sssd-tools-1.13.3-58.el6_9$>"\4{=z%2kgBV>2?d   C .LR\bb b lb b b b!b#jb%T%tb&'6'6- 6(-8-94:GbH<bIbXY\b]lb^\b.deflCsssd-tools1.13.358.el6_9Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordZTx86-01.bsys.centos.org )CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64P00H0KS@ |4q"1FQ :bo3] 10m:+}MHOt x>tH dC A큤ZSZSZSZSZSZSZSZSZSZSZSZT VpnZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZSZS2c75bb44aa666ca6edfcd1297a65a0ae086e476a013284baedc97a62724ef0ce6326b25b05cbc95a639dc51640f511715fb807c62851544f3d40966d2d0df9e50a086afed5d9c62fa9e54fa6429b0ac27d8aa8013e34aa43c7f6b93ae016163eae9c4b9f2a0e5fef07e17180a46857e5481a2079b576147144605a4255e9fbad2be2c99d01477e36ac87633a874d963177743272bab0f76ea38db0570bb0e367074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45ef66cef11c1814d4209e16d253e8caed97683ba17adc52c90c35c7361b0c9054c72ba71300b70edbd9c95715bf12bab942623ec6a5837b2bf5e23b49690ab3af52232763cd2b19b0506d6034b0c99bf98ff77d359f6726abb7c027861be309fb2e165c73861b1a12d3d0f43b9865fa08ca2daea1cd6d9f3a0ab029ef6c29efbe179f84dee543980d6ff6fecfa7cc2c69900fed2d34c50e3a0b1541c8ff499ca5e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90313b06097b136c5c0d5f655559c2cf20fab26fe76fca5c20564392eccdf0b5f50d3000aa080ad7a5881c8a49dd3da76fe1d6c6cc9269abdf8bc222819b42b9c22c75a1268599af05ed0cc0a04dd9acfd73e16a6412a5d3c0e498d4555e31c84e23425506bdda4af8cfd3b03f3564419d749f067940c0c4d3ff4e0be57991069c4fc3bcefc263239b822919149cda5ff37e4615f1f84ca34c0a1b625e3a2c687613b1af636877fa2912a36482b24bc0823c0b4f22749f376848f870a125435bed91e77ff47a91e4fb1698ce16a6091e14b9676da515362f6451be42bf4ba169e677417db216f67b03a91fc7ae16bd95b800a180d9421cdc2f4dc0475469db40419ea89929e20a817960d501a690a6f830bccdc97fce0eca83c029d23cca69bf5b25c78fd3eb592c4f9ab2cb3a846bece68363adca060e3ce994a98ca81b5e39a1e711ebdd751d5e9ce7293d68410ede3a69e6c79c1394990ea2aea526005a814b678e88f5546250961f8fe196461a7bc8eca26b4783fe9fed974fd577ec6abea703bda376ec5b5419141a902a19e988e4f1705248d9742df853cbab42301c2457d4296d67d7241a07cef458752761ba8bb724e2b9647eea0a61dd91ee240c79a21a224a1d29ae27e951de1133babf06b7feeb94680f851c8e898bf278bfc946f22111cc48c43bef44f58039b7e13f5d96972fa7b91a9b635c8e025f4f53eb774411d95efe410e12f64ca7ea89d33f87fa41bd7b44c411967c680b7274128b11504ce4d1519200914157e3ba9df7f2144fd42597a5f26c58eb4ff9d7aa7e54f162e1093fd8e3b76bf9aa1be3c4db4de63a83c7462b0c47d51dcae3150053145910ac2791378f73b979be8e47598aed0bf6a13c32cbd890a1a8e425fac4a61038f5638459a51e976bdaae341a3939ef61aa0ef40bc1554bf9cff5ecab78453d144f11c64364cf8e335bfc86a6cd797d3f7ba1591a3c01890dbce7ff38550996451ee259d84cf9d99c86fbf343b3d1cb1be9e942b14234675d8e7a351e296f72a95d39283bfd4bfdc79081fc113073438d656bee0d1430b484d67b4f9517e9e1a335dc9d5c7d37988a048246906108b3120a7d9ff465fe452c55515cc695b6ffc826ab9155d07bff1e2ab13d1f2085be637c43d6259aa920f94f408d8f8f2b1d239de59248760a97b39d664d4990be381eb364a0501bbac3f67b04b48ee635ea6cd9c7e6c56021308ca05c0b83cb0c0ea4d4fbd7a2810f60c62a9adbfec7051e2a0f5b29d34477b38628aac5f534a559bf3c0e060ecd176563bb968619af6d72d510a95212b7a8db0393079731272e190ddd161edc2ea98aebfee9977075e960eda2d85f9f1e4ee2688fadd88501aa33e5282741dde4bab11d5151eb1362434a7cbc4ece6145931276559af488a73f26319c36bb407ca226488069e039aa075e63d39c1c9d2836560a2312c6e811a150de3844c6ebb6b008fb79d8aa0cdb9cf1a43bf9faaebcfe61c74bc4b7704923ca483a906c5af3a9abe944496758fc8e8f0ad18083beb507678f3e7258d4a11c3c11c2fd244a72dfd9c83c8df1270033ee4d8f4e40293f0fe07b24134fd9c470fd1515883146784f08d5bfe4de420a01ca628a252f40713fe062ffc2412cfe92e68fe89fd46c0b6a38c09229518711f91ddcd5073bcb21e9372040ce1f635ef41d1caf1f9916196675e13a0007e42ec3d96fb39fcbde84bc7807d6d5d034d68b760788623eedfc354054975c58b79e59a378b94741cc1e08a1162835244b0fd3ce8ce3148d374ff988a79e8b12b994a9e664ba5db2d423a54500d801be898bc7049839217d8ed9b25ada18f60f0ea5d9ee69e75130755250d88fe9bc46cdf1a23416502a148708b819d763c72aff1e0d9e74d367203e93cfedfd64644fb6790e6df37bcefd9b53995b5c12cd376af384416ba54cd7a6b486bd93f07033099981735fe5a3cca9bf7e8a5a449d04c20c0c9a917f21e92757db0e35aa2d5f50f52126ccc2a56264a88215dd8178273e8ec26feb06488b39cc94bb3ab1f7b668ac0c35faa0b5816840161293c41ebf2c81125e1a5ead6914a501130cf747f677b00c4c4e60becdd2f27ab3912c5785783337aa0aa5007987b09fe5d131b62d51e4c44c0f24859dbf7f7c6c666a30100ead481f43d0cd3352f3af15147b499cc018c662026942e6dc93fe4a89506fcaecde2e6f54eef30467bc4422ed9178e5e3029b274592bef4866fe443cdd826af758d8ab26ef59bb0e66d29bd5e638afa602b9f8eb6eecde0982840dc302d5288d1c3aae408c81e1c05da6208ff91af41284064ed1866149d75229cdf9c31477e5f9e83f61670075fe73c35439e5f72368db8c7a0582b0fb75663ba8e313afb2e936290d917740515c4a6ef5a231dd83d15b2612a78208128e075999cfa225bc707d3dc3d420840e322b7f414b854730bb5db58efb2a18a216d44a9f2c71c76bd9fd882259d9345da4bfa87ee06e7a524479a3a259ba83ec126de750c296ac6d04f07ae79dee0b2fd01d1801ff04457071a4bdb34ceabc475857c8dcae38730b872e2be0c3e0915fdbcef29372eafb619a4fe9bbe13cc478cefa5ae70fee31a81ed1bbbd78e33cfbd735606b5e7e84d56f86bd3a42152e9cd068bebb4e779ae152a68185bd519bd26683eb8161fc53a69b169224ea6887dda3f92d37cdd63ff924451154aaf87b1aa486047281a5cdc1d258ab35cfc1db9f5fd27139ff80bc40dd6b1aaeb51547832eea1c30b3530ce6ce83c669b19c04832976a26098cdcc84bc7492112a6facf629db70fabae3473d30d823c0fdcdd658145372088a2416ee2d9b1b921c638cae5a8bb41238f48f94e5ca1240d87597fc0f19a16e82adf868918564908a90c69d91603676af9a32c792fca882fd9f96a6bdd493f0afa9334bae95910e1a6abdfcf1f6c246fcc9775891e955d279f998f47e3e94beee36bdb6c92c66b4a50b08246e7d5ad5b26b544b26f74f6bfdaaaf2b1f0de96026e1f123e1172b0e4a8cf81c6def5a6b9d39ff828202afd7196eb74ba0863db20efdaed6eba97eddad611c7f81116d237cae5ec8876bc6f0ad1933db1a4b041a1fb58f901850131eea8e3b374eaab9c4f8ba7fafe9461d5bc82c401e4c49f3bb82b18cd4ff1fec2142067a9ffa6bb94e58e6db8553bb59bb559d848f62fbfc12926972320c6b1ff62fce6c8e4ecd1945e5fe47d7f89f021bb6f80b8261cf8b50dcc3ecffecc5449ed8fd1c611844095d83f328a95a141efde0595bf1363485db8cd49c8d8d2064fa7e32bb8d9488cfadd483ac904addb95f1cc1a58c61566d5cedb021b0e7a00607592da03cbea0785a3dbfce092723e5e7d5a012f89b1108e4692ce8d4184705293a76fb9f56fe82692298a2f764fc49274392383f6940d5f70d0463ad0c6acf61e267f72f3feca4309ce8778d13f579fe68c8652250563028d777c1e9e58d6b35f0a2f0b2ebe0298fbdc90350cf56f0cf4881e205543cadbf4ed7ec338e1a084f1d609cfe8d60dc085f8d43b99018ae3964327c69555ffc35a598e13fcd24f4284c0aefabd661bfc1e66e1a84740000a4f2ba79fb17b36f331499b7f5f890e22663f9d56a921ff06997567b3bbbf6c6e6114f11835d1c0391dcc093618a9591c55b60246714852e4821adf67ceeec96e2fd39b79f80f3efc499d76d3f639c9e03e1047fd7c85cd8d50e82f110fdfb73a623d4e4ec14901c6c61a4dff8e18c0fb1b9a4a015b926d7a071cf1b5050ac02c9e1aec70aee74e1014b5661cc44630534d1a6cb2cb4bbe1158965683822eb952a47d193e69cc1f54700e924ee1104b8ec24ace3rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-58.el6_9.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-58.el6_91.13.3-58.el6_91.13.3-58.el6_94.6.0-14.0-13.0.4-15.2-14.8.0ZX@YyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Jakub Hrozek - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1534618 - ABRT crash - /usr/libexec/sssd/sssd_nss [rhel-6.9.z]- Resolves: rhbz#1473005 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-58.el6_91.13.3-58.el6_9 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH63]"k%}:w{!vQ_99g/I^NԺb+T!M׮h gіدpL1{p du7} Fug!Z~FcٹW=C]6#"޿%ٓR΀upu3!ћH[j? b-:W|ә-k5h "+$G\1'Tl8ؒ]ڕO0B~|W o=xKOX(c)R3x/kmqҘ¼snS堡Dvb%ŒQryt '7'~kt%voIgkƗxi):^őV2}$W(_J*lTg3.l21?a}k\MJ~712ʹ>Eؽa˚2y}(>l=* Cg5qj;t. )s}"MnYdv ~^js~y%jEHMA[ƑF+ 8/ꅖq44bޅdjfN_fuD f;:@"h 1YpgG3T@CcԖɩ`,$gx &ѧPݙ఩)޵)>u3rA]d|Ehqwo#mg'gI6~9\gtRN޺4ul)ybA^:s2LfjI_@]6iU(ͩ#pu.OC 4%{j>^"x)^8caGQl]{G̵$Cu˸0] 3& S ҕ +_s;t:*ʣ*(%ħ\@$3AbwF1δ=)̦.:y(y'tDc6}r gh,rr{]Ȋh=Q҇ED˜j HF`ԲŐț<+ȓN+PK;f6! O.$ 5A~7D/FyMe`"5[}!UUB ݾLX}$Ǧ f~CMM9,oT9sXGty5}kZ-~KXsv9vpTT[ p'yD)1ݫ7ːhL! עucısz]ЇD)KF/Iw+1\*cZ? W =©<6-0(WXKf߉Mɉ۷JBCinuOFtkhTHX ,zv3**o{@o((X`E,Dž|.Yc'D`dd=7k tfMK,; H?/3,/S6C5~ɷ|{Iu[^R&r3Rn]٠mE+|"iցk- \*EZ4B89tdˆ}D)HJ/2r /of45bL0rhE:0+m.xӼC6\ +..]\jQ"Çc0d1 Ÿe-jMLv3,0k"NmۆKEjF{س>{NT瀉OZq½,/!qNV.D{4z)WO{1EX/O:9b&}*cWdOU+heHNq䘏 s%Ɨ{Hx(g`eBۆ8"nh\dOjvʌMQxKM$ػ!t;ͨŞ1=dCrJCdm$sLʝǻI;WT?moib04l/YS6tAC%1+zOu9Sd,=!T2q);튶HQ!@_Қ<;A\ HJl`8!A:3fH1oBr}9[!ؗ\4m-eD|aJ[4UUcJ)f)ĐHT3{^왑z e#E (t-߅,HIa7 !>vȴ_Z[s9P@(&ZO!.RUoISzP0 QأV\A _p焛G*FN樠L /~;[[5ةN_"dcm|%|{9ڍ N ]xo4nɑZ/e.6&9{:߬ `pS9{5?Gu֡{`Ƥ UC7tXOAI$- r߷,9'C夦J5[X˾b3Y Řjٱ> Ur5ܖJZ[\%uę2BxItQ3?+ 窽cbRQ$,zj|cq Cmz`(83vzx}^xgҽ+k0V7z#`\#Pkݫw'cq ]l}"#~ !"T$*4V $t~`AKU3B0|{ϟd6"5F[&ˁ7]׌9ܹ_ܬܙV&WY~+n] T= ]_ӄE=T"E1rE.ϝ'r!IG8f-~UH -`(GQY,6?5HhVА)=TxnD8zXBj(')(W VN5;mCy!\C^{˷в6،y׊FzH;yy&x Av9)-l3yT³!sOßU)!i'>pYM)mm8ww y{(Ga i M!8쓪/ƶ`&(hdNq cVj 1eJ:!Ů͞QىZֹ t(n;We|r xK* o5w=i"rZ\յ1gVܿY y>-u72Rٜ~ijtLS]/Gd@ifַ1lr4s0T"˞7'r_Ηb'Iٝ-+dn׍}1Dpk߉@##73jA^&R չrsƗעP=ςlI>fjJ1X'=d(_p"|zF! QdѱN?~;\;}% G .(p2/Nj5X:\H jh˳yż&u4u"D}騧U (D&]1M\S~ѸR$ǝ* `нC&v #Tt8Z\^E @3얟Qv;m)JjEUxp2;&&o$ jz\h=r1G34]ɞmj%ebmh}v^0̜r[9"C+pocR*luǖn9iK P:öMpcCx~'4̋9r"vEp5Iw| ot3~_xe-HvX:n O0i{BLM?40v,2ޠ^.֧Ʀ r5^f4I$sE l:;@]N*Zv)1$ #Ruz~2*!{bۤn#9"M.[wgAKL&&͈"4n}ͻwo>/A!t4>BY2U$(xu'Vo8Z]+)Ww}ɮTpReO.h+mH]!iF/s _F{OtqbOS7DS}P1*qba&ih(yy.}/ 5d:_ߏ olJ|~':!)үlT ](VG/7W sza1d"A*;;1 ۾1XA۪!b>{ M8 @W_An1Ȕ;k6ArY$[ QÀ%B0jE!(?2pKSBOc[Ԉ7\eDz*Ƽe@oɍpj!EOrlnmjWK dz`MzbnMt;$)4I{b,%3C$\0gZ˜O/eSԒ)1ؕG;U>Z^V2jkg|cE#~PB4`;H^C= ,OE6rcy VE4)7 c(ʬ!@g]?(S*[Wu2EsN2d[rT1o]zN~#~Mw(+ut12K?7br3$B7Rn(Y_ dӻIZ5xJ'D _ D@ekTy JMPxh[Ѓ; 9@ ?e>k6ȃYȝ(bv/uڛSr Y!OCǸ>ǦԽ:4h9rG5GGk W,k{;ij18}~![VYN5@8.70@/3~3m.vth%­0> 3Y:y.8(yx,R~u7y1cdGO4s!Kk51C*$XƂɸHb''Xg-F:!l䡣 =mlkp[߫V{,& |( SN]r$'Jl6'nK9 Q-g҂ͨs0߯{Ы %#^>;vU_cK3􎘪S#68N `WfR g\D&/Cò_ K%MNYcmw"& x}iOٔ|KCi0s13QJc>cjigC<OׁYEH-1+Duc\Q'U#tG AbKGݕEAȠQii/4rOG9 $ I@Tѿjz"d/8Y.+r_ F?e19.19UjQ)Ծ`K>EH-/;8pnƠR-R0M}Oud|S^ՄH?}ɡV1Я\̺?ҘT8:`2d.S܈*UMOP*4,w x,dQq C^oocCx|Ҷ5aZY8ɻ;:=P`1`DinĊ!xxS4Xi̞Y;UeBXyIwtJΎ9;t(.n<19m;٨CQ8Nj=tf K%&Ꝉ(nM}@ zg0f|,Kgn~D {J6~>J^SKӉ D#@9#E0gy;쾙ӕ/'oڕ Z%=0u9S(p]ΌY_F$Q̭WC@4MPs~'}MHQ_8f*dK8ŃG]sE tiiBxYg?ipow0]?\fisQG`fvc 3/T<1^[E6|L3H͸:Lab ڙV1h(V9y0ט4&<ʇ`;gS'

3n$h]ԭu"uquEi˩+mW8@a& >3mhT)Ro!]Nj3g;El7/Ja']<%T_2`CʛgsFη"x [;R{XG5dǘwe6HZPJEؚyƨ7$dw8>KLQ 3>pS %ֈdqaH߲Kfգ1+ʍ7\<>3}s ';Oa#2na|>ɣ{~gaE%k|p}B?Nʇ5X}aUu&c%OHǒ:H٢9oJS_^Cya̓wѤHm2%]kGqR,bAy+`!`d秜FxGGʌőBwf:?tX{݃wʞ^VsD9>*hS2ީ'Cho-c 3eWdXWb`Ia9 'wGQ}nCEdnőS@:Ǎ[G e}!Dk' 0`c KE9|Z%Q9&&.l^Eȣ#֬ZEpyO} g~3x8x± U"'#+Wݑb5ENpire}")_LzQF {QKrjQ'4xx%DzF Ʈk_kP5<D4?c ŪCA*u$GOuE\:M?k}94j(" w # g֦ZS2I~tUXWEWGBL0+e/W75zm\//?S._QͤkN{U}#,8o^ 4#B[ӤT3Ge Qu J]ŷ92?Rb=^0l#y s26E^CVU^rS.Jk_lc&c*by sѫukIWe31P'ͷ9['ʥ㛽e A/~޾gR"9BجHtM.1ZaQ5`]( 8:[u4+UѬܯ8pIp'30z@ XۗuuQOWXӬl*/&䐄[Rmjy+U҇Y$EN!+V>NO=cPrljG ʲjdM.vqlܹ"F(n5*bPp:@Fj>$y쟢{GUFu:n[vYʥ yۈs-*=|]\U0@pfI}ԈԦiYeA$ޕ}jkm$NY`|MyQ{*Q55jWf2U;hCti԰Q)Be:"pNEjRAaGOlQe ,>XZ;95逖1z&A X]Gʄ3/Vp@~_aL1)f2W{WҞn171+x3\= _2nW;q=pJ8<79܏c/܆5\|Ry~ CcHY@_ ,ǻiUE:tnu"+?rH/D`|w=^.ݞR6FWy2`,fSw 6x.92s,fDW쥓(1甚֢:s,Ҏ5-^/"pSr)FϒJ8I(p u8t^;bkK=1G6"5ˏ"Xn^*/C->xS\˳t!- r;T;Tr9$v7=O٨j⣩|!Z^h2H UNG! ;Ti=?ᙱ}!&6tMM FQ%]ClgHK\< vv4m"ۮ)!#n$h$ݓ.DRL^ -9@ņ!4,J?F!&ekZߩHρ Ub>''K.r]B<*hl1hJSbHbz[T_lPd 'w5 +8ϲn'ÏD,]K#`&{1n0(ƍ8>3:/zqoD_tXdksHyX6 c>8Ti>x_{m 85L(EVĊ}x$=OCdYQcs@;uS;@ dAy)ly_65郑\$]$6?^\TQBZUM=tlj{dשnVśWv]J щ_Ҩ7o`hץGdu1O}\@:Y 1K=lL}Qz3Bdѫ[T:Ȣob3/#p&c/9&dU)? ei- iӒ+].Q;.cjf$GG,&_mz_P\^S~@ BSk7y{Ơ|6w t)xS% O1tx+>1cnk\c9^bQvBjc,EnU5xJz=$?gMzy+[OUyOc`ͳ͡@^W*,p(biU:iף2m;DFBtp%ƨQ(7Ky$K0VBYSʮp3ȩ@Tp\:3OX):ǭt-N7M*T"!~{«e $)(f+| ?Ӎvv\49=x.K}K3X8ttcaHcJs $ d5E!vFxVPP&.+z=ݾFrj+!''@1ؼbnzv6ڷzmx0,46ΝOߜ Uv#T4)u9ͥyDjkjw9,BܨXDZK36-'tc" &p; #=N[ U,B+H cu&$Z! 2f5xSR.&f}LEV!@["zRAv'Ӝ6֪Vj"-~ORkF#p{xIM$A~ӪU0ou}!DӉdcV  ȅ͙;2 ֻ r 3wg\,^'6i`./S2- @D@Ԓ&X' O+/zQ|&7J ޹A` 67r82;Dh ֥OԚF]//F\&U5Eb@# tԗY]!ueS[{ofnWX`_F[ہų(O-m8 X2?ޏkrJ{EɆCצc;Oѓ̕gNXn"|iGo1g&Nrv>"gtg9Pb V:X2tRY$q]) iGu JҸyRi[6123z,t^\Gƹ&D /1{$p|"Vw7*U;37 Sb:z7e6~{a*'ϸQ$3RC3_a)%49)E[JHkןz=nZW3JGC߆R@\`9UruuR>cJg&${>a$aO9"9tz[>3"&'P%1E Rjpa:H8:Sk@s$׉ LD-Ep**/2T}]3a1`nABr^y{N]2t @150[!fS+O5/|<7|OU g f1<:2C2*T Qz>T Sq/('YA;4 B*њQmVEb'M^ogb3Z(BHP.L1+g*azuoDiSEÚ ȉ3m1hy_2aE~ɳ_L Xp[jzNWJ}dxªq5A(.b]<+{GOBkX[)*?A D֡:`ݵCp=swNv~H6-xagpeQكJͷFw g+z /0%I̋uē]LvU~9~@:a͗*.y%N,6 E9Eݖ>j /.(`!܋Ϲ=X&$`B("v8 NF j^%oRz=.%֪yY} @Į4[m 'GDG!$;mY4=.K} G>tFM:.A4/zga>,R.T´z7B Zt4Huܛ7?u8kCdxZ e"٨2"8/V$"+7k=Hl&f{Z.rF6S1-.rtTwP10W y|P5_D(A]@8aG!6ĞňÎERY>48.ԲbڵŔ 6|:Tm} ~Ѹh5:ݫ32^qpQާŹͨjLM} O@Xlx FP)cy+ZbKUI >;P7ڡyN\փp:Xq:ݹ%M,($Twk4-7fAuRL6Ⱥ{ W :0߫ ;&HsOF/|7c8WA5<_:0J >0uz ĭXL|xh0>jqͨ ?߃aF|)թF]X0f!C>N&?Q(s%:I,bbntNsDa<=#OpBJ!C\)6|:CI{nCXVY6ON.E>#ϝ0hw`N@1~܀ F#+<~,)Rg{_֣fc~حХ&Rmw쒁)D3%R#Ih՚aPܬaL1y+W~.3[ C}՞HYnU &%ѹ"qftեd#8 aߟ SMvX"9>Y-:l@{VǦXHx:*I$I N 4<-΍NIf$kӈ;~ P9;Wד᱐J0 dV]η~zHrv{^Ta\a$g d'f+ .f&NvT$~)w?@ t^N0,`w8i?)؛,ƕ*2Vf\'—{B *z-W$qIGEmr`̚X)7ÓKLyr}!ĕz;$Nmot1獙dq.<1m0QfLB~;5KETR\EB;qad/ANE@S;@F89ixҐʫ!WMf)㭌0T/77=Ϭ0{?xW)(B{F @"SHY# $XӚ[ (H(OJp5PI2pu)6-i=.y4<ǻ!l' AzQcKxnռ2~ =(k"ȩ̠=ϲ ol 5,M!^P4+cv#N!?4SLi5h S gaw^@MuZ_+Kڑ9DOͬ# 6%0j9^ޡb4XT4s_S?nմ"N/| 1vF;,f›] Vb{CyNgB9ԴWI)^jSqo8ƒV|D7-fLm2ֽܣ 5ׄo 9Zfi$"vTu!No yd35?9U@h%'+:- SOi%zo0_)ܩA3Z\b]@mt߯ 2o#v lJCdQ m3 OT4q2j'aEHf}F#Uxlkޥ!2K6P0vMTxr44"]eXMVcOt#;=# 55*PoNx?EmYw1RQXΚ6bCR{>72:2pEe eUv10uͳ[,sjٜP {)+]窡+і†ȳTn?P3Ņά 0;zsB@o'1xN/$2  ,![&`6b>(dɰ,?bS!`a'`z6Dn‘@U`AȳS^TX00BA"/s.`ٕO29:?jdL#qˆt cUkI@`"]㊸GlXb @5STM' $Ξbݪ<_lC8@&2; jW>mpxI㐋>3OioV7H jRk.TVw5Fᥘze*ZTdpVc EDŽ5>l^/ϔ{x#ճoEWJmr'@| x𜨞_1*X=M6lll+Ǵo[Č_{lTwiMd1XzrA݆+wxɨlraB`Mf]ӵ_fPIrc5۪;@][u)巴y~]"|UE%%C ;a忖j~GW_`5y*1&#rEԜ18f'bl(YE0nPwJ+PQd:aY;͍X DJRMok2]3dfE@k8b@buLB沴#%v!AioztZrIrŎ?1Tn#7>됩?m"2%Y)!ڧkNR^V$d̽qH&:{A)c/A펽 \D҇}< M%Y=!q}` 7k 5Ӎ1x3AD*xh\VjI9wFW8>=YI쬘ǥsṲY '؊ e'am(% hT*$cY!m[!DBԝ<\*=19@@In♛ʆƯFRxt8}cChE9^f!!{p]WhEtÀY>#aTuSe7Nv+ n5GX5}(d XN:Bbfj:E1 R3+ZL`;差Mܑ@ [ ]bm?yOS %2J40x?&Ǣ:cc7f H֎0)I$}a^iOo'5w3!)E FK 1$&=Գ?[b. :{D]I7ԅpK8 k>>a6ݔ"58kEz/<h`u!gr/]hR V2Ѹݛœis\0Y j_P51ŝP ;FeaS~F!݆!A5w"=1 Ez}bZoM(*쎅%Il Q=N4&{<#̭ ujRh690boOrEUHW?W+/zUUq b< TRq=L>ozn5yRZݝZfCu:dI?Xt b/oMa^+=:Kz TMtiK/nl­9E ijW r+CysAv916n W'szX氟>+h$f .i}Rr/>z% 1±Ճ'daE [&4t tw^;?f9R,HEK*mL)6 ?GMN`4_D+򀇐#NP gOg_d.b Bj:wM- ܅GSEVXRXpl\]6*QDø=S{˥ h :DGPؙ=`RsFV ENqFF9O4`oLJǎ@y`'^qa&Ά$fRm %9de _">{w c$F2Ƴ7r^ծ$XwrJx$zspV%2Jz8R u: j0tw6BM.9"LDI#waI28eDfCt*v+LL$p ?}⾓Dֱ\~ m\x7nQqܯ5\u=}=Mxd<^AYVIណ@lIRގz,U^<ɩX ,1kmV{l>\&=c@gY>5kIYӯRA@2!&3:$xt~Co>mQ;Ux~a ; JCeysŧ t|<+pQ c!厱M^MJ5?yT@@i_s@ZĬ&{? 6 !C,1JSwT)jxa1Pz1c1'NOZ&Db h;@HU #}cST?d]`G$@^h-Vxhu Wr[9mxs"Ho]aޟj"oLmTf\OF,&؆NbBnSbD9n;;YV*xՇ|_dDV+]yt-$eih#  zVoKsf.d(]fy 7ٜzt!in# f>i8ug\,9PԣFm'7_ T ުat 3??hP⭇@ բK[\o\It_>Ζ,±D'q k*U `ub=ዧ#ҚU(N[<qCy,Z1}R/55F#Õ,D^B.뇹LYY }vnkiB~1 n:6T,2-?7߸6}TOB9FO:8]ΖZkxt׸牰=룆f㻻*NFJ;maCb|+,wQy13o4]UH;!S^W(PE߀'e?[G ]LPh&gZ1(i;,=u|czk+ D@){dhSjzSfiSylW`͖ b]U؎awf&ꯋȏZOSֆ㟤# J؊Q_36J&i ?F+L!FMTrt4qu%+Zo9 bfu"UMs+*h.>ya3rcbk2&rژFzo'C}փTnv"jBՋW,A:/˻z('裾 ۴¦Rﺯ-2ZLܪtXPqo"M܋<_eo8pc.9bw?.Fm@Bfvb6 P_7)3kOAqRm,lBGjTأXn"դH欬?qy/ 59uߧ{0!,d#ᑽeu..PEe$(J|ys~Ӻ*$RjGqkog<!˜e =OA';^}U3v\Ba$h'Dj{ol4 @MϋYt#6AK`qkaHjivk 7hޑIE@"ESP-~zxH(%( (7Y`m|]I/,qMy| hD4LoyAq;o 5M#!.ȳ2ٚRFƠ : c+^LmB!IoHe?Hnއ@K]/cӥ oNZcjB;NG6ᙝ\ f@>"a\|?\.a䍝-DC}S- d }>H,5m;拆sVU~͘Le#<~K)A4=גޘz&Qu>v/4P7)}6%+*ŝH.\KRFo:OocK :3evBsRK W%޵j >}2i( &<A_==xc<ާo聅6Ide ?TO9""2з00yNKaKB ?-QnG)>]=;ZK>SR~&6!;=BYt4iP 5#Β< z;3=ɋsqyapAxP.ǔT'(_BMHO7IL`[(rL f ;S刊Qdȥboe9r`$qC3PxjT&{oHjbp1`ܾ+%=c&.te' EWlRh:)+QPar@qW j6,E||iЦuޙ6%ۿ>MXl@4O'=cS`+p*ώ 5GxI?hFneED_呯@j agtJ 7XEpeZz(*~l+m2v>)3$paU?4dLT.G$2*/ۿNH.Xh`H"\/Rb)5Hz2.#>-nW&qOk1PET ue:&K_Ĝ^=6kxcg0ö65i/iS7:dUUI,jO6A6P Q*&rK/=v\$ T{: v=ۅ,O8BDv$ٍ(J,ZwtcǜLa\2,8˦⟎$XP=aC ps:~oi|Un@'N~_g/ä Sc B4dIy1"d4B_׶_]3{$^@W?7f aؙ9!l8n0eTϾy\sD57Q]^ %:Dߜ붒E>tͿxp` `7ҘӪi9HG(OS[!o9lĽ@3 h`ȦB,;*^.R~(uU*VGI]ޯo乃F‹7H5gހ?D@`E)wܟX];FCfԤ@D׿ /255̪ p9d崔UwX2A<ٜ0s,ӏi8:c o!!&b ڦAm=ήN-գ 5C >=FSE4hWq 1[\[cGcF_7a1wĩN^h9bXNLT65ԑ +ʀYݶTfa)Xhia7ocIC @xyj,ÿ&H=Q^c_ 0g3 _Z47<48:r$~<rivݵ|Kt ;CDF K ߌ4qfu}_(=Ϡ/ϵYXJk ~=1^)Z-$~vU!-uF8XLew̦?nAa&TO WӵEZ\ܲLΘܖi|RZLΒ\SBӘ6A7lJ=h@2AϊQdt L,MER.g0[n1u-eZE^mAZv'}ns![SP44 Y͜iΔ+0{C8r`( n|ݞ 7,to/`]0d*gp(is! 23]-il,qӻPEaL3h&|j)Wc$XKPE@3voL#ۮHlA<A&E|d]nh t3.])5Wf !wߪmcw xK)O\.4`S-@l_f`pcbab2ޯ,.Q,p7㤍Kjݠ.Z,t!$ L;L!=1/_ʇFU$s^mPNO9PTWjxIO@m\++:̬͸/}/Cw9_~$ ?_Ⱦۏⴴ4RLZw)P׷ܴ=>.ttT%Ui6ߏ{ ##z-V~3z-şl{b*mL@񘻄z=Fs&7"5}91g5 Rf+-vbrL8 bcwג'f0iL~"'E^6Vw^-m<;Ä1\O 4Ύ!D ahy(`$*S\Jff;{I(è>< L!ѭU✐D 4SlaS2.#TNF$(5xuDIiL"t6["o :U2ec$ckg\/#ek0'3M2aQ" ;`cWV.hNn-ȈNkMʢsj6(j.Y &!CT&`ۯdj%WQ:0<-2ґ*>kLՆ>t pa:3mX7UfxFo@u?/F ߦXxq$_8)DÑls 6PY\^f?R0 A'*Aw06Mҫtf9{)z9<.dmk gk@!5P ~{K+^wiM$oYJ*O'iFXK#unO\C؂]A7'<,XUt`'t 95Nk I! g֧ ʷ{NWw/x> =xWnk6k/ ;F9#2M􁋅 @57Ills |ZOI9Q8 ,:v"^$=FʼDOq9Amn3 c v8 AvuPPUj;&6gƱ"ÞK1pzqھTMv6_fF®vG'}d%{VG <{>K 9[As, _76C1@8 m! Bqw-_@SlW$x~pN {mXy@Sy~R-ѡ; 8\sWY&ExC) Žb.m%-AƟ>Ke1W#im)@Rqg/ %t\?|hQ%sit0j0 O0r+X ܹS:E 2Mdd=^y\r)BKag*nGL` /voH|<ʻqXFM.9R=Et۞Ъ2 .fΟt##0 NdNVb;&Ea` ;*&>L5[{92O´5U] ** %)"PrU.+n,[6sPC&BGYG%rDfCb3O~b8J2|qYU&v7$;I=7G;} ۋDd6WC H\ t"9!;;b?]n٪c\PnVӎ{B1!du]p^0¿]Tj_bڒ )0zOV $faF=Ok.̣.<#6W^z*ga#* !YIQꡞșYtvC}=cȹ? Oy؊ƯݱnbPI39H U}l6ٌJںEW(Xj6і!FXΓN*sjc aBwJ ј:^{n1H9OuX@tBM e ݉o2Pyh*- ;]~Ibݠ'漯qRw {v}vǝT:7*{A K{Ou-oqy15|1/Yt*! 䏢3 rئf?s-iag )eÞՇh^x,bM,W۫ab{8ZCi2ZUﰀtGp_ |$ +bCz:pT]v%.t_cgx*wf;} #L;Ё:r_Gҟ-Ѱ0DY@g/[GIܧ,޽+cɩ]]uC_,x\DOS1ykpe"'N*{rx#. 9[35VmP]͚/;kH ؖ`?5W 5UE94acA#5PzlhLWR| Y՜Ux[A_kb!~m0Nչ|r M(zZޠ vRQ;{ *򮸦T; kJ Lsɓ\C.RSsVX?R87x+z)`(F67Zs<^QI MuO66RZ${Y覐쐰,zY5 '5Y"a7'fOk3.4ՈI8 O)a:;!Zoj򽅝53_+[pۙD=XzlZ3ps\Mr}19ޚ n)+SC`{uGۂNBi%$&gl k~OdGJq;0C&j9K6cD5 e+jjm o/р) ȆxUV@LFKH3c3{gTK!ܩp/b꒜]sw-sHO.h ҦXjz&n-̣E5( >#\ fMjJji,Ef?_u {%얺YFHfe fƔ,mfSpBm"FP||WN'2/Iϩ F>,`-\$M8*PtVS$1z_Y=VJIN#c|eȁߚonWًKγO k1{`m9V8F)~Ԃj@&T6c^Ǐ{CЉyJLH|{cb춴rCo[8&G7Dx!ٱ&89qujs2aR& ր-KNް>y_ʘ9ҊOrcmک1I/WozY0Ahu c#<wJ$tG eqhj,+|Q}R%E:X,(q?=iR mGF=tgL Qz:m8MZDYGEc">S73 vX$:0eMWF{ c)f>f`ݧ5lM3̵fe+_G8🍿AԕU"jV=HzBƳF'M巋S;=\ɑ[,QCఌجKaNޗog\6ܜ*.8wC }y 4j֓y#Cq] GnQ7XפݍyboP[ⷹQPPZ[rHM9vy5A"=2S)bFOɯkA`I,_A+~U*S$y帲]k>kVĔd}hۄ§*ՍTnkd'3p\B]i9c'OJW)Qb#m AL^޾KV 0V/kA\ j`IYC(?=;(΁#ujLIv}m?M(A^B˽PLѽ2rxLΣ~Ε/ύY)صaI59YxëxҒ]Aϸ'ml#Գuozi9{ s}ۖ#u (B.\Jj@4X^|$M28o,+[64qQڑ 5!}7t[ .u[];dχO Y [˜3D6NڎJbU$.g7 \}oo Hq:I,'6/FxXjy]Q )կeL)SO4':^̓!@/`+զx,uv'S7c9D83靀 'V`d*< J^`p&r5O #miz5 He˪x ]e Beg*!m+niՖr> goU-ZDjDm{1F *}H%D`us@.bD=1:Vb16ldrԱIH~rCrª}akN B`>1_# w82s8"OtFC% ҺDaY2+ KﻈQyš)?oTx /:a.+/ӑT|2bz!63xӼS]iΓk]#sE,?ÚRkK~{FBv c5\WK{( H0ŸHAA}ʴ) %Jl.H܌8հ.`?f.z`|{^0InzBMYg 9Y}je7?J 6z(( r|WVG:W!ofSuuI%udOϏJb~~Hvg+rL=O%.!pWWmKn=bk`Q'/\U_ 9|g=޶tZr88dcq}sG"K^!'$ +XOQو>ox ,(W`0R` xG_vnvK2w5 0(hm G-EQ-hMug n9_`8̓ҰZq,QV(M[oF*?jlFCWDuA "-6 N00^'S.@>y34L006f 'o91}<#BAWLݖMI/CQffT7! &;CCllCұ;yx'}4&?Ŵ1zrxH%lÔ,FVƛL |P'E Rʠhdq"bR;_|Qﴱmoz9) 3N[ gMQipKdzJ\0}e9iӴ1`\ѱivAј@3bN,є4&BZSHRқ]e ^EA`.,hfk '0)+tn 쨭Qo?4"EBU^*RvULGr|U nSew៹3)Y*P+2ѪyB`y,X% 9El2 ((Kk?$0~PEb{GWjzc:y9 7k*C_M^yb0NS!Sjb` X 4 /g`kҎs#(6SfbP L2ơő5~ r/@H\?sGd O/ٟ# gQ CHU$ 2(-mnd*_WcJNǚ)IYw}ql3UnV' ,0Lj*$.Ag CiFz}vLnKʯ=|+a@.fY^TG}>že1$@w#`ˤxU/|Rj3qoqRf|׷ڡ^P# "rI|]+tc&xQުb4 av{X8Z ,HbTAGe([DHԵ\B-ז,ߔIS74)pQbE .viXe 1=q̰)/L g>QE jj[gw8~]9up̪&C\&HkjrfX&Ƨr2} a)[^N nFf|Š+~@0}ӯgZi[X쒩"6ȎLs` n>m1#B|`I`vh&E.m$i(Qb-DR~:%D@7+@~>jo@MmM\TMuLmut3Pd.WYj^^ 4(Y̏?4TuHx9bMWCn-bމFnJFmz#u #bʈl4%C{S@YTvyp3|]zEY=Gg,3,9l&f}6qdx#j*m3*‘:@!s($sL?BjBТ;FӸeA1,(~nkqaihצjDY 8IU Pj1I]DNYh׽d; ^-rAII,1G!eϪ]'0Od$Kݶ'reCMFyXMFJSu&X0k,9LHӺ8> Mf6S5D@Heqe<(]K-`?׼!(r{ׯ*>"خqbVETp6¬X Fn+[])v<0Kd:|Lϟ6ϙ, ?B7։MMnYLGJk[lʍP{|0b \P9"1+n"$@3RlGl9heB?VȬ6F'+kVgXo >Cn}t}CiZUw ?jq+,p}Y/vhxyG]>(OvDLN+8:IF10c8l}iePQ̵6l2HqˏEQ՛jIofG;4W>'N/LN**|ƫdm=w "Kj R+_ێ4_۴٪Vv?Hϛz3V=8zJڸ4/h.wnWh%dL YoF-گ9L\ -z0zB_&Vs&rY(9,t,[);&2b ӇZg. Z=A6;cDGg ܃a<7cJwҲsMPi)ZYqpEwd Q?FFڙlt4U'wa0|L*PVm'X>ǯ\زK=L2fŝPx'lhs. g7F3  M.e+zO ֆ`0aS(oT˹7fecTf\ֵ:l𾸵-+cm@1[]csaq]@u-UG )i*l5drF @pp[=JV}ѤZ.9N_zd݈O.y`hX2psZ6cVTo05>ӭs023 }rFV0~_jVDFO[dJ &\,{3 uB z<8n[Ey=C)NvT*="eJa,x~Q9R; 3au6[1//i=!ӅJqVT!B)|C~͊l\qav#ZY! !H E9 k!ɜ>NPX^lVzL>i}!!;hO%#+]ǔ}c.xf/d(THi2FVjH24/SU,?8E[h 9z&bvK*27~5Vt31Ly7& _ ㈵uU|4;ޥG\?r|݄4,uꏿ6\ڍ 2jrE5kXS*qQa]O,+˓*h 3 6}Gg.kL}}?Uw ~nwUMNKo2LSr4Yay oqdYf7m_rmt>9n9PycSdswX~+2&euXX0։@v#JLx/4*/b^ijɞ 7 %[5?-OkwziCg3՜T vN!·&"G~'Vp+:~+Vs@?5?t> XFbzAs< 'Xꅭ_:e 0O '.s$"{Pa 6VoB0/Egt9N@`z| yQ. "'}XOٹ`MbQ<3ߵ:Sz}T72-tŃehx2£_UH1aާW6I_l$Q80''E?#]SRVz=Ӹ3m:`'1x[xC& gNfǖ>U@2xux9Eqa`/ I$s ?@q| Ja`Gy82}4I86? Ee9 YX[Ёɠj! W2p*&,_6 =9k&_ttEv$-vի3/ꊑC* =9>ffrG^e}-Q vm\M(h`|T>O^$nX^H5]Lv Q,}lE2cc1o|o(5;Ty2TХ`>)x11)oG<82mY5)},RC}«M-DJԜހVG~-C.ϚnA.WB|޾\HQzXDnkUo%W&q8zP8Fo⡋CX"ݼgWkdS]D_H h}i4돂"+'&3f[7w4h-4`$sRHTVUՀfam5 [dɪ7Bᩤa!x\LS+|K oȱ# UFBCޓ$ ]\]T":ezMm"UM":hp* }m~I,1upҏeI9^p2 z0R~]1\u(F})?o&go.)`IvŽ# Q})vJ7adxi?ٵ6Vm%}XRs%VDLMgO"0{~ vzj"5J{Exӯr]r|y 7nߛI5HF46ؿe~z%IHZ.``eD#,EnWьl>a%݇˾Sa4# so_^n3uiu҅fx݀>ٳ=lh/A>o EƀCV@oj7`UA pIbG 3ub[z+Ò8L qZi|dj., Šb@df$V=dqnI\N3E$$ iI]cBDdO#rȋN hMvT-XS҆P[ ~6}cU5aWЍ~%/{ŠLMK6$Ր,H[ԥv3g_Ho5xN fp\l;rP(NjnR8ogS!TOsiwowٰT:HG{;"}>;[tLIIk.f"\7 zf;)])]_C>!md{Z.>xt 4(*K:-PgRJ `@rp#>cM;+tӎ갥3MzE=2M-`(V E31!ؽZh Vvd!~AjLz~FY~@li\0H^0bo\oS < O"ǪiY*Gp `۵@XY ..z?''L] *Js=8/*Pc:81 GIω O "S 575NYNAQγG{A2_ =y3&`|5>oϏ$ԱWy_eZ),ESka`)GhH8!C2HV9 E_j}hk?ڡ:&aB5ґd\3L-Oj#NKO֞wO򃹆Y+`MwG`&gQ!n1 $7"3_٪$e+羰4v)m@-gsngݫzJÿ-ӱx휮ܛwewaY⪵|oDQGSGV;&GHڄ~֦jOQC!r9T%Ԡyz^[No;2k~aS~'w"uq^V4v`1\o@^.Gto66ҽTU<)U.1s5{|TfN<*N\ aϿ䔮cW쿈*VlПW݌ ʾ{ $ MnTHem~q1 5v"b g㥼Y'½#KSÌ𤛉a+ 'B&3ϞALGI-wYG̕&>) I(\J}{c[ %f,f:& vyCY:pL;$2/p7^)SfmȻ˨s.6'&6Ov,KY[MN!^]&;f /kmrЩ82S̕\3#P f-U.ꔞ;-zLã߿GKw8уC]HA@̼M!q!4bA\-H*eˋhp*UqVIC{S,}]yzҏ KnwZ.O`gIĪ[['DNr5,5{o}B+ZpsWbIJO~!B3OERiѫ\xbZMxiitY'IL/PB[]K՞`Y)W ;"UC>n~h4@h08zoJڂ>ݥM0 2zWh|;  ),}4`  P2ٯY8\ل| r' I+p6ݳARO 'wԒؙ=];?8Fb6o Li ryby%c҆3߆M2Krh!,ʑ X //3{sXL[+/OWcWj⇤m,F..Ӳ~#~\$`Ulu$LÎՑ @fa=K7dM5MJ̌i/hpc֯8 ]𹢌 ܍TO?U iAR޾,)7m_5c}L0׾K}lV`V*&F sz0SG7W ɓ^#us%^(5YiXWy~[*gBȞ1EtS\U"|woq aѩ[޹eUFW0/Iq6fDU6i*4,o^C54TUFW*VP$ӗ; iM05] jo`6^xmDZ?N>=wDJ孼yb/ C4åb&VPL<_ˡ3)'U@8қ4.06*/.vP,0K*am~_Y4(P̗lp,7Lo{:ml(HGv XTڠ8'JEYo1!XJg\BG%SʴEw.YCK21UO^2ΤN L?v3739 _f4yȮ5&Hh=T`0 6.R0YxKHvV@ |!wjveVk2ٜ$&z]Y2B*މ(I=c1Qڀ>F~L)da oG#p8,]Rje"VhOCL8oTD  y ÊǹFx%ux~" 6 IVn]4+Wdȋ:A#Q~mɇ8+2uØ=}f"6kKtKjK,^`RLKHwbY|u"ť6NAT#%I ƗR5U搛$L4j:}_4 Ew7eZ40rq3@Bhӓby>2WGd u-ʦ7& _-x e-APcƎV~⏵z& XQr)#G3 {DMJ/ +V\ƐD ([%e{WC!l}fsU-ETsx"M#v$D`Sۻn l%^tIǎ#jC>E7в[/L,Zw#Dj O N:qy"šk/# {fαX ` h9$Dz9I`W`/_WmP񾙙W~( qف, nc恛wULV#V)I5h?d ?J\xkY6In\n3Okܩ L)vT$i$sH4"iKl YWVJlD s h 1}l8c9 {ߙ4'dM+AD+#32"8ʈZ]NqʨZ6tG()I#& =9Bz*ZǴ!Gm-a+{$y ɟs`'A‚%N`E#ziHrsBjOAkJ(m.gk*D)"-b0ޓs,49/Aeq"7 D$Z2l2Q0o {H>RCV[-SĬ|'H*{%v7~?1NcP̨7.iߤL8ٛ@v:}?x SmM9(R*H`"QIjKvҋpޣ /.|ΊlG<%3{ĘmT+s0-Qno(r 8yga / C*uH!bwf)"Biͺ!qSzx4#?WOXSЅNBDL3J {ľrW7-9K\x.p Z?aY>ETJ>S{R\blw_u-hEٽ-z gn(u -E 7Mxܼ:(23M WvDk/+ 6|)Y]etjw9BQϯ5ȫ<|ceΜY`!a✉,/wF+UI)xX8dz} GTCB3U+p[- 0ϛ^2b8_$L}5cIGU&A8燳;[{z~%Þ 1_P خ^&C}6kͽgrL힊?FU00[xΖo'?=[P`m`T&%1֎3GOrLtxC"(Z;>n/[@\oP{0GSk!F&EL ,=6L"S^q,$u |KVaYltr*?SDCI 騖.fWӃ_l1jTϽ5.O DB{G5lܯlzx +켼?Ϛ:x|o.JvQl[{ >P|_TGEw4V4S&*%2zä@j3'c2v(r2 qP-nGB(*B18۝`9ga.=mE-8}@bN.~ӮJutt ZiS@> jv[-_<Yr߫,* 4 Ư(X]FK(  ׀A_d}Z[̏iJ/v7 Z"(Ts 0]~K(ϑ<jmUΰrf / [#ܤ $בewcاg--Pm]`BONӞgxBjN/ĝesZH~ҥF" |W!וht[CUT9I&3/fmF;94C2lS֎>v_,NjVXMv Z21n/'-V}gBxLE{`kJu8+I4gt~5$(So.׹mLĊѤ\˞FZcU  k+Y@o0ʴ6 %Z獠Sz* Vz'7 ̀Z4c,i$bO8mub!MP;G还Y5N|$:qGoEGW1 JNg%hl6ri:7{᨟p=HY[d(f#W3{Y8=Ga8D@=R`0w%Bو8lzķ5o.zG;iUsխ[lTKo 6g7]ݔRoyD Bf)X;d7BNV~He?RqA>+`D ^S=8`=-E  k]:;D҃*˚/s&H%ꉦ#^f5`6$P;[jKNͱd"ҽS*nC4h7kD{W[S!C×k.q{.?UyH Թ]zt!ZF3x$Mg4OT_ry܃sT x⺑A 6,θ.\}m0c\$Eh +>qNPTjTXzY]9Td$2u:͇#s+@:3_Cn9|T/&Q 'K,0OU CaZY$c6MIW&w:K9nrs&mSt>[zR\%OhANK@NiXmDnJ_N7Zb4b:1}D_`p g&v dڠvG?\H*$O.|ft_D|1]"?42fzxغ*k3cuĔ *~M 杝Bwi zE3A\#QUvOVT,uT,'Uq6qv<&?0LT{>[C`"`P(K=j!Wj6fhSADT<+{=~jM{ -C&uAK`o(H 8fe(.BF:K28e :=,Mu(@ɩRLkrֶ@YEZ1HkNaH傐#nϷ~bP)jyGHG_\1m!a {J8 Jg|؀)Yh`a?D$[O;:^B z1A<1*WBe&>Zg\rălhM  1SNr;UÂd-~QW+ / PK-:$:y,رWx @CvZND_fn>O1f} GuZ9Íw(ߣ(4c;g'[ϡ׉=>;zY닣 n<ĸJQ+b$Ģ+{~hN<;UgS4g^#HSyM@9 e YC[_dƨ@h6}U`2)ގ4W#QxreDg6 *y:n&ŘfxmXV:` =#syQI 9Uc,I~ϵ1bxZ7 Z\$ 7>|~'ŸFSggP9eW?(;ECXc\d`>tM"Q40|)H\OމM%(Ji*7Vr?ߍ1Ը| c6''n .H-6 ,m; !*+!LھşÝ&bЇu?t=c:7`ymJ?b'j.vhf/?S{Q4TQ,# ȇO[3]y3PjYRrt>G)񢦠  ߙrW4u'vVbA| y05rk&~ +~xGL?b pX7nF=d^%6%RȁWsZ38{e~5Ҋ=J)NBl+eڅ1utp_¤D@&#-ڛěJG,ä SC-Z>!m ͷT ǧ⑖<&(e*2Rώ'M&l %){cqG.z `_!OSe<;9A52tx7 &.:i0] 8:EZ+TM/XO<K~3fdx x9Ab-uܴST[\} S5%'&S,2Y]?Xϻ)`}c$7yjj_1x΍1zi^Grٱ=])*az6dZ_`u~M )\4ղAAѢ/:f5|/bvnhc[ަGR(wj 0ڳ,zgcT=GV+Kw<) ax>f}42 *ӈ)rVPfږ , C3:oI?m_TQc4<'D |7WWnnc{3|2%jZSKCv'I#_ڡCX;CP9-lo"i|@Bu<l;jSTGggK#Tm> ۗ:kTcAcSGoamQϋ56"]o-`Շ\`~Zlo?8sp;"q#"jK5Ȕ F]drSg&V= Jѷ;)!@)OjvmNp"p +fsdnapU1-7-f͒S-ĦMol)۬nGIG+Is!ҁYcF8ZCxrr *p#ga~61p+n8-/iՌNXt"aK qh 794_\Û+n ]"6J >փ?B%E= ,:~ {jy]yPgT gJ"Ķ-wdԏ~*0}ذO)h5™O? qW,X>Ւ..W9,= Vx.exax>Xg#Gn-)V>;9LXT5To!j kOX!mv!~O\.Q_Q$@*Ӆ8 d4Ե^H S` yN"ÀitVŀg*rt`r OԵs >$f}#l}};Ft@veAjX\r"$G_S 6taU3g-XXKh:TyI\bC<*;3lr=?ΥEk.Q49A=, '] [zСն'+d՞Pe0k$qx7}ԩ%p+?vnbEn#TŧJUJ ;$F82wQo;t6:QU_XLDhZm 2d<:6wP;!3œ~p휿HxqO8۸.(i*'ݡ$8 Smx= ]Cl0^VN(wh+*QPRp?V/֔eq^4u/f4.!iPOh,$ d^\ f\nJP?+^n:{&P i}I t'H-i?N.$t'"=l]޻qBj9-5 a0#~M `hX̃nm~}T X-5ˆ}evdL]Wq7ܠ0_w GW4zZdJ4B^M֔p oc:s;:rgx[B>p]h\ɜw" oJZ+HdDSEv3"n)ڸFIQP;4LM!͔ :%.9g)oA@o Oi,)-fԈIo)܌}t'~2UlIo\7IkLÇ 6Y ѺCHϣH6cP1>E o'ZV G!`z7_@Mt1(.ncxLj6+|Ucx~ Q)UKHYéx곤Kof :d 5J,jPҜ+تQ7N񠲹L BLXánN! mWtN$ZbGIz] 닺!)!ae !C֕les],t4XRqw d_rV_PG\I}qXoDeRM'ǑʃnCY0Өnx\#{NȳY~Zb$^3ty:$V{,S. b*D[RlliKy[bp7%Lr[(fRC·.*B,!ꏤ^ҍk(Ab52$H%fP,%! AC3HM㳍=3^Җ7U fpPE0 c)ߙlW&ovy:k'H>'E x{ p]=@:H0nJXEϦ,IdqDIeUXm:Y}_*6YPH]&"SiH,4;ϩsQY<~׋Uu8nݰh*~.rq 2@e'#/`ɏ~xV{ܷaO @yC 1hbώx*ms2H^rMΪFm =bGzhu6jwtxUy"шy&qG$ /*mBš2ͬLIǯǐT.+',2%<}sX&)vPD0Ag3JNJmrX=w~L>JE1:!_rV|\-5givP7<$GqkDk`Ρӭ&aH!FH0̼΁V탳5 xdNuRTu Z&: \cEhʖWNs2+ 7Q"s]1!l$$r-%X=N*gm)}T͉y|hEϲJQs{KD [)ܜBZ1xtMp8n2JʋDբ`͇k@sM1̞YYxHMSZTщ0ke0^޵ N*_WRl'b>%tN&hZ\xë\P,if_a>{ ΟA.$R.#\~PK&@=5m.A+撼 DND.W#|7A=ҪstCwʜ/AyK,7܌}yͤoU %3L!s֫ߴ=uL3 ŇAKŦ\yxt8rUz65rt Kѣmw3V<0n#mS5:K-J73ş{`p4pq '<^J h q,S- ze|2Q(|$Vl*[xSYen,ʩHV\m2Dc!w? rBuMI(n\1lՏXA1Z~4N⨗k3.qcR1ZKHMf4kQ1Vw<+ â>GLߴ6tb.&Uj fٺ>WBԖbOh7>* %jd] L4d5,Yf crAU0x,lbt0քegujSǹ66?lL UĽZ=:%v+]Bjx4а^u?_:vvTgblAc7h[0mBG/`en)>0ƿ.0(вb-`Vdr &'\g+pցKx-B5PLG}i2؏,:[UTڰ^ (.DPb[4X! 30K^Oщă&I! -= ZωiWѴ-s~vVDª<4bB+`{ F؈y,l0'{7?aqiS{.B4uPiECb^W*ؒu<`~B*K^o0;^%^9x0yѷ(L_e<7f.bku47z'.]021/$ teqdf)b9+ַ}YS-Gn}> n+in $sa3_sCBs*4W !e0e~,Tл>\*٘0Ϧ%vVȪ= o_D /ULM h-^h>yL?5=K ۵B q>lȑ O*q ٹXá{2AXq.oV3sihK͓Α EX =v 7Ӓda-SLz$SLm8UqɞJUncX:d#"0N26a,֛!˥ZK:p>@kqqOgfۉ8o$LL鵌Go|;e(/8'"GIX'_Ap ƶG+V;9Oyd&r]ןS 1k+rqw#~)n\]mƮXD 4 ۢj""=$UU4~&cJrh+t(V);<=]l88}Pں)cT7^i%&6\Dr5kpdG $gz6HsgoTڥ@[tAǀy _[֟܊-f<Jhn M_.(Vv&uj0_ O QP~J +APjh3ȍ>R6͏BAp -cn;+QUUg5*Aބ3k*0e޴ zCEriޢt>otcX?5U`;<"+Fj#alwY+/\G"ZBJŻry`63̩vʉrȫJQ2+M9s }DOȵ5g/, N`t6FL?̖fEjm+rmQ@^*1eagH;>o^!y/&GqHSȁ}:'EuqXk@.pYl\gD(4ɥ؃ :4کKΛ\m\R^̵F6~c5*:"OɖHks9U kՆW&7JW{ag.u X}h2Mo3" 713"UG |y=5J20=¨X *WPyd<2B&4j_{lpPCSaJ3F1족CeGVac#aq;p=TF';ٺY'p@+HsֈW-@U|hqӆ c@e/96l zfebaMpþ3̾n-l} \ ߤϞǏ SJcz( D Kyܮ|&{vsʭ(e!DPy/G *RQzӸssua>.TҵP"s]..y+ CRTl]~H!p&|=z=Ųx"߁dz P7j0Ue myާoD]pNfFCpa YL#2V^g·W9&wԻ-.Xf7d'S]y'=j J(<;͕ `%+@ L:Pc\esn[t,K}lFӍ45ә$44>1?eM":eaBK'ZU"bkBZgfJ2ԹpY0L Ng +t(_KpBhx''s_@6uH=b:XO$4 $2zI+à Ȉi Q|6΀i?G_&o[tE r!A!T@VUIL8Yp'Bx|67>4dAď݄3Cm״ݐvOcȪI~hd{(1kDwl^GYtPt0ޏe '7,aoA™pwPRbg5+[K뀧JXCuBR*]6 PʯVT8Y^{B3p)`fujt7iEYy@~&r.<[&߰YfP X*xַ`Wd &)uSZʩV?xZ2 ɝ?RȒc Z(u@=(5&zᪧvR^`'uYAiⰐ캠d{s28 ~ %`%\s9ET  I@̎8{g:B\>0Ӂ%KQX>5h{^.!T@zË:vEC k0uj=i8!j&^CF4lO4ѿa%=0Hg(\TW x$8~3TU~̊!gUxW fhgQO6/wgpzCtSeEezAe,C.X=*R#DI^||i؍!g7{r@C@Ƶł2óV[!,֬ux7 {( Eׅ1rdO/,~+N*dXGKGz:~#܀1=͂I5uCvlakA!f;:J, gqƮúT8❪5fD*7-aA'<~5h \1)CRz]X|geKL85brraw9Q'0.e#7`WaPuyAXV~DF ˄e=>\ͫJ3d!-:fA3=xAV jxpLe:[^\ }/,MUKŘCWAI}XvԀvp,{߁,4m (GPiQhd5@HZ?2i\N50߉ sX6|g\5LTR{hF-A4kI;N3 AY_D _ЗAKkʼ O -7aW:LCY''vFU_EBw[vS:#ǖiV}3Q½f~ XQ1C.gP$(v*q IV<e?7P+Vhv 8[APձ%a<B9^lPKb{DZ$z['ئ*qMBi6G)s>sf\H;F:((hǤISneh˗0 䂄+g4ۨb!iUUN%T5>W $h3>B¸)`t{qF):F^f%ZzW3`8]È^ְjR+4#J`%?L3]7K/{Au%^J5eJ3ޫ/=ZLvYC2#B*GX4/3#ѥT9h" g7PQ+ 1 R>@)p*c߀gk ̓Q&w4)G*Swhԁv"MF]40^,kKW{f(d@I~4@Cjd™]}AĂ:V ؐ5F Ϣ#exʳSYhjC ֗`C}b۩m-]xћ@6]w>FZt%?e=žo꼮*otLWCP#uI$n-*0r_q}G}g:ێU2K Oɴqoҵ'DS֎ތMzGlzܡI6`x2HK ^3ϊ;ؼ%c֣Ag[g0@Z>gSy8g.F~D_?vg4 "1<n-;虅}'2!2q،ꆒ䠝Qֳpۉ%p3 ̕fd}F9g1ڛ`hQV׎~[)-y8R> gD^{ǐP#6 Вq[w~+Bɶ-mye UEݙ6YToB`P ~'T«9 m `Aح&qz}H!y.Zq5ˢK x=WZH^64?Gbo&z|-C ˼+Ԣ n H\Tle0<7T\Z!oc,!LLgC?,3GaL=\?Tj9mrMR cY56EvЭj~ ^N ]͇x9\"<#V6 `E9{Wp&J!ZA6R$}StH o!O|'=^׍WU5~U#fo]m-t.?̂>HSCqnLmOu7ThG) n29U߈udRo AU ahF:+z09Ņ˼M<-+UO]03Fj[_HHn7bd1-['X%BPAci|7ҎU9N׵ڦ55[[6_aW~Dul]eAӱeV:T;ȧ/E`u^^MO ބU& csd؈a3ƔӨ.\Gp {(x%ms_] ۑ_82eH76N{t:b2cR0x6zz ?qۨ]1l|# o_61cs]u%\Koܮ"]ʱnZ I椓9T*s˭f uV&%m8F_?3. .lyRtEoD-ڥ yHƳغ \S\Mr~oT5 n/lyyH9EnҐ+;Gt~0>Jd ]ZSdԾK=C_P_!LSwvNLO%0*&-0"C('OǮ,/18i) f{>1sI`kM,>5@Vo%vfF/8QtRw활G($T,/T4R jV kc5dMr ō-oMx: X;yX%)QR=h}XLePX0h> n[&́.6Uֽ3SI"N>=2KYE=U.1Eo܌,Ъ:8+;W阙JϦ!rݥe$`v'HA6/1KJÅwA`YjԸNzg.s1xqХd8+aT I&3\d"3УJ=J q\&'45|Ko6MauE@IO(KLWaݡz>4\17?PFimÙӤrn.Ec$%/.%Ð6}U/>^CJOg念A+CFy|{S{0B <΁tȂ˭$- *:>߀or#UR ] |"w.+)-)S7εM7 C--k#tN 3MdqbX\D b8ȡv a9=B"3} |`h6c0(WGᬕm찻܌s~i.yFdl uOb=鑬|L~S[LO}5/03wMʒ pY^^SJ`þ4#W:dF5ꞟﵿ}QT> {ҔAʼG2nV_Vq~1NEȧȯ``#!&lC|N " $ \)})QD߅܉P{^^A*bDӽ?yפ{f2C>8dɰ gtZz/ 0@ eknC*[6ddZݥz!6Z'BmBQQd ݌.[AE +Kj<0 5iss1.wLliB.o2w(rUB o_S\BԶ#h9*}ϠB#z"VdqC?%{,b'C6GG9&V~"Ŝw_mQQ65/FndgnmZ'heMb>ץ5Gţ𣨡;0x+ .UAnu)8U[PCFejIvra)4Nء%uVe5]W=T6L?M}m;:d.A$u+ K=$"z6MH9 ?p]Č&Y:S Q~/=c ~'v>hЉ/vpcg`?f#f^lga|+NET&#jF03g|bMF4qb~- {,_D+!T#L=RY"1'cm-]$ 5(2P>T*9mN  meu?.K=,ꁤugŻ[ $jf&pI Y<2"6͢Ã<j᝾bFwsZQDY?r{B*{Ub|"Wi׿2LOw '*ՈOyS{jojA74D%c R+F pHA~alW-Yla,@-b&s"mϋAbfԄɢ9oC{ɏ̨݃3R% LJqzŤI%6,ZlXA%SN{'% ۅC |?^g ?)J)fbR,e0~NyCnS[63u ]{O?@peBNw)b\IlFΘTw )M'N-V-E{z06?pɏGBrEArNiEǧo&8A{,0;%~uکve7.j08EXM 9h =*^Ǽ_sU/3$"R1Kh1Hri-*Pp/T:q.*tu3*6Bdmx8^Q "Ϛpon'6P6kע_hhU%ʃj䓷r oL9<_5d\Hp&/BBVyﯾ]+ /ƈpi` 3SAڐˍׁtd_BbF0PN=auڭXFAg1u`;l ꪟ殷3k a*fx¹20$j444{8mȔB=ٽ 4k]Y)5x!߀g~ !#TK'FǑdsݚb`uu xo^M@A 0p!GfIkǝ1H=4F> jMn H7˵# {7vn_҈з$Wzs|j 춓xOҡoG)荓\Cnqm$D{u- $?iIF:[W}0u[e'ad|xy+9+m'?YlNfіWO"mN4kWk[{ @1^^VU)y̝U.g;)z^Xk(yTLЛD2m&K1_+Y $h|,-5Kjh٢C=y 4'WCiPNKXlI訩%|:¸x1bEmd5<̏0BcY(nik6%*N).]"r8) ʡp'ar.)kđkָXsw$,3I'{Ӛ;]SF}6@Hfdy]'Pwbu?HV5.ƙVq_#5Ø-H te}&Lv"qaL $G!EM< HF`?ѻnqH褗 ӽ;%䔧)B&FF|ƊTح$MxI=>:g?+R\t e[s-7> W(-L12^SLUoZy.qؔMP܁d6$@t%T9Xv%Z%LDpPϽ\ {ed[i>;?Oxp Sl y%iK_E TdH8VO ^3%xϪZQL5ɧ{KQtW:Q%?lEJ{ot?< d>N>C^0AQaiILs&Yї9+m>->gqr5!M'S;K ;QF'tIm]ܹ Gm46TiF Rrt-nj vψv\͔p!`&e't,)V|BU^`S3?b# ?KH' mwM˕ "lYԬV+)e`;,$`_Ϙ]\swU~Q nfjFjC&4 m < ΍ĄQ7`MI+/z0`N1@x~輞K-sȿ/<ڦIU vv=4Lٲ(&7Ldzb;Д=^Aխ ;ybY4?ᗟ g4N?uXD߀'_V{?3l7X"9_FB!|D$S r2F?QaN#3X3ޢIuzwIz,=oF4d/4.!RHN+r-KMU0Mcd`t.iϢM*tLir% 1-a@>hauB.AC sd#3 Nr>D[fp$,ȃ@tw @U~7鐢8í ӽ|8 ; ^ڻ Q6֍{._/(-:'NJL8fq cM׼oiNk֍XlK9Ag}VغVuN}չSxF;~3Q]~Q; ON]L?XV<\ Z֥c3um(M yKV0H9SP"<n^?M'|t BWγZUWtv}d¿x  p`os)F|dNˆ2dSHPb ; %7K~c 6]rH[^EwF}x|aq?}^w*IXLZ >i8a^ud*J;L^@=("4||U'gSzu {fK+ɓ{6e3n5Ml^ 4)<2.uROAkV s8? ^Cω%LbAc E SV$**=r/SHRV}u[aQ"s$MdyGa]-j?I#,(GWka49J)&Mc 1@T Fn`ώȌvFx*U釳pX1'@gzm=!Ǝ Ի3z J1aLߩE×c E#滭3B֩r!\S'CM3E[&ZfukwoC|):aJV~RL&ƇQ_Kg,7>HJa;V;}~[Iްנ}Ui1;?4 n8.L %m}NmH]g1uRz6O6 B}~EGMTxeAb- -!pAM$/H╄LP|래HeYᔌMGsbj )^3@ޘ?Kf kUZlqj$< -ZXS_Gʉl}Da\1ޛzd؂>ToZYO}P=N)j f#+QDN6-xs2xu޳0tAg9EJK-v.ŠŲاBn:h?[_q'f(T.:v/<0!aiLC6V[Q%#Nr,Vf탦dGEJY,˲T$P*.VOu~w+.j͊YȎM`z砐CFھYWOM ήjF)QlwCvc3cxT MXC\ϗ{A(=Ёm )Ci A(c_{ 4LB;vr;(kJR:Jc 9Mi@Vn/SVIL6ǡs]컆Mva?eZ.YMW:Qv=5y#p a0 bzMgbF_aoy= LNȨ~Wє+]p=R=`o3)Lu_4[t|o_35 jPK^Plf͜?p,< _DK5clOܒץ rAn% XBާ7jGƂn^WXR#Bx|#i  z 5 GgOz]u=cX1>ef%o1M+mCdo["!S<!{U:K0?q=BPBO4xUQ&J:%͓~!ZHRgְ 1Y$V\,TnIөoCn4dmkVీO =2rɎ$FR'ɶǓRjq#oKhZi ΉHQ/v G&F2J:\y^!#NY(8[fp#u%ۯCRW6!=:9 ȭ0_KLEe Wl{wj =S pgnH}/nR Y0`5 "h3}UԊLXM:DHP{!GDSGM3;R$?UWT^L12tuݡj]rwEէ^ ^F7y{5gtYP"o}ޢ8MT3zyMn~S#=(DǙQp|Ѕ 4>,nI SԤ_At踐'$<{uT!yE/Z: D ľuVR[R݆1C 1@t|qbmklwnLLP7\>s)c4:6c#%ȁmOTثYXѷS^3h΃βyf+)Hz97(vlK ͋&A*՚p:$ԟg@l4?_ۧQ'#"RY=2쁃L\||jlƖNx=N/=֨$.VTv 7JCJ-q$z Mo {i2 "6X8*)m-ZvfuzˉF ||TMEwUFf@l:iwGֶW@`ݢދ !ls'!)SoiEHaN({ \6!wV'!91U ji8>>`^Y?;I>(~wG"}k`#Q~h{@gg}n/P+$r!N^,aE ¥E}QsgAݼJvIiVB#,mm}Dpy&>]ݦ͂?K-*d5{/r+%R D'dD직^G0Q™7{VyF{}~#2ȫ@?Yƈ+P12H6.}░VNئɧI~G{D"CʣQdPG&u-LV;c4I˒AReWG4rҩz 'Il=D;:FcpKk)/ (;HGu4)~|AxĨԄ asXoH:RBEd4"Yl7l@O[ˬi1Q#y FϽ37b~Y4^)#4hfT /ueL&ҹL~:r6Ceɱ -D6l)(px *St2 `ڗ6 Q<&4 cd ~C{"A \PuiUMVC?u=o("sLRkC;>J#"9t?vp 2ҰM 8yDLǁ۴ou' XOGJ`y-ZDŽOF/zxIޯ㷏*6Uc ZֱV=@%=@,p3}8Sj.bCTnm}!F{gX$s}7FZ&Z1!+NxP0a૤?beFrxYAt J:y[mvU1d]L伯f֚NA7 )n$\F"Q2ϡïr0m\nHռ)Rp;G{ȑj!1jRm,B"e!tLJ6Oա|sϝz%vl#L7PDMpV}D`=dkL?v5T5$%]1K8@>O#,h0^gb; ovU6 d,}MH޽)nY0mK&7ً$GWV-(yxŌsdvS:bSဲOGgUͩMqs"Ub"P$gu05vʐs$Om>¼(UXzta⍙e< 98@6`vqDrQw8hMո9)T4a|۔Wedh*@P|wծɻ^XLK{yf.6(gTjA*ސC1Gﳡlvh\RQ+#z07w5YD ηNWiy`KM̺4:ڌH]8вM@nsO[Iޛ^"II{Co/ ܢYa!m7z #?(QVVV#ӣ(Gq#sy qcb˩h=D6E)]x2R^%$O|W5>Q}ig+0WsLKG.FDo,zɏȇ9$!e7KdV:uACj?#N<rYF^J敎ib[o7!J7zd<_\;|NkϿ^ jOt?u0xR1qC)ŋga5VڸV>U!i+zi*@e:>buG+E!1~p[Dx;$ &4Ck|Pd bvܥe60e[qi?y,qL%3a%GQL؂6qM(B{zMj(уcIbXfOƋXdim%vX:s[<Rrs<00}Vjx{N 12y2WQ|Y tBݳ@h9j*#^^ŏNqVw:d8P,h&&qÍZSCˋ1([{!f|`ķ JJqyͰET6!kD`ʣA7 | m+ð܄rßL{lQ0|W//6yj ,Tn@Cd1^'drbU3j,1hȻxKI{Cb9'W~/z𾍍)*cuY1Cm2z`QO0^;3FS7,C'H;@M'ccd'$L/:h(`óśߴb.Y^C:T(;.4`,$*g_4De eMȐx U+",d:Lh1*Fqt88)H3DM3~ gyR7VXE?+"Lb~Uɤ|9u(iBH=EQC'T?2+:T.y]ԇBpBD6rRe WE::E\NX@O{(:Jvu Ab2  dI&k멘.=ӊ&t|ho-F)`@qShW}j/kycrթ uq M{?šo33ӷx\JJbgFV!OΔ/zmx5bVJ|cYђ%>ݣMV͞tJ@P!V݇'b;_.+YVS]wƬ)V/m{fbuQ]~%yOgFX219@ITjT.>;h mMHb\\ҕv !7SK,d-)*|Q]xy ޺T 0 6`/cڔ5` =|b_?c%(Yl=oG.^D?W JCe0R2]BcpBx#4ʼn6Xɍ blI,# "z-=醆2k|Ց4U329iթj,A?1q#vZ/B}"~GJ)z\jXVNf1Ďf0 gs6gzO/6)>BKqxNta*oowկ6|sE]4n^y#&.D 02x6cHn'D KM֯/Z4ZV}ٟ9n6lPZw,DVo/ϽvWo~bkSʵЙ3﷎PQQ0\^GUNDULɕ!t(I/ܚa DF=bh5᧠=:=xwG;7(*b=+JL_T%N?BY:TqH-ʄn6̫Ryg]TM+n HS~+'FV9^Հf+$+!ey.9VE>L^{1QNg{PE1Y1N桻zaUtq.#/nCL=oc!ˎ9cc-N Q(rDPA`vX*1zV6:JVvb m(䉢3to$RO 2)ny,Hӓ !vN:{6^wK<5tɵ'&T JN@nPɍ 7y4 ҉g\qBՇ3m͉Z$2NdIĎhcRxL8v2iK",I|nTk#jqc;90>뜭sw#>j@HRR'rO)0HтAVK@6{G`Z)E{1qP \M϶Zyɳ(1uQg:CrWW,HJd!a7v[ Aޔopur@8ڹWA.Yh R`N ȧ3|Y*GOc 3,-zMYqtv]><^:mv*)+33'h *CDȒ'<"Mpꄅ/yOQ辕b?&HX mO$F\n@dKҁ@B*XȈrni\ u!{)%0ooJ;smy{ErCp/|tt.}$`xG蹌V8p9Z+&ﴨŧw!UI*MteLc[sQD"Oa5*qOi 5 .l$]`Y44_|h/臡FNOU{nQ8 ^#?*Uj}ߏ* |5T+)[PQmX:6p3)8XP%F7aEj x p \%ɱ/(ݹ{01WÿKDŠZ>^r &m+%w {)=wPE˔ikRTn&7×]U/, .qr{@H]RG)ͣĴ4yȌ訝we z`3[QSg@A 6Vq)r[ 4\i6>睾-jNYdf5I`f\}OpDn%^hϠٱPX):!.Mҕ]״񼤗g㧻ȔVQWrI a)\LbǼ‘fU7{R?aK~V>Z "}Gz$ѸKBƜ#glEDpcQ2/}*n uN;oX#} 0^/liՑ0  i[Jy[ pr~ wZUD63+'l BܦY/>/d"V8lzg7Unâ~юh^ļ >^NIJ"0?;f%/fɡC 0'A?JJ0϶}g$3'pet< /`t)Ofb (7w MpH6KSϒUXT]ˉm(D4Z!#{6IZ^uN_T ,!;dJ'>/t"Cq$8\jCLZx İ>]0plbO! q{Dl@${ǜeҝ.UWSnQ9iL3WMf߬sLϛtϻjZcYQhU IMT|h!r껋T =m TW)ޗrrǩ4~([PF%MRVMp -mK;h7xKI Iֻϲ :5j= 7%$DTYɅ3,xb@b%7CEx]Ko4֌-=* f U҈hoF{z4$<eBy#FfG^d%kK9H<_0K99}wc /$* Λ9 _a} | hDh(i΅<&ҡ71.0klpYYw~([5zeTvr-`Ij+2*J[b?H:UqJs|ټWSoTU8e\`\$Ƣb8ͱ4.Z}kW9%ƭ1188 FC&|r*O30#FG]dt&51*cyaj+ச.ђAyKeUT8RWP!t]ƅ0{bF-Sj+Ӻ| f&X:%? GPc7xik'YYsq-K='|㙟2cFӪ'J#ψ}r/XClȤ0V䐱RȻok*In+Ż;6|G^e:ANPl3h;`7zp]cTbC`L~0,8w0v4*=/@'>s,Hjo9s&m` 9jQ+'-Ť3m+}dEҚ6z)3XkI,4fB/{iJ+YTE9wnHW򜰣6O(wɗ);q|gqėRFr7M7ޫP/q·6/q.>H ÆaApcRMAX0&oD46KAmK71fZ6%f Bvi2 hus>ѣ=j\P\~32rHZmW{6wN/*D֣;N(&8q2nBoNfc%V\J[@ QH Ƌ,c^iaѱe:x(`$tɓ9U4#܈fǫ(H M Ga#-`4fSbdw/zO. &b]45_NĚWR, rfϊ ܃#c JI+ \Äس?-p#-*C/߷#As9W%]F\a6la.Q#W: O.Mgbо h֓:ʾp8jR3L@"&搸ZƂ0W?v8΃Ae*w؉w&JNw Fp]5j}D4>+GP {A4gC~NA'MjK~uv$."dgwϏE \x7+B V:JUHMj")Kx~VU7iJ0 ƝfZu4LK/:'&Ó?>)*Hx R'$pȣX}O%ӁWrl@MT_4Hi ƗKw&SluI|,7,7˺/<~(.z~uuͳm]j_mԕ @BJ Fɿ$zKBsSB\26BBp d؃ :+*H ROYhDQ>;fK l @ ܮX+|k vZf%?C̠1}'ꢚ'rkA /Av }(;4ėA /2#y7}xYB=?'zSv6^"sl):UT׆̒#&\jh>wDjٕH.ɺ5!1ΙREwx1x54 g[ <on= e~c iwNkؓ36hȿ%'$ .l/,wAyHUߝq E\}w.T,#!(7H5tI_Mx 詁:"ܘjnOGihpcYhJds pl3ɰZ?@cg762B'L8^şC Nv|i45LpJgFz8T6i57]H[E?&|hNީI]=A٪lrUY[dq8Gy~QMy}}z<_<0BW7 $8$rS!+vN-i@ EFʂ{ʵxt][&cT~q7<{aOi$#3WRw,!0S 2CKhКp^Gycx!s(M XKWdNkV-ʸ%xF=֑e 8ȽNNjF#ː>:OH/K* \  rOO)`8!oZk&HJYVtWqh #\k:saYDNdW6-NUmp Thrs-Jpx_GKqgir”D=Rɵ{YNy*j h3ο{uRsU~of6x)àdnT٤Mg tT9'-N'_|MY?\ЀP##׆\id:}I`3d/;F"aEqO1'Xs.2 jd1ƭ y F)*g&MZXV7#-4GF\cI;juIۍ0Uko$xV|ɹh%ٗ?6|^MW q= zCoX6cg% * %~^"JӓXԴaO흟BG+` X֏:tf8&uUlK !y-2.W߬%5Pwti" ݶ[E-^''qg^{K CƸ Tcjyrh'݅W+l؎_F?g&*YkQݞ`nf5z:&$32o! h8cej k,FUX6eD]Zd"8)E3D# gSWO "l}!f4A98;5&/%MWmu8&70-`Q]/E؃A,'^+FW/tB15w% r-䷾p]8=d?%sx^y$b KTdžQ#(B6L*|"v h5 8}vʡ.,oڹIDaE9( |7ϞQj/Q+&xhy/d*~ r9Q; ϐ$l yP 0.?lQ=^?j%玫#;O`K7|c 4R ,%t$ H=g·BFEe+9FQ[ &Ȣ4S3͟},"eD1CQyWaQU)Wr dB1=60WHq`G rW} BWfMU ,8G-J)6,@sXRoHU2/nxT`0#:t[7nsÈ4޴>gZT;& NEo36o9ZU+va'AGƤƍĸMV{b89:q-9Xl\h’%TL (R6vӁRp\&Z-q2j:$9Qeχkٯ#|$U[v86ʪ魃܄CmS]IaEvsna]+ʟmsPד(x$'0gpk?Y^ͯq2DT4YLԾ΢ ρ]R8`?1x˥?i7x#ByvӠn^ntTEă2ʚg ؗ9i9}`I/86R&EFFӨ@̛w v!D[!IzTKnDph9j(EFʿdo)g5>rwp'ʜUNs̟( ժq'U9}cU #~D%ޅ{.rNXke^(bW`,&A$)80t_G[Za_)u3n1w^v2 B9ˎDY؄|ĺHࠁ 5"]F٣>8ӗ<Wh4x8~C8f6(F{/EE J":Ԯ󌵯ފs؀~ᐵ$?RUْ_%wY_?h,@tUuJ^%Z#`Ȉ|*͓(˪84SZ@a#LqRg|J\8Q$(iRq`126~xgg‡߬Tb$Ld{r*@$~2qQ $9OHaqOI%bvVj>?]k@PJqpu>kaVV\]71@ȇ S*SMxdBk6Jm, *Y$aC(G`Vzn"|~XQK &߰B$e9~07Qa0mz5@zR?K,Wm޵) eG(/)ex_fX^\~QsV.L{s @|A4`{j7u xQ-> P3,RӇ:l~o/R׵ &$VJ=oiJj%01Z2H^+2k ^;6WP8_nEj i#XHrt8$G -\}2xj=*u zƟU(zyļ\e#*af,rߵzM@}C98pVsJc*kPgyPBa>dR;"[֯b7Pa f 7NhXbg>am}W^)*Ԫo\uC\ae+8OԴh!:"-bL_ q=}8opOޫ]/Ϣn>CȞAdgH6 >NppP֌!v ^*{kAnBbSכwQ)oTA96iĶ"|7uؼ.eUp7%A 1l MG"wAs3TDO&U.(Aw7Vm*t#Zܤ$nJg9oQjh'M]4PL0x6lUޚ2|\2+ <']dЦ)B>Rfr%T%{| ?KDD6N!C%hBFTRK;_:zfE&}DacIbBѽWato^ W nrR0VqB^U**wpDף}_k5X֎]ljQ׀@]"M~TG9+6C`NSerh7HkHOnŶR vf(_~bucw1 L$pG^f'a!5ecz&d*4 #o \kBqkw{\uMLۭNM\m]&2iLOE$ ^ݨf}SbRqoYK>̇ )M-92LF`(́xe.lfsO4N f Y{ ؿ;j֖,5ߝ ;˔×ko|?4Sau5f6UazzEᢡr aQDh~y`:15/=[Zuj0rܛ-V4c-eO/;֗Y,,aC0iMTQ`q*{~DZS*8%D3  Ox"*7^g8Ot~ F}@sFN?b&x݌m䭱(aޅ5yBUr` ̃UWẒqyO{[s9}L5}ٍ1JѶn 92Q_Trɗ4HA) ^"׼YI hlB̯M6T$$(5S  o#+V 00zƒFb}w_(^^&:b>#]>sqބ=ψBR`#8Ri,h̶PZ7߄ɨ!~?3J a׈mQ:2jtÐHT"" a7SO|Iw傞9Vb0:w-228MqRw̢UII=G^1 gT1(MyK?^"R~5'f҇ :ݦ9\F8h0rhl:tdeL'̳vi0Uaqi퇺˝$d&#VVC|.qn~[ /`l5USNP >E wVmm{|Gv'Iņg9#fmZdj-B__[~YM7[;a D@=*yu=OB (Mq4!?'W(*׳u=f vȔpgu_QkUC]X(qE.(2̹E_}@=`?ӥ}2ٳ-x cPTNc<]qKAn =vuCK<M,fm%K] ʿV{ٚ'X:Ĥ\O:A8'GT R@u+H+t,="A uYJ5.ԟω V}Rg, L]xڎD֚œCN+@1DLb$7J!ncڔ ?7fϹ_Ba97aZy]/bfYze{q:ی֢*ՠafFz\cTGa!)Q%-[mb/ȣM}Ks5:SkEmcÝcOkUJ # 0/9vC?;v$8st2mVS:;n7oe"s9@r 7g^L[GHS S46%GG?T#!+YHܑI`Q >Z oa~)F\Dzlna嬕Fpp LӤ 0U\.P݇4) 0YBG5l-J(rX!:XI,FE&d~-6' ~K#g tO A%rTX(ğى  1$kFɹW k)tqSFR73% _LpAXCSB$דe@j`Q6 5_ Nwa,k(&3߷#p I84 -r'41d_ !efHmO:$ɽcSܝ&0Fl)Cj%$YQbDߨ`ZKQ9j";i}=0Pdio0~F?xx6we|_uC4w6G/ل`w/*Ù@&Mf"%Z\QQk~Buo_T_~ Im96Ƀl?t̖eѰc"EhLj=xjHK1m[86m3;i#̋"S۱wݒѭХW~ r"ґlʑ]՝]3@QoW*Sz6Y%pvr:׆ā3\,V^0 !y#aŷH?[d3h`;APm.$;gR{W*Zn`gJoܜ.mt x&,@ %hOV0)Ez'?^+*Bo5_""C07g lbäH!d#iH;|Zq ~ +j&qש%ȴFԕꢀ6~wtJ3d(&ܵd05 ?0UQuE8;}*gBYg|YŢV^gtC я?f{C+H|1]~I #"md0_XHWzW x#.*~ : hhE-{^>VaS|) -SI 1D#&> KTvQHcwhrYn JŠ:z^hy,fKzxCmzJvk@=UЙĩN|,)Oꄬ"͍_|h iaD],1-D͕۹pSx葋,@S|ʇՄ ꛘd'm*$8S*zd5YgyfFNr'(wxe;]W+\c%=^7fP¢7h簃+ _++4aǺ2o,64=tͱy.@4W?,EERA|Z ݂lsQbi\c[:[A:q4j32!*>\O0q@{0;>.zTTBoPCEE X7zsݴ42d䐴z2xdaں &c z>㡪F{ PH R tL 5tj*PWE(,E{*XpwÛ"(%ѽLCѲlĸA%Jqx9[ԀzY<Ut#hzT.oF m٬F_x:\&%Y*B 7Xt_{WA>fC(hO+HT$툍UZIilCΕK ̛MҲ"Ƌ:M;8.fEƐ62G'MVw {x6 ݇T֕+:܇!D 8Rp!~LpSxt  ]cѩ gxFxI: }>zҵ;@`u#qUsNshJ>)b Z%Wӗ8o!9raqB(ʫba֕98{_)l1 ajq5N&pVuȹk"Rpw>+ ēe Oz97!'RS{zQ m(S/-v@;oO=b)\{)ںpAH_LW!@^6&plx=X-6SiMMc9Z {;qk@Цܸ9M6uᰒ7XwiHP2}M\ZtWwRхM{tB<_/Rl]WDjz Q1=] 5c;HhF6_0ʇ.]h9Qz!?k•r70i5HMP i[0@~!$NZ;"}w{vU\Jp Y[ZsBhq̗-hjR%|\'ei=q t"~E#}g>!e;pYXv{=a /֐] )B&4de*={cM!X4]f|:U3_,<ϔN$4RkȾУ?&*= ~wŝ~]/e '%s 򴚅RC>(i0|;\*lu%6efw1$\:0 Ec`& ɺ?5rw.{3*n->;h y>Q2_RiB=G4lRIb6MGOi|hYf[^ >Y|1amF^!D$47IG_Qh>ճY fO#GfЌ,#Fje2DGQ$h~|~D5BsKmLy0(B|ᴆ &9&Вd[p9u^G|h@f#=XÖJq4}*"G{ܸgW.5 ["/X,ʿXH*BF'&}ATR;U6zʼܬЧA2JxRxDp,@nb*B;b#:}RYu ~dMu P-bjL/$(#j 1Hݹx>,Q)ǩˀz+GrPDe{2*@y{NP jf7; u'"J=g 輟1'uFapvÄQ}Shۘ.:&O` 5-mn{r퐌1,?w{Z 0 ڞ k(RrI(.\=ZPRM՝S)`5`ASv[&tLĮ0R:Fӕ֏ 1=ye3`s@$zi_Q<]WCkkL K;Y4N}. WYDqY8l]'2`gevD6&7h9"ʻiR$F/S):% HLFdKW5,4˸o͈J{Xq2$lY(GF)ĞkQi S-0SSpO {:3PC uῷ< Rr2sˆ8Ż zZ2"=:$N@5?FI TU<2Uz.xp`{8`4{,)ٟ}m{|*PH?A¦2LD2cw{]+CI`2Nw+<)P _΂$$byh D-;>{ E?=zřmԌLeM$NAIк9w)P@Gs)h}V n: |Zt#"m_:`!q||V`ıǃT 5(c hR7:th,&QQLw-dI['Jnox8C+BE).xРvqk $(}>>Z QA T77Y֕݌ >GdZ^pR ~3z ϨǦ4'\c.RJSg&T2؄_Fv%\&܇_:VV| qV._[o2CM/)90Ԃ3mkƀʀpf?n7F_agz`6̠$*-.Te&9x_G{HGogVYh!A>|fifFETT2QC쟋_NU !T?^ ]GfS-'&2AUr! 3 |WPTJʹRM+CDJBxzb1{U$?-bG/ ]DB7P צZS:Ճr%3)R?=ZV7fAܵw;:̉C[@XփUS0Տ}ܺXb"=ymߧGJy xN\YA!)x.;w Q4DTϫt\<ת*Z{ E>oCu8(Z"E϶e(y aBf(y5K/N m<bAdZPUzh\dDd}l<~9_DB' P5%n2ޅ4Ν]iq)ي`'~A"ID{40P`b"G0zg2uܦ@V5/\[jPq%ԳbpzS + <3H/ho!^3V>CKϳ`Z[{zw}X$R*C+f\7|.F{,!*):u%ӡI f.X'N`8eD2Y),0>=0J=<[{_N"3i !0X) 1TʯcUSWiOȕλ&Yݝe](<(x[]bcfw ;yLn0vs篤j, ˺޸^ RoPkQ 4 r͓kHyל X8J4 Ǯ2Htb: Z:n?'#Gm#C_ i613V>֍/Zqit33ދ5r/4- @&䠴{Ba3ՃB#cBd2";Duq k_wBikj[caICb\u&v/gQ; 2,0 -i]|)HwC8a*(|M_,"2If) Tn mXs:A%1U8yhSox 6;TFLd8L]̨Fq.qAp.u1#._5̮%qk\GcYNT#CL8e citU>hc Ve-o3=^;I~' xȿ 92;FNS\|gP~?d̜TjM.3Eރ[R />42fu%4S~ &u< &.a;op :,\.P]˹ ]jmvt~?BYΚmtg--%໙USX |gkV3}ݭ9r=`sȱ;!qG{qoO?)pv<#W'HHA+AEޢg3ҁqA2K̷cY=jᨤJ}#"h> 'caDԚ}`MSG)tQ~x/:V򋽩ʺtGsG.pJ>qB\%sח^N*4:)ߦ&s-[db l5N!HLJ~>%ȴ.R(=j>'O gS,Uȧ%I71n4r|eh[ =BH$hW旾nQ12s!/9z?94,.+yU8e%L>JPyo_g?qnv=zstgXJpI"\c%D,+ɻ6J>v} B/ 8>]mlhqoaz(te ?EʶSTYņ79:H]`QپD5~OubcIU-Cv!&Prj۽U=F$eErO,{>ծd۷Oh,(]{d1?@ʑjgN4F 4Jj剝ڬ(Q#PNR5*(;?8=[w CBLvA4X }CwFRow}|?~T J3AEF|a$a{ g-=%ƘCי:3i0iٞE8&ni6\"jouj{j26*i̭Vyƞ7C|ΙLsLIFVӈIY6-1 9Pozɤ-K,u? ]8K9sTWh̆ˤ:cن[Wq'D\G9>24Ps420'(Xxd`&;y2ɥ\ ;AV&W;8ġvt9DvrmG } ܭE?cp.Zu7Ek 鐹]bpރMLufew[ ~hT:R,8c2PM+JI-r`r!vm4mjdXļ6OEj?h%B%X’Ǔ6x;_R0 U 5.{aУ%-#OԦyмr_Fvjka 0seJ_5ƿ O[{ foPٚ\'B5׸NP p׃S^}F伅J5-ε"DmM$дYǨapJNH#;ㇶB m(PDBz$=F-VEI ɩ#|jU}IcND~3v?9u33R_ 9ZN4ILns `2^c-%o**K(LzB**[HM7'mYhL]RԙVU&z]4"4/!wU ^N?xľ85. Ͽւ^+Fͽ2t$^ͽf$5eAd.ÙlR)I*_EMUC5=i'3bl &>JHJ>-U% _^#_J&]Boeszbo`rnmB4ck6+|&ak*kOtO`kvH "':8TI?<ZDyCAk2S)0ubRmN炄.8h-WÉ+U:#>L.eII;DI_G`~\X".u?Yng5M{rPd@Pg,xrS_9sqUus[bܚjg gY)Mv*O-KM/b{{Hd$ 5#ͣ@ U'VT%d推)#!Z,a %2 R 92 ~)rTr&,%83P+~,<#a8| /[S PBjlP (-z90|jڦ&%ꤋ:LcEx%^r\ >8 hq$hфX[Z|q6L<ͥ S ]^)毲,{pN9)ϙЪ՗Թu8Vl. :u!]XF`Nm/3DzűqY"O1=YS6䣈s;T$IFfe'OZ=?J AUՊ LVҞPdt9pC{蒠^ظ]ze.em*[IO01ƅ?,AG JS3^2"LFhY}3WpϮR%*hXrVàIb#.YZEX9{jlz9&J\+iCV .w  }]e'FM|@K$֋qZ5vtċzV zX/0LВE߲Mz7 z1d o.„`H5o}6tEV]3; .3ao8]'\'Rh TlnU(x hi3}Daӄ35cMK7 VV_y/KRފ4,֌z!2~Ȅ @2Y7B f,fڔ.ppZr@xyxV8](E K wRթ_,ʗ5O,?;<Nj~S o/3#Tس*_ʼm\ɾȊ׋\3Q,VH]6˻ ~.mD #a1ufjGUx$&l*!]sF@B* x\:`i°tnd> -|W'RW|Bz{k)lC㱥TbKaB?-3zЊ7̱yc0<^޹-a9Ꜹ(y#ƈ5J.>4\Bm G)qN-_~}ZÖLShϖZr(9\wŌ4e$ƅ vbU( `2U I7P~NoѲK6^qIˀ99/9 ܳA=>{~lp`<}tQ提o!nBhӻVj7a /4<#F =塦lA `{ٽM43:{28$HInv1>fifWn4J,WiTba# PjA{ _UyS.瘑"YE΄2 TqNʔ!U}}70X (җ#aovid:^Ҭ0zsTc;D+لEh׈mz2QrRlotPKQ#fTW*??~鶰k[̗k>G'5puŇWNctMnW04\)3+@ 4wW⠄9Tu 1ÿJPhvp(Ÿԍ+{}\YQޙyuҘo ,v͚S:FAΰ.p%sEwغtL΍oJxi1Ӹ'T,#' Rzc4.}WڠO"D޸Upz2T=?Q4,o+Ϩx`4#2c@ˤHR]jfzὧWl x߫ EGEDŽbus@|_;v21bl͝=I`װb~qpȣdNg=Ē + ϑoVEѾlhx8uefz 3.o[)kTTBk0 aDg9:';d` h^ mKpԨQ#U\3UQ][?azbFtP1,|*)œڴ#$y8M_"df̸yض%* Is/;n<豭-sKĴcʬ<@I սƞZ`u+td%|e܌T쒜iPsJ'Oe҂m"&,D#zfYD9 r%$C~JoWyNF!K/]6L?Uf*@0\7Ublq)a(2C dZrH6 _FGt4 HBN{8ٷ׼ֵ|gݯ0ފ_o>u)MBn2d[Clב>6MGCl#Ա$Ta*g4RQcIؘ=ZX5[7KHƶc[濁҂d4­Wc{Lvm 9piniQ [k/2)ɝu)F`+Gt 伿zs Cz쑩C9EM?., P46%4a~E{ `"sŸ$dQƄ%OT0vfkA#IJ}#[ ( 讻6U!݇"٤VhiPnrF}` [ OuˤH)հBpu>f]2Tơ/ O2o\$tXg;ڂ9DEʼ\4Xc7'kh.* `*ՠwz}}zN֛HW:$^pV7&E<_kl,ނB`ۉDXH}67rhP̅fYl+u禬@a7M{'suF^T(@H TO誺,Ja G"0N<3|K>RT(DJ<huw(*\2%0<1]Kqϡ O _Y>#V[ %\U\Nqc Wմ{^5S.aW& L]6^1=4M+Pw7/ %ݮI;6?A_cX8?<-3Q2  (J>S48re Ey9~3`\Z\QhpP6`6)X@@}|UYrQ?  j] ̪W wNqDܑw1yUGtz@?ꆔN*r% Ք8;'n q6n3hK@&ֆj_Um6*$R8f!́&z7KM ëӓWԺ`庒.IANsxf~!^w.u[QCjVE{65w?3JG~#ၻV)3?ƃm8moCڦdds]!b!o";x/dI }K3n5XěVJӫg29ߵ=P0Hl\&GI̱7hէuM8 zK㜔?c>b8xR5CWE kw XU,c98{_{w R`'< e\X~P䩫 yȕ6kXi`S9 g`j~(~zݦE,;S Q&JD B}â>m?CP!I)o)SCǾxG`0x!T-}tUZ%X1\=ˍ,T9zR-q `| ^[ R~'PKF}˛5%`ۼiږRAE+ (.>a8[`2dzS겴R{.ˊ<)R &EWTsD5z.}aHC8$g]ӟsT!Ma[Cpb]a%9zey,̔m]zqfu+/uR VX.EJO8w0;ySTb a:Up&ڿ^xpǬ(%A &~a;<(b@cpr@\-vKP<2*R87nYŦx9+;ee#6s&{.9r9 q ?'%Yq{M7/vb蕬c [MDqUF"?܀W= #Sʧ3<$-K÷onIi/39@) ZS2Ǿ=z #Y4!$Ի + nZZ7 0V;"q#^1@?5*g'9LhIZ༈l= >G>  (*d.3dZHLi_@U_S-. Sd71.k%X$H6pw39I0_;7Ǹa`PQLнP( '/6 ?l몁OVnčQh$zvfĬe 9Ezl;y.: G^v0p0 9@*޼)Mrbz${Ƕ !kj 0v ."uSOސ$Al"ώ~ϫR7,nqpM`KHN gLc*Y6GtOtż툀mmV"ɢ++9xf]奊;C:r3[OFZGYs1HXD%%K_\]V ⯛# foAPX\Pe+Ce] p; ɽHD3tfK g hF[t(#n;Y Y0C& є;:DZBu{ PӯF/g H(!#MBf zIߔ\SQ_jkP 1+E.! 0-E|Ogᥬd 3W'I,"`VN*6ڦJ̇ ihuQv!{6jW5S :VԤI+i[}f4[h (I 0sԨ3)[.7>orMПSP;N'p &4:v0OYNEeD*`BINj!1 Əd*d l- `t?1À[*%s1""OZXn9j 1X,*J-/&z#Z&`"%DUƿSeO_B+~`_)vxnU8ҧWSV[9\IP-51TJ(Q YDvܭ_M~e& ț49JvjmV3tF@udyQ Ji:(܌C%&]٠-;ҥ- A';wNY{Jr3-Vް4{?3HJ'Pl6#gdgܴq_ b1)u 16>^LDz ҨBVT젍s٢f̭Cnb))_To+,30QȖ@[+^!怂;BJ;uFT!RTr W S#éDc=%$,$ケ=`JQ|f@=nV"S+mJN>TVNyة8=N~WWJ;D"`ڷj(\`u N떿~<J#F x7:YIG9 ]r͆jAaډjb3 >_;1O?h h?mERfk i=и>(<*`&U~3΄k7%t{ItQDAyk.lל%];ngIM[Hd{tTcRy&=tq* E^6H˙Ū}%OEfZCVAGFޗk~EJ[F y'?$H3b;~ I7Vl\Ϗ _m~o RzQ9k9)M;fwLNc044+u׍J jǏ8^5f![0H[UѪbmx Ԙ¥nE~ŧ%:kA;C -O?a&>Q}MIKlrvfAr%qw%90fWki):rrs|v4[vz\+!3kRc pᑇX=*6m'7/'zVok$Z;*e1y2ˎ> gE/-|BSÂBx}^R5L{!w?N}iRUNvac֢5 ZRS) D]ktsYko笽W8 lMWD#ۉ!( ~9x6m-39DzIӓZ 'S= [?gں+rݘ‰N8-P[UV$ua`Z5Z-"K]ʔnݗXe ө;)wO 0$ jv΄ r<+.|Kk )Z4 $l=NN ץsutuԏu)9̉jN#Z]{n=Df<҉UnSnߌ 4j>cۋKRG?[ #L3&U:[Բ0{!15o<,uc9s:"1m6m ٴ6\x{eJͧxZAVR}8EO|$1NQñݘY/lq*(mf7Yq'!|~Yiyd>M%U&U7authjY6ŎqztiJ(AFڰ^ZeMh@x*fZ(Uu٥]Db#pqu VG52Dc2KֹA7;ap }D0h]8ը)QNXz$D+{6ꐺ ]ղcn$6=_qⒼ%QQv`vŶ&Ջ`ߞk*3C>$`Dra]kŒ.r}j Ϩ%NamwC Mk.o}Z+okWuȄ44q=CZ=V<0$:\'?pաEǻkB/YmDHYKPIHf#OGST'䎻8~"P9S,a?c50U/bF4%KeaVBȽ]Ȇ [;26{0.δ2gP9yM3FsMM; n2,/Cu%ɜ.VJ#*(k캼^`h4_򬮾:oȴ nZU^6ʓQO/Q&S i}Tjh :2G krȦaQ']Aϛv3uZ3Z=6_E?/G% @Mp.ܻGdzT.O==d{inVޯ(P9~ܜ̾Po׎K!=,7WN ?H::_jeptD{P3Ѷ<*6 v*='j?TK;M?!M牫k#BGs=xAeUvU9UWgqb8/9B II#bߦ]cjѣm*Ѽ51{\ mg^q[ v8ԥ,/mt]W,hlsڶ0xDFԒ+HP\IWƳ =rgגnac0u.Ж{x8cX֓s"q.zM$U`xiHޒx`捻?؄IRa|oL!7Hȗ"fs'rғ.P L`4qrRt `^=J^b RwrnQtoOb(ؼn$otHTbXȲ.R>ryjF[$ݷ6%n2qFiMy^u[+iQ٤-`+%u^X9..螆/d1eGO&ӎ^.q?L/7{gQAG&k.mdCV/aW/>K ))O%kUdMtl6˓IȯH^;7qg-FCT ;akGZssy{*[skc\ TҒ gj*ŽsrN ^_.a;:RJB+Z23AZmL~:|*bh{Zv$?mvoɭ}C&6 e 9XŲuY!Q Jl89wmOXw{=%`_Rb$Sp*cK@{^Z)00Hqdy>c L꜑B$v+/WهIIV{7ȰzO]NZ5>7fĤQ.}8D}&S.+JU?g? ]vq@va6T0@YA lWO|yxlsġN\6c(n#1h}La</j7`.y}#tk6/"9۳Xue<a_ Q=i#NÇ.﬐6e'­Sj{Ƶ J$Ffα=, lP28 dy[ȀOPMOd3d̵ _vR6J sbXvwQm9ˋfӳMY;ʕ^ċW9ob8깰s$3y\aY!*ؖNai;2.u#z"ߋ -늅:;I%e)F1xU`u ^+b4C;6DqcTo2,O<ã"e+ZjOT 1(((x{)j\H a/n'XO{ҧZJRw9+$>i(Fc f|Z?Qw{20Rx-et;4k8ՠDLI48*ӻx}TegWKkWjơnDі$klͪ|uLh9Nyĩ3TNq`/)'t_/?Dx,A3Tr((ybY((Ֆ=JJ(5 EyLeV%-txw]`9T*9DZ8R)s?ςlVOoՖW}RxN/זގ-y9ëbթ#ƺMB_ ;VۣP9k.)@ҮWCPq "$!_ZRFEt/Xe$5",9]jT=_P.&,ADIySMyNA* N@,X"<͌Xlԣ,81 z!ocv?ݜvFO(^kb1{iSJaN"ht= n^06:_fцI\x P/=}<>{ڕv.pt%`.mN'^+רHs5='<]nGw+%Yv 40- )oY~TLPi\ShR}@TҾ?:by$9(ײ%N5}9x]ɐ'/,w3ԬDiʆi rzm`B%[@lt-rJ\o:9F{k2(F]3)L c8Q qlMg`6CJKi%ʔZOC}w-dO99?Ԧ4݋> M[@#jXv^ftKv4oMNYYG / eixz )hy}4m]#c/LMdkU}7f""*H !fֺrlc9nz\ƇPvgg0,0aKA䄮5#83|%jDz+acx6N\ vcYCk&N#lSzܭI khnJI`I:2gr62tK(-1CȬ~)+5ڒ_F"yGƉd eq@TPgz# 49.x҇Sa n)|M5S`iay+X޻Y)%% |.~X?[A nW8fL8q,EHt/%u/ 8਎cO'-{f䷞`I A$R@ujY0Y[A`>5ځ+Ua$(`GM/I|va'j9֒!H_v|]yserDeFJ#{eD9ƒ&CnL^gRcS+ <|o {Ӭq`h>1v^9{ _N,e5:-zLB{|vP Oj.#(l x`ѧp x u>9{=v(%ώMdZ+Բ`XφUY(Q_Og_&$ˈrFl#k™ "iw+Zyם"IJ 2%ulFè {3I>9B)GՓEu{àD Л r,qjb *9w'nQFw7?Y Y*q8eW>-/wd,L؏_V `OfX[VL('"Oj@0Ӝ]_ 9K6c@ySюQU<^L}Y~@lEX0KgH7ټod42}uvqu7(Fg0궞Q'C5sS WQ8qA120qJ*A W%H/t1.9RJ|]5> i5jOѿjzVAt h:_ lbez+p4 y y!7_A.-oަW/ȲfH`cMU:>nˆ>:6Igz)[$߃(HL8b9yXU˻i-l 3MQX*ŻI_|c;k`$0Gm}o+~.{'}7 9A:b' "V[:"x|$ERzֶ8?D yW?m. =J[dGߘ9%Ceq_'萈d-lTmh7Dn+'ګ(.Kd@S+q L4s!`L9Egw拗InNRq( 5|X,[6:0ɺQ`4~|b9GpH>OpK*:g.zîgt(a;L:!85TbB:)ROd>^&G x홣B*)LΨ[nXbBMCi" +KU:~=3ӎQn֔tilm+ iGXV`r/2MVLBA:K\njLpF_b Q!m?;mXbpAf"0\8Dû}Y!baQub<I{͎uY[Nk_pXqc!/>WUAl,<88u9Gw 9RBUq%PCtl!f.Qn?W)1A :o_(?ӵdQ3HG |c~YsPwJJJ"4>*h!}}x k${HdH05m<\dKs^ L&%>S1eI *`i'arMތ:Ț7kͨu4(_ ~\ ;<`  _zr[}'3+zO8)W9`C>dQ-jՐΌ;Yt~Y T .vFÁD@16RvN.UcXH6 jO@yZ#Ծ.4Z8PRZ+m~V,x/RQ +Z:5d]FR߫ Q'>n!ͤ;VDOƦz ,ZZODώ_CIK8:zE$b@%?jzLu JwmƅQRHpIQt)Tz@L ,#(yxi*ar'Sgʶ A Kҽ}Z.AzuCM+=Ͻf!]FKI11ЌSb|(J%<9dn=6ܮh m(1>!B`|b.hT:I­B")'r4BSwʟ.;+WC+Sq.fkD+/Z7ڹ;*%l3I* AD`6h2p?Ww*Ryy'"o֡ت;pODq1PX9-/ ;GXI?;m,tm92I )ԃb̥)thx.mƙ+?NBWg rڅ%ܻJlܬyHTP@͸l[m $e ݚ|1!ʷמa3X0ELy5W09ˎK\eÈrSrG ˅ͪ[gZ]Cy۶ml0kH=|]r Wsz*Ϣie)z~$ fA@9Q/ z؃cab:櫨nN-ڴqҙնಯ?gJdLc` i}Xv,պc7@vWYlԪCSnBZtUHrdI 'l(fQ3X|. GM'TEϩHe%-n0a-\0EZr,+R 'uNTNtPbjGF׸ C̅ gzfpS`ϔ! L(⦺A:Ӌ%D':#,?_> h虤̭zً;]R 2ERDc)2Z TYuh-a/]{LN1,cgF c"s{$nH/R*<EoVKR~-~.[Tf< C6OaI PFΒ|@; *נz} hkp½T,ՌpIm~4 4EώsN{iHnj]y`OR$N"YiTucF%qp Z 4`Q[G.r!&ȩD=e/# 6Q) {F0Vsn3A%$eTxmH* MxEV~vڜ N.7u=~ң]B2w{F4{k<Xi(a}L^AsmMF ,|p{ nK-ÝqcJE!ґ2t^ >;L0ExuGzSy {ӱA;gj1.P加_Tg@ڧYՓZcSD<ݿm:K#Ӣbeg~ B:REH^A$Xk{% `0u 2E%sP$\lGUSlBd.1ZaD]J$,pT1Хmt^/i<'ScoTXmdgbBK1Z o;.C> {}U>Q GRU_?*ɷT˖8DlNK M.%x\6[Ʉ8{_{E İJK\S w?F7ʮ`$!P{3rӕ9/CK oPrgdZ'}d"ɨMZߨObV @2wN-)׮W-@.ER|ɫxvpe%^o,2zc~:'5BAgvurv#C< )AP_B{qǟ }t.7W-ʩ.~sv0޻hOMaP{BkbY.Y-tUAfI$A)ܙ$P]aay<*(2fF:6~M<`3VTX\K`w!2aHH ObQ獼ځDߏ|}d0u_{w pp:ҐI}ɜn6YA7*n2D P%]3Kp/s!,f4}OTyh"H]k š C8d"p cpwg; 'RtƿhѠRm-~")6 YNv:gY{hVݞ*쳛[JqkUP9oZ뭄/2@otq~/HAX"Rk3|Z!/T:$!>}b (E)nZپ\*μwlTEe[Y_ [`<~ (@" sZ 2:,~&wTMqǽBxS$؍הb2&Innv\"9nk8T!5vCXS^6绩 yvs<[ülTe/Hj  jy9o,妇 @\:&ݜ"bw*E&wfÅ*N6^q0Ю0F~_ qvcͿi pFzOa`r 4܊e3zY#\Je$I3Q+Pn餫+Be _FPoO ઽ}3BGTO^r U ny/?nP ig+gq e ^(JS.[+֨P}=<ڪ\&;D1V#)Ecd 8C}mG?~}Y)Z3!h,5ݷ" 8,:mŻ=Zf1 (f]CAUf9SZQ;qgYҔj|2\$}4j&\1kZt{͆чhyA<挕wp,T=U+xǔ 8POL"Kz̨4>J!n{bxQ+s2L)ǒ߸럌[Mj:K_xp$ʂH֜?@y=u75eSxFcj9|0_ߐRVG.y(T*E\+YyĔFe1{R۰Tk(+R0}&5߹MI=$"! ] {ܘ=h{ۮZ!֗ifpXJsT;OwJǛd*O8x< `j j*gFѭlLG2IkVrB#m_D~``RO>7\#f];W@Ss3hX4;sHI8qyW 1;Td%&8l.ˢ]K!yN:d26:mW?3]p6>uJ$}6~$ ?LJ,#>n@dofkQL;"=Kk - d?5<8&Tf0i^}Hlp*WkǸr[خlؒ,DrDŽ#p~ϋ@\l $9]!ҁ y+_ 3HgP ȏ0jÊ>7j/xP~xe՗JFeLJ{HJG!TӧIx 6(q>/exOr|̽ JMdq W{dY cNjbѷ-4=ΦQyb覣޺> %ryʥgՙҜPKr>gfNM0 N$ݟ+.^BIyN+RU$!\7d\HTFfZAyUB cb>7CD Le2Ր*uQ3Tn EU!w =8y8p0tc;a <5$Ƚ/ 0H:@O*l~ͨ}+Ph,vkWk9Ko)j*Ih?N;"E-[H[1.&x&8j t f«1mC.uR–7T@/$ז95':hO OJDK'B~-Mg.{3$~C~O  ӵ!" j/HY0> P>_PG5Sg`/j֡T:ȡU\<儀fAQQs#<ԔUUKN$-2:+VN _&Rs~k3%fsq\?6pBCϙ3eX iIiio5Xo,T~]6My) _%:-PB/?V)%+z]z^l V#Yf16T,QœT"|AAsPVU5Cxt4(=;Op ^Nm:Շ5&jcWv9T5=Luyu#͝im pzq ~! ҳB ܐݑNhim_[X,FEFϟ ]++ ˁqBqܝyњ<MO&Ȑ{yھK({ uA7<"Ϩ9ES?AEIe}1 mc^NO_k:u7JQgW0m}@#'6cP_꾆*}x|X|?9\a/Kd.ͲR܁D7D:īa5uk SE*6"5,q#6\>KX x61[p g⊼lߥ$ZxoЎqh^5$o]>-!HTt7.>3WMҦ70 f Zuc+Oy_21f@1/,, ѯiٱl\Bw}+{ln2$FAf`/[n.^a <PkpQ"AM eLqYex^RG?JCX4XH=qnB@cﺀhT-[A1sC&PjpD_ǻm6vL*6hryaRO'걖 "D0U1VjqʾVNAO[oHLhFH 7>㦕fW!jjLڮoݨ6f녤>Sfܿ֋%L?3?J)fcTxM᫼75.$AVM4'`|9QFx1 Ue2 *@4`$X50y=855xDlN,2p qC::H.hJE!w3DLX_K t.Pջ@A&ד8r\Xp2%ћЀNJrA ,A'ck5L{B}J1h. /)O\4:G{Mʛ/E&vOd܄@R 3+A{Y^Rľvd.εlψ SNO5qKi&-#V'>{Ik打$OyZ&rIB S drd:` n0xCi0^A^2p\]k*bz}Qж ,[xn .^QsI9NsĞ&j83%U<#Y$dmHsɻ^}/5]7z9k)^q(*-kZQ& $5g6?& :>8fFBԲ:2*^B;8iB+c[UNca+唹Γ9C2HD/'K$N4NsרZxt*݊[֕uF)H*uʚ<M2 N2?1Ѕf'kNwz$2UGb'H愫`uAsB/X_c9]8U:|lKI5)|Сu^h8;fH3 JdM*X$SO]T,P,i;!|͒mKY3K29ao"uzA5pKSIXS ZxV O=Z֌zSϬFroF=s"(8( #[-|k2G蝾| dT$m 7{O#J?Gj| 3Y{Ι|7:oWx7!Za@u C7B"صJHO_s!Twm]HoJ9L@TcÄ$Y#oB3>4תUWȘI5Ѩ~`?b\₀b3eA|xfT{R!);|] "BQW[ljM`fdpK@ahNGK `JYZ7cΗ;]HWqF/g\d?g^i5U |]v ޕA҂gLN_vۢb DN! K=}>69R b#!;qh:Q&`@M: Gz q{sXHvImI-vEQ\LTk%2a!m S>p:>E{ FJ1BK4NQBӨ'ԝ#1ujwSfnZs'c]ʰޱ,*27!oΆxP]-?xWX}1%7Ɨsy\ƭFű `zGp*J!.%d=w;cHu5ɠ9NC-`rS$ Awxr.I⇄ K"fA$U.{v,_=旰! s ?#w%],h+O&)y }[=py@izr# ߇C}O9lRt33ܼ]f N]2PLTp2κpwrmX] *3Ek|GP 8]K|њ8MF1b-*Nf0 dΎi`+ 1G=w$CKqELMٛ|-gCL`QXb9;NM^;pKEHwT\!'l~?ԭnϵ987Rt NT>,Ekti?9b-IzYS'2M+ 0@+g>6>ò;琋U DS,S 䞹ː%qBoIuYmb[\o5E2ϨQ&r "} ;e쟒ƒt4G&KAr\B3iS p&l4 ^Ef"L>o=^8}Qw^v$^h/H173w T^(5=I1W9Fv12xp+v ~iv%R\OK֪xj3DH4MDY0Ro'އ73G-"3+16ʷikىWCrxd3Z#>?.xM;T o3_u4hf#˔pܴ_|5r;FJHLL\S5\ݖ'\?1boU)bť?\qT\64 <(šgdnX 1lSN۶tEs81GXt7%6ĒpE\YPJ+d$+il *X\K , Kt_ ؏˃6dn0v Ӛ Wn}A.f㣾7!qج-7%{}RB ]fr!?NG$^ǁO3 -#I5?-^G]Ko'z\F'Ǯsf5oٓ"Q"o{ *!FACAJz j"P.|jkAy⁡|l_$%弙z"[%*s׳{N>RZ]O&rN@q ϲYEU~3p*\./^MnY]^W3H)J!!쵰Gu0!4& O7aq<#rOaMr=g'kzE|׿ o7MXGKQ>R.SǤHއ:,{LU@ wI|"˿>s2D&c|&4X.r#Ђ`"oF yWT͠#h+f)!U)GfǤNQ,hX4vE<;aYy99L(kK0QbN|XkTsވSfI;x51TH~%sa|STKyVҲ˞>5,^B `2"=YÌ]OF;ݬ/z3L Wv%#P5FCbI*PN4-O2 cdia  Eұ*7f;knStg$_ ~YϱALFhְ|=Pr14~ػEP r SiA.?rwz%}Cqp#4)/Ǵ̅{4h#2X"ʞ0}j+.yFJrt'It щIX(E$rDl,~öNU1B24UݔlF[q/^:|tJ/##.FM)?>%??>+㛉%`3*T@2OYTX)c,7a&3;=- ǀh&ZxOck]= +r9) ~ŗfeS`~C\[@osScZrV\o I3h]G'" {o+q1ZHKG<6cM(b?+ 5Fe&wO`P_BdM܈*Ȇ=~h17ju`zͿ"="dlZ;?&ÊanpIȷ>0an/eZ,ibW ʼOxȎ?yDZ!7|"^,Ѡf};`HH\Sb 9+XSCE0!z$83CXg7.UC~aSQ-[-wQ1-Ր@^{FwǠ< KS4 ϨI. .|.@;K.0a 3ꭊ#.|bx%3RK>j]o}'-1^n @q=H4,uw[8s8!0D9ϯ&iE.mr-'$7iLQF_j2'M_{?e)~`JhyW,]@$~PD=fz6]9k{Xt(JL΁ hoɆc"i#`c73MG!>Æ۬4p<&Aö<:p!'S*F;deNyۓ!|sv ga BF/R㙸-S~CRvE h =@~rV|khg)Ej<uUe'`8sS~W݊ 0C2pXu&zTм5Y>y_֞2t,ƞ?Ә~PSKh>_5RAZi k'ӐG]|Su)dCv& )d"C=ظ]2'D>/l@ JhR- qd!N֡4u5/(tdsOxCZA: BDCۜʺƺ|K"!죠kSe>t?5@;JPTwM˔C ߩ=W_5;NH}o-I9U0*VgS=z>K(L 06S \Px\"79c [_~! "r* 'Ee+)-},к#UGv` /0m'K>?(Ȃp8jxRؠ>R5ual)j4*I;< $?Sϑf݃S>i69b l.ڪ1tY.i5(b ,^Ex EZok+M\$G M%a+l]D^0;/?U'ށm)f7޶ '}]2._)K)ͯ埽-|P})?KYRg9Z\R_@9uxY@ 9OPb9c{07~_ R-zbHWv-c)?9" %hp"`a:ȿ3)^r ˖Mb-6h#|ݡcԤ?6qOKH bKC$ )}c P>1quqL{(ǝ#a)TO`&J |9CLǂ'5`Zn 3/3ܤU!x?6%+X@spʘ8Gg#f]h$~!ofC_; Uq l0}YB̠l*ۓ^zY+R*'=o_SX5#.0ΫG9P'.2u52M Y=X!yܐ <>) [ޫw*;ᯂ?f^`B揢K$J>\0Q>J!COCa@!+>Ixze^1B>yzC[o /:E+cܭKV[ }^ȖkUA˽_>u^.͊ ܍ *lc>ҟhYc=f1WZˢ_! 5sK +N]$6;?Y *8:5L *=܆&S//]^ =(܃;u0ZwnmQ#^ gض<TG8 4^oh> 1|ܟg ob1ߓһL%<>LJ$J%tNV5>O0q>~8)\B. y_qX0nްkЭQFޑj{<=R澦@3DtW1ȷ}5,i#B©GWYGL/exP"$D?t#y"b7 )B /GVDnSLG%nԎxw?yNybe#`" y2qfY5@ZV"I͘vx1M ߡE<B˒=YZr0ĜcKRE`Yym7Jcaؖ)-0m ~U PQEt=>\E#4ɸA&G][7Wq\$@UlRW?puDW%U43'jgv`j'2Y95 WFh˶tQ5c'<)֣& ox]> =U lS46,6@%4 E~Å'WUcd7آFBJ&|]08EYyԜ.>jzʝj3HյEFLkwDjh-_Y,Sոr=Qq -,5CD &TZmKH;BxhܖM_' 4*[O)eB A :cW˛fk$z?aܼ ɲs=S4Ux!j|p=.dPڥ}woA7ֈ\J:sCWLKgc+ZsypoR:-:;Rv9MKC=.Y)wjk'4bOR֒|h<-H >"-Ii0<)'XJjmn4*oTCNߺ5LbC9u1ǜlspV( IDw ۞ؼ#fwv"Ř~ߏ$)ZYtZXM+ yu~:-\д6u#\_L K!e58浙ةE))t^ kmHfj;q^(ݏb[!CBwrp]R;A:mVM2k.[|F֗SY$x%vLOX{Z]_|-ʣWg\H1TvmSW>'7>6KsqnYtz5T!/yeM+cf) lSAiAyH&L6&,N2* dַC=Wuc;uWE40e Hu[.a#O +Fp_a::Rx`v  ]\j᥆`e<2VP`Vqdmq/'^bǴ# H/uK>~<5$!*ו,݀Zٜ!D[>q;>Nܘg鐞kЫ6$z#eEܛ˞܆Ám0 w|oؔ:uva9 sMd9e 8Dqk_)xK 5dw$%b [ :Y6Yo*ݒ:sŽVn u01l/7%$-N7sΥfTZSL6ϦZ|eZ4]Z ͶϽ_hS"1RnF AR!O/JɄKy?u+L@"_)Gsmܣo@8ݞV+%_AC0]rG ]Ϧb YV[=/ߡĪ}W=`AZrv.xa^l Jl:UF^3G[C^Jk u;N[k !N]r>hyUA >:$zO@Vce)W* [LtH⼃}XJSc.Np6o .!LrћSשZ@oz!lqyoC1FڠUw3͎Ρ5VGE0Iʍܕm6{5.F#Uu l{oA$fcO3Rv$Ekp~v{lၱI"9*%uNLd(Db^!QgP1vH886Aٓz/Gz^;ʏXdN Y"s(=i#袳hg s'x}q깡Ӣ5 kaڊy'O]_~Lp; 9ݽHy68䃌>u5'yGjg:]8/<2ey\(n1e\x{MSH$XWE1G*CWR2E NF.ShB)>@7҄uƵ aݽY㏬1֥u6XgȬ0g,{J-1*syіL$6 T054t;WnJo t7@A 0KoBwT{5;TgdHxHVm/@ Bw ѭ&Oi o&ʤ+< 0A2; 6Pn5n.GkppctPj H% "܏HsN2̻ E]hpR>ߌi-ȉ*;҅'NtjŦ#GDrebCfDٴ wzGa2,C0 N;ou=kRxx65ӝFhb\~XPJВ.ʇvy" J.)-JK2&$9R2SS`MtݺK oR`URk|NK\1O1*>KT>r`3.N֞u! (GW32 [҇tjXmڈ4[ݔaz%c1,Q~̔_xil>at:T/-Mȅa8$xHLAHC0,D385Sxu\SKWֹd x(أ_*8:F:.E LOAq![' 3’_%!AE<Š4ZsS}IVq)/%YZ@uU56y>V_jiAe*jag;,sclSWyse;=S4 &;ZAyܩ@q/ԔuEBIq*UiN% [lJ8bpVl~71yK'e8p ńxH,ѝ o4kfj!mCxUz%>\7j "UC2ȎOvu]CQ䓬k}Hqj~9_^Սohgg锞^H[+2N@_t@ 5?G#wfJI^KiNir~OZqXEe Wݸ 1UEYusgK!^1q\-8 pf ;SY97[|Y M[QWy<נor j " JcxA_HCiuc{ͫ8h<үP!7[qIĭtOW)Pծ^\cuom잛Q#`^jx y|Nފ &Mg vl%߱<(B{&sKA0 ^_EvL`m}Hbmk7z'j|ˆ [ʼs`>w?RSVTic6I,g単B3"Eţq飏ILR܋Ku:g ͍ )3CmX4rԥt aɽBs6`u2G -W-giX] )IΩt-g:;-TZ+^`2tr& H(SZ3~1pIxEoQH J&7.ߋ{3 QNGW%Η>eq` ihf9(4)^D0n"sΌ=Ķy$H[pRΓJÑ W׵JGAQ9c<|.ˁd7}%sv턹EGsqs44>4q[O-K.T}SRꐼWGeLA$a9Գf~~[eՏ MK-k!n+9V |d-^.h~%i-F8(ԘqL`8e;7WjMFzI^KXȻJދdUtD#lgcwɲ6 `bUlL]_NRf@c?f4~D*-3MF}e3ہp?S%8Ela`H3OׅbAegW@\.La"YgX0j/.T}}=u))I+C3e}6xW}jb)[4^&\iE~Q1#Opxh3 AOUvyb$m{ol̮c~-i|;=VhfR6j?NwKl7aQc<,h0ET_V֦)IhwW %C5_bKZ#ٶl( pN,gd*m`3fokxdJ< gU~/a) X?Xf+G- 3<1u?K 9 OHaVy{uVo =*> #+C>>T0gAC86cE`]7!Q:D瑗8nL^̬l_鰔Z 7b՜hvy(.`KiMʢ / +$p]wLvHhvI2,=<) [Vkz /oUO`_V }i1Lnzh ?=5i[H7}s{Uf\ Љ8#vG3`Ѹ3H9N Zu/'"Ю3CAUJ7~ {>ts_蝳T%@b*|hR] <;w.r?3/ŢW nS'Z]økHγ0uλ-I4A9Iz?շ7~gbsN 9v= >1o'9AƒEjD Lܩ`0:cr:ii׳luAoNWf˘,*~?YLt@]mGlB3xI#g@DFOuN%͞R3B2)OІEpH'ev{Tդ4'vg|ַK9b \n-jIxAidQO|%:_r\YD+%DK2P4"_ނC(_:iveƍ2m, ͓ʞ;W`w .4p_c\(`8>%ONj8m(w\U'McSJO%P!ϝn?\=} `=H\i+xX] ¸\(WjV\`ѕezn aEIM+{ѐ]5c^syxhRn59Z\ %l8Cq^IM {ԃL?/ qu)n+K-3P>sc_h" 6? tW\)ٲ-{Ȟo dBV BsG .Q{AǟQ0rX {$w^Y̾^g KjГ_WRbHUKȍ9UD'RԶ}4 VBL)IQE&;}ʐ9b eD Kx}-d\XM!'|Vg 5 w e`1^ Il:R4G]:?*,%K;Q6 Pӓ&>{F7|)keG]pMir_L~$U&<4p15p-xEB ɕ8YO=*jhn,.Eߠ,W$*c@/13ne|,|#Y܊/y1r.Tdx&KsMj$š((?pIٞMwji{\4-VIdtU/˶|pCvQ8O1 φ:Zb}BlW'r7O)i.금k'U 8Xlt:+n!zFRy[t9;"0 Y۱ߦc!Kuo)SVnpJlb׻WP{UJ6sd ) 0p+eWZ<`1: X-#Mḝ~׊Q~嶵2ݗԦ`S@_孺x/J4pn#07I:-MVA#^Lr̯!r[χVUDg2UP9ےK\  q `A>kJʃaZ }*vE{m&ΦPy4FvߜFy?^ 7=_s>>ULf5v+nXQtNho :an,YXMAc]*@R [/ǜzwն~(D}`F1oe7=gev3薵rvl[PQ *p?ME" @p_7\%N}F}DĤiWBOjHIݱ ǩܝ'=ىu?N-.f%yduЦ0aVfI™ᗼ[Πz/a$Ja#0BS)wȌ exU4)QR)C.t[һrub#  u|W~U 8"x)RXW :̖@{gG*Qe6{OuޫuQqkm)ܦθEQI!={B ,L4'^"dq)YeL<@sqʗ´{ul8X6m1]A ԽcRs}5!c|{< ෸!l1Jnh]b){u劺j9ϲGYI2FaUUImg. AmSp`cWѶ ~NxskȌ a˰}tB[Anw#4sjɻpVHaΧ'rz˜CH{g[8Wjv/-@}~2qģεTP3|Ŧer`֓S9=R71䞣VHR*JĚO0A_]f3hIj_}kkR9=GkkƳdv+V.ǥY@iBPH