sssd-tools-1.13.3-60.el6_10.2$>&^> >Jb>2?d   F .LRXbb b hb b b b!|b#fb%P%pb&'9'9+9(,q8,x93:GbHbIbXY\b]Lb^<bdĬeıfĴlĶCsssd-tools1.13.360.el6_10.2Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password\>x86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686+ɤKS@ |5q#0EQ;ao3] 10m:*|MHOr ?sH dC A큤\>S\>S\>S\>S\>S\>J\>S\>S\>S\>S\>S\>Vpn\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F\>F6e0820314ea3ec7bc18b1a02ec3301dcb834a52ca671d60e8bbd6e8dda29149e10acab9502ce2e73014692130c887714ab86d0c8455e3ca3c60654dd1eb87dfbcbe626e51dc7fdf478397557ae7adf0452f253bc11ddad6cb89d4d5fa8fa20087f9c819356c2781dd47f9abe0138a5b58c00d63fba576d13b27ca1040181516e865c4f8b05fae82b77e7c3d36a6b73bd717a761d707845344c65ad8b31ac2846074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e4b5ce8776a762c744f1a6baae5545d31d9d4bdcfd2db99a12ee83cd804192a1a38a9daf34044a114e85b3ee4965a4712cadb8857e38b24ca88328bcdd9c8941958dbe4f10a9270f7343dd9d7f90bb6ad02b51363ea969a23b8c4282e241ea075d09230a51dde5dac102de3ec991294200bd38d2e9a330a9bf9d551d987b0697948f560a1d2c5b425b6bc3cdfb439f6ba3335a7210d772475b29fff80ad4dc2848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90310e7998fa63a7c5fa94fe61532f72c8f103f6563c4f6881aff04fc12c72a2005ffe255bd2d32476ca4c1799d2f0880dff0d56c9346263c9b9166d402797a9597ac16cc6ef9e7cbce3b59721c89187acaf2bf74ee83b4ee16a72939baf79d1c994987c56756375b9c6ccfc6fdd8f141087f1de1a53e2cc7f9c1b8a64812a99c30c3a967ee8747393b7634a732da977cae90cc423f89519e1308b2ffd9d6500d3bce19c9a1c8d59d4467007dfa33a13148574c3b3a56d1f7bd0a5ea4d22a294cba70ab8ee6be09e55ef55d4df5462bb87d9171bb88c9255cdbff05ad1b665ae31cad39da900dd517559c2dfb31180acbf6dbf8c44cca601699638ee846f730575edb3bc87a2ed41ad0b33f8a7ddb198baf564ee3d5f73eed3645c35397882ce809f2b218af5f82c9eebbf77d4cf98c4ddf70d6c5def9fda0c42f60632f639f43d86e3546ea13860efbf7a889f672d22308aeab4854e590a851bb4fa24fc97700e90d2fac6d79054ae2e369e04a4c073e92d8225e8ab05a30acaf0b3abe8dda766545890f5aac5c6199f40080a7eeb9854fc19219f3c01f77ed18a2634b0612ab24e86b6654a933b196c491ffe8e198007de7b7fda4ccb537c9b80b72fefb55ad1535f17778e6082028bdc12926753802980c0dcf57be393e62848a083dc42727874608858fe68353c01c6d95a9faed0a088f539d649702f6a8767cae6050cf898dcaf95c6019e6d32722fd00035cea740bc4ce41bb19bb6ca38c4cfe2e0f4a0d3f33dad94c2a3f116dee94fb53ba321249f03d4cec1bcf19b73f7c078f7d1c466adcfe632e17455f2204564fc7999edcba0264521556b2977eaf32a175e8cbd234295369b56555fa293ee5e0b19d498798c7501cb0d7d6319e225eb1716ec9fc0edfaa451fcae313edcf7e91eaef9fdccdd4bf678e2d0f6641b96cc6efab26c1eea4aef71794a708908f80b961c82161717ec4d38e1071057c37899b4b3abb27f3398af40eafe3262aa2ab33feecf21cd2a580e50c3b041985d2bc82205d9274edf5abf7a81ed70904be6633dc26d7b97f4a822b314b80fc96da3397ef3dc20c0008a9232f1f1efa992089761253a0a8f95c22b77c5c08e61bb610c280853be10623c3aeb7d99a9387a928f8ab52135d04d087a014eabdb31485a16ed13014b2be0178b0c3dbda640d4d716bef05563415f80fe1b1c7e72c16cf8229195371c25b3071b8c84ded1e4e764264645e01c79ca04e28d35ec8d8a4cfe8fae48e131b2ab89b6d644af0d752da4bc9d07c7d932dcf2935dfdd1e96060a0e918db3fe6f7d997fd8dfaa45b2461800d9ad9150efca9c49abdfe42d405cff4649794bd79172b159e6d3e5c8994924c73393b0e032e3f7483f6e2e7a73dfa0d3313996e76fef64c49f786b3c1a5c4815f6067409536b15741536bc49072fc5e4e1c4619e9d46909077a1bc9e7c4fe450efdf4ed0a2dad8b909ef1d21df0d5e88eac935c9e722983bb0ff8cbf948c85031d641cad04ab8c7a4c6bbeee8fc8b54bb9da6b4c3c5046ab861e93605476aa9eaf25d4fb1ea3afdee0006ae36b8b18a3fcb1a6c5c4394e772ebf011b7c016464839f3eab352303c22eb45cceca781af6fa1b1be86f038ee0a1551c458c692a176cfb1ac6fd31854b06abb30f989f3c0c08e4efa80499446766a5877bbd79eb8364840c8d757b54fbbd6c786e22f3a892c1634f79e6161c20bd8eb2ea1815f37dc4a1a4e25d5b1895e8d1e0deb757aac8c898c2d91ae320fd5f44fe907ca0699f8b5273f5db15caabdd336024c509aaad69c18fb7b0a625e6440a939d5b597e5651b5e352d02bdae191c9386e3b979ebb52ab2c19c8ddbb9e1c70b639bee076b4cae6e33a9364ce730a767bd5ea602bf16ea511158759fe440ccd63126c792da795853c00cff6df61b615f3637088e9b73967873aee8136a57029a66ba7707710a6159290b724004daac15e5d12eb34b4354093ebe1b473de61f66330ffa712bee030d86e74250e1d8bb7209d11714bd90c6ba4bb6bafbee663c92ace0d73520617661242ceb9a20f3fb749d86862d8cc834a75d84eec2dcec4e21c1f5df89d94cc5cfca9a5ee641b444b39f437ec81a61e404175cc65bc2d095244b677dd868c382729beb40c65b39675056c207bbcc628a6f174bad6a2d8fab7af4bb505cfee2e0c474c8c8a8b5b50beed5d5a3f60b1361444e0c57ba3ff50fcc864cfec5ae128ed14f4b704de0339d2d7494974747dd3f2f9e825da1113ebe1a94b1083a8cc4ef3605a8025bc7cdc82d85f1489c4aa19354380904482d94c0d736616f5d9f6cff3c187ee1267b28144103ed9697270d1342d52267e10a705c1af7ddf4227a6142374ffd9e27f4a7efd70d905fa35863b0c85b4bc1eb96bdd0fe0b7d5e56f0a45169d89a4503003da23e1189a9cfbfe2ff00f1f9425b5a8b7fc192fbc67c4c9490b7abbf1d45b13881202e6ebff2c4f9aa93abbe60858fb3d23d6ebe40c44b74b30601af44b748967e984e57abd73c5afa1bc2913d9797201403296152bc129b3cc136d547e63c56719f9e25d26656348f8e109aff3b0383ca9907ccd3feebfd2bfafac566da7c49904719a5c1d874f70dddfd278f1667c796fb3c2c00f12d9b519213db2dda1acac178392510542194166731042f5f84c967b50add087cd806f24f2ca1208c5c685d5c88cc2f85cd9b04a5b449fdd89f2fd7648d0b68c2e74d0c7429dd38191248983152bc2d0fe5fe47e9832d526afcbc27a04c903b0f7042dbb1788ac6c5bcf6160d2ebec752292fd9d01d3de34a48da39b22919284fba837857ef85854776014c87199f35518887a91de2811e390aa23569ed3cde3e6de935c6ddaf3908d5b440f791a7e4dee8f11355be78185b97c6162290cbd2b8ecbbc6b231ae4acf6a96178dd7058caefe06d7bf9e6aa87924712ec948046d1489e810ea7bd822bb3e4a8485086ffe1fe36067571b3d8557d391565fdec1a0caa066c1ac0a2b260a150fa879cf48a50f515414444b1d2bd3c6df4968007ebf4eeb61aaf955138377a5d405bff06ea88e9526cdbb100639ff5c2c85ff8ab042cc56b4ab6a25b33cda4c8d0004e180a6a129ea909f6ea9f113b24b4e7dae0cc032a140a66d4aa6226439e643cd091e108d28bc5bdd814ec4c822299ae948b0feeb977f53bd4b10410adc4b4fffb947a32c27cf6729f50e97f8c63952065889c2d74587c5baedcbeec1a368d0ddda626a449e6dbd77e8d6805535c543cd55c29e93c688709038a4571794dec220ecd95a66d394b0c1bfd354f25906f46b7593b2db24b10259acd2957bf0cd8d4c7a46fb8078d57b9c313d582d0710c33949020cd27ecbfa2e51ba767fd99e1aa8ee5d4be965a802fa7ea701d552b9e21a4f512bec4b026ca161eca3889c6c8a0e4e2f1110030b7f2e6501fee112fa99b9e14a3224f92d7666db59e9ab4d7164d1dcb3340812c411432c813c9261d14d810f44392b38b57d7478b094573aa4e97127a9247ca47b430f4255cfd4470d52f9a331cbaa98d3477f7ff3b0d4f7a87c4672f16af2533d31633840505e97a9ce9adbda59ecea7e7aae994039eebba5f6aaf933a61184141bd06a744395ba5b4fe489171633b2ac7e9b056066b82625f0818034a016da47e94706366b72ce374f23ab9433ca46a9c0b9197b9560c30d9ffe6fa0d9a12ae5f26c93cf5da6b44f2b703465fd73ac1d6d4335440c465e5f40f9b58498ae2f16dab232c61fc9b850ec99e9aa2f6d79ce0517c0665660dfcfa9c129fe3e26e8ec465ce1270bcb6a8d2f943d32ae1b38e964ac2841143d7c4c8d1fdceb412fe00b5494c0397e4rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6_10.2.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el6_10.21.13.3-60.el6_10.21.13.3-60.el6_10.24.6.0-14.0-13.0.4-15.2-14.8.0[[ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Michal Židek - 1.13.3-60.2Michal Židek - 1.13.3-60.1Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1636172 - crash in ldb_msg_find_ldb_val- Resolves: rhbz#1576852 - ABRT crash - /usr/libexec/sssd/sssd_nss- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el6_10.21.13.3-60.el6_10.2 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6F=]"k%}:w{!vQ_99g4ڤ 4Й1Zfb`V G^ܼcskͭ1|s6.~/FY{EuF )j"?1b8A3_p>e%*5IyB|6C0eVyɈvU!b+ f8Nt!d#ή |`pha a,CԱ-UӽP#R'*É) n_n."Lm*qf\2/i`w |0MBUֵ!}vw|S`x|i @i_,g\Rr VRn-ܥeqnY'Naz'+`5iCoDZ5!Dz:!p P(pRو< OMzBM.ޣz$jEymirL^Snצgf̋!OG Ӛt?S6oWMKQbw IK?LͧKi>,ټfMh\ϰT5|%RT GN6zfoxWmR}m/_XAUzLj%j 87W5~uID6mx,ٽ4?o]&Ae58p97.`0ַ0P 9ĺ_VWĔdk^&H Fȋ?el]Y쐃g3H"xh`+$95 )L= !s;9>x=śG֒Y2ʪ\9(|Qef_/ց $(*kq<K:`УJ 올]nrOmxdynEOk:iZ T61¾nQ"lWڦ)ͱ;+舘K_HeK'Ex&4ǖWJ`i0}&vi5fɦ8ƒ$NX=A,t{"(kh $OwZ@Ed%3e}V|-) RZDf,4_6雘P2Q `- h`P g#%]я%BTyn^r߶mFJ̬wnHpm ?Ed2Pb kXj!O=`&uUԧc}j"Jmf9iEWSi>Jv,Xu">V)*K,c>jؽbU4CAK s,=1lZg7c {ӢCpN"GЎ쩫,eDe mOr)!2=t tTGLl,/gVwd>YMd2@ч 7 9|{*TWzEY?pPOZfs&"P0mHCʷeNRw KrizHI~^U6T&O@]h//TNy@ugA0> _UX"i0:jܖu۟xBûQ Jԟ ֖} hwm|4~YN ;k~Siq(`BYRܫb j x4 8kU'F4Z!J5{ܪ_)aSh; q2hG?QLZQ ߿eX7F ]AUTCǃZ.l0hV.}R}04\#bEeZC+n{a}u˓ͤ@C6;pgVUPoi-5n -9AQ10٥d*ccܒA7R9~j{bcƛ0uh/?N51<XmDU- (z Uylm{쬯t[7CP87hTBnIʑJx`gO+̘|ft+7ΥPEcF5ӻ}~ PN0IRf9sa{x3ݶ)8T k[q2F_ve4lN h,YN{>菈P&@lh+^z>^ 8&`7{JƳ.(dPxOޒ3Y,̟M8x'tԾ_&l]Z?QjygJpB-!MVN 9w1/,g }i2mΆ~UPN5T`랁X@$6G>Hd5NHJK4C YnfB&C=0=c> ZՎ vKK K 8$&So,;`CO—{RWc_F3/.GZdy2)&R9wPEyě 1q{1^19s_oRy[d=SJ9kp+Dk٤"jncGYvWE^^EBq٫M6ܾwΓqzXhFM8ռ4&j\NyCI2+k&jm$ ԰f\myX_.[ӏkd3q`KǍ䶎frwO !洰大\D` עw*N)~1Tfd`vK0ުd%AD9ɖO8Aee[L {#m/4Uy1c~TboзITyeoHv Axy wa(u"mͳ=oPds zjQzzhg[|Z0X/{A݆(ߠ/mȯ-< sRl ̮)I)urQ=UÀͿU̙M}Kp(1F̱]|10-DGT~/Ծ[K ,!W-b{ijʙpG4<<9Eesm$u%ϰ{V*|% X&0~ 2N%BafJhϹF}yn]%FT¨ ɹu3AyFWÌWGS%x%aK20 Ƶl/V- 2eU3 >2(ͻRC\qhK 4:iUʏgb#*2,VWʜ8M󵞆 P+-c$2ўQUL\0[96uM98 u/;kCIQpl&|lgS.. _  <m38;nSFW*4raknS1bv6 I!װȼ'l$$qՉm7P 4Ʈn3Th~ 6DCNVo-hisJ n-#Yq{* K*#a^1n$N픴6') "Q^) 8IAP+O3Sq 6|e \)HPǏʡ>/x$FRJwK~򲅲//gt TЂՙ/QGQjͅʵyJ B Y'|GH&|~I[_À4t@dSnxILWֈ\:G2aص8$Kp]|xs%Ybm248@E6m܇QUr ~iV#>mA'-ϗܧ г"qn}LwU:2TjjGL={:v&Wu]Lo'*h1+<~H9J%oCElЂ8e1~@W0Dǰ1F윎tv=y;A 5+vw,BManH(LP-j^D$pua o$nPf<㟀o\Y88sdE #<( oJ > j`&4yDoaCl hRyd(#B-Qn]Qs`v?șS-PCףc Wmnnmc^rz'bfhPHo 4 4xB)Nh95{uڟ4F,`G!Jc( g3둗@ iDeYOި Z0L6^V,>mʤz3ZMJyftPy'yبױww?q}Q&v~ *Jeu % nkK@9@xӦ)Ʉg]q?* [gMJQzhpU:J!Ro+]Qݑʔ]WK;{.Rz&UBl,p?\.L2-l4j, cL^ ~-xO[2Ք1a1aُŊI*:MRSf}E﵏(r0  kY q N[v:hcPi/PcG->6zɺti-ҧy8d{lR*oX8k2Rb>лpVo~#j]E"Z.=7ʱW#FpLoovA&1Ϊ9XA֕d@P)@:Bli): ><_cCޜZȰȻ뙀hiϷ;ǼPf{m$%TV=>᫆AEK|s2œ͘Μ; )_.!a偘J]'V:]#a|DTa1y͐5Bޤ_x4ΜV 3Ժ80nLfEދ7J6FI[dVtP1ic)&d,q dGA:-<I?K`ɦk8X.h4G#0\_oNm[{nq>~ir6v_ Y%pņe.o[X蹩iʤ<8I+nR#k3'+"G{\2,̒tn_ˬq"Q&e,HtFI_g}rFi:gէ=6ӂ=٬=@A/5mKD^̀|S#L &;1GN!9M:2 ieB(2v·2RtJ#67jAAw[E3<пz?&Djc 9\3(dN 8l=q/LJ!&FOJ^yr˗N*IV,DWjf&~8~(d{XlU\M s6X4R4ߐ:!B@]GBس=1-ٗWQ<\&|=g rF`.(bD(v"Sh$X#6<嗈#H}S?JΣX+VO ZJp+eXK;;v&((CjQo:X y8&N%6Fra6Rmr4i&x|v)iMċt_}J彑ğ Hjsܚ{|FWVK?0r&OQMJ}Ho8Ckږٺp [nT"l$N/3_J}/|UR WIHl_'`ֽnlE`󍙉*9jFD4Tf]bkؒ$G:&?!ik7O+ A%BYxG4j”\U`$|N^ Mͺc ͏$g)b*I1YP ~y`U# FCV0g0؞˯OH5G% lwH{3#|1HȘ%>L? Z ^<:e/oIP6 \rP0sYX^/׿3k7}Z|)oUg̏ti%}~3aWCӎ:(koi2< ?z淪%xHo|+kHщDyIK/hrzu ha3Mі0_yݩcLi }^/uFrs'ݔ4d8AJskd.ԩ4d;QCJϟCrzr?lcyA@|V)&>NJzeol'VAOw/ϔiEJzx7B#SR̤> 0}7r, wZl:׌z5yG ^؏1y4*t.zFFqEu V #qg.$|xCn*ź]a'ns6jTSdj& :䧢6Kъ0-"rϓDL`S*9~q%b 3lO4We<'_~uc7%ո@++Ā)_9d,E+Z|'D*h,'׎ /:#"P6Xfu$+.vWBo׍p poDa;4<Wȣ-z,qb]ȅ /:G?9.GGp*;{Wxf$+DZ%YI *K;wi=ꂜJk:]d+J6^WNʄj9~P[s~w.T󤷛͋z_.HMA i 'fO T/yX \1s,7 D p.~Pk~aqM65R8"zs|.:3Z$NaGm4ysd1ܽ"JY9AhOnwO'QH/o8,Nð05}yB1=1( N' Je`hkH]:65=a_]$I)Ih23 To% 9H6v{Zmɔqs{^z0qq?ta:Zse2j_;躂d/@:rQ%@;CFi0Eu E{CN(c5FGL9`_R4םb=c?2a`"2uV*%M[I~]#{/  Û=abkAZ ƎHXl^r#`Qzu)22`P)'l1G`Q)]8):t4ؑe:L{vޯXxCɞKaaa#n s3ES3tvհFaM$k8"R϶Mmy.MxQ/gF' 2PsCy;? h]FP ~<&mB^/-WD Y 6@:{We%daN,͐}bz>!%:?X1E2ֺ$}mb:GlѓG40[ڴh @OeW΋0pAi.NR+/9`C25K2L &{3ބۗ-/ÉC0 0Fΐ1pM~2Ϝ`80Ӌ,N&芗sɜep`51De=iN4M@b$;'WQ>ܵet"gr|`^&7z\P*RR/%˝DNx=.U }WYAE" ,OH_<9c gw B&ǹlNebec+?!0O%bSHGbL4Kj+DVTIiU2& ƥGAP Az,0 s;.P?Z/eqM82NwAQhYnF;9ߞu5~Kzds1o 'r9.+֩pӝɜSgi];LS/_ns gg%@l˩"CdE佄*tnc]b9OXTm`<>SV5omz40mdb]DX`Vş&.R7)eiXZ+`d2'z_Dl!9nNLvL.х^$LyΞځ{(U浤9TsȱJi6s;54yM,IooAUY5⏿{)8.BGHa5*nczND EƆ!1NTK~(;;)tƧgV"|T=r5])0Jn+s~^MMOK7;sq5#0c(qn6*O 1z9cwƳ{&i[,3deD{7mdIX{5'4E⺔ 7< qQͰeIf}ؚ_tB\q^]zʭp]"K)ޝ}~FAE~[ ؍ӆQ/g}UŠ &=\Ȳ{ a=F<ݺaM5ע-3ߥiAȟt]뛷dBڷuSQn%ۊGv >7^6$HjyEu[|G֘O}BR+Q[5l,oWNx%sD^▦NiV"5pJMU ގ@/LmvAGT +V lz^IQ&|-2d}C8Hu>oNԞԷU35MOKT".D{:5ͫ;%؅!?E0ZXYg⮉sjī(n 9+KXMy)(iI"Rj1V@oR?[_Ζhm^kv:ZpHҁX23} 9j.gNE/2E(Jsk) B8;;#U6wS2PP@RSs̡GPNݜng^uw7=%#rsǺKP3_b9cRRvo2C&SiEv3];^zW3¾)$+@G~nKʯb_BfǨGVR,CeoGCQo@A.{A Ѵ[ "7\^7[čG%Y9\J8:B3UV FV6%鴩,n4j޿η+,ZwWRDp(T&!8D{jBa%2Kd12@M1x-\.ο m{}zr_IUaFBëKt)lh9D4r;]YtTRL;^ n4{4̲DEA5j |=MBL6G[?n׊X:bP>8\-HCɅP[X8b[*+'=1.qΜr.'5?Msgi}`[ڑ񔡒# Ț"!VD9ܓO A1o |ӒX <{[ߎ 6a*\ g@+e~7tyC JIA#{!$֫QjhSO743ĖA)548fB #0Mu{bg3yY4+$95k3U5 I\qjontmu]4e p)>@q~UGD{rbz3-w +eRM}=ψ1F'zo(E)VmRMYLP"Mdu4ܛ"õYX5$W^%l+p,405Z՝Uʌ@)+P  m`"ql񧜫$씱#ŷ" #j& 6Q5RL05 +"*<># \db <(&vhGk=E?ؖcB)nO I /1\ M?n,֊H&pԐ.cJѢ ]Yyvbب-T͗C$*.ൿe7f'3"^ÿZd[ *]3n=ȫr >2o"Qv959i]fnbp$J9+};/VW} 'Kp9"bpCaWm5D Ẅ́ 9}#B^1i }>} VS2D{3@0P!$6ttּAfԤ+ߕ4"0ehI-*7xϽy\zSoSU8A I֏ ȅ "(SoE4n!9-91k6tbtܻ8[nvHYQ9c*R.Fq=lש]ݐK$ 2n¸V`+!Zpn'K4Q&QtH6>S5D00#vtzmI& BtZPh#ǰM( БEu e8'?G,|8*i# DcGLsE|g$鲭ߝ,E}Ӿ! |DžrHWw%3.m BCT˰ͱVx4k$Q OJ@ťljBx(* Ề@TE%_4miNvl,H;꾆#Ց7v9fbQvKzAP %|w.^_Ṵ_]`z@S:njnV]F<Aw+ŅWrcWX275 C~zؖE],DC~OњzO)aTd@ۿq<,;#¿^Yw[e矍xu? " SlbVǴ́n XE*y@8EQR(joGbIcG,+/Yp~f) dKH+/&ߪ& :mT_bY״M,a\ i6AtRD _ʋ7ckaBJ-04̌r,{s>> ZQA~jI>Z);3B,9[ G!}(3xKiw$fV<̴;q_Xv$ao&xt=Bp_%g$@WM{{63g5?sOSoQEAZn1jG>.i$Z 67i6('WMIy_5RʼgJ $JnfZ;r& a+Ci~Ac){>c<6XM RuR2GZm@Z܁Fr@ݝkVU%{uȪMjHK9M4drŀa[Y[ PaoHd;Xx=х E9"t78cҤnȖ<A*Vɍ{y#IŒA}5-^ȫ4$&ʗ>AR˝p[ɋ=WB cYhꦝ46%|WQp #hhI}?CWCvNA,]i/.O!TS3.-Ne; C[C-kO^\;3]L}#Mzn|J5w F|} aJPJۮHq|#GVgfHTzgCրkW@DTۆ EQ)#t( ytb٧~rOoBg0=dys~Lj˟)f Q <5 eCV(߅b潧퉵#uUi3G58Ӂبf#>P6)Uo@Z|. ȫRCd ŕ, =qb=_Lfc:>븩JorxqVPևS8ROhTsoʘًٝ4xB%>ڶۨYnzY:ZΆ.mYz7CP;(٬rw<>}sWxnQt&m(:`4`Ym:tIs-a.R׺4MB{xXD!f}ODB~: auRni aN1Dei~[e2ПVT ~鳻h,ў8:LJ\Pؘ.Zu1)e2*cH&?RR|F3"2(ӈrſЩ|%|.P&1_y+-ߨbq>n<%Ս,0pO3z_ɫe\m* Ng_iD`8Z+Vp>2:t$#$VQի_5Y|rhZRƣ4P~Sr5Tb2:Pԧ_ KI1?p .Y, mc}@?IZ&H ܙ~j^]5lSπw3=N>mxSn J;9:{jMי`> sO{:xJKGcMX!#XLy#m)2h=zSvD9+L\:\IYygUR%uJ ݂M:[_&>nyc[|>6Xݕ `?Tu!;`'w e&K@O:I{4Mg&ڒ2ф߀ŵ np`/D>k1?Yz"+7xq߂ NƬTPHq*ڳICxXq^LHLlrc4zKt;{rD(M=G4SmE}^X@vB_w.ȺË5~]5 iN!CXB}=0ٹsOg6=&z]zY 2GXM˘-s^E?%c1[3DK"a\Brg= w1?7e!ld^q >-y`,9ŭе<-];kKSAoMY{*rGU%V8rc{4u%evr;w ]*05]{K)望0-Mɍ1x#*pGFCfq،"dB8!2hQ]ic#ٞr(QrHP[aNӟԴcCfo\[4Q,ɇ;7!Z/N=ԅ#Asq(+O(=׾Ti 4.8l1X Qʇ5j?׽d>[g2} )MceЊy5\!ᝇ@Sa"MTxdqIҫ綽5+ (@Ƅ̕7Du6o&Y[8$Kϟ QԌGr\ŠQ>niX@ 6;qlj+8a^a {3Q_J1@"pï1U"k!,А1yَ Ў vҔLhȗ%hP50 k'3@ߛ,Wmh( y,գm D{*Xb*كn_Un :>ϝe΋."ߩ/׬@XN#55bZC{czԲWuD4?a}-jApP! {-S}`(/J, Ƽ`ΎH{-hZ |j Tv_q$* ة=Y4 ı|@]@sbkWr~H'z\p\5 g^Y;6_} ξ4>'}rP(qӗڊ %7b.669wd] N+2'&ɳAtڴ Zݹ*)gfjwb -V ,r>6k0-gHS[jl*pFa93t tXWݤ fYz9'<9!a`qYU>F yd=iae0 2:<= x^2ڢN{3euFf!=4#^hsNM'LV& HPf.m\%S%dZӌf[TsH`k_ i_A;1x51mr;KKb0QB{֡]31Vtax%fQC6\8GjH~B>gVk H!dI<:(yAaIO%c 67DfCKi hw&͠_J '\6`F-arGn.>񅑎f;55z!3v>ҮL Ĕ[brD~9YLegj0^KفR"*> Ɵrt[ ڎ/Bњ 93f(wQq>5#} -t`(ӄ>>Y*jT{[Ώ-yq7!+}6'fB$8W eUbҝl`[IHokq~.{tJlM=SSx7Xj5y9.j.>E,Ī he:G-4%!ԩƃ TAmn=/0GxI@8}V5F~vG$kYN`!O%YcHM/FR)NUm8C6՘Vsl@=ݎ _jA3H@ 8~,^9 6Bg]ixK ھ쿷t)Zth~o_A_d2bbsL+d7iu-y|c:kwStb*qtݨ.:`ޭ xO?7Ϙ9P+yiӯ 1afFD7@z:N[L06,1ƢvkEʋ?YUӁވnn D4i>^X ]]GzNBTd!T dGl!>ȝm ҪsKvJQA.Y X &yb1.U \Qx& FVՃH|㘎Xj+ ^[z 4A/Ɠ A>E u)J#,]P"mٻ Dp/UDB^0Uxi9Wa|c8/'zxz~íAI?ZbrU ݄$tmDٷ8h+&{#_FtOrqr>Z"bn)(%i㢕}5ά.X. q~g7vr cYw䚁#}]!8^ OwN#o|حd}HF%xb-"3.R'p /#Cqx}P'ȳ>f\uyyxUqr; ?2ĨR}0ՐL[韬T| GE}fNEfw'ı!MRK$'@=-!Lc d>b$0* &HpXk=E3Zݰ+OAwy)j?rۧ`iA{!8 K&FLhK_dQ)8+NCu-SIJmͩpKq!#B,d$VC2 5dX?Hj;j0H\3 ^h֮Jj \2n&m2?a{?k&="/+7 6QDSTS-;@4W"Ϩ!{-W!zAf+Rp gXql^oRulۉRFNjc% ԣZ-"$j2%y)uj /l+'`b LQHrPc002sׯ{F\jd;}Ef Aw1me%5k-W~$ۤ}DZޞh| b ZX2\ CK5 we4idݖ/ }蟃3cl+#Zy.9\N Z1b@ , QnO;gbqOd-bH-Ly=@)bF+qOGZ(#:o ieXYNe*0OT! Zj3[jȽ f%ʥ]lT ^ jZN9hZNRO2 3Ѭ'+HNSC5ץ-8!biF~wy$τKaRVMHR!5暁!]^V~ NY蘆G!CH3ĭL%3pvwyDr!/=eS׿q`F=$E.Mڂ4T͛Nթ:s`r<6[ՔDz0%gİP3|V25huMJ~&}{2 >TtPj Jby }[ @Kq_6Md$ jqh83פ6oT2y' *IZj\}ϷY[z *=aZFf4.%%v)eUHnѐ>pSq)IJeq3p`aitkӝ&w=jU X 8fxʹTa4̒%F|UE Fc1v>{fOjRYf-ˌLOAk{0!'()J*=:86/b&|ݼU j[Xf!+A [j +mG"n$ǒS<  %v$Jz&#'ǟmCw xw!)]M5,uO*I2|ޘiCxCEh\QVs*CGCQ LDg'++S:p;(FfBy8ZHMS)] OBDuAmG4nxy~A:@"vGIQmtUCuLa6-jV| b }ůqn)&sVd?s KQMF!<2FT}W(sxBss3q3-%TD1w(dM_]]{?|%[b^FSLv>{[G> _4C rd<^_y6Xef'Qֻ?M#VF(g68f<0 4ADSߋƲrcWODZŎ }%tgPx°bfS̶~߉> p<}D9@$/1aSX~?nDĹfLvWi % E&x9֟(uub7e~Zܵ (/jXp6hWCp Hvvܺz@U.M6^,~F?߸.Q <***,Թ ; y^;^Y~. l9^ lj#'8A{>!RIhʚƁΓO#o `=izƞ]9|50OuƦ Eh!A[@)|ea/E=7nj?[I<$a dC_#<Bb|2$2_T Nj,^ d5P>x F#]W^%>Z)+ŇZ8<8 GU0$Ǵ?^c#)b5 e)7JMh : ½7R(0$]w^l0?G0]/]:*/^y47)[ÒN,'-ke)KYًnM{U5a@-8Rsƹfady< > :D!x)pqؿ ֶgo>u7xª01N{Ӊ ,dUhxJUu_A}E m0 /»22g\;-O;++ph*"|DCTo'rGcXw}#GVijJޑ7;N%"bzV|2c1-IOZf9m 2օq}zâ>xo_N=a!XZm)A :+$YGUikNK*ȯ9cZfu4ab_̰饤,evʖBk `98No Tj K a_Ygq?݃7D1vq[ WP#2_[$ MNun4;c7PaTnT|QY/*|lGLdm.G.٭z-5--c1 9<03T{pc>_CJD%$w[ׯ7ځH2ߤ{E*P\\(9ϣVx8 Fp?Sn&j _m8%_j)B,$VE좨/9oJEced?vR_Nx:rw!r2cBER|Ie=GV^+ DPBPNVk@F LYfE)Ojy GwaJV~sSFanE/hl}(º9՘'09'q]Υ{L8uTigéo.ًkGDŽԺ~ fG]qEw9FEasdΌоak)&{XKF*(}nCRadJ 2? tFZ6}C-m/l'ٵV{'ה^?h;g0x]!edN|>[ sKoؿ>xR⽆v&1kU#^4 -q ]ti1 pz*aݳc+ ӒT,C9ڛCs{Q"!ڸ 1Ax(0 A 99J~;{>Ϣx^ b&ɖzF~X$-:UHopEU^A 4˷H)Ol*]^):VTGېiVaɂycŽٻ2 t_Qġ}m EW[`HIr"~ҠӿDXZ.Y4# #.s-˛gt`+xIraa\ӖsWk.x|k1QJL\d1g EL1/ JvJѿ~.A^u/{)n}7,K{| !]w6ݙ-,չ$Y$Ř'䯙YjRgs=?B4reZ¿>'W"HK7xh.ǿ\5ChZeΰ.놓;^Fhym$,A(!6aګ 3p.;lHְƫk.Mw<~̦bY.NCtoD-40EoYŕ Vr:07PΗ%f0P@B{ԱD;~!rM>t̀.aN ZDr[<tЌI[~&:_h쥵C,e AM[m^P[f_LCsr hanĬ3'4BjIFI-*|rm;L!P3+>5w˽Tߜl"V6pM?= .R X*#Ax.0vt2a BF^ФEbg +voT^{ll0#XZPɡ>I}(D܎GЕjB1N政>cMqV$@>Kh xt@Hz,9-Cl/eCa1I|٫Z{LANs-O_x 2ef3IR R3(a]L@NGɈ2vc^0n[S;Fs 0 'IܿL6#cfJCAML#q #E\ޢx«3X>-h$ JH%Qm4>J)ZLC7wNq7pZ8dlM(%iMĹgJZlu*#l/D{#/}MY]*MFBMXB26A?:BK]{"%8,)f[Ym,U +K.8,k*6ɮH 1-1.5ޑqE uIeI-F^]I."ٖHr]Bz~[4LjN? =%ҝ&.-|e-6H`:FPB\#WȨk;Z4Q)+H:$w*=ڂ.r:YQRj =~Qh !Mҍl fپ21#[hx!%fe:+Fܱ[`\bZ[?0qʻ[Ѣ ;sGe;T 0ZUuDZ@y=EX>xCy@@6+J" S2rAz,áEuB%ma#*$ke5i ɀ'4$m HQG9XaٱnaizYAPZR yt~ &KzhT[]Uu:4_C0"IZ5i_'>ԩb4'HϾg3b]Gً SsÛ I ΪH>*GI>@L:m˜a,=dq;5zEbDqhOҒyZ?ϯ/w [k[V eAvq{>nGA& +x7-3Uҽ픉Xs\律]iXm&14 Rq|eZ0$ߵx3lL=-f t%"0O9B1' ENf25U` SͩtcjD +|u!yj7'U [r@Ss1'U /+ b`]ؒZC)jv(i|Ya _κd]0Y/QW om+j:Lt/~#<? g ֈJ~)Nhsotp T@(A_ n#w4DP2fQpSq7Z=oyB@%rI"PJ? #b+l[5yyeyOej\l*P)KWs6(ܕts@ΙBT71waP0oH-"5*½B+m{1y,U+.'m}OeM<S,㽻6U҃}!F8S#YSXv`qHFdHoIڵQ9'VCvd;&d-Zg]jY{Di)&S^ eJE=PCBH"sZєȥ?iww;\bD}[obX3-:D:R@#0D3X-F +0BEžۥc T{*d^ Y{now,Wm#2׆[PLpM 4K?]L˥#l ,=q"( I?qԴ _-'j:]]M~7:/Oʚ+? p}:P4q46y>|O*vӡTT{$#n4ΜvH9 lLp=qŠ8y!%uN~]x>LTzC: qOV3fQSoh+Z:v.1h Ket-Oo$~f8,ו3k-6Ϸ !p;3-2V 6_hpI7_ZkGQMP~?'LiDqf|iiC^gKeVHE') ےBݖqDjdL=ߊkrX-_2N7W.Gn4u* (X &;hܸ $>%qX xʍTtߦfJaZ ROJ!@n6l?AF EJŊ@`-u4FaCI(~~I)זeћLUi#o{Ȃ x N]8V4s eC%@2׊J[p'ڬC}hN} gO K@F.L֗:ׅ!:XWɊ¶^ehQ7HzK l4"); 6K 6-q1;`W+E1?{>fAJ{EMȶy4F5I7zt \&9(]q}^D<F2i)E bq$8Fc;JCcˠLq)Xqm9zRHKˑ?4/z̬B|˔Kxs2m*HjA |.~vta40֙|0g"kZ"\M=؊>$ODl ɴn}%K~Uq>UHqо/XݦN=j=anh T7$&H6ݎkۙ; kv a:{7hgr_kjCI{q񜡹DrALQMьv 9s+r+v|t N?Vϵ$lƳXqr/6o}[A eT=+eJy<+-&Q@e4*X"{2>įBeby$_֍p*ABKG!D0SS@&Qd 3EwRpUjS< W6ca=yo7 ɫ95Jb7KKMBjFW|1Ǒgˆf߃D  LʿdKYk B~/WrN"s~7ӀrMqTul xmBeG9A#=n!^U?>3G?Ë$|*ssazW~":4y֜&I0o} AaHމ1h#S痉qK4BL}vBŻ \aƻ^j:cB 24 젋`bc2~3*27elYqlabi77?$+O%P-0-[tG3ŻW?Zg#}< ‹ԩ НiU֢& PJ9f*Ƈq߿j_r\j$ɭ[6 D}hY~Qy]օ;FGZvq1 X1]C.R݂hlDmy$H }n#̶m_^700RLY+ٴtp9hz+dsVj}tdeQebY{ZCnxb#ԗ;k2+y{dDrLR`H@z#}\t*lrybeœoD!m|n۪OéUy\U6;ZqcP7U `^\^o }W=F:2WJ5TGh~7AA$ur&fy1I6V@@ K'O&lsVݥv$Nvt+J'n& 4_8l#B60y]3qO_"Ժ2RE)G fˉll2&)cvEt+*Wa٧. vt}QM_7(4$hzA-ۣZ]!ۃ-U2gM`I-4&#Ngj4Eq\8}AAv}zYS|.(e,|F,͠]U-F?6ExaQHFP 8rocydm(y }oGbz2 !/g8j<[`SsAϜD*j =%9zh?(twuu8^0Z=4j+\zRuo-ބy [E ]0 bUyjedh>#VB loi6䒫.G/a4wP#3SNC27 _-5d*Ax5"<30[ŋAt~dU{iB !+^䏢C7Q9U,.'\߇4K χ:wѭ' sLnj4 "VC!#cMh0hvA>>;XUpstQ'WۄHzb{E %fly?)q:$xjvpU@nB7o3f`vK4l:+ ܫ{%87VQUwȽ?q(? _  6r[j Jzgbә+׬|۳.ٻG$seD\U)LKqXTj[#~uuur vA{YD%!~3WU8,Q/ag.Q/2rxF4P/{FzH+e*W 8iZNiݶ a($4(٢H  B2|7.Kܓt(`%wOBq+Gx]l`[e3 a'zZ]ϔ?fL[ ԛ;X77:edRRC у]bJ<It3ExRw/{y) 寤ypJ sycC`y0zݗk9r =$ znܱ lC~b)%h"clw_YfTT7C*}4cJN>EĆ/+& V7V$MSŵLD#78'']Q޾aP?I$x oةAM$M.{&;'Xu%-Pۭ.ˤm\2Hq$c*#cG_1bsplShM0`;5">6qSmZ> ̣m3=gT?ad`Y9嗸]E!?|Um6UN.f jU`YEynm֨b7W&`_aeqp~@ eDlhW%xm3ʟ$S` B^g+)eھZoUqK;MgJ6_IS f)H6KKځb)pi} tҭ(UC%h脏 -fOF+ey!)b>ucc?~> iL *6@CN̩. SZȺ_ Չ gwoͯT)G\OxaMH('/} xG> yh1XLa5SH=X N9!{py"jMI\5;y-'aT=In?6s2i|^"nV 7DWGPеGq>auD>7kC; ČJ0 EEG.-ρC$++ýfiKF"'Kf[`=Ntjd'w!g..u]*E|kx|aT,A1:&G9.*\o,hǯ@ w;UA,SrTߣbOőxףGy¯(G mP)k@!sˈ%b9(UYAA\XUkl 3k@ AE/}HTٶSD[yؗ^e(QX&v%(r%;YLq/>ѧyJc=ơ~s#@z4bvz@ܕDgw+P:YyԷy n OgL5?=+[j9iw5F7 p+v.,`l%<} nE TUX4ɮG:o~iNJγY]^agYmo =]-Ӽst9pV:9Ox(fcs?lߤB7s6&(b䛼ģ@5ی!Btf;,Ī7i1?o(#4xeDǟO[8 n jS`lUjr*VUF8~z1JQ=#"?Sg"i66S( m4X4sG:wDŽ; A.q]Jwk&(.(FTf܇+t6x0ΰ)?;Y 밣R/f,m聾;xQ-`'ƣ!}Gm&/yv O*GzwGĝigS)Q;٢1APF}3{ |VA aqthˊ?M.erxEP)q[y~B$Ĺ=Aj[.:ɑN?A3h"-B7SBMYh5Pl(N'UU2E.TLI&8' 5}VujkK+{@buӦ4XąJygFIat _\Cj}.#]kx(yR%0"Se8V4l|0•Έ=pyI<ȹ Pb* __ub _BX)nxVatdV*ZY ׮qlY"DyQhv׉o근y8chRH}EߊL˱3d+B:.'K/{G)yK%J)0n5>Ф`qQa$o+xq:#vuJXUe5*7V}¤>eqDU$F[eD|I2Q?fbC $.u*9ٚc_Oꘋql* I7}onI daNtί fG"Sޙ+) ahG{QɵخQg'BT\#-8xn>CbV}bH~1@d~*bhJ.\p[s'a84rPA \e|JyhQ55v%REmiܶ\+VQIS(}q:<_>``JQ2:Ƀ߮5a4)B984opw8Jo|N7*-b`FA:?E32ԕ<~lǦkyyr0*ǏRvޘ C7C+6?u6HN#o@],֞F ڧG{ k#N n;DrT$aD4ŖoQYL[8t! ]7~Q \^w~t)$n͞0ztX.KAFVʨ<V簳X~[*'YC(˔vZpe$33n{}ӌ*D5q="m򨴦#[/-!#Ksĭ__EMpǸIk2Tlw^6%?2䫈ņUb ?a B N[J BAm \FFS]x`Uio_[lĎC WD,= 11"17Qx?  ̤:yX7uilkME:왵ujihpUl^9a07`-,؂V:ĩ-Vv|&ȋ5]6֭J("M Syqt :;5p;:qߧOnPha('ֱIC?Hj6x$V,pؚͧnǬ֭n_!-ht×jY:Sfoq] Fǚhcڲrx̝^`u`MC5!pQ{Z;mYֻlٗ{[[]py2(H86;mR6 dE*Pȩ$P|鵥XђT|_ NBS_#g5-OEwWTqz Ý@[Ô+$W_ִ;F{W '5_304D*L0as]w3/{o͝z {awO CW!Zyqsӗ*Ku3f[4ߎce#Z5DOr'"L^$==hĬ!&F GiɩK @BfD˚4oNŁ mL^4oEny_^Tҹ%2]DzBɨ|KbR,),]>}R ~Ҽq@f3Pwϐ AP`'/S KJt _;Vb)jꉫk19K;˽ʁ76J Gҳ5[𬨮tɡd׾ukB C]טq̢0rܭc- )ebNQs/!lhsU`.U8mG0IС۬&HU6욶ȿ{4TA[_VL} Pb|\w>H(N$~4Ⴌ֣Vi&޷iOA"eД)EwU&7G*SK'\Lm>~΄^ȃz{pzlk$CX*dDq7[ǥ+I8iKnq: sQ핁\ܼuuC{imWVʑS8B ~RNq]d{P +uFf`-y{IL͉D;%sEO"sUH{mAÒY>ko߰PH 71=d9ĔAi@CZ$ʗtUfjٮՌ<9P Q–f&|؃g7(&e7؀'|:D"S+z,ͶD5dhi,ahӷRsN7mA1[a(CgPHY{W$>di8R)䰛xlϑaci^-JL Y?&}1SU=< ,e! hA3ȈZ?NC[?9]*/!?{h-CutuE VNOO5iUNS~Ir45Bc7+e3TLk Z\AJ'-PҀ7n1p^—CV UAKJ uMbN"kh "sshn2&[b@L(%|RYmYgC։rep%wϝV,o lmA*$vG2vHk5caZ:m5RUG-V0vFSYޛS4T oQЧAՔDH 0 `/A~'.ݜ}{G &LF8ʡ荪?5ኃn9 !GiٖP/yoRO}FoPd$TkfaILSĉ(HޞUh 苾]5iCuR*ڞ.8fSpK\jwߟ2룶Llhv*x oU@z55F5v 2'is8~u R?sTN +Kָ ,,Paz, W֘a6rlj1*lwS. z]Veb֠㭰J|'A;w;0#cX҈d2/]Wz uM)*@vss  9ڤHH/_+%vf؄J>zxX5Kj~ :Ƥ˓<-~rQ7Q OҮ(Z#{X7O )MNB'"a_pR o2 cQ<7 >`bЊ e2U79]vƜr[0nT7e \hd#?ĭ\rSp`݉nCPm2 zUw.ɐ,+Zg.JCZ`,>e"7i79Ŭo&5e 4xp4cZ$|}yQK`_I ёo!nٗɫ*b]؄Ŵ\P nʐ,^şvGjFa8`wI$xgڽ:WnٲKs{@'.Kf'm[8c `m˭UU7  ,b6_7`TnU.A]} M>0 :J0zAtU}EHˁq o.wyb&ɪZ/Wu'I$ 2kBcٰ"fpBw`w{N_FT}?%!ӝgK>7HYEB7pѶ r)*bOU2o3[A K@cҘY/av#h:тZ̠1)"sq!RXƴ/.?ɜ\&y;]OU>n&Z/hμN^m@׎pp&VuX }eg[1Ï8٢& ϒ+ܟn}@& 6\_ߠ Ϗ1{wN=z&2w1TuƮ(S?>op.)u26]BZu#z22y'ԈMkG`RuF499s>K >J+q"pF3*mx{3q!.,MiL$MUff[aU!hZD7=QQt eY/eB%`e!iLS:Ik{>>Q 8՝Y!8kـkL$2B>׋rf}5ײNEZDnECG RrC 49[Q}7uLX۴|<-j1W4gEBk߯iYڬ8HNtiTaenZNrz49Nh5j9T2x6G~V=Cx.}\Fƀk* ur|Eת"TS&L͸%rFU^+VXOy*?O.ݶf9 ;U'nt, ԜK4yXݍ>(ht)_a~*y(kB -IP@Rݶ'οa})`"ltT5XlAQ#zC$1#$+NL%`Uy T@P 7Wf[w]ؗWib­Dr&P/r*bn3PXbAk38شrӲ@b¢\z',K[wIpVfku?C:SkdVlieΰ(O^K|}(7xuAW5j}?b~Rw GjnN{=cvr{;  -.4mUsXT->WdbeQ_ /198F7b acd %zԒChm %ʧXxyap'k,n)x.6sɰC֘֊fkxm.xG71`e ݕK3V[Z(TA06si٤٥S.B ۰M]ɏ O9i;cҁD~KDb& +{+L_7 dRJZ3u7r{]QfۏN )_ HVF_k6;MGbWҧ1c$zfL&D ymh#l) CG I+^3ֆ2 "8#7[cu6ټzN`#@Wn np,T+(u$j )@!Ip\pϮqṼn* Җ9#AMi=qJZ~a!cDY %O4#jTl?~kM{U⩖`BOϠz~B[n'Ut (݅#"VڸZ!PbeNKu^ 5o‘.~/ɗ5;iMq2 T(93d4e+%I`w>͵2vydUoQHC^ńrU $Gã,4n.4>2<#UY8_܅84!6zʈr m8dPc6ݟT>:!?f[(Q_?$~GDM ڱo@CZ]5Hf /Nʸ?txĄVF]4 QvCj#xOʞztO k 2<ۊZx}*Jw^W(vWbA$@n75a!(|-,ё4.!^e:)36s-Zdh e .?(_̭r8",TVq࠸xׇAO:JhgVg$ڙ%/om( W yHAc8ꞏ`u %k@s2칱_|=#o_4y9\ܦ={l[7a+4DS8E&M˩8㠐+sxrXNOD_!XK4T]ѐnspkz+zÆB/Ƨc`["i۷w|9e!_@³ʗ4 Y+.ԗ;?[u̕LOnɋ!R2V-\eߍ4ΊڙD&͈$b}O̵Nh5wÝ"3K*vH,&,4Y#>OAp'xF<ϥSP{3\g |l:f|1 @n50kPC~_5黥ZŪ#.Ϩ.lNwq\ tvЫtրV(ڷzS Ȑ= -f]-;5&[`QBYT*=}eƬ&y-+#dWRwe抯F AW .9.>31G1u΍KA69$,G;u}e DH4 KLb 4o%8T` IPMMxQ=hEԏa!rLBwo2K꼾J]7sBH4^>oZ9%& ,@PGAֹ|^] 96<$U)Y!%Z6t(/„]` ƈ*Ȩs*@pqѭ,rU&M2i<DxrYV#RiF7*VxB.kr(Fio,d.N $*I|=rQx62(;nYkFNLzBZWWqr.6e.y(>ϥEu%L t~GPX*g(*'Zn lF[Uhu"V \Uj),C.uwuQǸ_T wA`:QJxa%%e':mĨ4\p5nez${L#H)e1xSydY݅}\)gmZ2 E^~ 2`ekp <'qv3]r?Wh0.t#R{LqZj!b-"\yŗB~\8P {?gsAI,`h2<:# Pˤ/^=snHrn2n!CsЮez`jZ](c/wޢMܝ^<\,{'\TQ|:.aCrf%X|pL+uL[P&LD;o_'DsRUjէr?*~IDe3`RKaC=+'%s`yTl %XrS]Ìa {_GNFAB{NkvUI!-15URޒQٔuJЦ͙+&< Qp Z`"'wp>`~î{X& 8EؚzЀv7$Y:Mo= INd:pZY.ʲ-ɶ|-zlTxs =[A{XvbBD6" @|n2ٍұy7-1TgOf\f 0=<."@5O}_U$|>z֕ BڦsE}m_+VVŠ8åσ㠘q2HCVZM&Pq2"y`ױxnCm}YJ7{xFԒQ$3g4}2@H(&y+OÓ6kt RD$6KOӡݚQpnԐ4D7["ƵAϰ1č 'x AS(~J {|.I < D"yk=H,\BfмO|.c@3uG3hKQqINP$Cl-e~{(qI庵8`L~=BwO#O"\b1MCËjI*:y#ȷAsr1|<9O q 1"Hb/z*LSB:Pn&pmdʜgXb2Ỷxj-78{<6&0"=M f;inu#+-%[oGr]- + $%A 4{PU3ukiްM*տL[IQ6P%G-}&IGO$bTARK X!PZ[~e`ZJ] .OSW^f^1Z,h.}A$>^Xg9aT:&Ȍ obB?\1zBEGPi%a먏_+:W-kd!kywF8H̋j{h.WhH0ny Ԁ [` 1KJ, _SڞdT;.VzzBk;1rN4UlǷv'ߕ\9Udbf]^ߧtXZHCZ'+u@cç)މ۫Eګj0HL&g\3=6# 1n@ޭq>4UqV95/"dauоnZT3t͡YՂk$shVz '3Zf~ DVcXHk/c*xV_DV7LgF/~KAoځ1\piY,H5s0\}<\|+4&c9 w3"ѧJ>A6rsO.o3Kpp._N!8Q 0ij3;: Yo^Em{mүXnPOZyHQ-'SŻ6EG3oh&_| !&=6[]mu$w=, r¹7O\)qr푁@' ׇsZ}h"wE34cr:}DR\o%uR qZ*XTۗJFM9*68p+0L uNJ}MZ4'bI(jȟ<}u֛H Lcp yLzWBEib)Hу磖g&C jɰ'zۻ; l:X !:\yf'؎XYZ1tsP\cɚk#Sb Q|s&tJz9c'k4MYTտQ+@|v#6O~T[1l݇Cd{?h-i2Pp3 ?'&BCeGƃ, @{+ݳq{0 gEP\/@2wE}UhFټۿ\s>*$ ; -71_®\f%lq|>>d+Q>џ؟ڔ4xgԜ$.45<`:F؊5c8's8߬č17"ְ񢭗pwIA>qe^ԻD7sn2T#X?ӉH%Krӝó y28jX mR{ru_+[zgZBoO  e+)<3mx2 :Ά@ݦa Z ^mcT!c2. pe与Qq+XyUhb'+u;Cso]%B.beN%Kro;q4A+Cv 2m'*KO@䌤oUy)W5߅&g;ۗ~(Wpv榁tltNF/|t` ]kt~TNږ XE=[cDrmfXY"l2!M9&mS,gCSi.YkN,c2kfz.HWqAO iȲQNPKmP0|n+Q^X*[HqB2]'[zӼ1LJN$⧜n.^{l_d jj0u*=+qa_U,)H i> cgv#dױNX#' zWue\ 9D\ҵG "hw/APSR.V_Ng| -R|F\ =}62!G&-Z7g:ӵ6Z\E){:M!@?kވRVKR痣Y'r# |R3S^[qhêׄc,v3 F䮁U4R T,l|)ہaT$ gB-f𥏢؅BQ Сjp٦cJu a&8X?~N|[tx'2kզ[]Sk(1](޺Ũ u C9Fo]i߽ۛ\ܗy,ɣ+}4VLVZ]Z16.P#HT3!!BI~z+9(FUSi mX~Wqt,N; LDU7!UTxn#?~_ @PE ]˩7CЇˎ_GG@9iܧ;p'c`g>'4(K7f 5GCМp h@-&]kP7֚Hҹz$YMII*e<~+(4Z)PgM) YG.\@&S?БEcQ zB60`8#h"h|F( Yx2X@uip܏Ow3].A ttp {w^#h\׬ %ccb݅Փ1cRO8;W^,\K,K9> #`jh t d|5Sfӆ4`Eq]|%Axzls#,;,ogZg7#%:e81L7Ũ9R g("j!qg"F3Vtr:&q7PT }#'%وK6e&Ipd9D b?Ɵ^W'vUnޙ:f-ں=0!ÓD U)\SSX/ANKY䦾zAzʏ>L]/0ϭvҷLe duCGi}F!&k] ǒ8Ҝѽ~hI,ΙY?%1 OSڹbM8@I'?;<p>zeDGQNt="u'K6.}P~Vn"7דNI;ދ 9fh"J $gL B/kxHe$E@ejS gQr*B{ԫ4PGi[5p'ɰ"H̭g.)M k0F@ ب>X0PmxI]kU zP^]WR.+D[/ ߰ÃVV۪ g\HBLc ۨ|z xKQKc?mTD3GE@g_%}|FqA4#Rpӯ dWWT2N Ţ ,v~jkf\o,Otي&E47WU*Ǣ QkKL781%1QИ!N-CŦN- D fG\>uhX+;@4~gK ΀#igM5u|LsvHϑv2KրAX NJ$[Pȟ]m3$ARV&3A( Ifd3~a֟Gs3#mxM$x{I YQ&Nf; ծzkvSPQB@&R 17[{joGI;a +WeCa%AI1oTb)igjj+.A4ʍ24""=R\ Q4[tX7oA3gK=&C/6_( I ҏ׌۬9 xO @1}{zہ|=(eTMO:151UX+-T/r? ۇo}]*2LNM3/}էݮu`Ba6iB7v 8R%YGl4* ~"||LdE}e6̚rL1VPmp]"}ڏ- {m$O 6*u:*>;@HF'dB]1 oi"۷ v;tz 0_Y:8G6&s!J'=mvI4]^Bq8OBVԳ6}eX%x4og&$FK`7UYɴml6򯰰4)OEK"YȲov ah T"832fV^iG^>%G#ƞ˚6T@6?^w0 gpQrZ0?mAh@r#yz';N%tX{Llpkrr?`v(D&;Q}ZvcPYlr4Pk̒E$' V=N83`\^DˑK0s_6I}\"ą hU߆ @dhmIvv(SGxΐlR`2c_o~|&E`jҼk9h(elAeO\ƕ9xGwr~ rTtRWF&ʸ&3}"Ơfax'3i})Bs@VBa6gR#PTT:ɶp9-Y`,Lb,d`r;WzA/~bޛʜR?5[₄Eꏙx$Tak z~ X2Esȑs^l~˃{֗ b'u&WmSHv_i:/3;鷳6DԈiFc@C9}E`wۢ>=L,tIQBBV{d[A t_XTAxVrg}<ʕb{ N}ТSEHL5e<1O?XM/cI_>w?wPp ʍJL̓GX@}c˨֬W㾘'lN d+S2/cmӱ@lA!qbK5ڻ4ĿAG2X e{[1qMW >=<|&7MJX(K-a@I^ԫt|-0@OVqb?*v_mhԠb *D(|3OCַ^hר1h;,ek ?tg|c&^L\y"fblԠOC-ԷdyyLLɌ/_0kȠ_]l.6 j69ѮiC*%/d]t*62MO4UqPW:F uKRnH0ްyiN酧)FrwIھP*l[Z48#V7:6_8>)%zQ;3ԐĨҭa s3Q$!PǠEV,YQ.‹ O)l=Nw}:4_6pt5Jd|1㮳#V չvV@]]3ICr$¹"^T6օ| ͢S HةGL eMBB#搑_Bg5{w\ Cy 3d7hT{ol_P*alYdgD@S%|OP-t4SfchB+QF0m 92fSC*?,I@ӌ,lF>x>V*d8})B@Px;JhU3 p³OL\iBpQiaq!? sn`Oz<;GGZ pg@ G:|:F Wp`oo϶G#:@ZKdr <ڄ?Xǘ~עK1j 5&^&cgY7z- t[x2) <'P}PSZ\);FϯkC!c voTp%n[֣p)#UdtNJ,fØiҭ& HMZU3HZb2Hwqn`nZ謹:T1G ΃kMGɟpP%I>k" _-Go7>GRUbc^-Z+}LA:־?^UhƲO/s4%Lm([pJ29`& 2Jde0ǵ el%AP]$^/c%zHaYS!w4`<?=\/Yغ`Ʈj'Rk^q(旘勳3Dms@:>t15Cp>z6;W,I5e )@]UW<2s.2.ˢ (%أh`7h?F#_v,> fR8|ïHd+)4.埪@dPƋ5/¬8;/[;?FibBZiOL7N!j uva7Pwrp;`(ԲaS;ThYU~f8d'4*Pɷ®#7i0O-'쬵<2-`[U@;TTGhyTq%j]WTFw^ynЎsqwCf4~SbyGQa1i1ܡhT̅] y|N/m7>;?1Vsܢӈgs:l0e}浜fGFw/|NqjHQ@uTeNu[4폙+ta#!eIIG%[˷j8j1'Wlrr>ieS*!UjM>//v!a|q^. @[ZeGfT~r𴎬a9b|ͅjy?Ctݟ gǫ?,| Lp0/(@G0rqZ . m>ipJ#yڰoa8SI7]ޙ{&}~Mhp/mÓg ~u ?ϫJ¿-a9x[VzTߝ[9d m9]ݾG?Fr q]9 NQw&nw͡C(0nMU7o*`O~D/FzsGVsPDiH,HL%78Yj҉ttfb"nWԘMّjSV+-(Ф }ZV!Ѭ֊{hv1jg7XC2PR?Uu(20vrF1A*bhU;{y&NmE]*K5s9xu!~ǡ5b{"z"KL:j Lsܓq#fhS(GD!}v5#cgU>cYDGT+bT1BuЪDTL&w=cIL yRi87=:]t')W!*0cAS|y &.3 pc PA&OERY`cD/qWaNXE8ҪLv 8tl;Sn B -$/g`)p$lnjb]3Crڏa9F53ޖvo$Kz$8A{>.GTH^=mi32͚^kAx9/Ҙ ?iJ97˜ݚ]inB^Lfv¤ʈk%1vnJoWXHjY>ggi"H4$ozbH|ʼn$"#E)RhalB\!z;Qh{'; X`aH.SSt3$@4GHDyN201= ap8>1kZeH̨ӌWlJ-3wY73e*hT}zy8Vhɥc@%c2^MS""PA 1qij7F-Q45?qEj/KgǦ*2p-$A\ D4sH g> 0F*q!dˏ3Ys luoTR6qx01_%txTI+.Ւp}0^A~:cpӚKmrӊZ4q(L}M<='6] kp#-LKbVBϢ;(m{dY[X8j2kVNnwBFdH/WUȉhQWƾ7v_+ (Ox(B zS׼lZrA+MXφ Ӝl O.A,lDãյqݿ`vW N6X  ˘\*PWZ?͗6>-k$#2Jf ZI1h.9.jZGS&E<* rl'!>j>lB'N1_y#Da^#H9. ՄB8qT8@Z׈?)l)4W6Do . γ! 21ҫ؏bAF! ~".7OPUSa*#̰7,+ll-4cM &W=l5;D:mX938s6UEb6b5X[w$&d|odX¥HGq=vTJŠlzҲTM;6 &֡722eVU5,qQpv폺q'sl#o64#|Ŏ:нԐAD5ic{j*%0.rޥ >O,ňߢWQcZ Y]FKY+ BsI1e+iV!\e])KBjpx̙j=&\ݜ*08띏؅x0hH2)*MKw/++!p|BH#O:5LABSRc'\z׎W&gZS;WNDӓ4p@ch~Vrbx"3\dmi_%=)@aWSN]/ʯkvw!=8ٳ^iD)l͍zy%+_wȢ+KUPvjD0fО$^]Ĉl4=0_'„DGtx$%dhϾ?24,xbeO+ dm7~Ƈʬ@S|gYoRՊf38siJݜ2Ý; }[<1n.t6>:#{N7H k#`рa0΢&@-R_Aa"dF@*'fӡ$r}6ag VWj/l{;ӧVg`Y=cԉ-igm$rX+ &Bs 5Xs JuzR%W) J^ Kl!7ѭ%X!~OE ^ T* Ai_1)1{ߧ?{1l& h="3ܻ: !R=+U)Z  %14vꮶ\.s^GaG}!xu)ai:.aL Ό40)l6޵iI kA0ձ-Vu-gL'{Sӭ^ `}B\iu v :y>6_#MCAgzX4rfk?Eu)@_D>0EۺQrXcBL!Cgfs7`ujI n?Rxޙ[S}I6v WFνcG'{kRF/:u|_tq+ L$K9LBkCܬOmH\ŶBŖ@yBz%H`a؆N@F4_~_W-MfY,Oz#Kd(w5vm &oP\שQN+ɔ.Cg9J@i5@k N';W/ [ DVXDYxh6{X;E&`M4FBnT_Vc2(,!FZ礣8 dE-YϗK7ִLw!H n*{bGT5PqB_I5nwU-oγ^y]2sʃ)$AjR*HFނ2sOq|PձGF5 ϡWxY-*Fj͋-zHMt\VIcMus(PyGw35Lʢ&-G |DDMn0V,0Z]SyB䒩 |JcNCAPa8O/t~k*ݰ|bXbisIWZʢI]awnh sa29u׃@7rY.;ܘ&8&!NYk073l"rS@`N -,G=/JoJ0@[*4`&IU ܖ̔ވo=txήN({z}ګ[1{2"}~{G !Kqן>-gpI7Fc׃ g(>#K0rf,kRc:R$KQ/|Z($w%5 =$ d^}M,M MBA]lq^bNԺ)yyI^(!o89x+%v@a`@m@^*թ %wp[٭ahDS~ h f[R`*i R/rxgї 3$^5*.8Xݴrv&[rz sbbg~@Kn ξɐiWK< ;Te yA327(MǕ<NmTQd|ErxJO ẂA Y{B%~1 Ǖ}`ybO,}cgk>;2iH#H6 ud#|bP\%3BɈSX1,% I``muk ҬL槥 z[0rp+J҆2gߠ vZ銛\`ۄe~p4n-C8nƿ@xCOa4f9Uq9Ki5m;~ FIaDZNEdu]^2抏[@LF TR(fu7VLԺ*VDV˩~eJ(xGW|>8{/z!2`9 В"+ą$>rq^\R9l-"qJg|ޥd3cs|Y;P0=@mZO~$!)`Ek v Fd)W!`*F jQ74`( L7vhLܷ YmΑᆎ*ZnaNђ8!XZ2b=AE8">=ߴ[1 =\ze~gDNZLĜX%刵b #m}r0΢CZZE9Α'h2z`qO)Y"oBti1"{k "Ty7NdN]j)IJ^ [~b7CJ X\M>ٲ/L97.Eo)3,ىm0tRXs7)_%6d UE!>^h"y_*fPd+υ dpzOd6+z:  eY.=$E`LNv1tKtc v3_ Q9( :";9K`jhɎ+YYp_r>|%2{}C Dv֥# ӕ)>}fH,}t^lEeh > W-Y6?v߳Y:*{6Lei7*b&gWm؎#'\Wd4Gf ׺oнZ8,:{A=e s|_ TS$=&?y=NMXC/ j&xB]](!ix,]ۃR i"أ[U)/:؟?Wl㶪r){1'-L8 }QSjC5BVlS|Zk=#^9'}X|=0hzC5, ŧJ5]pڠ$ydA (3 [{i\: k=_vA~pɯmB<5<Ԯ$:w_9؃a$"= F$Q8bzyY8"H@s~:SuTHOr9Ȼ)r,4$je)z< ch*Rfzc9)y & T`P"at0zeX+ӣm@eF2ܸSsf˸nh+َS8i+7xPR[E0x.O4[RueEkKZ guM n Ӑ+5c6l8pVwk{hFkuefkgOGNY>T99P3S6jEٗ]=vdN1 a$^4@+h&aN $1a$_BJزd&R<8Ύ !Я<3xa #vʹ7\:)2B6۫ *]FA(D7}7;AшԂu1=4JB"./`Hqp=7ҷ:Q$t| sYDYkg3mL/ÓƂ!I _EbUVNO m1̗Gc۴ U]I3Y9ݶ݋lR.?E`PzSa wo2>U~qPAZeg5in]WáK=+n]Kkg=dⷷPs]I-2co=1 Ȼ.3d~S{>ap*p(P1 VyH,?䦝7v] :G8ǭ|h?$'f2g۟kDݧla^SkVbcZ=iif 9C @S%#Ro$b.ª ]ǔOkA:tCwVjsɉHr,jǀ)Űo!3qh\ h\ٽU̦u$@]{;AQ&(!@Cy}fNN2iU ;727Y3jlp.+uuOY+cM$L(4<, {1go 0 BʀwKy㑶lZ!Θtݐ;@݅VH'x '׿폸U߹,OWs*œbEoэѿ彩lUYθ ; V<8X%t^RyKs2kmVޛbl 3Ggl&-gSL{QMJ,Uu_EvGӝXGY%,_AhEt}_9*Srվ[yn5WZxPyd2CGyg7ӟЉE~Ģv B.( 3i+"yX##\hZRy$*B#hH8]k/803dgRr #VݹVrFZ%HZvmџ\r}psq?L;5jgQ$0@L$-x@,52!ȿ&X} um1rLK%ziDR' fdNbHsPB҂ nPGrQ68LõLԶELP12>L<qIroV@'Ԙܗɜkz1'DΓw5Ǣ,+ڤzO(#M?zxE+GO+`V9li] 6 3 &w`P!)zٔA 5p*n^"LLh$ qͣqPnNPz6e&|3#~/!zGLfb *2Ab-5y3"лbvÁ{RDJ/nCm4v3$-x5Vir*X562gc6Nc F0&,A ]˥0N4,ώfUמE9[Z7yUj˳pn6@4/XpTS8\t$G=]qOoy#(̎vČ5$԰Vxoj2g"ΰ S Hܥo$i޻dTݧN`:/RIT=}S5ң myfsTh؈sfյqò9"Brŵkuk$/ǔG踉>BV o2zΔc[>'3hoD%16'uK3宍pkt]qf GCVFģ}qI{ƸS$:֛zX{:TR{AhO0o ɫ;4 *AT2 y^SҷTEߙSCfUc4ueTjL Zjf3Pt3v֜Rh}\v usW<+%l~Dn Be7|4>gl(gr 2Pm'IԖP=j S%cWOV;g~_N rI±,sCV2x>Gql0.T#buR4Ʀ1mx}T^f~}+aN>VZqR { 3)2{Lt~)v7%k&Tj `da@T{V>x.}"Щ5g^q-$MIn+εOT=lمϿEIu9Roۺ8 ĴƱ5E3BTD;[-g,qʡdx= >G,"!(Y,#/ǝ_$&l_ޒ~ʁh7 RBL@ & Uef!Ch@ˌ61=ip~9:%~rn?rҫ 6iO kMODp }ωב{ܒ s£fQ8BQlIE%\}0hP2F+.|x;Vtm;%8${DLwe7.&s<8MXOe_3"nCDfIV*CR?JH]Ʌ(V&i-y3^&Kk^0wqvvx7]zcxtOHV\I^)lyW@+zۃɃs4Dfa'9 أd۵LGR溅Q X 3f\ٙ`4&<'(P/D  c1XɽlWgwèqJ$.H77]DF?U(Ml 5%|NjhߵtKjuNA8#ruA_,T+w|LW #\}ui[J&ӒӍZɉr/_*ÉAU\qkZKcLd FjQ6ľ8uΌ")Ȑ[&NaAb-ֈhCDXfD5vX|yY `>,<85**bۚte c={"cw}?`eӻkxWzouaA۲ai6Uښ8\dG1w\b2A""f ޥ7Q#7ssm wD}>G )b3*C^++^rPe~OmQ^qIz[鼍MXW!M d'OG:2n,aWC/r*\Z@vտ,T=4~Vw 9* {1x-sַoW dHE[Sy@"}K )3K2ݹgOuc4k,~ =ދXydǙw w{Q aM"fAhwF*R܊`ORՃ J9Hxn}ek}Řo;VtډN.lX=.JT#Ԗk0+C 9C.ͿjkR}KoC=XUخzN( kr#K? ?c>k|-҅b'7A3s֝1<J mrӰ=?_PALjO'LwX*4' dQ͸cJ:v;|*3EkH&ŝ5rT_Skzp_"CӔ zi`2tMǙزLw[?g|7̺PC;.>8xF9Ż:8YG_Ews#U{S c_|YU5nȏ4I#|nghDrEŮCE}g?vOY#Ϡ%vTYMB-y)ccV8ǔ0@;^Ew" zʛ<@#~^єlr&u幵$mKC'7Oż;P" _2] r2ePOd)S8 Ӟ3'Ը2Qȿ%گ'`+< ~MWn[@ZǻpVp˛1ͷ?rJc]{N郺H|/ܭmԶZVu|,ʂP`a|pItb7}R Vgχ_.X ɖC;0b=o+F2``L) o'LOˆ 1'SaUK;4zLJ{T>57LE2c7^͉€eeh(' g=a@|C!L4f6)A UF; ƒi}~[P0:' 9h>VIy8 {,We]3U\ms9eifQMEXmk0|3B m0+/P$G+?a[E͊9,ѤN(kw|/E7IO.&;cƓpl9)9\ Yj<1{%%WqNV 6T?qhe z$d4F߱4-נ#-U&F^'H޷f''.\tAΜW/qz]ͥipܪ= `U+Sm衲щ54KT[C5,'kq~`97zD @>cu~d@dyl oю@\',r ^3cxH&7ӂWDQsݓ_ 魃F@7بB|"ٻ eorZ97D¼W鑺vwM<. `]:\F?ƗvtrTn?*Q!)kçt^c9þR$_!?`SróU*+]:_:9Ƣ eSlM(>DD(Z%u\Bh×,tĝ P%^Me=gs:gf8(]\Q\eG{N>1 dkDS"[.!=swv{bʱkPjf!ؤFuS2\;vrL f;BաYhb B+o\ kNy4q sM3iUJ}Î;AepßR W<0m|#E}]B2z%f(15"Wˬ#\w|.[8lL+ožuv'#!y8ѡ^Ǝyl*|]q+.jMP6ϔK>U&z Srr1OK 7m0]=tb~i.g\q_mj)\뻾ƥF&C!wp <Ҋ,E#YD~ ^%9 D,o{}DO#ױVPp+EvniGV]" &7N˸IT,*{s%1K2G "p& ^W(DH`э-ti.'?4PBwh7%ɮ ]y\E S .8~pccaЈ fFst #Sq,k)Ȕ֒2ʤh0l=AWI2E}HBHSx$''`oSD1-tiWfR@.h!1w4UJd`{ lmi_ t|&D!\`";ì7@_A]ȓ0~ƝNX|5qrܛb3BI!s\nZ49`drV=RcĦ[ט3V<jrzP홫PDҹjl!y!ÚFƷe*XS 4ѮTEbضU33_WhdV g2Q"Vܿ1cɘax {ڕA(TMh'S@|fF\sE X 4;Hz U3}sF=+ ש!¶V$f"V1VӫTI[:#Qid; FU5.lZl;fq e9n䁦DjV70uϽA,z)YZf $d|!ԃ ON&95\@Tȝ>jj[=KE).8\N%rOPf)#>QUv4)ajH"otUpJ&m[lXL>l.o.q3Ci̹kh .p."eZ}!<y&JwpNڀP4B}kV'761=M+^./!<쬅 >0 h<ЖEد?{ۋngvD1R#e/=0BW@aq}4R"mR`#*K*VuUtTlȸ1S% M &y]8 D^džM~"Q;AQjD9}!Vw]Vl29ߠ2=L|N!~ ً͕~wը.p!nIAۈCxdAQT;]qOw3:%$/lA+F`> V,u;r 9 HÄˡ+t:[%>&G -%zW&Z3NYk*҆i}Y/g Mr*`drжMA~;黺x3آ`2p ŔEzdQn}*ŰG./1MH"DM`RBibdTkXѠL:*':*^B‘-p0Bnpg+5)8'OhVc36ϰlo#" 4ZR.i{z NyZ= eUY}$U.x- Bb[k.KO̟^ΎQrVܜf5Q_qfpuL" %)X&.>C$df"yv]끈_#DB, >4D7RB;쐬VCF Xv|T6_!-+ؐHcIIâVT~(s^Jxb~oVy?]$쨔G0}_PsRGdû^-\i]>'mnCh Pϴ$SXgik_L5pO"J^YG1hwJ8Y)9ûԯ" w$Nfa$都M܋ қ:U DiOTAHQ/5 ^x4d'XrT?)48R<. 3G Ԟ#/u_ 4>ru=xb<;]s݋I C<"[׶h]k :g"e_ȁ yp1ҏoi_Qcu&{^5MIl0S#p2F^`T*QjO pʇ#C<?i"m5d0.~ht Hj'~䥒4GN?Ă1ⶻ[Qm>GG t<P$[5p~ L~6Bs+sYyPy,`?E?))@3"nSv@1U/fcf}' t;zHWRo6J"R,PHMy)Ph]!Զ]=}Zn__2:R& /v 2$]6F.vέtãw{ ȟvQ3M⡟^B^V)W'$w-2RmXo5N 'E4zСC&qLJ`u@E7v))t2{ęzxQAT>6Hl}qSM{Z5@hCMk.- ~sbɣzuE#"mWCIRnRg?%9Kg]A6%[_BZTH`94[KuK'?{z0-\9-.d_(S(M-Bb fևƝkh<}]r Ό }s b@X#]wKE|Lf( N㣖hFo v9&pi Cn@YOلS^}yIzUaڞO"Nx.Woę%?rP] qQ@oi 1Q(Gl &=_*&7WF~y~fiۘyBsxOYH:\89bEvˣř5xg6aƧj K8FTK^B iK0t<׸r6o+d/}XWWз űU*LqHDP/f'}iIkU>?5#k >9u]{,fA}YbQ/l.-A8*J;6m|e4?D`;m;vp%j%}Wxͼl&kA" ףT>/@+]c75{8rV奉 Vq=8b%"Iek@8AUWW۬7Z{'l3iX*D$ wC}Ն v"5NNCBo_I/;N&ڣp[[N5qjC>]z]HsL3QG8PG֡:?ܫ|}y43ojfMBmfCAy0mo@X%y"M,E4EPlt)x @Qt ZtT :8NP:Jsm9#Xg4R:R O* 2\.+$p?#=Qy}8n3& [| _M{RjX[^x4giz`"4gA5 "96KZ$_'vfrWx gx!aW[nrrG"h1o,Oˣ9-bW͋{.o=@JuWF&t͵& {y@$XOkgQ_!<3pq:VnpS< $Gd1=ECG5sx2,Nv{E=elvwL5;WX4+<7XwDMg?[9dpG) UO-P{o4QU+Ќ>% W1{ mE-.O/%Hѹ'h#y-1]tGZɒYJ>y<[O=~hf>̰Gۉtg?MCơL",37QaVӠ:'GG 1PFjT;$ܼap;6<{.!Q/HЮ˅ ePTA;#i*`h2 qax*)0'Wr'-VKĠr צ~'Lgn4&ghi@v(HYF;t))P)QIp% p $@#HLA"DUA}Ͻ -y<]~*\#b 2V9ʸ0=s|Bʺ"gް e }.DxR 3Fk[X-hNR`C 3fP ŏ|q:YR 7QI+2BP&=FT S%!B?핼?Vne;1b4b'ZsTLjag@XAB;vS :vV.zW8g Rl)c$߲"@qԭgxp#cz>pnh >0.sW.:<;9Q2HK\H4˟[yGk+S74~pɼC¤n6OkݼZũIk։T1c$osF[ؐ3 6Ler3q0|L1,zUOJoV6ƽ@k/F߶*p:I4T" f,gŧUj-S `ٕIê[999tD޷R8  nL\RARO;%o֚Om0N%||%C.fPw{zmiVp̈OO=QE! [)1^@=㭛=5e>/v- K9UKC=Bi^Iة4G6-dCC׃]1k,p4_M ^1픅g=1,2v1)|B Ɗ*궗4.R`S]5 AhK~o,ԉYg$.7F~LJ*4IC5,G""b/:ISEFwQtj-'\@F^maW u<NJӷ!\7^k2, p/ |T,^)~4 EI#_h6$*7x B N¸rա`= mȚ֬o/@htmtrβaΗWK5Q"\P|r~?nߑUz>*d0LgG/3^6 $D9͇{ݔwIL='S}V]t$)gvgvmjXqo(>!r]`del{v1ny޿CfNm^E%8L5 0-gihDFe < ! Ƽ? `˵ɨ9GcFmaecY:끵&ptf!?su[={gW4dNЙVo\mg)eڨdF,4}TfP}w r !?aUBm^Smg]MI`nyŭ S,m2HM"Ԃ+oD<,AϔJuafMf5&JꏅP6ծVb/޺K*$ V'`6hw+eko,jQ5'5!͛27KYҘ72k,Z D8>S=<}XY1 EGJ<ݮ"T pf0Ċ&98h"cLS|v7gXC(\0+^K,RXjNe1oO XQs-E)!W+vS li!Fs~HגLs>H<л_,}JH YN]9v+]Qs2'S Ң-Vcllܬ8)7q[/ gUen}>.(mtvuo!PŇ;bͶ{! [ vGLg/#k5{c`a4"˦9Skp͹NA.E/ yT{ 0D!q+)g8b eOؿ z#}<7򥯺]cY6FBQ ÃWe5DƠ'.+3c}bg9;L,</T@BG Ã)*J.n@B0#MLs螇f_&]F#:g_rP?)+xEg.f_<:ǬGp(!MśȈ۽AFfJy'97vz! _h;'e5iG"y WcL1ry2b#i1_9# ftFSšʲ ]&ݠ SP{PhƾVQBS)2H Pu:~] >[m|cUũuf`y?x>?wdrX,x4zbDP?\S:q% {6#mA8.|'~}lv2?WЪ*I'dT컸T%@S6O$8 A~KD|4&VM:t~7Gm[#(ܠa@i-VШSGt52 BqFΦr.xr1cblUQ`*َ] ׽*\bSqgT# ¾ZPmd'I`h;δ62iVVn*5QWi6pP y/@} X@D)Z_!),SŖ! r dbY;hۿq1RSp|UN&~hE8'oG:vQ``Od.Z_Htl|8^.E/^f>9mxvO$kŧE_8ح.UJ{d$3w100卟*ќj&"[Ʈv78_`"KJ۫GQHCniaڦ!c=JFrI%֜ 0Ū"J6QHxjV40-*e QѿuR/ߟ($G<8vdi9uV7ˍB+džBu3.Mq/5]`7ʀ0` (?GZ}Nf(#!з),}ެ%mёPjYD$p2J +EX:|=í-Q3lV6tN}q4[!WxNW %E~D*0/gh)J1ͨ'S{F1cyC2kAg.hO[fB*cRsɸ (#d9A:swԼEk XKh^W4e߁TZ߹tJš{+pG%̈ۃ}s8`zCCeɱ4Xw }iJyߵme}nG~.Sxk-nÝvbwuq s*ɄQEEu{Gq|3QBd k)Fxqm1e&HWcRS^+V{4ڄ70[upm: 23^!aPtˌx`vM "9E#`&O*v}V'4든ܜW+e)Kv낱ojոK( =Q1\18` $&iȠ`4[8#k_^d MAAQ8ؚ_( w:iL7iS :W\2s~+1-,~;.r Ki|o^*^\Q6n=;mz<5fp߀K$c'B+^Y;Bbc}מ t7=S3lq;T!Ԏn`~!|j孟~ԅ/"wKqBwL&()%Xb^0t޸#+&7S[×ELC"0Wb;/QEOnڦN$G}fЂֺPeǯ<?\㎀[QXhq&N®;{k-zMw".9%Yӝ%Hc{EIk铅Iv&po&q!N[rLTC0Y7>>PkL:u>oۡSžmr+U0Siu'R3 1Lf"ѱҟ<]΍UFK)j3ƟD^ڇ|tf%,T 1 HydDVybr 7.Ό 8p^ M'CP-\T&>̋„RQ tv 3J O*sm?!|1%b".ZB\86=2WfVGc\gگ#3Lܩ<Awhkd9M^|'ao٦HU$z:Xk{gY%N7kJw =0c۔pTʬve'L\X4iOph9';I9$n"npѬuzzG[+j敧[oWun}62~4@{-V=&%`> |+us d*9B,JO"#2 OLY4^Q-.%Z[`m6: U^G;2:*zhiѕ)\v{hdưgo.35(5=zSCb›$ tяf!(KN"5wύ8Ԁ *x# D朷#J uidm xAtwj}`eC&5̈Sєna:Nkf|ݶ%=A*o:W&iUca4>Dw1isPaPuF(tEM7ǪMQUP*K\ 6i@?Ȱ,,KQkU5+Q-,q-˻T}cϻì~Sh̖\ƈ^Di$  Za&`o܂텓RP(e!g₇sA\+ȱ=ˮ%|WIq#Mx{=ąbgoke#At0~4ۤhb7?J˽=1Zf&r?|6rPPĕY-jxUFEm_IrF8'{oOWP6PJ;JfI3hGm4D +Su?ۜBϽ L1;.Ʋ=pl*cHk{Qs{-'u!4,μ׵i9*gozxW ȰXǬAY4Ć9y3E~V ]3g a'}R_QI[w ̡282b")=G瞭=Ī/w1m0Y]u\ Ky@bQnkݦ[O_Ţ#6n=Q<')ANmna2[zKip°21'C8C>#ݼTRcB&3.TY=ݓǛKo+WA? /1>! Ց;OJopj9Nyyx- !@EVMP SѵfӁȻEhӁxB/Վ+>AƝLjfPZ zxn^H377DBx̎9X:@] d(Dtۻ)niVru&S|G.\yU8 ~x⯎CI-`hN7$+#T":{b?C_rSOXV9W28n\!FriNNC͠hQ1z^fE7KۀM13@nm?'^{;GMXOIH!$qCS}̗K\ٓ? + ڠn=|1#zr賸8' 8 lfQ`Bnb%#M1oλz%ܳbӈ3^, @Tn T!o,ۼO:1R=XoB 3y<|F_PI'? m:]bUD Z˜yBuDKTjtxOa\ܫԐ?ġ RڔwJP؋JK^ВHnCoLfk?:6xN=p"577+vSF=A߹}0&vk4okA/hƏW<}vg8"\ yW9dq Gwm#'XZdHl;^+o_AHA ge@0g1 %hcĹODl{D jR_Zzp_k&H+:[jf־5/Xg uj"7ܢL۬ p+ofyF-yzE2E-9ؑێwvȜ@ 0N roB}T"}k  9o˵~oIk@unw >3pv {i;څ7 _ՂV_>:/Yd6:F\" g4VdjT×uEa0Zi;5 zc։~%/ƲoT 9tQiWqݒbm9]g(9} AZI]Y4D˶M]R fE-%Y\(8˒ihSym}HN|JRv3v7<4XYOzlx#+9;gh^_.㗂ow=K1[S8[s^N 'n13 h:{z$ĒK!޽^\Iw@'8i=cb&jgj',,#gÿm2;T;QmDOo6"e ݌Med BARl:hkxWzj?ͺXoEBȡjl tA۠#e!1(-qiLCCQ*}\h^ VG-npvzсc!)FB.G LZ3.aB/3MEL6wa:DzsξVA%-:La=%&|=%,er̼; 3Km!^e-JBECA8Pre="QЃhg[.i7xB\h{)(I8&Bŭ+3 6g\'f Ǔ#R.G27Z34~!.%+gfP;cnbj-"0eB͐~e:|*} Tygap )91 ߞ*=`m_3U=,[/A$Տ0w[O>؋4B9]Y_U~ϴzdojdnOTta'~7ng Wf|ci'$9FV am"dbWڧXe2QHp爕mV ,nLnq2@`=K㶭Ơ\f [Tt2(Zc&f,-$M CP8_V EknUi.[JI>Qo/o/^NO8 b۰&ZFij=xm`VoϚc)";Y~ژCa1aIa1JK8Nݒ7{;`K""zLSW.JIh{ahcG'Tf]|cSx3;zn󧪙VU8*~98orLrxO#˨\l 2+L=;#5gNaagyLJ*)ޒoo ūL3oN-djU\}~&~Rٴnќ#Op׌P{XI.g q7R{XZ0JѱbpJعpכ>|*c>'>8~`yA-U@G.},"ݘ4;My<\̓.Vg..Z_ ﹪( f@۝?mdYQ%)b_ILz7? NZ奋Z/^?UVSغv\z:}C@5*ß#e}tH)3~E{2#nP),z:d4?C?Mc{s>1 ] [_x#} \%,Քb[xGXW=q?=oCdQn{Ď\srj0k,##[ Xj=R!5}ݫ'"No_y攦r+o 1ۇ6=Y(y(Ǔw.4rkD|)9.gL+HHJ"l{wlsgJɿQ:eP,o;.G8sxn"˻&WGG }3zgt4V^CS؇$(Ba 軰@6J*캹5GmF#6lA^i7V]c|Bէ  5=W/\gi`sg]$-d 0[Sg7w_b9@άPsU&.ㇰ4G*',?0cxJC/Dh7J8 '(W[3P\mR a,lv]WAƱtcă9TIҨb>m?C+4m)wXrA$:Ԁ/'\_;Jo}ik]-vVi -"NU7W"ąY?|ԅe-x eE&N幈_77iN@@- d6@y_R$b7%Wpe}GpUBja(. D0+ !u!rϦl4npXYmWr^5A~ yEcEZo,^2$0l~|hE_K2[͞.]+W&DvRA lU G ATDAi{#$|e;=#a8T|e2OK*r/bdO:QODˡF>WGc9ps%<#n!s'jpS EئDf*3c16ё.pmx-)|uB%qZA~U78aGBWٿ{w,]HgtS`1Z!cu"ʼ<>(F¹۞]pYC9}uT3Dl:O@(ͱ*!VAhnYL9H?=虋}TWɜy<$Xahd!\h.%_JH,zZe Iiո$ɥ}1 m/?RTH +!nz;1?,Ƚ&j~Ocn;U ^Gn KP'k~eX[һ{jR~GB}U<[p>UJ,hy~- eSVwn?l~d)gVc@w0-D̟])ho2lDЕj~;AMP}خb`/ @ 3ُFgݜɤv[-0#Rg]_chC6OQk1jyX .yvdz+&+ߚT)-9E+s HVj o 1g:FcCW:$P8:áIh̚v3^m7x5ݩbَ/2Rc]R{ "+㲫8mQMjǴ텉o+)u>;Eg?.0T[G?gH7%e=؏6i_G)}9Kzou*)^xOw=5,s=BcқJInbJF(&E?$ E.7w:ZEG(gMMrxOos6 x  c]K̥|/訵0MD|)m@W2(K"fSN6`u%vk %Ō>X}/$*gX~:p:JCg 'ECCW_( G5; Z4g^@7TMwA/r`'M Jza|_O(l˜ }JL +y;3Dkg87ZHМHGN2 }B3n&vkb[nvϙE7<gB#v " x5yaS8ɼY#dah +|Zpm!`2~ꭀDpj~d'c&YSxg+m` W|χFZ _VӸCnyL$I+̄=t#Q0A#ֽJH2%ns;J+>N6qSrTF:Q%zWKL34K$\2$Ǧ|zdY^[J~Wi $y2T9U T|kN*"CG.ήkz IzlVIM贅)Z+F,K+PW~qi1;ۋ3E86ƧE7YgE~ʍ EfLJe @n#%ۅ=*6E} EC!p%N{ClhvU+3 :cSnפzn&ˌfqR6'jOTA+tuY]I&IUҦ~l5NVlrC=d: &Z?|1et,+͒>4@.E~+ tT7A0e35L˹!_-fIeZ#_1~%cC*2AB+K{T"Dü}'ֲogj_k[w^!8,A p5*}d$dcNeYƤga5l{,7C)wjlUFfrT^Hi սfP+G*7ks$yڨt8j ˡO_^r Ar!`^̺]BN#:GѼ'+=BΧ ݉ySd;̸p>zQ[ T&>+BϺ._YBic4,)t4jd /,%+5+-jĜkO=kiBϢY'-22iM0l((ZM~Բ|%{GBzelsqJxF Je<;c::zaP_,5Ƞ.T;4z%=ȔojӆnY$3Y1j@.LgXKj7d4ʼ9A\ n zt~>o+tmur @HuװM94jcH=(!QtẂᚫ X4 5$i ҙ$ Ok9 d0m[j:GSxהT۠3lbdX* 5"V]> S 67hߏc [41Z! Z|3{T^\+cH3i<7vM" XT2𰜫{MqodzY`Ya/hk U`BWϏA$ z={ 5ŤmQ< 8mFENHUÍ[\ǪVZ"2{悦*LFaK\-+$@YE`=s!wz̵]PX&:j fhZ.IS,HU=Ǥ8>1?4I9?øwڃb%2,XKJj(ƕ(!kKUso!|Fe? ŅLtK|P CK gDrWvlDP=9B*ӂN-9AƩCpXkDc8Z000 XL {Su^@963ìCD2į;-!X׳"tA@<_i2'F<Lpyۮ>x߫YY`%Q25Vیn_f0>dB?ֻWpdNB`ԝV`f3뻣k@'ñGKXPc w&v{la(Dߘz[=Zx(+7KK4 mE 3rN{Al^[2|-L?GHS B+SS,t0Aa=RM%} #q'4M} (幮% G[IJ '5ne/8w pGuz:c\uc3c;T*[2 ]^V\Yrx}*ڞ/2}V-s1cn){z"$T-Trb/-"aa/r~|ܤ^#$e%S]딥/6-#Y' Nn`)ߋP:e$BYખKWIEݺ61u-?L6bΰKiIaUK*#sHxK# "!G3d%](_7!7I~H! wڑ0/t&=('~#zX87շpF?x,w[i5|M7w;OENjX7,/gh{]<-K0ߣ6Z'%<דWEj%q8f@*ȯWPWvr|%Q:O^O\gdib`zg "z1bH…Wy\eIg`m=k_|zvOdUl%aa;R'U'W Źd^ #9$)p]a-o2i(ʓ%Ͷ|7R\宜U(LHѮW0J$wB$d2;RO[zXϾfڙ- *IRUEkZ1 ~󱱃D)ĵ֌Inm5 C@ 562ap^_;(6cȫ\7~kp;0E*ShSpǼn;M78Qc9u{,fQF\ [S 8p)#-ԫt짼&y3!v g7jlS!S`~0Q(as4')\TjClA,.pT)\k cKcMg߫SBA`{y HZbVaَ(;nsvѡ6LZ2[C#TTb3cOCL>"rMvۉ Sg؂X`98ʍy3R^i YghÜC6ވ]eͰnȥFR rSA~gsf@ =r ڳ悩mR(`)wd=hZ#\KzX((Q'ŝ ,]f%AJܰ3?Ap,>Zñ7B%ί |1 } llNIyT:^h5I!]60Zx2zåJtjD=$[r]C%wk'HJϘAjw[/0*A5z(C+7?߆|b=uW6 @P8< ?)Xsc丗a g }#;0vjRIlb'1 :ݐ*xh9Mmu U{s6}SFu W aG J=".XPf2ѨGv#4[Q& %|x+,Iv_ibjg}E6^yr9m!/,l YH ]y(+gf3]>paE8Z):mPhM;5 ^–.+4}W7\TP}\ I\}iTb3 mH}cvV+01>9TtsgdoKb|ۛ qւYazNM^uo  X’.8`,8sK¸j} x";X.3kdPꞸ(芼nxFy#I(Ev3(veڢOJC)`(0k?B ,In(:'c >'iUN?!oSmnP5s %x0~(GҨB&޴5wWKpPMFa?VHAKDUpն'F]\"0'>e 4m%|wT?qXׁ^Ti7QFY:]eAW"ô;s UdB4X6/-vð(CE>d`Δg_—rGk֯Pz2Ev+G̝BB4~@U<Xws,R畱>~}%J",NG&y,زA4JU J MĶH[tI=b$t$SdNm֋-bVMX96yҬ KG !敬k+v.muB|@ct/!x.=afH:o ߆Exx&'$QbfP5Ѳ;V'B.>O=+| GȒU::feb(x»9B{3מ:mN.xy 6"'/(,пϼЪ{yjGA >K60&nϳ! Ay iIa(t=/ZPvW,HtzYbJ5uOmrǨKܭOng\ %ӈW$;A<$),Ė9c>_Alg .Xˆb.V'BtMPɔ*$LIʾl׋<*Pʿ-Q|b>LVf}1B4 (l`&JWx[<"럙YƤHG=+ d wV 5p\|#d]ԤKVT.RbY-ϤkG ^4L d9}$ެx~+B-8upI9頵%0CM7@6Ҁʹ){Mz_ SfYYv/C8$W]B Q:x$OexId΃(c0l:k/w$+ l>L掘؇n&&JBS8 ǒf)j#%HdvZe3lWv3r&Q.9sKlXA`QDKԲITm|eyњG$;qn~ӐsO_giRXE9L'i[Fxn{[ӹbĺAMk\] Lv;U(9:^޿JWyAhuAYb+ׅ̏dH#Ѵ Ns=>p[Ͻ؍5LN]^m:=ngI0,LWUӹZt5[7Xme5+MQ;ˁ=zCͲU5ǝz+aD@fmSU< g&j)b͈<؁~9_M|-~ʴqV1 W?h NfN||Rmԭ=:qt ڑ%׸.m>b2j/9ˋM(_^'9{c/t\Hn[Rq&.NQQTe DQ8}U s q7Nc73|ڳa$J$U.~ ߳54pFzo EjLm$ ⵴^BJ\srф05:>Q2(U{ň\\8cjI5Q.nV"h'A*?Aw,6(6QoM)k#]Bd0Gͪ(r9憪Ec6`bJscJq\KV{uloӕbYu+j];0M{3 vQrSLBLH[p`|)H/=1~~5r|un qnԣm.l*'JuٵI#} B==ʶӧme^.mV݂/_Ut%~}Zg0As!C`i`!7v,nQ+ <dP?v,SuK# pθyyZf+⧂jڸH9a}ׅ7iJ'hLx#dgz"^T| d|{DErDzɸ= njYe㳋WR@Mk2 wa7)P΂¹lG\ҧ|R.[R;x SY+ɸ2_鿈$ބ./v%EW~i"\\if?RhyDב & ` 8Tc?=m&[D3XTV<ww!b9iA&Ж.X*{C%I7˱\,#!UШ d7.Inb62+fx'7p. 0l ٮTpbǒc `wѫ%V*`0pvnWS**T]y07BJGӪ`\;-ѹCIrJ% bl`K00:AΓ6ٱ]1cpϿq70f_7Pv yWlySh.n\CIlbI<L3IBMMcB\J/wE>y~5$q2ծE-@~7۲ 9)6olKƃu@]l fp2!&ϫ<+wDORNe2~j\* l ẄܮǸ!q,-ȟ_.6X)R+]@d K[=WTFHxҟ<Ҵ|rU)73R&Yr-]#?=KFxF;,'`XTo]*nνiN9-3寧~Hx4݇#|_Fo_~w fjmC9:6|.Ĥ?bZ]bɓ]oW@ҍ YP0E nḙGxpqkzz?MEZ/G3QQc/޻.qW>h>dUrɤ#2<av۟:(UQq2p'|T^Gr4BT+_u%/?8z⭮xeLh?&3AOҥJ!q؜0T*;AɣO̅8F$/+qޘ28Tλ]N90Dq:< |ZDLMBe=лJW;qYⵥܫ GML Bt2O8M V~vж( 6n";qQG,!6o8?ks`uDթ,#l4-*tS$BGY煻Yx&=\"[Wkg_A(K?Υq? /)GBDYY7%<<ɦFCj'Tv7*Ө25ح*B=;bg$o?/\}yfb/ F[x`̠d.;FY8W{<q}9~OXZqmڀe+#AL\reɣfᑕ(V'hQת8}Ni5\KhBy n=aeqXI<U+Uթ Z]M$(V>6>{ILߗ?J:^^KSZl'>,l FL\S UO4/`ʬ W7C( ݋#/02E fAle P,x`„zq~[_FB$Ɯczp.b[Os MKBF-a:4 4%oVVR f`L1¾^F=VwEEٗ^6<+ڶpMD2r98 Po-O4+{LK wְp ik5 ]3 Ⱥ ' E~G@%NRmybq8kn+Cb y,FΎmspJ,܈$>I/8 r, R)3t1Eask)]Cs,vr+h/t|輅=N`-û;W~h% 2VHYy1;M WNujڻ+o$=?d f*Z{4zPCE?ĆRjڻy o+lwy!i}4z[Ac[3D,rC틙FVS篳CUVLfpr쿿ZJL6+?. YļOEĚ%hgMMNĿbM8 j;}gh=Χa{0u#"j7"3&ټ 0i cħ]V};UA/㺻uy y]ּ>=FԣF2 *m6ߌnʺ\EτďwU>eyv#ޟ]H%"]u[v}>(2 쒥eLc`Q~N;kұ@. K~Ώ(X);ᮐv!a6#˼€r<4W*j> DPt<0@(팅98,GPǸ#?[Ǻm)2Yš k  R Z<^ބH*b"Pו+0^{6_0vcF'kwьr~ ڐxm>ay)JHfC7W~pл:.\:5C!4o.ݮzRY꾙np7}wk'cr{ZuuMv,"ǟOz o6$д7IOD'+FgO3lu ,x.Ν &Tc9 BM߮`kaO \3| oqILj{Qjj ~\Q-鳥FEkHV%`H?SHSCfrǜ$Mh{-j3HZ;ƬM<ڜ_-TZ$-Ww@o eMBbǁ \_)Qjh°bȅ;]M*,r;TF񚱾֙X_KQ^?E(co()9( pmUy6wJx;LIƊ' *kM3_ !"wřH7Y;^M3>H,}9y` Cǵ<qߊ'=9,-כFi+_n٣:g,iX^(]\0dd.>+AFf^Ŀ3qg^j\;|^b}|{k'/y)%Z sUͥUNwPe ikYM~f)7>i]c xs4-Ql+<)J"y;O୕ ?BN_.*Tvϙ71)ЀӕJyr P̙k7aɭdPV{2ڲcpc\@pVd^=h~Ճ}=gIv)DŽaTaX<0}yenkc\qԓ irypL[DWF53r1i]h~NP}p"<ḓyl@P7GrVAiGFo|` [m ^qtb}_7u r:4ɤr_:9ύwt:52meO*9]t1vGTN6ß!Qr+V`y PŧCϔT0nR VZfgxcgQ_Wq2ɰI ɔnl ^%`R+ e#60 έFz%]z`$K/$SGs(7DM1{\Urnj%TL#8FtpOFݱV< %l +myQ@L􈢎'4NIOZo0O'6.Ut\}3Ycc*?,:F~øV?BvNKK TLM.ly&i%&(;cNFHЁs%\ [, j}G. I͍u.,LuK k\2y/VOboYZG6ҟb㐔DLR:$7q 1H\~>lQ8c,:ZMAxԇMd&I%``zcU9ϔT:;_ -A j2&hE&>, Cv*w.D@6${"PP]~El᝖]XQ=v{)\H( iTs~8)δS?`#q2Ub0NWQ)DA&%)O97|x;s*dPvGƳF;!a*=j,Àz8AV?1\?4S4 ??T"Vh e^XI^$lĂdSժ+">Adm3w>9n!.ްziea'l4ws?>/SWt[ojB+&,0(4qfN F{}[t[D{]GbfUq )]N־f>w]{lN6BL24jnN+DCiWK%L T5lTUbݿ.:ˢBa%+0x2=*ф[Ǥn%Uܟܩ.ů$Y8%AyU?`n5{mimmC#. c\ȣj՞b-P 䖲\@pB~pl_nh߀egF& Sr:g~?LRwR9>\V$ ZCu/d/z#>msWj2F{䇯z)waF s/TD]+52Liy7>4i{!Q/7( (==_Iz-d"Bk`R f y̗XgqÜ&&`\ޅ.M).U.߿-q,!Rk%N ,B nCGiM K6`7O0NҼq.\G-Z = {@g_rz- @ܥKĚJSX*GY?gG*pjg6 ԩ%!QGneO` Dh,;q5$Xr<:I/p!ƾ^B2w쒝b=3C7!R]$=+6m^>c]T/J2̺/wqEC. ;EX \?7UX"X5)]>k۪{:ʬl[3b0ki\e"*i^d(g}ϩ(Q.;֝%s_ %Ċ L)h N-#ӯ~waFqܒ1jS"&@Z< #3V/;(9*|F56Q,~O*diT6BܨWW[ZW(Δ# ~dM֭)_l-A8gبd^^#gޮ6 MސR8훤j~(-z5n%CLS<_+7EsV4ܣ8U!B-cI^L@؆\5g$į=L>?$GEH8=_P%\Gl JfrLzw`m<7E/!?n{v OUc[~TƃvZ!(cDŽݵwl{.b$R@ >ۄ3sijjxHdԎMAk /ûYzclH /=MLۤUFp ?ks.so?|uJը[;8S!}B3Py77=!~Š߽q yʛRi:y4]_'/#',[~Yy5zq΍B3ak*f}"CČZ*,ܠ^D?z/BzłWaCEm= t]3?X  Ge?ktGH(T):|k AKP-ѺOį9^VR\NY-o4G?`=Po]camBl+˚a ̙ID6z wÀCC$~$zE5Uͻr-['F7O}d =Q3<#/ f5L߼=A_m&JN 89 %J 0orxKE3KHnnֺaAϽ_fa^ ^Mۖc^[*p}ґ/K$lޡjХX z1?Ru8_w$ebjvRF Ś՚]xd+Eo9&Ndu9TNݕBw>jya<, f0_{?Z=N Ԇ}DDBAZ tm;P٦děG,ې1_pn]m]_'֫% ,  BT BJ^hΚ W>#&8 IF~.7HKn>VKZRWU"mtJB~ 0Bнf22e6GҍG%Z>_uRKI7K(ȩVܦO&q>Jz@ (hEHNLD ?!DF&(P^:g}7>0EL9ɫJs5}F}wnٱIGh*\ɺQ9W5*$3L:5PS>&0K:EFb6[xsD}-_V :) CK!5E=.ܚp `h–hTv~N# qsLQ6j6H#+?SwUPr~4D8G/ C91e6C@UdlH}K[vv8WWr*<~x'~u0ׁ#Z_OÙF!:Ϣ"v)#EZJ\<(L`alQۏ殥yguMo||A3&FyȦP}Hob`;늕`'qf5f fxHӲN^~FeVu5IphjVKYleU}?]–ˊ@L{݌5G*BkNZs'`SPC%ݚ]<,fIt*hJ~f6$P8WyvT\]%Ԛ)#uVi\fΗz2!Z*)Kx稲إ}4BٺdNFHTmsr3G-ִ*AرěXc|۲Ep`6SMEHBdI +4¾P#3pz "{FS`ŘthM{_oT\<\g9փgMWkcxsYp2 AlRmݐTД6k3"饮+֓e7{_e5-+P3 ^ٖ3D-kֆ gY12i_AugxPyL',CϚ[Cuφ><껥4 evD Y E|i;-}HJ< eCa 5 @MFG'H^"ŵ] ǚ{vk}y7R{, _eDc-eqeCPwk^"CAUNN@'ut-kmq˪2^ev8)H|2dNiQ5t8-h 'F|yrA(ʄ2>0|Q}:}LCkp 9Ի[͙=LaDGjgy!N 9*6?ZïB>p]Nl$TCmVc`V$P%qz$B?!ύJieјE!gw/LIx yL^i( a0sOG`о6lO Es{w#sh4;.cnwI^s7~1֔ޕ;0W>U!^x\ >ڠBek{K=Wu6g~?A$ У#: OT ^J8z4t+ɖs?5{ۜc0`0Jk%p ZIX*]:0-"Nw,b'dF_I_\oOLG}TM!k AM87;=f[Y0̷&p_֠sF<&ݕ2EJLu(qSȭB|ge'4P¢#;-,s~l`% pF`7 6}7Rj5=m-(]PT~f.t*>|84)(s=JC{NjJiar TIQ ӄv0qM<\V$/XkI4u&ԑҏђL l]=FTj m$./)qnf5m‹n)w0i}ߍa}íREӅ9ot]:q12҃ Žt䵛GnR}t:{q \[-`xa~&2r`hAOKCISdWZ$7k]5z /K 7 g\)Zu0t:J* P`@PއX{邺1s3# {[pE3l/`LQjŠI~WoQ*-ǐX쵞0@ =wRhpC/_<ѴOz=W#[k!!Gr:mKGi&s@UsE8W.]nU%{ N sfteK% 9I<3`L@z$WrY|젢zITKT.9\av9xx@fx)pNaۙ6\C_ѕϬ.B'x̹SJEgGEmQ_7?&P "2rpawQrJ$#{"C",˰A'atn^_AXC0Em=3:<67S -hb򛆯;ʟ2sގv)JiXB p˨r?oZК{DX~?ok+bO&)`=NXuxz?o eKg'S<8%kAM ';'6Ϯ5ؖ'T ָL.æKIm7Q!k=Z=dI@]hYsg}׈>iZ`ԡv*p}JtWjC`bQY u(TԇZ[r9DƖfz[TM%8>{7b7onD+j-9{@Mޯ'$O s3t0 %6Y-eO(a +*.z[],gg#MԠ)S@P  ]&(EJC`P48||IÖy!6"uu|62J)(b: +_(J=KSQ yf9RQ*tD UYT0oXZ6 G㼟VuQVĶ5{c%Pֿ8 g.W7d`he(>^CI9_?5gn8d.l|D1nw+i!9;tQ ,aH͌ko Vi`Mn8}4Hڴ>>*&u:XS"eɪK+6[ Eo@%Uo"Ob0 sǾxYr#!%묜Kz%Hy39{UT4vN8$ 2^7R.a;6k{t˒a8 º\,"q0hK#ڇYN.i$mR=]SrGw5j wLD%PHjKV\*R$3Ň&otyB."z+K^yIqi3*s+[Wt%CF'셚f1B ;8".p,؆nֻ8n="^>>0@W_98I.m t]Xr? ȶc|UZV !%Y^0ɺrec̥dR(=dNP_x HO064n)}&tW7"d'=廦63YUS J!T/Bhn+jhACb *Ud,hM"Л'Ļ&r":W8Rź$6^=HoehRTð?[^%]PA]82/;bw3lG M&;JK9f j",Z9B#|t(|:# 6`Qr'}PLH53Yc$%6;%q5 iV#)B-+LU(i_9#?AB9j͓LMN°$>g[!):M' -'ڿ-Ć"=ѪJYF歋_Η/USĎmq& JUD'uIaa=8eE|$@ ƫC }IͿ·@DRP]iL3nqhz96 GxxڰNA?!jcdpK-mE{gþ >bU(0lܪC|tYeRV^DjTPO!$}Ddq/U-a\Y?z1"&-BjvNp)_w߉ rc XJ.< Ji4Ռ#Ã"" -`?L3~s:x= r:9D#&NzM7 A*cI;& 5-剒 >:iS9\[.<@r~ddKA=YE5Y-=]~Ngip&@\t2qęy-:I&.U!e'ܰrlǐG\ۊ}9TA RzwC/zy ocQJ? C>Oc_R7BCCy9Nf"Jl0a ]?v|__o xꏭɖGfGE@wM # w֣)wT݁yGV( Xx93O6e`(\Kijd糕Q)*3 JP_{L/"J}N\VAb*>2G6EsO7Y4{ǟޜ ,r)˝yO57Z B B7\4.y7}ƹH)a)Vz MKb?Vwji`m=I5JZ*F|17Fq1'P}ީjd YxZ2h* XQ {XZB㣙[6ePgÍ֘ZZ)5-O忀G!?> ecfXGDf=5ngHrqI\w;YaPⅽ(8dtbTbN?t,c}oM"*2q~m's:l4{$ӈ3MO1V{9CdI0F V>?ZgN@P06g[(626xsVbxXՅӲz؎>^^R䛼tQKU"3|'[hL&T0΂eZch}ͬ5B4VBW.R[G1JGU\{&V*CQ>XsfFk _2zxZ"|gڮ ]w$,Op 4dm TP P#^V3 tMHEca,}desB{4@XֺBO6?|9;̪Q,)ؒ mMl6Pvw!+|f%w'//%>‚Hd-'g_S+)]ңWQT92CmuXjYCSkDI65 <ϱ"Mzn-޾k"H%l=QClg:mr݁]$"36D6ߝ =O3Cl.3S.y[ץJ;vjv1AcrrIn6ln:v:oK<4([QfS-/[;2>ZEUt L yՑEip/Qߒ!71wZ(1*w_o|&訾3a6 +x.U"0[yϘ}WkW؂c p$+7bbC5M؛@$=muFk@^D]˪oĜSzD4%17YěBV)L5Ǖ"͆9w xD3MhMC59#Ki0HY˂_߭خ?Ќj4^ıD<nVCβwD`ܾ ܓ*XLLNv/ >v%Šڐ7Ez$Sf|ggTآ,۸o1 A~x2=b~I3,Ue`¿l#$IJC-[gԒ0-Ph]e ^5!9ZMɳB4-CrGWT8 4ZXѲC#bj,ł5t<n'eϻ"Nu) zk[S`(sGsG\^ P',p GVMON>o hmPJ{)&zuBo,k *tlG"ǘYvh)(^]XKثیOS}hO +]JBdd884온~Fz*&7h 癬tl^7o, wxtu"s2lT^N&Q&avE7B (~^wKŬXO4Q4n).KKp&P1=` `N}z2tK27i퇡Jd2ӱ3IXq5dFڪ4 -+a[CxO@wi))/ωb4Ŷ(R#Q6sr!>['|e2N3bܼ|Rw$D#~;5 $[`(>r[( 'SpD99}>PFUeQU-$XؐF\1U|CATA-7cmkkF0+aE|׳+5>:e3:.4Gw4S& zf%ߵɼ'zFa+%R -V7\Nسl*f:MA >6'-2\\hx)A-A_ꎳWJw荥q ?%SwW3R_I]Z%K=co2Ti yڵim"o멦wdߊ56}PIߢ[qA\";ӵ`Ga27`a='GJzh.,$u1Ч(r*|Zg+@b{d$ iB@1)St#ΤYHOeTrp_:=qV1(Ƿ#S.~CE()ƘݸhtK1ݏ '%kg2CVtsviuhl̍\) U0O1u.5e|o .$c0l)"ҥvUaI*i JZ̐aCxhMzt\.}=clNRsQxm2oq%[- _/ G4\7RpW*Qa\s*S R~Wi2 <`e t4U|Z89sЮh|EƖVzܸ.uoWv:lwU0W$Rۧuw6 ?ugG4@t?1"HVKBc1"?M2ܝ3iBlO$eh^  C$(ܻD9@l$ߝQ@z@8@QV ;+PbQ4G Nr[1&XeӞ(%"[ͮgRXYZ*ϡ˘hLk0x 09A:="8<3,fP-ah! `f[[Ikd: \ jA2,~BoۘM<O*I|`Hd0~}"Acmh>_*;L o\k2&^Ys  êhr%tW,/"-@XwoYq&sŶr206j>j9v{h~BLqJ'nwl|NETqH0 6ܚYoy`(ID˩t9wP d|X1 2{f_c:\Z #1xY >*JhŸ'GP(-(Rt0c}%H 2y1{k]@D'̑w`?u۠?e"0RpMJ6l.{'O/i?ìy&yY֤PI~ݡ|5hce@=3l_?bJ{bGϱIpE!ڊךmFd$%K9>0DVupҌصJtXmeZɞY(Qe7$ oPI.{4A~v<{*)vc}@ʼnd]!U+q0V!1B![9¡; .kXC%0ec4o\"͚[Vm eR"|xƸ ea7-Bp_3\2QZ8x`2"f/I(N\s 蕊#}9NusI4*pEf?{ 8Pg{{FƐU҉y/sEMm–XclPvi^3j|7|a3o_ũ?, wh̳j/ 6a7), (X5#љ-SPKQtpR`0R ﳇ $KCGrր# mB*' {gmFMN9Eimʣ.#rs78ߡ"=RQlT]'tdy"%U'Eh*2q@jPorؕngbF֬,Tbjt7oy}E7+ſ=YV9cW  .ܛfіgԳIgGZ+҄vuuhUD%[uBR@QH '3˱Z,3N PP9A?:b8LǤ[s"_ FŎɈwSA0~ۋh:N/b)=oBնz`^y(yᄯu-cwB"> ٩vrj1sE$՟t~lNL՛(4 5lѤlJWcHY=I2-k9uPUm&Yp.*\P )gfyZg-SL 0 ASԅ؋Vq?ˆURؾKJcOn3"Y'0y?ڹ ;VBJcZ3P4fym^0dds  UpUj00I [I=Tٗ+Փ ǗM65r $83t;7at~,@eZgMZ|8Tm -y TRon#,0EvdS m KQh .7WL\zSԻrݢ38DLoiocN^N,I%I29n|ϫr2}Q$dW/{MUlJ\$T/T1g'f2j=A4havާ(Pt4#'."#px\ Z7'xfǶA<~D6[V׳ŧPo<:٫ X nJjX3WF $3=2z$ܲLoz7Zvؠ>&f(ϪAFg81 8@T>0VR3f g&amH%ٕiD?a9)+ϤAI=T"!nٮ#npVv+Lǖ*D1>#A=*|h1顢+6\_=,EPp4" mHE jrXoh:!mю{Ǔ́XC)䕀/FD~d gW1I ⑖XIW4l߇-lCkt|V5L♲T/,>j&u}FFվn5-'w+Ifwy2|!P~%_ KJG3!QˮSNAL$)Tv.44Wd٪{HNa \l<)*!y3p.Q8)MwJW3\+Vgs)j[{R{EEMOZK9J XLjCv$.DlÌԵkyBF R&0Jc7i6 !x@_* v8)tHq&"/C_w^{Fq8c P;E0;Zv $UQŒlnj"+ r>;=y:cQ4g.衟u"P[Xý9c <)=8H\"96\@CȍA+xq `Y7HkU3'Ջǹ2ʏj'71a]EB/꼂-O&iw=E͙7FM m6|*=xXw3*$-"LL7INTvk$ ;|s(s3a/N M=,dCff'jQ_ݖTzg}%LBOR16X@q-M"zZ(cZMG>ibDOIH_S)>tLc֭hfS[/5ΚB_(0G_jy8sGpwVfFLVSTDxY!ɸ<ۍG rP/Y  -p=#8kVN#GvۅΦ(F+r,n|Rp uoP)ڷ"> K;^)62=.!/QhSO NMO&Ʊ%ZX#OJa[3*`F.I$fokNn=&a)&u~<(Hwzsl'8_vSige $2g|^>;`C`l @B7?氞xN6\ņ,W.k Y@OS/+dU&ʰ2%ӼZްt# [ڭݨgwģ9hϋbVTC1s958 ՐP,DTMl"cY+mrLJ^L Ms,OoN1*E>9L%bq?\ѴR$cn7L^/YWvRpp/ aF;;Q +L= $r68ZP]YyH4fD"s`ʳA $!aiC Uҵ5psb=q#*dyMg*'RUm-J3Jf{ЂLo£7_P[tӵb U3KGx ;1{{2C~<٭>$Bʌ>g^OFvra'R{v0zRǵQ@T$_QK4}0;r^e \X4q"ݸ ԬBE ʗ@9]=6BSkW2^bWkVXXۈHiy|+5?E[ yS]}gB?8 š'B>\z& "jHFQE^zx":x{Ol6p8JGT=l$A\jQoEbZ;/V Big[O2u!+s.._B ٷ;480DEMp%%> =(滋xRSE[v "8e#JC`?3ek׿@/z/ Ն"#N8mIgEsrP\E+,l.,^-m8B*9T&F}}pV(MMON2|}.FZ{돹:ڋfia?.g׍+Y RSzr,w{CDUL90QЩ# #)?Jڒf(i뻰eÐ\{V HSR<߹lrש*_I$yngU9) '3ߣn6*hjdgq O`8hC f^f \P7"H!oh. _Z ovfrrMbx4P|-~IյdӿY%aSI5qjX1Y HؗI@2޶!T0/1h\ a.1 u]{oZX||"L0ntW.=Zx ce>E=% QkX/)Gޗl,h Bq6>-.iPl|fOxVߕCp;,yanp2̦q#G$!)F_k]MݠO$d?4?'X9-9NJ!u&t{7BZ R ڄ;*pReZ ͍NuIK'rJ",|K}!(e@Rts)KR -ϳ۰=  su@#mQWt] љiS{ju۔ sz?oA%le3sK!9D(̱)>xȢQp*h 3+>C~'RtBS^= hŪQfvN,NK:4^ST[=>J*6X5Ò[@ֺQT7#EnߪEEaHdbHU^..@`=aQ(RF_4ٵ\K[Lng"N9<W;rFը IK"D_@d9Rqx"0\Kr?NbޔkYn4[ ~N&*4܋ijXc#b}L^S xMd#z #;)"d8\o k`++Ғ6+NYG-xEQ{?Jf*겢8suS7uAjl_ـ~^G[,Oԁ"B RlP~3(3ʢ@\+Y4rd"57`bj#;J :i鏘aCVJy]~&O?M5^|'C''bJCHS} _5WoúI`t/?*<هgPKO(!R* aN{?30_{ȿPz_fAdI+B?@q㴨#J/U^23 6,ۨe ˱:Yr׻L6)󌜯 Fm߲; r%8ll CLi^QceIPvd9q1 fҋR7Uh#u$4?W]lm6!@r;TA_'6ЗJg^2gK\-PS`I9\p_7P*,86شA "k[J|"2[Zp `IU>^ٚXY * `a%8ms sA!0'ՙR^Lǥ#Prsh #sqNZQ@ʵR h<Q;ݱչ| Uguseu; Tj9x̰Z(iC??K2)'Mc#|aMOjy&אjeXhZƶd*LQzln :\ ,^M wy tƇ8`Sơ%YmEac+\!QtYupCT+@<%^ߤA&Zɗjh?N1PY]G2~, L6mnp3aH7P$PWkA6SFs+Hz%% 7tL=:V"jZRLh2X4aS E?Li5Iڼg\S5³Ga=G"[^3g0v^?+VfE@ ֠Oۍv[ U&'̶t' |Xtx[dHƬ2m+S_h䕞 ̑3i,ʈa n򤟀MMև5ݽ3z |zaaq{twMx< O{҂BE%uHeαṧ1sLa9;`J’A}2/nQ?d$7e͎US㮸a>&0P &щ2eZ$!-8c^u/NTl~LI +I31RrA|set_ C;GA4ܧL`{P2ᇛFqQxDg5wʹ~aeD>dM.|/l^[0HPdh_w[:N{f.x#G}R5g_AhfnJ?\C9l<(BqK$k6~'S\8a`TmM._a\wb_b֤V`onElcouO[ݕ&(N`]Q zƙCy ڽI`6]s7`h vGYT]*zdb($hfcD-5OSSKV7o|-RewF"Dnq=B7Wr{9}ϫ>э-,$4+ΑjkE8>?H:&"ZhC [~GUD T96ڱ5ǁ\мk'eX\?]0LT`43ْҳ281r!ĐC˵pXk32 wjD[t"kDg]ʶ^m;ȈaÒ%_ .N,>Bϥرav?x0f-jh33OSjؑb:!kސ.T0$c|r[8ko$0Fk6G$=1‹\\e2T .ΎhQb>giE7Yw5rys>)A1(:)zCd]z|֋ۛL \j@tbÔ*m$5ة-HX`6v ]吭zEABykd<X®Nu~irwxO;<l#]l* ]:~nE%4c`PxIM v 5 6.N=|W*<ݗQF/ZRcG߄Z*mdMY޻+BKl"!@ 4UGs?hDCj/$v{ ,VW9:uuaQ}3ʇy#`jB~Nk:A(ˈOo}.p&MS%{?}IENv.A*lYو%]|8<ӖUGJ}?8WR0ý@RW2wJ߮Pt+" 'nѻfzVrs@DW(iƎ G ODUص%[@oX/yn2n7硻.`Qs#8(lY][%ufпnQU?RƔIʯ2bDO\L#)G+;_rnݝufڼ}š8h%'x-?T Sęmm B5HBXJ"PtK|p+q vXm7a $sElF368}O>X\*0Yޗ4wn^>cs[V- ,Pu(cZcQyt;8Џkk3WVʌMPy V2S,V29=YqNXuN1lB%CE8ߚ'D\_pK;  OsLjR?i3Qf'J?;&`\2 +b{"'8D`'!'+ x+@YDOVMjb`ui{#)[iX["pI,m]+agYuO26_^jL6^ŗb~Ǹ ξi *dm3NK=(BEixIa~зD4G6'3li#91U:Zy{tφ5Ý[ N^{x"ͻ:gU 9.c3"'>>f*fpUT'ՊѾ5̽(q',{ɔPZHĦgRsB̬4tSmJ-g߾>ߌߴ)\Tz^$nj+]ʺŻܿ")$Bw;@ɦ\Y[|y{(RPד߭m3$p)U@d<(JJk$T =Ie -mT6 goґv4lP`Xix1VcǓ~3sqCVg@0#_fuF1#+)o\&vߊ:QQ7ƌ6W[%=KMK0:!JM[ܛ/8+fn"Cm$:kƙP|8=Ql@|p:֥I&9:0]4ˀOquNkWruRsYxgf8S[ !nG\hPwRCDm΄^ȃy6AZI ~ulx06hvPp˄,&&Tf\U%֡T (w<8$;%pފΌL f.x쓩GtOMv!ף׌eiKmļp(h3:o!@CCCdGu W Zh}tC)p8ƞ?{-UkO3qfpͧ0(GcO16 ND: >"۪fƘO @206ӯ撤9h_~5W+=8~7rtV\z;,2^X/zVwDzSr6\8ƌ*Zl8P{sfV1(Ul !ժ.Lx܁Qt`iT$esAg$ >cE-^- C6iaa͍ه"|ߣ n\JQ&ׁy9zvvFsDL&%Vw,%Lfh-7h69ݳ5e?غ&Dd _V xL|-2=,P<'r [Bǫ"pCTd +5A$a&I,{7W(ZMgѹo̺'q%!,N)GjP%V)N1vvWn@k-2([Ey8L.5)J.Bg ٟ)լV ޴U/گ *{i6PgIӶL3)rlCGZQ Yűe67'q>kR5"U&r4h.nrSE4NW͕f&t8Cyk%uTOO-svEq$0ፋ[x k@[`t[>eBD=Zޱu_ 8fM77},cA+6#\wCąuвE@}iZbFcҎ/;,-ڗe"_3aw}2G>=x!9f9+5ٖ:>x7\7"aa3?3ƍ\<"-7_"glHa:׾nRu-fGbcX0^gԿܓ<#*axzF jCyBC@ۘ73̜9ka~uF")\Oة p>w跏oQ6k0IΛ62C#NUvtf\{J[\H*sXeWՓ,_w"UMwѻLtR0 rNJ9S:6v E`<5}X kP'lJ܆gٹF2ՠn]T^uK2RTkȒCj\׽,\JZo ܽ`Hj{N}鳛DeCnIB#*&h}C@ϫF[#:j*"^ Y;AxJ‰V4H'XׇRJ[?B{-H h`S-J p4VxG V*epYG TMéFȒһ7?}BG_=@:l1OG*%&\qô^FjWqC ((Yx"w-cuGIj5 =~ƥ{GOq"sLPjن0TGqFhԸ 1= ^%`~$ɵ}:74RF2ekf3>0\hH `̗D`:T@>TAE)kZw(< 5d/IG)۲#q ~T}ndqT+׉ Mb$Ls׶px՞` %'58,*FK6fE ;BB> > HoӀM>[c% TM!7ه"6w0^%+A%E}\=~Â^[_*^"iL ՅȈ@n(}!j8 1quΈf 7VQ/ﴽϷXG璅N:a=TLUt [6@isW|Tۚ)}|q K/1j-.FT"h△j3G+"SWD0C'{WqwUǑE-c~kaPfBF[[rY`8/v5Vًف), ip2#%qV|pBW+cv䪍B>vyU_?A.\%.\CܯRHSdx݃F03 ]WE֛ӂKF@Zn5W^ݠs>H ~ K죪 FT;9T4]!e󧢡*F/œ#Ug+mRZ͚ȥa-hzbTlCbdfhBO6!ibZP(&OYepod|Ű·h# ~QaQ`8͙F}GomE]_)k䦃Ms̔zf^ޯxgVpܜ`秥nIb#S /! E*4ry\H4zIs`t\vدv76a0'. .M$A N}(ՌH9\! 7CqH鷵WR*=nGuŠATC W F,EE[]#iK{-1*vYz Qaع_̣ZS>/v{%tf$IaB;UhMa%es!fRKn .Rfj]z|VQU`QR"7DhCִV|Bpt߸D5+ DV'lSjo'͏oҤUoj # qG ~d &|YS/ ʀ2*>Zb 1)8e&&ʔRNzf9c͞t=-nj7IUz.osW j[qfqW@uN9Gؑk.&4_DE/-lW-M&L tju" 0q$C<`9sӭ5<wק`8Z/ @&}jʺ6ڮS>ѳ5\KV6 f4 *E;hi~*ƛU{ʈħʅccF`q)CX` '1&)qmvk WÉڹo8i൥\#a~!,uyzZm4 `h-tH:ӨX'IB}NWE%k=ei_"]ͣNȆH ?`nWL`]!%uJE~4T$$ toyk!Xdٸ]!Иfvz P;;!8;N#̔hn•}5 j妏&!rv%Ƶ7퀭Xo?0r4yc2TۭNq;'@lZ)3m+SZS[~%] 8[x 1z͊XBu Z>U^ƍv{]l_K͂%|",̪bϵ+vTIoil, 5L"4!Y?*oȫD'K^,+9$.XHUlX"qDR8 h xhjlO o06I@1S?iQ@w`g#OMl1NqD\ZTL'1Ts.(:T-mݰ |kogX9b MM/p\&7C}q^MfG?c֔UTl"+[|D/m29SOAAjX ՗ش%QB}MJہp-I5i85܌Su4".lvkX'E  "a=a{ ﵄Zc&a›qrzeޔP?JoX$ 7ZԀdhX1EW:%S_^3;iaY96tv٦,zG*MSh P( H ~S4Pczg4ɲ͡3ni] J*e@:[ |g,4 Pc󇐘N|%\1@p&"8=F[L04"`"h;53Ȗ+ݴ +(kKA m].t |  YZ