sssd-ad-1.11.7-6.fc20$>4(ܪ`ZWC:><8?(d   4 ,@^dl     6Tp%H%%lpu(89 :2GtHIXY\]^8bdefltuvw|xy$Csssd-ad1.11.76.fc20The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.U;arm02-builder02.arm.fedoraproject.org|Fedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttp://fedorahosted.org/sssd/linuxarmv7hlK (%A큤UU8T1UUU24be6a7c0b8d40303782d225ce770ac00fe451194344cd0d150f219c204ea5b08ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903675fe8c51a7f715db5f6a6dd155af376c59af881dc8de3bb7d6677ed2e9a47ef77525728e1527ab6e3717e759f06a33b2ada20cb0286ced89e862da245d5247f4eaf92e316939215d49ce364cea6a75287ab70e890500fa137cc700f2bd4c215rootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.7-6.fc20.src.rpmlibsss_ad.sosssd-adsssd-ad(armv7hl-32)@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ bind-utilsld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libc.so.6libc.so.6(GLIBC_2.4)libcom_err.so.2libdhash.so.1libdl.so.2libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libk5crypto.so.3libkeyutils.so.1libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr.so.0libndr.so.0(NDR_0.0.1)libsamba-util.so.0libsasl2.so.3libsss_idmap.so.0libsss_krb5_common.solibsss_ldap_common.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtevent.so.0libtevent.so.0(TEVENT_0.9.9)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.7-6.fc201.11.7-6.fc201.11.7-6.fc205.2-1sssd1.10.0-8.beta24.11.3UT T@T$T$TwT Sh@Sh@SG@SCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.1-6Lukas Slebodnik - 1.11.1-5Jakub Hrozek - 1.11.7-4Jakub Hrozek - 1.11.7-3Jakub Hrozek - 1.11.7-2Jakub Hrozek - 1.11.7-1Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- backport fixes from upstream- sssd_be crashes in nested LDAP code in case of ldap error - Resolves: rhbz#1126557- Backport an upstream patch to ignore PAC verification failures- Fix a sysdb lookup error that resulted in IFP not returning subdomain users- update the libldb requirement to 1.1.17, which is required by Samba- New upstream release 1.11.7 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.7- Start before systemd-user-sessions.service and nss-user-lookup.target- Do not crash on resolving group SIDs in IPA server mode- New upstream release 1.11.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.6- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)fruk1.11.7-6.fc201.11.7-6.fc20libsss_ad.sosssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib/sssd//usr/share/doc//usr/share/doc/sssd-ad//usr/share/man/fr/man5//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabiELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, BuildID[sha1]=d627a2518ddf985c5a7005a95ee16a58ff11b8ad, strippeddirectoryASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)PRRRRRR RR RRRRR R RRRRRRRRR RRRRRR ?@7zXZ !PH6ᖭ]"k%bP}zK抯Ohܔ=iMkqErkb3NH|oN`;x Gyi q/\Q~@oؓO&lMwK@oR5Е6u`gA#q}I==gfeJ3CzucKd.ʠZANM^!$z=:HxAVu MrPl7z- 2AO4c1sM=Z280~a59))@/,/s)-j+8GM3M"+aM$y_@⯧[p{J1J.W\CRehMë:LEwBxџB.9Sz9Tsb78IAqA rm$!iʙ@oڻA$@b;a>NIDbM)DuΉۅc'Ʒa˰fC"qIdϾ8^[ӒLcFhv_2TDISv ) F18Qϧp,/Oв!aPtT]qn C3 m<[ePK951z"-^#ކ_;]L:RͳaѿId^x#|u"xm?[֧u gDM ip|*T1uu~ZGs͢,Q5=*anm,Ugi~x"O- k.c50svG+ Pƿ՟ ' A%$~RX~X)dϋmGr8_&w\Pc K.P$ -c iA ?_( ƪYkU۞@Io~!MUW 'K+>rs!FSӃ^VV+HAzR 5i D4=NU Π}t`SU%Rr_ԅ<8#,Z=L} qgYu+B|8m8iƮp&]n 2縡n4F~P vYZu\1ĀH !&\Uc|ǵvND.k[7W?+rplkN[! Ah#q؁wab>uT<s3]qXBv[=+ @|bݲ^@BjXWI+.B?͘8ӲAwvub@}n & ϚʹT/_I~"R+c)ʿ"B5τhO/ cOH)4'Z `RqGxojN`?x%jʳO}T:PeC]-T,N@K?Lԧ HtMi?,ܑqU=${n{6ikY~Ů mL1@hϻdKc"u`܈!FM[(/#cH{~yd_8ub$MC ;8}9E.'MH΍oU [QΕt#44.}37\dE(bf&X L1kl툃Mױ} $W_qϜ2T;3?4 ț&rÝEх@ndǽ<1Ych಻O9 y 'qJ6d!὞WH7hB:,m,n49 p{/K M^܍z:m2@Va^E("77 au%ED Ҽ@!l4&9B dAIXoHSYۘЪB,BxF9Ckq`? EiU!朆.`up%Q/u%Gx.vpZ(4z 5u C{hճ56Y3dP0EX:UFy&@^﴿mH`3A<,17]!0QP(Fyzs3a̍4 öБӟtdYĤԤ3IBCPӆ3rnT e 9aڕ3SSѱ 6mx ј:fFm̤+-LE}aK_il;u |[{=p'ȀY+msg3]ՎcW7Ӷv|fO0C|K."urbF[] E*\Sp4ǭ'=B-)Nter,&?vW3˯J~jXn5RFV䜹+RG7(尙*ͬ$M7j 쌨R6oW}^MHfg.uG%iT`11-5F¡c4MIPAQ6!3Δnޥ]ҨZ54.t KjZ 8Bgؔ8~&% <\Пe;"9mf}&C-;o&k?0ɡ,x7׮м%Y(26i}ɾN?A!P<Zh}d`$9GKޮ ~Ь-;0̸hA%}I8?U-Ei4&uk^SJ⋋*,>WKYRss~qCb IA4 l%ߺlB?ޅd~dOc;k`E; |pbi1PQn]^=ث1AD06p<,7t,Q~(tebCfB>~}:Xr6 Sx9j2Dٞ{IJYۿwFU_ e}]/Qn蝺nXUNT ܁}gtɓW U̅=X m+!l/Fܿ{udjII !0}͜Pbw%$Z PK4z4p zA)IH _ޓTFO&4x>?i̱-%شn=9wA7kO Fӷ!w k+JsFxycgt~׈rޯbZtkڽܼ?M'Oѡ5A*[N51"^tp"jpa=^ufTxKg&{,N0cV8r1;=#asiܮgrUpwqvs76-F 6xJ?kXuaTSGu_.PkͲmh?G_dfr(jq>D-ho: إiFt);I+R•pfetr7@v _4y7Py mdc>臈<1ͺ_!y'|{Lt@L8f OaEYuwjþ ok7p18#_m~nQY/G_ ,M]D/=&.Kq%5 ÀaL7+ H.bq yQGҬi=^{4b>+:ᣰdXdm/bt9* yYu.i/RjXzgeNowHR*EL4 ,l.v}OLaqᅱ~+ Ї6қd9ř=,wFq;kZɧ+GB.7=H  x Q;PIsf?.VLq\D%&Ӱ5JL& 2b4e:j_S80=4!X)"]1SQ%I29-ȟOH x0t=?E֥h:#q(L+\ EBԻP28 gCVϳCyߌ/,t6!֗;*$a~uX+5+s( qY1VqY`5\Cv ,m 7KI6+gdA*Ki=CzpQ"5;b3?Vļw@Rn _QۻMm?;἖4:yFCyb{.ـb:ΉXa)ד7o:ug/D=B;R;4W`SU֔Q/ @N "0 (.F0JaEa1䬃EW&pzrh7AVn{W6%G5|I/E.4F #k=p_O= tPGqZ7v#G)esz^~M*Ÿ,"_-B)t%!d )ʤ_ ۦiOLhUKn ^vYK8Mg8RfbʄOnȢ,EH#-XIn>ȳlP[BEBȜZp)X#i??%L%9ia-fG8eႩ#7%v7cD_ّڕ4o.#ؿV`+ 0 7Oss4J ([e Ov"%ptB 9syzA=9WA-bK5%g|}<}/:#puD"k"X6e|bToHL./%wYȕPNipJ=zcc 8ӋD,Τ5+r2F0F#?u9$a6G@zн{j)mDR8q,UkO˭FҒ}ҔRCͲv[,jbFR}^Dj!ZޟUwLV:nVݥ))F[ h:U*@ؑD|IT+1p3C]I'WcH 3P?IY5v1"Fi}gdSͤQ(<׫#wuqx45sӈzkR<V[T{7HaW0# `Ġ!m^"yӽI* O಄ΨL^1' &@F??ǫC (k.PFW@, 7a7ԓ/4A譹4qŒ֛EnRv1{jKՎ.ÁG:bKV!Z֬v ;A # (mHq˻H:4++P+ILDOfwUh ހJH. VQ啺@"!EuwnlT'֒JБ ?;^(3$HRy{wl wLJPdz3^ZQC[D@WKh #^@MU prr] ,"Ij9?KSUU$`rRYagT8t30<*D*3ה] N{Uzכ,lIEVPnŒyJ]3٦(Ej}γuʤkvĆTRBqlA~>*ݼ%V13)O 1QFL8RT/?er'rOI"Mʇ҂檺k0.` }[GH҅׃KR"^rV0 (@. >:rrͲ!7$2S0ϼTA=b?lTSPAӼA0^i9|&C~eXUE,y?c&U˼FHkfBī>wO~NeGD2-` %v(Y`;?y7ϚAԄIE]ܛ&Ds->MP~gA? P#{ |M$c#+r"ߧ8 4Hi&5(zyWecr{y+$rshߞy8jlLDu({8i.! Qòf[†\tQY8RxBP2:ܡlփI-zL'D5p% 5 ɼ?0*AƭCvIO*+yAzކi?Ɋ}Q6TvrRʤ2yIYO_z(gp&C<0{؝nR6F0۟CuR-BK O/ބh;e߁FmBKn>$?$O-Ï( ui>ՒtCዀ(X1 %to#&r`c.]?(k,rkܗz VsӸgUN$kγ@ wI'Ag%_9)5 uq?J`rM?x4E>%Ϥ 7Xih ==Pv:zK͐/obö:nP:XA_P ʼnې T0eqRF\6{4<]+)Edg`X԰+Kwt;l"yY&DR9'6n1y+睘HtBskC;Ir1S8]7Ed[jф  Q;-χ 2 M 1~~IAz#ץa"|N7AAO15Xm78׹1(Yy'A)pd$$Pœp{LO@m+4 8~bwg١eԕ"#%>cׂ+fVα6:'07= ׿uo VcmCtÄ0Hgc4"׷=&S1*\鴺u!v]`/Zc"!kj?s!ʯn ڴ@՟K rjLټ%#M[e4G4ʖTp ,DyYjj E SdgfB$^[) ske,R SxPFɶnt`.?^놗1&ۡ,b ,{cKl*I6ZQ=As$Za| 8ƫoZZ<_F@?{SP&pe~H!3џ r`> LAՒ}u,W ?tFRec>eOi+D[.,]TA" Xi+[粑'>.I5UD%MaK(⣽SO!?)yuƻ֣ ᝟+"IҞ2h;c]²,\XmAW)AdPj֠!^釆\xk=P08,GT<]kfv6hL9.GsAjSWzܽ Ny.LКJ0gMb&E԰مV-h Zeܘ,ٜ<3Zv7q~I ێq!Z0OBKYl6C-s6֩^r%V}NG$umN-fVJB;=i CHhSmjEq UW6k6)ӨXi-4V⍥rWr^Ansƪ<6tR. Lu:`̓|y_;&3;Q\ۂ^ѸG~M~h^s͹o_ qw36Ŵ9 *_mե!ˍa'˩̇oRL78!Ħdv5]ߘzS wxEi=OyIn F.e4 Zkjv٨a}3>Y!Z,d `&s $l{rRhsb!Aao^Ua "9Q(qOOcHc2b\f)joRmF nQx:PL(_F*MjK(IdN~09eWBCb õ3J,!Bcۅ&VpLY C_z3'<  #x'Љs ԕO5`ucADdM `@ΙڈQ=93XмZ>ܴ:|*$MmSTduD >1#[x8+:S17u0$.إ~]vP>B\CPҥWN?9MCI\*3.~P  Yu8~ڰ]"S0_%ᲄث5Nk:ikn&;~z[agj iú=0LL53#f0lv4mi1r_y«j*7qd_w^;$ǫb~'h 0x J6zr. UZ8aj)pa iBcsRp[wʄ5}>p6-ONFSy6* :H^'D=!g(f{N[wvF=w &cJ>Xi5N~ww\wm)}?^(M;g-A7R0з-B|lV>ޗ*;UGtRE7$>ī'v9Ҩ} | ͙6BeAFH,˼LPZT+&s !5?"E]~0_Y U?8˒bN[ěa_*FAJv)9iMBѿ,J9S{h㋋hg' v3\E0 Ҟx:x~)}XULT|yYH֞_}nحO, *7WSe5]7: w6ȞoO+fmjYM{) /~\{%)(~2 >R`ɱN=gVҐa|Hjn*X N HjBn%DJLJs̐-~Tь+*gj5/[ѴGOn{ !xb'a6h)e.S ,/;f*}Wɗt-4"~*RO['ǹsH]&Յx 6BW,3 J܆տcbm<[+pEs.i;)ߔ2L  TO]o RHݤeMoNYUV=XQݱ%لgZ6rC[kT קP򺈱tO&:A^.ɸZbMp:3ꡲOŏrrrqGc|?&}`;!F>* }h 꼵=s=WIŪ섲y?ҶZ@ZSd}Lݮzs?JmKv"7)ߝ>1J~MLQYȳvnF|IvTZS,k\3S]K ן%Dt8M6kDiC^K{3'`=ǃ8.aN8:9<\i`LP?  s@4N3 ZsY[1[-$3 ffI wfAZuЮTɅ!CrsXVI(L= zVށsC%&1fh/(4E)4?Rz?|v6XFʅ7_w]-24{qm+yp烣\JB=B'(/UȳOhPS"SL7Rz_:g'@csh3{FwB]hwRq$G.U#0O8(E 1άsM[E\A!Cv<ӷb"ٳFZq7Iqj ch+I߀Y:!9/k f̜vW[ M 3Z(~#"*GqK[,rvE>9z3Wu:A+KVq +?@yi;L|5 ĴU\QA>59.Kf/M:MnK⹅'Z`|sBA<>*Yr8"c ܜʦɃyKLnޫF@ɝTդf/CM|9x|ϖ.c$+;]oqsz&29N\o|~H=ci /u8mϯfwQ4N4z E|;Cn2!&+Ԯ#( Њd&Qz#/ƭfdΩ.C P^jgz%,}ŘRGS~AJ|XZޞFGmsK_(3sl(R7VwO#p&aόsԦɽvIdu5'nZFFC)1| S~Vkft~IG^=i}S/Zr+}B!Y/ `~4H7 *oY>[%Q+%L {qaI:৯ٞbgUfqYSFfVJ3vjB¿ҏ;Wf:Sby;/2&Vء3u?T.ϏmXoV Yaͭ0%S6Nڭt4AcҞ@۠!RjTShkZ]ab Y_C ]1;:3Ǔ莠@p<ZIpqD"S/yu"+E (a=kz-r;# }TFʏ}tw}@yAF3o7u O# ,//BNUC1Iys'F2P6byޥƞieT, !.JhP T# 2 Г~ KʼxR?QR~]T8\RT)n' 5!* RN41I TŽ$=9f/a,+lq䛮eӣ ½2U=i*n,:Dd[LTC=1 W7'biAfG{DgOdc*\岩8֎hHnX`ȇ"5|δF!H[o)J_ .)vI2_P"F<>ժ@"% > Fzf ni Iu/3CFgW 7Ra=+o:_4z_'[zb۾i Sˁ-C;˒Y+߶/[Vm͐j> ۧqԸZ%]Ab;2eno?E,Jr(kTOok۳+Ǐ9ra9N $.Q&+QO9}-ӿS~cT %J]97Gn*!!颻>zȦI[##5ش[Bs(/-胍rl_Mx(\]O$jP:1%p+6  J沨gv>ᙻM MQN]zᇦZj#k*8*ZRi(5m3#RX0A5h:3F$Rq [MheR4+7aĀWԣJģzQygWwlGBZ4s=TJi8ٸ ϒE! }\6XotSRD0 π2pEL0V#i2ozh]-x*f9&SSHsvfzdЅ ɧAm4ap,U&V4ݦ~WJ|ݭJB 6Oow K~7(3BLT3:9py޴vZ^GwШHr&f51:hVd_@ۍOYjoYh,;|b8HBv3-j7Hv0F):K n#1.ڙ,4؞xZүt5tߎ ͞{@dj8½,t7 jx} ) Zϊ#o05L?@r&G7lFBdyvhOS5TM%r71_uIdbљ/;,z`,5@\~zd >88K7 0Kl匚SeGlb5ܑ7@ u[~n/LcL- 5G7Kwy1TWPР?/[QS˅bY+h[|PJ<&7L 4^ywr('VOR:_eN"I0O5ʑ  K Cf)t_N;OzY'cs5УAz꘵%c̖3>#> 1L =##Ũ!un$/Q!,T Йn* <uH6NiVVtX1DYB@Ȋ uZkKXrCgȵg,3""KO0`Wϒ]@U#CVE:<Ի`drzk``s/DPk#7P[Z%>5赀/ȘR͠ !/ty_dCpjTz/xh1H J!+}FhAo;"16 f,}8򣦛cy~/UZy?yx.h15ŒʐN 2Ϗۤ_<.&/Xg0Ro֍2Ыڸrq+VQԽ $0Iqx[f oXg>Pa0>I[&l~NB\tm+m'JBxr[~$C̣A.U( =Jso<1Bh\Z؊^lEaY^C#4tIS˔O/Q+?OgH)sCZ(P8yH_mYVh(6>?.?Nc S0@p1r"Gh: o#B 2}+%K;l P3|Г,ybU$kQ22\PkTLA_H m5OڪX|o`/.ߧ ^&YX;U* g''fe=32ʅ|l5:gyB=s[}vf>ah4JBw)z*9Vօ5c$yTMU'\`pO9qx\M.`Xsb>ΐk=Ӯς~kFmg1>eOl(]~O1Honj?xP|[Ԣ@dJj@˼\sM-IGk]M{y%yGPbf ,`{h '>/VAy22P s%f3BD72, Ȱ lXp5Z:L2/B`Pv-$ؘ7msiD͖$`i$"/[)6YyY MX4IGe&#sbGU@wgePi\Kf:Hv]5FPſ䪖!|.|vdݐ'ZixQܡ n<%]C4N3|5*Ղ#%>Kʟvv_~/7ֻ$u.McH1/E`傯t¢+!Vb=*ė5v 6N '/8_qn.ؖ#Sh *Ld,^POydS|?K_!owxy,jlJ4Rdx9n(%s*H9)Ba@&|_Ppp6km<}9B.,i:s^D|;xo}6R> ~Tbӽ. @.F 0UF\R4/t$ً̮tZbx 6q hxʹ҇'nonf)vv]xOkB}OsQ9e!4\*ӼL}MJIJ)0(soG9oI.xϭuH邏d ̭8wo >8.srscO{(H.ڻ$#7zLtc)5!Ҭ6fDuq!=}66[ɹMgq2O! * 3eo{Us)|CQKBcX@M?cs[aYj0k)}hS=iVcQ?X[>Սg#B!jx\q/rFOWx֦k 3p**od^#!rnʐ7J]$=|Ƃ9RִeP]Lpɱ &P+ӛUۺX)Sa ŦGno:c'-؛9O&Wv>ҀqmR4 cLtc H*[8{sռu[*+UPXrj]Wde3]ۂ趄}qߑθbǠ/Oc0H$sr5Giʬ<pJ۬82c|JC3oLKMFS?7-`= }0 vBk-#"XHEP͊6Sfb[Ī QQZ]bhXhSO49l?U{+E^1KysfIBI"+ڻBiėWc`R%lȦ/qs-T#I?ٍH.o)_܁ۧ/l#Mb1=U9>(\2rYKO:3d}Md\ f%9֔H`*H#5Wɔ[Y@1KVӰ_ۚFԘy!1c(}l|Έ`>c=r2R5j%b;Mȇň.dDS6؎Idxtg#V5Ι*m|p` j 9qqqz:(WcC]HǯBjp y:ҧHȜ?JYǭ.j1 54im<Cni-F=Y/k  <[IRoEIIgޖ!^9K(/a3BAtAl4"#i7z-9{ !T$hjEI|x=fK ї"/$4 T$O̲XAQm -o;gqQC%bJ!vbe}>|F=lh fE,̳棭T^qq4L#8Q1 A# W iul')L$>2j4[츦_tj`{V|C(TA’\'myxT\0\f~=T3DX_%>hPAvB Nn#mNbIOf*QX2SCeRXPHK\4_b81h1"wmRQÄtT||8X8X,FXXv.^U'7XN;y%aT׹OFIN1rGB< `>s, $ xYC[lYnE%j277 ڑa`k׃OlYwUyT)(΃?4A{g<T ̐{_W3Ry1.mڐaZoβ-/i/qb՘0ϲ#_K#LHB-`y6԰<Rki/ b]Vm"҅#B7XDPGbnM`{\HC*ma3xlgU~ia*i~Oz5!~Չ(vf$͆_SXP|( ]4\ }b|H4H;R$ך]L~V2fJ8\'ǕY{TגzgTKR%c0AՠOQ`bcx>7@n[00ZM_26W{ɵt|:X)i_<n9-.Frh.2_,98Ya7+}/Lo+w]ͭQJ'lT<[n%.C([>\4_=/kt iL?ӈB*9#)-^7<WCsYjh|];ܷ%e ie!nڢdMXBNȱ k >B!)e.0 Q80PzީG@,ezN7K¥g -oceӢwՎ#:jqbvc+0fbt }9>,YWgp̫QڱE\B)[ y|+2>`]:旪QrL[ u>-e4,XǶs?S=q8' ~9d2[L ~'~t¿>MY՝ݹx4+D4,\(ԐPu6^svoooAY)bZL6G0Wr!ERֻ> >K悾R3eytk'mT+`ɷ_^Wg5$29TG2H1!Iؑ^_f>{D,5a.f(Ml:unZ[$yɾ STDDvmO9Jwk_(=9D_Z+~?x1?_ F"4]I O#~;MGS-<0#.hW25sN 'a\TVBڎTp[ToDO~04Amq@)NJ_Ӡ`F/ًMo-իCE8y-s͟TXɓ* ZkCB [Y~&JQǐ(i m|%>˙]0u캪.ۏSu Kt.L*J">!ur8Jeנ0+&r#1\n!BT0n`Ip։Wncrs-w ײ>SH@:0m vݣ ٵn2I=5Uk3#Ykk]_7}GU,c wq+nY.S3|Gv!tHPJduXEfY)g*Amq298g(8V6$"y5#A2 Wq.OP\{ߏ Ԩ[N_U:Jb3b_WX-7j̳đ%š(%"=&BC;^y!)aͭCf.F8 c:ոGoM㯦J$O|fȚO# LӁr?TXjϯw6GFG 6$kæE|~ncбiK˸=:r@s/~Lr"|k?ۓ=rJ*5\RӬH䜼$U+")vҹ--;\}I4C1sL\ [ =v4|2sOAFQ˸tVqDIgK@Lr\ U&?Ҩa2I 7{NPF%?b\ƞJҤTn:*VgVc\'ĕ KEfks㧁}ZZ~,xYOpG@i3czec(:LM;gl=VTяN81Dc.oO& F"ڟ_'lU2H<u Khi;ˢa0C=pt&Fԑ{~@ѮPЦ`t6OibGuuǕ Bc$J -S?R 3!wPaצּ-[vB$(+^f .Y[dˆngP3T4N x-#N7>+942MD>[Z_AعF%'9^O@..C0˨&-.V"qZ[R7>S7 U.hv|4|sH>ŽR,Y=YGۮC4?ʯE: oݟVp4SY]U=2O[]S)lS\5hOvadaѡ佃 Qn#B%UM|K 㸗4sݥpaCY  U(zmHC{p;`aUQӐ] V|rAgKZdؠH_q!K`;Umn!f,t@:Ց0x2_q'̷@1ޛx%jO cM3tG:NlOk/jʓvj1iIȍNM׆bVĎl4fe\͠CZ6nޣoVE6p.ב0kS=45@#Z YYͼs^o{E) )н^Hme\zvR,or)e<z}0HF1 ȴ Pp%.{*SwZBŽDDm5Vcog\TTֹ f/2Ϙeb"o5Q 4o7l[V]Yq*.M8t4 0&׏;LKѥ/roWsS!֋k>}2%?f@?Gw^mRqhOaFJ&A.r;WV.pc?xF-K~?/vÒƒaG݁A48E'vX[~H!fcE:*#=qY^QTiwL#H`WD] dDP؋iEôr>5 J Eީ;,M6EDε Σ6tʂ))Ga6Ho$s*7hՆ+~&Cc=kHK_SIˑ͚) i{J0'C&=\lE+ӀNs#׾8S^9u&fcx.;/g#@oT:_j,KPɲ߇*!CYf18ojt~ ŘT*2AJ')u H,ow0IS +]JndIa@N:35m*q1OuҨgkN1 fR}S-w kEu aqj|3/YݠӬwQ2i?}XWuw'ˡFX!x#eŽcv(> E8/So6a R43 D~ {cXȵw_~3 D Ə維b7qS%,QH.eFc-< E8ߏ=E&e\0Gu@5yK1!k|Wj1|y3w:\\f)W>Vu آ!~]_3 bɲ;byO}f*Al-dnc̻-,vz +jo9s](|;z!pĵ5v|Hg렇<_C )Lhek`RH}(:ZRy~R biCb>,zgl7dh2O8׹9^ɐLGFEOO*>X|RJ us^翈δ1T+g([ѨjtldG腦rK8?k! Xڎ!bwATB/h&Gi+^28Muy$!Pj1NIegԸ #>5K?%D, z l$ ZY@6` Be? LҘoCY86:dlID$NB@gxnvGDkv6Fl*gcG_73537J৪ꃀȹdLSz(:Dk$9EBƂddlT,S~!|8*kev2>\$)&sm|$M`7a/PωOT<075Ew\-׈. Pz[7uXeXw$b$%+UGw\i[9paݹzK-^۝|y>T{T+èlRβ) *G`!c^۷{Qu:#b-ItBUIJɞ\6/}'@?U_ox~LB#BwQslU֑ 8._U4ګO"uK*7Vk<E0%n*ZV tC|st:;.N| :> 0ZMNX5r|DXs/j˯$9mhh[^֗eM~^Suɒf܋h[$]!;=Slz:VT6SP% 0le.*{6lo~iP'nT_uJ O{r[ ^础p+}%^] Er^c@ԩ5R"oS/a;4y3e3¢ SVw^u-[>E@5L46ӐqŜvd>G-AKfj 7đ#_I;8O^3x39x3k$'Ѩ.,v;u QC8%K+`Ǵꋍ};[E1ÑGNK,rqchuyc(=`h}@ 3p7UbO?c tF$5&4EӼ: ΁ow2 iⷡ])S)@^ ZׂP5jd`7إoH ';10p6;UrtIO͖2az(IK#'L؜[8K[cv FpGפASO) a$$ 2gn C^j> /|8Wn'ŴV#(-32YZx=i]4/(g|HiDdDk%N_zm/D=zF GqvךD5 uvQ*kruZڌXAM¢e.𴙊JH;7=r <\}a؜׷dbB/z"Q_lWvR|~Kr}~Ƅ?@3 h;8*ɽqoe۾: 9uI,Tqs:_JvKM%&e O\Jr1UFͪ+xKOHu(Ix! 2&o1fN} caE,*+gk,TeDNv*lK{L/}r-O|ﶘ 8APֳ4tR7IޤJ8rp@pLS'ǠX@աP 8]{0倵e4L6톫 }]7TWƎdkVb(†(嫷#⻁}i )57R2.v3-^t+5Z|@-%Td(\0˸hߖhuwggòREK $g7@~ 32DL4di-oMR;Xл˰ZS8f^E_V~,P'-%O;efj¿ '8ErE DR&8*2`vu!r {J ̺B*(=r`qTu!6F;4 wlCy<5Q*rnVF3)BVQ j%9^|Ap1#_DĵjTCB'/Y(~då=$"cf6a0a%'~ҡʽ\SɦCч)k+;%xr2o*kDC{coK BʮY!`żʬt㎛+T7n'XAz^gQƛB/p_;=G lh93,{TY:zvTESz T ~_|ۿ! -f/G6#KH rWf Q[\TJ Y2C)ivʷTb?}s>Fk rJifF$8Ngr=:CN"^х\£/]-҅ pfuӛ#zբvAQޥՉ9Է,) C12B! :ifONW RF=%( Ğ{_so[t睅I8IijPgS=#li9Mm9ys)9(nwW`WS]*  1{hV|Eo~%Etя4^q6 @# aSkNKsdpx al.s.\wqpX\؛"(Z$DTr,Qz4+/ܘM-l|ߢEl(0Y&v z֭Br+8"KJ'sLk씗IZal_>% 3d vV}! y*(ҜIwjH@xiF<׉ /|L i芹qh@pXѸL=;Hhro_9e3,Bԫ:%UeY8:hp0;zކp c0xh6g${8#*N0s|/KRNyZrxCq>C$&{8]_}i-r%6(eB2OT8IhD)x͟zTL%wW"E3SPKDGz'麎>d!)2fM_Dq|Pabtv]H&_8wO ރ C*Y8Z!z\vQ*.Uk2j7Ye4@4EAAV5`X=i 6(2M_׻*`Qn7L;: 2}dT X*ZOWhOVjxf>z@9$q%hU MeCןmI B|ȨwjdxSjVTa2e7YN1mB,tV#t*ۇi7h{n͔1n.~a(Pl=!xZH3!H1pD=4,M-t8J\[*pRTJ=Ј LpVdFsN5 < lH G=|H'x}^PM t 5hxsYuBZAtO?߶K*XUCJT#!5EƐ/+l8Bi06ŻO'WKg=|5?vً2^vsz)i5CGb_&)%0щX\˸+(-Mr3.g.ZbV(=@4n5gY|QQmWFgv4O^=G* PEw%q%Njw Dhҕ23@K^X4L?YeܻS8r]Kqšޟ VR[aկ>M>w<.1-"kn{oZ`1$r6!);q9-tRl߻\0FZݜ+K׬Q..B4jx}q-K#wÀ6ôp-dI(@~fvQfy*H;eO"mՉ 2 wlxEhȿ It` #[8;M_]yFc2C!ΰİ/4?u_hӦ8P2@7FY 2CiD^ hf͋P{M8imkkd0NTu0\5'Ww 'JZWGgQ WiYz[C]MO;U B9(ɛO҄il2QܷݫUb:Z]"i`ppm#/xMƊl}Muq&Y=u9"c Ti^359o)ߘ<7ʏVp1t/rP6OI JwS~0\_,!v~{.ILa N~s.,XOT 9)&\"n?Vlb4[i~sbUJhƱ7}ch_1[X*1[`w-Za @b{op͔4ۃYi-p61i4iJo)]aF"i1vfX4GY#SQ^Gh-U翕AcZUE%gӊ=XpA0(XS0+){}.P.x-Di2P/0C4\jfݝ7,ӈӊ™$q L'_ey-i[t3ڟ 9B]x'x2r3o#ݛl5H:m$FD;7HGŶGΏjIbmՎטHp-Np]27>*?^_P i@+W=zՑra&r]*dQ0%:e}4>^狊$@bԮy=ǚ;782I8ɋ}N?*ߐNb,v䊮ȅlo$ {xf,EЏ-|؄\P@(+I IhોiMOj Hu+P;Ҙ`r;iܕ` nxTs^ "0=}J!&ԽA H. &k1Ddw0O(~?\$'xx2qq,Y0}) ԛk pM6C2bd r } P9RcܰtQtJud!i<,E\x83TRzݭŤVU a3~KXT ]lJ^V`L7f Hy|&^IF!K3&K)?<]_ yI]rc93k8֏zB&%6u+7pdH5)@C1O2A/>/%Z_ؿ @UMJRڦK1a@jw9\&ǂ*5g1Q<KH !}u0色?gli|i3*چ;?c S,;W3 ;j}@OՅr]߃Sv, qFWx9<' G>~SRnBhKP'HRO_7ܛN xۜa_J!S _ Щ{6oǚIЕglqt7X5fmaR% GjN4cͻtݸpj >8Ec"U^Šﴷ{ nn6Uo)_%c-vbX(D^|؍>oHoQq~IJ+5DI9 /In͍.6vӜhOm85: +Wmf>;:۾K`^|D5$-!Q7Wf me΢܁6KWrZGq HXXo?K#ڬηu_T~[ k|&zkF79bjFBo}W'U;Y&ɎȁF7cdwI386ˌ7>q Kfgmu̝.Q݆E&QT)`X6ó`husNL"|<ݯ|VaD7M%bOE u %6C4>K-}7 fyD,#6.ŞH6\\7";U F pk F*vNKәTV+5[*R)z<])&[e :nr>g9e9_v4 Pqdht 1x{yx3fo"o#14+Ά]qUӖgҫb=2vI{KE]`4u5Z(i/8zd@?` M ߃JMWhA3<~1F?/h+8GnڦJAk2Lצ*я|l2F>l2x8qFb^x;6/FjEɲ5 N#? FE f y,AK>o~awMOixӥSvlew6虭m9֎[SӸv/%SH|p@{  +y2fs5cO)g6"+e>MN@^"1I<,duXI&%+#vˠR ODSy m\43j3^of3&e-P |KC,$ 1ȝy+wpg nk0kU1%~â_ZqUEx˻bok45e"z@b$<7\ 捠w-ۧt s G VXx;!xzՙ-a`zHd- Ĵ,|g8] w&_˜N @( r#3aӯjcI]au*i l8rM)>&tB|t?#u< hnu/Pȵpvts9Ja*|iB FFjQ ܷ++zZ}E{肍0YN~YR##T+ Baۢbm]ݎK]NtF F:6>.7OnKH?\&$s1)XQ0:urA@sR z5^ N4K"{WO[սMޛ(`{ke*-n H%XV1x'jNT ntaw2Cȟ3o0'pAv-3eo6K€'XԮA}>#ǃ%B+r2jw큚[p.khsU8\nU>w ;~2g+QzBc";F b =K_1k&CΰyT,XV}ЃI kU(@}}Nߡa<:ɶQ}׼dJkgۊ(W/Do;d$NP]~? PA48xk[ cR\7~_WҐ\s\B _Hbr B@Mſ X@+iIcۥvblOr=#Cn+X6 ::OnXO4,y(%|Lҕڃ"*$cMjQje#}nb}WT*lTܧu,4 %iߣ K-Tt)MxEpNjk.,nj,D%eWSm;ʠ.m)R;5&={" FbU"1a3 ՋdRlfo+)rTηr4eiqL@⿹]G,|+E^AJ^cv &9ܡֳC#E+'xtkjaf4fvr#:;FIey4$+vG^Kdi:e~Ot:m(pZ%!$u"?CYᨢ/I`u08a2·X7(WhX0c l9#5F 90v3sȓ5UJ2oBc;YG&29{rik Bİdk,n}h usj$<\W!o׀y>gAkNӂ h/eX8YSf?\uB'T.܏+X+C YRIl}$(*E3 BʏN(v{_=Гa,?;zOeao1H4CckzE1pH3 yf$$/̨w"huR;MywJ%J'!2*5[Ҥq/fyBX\Z0z5j f0 ^Sժ`qksЎ 7vv'evfIET,BbO-J0?RYtDzN18f$t7˂,aj&wF{!:nI jZCDڸ7O7((P ٽd%f4 46^^J ;ҟج+<]l93QAފEs͎-8:NݑթOn)1ʌQ;?O5v-T*Ӥ##Ҥ"B ߌ)56GM'b,5 *,=$2c>-X/wڄt"doz{aP LBIv~e:A/Ns y]x纡r\)Ӟ=oX\/6]JDI {4_/`o|øD` ?vs> hb _UW6Dn$jOFԫ'!R\d؃>>MFT&-0MH^[Ew .sc%wjuiZ2\8g(@҂6YjO\RԲ=z"xp$|$4XSmx7_,֥̺ĈiqE{g_yF8ޑjq =E)ykUM-Ɖ+L0!x@4 )2gC +O Pb&ic5oPQ^ Ge?V%t緡p [:Oǘ}[[ s:{0Q>g?F*wb]JĶ-FJQ:i2ڧ >5c?y3 `$JWGR ̠ra;p>Dd`"toFܟm,zXu|=؟/uq*`-K6 /jN%%RFPI<1dƾbv93B3gR;ھ=^~r|R~ ZU^VKDcB߆jDžqjȕeߪ`+9I'-"#.!Ah :Vb 7Ёs3#4nloBuMF񚁝LA<=a@3ܹo1OaH` h\|BʥDL}ȪLF]rnY`|smBB6^ OǠϡ$~ dϛ@$KΚc?s[A|[C?ʌtv*r 3$v&pξ2i^VD'y ]{ $f\_qDw T7`ΏN3T>HF󻮗+oFpU"Ŧ€ի毿BaOХJ^L?q{-'ע)Fo \/Sһp|ؘ0`cWLf,\zmyn6 ze#LK1sC'[מC+h#Dd:*oy/J3v^>Ӑj'1:gC$dp׶!w&y۾t0G?6D_pYIX O?Թ)ܦs)NV bD 9P=MR󀴦%`u-%<_8ot.Y2$Lo &-, h:ܺJ)nw{ġ͠LKdq]}UJ=e0DR+\OEL9d;!g51?RVEQ|UɈ/٩:*FZ=Woߒ}a(M(]X+h,G]* }G\{O5PD\pZ6\"_}UWwy3?P%5CO:MhMD:_bxLkS0d+a +vǑ0Y8Y'J7봖tsr+V"58pp;.7@Ì;hvY,2W}C0΁ە|橠Fs:vǓ t é16s4u~<-uY{hi_f[@ћ x7it TA'9 )~z wCűܜ`$BҸf.nK2n_7g%OX{@6mstAFQidt8]gUnT[lQĀc\K>4uK)@>Rwxw3V eD] ?=7T-pibiG'?q iڄ]^neS& D)=?277B3熄ڀ;iEv4'rң%C 1Oj;2ku96`7a$bWcf1\XC?hɫkfjQc{\4+m6/<S+=thz|E ꗢ.~SHD҉kC\r@? )QTz42c$oi*fN KQdFwi<:#OAf5 vϳ.Vɦ^1:5MR⣨r7dv go|o/u~3+2ˆeX %Li vv/b\ws1^ōt Q&@R`JlַOX-dtqx={a]@LQ˻aCVQOf|%b>AQNV_>GJ6 eTu;WU(רՓ"_^hhޓ'o~[Ռ&cpCX=ㄠJPp>v CJvp9*==j<>ÔZdij{yc ؛ dzCecs0at04E/$Ũ=xvI/yV 6Q#sק~fʬb1ҩRfEl6֭tY56l=GE!j'AIؠrՖE6{B&$OBs BhA& :͒| SJusptO R>FB'˭ށYB?QvXDQ>=W?+!]4<U.B5a%h?OIzV7iIf+-F-3_a8Wyڔ8e9ugDn^\YLD*]HbI_ &`olҶ yN9%RY5v476F BduTOW}vW YE瞀ؚJ zgGݷDDRJ\D뤒ֿ2~  a`p&"Z4u'[đh oztyiwFIuo52"eC{1L(kͥ}(2@8XK^"qMyэ+; ҷGx_ǴswjF8YWͶ&LJP;}GeѤBpRٙReb,XwQzi? #b^ ټvdj$0Cޖ]/޾BJbuP݉C154ßϩ,cSl9c8AP.rퟭLliK*)'Ur TeDžoXTp 4kIP4z':ORf`0Vۗ#tP& bV7Ivr>2(gB Ž`%xiߓOP,bĄDEO6aiU B}]OōskNAt5[& W"uoקp٭ ʾ)e6#D}> Q+\]'s4ZܸQ.6;ңdY"3;MIHl[z''&Ǜt|Dϩ}&W|jgŝI$CG ʺЉy=?e)K<42U'4<׈&Qt G_q;ZX{2Zëtm(>]ouy0%i$l{j0Uct;xO=ƃWŽa뺇>pU΂N$sG82UޒdrY΀W-XoyM.4}ŗ]9Ν߄[Jƙh! {oYadFU3sj(ixќo5yd}՝w$ISo*AYf8_e_'lNR̈nhg Ϣ33g4<zBY 9R:#'*uđbD%}UmA!/*O={OCn>! rڳ8K(t_XJeqt6I8Q(Z@F<m!֣sGG+7TK9G,Q,&ڛ B}HĽ*֫Ro?~3nD-Qx $ t4ZL+xƹ?b=n? 񹷑W]'~'j鳌C1qBxA"i/Xmu#.p$+Q%*v% YC[L>V3%a28 !|U^eYɑ(yNDJ+߫p{Pzs^.x@U,|nс,*Xi9GJ[{E`if&5J-[U`d9H ܽ Df 3‡z] W4H8MY+t9Ŗ~nÇzL성^ )Mv[M1I-TxNiڲw}=fY*kif!KkBG]}\)+S߮rs:*TOn*? "GV@N{t]A ro07bu"6zHF1*i Lţ3:%*}tw&a9iBs8-L=~5DOé)ze|pW녦@[`NU񔑧Wdf}1OFCc~~I63F]hH;gKZ=VȰOhE#l8MZ"\q'DUIk^5&1Ks>Rcjd A2m=}3 ~w:W\u&:f1 [W~#mN$= WȑJ}+6\=8}#SY}ΤzKkzY:\'M.|E+(?k*kFĦ/Օ 7 ' l9&ƽglZ_mn~KN<(t5h @Yyn__EYI:*1HKQQ&](= zMsJ ӨBwR\ M!^rږ.P$&@ܼB!mTZ|m4\ 8N ^]ʟ {ϟN&^y8dk,BPAboI%7FUCS9IlfJ_BGtg-\NzR~өzi iTvsCS34(f!}aaǐ74$JV-]ꝝoLݢ|̤AB_}1{!@8-5|R4 tFÞoc@5iOx4#hie GDe6)O2(֋i&md1+r%zm6iHvUd}NFB 'IzD5Jcsت6&gDHsΪl2iN O#K"%bB^@;_xjR. 2xXSWn\aS>KQ ^p$IPaXcKp5#`BZwz5r3mrC`X/ 09ЂB]&S//mH&BaKY(swp֙,a[K3 ,qK A겥eZ랓ٹ2# /+C.r˗\Kuٝ}n#cuW, ؽpG JN R&JDF >mM>6"СJv9Gq~>qcHkL奃2_BhMAdCuҾvwe  2`_:,#wS4eoz,e^Ыڒ K'^YۛˣW~N0q \ ~K]cΫ y J4M~vw79+knNa q0)`G "HVTΩz- 2$m CڵNz6dy@/ݨ,aOrH `,2%s4"ă_.0y ® . =chnK =Mʏ>O==bҹq!C񫎝 9F~1dRm VJ*Zӻ=Bh=ۃyikCIJCv| q~Ԏ|0 d!i"R Y{'\r](O1E Lyv,,,g-IY C%"Q׷ÊMђ3ϮnS̮{{BSwq߂;]%1H]/dMauxILd8hND(Yq 4(=fI;tTFwpaz|"ۄc(<@Ҏ 5c;.PKhN*#:{{ 5=M\LG& :!9Q,ǡG4M*G%F[}@4_!.!1&lfӴ(9EZډ t>_S*@뾽 zG&Ɏv82[s, }a#_xK-B@<`QeWg0&3 Y_K1K$H˿K}`j6LZ}E-] rm2%8RE_ҭ M`Bz+ ?5\e[, u{r;9)WRI0I)e%P੝kV{(ZOg*2Ғ5 7_g`TSW_lu'C6"p:3B p C!K|%9U4!g-ٵjj HU9E8tv)kbtPV6QV !  $`.LAYnf6bj@61 }᷒,pNd#O93@ õ7dER MktG=}L!'"A|tx/ȇQ<* y]n!t줢c 34bL" ֬b?Fj t: 7#z~"$d6S|Ʉ?Oެ[>AC齹]3u#HNBsMF"p_Ֆu٪\!BT&Bz: OcIN:t)\%{loʏEO% kyVJX|:!F-ClN-IͫQN]/zGyy$uZ's"CLxxoLO{UR#5[MnJ8fdi'z7m0Tt\lN˒;vUbrxN0p3"9|m2lꬒ޽b:" -tg *3 45PG0`l;ۉF3U\?QP_OZ9l!SH'KAVar91 ;O5yy/<{!_Q#Er28-81]*Q%&UM8^fKYK+W/cd[tD =Z9|ov8F#wi[h-c>d&G3[H1NY Ww+xF3a6=M(_0ŁKIvÏ(GV wyCO&s.k..&֫pQA'VV:P}{ !hD:`t Z(e(,O@a<@e(zɉ=? Z2EL[zd wZycӃCaV;ueX\m r le oER]Q8.iЊ}$SE@<erBߋd+6xft:<6Q%~dܯzU oƝ[-oB/8 >}GPk kh &Mb~CF/rxp}Ve3~8-J+XTj$9~R!&,5T] B,ӈʜcW- Sĭ"gɍ(F[]5;?աաj̀ znDpwQ B%LX`/&h26&M2ehbAncQ[Ĝ#bIU3ii\(1}:xǭhvm+.HDpzy4j7#hCύFw ޲ Lg1Xzh~mR&s-pNKǃ/娅:D(>b]pJ+y1$YG7n=sagr){JE7:\5 Z2kSn9[Mvco,4L}iZea0,zX<&0yt PԼ77,cx`[JcZ,8Bb n ԻOPC}G#ĴR5RU1p,ڗ%#gRt^rJ&xؔQe_} #d}gA#0Z"bcTr[=Z.~sQ#'7u1mu\I~AemtPBW@8ǥC4rѪp&Z8fqU2lJ!3LUO=A,mCuې 0OҞo22cS~@3Y=}*]wߔ3\IM)Jڊ.;#Yo"6#*:P;쉏Pڦ u x~v" [N3h 1L:y }*s#2Gxwz}k;K7%ImYY9 -*y)Og1Oϛ<73\^ۡ(x @%sZ9:%t;_ɇ.R>R4d" SFq>f8ƺUB"Q'ЪZ>G\͈Y/J ȐmO-|f[Ss"S%PڿnrE  ͜Orhe|Vhܿ_Mq AWQg@vLW CypM;k{s~T}ꖶ2I1feQu[AI(KJۈh|,?iФ%Өg4ké{4Rg=XӤGpiZ5V!y b"Gz4 CPL%=u*w}o;THy6 $"ˤey-0Jcl&x şwfZ:iR ϶*BɄAO}g` F{:S ﳵX#sO˘vZ姫| cMgP5G kw$C-2*G1/YfN uW畈uv mAY&烰.{FS 8^ x~7Jb -{`@kTU/MwR4Q!/ oQ;J?zއ19:`$lT$F$|(z$^+%ħTyC?p.o7Ɗ&{ߍ8=L9$ il'a{b -:Fͣ++꿦YۦprqWiuq4ӌm2+w5D#oO%b ]WQ㤝+]u)aמ%`_2)2g BU6 $i%}ãOpDnZGP/5^1#9%U14W,:qAEU?&{v͹.w~opO"wXE^};qn24`<7M.˂h ˄p\$eg ȹG*TJb9F?ԋ+PJ/\{5Hk;>ɈRF?) %&mm%;|:J+.."U;F~Vk!*˘./;f[TbwIpl6kcA7l^[s2]XdY`ʽ /y^,q9ld4f,d18*:P/ F HگlЄ]Bےu71SNmĞyG2 <҂ Gdn3w/]pF2 j}eJ/]eebH7tXfM' %A/*/uxf#Vxhݫ(bjX_v{)>Upc^ 3-jơ BX Ji)4$4$,j; Tk9:8%ÖhoF8TNy t4\Tά7lMVk4JYiv_͊+D* ٹԤ/oXbR~ÛlȝK9"-pHU6%1x0]'~+^xeszMhVPUb ĪʯxSK"L]7f\S'ovu Dej&ɶ3=etýc/cHN*ᑶ R#TXyq+c8wFQ,+scK'CV*ueɷĢc`qK^ܮ)گa@IZj&)7`KKZ]QT`lvP6ՃMݪ~w3KLM' w<-$r,nDvr( $/eد.C3J\>vxZ<q v/L2bo9EBZeu'0 R:4HiWiz~Q}m;/ mt<^iŒjǦN '@BLe:_sg{XHTXݡ$G\ (j2Kғ3oa/J+@̃8cYtP*|DSR( .I$ܿ9k7zx}Tjgh} +XFD IFuhqvkrLuUD-P\E|tWNJ|prQJBQ"]\?C#kl Vr~H{1#>۵3XS_p/͈S"!&O7${pj{Zyj*_[_OH]u^!ÝcR; b;u1Z;g͎!&-)~ه;y Ӑ=0 q)XM^ebUȂ:ۈMWk]cMZH6]&OxwZb_hC=p^ƚOï6"m?{׆ ^'muaBenU ĵ6WƛX PQIf4ql2o>)]t1+B" YL!OĄkІ0XE8Q5([>rnY8PqtFʇE)v"@l <;D^SzûH[wF\O~Q+rhzxF3RON,.ya`xJ7u)l<qԍN|OyxXĻyb[V>mea~5S  آl1X]zs;)G3n,8Ģx;6$\٤}"tǺ 9N:  0Α`=t,I:L0+rBE6RӦ]?T· T\Ci/L MイÌd~ׅһ'~GA٬ֹ)?ĊDdH.nD;DPQ0vT a9ޏ{ALu3B:@a\bӞ+m<&u^M~^I˟AB(>l!Tpc^?DE-f'Yʧ;iIX62bkaQ?\g;j9Api\-=j}]( |PR6h"5|7AZu\rxKn[IqmQs IlY Ѓ2%eE9f|̻厫AQxx23l룙!5.(^ 6mC?s-X)Wn!{ɣ]5;17ju D72v.WcM3*\ rXL?CzIT0tf՚ֺO(f&.v8 !=Cܕ#GPĂ eC[9K:FR ءq4[J7@x[t fCZUM%xiGל2iêINgɃ-xHBBw$_9Y9ʓ$oLFO`hҩ4G'H|^@ i 0uoIJB?rnxB)HVzDM ?>#`0nV@/MTRqJHotB:$?A1 CU<7:JZoe5 e *q?l_3& %јEoFCETOP3JV_`q08ڢ3҆6Eokb4 FsY< (4@E';\Msrz@ƽ!~, WW1i_r+)`rk4CAk3+ y biG3J%PQ>s?'YR.6ӗ"ܨSV:}sя*$<>nb7H]H?=ILTD;jM&~G޵ib*LzV=HI('4 ,l5RzE'WpzR&.tpQ.MA[ܔ6 kk4ɗF9z.Ba|QكR:\h'qR\}P*ū"{ZdG=se3xq!)+Zz盲_̨#:J[ӤfAM86 3=y\+`r๹)i8R)<{`Pчm8k5d!'Ep6ƪ7ۄ"ʂ4{}$A9i'EuEFoSiʓH~Efx( ]bD @' kin4 Ū@N2^x1^V}mt\ގuAJgZǙ7}fqxqRMs:Y|7:`ٻ13tg\B8;*bnz!QqD8Gv,Lq.bC`. ZI-HWf@?>ȫU6,7S| 19{1rVmy;u?<.j1):ݺ|,qS5UGC&SPP?U @|cpUѐ4is2NITsyU+n1vV;`X?L+@Y#ʹkVkb-ꔸ|6`5h\s/Nx<1.U# ̉# f ksDF*lbd4I$a%6vqV7(6,Ԝ8L&P%.FLpM@3|֗3Ԑ)q+SnYdBg5ޅ59*bE]Om: oOt 7RY4{)D<,xż? cj(zc.zED9߇j*[VazN%LPEm:AEFT3.D(6p#UzC! SV[AtD[yB ! sWU!|r&e5'mY)xhn\.㉽JQGvm2c"NOޛ/0X}خa?g&M7l#_9;kA5 U&XfQjCQNƌ[vÐkk+3M{ΨXW>ޡg{И(!QGﵼGw6a6j4;6%u,x_SyMxǿݴ0hsÇ Տ'H9~:6Zn%YKp{YSظM$jtiW1QU4L0t <[Ee|,V."*&xnk}3BQX7+ŜKP(I8;|d{A1~GSOt&!ms\pS%%2H‘\?3)Nfb3uuUe6ۥL%!H]a.`us!S +5 yںU3T*,o J|-C1~oвHK~rL֣1߉0_t3N,]z<~rƂc`>GLtjst s:/D U.Zׄ BR >!u7q9/-QO FnלÜT=5e{Ħ^YbTlÄTHUV\ ;&n>J]Ԓp4aԆG.-ېJ[Z>`M$!uEbh?A1s DtAZ! GR#vdv w@R33hjJK s283L w\ fy0=>;_9?`(khPn[p!F\mG+.rn]vR*^սL3#6H} P33ZG(V)%yҜ"u8I('Oo1'4IiA^sX>zKrGQA)WKaxt1 .9ETLMϻ0_H/2Ü 5$F:EIP9sB#{_ (cT6s9zj@NzшYI )q+8ŜQ{PPCwbglcC HV'kҭU"][\C S1"^-5Q"Wr7 qQQvI{_ڭ%bݤ>GR>m/pJIpD܅5}m_A޵ZλZ\્|E*4Uf>Yj,kI}ݵocW+SR.φjRQe~jI#`gǕ*JuqX.oV]vG*dn\mfM2'šZvU~W~n^ dk4 6넬Ybbd豕z}mvz+,&R]f ܃_FH N7O2hv\A>f YZ