sssd-kcm-1.16.2-13.el7_6.5$>>|?ld   H .KQX4 B P l  ;^?? ?(58< 9h :w >?@ GH0ILXXY`\]^b|dAeFfIlKtduvwTxpy7hCsssd-kcm1.16.213.el7_6.5An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.\Px86-01.bsys.centos.orgҍCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl preset sssd-kcm.socket >/dev/null 2>&1 || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable sssd-kcm.socket > /dev/null 2>&1 || : systemctl stop sssd-kcm.socket > /dev/null 2>&1 || : fi systemctl daemon-reload >/dev/null 2>&1 || : if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket >/dev/null 2>&1 || : fi systemctl daemon-reload >/dev/null 2>&1 || : if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service >/dev/null 2>&1 || : fi 큤A큤\P\P\P\P\P\P\P04a2af0a27631b76215f6cd6cf6305db78e371271c475ed485f4d563fe2f3d54d50c2b062a96fdc50ef141b24132b40a62b776e14ed89c824f51c45e7571ba10bc0f517f16bc2b28017f415558ec673f173b0513bd8a97bccf89aaefb1604f8b17b248da2be8951a7e5ccea7e68d53db4f7f1427c613176584e80b8927a65f9a4295b12ab9de661c674eedd60c971ae1355b8e7d3b0a2388e7a4c23aeb30ae3191b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6frootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.16.2-13.el7_6.5.src.rpmsssd-kcmsssd-kcm(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ /bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcurl.so.4()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.16.2-13.el7_6.55.2-14.11.3\@\@\@[@[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.16.3-5Michal Židek - 1.16.3-4Michal Židek - 1.16.3-3Michal Židek - 1.16.3-2Michal Židek - 1.16.3-1Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1659507 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI [rhel-7.6.z]- Resolves: rhbz#1659083 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust [rhel-7.6.z]- Resolves: rhbz#1656833 - sssd_nss memory leak [rhel-7.6.z]- Resolves: Bug 1649784 - SSSD not fetching all sudo rules from AD [rhel-7.6.z]- Resolves: rhbz#1645047 - sssd only sets the SELinux login context if it differs from the default [rhel-7.6.z]- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/shuk1.16.2-13.el7_6.51.16.2-13.el7_6.5sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=a165f35b374dfbb04b6dc3dc7feee7512ca0a060, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)directory7R4R0R8R!RRR6RR RRRRRR2R#RRR R RR7R.R%R RR R&R3RRRRR$R R+R)R,R*R(R'RRRRRR"R-R5R1RR/RRR<? 7zXZ !#, ]"k%w+p}}^Xɕv|~>Ex}zXҥmڬsyx3r":3Rۛm~}T!v{4"^Ȳw*A;ذD*u '&+A9Ap+9"7~3Sp \4ov9vEGwtҬ<à6j(hQe;2寮T)`}!1@ohĜJ4JmTѱH-7X; zY0I&8M^x$Gx3$v?B{`wX|6]Xu,ː7ۖNw0`߿'C Gw\D)Ҧ3B:Vb @)r|vdA8CNǛ]͉/b6?@|C)GU.zoŨ]mVD㨒S!7V+>?ν>Oy~gPN5%7xܷv;i*(nē`Njl.i+3q1^w|#GFas^Kk]3㒨AHA`%Ѩk @Ǹc tKk1IzK R IJ,e'mkQͭW"0@;2~'UQ}~OpZl6C WB3&AEhæs@Y%~M1k5r+s3OݎmӴE\w̓ O7JA9YSԬ}CCƾ }9" "/Rʍ(mJ *74Ci۝1)NVjǡnXT TCⳚplQ[bVkb(8ŋd>W UWV&N`k@Wek#L"`w- fKKu;&i\G {|hHrA~N7GOlqֵXNW$k#`PL~kk\ΕCji %u!vf-50b3~H>xoS, 3R.N$gb7/2٪Fm sw`Cig|0Sn4QYcMdqR⚟p*.<>ʐ(I6G N9z?$JX>D:agIƠy:7=~/**ZiHN:tѺYYw}Nm}w<YL;^K>БP<{Pue$ -/'%)} g f}ڜ2j}e]T(ac;#ǁRa[pv'eid&6`[ZtnxRYlc}/orCܞ܆dɲxX謮˲(ZMiV[y\Da! |^SNɦio&cF8fؐō$UfbTzcwà)Do4;[ %@*4&^b.cN7Q>'MGhvy!iRܜlʱqVi'!d X"ʿz?I3jW!Z3ae/Wa׫#ݧ*5ãwg{66~W̹qةՆ-oo¢ .U kg5 <Jʧtݏոq= Gm +U0`DBJ˕d|mp^B{tEx u&5t/07kÈ}#EzШ5a @YdIVMKĕWUƾמS50J&Bf$yR+)vc(A8$µ={6CV\ 2|m!b,e݇yӛ\]PGؗu6(Z λVb-+TP9MhގeEuzK MU3-hLL*;ͯ`m* $E{#WOFbΠnap!N#(ЇԹdIQ(8.+4kPmSy%]̨`/}QRpksxL_>ޠǔ ̡nS8Mhq󟉙[2,d~-5Ƕ")PC_MXG,IsfTY !=Gh^oC4j(}zC5C˷HV\Q,RAPȳEz]C򇮻[a\ai5aABX]?O;<ޠs)u ;6IP]͝qG+W4<I Ø6%~hcLoC6;wOS#^}:oKÐsUW5.n}yZF )ozp0:EqϪΔ*&oL^I9X4QgFC{sP Tr>i/r{r`{ ··ATCc4q:c` )neǭuxqfEYB|:eY=SuQАK~}S 5o.6ݑM9剫j"S|}Vkr6{?oġ>shBZ !to1h0Cj֓%U֜?AXɌ]50e^v-9=@Yz:̞>N|sfxf\ɋ &M#N,6}XXe4][Lyߌ@4!v<3?I*q&hA"T?Ir! ܯ$&W183m֮VE6 K`SirEh:,&z'Y,HqAY; UetXM̀G CcK~/ִgVv2}qz ayg:\]N8tX,}VEp#ilJ;ڜX O+ }PwXKbutz=}i ?<+Y?Xz1I.hɣү=qGr>' [U%+B0rn5*16 m|d'NvYsO])Ox`Iү}9u x2na09&6:&q5pRB#lih v&)fQ:Km7b! ^kU:tL"/1s+&vAdrm]Kp[!JX+uшH)oGQg6.H9pPĒ0UƱDrvR㾬&I]#ͭ%i0C nN, 7=Tg)=D1٘H0 ~^S2w&t6g 2ُ*#G,%Z/SURsf'C(5٘HSW* ӝu1߹|BUfYIRh&kkaMS.n52~ :8g*U7ֹ70AE.ǜ4)Ox <*kcN!s %<'; WWQ5Kfp)h澊6aH8 twB };42*آA+KxrTkLF :`CJ||`=nkO7ˊ>lN{ ayP \b|Hg'C|:Im<'l$[Κ!nCX2 n&< l^Ń\l8<{E@ CпGzqQ#bYdB$HUydO vE$Ťi2H%q7?H/zZB;J^w.av?W%ivwil/Tqfi?-6`06>s 8æU:yqМC 1ZVF)f2Nl1̪)jZ$՞^z@) 1Od+{QYư<=8fb t A*c 9*#88&F #_8^#Dd,]Tzxh@9N Ɏpodƞ#y"xY v??-Qyl`x9hÜ#8x-Xy%V[ $0͂*x\?SX|5BF`P!iRn{ 0 Z4cR(ɑJzhb#'#yy0QR>;!Ƃ!+ƮW 16BmHMճXw/=zԇ:Mh*Ƣa"3C+LKw@]Im??qAa|1[$exAzM/{0NswZXD097B^T@ $%T>u-q4g;-F[Bt?n$޳T- &D.s ?=3UUpvJj<*;ցss\+ Or˝dZ(^\cư9 53)mpS ~#onT{iDKϗ+hX93FYUzv 2P& \~56!!շXK[9lI-*bgpK a+QߦYɁ GS{v~nG1H}};YCNg i;MaR%TRj ]YTÅcQ^2ϛ.Ⱥ^'D'mj3p <^ Nb ̄=Z А H:7.~8D"[6_YVE!G֮GNނ\cB7Gݮ5 nr@(*qXXIgLU"GШ O4()y([bRM.Y@IUvW+_Y4[E![6Tq:2D ~:##4 ԧu~(ɜWPc+TN^dgǘ\B1eLo ,O-_[w].}y2φ-})\335 }0Zr!Y ĕQ;8I 'S~\iZӽVMPpGDlX 8!J K$*kyECeD9 0:`ٜ_TsZk2)Sj4"ψ-m4N$sDEf><]r\븭*24SNץd2K ~!hs[}0Aɚ^Icu5$ 2|JqNX=pw~tڱ~Z=8V +JmtW+ 'gߠj CwRY}#Jn:zٿ"n5ƝɛuЙ^OJiJz+n#Lɾu8]ID7/^=^[zIrw}"TRNj9;ypN *xLߝK|CQFDk}FĤkLXg߭ [ɳ`[|a[@jh 5@F.T} EfM]c% Or9 0J9o27}1?JV1`nƅG n"l?(0 V"&]mi8$ڇDdc}4r?.]^62y"~F6C]9e~Çijp{X~8z̽&A)ef`,A8밄 \?G`x&c."*p9<dY#n(^(NC=y-&PFbt$ EjjBFEϡhy&k;.{ 3KlAz2av={)A,#Yve~j-j^*KJe9Gvc#U+z߬ Iy9>V aB3%O#86ʢ`Kcxe|[ 1An貁)p?jJ@F{)\ۧm'aDH/.n&WX" C}V'F0_`E4yv?]=XKj߹`@ٺ$74{2fCGWILξr9.8JioR/dx(,N ?`{+2[tVD,)ıV.hh U}k &+DF3yp#xՃ~%Me<lkx0Qz'Vjd D29IJ./Ei&NFAKt}"f5|3@Z)#8N6=#D3ak(Xqu"=/qf(TZ:ý݈蓿 SͻW—< sR=)iן[B3_k=%6%bqeڈ,,UG"ؤpIuiA>?( xk;R@CNLvOh8@ LOO7]*zӓ84׍ ?Ԧse_Wྛ{JC=WsAg|EI,l/Ƚ2kQd]}#|= 3 [Ҩ{i|:vRh&e,QF# `[hZDфW3Ř{/olc'w oЛ)'zĭ$,)5>\!^0Yи/ڤ`XY e:oĭUf=̘ڣށPJ ڐĩSL: S[$ܙRb3',KuÈJxӝѹH8`~+3&rSR,1l@Etю}l<ieu=&F'BQX筴̈́w*ן0[9SiY6Sk.DBԚ#Cola_Q珊+|Y[yzR6#k&:14t]z8Bu:ek$ Lާ]0;H^L(=*]װ+;[CorboC3i]'v8-'ef;6s(y?=q@4A;6b^S|"疱품!܀\r%iInf>Rj4^/Oa;,LB*2)U9 iF#wf8ݺ[ #D_>Hp?? oh>Ԃ h(s"sS7&/GGv꫁P_W3+9d&?+^^l(beJʹisgqX;$=Z&B1ߺdQ™x-ɝ i8ZM';!O9Ѥe>I#P4m$GdbpoRGT4q|iG*diglŋmM )!v4cth5"hCtڝZH hTp|UWC'Fewܷ3g^} 䯶E%LIL^h]wrw7Eu87Y?pȮ6܊1eEBng(5%T+lzP44{|nVZy^4^C>FV*K⹮EwV!J]3ˉq2_.y8My 1]<ގªr8jܠQF/\7?& aM[A[FJU_lt3^u>ثڳwZ. 9xTف F+W@ܪ׺x\7Feޞ^lL\w!QMю9-/:&'fGF ` ggߞ!L]R:aٲmXF5*AE>[ `4̧]Q J1mB[f*5~=@'>թ8 m+Q =DPr, OMe _A(:+]'NpKC#{C3,*v8h&BvQ_vJOwRnOvSGl&22:Fo#/U=,XG+ =zU^~f%9:bE:Yz6 ѺN+.׻gAZIh3Tv=o`CxH sTn>i z2Q% #S"ow͚qm ;M`N$i.ڛ%*+$,($-oq;u18%oZ2Z;s-l|\)0)w (+[)VҰ8@'(ƂdX0E:۶ 9Q}߬@FnzXV1ԁTE^\5oRb ?^:+Uݐ>)\ Ojd߰WiF|'HJ2}o!BB`2("͖fXˀh|s!1Kbxc`9H~h[#R~V`07:DXTY[]'G(XCH )[_[M:1J2p~:q6JVPh#Ņ)O>,?OU!#mz~G!{DvTV<$AC / hҭNZP&utC ߽nb6Ji^R+h*-?"? 'g,Vl{⫔ &lcx%W!-v, cf:=؈QڲBR0={nf0|&ⲌNM+ҌUW֘ n"Jw9N IkIYUFBr=N(0`yr{ς?z L/6ݹҞAˉ}rqҁk&PuTc?QݺVØmHO vi}6 -!Q!#f_j&*_dѶ&2RgF󧁂" H9lI'[kC]lePUq,DmwR] HU+ m| 'f(^xU7 nBlP Lh&>s`ōe uuF^JB65ՋCm/Gۈ@\/P;CtD2J+Ԛ6ղ59έa'꜊Jb?*p.Hqsx9g Sޕ3ƾ8v6- Y,C]6!39*?{WhPl_mnd%%/INN !a8W !{z81ګEδD^}O64,BGǴՂ\_9xثl{97IHq?aq yѥ4ϖ>$#6"-Y8"2H7RSM ݋7>Ɠk^ (W>7N'̙QFF! |Yj8"$dW؊/ʌU[SR%x/4u {gRFDI@ {}.}pV8ɿl%Y- Á\ Td,AɑmWev2_nkfǔ)f L;5U<$r*Uu&p n*7M+à173%\{Cww!,畴Q$et#BqCU^V8x2foKm%I:,v.ٽNyWD]g <%Iq2NS]A$٤d*Np<CdΓ$֯|y;t<7.^Ő#﹞MzO.jT@JMLU8Yjܗ!uz&b=x7,\E!%=:-d;a V?=9Z-CkNc@V u'^&ρ 5tfIX?#G·wڪ|z%M@ c yAQE`ߎW{apj5@ՐK@IL|ߒ~c j5 /ucg/Gb+@QEVVqԩV|pqՕq@c6=2B{mde<$)` !Ms@DI~ E8fҦξ/U, c!~,EGb<͡( oa?/Gc-ݖuKrv)5(~@@`bf@GHo@'%|3HӐh$0.;N#LAY'RY EjU|ԝ%RCg*\28݃-yZg R}yE葨2]*6t+8ODQ9gv3RrӁ(vJ +~EoC,bs&f#rh{?Z UחeB\+`r;PʙaY4^%w)tD ,ϧ'=9L6G#IPur+g@c_wz+ދǝBH0O< IMTT#:&A=iV aޠh;]=. {!]܆>4'NYFR~c^WZ,]<˷g=vSU|ds֤h#rfr{RJgml6(Tju\ pN/->=^t8R^t4#ůp' ^@a8Pa{Eq% 5H9_#Z%+\Y6`q2p N=OܷcN׳TڄE!->8BA;r" %Ӌ2',k-ie8jcSKNAYDO;/nt[;;eeAhL?Y ьQ|,G̕B\O#WP"Z"^U3b\S;yMOjqD0cAbdzXCq΂H˴}!zwB1%APƃoNA6nd 0cmmHȶJ!Nm%f€g,o|pK^$δ " |m,$ ﵌$?B8%$i#V.BQX~D7vwztEst5nOiגwf1,%a?L=dT9+Y[.v١憕ȡInG+y@H^/ss{El/Tq#1}/6Pc^HT1RMz64f }4KtxLb$HRib4jյ 6YYj5il`ޭ-|fZ|0~fd-~eMǖn]o¢`\$? b7\+$Fr@@BBCQC3Ydo;PN Y3=ޞ\~Au] ]r"lcxK$)آrulC<Cu⋅8= ^; "ꍾQơlaճ#bJӝE!wqKFzםŸy۾Oa!bۘӈ@WAγLVB}hWy:q fُKrGRN#G2$78 뗁ɨT[7¨7y 04wEd_ H3s2cV)T [CtZ/9YޝL;+a`$5-;nߵD)$n~ؾ?!K8+Gꂳj3RO9ؐ?؞A5Ftչ˶,fic2aŊx[,}7\h)_ Ojhoqo uf'p@RWiy/FTϬH'c&Sy 퐥fA8c T!nҘbSы-NtI%!x2J59HHu%G_eOETW,q+ǣƮmER9'nِme1/8WZJϛ}Edkрm5ݙwH:P:}$7VYn˵ջ_|f rc" ҵ~1}-dvOyurP>;JE1d~drU%Ca29 B @ )}6Q4u2#|HUuɔ[m??3E6MQ7T吗J]F|%ҩD5?}c0A v2MMYZ\9j@:%!ageaObTQb-Zӳe.OLwP9aRL"ޏXHG*; 瘮V8aN_`%uAQwN:ܟj#šyg"c&cשEjҟDѻųh1#@Yy/pbdíW2gb/t1ݧ1'W7q=˞*|7_\މt;M>3Fn͊;qa .U=w3G d 3?{؅z6TGTc8{}t6*Q2`}! MVa{$G8ʵ %HU+"+҄h֎+ '2'ܕ4RAd e 'GNV$O0s ?+0#Su~u %[6~-:LΝ b!(VK}g*\)1Z;r)#oc$͇>0/K53c+ h}ߺY}H kݰtKѳG40~(+, I; \ B9.[emz%鸞#=ebHbAa`=ͦg݃l wM9nw(̮P^P-0|nqشڭ[b*zщWit):I)Z 30IMZ3h\hdnyHXٯU!mVb }$Л>MMIjfUE]A$`ݯɱKX vA7o'hh8(2Mf9mXOf"l"fp12O5jv~$0Z橊AKHv .\f NJJvGX6EP;Q)V]|me"~F umƏQpo^J#0] L;8\/uҹZ N{oЁ灺]>'rOqTL0} fvL- BrlWN #0wٱpMdJb~Dt:[;Ou)%y8Mtt&@=JҦ%6yʢ"фS lXt‹E_7-8hvDpvZ]okfe;Mq.0B Ġkx t* ŵmҗ{r&Um$ O** ONkhנ9=E6S\HtǍQ@W(36_0?3RBVWW fDBQM2գt&wG"{ٴ7_‡V"_f>' ^1gi4_UxLz{ (d'k3[U/dzfǁyEswȈ(Ȥq<{n3EXн;5w3 S&@/QZTР!޹@HDy>6pjw VA?^2]:i`V9:ʧJ[ZFZ%9 $q$ɾT7qɸ#W*aq,P0fJ„#\{L,r'b]4$L: [% ]p r RZZVCMĈ6֍3k퍱ҶT((7_{+U[55(y=3>s j:^bwquta聖/hY?a -%hL2T̛ϖG" (*_,|*DÔµ5J[Ff;#Ck\ZRY*-Mj''_|FJCh٣%=0]l~虙qlE[łi8n-Q%o^)֯ HZ34l`?VHLjW:6 Tl;NXnD#̭[;ރRU}lWh[]7CJ#̫@k,$msR8kG‘(,Nز, D ؗ6+FDShfkh ~a3gTm\ n~|P5`ZQ]wp k%CZgEXq<)3{ر57m1 n5+bkp9[,⻂ ?iaIDߥ@^C}(GvHd(kV$iY#bCI˦[ %5y.&>vvz<*yu~'H*9V0\JGf6=Y0oTӂ+]ȷkqJ|-dٖtk ‘X2@{}^Y,Y*'bP)O:X`vt=oGL#AJ{񀊯놞*h7Vƌn bɏxA+D^NM]Ռ|boE]4EhYws=K˽t FZqLB,IJ^}':>|oWEh~aJ҃}AvSJ w}p%a3:EHM3ΞLW3n &ߗ1.y˳_<޹;,s߈7 + Xf9b W]F0;2:g|:~w蘔bkV|ƨk0cGy̡rDpIEql&89uq7d܀%?Q.AX2g?,4B:f$q$|t)/s=Azn8-`فu.b/QNE|!'p9&˩hw)8LUFnZX3D2-%U")EZ\Y,\֥ Ks& ʜ%0*6'2(Zuz7N9cNH8xƿ|UY@P*}uSO ąosRw* =hS i2) r,iy\Npsv1L74Ճp)Ѕoi2C㥒ntw~Dhn#RX^A]fw ,eُLp9]W]șij]bL)Z+wX[2tO#El?KgaLjۻs&bIj\Cqy$'7A6$*y{3l+(]=EWV[^W"[4ZD'X%o_&2g%p[)ŋY:]ݸVhgrkޫtuFG}=Uv `Z+ցY3!畢eyb\3pN=6C+"}8fw$9MX5X܁e3T^y|hL]4-1E^s~Rpknw_~+UOQtؔkm]؂jvj7dg!(~yvh:B_ Z@ȉD: ,S*lG8?7C&q YϒDS~tܓjbK(Ϊ?s2"ϟsWDw--=0XׅTimlNYR5>N~ɒfr2} P3ӛcDGk(9ùlHa|5cE^%[!(F9tnImKqL`qzmu4fH~6ܴd0s#jzmi m?eR0"ψ'IA5 $yJI81%lSN8o0c2ҍ۩~BsEMH޿NbTZ22[@H>Lj}-^ڑi/`11ICTBW6nb`j5ezpQbkEiљVv-J yVt8r6Gz Z5QArXMgΉs^ ƪFMkuxʭĪ26ZX4g,~CE P>2Woyk`gFI 15{V0 Ϙuccju(8w|uPI *b#@!N8L >-nf==5e_JB N1]@/3cHfpNb +p{E9Ʀ>wІ|AHm(7,h^`%*=­;'Ksv5pV~ \$U5\<1Vcy| `o)n~цLfy!Q} 8~`b1Ġ%ǣaItafzmܴ).KN#Z;S@Ǘ2Jl$üZ_3awge˕sjG1h\ MP426e'G8F~Wc= 6{'8Q >h_&O LY4*dڧ}TN T!x@Luh>QWjS&"8V×,'D|i5@+"s%~ ROO03lqHƒ,smMd#qL^%ID`jG9",sCK* #f?]FS?}?0_9doWAKl^Oz(,2tA{\eOaGJέsD[p ٪,R bU?Mys (·+y(SE-MeOMC&Z#oe>Z￘i91)`d"hx4srB=hԋJ**]AOe+P\pNsR<&DfQG)>:U9@úf"NRDs~7 ,X ]>qq`wWC\,%uؾJÏh*af3d8o>GXݮvtgb=.$/a-$;XYeY%fpz3My)yUc-qżȣ=JCp!OZ&WS8oZ8趒17aGA[wp1lFe7[Jz Z<Vazc9؁hT)Žv,9?F$%VE:,=vˑmic$FqT+μY߫QJIjL#lU󵃧[nxT?àN`G`wlkN6 pÛro&)F`6f:UOV=7\tqjmpWh!6/+!eGd`Cҝ,*H!͘`0(WiK5Iq@o$vF3QL9[~<(0Srj=Cg*ћvxSL5o{u50tBW?kZ^LQLOuz9t',=G'vC'/l՚a`SƢ82wC$XR=c7*':>XN92|e @X#1ݫ%N9pWOXkPZ-_r~d찃ϛ}O)N@IhV .]_#U‘qc ˻f Db"_o 4A,S"ðE. H)7u Y;pfX=㺧S9ԋ- >tg0/]bܨFmqMDT.DtKYSs t,ڃFPךfa<'"bI(ܳI2|SLk,(kV&&]W WH_EQ.Ք8zRra bvķ0j_n=ydU3j3x7T,jD,=dJ~j'$1Az_c9V̠IuskЦ)9H#پh3 Nj6qڐ{ϠӲspȕ|d‰ pHs ƖӢ7|x,8%$u\G'J2nZ^ANr)@yTD)'6(x#P8p:΂_|KU}"©X˓fGFb&mD֊=([UNl@32 !)) /uBj->v;EQ XT33|.EAƢ:8jQ!@h)a,c'uF44կhNFnLixylFKsqXHf̨X";$-z`__~>(BxڴQcsYRQG.0В?޸g:L3;<;LDj۸9MCҌ7O.uP{eJKϮ^Wav_t֕*O){,"@sDݕbHO3[;P ^>&rΒj3\4J`_ d_Z{@GFX/1)kg ^`XaN *r1F](Yٸ]lcҜ4/20q`"62P}N;5o(B6zuGo/E0ʆoa)Zuż{f> D 0MVd#݀:=Pl΄zIַRE]g7 \=D8T5^޵[rfw;ל!OK\$|4BMF~+я /rW%x [_嘡8gyi iB.*]TX$zu纗 G=sٯ?3g&Px N5BVz[XogLpcxl0e=Fxdh܆Nm4BDWN7]S'|zh#npBI~HX|!}5d&>c&*Ҽ##yA@1.)CSAщG9w.3af%ё\t̮;E j{v)#)z)ϻކSoB.KM g릑\?Wl5;3~or,a`.=ǦhX5g,9̞B.ɳw:!*OnkesfQ9I_N%y0>g ]MS)4-_܌/D In.Q+YiC@= 6|%e|DF?m_]#όʹ-Qfn7x1{"U95l"c<?X%vXwͱ1@J=9t-Fk&HپNV3&N? n#.OnS(,.%4.^j:xri}BHи9yaXyf[\ÀMp,ĭdXbb fr h6/ h,%  t.Cӷζ?o%{*=A)>Z9Z!Jqh]بi盫 rq:Y ]bǔ%"1AkJ8V<_3݁mj>5 6E&{~irKl! zDִޣU*]\p?z.TR×){ ! "օMNNEjrSKd5(:ɱ{$oI4$m1z>i檐tf.\kX]-.R90ԍ*4`a)o=.w;O!K 䫴₝)FEx '@l sl6ISN@-kCDb| `uD׊OI#yV2+b8v>Kuw3nSr@}nC@LE}hZy>E#uZJkvw)0&xK*:r%Y ±8B"Tb-6̊ⷓC0ή [n,9uSssaaL+p/lW =?҉&ګ[6p;6 lŖq͖g0Pe,{`c5 ?rѣOVQ}/X8νN-V2tT:pJLj(p8 1UKWҥH`="KoU=eA;p469psl+Yi@( xj#,@'zɸ6)'Ӥ% tkUoKRW͒/6x| 1wcx*mt?jO#H~7r?mx?‹ q,ʁzLV8$:mdz~J.Mtat"iK*a ! `i> J0͌V7@2 ȸZJkERoJdz< TR׮MHe?\Mp`vs(҃G i6g]6q}7nj xBzl[cfOm 3?*ݏcbٺQwLXXjOrQQmO~ҫN[8 r+k+b&+[h./ ĜJe[S@!%sjlE*AV ĽiсP@yOSshsی1,B!&iK cTv0Z߹nnD]gpR$W\< q*5*ΰ0#jQHBx O,# WdW&ֆI| @{S"ѐ_2E԰7O$|L(D:(JFp1 ť JФwb ُ1PTQ{Um!q LK³j/i:ɱao JprvP^P.tUSle\b>o%znRK&C"|I$4ɥxeW+o(c:HH,79=uH0F :!lx%g9JlQz'O)#mHs =ߛ&^4t:hx^eĒo#q t{l 96{Q߆8 SJYX,i-bڊF3̓ޣa6 %}p s<:﩯DtHLyJ^]u\m>USPĔ΃iJt6SVPoGZ.^8` *C{ퟷ=rUMa;#O`,8GRGP3ë!V{ط*b֔/2X0Cp#F[VmъV :8SA\*}*9R6_,UиR2Ste~*7ņcVe z*e ty8c0{/⼝v{OnBS)H^Hmݻ]?0~k5ָo)Q0t|/qTV캡lkխڑ/{Q YJY _: 5yYU [&RG(8( @;&{'# yU?k}a')i:^iApoPs(yoͧwSM *sI+v`Mz J>lE;TPj>#em|ąэŅe)z-+Rql6!ˡNnML]]Cu 1lvy)q;NWwan=`g:/̀㽛6̄Tgjm$°Rt -긧˄#]" }E]js(g]ܪHj"^4ybX|F\peq6=@ 9`լ99FoD'(ِ_/e" 9E`ۖ9 ?1 p.EH_ڂ"NJDM) e{۷_! /P-beBeK sL(ɘ==- 1{2#MVf vR PZ^<EEpZx6̣$ogo)\V&Hlqڱ?6Y>eʦ i F:hPtgdLqR^k'%nI@K%ْW–NW~w{:T,13qVNF2JCd8"}qcS(#P9U֣}5nqR}z/KVkXnWKD1i0'F7!Ǯړ%oL2qyu=2 +vs/ӈf[b1WQ}3.Pbw@'CNQדּ'zXFؓbή@ܫ. Sv<55eC᡻&{87P;ʗ{#˃&ZԧQ`0׼V@Z %ч ٬<€1~8 }4 ujK酪 r\;Tt A*-')&y.OsV/Flodh-߬zgJr=yZ+S$b˦B![P nLʎt $8PWaqkO. w;yKɟ+$H-HCb1A;>5JcZf ;0 􇬙՘ F)6.Z->TDVubGzhʞ'Vr3 <ݙ[BR,Sj۷ayB[k+9p1"ޥ[5gUyg͵WM8&O ;?cq[o  sZмt_qvx*XAQOInkt0bLN3lȯF9ϵu]߱'^HCvTFVVuώ]$<810 vڧZC0;<]*8 0)z t=),ղ6Va )ڥƱC~9B,mdG=M`-W$&TD$`eC7/s4#P!(q"Ҕ72QS-7K]sYUn94l қ{{å}* FR7lBϕFWt =i`aѼHSWH`Gp987Mݯk9f~E&y{.mP* [QRnO; M{6olK/6*eN \0=AXI(LN DMRZϑy ю$ޭ>fҝsd=~+ 'PB'ʧn;m)1Yw  xs#~wR3pgu%W7K^ݹ3bqҀ%rpauz%}MiרAwoFB% T{(fZe _>U}ۋ^4 =Ժ;qLO5%\4i5_LC.TN 62n!mc6Rm¡ <݆2TG5es'=81>+L%.ã6{|jaCNԦuC!{.|!~k|QV0'f#@goZ}2^6ODrԁZ?f< @UmL:pd+߅[o]ݟLv&F 'Q[uIEْk}nL #1 cg}閶9D) yhjAǭvCPv7]_đ^0/˾ৌjqmCRFNWT3yfpy et4sHlk1:Z,[$C%[IZ5 j(L}P$_5ռt[E=5//o`(ildHa*p~9NͶܔ)Ʊ#$aIGТ>/"JS&uP(Y$a_L |cOqb{pBî#_,29ᬆkxi"8< S Gͭd gM)rYUOP$ڔzwBr?[tR(>Đ/ܯ3׍p(#oX[vڦ9\O*Me%=>TXFC8?lO(~pA/ uD=gE*JK.^X.z@O "1Jyړ!|G-u]HTV%GY+|Xes4_n"e=Hf?]׀Ď9] OŒRM pȚ%!j2;~%]ˀ3lx[ Vi`?[y p9(_3xӱMޫ(2E5OTN ̜$ [UE] bŅQ%&N mu)[! on}# 3L`tl[ʇޒRC0G@7oyOZ |ouY>mL?+"ۡ[(n'be#MWYz'6H ~ᖓg6렗?wHEUtwBՃ{`tQ.m7is>mutD2Ѿ;:RS kֻcZb@=a0ID2C[/҃Hw?,Gw{Kv{c$2q s?k@+}sg`Sm<#u{\$U C1pVNjS4Ŭ3-`H9aɄ[/,7L Ֆ:h ܍r(m7 [8V9i{ns?~f 5UMy3 WWЦ5tz8:ܱٔFE! [y:{o.WdH(aJ* wL<$=p&xW9`EI1<5?oE e* zD 6͜>@@RQ c@~{6rǙGʙ)zL&,N&Wz~*jADt0Ia$Wޢ B͖Er[vsj~3̶V~e@̌/i(h ~WY> WN^i1d0Y"g-wZya4X3&z `9XXF^3\xqg׹0+/ƦwN@U׆V? Vٵ~Ix]< 8iO z@U,sh=t&XupTJA<4V d=$%  )S14To«'Hsz0)z^Ǵw8κdo9k{cmeL{b.JP1"Zsŝ8O4ͷs`/_<aӄgqx%Dt-H7`N]m'2n2su+{y#fFBrܛyhv zHPddn58n6]k š;lˬ4(^H$ء=(: )q:4 <}gN{z%[T'(XM'3oObeg&<]? mvũIU[]~VtBh6ܟȷB ^qA*\riA@7PN-o3D>w̏wu`-\0 $Qha n"Sp U+^kF̔._lQ񙓗;۵tNH.5%_xoa08RVv>K+%e*6>j.@#/nHњ[d-zL_HL~>.6PqWZv)MW~WK~dÀB79h+Qv; _m7_8nϢ@4+$-ۛ3 !-;w_--(@y !Mc b_N-j@!߱}JMKuOqTq9% o2w\cJ"ߑgԑ@+^& wenyA_lmhۚf6cM1Tؚ:#8` M{iJ`{D UP sĞd8JRT~m'! 3Z$?zvbU Aa~Xc d*֬ ٹO?T LT஼G>N~~D>[e&6rѕղ3Mj,K4Cn\ y†0^ T<,6=MFq0kň~ݥ(=!Ge͵ 5˒O"EeUJa,c޴b-%DUTcx^I%ܴ`܎_L?|Ņ6Ts+$CM*y2|S4B&i"FY9=b{ \* M&I$w3\''\AcAړXXrH' 3J#x;@l|]:9=[ X\T Qkf \\aphC G @~OՔMta `~YFsNeO{@ w9}Sc ;̊2OQ=(`2Z%H2js+ppDV2^Zޔm"Ȩ'}Yňv@I&x>#2thG3~Ju')i'?tGy a* JEe0 :kNp(~+P`oXלUQ'[|eϛ}KucFNz*(f鞖(Ck if,g[ʉ%%G7H1¡_*wbP8i |nDPmB/eC ؏׹R^8v$3@-9eهk8aVIDu32¡V!hxfC sQOJ7R1}u%f`e;I?`S"<ۦ%> KiTv]4Qg=.+!6Ϟw_AbwD8&?ڔGP0\"]dF@~F(a5x|ʹ5щp^9M+6$mb7XAɿRsjobǩj~ˤvr^xhrGoW<Lsxq9R4k )Dm ۖL$D_tϫ`/(SU}L#gl]@U*3b3mgkg=pH) 65ja?yT`,ng⋗g]ുNu%{f˖ O xYFl䶋!6 ;2:$MVtGb@-P2Bg1Vs=&"HO~m\IVˡ Z.9^֞Zbׇ^| _d@a?(-cF6۰qz`cSs˝-ByB\(s_Kv3. XCg¯\~y; I4f{ɆYua`,J}|%gB:-1!$6,YK*Qh24eVȋCBKW7+eCM|, j0Y?kŗR1 Kګ;{%ΪU2)ٖxCtjvN=^`gyz&ݛ ! 5?kWuDpK_h'xt޾:|>dqq} b nN7v8ORI,Dԡlwrioj&{jc"~\E5kD"ײq!#0:.3hgKjneP2-+&U Λx4gzvfKu{ىwD2o=,?EJqo )3\MGq1ZaGfB(%^ڹ#÷8A:Osg1Hl3 }EUd7LEݳqP89QC-d6cxǩt ~u$EG3H6ƣ-d~ 9T3{R'l:3&J"_En3!2ub8sq*B(aW ى]>J扃C&N8MSK;Ֆ'CWՙ̢] GĄȲ6vGfqhq5G6Nw)rMH@ ~U3hVp/Bj//Y`ulD47ϴoۛ b eI£}uҌYt+FG%B^I{o~91Q6D@}ps "Yǻ*be@qHB ;¼Dܨ&״zߧ[y4xʽr8{&Fl5R8!^$ Y@ލ` Hl{?Xҽˢdao _nX+ pEYtЇIisA:21c,Jצho;./Q1] dEeW N'}BMr|@n닭k3Ff$7\ $[& ;j)X- 9>Z+z'9ኟ lgE0R +Br 3$m?k=h՝V.;?3*^aR?{Q l&|VG"T!'~dvDizoLK툶"yׇZdŹ{ VJv]8*I\`,7~0b2dY5}h*"MhQAFgp&Au)];?dJn$AHgztӦӡ^ $iO) &f%՜@k} xHZ^:5HvO6I|NOټls " ͚Aqk[g7OgyR d<)2sd>uCWD&Dkemnu~q쏶*¨GI(vO﫞樫mWDFye@eIԦ=(uR9g9M\oXI R7>(F |tYV B7؏߲BuN"h7gO!871rX$x VV}$w$wW-iaAM^PՕ^PkeEʱ5P~c:<ğXF+VMH^~58M,1E, Qd0T=J gbeYtElgn-Gl׊>ZQ3b7!B_9&q\3D= 8}όj+Baxm$UŢOXB҄ i9yNDC; 2rS Z9G~2/9 X-e,%1SIr*XHkVzÖ9*3L]RnU->Ŗ@T)_rR|I~ωw'ceڵ|@i- ,?%7Բx Jr3flQԗa-JvkYH_J 9Ic3;վK D 2_`1YW6cZO>Y 1oQ,;GcXVT3_ST*,$)^m1S ?iR:%TdԶ{>v Aߦy? *A[9-u銇Cb{7#XECϹcx ?AiuKѫ1 g؟Bm>0{(4 )V# e`gEn1S,y6A"RDARPDw\(^Wy 7ZStOVT-`cB4Ehf]r'i`+}pZ>,ٌ WmEXM?3=$2c%PBB 've?E/dx_R;klLMSC}Nu:P&#jY$h?2癫N֧id-n j>& ~Z9a$_Hl_Or}Vx10 v;k`*kiZ. Z H4o7J \bG8iP/(9;MY8} O:RDF(kC^mKYT- b5g!Vg]QR-. zY8B~}la ?̔$tC~?-}Nn;O#ءkQ*ΐw=R.ۯ]JܥqGl-JUPC}_P@jaƆZxPVۤ[ Yl'AzcID_S|z4/b:7 ^ef'sNG=vۑ)`v5)'AiгJID,%gN|Eacވ >3]s!>AOf3kpAz6k=ʟRbqC D)Ӷ"H@abvU٢{1۾tq$$ _&}#GԘ קay~ > 4ƬvCYB Xz!Sehwݾk3z鱯+γIAk i~IU4Al74pm2;ڲ|&Px*\6%%nRBeTV>6xb%7멙POH!KkEgŅ]u__qE= ]#xG>+*v3M4G$/2|A)@?ML%`'TpC 9w;=l;˴jUxjQk-.QnvÓV[ƌGIoH8<U o@gZAoKG`xr6ah9Qt\Qla=ͮOQ@f0̃X'(cP*w]$$Q!{tny[$JHX3dU%>\k(q&-Urׯc#*7~%JE(+89:/>B'ܕ=0 cF?z %\Iieyo3.o %[jXo=pѷ5˃+}~I^ӅUh*Q[NG?ApZnǞ}mȶA>W.HL$VH#$sufEc(x%cS?ے 6jFOMJm11SW>ֱh/$§4ƗeL||X9ߑ}? } ';!yIF5I%m٘ WKr-V lˎt -~y˩"A>_ytckCv[ajc) g>j>&bNOrA߸f>Sq"FZƯ]șed~q!_O3iGyd ?M!3ṶA\Z=GnvKinfMb]( :r箒Ĥle$X&ߖwJR_!a:aU#2XEX`{td-0+[ Y뛊\[Jq|Q@ D8pE22x!1V^ bELUgȗ ce^̤jI(9&k&.d꒜ TtuXzw¥"BY #KME4^}NttL!@8M OK籺^ci@X=]J*Z0勸$VZ,$[7A2ZڟrF'd#@ 4 #%.q,>.nRuB}[Τ-+KȔsˋ pΩq-T8MԀw5@:C*o z\@ܟz!A~}U Z'Fӻxp9;VY5?dOX)>sWPaX=ImvK{7/+Nw7tUtB]s%(O[7_KW,^6T< n~,mN XxmVĥ*'%*Y#nQwvt `e?'} t`F(>_)Zc2} 鈄0M1TI_7\Bzq9bYa JR[BoM pUp%tssMv{ιHT ޠ}LR)vn1uc9\m̀̾<5F` -L_>(pSmjWf2A!cN p˘rAj#5His| .=ƍU#;7w%rKIX'r+k0q`f)I-;B`1BlɆArm,6΃,|UKμoA?o&^pKmBmT1aK@-.=(ZC9}2CJåxȢB7sJGC XGƙa8(OOęsj16N,FbMǾ U%{i.n157Qo/>1goFibs6޶>-7?$ץ>,ٲ`Ƃ__ڍ3t]z63"6sFOjߎSITV,#|'{|jUpQ!ЋFF/IGZ/fȏ~%0c@|>?p..SppyT`yߡZLע@;q 跚3}Ԡle\Yb(o61}GL0em 8" d$3nÇz M> ^)]BzP(N2(fuiUzvsw"Q]d_SHP"O{ZwL~Vƥ@ gJ+k,_ycL80ڰ }=bRhDWRXm5tsQc6Yf{<KWW$GQF AɻY衞**_D? ꗀQ6 ޴zƄ`JңMI{rj,@e=91f/8`7ó:0/):_ TBT$5!g6K%T,A}g(4jT3wg4Ń"+@gaFi'S.+&)S5`Yj ڱ,(`Nϳ?զf e_TtU2nxzvX Cy9,.O6= |,;(/a]jcX!?|i; Klۅcܲ-^2NJΰ-va}ܦpeכޛU4*|cS`!~B;o9'~AyH} +̿97H ؗݕy:2p^ٵ*a1""Fyljhn_>dU/\ES(X /<0XuT7mv;Ahfe *qBv;[RCE63V[_Wum`JIdh'sVFai+ZKٶpڃVfZܦMolSy4/gگ4fpn<SA xԅ9}k{Ӽ`@Y#IQp+szEaTsL9"#z.,ht2~.@G2X=3\ UW{1PB"jާK8<u_,MdM톺kC 4Ⱥ!RPꚳd=uAy7Zcƍnʂ~0a^*ᒄl&-|Tн\v]|2zЌUz>UF.`"H%y`;"`zdG .հB%coHO=䧅m^w 1剟<ڶ"-uytĤ0\֪<ÑoT""ŰlWYn? `2}$X:`>2d.e|f'4a]Fc>Te)2\73[( *02d:0J".0]ȋ^_=jrT# FNA"~:8֋U5Ȅ %:BKC~~.%m+!j\f)ZgSA(ggwr#&G2̛!p~8;R|pj1%($`5ڭ]/?ʛb\6M)"{A P" JWm:._#saJvcEU|UƢOg=6e:R?r¥pzdu꡺Dd٣:MvoNzi*yh7l?l}@Y$/o{Xdw-iI62 #oןڒƭzŨ|z%;|J\ik'EGVD:\ȈP~Ȝ$'ZOZ [IJp:1g^tܺՒN% |PAI=Tkt/"fS.z`1( 8%*"Gx"O_}ttICc_ Y9 d{P~Ӭ3(nΰ!82?} HjjB#Z wm83:fz c\8qծ[UAMP r%UWwZpyT/RMvcY${e۾9e0zP.ֱ8[aۿfZx1xb!_CٙW)˔[C8dIA qQCE*?.Fўa-&TDM'NjG*c-5 ٕ>BЭd=1*㼸 }F@}r:q![Yun݉1!h6n &# aZO[` E07|(ْ̍Ε-XXft]=&'8k!k3$aLG1@Ӗ;HD7|_ \y& B61a Z>?#=ImDBRH6(֒m۾1ېc$wZ#lk9$Zs<{j|g%>4 Əe4e9#@B|Jd x?E(1S@0\|NtEuW\()~KK`dj:~~w] NZ NXs*7qUK􎭈͛Ip6v}SpXb0bC"El0"Z ྐkȍcт67{6/*Ydr KH!ޔJE\E!\$9ag3)@0k=u-WŀY!^GP9ͤkX7y2aX?Q9c>n~ s{ L+X%Z"=j:8 etHYQAe6X~8;#w,Z>(o ZrQ7c +I-XLjq9`a!TCCS`|}mtf+cxL\֔]rj j^?f ON,60l'T-c ] tcĀgiEmo<ߴXL<\"é0ʚOA:+EJfeNTB6G1rx`) A|2l;:7U 2ՖR, 8]'CW7i]_4Sw^`}>&Fhz|_h0^0p]#$(THd ,jE. dlb+?/񁷡 i#tUOa ž˼B )䄄{`"Z֢(Yo{N[c#V@ZahC٪ky>T"gtwO^nXFYi0A"BhJnCɭ#'gj1˷1b#,#KeĿ_2|;xk$K+{!ޮRoa˱S<:B[w9ɨ?S]S}x  nmi/us#UEL &"Γի8kF 'ĸ|$~O:ڙMmh7Iq-+vAJ?mz5T eUaW^c2gR؇sQB>'7#!ӵ:?,7UGUOP?]yaqQ$גy lkR%:YDPHtH?!+Lc>,^'Vx}}P/J YIQ8mf C:=U9`H(D;=hІEA *n2B[#Ivp2L$&Sn!{:q#PQeLA`C.Ӟ+r[(}R+c1S6O-ºotgrse˲x¡u Q$"S.z#Y-lˆݣD7G8g\'F_Exv}oQ޴ 'O.LO)Sk TY ^8Pt_1Yͽ jllU8ax&Kj޲-j2U K f]eƋa3Ζ K8ܐγ|T/p1A IqФ6C2|L% Dm,8VxfM^UOM)kU{IUy_ⶄ rjXFp'MuZOgm~lVKBޕʔGh. ~9^R1< קTG95=TN;)ZcLl<ިjukN4o%B`7&,%2݈JR&|C'Ԍt| M 3q DU \#/uW}^"YfDeڭ YmQ7kF35}L01n03̄p>|2q7c;o~dLD”N5*V$:yx>i.50vc%<1۴1BQ-EoK]廽%D]F•v]-zE( nxǟY];@i/ؽ%YA2|~QBd8STp$yt#3NޮuO3:Aݽwjb*R8#֐!=6M%U%afX1~ark.~0vD/X**hY20q)E Ǝ%d&d;PAVpmP]59<Ua'v%Ę%0x$MQ '"v*nm1sWgVOT7栣T!!zE_Nc*O8Uҵ r)';H={2t|?"I4+:$Rg6Q۳?# ;?RfgW6X=$x bUKQb;F`F8Ż9yK(*8/swwӾ5W8x"6tfEsъUf4=,6R6*q-_O76>ĉ]r`XC( ꃢ,(+@?m97Pç ٴp,>p*\|Lo5zI]mU^P? A?;̲=)(FJD%_.zR85A$Vw >X6c?gӛɄNGXeW,BBsI&pjm}%ș7*iZ`ӠeV]t;&*c{rg8E̿7Ub?>-3'4 '޴!SjU4F\^`9 [@F2i݋W:ƤՁŹx`o3[MHXP-" (? 1 [wbʹ hE=@p$7817v55)c/»b:g6Kj b(1+ӯ[FnU= b9D;/zϮxWðM ď,Z]l˃a@UTk"`%=pد~czw}%{T״~WՍ@\lvB2d:8J#PoԖva5h)G+%|y߻4\>>a3G@`q{usaÇ&ty${l=jAqG:۴h+JRA_G'!+ĂuU"^t|%o.4`M3xr'%jb7&LX1a^cUhF,R;u|l^mV(LXfF6K˷gr -9I%Ü Ƚ:7-V b~aHjйX 2j`AXz>]C$YFV I#, ~cUOԿXCMkjuޤ&SiltNz,u坣sT~#؋38j[~WNِΎo M&V9D3EENrpbsYp%^>Ic<{$RT(TmݹSQ @MZlwˢau0AO.N+\ՠpX&j]7 Gj@#&~f߯f ? 29&k1Po$>Z2ݕ+Eа(ƙ 3 O+9?&ԏ:hi(xrrA* baB\KfxI$<8B$ 1X.㌬c:ZP$H"&mrsЯX&gXFyi<^h^Ssd\; ͆nF''Dmj6{{xR`uIp.dBN),*|B\PydA鋪14z{$,a< ~/'T y􌺠"޶CSxjVro[\"FLтwo4mA iODPKhgdN =ce.:ռaqY'Aߣ-$~K<`}JPժG&.G(Bxh ʒ2\ze pbjx6Sf`lx$A98MVBlHab-fL!&{(v67ŮIy5{[{*NW ÿ=3:E)V73K5--{Zq'su]f2.D֍~q TL!d^KBeK~([<3Z:69 aMPWX֛vG(AW,ش@_E,*G:px9RbʍLQ\s,ԐMpayF1fQ~V'}ըqQT#/,^zƫ_9Y="3W=^ 0zRPSU-kLjKDlAS(A2*qy87vAN:[^=fT́ex1"m ,~VVcңE'U)HƆ߅ϋ6qN׌aRpؕ{aaf 4Xd:f6$f=y T+Nҷ$rI,;Tt%N EV-ׁ0W/X%>.z ɐzo&ssڗqYf:]Rď _A#y]Z@bgv1K<r F8LcɌ1&w X% Qyw}KTS?,0cݫ0  &;ݍ=ۄtK @h8M;k3# $Z+(]vh/\cLp&yx*%ehRI> pn(o{G*-SLp.@t\_qG(b 8z]Sq Fˢp0]Te NxC7]kٚ-پC0n 7j :PscB̷ CrhQaP4ӖfbNID Ombu&k5ᴈTe.ԝ{Ŷ/-zï3 b nyf`-(;>* @r~N:˵ 8[%2m.ѯjTq09w~KQ,%>/#[hrƲ2$Vy '9^#Նq+ey|\ab+@ BN&.ɴ8܍`[=:^TڷOm0 K{;|a^e3%OWP͆?N%)"a]u >x9Ki\ zDP d,eЋUiZ+"x:p* LgiZޠXbJrbq{v޾6I5vH;oR7sW#KjuiŒzS8Lv^$ ~`!>E[yUkZJqӗud2ּ_wtsosh7 ˠuUdcc^sS)t# -Dr7z9Q ?UǞyѭ,Oǔ1X?}䁁E2= o[-޽Į_BJӊN10aw!Nb'N*4ɷCn;r /sb+70x&u|Uͦi Fb*6bÞ!\e+8N[Ami|ZPJ~A tEZKk 97[E(*ŬGT['>[9e%{t0>v}CVqTP (@3IGfhk+f+SdUg}e^/cfMl(R <̓3SwQ.(L$V"p&催gc+R*E|s\rT|+(;i0 -uz5Jg ˑ:8@j=Rg )]1U%tQ{5]~ۖTsmIprʨ dp.7STcޞΓ=KP5T֧aCjW,[)Bhh |>W0#jZ_]DPF3B{쓖u0`tK2"kbluG, ȏD1Մ K[mC DFpɍ.śj֑X9Gynl=ERMmo>( +9TǘsOR%4t4ۺ] Uwݵt[rFﮜj>Qc\Ԗ2sH )ETt 2Z~%_.6ŔL=k+sN~ Bݥ!#٘|B&d8 ?:㪽P9,v`%y@/yၼWE \{{#fF7K];׫7Q 7C3Oȭ2-Z[#kRԠzH){g R*Le@qm ÔOm\t0IɃk.B&w$Om*Ҙa`eApLTY?xQ <_XY+So/ߌƩnjl焰 шgY| /7r_]c^rS.uLw -o)U%߈l/>iwA07QU1J415^&fe?/`uH) =\i{_ ܎?2-m_тpu0kzOrإ 6=^w06c4yWݲXE-4yҫDQLF`qkA4ڲ\p u+qNQh8Fb3BpώvF@zGWh-nik:`PgHX4 z~L=F-mq wNdO};pN:oPr“ADbrO* 8>3+%*zUu=NzF߳zOGt$S$2k7J4mP njj;hOz9cuWp,e6UT( ADv)h Ƴj<=ҷe XtwQ퐂~г}iZ{"a2 U~uk,?()>B*tgQ<~*P/92xs@swܡIpJ[ ܌p׼ [KG@+;"Qd+Urv@;)X{4'n}cS\s|O2T'W[I(0zUMΞ XYߙ3[|%Hy7+IݘYnD<ހkS 9ݣ=I!K9 患@M7~&P{lvf?˿o=#3UW p.0VD9*, -9`VPs'<5'=:ƹ4VtrGs0sGN#3ֹ,'h,ňVkd퇇 Ծ.ĹmErt /revDz$Ek6:(S!Fdj;ٙh4|s\]>"ޯb5N"qM5Cߡs^axd鉇4*+ %ZNwwdpOr]a ~ɂڀovݻ,^vo3ss \{8:L ?yK \RW,P7p& 9|`,jG*"SZq|SnM6ǝ뮒G,I#t.g|XI0F C"o;%S҆ EA?٨~wŁ]`J.շ6}-h"^Q#2F]9o uyDTT0Z+)Rm/A3uȼlFb8WՆaLI!7t Tt'_R0wdH[ڌyCig@&a hQA6VDiIV΢(y>9Zƻ4*ZpSX@)/:Nx1%c%7e|U^4?n\WSz"6:S4Gom3m꺢2qc]gWqz8ڍXZbgI LZ׸$W[1zj5?LzeD~)%N&MHD D\5dp;B8qEee ܮi *92J,| `@PUr|>|ց'~}#qOGm֨l`}؞t6pKE:Gֽ ֺ)*αp='X^F8.BsC%95c,G$ssmyp-Ė@5љM8(=G0ӳz|7y;{ vm_6ya6Y̒hT3?2[Oߓ{s6W:-m?d\GDJ%X-Vp#gòwY2.Oq &(sjtF-ީ<:O |vW8}qTGZvk- jqJ~5PFKf: W: q (AR I)TPr6&w 0OI ]TCS|悽bxRmif5k95 >tM2)Ɋz+]RRF[*)2s}tFX w‰N<IBhfa.%F=2y|/ H"|o*xDn_٬Y;f˺>3qJ+@q1a" pvZEd.,NdV9_NdG(Xoퟘ-U覀NKi"Tf5}/(0Z.=Ͽ\]ė,1’2N$i =sl#q%x.KP#&/} 1.L݊&%Pǭj0P ~SmN^SIe.b&͹LM, ;V'ԫILx^VJN8Hfh>>S(Tqt*=\KBOZ'a^!)t5"n,robQlkYkkf:cA&iԂ58*Ѫl&=jO_$FIz!Bwz|lǡt%d98ZcNK~\䑇-瑣)d}|uާM}S ZЯ^QjXA?+dfdk$],l94= 'yCg!Wr[F7GM*L<:w .Ж!-SgUُhJHpi`uE~,I?FKB(uQ"*IѿBX;zK 0aq M(t6"b6G"$Vh6萻uVf<#OT5}O O_|Dt8V0$`-S<-~=K6UWQ6KrTњgG98ؚ棯mڥgGt+!M=r RY}uļ^'~ϪTLwtɦTyDk l¼ 埥ze1*lK[KIHpm\$,uhmRw/_0m<:UViwO,s14=?}\og73kvPM6iϧV \X !97uv.Ѯ|,r >)̚rT인0RcvUf&i\mwI޽ZXgDt-X]hǎDR H(8<^yOr0h#~ԱH#--s V0\ʙD+oElEH[dGma* X&} 1oH5];\2Y%y}IY m" M6K/y8[ף! ̴'.DD5o9o~NlW1'"= g)únϷG$ ؀ ؜ Y !՜2}%3ԕ3.ۭ q޳_9x䐙L]Xi,-v8N{Q֊'ʌPfb~fwQ%{Fm@T d4ZSL!EtYfPIP$APoHN^ ?VJd"xQ4K,Zs(uFqwZmOVyߧ<w{8͆f!W 58x\Lh@boY0b7;TQ՘ŽarVx:nMO}7[P.*K0 d/zg6 F'&R_=86YꚎC%êOi,Y9g&?Khxb;T^_R`g= Leh>ʚ 0 T&CjaQ˨5-/:w"^ xkIΠDj#h6("htVUȷ>I|!8}dxQv$X Emg#;Pf.tt EoO}<)foxbMOCEZ^bP`j&܉|h{Bn6Q}H0AzȕHؾB?}5qq̾jj- zɵihmA܁6%|˯(|(4.n|} ŮrYs]T toYܹ/|0ɜh\^x#{Al!ʬIC/u;a|˗Ej0R O=noA=>j×\Rv.H^1J*~SSB\4en$hLTe׳;H4胵2_mϖJK1"˃a26We3 /S7n%]36"~?m>aNXzm-t,w1 XxwzW-!RhTVI6WɃgacj##`jsEI]8Viy%;,GUr_Y\ h&k!"'g46-Wy~N_|ٿ,yPOV:<^[Y]| ,ɚ5N^?3Bcpn{PlRG1$Jn588]O0H\`ty`4d_Yh]]7gd=gbC36o}ǤRi$A[kΣx6d :c%+ðcs`ew96<X7GBo?`A33Odu]$vc _]Yj82=RT4EڙʼnBznrrJ*Vk,z3 M-bk̰Σ,>ܸބS≵LXݎ0 X*-$AҼ׍NHWh햶hvCEV<((ÙM+Ɇ_,V ( 4BV~Kچ*H7@J_8U3-JSln@y4C[YJa NT#= ʕؽ9lo玃 /}Ւۦ_|stbSğU4hN&?U'+0wql nI,CD.wd@z?<5j11yЭWR^+*0ŨaTh%jhHH2yaQ-{$Q`'\BlWb%# a'IG ݶvNڹ*c1>gAaa>Lүa?lQ7+{;hҭ Uk'/RBv7}1llγ59dA:@!Y)ܵz8okOC vb~ ;@Q1&4v VtdTBN #y#a U(wd*eHn?|=э-P1B5 LQuk}w_x jqfDžS99)>YR&oM{/o2 Ϙ8#17B`FDUG@lF4W2WshbDf<~9<0hcL0{iTٽqWK:`-P9N.?"qgߣcR FXHYxWXrj: Gup(+3j90qғH(Qkfއ-mG 7sͿ}GwG3%Ӯ[36euΔYMr5Ҩe9p:eWeUqA曰9L(t:+iift K:*dй]uZ9;{f]pTeed?ϖu]3R(n̖ѾřpsܸZ\Yև&lj @?bY3um?CkpMx 0 'QS?aQuzeR]AhD&ͣ}a[d5ZǓ] Gg3vsv9S0h\0i,PyjF"Ϡ_,6ka9^ Cq +t.RPE sDv)>X!^ppJ\m p[I‚l1B[6fh|4>@mz1Rc=M (3hwM_Vz%~pc_! eL7 ,UniADezp0C=SA2-6 P[ 2Ac'*~Π(PA"a?ga 7>X08n@˖5ͭyhFA IGVXj&l )iN{~yB+H6xef32GS]SP// Cq1yHw{XI#ȬN;]3^ͣw)KV _DyךJ~Hr[WϏ @?l5(ll|ʴ*8 sH>F^j;Kꔴ*[I䴻μq}6+ 8zne\$40FY;.1A@=I3r&(9veXǙ, {P˕gKkQ VG&93)WM~( 9%%> -ʪ;qU'}*rcå /ɡoތ?ZҧK3sT$j5՜ œ+tPuNr}'# c#QO-;ְ`VOg6ii'&}rٮBB[n-([2+%yyDwD_81z<_߂s^U5J'(+ xTUR8l  G4wq$k`Eԙ,ث%8d#>FjˌZb?B |trQk9xd`-},zr+ v%#-8,jJo@6kӛVOֺЪ@R\'n3w;΂縄DŽ>=_ʏξhվPڇٶ$vt8`܆EWXVRU )j*Ik3Z qOS7%lzN/vC%j%fEq$szO;8A*e(@O.$i69Feu7prR0/`s t)+ `_rck`>ŏFݽ G4 Ez󢝄!jKrz}QJUMFJbMJ^!w`yረ$mYTr$O}:TtQK{2"VVя^[5,wa9ȃXt]-lcfA~5ۍ39/76snwqic6%6D¢hjL uPAkM:;pD!AryiLC*Km?5K\?щNmW߬sW8q=Y(*uNh!( /  6E=n,nk֑Ӛ&ɱ{q1yk {Sr|:ozʐ1U';~JC39BcD7UK`fX $zdvl""\p U:iJCh [iR"*Yx#{080R3P!{hF*:㝑gCOjE={h&:#'SƬ H ~RidU񔣔KZF/S:Ёx*A{{j>dDwBp]RUp_bR6o=o? OS"C|Ux[<6s_T}h'A|/LRlIV,=9ÿW=_%kf^B%Ev 09+!;AhA+%`l~XUFS#ԧ32՝.$x~Âׅ5>; >h6aRh/>"L~]i>g]QhI&]?=)ӯqt(R>s?cVfï@qeR7b+(=M0w:quz"Qc)Ӧ1faV2'jjDh$yb-kF{e9°ɥ[b.$Cz{O2Fl=TUKC=01*nL:֬3gF\gWs:*P4Wj׏1WE`YZ47="uI1z''3m'y/+\`*!|_t+3L,pPMU:P h~mX[ɓ^1,6^HvNͭ y2` p9m~ A"kZN[!Y3E2DCL!?%Y~L%D-OuQ#ũ N v=mf&:Y!tȥѾ._]"QϯZk1=]?HF E!x#-O4 N8e 'IP ?vmE惻+?AIh狪o{>:.88^ O^g yd()r5`^7!coUL/Au!bvR4~xbgV.sGEB˅?'#T4+{f/7'naz5:6aSY slx D8wMC_6Ã&ΩOgᨼyfvЭ+ RdY͉cęsADxxkV^/>]q+_X/u憡]2\h!Hn^saJ.kuFmms߷uo*g#hYJ/{P<<5&x_Zs 15~9i9{In'U᳠VCVml'bgjh[,D6ʞ!|~T_Im](WAدdK?z!BgJ@3@#瀊J ݶA 9/="Wp=˟R5dž4/fifx!:8|笠﯂74xX U9V#U116E Eo=R29uoŸL2A04 -zrgbX cB! U夺5lQ|{o< =86!8"U-?C Q{r!Ķd-@C/~Biڽis#,ݠ!C{͉$(mÈk&TN9#YL3לK,YVC>0Axg5w7}j|ȘȬK:o H،̈́@kdlh[iz$zx4tt*DAy}!N:WjLccQ=e tƩjhp;jZ (b z,kS`/L;Ox/t תtb%>|Zuzrvo'xBThG L{5pD%H9U.T%gGkd2X rO[gҞk4 .`'h`g|8=8tG$-n9q%6)=~ʜg۱@E}Kêvź׷R[Vl;+έ \oQ>WA4t]mÛZ*9C딺x] ='bDbEjnxi ڈ$>=SELDMkAΰI7)jfp! RЮ&j_50]ù| `U2uh9Q4c6&ZFEReGqP2~ \Ǭ5ڞ_RE3C-SJ$uݑI<Ftj I4DHs}o<-z|c)05.awC$JX+̺3۠RR!s~|F Ӛ\LR.չvٓF6QQ=HyD͑m_Q^ V#;ru<_u´ɬ;:R[gaQ vqQ!ejJc}`(o=3H naΝw bPpb26۟W%鿥@eR}|s͗(:Mdqe.A.SZcq=0r=G$ (;!(p"Iv %hK FrE}J>5oi6kAjm#A;eILWf)ŗŝgD:IaȚ[/?^FbI*e8in<e\)O7V4ݻL\P}6Br> l/Tƭ۔0]𸖣; 5 }Q%K/iā[ٮU32N)2*ܡjعFSݠh9>)/рRyuʹw]W1|8;L]kE9Y*Nt0,pM PXhr^K "=(n}7TPdtYͪʭ aDTm'eoGA^0^p4gQ^Њ\ w7Q,s_-ʢ7 )LCPu;BM{6g/.3Nr^1[Ǜ DDG3"~#e4Պ/g9_H3G}ˣ@TDB(Bl^ܚ]&C`tIBafTj7oD3Q֥S+^NfhkPD-\b' ,EXXJ#hBYu]K6h;W 8x{.A.(AnHLʻ|-ոЃ-dV7~.a _ hy/7gJ]mf4 sv&8ߴc_ !ZZsN& A`|xzB~wAiX>y sQ+PK7! GzȣYdmq*o/o:R$55 7QK D"zvAR,s*˗^;B!2Y.m%;_p&'egM(]7eG~ YԳMS:e LۀE\Ւ !o;Ux*Ls6e&3ݐјUXU3ߤxkd3@Reă+X"̔{@;Zubߚ3YJ8 0<_]ͻ/\4' _BaV~A;2ilzH/3T2Yj[mvF^*( r7 vXh(&rQ8o:1MNl߉F䪸t\݉Mj>Z ]P\;FdI\zq6y=qL?/Wc*M#$yzVYiDϑ܂+&n G;FgaQr-++=sFx?oK~~rr]Al0.%yseOŵM:>T4ŝ}_\I,- Y\cMƴi{:NDtm{TRv|#GiB{)7AvW.CwP!3kZc溆QM-ejt>fA[< a[pXVI^ 9{ mP g+혌0TA# oRs’4Kk[IQf3#8uԺk qRjXIY>$.!Ǻ@ldJTr 9}cngYk_d!Mc"xßO{Lj;/7&X]J;η|-g=}ӡ&$3\`zi%/À8rꖂ# (8x@rb\7adB҄Q(80=I@ kQ@DW:hz;]2+X|B}xDzF5:yfK\ /dH"v?uӀ VZb)AgF;]Oi@s: (84w)Kߓ n6,4!P&y2l0!z8NM n4ޞ.0?Mw%ӄ3-fG>XJl݂0ZM+'F`K*5BKd=W+Qp4ȳPF,Z0I$x,N! _<{J?w=#" vv%^maFܫ@kЦBAނkxYt0>w?(VkXPNg_2j\la ހɟ Vb1߮@b8xcjӂaFN>29-Ou&w 6: .!cp5ǝp;!|g$fľ(@:qTxR:u9|2Kgf@ٜOb×AZlwץOV̟@R~5!w@'$bVޫ]Wvis R넳B9 Y) +7:EnW#nUT&b?F^ C'Lߌ:v]"̾4So}FGMu=*5i }:v3qQ}IhTo߫:Mp1vi"Ehtx9~g&pfٿ f)g@ }3x3~psD QI (.9'E1F]YR-~!7Q~l^*ƖQuHE g%zhɬOK{z`RvɄ4}FM 67`_yV|@w[XϚOM/+# 8R 7s-ABU0kcJL%u=K[Xˎ 5ݤV}IaBVyچ dH_B^}ψXaP9aٺh|xxʍ[VjrrQmՉ5a޴9@QRӯDHhIbHȒ8ʏHϝR/+%uƥ0ze7]J+­@3ozҭă UEBlptG 4] ' 7 ̌zV6`ru%4t7ڗ.塻E"nQUWݐ'_P; ;89&8tPA1znvSG&i2Hm {y4JqgO4v_Y0E~JW8U%d ndN> eXSWs_Գ7UNufC}XF{ }#0eO?+*,UBUFRn>~";򰗩(}D7h\IW zR" ';vYɰ( m+@4nJ+X$MA5QGqeYΧ'G Пx+_I=G5%ƕby>jHQNiOP}8/d33*ٓ-Q>0 Aw&'9]7,q0e2VV7|ZA-.>oL!(5׌ҾAKY>%qX;'|QRSۚ >1b]ׄwUeHG")˶L B)/sz].M6N~^ {`FX5-;od9poiw.f*T&[QE5k$/+?ڣRFapbeѿl|8|qM'V]m$땍):Utc.T k|*E޽|vQ LIAF6zNp"dIXysAL)ٸN*mlu JQa6R:͞ N, Wny*XE6]LV2 '2l;!Jݓ4HD'MK*LI5zHT_uh%gE+j9 z%lj]z&F ?ҸF;I?S}EkKLci)T.ZVVAk n;:zAZ㲛&VwO٨J3~" }=+0UI{ -:kms58vsY6y6  #{K/23aͬg Ӑ\Uzb$d"ǭq]#:皥 MN"K*z,.==B /kƽOnt!|XEIҿǤTG_M{--,!FvuL;sX(i&dߕǕAZbTnC oܣ.O7j ff]HUv= >ǠkJHTNǘspA)!<[KŁg'DC)1Tm`A-͌Wc=ApCu&,2OjFWf'kdv[pVm|U?-ϫ&x/wTFUvƛ k֯%Mȕ H ]3^twn9 xմӇƑ[oO *w/4¿Yf=P^z !Bm//F uuToHe,BЭya1GL4S GCPN3>IP295y?U߃M{S!Sn֢QIxe XWݟY36C3v.@0WsSkJX50_tH/Xs7BuMmH}̢B{/#KSK\3ăC{E4%fI*H؞`l# YW0#ae{ Lak^nO~y햻ur)JbAwx)\z~Z~(ug-.&`[VZBxnCnL(qt@<"iCT?n\LlЀғʤ,yZY&J0 {l;̥X{u=Rv0- _7LH%o)T="?Zf%|~D mqoL1gȷI ~laQV?WwX,B&z_jNW[VX(kBNyLog&ҳv*̯rxmC㥖OtJ/8j/>%'TMΰ)篤(颟M>jg\$P (È}YUϥ#p5o^?;\kVI"s 㕺iZTy ȾCr&l˭3?m?Y=QחHS|L2֦\x_N <-F}u`>1l_%JӔCT믔:QhYaGN˽( B]^P,i p9+!CJRٜW=9U܈=By#$~j 9FyD" .OBl9ҭ[LxSTqC z HO;+uj ڀ.?h"3E3U/jb*\RzY+I͍ad47lhԻ]֙0Sdۢ]56sb]O=')@qۛy=`J =.;f|г<:> 6X }l{{: 7.v,)2 $ 4;xa&Z.V癸 |.7$cw}ά3֥^3 =},`GyvPl8E'*l?d; @4.Bquq23K78aJC_5~K 67sᮧ.LAk9*T ~fWگR3G4`ºج_A'^p2{|D?K.$AP#$e%Ysԯu#(|/̎|0[=+v;4ڻZ_%0g`}.#_> m!}ZiucGȝemAQ_|H; ԜD6\ڇzk_ڌS,j.Y2604j5TЎ )?$+D}m' Rr74s5y (H[]KJ18' 4P-G&J; lRhV2~(#Ũk_43Ff4im=OQcYɆ| nAw{n,CBW}B.^XE4EiarxC݊, w0d8}" wE2MSN/Y*N/p4$02imQOm(WoCבSOpœJz>[xV *y̏L'/T*W*kML 7jZ#=Z}$0y<rKQ_f4~s(9UVw|"}5'(5KtXW`jwkMmx]Ѵ Bz E>P?*H'CA5L ($K9 `*>Lz~> n-Q΄ƅ:_$PUo)?Ǻ \!9Ľs] `\=#U|T$VǮ5{%B޷` ԤOpڇૃ1昚;nc/x kLNh1H8aD'μ{{M汷% !{xY+}ixG吱f }^M8o7%e.@!A1|eud@:01q @.?"(# I=PcW6OYߪ+ĵF1 _[pZ? dw 4ȳp\_c.8[ 9֓ =}$co_ ]C Z%E5"EZHhE]R~>+S#=mxa.y s!l(&ƒhtBXea@^v;~%idkO^읮-mZ/MhMG@0%feZo&刊܉kY iᵺBw}9*WE`B#;zi鎾Wԩ(&D//QQ3@'^`,&ң^9ڬhNg\owj`'[גgIA\/k hO)3>FQ'&%щg@haKW X~HkY;Xl]kHef͍9vĨW^wŎ`>٪=v@Jھx\pwlvV|+^[i@&{srT]<]go+׬phK#ݬ7]4f[N] sd]Q*ٚ S?Q EXRudSeMBD) N4S^)e~ Xƀc&G:|婄)3 J IhO1EɌYLOWSp䌶Ù~cIdOEZc:'_?;S}Ra{*a2qvTZJG P5$#ccWD+tPmC4*z'aswæy3GhaX a2JXuys}{m9uʄolڕc2+2%Z5)RFFKmԄ\U.)^;U|&)ݽ `{۪Ԩ #2ު1N|#ik>90U Ҁ7V ZwKUl~mpl%VN/"YTsC\̣M|Q(S"2˄8 BIdO跲RWfu]=i=KǗϷL1Las:3vPaxLЕc`r;nH^~GTL$y;T>: *sNwbm>soGu&xFDEyiNkylWTT65# oф?.,Yk}~Q*ymkN<@SzvHQQ/k d^1N\a< ]hCp0cH$IchTVJ9x<4ws7W)vճKO{E[SgI3(\HXF8הUQ\vB?*Ҟ/J!4 LtOUXI_oKK|c9!@VvPkHBRZ [ F́+nONSch={@{Za`G/cLg}}!$f'UE=-1j_4<nRaܬ5[HLf6pO,[]z2ЌsÍ)HG*ÕMmNʍ"/>֡B(#oRj[6a|?ep Ŀa+2#@"xh%Rfŕ]ǘUmS #*>2ڝ,hF3Džma\}9E(84ҁқ廉J0@ktNl .HCa+;L#P"UMچ'}>1peH >kyY[##Ln^~mOf" ,b7I0B=7Ġց>TtӱmhG]q*a;7YxyݨQ$>Jeoi}% 'o>h! 5(l-$q&\/AApo4!!p_蚧z"@$m-"sj\Zn&aVڟ^(teqWpѩ%uD8$A$zKH=eϤ 4K#!:eaG]zkUNPĬ1L I?kj]0$e8}s< GXm(ĪlFyj#y,Q9mYZmuԇ}jdgIgxg3z$.\R(${kɼo9#MftÙg _dden PV=SeQ_HKOod/t܈2q̋ZYfԓbNt|C`K|f؋l[d!ɂ*);/sh`;a4ﵧ3LaTC8;Y]g~;l[^Hq}}Kѣ!imwc1׀4gBNn& BEޤY܉>/E}ƃ g+r3jzvZ$a [2`qS~f+CYf@_^,T HYRKaEϙmYghԽumzkOf2;}쩽Dp `w$A x)먙~,}GRPw%)| @%Wvr59avTʃ8-D ΀Pa&-Z(PE.OcCVӧ,*hU5b}&[rh}#IQ'LG?_N׊@uƇ|Nՠa|KP"N2vB~j\*MI_ة_0H}otYc?}rw$$ {UUSS # č~aX'&љz LL~dAHQUCwt؈%u< U^%B?`i55NJELGj Oc6pKQpY,H^Mc~ބr/+E\{n%#P;EVi"[U%ziOvS=YbϜ=W@땷~0EyT]K$vPO'jۥJ(96,F1Q Ah Ŝ,#$h%Yu~ŽG圁*l+ˌWSuB⥺J@U g7Kio= b]ѰI7t]ƨ V&elW]mU5e5&j>ڙǛI5lrqHe0`,|,U=]Ji։],7|vzL7+a?^mMuV懶zyGD]TUհjT&?K=+Fewg$^-YcO8(OL Yq5]]~lfg #(:MIc *HZ@ʧm:0̻=r*N\8ؔ Bc j;VQ\4a{a0W3"f  wIGBRb?.Q>:ԓv4_"zd|F$B|9nPsb g=yAS ggqٕA8APת|M0'Y!Ei?A$4(-Gf{"Ѻ< !ܷjVm LL4&lo9򪬏t4J}>vod(Ǜ6G -% rr{)wB ~(?z 0T.`Sqwk oTZU$<j4#qrzQ}VҨʩ( '܊.Oo.Z*:AA L1ك2JCnH*㉃/Ltg%MG)D4P*>0aNM_ۘuGCo=ZoɈ݃-gơHZD%^CbUȠFE%3D?m%WzvJ%a&+oh4( \,>(/-w1Kߝ}<{&j;̣{Woal*}tr+#4usZfAL>Q>ohmli *f,b9cD[y #ϷLV@J$n[ )#},V,xOeN,[/2_PgRhO4:"T;PD&yhy3q2eԛW)fhCIy墈9rHwW佦/x4"6Ca K%&U6\8glIv[9LՐ'ψWM$z/RF#~J"}<)B[}7b >MgVuKo#W&\ucg\17yhٍŇD N5P/ِ sKE9)P&-jҥѹLISm`Dna07n@[24 ¿L!p(vN?4FXK#Sn 1/L|h+c{%|>NO$ޝ  =1_{дeuȼ$l.F@5؁OˍJOo[9Z vq6\TRy;z; LŦ'!Bu5y4݂80X/*Ct1uY a``9:?repo3\&]EK!i l[4@3]QT ?k vtXլwqgUW*$C,.#[ꑞkA^[?0ᩍݫ1i`J)* 2L%Ky|?I;P$1pl/o_,yײ21& 1yJz LtEN67u`Is/rC <ـoMѸc>ӷyD&6җ M8qBqmo)44ȇc_ .I}IDv 8D=qmk#2IqˇeY1 NI'մ%3ߋOjSٲD's.4p@nn"(xUl(&Sk3-&K}:VWO ;3Ad:M(eJ5)bkl!YNPcK6Բ?"֤5Dr=#HU5< j uW݊u{۫P^I]l7/;6i9 ۱3VQ H~4e%W1F:u[Xcob|N1Ceg tu亻$k: Y*Gڋ Y"9[uHXABqdS)/oPE$;ZuJrʷ<dpiX٪QKCՑHa"YѥFvO:K zpV?P^?T1 szH4l)dG(4]3'yjD]!B- x}Vl`K/|o% N7oomͤ֬8BO38>1U!wd½sdk7"=ŠX|._E^{7_7# E5` fO3 TZ2\ׇr큏y *t 2*`Z*OF* q"@m 7td* ؈Y*W:ȦO:f 0JV0WP96;$+NsvYN;ǚB -FWOXZ_-vAȬiy#1m#t́gAhRЁ2}hqL W35Zr#[=̠~s³L Q I^gV IE?5ﭺ౓͐Meu]Q:%.xK؉(ůy +'cGFPn5gXLUVFJiMišbZ]*؋/JU;ęQt-ԆO& zd j3g&딪-BWo*JirC`:~wy#n`/ef y=R8xDjj~u&1_ZDŽ͸ePJoS3}YW:Cfy.|ZN0tgn1v}U7=~aMlmx<T{JdY+TXLdInQ-w>j Lm闔(EĤ2mOjU D*ub0Erݐ}S)hzM(t6*ed 2HTK>Ai,J+Иm,!HT} ']ś=$O+Щ"Te`A`ri 3}k۸i"+/Cu}a 4v%`N[paheqUr]넘BOQAu}# jK s VA=(%1.nxf9U+]1ݽt*E[m9*9[c%MUη-c n(02m02b@v,IpUju8e!cAv' _2x,\ |'/ZXlaMك_DbS]Hۼ<0~%3 Sb݆hdQIQM-'x*x`V|*>Ko<"q1 EfC ƦtmIї(c(СޞG|`Ⱦ1x_zgf"i8݀i4}W'eq\ުJĴO4<VU c>˯^oNs5v$$%!Ww*e<`GˆSI =GԐQʹ,m>>9g<嫞^!e"*N el-Z##S៰٦ /5SVNB$u)*[RbI[v~S&M[2X/s7)SVXx+Όt3 KY}N|[6sQ(;a'd{hE$vnR* lf* \V%΂AOm#H"oyX.$v[ ;=} J_9g)sMBΨxbDHo٠o$EXFP[ۇj]ʌ U؞Ww)+"52R+q(ɺ~/-tNVZS;{|Է05=:ŪtmiX̤Ue,E$5^BRhVP9m:To&n:81@t߇\V@;Q;zحlDouw6eCv҈sgONʥ # /\84's*~n̗V6 }9͑Atkgy.%ߒ϶vYBtAT>os'zg|<[w2 18U`>74q9m s#c긙^6> QmTXA݉͹p|sYu!7D-INFOQSd!wSmonrrA_+Z3sU3b [Ь"|)#!|g‚סc5Ojml yE$$ym2. `]'-Qv%祈vS5c%ր">txd/ϥΊ#KI@9~ wGì5|6.@yݍ-97߮<^*%pZۤoy-ܻyR-fZ`j^6SJ:oY4=Vuܟ.s`!þt֍Wzɿu> ^yh8/uꨕU{#xyv"O-sv Fᠤ'j ^mZ<bիZ3`Af$VUgh5 ۺg8Eu״S2ŪCy}\bnģƩfSX.B4^]a!svHŰr@^w^>rlqHXts%ĺڲ_q;r.+d [/szNVVs[N6R8;C2cv$=.ChZm_TfSS ?Z4gyܼz:rAm8/6X$;y훌Pp|7ALC2)E`t-Zkَ.fj+3%3 oEQ̯7i q3-:_U,@]Øm6![/;p[Wqv<̘t+ʻ9ѐd5C2xp\ﵻǘ@_S>Zp.cRjO:$;5㍶@?d[W <_\˛HYZsgfJZ6h>t3KQꡫkLE'L~]m~ 5gJRޠÿWҲByshx>C}}~`h֖ 7b| O2܉RtdBcrif8uYz]kMgHUO٣/e`QZm'릈#8hƥ؞ۈmZ{ḳBh@[RG+5s9E1eX5 Uy}s˘J%3d*w݆j(qȇ44r+r{l8Ϋ9)TJ.:啙g fSEtjIIJ+IxMrET'uK9?ALv`r[~Զ?/_OpBT-є=u쉾+*tӕ$2R"&QAĺ@gJ8 2֓dcW9+,t]\2?r_DƪB|t&2'p39B< O-fU@(gǯ&Tk/{]6F!,y+i'*L0,ag3/av AtoLw+EI]CwẔ5ܝ[ V5V\ U;Db_ }؋s[붽 y F6j8kQQD_n)}f`62B`rD涫pz]]WOU#A7ˊ$v:H597 LY黶ɌPnPQf.'e=3+ScM=@X`dH XQSeY)=SqA`832)#=ִ_%{%Gڋ[KG4 }g#Q eHLv&#iᕱoc]:EAjh]#F3J\~ݞLzut1{(X֙Kx8ՄΌ@-[ઃy,B{eCs^dW :@JE0E~`جMqKvcu۶/C̄B-&FВomRZ˧YL{z nuȔ2 ́\ $8G0{A?sb8SnIP QV-$ܱtlD@m6Wt^Rl@J3^Iill{JHrAwV^p;X9`q8^g!1{t5rd9Ͼ&:p21d\WCjťJLx8( 9wy @#>IC@4RF=cn{[M6c?%" \:* bFZ۫0cLO8Rb"24o_Ԁy6J[a]9EO9 %G3O`P=(΋{Æ4$J!PIxԜl ":2-[F׮tS>Þ&#SZWVS"JT$|~l'`nuoO3SvIn 1h%N3';nd*#r _;ND@)䝬N@:aIHWc h9,vrI`klLY@ZyjHx f C$Z&TQ/n.ϣxS⵶櫕8ݑ~/Iŀ`$߬iވZil'UV!̶̻P1jrQ)1͌!j71:e@5Vb’R+JͿ|͟_WN˒()rXVB^]a?su:6V&se;q*t璜{M8y~b k6GJ4 t;>O]{-" ipqd=#鳻[^s9LmlNSC[4b !̅7rZ+8X|aԀkfz9$p1<s_&*u<(Ov&e!i<fz4H,Mk0၁D2VW>{ˡh__ڀ.{]qw@3(8?PB(`iB]gDU}fz4 kvx c7٦ms!n^t~}gֻxsz6)exl;@ěxB'b9tSX*~p? .񔻬`gX1kTPwOQMBQ=t%y !mn( .zxr4@>ƻn˄-^@9\&?JQ%; h- -]L_J{G(3W*KՄ b^.87 A[Hė[i_ܵY#ڻ};L?<窠@Kmw1z0't$}uɍ 9 m!S! Mj;tME㷕A^ =I"#ZnNıh?4yGGr++z&Ow>bASLۀғxy2C'hdN0ͺJPDC<Ȃ ʩ5gJ y8 b?8X|%i:ZjF8#@bjtMY[QHrJ"a8AxJ2ICr xr-X1/ 'ňDu% $ہR@ӐWjQW?&>xL;6/ *-YЋl=nkŝLrʃ{EQf|ߠjY{d~YWRh'F^;U>z2Z{ +~{CXwڸ(L?+^\h>iWmr^(^r^{ouԉܫ/ 6bUJ͓qPOsʉL }=ZvؿW$J\qO6Oծq%<ҢO e) 3۞ QXM_MD)2T;:upHe#>ua2vUW `uD U'>t- P"[wՉ6x{ 7PC"҇<]P';GqqQf ôtw+;z ,O@C%/QXJ{> FL!,򄘰qlKgT"3\iea8A&]80K퓰 zqE4نX=xC~%Mj%\y~Es]rJ#~"X%^M?8nF폈T/@^gQ ~@׵,lWq+9RMFx Pi R4J$hR)GnnS]tM˄vCi;]kujMt]IpJ/I̭ßfl>q' <5. ? eYy >DIr0]R!V>aÿ`sz$` O]h2iƵiW%dFa9.Dw9 *l1È<. &-<։ ˃~7l'?O>/Aj !sNm,/*d\?a<ǛMG3 bK *7~2UNa/ _R&%nP҂&^v &vo7XnN'NhkKtn$htm@c+p t6?N}a8$;#l@P-ŸS_: %n!!V!n" YV'= 㙒-Ιԅ>|TSH~}-2vL ^v !v&g'@ gvL5 #n9aw1yIr):W/TE&sw8:`V&)3JcO]޼ʀׂ"g̺uهT.Lo|)I@>2GQXw!egP\W<{cI'9(%:wT %m <{&`(=*J$l ƴ[-Hhaqa#h+X(O\fSl]uWH"/a-C}f t!޺sSD*vM aV~ LD 6GYQ`وB!QjIW@b50}nrfNL#o{!3Be`H0, ɲ\T( }^|}] 2Z rd?˃e 7cf:۾5Є^=0=CCq(M)TP{J0Ǹ I_?(fƿkѭ6J_c{"݉T?1s@'g둢 kTZވ=覹'zՌ{`%td]U HgV0 %Մ>m*Ndx#oeGd^ws7;5tHǻМDͷV%o`o1m[l$=+WߥB-Wtk3|EٙG68l9nOΘW8tM@8YAן]~O)A=rNCMMbwK{MN@ā2GD*oL+8L3ӕ x3aws!{8O!FZfMmj,yS|sR IuJd# Vd̜1WwK;M:byO܁Vʷ#>Yx, }f=\H^BP_UP"0wdl60 NqF0(tfOX⿎;Lڷ”p:Hu$]7n[r>nj_H ÑhE{pJn[;M Ei<> Qg@qT}J>iW_hB#~hg}Ūj]&*K D Q>'F*ǟɫ CUȵk:Yr&Hɣ.ʼ' Q~˦*"m :T*IOwUte2ü+JyBDgkʅ}I M+q ڬF,F L~ʝTN-ӏ4,5t16t(6Yz=z;t5]$!=`#}: PWtSٝ_Lrf@F})й| 6`զue!FJ)'l,яD A::eh1E# aI:|Gm d0ҼI `ƞlМ;uLGs/HړX1^tL`#;)8 /{?&ngnEpTߧ='$c6aEȓto6'Cɺˣ,֜[,07W&7A%sƒH _lV; 7?``B)8Uf!n "rsLqP&pME [P Ew6&[ŋtAI 8U^0ah^FH=ldXLHe[.ˬz]x\AEfUD*{$D C~M2L5#nAdIe%NTu㟕= HL/·S ^Ys16,:0wuYINj6w| f2F腶ІгR#U$Fp^,u~C-᷃W6wNNBcβf[9J')jjQpaia&m'RvHlϏ6-{]Ҿ}ZYȼ s1Ų ^}U"}-K'o KP؇F0r;=9BdžE5ƽ_A+n^*°Y;<@qHpsUBVwZp]޷T3E&$ x}B- ,ᖺH/-}l!eԤP7V09y: + *M}xMq84)LWk1zYC%0CF7vM۳40ӋZ BRqxW:c6ߟg[3iU9ɷ~a#餱70@zrnB|~@{r'Vs_ɹ.wO5$tXH?͍ơj|ʗ7 ˯CdئO|I(2VN$jhVO[I@!~~28})uAPnG"ƗƱqcNjVg[܎bhAv'2{fT+^aryqI6EƠOpL!)`UC3DcsmwS֩S,!~zxl }ٞEXa|{ׯ9iu<-MIf0z[L=RK:]n{Lp C|EcƳ:op sOFCdwDl>`P"/改4[D<7=fINf<L ? rXh6V8pOta =naϚ솎Ŧ&m]y"A<{sG"t [ b0r{0GX%gG>{URAҎjYTi B0N|8h]+? $MJR%J3qf/w{H (N0:ǃXjbR\rJcx5GkNlt ^*zkyxf7hG#-Jq(o&)p7[h_ ~tOo*L9Vޗ*^f)H7S /3Q~uw܃ş~ĪPpDgϿc0U`Kʒ򯜐GseG*]UwdAN+W6;gg̅5-ś0l[] Pմ tT>33c:SWc[)Qq+<4'/8EGޤj93ۻLeh5;P|} {- 5ׅD&ѯ;&#iXTؘJ+'0HF`[vr8#е~hZgP^Kē]޽^+ѹ>;3nbY0@wv?tTskMs?Yˈ7څ)(0rZҞ7Kjb^=5C#l=PRcA)Q+{^j3,BAyOö{Z^;o/a9%b't-w#Y_򟈗,UEF:NT6"w&pE 4Rz ,$H(HAͽ,ZLeKtڐAt9uͬU$}U4ӅM Ѫƞ<=}@T2 &csr:jpw5NF5\G=z;"/&W{9tyk*#=gb-LbX40y}x=ܙY.V&AU%]6YIg6Naa Ul9ei~i,q Ls-R'd_JINކ*$Cf\D0ծ9ޡYx̔ۦ<ɢ>lW뒯T{_GZk] ޑ\ÖZVDI] pʵ OJ|Rd*}Qݯ˻){kVˬ[ӳLnVZ);"7xFTr' qSRo7S_v /25N--40x|\>慄r#ncp5ù GxHoȝJOfyBs3kjYOt\MB4)|%PrLd'(;sUL]D'Y? A-\GHв4`rH$,kgi\adYEw m]4Amr HOTyz$ܜO;/f/E!u5dj "Aċ9E Ue &Rʛr9B z@w|g A֭*'.Mvw04ϙv8o}^e$DdQ&f(9@X ):QYR ؏޿JjTaFR3 ,=p4 셊E \VK`^A~7@w)xs[;qZDk9xE*[O̠i'"y=~:Ml;"nc]-1p&؉lPf)mث)[ IYqâ5rO? B/- ={v❔AT C$ʘyU:-Lje=Wx+B"+<6ֈLc/fnF9"2;NNݬsG`.z#̼d 0ѦhH<5 y\&8$vRG/â@X\ isl&sOLJT/w`ԇ-d(@i"hfy}@圯!Ut`V5KrRdm_$u?F'8}8? r|M,fSR}!mRʳ"6Ϛ]+Z`,+֭ f?Pq1V=ӳnb?bhfgIjul?`hܲ;d,a;Qgg9dIFݜA)尜:Ũ $bv1ȇ{ .fv RZDrC6DR1S@bb֤K$+;}+8Ͱ`6t̙-;!+c+Sௗ90FXq4Kq ]it8zGz8-G9Sq\V'5gMٹRϝF\4xN,yPx'B/yA{ ˶%ځUrDCZoǸYb%aR)vTyؗ%霨ygPx9a1ݓ:qȕo\-|DW'NXRcJFdrp&Ka&Q:fc"jQ#B!QwQ0d<|uABG}$ҕ,?QAhU*)&oR(*(eZEƏu_~Tɉ a'*Jx~Bܒ O!dfJٞŽC2^g.S7w;im߸ ~I#N2wXFsôu+PdU2aS ;|Ʊ#!YdU0 `eg^FJb4$<{TWoUP̳.|ǐ}\Ćoԁ7e6c`D_A?i4ZėnTüҁNL5oụ=lmبZ2qKL.Ğ8φz5 y+2{XyfL>GZs  ?-ahljP?TK-zLɚLƬUUv]#^;]bg90h2.x X'$e?NGިyB6\ )B^t,.5oe"C\;s !JӨNN Eҙ_5w?ew2ҰbQՑbXirq Tǜn9Jg,v1PvB5"7JMe2rCk?bt}MW$tX}epT4OOhڸ}SͬܞF܍mzTadULfͻ:0|١]zs@Ze-: t'u7;MWH b+*_/:_o?ĭqA0~ % ͚JM"-W$Uh^XڲXi]wT6E,NڲmJrFri"SAD 'lD莲"uSvH6Zq>3 Ti/!XȫD] Ӽݎ3q[.\`Qs&z<kk8KEW{2'ِ0O"a{&N/ϳ%hȈ8oa G=EFK TCe_"OxCu hS9deϰ8'T$/,BbB)Ai,k_S;!51N+m)YՠY8 b;ʤ0"N$sDL7CBqh7XX^H:<}( ['A%^v3IcVZD,mҿ97e&U:WT9LmG6dE27k_NO\q%[z7D^-{^K;g?_SoAJħt6_6!״S>ʨE+|w㳔e6:RRmclp^+%cH$=;a䒴tQdEIN,װ/1kAơ}Q!RfI~}'R:fm⶿o.X|| {f߇:w+fhN\Y8KqSa6r媜C 3zP Q0B^AIg-^5%C/,P{Ryjjq趆(EU=:FZnsߏK^ C.)K͓l)IA*:V,Qh$쀬z\N29HP~X;|mk@H5DT p^cŒ]OL|gmJ*L]U?<!< v#XJo͘j7 .^sנUC <6R,~8k=.㞷 ^$vDC0CǙx?TZCa",< + ` $syT<$M^ 2)HFv:*l%ɲim~DMY|EJ^1"haR(4K{d]2XQ!R6%&^Ž͑ ٌWn^@)[a^vKØ>W]>_G>R7r"ߙ^us+^} mG߈65 +J&0~]>@MFD7^"߅SrQ1,d0:^6~z&B(JB&MQWDnbUt8aڏzңWVިn!G-LGL`klA KOCX>I)r̦n7O*47:2C^&(`Qw&s[5mQE-$V!Ұe% h*G_U:m\6*nXHPbYTv!F.>ā"BrvMYLu}<>=Nap@ƃ02Ûy.68-cQuiū=DEPn'ZXbG!@"F.h)O,OrasOCw Sa?oɩ+*Q=[?hq[RVS;7r96P- wI O?D򉳛N<6MܛR5:v;t)f}<,RX%?0ǃueiR홁y΀Z|{ vH +26umHZ5ΧJ $s:$NVXn;"xk]"ǠOd[F'U8{JI&몧R\Im@B݈$F.ݟx@J:u`QN, vcati[{RH+^BX 26bh軐gI:9e>1sB`;[!w{@/;A=|0A#xo(-!lYS)va\9|KA.V/鬢$`^ҦA ! N_Խk/miDtο9_cLTLî&\ݺ/1ɑH4D"hRƄ)P:O[2; ÀRy`ԕN@ITw&GvIuZm;z>wW|jkv,oU"#Mc;GM乂+ڙL,ݖ 6fU=9Y/N[hڿl#ohRlx ><ʭ8DZa[S?(Q؀``u^|yВBG*+Nr'*c^nD&,6c 4!B kó^ͬb:4±x'R3ݦ%QZA6Q'}ڿ9 TO*۷^+hA5xcQ: Wĕ݇ U٥,sAŮ23p(߹DTj] F2E!S:k\N5x/:POTij*Q]Fk?~ZDg&ۦM_V.yOwpN%\OlƠ:LQ&λvdZw Ij}l]"|4eЂF 3kmM/#D#ܳH zeް1 GzvܼW3m{}4ga|R=mI.3T |᧗/v0kW+ ، ) 'yRj,@Gw$e1(BO++``qͧvwaك-} M0nn-+t_/0M{;x8`K4UVuf)OZ@4v61L\ BjQJ4ռgkAUJ81iGՄckoos[(?| p^6G;m9Ko`ڌ>#؊DGuUb'*o3&}1@g1Vh TyXF'K\78Afc6C)gÕ^q"VZ 'j5ߊ׬'{׿޲b &O/GD9i?$cD J`[mj^?ׯWr;G*-qKj-(D1yi1Q>G.ЁܡㆢqlkC r֚inԤ)F&h(H>Ew_4E]vG2 L-Ti/L<gu] gҡt w rh[֋6at29%\V=dB8&lou:Ms!tJ. m08)|zeZeeر"VqƮ,l-S<RպOKuIkWߎ4z97ɏ}C*wgsfÞy=䈤Rv>:B7eIP:l9[Rބ+qu`Aax"F TiVf2!cϙfx_۶=uAIr8rozM+9I8r@ߣU`t>PQrgXO{-E,x"JvhDM .23e"kv&zVe4F $eu- e,!1o'\FfJ|L'xZԻȊ1]ڠ6"B|יMfF l;O ĭƆZ!Bf/^-jw f+rX!Rzs|ZcC)LmrփROA)n"tni=*VQ)i7N]hpyz1D0MQW[IGls&"4Fumqun!c;6b[?%O,jk`  fU ـ ocs~C[x!H=\H4ڋZ멙u0\VN:쮖 P-L9i|xc]%& wfyӱro.pF%L-E.a )^`V4]вA7G_C**p`h:xppnELBLfoɉޟ8dPC 2CYy힞@[/,=c"*1t# Y{Qִ_|J}gV;"әշk{r 孟)-&&;A}|YI򁂑%; q [S%`}Tq q193J4d轶K噇H3 e!psJs"QKy T rE5&L~|`hd&u(gO*EM:ĕIG W{x$  G+K"-_Ky+Eg#0 6{1Aa R5H+X"XBxuj-YfZ\& kjEnX*ʎQ;~1t8&-F/a%x(4l]2c*0}G<4[gf{L>pkǚ0Ku0b%9ܚwj_!f/D@PBSA|@暛kgcyZq?Zb~3 =},w0Z!2A{11+q ;dK/g @y5+u~7~5fה5<+VO-5U,#Q7&"y{=Mˁmv7 jI쿇S+&2]SX0655 Ep~ b AnƁM GhѮ-y'Ђd$wAl zT{RQ_>'wRy}Jv??J |fޒQ,(&:ٽJ{D!~Ӽl3#R=" Y=uILy XgV$[Iɘ6 , [ fgrZ4x:9\Il&-*X(+ ~>c67 zcv^')&q $o`{{4B7c6vl7Ԑ&́xkA{.YM7 ō8vId%_oӆ*մ_u{o-4AZUWbDV?%Pf۸+s6L(?/K6dNH8;aOf8/A6~?xGYVeyQ/bd;Kʘr+J55%i}Ee D1GAa@[ajbTv' ]EݥiuZN϶k`,=zC$U4S A.U.cqy20LZt\c>-&X{b8O IUbXR59 TΦ@0_ ɆMٳ=Gy=TϹUf\uaᚕqHjB4#@6 s;Sg( O ?3fMWwkї7O;su;8sn[ Ёe2C 6Zw܄.|_Qu>$MUՋ*@c+0ՏʥɖAc"ǚhan: YZ