sssd-krb5-common-1.11.7-6.fc20$>Ua<a?568><D?4d ! \% 4Hflt      4x!!!(89 (:1GHIXY\4]H^bdefltuvw(x<yP80Csssd-krb5-common1.11.76.fc20SSSD helpers needed for Kerberos and GSSAPI authenticationProvides helper processes that the LDAP and Kerberos back ends can use for Kerberos user or host authentication.U;arm02-builder02.arm.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttp://fedorahosted.org/sssd/linuxarmv7hlThKA큤UUUU7T1f6528a1c1f546482d1fdbcca19da06eb3fbd34f681fa7ca3260de5bdef20f738783b9e4522f46c8bb5588f5275b0af7339f555d1b96fe93398c208010667b2848690f9dee0b1680e0e5699fcb7fb1ad9788fc2e4a918e2369c8983c76de3abc08ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootsssd-1.11.7-6.fc20.src.rpmlibsss_krb5_common.sosssd-krb5-commonsssd-krb5-common(armv7hl-32)@@@@@@@@@@@@@@@@@@@@@@@@@@   @ cyrus-sasl-gssapi(armv7hl-32)ld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libc.so.6libc.so.6(GLIBC_2.4)libcom_err.so.2libdhash.so.1libdl.so.2libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libk5crypto.so.3libkeyutils.so.1libkeyutils.so.1(KEYUTILS_0.3)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.4)libsss_child.solibsss_debug.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtevent.so.0rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.7-6.fc205.2-1sssd1.10.0-8.beta24.11.3UT T@T$T$TwT Sh@Sh@SG@SCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.1-6Lukas Slebodnik - 1.11.1-5Jakub Hrozek - 1.11.7-4Jakub Hrozek - 1.11.7-3Jakub Hrozek - 1.11.7-2Jakub Hrozek - 1.11.7-1Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- backport fixes from upstream- sssd_be crashes in nested LDAP code in case of ldap error - Resolves: rhbz#1126557- Backport an upstream patch to ignore PAC verification failures- Fix a sysdb lookup error that resulted in IFP not returning subdomain users- update the libldb requirement to 1.1.17, which is required by Samba- New upstream release 1.11.7 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.7- Start before systemd-user-sessions.service and nss-user-lookup.target- Do not crash on resolving group SIDs in IPA server mode- New upstream release 1.11.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.6- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.11.7-6.fc201.11.7-6.fc20libsss_krb5_common.sokrb5_childldap_childsssd-krb5-commonCOPYING/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-krb5-common/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabiELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, BuildID[sha1]=fd06aff560440e76cf047aef18b83f1aa6d969ef, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=f070a95510c86b5c33803c3724a68f7a5331ae68, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=d80e2401e7cd2baba35f277486a8f00e42764b6c, strippeddirectoryASCII text " PRR RR R RRRRRRRRR RRRRRRRRRRR R RRRRRRRRRRR RRRRRRRRRRR R RRRRRR?@7zXZ !PH6Ϥ]"k%}}`ʛ`c䆨r.{kDP Y_ZH"i8/hdWTv *볿~pj[puw"'w)ܽHojyF`;dS#A .*Оwэ@KVIɸڕ%րZs9\5*TVD:rNI 0.!/v@Lc=A%n*U~zk!4/uZ6o{ pԡfMJ)~6PڭF@'ac4> H4pM3$E<Ov~?*0Զfƺt]|Lv!τ+݌ƴT(>' Ŧ G܉sdC6x Lf> le^5nTN&5L.'i ~A)6iA|µHW$3c!XċHisT=il3 wv kIVUF-)(&UD>fcs_Ldͨ))d@%a<r0yбb`FF CNF6{"Ԧm<+)ǫV[xHQo /[Ȱ7f_Z0rW[#˔ 6AsAٗPۻ:;F~X?(di!en_Br4@ Ov>*@ J+$$S |# 2Լ0t(ܨȳ.!*}*-PcvgZEYi7†ϤNs#v1[,\$&oS27?RW24o`1g}оi@읆m (b8ce3~h(.[Hdlte>mɠΖw•Wx}וDҦV 30}-5/ԀԊK~4 )QtmiӚnyeUڷN(딵OZw1㉨'@f8Oo hNPhӖtFyy-< |1MF#B)*]lRHЄy^jؓKbB:6\42iel7lX^@x}MM3ЛNrI`(|V;#F 6[1FQε " <(M\a ř!W  Ƞ9CLVR:*؛MnT;z4d1 mv *M<4BHkv> ) QGvɯ ms)$;6ݐPÈG;/aZw>FSk~OT.P`ak|9V(ŷyk ?n>դ2gVW Ҙ"b{rM)3sx]ʏrW'S|po0%Se9Lդr{Ea#ɟy2[7%cyOG%y.; F @H4#k~J3ʳǧ_.k&{v \BE*lXBlTN'[@EkE6P]ؼhw)#NDQvy5g$FDK]œ:4`q-\2W'̂a8HT; "R$C2}^S_ibA>S678 {z+q*m"1(R"sl'AQLʂمPPDDG 'I{06T!iʙSP=Q TNG\ G⑍ɪ*W|{[dӜ2+&Y#82sqy |ABx $A-y3T~Iv;Cf`]pq|+.}4-i0GV0e/1 JE |~ ykf00"'Ud{ >g6y8pX>.OdWۆD~F:An耰3`U*"3ˡk5 ؆>(1a#v=ZMY.]? Me֎d?lD$&{63#TFl %ʢ'&;gŇf*#,Zn~ro{ϗICF%@[38J#@t\IHžٽd|E݄w'KF%> 9A܁&t]ȏE\7;UdlR#܉D"mw#.xC\MS6U9:]i/fڡ>-t=o8ZP`X_-XTng ĺEd=w5퀑oJMywI_R?BH}Jw$C&Z9O  ՞?,ѶXi*ad]mSF<}G*f8I6|.tZ5#ߣrA8/~IkW%/{C936Şq$:2 K9Šzۜ=)]^kĀ)(e 01pJ?\2ܫpI HBw1l-8C;`RMF3 aw;eyl+F_A5o"R ,+@&):`bBC7=6Fm?p#ǀU򴷷]\NYc䗧\=[ "'U7f>9_ڭrdcU$B[<23#\q3K=(j],,݆V^Lٞɤ>J s6wݡǙk`}AyBK@{$-Ka _Y UأrqQӻJV|# y!DlG\8fN=5z"ńn5ybe&ap2IF *{5ee:~Ghǫ a[ZyVnoZGH].O.HMKZg Vu؂kQP'y;QۻkT^p'%69[lc$x3K~*D@\\|Y뭐.Pv|4"j LYA?ˍknCWV#(y2JG#Hvkj>D2:mo{x'nA*)Arw\mWHC m]eE`qȚ-7萔Jzjײךm_XH[J0L Kejyl!+ Yr|ܔ*!W50cq"}JIFtX* T' {-9!/̪{S@:@~ U-VX:3\WIXEI+Zh49Iqm//˖C VCMz(Qhh\D bPGZFhAa)lLasJ~4y-Qo2m"T˷208aڤډj6'yŽ_ˣ\17 |ilv!^+aba 5h$hrҷmYgJ CT+%.3jг(5Y`B,?9eO/N..]-Ki@I­t@J܄][&}]DvB$B|hĹi7|UWj3[`;#e*nN(?Uz9,LJxD=bjѩt:ze LH|* RNYA뫊aӤ$"j]3G {(ĠTOaZt҄z]Y3Ou%={†fe~LfF[#E@;n01΂;xn>h[4#LQU^ߊ=ju4pw8[!6Z=-M0Hy8ƲJQ< 7⛧O'wuT|OjjJ%XLRyoF<٭ T@k⇔Ufh^~<]KD+^K&p^D7P[u&a(C0K {ny㵔띕 r}BTb7qpx~1OC ivA&U5[؃N:XٱwfwJ,6eM_J%`" W8zR%,3s.LSMټٱFhT[Rp) t~g %4r䯻KNOvMʴ2[8@3م憡>W3&Em#DEwTb^P!*Ġ+?VmR~o^ a!Iu: eB!<ô,mIΥtQ|2%% .-tˈZ肆誦/)797#'Tɟnl%Ə.^kQfVdHVyMIs5s.EնS9M(dp:"o? [S0'pVkp~'*UcK* :-/uR X | RvkG<ōs&;70sake׺5`dZuM݌VrmbvSۉvpi؎ WHg7瞦` *<*:(mɧ؅-H@AQ]3Zai'F^1b0f]?DK*u]ɀjqM߸0,^H1  f}=0]+!}}i 5R@kzk>,'b6:`p;rڢaC-qp ~z# ;`Ce5sR/`9ab;lbr@MkC՜n?p!1M WIVO~kX-5Rpff=\0UiջS=̟g#k-hۮЋx]ZqWX%eg#2}=RrU~"K+wg*VPm^GbQ#b8A:kōL<`"OGS. Cg W/ twzxeH3_;ZɓS鐛qa&Ѱ/ ^dDH{uC_%zݷp[O C)3ޯh.!%(H ӘMGAFߑg9&a]Lm~#53 lgAZE9FxtUq 956 1u 2/ *?|G4|ģ?#ŭ*Yb€$DX/\NXy@тߡ(3S0'"M#WHaM"42.??z&ofÒVg%vLRݪd9S]nsR?F6?=()Uom iIzvQK]jϛ%ꋕ_蒌* 91;( wVbzWs#zꐀf!g= Gr=!&&}9 Z\†ߤUrb/Vr>ye!8TFCF(v?G/8-eUƁ!\qk8^jhղObF!X~%L@ M9c : !7Qn=u ~ pUecCn MyZURT{4w^44 Ξ_|KدZҜEzKpF*:{<,4Y/;|v|@:tO#$Fp\|_d!xBhKRkJ"gy]+M*_Xw%)ZgC&Q'WGGguecײ D..R0:B.'\  @E hmxW5j^ h-&:)y0$6ٟ۠'z H")C Ʃ1 tEo+I9cٝ3`oOX[Z"7[ P͒Ydͤ`'1X 0G)nS"Rߔ "`b+]p~|g?=Wo[+d hѺBs@i;fMS1[[*-?X6%e5fL. N 3-5A o:)GI')qQ 1d[Wv,SLZ3Pl7-S"ߝ_(Ӻ&~/C5 )6м= #b5ì^;0 -⥳u]rCjR·! ]s1[bK$I;${aay]z2z$Йd `p<2uܛ,52rǣ]|Y͝p^5hH8ܳ73cbNg͠M5WNde'OwZSܛu{`X#Jo˿*)2Uw")S 3$;.m5۳,luВ<{J$vB8}gvvQpuwH@ 4heRq@Yi(U'DB/ :e(\g(f+>2m伔~Q!A(DZ]@~뿎[R?.h_,v:M!Wni7 Si,gRUYp?77 UR AL*$dtJ3:x!7-Ax錎OjmJ#%T$nfy/#KB9ݤSTo*RgI8XlE0YbUbWb4Op@J'> |L0q=bb+SŌul}Q3K'p+OV'Xڡ[^"t=/h-HҨ~Tn; m8BKmAōo)q j$ oD]*p܏!P!OKH<1%RsC-֪%%U_7R1' aÔ"Z._K>GRw9dЕ8-X6tŌowwTs+F*P`|P"x Mͥ+a^ۂKj0 CNud+mDMr'o}Wyy%:0+ Vs"זx, Je H|QW9GO!mԳwBvtjXٛ#,ib%{ɷ@VIM7<0 \IQqc6U8A;CX(UAJ lFڋ|q Zd^.#CÉ^񤟦{B]'a_͛/h)^ZÑgR P8+!jű#Z;< g b@iCYBƌ6!U"f$[9LCЉ EI|8CHdV9/9}vINdj Ԁ<3eAebE0OvV{:bR 1 ea+S?sͷ2LCh9TF[J2iAVޣ;廬_LrVHuK~B؝;,D_:ҏ~s%2em(A|vok}oӿ:-W4>_N@s| !h@xYiK9+wMP{Ef>=r1cEZazT$YW*^H_?ZK!L"YbN0$ qB,v\|6Sa"+ B L\oJHM3"cofdM<˂GUb&^ EmA(N6(Ie&ӦkiiAJ1`tIPmYlnSyyEu<$C? yEys{ [gvrkjUkDPzh'ǶwAϓ&38*`B'XqLۄp*EXh:#d3>Jl\=LGءm ? .w jn*_ӡ_y@@&g  -TPw߻4EwFWA>gXZįn?+ˣ6 wq>tӼ_VVS9suW.O ?=ـgˊdy:S{^2@]?~=}VO_"J#\[7)qz #K't1@c sc/zLHMLz9f.mf-&5a'$H;tNɴv`fI+b/#6.Ix6OK˲嚱ARYJ*V6|Vy>C%Gc HmkR>6I8Y%Rf~BZ`Q#ނgԲ#kk[H C[k#uO''WT@I\&U+ZJܫx>xyMyM'rGv~vbv-mzwy8\iK5#Z[e(+p*CXS K}p;M/ xFI00ۄ9?)djVż`i*xl)r+ƨ@Y}%PG?":63NȌtUrQe82 l͋|2f(\4R27侀~/s`6ŹΓ7Yρl&(hj_AS3Ԑ5Xm|~C>&٩W[m`$d$@0_obLi#p>Tnky7 v"vxG'9G&$tW%Ng BK[jf RUi@? (stJ|7խi:f8("3xKBw a0 G-Ðc:EʍvK'Ybn(N ˌ >q*ByB"\|0U5*5Dً4aa@ƑW?WLpM=t^vG5``GwXͩ0ߔvn\%e\%2T?mv 'hb"EY.:D" ]~ٟ'?@Md]w/K\HRWPi8#PMm4n=#Og?ν! d%6G>˛Ӷ-suq+=%n暲p1*{̵6E@bLتJS]-@L볕@_ Ģj/V/~nPP6݅KvJZ-h=b>[)Oaz6<t5FJ/}B;_/1>,Z Iĺl)RĝURO (UtEn1l :Km@ߤHΖ!tQIⵋ颭.5 S@sE%t[mA4H!E@lݛt69"9b{>#w&-2*p>LbyGϮ}my{GS #-rt\|%$iIr/JK@xAMf^" ;VL>o11?' \1QGHUܭyp_\N Cוt`n~P׀97 }PWsDI+gƳ8op}:5eY`;4m[k\xRTv!0Cn䤠Flq@uqx>c{ C' {pւڒ2R#!suuDLĚ0Ch*&&ڻޮƹxd+ЂSjύѬz0ya )/9T re4t\AF:SO҇|@9E*+nj U` >̤/qKioYLF=˰JR6 (VJFp1(KM28[&c$O5ܪhL.ྵYƢeaGK,Jx) 2!45FVmm SfTB2 ׷>\Iܹ;nmG_Ǫʼne/~$nQ{(#?' cuu+'#1dHN吨u&ǚy@&opxY>𒊐?T /iryV.^wG_a W|`7N^w{m soqC!5E7X_;Bb6S^INզ%E͈<~bڅ5blg)ݮŏ7!e< mr;RUy? y" VT\Ì29*$-J2pۇeUǸ^C'&:d/#絛i^.igȋc;QK+n'JxsCk9p"yF< |@_@dx ۜ(5&\]dԁUl _s .ȼD1o}R,fhM<9`2JaZ_ci_(L~MU΢HI@V_Jù?'0"`wO֤@]ImVЙQ){mvCgasnz2;br8(5녋}u\56:&7D52ACފ?{rUj[т]U5o^p/)\M?zVHaT$x< .6n͛-ΗFlpͬSK[wjlN'dwd)NGj1'U PHWprI:u4kBʋCd Onk+Ҹ'B,hUb._!=*P':AToȏ/1j.~s C#f\Wv+ $NpDylF}j$.IR9}P|%KnҺ_mtH8fM];"KRs$k` q;pw\uY~E@bʆ3IՀ_"BђO TO:sZd!O<|DBeop?M(72xϊ}c]< !w07zRjhLDO6X -6nUƚͯ4p #`B*H$7HQ~5{*OFgkG }#* ʗ/Y~'Ne7N!qg*1Ie'#l:y}'L!h~:x tY39C.uN:ŀS.ᵻ:nZ>ƕƯNu-͈VqM ngUPW&0e)"v4\XۧJn:>*.;8Fb$^R.j/p,׬,9]M ~k~E?-sWEbLg-OgMRqq-rz$Xӣ֖4*Js)7.Z<5XP"xrLro z93KӲn#78M%c߱~ɭuоO*F"zzeJXWH p "3Z#ǙSGfwJlQu -yo}:fUF*9 Ivg5X,J}NQc>`\ӏlr^%Ld&?`_rWyQ)\e>]V$y<z9"w{ p!_՘. *,OlF~eyK:iR@jb/ȸ9f{|^sT=2dBd~IEPsf+LmbPېkJW& @αT?sqW[y {>=0tѧ܀lQpXC*h"8<ݝ0 MQ[{qSl;BW[#E~L'l'cHc 2?̒nrٮ*0"gOo#-_v RxwIM?_p tpCSb/)#]vm""uR\-6mNTG%ځ9Ӝ(jok|@?d4v`D?֨ RG{@"DcШ%e|}ˊyM}}PX Z cCg'S/ǫ}p8-R/95B2`  Oiv܊"c æR9,6p E5 o)_ECp[tsPUe&71ą-j5Ћܤ$[O5FCğ m4>:fQMAV\=DefSjXJX^g-:DηedۣN֘Cp13,{wΡ͓[Oxh<#5"$8lGvzSɍN?i:/d,(e$&km!n5t_ Z)^,x\%'[6ufSqrOC{mXtɝ BL5sɡo8Fm?^EN{|x43yd?JPN:l S5{]SEegR'imOKVvj4hvn){rn#uPw%M.k_8FH pBk8?>}$ti5X :As@vn|Y#9gBPÖEζ³l*d5t}9d9pt"]~~nTVvtK@wS_ P=aS,3rZA?糾GkYxLFdKݳ'o%|÷`]7-^-}+>U˚}rK<^r'Iܑ&2u$;;#`pS͖(._6*21rwæ VJd"ce*I<.mAc+=sq\H{n=)N#]pJwo:yސX:tFC!H]xǸ`?*}bY *Ccg7A/@8Ϫ"Fβ<#bʶ y x&1N V^h$ K*KgNZ(affbF>gYN]yP t9*h蚕_#5-P8A+7^xszXt,\ӤhB s 9&l9U.NV,͞io g%ƅD+Q<|.F<(v/Z=@Y/q̍ro_kdANPZUo! Pwx36pO|ZW_ ķMώkLENE tJ;B)E~v0O noQ?#3Y^ s6/c(Oh5\=f=˟<ժn,.mM cn͚Hπ/Qe**{xâ)]UAC/6dWnNZjܓvF(gQcag"m^)Z+(jPJRGm 4umc$' =tBědg04_{ -?WGѽ.T9]Djߪ /NޟXm]3OGq9[cxRj$KڞN '9` y5_ܻ8qvW!Ombz!Ƥ=yn|H n*Z=å[Srel^P$5 ntyhAkQW"mNM(]Fz ޏo EZkc"X m~&Z +ikvk&ᛙ)\¦eYعr'j֘SVȭtZ tf玛=BoB`s12ZM]@I *!$9ۤ;3%N;/&eS8˰~E&QZ)'5-.nH4˯(\uh0jXV#JpPQbQt?bNa#§'?>jx(rj>`uF΋ʰDW@iK9wsE<ƐLj꭫RցZ1{˅[͙g?= 4]\t.BvݔuN}qG^O-=3$U+q_$17Ai%7?5}xge:v@j9bi뻦^ة6q Dam 9Pi2M2_Q70e: i9t-혒6<)@-Q/>'<},_FƂfL \ HU,Qf͜@NSO˓q9!o+kMُs~"bJ \ ,߬XQP9mrOZX2DDwV7%gvR8,i8- 2=F"ӏ1X įIPK}بw ea#;6yϞ9(60rcgڭv5rn/'I1*g&}E /m^:>ɕNb_qӾ%:Gs eƗz2@\ Be)nmG9ZY| A4c>DچOjQc[S)j;d}кLwosVX{@^ꣃd5/[R\.QuHtlMTsH3n)yYmoMޫB78k6l40`H[yI 3=R>*\냱T.gX Z'\y@eIM1hlyJ`f#yȼ8KdI#row+EPJN{5Jי~@D7# U!P~G)YEI՜f4K5+W؞zΑ UkJ ׹(e7^q) *9` u@,UU1Su?QΜF/T톕D_i[Ĝ7D{0'Pg.qK=3XV""w=q@$ߏՆS*.lAJZQ1lW =rFP9UF$ex& 3LX>o%FAY nׇ$_JUozrsI\o >葽=#DլS]=\{t̔-l+NMFab#HDNpx6"jX&LkE5E&J 9D # _f7rܩwarQ&cxgGa+I Im*W?M\²Q`{ ɩ}m&f JUX &*(I19vIf9A)`h#uabNlGqR\1è}ݧA `zjTvDr(Ba?(F$Δe7& 0ΗJٔ+k4T_s=m8'L|Kf%W-Dt sr KZ[* ;mdGϑ#x+ּyvZLLYv'0e 총C2'bId~by,*&X]L+p-VI2@C/^m?EW 57{6p~c SۮyV`PJXWxy, 5C'l@#{ 2@iR\ Tyk!hY'i{z>[&4{A{wGqIx⦮ó@u!iڕ3ԑf7ڲ^6_=7Gvrs6qa+O?8=2DRN:I46Qq,”Uxw8Z@/^?ַwU%QjfE#47v!?u[+tI|ZIl!C~.dk5H^?[ P]ng:S(Y9Bi+;M&N1)R?O(&"!Bt!L(2S@cO&aoBǦ^cY\"xloŭ?۹ݍ:I\-N"8Qy; M8;Lupdl*J3?)uT#p@@+x!voqCcSc@JO/7G_ Xp< D|&;.bZxņESi ۮsmC}UzaMi`:IIgi=+~x9NʅOfD喫j2'qtM KР31x afEY(wnLb+Q`vsL>ѴEGB?$]EMBLaTs}P*g'QałMB+!AC@6B hti*Gn{4\ )41k6G)gAT @F:Hֵ?l^mH@5"6ńwIUG䑁#\S*0+g&ꮑ?8)?>:\Cz{&Iמtx5='M l)]jO Z IcՄYϬ$(͚8gcȿ,Xܷ c^%M@2d#;E3蔿\xv27y`\:8xP(/OVn%g; MԤχuCymCE6+> K{;=*Ta-W%,)V(;x v,p|_v%گ/$KDm"=3IK(u+gYkĹ``)dl"@0EUMDZC pʡg D$ sG >CrKPQJYӎ]&c5Cɻ 3Ŝ:g뇐=MZ %-ԯUGÉ>GT)Y@iCV(YJñN+5tzd)Oqd]>PqXя6~.Yts”+d/x kdDR_Pnf0aG#)Y٪wćU2˅Pua}>8sx`\- {0]j,_?P!D^Q΋0Gz9gӐ&#uG5٪ybvVЅQo/19x ’CY K :9p.`9).C&T@NGIu*K.5WAS |hDv!Q$FE,o,LLJj`!Y5A,64HKjVy3* T.·0d0)J;i k*WBѷxKx \mZB!1 HP |% T"YsߖPSꔝ.]5rt'O)hDB1\5ΧL=tA*no褍!m̼u0#Nd1F/6Q&UлdTXey蹮 syKa ~& X5bsMdW0hi+v -o* ؆c2؈c[U^džH[AB v⩴6ڔ@"x#^yt[BpjҟqU b(&ZAGDr=M&1MUeg.jL8Oѓ5ch@ B2 (9r-'x;Srtq}>~9Y '&+$])S|6hm #WgyAz_-fpm<`6b&1 :g|,r] }s&߆K!ŦDJ)yi$D2Cp{[Fɯ!XV^b'l6i %ifZN!hH3$mHz/h[9*dnĚði ӹ-3`qlP]5I㟡 )5}rs-y,mh(5˩[d-EoeFcI.5-_m UE6 յgi1 eJײ?eW,B82Wq|$5B97ͷ-a!#SæV@f mÜ$nP?\eN4_cI6h|@+6bS?`N+7rO+_ՑN.ff\pKQl%i8L7F*Hئ/jCGB9-A;ܧ(&棗S ͝ Scwю PuY F ˲h@1"!냟*mQ\6]l\p }20yr`||~6pe7Юlz4ᜏ z .mR6ëV ߍs{tmJ@DjY>ƦODi~U찛[cI),s2;Bvޝ=h뗺kg7|sO6=@!B j bNم~Rncg-랴Th"͆םBKv[Lr򥓷ugc{VgђS,lkMQ>?37ؘd¢OXj7I{f\o5O+hKV_ VP9:M$}r{=_.;NՏP;"ť1o^DUK@-0}_;YA۔ѡMspzToakBԪ-8KÛ7p!r(:AJ P>GH 8)E@^ib=nlӚi p7j3}ݣPZ%0勌/>D9b⺧40["H_.6Y%| |n O&\\8xҵ كL_hP8 YѺfX700yylQ@#Lrb˸`cm:]@ wtuOW^]~fOfx{;60"T"![(\kSY"M9Vg>X izfoXۡNeP&<7\eiCWՁp=3-j%Ƀڣ"x)[ , Mk 2+dkT"AK4B=r=P\.Ej~8䰣 lK*F:YKvf@hpbm>" tkyW4<38_yqzSzVƨ̮El+4cygU:&2`8' 2 ~_~(<h1B)6iBlEߛhEJf)ReeҺ^g >̥ygZOKt]X.}ov^@&v\1M .AeNO3cbIQgWksCQF @kJjgE {0&e]6~-Cv1U/}{w 1P$#%^#h/TEi̳yM+u$Ԯ:_BN3d)=ў~ѕ4?@Zkya~"͒np*D v&1b5]ݖ887??t€,6z:"~9tn!d-V6Y;ٜTt7E1/NZ/; eEr+v_L%Y31%ȩn^ L)4TfMfBAF_NBlGzuxcP(F{`'{Ff`e@MRLgctQLcPc=z)) LXA }8 + bjrT8[ BgjYF.{cR15sGvlSN<QʼnVm|!Cգяn* hRYn>pop = ܡ:QKcOZaPUHYj.YM@􅳺/ZaRpQd]z# _S,IʋVwrM/`* aiY'aZTOy@yٚ94:%&KIMMَF0y2VN7 sĸ:3Hζ~gejF >U7T(*"ڳBh20#.ͻF:<rCrʌ6 3v$mG` YJmIG4HzA+}@6d!W^ ~8"ewa| r\ #Y{O24p \QqfQQLZY?NAt't6^3VtkPxgD>,Yc Y2&.:$k^S`JnE*qyFK#zepƙT*f3#K9' .lT;7lhXK!kXQJ9\J|Pɇ DpU~L3&c*>M7ܿ,!كE\41k6ŒG$N_HCUG՟51HQħ֙ʺiwӮMLna#}8Yֻ hSd hMY(n^&@Ǎ1L)hɖ~cꈜ^ReY=-(Lfcy 24vO-iċts|sėdAB@" 8\y?ȃE=L"0}Q*VWyUP!n2gn8_z/A,pLH}韃h~w Wo<,FncR] BKػK*5iu'Pjqf7H.m'G&=M͊#xŖ>ʫ-o|!-]h%I|ԢT`Pg0/g&z~VSDCt*`|Pto-aYr6riEYjg1Ҹ)f2P3%#ft9K5SHZ %(ؐDT9?tJDAsG`8qD&';,,b?wpbih̠ع8IoB=TWs~ـO%׸dgi6'* gN-En އ+XJaa GKsBu]e`F%3hRikugN&>1cg:QCpx!j1L-nwR&b옌E|z/N,uݚ`D/hn\X;HCNyl[d%\oɆXί O_NU<z,6j=T'~eD~oB*WR9oj:x]Ϫ V_ƈ 롤[b-2F l~S`\);:2 P𐒰3f :.,2Y+C 4@oE v?Gl<0iʺ:s/OB'Nʚ,YQy-/^X4yHo%q5@ɷ< p^ ebjV rPMʁ%ӟeyjI*}mJ3(䂬~培Fur? .;3^;ѽi˳v!𵭺mˮZi?Ps10̓99DD},Bv F8gc#2}i>; t$f]bQO *͉*Dũ!a:UAmxve"7 Iu-ɗ}Ddp";2bZ3ZԢZ u~1+t|J]2@wg@b kg |Wڱ1,!:GachMY2l>/|JR&Z}OQ/fU-j?QL'(%=OG/`$a ~\f.КJiB5N7RJǡeݖݠBM1rbX"^-qj3L Ta@ y¹]㹾N~Z$?+brmO)O f_Jo(b$]KWޅ|C+3# PAr9)vΖqBy&s{{~ =QќT=؝^aѯq}-ˍ M$kUx:,?bgB|mlz78ř?NP_Q-WJ+F+ Z_A)) Q&M[zR(U=$Tvm1D0hBe. -?Jl)4O*[뚂'+}gb0syTЙRMJ¦<^{j42/i &w^]$5xK{ɹ鏾ֹœ9 Dٺi/6H뤅}/<#|R"m,2ч4_Ԑ'1C:bB+e7ǖ_4[nYD?IlYh0Iv9Hvj؇E"fh`dvbeqQ18 w$BLch}DVZȿX*/)'6Zo>nKy|';Mu8H`;37)d0֏eI}T|9#KpuQ~RAq@:P/Am1Ve T&8$P#'j`.f}S:x:ZZڋY0n),5usj>d RJ}yxxaUѺzU0"B :1j`3Ղ[L$ g^vOfLv? ddo [[+}yg z<0MMHƑ$3vhѨXU[VsDž
L!SM)#|c,xG"/;<:v+OۼrI$φΫK͓fר)&\N咻eHow'J vTaV|5oc'[ 8&Y9zkB=Ƙp\૬߼ @ 8vMJI? H+fsYǎ[w ਏ+:};wՄڢL&8ͩ#qT" w#sAO8/ CIyze+I@4K04tOS&_AD(,}& ugE$#7d3@~0}o6~l I0cM;\%01Sb6e70'`)=DVhn6SkwfMO1T{-K-* xF6\JA{; 'ONYEaЦ{PؽR7l'αSwz:a?6F7ӄb;M[ƑUG[쇪#j>Ͼӭpjc=֫Cef3wM P6׹dƂ{xU^N_3Aud4JN[ 3(uV0l*S:|w6~y\y*Zu¬$݂Ϙt )in$M;KU"𳆜(%)>3fzL U3L8jbQJ4uUn2LM3;r5h؜dWOW7-6Ȭv\\s$OXdw3wr֪B=H99j$DkS3j3 :*1$#vK L2qR MRɵ0,s v["ox Hcۢ!29ɒP2lJDc/b_nƾtcIzp;.W@`W#}_1eݸS&%{ڥ0ѝyCwQ+h)rNXb)Wr57sLpj;l/Ĭ$ACՌ IkvE Dj (]=E U_\P02҃cIPJDًhfZ6C#PD7s5fLE_ A0qaZK}y|c]M'e3AIQ4XcI-LYî2Ck8[ hxX:Aoꞑ0!Ugr_TbB{^|UdCن`)L܌=钴dsr涠X GL:@? Ҥ2qCItWo:Xˎ@LǼ9Jb/|]D:6@4)@i1oަx?(i-ȅDr'w (+0W:~{H*zzŀ)@p'+9[|~z[h.v{׻5s Za=dnoED5Ov͹9ɓ6yٳpz!p .#4^3Aac!'>ڤB8 ΟjtniN8AB}ʽ/Ai M\m_0DjWrt .d/TTfD@A.?~/(%\1jpl .4(YܭxsU4ΐ% >Y3q8RCUDjj{hiP|,hSI%7`<ѥEbB^bK`"AȬ#b"gPAdO3ICvq|y>6S-Ld@Rq&39/ؾ"s&lhȶysc@7Lkx/yhC G ~LtSZ&J1NCF+;?U\~W4)QcNC ? >w~659֝Tt b+l^jGF,z!_$_GUw;jqlP1Kŵ]mzP7Y`k?5=ZEnZo򍑁=I'0|'я5AH^lƺ!w^,ЮkWeNOymJ\ p{U/$y֤oi'h4]W}VJ!1Wղh 4Ϩ~{Di锞(y0PIo$'Sӱm'gnNR.5cem0Ib"&dq1 U*-lP#,Ϟ&9 RD35sNK4".IG# NWW&%eA?P Cz;4TBgx)ieO S6C ▓R ݴ4&T1A>z\_d^z ѺFg {i_.KF"M|p0wWЄ3+=$(!\i_%s[qʻ ՎB8=@C$WMm m;1=hN3C&?uàEzgF .2 Q?3F4PoF+&+I iU^./m]yHQp̊+LlETdf ,1N]i iqrBuB5f_Et) {$*-L$YDpA㌱S]yV/bSܿ4d q="C`@<^gq\g|]67 ͥ_;#0} ?~N?jNUz& 0mxZ_MiB"$ʮZŹp+J*XU}K$@EȪ^%  9+2j]~M?e0r7 }țUarחrƹW?#@[K_z[Lu ${ڦb.AؾDP@e2DYتsHT12v}shN.T&\gI[rHX}/k\yT^u .Ю,.DhG'ZM< XNe9{l:~yX$Es6& „ ɇ&@"{j :pãVV>D-0i:^meD5;iљNKx#9w8<$(9/QґT9+xڳtdٌn9A#~4[ʝui5,Z xQ{{]RVWxiɪXeK 2]) .1Fmi#֢v2jfnsqx"sJm5csw&+9P}?pL,p;DbrgQ=nQWcNٓ=4=,;LaZM &&=Ri[<'D9y~d= UkV(#yrd&,f2fj+5YdfT /1t(]n*!V/sYk rq-A$ 2{l]>NghcxޞFbQ!IŴ[O L {Yopy7G2-``deߍvU;<`2(+,?C6,3-~zo* vP)oIKk@*Qр6:bt'ϔ\[q !1|9I.Ɗ9t:ɄcqFR96~IKY}B0C&}d}=H+H CVKz؊mѸ2mAdľn'x80Bd +ݸڅo&%t1{E υ7u}d9^ڵ])l@uGe0Bu-Z}Tf;4OC Wv1;thngTX,%UhP,+)RJ$.gwt` t"Ka H*k^P*smC@p_"'7L,-uhbwJ΁a+2kRŽT/.ʗehgK)Ow> q\2`N;*U`kW}Fx^9o+أ.*sz ߪ+07-, i#p. Ds* tjy`VNU_q [I$[2 p+_}%j9 ϱPP13|2vDbng40("eYhu6R~: oVWj1@x.ZoE X)xm5 ٩,l)Zڣ]{Eb4Qw鸫^U HC+||Љ,:`ŜUL==J7>e l_;2bN8ky%9 Md[Ɍܗ+` Ds/2HMPjwQIȼon&a3Hv2CaZ7=N`QF|mN pͽ< S}NfWZ*Ve%sJL| L,mqmT%px=tUu˙b7vҧ;C:27_PK~-)p{ ۴ucD7xT-ߑvB\s<^i74 y*Kh3z4Jқ=Se.a}873Z5IDF~n z^(Uq xaE_^t" ;F'/ /E툵jTnUڛLH{¡Wm\qxJ-"3I-ʗLHS)dfSHޙ0{X >h7Çuf`Ru6$06 OczXeuP*ʂV<^F' K,K-2Hxa2\q UL2%5WE&tжE)JL*q\ip~U7 FL #8 OB,2{ z̑ dERB4Uh4'wHȓ #hR A=ʓ=  xw74>vywT:"_pSFAO5^wgUCM:ZBxVpHLQFSNjكxYn13l~ɀQJɂ]45̲-C)REū( +a Lr%iJLL쫀V{qŞ*;J voؑ3]ULѴe$+]p5)WjD"1U&˽7m'k+uL3҆$ p3ΟꝎIy) \-vvMIB=Y/z;6`J؛h M s1 g`K5mhX6wj~V@B\ Me"uxoWLvED8"={ҰSWA2㷹_M !GgMQ|lC64M0PiU> 3ė_ a\\cCJ]ukDw4SPiטhZ U!ޤ0|h"VhJX[H#Z4x dVB)!'55R I.vu#Eቔaug:(_"dXVGՌ:2>X(̩ rw @m lH;m|~ ?z.+uMbI)QHԄT1ki)4LAP [bHow*Х ;,{#|+<kfҟAT ;#`u7k0d=4!gư <, ْ'52pUxE+ȕ'I'L$yEc35bhZLoQuR3t"ûz>MFqQ8+;bT﶐,b]pK}OޭרRܡRY5GЀZbv7(xLLH1^}w GهQ<Tb&0₹k>W^Jt0_=Va߂?සttn!5mY5J>A F~W~fYzvC.x *!5{e,BKhlV6]lLHNiWhP,jw!6~bEzhFK'VanS7D iS +,X9(xn洅\f y2~ =_'@-.`,!g=[7 GRTXvP)j>iW $"Ӊ{ ƨU w-ޕYn)46Ɇf6#EoW~wV89z3=S9"ߜV n,Ir2[,2Ԭ_\Y6 It/с5SY2`ϱ 0Xy&PPyl)tt&pGfܟooeTƨǓ0LgsxX Kc:b?!*iR4 {Q澂wGYǑ0-ey^I E?pK!M3fROrC; 0ݍ=*6%řjj9{bѬg i`t]1Lb3 tMu*ڣT7ߚV R˓nRܜg%>߼U£g]ͣ#IB[[Kb."0ڨed.+>c5'!x&=Ѥ]!*7wkdy+`F0⬄ H]8#Tj9 hMFPLCٹD!DdcBw!HY38WxZcj۹mpophTVr//k<??*(չLKF%CSRq>+0d%6v.~ZNkSت NV'|d">"8)(`;~hsG4q,6ݨűTK\< hiؽ-p4KMy\h18i 4[x`xʐ=.2 3F6x4؀mTtZP9BoMLu$ѸbŁәXUb QdTȖtҪ9ˁ4:8SD$y",S^hDw}W,zG\t&xI| @?{\O*k)4 TtPǒ'wtgnkiR%EJt'=^$;5lrc߶fn28rqRjÍ13S)l(GCtllWY c#<ҙ$4}"3Phlha)ز}†BPjx)f䍈4 Q\XJ8rK̸^A*~yK:mhģʆ7wՈ"\ 19 <޹.:ȏ󁊧X6 t.:@6h9V@\Vpfbb%)H=*9sE%>iaS6YS7x옖/뱥3AbRy#f`]IF#"Oh0toDԶQNR YZ