sssd-krb5-common-1.11.7-6.fc20$> Z!ɻ(#><D?4d ! \% 4Hflt      4x!!!(89 (:1GHIXY\4]H^bdefltuvw(x<yP80Csssd-krb5-common1.11.76.fc20SSSD helpers needed for Kerberos and GSSAPI authenticationProvides helper processes that the LDAP and Kerberos back ends can use for Kerberos user or host authentication.U;arm02-builder02.arm.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttp://fedorahosted.org/sssd/linuxarmv7hlThKA큤UUUU7T1f6528a1c1f546482d1fdbcca19da06eb3fbd34f681fa7ca3260de5bdef20f738783b9e4522f46c8bb5588f5275b0af7339f555d1b96fe93398c208010667b2848690f9dee0b1680e0e5699fcb7fb1ad9788fc2e4a918e2369c8983c76de3abc08ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootsssd-1.11.7-6.fc20.src.rpmlibsss_krb5_common.sosssd-krb5-commonsssd-krb5-common(armv7hl-32)@@@@@@@@@@@@@@@@@@@@@@@@@@   @ cyrus-sasl-gssapi(armv7hl-32)ld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libc.so.6libc.so.6(GLIBC_2.4)libcom_err.so.2libdhash.so.1libdl.so.2libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libk5crypto.so.3libkeyutils.so.1libkeyutils.so.1(KEYUTILS_0.3)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.4)libsss_child.solibsss_debug.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtevent.so.0rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.7-6.fc205.2-1sssd1.10.0-8.beta24.11.3UT T@T$T$TwT Sh@Sh@SG@SCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.1-6Lukas Slebodnik - 1.11.1-5Jakub Hrozek - 1.11.7-4Jakub Hrozek - 1.11.7-3Jakub Hrozek - 1.11.7-2Jakub Hrozek - 1.11.7-1Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- backport fixes from upstream- sssd_be crashes in nested LDAP code in case of ldap error - Resolves: rhbz#1126557- Backport an upstream patch to ignore PAC verification failures- Fix a sysdb lookup error that resulted in IFP not returning subdomain users- update the libldb requirement to 1.1.17, which is required by Samba- New upstream release 1.11.7 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.7- Start before systemd-user-sessions.service and nss-user-lookup.target- Do not crash on resolving group SIDs in IPA server mode- New upstream release 1.11.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.6- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.11.7-6.fc201.11.7-6.fc20libsss_krb5_common.sokrb5_childldap_childsssd-krb5-commonCOPYING/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-krb5-common/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabiELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, BuildID[sha1]=fd06aff560440e76cf047aef18b83f1aa6d969ef, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=f070a95510c86b5c33803c3724a68f7a5331ae68, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d80e2401e7cd2baba35f277486a8f00e42764b6c, strippeddirectoryASCII text " PRR RR R RRRRRRRRR RRRRRRRRRRR R RRRRRRRRRRR RRRRRRRRRRR R RRRRRR?@7zXZ !PH6]"k%}}`ʛ`c䆨r.{k:Rl'8A&}!\Dˤ+'2b9/VM2l/Dh2{+Z|qқWdn,pвO G@]OSXjΆ WBZVLR:B?r[nR?g}5q Ruh?$_Q TfƄǠT-5L!RBxMDvt>Xgk+(snʳr>7Z1u;8=yxO^hڀƸTV%f3m!H I<=D(wA}gp6HzKNywFhf'\dƾgQeeZIܸܰZh>V*52ܟ> .Sj0JHUw2x2Su yWq6Dζh%4FRAUSF>r^K͉SHƂbDg &J{W8AN:[d4%N'$tk+b.v"ByF%I#In:QWF5B|aj %l8 ZN;pg!7{8uF 2SB't:Ls](dzO9Q\h$]W[$֏JGyeV?Qgb%G=B,Րb]blOt(HCR0Q<7U|" r4 r8cO0P@I俲zR@6h?бl?˕7 gBuS_R4vO2/<*~l;zGMխ5IviTr]C:(Ġ!u$">1]@GΛ^On)4ۢ9\Tpz OQ+F+}prU=>}У [D 0=ٶlmz[+'y]% A\fpLk_AFm'p W)lv,ēJU#~~6%8״WJxB;SES/zn,AF q%P/Dvm@y"F&qȲ85,3I'HͦWBW>l h#MFy~B68e o__ܑ䧐h3Nu EE뾚`&*:cFj/ֵQH%(<;jH/CA794OIX$&u?P  rØD3Jh8_ ba/rLVV= YI% J:c[gmS%y҅V&C7>SNȬ\Y /}*RJSsq%3h>UBN8~"4F$#9fs L=gI..q)SXk> Y-o{;}t;7E>π r2l(h_6sS}}2WI;;f탨IVV& Pѵᝉ{:#Ne 1(J&TtpiGy5Rn9X0OS k}NU)R۬ß-Q)c콧n܉Haĥ@%O$MkM7#mfR,7ѝ6bp<.{d HXutdr9V eHGOiR+poviBfin|djcW v%h1|SLxM@ ՇN,R_yO(YI/-)Oq CXr) 巠 2иS-0||$7 h itTsbjgP 9EEBv=3081"Vv5r **Z#Y;XA/ydI1y`/%a'pתL! $6D8C;GC{5E,Z&_ x(+8ah$J$@!(]:r b#+ 5pb[&Ć2ZzU\*'qbq- #'IQN PrTR}eLD(U)\k)s܀:Л[g2|8{Q1E=9OT&-0E-NlYƜ6)KւR/J} _$8{V@nLo/ʎ<'7YU (>;g_RyDn3&uT+Ɲ66i~dXNxLXׂr:PΪawZ8و7,S wؽf!bSomWJݦjOtǩ+fC0~R~sH{j`qbXZo\jԋKHhjQ˚;h^.Op_5V˘E\I>M3iayZ ٲٽNkط $h62dG\,8 [ MHC˨I]8c,>CoC[_5.^ ikK-X'Sה]+,ѕf꜇?xӸxīz")B ?fY.Lo;mLϨ*.p&%' A"cf|Z7oٛ8G 3-X38U,_ױg@T> ~j\8 -qyvy6?!2sϜ_.Azi@mqL aᴐf )`s+2xhz_GO~r6$>*ӯSvtB>ЯR uL|pdQGuT ù.ی230а/2;0W}WN2{8J@p͏,k/T64oO3yӐF3˩ߐ&*=(|mJum/vp^AYx1Y @#@ί]Yj)'c2A'h&.#b'm.dta(oȌAH0/z6 M_(,v x9Ud9(ͶN] /||xw%h7zy z {^vhQF[X•H!jVJ[9/T#"TJ"-?$!Ydql GvtfA/bϮ]XZPA /;1_J3 8G|P8, F~5MCWq$X(*"M^ u$dT q2C&JxV ܣUh;x6 5ҕgDcE ]눁.? rڗpfQ;KI ;6996|^nKg!<}fX)(S\A\=.jI_7E2Hj"(ׯI|À)cگtbxct{ٸ8[Ƙߴ+qӠv i+XpkV6}Tᙯo\bt+|hp"ƏX ?ؤ8>oZJ?Eiuz3dlS Htϓ mӨ@" =N*~՘qwCE ;rP{ɋVvplrZD5QRuyH),cs QCd5Rӟ+Lq`* ҔA7`A(d(M&|;!ɗ]VR(nrg4yJt`X|iUbr]_AdAiymNh<A=gg#Q{G?-Aq*IЇ.ĬHsŴv}C Pgr`8(ch=Z]?co.pODmOzHJGfa'oh6dYlc{L.މTWa>U2a1X6^m=됙pa۳܈Biy@۾;-IaRS~#iVJv{q"^g>_-JB;_:m)S1b8lZßNPO;&džvnhI~u G]EciµO0ٕu2OY^yV+](1#=uHYI.}ML@;U48U(`H=it0Y3geؒ֬s u${5 ̾6/075fZDOmR_ب4'^}>﹏ ׬Ns˴CSiۃZfjZPzӓG`(nBmka Ry΃.9*'>^~WEq LC9B}y5M)PGjH t6}ֵ=titOz}CU3W?>e'ʴ7|N"= lV]݇+9 g~#Ή0_5鬆M)95̚\"bB jL J9Oӡs ]%WKvRݽGDlEզ02t{O50Bu D4(ԎC4=2t,Lu(yCbG>Y~S:ԳS2 };tԹW~hZA-n4dӍ?4f&u`s {o}a<kɽ};#bUkZS{`L0G}z-\3NƽrD7 =/JQa e WgWZZm.ʞs4pd۟ Q(&=+ VITM`mmV@d0dc8zaR;s&3`+ɺR G3 VSh2?(䝔:&7E}p宦T^7VQww{HU*Y1#xY*|^X6>LK48 'jZ{n6HB:T8'7aͩKG)a;h;2?7DyCz4|V]}z˕ w'sg# usielZr\Tn9PkQ@Dב'4džZrр;#GH]|HɛY6Uˑc/mb-A9}֗Me pXuKtCp"(3) G+o^0o2Vi3%J[=PHr"࣮(p纠N_R`U7^b}g).e'eә*}U,~ ҳ3}48DpIPsxsD+4pScDm+M ΄4[ǧ@l6 j⏼67OZo:שYǶ8'b8Xu[L[ 6  EW.W#L't$dݗ +NV^ǚ| lPSrOO^yZ0JPի쓆<"}nYAO;Ҟz6 locؖߕ _/5!Y>e'&<`Ψr$eP zPBP Lm[\` $80"ޜc&OOZd t}pZ vYiOQJn}GE)<,.HRsŧ:ƛTG=߇#R(*!>:Q?b۱vRܚbwtTk#EKgs1`Â5Q8x_0L-ΰRL{hJ6.s?箑YtN1V^B;ۏ)\TCw?ͶDݴ).3n,%mvfbyԠ_bp>:{N 1? $J]9͇:֚#ߌtMWNbKafLvxw 3 2M? ⹉RH^r] \Eի_9i2 6OuF/&MV~ _VqǹFȫOv{1s {G(͉6M@o~E#ޝyI-AٝR왮ƈӻ3ib֞w%hn(խ'W)hs֤ \˷ gTێyWȇ;g&ܑ9 WպC$LW;zĺO c`Bpѹ}-q{YD# #j' (RH\}%s}gFJe}V=)Yu]x*0GrOo-[6QV([e}cURAŦ49 i*e>v kv*Vߚuݗ {ʿotj L!o'xg_I"Vas[ Kr Jxf*׿O3_!@6i4?>ܩ7ȄT?OӵӓuXJ4/ІC&IssF (A=l`*&9JԂ-&_-Mha \{ 3aͽl;*~`4?T`Oem N0z9u k 3{;ꩁ@M AvuP!sxV,IܚQ͛_puMǷ8rOItX2iNÉQī7il;"+Ɛ<[pJE_[*ib'ڠdFP-Z33VB(8SLSpXKTA*q/ֳSx@Ncڃ B3꫁ QewHNt|ek@!\enS/mzz7R6:1li̟Lѿ3 E֭Ws8=2Q`Ѐ7|Jah!U&#ѭtfc~SqJsJqAggӋE'N$MYnFFShcNc{IR/!62VƤ6zя=!P7dX聉.&m5NwAqXIu.^9Hמd<#}7o?q .haٖ{Bl")d&\~jLϖjcKm,)&dFݷ7bPlgbj 7Sq'1J4G0ؑɓNr 2͐͏[<]|weG, YMڬw!]cᱵ1BXݛuFx}~f)Jh=$9CIj_qy%mC; j%:Fbw"PU+&Lj{׎]'Yv-xzk+V滱K`D|( VܤvDq# IN Wr[Gu?d׈ Sx8Uů>Q/`ha:"0"0C7xd&_˗ٵe!!mW.eeuMĸ x$n}q&Oh /Dk 6񌎨 ŹGJ;izox"M ڴEPĜ'*ppc;c[2qp< Jª'!\푔 ( ~ k*Q4pu-$]*3yZH-  #UWD_gDxx}Ne޾qzgԨևzmKޞFkNڴ%CHq-Sq'xQwb"sB H@ZD= ˺fnB#WQѦ$r'?}J݁c8dHS3 b閍WN:#M ]TގƓϻ 7VY07U!SٽqqU!I ; "5Z/Nc\{y$KWKȊ &(k gO&|D9-b FZK^ ,+fp0x Ж8 j>` {rx Nw>BNiGs[mk[,e&jR׿j^-_e/fo;|rBV^ǩ_)5Z, R.MhT%<67C*tbr <'F3GVQlKlD_C|f! /.< \K%DP`,C>%>I5W%Mx+Grbvp.ݫԘM*N"L~mڱ\{)8+][Mu(gT3%o/㨱w|׌%Ii'[T-GI.x~+fiv!Z]pY(ef[I |#[CVinޜp\gF}JC`8А*fƿ9_8 8^!Rq䷧  *-j~*wMqڽ ӟR692s3ߠ 0EѻRt J6lvkK hc{(D3SLP2QkUy&̑`[jWuk'n!POPZoc;٬e&t٩g+ A@sl9HBQ|{A͟CvP90N9_cwB[ +؎3Y O]kNSR}5i+w3b.T(,mŐׇԾ]]mZaP?:u &@@z쿲i<2%@PHV'~렂TDיe*yqQɀ7`oQ56QO7ek+^OH#'D걣txnNDk|50^5P(v[KU7xgE0t=с hPK`yϰ &A3*%n!+?{ZofSzHr9o/#w{J‰&QyVGӉS]d;?A%M;5]W6!]|Ħw҅Fo&J0]]_s&, ,K`#nYo!S!W` `,0SvrwKZϸ_el[%%?;S4 &0E3xMSl'Z-[XC@J9e/D[$>xG*w4u ]]i!B4ẩ鏺Ψwq^f RavDY,?Lxx Va@ =hMe#Ĩ-5ݔWӈGUq勵5#,2`>D-z9~4q3vWn҉J/P? &܋@RD.G&w11Rg?yu$%Qr,ZǭK` >i gj4H45K[GLyh{)tQ3`Kj,+|+%&(,|tg4d-w6JJN^=.Dt75B1rHN:¿U-B,P0ԅP-ӴPPQ)dwx1tjٍ:tFP82ZHkwlN6 I_[pвY5Pwό; D}QU<-AoXcJ96TL%V)TO &5fT3^pvՒT6Dtpu.{"G.CLZi/MlFriqZS+{4ܝ%C}kh cnoʿd ۉ3QKPCFK[:t0Fd be:.?͛ gI|;[`#e c%4>:|_:ƞ _lB;擐?&_jf[ÒC2bx۪-[ka[޴@WFߊ &k B+>eڲdJ4F )t5'2ˤC׽0(r>]ta9TbfY[7@D-4D-LS[O_Wvj"*.O | 3K<M[%gRV`tsRe{08:P!(w`O*7^f E E!mJO;.sg5|IÎJ?GWĨ V@[Gi>⎬G& ۴V`% 8/냧EϳE׆9`m*p. ;*b3-`$<6Q ">M&V].CIŨ>݈/I>$3? ć|FPd28/p?-2',"yZR{w/.kn:-Zۿqz7$yfc(o2E]k7] >3^гοɳham=)@xvZI_[{`6$B0FF?*ZMBDNtZNU(L.Gݠ.&^#n gaǼ=-\:ƀ{c!@q8O&Y>O/G SU^(j{ ,& Djek4d}_wi5<~`Gy \mV/fVze劤%U[E#c)G ,5 [N\%޼cpмϑ':7A`eJOHN3@u`09PN0A|Ӽ\ZM%D꿛AFܛdFX9~.vXEXY .:{,jϭ#d}h е6c> A) qn_ 9v#2ii:s$VꝚU}ZP[f 9FaE9lVPu ;ի>onSv`o Mqv;**ڒ/?+^մT]\ r4?d|+ݷ*nkeح7P 0[Mu:jfc-wlXnv0]yݱ4p~,(rrOZ.|TJN{C6ĵNA)t&i$5$x7›C芊h}Gzrp^(1'i4g$9B[Rj)6_ݞY% -H“d"VK]g.h9r 7?!L+_ȢaM{1F,7hw#َ11;JP|m{S# 5VfN_5lycOJxE못El& y24|ƔS$``/#J߰$q=a5UVa zT׊, c>Ldi23WSp'\ 2bg|L$ ').;+6bjB sW;w;ᛋ'8BvADrSɜwW1Ε{Og^rRخ Uðc4f^Һr17oTj@cxG[ BȳBwQI G߹r zR(C qS{gEV("e兛z+u/盦 0ۅ&D¦^l"Et~@P.Xasʮ7Ƣ0 _Oķ:1Ōvgpw{[H2O gĮZ5DTTOBso#S֋}RY(})uJ,}uƱ>Qap;DyHn/sWF|NvGկ R ,;·FMG/@#v9~ŕOz1 {h )RI{o&c0@l!0J`z)5Ba`dHcv `Ty!QWbVe,a7XLAN;=$'!S[$x)`n.ׯOmn3lu}EoJݿxǝϖ?`㔲h Nu67OزOR4xH5NCY({%6y``^)^9ǟ[טB:r_$j}PiSU1"1YerF`)@=-쯜վɵ4ctdFx%m>J4O!ʰ+vSgYBXWs-B:~ k]pT RNF$2%¿r:rʛc?Q>bvȱ K^*ģ 94ٕҮwfa.y,_pqhtaEGC(޼D ǑњI چeU AZn?|=StV-eXoej02Q0?)6uLXx/3VI]K^@:^נ:A{˅jEim_Ѱ--iq4HiVC{'h i#7$oV3o@˒w$, )kE諕c?{v8^&"xA\̳H4K, 4gNr !iMgt\Zj~lvVG[g7q|#ڥ(Oχޙ7$fǷ羉-*XJK xoim!E;쑨bUr˘-l]'{2jKTာs7;cd/~䙾be"Px{_IuR׫{>7>k&?=Lfmο˭5>tP?)$+BX⻼85MG&H+gw+(FmGȗY<0nYll2D 4bX{~]UCltqOY|A0Po,e? qbOQ!O/$ZhVP4S?8WD j [lfgѼ#n!>yYj=J7$ͽc̎C&{S!neZ\qQ# 靸twgeh-%DC~<HMyYNe$z~]7MEN~ol%ZCTJٸQ:y7`|"9vVhM@۫R$LhGBLKu#6d]H!~I?{’ ]/LP6 ƑBk3vǾ_+D<nHӠ)Uӫ^awKfOVpŇeep}WvpD/rS1&?0!LʕBd0[K6{tPsi9Ke\2'Wf K. 3 CO,l If<€thz3'1'J`ac+c0.CTn>8eSNm1߳ /y,FȨP{3ۊ&6Ϣp%fCjWVM:4 |sCN*@*@+= M齻)A(uC'LąҶ쌜}S+jK>R⌲< l`3hڎ&}-6 |Ӷ()zzQys[рVmX1/X R7K 110A/].P31y4eM ٓTGvMқR5D_"Hv12]~4Wb!:$/NMLi޽>/5~ :Mu,ݙvM|Y7$ݨG+?}6OKJPMмK$Cc 9 >M-.B(!<J ?ueZ@vV82bHu]] NI0L(V(&~%WPq"  kQ.i[W G;'5^Y˝B|Fѭ(grqf F 7u*"dЖ"d77POkHWEfr/myEo)G1>?\gS:ú< XOTj!<O+>M5M2?ZiJ& Y,Z@y6fqY! uW8<̶ J~qP$IfsrY[+PVy7vF\ !,FH/l;+sU$/XVc+1Q .?eڇ@x{Pk^-"k~K舘¶NFuMe"p~DWUBVH],Bri_߫Cp(2oi&HwP}wk؉+F? HDƒW4]jbwh`Iܴ8Nv`m٥9`0UN_z i#AtjVޝe6 $(Ɗ3DN=.7Rr`Q=m!{dA8!%5O/iX D-)p#{k@rQ&ڎIPn+ESo]mT_0o#^sf 4S;CeqZ`W-jiEЇzbR *K&:(2"CCf+9(c59a6a@7ϕ(!96Z3#)쐮ŪL,pkGK4cK+"&6craX>PgbZEG_[.яg+Ss52=l@;' unje7,ǡWȃTpҙ (@vɄi+* cB*cg n֔W%lԎN}:PX Pu?!vW'41n6 _V[t9F:HA<Vsd&7`jr>9`o5 ^۫"_ Ψ_¶"ȔN!6 S=n J-](jf@n  :U@f./B7ÁeZ \l^?k)$=t.3Ţ%}B"mMO/}-@18΋wvWae_m} \*W[$ 7WpѳyUQfylWʲqo6Ŧ1B8'Kd _6yGPOtSI+wpėE/ҤDc_EՑQJD&W@&ϙr _?o6۔-&^Va3 pM IS"Z<3ǝ)!P>CG.m6-nHzaU,W^p?p/#lf2."m٭-Dcj7*vSR\!+[W+Ƴl9YQsBg9DI3ȥI8tNQ& |^VaVp<{SoSy|=ks蟘Q7Ԃd!>[Zu:NNw7"ᱸOt'YMҍ;6涹ǭL.!F> EJq4b]#5،$5;ʎ!"CDB.jIȲUf L5a=&C 2`̇&)H)|Z\4F}5i3kӽ1wKyg/7 0cyBIa8-RMo^)ZcUi]WRq\nTת<0-1| EYϓv:fR! IE6!` w3KRGa\Z61:ia -(8!E'Ů9S*ϮQk.zʲG /+ЍցZ0 $lR PUUA%GB-\ILmō?[>^F6Dr̲ݻhXǸVS0Ȱci:qefI;[W1 N?q^)䜦0 8 gwXoB5T 5iNw̜0]5 hմ75{PB*>֪jZ 1+\mvGXZ'N +jX P֓I5{l~zDa0Ւٹ2?ԩ4zk _2J /(:V|G(Hs\i\D*7FwH|8=iA# ah%a|2ؑt#D=h ]<; T lϮ+}㞜wl1Qh`Mف\zwA,t9iy!9kQP"7D!+ٲd4)ANdb8D:QzϞJҌfi={`y[wJ{Cpq4zczJ np6 {eg^gg(V =ch>c)Wl>['t#(mׯ6#"5q]}JC~`p2 |0ڞ9[J/LCkGtD R$3ƔDsSճF?MEEUJtgmJ}롾6a詉k҂3ӿډYG\4l͋0SYu# ?j  s>fZ&V (˱t19c>tUMT vA 2ʠ%!M0t(seߦo&Wl?k&<$yJ<,(&ZL\zI`젊[zfVC@#mzl/j7_ХtJ%sZhųt5cBqa'wӒi6Kjk=r 0mάݮV{UH훢C2m%?|jno;4;vVyîK!7W\ʢ'ث,ܺpyպkT=߆㗏 0[ݔ [||WFSx9 kTgѢouYȅ1;^Y6<:dIN*Ef7R8̓T!m՘ 5 YzQȸAJW4*5H0[ ,1"NaޓJ'*ǟ.OS= |D;^"9)ޮ9s>.x(UөHlJl ZtR@gC~1}[Q#+bntLax=C 1tGuW^'&iOy_h~ f1H Q-֪1g6 FzjPv^b XcL>,-@Uh`evK=$:4V۔)Ԝ[EPg;(vNn5Rl8{nݭu6){}TpqZ;~a.Ź7Ib{<R+dozq6p =RER`3(kKyۯ*_^Gg_R~сNny`=J78ָx;9v^ ;-h5cm5583KI韓e!/(=W±ll?q ՀpUTz<"Pi1Ơɜ;BBp äp~Zd>bב"vaJy_8S?9f̽6@Qݎ^L5?ivtPrv#':~dp#OYFͺ!-lDPW캷QQ˗5&ӍԑycUBu[۶eH\rۈAf]8rrX}+Ҩ8yaTm$L9;^G+Xx76ŮI\?j$ kŶ A 90\kX~z ASMWӶ"iI^;QGR8m;LtnzeFVq=avM;V6_z7g0tqMf/4bLh b4c,mPYg6q6XiDY^:-!ի'_zjyۍCZcſ+YmWb67~6)ϚB~Cl@|_ N [ތ-Tq4jA! U![!nAEΖLF}& QhLILH0!˖hSY=K:SvIBEYN(;d?;#Nm 82r(w yZ CFĻ>ܲ4JPSAw6N?to"DBH#>)w#o -o+8Pu F*Ђ2h TL9Rs7TJ;mQ+uˈOKYaP- /WVj!uYE6a˰'ZC7kJ7VG 8*D7i(=1N!Aw ;`TPvm(d0ΝA6HN)%E2S7`ih8Ο"/2 26Km17NXf8UQ[57~9{w^Vf>tRȠjzo-F_gaLMK{Sp&JBS@gHWƲzgVHb> &mcFʗsxq|Xyp?L4zG69CB/fPx-?HV+<: ʃeLGY7 46Bs)|DoAu.tR3Zze-K8dt Q P՟_ɋ8vyTlDNA$վPo@=ǒ޻[܈Weg5 F:2<(~MGenaCL5%}ڪ[ܦ2p H㇎B &s$({+NG4YJklsjƍ2f TB[2DH.ikۨRN AƣNe HYiA[}fJ'Sc%ڋǵGBbghh_.E{-=Mٷb)ߟ'wvqup]p@j95>?/㘆i〒㑽(4GMeEqxJbXc`5Ч4GZh4vYQnWZG8u3e.71[7E@Js܄G%H7>74ɞdKEGX1FƖr0m Vjs /kRkjFuMCHR|>"pNE"R5*fZ4E~F(R6ҴȬ ёu+NzGTCig6:"gEdi[Iuk6<68,|06hZ-{8f5oѨXyi7|s>`FaL!! ƨ_ULs}jh *o3U{;Ho̗#;1]DeJ_РM{Zcڞ!QcW;_eQJ`Khy4 vI[itk ZHQǶ[Pե 3 VaN(D>$wmF7훰I -eRI' ~U?!jD.*|5I j-¹+@qX yUhqI'2*6  K,ztJNGE|q9ż[ dQl@=?DhE@ѿD])C~yb 5a0BՆNOQ !'~4 :7+mTl&8R^r2ÁFSK3M#i?'G.9g~֌`ZҷlT$L Z5gZ~/{VQtgLhޙ'Ӗj?Ճ+5a8&"t,I,>w/#O< 5 AE驱rf5섀kG+#r~AòCg'c*M79|L?Gp12tmTY\~Rs(qf7oj}@~qD$Ry 2HۙVh[lp s2-L_8?K i% |"eGj_2ֶ>MR >5Bnp:љ<×iZQ/COis~bk p*1 \HqCY `EVEؼ w1 ?mv[+XS:r_?^D x  $iu?4 $BLwģRVxP 哚Pg߻jٞhbiE̮H=إ sUeK}ܒvâ]%rўs{Xi@s(wV qԠhD޻(BYC)uwHCQ@FBUtIěY¡{4+ ld>hX~5:P|?.Zԉff?hL"I ɆBAzI1\*G%“(@OnrϠ[:\u +S=Ki mWeէd(?GWtL[[J1wףH>Ѯ0%P ;oNF:vOL'j2tEpazf]0b ji [QZ&\?mX.*nrA&LQ+V=W Eƈ}36|t.Ҧ5mRLY=7 eJz)@!c~ѕWAdJ,P.cv(T߽89n9E\Qm=oni KS\؟V+Ӷh|Ҵ!*gWJr/hT67 Sm\gY˒_.+R1 EϹ0o` N-_E!rPiBLisf$؄h ~yȱ*iXdxuԀVqDvI Lu1tbN"X; pH\z--f tgjN7`|r.a-I.jV qYr?N%(~ϼdwv&{|WX5cS6bM1EfL@+kw2fC*ɄV#4j6~},{!Pz0iC?"/,4xj,j`)Al$ʖ@&`͇l->,c=5G^J-;` EHb^f PWwݲɟ KC\7308Jogb[V]VZ=owXG(47#i4pT-Z+_}0a wR!2VxxsRQ,lxM'AIl~3{d?gug72 튡·CF4RP&R8@ev}18bI j"7r"ݾ~ik!RJ j#k^Nem~y~JU%ϦԲHtcy,t8J[lڽOxV.5DhIIU(3 & bX}fIk7Џ7{7&!:$͒Z2{bWP*=9i.f4 L1849HqZKN1z:5ƢRhfxPJF-Hz5kƺ;r,ٽ to0,jia!c9v_ Y1PR EIG*cG46R`S.Mo`r焩ꮰ5A:&-;ٿ#l 55.g54^> D"f. kP]>  }$"Y`%.n@d13J̼N;W'r2Y櫽~SvZ^8gQS2eySN[ o7k ?CY%7`!CŌ[0&1unxQ9γ_;B/k(('쭭 zЃv_H0u- PY F,L ^ L/RzaxHNn[:gٿ/qܡQ6aytHuO{4'(!,v'i/Jw+PW4% NEN+W܎?^쐣 $驻;c(QǞ5`f/n T#fpgb>ȍ1Fʦ2ҏ2.~,܅XzWcڙpOy298A1izfqd88 Y\؍Oԛ܂֢)ӂSv4j~'nǂNi^?blAK3O).w9ҦvTƼ%ghclU tA^U'4+,g5Tne2 /R1$ E{Á0Xn:Tp&9X֋?/u0Fc~KEt*@P(te$?/Hh`ƾCƽ6MWA4כ @qO-dn$h,^7XfhC1PE/UQBP%lrGI˂z)jDBK]Zb}A*2eP݃X,L!F#`%Zx&C%W`joiEzJqIQ "ͨzh#JkUL"At2dzn)Z􂥞~ tqN!nh`|_0 V7J.^lߛ0I@WmjsOis.vȅ?ikJ~|2'GdW+!%L=խQ~H9TJɻ;˻Rw:mEɾ2JPZs pRy䌪q\\ Ɛ*)y|Sy%d[s ~y1D瑬KF2~tfÐwÌi՗F} cv -_wH!׊ӐQ׋sokWDI|YVPF.$`QajH30(svepFGU?p4p%CeM0?ۘ4rhqȝ ($bC( 2')5"Yc͘F̈́OJ?oW}ʒCi{W{a4̤' E*582X]o8- Z z[[je&#l+MunklٴOZ!("3AI2b7O7ljE%Wk'|#CXȀ.~!cԐ$嚪ys8s.C? T⒧ ?A>O"wYM)p{ "X ZJg4piq"8ļD L;3RnvY϶B.MRwY1Pl@Vg` yEߞP`AjvJِ+͆X\RQS1>S׌Hr\J$c-3CT)EEgE1i}#HCm As##:.3&8bግgc~F/;K)sU%S1f 5H"7Qt^ @q󨟉RG3CVE;L`]7뱹]{ӆi1c$55p(fyhvı 78l$Uaddf+E~oBOR=m5{V-#ȮF2Kix*m6B1 Mbe{Z|I?h+40 x\5ϰ`?Q$-JSYB =&~h'j|zKNØ6B:pq{HUԥ|ᓧH,.40ݾlk˥vN<{W@a$:rQupl1 m>3.4ᆴj<〲ODٜv%UѠ{mQڃd%ģa:h PS"+: &e2F*D,f}3 hlg |TS"Y{2D N{snr4c|2JH# |lAHP,rLĝN Tm85hD [P&@ Qj1ervIWf< a3>PnBޓs).#b`8qGюfc!h"2 ]Xۥ0 #CA AXנ\3Pj!XOG㭯J9DMHtGw}$5VNg'{&b@x̝=FXvbVuEw@'OM>]_*DèGvT9D5l1Pa5k 1I!fQ>l2MF7L2澿@(< esh/ K;5s+]4ȝ;b 4mHVfIFfD;Z$YYb[o$e ٸY)6[p>)؈ܐt ;% !-*00S] ߀}9͛S4슕&)M:)xVծu7HO\B m>+?ŭu„+#|&xeK;g~Ti[75ՐaI-Jk0Ys+Tw1A NS~> ܄9jC7%iD|,kbxxqڣS:& ~QZ.O1^-Du&ba\/rC KOpu,ᓵK U ˈȌ'51s `DbUEj@,b 0,2#x&?pJb 1&}zX@s+'nz\A(3hۜ]sY}acOg9sV-8W3C@ Fn߇ހ[Oճ@ q(5qD $0SAg?;%0ٰG U|:cL|9^PԊ ia[4de31*x2:wRz]w͍t[zY?rFGJ HkmFC犈Nz'ѽc=xYظGBb(FgANWM=RT+DnUqR|g1%"|C041L"# ;XPj879PR:^Q2UpsErN͖44zƄ Df|HpT}3!NB>]Xſ~%XRi2}BL}&Q&|6; '3`"7"z$|SkW;3|3Ʀ3kXJytN$3lf'y]Ù(§{חQ,?[  `mk-RM2%B^J\w`-riz^akt o~x5hTMS-$ߑ4ComͿJ[ܨ0,F2=&CW/giR' 5LU<+OQqseν-o=7_v.N'fŰR(2g!`PSH/Et %+iM(ৡbtJOjv2FwLݻKEum"ߖ{GijȜQ H'iݔΧ4Yas`Ԍ>s.1.Zl0i#˰nβ?18JURy@ y:hV sV sh=>4"˗üjK&8@t-f}d!BI!4ܶ'r>YbK M^65Nj kR `ۀ ZFL9T>vәKu3'3PZ=qD9 o"U/(:فfHT&C`Bي!j96T\&:5١^^9Kc(*Ūv_ q]6J܃SFԅT_#L5 9I 7ܾ4'B2'ʑztgBǒnD;4LWJS5j<</L!/{: Ӑ5z\_=Z j!VqH%nYDYkQ}Ds 'Uд4Eڬ)BGgRX=sI¢O/{Bڙ>#TQ nKMSc])A(^ x夌^2vg!P%֜%@OmuJi6\^u$5Va(Xj#ګ3=,ƱYfrCe>TW-'c?1jo4& dmH#2i ƊDt=yˢY\ J WnQ/)9TLM>jJ!5ދ04}O#;b^8%xDwF0qA*BTtp2΢rčQ6Pɣ*!A@oN6v }[4qJm#!6țE׉-? |#WZ!=FNۮ$q+G?-< nVټHghtKylI{.3&(tH![|{[,`8c oi=}}[ lX03"/zYqEփgu Oq(bekܿ$ȏ9hА8oO6\N9xQA7zl[ ` SHi ݢiR sVSœD?L\~XɳQh;5 "S X괿nbJ Ǣ5挾og{Jm͎@ĢTwxk딬iQN mWk9SFtb*y~TΩJvPunͽAU:k׸\(b4E>hk4sv0nz5s.!'9D;/PCcROc&Iv4 g`f:ž slK??*!_?ѽ$IKMk,KN )l頗hhS E"381#.?c5/rٔ]LG*3AoVA>H{S|`xȴ#X-4$AW c,5/gJGܕ'!:,en ؙV fjoi^#m.K`i}?[ X'o؅ ѫftc%B II7:ݔCYz3} ԣ% CxiO$ C8pVOy .Q+Cձ}7 v5V`ɳ%sqd{n&_)n|BsZ []S*$~LG3" [JЯAp3 hYvCBA_;S8 ii9d3`0@77^ˢm 6RnMmq@2⻡=?FfI,ސGRuB`y%H5%er>GMM˄Bjl>`##P+2LzpKvf ke@ep"T#وv,L~q)Sj30-jJp 肵B IGģ* @i}bIԋx 9*)fJ{dZnx2QP3cFē Չ* 5"ث1.9Yy :YA8-wAEK욡O:v=M' _Ftp:{v^xC纭5Qc3D6|S>qbRo'kK^Ώ=~LS[<0&M.4PȞG蹳P !_\Ȏ񼞒^M!pW}E6>ӧ(džSU8._q~?gmjkqcΥj漧9]x@.II%Tn-oW5_%孟~#Rp0fXzbԕש^Ig1bQPݲ!s=օFAHzٕ˪p&,W ԊVYoխW\2߼wׄ:\3VdWZC xp[_1%0)THgM 2жe9b BU+Ms`t0v}~~@08q CӫǸZ<ƹJZȃW=-^-d2GAY̗=h@tIqAgH^ЂPȒ. S DdFSzx) zBI0ZHRya߃EڄˏQ9ًvk}H%چKK{XsI^<#NW%j l(GX97TT@ɕxޅq U=ͯcD -%y=5ES4e^(0(dADȄX8ĴYrSv vG3VNl6^mc-7u1&,[+ϑT5D;pZOARr~k;: HWUjzfwAe17'O<}F"yC[8&DbDM3V'fyX VMIU0?,[0tFy'-L"Rò9fmy3~0҄ 6T-! 2ڿQUs$/~LNs̘a"K(ɤs4pbG&Hա. w"(R]۶.j;it3uҼhyBTu+E~vseŦY3nz(Ic 4/^v/C 0jN S:%jq 6V.UՁ62-6%Ё[x3Jr!sW/ђ3M\l],.q,+mZKP{} =SfUx*oG}ӽ|fu6Z\E|!qD jKY}21nA\GGMOlG?4{Ny+oQwu5Vf0vBR!\@ldY"m{2~Bz@tl(S#h1DfB~fL|]85.Xgb^[i=)0-$4 Tw0kW ¹qdcssށ˞}(~ȵF>:tY>' }ɿr۽o <=Hﱔö(}\RIGr?Ħ!,Ǔ3A&WO8R@-Tp9umث$7*<@n"#:^(^o2撣#\UL_F{H͓Oc T13Xq 9cdAsN)F澍jD)[,^t,PlHJgG*:6𐦩=ŞDMCj¨[_+i~M!Ǯst 2Wإ <eA)?}lP_ z&f-#z81 ̯*F-oŊTendv x. ^z'iG:ʵVmC0Br5(Q@{B26CQxj`#=>#U=6,!/)fcqzqX/zq15z{gdLB]R 9.+;Oh 3u ;4Yxu1.CpƓѳ1h&ѣ^fXU r-GԚ۰; OW N`]lH6Iv"sUg88& 83\A3CD?aѻ ۖdW"'F_}RWSx$ |-ڤgX^/IjK/cR{B"c-*-4fb[HZ {`Rscr8Xj -ܞ|O<"5$EBRr%Dê&5p$;IS@>3S#!h7 ڰZɯ^#msɦ;G `N3P d T/Qf^ZsWϨBrAIbh{bҁnj$zNU#Fp? ~U]e>~;ZF]˜|"jQ{%\X)LODl`* fr37X!K AQ>m7Z;V)4f:y-W^ Uj*B6zsosPRd4[ J냟'ePzID.Մk1A3RI6owwJk֟56MqlB'13l5Iջz{Fː$Ċ#=(q'X@$qq˯ϟ\2B;7o#Bb='_3{e+sUΣ;"S5<72㸶Qf>|j$T(ƱG+H4iGm,ބ#Yn 1dng?`2T ԝuי]`gb Km ɇHvvH{Rk ^W@{lU*A8LF89 c#P+?HI0Vi﹵U+"z++ȈKBYGrydNF+rH 9&ƭEU|\}$.ͽuC'OJ\MٛGp'=m[Rl;@;$c@~Z)eCjk!G&@ gEk\;(BiGx>d(D ;mf$;Pf~ r< d긘 `dîe1kADu{^IR=x8ϒ^xvw>ՍytƜHsu񉓍ʬ8Do hj$D\uIwgƒaKq9lyɥJ@!Igb8W 5$ӂJgN+&>"ٟ|ϲJ+]ßR'!^oN&%R!wg+AVSSƩE]AJӳkfAϧ xfOJ/)o'UC/ r1E>pv*Ĩ1CοTvO]#U|ƢH=ƋFW[xNH1&!=Wbe}LS3_1/.y 6Si7n݆Ra.#w{eTs.=IkVJ*vg*Nm3:'aq+Nj!|14nN_bG ѤR/cby +i ʏ΀ cn2XID9͉ Y2a¶H.I܎.a`"FmE˼0dV;˚VJ-;ֹ4D/@' j-2A9nr+eP%z]ltD:0iADb:1WAN'o o.ɏc_uc/Qw{m9؍[Y4a{ s{Vm,a`ЀbdbxWBYp\' ~dôubgi}֎7/c$ٝ$yc|ݤ8k',~44W紩Z ,#ѵKMt9n7mBDv*/^Vt _(!>@fY-:#ՒORɞCxij-tc eR2oH53S`6f5NSYގEޤi`Lť0|á]ECQY$+`R!ySXZX^)n++jWV|Xv* 2+a157).FQ8&qsv,K+")RdƸZƪVO?cֆbCyrô0krĿfEoA[%| W-bP/Gɀ8nA\V/9KΕ-,lU\0ӭs:>dĩ?*7=FTݞӶ6KYϕRF1kK׊OeR]cDXq5a猕-&@V4ͮD~KL4DAwi03Jqu^~w' =)u!RϛmNʶ@fG~o Sx&RV/c 1í1nGA§*ź60u K!"Ljsl#l$TN-yNvM#n_[#eBw\#5 <B.r„gCg 1Ko @ey÷| ۻ_<4K>>XUN=. Q+ 6l̜$i:"ORySK<3Ը KatPfڟ4a(= <]{4,ixsԛf6!,!zn MTq1w=LEK%}C4O?P; \L#N,f%CF™Okc98 dRgr ,Ϡi2IŢaZ^CmZNm>L{ y2ik2O?N=H<}U_ aO,X +:wjճswț$oQ'ds.J _DJٱRil(vU#⚾])A^fn]6Գ ƄWT4غN1,N\ߢ#<@󲎐 x(h7M'laJ 3ƛx-\&ymi%^yIZϲ+y-hIaXq?nqI~~xE̘P槔DBS3$`a<=׀<%4) 8M6+> {* ZsDЦJtڗ)vQfG)!4:FURnP6 zݴg؛7V-ZN-*\(2vq[Lmh/z-hef}VF/`x(D*0x6Y$=Td'gry ` %_4  nzJL%' fc?ֵ5jѷ G,yGN*Vҙ#Lvm:uVyH?OL%T7{Rdo V4G"Y⾤5n.z₭-l#Vڃ7TU?\=OylXeݝt(@l`2](쫽+t%Nm:xP-NzTox +ZF T4ˉP'Qy Lik&,FX5pP戤.H\E+%=.M? REFrZ ”D&Qd5=B<cqn al*[$;n׎AN2|4sa/B@N^yj?7D/浢o/gͳ ?O9!JWڧÎiusv) |0mz{VԴJӨjPqFd2Si@+g۪Ǣ %42.ڡR-V /f2JgtͼL[Q]S~+O%# Z{vWMp44 MyQVkI> W,3 O t:InEz֋A*U.v cHUԇ 쭀6]yjRbaZć|L /.z%*ĉ3#Sm.\&o*NEFؤPzFbpG¾wOB2.ˬ1ݎ DwAL`i +ؿ,H"<ѳh9;;+I+!&K(9*{^Ԧ A.\PJf~53GcAd48W by&Pٝ4LM(/3Cx5`  'reX>g\=nn4}zTZ&b^; yfcQy&Xt2`rR ăAbr;]#I5lZ72*n72 h1B<\n,Ǖln2x|T9D';S9X6?W\_!dAV`R/Vnz ,Wct62ju8] yƷ'v=:XGs4Ob;tw \AZ$T 2Rdy;k"q@CT<[:QDf N'}CiUM 勌}C_ qZ9Cp~S0Źs~t7&6*lopv-AwZcoS=%5X+V["sdՠDRQN9F}S+QT Ɂ~>ÈHMLJ|Fl1(02_, elcdjBZ>ƕsޡU;_05e)ֈ`yIۨCH07yzEt :̑oLvcޘ}=}NHab]t+Yŗ•Zv$D/xl[ svD>A#P6+.i4@ajA]Kx3 \0=C/tV.KSftk4<$NNz Ms8p4*UK0t3z߹[K`'vKތW|;{C됙xب2bJ92srAxIxQ(kb7rpg񸜚M0Vϯ۠ILaD!c&,:Ib,̽;;( :ʖ&WVfQ=,.`86nVbR > t'-- _ƲM5{1 t6~8? ?|(\ˋ\!8_/['g)X V9.¶c$/uWͩqr*Ҫ ϯ7#*{%V`XNT+lh>5zse6DϏ8q@id*,߿$lK`%VP_G2: jӞ`4dZ(ȏaFy9Mou2ˉ5b9ůs% }T[IZ-*3Š'#.c-aྐྵwL? ڂd72ϮosTX~tS` g+޷u | V'$4a/d7E  \= N:XipPg|, GW[jI3^} M$ ͰE*Gtqv$d[ㅫ'"H3|2eR=YQ2^>[{5Iw)$0$JEWۛ!,\ ~>Iyw| haC'K6sl <~ jښ2M6%7TWx a8$(redg6B}G," @܊ήwn+YAtH Cܨ hlneVDnԵ9DK`WG#fE-kQʃraRbT? CSMV!]`qnVcXq 6.P-A5kzGn7WC[rOtG8տ21̀YT &Ԭꐙ\{~N]9Õ__KYɎb{6iy378LDN 7^Ym[9M!"O8K E3kpNQ߶KWQ?!"s(@`fq{,W 4M+t&WcNzx-i wf(AFV*#J!N|Iq6`Ni쨴-{?'翼7yxǧ 9l蟀fa*sF\LA@OmYQY;jEG/& Awus@;#s/IhLXU~Zt>,wVI4[|22,jZ028M% u8AC_n$|[2ӞWp nkW7F!w3S"Cm5R%6"ԀHjDɄ/Ae$ 9mƺ /6|htN^cSVs.AԶ9 wU>/35jc?$;%r:rpNt&}X [>p&x5dIVƗDvѴ&4w@&ÌIW@<ĕ:ur65v^$?B/05pWoҚ>EBmȨZ|>3xN|83^ft05z)vGMN̚~w[6&|L:w7ŬIVF%ù{YFTϧ{.*yyqъ<ªAHmyDm0iܐLA8z[7eT@\ݕ =S.,׬f}r}I!Gb6PxlqbI`-nzC5ږN6~⤟dz~{3y:'V,p0c+6Ůމ~5~@`Ԅ¶؞ k3e#G@sX7Ҿ{;s QoʳCF9MZޕt2SK-MZ?N[&8I3mLqyT_p('eb@, ~ \m de~@9b]KS4omUT9H nJ>^;**T!QgT ;PE;"stVϺQS 5S ŷͺ8v 91ZcL&7R rcʘ[c99U&޾aƚj։_k8p9}Q܄I jLdTܜ_x;%BPX,bVg3Nq4řc?V_l!aûZ+!?"ɺW]?DǬFhe4[ѤS|}肫/sý5WR}o}W[fJrUR}[i{ih1ǘL} Mz,p1ɀ3  FtfVil I;^[ A9xH8 URRU:=(8 *kIpj^,153W$<!SK%Wܾރ}-)Sl=o#Cc)juC8GS|$"A^%*#5. EՏkJ7gk/cb<ΡZN*:~{YP毓&~+;SYX {_|帮q}/[GzNoˆt^C}$j4D Pu;y:VDbi!>)]8TZmWTDv>^x[T}[GYeUd_PLP+҇ C3~#I{WJFiY.k鯒L)CB_\X@aUq YQxWVD4B-|H~cOcE^s Zb_CS>[ @ɪgЫ*F\HZ/o+i;ck[EgӲMi 8m"I+(k;W _ȷv f;%mۉ}yeP!D b_s6a!NO:4 Wܑ>T/1&Łu[V 3pU# _RkY w˝Lr eHٌo8Z ,l^[w02Jbav[J׽}"3-*!;$OF…zZX$~[Z BA:8{Snww5B^*{.q7 *7HJ\dwosgl 5R}0;Z*vnl3"DOpe9joQA{4 8ݧU@*sl[7Px̻P(4xtKF孚_#kgx5ȗ^3j B7gHgZ_"$М$!1 s3U08L@n葱SG"}Ew2p>cp7,A/"qp&.Ŝ*׽jM ~˧ %-t^`ثJc j;FʒP8Hit7a dLzypzg^AVrWJSʇ%~G٩H;(Ph97 2N+?+1 aZ!TF-5- ƥÔt w e?S /|'G$ߴ1r>s0eVltT~Km ߳R3Ծ_XJ{KU |ؗi}3V{$\u 4`r޻RRwAf:,Sb#3Wjq W9"s!,S =a:nlSOhIم!R?ͫy=h^7e3x_?xS͇Wƾ1>䭬nGh/\TJ"̧g-h[X*3z.-mEeOY 'G2~J証xtD*fVr,u2mAޫu@%W`us6Dg""xTBUyZYJ &}*vVg8=/BfHzHx8~Zn<6:ɫRs7f ^ oZáϤ- .62_Kפ]KY=jZip>ikuaK9yٛ6Ztl s({o<j,ƄV4y uQ8? hU"*킈h*a8kDB t qHFLasWA9,a6[GGK츘i4K> (i!9x%+hr˝O+s%+ڬGd+HR\B(X`jR]*gylqu&ā'D#:bwhL2+iZ-ڽf`b -Igz!MZ=<?Yk ݃@T=F}*ZlvyB #ʩY죦:(9a4xMLsdDY78F#η]vꂆ;.aWRo@yPGQ B/疺{PAWHG1Rˬڻf%4l$kOJ9`$CYW^$H6uWA2 vkhm~->jA;&o9ڹVop@ZXpJz[@vX[23~D2(w6xVB侲,6~S6G\72] /ÈG%.om̙țF_r/IWp9Wq8uM F$~7y{OlUE1Fnϻm510uޠMy"K52ڻYGjڿat։9##I.xa @u9LR{G$ ]ۣ56QjA9ĺràmf#j $,0o? V vk̨v2iΦTHY&51䇍@:sh]ު\>#oRW2?#֎袿5>GNULN3߬*Bek3jaIJ0Ws E6O@_v$) l@C=a*ttk5"?/2Њ]S,DbH >$~7,F{wӜ4Ӻ=HCn[2ښov72:Z@ f-МxSI&ܷi- G1B AZ]SWER@ܛzTU"i3<\dO@B8ͨ9h έDţs$du ƆNX8,b*fs4^+tkHi"?I396 lʳ].S%dmVB$:}5]ҟXjWIx=`?0 &Tn &/" >wS/nt pc /; Ґ,j8[=mb҂FrCaL4h+h*R"rj.ۛW2'Q5Ha[T4%է'B4aV,hX%=$ԿT:z,vnAhvMO-Oǩ3zMW};.f1`/ГF"(V$h+UT5HkLd|xf{.xPE *'tpLH*-@I-& G,sہC/i1AB9,џ6-U_SX u*T|nӱMʗ 8hq8l ~wuI>+XN$8BSa:U &3v):aoN҈% ! Iav; x$| Y&ūmOa6s }jPb}W;rZW:pݥMz%?J-oխq/l~O4Ԟ˕Lޔyf9:q&&4*KKvC:DU*0:YQ86ƶeyݙIktK,wX)M+WBbѺ ,鵻ȇܥr?r/K]pi-jB:_v^FS\Sv$.E5 `y׊φ}p@+j~EKy;d _Pp0nOI(IR?r<)=``,G rAA h|H/qU7!@{u,Uˮ6#9բRt zd{0s ٯd<1[W;NHdfXI@2tǝd#( yQxx`^nPqjn 5xBzC\8rp|rӿ99mmUX@u;U `Q@ cy+߁B (>MعБj߼xgI«5Fns)m:fF1$n~^U\(~m' ;;*ۆ+֘+8EwF[VO2Uyyv .(ֱTd؈ /0CFm;mG01)?%4lV0I j=c6CXj^/@v }\cRf̮CKd@G-%h$?:6 u BfQ^ y]쬷VuG j pt\(ћdW9nȦ|V_˂w [m9yP2=/װw]8?F$i9NnP7s?佔?c\;gvX$wyՉEFOc.I%[5LrDM+94U*B:JVgӘWߛ2v")\ gQ}B R~yU)?=7"/aN̖y}˶vR{c 6r=xu&sG!tuucs ѓd[4`BBW`3]|; nF0Ū G(Y?gx2C. AeEB M!r &bO$l9kska3(SD3~3?oY4E/45ܽ -Ns}^4\ |d $|ѨMotO.쪖mWAZUX4HofL݊ѱWrput4 XW5쩋rCbpD[B[ ; SKE墦zqPh$)~^`]&2c *L:6=^Ɖxֶ l  Y~W7\`6,o[WlA=7PskVL[hT ~ `\|piĜWt=2@Ǭ1U`Nhsf!ԭ+/iYlUT01`ߝ/M(B_F;Ii8JD8'drrI3l 9s boGR;nƵX˗IXUJ 1.Љ(u Ov5 $mG]q(uP#e Ov~}ՔxfPۍS_%ՔTˆ(4Za$1,O&CV+47N[h@ hfn54~AduXv.tjff=CwPg]RZ!pbUc2 KG5J| ߧESw1?rK 3QG#7n8Qa@P#W~g*?+`LRxکypW`|AE+XRah[[;S?FmPI+An" JZD%+$srɢIEu)]X!ǰyӸhY~ΓmovO>~]J֔]?qXSaSxMŵ2^@ح%KUɻJ:O/$44a xZ*JD6,r!Q?-30,l "cdxWCJIF&z?9:igP SՇ0oDشx3B~D$|_6n\:bNB_Xb~<6T?Fտ$jPa;f-rJa0G,vSz V"=֕5IYv Iũeux#6A mM&<)Ay)x)DdA*~" n griuG/a귍u7' xnQaip7FЌ2HǮλKX4IrdZui'r#=gOK?Zm9h?b^~-<=eQB.8 $\P ` H?&AK T%2*sqf5E8zpaq]"$SAfJޭ{4&xpw"2 W|)L1e#4vf`53LJy9yy6혈Bv--SmjlGa#L\$H[ŵMhr)q"$[!0L`Cv,{EF҂X"_|>|HCO-zV #I"e}U_h'@#̗Pρw>rtE^ACa!Rf($qE| $\z:J"Is ͈ O~MLMҍ'ȇ}GϪǹC+ )yRՌK o`!A `;<_C_ F:;t!, T NwZfL Y#6G.ЕijDW2HR{ye'jGJ8H+KKvǒq(y5Dt|3uSҩ '̶ YZ