sssd-ad-1.11.7-6.fc20$>Έ4Lo|;><?d   4 (<Z`h     2Pl%H%%TX](l8t9 :3wG\HtIXY\]^ bdbegfjlltuvw@xXypCsssd-ad1.11.76.fc20The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.Ubuildvm-22.phx2.fedoraproject.org2Fedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/System (%A큤UUT1UUU7af81e90283dcd5324e955c98ceca3f46ef75e8d5e478af75c0b898b8e066fa58ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903675fe8c51a7f715db5f   @ T@T$T$TwT Sh@Sh@SG@SCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.1-6Lukas Slebodnik - 1.11.1-5Jakub Hrozek - 1.11.7-4Jakub Hrozek - 1.11.7-3Jakub Hrozek - 1.11.7-2Jakub Hrozek - 1.11.7-1Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - Hrozek - Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- backport fixes from upstream- sssd_be crashes in nested LDAP code in case of ldap error - Resolves: rhbz#1126557- Backport an upstream patch to ignore PAC verification failures- Fix a sysdb lookup error that resulted in IFP not returning subdomain users- update the libldb requirement to 1.1.17, which is required by Samba- New upstream release 1.11.7 - Start before systemd-user-sessions.service and Do not crash on resolving group SIDs in IPA server mode- New upstream release 1.11.6 - New upstream release - New upstream release 1.11.5 - Remove upstreamed patch - Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - New upstream release 1.11.2 - Remove upstreamed patches - Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - New upstream release 1.10.1 - sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for New upstream release 1.7.0 - - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)fruk1.11.7-6.fc201.11.7-6.fc20libsss_ad.sosssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib64/sssd//usr/share/doc//usr/share/doc/sssd-ad//usr/share/man/fr/man5//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c8d34b826f85f2bdfdf138bd24cd042aa2adf82a, strippeddirectoryASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)PRRRRRRRRRR RRRRR R RRRRRRRRR RR RR ?@7zXZ !PH6]"k%bP}zK抯Ohܔ=iSE2z`)9ŧT ZV.oa^p"m (BkZ UomFRU,'Zyon&GdY|%uOfA?ScJڌ]'MBBr7OW5MݻTJZ;68?WKGum;S=-[LJnj6 ĬQ.4$:" XVyGQ /G>وGnFsTpvG)ekW!{–-4)K6l3 e, G zU˹GT|CT f `n#$)1J+!H,i6sG,/ִ= -(^Ъ6<΃g~a9^-' Wӭ=@D=jklF~&= ż.h3̪X i_A3_aDswLt1=+)r겠"FOYC(U~B̲nQ iQ[4 hi6It?DXV,rܸ\`Mlr^+p >§$(vSN" Sy=Gǭh\Cm>D7ɐʊFZ>s;tܼ˨K~MojpPWjI wȧaU,CsDPu]DܪZObsdפo}4sNofu>ZJ,BmР˲.\S{Ɂ2Wμk='"I{b${X'?z9,`4C ]:̻u؊`F/Fֈ~D3HE@D_0ӁqG)fNԁ 6gcm h%NXwXD 9&d(J>J/c83eqy `}{꤅AVp8Md|Yop$n!h()yuU8︑.rr6?zsGsj]YRZG-1RRؽgCy>SQ!qcʾ#U2F羣Q*9[3a y7ϰw~4'_ISx.v;_ KSJ 3jO/E!h j[ WFϞfY9xnIpw@7ܺ&ø2Rj&iH-UP>X#Lj 'zzpˋe"N=I:|g\mP ^ @a *XaM,R$&xPu}y3 LZ|ыEPP)ףUfw wrl+ߎʉ_@϶btLpj}1Ab޸!Zc#u뛒yA8b+2#ob&)7* ֿy.)0ѥnsԍXotpjPi-lB.ˀ^uѩ.$:|)~`[VvXWd\PQbAg"!m_J3s4#Z3Vܾ\|YEraEUj{3ϩM`T^ xFb ?gH31d?YhRX#x7{6)Lܖms5K!;@a^k"[LN/Nu1LV'%W5V* O[a}6T1NE<3Rƴ(0 "{9Q)*⇚+GLuݿIeg97ɝbRRޚ`s x[8s׶V# rfO(˾}96ZFeY 3\?2̲"OQTQ۲$qɳTx;xv8 0pr58@1MD&}l)Sx :pn~'̊ C)[E+HQU J[I U5!HZ 9c ]K$Sl%~Djߨ|̏Gl.Ok\}*-P#@K=1J_*t~bybnVSop^`p<#=e3,S_ ៪&U|℮gzWH6H٨ݒt6 ǫz+Q|FL–mCiɈnmJ6DjRvKbO=4cc=nqr%X/$=D{M`!Aʠx)h)KFեeIe:Ué詥 h[/k _ C{|ǹM)eӼ9 W1\اXck=y^6 VyUͣm|E>Ҧob MDG+TwsMogom!2~5?5V]wJ~!)Je^ igއ ?ƒ1I%VN})1kȕ93k|Xo!x!`O<_~2U0aMJwvCblX3nskq]E~4xE7eoWBP[NjRVz?;q ἔ^Q] lM6qD^D~% ^)o] Iޗ}b#jB"lrMN=ht9&w/ H{. !!E5Šu8n5=#qϮ+aV(;7RjKu/&$=ݒNx+`>x:7#GOr{O]M+C^ Nҳc\x<EvfO6? g S! x|tPs'c7֞{x 3}6L3ҭ6+LbihIw ] `#[@V;MZִ1=mHDLl}o;F{5H^ײ%,9ڪjdxwׂWx`]Y1r7R6tb`cl-9unO!'un7wbZST>O~ , bKj7BF޼Z|1kB@ZucOϤZ\JmZv#gC)b㌛s/mڼ2>YI E1l;U8ۛ WF6N-P•L4Z}1,?zH\A-obq:V>9'o :R'ҕ"ـ*o-HvpS +.H$EШQ?iGzǚ K鰛y=} G|g`<Q'Ia6 o|#N<7ҡ#)Fq&O2V)ldVHoRAZX+k53Ej̈HRa߯7eBcAG,3TI$xA[ȁ'35<.|3R>wwݽ!R6V2jV7$mz`9 ~gJ琴}Ʊϓ%u$D"#k%COmCK`fVO(!X%lZQEW0Yx)L~N[OKx+~Dd.qTQ,.>^N8 gfphSYsͯt:Y2bŊXGnewRAت pL_C oۤǿ<]wfK+v>CT/5S毿*Vímff?47Cv8ͧi{їpR 0ܱ҃͘eZJ@I+nҵŃ?a!]I'lt*znR3Q6Qla%ÛAEr2SF yzOJ B)ҹ5[Aʥj6&+\< oy%1C@ w9nutMzP? pJ q=% 2rQbBzZE69ʥ@FKEev\{'I_[{IR`j۸I{\T R*~CGnM.'Og`^$_,b+3د"GX[2jRB hsjQإ]DzU~$[ߣ9'~-`W/3MʦzVH5Y3Z 4)E:`ՓPQ sEXZcPֻ_Eyy9&vKB;enA˸I1۳ oq 䜌,i^h"T)ga[F_6O)O{sIwvY/BX[v40&{E'OXm>y4e°jIJBc+u j," 3\"/}ѳ}piqBwP\xnđx*0}9["U~}ʁĿN^RAd |Txm)aO,D֑_mI͢-r38m.y#+bqL=M>ϼFӑ7CtB4 ƞw`iapSN^i:yVrKV951蝦/^dl5g] ' V`NbR#˵(Z*]2qs럆Gqb_:WnRs,ڜL;&k!'dl{λ}mbEYU8ؐDiFc- +N6 T@ú4[%v$%be2& L IDfFYs/I Tw(GxqV`Tkbѣ\SD0tQ 47nj;*LAp-acoi_C7:::A.DiѸu޻qUc/~H&cCgVwh=9\(@ 03:[˔ TAOd>u­Ǯ^Dmv늽;Vu\m+'"\qeĽ -X'I3ʀ{KI Br%e+$^Og,jͻRpHm?ioPF<}\p g dޔpm2n<6~ڧo8]gՆgwɣ1M: l_cM}9MoK ݹɄF=`giv_fu /:_wL#h e PtiX 4 nC >F4ŰL-Bwեh'9lff fxF'ymMG~Hٍ@@Pz8DQn>>*:~e%Oj >;.I2Tr'>쌘5M78Mv,jz}sP[CXr4rCT1ݓ wr"wO ':kIi/D.^)zCs僟IqMdTEPhV.hc6t+ja?I )vr(MNi{i؜5!m}!{7_{dpYf:,՞(`j.TՉ[@:_DoBqnsJ3񋒒mF)AO)Aj?}b=|p: V4̘3A'-zP/nƷ҈(#6B&uKAuk?TPɱJ}C@ Ie:yid4 Qґ\q)\YQH CyHBzv;#֖Fh9כB 9%#.뷜~ηvb[;ZdV.Ž$xM rhm T=m%+}eފs]rWgYUB&[oV0"8kObVӑ)ByM1V{}=W&&\;Cac `GCZאx5 ?$=0yZz/:N #c@UV0Ab徍:UoJAm/&q5I˩-nx9zXgf=3h.M(eb%ձ=;Qz/eEzCЂ LC璁,l-ݿܴ2 mIb ?OWyY@Q9 '~hk$pMnnmGA(Oe6LP(0nTCq!K 2¿쟣$maƩQ ԊIh߫ʆYwђh 4*2y>Wg~|^Fm?~8u+ SBvWalC0_02)6qWE mJa}WElr \~ ڢk7eVG|b3%@<I1~c7owwu׿vy_S':_)~VyʮYƽ~A0q :Lۑa4DДVb޷hHCH& Bf[PjU_ icw #2 M+Į:XBG&'{KkK9=&}\N8GAnh<6=C("gNIPP:Xwp +ڦ -R6svaDk=n۞)(}#{7n,G{]rD}6s[oږ!9~=R;BJe(m xӘ"vz8贖$0>Y".}~;p`+ط#`:fj͟v{3@6R|vcw E(NaZ3`91aݪ28%ZAF+8t3 >d']DYhNə^q t(rp _T=G,Sйb*5h%%=T9s$v Lԟ~_ %`]VHrI/вCGM+wɦª[_p10eԜtv\-i4Yl/8>\v 6/I4Y{B#iO/13Ptq㟺WG`惵uvA[ Wq Nl+#Mo#Q $~k|Fj;+]KN~vCުؤ7%Kn,ȄQȶ92n0L[FΓ~>XlZtiwEI /+=?'& `c]iTKzTmfw]"\0.o |"L]bs pb4ED_$d27OY7 8Г9|Ht3(|*ά*AVf٧g<6fet]GJZ)?w!@dٴ9G3OvEwc.%esi 0%qj:1c/2?x>)@I5tPQǤATH%sWXiSX%<+{KB8ͣOJDqZYH< "<~.o15@ T*_j +]?x^/t]$?)9Py0̍d Ǟ.{W&mC@ JW !4 $Wo>Qhn6mI.*XGu/_!hÒ[ "א[;:~\f?>ԧhO}C!i1y"'p lZpsҼ7Ȼla^o[|9&1*1ٖ%R3gs@2iНL8J_ыݫ vӾO (*xmڦphFGy^r 'Q ws yPL|>dR "lsh17vK*oC^ \Q_2֟oZY&HW*b%y)z9nPUWaL~-Ng tvխ38Zp9g˰VE6\x2;tHkx{7aq-_2CRJ-Jrl0e%Ezdt)boxBN\xIx/ƚiXo4-ʱzui mһs!\ֹ3t'o.sđ:d&:9?#>ɍ(ݒAƾsMm#srZnSu\lG荹^{ e?ǭp"C~ME \iw]ױoA YFm@z6Z/'vby?NEt_:ĒW@& iAfH)Z]oSԗ-fĜ k]D7"/,^/8ُ4L 'VnTdJsX*Oξr1 ɒhGb,U7'0] 4#JjwJiƭY+n4p@v+x*hrVnq,3MeKh "Wݠ*iĹR`pe*jV0BյW@B K۴`UhTmѱxY##N ,\4_R]P ble#=fr.6$[KaNr_Ukw%M4.mb wĀw4{S.IOS;7nK@X#%-% L Br%u?cZ)Rڅjp%S(Ay wQM YpϦhގF BUQH OIܭ=p"2&Ak<m\*v)p=X(rlO3`Sk/ln 7`K/$R?D\;Tp98.}Z>z%nOlQ PElg菷 k>l3T̩Po&FzgUa*2j Մ=fRjˣ-?<' (NuY-JܡtUqq^VH?ZE;XH MCr U yuf;> QW<[xZaHCJWAu~Hvkn|:\3V2$95ě BF5ͮ LQ6s& oޗsVVZUMڢ>c]W.z]J60_j-S6[3p#* ,0Cba; OɼMwO8 a虢N 摾{)qG6%ܰ#ӮV#`l5 x+ H/smls!,_j.*y~d o H)[jI~킲Th+q?ZxGZHîb7UyNfX>z.Vni=/⏨wJ(@|Um>3FgіeLɽMr ͣ :mzzn?Ѩl 4B Xb+,zi*|/ x|/% }`{P15ɦ3cze{m̘cgWpQ vG3 [w2ˢ¼_:խs$*~W{cx;9)$6I9݌{Z"Ď$Xɺd]-{!n1LTӼfpJwPpu0fЋRBzy; 8ˬ>jqoZ k%?K:5~߳`~Hc]3GN5) 7P&| i# S!Kn{lG[PWMN Tyτ}bR7Vo6Q24L}J-@u^\Uhe38@k)W>Tz< ,eW„1%kpMZqə}tMB)1 |NBtSߋRj_A.P_:xd}bucm̅VeW/qRbG0>me] p$iM +~6!<\[7něM͘yNE YJj tncRi1LTi|g(VEc#ZV\ƐQZފ7"B^+U)f̃\8k ^5ۖͿkh܅rn%͌3v6 ژ~8`.vv .q961|V̱_ܶۛF址 O+ױG&4N٭R Ս쟆6ڗm-$e}RV s K5+L"<*(.iyB&?u QJ5Lu8TPQmNR4Q$ζ( $hǧ5S(W,1Ϲ(MK(F.Af,61zBzmIn;td6[v }sیFlL(gX4zQ8N09}lTEb4vRl'}K3Alݭ\"ه̴E@; .U\,u=~T:AgbIukbiw@i)o$K1Ѵd7~dA/ѝg&7IhP#EI 'AE-t_QKvRh3lrjPc.s]P [!F^ I漁dd@* хGHԵ4 ܬJOUetsM_FɈ_煣e<V杚ALw)/*0pǀi ֥Wx=pS ?YƳzv/p:ܮ߉_ ʵ?۲ya`GMZ:y:I dk+BW=TQj=ݙZÛ}cD2?͔bJP9xM[9L EeaF|ї6@_+LxQ@ϒ=/}$c݈jGe^e|ǤHٽf C.PƒӋt;w5hu@йz6%EH}E<M^J9 ;ji#~~fNTKV Ǧ =/i蔏 2_9jT%!q;Vo&e%8=ZD=DK |ݿXisbAs6avDd >X qGpzą'8,$[lk^;kv|T=3鏸J.?Z/[K"(PK#>n8:qH%*n8G6Z+A}ǁIu:g}X~dxGk26G1OQXLDus!PN3iNoMuhN44u[z0zh3?~G+}7㉣Dz_1R?ę-m:ع(Rݧ:=Fmz;HR3>r@ :r>Z[r`s/M-'Ur(2q'] z :,be%c}GQANJE w Fʜ\+&ǭࡈ"' ;[PtխȂD~N8R(}NLJu'Ut^11w`hfofvrr?|=s8ڞ[3u./frח_Wx(,b۞ڹxzZ46%*o{^~hǍ3YK. XtVD{N" cz/ m7†-7}*ʛJeCh:%1.N~8CD&l,q?IͿA2039'{"jA"`gVX5=Rc Q)kAoӄTPax[SⰁ@*Enq0ߏTœvcM:PN:X [YvtP!@4;oU 2/02ĵv$MiBQW}&(%x˲H射~ ɢ+,(CQRs~ut~սуrЀ8a"fѓ %NuA}}[!4gɽmǝ-Lڭ"HOTP\q45 9ŒGJ z [jؠXwLZ>e̓Dl Y5 D;.1%ZeCh9Q g_^Q)*Ȇި4{K7bKU.ړ 8*15w$C鼍 M ka:'u> #xdsWC-.i /AL~in*MCK6J:wa^1ln+: jf Td%se7dV׳jUΡTnݕ~ׇY> ac7DUMnkIf@vj4ʹm>?>T$Y:JRY_j}ZPL{dH.O$ a?j&M `L )!<H&P[ueZsιIBA7# )Pi\ wc]yC rFt'f3&DYlW__i9xd@W{Ly`/ V{"▵,~Ǐ{bVa8US6ۄ2ԛbDcQ5>p%X!갾wsy3s  ښ]eaZ>r\ԬHG};Y$ Odv̀1Dw] oܼd FSRrJnZ4P_ψhQXW!N vwDliNE9nRr\c( մ\]'th_@0T:kJU "0a< t ^UT_?%<_^9:jߵh/P.琼%xU\h0@UNm]S\ԿN<0[3$ csP[镄/fxSn@=["JXx -{cJ:F/9xV42ĉ[7n: ֠[efPZ$|n6z,BxG`\I+"oG9[q`w22>m_6c&t@l!;i7 GpN!*zpKVu(jF:3aL2+??-ϊ7c/-^yd?O) n$2|xjP1αIajNS.kQg:""ul2,,{@ l'E\b}s=WeoפnU[;^>E|q?t)F5_Zl0Mޙ}aqL#cYX vO/?P4@gwMWeS;:CO2yfC@87h5bBW&ayt&C5ʼtviƟ R7b=֓:ezV*ceIKk~BC +dm&Y; zJxp'$OI߱֫` p9C}OkA3 DZDx'WUi Nneld1k;`)wAQ79 ~j#~31ʆ4-폭'uy/ibSen|<ƷE2g?ZBdR)e5U\Pq=ј PҹSYA=7 GY=/U;sX͌.-Լg1F!UsţAODe>K] @\X`=`#tDtǖ4+IOAc5S4zJc}7?# ӪȾB'L g#zG&;F@JY]01 x1C:QuFh\?S 1NNγvw{!j"Г֚˪95x0],TsY705(0-2~rǀP bZ6i]u2\ʊ3X;5%݄?ɴꈝ'@ӡ W8ZV@pS:lAdl&tGFu?#ѽv=dv$ 3Ap0}:GtD 06C4>z{

٠AnQB!Ƿ~]ȲC׻bQ06۞"I^HfZv= XSĚ zD lz@zN6{ۋp#f5%iT´z$!G$s>F=yM e^{|f~t.H#(ˣǯ ߘN`w Z%b^+Ra4@fgݜk&je!Lr;zo 5q]atXd6Z9O͸E0!8euaQJ:{ R. 3z6XYa8VF=E <~E:{Nc!4VD.C:7*1}Ui$lAC- q}X8$4a7~4 rk~ZmHgwxV`bhS ~`T^Cfe!=9?hz OY× zmd՘>;i@oG "kDZl)z8@,梽HM4<4k9VC-c±\騟]vubpVF' B`ثarp_7٫#%0d"WE*lVhXcͮbrp:Z-D6w,K <=NQrv;Yl#9yr>UBhƱ"<8>y 6B) .I$A42%^9GJDg:`dxlcVC+`B4\E1Tϰ5/@8wgy7aB!^7aKW GxeJA' g pU \yL/Q3OroنN՞J;Ub,:Nɣo=9C+Lz qm`ޫT_$Qi5!}&?:]q7DoL;QqKW9 ?Ҿ { G7a``&Pj QK蚤s~ɤ4`2;Xtmx\mb[M߬ aƜORm/ ^U3@EK:/7dRUciXr09jUCw's>C\n+=KyXQN$hč|+6{BrĤtժ1?V~OF %:CZ!?A --S61 ,GZ.v^%- e~cVc~o+2ep^[1@7$9vDδvѾv>B6\=ʼ`Q2^MH6ZXPDKjn!:zgc3 셾fEDhNC9ES AGΗOF~:3v 54W~)ߏx>#ࢪYE02bnl]Yq&h JpROXr^Ͻ4&Сj\R 0݁>dB>yftQ)I!i(E@}电H]KD(.Ԥ*hveU#y_#献cqKyA|a 0 wO01;pX 8<( e(ȣrjD*_h[X"+R3 Hm$}C9#94b GflvƯ-s64%~=ES{դfb%`~ F2t)bt>2.pέ'y͠2*]rȓ,b."#LswnUC~qXߵHxtôYVz[8lxerkUWY Q<9z1v&`Q%0dk)HUEȧn8L[WyZ{IVIcg޲7uLu~H%g":Y Ѵ$>@hE7:EJ-Jl湵WԷ546U,1,(Y]fFDJbo|'"bii|-„ ZOdB; R4]K]޵,%cK _^m+GQ"4=#4Q\Bw'I, *QcF $Z.P.s>#a9#3-;ڞV Q{q7SBQʱKdޏȖ$HWF0;ԇ,m_ l" PlwtQZ9n IXŚȕxo ] :hvYp8>W{ \!]pJvnt H \6 J,4E:%4^0C -_sl tHHt5c`݋0^qG)_~g[G/E\]ܿ}u=E*/^lGRGswXU !`$;d%c; (f@Ltc;*UݟaV||# _ʘCG喾7ȅ¼F7(AːgU_Ю]CV8=Ȳ?Z?f2kVMt< b YjeFw 6#Bh)(.W5I2Pw~KdMIw_Vg1۽kmSɐ7*fMVL|!X i-N0Ӎxq;R,iiZ92WOZJYcDSؤ*N)alSͦf`3I,`o ˨R3>㸍d(P;q fg(9\ei0B`o/(N]&"tH΀Td4{4A*jRԞؘaoH<wŹ%׎(vӜBm"W0JC@K}; <)8oկT  =don(.rqW}0:hr#| ;FEn=Ƀ%hM^{ʞ6Q: j@}{ePc>Lu.yb>oSj' (\Y$NY-^޽Se$o!sc$"=}@R;i&]hd? D cݡ|(%[/߽-zD?Kכ 3 4keOxw7R&P^OVo& w)*>W5p ;mrpJ4kr2eLJӱ)tquh;񕲊†|"iQd&ٔc@0v [>c޹DhA5-Tמ|HoW: jۺ$9Bc6ZIvԭ)΄ VFZf}(L;abu JC2^O)&-~?9 :ʚDqfɘMB7Q8t3J9^M^dy>Ś?+Yi4h/c{@53D.4YmD?vAA E!LH/-_V ˓ 9m dJ=x*7 qceb?菉 c07e*.-6p B։/`"962$rdZC;Y L:߹ƾԮ~i+C<Q^~,p[sÈ*b/v%xe.16u\ѭ.k[>W;Xyֿۡ&5Ҷ /G`% Da/ mT VPi: SKJ{y>g~j{,  xuoNo(F'"˚١K [6Cd|;tEԲ ?VJՍEl;FǕ\fdL[U 7䡟*?$ζGRo8.&8Rr9jjBX hʜ/&|` ,Ԁ`ͲS:3~63* \NFK*'KI3❸Y22JL+O3~i]v05ftѨ]\fmd_k[/+62;VrG7 ԿGXTN#eC4;)*Y}by02X;#~_{SW{V~Q'`w E")xШcpozg:prEq<(;)e3_w2gjZ{K"hG/*y2&Z 8˴VP\l_jX~\sZٽ5?:4 Ӊ"*v6Z x;[ˡ" zxoۖB l`>-:q봷@ Nn|gv_᪕Ʊk\03ׯWe]჉G C4 2{' AVXg3pg+֎<9Q=D+CxB<C| ΉQp c]G^&RDzgHBl`@4}^B:dՙNb2m©U fsUw;Z 3"2 17W*%eʶ @@>?eҀDᒷpXsDk W"'⹪e[SK6Y/?% j9n :O- ;2hl[gO}- eWSx*/X됀* \B**z58bd N'n4qr TgM]p]A]PQaѕbM#7ٞqXgVG$3{sAhT ; ne,{OaȜG]gM E/(j'تѧLԮ98iW aIcGcx5e xEz},N4!168UgPYZ2W:TxلGtߘ~gn'H^2Ay $׽tGsD,ۋ" Elje*:֑wtҔӄ. a>M$ ]ZՇ8-$ @-5tY6B-ApO)H{Ns<\%nsOl PۆuL^EDk׸ 5*$5Oq{Je`02$#]v?q4 80ǘo84SdF`W{t > VCI\ @Ggf!% Ԓ'^x0Zꘞ|٥`,X{& m#}nW!6T1&k\=x2Aɝ_xkL Z˵T=:X ZoAN!Xpjlnr7^9Y@7T 1<*ėU2Ơqw`@É܊}a&,~D}0"+JB9x+#uP`ѵdsSU/&aLG/ SFV711@;@ma7t[Z|@SCɶRI$ehS$ې@"2ەȩO(AUo=\fS4(Mپl%$c&΃6pRx8_`ksC{f:`6扛|w?䮕(Ѹʱӛnv^!m+3 ъ _GJꚸ.pO2b{jNGq).J('0 _mU88+Eԭa 1/[!Ҷe'Ea۶ ~H(c868"BH}!(hM Bv~۷o!_:#k5 Ur{VqShȩNxcD^yqEIH1p~u{>}[REKmރd<}V@BC]gkR\̸{opGb wt-m |0!_R7w|_~)l QVQ,ܠ#=G=˕Ѭl 1 q[L$⊢3%ӛXe:mr$tEGHb~U#j\9Ƣ~wW@˧Ƚ`W%xtpoJ{onjuL{_|mDSpk!65\1lY/xmٙ._l-˩_ڐ/>ޒQ%2 v e+4xHy J* L"8:|s,©YԼzǮ[V py(7;Ys0˽XC( %o\A2}e)J 9B߼/؎QT/Yz밬>;d<΂+eJ:xgYu4O{?@"d@8;:Paq꿯}kϒ8Gd4^ڭ,0}q=7V553SԉFn3hU XV6 *~fښ#ȏ9tjҩ꒟jV C8<Cp3z1`C۬ĻcPEn'orL,&dɭTA aIIyMD8/9bw^W1ַ/I9f:ȶE2vU/WiC Vqa1t䐿4Pk8RU팰_CGTV )s) ]nh|&pG*Fpljv~te%`]9fOsbBYsfz6't?k%VK89"4M% q.qLH"~쐧_et6h}K_W203Ft=0_lN\[۠_t<^e]f%M- }R(ua)_P 6@~g9j#x}Ͻ|:8$m3G{شv*FqeāڶVC49}{SÀ#.IDѡ|?J2s 0 `5M;Lj?M2gg<{g0-CCj=.'~ xa"/pCi\FJ;-ڔT(@E0|e@2+5hp QRn0}J4-ɸu,qzv!c\68|6076Ia I'KS8}Jw')¨ƒ_rG+C}=m(#OO½[Vߨ>_D֓gC?&P=BnulǖX{0Np5H>X?V3% 8.4KL_8wdL#ʂ[am'% d6 Y%8CtD tXi,.#S98mp wTȆ2`=Zqa,s$O0[s2ḑΘWpO 6,2}VTwkT}DF'MNǑP)N[=0z .GM'U}eܛI=H#d(#dbŐx[8o#Hy6큄DK0&}nCB6]QILߔYE-Rav_`On}kw׌˧cclTI>Wa_Vԙ싓Y ; c"ȥfl(TCߚ>giF,ݗ+.E}uFQstoω6K!2!Lעx# 4!4V%T'V$G @E =|g;**]?W|Q[So3Y>>5W@"1`fl/* m@3yxJ\'tA%zx0N.BA1n+dflxGina4%m>_o\"arGߠ O5 o?zֵkJe^QQ n0F U`plÝ`/`,写utR@]ء]ݘo$0T6ol(`bv%</}nf aCyiUHj(5~:tqǦ5=LP[[Խ:W󭟠L>PҰ\ept9:e.CP|Q!zj- K[ qïe4bsH,Qy DjWuA ݇mhn;M[Uy-Pq'{sn)2)O_a11>#2Z?lLQ%A l fZY(7'O[&;{zE8 d\_􃼦Ⱥ7CHg֌B(?K0MM:[Ql ůIʦ-B"V8:ܑcwCSWlDȕV, \Q7@VczEV/tj"ŀwɷM A~wAY2΄sXzG) EjJl8/u] UdguG/b:1DKa:IYw)<Q>O!Vd+-1?9CS t=TV%_y*N(4(2l&6WӎOկ *3P[z9.=*G-Ŝ:oZ糉f"Uy ۥ2A#kF/rB[M|Rh7~@J砎팰M=>isQi<'Gz0-5uÒUe+Swy?;Pԑp׌.e]~j8KhT.x"AWx>/LD[s*Ǎ!Xɼ}I?i3> e%Ja<}'E x,ߚ m@ILֲF? W* 3<j Ғ #r1A. . G}r:!ɒ _\jڽrPHp(Ak!6u"Ԅg)]gjr1G@yNiC^ =^3gϡ;1}7Mht-:|(|g#o&n*K ĬpJhg}T<*Qx{}P_ͷ{em̀W|x71w$*'SI7ZzEu< j:h6 ccBj;@bA&, ?G"(F͗u >Ҁy~{# S]2y DѫG̸ "%drѮW4 le }JX<"n&؈m:eǛU /Ye/|!YS8B 'J_k8|OLw׏ TV%jB_ Ҟ!x ͼGm)_"Om)#ITS0uO%P'Sص\OV2 {ꩭzX=q&˙#%uvSbn6Dof݋?ܞF($Kg$2tA*i_at {eD.\u(Вz-l;%Xq۴¶ a$`DiZ͑7uMԾ>.Um[4wLdO9S= E3qj Fdz "O&ºT[F~34RE|ԵI6а.rЃՋb(>0J Jth,sA;Hʔac fǽgM]K_>Fלd4WpwثCiky㕿 tNE_2INY@he1Tq8V\ $.=j GpD{YYU ں} (L#2kʭ;UdQg+B..O7"zvZVI]dbB6KY""oI>_r5Y? 5A6}%V!ay<]AE8"S;lxP&_4,ryk\}'YoK9ʳC넍yBŽb0 k(2{ļH$t9+Ͻ8!?9kZC qB$y}~U3%Γrd)O?C7nROax$@z~G^XYbZRp 38]1SDŽTpG`7P`ob|J:ʱI˪)}tgE(}MwW-{޸Ss.$NDQT^(;C@A43hg:S+*z7᠑U.ShXUdol*E>(1DzS'l{~\JkhDfN=rpcݹҎ t!dLQ;:ze9OF`nkawƦt| [$8tF1ot#6J` H?YEA:zGbtj9{Η!Дa޹e嵯mpSVďqB0QLSVU ّ[ [E7H#fTy_H wm<a[P,upyK: Dd7=8dDmU) >9CEW}'9KCBbPUȓQ+y_āHYIC"/͎&q2cU{=rHc>6(&Z }=)ؓXp qNk{ `M-].ZXj#[ 0NzA&;$CLMKzuƟ8MЌ's%ыN+4r`2Q!aFd&^8<[i;2)%q:N M"2UcW`/NQ ?,GFty%y ^ `A,}>FY&κz|u9:\poo_`1&+%N$qg1'_bu[QIwV< 7ԣCH抏 o̶6 k\w,P%4bbhW Mh~)&`ocWշ/k. vvtsX+}cw _Ԓh질;oefR]T+gu6>eLJ6x(ց>WҊg;mȌEݍr'LuM6kXKnU6J-OҊC^6+s9/\+t@ ֋j]ʨ\]#e&ퟞIJY?8!+gBj.:vM @D|ym{S:\aPcnڄpp_eX l j)#7( e9KwY3æQr4̵^] ^ Ae\iȓ-PWXcjCh=+m%4ϵ1MK|_E!uwa MIW2~Z[wLm t8{y‘3(y խiޟ");١ n5D]Fi["X!9cuv"oW qԓ}kUнs~0-f#vA*]\ɯBW_uM#i;WptPDPAN+;X!LGfE3(JhqJ2t襷GF(rΝag2;ȑzpv 4IvPǦ‰Ca<`Z$:3xYӍysJ | K])|-SxSQ@BqH;|='-+W`C% KRpҪެ/x’3v,hZEPt+Emؒ~PI^uFt74qhT\/n1%h钝Ja4b2$\0x߯n D#*+Aru v&ANe%߂77T~FCjmbdQקeH }߅̄ B\-aǔyFgZ!SbP4}[wF'UTe_ՅTVƗggҽl$l_dOI8eb{{ Xr%LM6feBX\CTw}_[IFe:FO䔟M2YGQPzY-{n"FPWEߙkqvy{Sܘn$yx 7!Ϙ f\W7O]NE ~jh :~Gii .KL(&@vZgFMxڻ_hŝÁ%~r g/ [^}tQFh =0+u-01F̘&DnE:Mm]bhpԻY雝vV_1;ntC׵;0}5ym26"*n-KŦ pcwǐP'۠*U_ `t+sQ̬Itab/IJC9t&eNAU>`v|#:-gTgٔCRќ uBM}r|\y.ҙӪ#7KJMsiX=O!Vъl0|hWn%q= |d3x| ݌b,[PIz)ý6hu9vE q?Orݎ>2:Fmy$rJOP\`+]BgMa zPקlhęEI:m0 l =Ӕtnt[OyXnvSֺ3Uh\C¤+L ɭ̽Br'C 1KNj7K|-p<5?#pOPo6VG>Wفo=BEwݹ>$D_(7F/O)]DUE΅{=dvm;]dRc Jq d:uSM5p8g?!-LgR +,鿇nww%ji++"X23{;6N,com}kL^p LRQQU,1Hu"igtP-*e6;MnGSWdKާF@Oz I pC䉻7N>GS5{8-Isa3"nyA@-I˭0ü᝺R_J̚"7gjykpMt<d_jMN3ج(%3_L5bJ4R9X'E(=j.q!>k0MA5+yaxC}ףt\V?(A\U{b[=oЇ/mVn| r1P儍Żl)H=G{Jl;I~#BLDXh[Q|pГ;8_7<ˡTh99~;Ls0Tڥ&%y6iG`DyƐr|Ƹ>i %X¦i UJi@h.f8Ve]IE' BQ*Hk I'g_ =hwFN}JpPǽÃj|ؚ_+) 0qDu= (V("u$a-$[TY6aZw ǔ*׿mer/ԝ+I;%V 5TTQ UEb=a"z2_`Jfx fA$Ӹ%*[]ěW@`!H3%QKas0yՌ-fRu'ߝcci{=~N7$VV/npp t-ȝJ #^ "j4-xr%ړ 'TCKRɐiObq7 )N>-U"(FvܮoDviL+|ҕU#cWRdeqZ/M͌Q6W]qU^7%eJq[Q[NLy(nZx_%b`KZ~Brdm9NsN6;? (ԠjŤ |w@٩*WP4T1I3Z/wqgW S:2iM8bs=j_[XHWޥʌ]n!Wh[4E.a3eMr2_r]AX % M8TlC$0:;o`^i6}E :*'To5*}P9Y͑SG-'WX~ ڽͤF\|[(CaxI!ҷȡO-,lQ ՞7B F ?℁#.'k5tݰ!!fQ]AӉ[]/^{1!STYȕ\Xw<f:= nD`XOGc[W@^.YU^RaURt]ϋ|OmM.`ğq5%yrj~?#jmIQ(j{,+ܨ)zz 11'X;*vtقO]$' B]ǭG6jsu$9\!<_KJA OjHٷU4%IV"d>I,jp]#,1HNby\lɖw+8`@`Csz҂PZ%J{a=`!YN)k:w߱a pUAkoyZ> 6? L_&B5GIȘ) -U"LR(#1y"vy;;JtyA ^ ST:[K9ZQ%( 4ѷʕiUEzRSzO4!4&$eUz!L},aSdGC!9Asq*!_X5.|xalLlo2}Nz;]mTTK@1wyPDS[Iϋ0A&F@UX)W0!XāQdTb b[]9,A vKFk3ƕj~3F&wTM l򀋣"5ܱ~ _Z0tHӣCz9cBӂcw%GJ7q OF +QpV@&.Ю ϛ|pcL}#3U"+R5A`\Hm?6,$s4*u1ܣ*~w/ P,{H`qvKr4$ppRu|ո6jZ'rm,p!t'zm`I t|G:e.$]D 5^j&nd7Op83I0E͗ 0 k)Gb07+zZ^pnOPn굑ӹΣ0F׽(4>{Moc1K =6pErPx%h>!;]2 QYv(oW~T̋oUе?09~G 2QtoeTr^2_h9<5P?hO;M*_S;M[1Qh8YR'E:ݢMC!YPP]n& xOCH@$q?+FI!n!^);y+n>Z]4*_*lc,mdy$kn[PJEQN’ tGopb&>,%-z AU6$Q8O'9 F.UHS&t F۲9,QgC܆Dy&j93!@,V.\T3mhK_T8[P?SlqV3"ҽg:kki52G`1 K'r) Á:mخQe @X⡨ɖf"1n`藙ftib`E+{ۅ%K7 !=sG S GWAs5R-- M}Mv@XՊFtTSyCCY~&N<$d|+/8ZE ${̞K:E7C^: Z8jz򒆥)Y@i4g%RgXS'uJ䒩a]"[:5̈ziTrwfUSBŸ`df@AB;M*ytV<\tA.k 2B /Y!OFL#b9DuT'VrSau).>yH&eݚ@MU$raFjYIJώw^`iklʼf vUU'fg7|g;Volc$k[DӹB-o+1Ř%Xv*||䂁&0(JľI ) y[NPE2(8<!fa"=BўX-(ȥ@d^S Ӳ)nʰ'z^ CQ-<)>dxQ>r?^5khF^n0 (=Tyԏ{7D~R4z.\, 70N9e< b(Pqc+4|'Xash([.R:9mzvYV Q_TXmZ .1$E֍TJrCJԹm@YnӴ lԕqfg' ~d? N|^o{P(@bQb\}*.3DJ׆;YFK[X\.ku16q lQ. :~y dN]z ޥ؎̹D|A%bK K1m؅EddjGg+Oc'+/K'_yA}ZVEk:F\tZYuvePaFn $U{vx]ENjyL0B=Zㄑ8+ߟX7ۭ x?e)±hx+P;_>_SdK4$Js9 , s \}ט*7 ʎ8vGJ-` F{V^b۝ni-! ^XESˎ`}|ŦlLnH Ҥ:Iiy%ӮlTa0tJ`;zF7"ڣ5F7Sǎ30& ;q(g=p^b:w/+O]?Y~dKTwr"2?aWXt'ln Z zeP'I((ꛨ Ip Q2eĩK¦d uͰ !HٙITrv\z0>b"E Mx\p5Iͅi JvgzF"oq/h#@^_#5)hu.6Ib̝oB#"?֜pV !cyd"ҥX'[J3IP;jK]4pWa[r&]M>H#˶w PJGvj]t=6XV!ƣ?z%xwUࣧL8Ƀ҉m>Rۦ&*yXhq6ߛ;*gc"߲ #\%Fƒblb$KxSR Zd-pBLԐe?M &{P2t-ciE3>!X#XJIZWxlZ$,P,xUp SmvןQ[ $aBڲ= %oKjdHm9jqOev?a͉zfJ%_M:zIe){6^)PCQ)nUs6OQUMX -"^xojs'_>fX\J=V XeR#bV?D8* ~ %߈#z᧴Pb.'tކ@W*.XZ ,5E\#8؍|,)15(3ޝd|Xi:3m >}PY(fPx7`?kW#E X tqI𢵯s.(1dwLU?`A4OAvf_Pѻ-`8dTq'_ML3U&Ǽņ(52Qjr?Y:*]pq$*}x$2~I,G~|\]'-elc1)ķ _pfso^=D@勪:ןtFH\50 J|d' 2&dRݏ^TVSFBėaFO:(k;@VZ,# V\翉-Z^|Q \ASѸ,YI VW;Jї'ӑf其<'Nd35i*@w;S N?CғDRNpi!pj6)m'6&$1"Yg|㣳SrD\Uk78}PM|# kՒ9Hs*M>dnW#G p] +`$N:AF;Sգ P>* II S1 eU8|-Gw\rrDNG2G} `J6D]3"$+3d o],7|ά;nN;T[ zr eV̓1Qu=gUGEd_6QpGjz(XxW5ߛ<8m$PIY'|*U"~sOw\+I&S $ii ,FTm/~+Hm,H3픫 [^xt{dLBe& "lYW΍fQºM y%w vi4=.BZa_еQeo]9B <ـpRH+-֠<ĉG4^$M$ksQп{ƃw(ݭbB$*qH#^9Clj7x^S9G{ k52qd鹱` Kk5FTc{it,Yʫ (Gj>@$3'zr.+Jpm 't@C=ګT⏪L~~Zf_Ch 'l8zˣʅ8B|x-c@t,&/$F)0;mP2Qm]'(n fLt{,r 1/ĝ朁Lg~#æf~:'(D35\u3>Dyn~Ǫ;&~ì}o cP;ƴZ#Iy"e݂v`[Ww:%!Q!t VMf͓n`$;$En̋jTB5@/l5zK"o {Ũ{]9WLy6E%Eq^@j\TʰC<"f8C@qRГF&MkTdu6vF`! wKDgϒin56kGg6Iu2}#1E3Vu w_`׎tIW=Ηv[f)7gD˲|0 -X%nQ^`DT@dQyK|;-><8RW,0ٚvNe`(HrcBӼĥ'Z[B==Q<ڴzKj 3 rfddٍ]ƒIWw$E#ɱ~W.C G9rE{^Op,2دzrqA7yR ]_=!JTLd0=*z;sH0蚙.[9grCXJIw<9`KEUw8:G*(RфN@sdt ØAï`H`L3N6٥w&Q> 5v$Ķ6q8bQ !+O:{m_>q3XV`j/Z'i6|b,mBzuV*xPI|K"gfd8T[j(ZNÜw7H3*;was+!#p4X;kWlPfC2GIRv&04n 9gU}%*h(ZLR^^1oiA

07~C2TopT5FA"x٥Vc/&o[zX"݆=ż2ijKLVv%;X u q 5h v!10Y_.2ʔ(_r)DV@9=}E/\Wib*z30ճ)J aV-\\/(] ~6S-Mtj5qwi:jP<*,M54@dx"qJ7!-k |NNyw53OE=}A7$hV\z<}S]3oԽ>jȳr%FPI>E}QG~Jv%Ki۱l ;Dt/4(F\p :~tâxN5IY(<\Ipe.E]Qyj1vÕ 'A9zk8d)q6`ӚkJʋG[V>)E `#RabOg7IT]L+ 3{}ưDHk9R-5>w:jƣS!MU|xSbBâp2g֚2uwI I$U8r^kv_~6(w-qn JmNv֊M[yR)3+ߪ>)݄YK04]qy6*hWyY:Rwunu\3~+hUˆvU_!*SџS:/.^Z- hcr]S4%=-kfP~gdј󠦶\z Yj祘h;8op7F v"}AaRIN5O~\ \pDFf&0/]j%~YE;HZM363';ԥ\d 6^s\DKYE_RF??l1X/iDK|gk튕vP]Jz_SlF*o+jƮct27 X{ZY!dE8Iq,tEQ[<FzJ#ya~`1Z }lYX͉Lk,p3oA/\Ia%Sأfgǖ|5JE EJa'HL P|yl''Fk ҷ$pՋz^cҐ;+^G nW\e/Nt(OI[3i Wݎ g=I-Ard˖l߷tiV,iR"P2svkoUs* \fEۦy1f9MuaSA4ԄamOv-[w g6y/v4."׉q-K@\WsfϷ@"{\) eBX"-=EmLfK#eL󄅮j,L=27#)r}h,EyRtZu6w =X;ܦwv@KVhAr͐h |;,ے"a48Az\.SE *#R*dBGEtE֞cDI%\B#w[>AM??%a␋yMsWUR6X?q\̤&t4Dxa,! PROTmҥL/"sZ!a_jB֍R1 U!mfҷ0whP No)k@2]QKD܊ԩ=t^VbȵjcqmJ˜jɐDDj}-r){ }X;z G#M(ЭnSnhY[ FI2k[ɚ3{-ͅx@ 7i5g stKŴ4A%e ǰ#[9U,( ,mb' Cji=ѡSC]`ME?[Iڂ(O rSRxyk%W 9^_!AMs׼rH+3zr.˻3NmEʕ_T|vRHꌃ u$O|+Ni)ZQc'8w_ynV7="̙ _0!;9I删DѥbHGcSEd uk;& Ss[$&C>X-,@ZBn_MHzVZsܰ}<%̥"lJ_ZC&O>6L8Izr(JQ%\k7W;ZD+wX`C6bNgRU(-{={wYNshSs̲?HgY´TF7[oL0&3QpDiUr'D8 >J!j фY/KJ! t!Ƚ (sB;T*^F tod;˷CN ڄF =s‘5l7z(QzTӳ0x;*v~6S7&E%}֓8̮t2Dvּ=SkQ&FV~墻|Qd61p-HQ7ؘU?.r]PsE)%.HH5Y&W3=3`ґ!/NkQgUn1 z촢^" …!B'P%c}&4g}3oєCfW Ȳ[op>h@2TTwV;hwy;WAtZ"-7z\|:O;PE*s"ƅAN|xtv+&|CTOS ,|N ~^o&yA+{} `\(SsZ =ܵ*pNw&ğŶ)X/$ JcƬWYEQsjx*^˅r)2]Un\O >!1^܄iϘ C ^9mhD,@^;*%EXʭؚQ5v2ԑjo2s(*v6V77Qa"B ~"Fz>"=[C*YNg39Il*w9XG ;Զ&WS}%< !}+̋^J66`b/"ŁFYY=ƒ 檖Yw;Dh37e8bV heۄ6K1<ݖvWL?Ӝ">7F)id⊅f+BqE7M:{&񨠪O,`}%QYAEyЁǺD1>qckkɶ*F@ޚšSp]pBc#櫼P6`60Gk#&Bb^`0jSŒXg'}M)5PgR˰N7OȪ<&BeiNWd'봣dhU1p9<.K67%g3Aod͓4 ݿܩS_*Έq->-XԪn)@'xM E&@x[J{5Τs)j(iSy#E$[Tqc% O 'fv4+lMT> wQhN2U#u g٧}3jXv-O۝w&6y"=ľ*_K9iP94YDai8!JˣKSovDq"h0v5Q_[_;;/q$7T FLKmry, =W1~k]@H΂I[36@w EQd5O0Yt˩4jm< dLr ;A]gRhBF(sƿ1I22RB⌹%򁴞9jJup9 nܕ*ݴH;갲?*3[q25O0UI&&hA>ǁmK5\2,iZ9Ej>7@wBGf35GM+SċVwAxu=d˲,%1 M#VY,E}9lA+A^aT 3f@+;30 ‡I{iKv f% |tj^Ì+)xmz ֎V #D*"}tHjuб5D/yRF8:,J?1x AY R;oW6jn{{5 "Àڍ èlFŞG0ٰJY&xS(DGKU܏-qd+2u4"jV;}Aͮn?;4iK8߹N\Tݢ0 5r+ sp?OP7VA\_t!I*h6 /fʙu9Eb 4 wh_ 悅++=t!5p?vSk`>H1IPO/f âքKiF',3fN*_\Im7 W$)fkHxQCc8в%M{1pF.h|TVӤ'뇫vp2JO)G_gh_T)ˏ%g1REiDPg̓9Vk kY ]qď⵷KũtnStBo2^G-){ ,Gwaԫ3bn,h\̇Mb@E;-NƑa1NNyңYYHXԫg˚>>̆KS,v,\9p" )5kktl,kBh}56R,q}!S6ŤxA|4BDŽH 7x9@ݩ;{ SEzGHSS$.\HN Ud(oa7a^M·=ϑQb+$+Aŕ0E(QtIB)?R 0a_[؆.}û% P+ )N/{[:o3Rۊ2H{j4{L8C\K뱅~q_p~B֤D֞/bds%ypߕ5 0dP1Z#tNJy+yȌQ5eӟ.ϱ :v݄ySn+1ʎpfB_NIJDF,Zjo5tZѷe^td?&ɩN/0L u1R1i #Z4$j5U 5H2P}vTf5XeR~,ĦL,aج$3jxf ͥvcq|.PPm^aɤa*X& ՍӜ͐D)o)l[ρf9uut nVF&ڿua;^a,b1Lrkv.Er~1nI/KxEVc2a\rX[rN.j?7Y$uQNSY+QJaOk:6DJ= CwxQ.n2\Z6K<"=s,$Ƨ(e^R>V./V@v^OI+!yk* >aiH kA"yR='TJX8uBG4:#Hi-G!|RZ):.&Ot;-E~ΫDO /zFjbt/G6h  =v]g܅YCɱOozk"e=0).ΠH-)zYF S̃:w!+oXb9kBetz&bʟ0 ?bkm0)Zۋ6yB4REUɅmv?` ( ΨL\m͹o.5*鴸\AsV{ɀr pbzh:Ʀμ2a0SoTJ.Z36a L>P<s_u8ks $SiP{͎r,>5S7k:!.bP+WM&GŁ?kf^;[c+ҹNr5_U#T҂,3BXkwai!MҎږ+CjU*y2Zˉ1|[茬GC3 H-. |Tw-kd( <O[wMeMCE Bdo(駭&wLFMoxZzƣ1V}ѱ HmдԘ8z|,frCpc}; Ftw'*Ρ i6nNw$G"_&#F+ :Ay?LH7X$uPhuqG/&7(N-9Qhwxe`5níIA<ߎ }挳^eC묄CnZk ʸNW9 uL_ZШA>PKKc[%.Lgӧ7)Д3QAg/E )dm=B_-du{-O%{ xo:/<Ҁ.z `me $$⬔YwxR~ȅ[hNSԇqү0~s]įr/em9!j^"~ gJ n.VXNrRb eVѹ?Ï%a iI +-?Sñv-3,O<' ^q*+ Xl ox> :&:VNsڏ_fr=™UQSK7 ꦬ2VwvMuR{(qֶS4q <ʩKJu&Fr\aƯqf.o:W-9F&}%+t,)j2TթB(AV!U%Je=< ;8g5A~fqS?'YZŧuр0.K+<ljfdCU%HrbۏrB RNgc^?(eGt pV+u AH>ywP ~A1qThVvam~{1AҀdR2􋠠Y"D 3G65D/[t⣗߇ÿޱJɬ$V.Ɯqy -o|y~u( `怕)$I-DC"/26c>wݞPXtKisxIdU}N½(2t5B,?6ũV&iLS<gߡЛDoK5d1msn&<UicPG;Nqͤ6|]WchZۦj1^ZzЏ.BZ ;$2%MuP=q"GDQ?;*  DMoߚ܌@ԄcQ!ZeH> QĽ9J8i}D_E`,|7ZoqSۣ#gWo˺,_T%CK@ @DCmhL1].O\IЄFC瓪'D(Kaxa2Ӱۢ4t.>]#J϶+0z0zy!0/,}}NasX8{"SI2 hLZ{LI!IDyg2{Y(xI U \e;#HƊyE >d8?$((A %bTBŋT4(  8Mn#}Y z '{cnT 9~m()T$H0pͯ*!n0 $lDIR̘=Y(尒dyB)0""2 ;-["J&ט0j+x7lj̞s}LRډ]`UTsUEk 06$C:*sT.ADa+@1ar!驌&f/;>(l=JO౥GYm*xC:.ppxx(r5^+9փh@Pyξ&os~/Tğg;* ^(*<{o%:ݽ؛6Oޅgjkԟ#f "ٵ?ࠜ-e^:fڷޖPYF~p`A<ص:2I{=I ~Tc-ݧ.b Íܣ #u)4Z7}1IAۧB/!tx1bIe]M~Qk:%5 K'bC?n<ǭLW|菛ESbr !CG&tD,fgV,P}"XB|]:`#MH"^=)l>|vlA(vΎN?ߍW-| S}b00>5BTFl@%z!meQN<Ņqo&+|qB18[E,*9L20E ?/2DeJ|XE4OqiK]ۥkh05EqW9PT$JsK8D6dAwb3*Gn^5eɛ'?) )}d]'Pq h#*i)NX}#pUJ 5Y ֯b \ޢu:$n 6#z^|p.^(H"y{d/} t44'*kQR&?0`'ơMV/9TgpAԓO_QJ u.ˢR.]ED7΋/]??K~»Nd iC٦r{{C;WyGrߔ.e.X|JpkK +/_-Xshxx$ ABᗰ ?ȏJv S@Z$rr zsf*3mXmC~vA5<[X"%޷{z߃~W;9zwB詭M*a%oޢؐ#c;ݎ|܎F?ll{@i9m X[}K6T\]J4qXMrR]^G4I>g1O;!o:$\I8;pĀ<#r L*s$}4rc0[&/ D&j˥u>wE'@ߢy%"˯ŵ/> @4J|Ht!!У]l_}ai!-dvSaΜxߒ"$XސdB@o˲BA =d@+;(o $P345@p07fm ;#p ŅGy{%$och-*6YgH}~ !0U^ɷo+RPq*w(+ ~x8xjؿ Ӈ[?r(ׇ_ҌX_!UQS~ܻP9m̐zJj}GQWvPNWY:Mcxc$ˬޒ?ݺHM07Uc} w)x 3L)u׀ wDU 7x~;Fo_[>Li `&}i?UktdOZ42:(ڑv۶x Wޟ -F 5R@;̱ښt ,maljn^,-Ja b1][Α8/̖jɘM.cGFy3d#ԘHC A=CR7aP:WMJ-Et!/l#n31M6[R$ֳʲ Œ '{ y(ybC 44,e\H ]jN.)mlm  &ӶQ%oEl@3;O'7!lI54x;߹x }ҧR|+ZOR<QR,="YuJK۾jS|@>}sMfvt4e 1ufjXr .2Fz!ww<)W>%͉&鸲mvIe` VQ7u9Jx]{<-tX'.2hHO[_ "9kvFlׄ6$X҅#D2B^dЦcvyMq#R(woyy˻A<<|>&K)vӾ4A,(-ZRT3B}X+)|L׉nc]u J'X.m.>J()@IxbC ʅF6h`q@esю ${Z6Xs=txo-"6I  >7ѬSp_<։{[/8=e#` Yj/dʯ3l 4R9D)m$[.[XYvFVKJIjϔVE;t8FQ7b,!H.#){S,: z,TPeD[F=ZE(Q6Y(xceB@sO޽O"h 1ˠ4C`:RFQFyRo;"녢VHr?k=L-P4-pIymx)b_lF'Y$mtGf&-),elr"3JdHL.AyBE:%bXUTS{}Np>}:B4ܷMH8ӨgM0? 3^՞zw!QNQJyZuX1ͪ-n鸩V\+*<|7(9.9$q` R~D] =  AQQf: k.:thBȊDHm/PdOf1 Y d~_5hcLD]@ $q[6b7ߟ4aߥ嗒&%JxL}Ȭ_h}|=̗ ̴Ҙ;z49˪·k9g"7$᠃2.2 z?-vwu./Ka&VB]b [l&@!<;hG;&C(?mo (9hrZCm1ʡF|o/= h~$ 췛JozVBCj3 QsJ&RJ}%*a&w&g[+ld $Fq.pGR`H$Rk{jמ;G7^FHdwy1{|5Y]Jb4/W+Z&;w_aaggǤfşFY] `a~u+\|C.nD{ujOkD/XllJ$TqszNE&R~ݸJn({oU*q2O$㞡Č,|@S);D$"0|Kb#8| ݘ@l*@bhq`%Gi!@[k1nWoY{oN1M_SzZíT P}FE#(DWE y f$:ɢpwH=_[L3Z9:Rqd^K99J7Jx]@~X-o5C+e6z2ߌcq2Lޒh+%suB,L+TM/ׄh*o+ 3T~k~~a巔VU)?۠riB]Mk;&=-JNSw4NYl#nhjYdvHN(&/=%P,dsnJ36T9,ǖD%Y:?60p<㬚ImeX'k ce2!I!z7c)NVi YB6JjSCL w*qUPE<=-g5vϕ lT1X0Gd~b]g{,F{1iLe,N{x,5  Bξ,&&iOĭŵzu,G@C`Ѵƕs>#ۘ1fU Q}\Tsb=vR^W gDc5^1YR q4a-$QZE:FX.}hшd\/Wi<%PŠ. V%j1,TV|1^:J*_rՔԲm) 4_X U|;Hb`;]3ܦY)k  x ?1LP>!R~pyyX_235}n"7y!yrTHXؓSi pPKN޺9⁧7/A{e&ZcV 9e 4hBяqN!ˍ-Hj) ipj,ǟ$4 /9d:,<6 .UHQivL w-=n3F}LHuJyC!F WbyNMjT]V6aT¢.f X0bSV荹m^[O<禟h7K*r2Z)u0\Bwl7i) phGY <:s U*OX|ZʽRVn~`/WEB+5 ="PiQF-YL_\r㉘˘uQVu݌ 8X"Қ ٌѾ"|C̫n T5lK sIJNҟ!la\퀱1q'.?jK[>Sfl`fڕ6geMJAURkkU}"Cd8I.r]#pnZQw4.}7R2N$wFI.ys1| ˈEirRh[4 5Xf9_/[[^T Ǜߢ#҇m8k5d!'Ep6ƪ7ۄ"ʂ4{}$A9i'EuEFoSiʓH~Efx( ]bD @' kin4 Ū@N2^x1^V}mt\ގuAJgZǙ7}fqxqRMs:Y|7:`ٻ13tg\B8;*bnz!QqD8Gv,Lq.bC`. ZI-HWf@?>ȫU6,7S| 19{1rVmy;u?<.j1):ݺ|,qS5UGC&SPP?U @|cpUѐ4is2NITsyU+n1vV;`X?L+@Y#ʹkVkb-ꔸ|6`5h\s/Nx<1.U# ̉# f ksDF*lbd4I$a%6vqV7(6,Ԝ8L&P%.FLpM@3|֗3Ԑ)q+SnYdBg5ޅ59*bE]Om: oOt 7RY4{)D<,xż? cj(zc.zED9߇j*[VazN%LPEm:AEFT3.D(6p#UzC! SV[AtD[yB ! sWU!|r&e5'mY)xhn\.㉽JQGvm2c"NOޛ/0X}خa?g&M7l#_9;kA5 U&XfQjCQNƌ[vÐkk+3M{ΨXW>ޡg{И(!QGﵼGw6a6j4;6%u,x_SyMxǿݴ0hsÇ Տ'H9~:6Zn%YKp{YSظM$jtiW1QU4L0t <[Ee|,V."*&xnk}3BQX7+ŜKP(I8;|d{A1~GSOt&!ms\pS%%2H‘\?3)Nfb3uuUe6ۥL%!H]a.`us!S +5 yںU3T*,o J|-C1~oвHK~rL֣1߉0_t3N,]z<~rƂc`>GLtjst s:/D U.Zׄ BR >!u7q9/-QO FnלÜT=5e{Ħ^YbTlÄTHUV\ ;&n>J]Ԓp4aԆG.-ېJ[Z>`M$!uEbh?A1s DtAZ! GR#vdv w@R33hjJK s283L w\ fy0=>;_9?`(khPn[p!F\mG+.rn]vR*^սL3#6H} P33ZG(V)%yҜ"u8I('Oo1'4IiA^sX>zKrGQA)WKaxt1 .9ETLMϻ0_H/2Ü 5$F:EIP9sB#{_ (cT6s9zj@NzшYI )q+8ŜQ{PPCwbglcC HV'kҭU"][\C S1"^-5Q"Wr7 qQQvI{_ڭ%bݤ>GR>m/pJIpD܅5}m_A޵ZλZ\્|E*4Uf>Yj,kI}ݵocW+SR.φjRQe~jI#`gǕ*JuqX.oV]vG*dn\mfM2'šZvU~W~n^ dk4 6넬Ybbd豕z}mvz+,&R]f ܃070701 Q+8qJ5v Wf- YZ