D\z3w\d-y Tk;WbPj h'va}4-R_"sBC p5{]IIZw # nՓ"[t_{QBҌMX$u-ϝYh#.44",¤ bmgw A=Kx.G2e˪(Ejl%Ky o~użl#[w\®v(Q*dTⶵn/yY1V#A؄ɏa{lGl/0 4';!?bR 1& aBQq=Tk/A 'h:QdiPe&ڄa{~y+8}_߉JM|@6}MxViOR Jwi{.NE9J81O^:|)~''yDlb62A)Y43grk]GPKDLBY::aa1 ckZLDjpͤ|M7DL<ϒjZCmSU}N"C{CaD֌EyvtkXB1 :ab1Q Hv$q'XHlp!S"BgQ #NJ2Ax;u|˩gz6iqUF Z!_r>S3V.Fkh{'\Vv*)<~~mJrÊZ9˔-0@4m*,ܶM94c릁Up(bs*$0>&7IfAڭ\h/L`yoִ^f:7 N.ӋcnVgYWM ̋]WY1&4W^=vcrO\L8!cӿ϶ }dLQWmd~M"^5Up J39LtH=a5 EU 4xuSVtt%w'prQf8gjP?Lx].n;I+ yw~=3cbҩ1|^K2pz4YC =A [°}+~~54鼤.\㮛M0?K_Gl?qZn `EnYzV4@{WC"ܖF* 4D5C73@To]-fe ꦾͪ`Z"KITpJ|Cz%WﵤWm>ae1!qI!b}j}J`&t8}d[(N<2V 2fe3Hbra>X4uFD a汿ڈa(m L0Y<~y7GfAa߬0wc%c1m;zJ/,/ ]h^(q؆X3G#%f;bkD~PBҲrmJ̾0"-meȃY+Q;IY˲9SݫIGx"VϵNjV纸Cprރ[ iX$Ri"ZO0zW`"! [/f:DZ8% "a pSS?{Lrv |s&LJE|qoulSHnK׋Y DUZv58{ Rd4RA~swR_wELRwHe8:DC&'$%z~2gpƴuwCpԧ&sq8Ax ntlf=6g0gĆﲹܓ y6cA";Qp|SQ0]my9k_P4hI )k-"KdrN) џX!T!Vκ>ڤzfK>>S@j_*gJdWBJvb'wKA.0M+ln`a,sKiF XHChС; .:ӤUPqhbyMc7ZF Hևz9/{h _i VNI)] k`i{wb. 2h)sQpHSc$~%DGe_Z< ,!ؑP-'{EV?,Y#)6Bx5`R]dӿNq])JǙ>i qq07mlZ.G @=ф}e~kRܽZy7U€Fva}ة^Ӵ&PӸI t203bbȊ-)ą2rI v 99U0.Π`T>z^}U Y?A2xqnP3i_C#)5 ɚ+0Ԙ j]gV†K0#;!Dr 0]nd l,%.VeGj],jۤknGYRpEuC(du2bH_n 5~罁X'EF-dD 턭lO YD /tݔzylE>qkN)a uWu:)&{U< |k=XWP  yfQe !;|9o7=gr\+P=')ӏ<&>BՃ'Tl{hvB C̛1d@^KƯDp$.RLCcT[xZ0-8Yc5a:sIoX4,tK0Dq>e 5φ748z㻂^)Րߧ NWwb?*Bѧqe&k.'}9Qzny(A%dlj|gw_q|K5)=uwsb1WL)VG* 7u:kd`cv'!de:Qrܧvk(,m-8a`R~Ck߷r*avP11o]&lx`$l7:ΉikF$3|q 85`:˘5KTCl5O hX{W r{*zgn9u[q*e\TG/-ɜG[}IJ}^= ͰkN%|Woˁt$N-(@݂;cRE6*-i}M,3޷c]P9h&1C׌eX_`v\T{ye&֌+LxкsUۂ)]BJ;ӷ2=hP]>Ar!cv@Z7)nsEV'|]KH WOKfe})w/?0N͋}V)?&TǦi2l6UY!PG̊4=3)Kw$濱d_aZmh|~UYF  @&[T;%)>jaTKe~mzx7nY:0`q >v[5W wKvQLFH!l 2X2F *b*9=H p5M~-#fpu5,.qxW-}cy+=hD| iB%,it2P\UCbxpQ/8r4;RБrwsX6FrZyqR~.mb6d%F!azQ=Zsw |KklρS^|#cz'ja3~=cy3e.O=:2ajF1 偩d1;=o^ RX"ѩ}nIV xe"׎fϤ0Vh(kQ{kocz}O]AII9 SA`$ ;qVhS \_(륎bnO?-dss4M):o/`Ѡ(L- boMrr(GDnV V:GRܧ#~) BkߝQuR伟PLc'c5{H޿ gK5mW| ќÿ%oDf/''sqe{z|Ƌd'<ʳŷ㑴"YP Q^y}BYl` !fV3sv=+zo Nj+f$G(LrEl+<3B[śm<nVP L ++ ^ 3y 4Zs3C+`D|q^[&reRJdwzL蜼}OS+k:qĄ4uq,pf[DkUU<=tS:nS-d4`JK*0峙CU<ƒ)D{h33oULmzal qˇv@x¦h͐, G#Qyf$Km7c/_*o˛d4ck8[1xk-=*wH}k}D9pd54xQʅ<#g$N9ث'k*^{ zV[O!L닃F͓rgHg$U85(J]l㓠D66iNBQHnOaZUs /{m44v߳Kj̪9Z?C`KVt*;L+Co<Ǧisf:vn!6Ϻge]N;ɀȕfe"aNN;KzGLRt8uYtK5js=B݌ϝQQJ:7ʲh=&_:ƨ/vmSWeg@XgL4gψX Cc tȟ;D{Fߙ`PЍIe jC%QJ`|_,_͇ZxhtjoƟ^3,lxeb1S͆U.Vq(qm$֒a,#${aIvC}-s7n3/fVELo>w*8.M7"72z03xg8p4K@i\x59n[D+M As݁И }@uÝ59+7z*YMG osHry5-ĩM7p۫)&O7r#v~&x^.[G5\\Y1;G,F6GU {)q-`m=r8McJ[ys-i{|c_RBCz8AJJ=~铯YHp6ODb:#)!g\l_Ҥ?_aʆo Cؒ|UfݡtI?!6@*N ;*a|y|i0_d-qqg lK8w2g?$Gy #gX/pI#w}_Բ 3CmL}~ZEϹʐϭOK6̈́ &#({xwUre*b;G'ӲdnSk 9N lSI*,וt{Fhҷq^LIwal>?]d^eQ"* ŽzX*X 2bj&1(\R:.pu`%Q/=2U @FiwT0JPL'&0L1PC ҭT3!p<"!PQcTTŲe LP[*K1<9VxwHY9-Vꉝق6psSc/'}b9 XT }G(Aq"ʅ܇q gܣid$KߺTtf}dےAZH=)_.:(NnJyȂ#gMӅ ?Tو%()gEV<[B8%Sթ]{=S~}BPXX짷6aqYTY/hxR,~*م^B)YZά`k ;PN)c:8bݘ$#-?U5.EEdAH$VR$c3)<ڲ)` >a9.bB.l3u se݉9Hqwg7GM{ mU~qi^#x+h\IV3v 8 R;E$x*bQO\86Q$=I{ΓWU׀j;ENo4H??@:ɤW;JJcz| ؃n>o?g%\lO!E W|cMWV*N \:xw7{Yr0KYRO~1ArBϟ"2qVĎkyM_d Znmͥ,҃Q- ^ԞB`{2Jg4idϽ5lH }B@R 3]!0m-LeϑCQYY"DHvۨ~ZEGȷXimeyTRU$\}(F1IQXڰV'$ Hn3p|$m2 /du& S5DcfЖ) W[ u4`|Eq[{4IcgW,c)e}#"cVx`1gR#X7vBۂ"xN^h ]Hېp%sWfL N=?,܆z6PDZ5:pS@+8YR(6@<`MoRԩRvWrqeZT & ~@YfEu//wS'TeMBdZ) xsQr}n|MaejĨ3l$ھ2H172bX-JPzJJf\yO!Ќ9VS5{#':0'Q>Y6R+1mG /KSa/&n̶{?G HV%~T<_i:w8e*؟R\8C[ ZOtȱf(JTi4$EC.w+eVKȺL~)wg:2ZDH>d4otiSv2"WŜK76L:`6w[V<5%Ş 2OeW(ug(a؛%k7p+bש[0Q4`~xnhnMlKl\3o(*g1a`cET QUH8qJ7<~J-H8@eȁ,1{Hnj2-M"V; 4XYlNɻcXUͫ2@XE@6dϕhx4UĸW1OnH@ 7r[ f"< }}Ťfh)Ȱ  GpjIe_p\tjer8RȀG\p\"Šz&Y%Rԩ(WoA2mX64)"@Y#¬Lsa/9߿fo0!hOKyJ`+4 g/j;>/R缗\D =^Ty\jKffvIfqwtȌ!H~~Ņcݣ$=,eڇGihvԡ"D]G q@8g)5nY>Y!J1 3M+6-B 8CJ7R"D%&xwRbhhgOe6N=/&jVXCM+B>thMʆOJcY mnuC9|*¹#C ,fg`jFT ;: GΊu 2}}{*znW/?ߗgaVNcjd&KtE'*w[1xV008DIP[nW(<'T3@X$',)鸂 TbؿkIh['Xۦ++ zҢzDܽdefjѝYyϟxX `c) 9M גo3 *!EK i@ߤAMR&[$<u)IS(Fӥsٰ[xGSzk -7M6 n|pQ|zQAtn-γїT2>qQIhÉ6U7ъsӮŠ2rlôT9Sr9vmsGy+rP4h|~b _^%wVxXegOTܠMͦ%e4H( u} tyS() n iJ7KOdn)Ʒ0T;:/Rӈ/Oe_D)ٝ[~Tc/ۄʹ`)>ܼs+CŞFoEx~;N6tpCo_7ݢ$QPho&=qd MS/r۽H ?4Wov"X,'6Ox%3gWC4'ի3wS']yyu/Ȣ<7P kBB#,p`R0>0 8hs,M UFS"b4_6)<X;$ADDwhdR+mU)(6^~ݿr%\\)n3EѯpZ>V<1އAn67PZh>&j\.+MX-oY}۹!zJJl90嘬fuzYͭxʨ'a~MHȈ($[o,Y˕ΦMH&EW% NQcSF1n az#(Jr|B.%"ew"~[49nhĢҵ^~Q]{l}}!k}":itr65}1.5Cj6PTsN3ޗ{ B4%ȔH9w/;NLY  cC1iEάpD)v?ε ]mzWQHp(䮙/9(D0VSm.ΓF{AO QXU>oZ3z8%vq-xpnjQg`y̛7%/fL(Rը7$"7' fx5mqC9i%$ny<̼Pw\Zɴ%I[ˉ]~kpirUozCeO^ rW@C&XĶ=>=bDX\7J7 &eyn4$l.K{"j)ڞݰ)GpI+ A7UJI?a#u'Ks@<V 8] mH-%ĴH1*nۋ/WblWhh c^I H<=@tuJH+Y̱$ [G 9m`9e'eJ"I/[xez8֏bmGѸfHt%8uS4Ic& *:-^^9%? /3wVOb8q!4H|JzOu(  b_sh;fKK|m%zYt,'pڱx}*i\ ܬRp$!U``׵dn"k fgAH 늺 \ږæi oC׊-v2am ^1j565$$s^eHnMalDSvI1 0;bjxAz4k)N5Iͳ4,(@2P@V8(زVgy]I8޸K'@ 6-3f$kuE ,94H*xU~_;|`+|8L塓s%5Dعcjk\NY廹 ֿͭcPG4 GKU8청% A)˩,'mru[g2k {g|>35o~vɋ7s닜,8_<+YQ?: suDʸKsڇU0]`9 9L&EyT>%q,_t2tmУ1ѝ }<ힻy[< Z$WRcǦe%LQэ '3E)@+2d\9BĴS[9q `|k5<!|nȹsM鏔71*yr4NK׏~Fk;H>Rf#3`=p6>3琀c [ek]׸ %:e>z'CňNq͡uѓVsٽ$N0=IBsiwWѰjnܘi놬|ւ\-n˟:\Fo۵Jȱvcw@==0 3Fnv՝X_ڎ#ɢlCy}\)Bf4QD٦泠qj.(z&Mh?֓y3}_鯯xvtny !N%vT|.~ysu#bX!rXdhЙqldy;;Sr6[܋ <<M0"pkXXA 3ym<ťgIoz y۲ZNE}\[rPThqxƢ>x};iHv,Tfe{(7IRz9mL;y= 'Wn~>qL̲ϡ/><ƒGJ#]a/]=ma\zF:K:;{ͨ+Zm_R6k*M}C7b+"؀c;*GA/G䋽O,)ʦΤr=*e 'g=s%a +ƁKN!PPXGǧr3. +KN* ;Qud(7$+_%=}l*?}|YN_mDT~ց?PI;BHGJ׈=:C^Y#nѐY G:7R<r3~TQput@3 wEt*W ;`sۅ i?Rw|(+,x]˽ƣ3<_F mہ, v.vYҔ[լp| T&NtڮQ4hb<ǨBа&ڄiD"_D~ Bn5vj0`D S2Q~Rx4?lmlvj|9Z_H$ 87h`g&eXCo z@6zC bDƶT [DaK_!x5Wd9dZhN} P败mE` %wfCXu^6^Wqv|{̎W@:R (٧8Ns6$L*w˰jIZUBt"E7z.9]dM\$YRgTh3 eLS"w7ںoP5R#~|9o9Bej~pÙ{/]W. QG4]ÑpҖ`U>S`%5V*4N!C}eD[1MʛF]Z0ľΕۤwL'iT,bldU*`6d^V:y ׸$/lCBp|;Vd7T=DRXHSʂxq`TjF C.TA FW]}zd,f7]js =uF |ff XXQJco* y&D喖Y s"!+ra入KqoR|2 /71xNkj |hk5%~'Ӕk6ԙ 0V )N GM'x4ޑ4m4v{Ws:30.<Ж5:C}i*8-RD2oLd8Э05͘&4(ؑ =# k`c.F@;Zo&9>:D|ukˎ(Եa9k־gs3neb@z<`=(V Qosa~ xն bK+:D@- vlN |`;ŭ2 WWAdSN?٦eMQIpM8%LD ] |XҖK9ǞhgABMl#ףdTC5-+$4ZXd4TOgQ*vtx :Q@="R2#oK:C)k?"> R9R'Y}~9Lo |SJVP iF 橊8#QNR^"X,G \9` ؒߟx&e e<4v/*vl2VD ¬jG~6d\M2|Mŵӳ&*8b9sv"99\jMAM5.bxԠCd6瞉^S0' >Lsb VӆCTh+q{mJ\p2 blȑ{J .h6w |TgVs~c)I TsO1ĮAUoJ=-_t8 ]BTԅ Cbw>K+ ʴs4Op^+i$;9)Րʶaeeʚ\,B# eujN3?y2b_ď|$7"9.JIm1Li3d|ڷ@Lon=k9<1й{dH i]:48YaN3L'="$#&Yzxd'GUր sR61m5VAYe][dt{$nLKIqWwNd\1HT>9"DK<x2"HoЗSIw] -K=5lYȊ0!ٽotz1+Yٻ޽dw2O9kt9D#$3v;NIklL'-xfI[dEZH~  EӬ},F)ӻ`Z{n"Hyp(3֢gDo~\+ mJ^d[Y8;j%v\B0m`VFzQF|[S5JC'2Fo$[c\ .t1x/yκEbUzH NoհsZ&,?v~x' 6(}+b 0]'X3!,Cc<  dl8:@;Tuʢz[̒ɿ¦R#C\2&ByJT7ߕֽS"qvxG"q{4y0/ !}<2kĄ:.=qa>2c0("8؀ECnhMM"TӸ i3qO#א]W`\G8̍otT Fvohljz-ĩ96#e?1X{,vxHSD %ƛB,<PhH/[{IW1d: q8U[Z V)h[)#,uxU곟#ۑu2DR,JԘl5Nr:1iG?14[ޖ<˜úi%Ns#GƷU]^iչUqskp{)ql-Jv]Cp}KTru?B /}NW$c?8C+߃L3k4/l w/o+<-μm-e RJ!sG:I~8 !M{_ˮrN8@tB286_QǫG% wr <,dd/r@pY2]bn g$ f!(TRp # bDd܌ݝ%% fI! pLjo#9$Rx4[صnurOL !Ҧ(8((Y#C|z td0nX{ hߥr fhH5IBLM1 {hQ(52ƆR1#VT1>1FX]5i` I!@jFNf9mix:5JH\ДsC6=(D!!d1UR:^b`E`bTGjC%ݴ@R͞ڽxYl@MLy8 mUr;0NޕZIB83vϣ\mGW&][>U0ixl\Ge+k>2?չG[ I4 ?'"-ƿTrDbd } Rίq]U=حc;n;ȋN~LIz[/#E5v@!4÷+)5pi<쳵:؟6M|:Կ fFU(z`^l 5z>k'8{i'H]cj+|ov] E^I$7T*P. Y^L)6󚻣LȍGJdf-L.b4UӉ*%ER̖'Lfڠȫd-,$.i6M0Pno =9oЍEDOQ=\aگ\M&n΃! ?f]pp<4o`Onm&=etw[c0"8_><]Ϝvֈn$jFO #r`1%mTƑ4tL}WϿal01#D:R0+Y!0Bx,Q"RkŽLRRPO|قsFL@ڋљxTT:BP4|*6G3`Ii] nzij#JN+ +pF``Crd)\A7lQ~5P@=;<+R"k&;2j$]]FT)`EO/d㣨( KJ˻nG2jd(مCvza󏜂oZmHeL .ھB6xKC)s_&YUz{YHA2lbpF LяJ=fRTK ͭ9B4#v(^R/F_tȜuXd*?5zQxD6$ax³CvCz+Azg\俽0.yvߦ,+׊U߇*aw '0 P9הo|9{78WqAp{XZA4Ubt[Y"D4}4+Fjםw+'vϤ@ka X!@*%9hn#M.NCvƨD$k!@pL@4/flwU7cpǞ" m;n4@ǯA~D{T^C\s3UkaGUn!ScD^=u0Wm{+jtN]4;c!}\$Sb,Bm [2_dOHs-ϵ\%A[j4fΌxl6x2!mZ*jDS#>$`aN.G")px(3#1$0clM lr:ނE/S$ 扡v?z4*!sc꽈F 9bk8jIw›MRhb̼oy)sRУ1Ib|x 6 sGFIҩ_;3_8 ߀; Mmo:g'PҚ}f &Ø5+Iҏ<}/,/ʖhnn-z͏b@\+)X@/5>p&;ߐ, q OֹYoL 9%&[Y:j#Ӌ;KiD{P` -d_ꦤjߥ U<(~,hv IW`2;B4`#q\B!=է;_K wE߸;ut/E2>2PQftccV+uO|s)&6%$ZvZhfI.#'U(UE# S98qP. d5.qqysv->zm>Lo:l%dM-xyTALpٳkag'0h 9#9'UK9˅]ƓoPYf;Tω}oL~Ĕ*]g5:7‡^$=T ч)cxç{[i`p֍q/g!yim3$7CT1,)lqi|V vL5W/udEЩW`Ʀbic)O^ݨ'MXTe2)tk`o+t}(^q fݲ̲l53cN}:&myWPfE*:kvPI%x Ox1Vt8;?iJWkM<tˡ`T}seWkWwL/L83Awk1~/媙iOJ$ 7zԭ(~*Ӑ{T+ Þ\qA6Ҙa?q_G#^}OkyЦk͡,6>[=[@%=L =f;d=$2>eKSK/dH#.?V#̐z^[b*(LXɑjɧxn᠋ёnx{ty^gˉtMwlx*te_+G?xz`]cM?CAi c".^Y^̂J7oz`mF'`z? q.Q;-0 hy=@j0]Q' إ\Gbl>9<H9Nf' ap4w] Yy8hCtF:3eТdΦB5w䇎->FH vTo7X~KXޏ@k)Md4&?iE+]|?@ x.?!z T΢N=( DRk i ~x"(T@h.c ZTI0?4,fT! ^>Y@@ JоϏ BBV_H'(q5BKmAV201N,@膩-f, 7Cch`h_X}g`r$SEfnVvSx']XW+5iYNDfuy#zTqu^>Xb,bodӋ}{vYN,Uر 4N5%)Rd..ݭUH,%"9ia8dW;ֵ_UUx1L{puv i.Vy1ļh̏s=ɮ>`>Yc4&;ּnyM .Ž|D=Wu.[/DZ`C K[\D_ ["P M@^8">j}N tv5dZ`.VbLcURY2y #tr` V"ie\1MmePcMjDKq]>NJ@] eig oHR#&r/g a Lk*\'6VX- #o9 r̛<a=R^#2#DPa54ecLjQA2,}/խRJsնQ*u_ϑ]yu߹g.giQii2X2Lw\Mj9t4؛ >UQnzAĸ"Tɛyfm2Zsצ{邩6b{k!yjbj侫,-9'D3I [čt6VI8Nީq@1>Ut9=O!][}|]Ǟis860@]J]Pvݳ }Z$8PCˏ\zɛf"$cC q~.mNoe=K-? bpbSq[:m-9(%hr_|- |Gdt'7d)*6HWt(\ &@uq{ި?\,[9}+7-lUR^mKnmJ$l.8{ Awq"hѿx>f )эG 9H0GeIY5X{Tl|xIcؗDV6.V01 o3JI!`a`Yq|Odd>4m>GY%$<ˋQ]+W=f=(iEH"$eJ>m>A@Ҳ3@yi.3~ةezl &bXBPy@ 's<4W=ܸ~aJJA ȟHtu;|71m>35g`a9= 9i3J-N7Jn :16C5+47K}MoO/7}JٞJ&}F!}–KY_4F졄47M1PM &ǫ:S#1~W#~. $=Ϊ1 ŏ^z:3.]iؤsI*^!>3r󿝀LoT?p7W><+KR H/4<+6z% \.[Y1V8ަIû^A/ߚG%]߼O-,MhpWо|ߵOZ y*)iζh[D;0]*ٷR_Z2넟SvfjGk mң?ȪYr)iۈ'W-f?nEG*IH3 `dqs$|thxvK x[mXGDs@sRTG- υr@'T%u^ -O*ƨ]S7|tC#y_I;8frtaX9'>SaL: >- īg'tMZ7% PXn.iBLjaaqdgUlkK0jbdW367*D-Bp &/:o5EU0bC7IX[-T};D€2x; =$ju,&Rs9SFroWN9L\r^?k->c@fN ^'IRm/0a]Do;gVbŚXͳFўq!Z R83^coB]̃>QPog٘$rg%Y" Gj4`gDJC2YA8*S'_{`AGJ4^d_ڢ#R,</B0 r$L潯uɾ&<&I< /Z'-3;JE_/"apXjRÍLb  >"*'!b{xV3hoӝHNHa2oտLe9l+Z2zG2\ȃx1@{i_P=D}lؖDme/Cv{%95lBNv dHO{'!$"sH[5'^Sغb̾s S/-`|W͡Mi2uQO͚w+>}n,DCymY4#5u;Gwzp}`Ct8, )10#8D+%ό JY; Dռb)[$Dz=6 K%r./}";X"1b*x4gE.cofӛ C8Z K7:+1Dj zZ$ ^[ߣ/ҥ;@>d%-2&%GѪ;n> C-0ݦ-Γ`d82>N >az,p6sdX9l2GDiGOṋf >JD[}fAoX<(_l5ѩ)ATp@TfqzUkhBȪYH"3r;Zp).mOnʌ4.+ȠpX3xnl灷v.kjNXlmTUn?ܑ#E1sΈtyF(;ҊYZ[W⅛ 1.v9[r"f\p5zryv,=/ ULeK U0 '* &աZ7@bf RCYM8U*+S<6$'E(ll9x%ϛIr)*y3` W)*QKWGhWBE^-@}NFat*f\0)mW;甧*WrѫC>5[9Gɭ׼KJ0Fl)jv/ |kxЦIRaX?g6~]HͭP4ťrJTv :=KC|k@QӾ[`M60>HLαX[_{`t?$t" oxe6J/6[کڑV)Uj׺ ^ZcQ]园./^>v;ΫNǝ(,N Nw_KZWx荹Ex)n1YE&5s=:[(\GxG܌2){,EکV]-#arǗ"߳`Hmg.Q /ʛ]QCnX6^Dtib":P°ɩNWDp[tLɩrͥUwW6sӕ2=:HxAqr/]n Eu|Lℜjr PEDRli*-=`pr5Y4kio:@ <~NCo~8į'PyZhaüFP%<֎ov%YǼrN|IgWyPp/f@ x62z:Is.k`VȋʘnfBŵ^!.ތX{躀V&o`N~5ż74t+!ԞSO ko=,:cΖ{i-M ^Ţr%wm?TIYny`Z܏i-uANEU$ukb/]לUA)2^)5S+):1~~e l-*QOFPb)k?:!b{[dÐhF k"9ᜀ{ͪʍk$ ,m0P(v+,:;J1,hPp5:63lUݲE$_MG0yLwo,K,RN&GL8%ɼڇ`~Czh 7*"Sa7%rױlu]}4߅J\ A%^. c!lf^@:$/w_v|Jn!N߬BsE ٕp}Y{;kxmxj\"*{T\Hy%O߱8V>|Ts-ZpƆlg_xns+/>6hǺIf[Lc.J.2*%e栮{ {(7&50/i]j$JbfݑJ&:6vI>栵L'i&J܍|0U4IuZDS>WY{@`LidÔp(\wGαBt!{>n"tn"r)Q/řɍHz2[Zݪ啞x'hme1݂PSe9*BJBk~k_vO8"[-+ĉȬLԦDzgvgZ,\|Ȉ}Y6|Mm0^/g5-x+ϕLZ8T>lswE)ajqmz a ,Wp[홧`zH,mzwxhLgM @ /$1zY+٧pgcåO]Cnxp#3ӯODP8cIEdl!#smg|iM[Xy6 %A}ohS%p OP`[X*_.iahwzњ2 P/Yfیf|T8`ObСtW; nRʈkQV {* 9hr>R8zĭؠĢa'Ocs2R-#O[s82@Qz6D*R!eG5hD=8T_Q\Y7TO{g/ wE{c󈸯w_Pq#{@272E;Y9Vq/^@v({5LŶRr&x(Hّ<#`|q޶a]~l`'mqk#Nkp ɯb7V6f%Jr\JP)ZER8"!rA7  1lZbdmd~.Wz'yz@ B󕀢QK7.登~,)y*Z jB6HʱY|չl!"FA#|"SUi&\a5mo@Ҹ;φǁz 5/oWrgTǐn 3Xrݹ>~~#w}c E&6 er6- Ȉʨ1)-CVoi 4F؇^tbFwtiS זZHܠ{!7i+Tn#-d퍦13h¼%P1ӕ8F6!ԉމuI|bDzTaKYoʞEe}_}+EZyvNs _q'4 +TR܎OeDq14F#$xӭP߃]@uϔC[Ʈ@i"fQ(O]t3 A2cύDuSѧYO|}*E0 [S/C MzMW*`Ъ5s/qTDK%khbG <VG7~=F6"b;7n"KT~]wsm-?~׆J53\٘$CV?03IH% 2IoֿMtNjdUIw;9 Sq:k6֛:F@L"8EFmFՐo"W Mh7S/7Sx74Gjʹ #Ú6o8YNJ*)-`VwW$@liQT@xY 0 je5:`#fD`,@FkD0j?e@̵] |{revkӁ=Cka(7tF$[wj h:C 7'a$?X9Ϗ1(:{#n5P pPF r.얔QQ;e4J 'ܲ[CJ ک$= WJ #8Z%DZX,׆ H0axVgԄїH> C;|g^ L!iLfFIo5*wOn2䮲s|7pt zFy)kdb(XimW dg,DkϹN o'CI8U<+ƽOOr~u cF%5#5^yJ^"ekUQ'* pX,?2$p &\bFXhwu%r_\Ǹ02cQֱX&W9))^feDkvM.>1bk/fGQ)K 'jn8{\.,! J@CJŴDw" Ĝ~٧v_y,CXc93 5f$o*ТdwKL:@dTg{1 "cFΛV#U hb$/VNP,,>.ه :} 5jÂccm/z2eW1Vr%yv@eqqkPfiE۞L6aUecoL!8K"MBZTwRDf|7)\%Oh3U[pԁHR*60GpVMkيNo_Ù0&?&h!8>eg>(sNNXXG.f\"5xb/u[P cek1AfX /&ZʶPлsdANh#D+eHNŒ]N]kIKz$2uyl,{ ~X> .ӑD?I)o3hOxO;O֓^`x4LG'`7Φ;B1,WS1 r(5PW:IaRϜzPdcG]gG^ M7Okt:"=o$ .zF&+| ? sfۧfW;ɠE'[2[(@b,#z%ŀl{ VN㵳t/Fe3!X'}Fyor٭lKpͽf27ԲOwZEz40}%͚z.nvD{5_np$મX X(8k[&%lص 1a3G)B}9F\bt -MӍdK Ufb6ꃂ* /CQiG#AvUJ2xΎCpBZ υFiao*eutG`lܻWW`vb@X{:{KT? ҄:͞z4bP0ʕD"Q-i@։$ͷOs<  PyHǯJڥC-(9^*iQ,8f̳0OsG5J(D.'\Sj)jb0[R;`gH *W;|huDb"%p}JelK.g1m&QБ]V^TՊ~2`<ѱ$Wqx^007r](uƝefDijhV[dI$>TCca`rxmpS}"Zİw*5mo}g\$$&M7Bd:vh6kLvDC`.bqrcc(`SīxmUO]T?^QT}Q鋦9]]v==.Qrc!*;c!~ˌ`EB&_G cLYyq<r7U'bʼ zυ ޗ۟uK||o?J%LV"@ډjl88.q2.4 #& "[EQP8ry.z5ս!gG)MQ%S!n ۼ9v[ W|B~m}HuYPD 4żؒwlƋR 7 )U>[gs&]3SB膧| D)# 2:OA0 ?iy l5j2Il){}n+[GuAC`3񦄜 D(#5V>fO;#;} F翍Ejcv-J 椲>D{Hh;E$kAcYjKM*]K pSއ*SLV |~ 4QgH(KNW:#&o}3=Z$0ElCV`/W_,zŔ[fiC؛Z~=@%w-C7qhlV~"FFOn2f=}Wvf, {5nirɆc5aEyokBNj;U;p=&0FSz ^mӠϮZhYw>I8$"¿1!Bt b3Zұ< GT=S!,XF羥͔9.ru4)@ZDOXY_<|0l#Gi!>) ,,vF\;ԵY>sC-%Wn2 6V Ax r*,d-MwУHV)j(R*BLMPQzͱaj \Z'G7:(2b {bbӤ*隒"ޕ`"cRbBK\e-.%]DSUF#k~riߔ@T[9R7,WiN2&PdN6 ,KyI@UEO/[e*Blֱi2޸o7зBK9lbʄ z'm\<a(}:fL.{/Nd k3A'&R1z9""'9\(Էhc'BX~GW9#ChN$oNQ4;uӝ1dQM&(Rw^m&TQ5ۖwꡊ^Qzz٨`IsBu Y]|@@8EK NwuфJ%3Rf@2\_|/4Ȳ}'EYg`a]Fxyoo<'Wg{)f@|*͠ sFDUQDսO p"kPC-;1*ŜNZlY*rg! n-z4~jZiNՀ'P`kFF1k/qE${A3\Rlb:E| ' 9&u^Rlrš$+e"w,u֖eIqcvDMZIE*qZEb8euW'`RS ۨ݀4 HTpgB !Mp17 XyWQYƇܺl9Qmy:zxMva&ͥ+ѵ,*+4rM5hjg*rI_5Y v]iQ"~R(_Ι[7b } r%$A>j\ Fw g8Pg>okf""PP4W@VMVjDJȆ#.SYpn@AUrCE Ox"Ҟ̻ lwDHW"pHwil+bQ v`4% ~1-nhHg{G"3h-9#O5bKWT}Sj@6]ȜSA"pPIO݄W쿵A#o(ہqWC~; ?*0ԦXT/M/H,"`@ZpiV@;j6Y[13g0r_7+]5‘59_eIu 8px(~#99x:ܕ ,VQÊɛ5hQ:̱,`B,' #8cMLHH4Uŵ4Q b0TY=N3uoSWw$ņȞ5%מ۱\2 R\[zG $,߽.3^V9K@U8Y H2P{aסHF"`V(QH &W_J^Sr)d8K{Ն%~>x!4Dg˜FOMs~lZ u Qa,t7ۅE~Ň ^ QxQdgʖp'3WǓA]Pib'S(i@8T!pCgUNU{Axg4 ݫ[ %6h322uy_KR4&I֍kWeRј l%kobw/fe [7cm@jgz`4! ݊ؽ'I ,&Gd+3*Su5!/rRDy⫎pkIFW[r'eLjT4b,F9-PR[3J+R~eOߔhLRpd~`C4:k9߿wMktp o]1œZ2ꃲ]`Pv`]usljSNV{VVo]L=hqGـ{6\n~N͐UYvk1pO _Ⅶ' ϔ%}+'(izg¤ܺ/ Q7|(I]bѿ+BDJTn,!J;˰.29L~9΁ʚsᄋ %4'ل)e-9É;2Tz5cJ*\|ٱUwfFty -t1mez* N3p!6Ϗy0+"i0()O!M$υl|6]7Hu>_*̶L!Ñ`|j ;X~l߬(lgH2KhGk]Zb $aQJ $MÛ,QiMfmIN4& K+IǎqnH*j,ɬDZ|-T&,XoVوI)wKLIyX5{"ar[KAg+!q9ĊOB 3$?HRzv|2¯ڵ`)`*o' Aۡغ?B}(ZOtUkx:'8qhZ7Sgҗ2;G^ Y1V5ЌM\A]7 J(;g]-Nڤ1]%Ox.H"f`IAgosYAk M4j /jF ϠzX\oBSov8:hQ]-$uJ|S%(! sYABC޽G,@1Tw퓵{Ԗp3uIi8  WGB:l;:XN=q)1:O F&xr V7D\VL *.!$0/qHrsiWR=A;ԩ6Ƒ-q zB s_/z6\o7W9 bx$R}ٯ[g@aIL]^@-%wZowV-d%gT7~FBT"ᚏ?I Ɨ[z3dn1Q˜Vvl4+qԓB7ZQ# kB07;iS? X]YZ%3ž`@5px`-[ (QƃC5_zYn$)ӂcu3)Lf. 0cGG֙ +*JH֘eP<3@V+PW$ŊO_xwP +zNIBݓrK}1۽; j! y%89 _ݿ/lP e",F tƋz"a:#Buu/YșK(szMOn$9}^ b#8fpXAv߬Oyqޭ~Wb %;v.AY@{z Vl5r=NFhلf NgE=剙Ɠ pw'Sϴ>+uTfJ#.Rj7!T[гENnN5[22l>ۈURTʱ_[n_ x>xkHUDrtXIp'[-kz'PLN"b;lX?x0G߆$ZʳV0N) A7Hî3(F7Qk7*"T=+/SgDX\+iɡta9mU'F(0NjX! _03,[̺38j=3_ޘ^.pf+Λ⹫.H.:'wF!M$ 3bhu&e_5 ImeOؙ|t%X3dpCHP.-of3NZ:RQ'b|2i 8/C8ab hxa1fԄs@jZkC_Y8Ya.$!m]&qݺ*?ayT 1qz^`mr3=yG2G <3(t #EP%|1NY'$zŝ؋COqcCOIH `cgBmQ$JځN@2 LWԯ?JMXoHd8NF%Xt& %s"9tt'yLRs|2PڂF +b'FM}&^àH6v%etso| nt xJ]Ld)9ܳ$Bj遲%}L{)b7}d{V 7Ȓ,ʀDLhNG,*O?9܆0-/Sx 5Yd٠eJxnoE!g TH&_jZN¹`yuc4&%FR:,ؙ s( ~/96f. MpDÉ 4:k_[*0*ښ;,{YkGb5Kn+^c14 ? ՇjG S &Jm2MA4~kQb\C2!# и~Qʁ%-/ospL؇Adc 8#/|Q\Ki]Nwa;Bpp-Y4әqkHNA}'dJh!Cv 'E=vngA$c {p&6߁n EVg e^Uv8B*j*cUqSLz"sG2׻K)W07yehlji1'Ա9 CJ,z4rnq磺 v351uN(GDJ}5 nZỌq&Hǎ]y!_G̔OH2C`FWg)BS!s-X{93*o3Z03ȄSLIe}58ea" fb$-;;no/6kФ.N _~KhQf$>5n94%dgϒ?bsLH`猥OK]f!vG8Ocn: Lo <{GݟLF)vb"k /4/'fr/Hxۢ~ \jIs[]#1%ISٴ\nX1vte]hw Enp+U#~;L9a5#]Pv$Yb{d 퉳<}Zx kn)j"zj[7Bvu>?8}Fl>QN.XbhU|a/)8_mZ5Uw%Nn=aq B o1'd"1c+2B&*,fxBb3@LЧzOMt*ClYIHOfRAx fJͳsVƇ.h2rH6r><%fK[kMRRIU߾E5WKALJfܿ0QA]^_]C7 jAÏv*ECf>x0qO/03I̖>Ҽ8b;:"#֍svyc<#JaEF"$HNh:צE `m7]S9fkDY6?tV/}6^Lrdw6|:]ýU&@ҠM&7[~  vӿtf]6z}ҚvQ: 5h6, \x\j@~[kfEzeT=.Y]jk!#q^f>"ݬ'd D@֮QOI$䯙[bq%)!ѴRh,o\1DD^fWj#w511H#]7&nSc-e7l@7塥(~LZxcb)iĄHW\#F_>ո2~] h᣷bD xDR*hOk {:=[*O@72w_V*_⃇CgʱSR# 1 l`_U9ossrv=b>TĂAi!P%h:u `!a @r[[iE\gBN"? j!/܊DD*[Aj-mqȬk \%PcfȷQ~nuVqXe\[!X]"B@?dz5f 5#*ա 4"7;C[9TLʱ0n#x {ʧWmbƢFG\XwB=;j \7CG0Kk7{ƨ 4N>v#F|EDŽZUQ9:\d0JJ{/C^!PF07Zh*cd>S!1ҶɐG8Cj R\RbArwKpZ%Ȉ+%KnDq ? G|MWeSLhczU\