sssd-tools-1.13.3-60.el6_10.2$>Fh+qjT>2?d   F .LR\bb b lb b b b!b#jb%T%tb&'6'6- 6(-8-94:GbHHbIbXY\b]b^pbBdźeſflCsssd-tools1.13.360.el6_10.2Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password\>x86-01.bsys.centos.org PCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64P02H0KS@ |5q#0EQ;ao3] 10m:*|MHOr ?sH dC A큤\>d\>d\>d\>d\>d\>^\>d\>d\>d\>d\>d\>Vpn\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>Z\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[\>[f5c397f38b0775d0cc31c67a713b30ac4c3e8fa5aa1bcb2b98a925080546fa83b94df0ad7e7e6f501583bcaf112d7f37d9a581e72ac22d193501a1f0cbe8b4434875ce29300797ea14c61a6f5396f574330416512a85246c7e01981a4197413242b03063b61c696a558cda4617e82a7c02b5e13948dc9edce397d1a7491e8fcc1d2010459a97c7ad5bbb048b86030355c73e0235c8baca4121f7841274c5bdc7074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45eb180ba6d581afaf319858c367b19f92a887d40697918e6e10cfb37fb4d3d5f69650d72d90ca2e9d64239f9e5500b2ab18a9fc9bdb32fc4d187140ddba6a6f56156350db3af3415feb9708cdeb7b07beaa673c8454aa23a6d9e27264c5fc18a308af39eecb3b573cb1261d1d1ff797e5fb5c461f7fa6566c2f2c9588ed52a215a2044d8ee186fa8e993fb3407381b7d1781e764b0aeb22c6a8e9fc193fbb030da8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90310e7998fa63a7c5fa94fe61532f72c8f103f6563c4f6881aff04fc12c72a2005ffe255bd2d32476ca4c1799d2f0880dff0d56c9346263c9b9166d402797a9597ac16cc6ef9e7cbce3b59721c89187acaf2bf74ee83b4ee16a72939baf79d1c994987c56756375b9c6ccfc6fdd8f141087f1de1a53e2cc7f9c1b8a64812a99c30c3a967ee8747393b7634a732da977cae90cc423f89519e1308b2ffd9d6500d3bce19c9a1c8d59d4467007dfa33a13148574c3b3a56d1f7bd0a5ea4d22a294cba70ab8ee6be09e55ef55d4df5462bb87d9171bb88c9255cdbff05ad1b665ae31cad39da900dd517559c2dfb31180acbf6dbf8c44cca601699638ee846f730575edb3bc87a2ed41ad0b33f8a7ddb198baf564ee3d5f73eed3645c35397882ce809f2b218af5f82c9eebbf77d4cf98c4ddf70d6c5def9fda0c42f60632f639f43d86e3546ea13860efbf7a889f672d22308aeab4854e590a851bb4fa24fc97700e90d2fac6d79054ae2e369e04a4c073e92d8225e8ab05a30acaf0b3abe8dda766545890f5aac5c6199f40080a7eeb9854fc19219f3c01f77ed18a2634b0612ab24e86b6654a933b196c491ffe8e198007de7b7fda4ccb537c9b80b72fefb55ad1535f17778e6082028bdc12926753802980c0dcf57be393e62848a083dc42727874608858fe68353c01c6d95a9faed0a088f539d649702f6a8767cae6050cf898dcaf95c6019e6d32722fd00035cea740bc4ce41bb19bb6ca38c4cfe2e0f4a0d3f33dad94c2a3f116dee94fb53ba321249f03d4cec1bcf19b73f7c078f7d1c466adcfe632e17455f2204564fc7999edcba0264521556b2977eaf32a175e8cbd234295369b56555fa293ee5e0b19d498798c7501cb0d7d6319e225eb1716ec9fc0edfaa451fcae313edcf7e91eaef9fdccdd4bf678e2d0f6641b96cc6efab26c1eea4aef71794a708908f80b961c82161717ec4d38e1071057c37899b4b3abb27f3398af40eafe3262aa2ab33feecf21cd2a580e50c3b041985d2bc82205d9274edf5abf7a81ed70904be6633dc26d7b97f4a822b314b80fc96da3397ef3dc20c0008a9232f1f1efa992089761253a0a8f95c22b77c5c08e61bb610c280853be10623c3aeb7d99a9387a928f8ab52135d04d087a014eabdb31485a16ed13014b2be0178b0c3dbda640d4d716bef05563415f80fe1b1c7e72c16cf8229195371c25b3071b8c84ded1e4e764264645e01c79ca04e28d35ec8d8a4cfe8fae48e131b2ab89b6d644af0d752da4bc9d07c7d932dcf2935dfdd1e96060a0e918db3fe6f7d997fd8dfaa45b2461800d9ad9150efca9c49abdfe42d405cff4649794bd79172b159e6d3e5c8994924c73393b0e032e3f7483f6e2e7a73dfa0d3313996e76fef64c49f786b3c1a5c4815f6067409536b15741536bc49072fc5e4e1c4619e9d46909077a1bc9e7c4fe450efdf4ed0a2dad8b909ef1d21df0d5e88eac935c9e722983bb0ff8cbf948c85031d641cad04ab8c7a4c6bbeee8fc8b54bb9da6b4c3c5046ab861e93605476aa9eaf25d4fb1ea3afdee0006ae36b8b18a3fcb1a6c5c4394e772ebf011b7c016464839f3eab352303c22eb45cceca781af6fa1b1be86f038ee0a1551c458c692a176cfb1ac6fd31854b06abb30f989f3c0c08e4efa80499446766a5877bbd79eb8364840c8d757b54fbbd6c786e22f3a892c1634f79e6161c20bd8eb2ea1815f37dc4a1a4e25d5b1895e8d1e0deb757aac8c898c2d91ae320fd5f44fe907ca0699f8b5273f5db15caabdd336024c509aaad69c18fb7b0a625e6440a939d5b597e5651b5e352d02bdae191c9386e3b979ebb52ab2c19c8ddbb9e1c70b639bee076b4cae6e33a9364ce730a767bd5ea602bf16ea511158759fe440ccd63126c792da795853c00cff6df61b615f3637088e9b73967873aee8136a57029a66ba7707710a6159290b724004daac15e5d12eb34b4354093ebe1b473de61f66330ffa712bee030d86e74250e1d8bb7209d11714bd90c6ba4bb6bafbee663c92ace0d73520617661242ceb9a20f3fb749d86862d8cc834a75d84eec2dcec4e21c1f5df89d94cc5cfca9a5ee641b444b39f437ec81a61e404175cc65bc2d095244b677dd868c382729beb40c65b39675056c207bbcc628a6f174bad6a2d8fab7af4bb505cfee2e0c474c8c8a8b5b50beed5d5a3f60b1361444e0c57ba3ff50fcc864cfec5ae128ed14f4b704de0339d2d7494974747dd3f2f9e825da1113ebe1a94b1083a8cc4ef3605a8025bc7cdc82d85f1489c4aa19354380904482d94c0d736616f5d9f6cff3c187ee1267b28144103ed9697270d1342d52267e10a705c1af7ddf4227a6142374ffd9e27f4a7efd70d905fa35863b0c85b4bc1eb96bdd0fe0b7d5e56f0a45169d89a4503003da23e1189a9cfbfe2ff00f1f9425b5a8b7fc192fbc67c4c9490b7abbf1d45b13881202e6ebff2c4f9aa93abbe60858fb3d23d6ebe40c44b74b30601af44b748967e984e57abd73c5afa1bc2913d9797201403296152bc129b3cc136d547e63c56719f9e25d26656348f8e109aff3b0383ca9907ccd3feebfd2bfafac566da7c49904719a5c1d874f70dddfd278f1667c796fb3c2c00f12d9b519213db2dda1acac178392510542194166731042f5f84c967b50add087cd806f24f2ca1208c5c685d5c88cc2f85cd9b04a5b449fdd89f2fd7648d0b68c2e74d0c7429dd38191248983152bc2d0fe5fe47e9832d526afcbc27a04c903b0f7042dbb1788ac6c5bcf6160d2ebec752292fd9d01d3de34a48da39b22919284fba837857ef85854776014c87199f35518887a91de2811e390aa23569ed3cde3e6de935c6ddaf3908d5b440f791a7e4dee8f11355be78185b97c6162290cbd2b8ecbbc6b231ae4acf6a96178dd7058caefe06d7bf9e6aa87924712ec948046d1489e810ea7bd822bb3e4a8485086ffe1fe36067571b3d8557d391565fdec1a0caa066c1ac0a2b260a150fa879cf48a50f515414444b1d2bd3c6df4968007ebf4eeb61aaf955138377a5d405bff06ea88e9526cdbb100639ff5c2c85ff8ab042cc56b4ab6a25b33cda4c8d0004e180a6a129ea909f6ea9f113b24b4e7dae0cc032a140a66d4aa6226439e643cd091e108d28bc5bdd814ec4c822299ae948b0feeb977f53bd4b10410adc4b4fffb947a32c27cf6729f50e97f8c63952065889c2d74587c5baedcbeec1a368d0ddda626a449e6dbd77e8d6805535c543cd55c29e93c688709038a4571794dec220ecd95a66d394b0c1bfd354f25906f46b7593b2db24b10259acd2957bf0cd8d4c7a46fb8078d57b9c313d582d0710c33949020cd27ecbfa2e51ba767fd99e1aa8ee5d4be965a802fa7ea701d552b9e21a4f512bec4b026ca161eca3889c6c8a0e4e2f1110030b7f2e6501fee112fa99b9e14a3224f92d7666db59e9ab4d7164d1dcb3340812c411432c813c9261d14d810f44392b38b57d7478b094573aa4e97127a9247ca47b430f4255cfd4470d52f9a331cbaa98d3477f7ff3b0d4f7a87c4672f16af2533d31633840505e97a9ce9adbda59ecea7e7aae994039eebba5f6aaf933a61184141bd06a744395ba5b4fe489171633b2ac7e9b056066b82625f0818034a016da47e94706366b72ce374f23ab9433ca46a9c0b9197b9560c30d9ffe6fa0d9a12ae5f26c93cf5da6b44f2b703465fd73ac1d6d4335440c465e5f40f9b58498ae2f16dab232c61fc9b850ec99e9aa2f6d79ce0517c0665660dfcfa9c129fe3e26e8ec465ce1270bcb6a8d2f943d32ae1b38e964ac2841143d7c4c8d1fdceb412fe00b5494c0397e4rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6_10.2.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el6_10.21.13.3-60.el6_10.21.13.3-60.el6_10.24.6.0-14.0-13.0.4-15.2-14.8.0[[ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Michal Židek - 1.13.3-60.2Michal Židek - 1.13.3-60.1Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1636172 - crash in ldb_msg_find_ldb_val- Resolves: rhbz#1576852 - ABRT crash - /usr/libexec/sssd/sssd_nss- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el6_10.21.13.3-60.el6_10.2 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH63]"k%}:w{!vQ_99eW@7ap#ifS&ÐK ŝ~GFVM[Ϗ9%X@7i:t[H: Q$E7?›;&7>I-o^$)  oHo糕X@2m3 Z:X ,:Jl;Bήa/_RKlw+n,)as Qϐao8SU 8Xt M,Ϡ^!WX?ҥ{'F#jmvR:D9n~r.6҂"oRrn Ɍq X/2fG;@0)y@S+g@ǯh_ ?Y&PYJBO6 EŌ [ouߘ9_?.^Ժ& X}q 3( Arvݘa1rz`?t̬G)ЅZ=4ϧW 7ws\]b]X'0k`wJCؓ\Õ! \C{u"e|֛JRq/v?dO킯KOJ0D܏&T)]i0M9FMHF7`۰%I;sӕj2a":gYp-uxfdoog8+ܴ .#`Ra>H Z,`SYgn`(cs 8o0OkN4ݽqn:<ZHVo=g`5B lE%QZ("9Sy_ӟI&ŵ*LdhdbS&t@7j!V:m0#s^ .0r܈]y a,+K:座 Lu$c bJӉ3B|Uf,䷹s!I2~?y-hg&бsU=|f]쾲=P5'zco$*X`5jQ@~דĶQzOϐTt1/ B=-:gh+LeGD)8_H9B8^[e_U͍D&GN1Eң4u !hz}aKLz#;6RJVe _9'JY[HҞaH)ވs]d: }L(7EFyGj@Jw# sq-B% nyE%/pw~ q<U< XVT> JJ*g߮ BH\ht;tc| NT'ðJI%5sWEiN=FS/ oh֠fDKfJ$j5 $G >HGy7:[}Aey̘aSYǧ89'prx0kDabI[Xlȅ_#&%9BANT 0`4Ђی2UR|.IN Ċ&^3 #4"W,Ps6B"n"N3,*: LmW2 7"@.:tZ:T1~ϺcُM8 'V/O:Hw65g3Sit1ANbu)0D`ݜҩF %.㷋>rKEɺ)_f&z涽CWJmlȭg.~L+ <]lg)|`[lMt'/۱&Gp0/m mK %9ɽ'2R ooJYYa%IX9ԉ31 fb;Zm[O9yES&7_Vq4ʂ>;:aɼJ|i/[:D/Ik>i#PTقXU`%0HB)nH,[U nIL_kFAQ?mz7kHI_1^@J)q!&O(6l㯸ihR]KweC L 07OxoGO߅dU~Tk[fh׿u]Sɍl3:"3ipAS?7$B= g9)9+JSx@^1nP@j*3&HL"g!ӗ"}BsY.`ĆsXڭNk*~ޚұNҐG;AoX$>U OLiU@.U5[Lchq K[ !@]$!+P5#HXI-HMxT[Qєm,| XP#;0åVt֢^%ekRY49n>45WB;w-і[|t&I4s zmsk+ 4c%>ܥw~VѩG^ϊ   %?⯄%,UȡzI&`e-)W1]U,Q:H_zzm_$`~Ÿ vC7#df1&թŰ,@&gm|W96f*} ] "E&A b ($W^.gU^gG~2ZF:g?-+ZM{=sablgPi4QֳLEǧ/߬%ҁ%$Ao: R4@+cMnp K ~cdF2$:O}濽EUu#D~c Þ:2{Ǖ":p"օ'3wF\aԣ5Xд~nNFm]?T<,fCGbu8E֞ i y@#liX/NW˨&GqZQRs(FNAWB 3Z;1@>L@}1Fs^Fl;IgP! T uaի.v_/fxT0/B+y -+n/>i7ekIv{"àNv@ &{, 0qԔH#lQ=vݪfCi0~؎sQf b ^A)4"K2|^Epf2 _oRXA/qPxZ'7P34Wۣ 6?yg wikǡdBlNecaA;2%gTtgc9XJ|v?O0*w#;ӨbT1n=ukwQ#FU1@r!̻`R֛468Lm(HZd&Aa8 h֧ B[n(%Tf MЈթTL [ob`~z*`08xך2Sw&^{e^|w"k}y,.:Rʢ'[u,b5u1Q, _xmC*mP8wG,=icg%h ULu3IK}fƤ{RK;3\ @|=7d2Sێ{Lh4pjw2*Ǧa``gHPI$!AUz9a- ZhrИRBPKľr~F7C5 }7EY*+N~TKQ{q@U;Hs~6܍U dQJx|"CHx` 䯱-Q6 Ng',A ?`Ak>V7Ĉ-ImkP?:w{U^w{4kȫYRyH XrmFJB(#"xB)ID_ ')RM?=&aT>+6PT6#τfq>)"Bu{pHULܽNkE/cxC c~^r/v !B0ɠ`"^T.t`IMqt\nR7/maW3^ 'r<͒UYˋ=KģlC^CV7_B<3.8M`;śh 6K@~+]<W7|JCxwTE7xӘ-H%l{(9Y=&ZwNM*veۓ$Rmyߒ\ɾbU t.@3^4K_%5yzSyc+ vaeεTyAD347R?Yt\=K0ZLjǹ~cECtXYNh,'E!n,GRye](mѧ(EftuT[UȤ{ߪEK-5U6c %ٕEv%%zȃ>{rߝ>ֲ;}Tkѻ<yX1.U1w |=?IV'OgUGgcm{}α( `,LREc9Wn8YPgօԙ`>5l=U$NLꝿr҆ќ[u%EPJr2Ru96]}Z'pT\L哌F\ZQP,&>P 8ewX=ZL h\Zq`XsY6J>dp`QQ'~덏KJ4!*Les"{%DG^ڌ_ݣ}8 /fg{i)1̤Vy ˣ>T4eF٠b"4R)ha/4WT6~N-ue9F)ZY}yb{y$fVg:fuw FVdwqL4?fI9\9v-]fZx`ՃPl]1Pv|&wh՚--*6) ؟ͫh=0_8pڤ#)kIYQ8aHSfna:.}$;H/*r{iEbsz'iL6OGH tVosD&Ar]o2Rwwθiľ] x"]|+FhCNpƋgkLJMAzv$.^>whfđPpo C~Հza ip^ P5_`:',3\Ǵml7>p _(`]dWÉɊM]c<U7rOb2;If}=[3;X5ge6<" ŹM+Ye@H*tNh^[aݖ  m"k@_\VqQyL1[ZU˽ ֚Gd6_,ȿ ,a?q%D(HQXA'J0m@%H*)d =e4Ɛ3朙\myHM/U4k[KK؊2}2!B'^*>(d띎n]yGgdg ;.1|xK8YcYRP-F᭠dS ݳV<)7Mdz!m|Z⫱a1O#tZ>9#ͼ_y~(1Bc@CQ5X@xᬚ[?ijTD0%`X D h;vqO: lR"*/Q0e=2KJ])|J_OS nMTu'[qR -!(EcGwUHsPZ(L~e[5`Ms|1A]ɅSt$"Ӳq7lK- 3t[qŸJ 2Sи/=0X`H#1E軰H[I,g@c_|:YY[0eVXpA.,)G;GSz I[%~,k Tqɝ U'U"޵G\t\㵗ESz2HsV!Qr@q|nWSv1E_c$IW>?ѧ-}Ƅ Iv B< :]JPcv挷NH@ŌdB/o]獉pgkV(j]uQysafi0,rJ-I 4p!9mI*梁rp'V(2?P*4g{̐wVGb!A溎mW'aݕ m݉]6lA]l4zc''Q"߁5)jS ͲS8ϼIH^,6^|<-ZO]}Nj(j@$*X>`=]i#`z:?DSΑ$ ۲}ADn]rf{i|zT!3ҙo 6xOr8}IڞS tѪ?q͍&VLsd+IwAm</'üK;,pX $hBE+6vY騻Od=mU5˙$$!8!iWxV-BE.FC}7=~@&PBp$M I8ua$M=_4 0,Urbˠ$0?uOF{t؂<管̼[!#gq2Jo-v!A1Xn=^ cHB]2ݹʎ;#)ض]ɩtP|2_~M"ƤI7M ¿>E:8Y˖1sNZ-h­+RKWV='fg/=6Nwa%>-SE0JІ{Vt_Wlu% "vSܔ8_bGŞp#9~Md7m83.Tґ鮉UCFT&9ۙ v0>BCض DV۝9tt[pKRn6'^L.R~}fiѦbXAT-LX0i;#EȳF(3sp`I[N/^e|E2z09Njfcud0RzvBwpN,12uK&5|)٪l<.^Z?B&@ ݳiN:P U%aM]eb|LdA JݛoJB!@]'X.Ig*uX%V&D[6 >9~[G<{ QjxඓgWuѩ*\PD3P[P*;L{I1økt/Za*pOnQWVEtD3ڱj("ӣVZf/k)dȵJ6pq0YÃWZ-6`a4WE ܾ_3*.RgEDYQ߫ W^fiG4b ^N-`c6L/` 0ɵzMrn< }7k̒ ) ,N;l4 EPRy:k>.M'~qw XcB|(Jg8Z\vъJſ3?u;8<:v h_g0jz*0A&T_оʿ9Ó`+6ɒŅ 9JkrrH .jK骾^OsȾxoɕN--nΠ$itlÒDsB?ג93yZؓli)Hw~$(z>};}{)⩀a xKJyxlH)! z8wgMOl}U1;q~EmnDVm1jM!K)qSn2Gu!=MMqA_D'Ӭgq1Mwgp\tpˀ5"zmo*Ex?nIJڋ2eݵ=i _C%(ux熖K'O7fzuT/F5iAIxQJFNas;p jݕ"jzcْd TЛ|K 7ɣtNPV\![S(\V b̞,E4R/HI9v~̍'ir־6Tl&V|c֖MDM};MM=g^/3hH|yk>+%R9!dвPl>8S>w,Ղ*YHӦWQ_ږA+Iv9A'sb.B7/zhDP\@;.QbYnovx/vC1lxTc8hcE5um;ؾuMzIդ*ۨP&, {tqp:n>nŲ|%GaqT>Gq"w MT/&R OOΥA{8ƿcIoʝQPkY3=lYMvl?< d O#` ( OP89$ Mrd ?5{.+9f瑲D#`0 mw+IlDȫwQN&B\8l"$|tZYMr5fV&wX6 _]r%Nkg Ct8CFQNrM @0RK>Ii>Fz۾i[{XXeN?v\*02hتy q}]![y!nVbsXZX ][㛯Hl Äk;pFSt*$ :.0ӓqic9Yc$Fc`ƻV{3ƿK#/Yf]zmjqI ?X(h:C gfd2~<6*gY20J˯~hHa\o22lkɂoC˸teeW_ 8mHDVwB3kC?r+B||e)x%tY(aN^#S='asN r0_ezF#atp)4j OUyO dSbyNaGL*,}V&&ȶ@BVC.q%Zrd{|g}u%i$K .^@ط}rUmn {پ,dMؑҴ>źdk \R/ij?'{U%لQMqaS&yʥ-iqx֖]Q fҷZmSPΐb + u_bhJAUZ ǂG1UY~sSU<*ՃX>zb*p1C<dG9ދ܄4B\p ѝ KlA7q +5H!"?ڇ͢>=JX9$LexAaK6Jz,ڥ3 KbpBֻO]TսdbV}>A]mB@qh-5Μ [WK@hfЧCsnO &o'tj_3r^ 7uM렆`d 3Lȇ@4Vj5swSr!ITj/s䞓sCA-݄V#ոd` TEb/5G~''~SB-@`v$ܗI} a_ NH}6gdž;ʛTrص4Po#e$d) B29zOB}ƚeݮ./*-3))Qޘ\Ȝ8#Xo@P>ፔ+Y4^/?W9/,psߟ<>5bFj"iu?G'N29iDf3KRB)Iv8!J&ex^::4e-f!}TK7ūAr1)wʰ_M\BCۮ2%^c*╝-X]!-W;jVeT-Z(4vR_RHxr r~Q!rLwƮ. |ߓɄYOXQ uYǘ`==c! b ĝ/6p:J}V SE~RӧU:AN!mSWDUǟ wiӋSvFzӋ mư_JHK{Tpb#i$.@U JGuIF}w@;S0K%Uhϩ_dY ef= C3Nx BL*/7RfZ2 94Gzg#J=R7}Ʃ:- ܣz*;E^7@QGv'll-;;>"D<`LeŨ;F6||J+"k*@#ݎj; *ȡ"ǵ *:I$y(Nv 0W( nBYd. r|ܬI*nՀ/[R']bzL~<3qkc|< i/(1͝ɴ;0fFڐ ?|jq:7>7'M;v o⒴24ŁsCAXaXXVUJt Dmツa,A>3GmNz9uq9Fߟ30˿Uj7.۩W; j`z%xWeT]TBk?v: us7 /Pt1B8“]R}U6e804I57^?3Ƞұث uiU@j~& 5FUIj@689:)S8υ-T cP΀!WNrJ0u~ x(5 :VwdD;V%9TSV_Ľ7Ԋ!M%MW4. 3Y?~.Wb2"h!4 S/~l췖LْIxz" Fޢǥ\ [iW湤zN&,*/ҚVw[FvU+jRK3nfBz$ƍ w{6Ж`?p~M ])~=9AHbPi*q@8,diyE'˿TWN~ cK{ea#G~b]aոW9F}ƣQwʒD%cԃDT%NpA+$v? ŵ6%=\8{xWnB-o-[;jHͯ+O}WܬFm2\}m`0+6y{/W+ y=:>zxӫE'o<f3v=س}  w?C3KaqKIcYz5nM,%S@bƱvN^~HKt a$jGFDy[4QFq6貱3 D Y+v}o0’5 ҵqcaqO|W^@aXzU^nHrxEaFds~W/kxY!\!mNp3;D4hT( 8K2FjqsgUkg0M  }_S Kc2kiNp<Ț[/: TVdRk"Ƞ\*"xa'A_%6tj#9&X~[_Tҝ讎Pl8t%Nl<+9\-<+(}w}p_-}pE0;0M'{  R:ށL[fvEar !be>|o]P,-xQk =geӔ!oRAm~iCQ z _E h0nc"(P`e\4}7oMKKvͶCѱ]eHmEm \ܹP-45Oumcα9 ;r8E y{Hq\Mv5c,wya(YU+ S_#_yu Ɉ|7p۔0v\[:t޲y0T|s3H5UM<{#WC|Z;+E[X㤙<Ȣ@:$k|x6%8ګM+gwjɃ!XK yiʘ0GBF4gf Y]*H+6dEF]{pw*^ilb65|pVi.)4]~xO ȣ0)vGuO|Ãn$ n7 W̓>^%11[k Y=@ qqv/"wWXQ<CEl#ƁF}]2sqSsXΊ"M-\|\RrW^UVI>OT[*.05[R{QG`3MB%Kc8 )F :-/-\Բsh3"ER?6(!~K_6b:e h¦l{D~p/,RwH ;I7:azo-+Vp9̀=m ]Zg{إ~e`ENE!v'g*\AlsWS /Vl6GOn'0Īn8vڰ2NHMSWH:m9$ȄH6K0]kJ?ZMFۋ f"6m"cX5ei?xxFQbJdͷ+|BY3oI3wdvQ/&W]|2#1 6$F1*K64QF&"t 뎊ꕖl7$tn~}8CWqaC(+3`[iy&m DN;L\u(3DR [7 <>X{;FU,`6W^]Y/kxR3Njкk[4O:hyTbUZ6X;0C+JEKlK$FM8@hO=';-yo zhwsap/ =Zuk&K#z ) |D*u}oBގe7WL?7N RAN[v5Mb'nA遼<a_ڰ,I9~n^G@N(Ȣ^&^Z['%6qc-ss&T1]o4p,=SK2 &-sޭ 0lVEZUH G$N"B'rʅTBwlJҔqdq|}u磍 hKsum^50ܔ-w$%q($LJvū3pv^O 'Zjվnxwhvd /1~7ɬ~TzC'/hXgz8{:*,}9 *N_n(Zo|hI'S`傏qmX+_⪢ڟ *$/(mr.:`wr7^ 76]\g*GU'Z,gWdD ]̜o7AX⯑+eݩlg};Py4 e'!ﴼFn僳:Vk^Jݱڥj8kc5yKWgcdƌ*w $W}2}uHQ(s5VWEaf蜋 -,xdZF=MX .crI #q?8䎅g`UNjmvsblN[a5]7ߦcpKnBLӪA>Yv%e lSFLX?Kiսyy;u2w`Fx^v噗g͔ytȞTO$IB秨>V'6UqbXm{S]͊G\F2ƙA@'_|)ŸO@~@g=uD#FVi{N̬;dF&4C[f:ɦË#LTMlmRY. z41`FPCѽf]!~H6TϮ.IT'ntcC:S Y%*݆W ;k4BxU"m鋫ӏ`+l`,o:kL+!9fyg{͇5`/9>yVjzd¨y܂[N chMȆ's]v)]JoٓF+47<,. #-jt#h7߰zA @$xBֳNgveˠ[T-#D[r[3s\j\RU^Ic,Z?.:L%XtH ׉hQy=6g,xWf2j9c_ι<'>#CH;rWQNb,kQW@k5:sPKlHT`˜yvjp㊼,p=ԶW~B2A(ad\BN?>sAżEʁd) ]{M\ENŽSh L&+gȑF||])SiK;׳h|.[:D( rW2$K9lmW7bKYpJ d@?2NԀ$%.w=6c V)~/_e0ԜH,\~b̝jo BޔȄ7c AazxN鲻n!u5f$"sy:Ř塤]Ğ)ióKhAՑ}a Y74&KĎTU{T0ѹZ}29aMԧ,-UQaJJ Rxr wMElA5-OUT7ȧt>ޑF|:*/S \Td Z9=j|)/TaOF129Cm'NO³gpF W1DKjlLnf9u$ǔ>Oa~Sjİ:!2\(D3G=ާ0g-4{wPb0썫<< \ =f;e+;$Q;pd lfHߋ F=B{Nl :vAt /@8Լ?t\^ӬG+kdpd{92#ퟂ$Ѿ߽P)8ψuVg ?,nH-n]cw3NWȐy!!!1ڋǀRcJ;ܑז1pEtB zg I睍z?(EJ ps+yIG DlukYdcySu  IdP=&NK`o2 8g1xU!T " QpԖC8NU'|pi'$1^|'J }br ?5$׮.t9\QR"v ֈ-ploeey_Q|k|xzZ/'6@h?ֹӡ*@pM^^uIL5(9;0'fRU"XVs~ԫs_{NDs^ ԍss>sn 6%n2r1сoJ-Rؚxd BVnuWa+[-X8-3y?a*'4)AX Ǻ# =.fQWu@MPR\xsk5KB+I1H;H^`SOBrR"B]`7t #7/v`F""eEEwOSHx4vŒ鰶MhOg ~_ B-{cCer;^܏1S@ߥD- {-ܢ1?"* 㾨Ω2 N%_P>Ha2] vtAk|!iB*$lJ4փAtI}U<"j'oJU3ޚZ $7F"H*ŧDDgP~L JVkxLZ [9"@t7`i+ 1pو+>2=ͫ-Fr2e+ o!1ɹ!F$5s/(ֽeA PMHG$ߗ۠Lsjg7P˝@S|Ywڃ dxnVJ"UՀ^@]`EAW|hOѮ)d_:>L1YH uk`+xSӿk}W9ܼyjoMWLHyv9N<E0^ Fӹ[W2>3*y!w,DF?B2E{Qs2"HعM^.?*vK+ℼ0Z}J!p2GDRf[&N\@A d*<ψ)&eX=ٍtPUJ~gթӪA]|iftطG⃘U$2q+ g*Kh2œ|E`KyY"L:e嵒HշV>\#Y;I,3F+Cl+8|$D`'*zځn1Xs,.~Yer @&E,ey.f@7pEKro$tG> t7e9)v޺=|%zd}+v~5ߛ /̹B't4q ގPPoۓ/3hNyB3H=LG%8Q̎Pn|I(jcz|g:+u_PY w&$WXW?9cY|KrU0&›TVWqh l 0Bf.Ge_ԑ8bw' 60`cHe=ӵ PC$/w4RO\Dεڿ+V3W0[Pt;b3գBK`V ?&\q0.T"!{K 0$ݲMƝI_4c!P%dEA<ed;l8l|NyCypILTl谷hc*z[Tq|Pt <.I3}ΠrsM ֻ#W+ޯõePBPþs*~W03!f_yO8q(#F^U8C8h暠ϸNIX%. U ^nƍv녱Ǚ:]6<*1IDNc7ޕ9ªm k{t9/wMOu^MJ@za Hm~Oi1k'Cb4k(Gti3v!)lG^ETV|YpC>΂vlb\ Rcɋ3d%bkZYM#Q'4řN/h4Sx\K(GrdulT(LX%RicPd?{@}g( DzWNsX\ `#'ѝDfMI i.hw b7}'VغbtВ6I3h۾ʲ<l)719[gj`qG'l,%ViN7A*_Q}elM"Z';!{i!f3Wx¿-D]H֊N h:8^C9rHeѕe!*$7M1™v1d۪phǣC1"–d3Oa J>cYnR vc~`Sj4SUh4s_Ca CݖTū[v' ٕO&iJ|CÝ& aP\*Sedo/ @I߂֏:lL&AR=8)hm/$= F b<=r*)=h:_E8zBpyQGރBl f%=2+ ʗ#=߈(b\9\3nF }++$&Nhޛt(MҜ') Sc0a?(Zu{g*skȃ=kKGL'Ro[py2$^ӄݠW9S!,B% cgpgQR}#1(~y=hp~% ;eъd8 IE#6RE9l`o פB3yf us g;KZ?}RL ,wh$oP  XfW4*4/{uzJ2r]B9gP2>= oZBౘ/H `L)Ujb%3O2~2I{gc;ioi9sZ\Rztt5'me[vg* =Zs峫KqX4@_{>%*z`\>u#N/%@UڽܹGyhuxugޒIo^&-U'r:!FEt0ZE\?M͋ܚEĈ_?1öK܁'bryA!h-w5ΨJ䫆Qd½rJtT7WT,//hT? d~YTR5ϻY8Qc7'.{'!CGFź$g 5!8{HwKK f#]wv-bObkt*ۤN^  rW׾ N}{XA 2t?TD1#a%Nd.*WtLޛh}=[y?Wx>CN#QZ}n<#a/kOWicb}K `%x6$_Kʡiߘ] g{ DDܦ5\Ocpj^G7o¼FӺ:| 5= VwAM& ?4_.V&E=|J#Rhs qRY o-3|v[R%%m譋tcV@ŒD r>ZgG@vC͕ a^Vɘ 2&Ȫa%7Yhxpڑ77y߄ o6NuYN}],[ kOu@˷5T7tӔ0(wQr *!(9^ vu?OhOO%,Gy|XnYj1i,%b2ͤ*-ETPf]9B.F!Ea6#,xUE%"h?)(A:K)~ $C sI\I&䰧 @PP<"㉤L6.g~#F[㗾Mi΁UqTр㟹\a,4ɍ%vAt>Nj8R1R(O`+.H|B|_-‘ˉ')6 3kYؕN6Dg_w'\15 8 .Zu{;` /꼨@g~N*J /wpydI\F %]eNeGl2tf?q@1UFHo 0 xi!,OF$;?~0"sCsP~n~Ŷ44 Z[4`w}=sUsƼͣ70]mQu`=IL?v Zc]gx% rт ^+HMt6o:[L eAB.H;Zp, 1^ Co`7CAo48X"]``C Df$,Fb]Y]۩)k..]eYe@ 꽽PͥҥIFinLl4Q׊\Y0>$1 s~o9Aʰ=!Ccn(`2%0O0Kv!104m1R((SUxc|/מLW ~'} `jxAL.+ݸ"V.[l=pX $U\x̣%tU_`}BY+R`C{ڶ̃8IQ l $bҮ;Tt1I%}KBI%)΄5Uƒʘz64W>MDg/Ouf:LqG@ !Z%S" 8,4n_Fϓ0ё*ȩ5 ivcbHY~nL%4҃?IQm 6ۯ7<յJB_SLk$*ۢ[9.~w .4R__>NiUs˫"kӭ(> {X -b5AX 1v#iFؔ}t{ve+P ^EUfSF[Pen Yt?C:QsjQ]&(;25Z[ F[m+,ioH;YJ\ǯiĜ"ՇA+eV(8fE|V>Zn8;cmK옠=G}L3yJ8~J#%?dԖ]( YEV V_ O>(|-HSh- z5]xwAU0ڪopƿ/-X̮-;BVAx܊z\ea[sL*oʫ[FB@$nҦPGh('ɭā3*g s.q[6eOR $j񟃡^鴹Ez~>*6咜i=P/(Za`\SDXZitb筎kk)˴457Q# !'@ʡqxhҨaĩr[n8pd4h&"*?ϟ%2o{h lT%@!t SyG @5Js ʢ:Sm'&`kA[.#p0Mzk!&G D6<ewS"HnUŕ+RB9V@R6#YUT*uUY!|D|B5̎VjQ]PD×;$k@==L$F gu-Q?=; {V"٥hJE2 1H'(P2+C֫h3eFO-ˣx1V+6f[3W+ϙ_ª/pβX0jg>!I/8ޤG][u4J/~Oz H67wnE 6 .W-٣ؕT2%R/NmGjzf?65tUUs9;l/sF"{ݐ\/qz/5K~@X 6Et=EdmB:>q r:wG { $fESC*C-Ⱦ`IC)oS4͘ @ELItdƦB4-l9`=JK@ET%gaFo4LviJG< 61XS;<[BwG1epp,mƮ/6 w皢$Z 0X͂;3Sc F'6@5kH͈Q3̊vj.63{"bgw w+pgrR7<EA"9t^A:X~D Q)4Sy;_,^j쭫,Q }eB`"2>^ueGbgvX98bRQMʎ^E@ݶ CѠ!u],jH-#ʎ*)Na*KIt[z5q-9V0)o&? ?2sVAaŒа8F.>1Mond0F)a}V =pz>VM=P,F2{#A+PLXpr VZ {~gB)c*$Q}"!X#9uy_qљ\y- DT',\%ȥJƱ,PiH o"=.n^=Îa+qlKP0lmG&|wd|OV.5*ߢ |1ry:[hˀPy;jkLx\YdzA=]G7s 2;ŕ&GiI>_\[QY9g6\n &/bblҧEY,~cIKz^dfUZ՛byTrWwnڈ#Crjt?/ J]Vb t.?TM„,? ݊V/L oc^Ic~`Ɍ-U鳦cO:lMdbp$-gɅ_r kleU88D4olڗ#/uϊx>cU^8=fI'[$'G RY q?PYZg4e25҄LSbt@ #{.ozpP\j\B *1A \nLʧs#y9fj7tw&6DaY a ٰ)"^[fIy~v Jo,T셶`<3֒wm6fIb$o])cMCa#sNi?BХRvTyGPϯR6A25\,/LB,\-Q#_&u\ӗm_ᥘ[U{e)&P ?*֫එ}BhJ37u 2YE4:ݧyҒ1b'I̡ OG,]#6˸D},`! Vo[w`6p"5c۴(23иOMK!v ;-x{+Hݫ:ƕhV}XBkOO >7}M eMvR]]"R|k&=.>$p"8p?F&c/r&1킉(G=aռ  Z '%JɅcn[2sa6ܲMQ9L3q}=n^qqћ E"(h R`^(rBɳTL, 9ii~>W&l4#w%t;*Er <~'yÞtCnYRcG$x#-^mD@F#%IL][!yxq(GʧHLժ>HǤ%.t<= ("h_ D8aݩ Y6p!I OC{3.lXɏLhp?:T24"sY]@ְK\( 0iѻpuڸUK{zv k(MeXț,.#J,wDcW`B>mpa&2 ?«gg*~Ba:NJq@CibIԮ>A[2̶"kj":%נ̔ɀl”yw@,͒O{.ZEcF?&Z{4yQk-ExyV+?W J1xA9mݑ 3KԌ!o .g_, H-mI,#_SWOF K؟nRVīʒ_kG M- J$XXG S=3|S^lĉ*[`; SƚzPKfsbc:¢$v[hMÙe )f6*8)Y:7odRs@ #"-ӭu 9fB`5?28c-qM6u:t7 (\g:ף+7d hV\Cwgyz/XLouE=ztXb"*[Jl8 ^8=;C IՏ** :44Z >0[?xgGsMtj˺ FWgFPƯqkmDf1NU75h&uMkSI̩9/DP"q*A.p8Mtfsz`%^v0/r.)~d^f'o5zRG`|;&Ef'e.zJ|hb/`cXԂf# Yj/s5XtzR*9hF)`$ D w#+" Zb̼H.ܾ~k!up>hײG9F 3WH*%t L]A^g0? 8.q3 gY"畠P_TIԞ"|E Nq~Ҫl1+hD^yʎ2R@RʄHk=n u`-t`, #σ˕֑+Q ?$;ҭǏm:O|m}# )?\cyNí㋲lob,hXlQ[NMz_d "fRtVy--A H7mD⑊Ȕ}Q*gʟ7J lEdq-#͙qFnLLCgQ[mF[ 0c" yiEol'i8oK.hd7>aY+Ui7vMu #%IY}6W::,cNhDVJK/ `P0Is/BS&Pko))zXI+O؎ұ 'k I<ї<`cSIo]W,+1 ۃrڸvʜick0Ӊ|Pa<f[@k@- fڜC,iL.x'Ԡt4 w|l}>vo &k| |wB4= Q&'NlS`.##V(IosVY~ZMOb \݀ߵD.qU)#V$Ώ pmCE" ›,;!|O/;Hn̹}L:g[{tq }<_P*0{)IՈ4nD6`DT3; KvqUNc]$5~m}\VzTXbfSzcΣ{:&7wr&J'ΐ LI=ǩ'{p/ڿ71 S)^qhUKkqM톧B<4 n򐡑'L {w1K_HwU-eCoRfY8Dj#2k$"3`0Akߪ ԟikH&蕶r)0e\U@8b̵FP`0/+" ȪNKDj,L|mWFQ ۞[TY _uȹxMxt{;ob4kH S8 *2F֋yT>LFon[~u^]؟FJy[[=g40za|+r3q¿>M'5B=?PN98{&,-reM?Dܞc+? 23ƚ*# ghqأyqF mG{Hr`X.,颷\πF,[CDqɜ &rT2z7DɍpR~{hΙ8G,VH?2;vFr:6,E8bT'`m^ w-oIN Wm'6AxzyYsG2C06&ȋmR{2!Fϐ<38s%X,Ijd>o %g ( ;/]S!"hLpU Kqr <gmlM5B r%/L:۬j' 1:nOQ:\ uv@ա%{&Qr_ zzo>dK]\m-P _ڃS>Ⴡj*aA^_tgD;\ 0[+i0jmڮqLݑqը >|>r3WM]|bsҨIS&qVs.H_)Oqiz* ,$xQ-O9pOq2Q'`Apnl&B%? 4G #@Ɬ:6gmqi3Qwa/R('$@#Mƾo-T(7"?o6~L٥L }s7Iy9V'4*zJDe<0WFKSƌ٢{k9lrXcܚٸ"OmNWڑړ_:y]M1> U苍pbTõQxw܄gg%-)˿kU)$+5pB0=*JYLKNCL03 ;yA@KGޑNgB]ƪ<[8EAXdUˌʒ`)TA0%Kl70< ㎦A.]ZvX 4ֈ. NkC3b7,9tF{'9oPQ u R~s=`W걄Ϣ:Okix<3e )6x1v5Ջf=Fl5po$bid|V3JeF`_  hR_;8-IFZ;&ՠ:Ɏ1W¡쐍UŘ#[:lL+x& "7ٸt?Wf5 NFOoyhxMv;.=ßwRy$"*uu!ZZ 8k 6 2i8-z?]o6vی,=*.dZ.ϔ{1tfHvj7Ec \·oeG8aa?I0 (0O)Z=Q&JJiJIsUKB~&dDUlXr\B8bEf';V?(Wkkăg+K>ն!Vk!s?{_8@c p1K \I͉7XdP ~B ȓnaShpZJ~'`{ޱd+C|!1ڑC;:]wu2m`HC`΁ Vt( :ol7a9W]WW'e(knV,zG` ,6 x G# $ 7.z<ج@tGun)S.d!ol'S̻DSAKo{,-hME\kwMdZ(e T^Eµ4Ϟ$-8zMr.,v s3KBȚ\2Ճ߆q7{ߜ甘x;KXjX7$= Wm-zv#߹}rZ^Rֿ#<8%z(պ<ʕ/v%"b1TIqsDcҞ;9?h y2_Ht[27vg-==L2LIK*uK ζ)fD`35Z'gPUwh$㫊eJdV=Z-|?<&~3D("'<j8VJϥX1Bswc,ƓFşj )@%C]@U{@%VxS~Zr7S* *D;KRMXNnj B㟂`>t?j2c.ФqiW~:\³)7>Eáݳ0ϲڱYR~XY-|j7yO4PUTͲ^1u߶߱ ?֨f/O,%sНg~=Tv*$/\І ^`[6ץ #S@&@}44%Ҏ/!;4A*S~g٤"~yiߊ*^ReTB؇»xIBսXb1&#WJ`6б㘤!ʢ}wEC!^nKo ̟Q\1Ʈ8w-><CuۖMԥdݜY(E裪@FY6 tV߈[Z/ԘSĎ: /ъzjk%'JغDv 6jP<{Gf1VqQnUv]u-^ZWWJQn;mǯI1A3Yygyn'hDy` D?: q 奋0˃.F6nseBzueg_Z`="{ 'EKp M\/JQ#`e5y=}ʗƈj+cكS2icO:QMHjg"acfw?^pl*1%,b+cԥ[)ҫgvikôO B YT+I)X1 ,SAzc7Z6CD.#SSD':1̀zhJ(#qKQq;r(t_<20gي̸U[={ #2ҜF(43R^q[.AQw%,l}!I-X*QN/BhaKVw,҉\&iI0& a&Tk+p{tbiV>u'sF[yʱ͐ܟ`l4b. y7IǹވCƧ/Ğ1;s͘bCiG/f_NиYջaҀFR}E< 쐹Ip(;DF@|Rn̛ۨv|#xYz'eylgZ ,} riK u.&d(2>Q6_4iEb&Lh2{, Dsdd5Km-2ھ=_"Z +#ji5`?'#ZfQA`$~ԫG8- c D PFsAF'ʉb>/̹+~0:˦/cK5 j;PP~~=%ͺkN}Aѧru?W;9U"RHu#moKa>_ ipD)g&hKDj_U)! =#z9A0?HLdcy1 _bKkaX9'g=2 a[.^osţ3DQ .{bRCOK<3/&DE"^*pSU"|3M` *J;)T3p3r# i&Mi\gY8^<@]ve-똺VlmvS,s3|f@_ \aWm0T(A-!H1(v2ASEjJ8bHV'%gyl$XGʝ 脃IwSI'A$\>co90\9vM_$܃ t谉դmKTʰq&('pBw)}frY+Xlvӑs_Cҗ+S{.)7>gJꯦzmS^Ƿ\Ogw4JjAf{@D˙Coy @!a\_ZҖe/f:Sf\!P 44Fo·7-($_KRKdߑwJ~BR}2̇sjpo{jXfJo8Đ pw6S&|(ʠV4iVIzήLUQn@Yt4hYݳڐAg!:=;瀤(딞G7wum(|adםFC!j紱* JvոQ]_aIw:Da`Tۋ bV]ˀQU ʂTh1U2:j["D\24L -jOY!ԛ@\@Qvzic66B_(rXV&3FklӔz m ILzKIg̙ .|8ġu( t=Nф. K4H`BrHSA=DŽJDn&hWt( t?ye_yi nhg * θ}8%^MMAb H& 4;U%TMPEqxU0pH*=>8Rt<*=r} iwEvJСQ K 1m5(Aaiogmg6 ̣Gx]}_]'݀akJc2q>|j_ʕ2K]^R6{.fnN!LǕѩ 6,AqhhceCL-AKI4$ tx>a0 Ȧ4ǧ0t*1A~BAb\H1vKZA/gZhTS~ˮJ j>X2["sP*؂b coU[CɘrFzXkH~n ya H,aШg[*r9m.ܝO|ؠ!ƕvDvM+aGw##cq58RPt P;6TF|S#?y5n|n7ݷxй0.) 6\ [kӟ` ,F:L!a+wu%a@xYEhC-X̐4/=J0~]㌁ qls '~֨y\gV[CyuY.waE/Oѯ6ZkPKIiFT a }P "u*OJi~.a\g413 H֣TY^@.zĮI1&R7a[4=zAhJy!dcl3:zdj@ܹo[,s A ;=pos{7~`u1 nŁ=]=3 S[(h*ꄚj{Bn*`V9DZ35^ P2AP}V0« QA`%'j~H;}yQ3,'@}<VV;Γbhߪe Y3['' (b3={흊[T5WQQ!W\t2'd:S4p_rCU`TZjD\s&ȈgSm5'BbThW2Hwڂ[6oq+>:hy[/Ů3~saudGހ\44`WIV+<|px=ϊK &H~ ?5@RV0BPA< ~oJ!Џ8ז-yG&P7Ȟ yeM]#W=q&wC4IXdpO mxž%D7c~ Pw7|<>|()]25X?b;X;SiMXr3&dꊌC& K {6gj22 ~)=鮄҆ vӠݮhq qQ2Pɫk t\c=Jy^ϕH*qA %q5-=6 |}ط&U!T7A7mz5O~cPhM7NR'ؐu1_ n9!-<3[%m"L֫R/~Ϛu vKhK') {mAF+e܍.]D5S>Ikl(/N%jƝ;tE+57}msUIP;l,[8w>>{ KnPF'4Tzcڪ(mBrZS/EKϛ!wn*}| o/ w7]͗j$Xz%XvU:C:#! RGe =H6HEbB\tONo~`"z]31qxvJjZJ~4Ӈ3ۘ5)jrͼ#`0yl 09&k]v{ی~/*Zx:-.N<Cg#o>kyAk$B<;T"\E|#zڜ2@cB7ʻ^ؗvQ֟-W_oTQk39g:7\L7F "^81\K˅l=6ﭛ-iXz ~zOP럤x/-7"!tI^3Wyemt:d$:+x%5[Jrx7)\er̩lXѹ9cyI:-pu5#7q>Ke]Nu-&3i|8ī \ZxA۔0l^D F&m$s񄮏[rJϐDlI"Sߖ' Ԙ¼YlQF?xkdz'ẁֵLĎψ?$Q7tٍ7Z^2R eF,|ĔFy7F}ѯ? [8ߢ0@XXvؔ-!l|Pcמm}j|)@Ny#le.TPaO z%Q Wxmx0,*kW: XS/"A6 NW+`j92(0i .iv] +混8quXT~`u<ULK_q@ }ᐱVSˣ2˛eƣW.a\I_fp[`.xvHq/M q ʢ)ZbX2$T/ƍ2%˃Zڗ z+%B<AmviygOJ>1l̼452ua lhSZ_i+QZhs:y_j٣:q?#iMVp8-Tֆo֊g0?[x^*:J~3N:T7Q&l-;Â|Dj҇ <7Nkdu ' AA_LDa)k&hhp,oA<$"-⯾%HVTޑ=v^'^ȐZ01aV i* "R( q{s(m`rdԁ ²<kVm=݄[s1D瞯5o~Pi ;kDBA_{EYoLF @%WNP9\j$+|wB7 +JxZN'Fb039~wv'q Qn/]1D 3:15Dgo}>q[FA<÷F)R[ZU1Ic 0ȚQVz:W٫󫶰]/44#tOJ$j4M}O 5<$b$>0xP"'Eð vqޔṔ>a=u'vbItL̝]W$b֏Y<$"~H洞3̮S;_)5sBP;65.oAVbva5as}gz Slm 'lCCU ruc7X*߲5]<4|Llkuv_)2V߼GS"X(K̦T{&4i{+nZH<Of-ʃo&j~~r\ƉwjKz􂬄 Yn12Bg+ H?ᑭg `IŬy>5o~7\S*k}|SW$[տfer;̥^1A{ylZmks  x^z@_UÊͨuEX|v>ma&̰tcQ &ЈerC'  |]A *#I+K\/|- a-/CM/@XBLfQW}i*VpF& Jxf`wr*;Ɠ9Cuc)L@jcFuॗZR+ pG=Fك,2.AvGz ˄ر)'#)Q6KU@Oj9̥\Ҹ׽qyz9܇щ337^]EECO~' WnTl?&\gE i(> zHu\DWfͲ)bi0%\wr~E6-? ש,AG!#v22)W k{hQa7 HO㰌CJ?Ij Qcnvu E|&ZslJ6#@`֏ %vs+93ҡdU6򂭢 -R٤lY:waЛlV-h]Um%ʠ(puKuWWQ z7D}*׌CQ%䜶EW=7H@8T< M$m. c-'S୘oBG, +TL+Km:m7k}lޱR;T /M`$m]lF<&cBr%Zx:=c$[S݈})JqO CYίwyN :Ff?[w'mhn%$iE&,7_}u֯2[dc#*aƩX+-y쥘e,)/ ]El,TMA[ `p#:'$$Zu Aإ{aoVbSnIdUNz{va0#At.lp{[B):U)# bXa&}: oAa#"GՒhɍ8jîYJ=}܍ߚpX=-H!.1R8Q9{ %?~iP$3odM^/ٮ|Hsx-bAJjEC HLgJXNZ)iN5Lf՟T7BlU5| aE"pWmnH ePoƀFukkl`[pKidap!|d$:\(tO [(;y AVj{WoהBgq% QMJgTI:1bEMf2PK4gGlfv (q<6uEHCxR7Rw7_}IYyuet2q# Q(0ގ.ܞS^P`c=7=*!7Hq0[ʊZ3]0PMI0*E/b&LPoǢ0{IL9Y\^Gwk1kl/1 ^WIeS쫓;7 !L2o4:6/a:q~^&zvE.5Rx뀃W[Ɩ HbɆ[0|aU˩ˆjF&e5 $.>'=)6 ] CQ);ɤec#yi75|pw0 1k58m%p?Oj.!,hT6?ZAd?S[{5c$=ݸA}mRBqy"&0;>Ea3)gNs|Jx]2%cqq(Ʃbj!s8.Գ4vϫ kqee<@ܼEd~$P\\Vsw"Thv5t.䱾JV}%nXsVI)GoA`]/ɽnB@Oʯvަ(nc5Ckkyu7?m+S"5_h # ;hԵR/^P7737uB,4㔛.Uh!X#-{v.%|ZRei0\+@W||Z D!a(5cęNݣu` #uz>CksU%.. ŀ :@\Rv L $f<)O{^4eґ˽_kl<lGPfF]jJF;8.D&^v7yK^ޅDX, FXi kJ&Tyo7vI~cy@,ן%X’0=7M4-i'% %XxTrӒr($j8U͒]}I|}4?v%s =Xv@3R:S8w،EsvzkDs#-4">6r\ 󇳼ţ[C|XmiYg$Y{}TX Z[?c|bBS6u_0ƳJC鬔HiK7̺CoWx/d@{.L+~Y:^y=AJ}`Ƣ(`S:/X*~TlaV|ay1&1BNH~*TϹng]s3Qɿzx盪?$T8׽N* xt ۿ \P[[~Jؘ5K}$IQE kA|B=)2ygmX6fJv\wLpa>fl9)'bAкl45LO䍳p D& ޲=i8j, ?FFPyoНtQsfA&(0ME )Q JhkpXj䨆 )P?#\)txE t&R ᑱ~`RrnuThڌVlw3*.V$df<3 1ٱm{{B~&EM?Vdc;jRP{ǦI"P+<$+CH"(WaTԻ͊05ʶYǛM|gp',IuK Ba(מNӟyriu]n]jV'E0ޜ"fd9PLp2ĴਆvQ$~_ROV1qv ZcX/w|'Ѿ\/ lUҦ 'P[E(T/b;~I|Q7.#]Fqidh3NDv \j@ramC$EU5h[O5ALW7Um>aȿje$4]H{Ũ< ?NJҏz:81@sQz`R7׮Ӌ Uz>RZhoځ-9:\Ct,10`՗WfvVqEHA;Vޕf/Eч20)hfg0 CVDz)ekN,&F * ?Ո˜ pv":~OA-'dgQEzWpHD0_o= =B[z_$1UTH^HɘygZ(/&eӕ|o&sz׷%GI'ӸKl} G?@u/TaDŽ$T66E:%"JKryG}s=2rFvċ"d rH͉$ eLOG֏XûC$8 8:oNx\Y.yDڈ{#j& V'eOFc_\$BZ QHmN \eR4}>\U w^CHJ3ED>gk'I.b=ʬ._`CHPg'S!"fTnH1%W&~jqM`b2ݞaoO)jЧg:z|5o<yJdWye0y]&֧tGjSfr`7ފ6j7$ȡ{A^`aǵ𖔙5V"ZO+ZFGg]8hK 6B C nڑKk'R^DX^"IIA)بv+*ػhW!bp_pObxG ՠrP #^C(i3Xl̛ge]\)(aX(u =oR' >ŦM/QvZ g j[+W-ѧ\>*oGrjR Ո[ V *רOCol풉=D&G-cM4T+F H+D#IӼT0NAFX,2К0JªHΙ $xu}/xlx9! We'T3'5J輔Ի5 2T<0W?նwVERl%t=3#j)Y#ɠ|Jg:OԚo'ԅ7=LWg]i`J rN D>cc$L²k2gΞtVdw@YOpUSMkc/4]3,KHc`O2s{!Xtl[@#rYC jלrҡWl}>{RAƈyݳTmQܵMꅢwx7#fiP=)Cm,'^ٛ 8ٖj\M,dVc42\ɉ{U >_[KP fW {0Fb,=IUu9Y_:'nHm6p?ukC켖 vo[g@ou.[>ȷnde`Q8Dutj? G4!?&gDv ¾mZў́E]dG6WVHTP^>lv5 |ߜ J\j V*R+)`C"߅Cȗ[维9(_kTƇKlAEW@/1qKw]XqfX_Yij#SuOtGy w\)g' o-^E]\Y|r˼fO/d=$i$2_+ZO[w!B4W] >`hN*&I?kOǰ߻T6.n 5{|K)x'F0 E|%4a7;w, M^Z$4{C+Q'%n3Ud 59*4H*' !؎OLSA0 z]ޝĨм'ee%NDHWXNb4d{*)Fm$64[Tw㹐ԔF`k_*Ag}[5DS{VP!`ʋqsxlPMw%E_}Ӄ0K77V/}#]l}@5f&&ʧh- F;O~3P/+xx sCe/D&Θ9$~բ,vrh!*R4eڲQZL,JG[QԃO'-ސݜ4&3#gl͒ڑ[3T'i<sřr G??(fVk Y wsľ>(}/ȟRMJN~1 XIRgKUn>Qk0E&1f:GgPWv;ӳ˹ƍQi~>]um{tr~|>婎kKQ_}P"{G0O7t,\'6Oy$n_&h qg.>?$ 8S+PiMAR-I0RWq=]CՅ1nt Ls5K ,mHjT-k\^@MנBur~cI&^S1>"TaH ,gY'aVEX[bhJ%a!ԋȸi`Л;5q@8ڑB,bϸ}K؈\v;B6E{+wEԐ[/tH_ܗW ݺh78M{ܠ3̠oXYXRSXikp!pf_"q !O0Lq;[5}˕, קO +WX[$A sȮ%ar \oNeg: b 㙥 M$JBpnFek !ҟkvQQyTy&!Radqd_ 93߁a#I)Zh\&ܝeC4iIG VzQ\ilvй>q`͖F{qaESN,C^_$J@,[~tٽY@7][؀D" _+4Bo~ i5x )ӽS2̟t֟lN絾!*qB*,eƓ!M[>7]U^FO- vV(H4nPlA Vm*E`Q׫ E bZ%G@跈B:BN A8SvhC YD'(U)ݎ)K&0ǡ>G=oNƃ2JJ `hVj,I>M22j{s _R ;>mK{]HΰB1lo{-o4 yF!qGX%#1_҂A|k?8w6wgHuPSeF{!z7])T;Djr] b nN@vQf1PIV12iYc@Qs //bC~zBUJM=|f|uvU/e*0Y KIə)]PG $L>ŰbVSAӇ*=?L@<JsYL{ꩵ:! Ml=}Fh{#-?\RWн6 |o|HWYVpW3>A0hXkUL{`t, CruWI14d."߃=E=Q Gu0BB̰_j_<"=EgoWS"B&g("Gӄ~ʲu_EI\̡ N>gOl8"_37-ȁ5"PW6h3„8`;\GlpǝYoiLǜYtiB@n!|oJ3pZ>5֊F/C(oyIrU7M$.8iIT%Mc1Y#?Zf=}Cque/:0L4{}ϳ\ه, H٦ iww|i-UCƢlU8gOA|y Da7jpS0uaSM UB`v)^aQ6W7׶+Hn۞TZ)eEÄ95(&YՏg p..,&ux%ҦYo{Yl_I ڝUb)Xf~ }HE1yn6NQdSO{1O_LFApYTtla#nM-E#±9H ވqk=Mޣ%fweΘlBبW`{AtU1\R~[t`%bӂ~0chm$AB_l~gn@7{Zv -ُNEf>}qoAEF)̛W0q]~kÊ@ SXOG x>{ʴxKSu^9f jN1Ez6eݟ}v6)ĂjcW$S!6Mnc}ry8: uLW!-| ~^T(bi?2n>2 CfYx*J7_Y挲 F'7l Y&sCɫN*<;ōY&W!*^Aiyd'a&"iRh*.NH:Vp/m"L~Ͽԅp("* d;9ZTFjX~T "v{+Q=: A^,'ƞ$n6[;Oɦ>ǀCUn2)HN8^G  -bskȪٰw*p5%9珿eNA^&bXwQ(2kG|A{܁:񛇞G4CES715%Vw לs㔾C=^e%# |V[8Ç_(tdjx;yٰ45x%dl4 qbF{=-1:^_WϽrJfj&8,lvV=th[49ۣ5Uol$b,'L|Pϛ3l[~zp?#WUL!L% z'Ma4%eKJYJ1^ؕ :r`K{QYS%64|xuӉXם76(e0:0NDy;@sX,Q1B\ zb\}gv w||VTEcM6_dVijv|U.HC}-7bn wegfKMl`|c9NH!%4 -4Z h],@yʺO-D-=jlXɡѵͫ' j(5)SV؃'$b5YEE\;T4-Ks',P{*S"1͙\b 6=V@bx8V_g5'&ZB;'sZZKr< oWt1M/I2B`5)2L;ΕE HѶ{L7Gb, ;9#u_BlwwFFф@ֱ\ⶳ 0h_AW{ m~d}]mśĊsQwޯlCH{kC'G`FvlX_oG ,~RK\ ۱&gR! 9#o^0 }=1d7b.b HTogOrVyqń['IIuYಀm*Nc)?oC%I6丟A|Rp"ue VeT!cDBLyxtjƻr_E=kHb7AeG7CB `&2A TqHBҏF51$*D儧n秐2ߪ RaG;5τ #UkR;x)= ZjB|iPCMjx-LXs^݇WB9>숝-HH\T#Jk,*F [ȵ\OUD Wϋd+6z?q3Z 8P0l b2ny` _0,m8T~5rVea_hUa5_KmҴtDtlJQl)xE3 0@Li/*Sp>nzN6vR۰) O!`p z%ՍXMA Anʫ59A-py2_(Ž3`FݙѪ ۡ_T ׯ9cG []xN!Yߧ(u[BNy*(mZÞ#W9 aDd\&LyB☢52pTІz<#_"% b7&#{Ko5גּJΰq e -\M`#n'oF q?*H[Z:SLWo%a49AvQ GLΟn9mfΌV"OQ"Ylu2 +ɖ0pdGKْ_doӱ։+\(Z< b}ѣG|p"U u IKi80NHz{o%}O|(=SN ft+f8R RF!璕䦾N8AϞbL| >F *O s{- ѻ#Fl!*Ya1TK"|B 嫶!NXL[7 ?c⷏S ` B 4H=U# zZjۣ3,k$*@5tzM1(V!?SδG5=ܜ-ˎAQq"I%>܃]!9+=ieY/_@K7fn9y]ZQJ0R^DJKr%SCK53bף:^;o䍿-{bTc ߿s'D]}&΄gK|pd77Jltu?nf2Gc9x_׹9i=o.ȖɈY8*u=Tv2cSȼ\g댦5đH[ֿ< Xo~Ѷs.+{CbZ&8m${R_H)9S~`>"nޞ^~`ILSgy8DU )Xov ˚ Ubhe/ݔHzu xdO[=R$ x,wx׎_NkH'vkꐚr!W`.B9t3WMӿM`Kv$oT ?Dyu&} XXC;?)APďNzY)^ٻeWvax:pz~c01XIIBd=nq~ErO1Zp*!ه̲ځl|!ǻsPXvsfdbo-?C03/6ԞΔ5m#Yæ3LLޮ DӇ+B} R[l'V9LlW#EXLyӰQ%4LM#QuC}A`\lD9xEF̻9(fmZlR·2l,^M;Tqu=]&iZ>L0ٲ0Halff@yzr;e y+Jc_tMC1‰g8j|VO?vY :g֐g6͍N)NViAc(:z}qy ay"pK^|HqO1#9fxw+eXu eR6RO*(prݪ Zn]Q{AͿ$042ĚmoCl}@vtPEe?aX `␪{j& reӥTelpf=>Z"ZE4xM*cMIF]0:=ju )bTUXbhzFrBePi>Fd{3Lb&4kT 1+4Qʢ_.7^!R ڄ JP$g\sT٠>c>P*Jq𻯁:hݐ+K |[1nQ8Ri|ك9?~룜1F֚|[u(k5T\hvI)(hW^K)RؼȂ~=p!F袌l6ݭh]\=꟣FX&w5W}TN5h-a][꤄V1mJ)U]m.s<*9c97B,H*DT҉\z/ -̭gAj?a?Ql" r$ ~!yi(}}Efb&DL]A |)-Ƥ^]j\{zKcWA|؅ \|/$u{Am rcUqy*w& MBA Wۈq4cH,T.l:Xi :n۱ẗ́ _@MSDTF?e"] )s%54Үzf||Wӎu"nRWf#_S;Ժ3݊Јspx?m44 B:s;7Ri\4c4suI xR'BZuz+g78Tu,˥q(`XZ} {!"+gţy>@F%ih ͋' 8k~3@,I]ZʣÜޖp-f'kXpaS^P$G`yR~( l`/jZN(QH/|ҪgTaҐl,:7&r|} kO0ЊpHҝ ._SR=4B.5$K lɪw pK8щ턔;خvkr5)Wcƅ䌜;1Ou[tث=g; T?R5)Wזʋt@m< QlaJ]bsl $Z+촱PG.T M>}b.g\R 07fQ#VtΚM3z[} ;PT=?rNT:| @瀷"yFS*-(ma)#O3UpB5 4,D֦쌟3؅P8f-q\*^7WXЦ_]L%lXp3g[{ `LQW+D*g _ XGCQz$ `kԄ0@rЊen4?-&  {foC?0̣DDrwA a[F+ y'cJ26G]޴vp:$ $p5?Nl!0@-.W37)b HE`\I` R%ݚpO *m{(C|8bQ[:+iL8Ͷ Zhd9aK O~=c㤝M;X=^ԠNHs͈,>HLY2t$@Wc cF&5%}Dž R8˵X3n7mF_HZnГ%jHaEi熴C4_ t`)=8g,/C%BĽ}{ (yQ;ab+ , r.rZDb%^+֖퀅/nZ$;q;ob4ՈvvSge:瞤 /hHxj_@+5ޠ,*)` uJq>;HRK^9[\/rJˑƑea_~D($ t,\9-z/6j_w% yČ]lDKBDnJS,GL;Tl1բY_ W{3vK;!96,ۤ.l5]O_ %>55ZB귪(Q,@+ykN0DwsYƁߎEx:c.ᒣQ!<@c0T8B`zqJCȄS oI@ Y{8p-艖mć#譇4NyZ$k2MƉHWhcFC4. JJ}?~&x!2׮+M_ ^rutio'V;~5[6TY+/%̙iM-hŤ{{ u$r6Q& K^g*Fk(K9tp،la%3ܖ? @xe>Af,Kr=w;+2m4 <@0Zn`4&JKG+0j7ď@IC?y,8G?Y%ea `0$~Qo-qf ,l7Xݦ PgۮUXW䘱UM?SWSiSz"S2Zj!$"FI$YYvcL"d5L5.WjuT @a|0m):\:tۡ7eEӛPq0d4nsO}cEwPMrp0ag=6kBibֱ䎿)/]@7ZNq,@Dhkxqu3+1d0T67gWɂ&ǍErيOбt$[l k*\kY:P\7Nl^Jho*[ {֚#62, TCTN'nFW4͠YOp53о/gzeO#+8"")i,B+ vvXL)*e# x2'cPIe*/1ۘ z\U{J':"E63lJ&?ب|. GoC$iu>,0i>ت-nN(:5QdO\HHgW:p*sa+XJўt~4X@m7j{^\O M"2,JY9#xOWZPߤLMAϊ *-RMԁo)ݑQ슩y7EsZVdzd2+x~nJqk#ZA,y}\aVeUWCR\smqyb[S?(8GІP/{,_; |q|Z jyڋMH^nTo8>>4JpY  K/6SdS h#}*v Fs]V A^ ׅQ 8}|ZTa9};Uj&(s <€&uӎb BJSm)b_)d-'ihr>Ov`x=ZΩ@[sO;upUq9V#7+,I6 -UG&^A*NAutT x.:h0 z,v(GT/eOQs#^_;E4م|v7J8⭴a3S<6d7T@>w8,k/;~?+ۍ/⠊tKm.7U%w9 £<0: U"#=~wg9&vIP$|Q0E5{4p[Jy&UZby6&sX{d˒+>1 *|gNՌ_ Mb9s78.T{ϊ"A{UӖi|Ÿa$.ugk|lv bQq?wdrN!1>CQ̀(3Z:_|;`>ԕ1*˴q78>̶=2XLx/FOGG>R(tiYj?c#i&q2YYknd<ƴt 2;S Fl.Fw[)֒{\z2Lzj:tihZrԘ]bր=_:"}aP5bT"넬V~@5(}x)ϕ6c*[@b6)<ܮtmv^UF'44rSxY}\Ѽ[q8YNf6.*G<%9]ZNħ:M4v㫼O+c4iCKHP$j‹\JBqW*h #_mi8'cOa<%?*3ny{JFd:zź`y0*GlŠ\VaZB[bLqFHMTwx-\#{auGvR¾·o&& 'iAމH_rRۧS zgQ q$|*Ѝz.j;ƹH m {&eh2o#Yo8FGo4lˮA ! yBpQo seGcM~OCօy1|]w( G9mfkdNMT!Rˣ+tT't"F3}>Q2>Ju&m(z5D|YPi/\JPo"#ZEKT:9ďɫUfݾc~YTKDVU0ˈÂ)E`!zZq `|2 9?(@H6XD垚e)m1 9K!GD XNk^w_;I5tQcLͧ ,\kxX\|)~\Q06@|)G{~s;CL}5ISiw@ OdZT,/~.1}ֻm(59n@՛ދa~y=B?c .acȶ+*&AMYe׶õ#͘ejN؋e,X杚ӆDЅ\wSsx H,ɌCBJ)Xg[ul un4=qk^V B5v1_7@ULD+XTR])ī&a׮T.?leXYFS^<ݑ8[*OnjBafqb-[MGzlG&P-_,SW#;1Ly^5'*mgm +U7^b `1ָ\dD(_/g,!as#'3qU>0. Zx,s2 }~sZcQRfpMO`WuuiAH)ҷkZe ,/2;Wo{oƆ2sޤ}uW/a@:#Lm\!K,W`̠}0pI-z0zƻI:E,;v`)9k  l~)ԕw& \cCS;c~\5w}Pҳ鮁HSV=НK *iP\;zId[NV])Ntb9u]6#?^H=SŰ}R^kBHńjyy]⭻{a5qqEmQ,5DgE`Q90sgLQvFF!sՅ"恒׮AzzA#^pX дk" hҪuPJnକ 0&JG,B'W} 9(S9dT;}T-rQ@ 7 r-焯@Ľ/g5fF&DE}^e4ieXP\e1^*k d=yf1'{f Sݓ#RuU57L6oFcoa Ohi8Т>g)P6=#qmQgfC`c@!T.!1bT٢#L'A|įj)QgM5Ɋ8))_lϞʮXT |d|H7Hm9xMn㨩GXÓpֹ, )v[{:YQ{Br(r\QcH)*ԶLѿ,FSmYQʯ扖A6!GZ}W-%Xf $UQdzux!U?M_ D0wIFk1P^[қo{A<Ӣ#1Ylr/W߹\K=sJs`wyÜ;F/)qAݩv^)`lp{ ̚Qꏞb33:cϺQ"5:NvE(oρ>p@p<٤boPDfC rVHaF.d-ee#v|s2w3uE%h'2b[u 7㡶2[ޏF-nШu.f[zjw)'ҡ\3VlJJp'/ZqAK=pd}vv#z.*!j=H[͓pmd> ܭQ^RƂ ٖp.5'x0tu\'Q6bd#iq#r- dKͲ3m &/mak{.ŖX ےW&3R{ZHPj}W`5 }׺l\ptGhj@ՒA) QM^_5dT=x!qt-RmClCH`B,lU#HJgd"A*Σgi)ldGԓB,۬ p1WS˄؍-i7 \prI#v37(E@V)_Hb+ˉ@) vS@0f;( 1QYVA7911t*Umzds7f<*kD*/ei~eE9U[) "HIܨ0VM '@KOf 6L֯ 鳍)0de_!eJd %Q$+KC^M*560Pڌktz3˞^̝JIn &Rbl#rʿbKm-[Hv ;ytY|%6 w3N;&Ct;Dh0p))fITf\F! }뽇Td;+:l9c3Gml|=ڹa Z}CIg /xBqN)J+!Ҹ\ m*}|,:<rkO*rWG4/9ZdM, Nx /D{;8-9YM9iHXN݋sod[ś8+GQؒ v/Ȯ`wCh.+bۋxd*HCm\NZJx)m{k&#GĶC;\O#x1;I]aL`$ l꽺"M '|d `s5ݥ{l ]류I y(z99 R}A$* Px9_۴E v }=-gua Gw~J@'An"* " ;Vluy"mTH@ҼJҮˎDsnҮ[dI>>ZG.Tгh Y{!<0JHuUJ1-.Sṳ.籧X[%£"1QI>jUҾ@*4_Y ] a\xTK0"-+QseYw,/˕Q|1)T El<a`" G&J0]1B+3!C3_ X<(epRR b##߸^يyր⭆&:g aUj#V3_{'i sEBf])whߺ.v}޿s+@2+JRIwHB,]>3}sƾ5X" r˧D:&7bRqĺvbh5,+]!IK,fM^RE]šUoiDWfAI<8e0ZFXBҪh jQ05GuyjعRBr."jw{Yvp'b&%B NLKa˿̀WI1f$ &eߪ ɜnF'C:\bxLܥ=-8[;CWك2[Khryg3nqP=Fɬݲs1ֆѬA2NN`]"ϻvs8=4a= Ml] \] hWvW;UPlNdqn'# [I;:S!{`њxDvq>,P <8RFu64b#*@A?&X٧iFiV0Er~^ZxVK#Jj{WI) {8'ҀAFND0}rc&zXҧoH3|]w`I2NSB){;{} r }QƷ;ziV4wXHת(kMVwhN`P]U|,~XB{'XxM«Iq]:R-+uIsuyREOnXz"q*:|y>uyrv_oGnӗ{Gh5[ .8u [4yjaU|Y v{$/2~Z W"]?7e*]x}^jǭ,DQ$dT@2)uTղ\0ٔ/rtuM c' ! l޷Bb_ RR@Ҟ&׮ٶߗ{DEO t ySW;*tSY~XeR$SR[Tx5{X~R5֝m a?o8Ʉ5"Dsq'EZfeɭQȍ_;fA]DKۖZL( 4q̂f[I#R`"!RУép%{o^&2lc C3K PSfPUgl֖!E#R{X]w |d\/7θLC94D^ޗ@7} s[H]RŐHH P []|{>؆: #U ) ?cKD@y)cZitԐ@.s`.\Nu{4Pk*lugNlR:`Of JTѤ@ԾWߒ卒#څH}scFX Bum8ɣQlg<F3”ΔŠJYRΫ4'up1hݯ0Kݓ`,Tc0<Bln~j5pO]Й~8 t} I yv$,6 Mt:V_OKVẀ\-ᚄ;1}D2KbױVγB1QBUzLZRC=W+vk_-:Lovj՘=y =#?ܒ LV5!WHGyv\a%WZ%FY'P}p@saPP%N7T|;M !fM|M/_tQ`C- 8e[)V jʰ&Kbp;}GV|ݮ&3(K#;|W\+ sGyeCݪgZKg7DOKAޞiyq $xE^2)xQFe!Yw$P-sxVl!otq [ܨ1 @V:OSIpB# 9%kV,5 s%zvP][5*Ff 5w 5\0$$Ftg=!p9ܛZuDZ0/d%w83.TF6i(.2L V|rs~<ܯSh»HJ񷎋2PTJ%J+9B=U'lxxTHV 15 .4dz4>4JMT-A:x֧ۧ,DTJ˿a!!S2<`G5qǪq?f7U>Ko;q TPęςK&燕#0apF  $(#yڬwBg ٿ`l$`E}ف拐5}oUdy))N /opC0KgKdu_Fk6YWJ 6,0 ;]d85;z.IR.O?}{,3&l0 ^]:55Nljz?^ TODϞeNL*#h5D房'VF`GVLR(,|`4C,B'guʧ[&eal2`T}&Us#킃C5!}3o)߂̫ĢvjQ;KKcȊC/,4_RkmNN N}1gkľ?@ǹ񹸱&>!ܵi{k w줥}̸r  *mo'g!4-Ѝ%:[D)D}En/D4kS~l;JiR6 F%@ 68(R|9ZVLOD&<o'_ˈR '^ŁnSpH*V|?筚!vSWbGqĊ_P+s ?0UdMX4sm/뫃:h-円/ˣpg'3έoF-3|R =1#&[J20* hՂLbnTfUb<&eNԶșADKJGKUqwb\u BÛRx$!"y:'I,$ph4$¥.o>v%]FK}S*76A!ܔhc Ja WrnI! ʚvunZ^,Kd̺5G=k2UH)efvIڱR3چ wٞ'xh?GO'' ݠHĢy|0[ j4!Pw;obͬ{߮G/$P piv{7scր9L2PI L)R! V:yT &E3s/tY1sAZ{46"tA4Zšspj*k;fWYPmj.THA"p[s5Ԟ-J|Pof.möwP J,REeP}Bmx7J* `jƨh!V?}`8_m[AFXAGTk~~trI=kܖ\ [! GH*g嬬mK39 <P@gg@!ө C_zѓoޫd),V-/P,ps+̧!c^$e#h)9BHY_phd8Neh1Rn"p%3xZR{ռ 6N01\r(3c[R ,h9 Ip4;ɉWq\-*_|%c<~ymG#NS}Uҙ&%yC.[w8Cu4( 9CpNմ?FEYEE:GƉ?Ša̷J:pY3t6BpJԤUhuA *%G8CwxMQɥ *Q4"ȒK[IFb~!+H򀫅Bۆ?5a,!5M7L-}IąplC$ǜX9O|LRܨ2IQ,ˑxܰ=X&@c[ѕsȧ`Ǯ#̈= vۙ< udZ}ۆ6'bx"ZTv"u|gX,hqD-7Dx)6KPAJ**܅O:  BhgRP=p!2CaS *ЗEYTjo/MhP%;T kziW+#Gj!9>+'C)ޓcF R+^N J Bݤ;{:gE 8_ *Es?Pgz[-l놌c`f/Cwz){m4*%%ӓP#\7[{F 'ӑaHє%[>oʷGCgdbUɓb49rA0tVޗ Ȍp'iÛ˪&rޯz⣝dzJ[!:ET0=)u.Na›XW^,(ѿ^@8Вd)$F"ݫCXQzZDMGIwv ,A?3> _> |h'|^_S7!ohb! kH<|c}sGX)p(%!zK04dqyBk!z&AC̐f& rޙOkS& 'Mʇ06p;E Sm( Cmi5]1SNa2f_LcSύmߚ]=3|ubv+_DܩWbO>n`cuf{1~ЗϺQVa+;"$H@,63u ]92^;娒&D$|8|?SY%rb%3+!ёҶ*^0U42wqO !We{G8`8&繸pC\<>9yESFU9zTIF-ۛxmçAJnQ m,P$ZlOȥ軻o h=}M}(ºq9)UuS qx['l<#O;ػWfi 2Fx)+Y21 Cܵp.n|])ɴDf}bdX@q wqo\$J΋n ~%uH}wE`iR>a^L +q 2CnloK.ۂ-cmEQH0íT qNNHgkih?Q0ABr*[mvj6Wa3t7h hTX\eg'|2-ζdOEZOD8M h k ~Yy׀l(!+8PD!?[ 9ލ.خw e-.); 3ʀO%I)/;MG`պx4_*uxI$nr8GoL!y-AKlӝU^3ikw꣋}MƱyN߰HP*YWCBQ;'q;Sx8<*Iܰ\:;Bl"e69,cGx]'qԧD3N:qmb󔼊ɼb\f`3gmgBtUfQJ $\H7&H}yn:PhI{E??uCN=cz߫D=v2\=epXN_^5|hw ]4rA#2nUn#+i}v_ ƷL&oh1-j:anAK20n]L|lE<1qiSDI^8k>D[6G:j əYbÍ}D˨6UQA9hf\'^0̩s`H 5G(9X !~jb7܉ J0[}$ f>,[:>xF(a2?G{RGᡂeb50YM`Jr}!PNueMD趉5E)qQ{k e P|xOsH;jhӛY~!2bh@1ށd%b]CȩAwf i6ҟ?ыV{6aWӮ[b\j뭃9ćjtY); RTji3AhEZ>jPYd)`+k|"*Z&ks{P+Gt`nOVpF´t7v14`x%uDxQe5PxU%ԟFãEGƒAqMR5 :Ȱrr.&Z,.,O#ANDM(S\OC[$Od><=Q$!}5cv2Sm *z#vh`pS]S%kEƌ6d,U7F6R?GIzݮuG㮉y(޾;cиv +q+~eotlݙ7#\Iύy;$6;7࿛K]֪ܿxOY9b?0"=X e E=w3RĴ/&Lv*{[=P0 |,tR|f4 .\\θE~=H9r$501G 2T9`lƽ1KR_A1N|h^1[<纱rL ;@?7-tuqE6gS2SrxOƣL{&ړ,BURC } ;y@ QߝnNgk%p } »v<+\ze?Wd/5`aN-ybSUٺ * i'\iao ;K{VIDyk"ułw ?SHAn gWU2F{ڵKyYmR(5+J|KآB , X5m 6=\/d1sE/,gqr& n8%aP2hlONbYwWv> 0\Iǔ{_R o骺 WڮUuje;]gȈTY ̠['W8fgʏo8ɮ,\JDPF7Bwb~ӻG,my>&w1er]HTw,_$ftŸtRν7(a 7\VdoY#@xZ0.-.q ++f^'k]߁}w %f~ [}m| n]W:ݢWXUgCWBhݳǥ=Jׯ52f6pIŢͺpˏ B-@F!nޮs@].ϫq[K 3%~|0OI֩! CIpQ܄qy9Ql't. X8"__ģ@CՄC?j&WF̟BvPl}ѸI(n1Ȭ+- 4 -.,ʀӵ/Sۛ}n#ΎuQ_b:0ELLB+;agn@{+校 Ӡ5@0;hA̢4s8iux <zSfͷeVoSc7k=AQD}\'r͆I "\&+rF$0r)`VJx6yKcG^VwX-ޫvx{Zu(^pR1i%+AﴐOpf[Z%c)(O >ʛ wHB揁A$`qPxd;|J ۵:{/ >j'݇H%"X|kkymoNTP ELv!D isĤXEx7MfOen \r⴨fx au;sVFV,wVLj^h:)`mgH1hxFR%EE \d1ngD 8@NGd^R9_>Eh1IY qpnϲ.?-D"p0w5h)xr+4]D ɭz"|xz/VL6M^%Wo:SRG @Y֭|lL3mq/00(:/GܮvTU4?蔒2mU'GYCmА_2Rh<,E{p*&FNvqRw VqƄlbL`ޢ{ U9(. -@ v(^x)·gbq: Q$}`cQQRd[J*4Μ٣ΑHdVZNl}2AlS")P|a?%`rd%[= av}KrlGzPIbgObLS*? Kf~.ڙBd;r yim 61TΙ}M렋[: |;@ +0jD.UV⏫:ZH=@8lL Y>Fl##HO3"(&ݘڜ \4f?@J'.S:GW] E+!9d0ưfdobIAسl3|j؁(cj , F?`ܪ7JT2{;n b )lo07O':]'ψF`}ˑܒ(n<=!(7]pXrB7@?Pnbұ*qR;z3_c[iE])!NA\GKbƧ(yN.z*dXxcZ^K aEq3DώU BThi{KV{8TIk6Ie.c#L|FQJWʙ஡ ?;sQ|RS攫ouTF(%bzT=ߍIʉVź\ (q#GA>S@B'rs ]ርdt$mYw*€%"^[xU4lػBH4S2Voj^tϚYpq.[:jjرԢ`̅=hdwHv -{xzlk(РO؉8[mЎѢWB ])ۅ\)A_J9^"Ӻk\{x6 .a9)p>`kݭѪ+(rV)oT"ey<+hBLFAS(UE50O[ѭn.u꛲2ڲ혩O'*{h;M6)uN!$73!VnV4 ffaODEy%4.$ N]:w0 f00W׹YЇ]_|ސ}d Vo—6*2"wR LXi4W4,s|qibݺ@2feKn3i%Af|wa^ F웉2ܞ }U cfvޡ2 iN +yʸ uxUL"c^2**(ǠbǥXS=Vj 2h^~dzL jR>pnR H(G,7bYd7-ؤ_A=xWA AbCY!9㽡3Ttr>g!iO_'Il`tJFWrd*5nLVϹx/>?:]Uўcd"Z})˾rIRw6:&i0>(n,CW"p9`֢LC "$ JX="%[ˢZ~/bz_Gm_(V}Bc6*2/zu"%~z)^KajBĻ!៤Fȳf+D+({n;p4 N%!Ц_Sі) Eٞ/dԜ+O)Pn80DRM:TTk-r'2RG˞k/YhJ卍I UDjy,zʜ;{J牮IJ`O)2sճэ pxt,w`&qjM ng]S^^.cm~z`U^ ib&n4=xk__O+(hr&m^GuN{Wb+l@$$̠NKZA[lյLpY%@<` rk@3DOv,| lRk$( fX԰)ǒE0jjg45z7RN 3hE![51 @w=YB~PXx6YZ1BwdX-^+/!ung/M׬|Tk" T`UiȀ-c6^FWj{i;-'®g4s hg,)Q=iIЅ-\cx禍5w?qKJ=3+gd[ɀ7E:rn{|{jl [IhՋ/Qx&xyqDdKom)I9lۡ% 訬Z=PWHWwsb8מvR$h!'n$4ƢR<FL{Ne6gwbDiaҏ(K4PQa(\2~̥,7: 7R`^뀜~+: wC_!"P9% B{FĐXy 6BF\C],,j#M,jWvηӌ 2bJy&E{TdI6+l~킡sow0fNMH2k$G #fpp˅3 3$]SIBZws&>,TZJ Wa }G}Ӡp$IkHf9 t#;dl#㌵U~G PXJuI0 v: vaCdp ͧF^K|H{!tMNδҳލxGoJy?Ӗt' R6wax!*<JxIy8#9g~~{z'%p#4b;0`P!;K[tL:*"+"^"u{A|,cYR$/$.BUoXqHJl 90 r8Yܰۃ# v`.PNw} gx=;gӤD[%n ƊP,Mn *6y$9j&ԗ昽FɅc$sg@BUY兙oԮ)"9nX%g.˫+.9T8)#lBRf o(gyG{kGovdRtVD}bv)<< SE|cHt&:iTM%Cy>̡ş O6Lh6rx= rb| Y#QUca4/[V<u ]a?R> 2{o>ʃi<ҁ7@SXpPh(a&.Q% S헠ybh[:tͤ%tqi斠 9?  -j`ϊB0\~U瑊H+U=[u 8; ^[BX(^VEŚH-ʅ!@*XmG4"_8c|)}Of%\L) mO Ƒ2?3w tgoV)>Q,PnqW[4p˳ɥUS|X2<^'OV {7x%L`h{B,Jk!.\ 8ʳ}|`2QE]ىaB'}I{߃ꑠYS5Gw HB/crZ)1?Gys\眚Cjy4=t[,)Qe/DJCp)Z.@,l3K%JXKU@lzĐn5>Ca,7 n WEx+z8[՜R5y d,yO$A,r5"Og@M#hky*U 6齯R;B/T'j匎2"g "Rx9xԖUIFK'6nLۓ k F ^LdG7Wo+4oЀ>\ ,I l,>ÍJhԀPW.$:6ܙM?C`p* HuDAIj =pV-W-3b53/Td*x/5yi NBfR ftM{\MS=ğ}jL1 Y-^g7BTSCa7塭竡y) Wo3{.fln \:=>ftHa2"r(cH+ t!t/zq٨RbS-'/gq$4iUM9r37$l~В@t$:4#'M2t }S]|!zp!(x#g&͂@ '|#t:6uĿyiW BQgmי&/~SG!3(Vэ+(,yH]콆|WA}úz=^c ;1Rbr y-3 }#W;)2Aܸ+cCPH]+1>;DΛ(zDrVYL4XlYD\*2DloX4+ uFL< pJ?DVOb(fL#i)Au ~AO< 3x.٭8qe>"n- 3s|[T jU˲녷ƞ~TX"d\ޓ,zj-qe_ӮDJlYpcc x:A^%4anٌ sp]ί) eWjX3R} QЋZGlHQmWr:YF`Y`B}ˊ gdFxyDn~(Vj0%,{IHaԗG+-Rrv}4,&rDM ZlIEZ_=֝1$g"ܧ#Q]4;&g`VYstÁ_N ~^FOCV1I%&a?h!K :@!>PG>Hcv"No.gQP(&zRRðF55M! dOMeb0=|a-9藹ESZ?:q>,xZK ~Q4ͬG:^$n͛k/f'T:|5Oߋi lq hKLy7&ҋnp`NjjƖ6:[za0CVxd,nN8:;nȞe^7 IFjd6pP&LT3חZRr$6{#g? fu#dh.okn_z}S)6#c۟ v5(x}XB?"ptgg7tGoNjU(9칀L5!UM &jZ(o|ed$mQݾc̉[gTK&1lH *Аjv |׫&{+dIN㕞ίG]=刐X_6M?`qzS N M$c^3b*Jݟa0׾7Mք ?m˴bUeH%s'=7.˼,W2Iϲ yxu.tw4JT={@_c9^CV.Q Yo֬ǨOU(٭ ǟ,"*@(e94 p5B' nJ۫ RR] j}}?m F?[)NoJrTTU&P8o :uxeR ɹCWwS'v.u f4M4rT\𷑅oA(att"}A vy]Tː,H(94B[3@^}s>кY%w FA NAax 'fRsȕPY@IpWbl ;d.V[!yvf9e#whkN]!OUB XWGVEr*ݱ)$Oyc#٧o \qf ށaW`G[OA2ܛPMXf)MZ/Y5 OoZJǗ<ͦ_Oh"7V{voaj!άEqȄ3@2 $LX 5| oj*$d:okSό'yC@Dlr0B^Yj2[WtGNEC}1>sŀ?f@%LDR&%Q{K GF]sH-oU-rdrO75]U覫 'f0 ;ڠ%{Nlcnd`xLl6ZȼFrkiD⛒PG*^}RC^0VmPe+2]ۺ ~Ly a:{=(J\!# lC| /qHNAk JSXvr*:`xf.o x= uXqvb.:%g|lx~H\nþ.ϔբnYE}4lV5*#|tP= _h r,e&xR~EO@gh̝)z2;nNwfeD&% n2[IyԦvVc0_~q2>fz!b#<S4хktzq _50o5ӿwW[ !8;Drk!h?|_{~Ƭϱ+h4mQzKs>Uo@<ҍd55h]4U Z 3E ʂx ̞l6##?<,?V؈oȣkE`#8RsWJf-niK|F$YGA+k-ᕅBMGK6kUѣ %f_P߹\?DEI}1Pv`] wQƵa]-vǰG?T7i}5D˜`Ir 2zoˀp,@ 0:bA( m$9[qwŒD݁PK˄غYW.l5j@i}d-S zCM?~˛ afM!Cdn zlc"܌kUL\\Fe3|&,楋-jXG "'JD9|+>ȑ4Mx$|ZzN7{.{WΤ%X<@zS% !U|_IͶKu/ %<9#x ::嚌iQ .t0ʕowxq^:,Fg㲳ӿ +F2y` SU,`΅/)U}npnjmHo"{,#C_IE%*7SC@1S,R{4#0;D~D`G;Bk]V0(I΄%rj VC??L(Pݹ:Dyz:`K8A0~rcE19:+3 v\xK76$}rP'riB9$7l#'8-7o> V$m-ߴ+Uza'&D)H!t@`/$2ei 5jTV*J7'y%1%Qk %3(td8<5-#`7(otK]4Yinձ8cLfmYTAˁ>96Ɛ``+X0. ߨ(%i{VR-g!f7¾pMìisabj'>Ll 󇜍glyٍ:=mq`C?N]IS2BxxzPkәBð[kwi]ീ,xe^ C jg*\VBOu5"V7Of-T`Q[#wt7Jz]a 'Aq~сm< hMksܦx|74WQ.5%R !ި%p(gIŰѡ `iZNIj_뮜i|6|t>tL)&W{Ƀyӭ!$4J]iZe>LӧLBGܝJ7㕧1Iivh Fju9t4~IwO2V "QSk(UXj[lYZaޯegtVm=SB9mے(hT mV(=>LJ5"Uc?ВNIi*3O. @gޕ=~B7!qiKݱԏ1'aGL 4iDKD4(z>k֡O=٥R7ތv8D`YYmɿ{ 4겲,\cQcA*>E{zM ^60j3'3eJ8^S7 B!{+_Sr&<Z#3oYOS!D ʉU{ьI8X<7<<0`H7PSԱ% `DBvKfI0G 019Ip,OڣD..*32a9NHt*8joGM~R-c{刿 k}HOE[l|=O1lUڻ|A^-}0fH&Ax0\KdGnOK^\W`&%QJò!-zOUyHeNqenICF'=Puקw! x?pIo̬,*YAX#+0/q+8L,U.]y\9u˹:Sf! *ϥ7s[$T6R7IO !˂3=|r9O)[΄֗`m;")QTs:٦=TvD-%.BA-q,O?5$fәX[y 8m]1C=c~e("ū3cZ+V~SV.gyb {;GIFA#o֪5QI roW~옴Ek VjF_7e93 l F 1|xE{l0f;X7$>$;K3t˚wZcB>4&vj^׫GL;rC1v=.$2, L] sɬf_?9z٬xlm1蔚cɾ({UP*DC`NJ΄ZqڥEش0X/~ Cic&_ ]CK6d-w>67dH("#:m:Cgㅻ ^_|Y7Y}N1XӫG|s71n5\TgĨ?GcFdp?b1pu8::]4RL)U"ԓv7#s(riv('kf6nhW'.#[BYWH^wLCD*sDove0.Eg8᫯X{8G`}PHٸpR;-aZEA2}qjYczgq(yBG lIBĪ#]=v]t M?3rV A;`?aȻu:y5N؈XGװ~ `k\6b,_El DvSXp$ PIL=!mw2φ¿"'w+ %ح Q$@O+CASЙޤz_7cJjW2!B·˫I%Pxp8\4 R>n0f_9:.| =%!Ȝp=Sdf/WZҳ>xa >I!- \JK*G ٚJc{rAʙx!Y2֯,h%eġ2+I ƞIUA v}3_'k :M蹯t/t6 ǖv0XSi(P2l˪ఏ,'O3 &3g2w,ݯ}pBj 8J̄-BؽWhF ۩[-nJp31Wf|{̤;zc+S/`rnղ{ZۿUUHmLI2›u }=/ ({>]E%pSLW2AKf0z/օm?,,}$Lv}%p_P5;4s6tbIՄZ#-dV hCƑ M{|獉Jq#tPi5 =K'~AO߫w5}gSI pp'j'oQpB릜sX1&V*E$ld6-+,1&:Q$.) ozHǠ\\v=kFC&%d-nMë(֒!Ju{W@I'}_vVcb&Q}$.jP?K=h7PɆ?+>(:\rs>&,><*sy'1.<&XV ]O< LBeO6X7SL71 c1Xq(~-W| 3 Fτrsvw>N^pP`6ۈ&6||L%^4QAulꕠY.-K eث1{8*{B@JN2e}]re 3˸i:TR.h(=tY!ޘKWDx:z3<)~<3+*Ñ޳P2%M-A~٫\"⤬d8=rImɛPkUp0juNV$n`fØ4{3GRb<IuEv}N(SN!c.s< Pٶbݻg8=)9XYYxp\+*YY瀧[!G˿>_ K~|c.4i\?ŧKńuZ*r? >Z)tldJ=ȧt|f$6Ad9b'r\;,JW(WzPeuOه0Iʩ"hgEJ*:!".o {tΥe{c GS–kk:]{b6}ƖQ~㲮b][ܑ@qv +2Î#z ,K: j|&Zȡ6R-jT%ʨR@v~Io 43\A|btyW*$!^I_B 0K{b5͊8TP#=;߶"VE0Yi1ć9y98@X|:oiW=W `c/ASWHR@N@OT޻e}葨ڞMJ/:{Nb8[˩ `>!6v&8x:*[=ΊM)ap; A%kaUDu׏ˬk(O\Kq@=\Ǡk#}Д,G, JꌬD`S@5 H 'ojs[9Vǜp"_azr(ޚm'êײTD$Z܈vF~&^|ejKNŚV]M52_:r`5Ŷ#EMyY}:R\\eϸMEaauZ$[qS5ӆBT4EL5͡mAײ͌B}HؼlouO08m gUE=4{#0!;*y)Zp^~I#u!< HucnSφ]s͢Ip$fr(^]B. Mb\-eT1]Iw<.++PŖk+E /g-k ԽYk7yqq6O9%h=*+5PK#~~VEQL~8)uڪ}k/A%tq瀅õV `)NSaAZ9AO]gv_/2qDWCIoC:|%BjFMd@~D!2?%ݣNg죯#15G*rGZ1{7Vz@~3?6¯DD!>>VKBВr>N ~튋c"Ѕ%@ǡ# *\z^aw`FȌI"quRJĉyWA -ѐ kد_6OyȭdA/NO9lh1YYz!\vhz-b&Ln'|-|&i~j ,uhh_3)7- A{ρ ӛw=4Α=$=j%P-m>za|*B;kF$;BEJc{6>\xkj+[JzLT[|@e'Ϟu5R"IKiL|lz jS73C<+."X)JC],UYׁ=.V,L4DǺq_eFxG3&VPD6 }yF&`kfi =#J[%I ӤLu=I2DV2mn8c.$o1S+0o+W=[kA ar&*]9X "ZD%K悩0>J*܌ƞH:gy[bFluR{[~c֒hlMz}@9,6Т~`ýҫw~ 6\ G\Elx=F!8HBb >@ 0)7̍k(uBi#x$Wg SM."zX_~XMԡ %h9_Y-+^ !YO1vo.X+;l=W bҘ䞯3@ʼ>(rg>wJӹ4C7L iʂ9!FDR ]B?O}&C3#ͭC;N6Z7Zw6F9'k fܚݷxy$Vg{]r9pKRUbodYڭrIș:(X1J8gܴQTF˲Λ.O=?Vp V]\Nr'!ǢvؐYm y4>MOq9$V cp q?}#/ʣ[; m DgTLxn$]wt@ڢS)槹ۂя|6O^r֤p'H;8Lk#&<[S_]+ "G "Ot2d`0͢;04TȵJCEmmMyܕJ5$wMKMGд"1SZ9j*]e@`8QsN6ֽOR]I l hCu('c=FsYcf;^=".B꜄Uэ"~3nRxQ\7c_>RB<ǚvst7 R2rM+i?YKgntӇ7r\AUCCEO5ȻiTSJwbn=8[k_t-gX/XǬ'lVfZ_B .(~=n]ˇ:gJy`H.Q}O 'i,3/ՖAE UzQ\uJ³qCY*#8|u;Ǿ<^~MrrƊ-˦}s22Iep|x$Eã],DG>j{ӳYXd- miB؜{xQ-s^ǚ MTLgrm u ,~1/acEA+Wnx=S!3ŌГ3ris j +YdvaǮTEC>e߅@&)Շ=*nqۙ fQlZa:ᬦnː ro caX i9rbҽ/#1 :6W2mʷ)>)¤ A\E0T@ƒ[["G9֊B"\ Z$AbG,zoM׻PkzDxսnGpw] XB>%fU۵e}U1LvJ!- ?- ]':=!܀do~t]J@illcL}+4j;/l\6Ü3}x.ufmWd l{2CT@w!mͺN?,SŸ\ $M(jO"CbS]r9M9E:/=1ٴ :soⱕe0zѷȿ6DNs~:˩Ժ:{&q=ƮD b!O9/J8<`g $qO Ƿz; ׶ kފ_x5 a3OJ@ VWoטJPxlPfGVi_ORhO 6- @vCI2,hXmlD CYS&x^N~3]ǫ$^Hc{mQѠxk'Fv#v(E ]QI26q!~$Ȱu_/EA5wǁ(EV4j@˕Fy& ;p0D1E FGamf@9TdN"rbUk0!5ykߢ3WQޱ['vDL~D\CsX!tL*)]+>DK>nicK0 \PӴm[Ob+\D yn-$ArXQssi x8QۯF@GoP8}g( m,4 }!?F9(Xwߺ/s6i-kd ̇eutMR. &XWuO{"fX[J‘k2 b&Áݥa\x-dn>}WOGdsq:WVvLo!dׯ.kp@2#CxՑX _rsbߡġ/x235圎6~ mG"-z\05\N8ZJv[;TnI\ gCDPdg*j@nyVe )#.& N|8nhٝw1Ojg (6DJi^e)`>X wUw ?GWhRAp-K6!e@f{&)tIrbn㠢M킯jlB_+.TNOyr|د)'IfX-|eʞ磷Q prV⤂u@5/>V6:ho@. E>\1Dm<5d ٺ+;?$CZevŧURlw-خ݇&:*dnМ18*}X xh%޾/}tMDݼ H˸z2n|7"byDK}.Ɛ=㨕6M8&"!Z=÷-#0)f;]`=>8k =v7;"tqWH|Hj=P3rZ 5 V*L"d$.GWfO۶ 5aj\4 t\T{`qAWE2UyxJZI+2K(x~ԇyJXJz:׎bؔ|n2aN,ɐ{U'z籓et "_z6xR~#X{Ģ@:"HEhRJx`:aA\.?e[=v|Ԭi.# K!f.6NveO/OͶ죖V["ש_v&jdD|${ V;M/Pnvn-"G  Ŗ';1LqZ&Vs31AMARԑa!b6`.p;߹IX GV!mJc Ǡ%3ִ$@đ4\ǟdO="15nQ܄P+'4OvAk,_cjT"Z/SrfBa=0l7,҉k bKX1"MFXgiRb9Lgykq*ws.l Jz8;3-;Tm+6QVO*|\ Ӽ sjlzq {vRlcQ )V+Q6:E(܅5<ƫLceWwW_:، O|6) :hw D2]R9 ݎvj"Rt'WP\xRA9ꅮNiT(Ŭ6btIXE2&y?U*90j'>K[ctkE,K8E< 9m%hց?̤ F[jAr"GG.~EҗKFE0OmzV]rwr`X`^9AEf _j-y3˹ΘJmQ91}J#~N#- yK1y.-,f_0NE9h7ڸ|wE'N3{#lN)`;(:4]b*BcMP6[#!JM< <)2#ַhv|b> eh姃!.s؄h}Kqn9:sqfI:ÞҽbUMBK#4ug#I̴p rFI ]9Fp;P9C HRL̗"x$QeaÐc?"_WfLiMڍ)҄η(7%×(}k#N/W9Ir] 4&Xm3?ukL rK_'a}k@0sI6yKH/ھ* ?s}R`\MT=$9A®j'B:9U0BHLS/?&| I(),`Szdx7%]8D{J/CX5}"2٘T^ ŹDBAh @3/IAsU$BcyZgΎrOSC`nXo3rU#rZJ!MFr5 1[rYBE'͍pKxф|4:9l)1bF_W1VqY_U+J[G=rzp$?Dt2lNU1u>râok7(F=j/j֧Wr=ɻ mcDtq?v0*uv4_ r =G9+j↓@D#]iq#vdme$Zz&^fV!&P_eAGM[z3B L ?{)ޔLE$ )yF}̦cZ1](/kJʘNVhϯy]_[Ep Gu_FNP(rS/=!c4 omb\o$BSO:F.tlYCQ9d\o9p O:P/Js0mea^ҽ&oHrRg HB;bύ<*yZ\V?.M6vh٘x1^🻒S|F>j7sF_^Ģ /).=JleZF 92y1ܑ.JKޅri\T6My,ל&X@ K5BX>f$8wX Iø rVt Aշo.,/4)G!PQNbHmi,9D2Br wݚXOO Wj%rcVҊNvӭ.V/c{:ȼ/ /Py4+䟈\$Fns6< 2ĒzjFV/]82cߖBղ.XF2 +Di2b1ãe}(> Шfb/ i)҃fpvPBy%E+DRNn)Pu5¡ G{&/ \G\ʄԵU<?atSגOJPkQR<|'([I22G-jpe`p70+Yc再To]t$X2U{6_8ynTeӁ<s6H!`@ fK̈0~bZs?r vlh#) |Lr,Kmi3FLM`[o)%Hf$uq,D񽾉%=57q{U\(lx7X S5<ݭ:$1\XR!,y[,'_vGoxCTP+{ֆPx@+bReltIuL>VA/I[GkBg Mö GȉeR;m'KmuNYM']8Ճe(e,ӵJIs` N*܊G7٘MEH竏`v., d$(;3_8[ON7ha9f]a!r+B=\I8ְA%o$:YEs: t*sx?ϟc<&ds L5t-eJ-de 1n. >{oƪc AZtjVпT%aAZ\չ`Byi tvuv6vV ` rT5ΙoWLx+$i 8b{޺1PO=PN[t'm27&nQ~򑮃q۝y瘦lo- ]Qn+ crTpɅlKr`_+IHz%Y dR֧!J9h 2.t\d& ut;k횟]BFtb>|j*7ʿԁI)U:G݃8T=on "ۖ¨'obDk3sUA'qei5h ~ Yq|x1!FU rYwI6Nݳwܱ`pPx .)`hb˗$@!Hc,|:%_L訝qdwLr~O2| 2ʞkI)qvL;r&ly86t^CY/B=Mp5  YR۷M-4M8u_nk2bG_As)wYՆ!Upz(Ovi*{dyҭYota|ot}!?iS>yO&薔p|/DcnH5 >[ҐCw5y۬f v # 8OxUʬ{We-M3yBV/SpEr6d:WXJٓXmBB`ްӖHܡx̊E倘98&dw'.`[AֿERkOe|&9M%x?Cx>Mq@t!}S Wpqg+{Ŵ*.K!, 2M.#'OJY'cbSy1-|sfΉ&4^}kV!xVwp3rHB5L*$ƚIKbk."w!J7ݲj1 Y/>;ۡ& ?狋2y,YmG@XWee>L<*#c\x)9l/*oH6H3\ z?hha}fkD@ӛN07ޅwRVH2H퍀gb;5V0W$:=G&(l˟I.\҈x$=^\X?o 8w|C畀Z-5;cҋeӑ"|W&LH2FΣeWqQAЗey5ҳ?ZPN mĞ>f&xͳn>?mR!Q M7-l^:c'-7GK(U!ʴ@{ށG7M2A?u6¬H!]k~~t\c(h,>A0GB'^;G^N_ix,_ok%rLQT!bgjd] -scܐՐ BhHka,{)mbq#6(7|6~6J&wDi=3[2vϙ1_ Qfڵo&ZYtTPp2ᖮsQ9!hC7^|}hw&[phS ӽ )v|C:`??_ệQm8  gd_'.z v_ rqV0`£`TWk_FrllGJ`[8z>fs| ~>\A<]nO/;z>~z{9'3&]ʓݚj70D`WCznlC"OǘsVx/E, qD |DJ'!tʸ<Ѣ@uUJnړy٭>ϲ^7y0c(Rg=Pp"I۟-}DJ}:6U''Dk5 RQ/5K:*P*:xeLeߧv!pkf#K2iH6>d͇rP:<=sER cU'+;@Jexd!mw+qֽ>0?pєwQF4/cK'1$`c2:{{]3/+YG9Tp/'RnS<$g˜J( FZ``SB۞j }+!Vyh4l?uƼ?y{!΃Bdk k7EɥWB<(kbI glFƛ2v닣y[ߛ>a.Thpdpՠ1(8t#T{]%DJ7ju"Aдs`Eƭ%X!K5jx"aDshx1E'4+JڷD_Y; | [\rǗ) Rsg-xN4/"Q>QiuJg:ɫV nO<:޼=3D[3duP!{v{EóleBQFa`@~sY!#"0Tsj??)h+tV?MC sJA4zGmбPvаYA}0w{jO/QR$'c$!ȶ/j:0C2—+a)R/a3wJk:)Y4 ?FN-1>Z{d %TH}<z(9~Sr_P?Eo U&WCcQDDܿ؏yk$1y[ {l>9sUÅW !3 ,{z^ ?17-(YYWNW`yK"bFĮb񊬰̘ai;NYo0@e2seZKl~z0,n {X\f7PA<MoXURJjD]*#H_z'i`'ڒ$^^S~/IC~+A6Wa/5XuѸY {wOP QM7n<&mE\fu~r %[ iÓZ%On."4+`>ֵcwbKu%5JZ\:s& N/+xm.gɅ% LѳpŃXLM>BlfŠ }jzM@M\}HHDe{]`*NR\tleT%ÑAo6PSjݼΨ p5$'XE+\m[&þ eHd D/GXh%aD50=14GM=ӊV(y p1y;Q fY.s7%bmW k̕(Z'MAͅ/7)M};@:4YW}Y(X7ߎ)|q6s |g ?8PۼeBhzN8k qE E`ƙ$,()=1El. U[Gu 䍢6b'h#U"ΈāTTT_hV %M讑tEAEK|3M 3<`N_0./6&[0*@β!/iuC+,}U` gJ"˾)CCȫuf,K 4ej7 W7ɂNg=rέSt%>>j) ݿm)lӗt]tcJ{Py}8T ugڛGUCʺC} GT)Y̼gEH扳Aw_/hG(׹rQQgZ tb>fJ hqŢ3)KLRu~$Ķ^dn&fW B1(]~C_~4asY!/0.)Ď+?WV^umA_pRV>oYے`p2P!VVtAjzߪӺpuU٨E_[õ=t߬SatXS$i𶸢@;q@bpU 4-^X}Ш%jla<- 1o-WhH KO.Qp+KE,W"0nj)oB;!^h(@*LQlf/mUkk,zrvܤ=S~ook\%d}0[>2]%D +ڗ"be.+ 0z5@ åZes]XlXVi(0Co]Ȯm$߀XD)F1*0緗81:,Eo) URp @ ZHtR 'MÌ̢Y`q³B{6kfAk!LaJca iwnĤEl鑘S€妏 [,~9]7JЗk NI+^SqY f-}~cOi~R>XryQ%}V/!פyj.9H8!aX>2MP Q2c'iBeY2S3es=JIS3H(h#ثFoMmo7ٓ2-DLM<4ձx >jas<RA V _XE;K*!r{)> RhMٷ:!K k$vVJt7r8{\YũŋJ7nߟ䘭WF3tVՓ Lɥ!N^ZXC_b&>R$TG;,VL<"xC&vՂybAhq't'movwb7fCVUi {=MY5)wa0uޒQbP)`$)BdƵW ֓k qܔt>YoY1랽kxX$||,5%5?_X8{ȼ8GHNE#ݭ5R"xB񝯕?Xg3-+V"W}pb9Pg!5.ZXt-deZd,R{GY|3s8{m <\|&asT~/QID'F,gsoS&NaM@]>,`?pOBɚ gb+b(N<9vxՔХZ* \K9ו|JSOC?{ ѧ ƘoAr/euڬ?uhCG0fJe-?}466F~'eOlNr!Toa.T]"񜿂Pѡ,19l ͟[MchNv1Ӄ쀩1q'9*J o`SZ~JP^d^ ҆n e6jl;$E3busЈ'&{[X$wmA[9[1PR uʼn=6u.M&?xiqjaJpUEkة7OiP.(B%I|:ZDW3#~V #]uAvwoZsYC+&,~2faq겱 Fku)Po$[ w1h 2 YUpL2-*!v y>*';A˧,ov,QfȮ M@R 5LINr4w*d#2,joր}R֗$'ϢxSy[Krq^4M W #Bx_}An( PZ~[b]/F;̎sLF^بXeFR4ACmf$qFoјhӧtD >Zi,I52X~w ȅ aōw* _g+qj>D6,,zV蓖9&VۚJı+I@K/#A b{XU ډ>nV|9*xaO b̚>r#ws=.srW}mc U9<a)6 2g,dm-5+؄5 c]$O{:: 򺛞3J5ѬnhIrn>ѳ9 r놫OYXB4GEa-?JD}Ӷ#qB-rjqӺ>r2 1/M/gQ3Mb<fh ;ǤAPK/vBڟiŗbh_5̤7o|+I+j+p0 ڪwM3f.,IRl R^ qs`_*.S|2>*{;rݫZ*qW~)Y C888m?\1XfW\+-莰?sLhK ;}m €UlW E׬D05$~ls>5Ҁ*N5F!pb6oC'h}ß<0^ ȉ[+PNb5~LwfHq` NV«D t«+m ul֪l`ja{xЊ@yQ9*+EU7#_}Ghtf{zhq*bupQPMY Ke(W! ¹S MMP I4pHpiqҖ1V{j^[dGaP8@tKLgMz63z,wȖ1BqHbW SbYČVA'pcPqB_JAw(@YD@5aET3ߢWWev`^<0yU?xdbdFk8ʼdsVa:zW`+9A>4v%t*q7St"XjW'7g057˹:vDm^_"oOxel<,mAlSp>hB:A®*=1*:'gLStѓU -7EǴGG ڮc9Q'EͧlcsY#k8IC_G~M>|[:#ag߱fXA/Bf g"F^$MJŅhEk Ҍ v@"}3nH#)z$J(?[8KV;uq^P! d Z!3(@nZ~k#9oؙz} ")&E@*+5r IٷhC%5'A*&.{WY-63/!P4@k"NşVr9̺]Y`|j[ 9L}yN4PavIWRԸ+nܗdz۱]y$y@y#z0I\쏿:,O N@e+tnDM !S>B.+ S@ Dy_˽B0mhMaj$ܧ v37"}{kvAZt2*Elt.&OHnHӗlӄ\׈KV]2Z_VKG(Ŋu ౝ:rH v٣ )ky܋0ZyN)t{0<3"iBҖ4 ("H6i ZqZ‹ZbɔB/eޢfU tHr1ϕW *;3Ñsɩd^RFP>~ )#ji!x~z,/URF (B^U4j]T9Ϩ۝9kO, <WTji9}[ ?/H``% Uo77zth Yy(,lG'%TArMz@DHr^v? F]e g&K~!m…*?k'x.67{Ѕ ئ~l2_L]NƊRfnuNI\W;m9Wk‰j%/3hSpDQ=qoo=Of{CA90B)BBe;ptut]]B ӣEGɇ(&WZ~@~U{ dGbo<\r\ nǀJ/~2a4 fqA{N]|oK!)ԩv0HĥF'Ta|we**urk 9?(^W{?i^ڻܤE fطw/5f%`7_B8NB !ߎlkteel]>`0۪g!_l6޸"h!/nȬ=oHLgWחViL2dҝr6ؘ1`9Ll8ۜ?܈KZ0JjmZ,4"u^^QTgǁd.g坌8YBo*4cr)KXɆ˘Z 0:I."n 7Ŧ2x) aR:#fHeSlEZ:QN%[l﷦' 87D;!,vf/LhxcͰ<_!ٔ0" ۲CǙ ۶݉S0j鈥mV+ҟ+F*ɍh]37̖Ki+&-Ts!|d/;+g]1̖k@aRYm(oD GW//N"% {_°u\&kA .+>Es?$ ">UoEb8G (G+_&g^hny8oܨѪ*Zf &1F zu&#_?R0W;OS^Gu/Lڕ,"԰o$Cyϝ'&Vqy@~*).R\/O1,Zf1StSi(8+.@oѯ[D8eaS߀ sSt T$0=C6# R>sˏ3!޹AHvkR5#+cyMHܼ}_5_dhZPS,YL+AR[yFȩ'?T&ByX ^BSlLF+Ӯih`pN__SrSrD!&tռhLH#p&`J/x-,WC4ohk|=RyD ؃`:Vڵ†YB+'l">\F &4Arӽ_G<9 ZO ˥QquiXxm0~NWٚ#VnsqWάݔm?!9C:MLn+=2D׏zQ#Qŕ+<!5\Ԑ7Þ%νRw*^gD\;!F{чrE4xLem8uH}tZFͱ2=~mv$y6;/qhA0 ;T5%[!ߜ= ?!Ofrj\>^ۙl!_BEz8E\Er_5[ڊ NJmBٜZGĹ YFQbo6ۋ ,e.{y`t`lu~vA:C9"17sypU(",?0mXZ!PiJ-3CEax{9=}X2{U֯:~nDdZ8rzj-ΎSw@ evRuUZpV |X$$6T&>=~Djtȵ QZ/ ޷CtISN0TLQR(~ fu>L_uYT#m͗V-OHi.ee+DpOUۑUPŀXwဌ1u4 TQU6ٺY?<#zw'U# h6j?J#2f~!{U Jb==5jW (%={zhϨv#9G@㴩F/^X!@lˁ^"~U9<Ћx¿MN s]]6S`Uȿ3>פ݃Y3 "!H Ej6J~;]v)_sdPhA\Q8<+~_p2ᆾ _6.}u)> <)({c1ʥޗ/ȶN6.uU%@4+#X!ogEI+֚Mj9A=a@Od+ـcE E>CVJ4u*\Zؓ G4odA; DtJSt'@tݡwS']_ EsREB-K;wΎ?v!'3lNۦg7Unȱ-k" p+g u+AS> 6y_snvtaJ^Y7}d8ŐnϤDbՈ{'J  )<R As11vbM}D\_̨5oͲ}) ci)x."#|yJ,Tr@ˠa~Z{#jeU;ԇ!u'"s#ѐ7ym.roD xىUɼVc6؄n貑f.W{L 8=EAW4BNd)ϯGYREk+IB4Pb~dtf8*T$ānl{bG@wC˧U`}i(6 O7? b!$r܎S, W^ c`7Y3Y#??UsE̬n<9O^5S/SX꟰Y)@~kX^wIzlJR|sD(;:C|tL봭#L0QTcLang-oGҐ?ETHEB~ ;G#U CD|eO.L08J`FT|.e̟|ehAb~cࢾ4!YWO{8H 1肢d} d%c̟S WYH+%ALӳ&|3fh ^42Mԡ8*ר?jqQnLF{X >ײ W$)*"`32G'HL3Y301emUKx~!{Wɷ_DDȈ xи6(:5zXN U滿 )6A+?22ڰx$~1ZyמNvHZV³ "Y0~MT,3ˬGVAkԇhU@Qޡ ,Ʈ7vYplb$N'=քCZ:58:sBvV)YjѾ3 e'/M2adֱEwT/t}'ȑu4_X nmX K,`aXESѶ:A)q~ː%Aiq`P?m9z8ѽrםG*A;ϷlMp$ _L۟uO m5JdRt0ּwݪ&*DvϛY/i.kX;Iz^0TJZYd */ YvJԪ-lM9|^e_NNJ֋njsׁ+Mݐ߸X=3.QZeCc>pf-g`+m˹ EDI3ϨMؽ\}F :$xٟWZ&9MuJ)Hlo5dgc)HR~H(eM*a_hjQKmbfҢ@e#A4(+GvfRBx(ZvX#WU/z wlĻ镤C}^5w\޼N|QJٮ{> <fEkz[/C"YXwSZ.\nTx7z~Eז~`L^<`REEM*ڞR8 ]36af-9qJC*[=c"=ll}/ x=kB:bO-;Wߋȯ6@N:6x5_YAVFmC|RWes!]cXJP{qrUmzgTp%KW)AQ>$/oy4J|/ Y' 4ߐ hYhFkHnkfh!p{Ҳy?yw" ѝgT}nY96XOXU~sx-]d|.feD9g#$ 5NS^Ē(4{n4I.q @ W&ƔZ[oN9DWY@FRTB8{# 8e^9܂ޢ۶qI"[.Dfcisr_ !]nrrj?k CYWR M@{󋦠'd:8$ঀйgdJmx]x%^>FPUIF!  #U !jsϣtnB)rc-"VZz@۰}-IuȺ3'Vξrlɴ56EJ۩>+=uyqQ0T`&G{eZVGKQ >{?Rj=Q&\=V29RT`)bh_um@ҽ/'L1/` lR/9 ]̪4m~]iQޯ/)s_JA%2F.Zc+D`r-QmQ)8݄ihC1tGYΠ0hѕt ~j=H!ThlS3&4wXc!nz_ruH[a@xkZlIOfuL]Jd_b˄bKI4 #@QRp'bt%q\ba-DWfl" L>#Kδn #x5@iMɆ9WB)x<=lV㢔}2g zP@gb:)Q`2hl,9o`| =!5$؉uA/vQLG:׃[6טlqD=|ZVٶ#vEqC˥[UfR^+ɱ/ߪmlѫ'e]Rv8R dTC @~V5>`fsӪ効;K]M Բ U]T` p J/s(2сtFKM7c Bs]C}抇FU 8p ~NɌJaͅ~Mɡp4LW~~S3v_)b^lAAp| GNfԎڶ39CǁN & ƕ#k;%Ծ[f?aa`E}E^o3 tD} lF ڧ?_>-*(-OR.ISX@LaoGTf1@3&8UJdO3eMqBV+?ϲhԿ~\hȀrs4.jEan63!QWEñxr> 3\rT:XMz%JQsS%awXjRϘA3[<7#2sp+)04 <^_>P6)y]W)EW}kDDRޠY@*vh- 2 /u0cBV@~&omrfsT4-LE7rskhXHC.9|LD2'J.,fO1af>f P k2p`YY`3'܏MCw^eg84g!28O*ZE?Rr<~Ȝc1w5\gUrI%VBƨۈ mV@4$n BWic]Ţb O~#&߯x$x nx$~[Bf˸h2pKL]'O ,,7 F x #d,.aVY Qѭvkd@__ĞsavXԶ$/$BH*cмyŠFI(1 "dJ&h#~,Aac "ᄘ_J QnsB";"n}ȸ60B>@h2o|,y{uǏU8z:Z5{vUK09;YbOƒ}t*tsrceAF0 U)*vtlC#>SFب@d{;V=m-!"VKٶ` Ͷ9s6k uFdm-i 5͂/Nj>!pɤ1OXD+%ͯaKk\Y `s*DJNZC"ue$~iyo m.EIt=vA+Tܐ!&!DC1i^ه"I0g) Vg`U6ol8ۙA&~Fgo&vˣ1&ʹ2_ؚ4fY9\\F-. (uǸ 2N1"ЧY>O2h/_@'m"`.{ 7ؒ([Uk |ah,qUEݭl6;Vd䖺B:ϢXC4M[py 4O%)~:=Yy~Rn1й 99E#'.ΤB$6葧Pt="ʺ,3l oZ_T YKd@IƧ]:Nȅ 7)[M'~oŀSZ>E59D:˂1Y b_3,ꦹ㉋2[:(-qxkRjBEkdbUm2FmIU4>] ݅q.|3ށިH3.8h#H\"~?_|G=ȝ})WPC B\WmrHa 0&+H7~4(iE+:0;|D'*(HEE b.׋7`_&1O`D@ml"ښ LQ}=zHpK4+Z Ra`zAV[CxOuj=͏6Z}Y̛Cā0dP|I>wSp^C:\ÓYU``]8ٛ0Y#vl6Ǹrm7Ғ"^IF p1 ߟ =_tqX ,cW2+аm_7G `n53Qn%r`%aT朼ۓ Z劵xnMOMA z4w1纅Yɝ-,OɁ=fi~S6WQ॒ ߯ U>İ᭣`fD!3@>Wfצmٌ9¢SOoѽg"(`}sz-m|pSNhD4 Z <}?ȭx4yig)c|%z (ҵHu ç ~qKw΅2Xy<$,wkg&}Oww`=ƩPꥠG["$o_k,OiHu3Q`*= j<8}e}c Ju!NÔ7YN:;i˧p lhw[y1%n[G3 Bم_E`o&*{><=8<2&4H b2$n UoI4\o .H;@HLGs]o}@Uqů.Х  nպQjR& 7' wԛG ]%J ;|k ?m<ǯLQz b @k-3DsWA'XFv݄5..sPX@nDRk攕'y n vC~1<%Jr: ڏc `? DgwNX9`G!~Qtyba |1V᯴WǥD]횲D1`>KZ@Sf>qB83T^1łKf~NDHBz/7,"ՙ 7]zzWg{Vðzd#DF  4<٦ogI9 )~()3a4X7]ӧq R(T/:?mP6dx]lfHLC͟2z ̈6ywaI {Г4Dz}_t]I;i*nks󷄍O&HWN r2_ JKSTNg 7dI e'0YdW!+ sG}P{_\d(Dž퉇)K`bPD[NW؊$= <$g}Ѹ󷑢hnm$tA: @Ax_4@[z y *-r { u3+k}!=Rhgw94%m8c*0?%Bt:+#.Rhl'-^v4ݺ] &vgna:1;((+ o0 h.k\k[hZCzm@$hW8ߖT /Cf`*Okz芐NV5u/$*L ,FK #p$|]>m*&N2g;-!g'aNhL/DWVi'9hR%@ EJDIY+iJMU2_Q_sK4`B}NlS/ B Ѕ|sGAk |R +&;I̙c#>TW RiQ7Pf6A{QZk?ys%mڠV<.M.Jš;| &WƏG7L &|O2pAI{P({u9\?fڍi/iiOň;wjՆ/Nȓ;G/sE3sFxgCN F<%Hcj' f@r->:.eVuTud(~zYK9;IBϫsvZJ7ԟGK@%-)f~E#(4 ҁb %JI0]26vR,!C(* e[j4>Y.܆O@P@L^^Ӏu}ߛ<0AFL8/.6t22jí(m`+@YжcER{Cb>rWAM=.1k_tAb|@~$)HC\`5'c8xW#"@mJe=\'4U #`0%} {ѧ͟ZD(t@yV#O'ըDɳi`rCι?vf7S3z3V-3R'Y -.ǢeGe6躐s(FKTfԝ^J T:5dX)RN?ն>j-YҴ>Na/{άm3~@ٌ(_+(d sFX0G2̗9BnE*dbzm|;?s+o}o"ZSه{-,AML~ C;c)7dyjaE4R}u}ν!vZ#3T-u\>lk=c_(McQwnD\!4ք%r^s\xB#( zniJ}t,!byuR[| *g|6 Ai Zuڄ|]a ڒ8j]=Uaң/AMC :?e9`|1i B;e+b W;PDL̄sG)#hjbad-4'G,eQRVg羍@?]@{ʧmv %7_iK -l~QXPQ%Sm|H RO_q:}>rYݎH0'肽v޻ڏp5M Z:~| GfpUHv#'VL׎A~yN`sX]f]3sZ!WUYː䋞LJS&% N$/.4 1{~en8^t=z( GPdfD1}Uy-vc]D,HfZ>QG!"?ڝ{D@T];MXm%Cfi錵٢G?F.Q4N= r)⥇-)캫`ԸoՃ gT5<@Tm\{ ^ .wajٹjsfK[2_R:iv|LPHQ65NpWkN8#Q(jK ԑ¢XM4Crw9R%Bf[=Wv X s}јO*z{۷O,9X fZ:Od2c%T1ܔ>7q |$K;ZF*pt?_s?V/tF q*،?p1(@ypVBXzZd;sv( +rT e !t* x%#r ?A{#-"ꪪtTR+O$\<T<')~[?Ž3e/dv b36Ă71dZ0w/D)<ې*tB!X675d{xa6QT?ck*GдEK![Oŀv^ġ>b0~Wg zb7*[ rx)SGPC>_!7Hv+DXF[)<~qw.3B;FT *2Xì}G[0BV|5DTsQ3 ,c;JnT=/ϗN\}AWQ }%N$`;e|۴MfV&5GVk)N@Z0Ȳu?lu*zs 4GCOȣ-XҡĚ]>/HzY/Q6u"1^<㪒#i8֐66H38+7HvЦ>s GEP C"%3F+G^ ZET|1@ff~5NWkȂڄ/lS965S bfU;ylzK$5Mƹ1G"=#cl/?{VxϹT@V΄u51U6 6ҺSd_0אWh[;0@t=byϞB0QI|d - NUve9E+1:GAi`uc_03Fs%{iPPfPF 9Y6a؏S=8 qkyV[صIF8n&<+2LDL&##~$݈#>Gk8)wC:mX_=[IPPJ@_* 1).IWї+Т}-jP>/[)FS9,o鹇. 7uAuG ,>uvK8u("` .8p]#>ӗxsG4gX-տexU.68a}'3`BȺWOOx!6n+n̏TkK:d&BZoqC8F#Lʃg #ЭG!n|Ћ?“ S2pMw ]65m(euDP; ז*{ԖPCY#pctK7bM(GgSswdl>Y)ǓѺFLk^ Thb@I۩c}v⼓yڬ[5dH",ޯz|>D gPf"ӜH/A-j/cƪ[WHLoMJmEUkmպ=ӏ瓏cJ_~K$2IKwvvku:oOhqe;\%/vA~h rɌ.# e-YB`jVE-Ll1K ùoQq*HdҪF^Y Q-7#ꍄ&mFD!;${=yk"|ˈú{'r\66נF|G(~Y(cU>-cƹ23?qa NgxxXhm=UjySI2,2uonœJޏĝ.}LZ-OntW "`(‹j)@s ,z(FZ (ӿbPJ$azߪ,X$>:T l qPax؉%eDt)9% gkZ/QLj:92ZK^1XU))pq9.%0Ej^gLERpF*&'eKHY NSh~$ǟF׶8R1wU /X,cTv Pui)N]U*u]ݼ$/t6)^c+5|O' 6Q\#3$2>Vsp]xS$:?ό1EFq3n?H_;# &clۼhagU oL!etGpZt=@_n4 U / xN,yLE,"sYƦdi i 9}P 0Fq,8D<4VWUyc頰%Y%o]3Z>.j+"T5Kl{j F3 WٰJrrİ1;fܽz bұ}:؅s[9W'Hȥbrh:]Rmp2X%@jFz 5V9GM5bڅ6vz̙˻\zۆ0Is tfC_,8TXn&^n!~戞_A]{Sj=Q&׹MZn ?%Y knKWyzʻJZcDKBn03r7n5B]`5ltAq81* )9ʱ<2 &iʅrH!m)n ؞R@uabbu"W QHo^A6⢒;cJ5=GjjC^1̋ E JbAZ&6c~WmHfŠo_`.#hƏy`G(13˞PxVm/0q_y%OlSHWizy ~G-%!7)+ۏFśh DjN%jp/g#LjodLWKW7=߄.=[Z6 NTHB(KDQ63|[6rˤ=~9tF63g0$xNKcNzh>Y۶&9虦. <*2&QO& /ș^d=lNha`g]]=i;ٞ'`,VܑG%Z83;lo%0 J29Q ~,(7{N 8 xͺ?J.ķ"&NP7UF 4 MV œ}` Գ%@XI)g:v-3c++ڋU[UO{!6ʵ a=Q0ed~<{Ye>P&4jĭ6pK^.]@)Q,&3l6b-ׄ t_8I~7]<"َ_p](y2ʼ_Bu'5́$#=5jG9 !iaBJ+}31uU.3㟡n םef>6EYiSH^M_{Vo_=@sPnj. xx5A1e/0 n)Zoed@,EE^PYwA(,:F9*>uf~!WN÷;6i]|}\63} #cH(d9$-#R"IV y9>/':iIh9ET?R(.uvHDU~7UzZB5*QYfNN1A}9 ݁๰B"cZ4 ,9cpKѶoEYQ^jr&|?獉D?{̽&r͑ aURt@]*"kG䣺 k/ٰMHsжb,# R#s@MUNY4Ȼ%/Jc+׀uy\ken=鬺1vZT]8\'ɠ&Anx/,ЖH8@7]-SbI}0"L1 \Zfgt2-.Q>]%")6gv|K5h1וL`Ř]?9Q#x Tڔ:8rܯ\mo~貞2?ߥhi,ա*B8oQI](^1[%8{HvE%Ll+':#7slBIZ,yM@7}{<^>Mx~٤$쑲VQܒ,_nXCE ws+^_p5 ;4C̺sκ8B>8:+IswA(hcי\CEޤEWC\DJ/ ;/"[[Be求Kr#L*p\e} yRt.*J,V}1pX]8`<Zkw"37Φu\zŖ |(ҎF^옓tlIh(`@JNer&sc{h0*N3 ,g-ަ-e7>`gp3Qg l ߳hɪ_`-4{&p\Ͼfؓq5@`%mH}f ፭u +"q}Kyo>,A}||UBx)V&^t¨.Wmsd֫vpi46vi'ta0)ݏXy&&0C*柢$${3rj( '߰FPM*D.iRd7+-#rFAqi0-uָO_Ib1sνQYV󼸈L H.1GyKk.?L^3X{;7ҥUUDKObeIr1H#mLOoԒFhM8 IF hcb+/3X1lk4.e!US̮?[.=hFqiuʀEG?/ŖA+4`QK>3W~@RZ_)`\GQYz_F?D#V׈@RN1w/X+Π5gX "0<z" DcPRNnr1d$"r1{)-VNY'A%^G3YdKcXw6lR*!]DE~% ΟIRJ:}Ͳ)Dqέ˜RgW5/kbjniĆF4"3Kq"^n0o@c5 Tf=Mcieߤ7? trd%o7CuK$ 폑%i$ ?Hx"W^܌F n$+,r5O L.3A6s)#] :b (*Qonơ޽8u.#Mp|&lVakA{Ft<YI *zw(ϥpkᯬ+oj9uTFIad&@s W7R=8r^XZȮ^nt& _;XۂRLR6@"=lCx:,qÊt/ 19.%[7E<Â!s<|xXH<q7aZFӅC/ZSӉՅ ܝo{*O~RV\j5>zvd֐pAgTn{[-;;g%xus)w3rwڞ9!َK37jڤGP@ z r׳6jft 6'B-_yD$v 2"~ncĒI6a?UP׿^]wTl22t*eo z4_Vf1lqꟚwR@CNcVc4G"8o[\^<9&ASx3y{C8F8Ś:ٓ7n"Yw)eWX7 ybrdNW>؀}Q8neKҧЩ`oU."%cl(9U֝+TIkNq SVO }Z !`S=.&T)xnͱ|: 7t3)#d3Pw?Cjr7ƥFZٯDW 8u6-{a2Tj:)ü±Pj#1TFڀVlOCr^xr"T\J>9"?).qTHjV1LzjhA&P/fFJJK,S釹I{N?냘\klv 1L6j~q`56ܽTE o |N(C(}1 b)”Cig2byv \T#t8Pj6~) >;O(&q nxFv +qA> nVhu8#26,n ܙ}s|kU <2q&.PL484Bo.#&>4m/f: $AYuٍy+®CbXeM ,TP\,PiǑl^BFqI%"2ѥ? +4MO@%r΀GYY`'6*9+25a s`G^6>7" x>K]촰0\nlz$S| s5=댅c(Wx+JL87g|S))ppu䅪`vp$j=_$ )/wYaԎOv׳ \8uQJw5nk^DAw>=]Ibœ$O/n2ܴ<ԡYpLa[5LVCH>8QԻMe?lYyA6w ^h^_u%_K `}-(~/-@CoW%,R*vh$ fje+J)^OsS9d,ð>u*kIvGՉOLԩ*!$f/&ZUԥz2^ZS&>i!s'L.\C} Y"1iݚ|DU(z5jn Dn^6zjڪL,-dksW7H6 UGvxSb!yĔWLinoR4&Ԃ}.pKw8I똸hO C`*Õ{P\i_οf/ʟdSԤtse:aZg Qe /a?잆_s쫨rN3V\jwІ/٥YVƸ_rn2=>DޣY #xE0w):"%2S|ԋ9o‰vHz=%p+ Yale7r',>5?OBl-㨀Ry/СU?&Xr< 2IXYSe iW?+LS{`V.Y!ƻ0V?kTH?8]r2e,`vIfؽuI1ҏ:77ՂYj^H (R9-10qq/ 6R w|B@si7~հ|k Pzy `/7@2$K]UF]ulgݐnY(J! '>f.=X@wl" r.`!U̠4doB sVަ*7֤mor:aKŝ(xz?]g#] RV{tj+ D)r{;3W@a.( ڎ-Lx).#zfH(%wO G%U53߸9]Qﻹ5Z#YS ([i̛6kƌ%ҟcUNx{h,|bxw|@pi,>ɫnA%l?L'?!5% \8L`,G+qlB\ˬ`P%G)g/Gi$qSADFO5-):}tɥXf]׎OĝJ8ǼTg  7\^$A󄸱`?kFBH W'kq[ ;#nw,g?V,fa@SP&< &1bTvQ#lp(Xȴ@St!nW4'cdfm ~Ww`]TaD|rYs.nu6_8{ZUnrga?,%V8I 4ڙ]_3x ᎨD1kzWRY'wlIJ4<[[04XINX=lђ'YUfxApcg'Y /5W ;\"?lU#sO[&ַ̼W#WlGNqݧg` \0t@ZHLb"!فV2Cv8w(d I+|C<~szo;zxr]5岼sI]H^d]Ï,b۰ T/97+稘[!E-_W]ģnkjw+uòYS}l4>!{ϰ=۸boX;0ƞ'6YШRa:o9d8#-B46a;)_Y & q>=&Jv껷ߓ'nq* ed)c`ѦD%7{5AR?W%|t{^ 1T% F-@- wT$أ#xkAwae΋Df Ih&%m:ʎQ`̻R*Tm3ז_uD-ajь Edo^]}4$黋uC?GOx0/!a7,bZ_ tIxvفTb~[\  Qg׆p&T/囝@S!~poqM.yp]o.f(f\1kD`,+݌;#·s17=䜠 i >Q)0Y_5\ZM\#h~NWH-\?fӊ_]FygH:x(PeeApuշ0ROKv[H.8+N%_صR!gxTܣ#ڋ;pz)gȐzRU")3Y:yEO:MP"ƋUnoݯ%BPUHHAU @QݜAl j"[^k5g?mG4bU!3qC d$=ء~>uETiP\i_w#6r] o6X'~ rUXDPRڏʅ ^Ѽ7-Xr&R>`5+3Di+B Ayfh!#s WjvuQ(mϯU! 3wJPh R'a#h*/"h&m ՚?"G!Q++nXĄV6@+ ϼ?j|Γ@z`&9wOgUrWw8btBi}jb Zla0 Qs"Vs!,m d z Trv2-O+}őO a[^ TI랱 0Jm%!x!}?}:kڇk'Ԅ0,E\Jy?Aia"7 Aөo %9ܢ^)S;ϺscR н޲2U5pZiWsa~DŽ=ZilTˉj6VlYl@Qe鄦@2F8WsTq;], ƖMn'@n3~(viIJɘx-epƩ&q1nΗ>}/ #?\[ o/՜,MH^ \eW XݽqEez 46 s:K vaFOKԺ3$?ju RQ!kM0eQՖy襑ht 9ߘf6׷.Y֍;,Nsd160&~N;;6JeV ;L^2GBpr2^b_Huc2%%wU#C=v8{rǨ'yʑȓ섬z 1j<-\d*#1j?21L':}`v ӇryW CP'Xi`:!ZW嚛!ә§[i<7S1=YD+>Xx!uR? V,`eroer>39.5fIo8ŒLRL=_AV8j^C \= y\Ɲԁ:c̴Xʜ]Oz%w4~C *1ݏ:tʥҺ+A, c1^/7 ZceQT/M*'ðo44|jG#G*ؕA1͒'{Tc" KKmheUʾaݟ ^^lO_oaGacq1ty~ĵIUP c&"j+ v.V !iaÄLoOpin= `Il']l`0E-`>^_@9:tD- gxL3錶9w9N̕[,ow,ZCF.pAD({3vebOD&x.npƩooyzC Ԅ*|af2W.:b)LV<ǹyUuSAt\ R7o컝ir6^s>KÈ!Qk\@0tK׃epQ"=*m'륥/]c &zF2ɄcTQ4 4.fhUWv~6AcuC9SK%}abuVC ;63PzssTΔJ&~eH~.SՃX'BZZv,dxizF<5@x+{x ::xq5i?,% dH x6I ֧U?-5ruد%87 i" ]MϗA4' @LίÝ!0,N9:hJ;ɴe o@ciJ@ڑkMZF5G Fak0Jt*CK$^&Ib$ ]D<)Sƚi/NsҶSߍm=$lMs @vXpH`9=5ެSx1<Sw*: sc,)\gDecSZvS;T椑p羨?aPg3p*ֆ LHr.?'C2աAid(L*d\27UGJSȞyiqv|3OzHN6 8{~jk;Q7?q{aD^[YC"pG[p-݁` aCxBE&@laPCugrih2-!$A* 4هu(y<]N4FVd^{{2 g3!"z:0܇j'TCr:7ثG]}Y:-f܆c#\~SO0Qq7[en47ߕ΃i L>Dz#lGaSq%׀ :ٙKo]# TZhi(S}3Zّv}'4oN"ᥔAɊƳeAG9[[S-oa%*n usm-'jw{3Bۮ[eVmo'~m.LZ hq`;@-#I=7TeAf(_>eݭ ![.}3 }Dy5fiK9Ts)n&Xv.< Zhl Kzp3{Uf ']VP JK\K\6(6 yV?<9bʒºYaX&W=ƍshYoU@AH]jXq,{ìل>jRj`K9fUuKePO2yhkæLMy8iBv85G';5a BM?H!RpTrGy_EޭҊZ]vazêtAD ̧yrzMg*mQ21>* Dj=c n )kR_(0*d:\;J58WHJOXhu yȄ(.jӆUS 0'Ib߀k΁?Q16PrLjّ u gFJ3yP8PK?pZM#X93y*35ͷS}X&7FݼyAʯB^\^ƕc8[c I]ҿ?8lTFvh ѕ}=0H2=d$߬:ZEm[g8;<o;CCeV2OV@.m>ɿ+9lę\X (<,x(+ ^PֿA *z]-Ř:I2R@UÈPTD  9u.*p e|( 1y:[[Wi0kJqX,2.Jk;*_kE-ufK{V՞;`8fb^}>Ȍ4%Gʴ;by+'CiR1xnejY詜ߍVL3>vOCO7Yw-ʭa]AjBm2ȇkR$BCp匡wSQ3O/Æ4\xMu|DZQ1dCK1nj;e0VUj1Mw_ Ehb}-&CϠ&o؏c52%D։񨃭|>l CZņei>']эO;4ib^BTV1rMA6cM*#Q:@`B:'TًV2}EG2񿯪_֠#AU~Qwȧ l|Z?Mt N$:jҬ<c"<%2"0Kc9aV튷 ?>yk3l+>WV9n"%BdΡxvݍ/Ll UwnuQDdqE٨Zq\;ש/fTPv :#WEB^ფ_3=5¾Qbziw>[S\E?ODžZZgi%Λa};\53\V&Ȭl0ht/Q9Ƕ9{P$1]Tʞ\N{T<ݼ% Wr,^ju6Ɉm؃M>\murzeY{FIƟf0ok6&|]⫶b[ `w7`qK`b&)P")̢` x2J&",!B;TEUO e  }UQhjR4݆EK_!=eD(P zQ?D|kiWGl>tFm@6 |U usX&FQ{Iꯅ_J:Ҡ<3_)%p|9˺+4P: (a(=0Qt!3Ot R(Q )4rDr]:ٚ8kgeS ]:lё y6crӖiN]G¤ v.(pIZʜ+,H߼fX3)CH%ښxmafZ2h,h =˝4%`B͜?XX2L 7j>h-z) 1nH*R%X:vD$E} Wi A?Zʉ}%&%cz/ߚeEg|T!WɈuy?S]mrS0l(ߚQYk(4Alj\s.>ADMKV65NwnJefxlnׇ6t c|5`̝~ q߮Dk_]͊BALPuK+ Qİ3hCSxe4],Ժeh-i 1&Q!Yfd=_4#h<3%\L=pTX<.E9厫<0K:9G|9pӛ'bO\i &]^R7ix'f3afqc֬6MڵH NR .N(Os`G%V, dj]v+O;;V rzOǯ6aͷ~4V5F>r.45&ȗ=`lM nO{XƘlQwI/"uӻ l?w1y1k3>xV3r02/"<+I2CCI3V[iS:y(&&+_di<3v)Ckά%G.\ZET9T`3??P;`}7oo*".ĄrmD`Hoy7'vӸW!,n6_d04\YJ^Zx YwBwOrb X\qD }o ۚ5ib'G0s'41K=(zcƣ`Q0o pFlG wvq4 v8OHFO(@h1V v-cD=odCfP9N%;8 %#oM*9ښ٘3t\`Ds<߂)U<_1&#^Qr{T#Uiuz됟L뀢ϑOEN=3|'a*~B|ȶz@g1σ UfKڍmPYCD%].mkU=: 7T*l]R>bß~ yww᏷}L 5g),|IMKJA ;2_ 0ֽ.|`k B֖qq}|;1"t$A pu6GGq/b L-+DߪQcJo9H\stW [o4ha料\CJ53Rт 9{St~Qҹ>pRkhtKn{]YeJ"VQj*}xK[QV'l w^ÚjKRvFkCTo;!2ղ^jakS専s.Ԇ᱑>|ŤB9N3#t}^YrE̡Z&-/<j3c%nbNJK m^혁;O3KtyVۅƥiXHvLbnC);7[IKmǝa}Iں[k򫈠!?bEAR܍˰4GW^׆-b@jpC0F҉JIgfʮM YV]] ʺe#fAX)}yk"4*iz^WpUw`˹ӯ.Z˽Bբ7jrE4&:vk@ XlDd6=[Ex EzBCcA5xyޏ-Ӕ̏߿Z;E*]ډ S0()KK"cvĹQAUZx[;vok.lnnB@,fԟmS!@*b[桝FL'ڱɇAW]DBÇAը_%|`( HKpޏ*m cv`6X c7C~[S - YZ