sssd-ldap-1.12.2-58.el7_1.18$>y<0>;?d   = &DJT x            % Rt 22 k2   ( 8 M90M:NMG H I( X<YH\p ] ^ bdeflt u vw x y-Csssd-ldap1.12.258.el7_1.18The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.V8worker1.bsys.centos.orgiCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64]hKFICDEg<1S5A큤V8V8 TEV8V8V8V8V8V84f9012af5a4487cc9df27e4b2072ece8ca758f1ef0104273213ca27f6820b64b8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f49420f4aacca37f31ec893449fb5722440c08b8a7488b40fc83fded708b6adbdd333844f930d1996202235db55ce95ce2ab4070d1b7aec333a0ee3bb6d5c37a7bd7cad2854d2a00ca831d05db16a62554b00508a7d792001c9fc61db7f67f3969195e99f461c07f40c1402c8b33996c7840c0569d2260b9c4f2e88c1fc380b206ac7cc034c86e45c50bc5663b574bd2774ff401b35e849b2896bfc572ed39dc4b5c2ae09f5baf239a2d9da8d462b6bb5cbc985512e4538058463249a9894369rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.12.2-58.el7_1.18.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpthread.so.0()(64bit)libref_array.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd-id128.so.0()(64bit)libsystemd-journal.so.0()(64bit)libsystemd-login.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-krb5-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.12.2-58.el7_1.181.12.2-58.el7_1.185.2-1sssd1.10.0-8.beta24.11.1VqU6@U@U@UUUuUg@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.12.2-58.18Jakub Hrozek - 1.12.2-58.17Jakub Hrozek - 1.12.2-58.16Jakub Hrozek - 1.12.2-58.15Jakub Hrozek - 1.12.2-58.14Jakub Hrozek - 1.12.2-58.13Jakub Hrozek - 1.12.2-58.12Jakub Hrozek - 1.12.2-58.9Jakub Hrozek - 1.12.2-58.8Jakub Hrozek - 1.12.2-58.7Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1268205 - SSSD intermittently fails to resolve external IPA group membership.- Actually apply the patch for rhbz#1255442 - Resolves: rhbz#1255442 - getgrgid for user's UID on a trust client prevents getpw*- Resolves: rhbz#1255443 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1255442 - getgrgid for user's UID on a trust client prevents getpw*- Resolves: rhbz#1244761 - Relax the libldb requirements to unblock RH Storage- Resolves: rhbz#1232130 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1226801 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1226180 - Provide a way to disable the cleanup task- Resolves: rhbz#1227772 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1214286 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1214286 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1203365 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1203365 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) deesfrjauk1.12.2-58.el7_1.181.12.2-58.el7_1.18libsss_ldap.sosssd-ldap-1.12.2COPYINGsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gz/usr/lib64/sssd//usr/share/doc//usr/share/doc/sssd-ldap-1.12.2//usr/share/man/de/man5//usr/share/man/es/man5//usr/share/man/fr/man5//usr/share/man/ja/man5//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0x5986139c103e263fc91b7c1c18db8ade2efb8f6b, strippeddirectoryPascal source, ASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)-PR*RRR'R"R)R&RRRRR RRRR(R%R RRRRRRRRRRR$R#RR!RRRR R RR R RRRR.?P7zXZ !PH6DLT3sssd-ldap-1.12.2-58.el7_1.14 " W2 =JP^rtˇ:OLhsssd-ldap-1.12.2-58.el7_1.18>t  DH`pV9 $ƨ*uCO.l?TDK5s.SUe:Ԇ.-tWi)K~gǣr,J?|0Hl*2@5I4ܢ\%w{2%rJ'{_HGNIMb5OJOZ5:Yle_֒4Rj@+.P>B.VIъ93$BeI%wO <kɁ#zӳAbJsrlK1bj%G6chܰG7n H{~qRp{DdgG!7U{@P"WsDRD(p}G~L*oџڃf85:&0ĈD`TUS5rg+a4(58EVU"$g] ;AW#_25Lsx*q1kk^RLs0}-3Y};6׌6џKu(*1ecac033e16403f3f82cddb9126e4524eabfdfd4 V9 $ƨKJH#}Ub8,N0SJ<}\T>M_ 2sͰG%kRyd@Ycd?$%Vk+-iU##~*n0` 4(Tg,9Zi]Si@?#~- tޝ0Jnᢅvsb08Ĝ@nA{x#^:xsHv𽄑tC͏/'x UP(1L pxU[!BU߰^{F]ˆu%;q+xiʿK Y ؐhI6y/lo+ $WBB3[MwW[UӆorOnN8i;D r,iaj$%ibAlQJk ?m?dK6NnVf}4`C6iP6ޘ7tW.sNKMh@.9n|;,AN(;"|NGn!8> 9IK%f 9IK&YI.8BZh91AY&SY`a|#|a7@BPD `D@@@@@@D@i*yO6Sed2b =C#f2l F2dL&F@M#4iBQ3)4 2 PMUG a%UפJ2cBVpG!򃧸T" .5ED̩]TsE#@X]_sꞗLyF6! V6XĐgbtm$ -ұj& j$h J,&H @m Ҵie1!|@ B9YvP@.k{i aC< ]Qg)Pۏ:6f4QLePe2`L-FbOlkx|ʼ' >_5x+ *1L܆Vg9R&g}EZчm1j;-'\ˊ&棞ɲ 0O$5D!y~ L"J+k[M?ܑN$aovG1eRmY!R6"Qx Udm̥Om> / %Y=;XGȢ*3ge#a׶7l1ۊ=9+.trفFJ, "-c4SZ Ύ4aj,hJLZ)T{ۏ2Rֈ?mt2[IJ >{R\y#u.iokO mjiM`d{-u L_m^GxpusHBf;9]$.Nhx'Rekw'1mP‡z};۞m3o{Ѕ4 O2`H89?B%qm[kύhBWź aXV$2?nmKO*7ɠw2Alzg=CM->=Z+Mn VG#eU/^O^4JШ|$T4UQg, ᡻i"#m? C$a蟭16(QG*Wícp !@=Շ9Dt0MAٛLNYb >i'p:qI1()3dVk|A-rBJO ,Y_=!5 F A ,,@-^T7p3:?;6WTi(!A:k$" %`8R:H8ULl^ugT-/\ Wb1BŴ6iqǠD%YxbZ)Ȃ2B;]uyy cs&_?'?7R3S.ı Ӣ*3M+b 'i"Qy qǞ;<_6D?`Jc#\j\B<_GQ|Ux^M|>GD%Lp ޴b2_28IJц F4~ ֭Gٌa >t<rC"4w>@p-ȿ!x5eATJY$* }VKvY—4C, ĹKȆ_sѦ&%C.Vgij i>ԒGy^u F#-Ke8MsbHQBuAҊSDu\c5[嘳85"j*pϥأmĮ\s9u$  @Z !3A r{H } OC1Ta8?%Zh2"LENf^’5Ƅ@Im:+7F- 6A%٪`H?ks 'kS7tݧ<ǧ-R6l^ L:uc k"q-/&B,Mb Fl"8x, s>)1UD%cGT@ۖ)`8z7y*fnڡ,"R`rusu ?_iیwP3kl DOCe)_/s#$ r A+&@W뀝,`t:B-frCVMSH0*ayV6m|% fiiGDZ/.AuqK+wu6ț3tDSJcB47IU; VxZF/ɀj6vi&L& PJwZ.KTN!d(-y_.2*J`}+A;wӱr9oXJq ]n[ʧGܷHgم!rc܏*m9'}VۯvRώQPʹLD ZRDžb*Nvե C#ɬn#+웨v: Vvܽ^@mn:3SBbC U !Lլ^]۱7a4ד҇ʱ 0-͢Ė vErS8ڔdzydg^ݨ)*hpqѦ$x xXXƪ6H[3#J Gcһ?k3c]h:WUD8nsg _׳)8T쟲h6U]sZn t wgi2 sKȪ\Q+gww,P{9T%kI}&\-8"̲gE뵮 ZaDǀЇZNH$3kjHqW[^;HdZoKhcV77wo]B<3-ƇY[`Pk5qBaVbQ-ki82woo|Fא&nv&Bwe Ef`L-7'iftza%!TC-GE9d6bTqJJKwoK]N#+<;XG*\Lp⍢;(ؖOTmUvbf2K&xxпyN+\*n!reǏ`TrUpd INA;c"oP ܥ"|\2,H1MiֺJz GSұRwn@IZAF)^1Rz*keZȇ,Cx\SZ Ma~?8kJ_\9'6%͍V~YEoJ6 z6]h_pn-V_>Ó]s-&qm}~U}߬p5_' =]~e`EuϙV'4xZyCvzZ*w\͉b +ոl- ݓ.nTuj==W}+V[ nY"|canx 7¹6(-\ k[nʮ.W!Pu=N)J-""){2nmp_Dߒ)o>@ђǓ\%Ͼ5VǪ8>: ѭ-ȁ-{*>m)鉗b%3{,P>S}(X… 87(7L+YNv9FoA`a6܈pX~0 ru4v:2o~IX)*/s nM 4@K~Ĥ_u?(Bc"| :]A&Yybh<1Э8oPM}n6@{ Eb^V *\NO):gx)@LR4vr98Oܾ3S*7EMbM%’|k66E&5-9/=&W3h[_H!&+NR:x abdIZ$Ifq}方9 XR/^h+mV6{5u>q2(3"Gg'z~G4 %"r% s-;oL&s`I |Bd{JʚOj8S_-#ϟYEE,a6@-lƹ6)e榴|TW2)Z97!׀/WMV!px~3; 24lWka"@ |?4Ė [cV -9~0o;@vߤ^MMuo)dg0#k4)X&. | abwZPı5=ti#,P,4V hCƴA[K_^'/8Hw cY ~@u}2yM}/a׮ Cq_x Or.)ILCҲ )8G eM9%EitC-N;mOՕ(s)ma %TXKhUbbdL@i?j7Uq5QUM VUzH Q96YH 酠Q2 TVY^B&Q#)N$s"޹:ݓ{`Մ"2T9$H;l|.m2\3T<fWw7/\i,ԅ:M %sg.+9NǓZnwC&Я'NRb=MMֵlK66I^R8lɁ3]i& $¯.d`jpӼ Atô nQt I}mnf|24. 8<v.BlwڷPFeֈc Nl$)fM2ZIWtO_g73s5q_]N\y;Հުd] eVKRO--/S/Np&Z[6.  S>V? \0+m,K0-[6pLhc93T?[e\wP )m֜ &[ɀ]frZ p(˔]vkmbu?vodna)[v͚J to%ê} ( Ww z/U,Lp,bZƋu{O Fv0l= VJ*lMMﱌ. Rc2XgqTbn58ݣY5N:0^^^_a_!BbH.?E} Kmm_¸U'Bce"C`*: U O'f,A? IAã'W]A(]|am&lGW\%GdiDjQ~Miw,E'zLU Li^xH?vx(\y͏dIdSIUURzJ(`|v0<9j,+Cw)xA-^|r^z ZųB[oAsaxMye.`|KCJw`cC&&CYJ@lӚDgs3x |_dV@8Ofe} pDDY{5PXه$=mͳ2_6jL4Q] `PAI29 \PHN`|A51 Eai(ٹ/8e긮>BWL 7sp%3`$3R2 i?\{W7GRE ?(~ 9r#zw֡߷Ǜkdn`]Seᦥ!;BHľwV%trtSnA.{)@ՑI[M$;dD^mɄUYMm[,a5YK_jɭۊgB M/AȚZ@B x%[)`W9a%װE5!1?ak;ebq `X_pmp V/3jb3"^n>َ#l}7߄Z6+G"ԓ\Ʋة8K6L#kA7qxm}Y,|^5HC `/{[[@K3Js _ `2{܎oONEnP%^$Ka]9ΥIr0Ղ9w ?*! Q뱊In, 6t/Z?h[΢ثQKgpz6|E5g\6-TPEiPULR+M$pHGʲƤuhMXއ72Yogךzpkrelz+GCeՆ۴&UL@|p=u0٣Zـh/DuO{-̗~$4d0dgL`bWFSHH"e fXM@\1dv`SNۂbitvN"uSFYwaZQS¸-7.Ix،l\{2I&[X<!܂ݏ&|7f|,rۏ1ؽ .^#E5iIC^ 8tԊ6Uj#|q8?YVi Gee`K'Zw˫O6#n70hxހK~>D-?'yV)^j"q :Ff _wlZm7k)QQ f 3%xC'7+)έ<mq܃Po%2H t(/jݼwaCrvSd0SnAb ԭX١hkiZ}9)i~F I;xf3moP4_4)d,Gq;VX=իqBWizo P=!žDp<lC]hKY$'Fa $Q=A] GXMDsˤ2`\8Ȓ-QL%ԩX7eZ`(hn-yK<}(?؛u3s2-kUCYj:?Oi-`Lm݈v4A]-Igt@AO{EkGrKEbS[O&7;ǯφGG_O8X pκ!қ]/}ŸF=E;K/xRm?nm᭽|,vKܾ,WWj~u ҾS<>J6r& 援j&#z- Iix ]?u8FySM_w^D}4.OݠnfWbR]GkDxUk&{Wr6n!#"HkC>DWQp u$MrI-וs CִE'9ou:b+4DWB'(Ģ3KXiǴ&_7W5ei >xkGm %=D8jB=e C1p*D__sg(ϛ$<'G?ʢ>QwE\]cYe&y\_{?q~7Ja$1T|jsLPqIZ"Eڂ buv;xٍD?}r' ~7gߞ<[Sv4JLO,v q\AL*$-44T.caCOQjE]4YVL֮4kKՍja;gך_ۏ};""=[ tsDCCc<8 ⛒]āo x;b?#buᝓ{_9ZL>+j՚_8Ac%qM|܆'18Fp"w`44 /yig* dN~<DBc@{á&%1PzUԢoԄptF 4M˰SbaGϫX&S펭펭펭ӳIx/wN|rrɗ;r'_>,9˝x/w哋u) ;s'`̧0! aX纃ZMZ~IxZ,?$*H-03g-UH<"i!J<:mTʦڜ Dm@*Ya/\](3],fzȂ#Y ۢn ϒf~/s 7! ;MOinQL!:;zH/G?eӬ-l mJ|"HkI'I YLOuAbך&%WMf&`#: sn}.WQ),/ZTzB,Ư?oRbP M, 7ڪ>f,#?<|QCp>O0]ߟ*pp ”.=[Kb}k7\bN၁'v>s$hu/Lǹ1%;iJzQ"E)BZ!1b9g0̌r sÝCUV_U-e_aGwfs{Ϝg\!#v DsL\1Ԭ8k)Džz詈4>PBwpn{.PoJZ* æ\4,fYm!3bw_;j}AU03QxyW[%LI βwXB3 ɫ~٨: B<4ngqTڲGk48,0 dy=3RWL9;Q.B-vcm˘3|Nye-y\mR3ncVb]N;֤f,_]1qDIp:Qٞ%NwvwORɴq!2S|8U\l4XR* z˧JF"@ߢYK6ȩ"(v4ƓuDZR"Yf|w-,e:#'[I#x/5BbnDy60zhu. nS?&]C m*mK#;D߬X$wùD6}FC؋L3) 1pF2V!A|p!rA"ɶ"|ZSx4p[4"J"bv'KRR=mFK^JMn}rUxE"<ƾ$0D!7{=+m+ӣaß஫X}A.i_wE[pj7rٌzMB>pӈ1ݘmi$:=G'4_]Y&/@!>˛wA7RY*:-bzu`.zݏ Ϥ䍋r4t)2G۬Udm[u51֧ $i_mH۟>c:868l?%ݎ{)?Tt(Sv|WF.U>9m\I]8{Ɖ":qExyUr$Nt_Bg2l!bedeYLxH{fw4XKagAƒKd zA^Npr[kO2T 8(QCs06LEߒcYb\ Xy{з"VBf2MNћW7g/Og ix|jޟ89;;> T5oΆGj6m`RrО2zxJfY6+rrțJ 4T/Dњ豸TA5Oԟ_EyB5}pXt6.>oZ_Sf70 ?݇)ML.d_,Jϼg<\ϫ2yy;tsj.eqs,k7Gy0eAcjX9\DtaŘ?>_Ww|\bΎ_,6u쨓_*š,'ww;dZdO0y4FDd Fڤʆ7z#Ek/e:.׺8vB:g?GP#),USyft+Wqƒwo4PUj*nrFuS-+A.Z V2/x7?>%UuO>: ،<ƻF0[ :bMBI 9x9 F8Ϟb$?S{`=vlG' u%ן"m7{AWPc> Un-uf ގov{ݟpZ7wmTHA&RT o壝U j窠D9(mWŃNcPiK;mhG/_ܽ:NH}Wn-y JW=,58vSTN.xALu}AlcD1D\H&6e mhPqx,NV c}lko{ I3rexXzBBZ"8kjP{ߺ7]l NDzЫ ZurG,$7եM̫ ,ʨ:|syy*FA%O>op*hgv4s~.蹺6 : ̦B&lXrC=߯Y EXT}$[ul 'WrA`bA=h*)Jؿ f:'#|ob4g:N){ݖtu9Ja"$;;|?Ӥl. W.$❖uQ:&o^I`³i0|!T+8L3\]U gGS7![ dUG^R Ux*>yAcL+ৼw_C wn)N wj{bNGy0i%Si"#&|w1u•o)A1* s+ \xe>Q@+ 9Fᨴ,T<rt{ZɄM}!yfjRP)2"Ld0E k[0)]> )g/zJ-:SWQdʴhAe=B=G=. fccFY*V\\:*u܂ ҒKPqK!|s ^oBIE~ 6Ȗ%n=؂L Aib^bq!W27#)>`zS #be2l;’N~x7МCU4/nʼn[/h%/m&Wlb5ghEInv%P~j}b0σVt$&zd Ẏ 3ayW:n&[wц*zRy lp3i< Fv#KCDޔn>Ccŏe)im r wv #+_i IӘ?y' j:2ye0; ;АT6}h-uqͰc7?R(ib)׿ڨLh.q[nG;+6g7u6^s7WO3RBn%l9F,gZ؅8r|r4lBS򖛖 㸚eia!IB--q܄ipgī '$de>VU6ӂ 30G356cs[ojЪTuii3< &2(J9xdhr0& cdT[An@nլ4Њ&zd`;mo'HnL{…$,Q[)vA͗. Hz :ck~ s~h>xCf9POzX3 ^Qo<*. [~bcR9EzY[{ 絮-'f/ 7dK\(Pۇv3rWQu16i;]Ք#qB^BO3ܻ16hi Nesn%UPV߁J#Xwvs\/cIqx3" / ɔ]jVX,zCڮK֨{M;gH)pRn|鋃`̛䪩 i}ƔqmZ2LSpU0Qg5Xj@ڣ|lKX | .tUudA $M$Ƽ/3'sI]ͅj-0+Q3) *<. mJT1&ۄB> |b`?-V}jx<] *:]OL~6c> r¢VqH;j*>MXZl[MؾL9.^kP:iL fK$]ʜHo$'Q3ه*o5#g}3(Z߰%U`WфX蔶yu!PC'ҼǠp2x}X1poins΍1/ĩ. kTOusCc刎|CUHZJ謡?L9k; } ' c>(e.H[Cđj|o)"ޙYڷh9 x;_$2CWhOƟKv.y7šHZl%WnB~(?8gg\K>r84sbUVVsڟctCF_k!bWWpQIsA'oз[λ~ܷm= [ >px"^1޲IUl;Zg>jlAmޔw!TIqPXG-wKꬖ&ԎR8 _pLݺ͔%U0c2,/ U;꠶Hʱ\I DZ_gIn$]uCFzUL/ !͆j/s^炟cqWkǟH;뮽R6[p%s% 1S-Zd#P3J! wVee{#[M3Ў@\K0GQcTiiok4+>HPr G1Ӎ3Z&7Բk4B,=6 V~vncK2٬ ß*Y|uwp 翷rXr:yuFznݮ[帱+w}B=&").Cic^LqIX ~c~?6{ $%Ʈ UTE}}]KN@{d-1^xN.$<+:T.S./ipA]:zCrQ!kUϾe;c$eϔ"ID斷HY~ۣ )*[Tq*44XU{,Ų7ZUR`?ݩ5Tکݜik`q[kY8❲a}XElB\ .pho щ'Y{wϮ-~o+>~F.G#qRK4 ;gV*U?J|X9Irm CWgC"wyA&|!M}.׎>ti@m)_u1#KoA6MaѾNhHq*X.w`P}Wf\;_*tz ?!紃1~jmҰCb.OEDHԎq\`DYiM6HEƇ.f;HT85ē꠼2$Epӎ 6rj!qYX=k܃EB+wAt{e(zQl<"Y [pP@? +'QrV>fEP7`l޿Bc;)OGV)n+ 甬(_'(mȑ+{{-`q"*JgkLf?[P|\v~HX%qY M7{gmcvgHyLguUPem%K Y45J}j'q[`痵"}EZOI얃! ؇$*wK0P[SchAfO o"[zDol)}98@I/}CKSsQ*=ʿ;%(B\&)C jtLpj5z/  8C%;L8ܨe8SL:bޟMvc@@PS.x5,A*^H5pTӶ76XVˋjQ z.,.6l"JpnSж,}]tf'Iۊ&;v!u>kQ!SlL3za=|IjX[\1N糷ogoib"qvZrdŕP˅nL@-X<6* qg~^Bqb,nذbp2rzBd٬3A89A6!4oI>\sj;]yXt7K?s`p=\II;".ÁWQv/61",c|/.#V)$kt`JHTp38Ÿc|Z(ÉJdWuĞDbE96gTeqѮM[+_#AzG꣦Ѩ,Úealop'ϧ7=75Q$DžudzΟ//g'!a4('.sNU,c@LNgq^R6D۬=/L 2 N#C#Q8֝o~mNWrM(ǚ|bGS%Uh,v1USZ +_}0-_HZQ֕fsE4tbBUkz^ Cvo8[|# Md-8zr ^?}AgX Gwqy&\W4 "jB3(=Fu(Li5wT yEoY>ogs+B;b!Y>YQQ*sc. \gJ1{4 5f4.^97`6 M5$Irj,&~q>8O<6\3Q5}RGǣ(ejHV.j5hG{!#2+ÒkXZ> |ш֑,jR``c+$::^kh3y(+4 ViY`XEbidcdQ?(.+#^fRzvY0Ԑ6B Tf}nZAQO;|N8/[#7ī)ׇ}w^aX@yǖ8D 5bf;URXwI8#b_`.O"R!U,y.'f9fL~FJ _;Nbm)̧nE].XL7oyK9bp\I7`i kq-<:]sŢNՄmNK j%;e{TGNnx8X;tȣiy2{Mq6Q㧍*H4y9zRySf1 #)ԯ%Iw78'@c@!ɇ&)u~R^R!:B{ط> 1<ƞ6@1͠GϾiV(798o_F^""gIDy6)LVX?wy {͢ G+ 9ʎuUH>`H_&5Jj5G[̄^AdH )Qz(Fzd :a@%r#9spsk ypnzoyw&\dNh8K-{`\Q},K\]~BMhJ)0ݬ2p "[1Kt%;8 S);C>' L D1g,L<w \UBe> if=KBaʤD M\j]8bƹ4h xcؕ)S,2V=42 "y";}3h~ 7`J઎ Mx?{az32͞-u4 Ƴ@T.(+Y@I/!%%) Ig賶a P9fn3P y糧Gs?}Rk5jPD@PN< ϴًd) M?sc|/hͬ&j\?#!Q <D'?QeY&aE9Q]2FHWh]Bާ9]kmTLk/2al0l/šU G s+xX> `zDv@cC3ſ=-ɳe%)]}~gZz2[RTb]4QYlj+_ Nk8?ߥYThr$R?[(/$PRq^Y H_|'H:1,K6e1<{sYyeDon|8Z Xf?LhI3`4>el6Јۓ-A(Kuƛ\LeβVN^ `.2y!wjхKhP9/}jIGqSEZr!IPIPH8$ Q@ߡT恢eE]Er\P^7 u*tl@pE#p x1.h/utC9pWF=Dk*~]ƹ Qqk3q7ZjeAD)Eɕ;'›[S+ ƕ v?H8o+bv}U3` Tܢ {|Z1<‰nKճ 1]~-S6,6x\䜋z kv ;nra$X`e'\i73Lp[Pjf2NlXj֔2a²nxijS_r o ^j"#h5,zt׵A칙#Q.[>?2?ʵIIK96YD SwV /}e $8ϹUO'sVއfj5x5HbU }{N9OjuvUe+a q8D}x%D`i5:WHv>}yCep:Gp2 >H}>H`\I]҅zf3:,-CՇFR ?"~v*ZѺ$֮?ݤIqtZ q?VOiVV+>m7R! $V1@^T\| QfM]NkЌjw\%8i&QS:N(v.35yTX2;=эܟC6a@GO*Ӈ!"RJaEi"К?Eɚ lTDP[1VeQC+$UTdv:67(7ttkdvMm^eS-_0AʓEYjغbf[/7\MeQL~ǁ"<54Tڴ\&OW,A'niAMoAQBK(6vg8x[ո$ Xk;Wcf}7]sCB|XJ>%[#ϮXX]RJ{vk^jz[W3Tdz?[ .FYPa q:g4“ \>%Oee]pe% rW (-g׸sᨒ-b S0!a灆۬FΔѳ e~ju@; ;Jjە<1{V "sm.z)Z0R&D7b@duQ $A;z9=T#Ic %~= ݊'A0:2|y,8@"q5v;:\Lh|% E7[|,?e+/n݄ԠK#NT96ҩГhp/VOe~w<X">NqC/|א:kվ1ҳ X wuIia{Y!^I6L#dJ+ Á;h [$ZZ0%;xm-wkgwG$~vHjDB2؜$ pE(,,pߗ^lA41WQys+c>/_={ =$rzޟr~9_ϗ\#4_NNk/_x^9y'x0͢ ptĖ HF DtD)ے< jt<z; ~Ml_b{Xpq^t %pmr{fawVo<(ن-L]Eǡ 3Nj39AApS:֚KILctqqE=/pACb.+=5Ft*zTA϶!@2m~9#W9ʥA}R@m^ Nᐵڻf1eYڄs.fc"8k2u_%;~/o9pGm^Dr]ҝębS-2![;N@JJlaϱOFN@K+WđnElټ{7Kb SA\#>omrh,0g ߔm4DMcAP5‹npFEW<{2@_A0Qg$2%[##(P3^z =h_vkwrRkPrz>5_Xդj6yob'\iw?Vƪ a&֯,2¥.'ェ"5g[.=Kؗ;wBpABj֑n|;(A0dwzq_5]* /iphlgK+zj#F[?'{4탯Ar禰Aū(8Xȼ+֎; s  XVI9E]嵯ȗ ց^gL0ƉуrO4_梶i&v)&lv79l͉-z wQ7; db cò= Loko/6xw?^rhO 6&Ruk/w)'2V+N+̠.υIPmI`a%Om$CͶG_fM2fZ v -w YX0ڙT\9$qlɚ # e8:cܳX[;'~<ۧN.Ls?ݾ84t+,Z\5]v:@l K`eApۥOvjvk6?Wa[h?h9;.&r +t煥 #9BPr?E8i {-0dݐbwtang"~ SfvxhBĎ5`vưEfStG`U {C KrfUzXLOhqJj0c80tfv rqy lUHAv$g &;)ɠćR1 {^{Ϯgk ߷l&Nwlo'|)y0Kcѣ6POJǫ9Fdv(TLbHqHK>GYAS4{,;mɠ"cьeAn]Iyucf Z5mW2hPZ}p?WU 87^8 4v2IpHT4Oi"l`|E>z^:=EF sdw=āRQ#;2Uz*o:!PJ{m2L 8d[_&t:0\#g%%3{Cz 1ѹ1xan'Bt^dB /;duj8{rE:,-} gDnM~p:i[]^XTȉC闹Fn5 JgFd昺Pz)`jb6vOt+* ̜ ĸsE νf]LQ=']RMuY\x ](tNx=ܻd{3l֮8&=7ɿoCAέ)Q5 btL 2$}t\% |1?Lvܝ2eAgiZjM6\G~L"10 + EƷI P[ӎcX1D5ٟHSn^K\%5XC_ZgBk02k:xм!+3lO!̏!vׇ~|ܷK&[M -@ҐLxLH3!]ira2~0N7&YQmޕi%>!bbβS HvD&RؤkS #fzQ>S9JF1vZ]z-{Dt+@p+97G/dg6}SxEtOZh)Ј\.d1t2)WA+ԶT&L\+ >i1z4uF tEh˟>*._ΟW`|&N?ۿ[Ytn33[&NWTi5tNd3d rVڀP0$;lE52=pFy3O oBXF?Y aZ̥Mn$KO,ݕ^:aIxMv[. [p 8vmdM,nTGLs.RRhqUwVϱczRTi @nEOHQ2 c?Eg/67m[OL3G)U07070100000006000081a40000000000000000000000015638baf000004413000000fd0000000000000000000000000000002700000000./usr/share/man/fr/man5/sssd-ldap.5.gz<]S9 ;0`, 3bx"܎u[vuJ ]{ai_enfvPJe[)}_g6.d}fҘŁ-Jrދz.b^Qf=ũx2.&铑VIޓ>wmlvl%o˵m: Oxԅ4 "HM 2=4| 6"kٸ5lQ,I&\dTlm󘥏ʆWǧ]_GGǚj|zh}4mL#fQ)(ڡ6d"FZ,߉Yx 5᠜a~O7fӳdvJ7˗'GW }[?s"gk8M,3'Ah昁&+@ .tv+`~"8e9WH[@;u/7.m$*HpU‡BLyNhLd,0 +"_;HCssceM '3F㚠E/tVdF%''=AҰ_Q?9΄GfPwk)_MO,SLXc:qޡ37@1*R5x~g+fjHe4@4w\j h^3;Xz6L7=ﱯz94J>̨ұiY$t {[\h,R,ԭțcz/n/)ux7u%07cA+wIY B2 GZF$5xF[٩+k0%8P0u{d5~KCZntZ x&ai- ;y?cy1}D#zp9v C j{|6:qHZ60uŵ>. 6vvw{n7`)dBheGkMxkW Y+ x2n%c}iPs(\[9)m漋nGNN2h)_9%eQ*\Cno< %YCKʵOʡ(`eJ؈ )AH+\p!a"P9rL]O IyDR K2)𩈐5XM !o떀FQ>ѭqvKRQ*Ee^XA6&&^`9nr玢W)R JBSX Hs0e"$8Ҋu_k^UXl+1x5$c{9"&mD!wq-([|nGǶAMt?YC ѯ\z^ 8b%+c?/v1ow~яֶJe-ݵ3Szs4tKr!dӚxmaPQ/hYRJT!@|-ȴ(?./ DLZr Y(-)'F/wPHUo$AJ=|g } Z8L>Y4*Ifʕ8ו(e] pa{;;v` eC`5W`$!%2dꮳ Ӌq\$JB)ځצNDc7Bw*P4`yKX&ڇ4Ep(:^E]:.fcu5/N +"Q__Un^8xQOf?Sp:ib>kaRw@1A4~;2V/n.I H ˚EXrݱp1L ' ݽYJf+x¯?+q7Ǯ~ W-}V_*mҠB?;sGf9@J{ڗsG\7X [z{PkGRX͵#Bgy*$1DBCxGJ TDҟC@"0 G7uv/TȟjlENqiRyJ-fKnNƄ,טv=>NcL;8iJM &,BMgKEE?;:}QGfJRX1h 6UȠ"ԇ>,,qwTN_fYCp`St>NR\n%[ǡm|?*n|ܔhZƒG.ƄLOsh7z@7/ѥRٝ3mOqػVfl~'µ4 $]W C_){ :PYj†0u :?gH=.T$)qxJ!~uCc%<]i7J. qgɽ7Myxj2};5'JV?A\Sq<Ιq7΄NZQièPt dC42j[2cx"p/eTsgj)t}IĈox]>pb]Xlad9&Bd,N0x3ƐA{dD}9Ougág|KD{~/0Т 2%J<0ªZ{"&\c! D`~t. 5'pnypz$x; r$QӢ@qq–4 `d-\׹ ~WY8#(g[UW053+HDivP-(֠]uPD/ b8íA#*9MykPC0@Ţ12HT d g5 wf?W5XĶ{OMfC8ʒܷ!b(BX_i =3Of<>brlHh3X7\Z$E=tj’+ҕw ;zWLkS[[@q:i"Xlm hUm`PE HhH2u^$7i o1p23-u'z2*zG>ǡ/$ nQu9/kUQt ;E hX~t*kajŻ~;*eczӍWxdhm~7[qƂ\,"_?7pfۘbF zjNUۢ?ڄףqz:=)~=[oX:[@-_5*q!`K9D?噐.~Cyܝ"yZQiC[B'[;w6I/ jqTy>. t`p2݇=gÚ|M:!ݬḇ% U@8 ᮫hgԝyA-[_S-ʂL籬RؚX^yFDVBrf.H\7+18w#p5&*15gTPVHQ]xa8j\M㶐G>AMeFDkZBc1@RR~Src[eot7<YI)%.X@x"{TFua.u4[cW}X,CZ^=x7%JQV+8+|̘iA],7i1 `gD(]\o}s­_1Hu.91%49IK5AVoHy#hsϿPf,j^ؚQ$z\uE):S  FjuCSOs]3gyDH+@'F#Yj ց2NQUλ QvHePe5l }m<G!7(+I')62LtL#+$mT7#fݥdbjr`(ˎElF~I`1˖M EsN%6g??N}a.QcBc"C Uq §z?gû\9K2q>m)nOykFV,2/bcXKo`I^HT'bŗ-ߡ#2$Ծy~vl_lj u]pAGE 012|7o)AymQm; үmrRMf7Yy}/ONeAʿ9LQ$+b'> 7HD0!s1DKFg84ԃL4"4b+TPOA]Um7u[Q#-Hל][ױz0e׎J yo2sT Y~qpK<#L|L".[1^-.k,4!l6_qiA.`,/]y„0/"kmlRr)ڦB  `1ڛL5{K,4꠶ȧbF˦&CX;0 >(cbx@ۢ/x,0jPE7UkϸrB#Kgǰ, da k\2*\Y9\\1pauB.'cr SE5fSPuo?C%)_CYJД<t+1"^&Cx0\hLf[ 3 ̼A2K8DiX?w8`0|+}֛-ʌ2$c ܆SXdLIzR[Jk3VAD5ryS. z blJҼ^/(h p4$pze,ht ]P0>3W|y7'C1!( DU\\xJN@Is g|>ЫR]OvÌlAJ'cg734̂!Ȓ}7/jFO0f!J C+RcCZp<`huX&}aK3uz7ӡъexZh8FiIIm5<u9-fI+(){8LD4Ԗ-RߢS,g5}z]*e D1LP6uvRyP=k"4 oznW: = .X&S#=^7[S~28glc/L{z :^k(6֌ rzKw 8ܗ%{4&TbL.,ȫA&~)BjDJK|¨`:cp04NЬA3}r-Φ 4dv^fS`{og:=YIEs,njJW;!9;ܣoz _¨g\b?& /Flrު~݈[a j.!kL4DR¡L>`f1*M|4pC`d)K~ܲɟOmiBC{oaGgdK00 uEqcT[nN84 R#8Od13>[T6ҕi*+qW&Je;Vp6 (9cNOAO腍ҍA ܬBI m1-;"; 19[8)#y7:\Zp+2­)j ;0C1shT룷SB7BޠQ8z  V'j])@eR+6Ʌ_^|stO^2FƋ ܗpU ސNN+QW -g3(7yc?ttN>zprϝs{iB|# I bփp.EX9zU6<3c=9k̑TmᣔahgaJDn>?< @KRȍ-A/(w?H=u@zS}' ČɄ&dFb&x67V<kLtR<|b-Хyc*' ,<bVH pA8QT:Nu䈈vhϔu.vm?!x~i ^Zkr3'f4׆OZri.C+*+Qj(%78 ʝffoĉ] vB(EB"DᨊjBʱNł&Ư+V-a`QiCryRe`SI%BD2)O0@i-|fb<-t2% -vx]0,HcB%MSF]C3Fj|cyo|WADvL$L[B:%π*ldv]K{>O0zUͯ]E ?8T`:ԾMÉr h rP`L1=Ag: ̃XqJ’ZB)V \QK-S: Nڳ6޺N- e]^T(=ǵjjL_~lȄb xM۾ym[c#6p I# t27HVuw9CblV4Z'/zF@ %YdI\|uڌNI̦VK$^8thEXd- ^NB*GȈq_ɉ\YȆEʼn8*?~k7f+Rp4YZ *ZHdQs*eĊ0'!eC0 Mnikcrbsp{J> ]*M,{:>GpjR? 6QH1i9UʦSiPM2c} [넆0 =bO z")vy-FnN4`0Kz GWE 5|n˂"~->=;X8=U^I'r:ծQ둂`CRr,+''aᩬdn7>B$`]0p&{u{n7Q1e/Žee&oZu/O0)t2Gp#7h8 ;Xmَ8G}}♅i} s}PB+O#nxzi(ZPԔ]ԗ&01@  Y=کL]>_UѴ񪑾i?)nf^_k4.߶E! i)J`V&&>Q0\,@웋aq~^TB]X@U3/.ȶ@wwՏ#S.\!="?.冎u>n`J*wWqN2hB}W/- S.յf,!F%R)Úߒ\)._2ܘI독j0f])p'5R F– NS4._ Pί'T$eP9%b8w䉶!z][h5žn 涨#_KFPhхTVsV[?T2W:1s.Y0iM8}{vtz2NzF@@t=^f;NFIAީ"\+DaI#ˇbP|&)|]ź>}BVv8PcAF탼&C~bL`҆baVdT4eaY+Q૭!GQC9z$3mӱοobJ/PXNZѽߜS#]4?yfl"E}+v6AR Oܕ͚bշk=ԹΏa@7 e˦HHC8SrUS"icwj~;Y?iNKWqKܤܴ`юA@HV\qf\k%9z!]GL8}M≝},ʗòi$߸ZZX8AڒV|D-Σ>l~pA|qb%3шki+W>u?k9EFH'y?*"جWn~vbfP\9`m eVW:t =CPd A)Blӄa F.ڈ]-W%lLvEi.jDv&~Liݼ_q@QCSh BvuPgf [-WK!~ T\GU *P4ISڦ,.?TmUf$ÀK(]bGN&t[0TA&D-_8lf|݅o-wE0Zfo&.3-3Аpۆ%5"D@6:I5\w2(1)*e\}pS^F[f ϱ/&B My(ɮ1f\lL4alSd/׬n  g_i 1fR&(s޹ڇpXu(X4UGܨC_ysUÞ7!}5A)"c NLWϥDYWB BԇıRЙojd4 u&:%P;b\xKF'kLJ6&L6Y 9k(fT[RG̓4ޞ Jɼ#k!KCT *H8E +rW"t0 ̢()t]x9v1'hg. Ox=3՘ 68׋W+,#VdCi&J^~}c;z߸eW}ߑ}좊 X^a{IlqNPAC")vа#+*dDmgSfoTF#?kœo'G2 7xӽ⨦9tDrg:*8:{J!%d4!v]vB Bijt "Te0?P՘?OŐLK[2ۂ9@M `qcEES^ qH~$$,Xf0\%e,"1 EG\jG#(,!0eolˢ9_Nΰ#갾>Jұ :A?9e۝:E95g9A-i|g+ij+zY=ހV1.AHLH$?㪨rӼg=Pah ڦq{{PK>.'V_Р8_4^-S,jQDZtNǪ&q>q}O|k nc,'gA6)!ӟs$c-UG9[r)0*d=0QuA9mc=* xg&RҬUI(1#KWps"fDۆ~3 CaXA"pݺ Gp~ngKlM!]{ڝ^?p5B-WWxmC`K #2wi|)OPo"gw귔N-2:9=KЋzp_]up/YJ(ۡd PU}@buBvRb*)﹍ ފ-A/u"DK4 o+E1:{\e #sq)=j /g{_o?_sbދmioG Kt&4EvJ(9B)3sDG,:k]5>I酕Dor#iQW"Gs&yLs+ϣNI +ARsIRp յ Q.jwLlr;,5lޢs!J)ufJ6k6m c8msbЫ+1>fUewlP f~4ۅ7c!W4<&ew. OOM1/($_. *Ba0*.6o^kh2ohq< j tpH?._cR~Q89%]v^Wv'M ڷjYOE0\5:k1&1qĸWLF x_aMIgEh3(63G0ddŊۤ"Ji][9fpv8 8<z֙sd&4S,Ag +1"P}wǯ 냳wC_ᦴ>AyGgG'l(sP nwW%F7o5ՖKLBT>#IZZ݉aY^cv&#٩:?'Ɯ1/owv_-%QJ$)x-: ER:żHQEm8Z+Hw)_+یחbD`XTZa)esyC:y7lvGNj<϶=lC}e2cqc?u~ʍ>*ewE%i:q:4ۡAF7~5~Cu(>-(^ X"UtWp_5HCFM<(b6p &UK1^S椩2!|lIOARÞ%= nfpua7W'Oި9{eϖj¶]dve;`m'C[v_~˛7_?K"907070100000007000081a40000000000000000000000015638baf000004567000000fd0000000000000000000000000000002700000000./usr/share/man/ja/man5/sssd-ldap.5.gzDMP]F?~sGl^=Ku=mO7`h݆6,H 16W\0kWk,Zegw!78R?#?X-q:lg{=}wfidzL}A6`_߮ݻ{o*̯\_S~_>UO^&$,V#P̬dٰ5t'z&>f8(}`hp-|tvZ#(o!M+Y]%e2;E 6eu$%ӻݽ#ӓ5=zjNrnؕL]y'۷:gI'z4 eh[7OQA:e(᲌e.鎒68 9n*nm=f.Ϟ]Cs13.+vV7eζEcƎ(KL O$Z&;ytp{[d0hY&ubhfyf 6X_:ʌ_ᗿMW.~_ZiKf>@x{mչ//S~EGpm^%|nڗMt/K ty֣L~_Z7CktF~[88%;m~◿+K[\lyRk~.=]&N ),{տ-#12IKLN( ᲌ \iZSrau\AyrgD9_ $JrU||Ԯ>~+tMHJ"8W/`[~ lg)՗'@eH\ UZ]:{YFWJ~[rŇN3Z+a`.,q/-(]eN9!/XpJpɕr@,bh(AfۨV[]"7 )0֔ЂTF7\n[6.U5;=-{gt+_z*V=󭰈uP ޟ8o[0^ts=[bSZQxuޛ?`% \BTZvxAXs?ά t|8p{urgh42383ʓa 1D#>8tbKY޲9nsE7,@)&a6ۤM.O`WhS64*TNIz٫n/jdPR{ n ^-^Y}M}Vؘ!j* w~olzwmwWWW/F;jb >ɍP8xiHy{ gS-K+A655йoO\H!Pa l+~N #|UJ-[%H67!uі}LScJ`.v?QOT nbɶ2}ɶ[ PZܜ7F 75jadE= h~)!a.0Ǒa 1]H ƭ)g3@3 0\"/4ySX u# vU`a@ QU4uX lj#@or'0ZC"9 lnx`e =!{o\3a]zs9ؠ8sܲܡp':©Kh{ Xd<_p&$B`<&$Q90hLD;8JyezBPae+E\1jMkB (HO#@|A?uDU HHJ5Ju0 0CAMA}*\BIy8I׈|ؠZ`G=!<չ3X}yE赬 =6Ob0)Í9l7]|VA! xX pua' }`ҝ-G[vb7EAĠ# tXr 7(>w zT=uME[<}S},[ +.>.r;AD*Z^XlFC>}t} @ض  YOV2:nqR-m*o,*7ʐuCM|[S Y {nގeHweݻY4rƟ9H~],Y=~z’IqkcpRr9/".>D)&bcqN ou7u4BTGh[aCD_[yByUޗ?@/)gAY E&{n$3$u:c8h75N+fD|Q7=M[qH|pI%aee"Gb 8xY{S`Fc:u: K==^9iUfWQ\ri6(S][~X=jtsm%LG苫^hNӶSsZk  <9}D5eM?̖f0|j$(R:.-m`JuT+aMqHsiV'!VBw9?떉tayP8 nwoޟL6V9JOF;btG?J FgjEz<~)j>pW1Ű e z`c1@C="*Un'x]Taoo BLU8tj:4qc"NgCOtaxrzkM lei<:8on[fd;6YƓXXL4 x(\oKcGJMRjf8r! u](\..y>xFɗa@=YF1&M/eb nsA.'g45< xnCHum&w#$V~*'\ĿzXMmxS}"b5[/dS_'u}eз!eqC+#uYnN 48(TPL&&uB]UVD+քJ1%3 էt'ZitYS*i*`kiv< (JTV-u kQեo+D钬OsGiQ6m*RieY?F`eD[ Vf6JsB^qKֽ5B43@ JUxxX{Bk=@8Cm6qP 0bo+-j0 ٣@h'vĴ`Nl ( p2hNRr&ك1I:IPODZZoJQŖUys[g" %M~ 9$G%%Vd[$7 |7^.u}a 7PfAYM/.JF#QfȕLĦErnl-϶}J*~d=z-F"VvTa[oXh)۲VW#Y;Ovv7odZx_X'4&ViMjؑ) %Lgtk;k[u4|}tp.֟O=:u|DHJX(Sb!lQF#CP8njeJlϟ6G 5KKz/`HYnvbg;;;Oca 8(qmKŬrw*H Hq!"ҜBG"VNA-lRΗt@o@@2"VQ!t*L/6ֶd(GeÛ3qR...Gc䱦9^_ܚoCYnurzt<:8=<}{{~v9Ed#@j6TYQ; LY3 M0CHZ8gGl  ߯Ǔś fUS!gkM|`Bai!oNY HtӔ"iFiH <(%4TWBe eL=c-}`p#S-$r*[٪84 ߎ#WK;NCrIM9$sW6LU* E `,TQkx4'rO;SFJ8~NH$qrR0b&)5d+Ԕ 1f, vvw~{aAqkcGP58]LD -TU8%Q&N܈I*!⃸:i_$+Cٖ郦ܬ% U3F"ʑ"{IQ2xN܀ vs:%4tFAhV|: t6eb|뗭w| P$t`Yu=V*^vݖSJR\X^I7D6.|ss*"< go-hc6E[^0xuK c^b 9_i|A W@`g3)iAښ:ZLkm2M0fDUd﬘^h]db>n dD@ )rXFÊ Q aXdBdSk ÇX#DB.*1Z\ Q Wsx& q`B(//)F=γ p)|"O("pl!E2hܱv}ya+ 3ת+ *w/S#sHI^j m _nNlæB-~'B_"Q~! S"BSVl'>Q!XT=^Ͽ`Zq)PGbswm\ ޣ{jOQB|t&ōR@V-K ~nnؕD%SPX 0 }8TohhMKx!%!<$sR6H<?ST@v́98jr&fC1363lo U`y9qK3T!ewK0R+T\MОs>Sik X5\3z3J5pba2J[,E \bvc:aX ~_% 0rF L=smj1 ^+u g+O &^R=SIZ=:f~gN`5t]Ȁp!AL?{V\HH4AȢA_W1;WLbᎷ^Atx^{wz "M*Yt 5sF{v1RO/wX*z<'.:8) 쇫 (aL` x7 հb4TZkꐞfBCT[@tZn2*[#z.#r* O\o:}hb,^CF({m˰&v-T0B U}i-Q9/ =&Graz cij@ SLjjj2L|2j2od.U WQZMN%$;\iNOQV/& <~ Qtpg`n[ \SvHD+Ch}iׯ]cxI;=o•I ' }+d.-igu%܍9hZ-͵"_e7EM9:O!=g-gD)7$BOo.V$?8%‡б۪aP1e2#q.C(@2w՟PRGة}&I-&!od_ ˽Ήwh3;;?~AO {jk;C7o)l~L ` T5Lq]cGU9m&00[ע]V dЬ*[U,mT#ऻgLddM5ouR;M 2AH}%F5Agsڊ=aXaWM37ԻDw>yC ]xPټ AB'j bcR5p Vgjnն+U[U) lnR+ހրexϵޔn>ccECW.%"v>)T"a/AT09Uj5)3Ȩ&h\81iT$uh tvBkڅ&5D蔾֮3\"~ Hݻ"2p~$5փ5 :f=[umLܶ+ӚӪ kLݝq܁L" 0Nؤ%5:Ȑ/ t^U۳2YԄ@D/߄ r(\;:҇$&z#Sl@q))A\gAcrF7 *U/əL&GF2;y#O9d1Sl} (j> 5fDӱnK{׻[woN!n x-\N}=/glT.×]xdM= ۶! 6rTi嬯u p͠6oܚZKtn 5h'nun@؄0 X n4 zm3yG٭'PVl35^57qpƊ%]ІiݦfAM~ԍ%NSjƕZ1'3[Ґ0sfW u' 'F5*0K3l"#R>t/듮=#si#.{,"/>i0we7ڪ]piB:G%'|â;%֎A99ER*܋"Ol2<y "\\֡ȝ͏R_TĒ1ǡQB~+6VBۘ+ɀ/'_(?vqNtA\ \sU9S>ڔ9dᢎdPATq A0SGez0p8*ۗ\0q\7(dOjaكق%.>"fSGDJ#t#*s$9f]6ZZvuGz8P-\#m[zן!(fi /TR?*OSt88BRb6w&y8Ƌ &rڞW|"Mk=nBI >@qe.U ]QK/VD^S K. *1}ADޙ%c_|*zKrö8!kOdžu?XR|O WZHn1 2L6˜/}ݏ!r3"?wTm!?NE>W+oacݼ` b>WΙA4z^{@t?4(b0ek ~ =BIRӸ <ˣg '[PH8C-_\T5ZJ J&J?'с]h!q1 &޹ ']KVEd4 Nsm+ vPOY͇NyC#g1y#teZÑ.u/"0R#O 3萟Ua0MVJ9ŐAyC9PnB_lMeߖZB=:l2`t0zMg?E~] Mf_֨/P>”/rőLl$߀Db gxjuKK\4?v*_F|g Թ&x]2yz7|u .&RFAuUT?bC3XR E[x Os>/F/"uVa\[TJm~0=Aov3+u tJ#x2yJ;^[A+f@`ǜGW-+z|F5m]@D!3"^:]LKl53̒1HyaāT5jw7/>s͊`ŏh]kSf_rLNc8N)I<%ET:="3ULLZzsysr>C&8e 8-ITM[CoZY4wBϤ,_9q2B<֑eѳ=zmj/jWG@;{h)P=oK["8?)pdbOm|g"瓺oMc#㤼41-pBw=4wلxkMAjϨ\ ʼn|t! q·Lk6S nIe.p#}h"q# MiuNq-);l-X&Xdsݮ} @#Lt#ަw ~F7х[R ytRSt8 3N+*_vTUتF0/OГK$WמAIJs]$g9^Q$N[wie\M$DoBC1,j9>%k-& uURIG8 +BDYBA3\ }bIJa$QKcc@Obje_.EM$ߨ%ĮJT ) ;e}I E*N!i)!Mۊ9^~mpY4]cB)" 0qp. KqjhB?v> y ,RcP6oV3 VrraKmqMn$=D4H- 9I ,cI" 1X+ӲXދچFoODRˆgH >x8ex9yAAB$1YKVi>ZҍVz"P4zSRThI(跤dkn5[E#휅{h蜅]Ou$ Ɖ oDj¨bX wM˚QeE$*9)f| EIWf~?*oKϬC93e/4|idD9OI VQw6B$x9AGXȌbn~wz>41Q>X) @!%KMM.A^(Sc}iwD0NS<ĩa$]ܮ“fy-O;b bwbZ9t(^ aɶ׵Zn|b߯TLB\to3/ GZEGo61e gDv=pԆ%]WRn+D c('K>˸t{P X5mPND:Ѻ1tF+حfH1.nl0G!v6ΦT\֝>d{S`&Z ,kiwmT%r[RިZlݲ>P?자agW\PEG]˯]~N9DL˝C+{q 0Y007ZRFFgAwy'g Ӧ~lmU&yIvD={| )A~fh+ruL/Xl KG)?ӡjeqb{~} ̦ȁ֠f& "L̩qx_%O:›|:9_#LbTu5#'1mAd$ g"=ٮ?KP.c7i$J/4cM&Wy;rlm7EhyCƈUm oMj+٩YBWo4-ݢLq.2ɳw۳g-8:2IH - /imdoYe9XD|-&=BI6Yſ̵ADV-cwԬ%֋  #V0{eC#va hx!`(iΎ< ^SS)7İdAbp' pՃjrc%?!ߌX6A+fv2L{mYg證>V qq}dKJIi_2^J.Pˬ}gpnKHnQe3mtC: U6sZW5QZ OS(&veiUX'Tb9v}1+6y$1 $Q$YpN h@d0̩0,$Ϣfd>|ڇOKç i#>m/݂U {& mQY+1fVbndC_fޞ]>=omqA"'ɪ[_ \21fH4q4LTPkܬ14l׾eՀ}CQR(:|ޡZŸy3:&/s`7} ((mr|ں^94AsG2\V2b ΪCpXzC7kB!HDLPΞ]ɏ;o{inrOJ#$R$]ckQBb>HR+F: &C]  Nɽ=>[O҂wtp2f},_Bl6VؙIG1$6Uj _" 3d@Yƛy[?@Iߐ!=L]6NMޗH|n@0FnGpdiE4-?fkhB1Vq!kB#$x]c󭱻FmEJNaQQZ(ҥq5ye$#Bk3\xN&&]K.$yXԤ7(QFdLLXM%΃\G_o_ٜO@ |I() Yi[2w|>~U'}Ks(Vuzt[MnB(8,ZK3q/R=3r?%hKd7xHmTn%H5AIz'HH%wgKTky(/nO0ҵIBN%+!An,8ݬ V;5:8Y!Iѳ9F^iN4.δ9:Uw%OwW԰@Ͷ6ng1qT҂T^( tld2y(,߿R r9Mf۳UDO$d*lC}>LB}ř D[lF Nq\gR̮-8g0b8Yȴ` I(*ERsbⱢ4.0M7@ٗA5+iݼῘk_B͗ȂBo9+^89-켭^&;f"_xLʑK8e$h8@-fcxI %QKGZ /Yʡ&5hl)pPdEGY;.PYJ嬨a^*xźO{7:-ya6:G&/zsv$g #8dSBeW8솒"`KNa`K pbqK-7_ E/pmp{hpW? o!]|j+9øp\C9U [[ y'|yoЭfP9|Vh{="%'MJ1 @WσKن6} Q[ O&L] JM?^B,>""w$ L_ƙ0阭^shXt51-L1Mք]Y6$4?˜ò9Hpԣ٭h ])%*o,jγMe7[K\SyIDOݺϿ EH?/AC9H'$l7D]*눆J6  τ;JDY}0C:$jp /Wa!%I4x)ܧnV &wjڈ_@ t zdHD_+,΢o=.>-Qo5E܏~W0t@P})zZmn~sro_oW77^m7ֿ/=gZ{Ə,ԴhJ,iHuAVҒo瀂^2(;11i#J2)q<(w0?l€r~STg]2=&2/E D=EYHTN5!bY'DMhZ&R ;Ttt!OX )neǺv\̉FvBw$ЏiB7OsB4 A\d֡]4'-)*# 4gND嬪nFMYUm5 LvwI<_5rZVQq΋V2i(~ MC:fqh ^=O,OY"'4/Z, KKO8$P6p0aG+78i e"3j?zwpl;dr`nv';'{g'}?2~߮ŋ֝G^`Ia"r9[@\9͕ˀA .')P9`)bMl~E_bCl3jĺ~'~FbIj0BY[#6ݙ${J񖾈Tf~x3'P\~j-?)Gg5|aK !33Ȇ7JV%msd[Kgd] r$B:eV C:4^6' ArJ[CJzH&0r{17Zpi ٪jr(nOrn ?5VQ"pA{ mst(wƧݢirhP-8OpZUs}Zω_H D{{Ýas2ў3D $4TL=E4]p2>h B ˳ҐGB =K6^OjD-f0>~x#c'bMLV{S snYJ$I툏bbj]FUiѵl8+SU9|_GMSN:ZqW5T3@^÷|?EqZ1GF]֪kQT*)3P9@|ͣbɡz?/Js|lQ%#ٱi5#fC$:5bLy}]$nGRQњ/>\M38֜vQ?p>g}]TKi4R,Å_kDҎ拭j=jkF*ھSgE?wsɋ.\~΅wk&ž>ww^;c4u0%$ظw#Uw{?7voE XvNlz[g \l%xUxZqaG<>Gobݛb +{B_@ĵLU~ Ә\yktE->A(,߽IdROR eT~޽:B$_ݥcw>]݆T}ٿ(>,YSƧڡR^77܄xFYgp+TrkbHV͏ŢGOBīZZcށ!Q/mw7`e!Ap6v/~ę4HdX? "ўI+^)#fX1e #qėaų'!,wMx?U9#BsqƷtYå}"u/:y>`I`5AkB/,636,*g~q6Xnܸ3$ld\HMVAerN޼" 2#gd )n]i8n905R4tZkǭǂ?FMsK.U,Bݷ6p <  1UOđ@Ƚ @\=s(p)\ldeTA{ Q<<?V((~|q F7ȻRj#tZB?K:x!ﺏ̅.;[ota|7TOwܖX557Kpx[Q !Yd{JקFJ.9N4L>VCI|C fGH0t=oDp_[]*Dw`8\Jilĉ#o8rGh@!OT<("ޏÊ S[-Q:<YM-T2̿-|Qʻ_wЎL-ד$n]zq>VckCO0D],ܖ5Py}&FKúeYBk4 &BcLόCSC[SҤ06-w<ރ`K>)[3┐L5AXOpRHywLAsCI{üNomf8pʸ HܐA_g,`f77pҞ1wP39bi>lZ|9( kz֨4<[Ig݊Sq]a+ި>x5`u5_LXVu|ޒȃ GXϥKʕ+bո]WU)#GWWa:OFjqY Rc^Pe m_5!(Cf2R$f\We!#p\5FwzR Ԕ`/޹ O%G& f[f8 Ou! B=+8pRV z&Q?YJ!k>Ի/PQZ7`DRx]g :歜(N?{3"Έ9,i]f;]8WgO7g U7/&;rզz] %xNgdJ!jl%%exL {2ln.Fa47Kk!Lᶡt(EcFyg!&Iei}waeb>&08_nL0 ך!aځo[F%W\5rjYLotY#nae~Gű n:|E|.UQfy ]H5obl֣=u`jc^>vҁCSpRtp3#):r(~ ѱ7^ƒg?SSV6dGU 3Np`)(4Gkr8=|Ӂom Q䕥#V+{t .LU3q*xXbMEɴTs yby26pb (@= o. O-hڊKFZtdl֑%yĪL^.yv_ܱ>RۍKk GfLqU35GM% JG7-. nhLr0Պ@{>\o Wt4z>L&=cG_o V llf~p{= u1Oi;ܠ@ЁU ͮ>`TÅ/KZ#/JN m#$_1[O$RnR-)g&\g_w@Xm]dLyB^4=,t⹋qӪ)uHhj9!V>jt:'|ŸpTS-&sg.{lv&qV"'.ʙCܸ2-Njq^q~u+ e(CWըUKNң f ױs( 3Lbs bėGs^tV43O֔b$O6u^A՟}ePx5Wz>EKA&I3L:BN] _!!ݖs^?TݻEZtiV5WNAW^N{+էtUt/wiMdON&YALipDA`M;&@3 fRAj2OHD&WV2iPW2@Ϳ ڐSd{9\**ѽ'ڜi?bțlUjb߰N} W<Ο}1 z|(<30jU.ۭ0\$f'^r6>b)fTU%BJbopkg$i~DԆW2uIS~WDWqwio[o:u34&&]RMk|foci}JPd.7SNU~ GYk͔Z1i3VL;nYHὝ VUu* TqIϨ-Ӭ'na*CAY 6 KW؈i'iTWIm]dZmɓQ;͹F=1`J_fzB,pZ`*N &s1|⥎oH M-nvf !ҫEīT^HVvO_8T(R<7j4ZxlI<݊5(@Jj*j%4abt;^N~q1&K]Q%Y\emZB1 :ȢhIe~O?ݒ,UJY+8真^L i42,M)L 9wm 5[IZ!lSU0-&g[ʹ*Z|q3Mӊ+Xl7Pk{m -gR)r:19NH~Ȉ(HNOPC-*dݡȕ QphKXWt" kXf@PνĦIcc6l,6ui.FQU.<ct5 Z%Cz(85d=a nE׸Ϩq=$o&4x8qPb 9ڷ @iƶU!nąk\(|pI?or4u56V28*Zm w,9rS2tsd)ӏ#G̗jY"p78 /8+!,BKVeezׂ|j9nD61/тOXe{X1K]E?-ܼҲr.KM I.FD@"d#lWWLJvЈu>*TE#?ݓYf< Ơx_#\5\%X  es G5yY; oQpp? {AkYZ,ljcζ>VDD=TA K(PݣA+ ;\7)"la]{# _RsׁLq.Grк`q4_fflj9O4fqgVݒM ?@$Jx c,bew8BTK(*) ԓTSY*I U 7u`L[W3LL,8&!AGY]*_塏HetWQ'TW]r 3 GrZ#\<3WӈՔR50/8X\+˼\twA ^!ѧ޸e32sH(e@&@f؆-en)KVe/f #&p s}Ún2aa.. M$364߈=/#Jj?S.:b[l*XB= <L&".t8>`Iхq S""~<5? bp։?»P_ߛ87rQJ|8Ty*y^hwlj%v̠謭(%hjֻ)z$Ο$&0e-pS$+J"DvΔF̬mLaRrwϧģ2R|ȴ}.C{TN[6.d6G Gc;wS+![Y +oq59_O!KK8xz_9A8FD&zn [f-~ E@6VQ!( F,f|m8HE~^D9wE0loH4tKLN3af8w.Jm{y(젵ήGC)čflV j΋Lh7^l\` 3& fbYȠd/>5@E ԉjѩM%.L+!wKV;Бpsݖf=SJ:f}𥜩GJЉ_ۼ`v@9ҝ ٝR}3 gSe.m #EhQ=n o(Bv{s 7 SLhYvZiΰ?1`y<{Jui5X~~?OeQÀr)R~?+fowJzݸM :!/V1GHf6N;$}f%[\LJOXvrC%鿇'2ptB'P"6t}N\mI'iVt m;rN@Ȣxzӑ,ܑBɳ{fL G*"pI_iJVWGlF#s ,`%sLk폕 V: emXÿi/9X<ۜXդԠQTXr[MA?uM{t%}82vS χ Uʣ=*ْF[=w]6vg2vUmŕ5jA >V#BB(xEqZaH/ap$N#idU{ǗI'.fn,f]6"UmGVFOQc5":>6PN=;0+pF fhSYŮVwӥ֒} cT`Z%VK5Rm!_ŀ@iD̉93h[yoDb)ʔOYc}Lǹ#cT}<=,DS@C3}@9@{#& )oW6B6蘲n.p7݅vpCt>lki Pmm4HGx4P$^ >5q\I EO&-[Y{G#O1 m7&ET3V8IRY^M`5f%J\1gj6%Tw#j$3Rz~|rńQ@^[uvu~Xyjsrt8F3x.$3`4\6.5YT*\ϥMIF3 R#L,:Cw.f*zfs3}eYqKVj@EN%O%l` -5un*6NV8e/IBFKGJbH ߝvAE1j4sV3m,u&S|HmMt`W5J,j!؂JK u;h(`%,._} `HMuj5QVEl8_Ou?;pW[؋dY~A\1(kQ-< dlrvXL 3'Cb#̎Kaf8$lۄr,QH}^TPOHzS $URh[ySYu*XlۨrWPodE`j6M,9p~t D36)i<d.edLG*Q:t}a;Xά Cv6ꑎq^Wvl4NKs-Ll~(0{~ݰ0\Cܟ ;NJ|= M R`="+"‰vCV\E}6.QFTMuAkz1H &X?Žξhηrqu]_⢛3t8< w{Ͼ#zTڶ^koHz|Ufpt5-3euhPtEtFBZ9T8hQ3%{$?,a Qg/ YJ+/e,&ɕB)vf2LB(~87$6+qpNI=R oLKMa/#;ʜe|ULOGu)D4xDj1 ҘʥjSm=&Sf\$9;u<PZSl+ LT/L5!Ig[5U: 4T# Yeř0܎ =9zhL< 򶙺R Ť;VLl-maJ$"5tno\lO'#zs .=a+}Z#$Z ؜*kL̓.c"^ M^AYww({^?+Rn c )0|~ I; yڵ⎊2ZTl7ZZgZǿ5{t ZuZ(ڬۛԼ" FZ?!w\0dI(/MNCqZQ7}'㑁̓`V r[w$N54binS^ :aybKj۞`ru]_41j{o=ڒp57PI~MwPSZ ]5\?`5ݳEAcadUBO5*j [sٔ,IM: '[2(`sVR0 TMՐEWV"yMΪA@Z sa^[0 X (*hu.֎>KU-&s-zTBh|(c3R)[iUlZֆoTW:@HaTgy@G/40`L.z &yZQij~JSCJ.d~_-C=wqܳU'1=UJL q{0asT{& )7%H٪R<焪yFOҌO"QixVL FLJ :WFkn3ZxZ[Sv6KbQ,bAN#ry?(;t2RZF>U%FW7%w澸Kb-H_xCGTyjieX&IEvݬlBEa/4#r\Fޥq6 \ Ofvmlq]J/==o% @aWsҍRXA%N/`𿪵vdM*<+0o_D,NM8[LJF] 1?{Kh|&KZAufHεIuYwٚ",Bh$j\ךbyZ=\kT9?Rn;ŷ9Μ0ie㤭 2zM"uT*X~M-qczX9!qUnf3m.zIF.ӻu0zJo \u f(Ur] 7f`ݾoY %yt3aXFޖ[v6~YD7IhtDT_1:gweԶT!Vei笫7זJVn 0&FF82Ъu Ǩ .LrHўG[qN*޾Rv^ šX;! OS6GB=ͩ*_Fj"Y++6)!Px.!U|RǙdKRDwĝO^`xuS.򽋯oTzwzel͕!T͢[ȋ9eZZtX]?  4}WWV  W9*@32z4J.ZzxN[o 38=-_%*u$NwæYQ*o~}F@(-jF5c nL+ +fh&.s3[.;8h3!D/6@u| }HNY02"J KҴw'Y92S+.F0sLX# <7_3@5:m|?,L* Q{D&H׫q~ZJϲ=Wl#n3vMl+SqZxd'xe^ItXQB_?cН`Z /Lbxi,G%3XxR!iχJ0PP=Zaz-r )B'ovl4Ĥ="[)@Ѳe-=E-WR*5fD"*)NҔfh$_䢱mf\V`N.ll!"Vh]hpfz8#M w5fwuR=Js1nJVUZYl7Kyxjg'kP<ךF3nՔ~js$?ğQ ɘnKyD\)vjoWel:Lˡ蒍Ϊ7NVUnϺypYM3;alC =A-埝fU!f'a&!h@j'M>-ý1c-TEK?>@n>kWג}_0ח4]H $^ EN$9&S0ĵM;:GޜJ ;k(8lφ{UbψLrǸ[~( bwOMB@opS*VggI*i ^T>j܂ʠN}jHy2%E6uq™!zoH\>˸2I1&U4ɧuB&20.8D\DfIZ "/aYX6UDST.Լj4gĴ 62bҸ ` c+?QhP8UȨK_'*{ZӐ"הϻ: #T4:fձmaʣ`e:PmkGo߯o~c4QV*wN:$r Т,͋iA|1l !>juj1CNj€ _Q"v9v\hܶGr), !ɥАsTO0{)d15OhR ՠO]#,)m(}h$~hѼs 9@=uSRZ6h לA=6)7>H$FDީ'!v>&eNzHs^[^F1뮾ЩJ2 g>!)lBH+bahĕFk_NU©_7 tMdU5Ζ}%N }J{8<8?UcNU&54aj0Pxz0|+`U/t.fU(nxjZLZ|*_z;^$eF ኹ$4 lLC^ &rjZB=Aj![lͳ*=|jy@eXyDD5`hNp )&4gak>c!ذ$-łvj[{#P/0aAry1A\ +n:z&kk%sOiY1Ǹ46_VFpZ4Q1k͟RPp^iVTmؚT;,r/0QVw@;FY!S@gS(VWwJ\W,"0BN3=X3rO&=D{@߇$`_#>av|?:3<`mN HACR ed $-+FT93\90i! CM8[ծTo OjBm,3>(U|g&&\Hbk1JCmwa1nXmBؐEᩀg b÷R!g,E}]͠Xtns͈v7bF=ŗ㚼Aw]%!ijT |+̴[|P(є 5]=A-<4aRG"v.?ܑ\6n4j+\69מnUJǎJn !:y&^3z+W쑋A#GWΔ96c16d9ԈFqo,<{iSxܞ_xUgKn`'ra4"_RʁEj MiyytHX3UC#&(u l^/ G. ߅ݪB% .pyu:\^.}<\^.NW˫tӅ2]_.W˫pÅW˫xyu?.~Y_w)+6t Km!u,ܬ0@[&FQ$~"oBwfu:6Ӝ̴-׸W."0aU _ eՂ}a|ĭ8HV^xKmaR**qƊd%kn*۰Z_Oq+M _65eV8wQ$m2mu8( sݶ ȁ6'`o#JTJɥ6$8; Ht{{|ԼMj ӨCsW" |>weTOWj~{u[5FGe= m u1&SnqH `{dz*N\ /ADiqW4yW!i9;Q> 5  {51M4N8k_pGmcCNWuI+Nw@ѰOvYFDXuK&qf+W4hNYYA!x7aJߴ ى>TϲG=a=HԂ$j9\z|D6lN0UEF }avӀV 6g Ba meK!^j#1L0W &7жDL3uw]Qg!L\E;E)E`G s롭nU޲(옻D56wvPʅ8\9GUl {@s%whH5S@u N kf'r$.t¦U`͘!l7sa- ܶ[nEߡjoIg>Vu0qaNDS1AFiMYF,/Rk)=(.@vkeɤђ.1c}t>NGAQ" g0V3ڲq$'Mj Q6&5d7p~ju4}>gPr#u…k`w:bpfG"##ԈXI 0}m ]0$W+ya-RȷK0Z(sNZzյ#vEPf43SHD0mټ bluշG>NliKaA9ڡaz`/zJqt1_ro!!P:b^D#rl@ۓ{z%ia~`4.5>]3~Y4JO4=7K# S0꫷&vĖ1duz\»#ouD&JPe3pQ n[oG+}?g4ut K%3BHv-PR4 X]`-tŨ"[# C׻ziʶI`.O \*~?b1ΏRa:u~u]Z>ׁ4Y("~n3Պ;ͭUCҘGu:yc`HJa1 8gh9Se1*wi_9tڂ3D-=Pܽ`̩ĞA\27`^IœeL ^0ad QԆe~C%\^ȧ‹eӂmQذzhR";䕷,Fyw"iO˜wl+iO߭z~KB"?NbAChS%} :[JkN? OvIGc ]{{HZ*8Aip|Tw"Oy+ N-eykyPĹ\8,ryc0cuPm={6[{yYJ9#V/l̄ '" $lhdήeAۙ|,+xh0EٲҚٝU'^{01n 6 ZoU"J"9߇|%+&sG=7 =ǣE|!57EGL#7S]Ex%B^Լ+7NW%Na{-0PYJh6[f{Քɢ*_`3TXRznXޓMP.F<2o%"<*?Tm$ zL'B3۸B1akWsL݄Z^K_V964`n`WdWZ3;V^h y[Ewdݾ%~04rE+[`m`mm#J6ιQ `  ppUZmI\pn&-1|!%hlj2jtmqe:\=x2duoBn}Raɇ@)Z5L/Ae&%F|r(ȊY:H)nwX+ 2mvgt}x(svmYāy/ 2HEw7ɖRVd}:wh769#X)Ǖb[L {dv  E&eWGu/VMxҪl%&%o_ONLM }MMy;(ۃ9e9{-/84jUӥ|۞sV qP6s<ĊX$.52axt)VԚ UDMMh^g10E/n6ɔ0#!\2Ytzmqޫu"F]=<392ƪp=iΫ@N5)[s$UCٲ&H\g'F`߀*~˺B6UXO g\O!J"1!,Rl2!qO L䑴XٷjfX#X|PDIjEѢ5C8qux@ʪӽ=UU6Nm\MMq> /P8d5% ѤOx)js}k Uv;ñ&J$YBkVy*Vَؗ7 5qם;WpV9[<ےҦ9caQWK9IV\Y\N9U<|klIeDAb=MLH\a^z@HB!9}T.-]D#9שբS8{F_R^J?6Zٗ{dgKU2O)?vrG](C>`F#Tkպ~U9f'XWk"A"*ܖՓ -es e:~;u.Jz Fq=O7KCŌK_n/b$s*4XS\iN;ơ)%F٤ضC,`>m:J"KuRT|,LDp= Zo@߹Ξ~™Jo߿pv"O ~wN]|B#7UA_~p3tr A|c q