sssd-ad-1.16.0-19.el7_5.5>t  DH`p[;1$ƨ_*>zG0TkA)ǀT1/xOg0yC]|Gm;Vڒ #6nexayntLUOF[4>; ?d   8 &:W]d|     .LlJJ lJ   ( 8 $9:rGHIXY \4]L^Ԕbdefltu v8w|xؔyجX Csssd-ad1.16.019.el7_5.5The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.[3x86-01.bsys.centos.orgWJCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64K->ԁA큤[3[3[3Y [3[3b7d8e8810c3bc0044ac877126fa6dec83051b445b783466018896c1c6bd84d7c36a0618254514fa358503707a6f264df6fb3651fbdbe036e76eab3df56a078da8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903b32f946a32d2821794b45e8fc4d7909fcf7b6ffb4d151f68663965534edc125f7f24d815aef2897beef9c86b89f27f650378c467624d7bd5c1ed070606d8a8derootrootrootrootrootrootrootrootrootrootrootrootsssd-1.16.0-19.el7_5.5.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ bind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libini_config.so.3(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.16.0-19.el7_5.51.16.0-19.el7_5.51.16.0-19.el7_5.55.2-1sssd1.10.0-8.beta24.11.3[[Z@Z@ZZ_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.0-19.5Fabiano Fidêncio - 1.16.0-19.4Fabiano Fidêncio - 1.16.0-19.3Fabiano Fidêncio - 1.16.0-19.2Fabiano Fidêncio - 1.16.0-19.1Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1583746 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process [rhel-7.5.z]- Resolves: rhbz#1580281 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION [rhel-7.5.z]- Resolves: rhbz#1579780 - After updating to RHEL 7.5 failing to clear the sssd cache [rhel-7.5.z]- Resolves: rhbz#1579703 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000] [rhel-7.5.z]- Resolves: rhbz#1570527 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash [rhel-7.5.z]- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.16.0-19.el7_5.51.16.0-19.el7_5.5libsss_ad.sogpo_childsssd-ad-1.16.0COPYINGsssd-ad.5.gzsssd-ad.5.gz/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad-1.16.0//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9c7404f8b0eadd9c019f720f3eb5f526da6dccd9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=2e7fdcc38a7867e972847e5e28260f4579f38e53, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)AAPRRRARRRRRRRR RR>R(R8R,RRRRR+R.R:R;R*R%RR R"RRR)RRRR-R?RR4R@R2R5R6RR/R6RQ5'A|_3&u@\`*dT@%R ytK{|,:U\ Å&ryoFQ%0Î>RY{%1x*|$i^*+ `o_ocɼMvD"7iuFx!)IXz eeyp@6q-qG^8j@&bׯ T0UG08}S(V}g}p$QyjpWay|)TWM?<Ho'w5^ju(6r1Aʢ>P"!A㹴F*[Ҩ&I1ˑW05׊hq \ԐWpMNJĴRA# 7$D63t3Bb4L[gi`3LԦ>eHwo>PSߩ"KL_pFjz<K/l( &Y'&S0, 4ڍp٣ &BGVgS6Bƹ5DMȥ{+5`1y`{>D\hkшئ~mѺ=PzWBN*5b'Y]1p0_[8.f3!s@ {Jߦf2Ŕ߄&rZMeÅ'*x+',y gT!$*f rf)I)(e(C; VQoSVzYǒl8-gԋlް18$1S>M@_6 Vz½uF+<#v(dW+ݸip;haJĊևz ;|;wa (+8($:7 "^*d  Xj'#_959ܧh}-YAf<"ENl'}F u4E@W ɸܠ ' S];' +ȡSy1k+u`4rQ୨^`iVn#\D] R'Qv-`{MV)-b?I>/R{t1Ffˣz4Vus]$rS^L>;[=W/޼|@ƁW⧇ks 3k}ᶑ\׬aKG5~ݘEM+} qt l//;?VKf%BZ?b;:s-1ˤp(2H6حW VH)PeeVa3vz1:  A7Q: ̓Wx7x}̶۟g(~)f-JHz8 耊*)gUAɤG.W-|. 12sy})#OD`5KɂD؀I`PmG#bn]x Zh$ړt8ًi1j3A:fÛ Fӕ₺+x$YxxչV$.>﷖4LCѿ#Bg{tH.d1_I*x:(+esJ`ھVgZ\RL$ā~`gIPR䖍cguA4l:EXeF4!c8<ԑ'XiQ$jRvS;89-+H#*S!ٿ^_ MP^#~iH^ _ }-j zZ/㩅wi7_% ,G{퐯7 ! "ݒ}s(73%g5WO</njӐxn W0olRN0H)N}=%5ut)65ʻ/\D,hytZi$uc^8"׽ex뻝2J G}LD?_N L}|f_]1p< ,VqeA28fY8/Co Y%8ۀ}tu4Z* hKd@5.#8YӶ{ߣş LWO:W9 j@s3q{a?L#Ľz(5ތ0D0|IZyq@~> WjH(&w$ɀW!azi _1+S܅+r{ &~1nqbSew2u<:c,7]k@lgj(]F k-IlqaJy>oDJJ&>3ʍ707+n ?6Ml>+W)t7sznmL3= qB7DpٶaC\s1ZJ{ O*ù=5a!Y[}uy 'w4kpMH7A7@iS#c׿)NGKl9WaHD@^ʰǕ!Yp|GO⹁/̫?,ٟ%/`¡xeq𕩿dAqS-/UKJ3FP`*?Xw"R`h:tU:m){9ׄ.dVH-i$V)ȷ!0@1,?̙65' EX>r< Ѕq"zrZqi1Ji/BΔ:k3&@rܠ`UQL `O8)z,IJe9&7hk)Z%A֞E ܻ㘖I b4(C/IQAxDx!6|7|^Ӗos-*NMey47ji_j{\e_rDP^^6S8P-!XkE*!㞮][ƹ^W* z`JK$;_K#("Vh'!# g$مƩy 6H/MIv}B!~I,7UG[9>@%U\aw/0ٽ0 'P1~,{f>"~tU,4hNpפf84B#98WHb~ גzF>}Ƣ\L,el.Î`_ŀt/ՎM]X93ֿqӭ Z- @~o|"`LH% ՍU?v|FaEXך1@~wfVh>>n$wvuK&^V{!%тk,y?mZm!ʀ͓C;:z:Kti@׀Gp*6SV2 jP+EWjgw輀>)'\%aс0Z%cg>P퍁=%DFz5`^Ie@-ID'(زG_|+kqf+2pN ߷ep$Լm\.yd6pr9y{( k ʹ)VeHd*_kPn?ZRLSe;2 $v"5E ᲼.^ *T .i0J֌h2*fPX^fj:+\{v|*mg߉~A{@ ӯ&ޗ|BJΊM?d&"d6Va&.$4ۗ\::~|g܀;\Pն-+Dx7<|6 u$`QM I?-V|a[r`b6EA>3hy*ڢ|K@m@a2(KuYkv=.h|DKKZr əUw _y{ A E+R|[xJ!N@@ΒRGmy撮$@sD;H$4&'ve*ә֔QW'`xȶ1逭ᶽ)rnEӇ\xT™c1LLL44kUbF:H:]m85l¬[:oQO@3Ji0ژ;wOY@ xs'NQm9;2\'=+@S{]Nur<,3jSeNIX٢N> k %f#tӰŪ_# siEx_pUG VB]gN*պWH|A=E%LR~i@5y`3P+v'?J㟶D{)3ǰՉq)5T| w4/(Q(oR]~!w՞zERWϮ?aL7+2o!&] 3zh |{3XHktE?&RvȾTh paW1{X):bC2/(kemֱWBg_*%߬R뿅@Š/ϖ z'Qea,uc #7Zf_]$ӁtɢT!M*M}{1J2V8L .)7.1N8ԓV"vZت% }ka ~;Pt_ 3+κn 8ɘA,M"v#(SCjF+]Eqi-o/젡b>"e}@_d] BadME/)@Yig5KI'$5 UۨY~k4TV"9֝p'අN$ 39  @W%UV=c;]ލ@"07) m5HScUm؏$AzF$=WCi;9ASja XnЅ2K2b{"Pfǒ5Jۣ {ڍV}am5jp*й#Uc39&#,8i~ZPoAe]r%d6?isRTH N'P̚;gK.[Lx/但w1l4,k|-A>5+$fm} \'kc+GPA(ֹh**W<]Jcj(5_=O"M&H_]m%N+~,F榒@R{ Ju0@bfцɕ5aMb^kK{ʹ!ovʛa@Jk'Ɩ8WF,Lm[ЯBW_zU=Ԩ^ay= ? ,.L Z-/ip$Rm:h|diς`΢oƋ^}K@5A(vHϿ-e]JS9"|a8+,AK`Jd̈́GW*;7< ⺫pMggnRUΥ<"Mq"̰2;!;t$Gĥ^֑ h ts2,;~3# ƶ3KlA]j1W5:Rf)]@ȴtMiNv-Iz#`m@+i.:@Puhb"`>I3H U(:j] yjT|c3ʂԝ'Վ 6 ipƫxkq3O *z3C.qE8=_8Juݨ]ɽ}Σ`?/R+whf+YWU"&&YOИCR:$+mw_~4_4$S7+D.9Л]1]1=lQS^Qp`v@(88N 4Ste6"9]8LO|zwc|rE]U762F˘rKSZz@zǍH$l,}cn5H9ŐP^ C1h?{3:nTڱxc*hU]2>}YT:lV+<-t$T &zh#C uVkRUW< G6NN\@9q.0z(l^ nDs$!bD?aɧuoxy>Q83QTOB !?XG=xn2o#yB`DUrH>/q8SvHJl%Bdتh˝`pd$}"$Vy$k&Ytd H=G r'KH ZWi.ccq?dZF4ϜuEyT94fŧ>7MEW2 /K4" Z&G '`r=,yF0֖ޑ -42BLA!ƐS a搟<͉ K'"< & I'k-ߍGg-+{%Y@S' g3<&2my+]ޚS|wFLjsvPzTz~ZK[ ]QWJfTpA~UV_Nx"A$3#-T1Y+_A TUF1Å uܒ =x = ]!(ˆBM5}/`hcU)*(H4VR(ͣ>;˫DYț"W j1t{)X+I#$g=54mEr吪rݡ^v! G'!/%qoe?*C)ȑ"~B|YnJ#}–oɰj{ļRF22s6N>t 7TvKoPkZiRZowŮ@`l1O!c:X>/h&1Z%Ch(xebs2cX"\vj6p3^O}\DBe/6Bmt喧੟xʹ< Cޔ-J '*e~pccl%#-9V)k~* w#ݏKF:N~]s6t]n'Lש$Hp";} (R27{5lHe y@B>J;'׎S?eiPb}༔Ʊ@We\*n3GHŭo܅J /~k#1 IOve¢'cCy 2gGMq3 !$lGO$QcMm\g ھұ#(q7i1ڐ3NIhr5 ZO&E+T o񍌌yu{Lqt/!#f$[^䝹w <|ȩ?-u&7[0xf$6~uASgk=SrC|O00 B%_R,ߜ;痿=Z"HÕ 6y*MFAI ) 'ƝC24w90%nWpG ۥmʼnF;)Y:BJ2;pF "A~8{eg;ztTGO}2b},A6Sjk=}TIOTE`DK};gvd 5.by!)v*D`Jp:h,3TycDOIޛd4JqvEYV#{'V!d\;KWo4^4TՈ:(-Es)LzY+sGA0N^>u ]2pLic #(w$VӦSft%"i .3*حlI~J-GQd#{P}L=LPOREɈ$ʺηr %|HF>(7Ge(l5ptpoS@ #BXeF yWvUM8'5m/,R|| DENnnN:5tA E%pC ٲ >jTr6PjyZ3G,"YxEܷ%'G\ɻkHeGUTë,?}Ք%lLtˇkg 5Ru)z?)K0;4T2r؏Oql7||CgoxX؍ځ5D3w$Bw~T_׉|V`sZܳ_<'Sb> ^B5s+I(e%qH+ҚDH=o;z&P |3A)T*6:* F]i"fY؜ԿUpt< ȹ:-$u08F$N:wQwn:Ync)fb Z&o-]=XKLz tN`F콏B xj~0৆NpOY$=*{2>ZFo l2}('zK#NG{z˳ fv.Ϊ?[&f'a m<gc jNI&+I1A55"#Ӎ Az)iSڑ5"aX)BXi dH؜Yu~t"YBf.|DJ3m ۍiX|PKu#Szv0S8n&70?{v;dFHP$NcO%U&X4Sτ~SOp$j 9Q 򱞇tibu)=ݝyo>Qsʣ 鍂2A=6# cNcg|!N&$us*1 {uǾF܊:.êJ`5}/ýSZnr{cy Yqc\S(8; k7(2U$ b1\-yOU@_Yʉ+=Ͻ T1ЦY]/=RuT"rsɲ̐XVݟBls[,Hv &npE$L;>)]$GXO3. E0Q5G` Z#0p\a2mbI I^wh@\Z\-~zkGY0^ul@bAӉ@|4eRB'89"y k+$&2%:</'B)hdg$tG27 L0>M "1[o κVcg"S۬^2)̕HK?$!ޢsnǤ|G:[½4w˯vu|hp]vzDM0ܮnyQk1Ly{|>y$'զYpyeuSle+KbJ/W} 5i]O3$f%hXp[8|h㑪ZP?U灀 g 6Am<6kxf>  HMht_A~V*:beo:հ7}:ri2M! =dz>4\b$ xbFmKA -={B\*=475ɇ6'Nkz}}ݰ?&o4>D9#ƒ=\l{c$tg(^*x7GoX6uxNa_i>O$ccf>ND/Yvj/ ٺS׾ c"#C,p^F jR-?y,&p.`7>E\1, Ul#k;Z݉ cm2bLEZ;;oc~/aJ5G-Q}ʤMz7;,>5q ǫ1#XKhS/ emB#A`I߯4s;»]ܸOИ1 n;PUoU\;h;28-+ʐTSoN2*MLh nBgB)2Xgnˣjrʾ{2L=YŃ$a 'GLj')qviGn CEPtY:wHlr>ˋQ)$f=ۄ穙me5$wx6%VXzH$z| AhqjWG'ƴ%RP1%“v$rC[pWuuH^.#pHh&tC}njb~NػfjAIr 5f.rm+ehîk,Aս kic -7F:!3n)nc)4ν.GQya{ԣߕxqKc#1]v:5wlcZ< 5n#ODqz 擀-=IT[ {ߙ7 0{3]neW @HRۿw "gĝ<KBCk+xNIsC0uYPlc*4ciptg߷ 4^Bxt5^Q~pfkgUg~981* nTN!_5Y_[kXVsg:x +o]8'e.Zxk@xPoJ}܇9~WhecE8F=)LM-#2r0l7&\>?1@)?ص핢9X@08굮X5mB+؝[!f^kcQTuX@I+?D"ՃH;ƏYjDbKJtIGGK&))BW,cZf ) l :d,eՐqR&j K^&a`b0eT%&eLd$KqgVA 魂'@(+\zw;F߯'K)#W@-ktWm3 ; H eRξ|4&pdQX`SyϺHS1`J#}飐M3; e :S;j񼻁&l)&|@QSFRAɂMMvRWERHd Cm|3%N[|1*UOb-'T<\5h_bx 8i;vG&+taoB:n .mZ`0g)!> bM[7w<,Ǻavyo7ILNm7EP^*89Чw@bGnTBw#U| {-oQ1U (ض$ ڜ^SY?϶V/b go2qja\h`ś'F\18%:g 5mtOR\~낿T~nmu+-@l;o8$lYC*!+tkRl%_U 6}TDCϨlNZ hlBu=Yp2\,PpwmnLG7މ˶SCQ U|uMSu{O ZMq# G\-RW2#0g_U>yviWklg1\.nh齃yxXݴ!S`2heTl2)?H;:s[ ;D)#n1@6TYS m|7خEʨ>{:;ЮZajkqFtqiƒR2 <ДȢɄI[o4ImK23v,cjdyw 5GWZK;fj%| 1/)4 P`x5/t=>X6̎k م:Lἦ!:T#&QIx! 5mܯ2ـCP>'I0|MfkbVM7.νv\O+]mZBpXTȶ2rymtϏ<,0+8-Aab?ǞBR1k fB;r5L6i]鄶8Q ]O_!+. ԔI{8J֋"i 6~P"tuP}_Sn9;H / Lo&с uSOg(e5NĹ!3ۧΖlx9\_6^S4Ketc:Vp5U8mw\1pU9Jzo.fOr!,RܺMz\3&Γ8u^wKVaV<jq3xzf b +F'hWLNg\s@r[hj8Qp7ڍ9#Ǣf\*Eer2!Gdl F;8n4C( !G*/Ş:w@%X=AuʋF#쉧[>N@۠snBmOg"Gw},0&gU-R3̈́ORARɒ]CN,wB\?S#V=Mhw3ؔ w.GkHIj)9jN7ʏ#v|Mߌ y|* oX ~mYTc˥~"6gX ŽKR輦=mĜjJC;khL; .F[- ] /2f0he81% ?Y`(>_*cԀK:TsRbۉ˨t Sf,d()DR #V5{]Bt_ lE+ʈb^꫘!m,U!~e>^.ȰW]<燚y6Mz1Af^:oŪ [ybz+gOuw> ZSl"= f\kUd0F6x;C2mW ##բIB} tЍ'w@@׻bΒkJ^|Q,ST@^mC N_ӌHH?34׳<YJJVbE<6VL_ bqs I=p{Mӕ ITQbɭ/jGgR2T&Rx<4b.!'I` AwyEMV =j/9ㄷ^$PTH2wʻ uE=,gNi=kwD hso"7mg{t.s~vL8WXf҄pc!b[b,T[x\ꦸ:UMc,ݛXp \{VLQ0cbNxn7{L7ܵJ_'cUlӅYx 4mrJ~͚צ5,Vo@C!Qr٥ѺY^"XI X,C3bqX*aU+70D;:-s25y=0~>3PF0#r[s/|,h֍s&,6Dyv[ףEXHƒJ\WFfu鼾dek`ݾHIȺReO-vh IkXȰj#z|~ 8VְsiMɇ_Dilhel7/d2`<#~וiYI2 Ϻbn X1s}G {8!0|4 1W<9|eA 8h[O^H@C~91xF4 EY|Ac˕%pR ByRZn>$[@wP󊔸jH玣lcZ%]/OyWe:EQ ҽ-As S%I4/`Ct A q39(yG**3$ȭC` E'Yҧ \Naszo r1E=k\{?UN)M=󫯪ʑ!J)> vK*yA/z ē,U-A,o <8هhj֚pRpzU`PjZaTkx4 Uoѵm~T9LL`:G"i;dJf/~/@#͐ v#UdxB_Մ5 fbZ LN|_a%DbM~c_]}ގ o-2g }͌x 5DqK<{lYylm&H);~:tT~b}1J "DbusM0Z1Yu0_$06樹xUrMDv@diѝDe8VI<: d2(_ʎ:JG*6p hȫV_zM_+kFaC30'{CE]nȾS]ǘΘaE}2\";tn_/7߼V\YgѺ{{긿9B%" 8}|'FUujù=8@=z}q A$MR)T8ֻl$ [%#L(oK-=̍،o!9!ƠuK5VETfiF VDZv"9*3D֜8F E: xG] tD%\G rԮ#Q\g'4Lv@/f;/EZ0SIˊ1"ZQmOWHCqD- M]5F] 1KX~>7OrcP)K=tk9ȓnmHa2@EBhTίS6c:qwuhK ^a;z|ݑ*z`qzCiE~#2 uqGnT`\o*&?*7r%95wP7*vC>yD35ѶP1sڝ(y/cz9UNr$ہhҘen4׈|!~Ex{)X=3p]0"gI hA2w]V/wPc.̙@~OFk A7%xd(T Ԋ#Y G&]HP')!z$~ !Oh`;#`H{,+.5vzT+h-WFrr Q4/ ?F5+SIL-HUSs&HaiD{PI|&f`-(I!p 6ߵʝqՊ)S^1 |uVSV뜷RjG%&.Ir_ Hң-٭r*@IvwOrְ&j* k287!"ۚw>\"}T i].Vy ȹn-f V_W`q'JϜWMEJ{[,mӚ-Fya*O޲6I[ {#G<>WJ0ǥa%` ,]%TJ[KHwD3Rh?ڵ>%oHe˫d\ɑ# V.u84ꍾ[2En3.kM Q_vC{/P;G׀Yiz.,qL^3!y機>ʓo:%\ 89!bˇW=mT$d):ݸ#7QB_6{;v%Cn٫"I9mNnff*䧓oR>*`ZЄ D++ǐ, [J)Z;*-P~w<UUрa`HtGP+4?hgN[N3Ŵ"/EBn9땇}?h*^O6gh+}~,ʝMRQ} VCCv=Ē{|l)5$ RrBL`%Q-]&:G9\Lۙ!\DZ,2䷔Fi 7X,Awc5vPDaN6s%ʱtq-R?#3g7(aflX1bz3ĘM`Sr4^f?&߶ W̐+1 /%/v88;62#sdU[v%E3㯔H B` -1ͩ/N&MXFUpY;N]V!'ىO QD.]ǼS\ DUGCK,e5 "97Oⱈ<u˫8-ʡMY}kv |$nyG`8E^!#>:뒼$و>j2? ru+Ww G<1X|;KTY gQҒU*bAՆv-cFq̗tB*c0ڶ&7q-N-!Wfk6{J =*DGWRKa!##i{`?k.fMjBҷILhJE y} Xb^ 8A| V|& &x 4ey[U*1uMa Lq^m]74.#h]34l 2`*R\n:1C~|-ACHu~Q?1o1_coQzE܎Г 6)JC~s꯰HYu{[X4v{ZaȪW (68qX*YrƳ ImZJUEH0tɻ0&Wg0Pܹ["u{gQ!㔅HK(&1Rzf`I׌$H_jsEBAdH2  :%y,2)e:p5KB\ (vc'+%L`犞} i &?7Cp;:T3[SΠHn0tb/˼Кvz:n= G yv4򄈔|df6znFr[z6+Z-{'!_?xH^C~/ qM gNhE4n uK\ ̗oF4Ab BurJܲE;ů btʉgfdQꇥMLc!xoEh,+dDϨ,: $ Nۢ$T} fj8VP굳_{QZ}CJWre(&1D(^giwZtUC˶P!ZՑf\=18<sAmz߾BA);]6̱ןh%LХa~{bt a.w gQ".TDtRFJ2xPX/0,]a.4qhZޟT4uA ~L*&!zU|ҥCMvgH63({\j88 g 8;zǣ35Au&7YtBs]XG*M kfZ98В gYSRhrbvukڎ]I{iM4S`2ٚIIlZб;a|џ;!n[ZTUlHXrx#4@UET{i62*d[,Fa]9@N= 7Kq/$7zE\=& >js?~JCޢOMw8uQ9@{NL;6*LcQK ) 2ZJkثwqr|3pgr+{JJDzsz"ur`xIDwF y@\ pvmE[ozw</Ju>C"rR3a80n|m'"UXe$W"ɕ}^8Q;0ޗ!?Fqi!~#.,|םt4rSxYjM( \E0J9Ĵ$ԛ@3J(.{+^AښZ(MjeiܭFԠ)B12ʗWt\z1iTrQ7?%rhݞ8a麱x{>҃/M5jCgW RX#[h1 .kf?-#_9 >zpߡ/?+ 6b:B@BېG7 Z:`5#KTa2 ;B:\ >S'[yg%b'1R3]ȷ<лp@S\kdٻF+ӰnRi%oj9ؔOEM[FTx>V[$YjV#+{7BR®E owx?:C*RitָmVF.ϡX37`ߧ <_ȄE7#SSK*}JP1!9z4=}$f'˧4jM-fȉ-=LGfi^r v#(Ka%+HoU@1,z~)\-iDDYqgcq,MEOR-[n<(6[ ~8ֻ4S \妗Nϧ1Whrܵ= @lGfutAkPVFmdԑK5"`"1r1?DXXZ>_1>Rߊ,5@Gy'Q5q%9Q4J<@ת (Ta*jRߝ~ ny==J$k0oM )bJ-aڞVy=ք ۄ@8&gFLy֟!qWݤgX*} S#kh K9 7SФ9&X)-B[ž]_CQʋfnk_ڟ i˱fR1 lOj$v+6/Zs}FEF/.bGRl;t5 |jL/s[ yw*>njTTA 5lv$ *lCC&9h_ .k 4OQч6,{eq@;Õ XD`=v`IH*T J8{M>nA?#g[6C6 +^kySsj*۞Lt<&\`n>fm^P(V>qu6koG@ݺ`렧nTGdoǨFҥ@y$mQƊAB]݋N`p兒l:[#f/*H,鳄)~7""4j"I3UDRnUk+ӹ"k9"kMzʇڙ;F(q~ϧݦsU_'`q}U*=A&v|q~ zY= & p,llA|`vbyzÜX a:E{Qz1r&nٓW@.I3M51ܰzno'! !B3|l"P|_`JcP@A~c頖>]oʟe W,H\QjZBϸū\,Pkr^w[W:A?A4Ѳ"LNЀ5QP)b~W`Oo(pŪYly2^GuTe9 (Pfo.OE.,#݁3J% 5rX[!i:9N8-F=8JؕwdfYO!Д3iʼn#@9h B#!Maў5L5=| 惨-UP0ln >]ěoQoR3ǸK7q+K)_D٢z;Dv1ە_r6b%pF$C >B.^bؑ{fm 5bڕ\:'iwFe[ )Z(hHA',*<x 3 &bG|/h^8-IU'P۔*]# kZX_5$Z2 Z}t*bj{D9 mv 7L'k:"/ec7pq^?Ae )@zk߯"Ja9 E0T:nfBOɼx1NkiA{ Y Uo5C]dkca&s۰*`^e%ŕqY8l:Ã8^>W$j"8 ~XHfw0\//?8@60rߣZTI9Z/Qm2 KrKGqk4]7~v@0XOCfMC&|v+pf}7킗X$[ꥡ6zMr&(Q+0R<^s=t crJo?R{glI<72j캲ro l6l. ɓ2}svMla2kRe[lOuS=5FӜL!7 `5^q>p;1)L/¡ErѷꀹBWT#R TTY8Dj;(.Yߩ,FVVT&K'|Cz@gb̢xFʸw/P!'.DPZK5;ӶӠdO4u,ݕV9Exޖ EK5'omtHbTzLBĶrUpȂVMʲ8(v[˕f#F}7H^HƘ3UStb;b2'PRp8:<#߀z:o"մ:>Nt:% mMl#@JbЉ"RoEKH֋fyǵ%. |C>-mAzhOw6qSyCx -oV %.yT =rːԹnb*H%4I{)ӗDK]{B1Hp|KT)62XƔ$YCĆ+G tuJ3vP95(*NX^D})]}^:_ݯQb/BƲ$]%SX`a\ޓI~ykK/cZC3xNJ#myhiNƉ s(9~z{/ODV2i)n[y] og$2*zaL$U9COMQ)盻 k0ٔ ǘW17i]; ]/3K*Ju+G6A;7m%($6ϼ3JK%K<))m1:/,O:J;TsHy hx2UqAXŒ3SNXWidx͸{W֋ o$껳Yh껌C~Wk2 cxQ~BdRYL5LZpp˕! m*kXYAYiyOꐝ2BK}Y@ z7'4jxh+ պ9tkĝlX~2`lőW[yU GqkrI,nV٩xaI8#߾H vq!.&ni> @]dȗIP#|"Р}k!i6 uXs~uXO#>Ӊ ȞAv@9X,h1 ojwKqvDUEǵy#pFK<_Lk㜖j:--?gҮ_ےADBJz.ۯ3C.gWϻH,!S(@Ldr!M$ #[ "I>@AupQSad+ 0JĂs\Z2d d @M v5]kCMaEw珄=׮E3N]Y@2̪<(>ь~r+!*VzC<Sz|/=]@nwiv=7AAΜiD R?Ģbz)PK˽0D56}@Pd,yFg mqlC)Q$Qm*nhWPV QO bZ|/Yh JnDTƠPycЃVnoM%{n8/kEщ e5gimas+0x4*RnQUW }EN V/!Tt 2 (7ݜcش8V5y,ys^eʟl vwj7k~AͱW:b4دl ˫ȲU_Q\c5(,h|W^V$Y>A dH g7jPIuIT#x؏‰}$oLUzkQ.)L Ȱ^ N[TH-uwRWamv<_"+LQA&j| X +ST"R=E3~$ HpigHHm{' r_.Mȁdn_{OX[CY%q D.x+Jgf}"|sب|~pHMяɴdVリ5E䮜 1cp&jIr73FP_iO)L<̵LN\[b$bw-#-Eļ][P Zhbb1x)虚U-ͣzbt/p`ś bZGm?raVѷ3˩-fpRo>JJ8qTMr0Uim&fp}@e, K L&p\LYkʯ]l1\uG]݁R]lJmIˆ,<#Sw3ekӍHT(g)1s+bru#+("<5cXÙ$`  ޝ|x,xuM4$ԥCHI'iezI d^xEoh{8vp^-ydP^0Ց¢ad/T|8#%(߻7pT87I&%jBR?N zp'S߱m/Yoĵ)cyi^X)WȣN㠊&2j/UblFȜ  _uPG;9Jт l1YF c-\Ts szвX_cEd74Or샌tk`mT(؅#8tWO#p"ɣLArᙠ.a&#Ar+l hfY@|^[Qh3;cM)Qߤf&g -bf cAN⅍?&\S&OhƷ(f>$3ɀ!aēB4.Z"%S4 tft}&O<_gRWzյڕ=AǰQ=#g6迄W <0/٣l6ee">{9`"H]ZEI2,:gU1ҕ(X: maKr0WbwD>zW驾#PN"=Xl&kͿ ֏H@.^U@HOLz8_a 6*@Y1P-(@~~jHxh iFCɖoCx\Y1: bM"<^(m\4ĥ Y-/=wo*$B㛝I^C/DiH3ך"RD9q(_< L7h VNȷy#˦HbĹ5T>J#_#O #Shik1B|?4lb(sӵ4Ŀϓaݷի6GȬ<[X'+4 ʈ= 5,(vn[\a űGGqUW#h: P)a` lj؃!cNyn<~5J.+l7+G!3 BzMf &hob`*$`2ck+^g-ChCF剁yJG1=A݈')j@KO61Lety0(K;G(C7n%h4i•79tSD_7?C1 e?aTtZX.'NQWswl\ }!GD;eھ/*p?gz(qvmӶ YF=6%΄cFbw 9yD#KV:^ifGI| ~NvY^҉,X<-Q[_+n1C<Mh/&IOSP^-RBLhz+GA`x4[.c@ bPȎcdw‘! Z1Mm3]`oN\6zWVȾ^ftoM @&fl)!M5@'}ƎT~4}h_#SMGV{翶DP`H̾Ys gCJ`q?BΥ!qR~ ZҐ4z(S$zd_g<*kYW7} ]#TOh@pwMAyά 8 1ǥmhogY=C!ZՖ84a,ڎL)&1>7c#LW05z͑ `X3WFZIϠt,/sxn}XU}06RXuhGBSFjZĞtK(7a.? *"g4* ;Ic#ͮv䌊> 4b9gj ]\I5bl7sO.?}8?nTr>4UWRdM[gcEV$uIO{ut >b+`Ǫ5Htot e$~DH5)+oEڝhZJ+ !,aҾ5Qbݭ>jgH6Q Ӻr%)i"R$T~ ] Hߙ0TRmJ'#+ }D:ˌC1n?chG8R`܀ݼ< T+:] OBF- W轁#*Ti!SzQgr\1s|<jkd3A]NMhU:]J\}P9@_l-=WI])@zPN&Sqn<PI_RM $=I풙I(5ǦIiAm4Hf*L>d,F LnQb#94aBI>v}GP0*dSv m@BhRĬo;Ey Zn;w^"!dۑrq~𷏥qjD}͒Ą轸@6d86 r(\7ղˀu7볭3K+g,\ Kx6[/)2g`d"yFddjiXg1ʎUs+H< eٮ%~?#|bgl܅ O:.rYwx[CAj=!ouv4wJӘTD~nx59*)hҾ+$'kOof0Ϋۥ Z._2}~卙 cjBڱ$nh1Uە #x)՞8QՀUr mFDKىd N ^+cӎ4hZV r/"=ζwBFWkL-^`K'D=}"}NجHΦi2^h~i\iNa]0|k3l<ΫW,8SVbu_g5.BUeHǁX{YbyAi{}S\N o:9Mw5uҚ|~wKnJr4C ۊv2-oY?D\ k n5v SVZTF5jb._7>HJex"MYE1脊~]0/vh1,;]/0^ՐЫ&c - pCLДG>NH~H{j4{l˭fߣ~fǩ)Ql[*A5:i <;dY$J/5I.^i;y鵖koΜ | [9,].ѦO>SfmTGf"ũ#'s>UR:nyo?dxXclf?Ify/"Byn *aC*[?.-@LSic7[j٦#}GV%;Pϯ4$?e4Ar;*cc }LI]3q%m ; Ӿ:TlЅ\|3"VQuS&o 4bA ^!P= u=Ϧ }}g3.C&7vuY4*1+Jk38V`r jNNX=b3Rbb˜9_3ݣ@FؼefD@ %"S㡤}(8cVL[.:voh.VpT`45N`S]}B2zet8fUtp㟜b J$߫6a%s, P=ϤuQgɝ "b`KR ܫ Ak8vv[hA |n(% TM@_:AܗC{B2L?A'/΅> #ѱj+Hmc:/_O끟uK =+.C:O6f`t7cS~^~\{DMb;)G=^'V$380/r)ɀ8ԛdVD|AiyrkJ3XdƢauۣXüi#g$p~9`!Rf[Xm],#7 tBB4B!?:0Dk(ThѸ;"қ3Pp\7!N٪#k;p1oS?^P'|ӞeѝR++ FJw9)o'K`xQ ?glĚ$CILdɴn&,j g^9YveJQ;C#~Զ^K(Pn\w9Πk? hj^ej=NP#Q|kEW@T\g /0 =3W3I\lt<үR@ 1%>JttN3uuC4H %h†i` >P}M(34@|DG+]*i^FW)dU`_0{# p`4`,@>06v Er(~מq[c#SVy깣>dPWBEM9ju2&ڞ9?ջiXk0k*p=dg{JG`Ѓ~7jtz6}ub0hc ]^=";*{+!ޖv( ;dd׀EU)$H3Nnmá `n;pT't3F8SfnEAը#@*-fBH'~=;(WsǢHцsRϛ6e\Rj8|R|`d疁 }k2^"2p5"#Gԣ^i+vKMbCfstJ<3۰>P!gwbSHL).>xम\&2z΍0s6Ml/i뷄z v>F_'كWY[9Y8HwN& -H(On6\Y$+ -V^̷_rѦ@$ xdCu ӌFR=^dfCFЧ~ۘ n3{0/݇)ُ _2&#v-`)XI2-w=P\%sosߣt IREŌWJ*'$/}]Y)t&6Ctyô1Ր1(AJg\iXD "z:(F$_/#=l&YIkoB qd[3΃fYɪZpHY,' a?WԍJa䳺PFrWITN[X7I0p3ސ o>ζe R7f}(|r$zx-q\o_J^ϖql)+ 2/8MnW5MfRi5iAl=;A/)KhTcgth|X}zUz46m*m-)(y_ȝxFum͍/HIo5ؓ14@2Ά?,!;]wPU R?;=CQֺBf&!=NVWtxh! 6< G:r+,14vXsNGsQ*pJTs">˙7irʡ|ZXʋu:k0;mȾJbjˁ>8N5Sh1Qk@aZ$4GrkCA^1O(*5ydqwVa8E\A3JA\n_=ߚFQu5UI 8Ծ]ZGڦnJl#IULo%ɑA3n ha*J+c1NNFk*B7٣̛{#Z]{9^b&eߟj(N?:Ol0k,ǐ`uneFd&mijϸn0l^l`d^JvΎm!*Mw}Zm=T|j_t"ΐcLuOۤe׆h\")r+U 3G|7HM\4o= YLM=>͏7D( 2l Et()ue:M{8%ң sFB'2]$7 [KG4Jk xEnim>~>b u";膟r[R}^I_h21>jGx8ᔎEG`cV|\*t*˜0b|Ӗ=nb2{ {?J̷i~܈-&ĦUZfffhZٮڨGGV!u ze]-'ߑ"aNto0A\¸*UM8K%4/SSiH^rktʰdS@n5Nu4ku2QQoSw}Vwd,!z(YIIۏ&MS}pXG-!7(Z|B>g!׬Swi,.yPVҔ+[|RRa סx Zw"%侠QP6Q$4L4/}S Vc5zLg\P;o*{ Y[* Q{M䥍Ty|Xux[:ҿsmR {;KsyDiHL6lE TT"r~ >?s.rVgJifn:L`W$w6h]gl~N c!+jn e碉]-iO/Q-Үa)`ŷ椇eut:'|'\B:_s+"G]}*X!Nn`:0D;%|)W/;,[Lߪx( @9'Dxf}G"'9zyiڬ6"߉B pG `猩Mlj0V`anZD_ୀaZ񃘹Ԫq9V.n្xx`k2蓫hb?XJ㉆[Ω +ph1ϙSCΫVS<.[D:WD]}iF׶Hwak$l㹑 AFh.m;ۏKQ쓘v2*y(Ĕ@Aճ$ʃ{ L@gݟZ̅VP5BNnoqq$==&!x<b9׬͸%ɊA}`tv#岨 tMiv~6NT(H ObQ H؋|,exsDd (7qԃ1mB)݃Oeӻ*E b RBw#/wp2:ypZw|2^&Cgg,JJc@{D:*3ϭgdk=m|;e9 Vr7QBB\Rm}sWv"wC(nڨyB?~@81Ů:}<;nߐ>|:$g!:)aS6r6¬wqV"[wv]?º)~UC->#Y @DOI H׹RVLN ܆uo(ORe"z|*ATW rFA3E#uϦxD/~efI|F"w}9FLى߾7GquTRxvV8 { % DY̑|Flrha,ȕΑ-T4q t0J..ڸJȆJauAE5v#rsÒf (2"_+/iFp]Q7k)ȇAPUD䦝gސ錼}5/V @:ba=V,9KxUe2 )K]T=g]8ZPD|TG/E6g=+#_R0a ֞%zRY˜{\kZ֤sHa#خ T}92zqk'A2>8.kr`HƊn Yyp#*|Bs~"/F,떭/=-2HFCIԍے(׉PWRc _XIN2GGgmGXBHc<`<ր0,ż:5ˊ)r_C\]\\yl kĠ0ܾ2-0ɲ"o蘰`ٺaI/I)wcYIt<[߿8>'{fJ\+tK{C /N ZPAm_`YcqUǪJq̐~G|)3`o-ZF3HOL8j~GJP3z-i䶠:xQ29'{W{˥lDguZڢ܍@(eۏ֢:i~$=Pq?@Ы.~C=]# P,&r3c\fCT H ӱ9!?z`JRb)p@z+ĐSVje0Gwf #6\9**|.*ݪ}\S =Y a'5 N#. B /,H$>{ml*?'wv)1>+|ǽgR顃&-}g^+H " Hf}Avgi-Ck/Os7 t&su+h. mk@9F)驔^ܶ ^- ]E]L|QAAiJ}U1͑КZ_-`p-6<8n4fpKNPxTڂ*-ՠDw@[n@@T3N>=#*?M4V/r^C@̞CLs7\/ŘҎi3*N8<6hѓC;IYk}lA1!Nmն zCӯN[K/N >E [Ku(gƅ.1kA$ o 0{ Fuح ^Q3k[3bCVV盝^Nh=4o0%U%Kd2<ܿ6?u=-aBC2K2 /+cѦ>kdzBu?Țq4pcOA$eXhXvL݋$2$Ǹ㗍퓭Aq|g'j.ChetɟEt嫓+ҽI'"mnLpYTp&–h<'`Sz$-Y3(x/s)Osy6-E}S#F>09˔F۹|]{Bue:n2[ Ƀ]v/c2yxܠ{q@x罙ٲ1Id O[ 5-!0uWlF]\ Lh)>ǯbչ%k&oi  p/gѳ')ڛ):F6װ'\DrX9Y y*)P)/1 ^fƐ;0Ee߾VJ kٮZUA([)F(׺t1,H8tY!,ڐpͅNI3M.]2`1ބl{[]3N3mTYʺ|ِE&!lG.oSeadt%gy6,L]Gs#K&'HW5|ttQ;l弌c΀n `" $5+2uoqLj(q*?"HT9WʘH(K.=1˔Hip۲ق朳c qxNp>aJYʗ z"^N]7G z3j~; O@̴ x=#iT*_g$gs[{rElc̻ i 1:t5o smVؚFi-6^x=p逶rK{^uM+d5yRX@}mH_QZFg CaD!E.k"DA`F"H滋 YV|;ZkgO vCCTv:Dml1ōi o! v<9[q'뉉_l;n ?dhZDrq:It I*M=Ur;́Q]uoh\Oؤz En9t v4I\hTh1+gZ6}<,M75 tyGH[U%q٣ɍxUiQaIX$+;lØ= Jr)M'Ƚޑ*2ٙ(Ɣ) I &$8,rl{UxȁxgK6 U]}g Z+?;P$nk@l8~9d'0ѺE8}%]8x(NN2;S2ٽA*]fj-;e}Kg6-iaǚ5 FI,dGFcR3nBQp51+;馿 ږ s0pxŶ)=47 *$ p 9sjA) /ŝHVv `E,H b&O7}H~]n(EV oQKXFP u|ʬ-Gƻqc>`"}N*ʬ\gλ>7/$G5\Rjف8%WwTō u1r4k[ER,Y3񄏄`1&TKWp};'_UEgb,RQqxkEr{guk3xgE8ʀ?f9s7mҘHr%Ct ^xU!zYj(d @>5QU;%ogptFEoZB4(-ICkš^IfG˱-[sF^obYOz ~ 8 }5I~*~hf]oN :HBv?9wHGΡr(."K怅OdBjR2p҃d{NCm ɔ/^˰=\wDz;I(H9b12Eksf:`Y \:Mc V& )M~.h":CKLe‡$i?1O>UQT BfO,k(GepR?lxu8#V Z"aNFl@&W"L:)2|ð VFL GkZ684u+@>4");|Yx0$UoD{h@.c9@Q.2|FnG&Wa%xt` ldʽ4kDtžwZtT~W!H}a1Q Au;$,V 祮~g]sܵ 8Flo` ֝"͖u:chW}eo9Fv ^!CyG}?e YxᄃVgHv].tЏ3$GdjP2W(pt{MEѻ Rt/Ajpwo"8(/+'zxϛ'{ȵWtF,Y5FT:KyFz津apͷ1YUDbiWv%bռ$$hrI`;V ^=̀F['L2eB"If+k`?[+_8#'IJ.P2y|#G|PqYWMō߷J/gR;lϽ ~oа16dsld$Ь<6rfr]RK|$b.R.R&OWxq=mmOhql뙺zjJP,dI7TsG'){{$-&qB((j26Ns"ђ#KbBÝY̲Ҍҋ#0p5D or4εI2ufBc(yԢzޖTl6"~lnݺu(oIS9$j+jo[*'jS GA;:Bi[ sy⻼0l 15:/ YQDŽ)Ł~`g96`f}: ~k4Hh,t.!p~) ׫Z}"#4k Wn{*œ3+0fKH~u&$ۂg+oBS$Wژ.=fW= >3:b)e*r%uxy~K'dvпvv4J2,kc͈_ٕ}l}4d7ѱ&`p` ]Ej+1|2"9cs?e/e"M QW7L&X/fM&VυYC`æ/ ZZKPӺdNچ*˾1>wzyA#l1oy)!LJ܎a v^`Bm *;zvkzÓއ$>qcZ$zC9"ߧQe]u(-=0xZz_^bCL!ֺH)~'|Үo:ϙ"ڂY, ndb'>ݪ1jFE/4&K&i9@NNHF&!@ET4?] 8^8/GMUO!*+(âӁ~LWz〉f -\;X釪Z uT:Jy8`Q;X45L{w-dm/Q>o> 'ٔLASSs$Y!\A O%4qC]W# Y|黥ٽف 7&x>Nhxlޅ^ }o{R}OSo.Nٙ+f)aF0zX y8 Z$R:X.P0 #j|i=wLK>LK}l#+?0T4?L݀T%n=ހB*30TI֧D649+Hd(=ֺߥFџ' ~2U RU,y5?!4#Eynl&a{+5C]rPWˤ3Q9TgbefB2##?f \^Fy$ڑ4Ry;YGt[/(-Qȏ~>>萨ԞAЭIވy+nY At93SE,r=Հnb.Ox9e5s)iKv3\'o5cxay(0\2.2@4:M>gZFQ5L)kB,[d)&+Ԝ}G/qH2w3Yc4{p^.nԻ1-uS]ܓ*zb <·Bѭ꜀  }' .k7D64\Bٌҩ CIR`)njT{J1^[63>S)h{@|<@XK'E~c:IZZPcTzSF HpTtn]?Pt~_Г.YS%ſCD\Mm2*8)m4NKA*P]yR$$[ח$USi^RWjavAmUYSUcvkfՆ|D w7!ywr1\nTҿ8ᤸ⯇d ҽGz4.9d0]YKe7(tAOI31wbƟ}05> `0ZCjQ[IFm=[mnW-Ig__j9'QS` .D~l_B6D$ xI~ :;>92Ĭjbi)w#F[-mt]86һ膏}!g:.8} && h"&HxsQ:⚭Q_3b=Es'Ib uߌT`1^iU?"zN셚?~D쬟x2=EUV(xpA_67A|pn\A\(A~ 'rI V;RkO"ŭRyfk::G!Bרf"J+T!)dVXL(r̆cYQGPG*N+=lsr@@fD3mM3胪<:K Qw<gf{+;F&#nrK3z*1Guv#@}H' l/ HDh/'WCn"؎*|ad|5.6L0ЭQbL3 $$Ѕr 3WP\ά .y\*?1t'X@eO0өpU;P4q*zT:~K( Ks飽 ^8$6t]zɄqޕjfA8񒁮 K%rl?}%_&b qP:jMc\Rzcß|N c_/Ӽp~w 0*zCPJ!i!"g/t쐕I*d+CS1ȄLУ:W:\zV!Ϻ6D~@ާg:wjq$Czs`cK2xev um&jP^ph{յt4kc[#SZ*{Q$X\;P?J8:ڡJ K_sHTIl}v=v Ȑ Ib4^f_zc֏ BK5`ˍMf0QFE27ܸE|>4Nq5qJ,$sEy`4_еŶtxԃk1?H @8B2l}tL1xCm=eL8dFLʭGK )T 0N*\ͻ03M#u@Mkezz(p+IZ_٪"@!- $FW|V?= u._]z+dMJk>}'nW`MZA@xO:~9Bs_MddA GmLNټW`nSIٜH:O6xێ4ljī+f=9{[V N(NNR?/;]Z<ҧIx.{,,*ci^ Źp HK(1t k -"ۛq%D2:u%V'Vh:Ι%ViiZuK/g41 E/'X;^OgI%6h%ӤZ(! 6'ɨT]Pm%ǑֳmC-D0n5z3Rտ},Yٟ6ոV\4ߑ F{;XubvO ܕWoFJ:1u{7)Mjo~s;]Τ{Ciq_fai5O$ȩEGȞsJp#38Z|VWGs#yi(r|!`6mLv|Rqwʠ ytbg:7-?,G?,òaQSw%[ d$Sˁ +f2UMI`odTAT*jpm9Jtqz&"G6XpQJ9#/b|jq=*? ҿt\0p#y .9f89HW~mT ӵ;1|'bj<()-9_ Go::FQ.Hbm[ߴf++yxq5QײКeft1vgU:{ uQ5ׯ^0 ƫAi@':^,3D2R4jk?l u=}m* 9 ĺae}i{!c?y˦UA(^{p7u:@^ 6P{\i]ObhF <+GD# o-Y8IjK0[d$H J݆N_oT+۰v@aM;D.zS2RFRԔr6\DY7F~;}h-TC % k8qs}8~N7HO]Ri'sV(*vb׻iM&so_C,<}04n??f+MS4vSփ8gwQ95xFlkÉJe5#_4#8m7JF7M 3/] I Cc,;ڠC^n@oCޚ{  ]g*ݯ9-ڹ0Ƥn (Ļ?LKx78([o.6>H[QQ~Bch2&B6| w=Mo6e1q=[8O S Sl~kH%bIQGEL5/*,pbaQzb5.2^3aS{NZI.elm' Ppl,T󶪧iQKL -4YOfOmŽ_W3~FѮId)[-H(H-߲8Fӑ: zpچY2r'K /ĺGtZ+Gчy_)Zk'?!9iC\ESX>ʻvx|(xMDžd9VGVpNںw^PX]?VP#[?Fs«ˌLqVZ&BC2c~XD ;Yͷ等h(c٧@麯B!e'4 x8ۤJ9^³`wuj \qŤ { v~XӬZ @Q"wl~]:n%U,*O{ڛn[cY| /卉z}z;H'Sx‡0z13wC&_fS1VIQ$/&@8SSkj^U!sPp8٪h^ iJ]R>]dĆ${,UB%4['l HДQvdA-2I+?샧;}cEkXY'=-UG ̾w' 6 2u|O"_@a{\R-3c[l[ i \?Bu-T= 3lI[  v[RPO@A૸An A|DăajND@*ҼnPcڙFL V [6TiX74-j,uAgDJ_YMTsQ 5C@"Jd*n!gpjBXVzբ]׿omK}c00J8.[ Y.&ȯnl/y-g6I# H]hQgjbw6D]v06ܰ*u‹9d]#FLrW6D\GڒXsY&HZ\^k5H>sqVY>/^W9b cF32cJz*RG; .-(7d=2snM1̽Ƣ{Yv317θÃM{^q͕({as'>!$3ďtZYa:36v-v&7jP8'ρ'KƩ$7ʜz 4UԾ[t=mTŽo]"a+`Z{ʈHQ87~мr@pաYR_=~ ƒ! 9OX|cesnUPz_Ql+2ҟ;B9N}6)/.$=ŝ,GH "!9+ɗf/ ImA#QfT8m"d^<+t;[/~<%Qh,08ggd F QƒQ8^8kǓcG<3Z!J4WIBz!du3u5@ׄ&IuRuӷpqdT7jID d}pYN5>2M̄7ts<6EکB\g ַnƱpL!-I~F}2~y`¡pd ~$._C*.>ԗ+g> ܷNQxk@R^qW~,sF?~ =5է%AYm~v1ݜC\U{p:j6Qiڪ '{D>uT=3=S ot(k`pQ$U;@ګ3 Ugi)GʦRtLh]2F,$yN;Wk2\(#xZ.ތmu|_5ǐw:W ,w׵OԬ$&OdFXb*k$puN `jN A(q5%{ [b!xԅp犜\26e*L1?BȢ7? (`X7ӧ;|7Ē*76n,4^Zn 3[ctLК,&Ϗ#eD}c`VgPOup[MBN]7*5)ϓa-ؒvXA"72qV*܂L LS]{A5DL,/c6{X#dFT60o_t}Q@m)jx˰X+ύءo_@8T{Q9Om($EC]<9C0E=/aR_%U\c5C̼T^>tez-u˅a .2M]FU,\lγьq(Y~॥S3)(Es0 Wi"J5/|tfpotFN[ Ws#n$ت%-+ILZ{ DC,qj*x-Q`P!?EAKre^}/7]I\y`VpV[\xY> ZǕ-WpDO E] (< շU/ϾCTG~l節;_q.DQY1TNoNmM󠺻Qѡ/V>6~rМ6ņQ#-$r:ȴǍ =XMOU <ܝ)MܺJ>o '=0& &_db٘4eHU'Uz$:nP?p%֖R!zdy 7Dk7t!ӲVղ_ NfU'#b@XtWm㹮JE S/y;lEx=AG8!xWStC.n/GZTՉQY8iYC}NEb $(9Iϋ.7f!S#F ]-7 &_P@jWa@b!vzjs&MX|]&N %R^TJ knZӪ\z$d;WkK"q-Hk4q~SI VjGfAUʍJ+'c_n^M㰱7T]3#S2 V!]RqD}ܪgwDRWi{mP B 15$n1yp+\I7 3bizۜ)@o!85rrf(~S)n ,=K o\F8&+,L3{+bAǢE[dW gN\|j[TQ4d{qO~DBrtl/oBIfn?SDdGA= ]\'=jd^sͬQmAh6?m&5B^Ul6-X<5x!v]hBzPB*BOvw/%DПƋhܫ!07FL'M0, v_F2g?Gm;deLhK=R $퓝j?eXV(,>3.Q+uDGњ 3QA~|~c`m-Be6H 6!C?1S,şd 6t(B1Tu8:I;5օ 1@o|]t /j291C~JTtcu/,GM MQev@aAC۸ER%|mD?烅^_፷Rۋ D%QDAz!+0`U|_ΤB(''PvffbNߨ0Vx n*PCǑ~t-IUVC Җ)@ O! =I-n4u'@[#ElMPHϚBݺlVVtuqif{fBO?ԟ0g$ٝ~V &# /P\ЂA&ݠgbNnl=h"  6R+S!1@D\Z\{ӿEsZF"ՍRhV~:ha#q"t|;^ /i gJI7`zJ '?J5<Hzv^iJ yoyT6\HyM9#CI5ncQ&ܧ8j6d!>2}^Bۆ+:!&큁5K_=C$F8֥:*7ѲNi[52QL%Ӓp=j174Dd 5\d/SZӍx -J xUpȆSܼb4r}1`ְJfS"^RLdb&":7|~!(n4G愸k_%͗!_6IX ie\ P+QH!;>qY9@7Ƨ%umu(Ƥuyw툹jǔp@#%m}|NwTs*rFl =ˋL;]ump)W'ٵ߀sAEV)Bp18Y천],ְ81C8[ZL`f."ԣ_@7d8C Á.K<",_LrWu 6Gԕԛl@q N۶4J&X vD?#vF1-v%Zv>gW<x.3M듬.Mu~x%t3qPJkV"UTRۣT`b}J*$s ë3 ᳎&@c.b #¹UuY.Up]^-shnf91I\KQK ~u:ɏcN2e k_/F zo"0"1dUOCQYqzsbGNL# PIz{̵:pKy;mM4ép6` `Ȓ33GțcHV("kJRo3Ҧjjjj780 Uȩ0e%v%L3OlO-yC\8?ZFHU\)d%h-2ڨ<'@)RXzs˜JǶXsҲv|yw @`@AfY_Ͷ#]](@qmQϿJUF'mn큁X\{_xZk8M oH:3"J %Y!OX^FFA7r޻He>5}juA]Byϵ kGl/E[),rQ2J1_[^,)Ͽu*̮|l "+ѡCnSIZ_Tl9d5e⯮X5v؛ݢM|o났-4W,-<Cy?KT^!Brn;uPn YR+ȂK(1g5r$tת -9I/Nl5.EiM6L+ 5]}A!!6r'>|%b-=NT a>2 3?Txe Q͏{hŤ\X͢O|d3F5Md ~ LՒW"cT@y0SڋgdaۢW*p|mF o믗ek{SbguoT7;ޯ{>= [CkZHjg^Rv Sϫ$WYeyI a4 ԓ-Jm{;Go6ĎP/. ֧aaHUޭ["AN$Vt5<n=IJJ+J=>'3LlLByqQ_ iV}5B8dQ*~mZ5hϳ%k+'pn40C Caxq*%k. -k^{ cODK_O]Q)mтDh'7+ef?'QƆm0%1(о%냞;.oտ%Q/Y{}7"~fNj :4X#4Mc,1Oh?V=v5,~w:Y)6iu[P> Ed(ʱT2q@I(tQNntXO0 ?Q㲍5Q7 oc@uмGymH#OY7S?"ۋٽ),w谖r_VoF޴^?tU<^>F.P!$D R9%R!_ǤZzžT*儐=fC^x }͝OD.ضY.h;F&vZ7.Q2L)x))_v1Ao:T lC4};v^y]s5 Ս hN|!UaLkxL8=$JK"i?.PiC[ܭ3L.Qi>Wވ]7 X[ıb9(V`:9u< +&Y(Ef #Gt_/s!*lz3s*nsYƬ2*l86fC4TPRD'~#Rk#*q%J"9w[>в4@zB}XRpu/-*cά*1!#Qj9#)YLZ<2Pa>sxeOsO]UCy#zrIB=ՔoFsLXR\5Mi{)+˯p~WSȡc +\ lc%‰$Y3Q5dXkdcd۰ ZZA˥B^k%&7oիBLB>TsjԪXњ.;$@ȧ9BN@Λ` Dn; []B)A8(HO~ 1)~6[V|?>1 aCyMD*v ŨKo"k~"3d嫉 cs:)C^@|1Rj]3gO㶶i"cA Je8ïϫQ?]^urN.\ʳJ b )l ".Kx6,x4m2{Qeϩ2LN &FaҒ^8L@D΋3<ڇxt3gRO jeд qbC7jOgT[6֋sGa* ;>Xr1H>B DM8\ iCMtZíY+1z#Q܇mΩel 6hCIdfZMcFjӲ;Zv99乬<9 W ixC蚜/l^CJ=O#A.luC7ңG Ԙ XO Q?L/t\i;mBH`\ &@&RGWHFIC@ckդB5Q[Ǽ;K[)o “+WF,dvШNs5Ky\n9>m64##+܈\W d <7D7{r2KTF}-άh֊Iv=qѷ=s49*{C*"rq*ԏET$`tߦsrKV(uDg6u# EG{eXMmU E`E`ڏe8Ӈj8 gXq/|](X+Npm /#9siK/# _-g|~ m$FP\3~:~XG{Nx_4H(`VY &'uW5 ![ӂaC҆f ;GZ).t/,U|в^7Ů$/)mm$=Qύg%1OuTǬ׫wz*b*C y ԲZG2%d)9r(8 "4M8(+qB~@8N7[뽸Č.ŖC !=L|m[;Ts/n`hK ^\8鱰C⍧ů'TVEG5q; 'mV3t/ᮝCM;:&OkχwfΫA]lyd)X Ι-yOg]1vɵtEY<{x)x| u?=4Ƿ3tud'')+ϥ[n%K y Y=.~rtE'Q_;Iﳝ)yG$1fyDQ9{5g^wîN")N}&* ILe'M'o:\%Kde᭘zvٙPx[^%;$\.ʁ:6n%RFgorsT3xl#yYmYhcg د)u.ba k+*ro!W)Oz~m(=*AW>i8F{D7!$jS?"| u9+ğ CAp \"UeF65#,أ.*l}IkD Fg>: F-JkcCNxEA.{~{U=ڣ651|T K2H#c}s=x&WBZ\Ӈ^V&SUƷ_V7IO<6,["hh[L,Lp_买C Ӵ1k9&1&uAU@N7=P‡4q`.v+LAE_h8U~f! G]+LYPufiOHۈ6KX /~3)h~bUfvN#~C0l+.pn? $U?7 %P%ķ BqaX;8B!ƄCDO'Ƹ "'pΝUxZ^4,|iHV*v^!C²[o4DW/e,7JqfCY[Nd&Aڶ?d[$ϝН~";z:&[\ĽeP%~AAUv5!eji-f4|Y?XɽdߚbG\&g4r2ǽV2aqE@BgEHD>(ƀ L")|H\fa{ /wOڍNI7[G[_oy+&V9 IaYfsR,+ܮm5/KC|ޱo'\.zW8^̈́9W>j\ۇ9!ٓ0v--?!p2}OJR.[,^][{iOh a߽+6/dKs =jxqg2}@bƥC"rdr3'v"3n"J#","#RE ;t{מb )xj8M@N<ص$k0oP DZ= XလmPd!߮l(ݓE0. s>7,uPŷpc`nLuj 74ZKq20 2ޓO.A$Xy@ru3< T;H_6MbC\FP2@|0(b K<=a0}co!_a*Q}pOTMNSfZzZ}D!,8 .p6XViHZ7Te.Yj_hYvx@.Vu}e)̓'qZ@ѾŁ[I,ٕ6-/]d]x:tE ƫ$pw7^X>6-PA@DI}_~ 8DAt-H._Ǐ v7\f i)kA LrxTt@+X͆567tbwH7~D(#g yM_h:fʤP!eݮ;\1j֯O&y9YYWZe6kq" M5N|z~['z<7?H&x,t38j֒B`ԂI*n?cۑ 2>{c'dzɮʎB/TtͳM sAAwAg%ѥÊJl>}qʡgpO^χ WG'<<)%&Pk뜍icZq:A& 9/dz-m|L`%hRq#&ZFClS@ݳ,Jom 0VŖbb,PC)E)oxͼa<Q{$U]kR=C 16feUn nJcVhZCHbuF,b[$vΧYG <؁B?89Tpr|BD~bkMA|&Pڮ}>-;8Ðue͔ | _[@NG:DWu, Q$YPA >t\QG͊FC> ^/PҰG/ 3}X~!\ۓuX]?Ƣ#.xz V-2x`9ogf\tz0XebmU‰f kѨ2l.cŮ {vٮ:`5gB}5^UBGRD y# e jR-ٽ'nU>o^Vc)S2Jc$l$1D:su;&44@.{-Ņ2?5ZfX]_jWb1tL ]T 3tw:|Q~DX) 6Yn@8 3\QՔ%̾TC$79ש^!VdA^UVb򲀶qD[k-;7MX YVfPu5BJ}xE.YJ%[HySkD3dҬoh+ |ґÝ|.w7ߵFo)S<ժgT8ɮ8 "<0t&7n-Q`?_.CUleyRyP_ gtC@z)\liu`T=uD?͵w޽lB]<Ҁy9P4}+hsO=zU2q.AQӏc#s jCuFW:cn$㞈wu?`"J`g3R k8f dBΙ&]^ O!i9_":4pEN '+A^Rwl'bd#͙eY"Dڬ^҂_A-_:iY *Cj-|⊲e\Zٌ}Ru;c`c >AIK;{2N] =͡2/crtbr\_U[*o['* ^h^Z좜!iC{=P_%4MCb604j>xhjC7?6Jh!_Bnuzϖ=Oj'@>C&$E`\GYmK PV#\6$`xC'ʐgN5X 9v7,DH}3ߺWSXfCn@*-`sSA)q;!e1h_*2-ү 9{aIDp72i&Õ|e*Njۊ(^,D}E`גL~ȳXw-*Z}M;]vg@M-OM] 'o,+;:ozUX08ߣD~iRV.&扙̾.vZ)SU )};zY؈UxTV̼V(ꚕ%4K}6h6w !#}wS=--Er0"Vk%ՠdBGu;%PPOF=&g__g"4JD=U5Es=Y'J $yېd qЪXG9?g1 .to`+?SՄY I4}qٌDjC I8.f.bº ŏ,氠ҳP~I3MoL3R寮fz)'Ӌe\ܴs:4c؀xܮwb"+>&+[Čb mؒ4ˣ25>'Uܐ|7iȎm+1FP-}u2@l{6G? c+eTY-|h mGv|g!>e/۱0B@B$27A讜.KGRaS(~0 J|lÜSaPܕ1PBDjZ>":ohܳ0.+=+x_x0JE[t.]zo͡h)_(KTMa+C59ID,Cq #hz%dTy/cF0Gα0c%4?vZ3AqiIX5+uwFL<~Fglg,]&2 blyDwBD6'a5 S^|s F*@;NN&z,}.G#[*SWPz|ˈdp&$=jywu+IMRGbDr* XqkY2bʛF{fmelq2DLa1NôrQOv-\^~;5wMŻRj끰jDv.#ÄJM۠P$#dϻ)A/^rJ( -}zfqF[XZl?}U:D++WRc<ށ&ro&`\{7vpdOGdsg_CwȘbO{VYFՀ8ߜj, Kkp3}!)YK.[,q忼-@& Y̎,`23G$BKu1Ra+.: UY |cf0fc$1¸Xi [{qkbb5uafXe9+mwGBN~ǡo-!ҕ-Й#p07'B!)bDmGhUԽy&f 4P,3mIqa/_LY-2]B%[m?<8;ċ[8O~ I#C*oa'zFO3dxk0փCH/?Bʷ]`*l2\vaDҭ E k;~u"#CS0vCHuwjL65-1*R "gB pӅm~UFdJL`1TK9NOu)v DD8~*F'j{k. ؊Jv?"u9#*tjدAy * ncDr|va;  w0Y.H[`..q{>vjsShNv|+&FdO{d{2<6;݋T$O78j[L}Lai9Z86uƣ>MS[Փ4B-aNJ3_s%AMdx g.o Y 4ϭZ$"q1ҍ o#6 b8.DmXvrEt4 `+~%t@-d+p=<-_%E*i3o B/tjHbӲQx)4WPU5QC$j'3O2!\<<şH ʜ(5O9 :篭 X$r3P%:gf2%\g5^'Tˣ0ε&?{0S5'6J(?k=%i0!:IYUlI1ٴ〲0 y=:/>Z!n6sEWm S/1Ԭ(-z|R{B~;8N#S4D[Dp.d+vƃs]% OkMV8Uw k{s!?J[tEBD ^]٬XLC'ityGyo){iaἷ dO@ۈmAGՖ\I<)Vۣ۬~a7ځeʳt2/Px)ꂝɿ$ @cvժ pU·Nbִhϕ$| J#_`"u7ѫx:h}dHCf."ba(ᝯn_סEcgq#< |3zCXRvVw[)TKw}1ڹ G4+{f˲|:n_Dӏr`xo1 :\ R`4QǰJplXh=QUb׿\_6\uXΧ;t׊&.--@8_iy$@׉s ĐգN>.D-Qf{.ήnot'ew=eY)?fbVv4m"M=;Pl\rBas;`fWzp qST8eę,~u'e  on,]Y7@>hf#+KIɱ5ibZ$9uRFٸMyiŨdPRqψbY$2N˞e.HeKKeD#P"W$!u* JVHiM"hrANǜK.]Y/eyCXuOt^H'E_6f)J-i*b GL`wh:(#D!/A$Viɥ IH{VZGrd?pB-`}ՐfNruFĄ_ׄ`% ĩ*H2 -wU]Nx؃:1k 9fe񇍑z]pkHeNoUղ *qSAݒ >U+>m56El5D W$(:ud lE2#= ҝ3 вY渍x cA"Ω2A`4ƶ8yK56=<>%0ZSJšbHhj2f쯖Κ+p}>zxX)!bQ.j ~vk13TVh?eд  }٭M>XO(+W l4t >Ʌ[Ű$+ihH*Lն? 7=RpF ry)ljyNj ?=Lp%u[*+xSS1+N"f}m(*FŦIeח+4Xo&v4rREЩ Hh&_;jD_֘&i?~p[H-9KYq*w|DLU 3q[mu% 2ZD4STnL Pӽ~IH<>wͤAHwI<.ǩ`P_ J' L^ء6yj^Eb9کoRA~̀<pHp[A@)#s7hzoaA_92^l?l-vPT9zRj[וYmBZĢ.q4M:[0='PGg>bIFylW,.}&vOd˨cIںn&9mhZ7Ym= `z)%Uξ։Τ%h?aTj?,Hx#pEVFvKYZk Aq+ze6لrA+թ 9~[Xp#?Oj[+SRj}U|* vЖE?^4]f7w=Gmqak@AȺ /%RfZ#f)E]ⴂ`qAtYUwTj/ru)`ȏT.PjEk_F] I/ݕ"Mȼ6r3j4Cgю>7yYYCf`ZH򪋷_NVn 4LdS$]F,}ZhW ࣅ/MWl9hDэ01T=Czdj(*R͵D<PlvaʁLF#C{ܗ8:\bsPDè'6wa4m7,t}OCNg4IQ F*R\HދJu?X#`Kc /! vP"rw4U:BXL6'PTjdzQ!% 3 ;aWqcO;.O4ui:[ 9򃖆ۆG Ӵo ~rvyP 6II}9:>v@vK* LW F^R"*cغ +jƎK>TV]ށyfHw AEr\6૨eTriӌ=9/vm `V(𰉽ѿ+ubF?^"g-]4=3evX+aڮlW02" ;A2ʆ(QpזH)9}=c1SQT0;K"/Wb}B]dEQ# orCpAqUtjC=S.iζu㬛xu?K"UB9 _ΈnjoJz(^+ΘQJEۯV\gtŵi #a0W.~}iN~)m5EHŻfG^u*$jQ2ߑ?L]-`$nII0? z67$Wpr< ycWV%y 2p<^0f x4~8>*# 3˭ĩE@1 BIZ[mcD *Pr}hu+H]߇ "U }OxZsP%]K吭W@ co'+JXPf${ }>`1'ԶYz;)yON:ZzjZ/+[42DV7iݣboYJسDI6g`y\a7yFAw)a&?K|32;cX:fT@Y+&T.)22h>8@[_{/!O®~-GkwE%sX]H)]^\ "c' _Ú,g~עs p_ӆE)[ f4p|a-𛈙m;~/X)|+ Ȳ,MāuU"Èz Q84̿-Ȯ1:[Gh'(ߏT nJ,tҒf!}06&U5so!UL*:|6%P{A>Pkȗb|a߀> ZjږϢck4VV>\*' yLNO$kFnH*d.IÃFw,0ylZ@bv7|NfHmUFg\CHQP?TۿDGiB}G"k!YG==dYt"aݷR#^yR&멋w"BL yV?nAf(U錃Lju?agټZ̍ ک~0eM/.=EA[1BWbcuAI'P`]#@EY+)H IM @ Zy%O#=jG7 AP`Cqwc}*x̪uY' 5jƶQ]}Y"!5{SXFd/-[nlR^x.7m?Q-JEE?x%u ȩ5PIEj1p7U!%wHj^#߱eC!Ǣ!EGJ K֣V~y7,XϛÞX1mOugFTokp'*?bzJk:D9cގqs`!Ò5SVb*pW> 6)}6c3".@?:ߴ۷ZB\Y;{Ѐ62'ĭlXp |*|q>& j qUd!iDV'qD@cCNUG16&JN k!2PڛRSN +[G^W~ts&x=kttzaCQ9:fV%]AEb24à s0geck5kH/hJն`L4e!Ks :c1*9B!Jyc}TLvz|Om$IFT•\bQX%gCT&1';?tk \ ˁ'7^щtrᷴ[IK S*Pڭc#M>{Ԅ'A1l{R; {]^΄dWH ,;\n0/nn,FFE4-5VoWԳM}IH3!{/9)"TQ= WN`aЃes2cܧ-UG|s? (Bˏ yV2LZzԔzV zLgLŁ곮ջy?\.<ѻ29c!i)++)VI9%(Yg3+_<'THy|߫6xR~Sܤ+ҩ3 iyZ6[1NO@);ao2ǹPOyy3Ey=NB(x;uAy1B2=\J(o7s&YJU-9G; h@74q-0MZ\Ԩ um!᭍ ȳKg{DpU2S"9Grk'xVư!IH{8VW&78*w@~g;rYq9;ϛ|'&`+sЃ Ҥ@mC \,p8 j]`\bBMgl7QȖ2_Sh/)V"mL`O!2ǖu|h0yTشYb%Le1)M0^>?khSz6A5Z7ڻcpM*Kv9A.6b[f{a-N;7 KrhgƘAnw F{.咝kFzb5ZYϱmt3Ͽٷ汁lLHn ogE=0*T>"ik jl ;͆z70-ġ8Lҩj|iLI<Dx(Ⴣt `zMՆ4/xъ2LRe.bKZfD@cD%az6^ '.wG~c. >߷Tݑ zEQb,G Hr57af$DXh`=hB}W'+S2ULP6؁w(a/`H xa̘b/[fMj$zbx3Ef%әE$Zeq_oFg0 Iɷ5Dڎs2 1KmlEZD:HB,8(IpU)}$P XcTy)$_,'=H0@ıaȚHx0W|AѮci3Jhi[` B-Tl.*/w@z".rlU8|4S 3a.$=`Ѭ;t퉉[^@\33jg!N.bU,+ ~Teߍ jk8՛{5pMOAz O.Ӑ#-VjRԗAue5fxT==sy~|P!P.vbg`RsplxPn7ؽ`)~$J34Fi~:jhp6QKkbǶ^L"ͳЗ0>a>ꪤ]8܆"fh hVfAY.J$7ű۪'#%MPa8?8";*7/-ͭЦ[1"K@aT `Ǐ((PwBQ<)h${!w_,ϹaXn5g6$Mh̒jY[kI4)>g(z 2ݩUBpXttC /n8#b~WNU'ʤ2Dk9?z7S.iL:⃫qCY*S"8~ W<l[mg:0VЗpiW_qD6Rܢ+Cv:mhG6RK_}?Yy b)NYyIZu/i˚+AU{ɐb_qsFH}!Cm&D`3Kl %uDL8'kSNFm) Ȯ!Ÿ;G|>@D0&aGnYSByԗ&&?8.j>&HE>k\:?R(YN'&$'IḜdPuhk _h|\؄bFvt:P;OD!rB7/SuxTd}32b· c$oMP e11@Wc^_DNX."mZT %LA+MbP|4"ac /Nc3"j~ߔw촻$g {٩8䨐A [IwzT]D8Ă+Λ*RJ!y 1F*4E ;kX[χOao0ibmJKÂfĽH8Md- 5guefΣ=U8Z~] jb sm7qaԤKRH9Ɣ}> F N>zN)fa(D}! ͟Z/+=<7?4w  ̊rfiUҥ3pVJ&'srg=P:qb"bD ieE)Ýsk 9tŹ"Pq׽fw|"'Ԃo\!JyڏRX, *eݵR6N k]ʙ8uF?Jϼ>' @4N>Z+-tYðDm!zΙҊ5bQ^UaLd&ț-J*jFn&5^l%t3{4m$RJ]~ $bkPyS 6Ӵ|j{8McVILF|?^ðn]L'w4e"d}SB=rhnˢNy?X.>q?Cו?/s?/l֖tJonŻHo܃"W_ =3|,5IovOXl7b&ޫ Rd\ENR!!|[oyL@Yl󫡝{z<Ό6X> #ϊw~C`x-gDT?kN,#9\TcKF<>WeYs(K䡷]Do%2 vFpQżѸQ$oPwr#+)J}BkkzA:zT<,32Sà)Zn_YdW$v]&FV?:~̗`>n^"ROΛ@,}NN K}{; "u=B&$/뇽ܘKL+MZ1kew1#;9\;>?`N`5oZh,~ OUeِuJ)MӛGY?"cY;vy7H+eh.u465rX԰`ӣ@yДg:X}B{g@uQM&J\:vEH>:. T*C\WQ ~ĹmFc̲M(#ф_+Evߝ%֚ҩ^o6--wٻ Uϑsh1*e)h r陔 nmke17MOC=&-cUu5I`M]FAPGu#\)0r-7;)ih/$@qײ'^nx:$gMfD]ИLXMGs.$!Y:6dxaeeF+m|t+!dt ޞƒg/wYPM͵^e/Z'4b,P"]e;J1ɐ+z|Z"G/_kd-ҕ*W+`>0F,(fL:&K$ͺ9 ucyG~DoXime"v ~PsZ:!7 z%Vg>~g8u&nAEe3~s&3OFoq%]Q{cnlHi%Ym:,w<v0ZC@TR% #7I>C2 t1s^RCpRp 4̍9;9(tH~c&ۼ̦шktZz`~0vT軸wA ߾&R&=@q*ڷAFБ+/eMa*elK䐙4[:8enjPM2rU/YX+m[on ^-(츩rļ!rLh|%QGgSnPb钗#]_?b[." ! +y'{kFjK)Qf:x`9! R]IّaYr -6nn3-,mG;j.{k>|\ͷ ,qD r4B`^j|L. fGjsO=\b_cv̈́ǀ>@x8A儼&=[iD-s,@\ 0^c΋\}hjeRV(Xcyv=-st9P_khf8\x?W|U.`m[Ap,G(A f}6OףCؚ'g@"MgvA;/ ̤A1𽴔%ϣD؛XRWKȐm 4A>`FM]1vmbquK׮.jb"3GL:M<ȥEQx:SSNhd]Gu6\viby 'ѩ ,!Wt|ʡ_֭Wդ[@ 9^dmxa5Z.DOҫ^܊A GlbB$۫*˖2]qsK|<ﰟHы[ԑR͌Q5{ [YNQo`S}]Cuq!?WllTuZ2Io<H4PXF [lIg#eZ-Sg1Hq=z.dwӺw"\!F%U)=W0(fdmK)`]uN?#vm׹ 䠵B`dݎqp!1 3P :K.ȸͣo/ZvqR\ \n K!W =xl cO1I#G4`8/1C~/0*~PmL/27$K$^{o x UQ'k'Gn 5Vf+5[\g3Ed,c91,1Z@uŝq͚ 5 ـn=8[i{"g#ҺB-&7hR+F&`)'mF_uT$ŁMn7]uLYڻa;Ҩ"o^\(T⍀ʭtcE?4m(Xh¨qpu!ȧ#\d>#""b 43 ^~Hw7fWF;SÈu2Mb;c3^8YDx]]PStG*Hj`dK~>;|&EXA'v4 GMxE.~R8v6#qnwa:h^RGڳ3.>~_2;=f)Q+ Mp'vPw!b]ϯ& n[hz#lr~KrnYIl5}&J j^N0*ynjt035_4;:IʌӕՠE64PBqsrӉ9O$#`)uB]-5EDS#esIDA^w{,pL,+9/{'H=qƵhfDyt (3qQҔ-]M-f%0)j=H+ZxKwJp%n); y>6T3TCn8H88M .Z?xyj{zf6 #ָ{o ,{)a< :笏)KAb%.T;2KfbQ*[$o; ܺ4DUO?=*e^W ĚxO|bsT]iKN #E8edXGQar̙xR7:6]h5+L[9wZ"G Qhh  mWF\ؼ miƙ279Ci]O\ s3<4ĽmߠMyY$fG褐u`0]X69E6杖}屿>vͬܖYš%Tdzߔ#)(*e}j4|yy~twK3*)2wqA4mP{(9Ts{gs.tij/+ӝVCN,<0^ub ,g9A+TЇ} do%hěaX}} Q.S^ׂz'ӿv/,CӄpXnW+V@ˡiÚ}2ujQd jLC1zs C׼tLQ“+.+O#|快@ϙsT]^aI~qJfs|&DHړI 5K#fu*].Jל_o""NUδ`>=q8Q޷͔_* حZ]<tSw)IuTRl#{DvtǦAghb8w6zCs:l/@S%sG!c꯾R;/+#R /O' io\O 'QGwC7E4[;!j1sg KuRЭ>6'ڂr zm7EĴk2n);H!m52fƓ?co{[8 n{iLҚ0Ӡ ;l( Ro7@{ *| r-[>Od l}$e4u v"s~Z&h>V+- 4[Gi_3!0eP7/:7] S`oZq*kfFt5Qn89cL1ĩ׵ h ( Pq)[BP_9GUDdP׷%ZXG%o eToU8} )k554Lr/h _h*oc$6ڕ4}sUb蜗S ̙ie0e(KEښr#[}d@/:7Œ!ur^DA>/Cx&f{-IaHL+p[>ݪu JS>c! vhťo}fAg–\Zlu$wor6Ʀ7h)ast}뒩$4:+OE 3c-fK|V՛s/$s CjD9m$DthZ34V.QJV&e`j=ݻkFuzAl5MYUU<q úH3Ҵxpf b!*4$ r,`KmOW5WYU4zٵ1g@9?ty/sѦkQ@ZcM7aeZZ2kC)n9dPp"ɛ{8n3c'Ϡ`g}tMmGum1@"),1ll1=}>1@JM+t!o뽈^ij]{KZuV;`W>0m *Y-l> (FNI a ̕f[)nE#xj.74{`mU2YV^k:F ;ӿN9sk A)äl`-7Ӹ> t?gt)5S*"f3Ţ9>(Rc< 3yd>ml,43 !o0TMKa”،\.иedlqO0XYf̔fɳ66Bma ]陝ʈp88{:XK9>7?YAU4I?Y edWkf32b}ݐ+4:p?(\Sp爍rn K6}rT <2n~`;=7iU; 2?OҢAb&m U$ Xwq6+s+$I-y3* y,|:X(G(*sQ?A0 RSSX05TV]u!C%¬ՏU:\a5C!l$&; pҎa#ǧ* ;G/v@v-KPQuȒbW!o+#t/O$U@+K&6ͽO i~&!.uwC[ T\yMhy%͡q2,eSïB>R7 $jv`)QpV:,Zo+7sn_mvex!줤LW{F0D! Jq-7D @vubR$+C`9^dMH,vN oJkoþE\g{rz#zWC(tF`c6H0eo'Iߩ|8Th ce`(0'|5M fhcJrgt"}R1 !O~!W޲Wc#2q[q߷=^Ƞn*L$bZ},=ti0Wz]"[袼xpuxEO $@xG'`5ɋ7vϚyx)ŠKW) DދR?n909QCz]%#܋WQ*]%y9Ok!s^Iup09yg8J? evgc: ʰ*l2,GE'&l,иSl Y*ffcrIrgxJHlW@jf[?OM![ X'$t*1skxE5!$i!E Wu?wcyбֽT5L74딆Ɓsm)k;p=(tܓ>o?mos{=lS@)iv>JY˩$G"l˃R",) 2{<F9|/R p8e;^F]N_(ɵ0_h>|pN}kT@xQ(ua`|5|qJ<bb55!7/ & 95wwBo|twصz0[y={6@YoC*@]Yo`Ϟlu%P$ ܌MWAn03H躐;,U`(N{!p2}ItH+'G4ݖ.ҝenꉇ\KxwSIB#[&rCb҄p%yjiCzT]MRz9B(7ɉy0Cᅴbt [IS߱zt*) DD|g# 1% 0'ycokY)Xg$:FBD{k}2ː.J?ClUZ )doǚ^,[WA)4 u}MC_yrFj ݺ GwWԲJ0ɒ?xͦ⎋`1xڷw럽5iB+߬NE]7S{_p5*dzAmQ_9I6ʯFBS,N;m;J*VA|QRGx/WU5)3^ldglTy2s o 2!mOJ/(u<)T)r)8@o\SR |RSqZmCRwrͷ-Q/,t}M2u\+y#cU;M_{, W7u.A}n_0iKu5dk5yM*B]ch˕x4=_1/V3Rh -Z]2d vRW(v]"Q{kiZ!_)0<.2uL߄dDcf.<9m VcAa^$cHʢ #,24b@튚=r z&,9]I 3m EMPMGX&6Ӛ=EJs$WÁ` 3;Өm\{;3X/y9ՊoXۻ{Fe zLqlf\zwfVdqwh̐f%|AƏ(:2Z XG-Jd8pnRt:W mJ6:F0/$uCh9^vqm-OIY)"=φJu=EL9)5Q-͔6-2Rkgg2{pMTZķLuF>*}V%_8$ro2ej}a~1ѷ剗Sɹ_TCZLmʟ_"\XqwII66ދi\*[5a[Gv ) 3R@J 2EĆ-v5uJ3' i3w{jM ɗxΌdn ȣ+牒a7a+eRգ^:_ny1YeZ++G7*|%C#>:*7\v~o`-Wr)6kg 8؆a3Ё'0c^rߙq!U;@ˣqu,Ueplb ꐰjqCK|mkAK'dx\:}gVdpzGocu!%DrH{eʣ8.t=h6?OgyJl` 9є8w䋕O #%VaQ9ݹ.W i:DW߂U|J sGXdlL3*~+'6)NǓK-@)Um Uw)W1"u.*oL"fm6V2AZWRj2gS˜[~T! 87(OD i'܅ڐ "i.K.7;-*F5l(Ёғ W7ΙeXc4;J!\ YN>JH.4Tb85oR)qHd[$s/ӨLq;ҝV4;cϙV 4PlDZgpn.^ϯӛ絴uJG{`\u5Ya :cu'0j>AČLUQo%92\Rwx_ۨlK_Z?`xgﺍCnO^#-M:JPcE'h6\B$$e%hbvեndv'5]**mZUq 4z;u P-G/h1z@M';IR稊 QCq= @.~_@c"5Es&-Slf2{LFŮkMɨ@f] 49< %u˳FS T6H{OhfJf0$pLPƋbmO v}dI%xx羇rqgR>CRiVrS_uS7׵Hv*^G7wڎK!YRulIG^׾ݎ)o~:K1| 53#Nvmko~~w쁽הZ 6[Txyn,a1fb"7Inou ^U@,k4 yW1g.^ Qȏ\*25,\|V*fi7(mVOS?rM,XBu 5 /kJ6 <-lU[Ƌ$ӗٍ3sXp $V{md{KH~# udtB5IpEx7_cH0)2Cҽ )m=0X3IKA&&Mie:'B:>`sKLH:""@J! j M^}>g)jgm) +6o:VR0}CQ^L13[ϱwrcG7RiUէ]y&.="^\qIJE:ckN߽ Z} &3Z^^||e1Q ]9],kEn汁`_OwUH/nf_Ґ-*IX.Z1$;OQ&Khh,?α/<7dvʹڗZB~/$B~5u,fBdURXJOX7 01旅42;lH|*s& .~f"`CP@k?.a}OciHZ'x$bM+əEo~ +gDΚdNE$VH5vHw\`К~-Iy{yBvT€D{Yi ƒaH<:{vGQ{ Kl(Hkv0TN?jrF1 8QAv`g-ƟdFK`S| Gg{P M9S_x|(ZI?縃dj 9UQVVXYd&j; 9K8q*UohYrcmKYpUmŁ<-BǞGgdף>|8ٸ^Wc+ %WZ:߻Ot-b8lLBTcWB!=sneALd$.O>I&V0=Q7lVep :WTs08{g>h=]&'ɟꬺ~8Yoܿ 7#yS]ZbL} x0t` %_ dBBCϧ?,2zaPz6uD7L1 +,+.qe15d2N9ܳ\U@IHpi-g͵"/({c􂑳ͫ0֖(L00My!_~G?xg.S0i2X#r>if $荒L6~g"meƒzjoqv!?c8tbwZ|؈)²ѓ|$&X_\.dNtA}pv ۊʒ)c/W[g'.%j}l~Ti-ԝ j"c'5Qi> `-6B|`ߣ>(K?Բ0珎q@'\<hYI%S]Ҷ"_|8e@!e3p(&N;=> g+>mz'5Ujk!xa Dڃ2"Zc~-'Uӭ"]j ෆpp&/[|t\nKֺAZݠct<#f }WE6fW`Ӊo9Lht0k݇{1pm?Řۣ"[‹!2^)lW^M L_O ГHՙ .tv_ џ2ݱ%pp-@l{#W 3-q3=*&{o +vk&^&ɫ{|Ǡ 2a6$zO1dn izg+ݖ+洄񂴿$a:]&BeV@&G9ΜҰP2pn?/ Ah C1wq,ٌ=j88\M2:!O.|m05cOjo\k𑍙d@ "kLF ֍{Aa #01}ɎY)B ʒ`X<6I^@+O|8E,d_.5zƟŲI5M(RRz@y|_i&]0fuɽ)j(`BMuZ㘏ROI@7]F£'DF|t;~ &sͱsfL^ .k4/HThWR)UlN3w.\>Bj6[?n# yj׻ɩ{pY 2T:(=.;m!a;_dS`C$>&Q#SJvB83Vr'01*MVwZiR?|-=r7ǟ:.z1Ry\ nƢÙ6t`5KWID? )fĚ~N=e\Lܲ *S6Qg0.$HjE<{AIg&DC >9~zqs<|N|UQ!ԥ lFA2T WnMz0B rRXK ^ xU` Skk8DdBtMbBxqr5dOci&m< LqlDDn)et=e ?#NE"4:i g8gnʆĴ0иWŕֶ|lKOAL+_En窫Fts;$}VsϢ1vN$Sr<]P$TɯXrC`fk0.A>^ꫠCo}:I-qwӧ~tϹs c, j\E]V,x!gPa66pA ,cX0 wCˉGQ0~cAq}m;eUdąFt~jOr'C b#"nph)̊I,<o=je M%S ]- q/2=d#35Au,AD_>UN4r8w 6{ XQRˊ jyURұ5䢽,r5˙+DsC ǠdIh$J|Y(RF FEKμυX@K6oEaPCKb CMJ:Y-ZEa.ѫT@7[k'|iUsiVA KËQfJ#~<]/?8pV5<}8&`K5m˦'OQ 33e֔ŠH|˔M +FzCнkMQc!-AWg8XuLC9=&w˃uVT ?zֳ'9)O6ӫ/ZsĒ[;P}c|%q`e.{#]S:7e zTQK_e=s[C_g 䪧`| m9hٓ.ˍn _n \  oo>Îq'HM >k\=,#8?S. Z}!E8fvprB:-e1iG4?_ Z w+N6K%}LHe+/&WEUc pG ȥv,ť/P&`) N3&:Wti3dD fJ[ b9W0^BCm+ Ž~ ⑟4>QrkxYb&6*('Ere$߭M:U*T˭d0F) {#UC&T;5U]忂#q-Dわa# "w9™e@HxJtq?/^OWu Rgʠcr/-n74[)vu@Ul /p)ja[&]z\zv;W,@ݾ][-="Zʬo^bXU1P07D6(kܥs\*q` Na[%uutN f25+@ +'@Qͅ4Z`+wyS"鋭*@u>YF)>莑$)c8X6}b$]u;:YLPT%Tɽ5QO s_Z-[!- HSc|as9>͂P7Qk+fRMwjy o,Ti%ny%qm \fOn}%8y˷[ gQ{h-TE_&.Px1 {|VDBTLs&$lJ]xĜAƅiXMe%yR;;G[CPQ2ZRa C Z{?b;k $-`dC( hk=LIM ! 6&EAg-g #DwWJ4`fEqqgĢ;y:Cc?Lt 87.MGgp}L@ns0|~gRJ.ws/> - "RD@%z+a }ܜUjkـ{Ap&c_`dNE^+ɘ'e9!c{Xu ]5BZ"2C[PJuְ{ȎxX]P9B@?]$a z@T}D+^,ԍHD\L.Jr|CgVj'xЎBu5uDR I7 f6gӜ&C"'*MqQoSȱt~W|4?']K~t0mN^+X{e-37"kSg^IWTl,9C6{GiQQ܊\±qMw5 :J 6noQT=%sT#ߪavo:Fqq?bp琳cA5V rDP0}?PHjrihl߳F Qu熧u$PX}n56P}@ύ=2pas>_QJ0wN#tXhqJ K!P}hqP+ܙ*!l: ^nk%'N玴6wP"=Tt6MϖVKu?es3V, h0bs*EeM Y[B23zy9G.4Ue d\U`Q]Ƀ[wY gP3`8CRd`;9K ȋDE-o`ҵdS=gTZLaJF `tY(Ew(cM}V$JȘ[*5h|h2*M윚$RŁp.yɋqx;7 Gg^歹P._ϊ#q>rߌ$M"ժ=uOh‹h utZmgoK9櫜.[r:Mw[us0V&,x$Մ ;0/m {VS?.F2 v:RC xg @KusG󉕴Bt;tF"-[r%Vwja"rEx-ouIXT[*US@+_]]8-yQ`_vEH{t׍NhT+vxXYA>9utz.v1V7x&E ؅Y]OD`2b{'%Zib<[Wj!wmߝF_r5W._*j`QU-tQok* Yc?phqn|lWaLMBy dI˲[PY4[R5 ;Mnq/(kQ9-3Dl>,w΂ÉMŤҹ eokLӰe>k=`<ZMkh9JK;Tr^sg^4BnL-N3=.IYjV2g]ڀ D o&O̐(3#_"*uWIxC#@pE,&uG K܂s0-D " AwTu͊WFr37uRHJ^ 3`Ё:%y8#ӕ̑S3c<|r0!}^*0†,ʄ>Ng!)*i<:3>=Џ9qÙLG#s&B~F %^*k Gm@Ἒd\ḽgr"XQl AәQT^8f*ޖm3 [gT$Fy)(4ژ{Jjg +[0H pC<T<I@IOo8m}L9Va=LkH Gu"r'y貍 ;JtBĆ\F>G V&,Kiy8BTn>X|$s4 q L^ n_+}Ŭ۞rk P w _~` +>B)Xvh9j\U tH-s.22T1m4pJ 7>meyF,R2zim0+-@C^@ҔwDk<]d[c7z7 0 ]U! CD ?X|^U ,[D_Ҫ9X{+UWquwp.F&ڜkzĜED31u֌5_pxd$ YEtKBsWIE?AMn7>ZyA)/N)3eD<9qh'_m }7S" Q NyYKȡ1U#?J͸S>vN܅pLG9liNo-Mcya]u; 'uPgЉ\l\vE\pB(5Bpԋ5c$+/"ex76X`)(!0/u)Dŝy%=T٧'Ñq"X;f3tP孳 }lfJhV4ѹK̿ne!SrO1D^;@!@=v邗ѕ/4緀:[ #}b[MŽ.[jGRdUͪ+cQ?r5}#}MǦ'Hb.keiJBbHDX4 l.si.!oȯEV8Bm[Ϟ70#ȩbɵ*ۛ4=gZv +6̄Boajo@p/z̭|n>憈h';vr8`EUOOMTzQW~*> BL4'XI }vtzu@ϼ`_MLx^`h?Q3r] g'^c8[{S%0. m/p-GUR p\ nzgNFZ, 5nHovJ< _"^Tf޴H RUww J4uT*@^Z8̄k?/F<*9e֓YLrt)4rWRW#JG!C&/=hw!P/vLw]zʺ_zM?6e;\r*5T嶵{/6?% 7aQ? 'u AZWbhy^4yrG}^  *$$G-a,w]آiURYl۾e5cR*`j e"Jc(H؝(hgINtN8G)9r1κu#h@`1;ysK Al Sz zI>!YNPmH́AfQoPxrRQy5g]H" hW)(j~D_>13+y#£/`볡DbFҕuEcu{HRĨ+"Cm~;lmҳwoҘq5Wf/]} It`ǘ]N%<4! -[4`SW (IG3/Z,zGZ4Rbv:5 k0KZO{Ԣ !`NhGaX}tz%%K5}ڦ)KEJKJCQ.D( 1,~{f*% կ`&GΝS ǫ[`6S:G4o?J%{! jf22p3FARŸKTlgTCA33sHcp8N" dT%)2%?X<8{'9;Z7'8}[#"ePsw.W@`h<ė7# =Kx\v, <@)+ÕR: }]0gŞVPQG?tEbᚢ?{ћ 0@u}{|JOú bW`!#^nVPIΠ7JMF QY J\ųI<$qٴEd>LOAhr'br/ ‡"$׻X`I,3E֙ɑ_u|n+gﵹ6R-ESnMuJ1tqk4h*L=No y޴iYڸE=Њmef{_[| {5!`uJYgxdx q,FRPxMVM.o&,Un {fm݊PW; u5,1 Uş): aD%`ƩmƋR:7U?=5؃l*uLv L$wou.zS{=G ͨf}VѰ7o͌ Xߍz2kϏ4]L0D`mG~3mVd.<8.HwdH/,.@*t{SDMVԆFw@DVI@%8d8d9PϤwWk)8쉽y +-čJPV1 4 ^$O}' <˞u-ۚ 6,LԌ+o1ǘ(1wNɍ̫,_Xi~`L97POg\3XjAv6#_C>΋`rk@hV,ͯ}{`]uXVR= {dZ)ȿ-AW gSroH%Ks#_G- iYMNl|DڠA嬯STY,]$4 :~͐SUC#]*D(\@I≯:#,[oFt2rQ! ?9rϪR5itȤ?8CÌ)dyM%YX9*8ku-ܘiv5\qCA dj(F0c(Vx&7|)S-u`_B%,XTTs| ^Hr1W]3GvS?&! jlbz8& \uv-"8]acUMun1P3з^P6R=d^_Y{9pk_RpUH,520`uwab.gݮ(td?BG.Sb*ܗwC^! r}۬x IX+喁S ܂F̕(MT3,=_@ q@b [KQ?r Z`=Gt. rZJ c7&,٥N nf֧|Vr0Ņ}E5l)! Цҍu‡P|P ;+wf*wN^6$j.hy&Rw@xB.=x+VH $*#V)T5HYΒ#i}镺MjNU:',Xc;f8>G<*Rooc2M-2"vw~:vu)b? 57LI,Y|Ut 9ϸl޹)ЭEW/[f5}^pM Rbpґ1Hb=O #a\{s5^ߏ)6Uk.mXBvf[@4@^?(\+ϰ&( rl)=-~p { qзu! 9 vT#lJ!ggTr`!o=)X$DPS*M?`9U=(+ Og,H5K, 0N{zWnƳ7{WF˞#τ9+CDwP' :]2txL퐦L'v)OΤqғm{fa+2yI"c RNbu*QB_M 9#z}jg`sG<@}Fh5:k˪gaܛu,G4lg_m 'fYY%H>Mm7zOi?uE4s meqdV΋o4MP4MY v&BZ܎ݝ# 4Уmi{;^ XglN_-H{}Ht=l['n,ɖBF",( ;J_UAvŦz<3$nЁ}D _ \A&"HX6p7z@VqJ9A P"xr ə5Eۓ{6}lm^7 47YEG5k'C|`2}fh-UGQ M$Z3a:2Z{v6 aZX8}-kEDowaT`H?*D!]8/S|)hjquݒINɊw"عHwS۴9b #zђ2*OEK`b4rɧ+۾ğ}*kl["ϼ8H.:N Ox:$oM7l2V<;^)nfI0Rb?QZF4P _Ѯ69,䶀:# ķnbrSJ+^ Ƌ(Ȫzuz5nh {J~Q%5Ck =r _!41.Z 76J8q]#vszQGq4+X!~>+VVϙ utvO@|2XMO!Sr?ExY*fI|sВZv"8&~g@JoɖJF`:oFFEF ʭy0r6GZ䕅\b<~_W=\4Eyi/Y 78ɳ^TYBрo:T4Z%v(2Cy5_Ǽr#;(b۴#k3%# n:?ssU< RVD>kI!,|_G'DvAcrxψWp^ٴd{tzz.kN }{A8jl4 z/IMXq[WlcF 0Bqm4 !K%",c\M!DŹ]YǞa;BnϬmÁҞ0ġa=V'!b;UrGnZψ6:kQ}7Vc?.IyX3.? (?{E1/[G @7V ` h,aI1^<{57V<Ԧ5hq') +.M *צMșܒH%2˫ݑM+rP*"*dߨ \7}}SѫrϩaBVh-p6 JV<) @rwE :斌}l藼QEL#t.њRRYKhK/7dtks#f__RUD 091adesX3(jYGdϭIұ-`R~/xgYAEZC[h2HqdF5u84Bx`p8AZh29mٰ?P\ԷB?G{_0gq)p&lG.ӭ]V[Dgzs~7٭c#1e+=yr[qdlUbAGN|> _|ZP <~3ܯ)G*JVtx;&%٦pѩ-""2T}B7GBvmڤ[Kȉ TCxvA墓*B#ca%&I"W_$?o\Nm x<~dMYFa 94@Mq<Ek 튯)y):ײ8I_86%H92 l:Q.-;Ц=& ڀ-?o)x|6ް(XC!PLi F| q9 ҿ,kfVʮx-6Nq-@[bW٪sTlMz]/ aC  QI!0aMߐMzb m‡ꕪx0=l[**Ǯ WIK.5@.?@4TK\o&Jѐ,>n,dI%R1s54\p)@rUݖ ㉰8t zuP1ǣ fɊ[ ,h2LJYct2`/ xpOP_ౖvg& “Aca?$v4],~I Uυdx>QRIP)%Ë0!D=eb1)Rs遜ZsTZ)dsxH П(Ιb^ ~"aEIBWPr܇]DtfcMSwp--wj41'M 0>b h% BHv$?H_&Z2A{ƽ9*[vHs:F߁o&~嚘\~.Ѿo%=_622V.z=H+tv)]tg d4tFF咸F:WH%25pN4&2 U,0۶7Rm8@2۽I@<?v;W(lgP6Yf,@fl V)acH [i\N$s1T -6'W{Ȩ" }#R`řHX/Îq$F:fKz٧o  __1c >] WoV+tB &G!IV2I 80tByIW9v@HD &e ĝ6K)k˗f` c(ȭʀmsh,i UA=sCc3Ccssh^5_)FR_ o$ ksu1 +յ^e)^|i~ WŤؖ`7VXؑa 5/ău<L)Lz`jV74Ƌڨ_4RV?V܋#}P g_ׯ)R/=n =ip"o:#Rq i]#[m,(LqRI ,tFn ŜN_F-:Aq g;A:!eQ_ rX@Lĉ$ 0.-aiJ=K|a" c6h-3Ǥ+ңeDXbR%u4l+qh^dŀHj@ݣ8Dh_(5Mya)A_7 :׳ yMMj R=Rym>ﴭhC !*Hwo]_517Z;?W"x6ò7"%3 83o Ю]RyJ2 QF|NOit) $p nk7fc*eIx̓Pކ(-YORck6'd֊\$E4avhPfiL}e;k~M(UT) +Atd}젔YH}??v~j7vDz7neΒzSf yXm:YAû&󎣅@\V!6#j,IZk?Aڦɂ|M cݗ@.Eh6 iHEɫR G-fV|Gɒ$$-*z̝S#wa-v8v'+cRг삦ORxa{ $(˫vO$˸.#+ϗ|RI#!} =o4Q- |,EyA(``˹ T[_:JsiCy{cI ce (EEmbY䙼?"[8]<}H@n{+ۤ', @L?0 ^(0۶xw^dTf< )0{EC ,+SۓgJ@t >S(I˕j#|opm0$uekE"5ϻ#{յ뙜@EiK;RF3V) i|dH 4B A!w>QB'2z7 ̵"*X0{$ɛA6h"}^S$~&V=ɯSh} V)t*}*w5^3A<|X"/D4K/o^97{a~b\%cXeƚkP.ފpUУ\ bM#kC?/ܐhfKw6[Y2.s96?-mVP!i*8;.XLkk{.g JFP;Lhx6[tKe f*&voe)=FJ2iƷ8ʚMg_h!DvBR'xDΟEԤXI絗'ߓN~~^)a1 &ñFN2)tdv=\cEF/^}`GwR@Y@5co~ÍD@oܳnp:y50Ɓ *m߃,fk! :#nP\j+z{BЕ 2}^,j1s?KFOεޛ|42hLOe;;6X4٥ñ# DE*k!39LBB2Đ%h#A;܉{;#{.Yr{gdH8ge+ri'0qDGۢ)cIATryt;=ŨM Z#E [uA'ZT[g3aV'ufIT<qmd诰SC,NG8sv7\pNbqC$_MO{Z0h%ojz_l%iT­tӋڎCUI"7 cCy1,1@9!f<[0#":}Į@.5Z1'KF6Bn8N0j0;d}gL!eзn=oJ|%PʀRJh[̃X#Hm̑(*lJe\>" Hْ%.%2l$t(+sVrV3ͺ8kT6?3<))@!*1ϼ.tå#<*j*YV0rGEH+x[ʞ\IgputWѰGz/6biC/W&* d;KTء= Iu׋ϠEB*m?7 z/6~w?, uBWm~{P}[ b 9E- Ak(a2*].>^&o>ȰuB A~g6b&gn 1L7rL:2 P;[TpT/b8RpiIR`#p^0(fSE#Zg/"o)ovi{&:.3 ػ8;Bc:ۊy!lq;`BM)z07ÃshN|]84f$k#Uq`]:󀖃 vӊӒpH7\ \^[HrcĀM9$`9*s1}^,*`̶Uw]t,+^%‡"w,#e1q^XZَyԅdZd0Q]Š:t%"25bn/|nx%~ĩ<U\4ɡPpr?-'4s#\ UQBq@_S)ò DH:22t!N: T{P#r$5Oö 9_ 1]0=URROm˾M RuM&8aD3>\Iքx*7ѪRU͊aq)O+(nBNYn3ϯT4b@Hn&!, IsPQkaHZaQqlr&*rN\6o59)eOFdާkB QV4@D;k\Sf}E~fjا^~Z-`r1"B ri )Ұ4 yyA)[~\˶'}^Bg*K)pQe}o`KM;ГU猕;AgfFHc9&C 87ҵ{jaP.) x!p`pol':g[PjK3S>*']=XN+)= &9|674㾺@P]m;ݷ_h)w@Y1X!xcLq|G?b67Z_l4 0I>c>ʹWK X~&U7~Xy4K2̘d;R fp]e.9>ITk&=dQ:mk@.-9!mP!hP>!R3n-.1|if&} ǹXS0g? ?v9IJ?y b3'Y#ŸxQIz !ꏆa_ftnLeTw n'oU^ hf1U-Ȫ-7x$В`\x >U! yYq?+yn9mX$^>+@U q|X[؅0-.h8,uݪTmzNdlR&A26^{؜n'cgf\1袄^ 1jMх1~4\wY>y1.wc[ip(sSDU&c@&9EIvԛa[ܴ+z&6q7lB 8&PShNꣲmJeye &"FjƮۭea/-Q~JRj׌\%Ƽ?'׏*?ٕ)w"@CJ:>BH@XF74F[[I%f\WO|'Fī7-KQ9lU&*{8'D{-"G]N|Gv}V̑{.mS Q5Kg}zlgfQc;|%nǨ YK+]ֿ6jv[#߳] ~_]#Xt9ܿ #ZdI̒lSB=^ׁpY<e{OrUֻTŧu=ou\;fX.(wJƶTf)`F( Z$ϯeyFkR`LX{xz#g Z-4r2 Q=0Ǎ` D*$KqZ zFBM+a0SēW^zD0|@hdtzmFZ´EWw[ QJFDrZFWe!_3N La ;x{=֎2-Zd[jo΍^=,*22w7ff_xXXF9ۏ܂lM}Q`eM僇(r昼&ޝN/ d^|*吔We6JU=x-bMA.G,P˶UHSsty 4*j.D8ɶ4kmƍk;t̐Aժ6 bUib~cu'# cK_@!*yfؖnJ3ٲ)% Ԥ ,d>DBpMhIQ%KJZƩ]|2ufsN3vOj֝-6b}! ԑ,Fhr38uELr B]r:B{GW8gPBeC'되镉$׹-%5_Tg ++5io$K3Q7f]0JL{ԔW+3MFZceK H(x<ͧQzYvGڗ^caWdeUa[6yC%N<avFDYpR-W=$]T'6a+]꧵c#a =%;?K9eXփsd.yf}5jɮpT?uϭqL WSA> 7m;v(P۵N}tf9giwf*U:ey j 5q*b~n.WhxQmLkn-!'{۪ˇDz-9|7zjtc҃3x"NӞ\IX5JP?dݫC*-ٍG^)8lrs.]_#&694(c4)%mVJR\J):Cndi+X.{Zp!:?)1WH qbu}*(Q?ߗ{kh?X6'G> 1ud }3F#KUBK9YZI4ѬJ0g !14%1-.EP*<2o8Y[FԜ/(֎ 8g Cu$L9,&IبDͨ,ְ0AF)6V7;ըN k%?_w>e>D;t,fgta˄d$cw>bv4niU,'c*PeX'vrl Df8W2RoŖ[O7M|PVΞ%C X=O_x3lMA|N [ Ř:߲۲F¹4Y_)mCD 'GfQX Lw 拖o۽Az aS M Ay| 4eCJЛWMfgR^M#<ۤViL:[岗!Q@罗x:}btaڐ'@]mmݝ:,k֥?Xx(Ԥ'-qJ}ooT#$Sh^6*y]Njaкx=6;xg֧8i+TNV㫨xhJ qk(pI߷s;p79H|eAW}.oKl1݉Y 6[Z>]javno)0AwjFy1YM]mEI.AtQn-ꃋnA)U]}/&wi}A-yPq)偠`c=!dcP&ݔ* 0A%hu/0wh.xx´C V%$zYyS>۟e[F9m)׸%>0\_usP-KHW8r˰OZPC[!ʬٌ\Jn2` 9B*p yuj̼!{_ᄄ{ kU<7k ~@.dسsY$`5ۖ7\4UK1eg>.8fXwVazHLk`ܡ}8(zTLǰYa$Z?5[:E#A y#Jňa5HҨU\ʕz Db܄<.1T xلV5Kq%a aKe^,Q ٌPF3 KХY1 )jWARa'4RZ (*a=֋GaՃF3VDu$K&ٜX~Al-\O# ILsg|.~Xu` 4dqUbgs:v\^,}I'[Eb21(xe>zFJxf~j: G`B[@ez G3x"#g)g[1!إ|l\#Q0&䕾D V8 +#PbjQQF8 e&@l(T~l>i^*Fk*k̫EҶy(O(g?Dž8i͒M.T~х@:t8C~4Vn Kے!f%+t1O)g+X@^jɀ~nq{Us,;}#CYRsmf. /xTA1_k!5n/H,\.ֳ /'BH_z_< i`2=5Q I:a*K5-.o\jz㜬MqmX@/Zm+0W_;eO10I\Vtr0 >] WDQn|p U.ltu!o҈of%#"(! r`^bH:ME76 {V\##ᔗ/͞Tz3@:^c8BvJb r\xiX)4$que#JZ!,C6ls}dE홾R5Lk6oKQ@kka3-8\/>480YY'/: ɥ,~TȉXi?=zmCUyΫ~$F,@1Z*^"gce9Au՜WLҨE8oD`nvi1ǤSx^"CbR,/uI|G+SlUN yY uͺXOŮ\^&bX\@|m Y6(?W[x K(%KqRbOX|*ڽɳ$S#]cbRy1C.Bpa *\j˔,9jLKnphYC]ҧ[/*l&4jפ?ic(5%ڶ S(ZDZG8>gǕQmi y0D7 nRbr*1x#AP Tmv_d.ҔJIk goŧfϟ̈́_ dH'8EL,|Sl\3'ܪRY݅vAٳ-IV?cYUr0 x$O_ 8Fv^$>*UaM*$Ҿ53I!h85}2ȈoNg@>e ޞ#kq6". il*vO1IQaْ(U6x' @SۥK0Y G~q1CAo?<|>Ds̫BTablיv ~09!@A+2n<8&z[eQw))<P8zDz{A)zU˔3țEiX% &>6C[ ?Ѥr5\ &f^UCc$$ؿ7t=#)<#QD.tjhVTϿI >NُU-畠U8 M#G}`H\Ʈ7aQf)55Qnh4bR!,nXv3H/mP To1LG$:G2*2;Tx}G;?]#|˧tPռt^Iߢ`Ve( `[RfF@ Y,6Q-f3rE>!vMiiS[l Zm)ޞ56oU|]2+z3k[ZJgjaӆA3-*d0ƍ'Gl=SfED,6)m/n8G'/cY)$a@ 0NYIR=ʬ++n#KsZrP&ˡ)}'mwEQغgF1}U"]{5L m!sL)U~E@baa5jp[Fţg$PYypmaG10-MK@ˬ9qz00z C;1ISx.*YDd.-wx9aX Mt|Dq)BZxD3Yt\W=c# O+R2!v _S{RA~uݹbUbrץ85kv)CӛХ|L< vI1]ݡ/Y]RQ€ftjf= YH,ܪ°mibe}xss(>IJH/tg㌏_G@~5$(Gʚf:#Uv;0eεroYUyʵ HV s=KM+Oʰۆ2t*qܺlƕTrt)m^.OfIUN^6,jGB/Yԁd_OM7mwbm87ŵW>|UӭtIH鍑c ~j>Y->}B\ fU"{mo4P(#ǻoY+B>e' C;~Usv )T(i*O=mEۄ4YW8mR/Yhy1.;{.f6TLUMo'%jvZ^zj V:.ӑ_k9M~ġ)Ͻ~͆Jh3r݄ւ lg۵u{1z,Ȝ=Ox|< P`HiSߘBw/\߽W;翾4sŅKoL{̹+f|ޘOI7{•ug쑒K3]!vI]!l=nN[H 4#n{_Dze@늌Idb߃y_V.g]]G\Z`I,cZ:w7\pJi^Ǣ:S>*B7aqf% LP*oƂ6"xPO|XD!螱K#4c&e\1jsQHY' 1d=mu;т$G@TOe+ 9] NOTD2 [&2 n^벸&Jt~~״:P$,tCtCV$-,Lqq6fA:>*&8/&Cd2{?3<^櫨6&oŲagv8~d_D`PN um!r }$܂T1"zBg|䩉Wz%y'l% gc9u˺Uq}G un&х