sssd-proxy-1.11.7-6.fc20$>%kEe}# ><?d   : $BHP` h p  D HXl***(89 0:2GHIXY\0]@^obdefltuvwx,y<,Csssd-proxy1.11.76.fc20The proxy back end of the SSSDProvides the proxy back end which can be used to wrap an existing NSS and/or PAM modules to leverage SSSD caching.Ubuildvm-22.phx2.fedoraproject.org֫Fedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttp://fedorahosted.org/sssd/linuxx86_64\KA큤UUUT18fd72a84b6e2a24e4a00f39e16b8465fe0d072cb8aa3e128ba230d9ce7ac398f5226482361635f8c821b29ba546b1f66a8cc32b461dfa8a83d18e246baf6fec68ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootsssd-1.11.7-6.fc20.src.rpmlibsss_proxy.so()(64bit)sssd-proxysssd-proxy(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.7-6.fc205.2-1sssd1.10.0-8.beta24.11.3UT T@T$T$TwT Sh@Sh@SG@SCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.1-6Lukas Slebodnik - 1.11.1-5Jakub Hrozek - 1.11.7-4Jakub Hrozek - 1.11.7-3Jakub Hrozek - 1.11.7-2Jakub Hrozek - 1.11.7-1Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- backport fixes from upstream- sssd_be crashes in nested LDAP code in case of ldap error - Resolves: rhbz#1126557- Backport an upstream patch to ignore PAC verification failures- Fix a sysdb lookup error that resulted in IFP not returning subdomain users- update the libldb requirement to 1.1.17, which is required by Samba- New upstream release 1.11.7 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.7- Start before systemd-user-sessions.service and nss-user-lookup.target- Do not crash on resolving group SIDs in IPA server mode- New upstream release 1.11.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.6- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.11.7-6.fc201.11.7-6.fc20libsss_proxy.soproxy_childsssd-proxyCOPYING/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-proxy/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=47c22eeabe363cf21a0a5dc38bbab4512e648316, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=a4505dca21bec8dcd038773dce0b81c17528028f, strippeddirectoryASCII text$PR RRRRRR'RR!RRRRRRRR#R RRRRR RRR R R"R RRRRRRRRRRRRRR'?@7zXZ !PH6׈t]"k%n0}~Lf-W4V%38'Wzj]Z)wM8pDHg nwVKtCm87~AuXEK ܠ{f yP0¸#lh۵zi޲D[}.+J^ȻkdBQz6JoZ8^mK?Gh,Cp0y3`$v $J.*~{C1:'@8uA2vE/n\ h햻62C9f<*!C |NXp%G#vlǻ=Dܓt0O~d5ƲwQ Sw7*%Fkc߲.дy~-ϞbFOe0 f $FQꂛ,)S|WMFS AE[ؙ/>8n}ȫK7*]d>ċVoK"O#6Wr 1P=!V,tU<H;y!#X{zʍw9o(&@m1Fˤ%hql@ҕiY;1c㉀VV'=-y(A73G0{W2J+k9t;4m8t߸q ^cOJV6%ʶhZq2J6N Ŗ)ӦlMػ%E$)iTyW=,rJE}D-`4^i:*GOxsQBGlZۂpnҹϲ|t2^SrKL?Pxa:%2eOd]6Z!Dt<at-VNUa4cSS˲ʽ4/촠eQ<>AѼ'ד`j7n3BUU֨>&U@!!e6p˃"'l `7\(b/ňѕEwZaA{E:Hl6-Hf8=vu8NX4V_~8627yCh>dhxDKsMG:vjA4Ũt/>jp2wpT!GyXLQӲ]Е,0z X hD2MKןqXb/䢈ڿ[L2 &s=I4BEg46v6"Yv:Zp9“"U`X} z$)l AbEhwȌ'Wy` 6ttDcx1˗ȩxxYQʚ* )EȅLX^׌g쪂&-%>g_*,c#oreWY'UE1JL6X`^Ӌ=xvչ KQ uԽE ͡vMalxJd9u7VW!V PSPn F"jh B,aO8ڔx*wnJJ5RuM+uY<'z3Ϩi7"MRc4lqS1| z $z5cge*['hpD2R.U2|[Eʦq3Y;bRsްS%Z3ǨyZv>H߄KC#=疗:b3U:I{ڽtxIR+1D޴dB;]_Gy@+ݗ*2p\v7trGRyE!Ÿy4awn`;r%1S@W!V?8N?J$=uZ.Ao\pE|!"lB0=e@g-uyK4TW9>oR&X}R'ǔnٝ< ~O%wJ~]\Er2*&I^gS.PL1f02_[)rrQ#w)pk+㾲l o{ =( J0.buXׁB^٫˸঩De+VbR ׽?nUJy>"hҹ7^rMKd|oۘ0a:$G15b+.֤SH<.&d|%_T 5tt >* ?nIZiR #.Mcsހp^s##t Hj߀ ұiVaOQ7"/lpY7\,%P`Pϸ;_ޛijg+𮟕/U7nyYNɄ0jp~Ϳ8X&J趽J g窾 @r:a Ezhhf~'?KLJT#p5]} J'mK&UoLhsxr\͗iՏ+)S<GsxIsAeI cE)CgfVl ւ*xө{cn)@Z끚!2*ʅa19vS(vv8)泙BbIM|%5ԟӝ A`ƐkN+&aMڭRC:, gޕK?nO%Yjhu8JldJp_pl^Hhx^\vomTzF# ReƱ)da0I ,jVHprG*Uқu^bP.2=%B31g^ |5B i)jW(z&ҙ=Q^b~Ԟ$<*R}YPqJ| %Ƚ nE 8Z_Дha;0ˁuQ씦3r]*/F 8!KxĨ_%^>!fQP20]<&O8W(ɂO2D7-5`2v#'D<&{wiTGG3#۫&dcv Cp<8Pws6;; eD ZP$NiU%t:[L,|vr2ڙ kԨu#F0Ζxa1̏*dbbfx*y[ l>UM(3<@Xv?ػM&zlQ;?lF mj9#US.s '0  tJ! z4bgҰ&I}}bzQ}1uN-RڪkTmՆs}gu `1vO#nZi5@Tq8c ^Rm&s+JW$\D[$u/[Cm:N~ag\t5i'c1H _rbBQx#ǨwAP<:ps8g.Tָ&\]ĭ%`1ŜuT9I VC&vI2 x=cHkOx4u_ \39(gOe<+ACSl1AHOqHzdE2{CNmk y]YW ʾJZK3~A7;^.3f5@r.7*}Czw .E CtHa`(9"DZ}xSI3f78e4`h|tx v*V as w|lJoXܟ 02s&r5jO|T3P8 xHѼ$\ Z FK>!e u|+YEE'5m@{gG_PlBԋ3K k`?_e>V pT'K,CBjY!Զjm"`J< +;N\VZ`+'~`a.<8Aje/F5[tpΊotT*LG!p>d6Y򼷚mFDhO73mWBmMuˁ(S˒kRؤ!0mg Ui]D5]}o 1q- *\%`EkezabU]T^v Y%FV_I@!˵0ytkCZ0"i琤 h&N >-SŒmn8;GI￘& R"K8,D3#ϣ#/G(?$p3LTN)w B',UŲSu>{D:褙ȯ*E1k<3o؟iGA6(!%9*Wo%V=vp6IymRjV-QplsADx+o^0Ɵm41yJ}?̅svoyJײ$BE(oc2Qu=>j&/_ZTKR ,}X[ULcӬv6gl=BzIgO!Q[PB %rV%=ocAt2%NޘϩR H:Q4OE㲀[Q? j}-৊h]\2a("6)b>eWi ;!l22 Ԃ߶ioKpp%zw9x)R&+'> eͅ4r'ls#eW{]npء̔ZMqnRp[_enBV3=!3>Tf&Ȕ8x1x9QCΐ'S#YˀWkeOR/%5;\ʞ#mhͯ ̗g̥?%pE2_~W^H VuGQѝ Aڶ @b]Rb:SU>2lRYYӊ L!pj!`$]`VQ+,1iTL6r)#%@xNÖms67"ש-oĒKl@fU6";h<'51*NRG㼰ޅ6+:wp65Nߵ|'6ɀWT6%Qj_䉉@oW\'ls\ =fRх65JJEB<,x%g aP(7[58Lۭw⛻I]1=B(^:R'rM@!>&7,R"j_nSdNФ%Hٹ3@nt.40#,\OaYA-F.ɂa͓>V0W9W.ևDޖۚPUKZ cV% )];I9*!J@KQHj:I=FGL i>OۤZMʾr!2̜ai]gI{q5 +uddbvxtĝfdЁ,k2҄6[KMwTR0zb5wTF݀¼av:( {솱K"E5.=UR:Ş.(nT#hɆߒ.Ꮎr3]&g=Wn_ϵ"FšgmBҲNa'n<ߪи[.7oqS57I=4W&I7VBtX}[ ݯ0m.H_u_0V͖<4CqFjv0HU )v;?ݖ#y-}]N,ߪro344\[5xdx){ '\η G CԼ~ܧ'47uf(wqOC#A!DKA):CU>CL^WknMY*@ D 03xM IUw{d8a$ aTJ"${,Yj;UOQy:8fߖn5KXie;*NUBJp5Ͽď@d֛IȖliO0yxBdfNG*1qzKM͕DG@C,Z{ /^0 ]"xl |ýh輅  i@!=4Kǵ7&+'b`gXߤ;嬵!{W]՘٫ݰ[;R%10[,L( CؐFz >QÅ7QMN[j$u?G}@WD_iڂ1jF`sK(Q"rI,|RABwe5D\1pnz`sWN{$F M[hO=+£Ek%Ax ]Q1jj="^=IzO4epc@&V*/m?Lc蹰0ɚ^Z =V9z]| j$YaJ:MbW+2Hp8z-) ya.yYsȄoH;*ceb | I.G ̦8j=Q|m ֽy%o1EF^(=H;yІ$j pp1Jm!b.~s*'Z{e&ytyWDj'j0 (mVK@h ["SVglrxp la6u"~ ^9`g^Z$GPA% Y4?(c@K%ͭ|/ȫ֔>?}I?_jTcPmk1ڟ@Z,|3#c$h(|z뱙8E9b` WA;R^D)}@*ݿ= ,ojoɯ>i3Ś+ۚZpUtʾlb+9ۄz.}$=7~ JBy0սܣcԧt`՛X͙M}ȎZ=Ƀ}6/ `J\ ǴN>XCR@z-ҦV{mVߣu ̥Qi/!ůVV"S T"9DEhغOB4  0i D_!%gҾC!?2l5YtJKiŢ^%]F1ͰEĝ7|1I2zg܇FDJA^r3n_xŵih^Vru`߫ o@~Fy_1W ƞfULӎ*A$,dD +:=Iyɛ^>?yKX AG޳lڕTC)t0TpTmFZQ6ֹo=8[w+po#oi9L`DMr@)oڧ..n Dvo+ ag74gϤ}oqBfH]מ^@ORsF-%b>%;k0DĢhۥ֧ 1~2Wwd5A:~OJh9T\}vFCBI,Z1TL3χ.1bJ,,>)A:n+>Yēy"wk,W$hP|ryV $x+EtV $_1":dC%*@؅ @0l<\xDaqs"I{s@9 s=Kn6_2޶KEXߤ$3XrҮ\1Gtm -o4Gƅ4hBTp.fvm@xsOyPd~F鸺.neI/Oٶ1&b11)|3Ps,7g}? u22&[2n3 ru$}>osQ`Ege2o沏)Wq 9dexaT1%eSAiyV. mqʑ\R;ϧ`/Kmx P!o2P?<̗|qOu •GҔ,K>h0s1 2 0|r\VB!ߩ`F𠃓"[MX׍ LTgD]D}l!!v#?YjBsrSXh3 e2 qx6X VI8_7JuKջEm6s OKkj7 Х=;:ae]5r#ϟkf>x *w7v?" 0ѣV-e[GM{Bģ<B\"&)gIXq=m2!jCG e<kJ1Xd0dX߂sua~עɖXs50},di0".L*gS{|X$P{" x;ϥܧɪsQ?/yVDF7T.{tHӄ0+' I~ m2,0,d+LɗX{RՌώs*&Lgn|-' Ck%oQ.t綼t5Ŋ~hz#l \ʟR7UH(#cdQrZ%߮O.`Pds;oqLf{WìRr Ri@^'XsG\W==BthsqUwsb.xo̔A$|y?vdv46T2?W̮H 9qa^jr+GG7W+]X^E-bռwº Ud Lʲ0+E^_H^SnR:a +&;sib,c^YC~A#{|D ~'7F:ۙ_ F^#jy$A[6s?ϻߛSlVwo#, X?VyQN2O4f!Za~Pub$A_q)aз ݓ z.Xz!t>-8^J֗P;|oOQֵXk> Igko>rxU}V2+|n2]y/`DBb=}g?;SypG8ïHόg܈l L<ףSYT]32/=uOQ,wk}2ۿw+!wٙu+ 8P3sʨԣ$B!B/axF?Vp/щ_N-JXIp\zق w]ih,O n%\@2a> >;?ӊA9oOl毈>ED% {΅ ['b kv~-/*;V6!]i{Jf폢.ehڌ*;J,SM`d /<|5'roZ6:"̩CǂOlk&]uU>] `(F4%Zrn 3󧐗%@ƀz.򄡼"3ϊ!@6l@׸&fD7oxE#ScV1dΆ޼HP^1åtc Yc^z Ɩq2f۬<KPUCMQڜݠCE5ޞC8O;*c>n˖?E^tX6I"N4{I65c G[F*VՆ5.! lG`+rXF(pnJ&[[%)PAx{(+-.CHahQaN%]7^Co;PƮ >7m|$0a@4\+s5h#v!-8kypP6g(E9#}lNG;YfJz Rsvi銤'z!S&D0L958e;k1je~.Sa߅f~qN[hhfeR] EDٲ3aAE >H.򘴧kcjdiwiΊ=6 Qgܨ(кJl kۆ$*ͻǙo{Lhk[B1 i{=vKr#=|f3(;ƀw[% M~f%cSA2n™15O1%l ykW_ Fhj2~ns0F.:ލ}G̏Wl;D_yiw1@9;u];uQ]lٿGg!ͺ^:uK j8h̒4ffU>s ݟwB/4ۅJ^彞uB3k7k: %ҙ[i ї~Q;{@{N5r`D~iQz~;j+ă!.y.RgtXf~ㄟS]!H0E>4O/F,3_IVӑm#ypGt7M"!hIKV,CG^yJ:6 TĿb4u+4΋WN85@}w V|334F-[Kg*Sꀧ}0Bb-*j9`\ƴ&Pՠ .ϸ/-Lf_K@jzՈc՛\#P27Ւ%/]loh_+~ii(; ,4(84Bd{[;o b6S#@l{E?$+ uwR403iS91$Z5vIhʮS3v5.(@ ֽP+`_KՖ _vG&U$V=Z'x,eLmY{XLN}L$Y[S_9|nųg,s9),iMhiк+:wW?AE3B4^QʢtUj{+-_4'%/"6U#J½y쇰 limX-5ʺ[KtbC% >ʢF)[rƨ%4y[z0bcv/ $_;Gg(|ql$u߰8]'Կ7!m΄6QV]oy(j {*~%THXғg}Q$ͫR7-!Q|:%6:-n;_a1C8{sjsR7Z׀}$ Z~ъ@ϭ2Oy&l3B.cbWI_Z qc`Kɪ}esN١*Y1xH8oiZ9,3X%糧ᥔf@]֣jIJUuQ=&}ɅOf^?ٷ{h(*&ڲGyT:\ё2' J3F=̓2\KniEb9'2yva| VTa90et~Z@Af-ʫ0c@sˬs.u0P? 3$s*Yd ™83w$כE 1 p8ӮTSU^+4IG 6o[>%iSXjV&*;^sEZ_b a?9'qb}aE$l ' )ރߒrf_ӺZa&E!+sl䆈fPNiο9\Y9QfAҟ#mݟ3`F5p#yV ޗ;Jz34\l $Dt֪zTILwotb]if_pޜ- pt^wQe%,q*nK 1rX`OB>&@VBf3ylg6\VWj,]KOho_%8QG g.tC4/`RuWx_7^~ /W5+IGOaAP9v|i@F=}nv)s8 Zaho(:zb{:h mFY?O5ǠڽJQ9~b[1pgY:L}Sg3"Z7t=0?e,>Y$Te]rbdvV-I/E[|Rw+1kLqXJI]B䉵Px@ZbLDzLI5Zf?A>9p|ZFO!/|k΅;9'FK.w(\=>H)~IgbJT5qBMPZ"UBf8&+"Ɩ5@s+5AcML!}|♫p|L\O6Q \CT&_Fx!b00+}S9mw7 #(cWXhsrIaEʪ )sw\iz.',qIЦvP $x1s%`NgpDg"`fݢ&&&ӣOz7êRR 5h-(7\)ʽb+;8 $Ĥ(W2*QOqYkGœ[>- \tf/!uKgM)U*TmP?B]mJyUDӍ =O"L4lY)(8v 1quEQetCKza ܻkK K+FULLiwdraA1˾x}3$4Sh^wC>tü]'' UP [F֧{Bo(İs8^zwi (=<M5Ԥ L8'7jFp"D2휎رb~ˁ{-I <h%?o\yO|hU֜»֘~]Ѯfaff_UaZK wxd4 8uW.nKl`sGlOk:\Vh1mpc!?;PYovS|4 %R]^>CyaPFs/w++g8v=4tϩ\V0c#,V)ޚlWZ5=M9At%4ቔq} yT!i+qS*s(˺~ZvɋVcVBwdV^:~ lCHє3n<{;s{Eo#/2>ct偔fr(5%Od,NPMCMϪ"< 9y\w֌иϕf6r^xt2׼C1+%O:]Q5<͠Lн1WeTPi7Rh"{+Dw-mU/ۉ@{Q^/]IMKcD>/kx,)tD7C`΋ #,fAg.GE(e]ZiA? C`vvNUfvq@OodGVBO(xy):y޶7Fp%fZE{NZV98,p˒{hN7ԚLB[w7, !i}sMV .fn죻m9eX"}9P^M{{ f@DpɶQ TjhzDbdhvN춛Ufr Qhlb 5TVu0'm p#K,}/0uF"lλpC%Ae]j@J tHbxHM=b,Ȳ~?_ZD&kL,gkX>o>w\ߥb) 2{[QFP̩6Qq]6Of'Ef"D#Vm>[~ؐFr0űL`ɞҨrw2OMo"S]IxOT:J5 \k$! H;w? Wֶu#ն<`vȮꡪ@oFwd_Q0ѫ@vђYLRRY[;joLԧo=<ܺ% A_vZV9pvk 02Jy9gc3Msbis 4)f K%|Q|@-U3Vv{|ܭ\2>kJ :D 6DHyOX\ACl)o-byXQ-!aEN`FQ56PZptuݍ c$ӭH ; i|7ƺE,Vs@fjmOybKHО!3uM|O(qKxD%PhL;ݧgP8S#=#ŊuV4*D"[ \R|QKqISad5't'wy )%hQlM5w볬\MeP_`rJێ8r½QxEvU]XjD"E0Nf]!.qq>"5s4"f Wyd՞A&M~:mxV~ ^~Q;T)iW9TX96+V3rd&i$$CQ9;ݴXiH8* R)Zaw )<=5A)6Aǫ *֒;bJݥy`Busv7unR"Tϵ9Ŷ@I2c*9&=Β/<"ܓ-!O#|U-LTQ~UOĆa4gRA*r'h"_+վ _? kYɏL'Ϛ%a z|Ufw>X߷k^çvC$n[D 'Z\iKGd80żC~'}ZhB07Nn9}{?|xD>cUV%9M#,KCͶrHu:,/rSbp*[H_zqvޖA4J˜ L>F8m |M PkiJ~ 9l } (<=^^}P2Y@R jm|%fvȺdR䭰daފ8Rk,Ggח<|fG]+svzP܏-]V \ᕕNwK((޶\pw $M͈ws(S vFUc\'COB]S2rav*;(7M`Q4gJeik; D \Yޕ9% gv%=u}U!I,z S3'ali%C&{ a1|64KUsi+.g h0ӚjH$ZDDO?iU]%u3LNo'u | +^GԽ?nCոh,%>z,M׿;aimP%Vx]9KpSc/4 #o`)_) Kd<:]EsdȒq)-˔> 9.%gw%aNknxL(ThrI[]lF_ ǎ?-UJ/=hA pqRGeh0|,/xJ[{~ɷ& WB]h' At!?K^4АU"ϊ_l-G1Rr{+]=';glP8if@n%c&lbǀ0%NV.,>s@@S}/Mծte)J\ ۙ5^-lGFQZg?ǗEZ9eWnQVF 9R.}%/PT ա hv&MӳB(U2ϮK]dR+p:kDOؿKqAMdwI՝i$Z&a}ANI1E[䢛[?jeHpP3!{! 7z>uCAk?T0 EW0`KV`so¥K@iw錅jkBt*F_r:d/:%YM\Kb^-`m0ݐ2 BbGw0` "_ci@K˜xi0AQl`D yT>7XiB3AcU2|Y-L>E̤~9'5~QuJ?BSLhbEkЁV"OOS>%㴩` MLd @Z~,3WF/1޼W wCW.PV.T`;Aܯ#'KKZqBq{G#y-~Y~jbRQ{7]owJ6#B<'m.YGG@KjW771j8ӋP`9pFCks3?wePi :!(ZƣuU˅~f:NkJ/IԊ0j ~{rKw3Nh-qDžؚE19BEjȐF>LֻT}G̟_xB=c!46^.-4Xn Nt:}ߞQFl &%\5jnQH7VHk}S)h$:*-")(yΩ<^zfTVAd$:8ᷮ4u礉tLd% l=urC,zR!`}ʭB~߸Vb5Iǣ5c%_P _f8FKtT:fX"&@ĨZEp)|, N-**T$0_>mkR]lF÷L!ϡ7ZsEk+eC;Gfm'47Ǹ:Xa, DGMBx |Ciǚ33ixy9l\Iʰ\DN.E&k蚣k< ;E6R/OĒ\+寁M\o`#=27& YrZIzQI{1L"(<@ K򉉲坱_iBUr;')wRTuʴWC}'7^jsG}99ekCHZI@hI;w04pe㸩z^7?NhנxK4Xz_Y\;tx~6c(RTn Q#eUCp j+Rib*ڈ IC$<8шiDLD+$ 9 5f9uV5N>vwlOo6z~U}9_OV*( VȜb1<]5rttrh5g9 }mA-ȱǮʌ7M+FZfV*mu2JPx㇀ -=K9 白d 7#V/ܴethv`cyKV e(?V F$VǹhS|.Wp8 &;!(4~]O[y ?^5g1c;3ep>o\ޣTvsF⋺5ʡ?xTe9I5 u@k=`sQ6WX9q d%&E#7AH)R~VE [h"t&1[#5^Vr:VrQsRZîQ"ӧ "E-ڝ?[RRi g}@D| ZqvFX7D#5YH2Njԁ% :I9ڃʿ ◈R0OZO$jF@#7JyEqm"Aq{ϙyS*8 8,ۨcJ4ktGlRWˌL v#+(xQSR/{ h&)b$ -!u>.xi)xX"(nO7͡ۆmgX(I0: _vyK܁ T4bi~`dZ.M qu?ĺr*=gP5vB%’ٲ*)̉sAuZn.s }6 eݥUpv4,\SU6C Eޓ]QYo ePV ZpV_K m[] "in\eS.W=fՖ402T@wbE͘ QgO~nn73(֖9f0 U^ȱtjph m0;jHp'Xbڞe`uϘf54Z6F ay+>+QڨY]S hK;k}]1XEɿIlp>2T$U^TvmW fXbʮҼ̹N;Q2U^. Hi5RNB.~'BPiT֥-D<Kɧfe&ӛ|kuivggMrӘ\S|'"ggYsǑ?A0<|R)Uw|\y ~܃-]ShyLn"7LSI~8gK#"yPBsxHol:ufCdWt”ZMX?CG5~MNXone0$S~qݙ+DFeԘ3+NL@ay#dKafJpuA#JC]!Yoۭ z/iu'u4M|55Co;m j ήbf cfr MߨR-|P& Ͽ2p<>Jg2,ȯ7sz ?^גllXvCIrP"񃦎I  N EOev9})3ѕ ۠N[X2_*PGC*ذ{dbm pJpS$A}'~=*)*{uV߿YmChbu`;f|o#A4Cj҂,dވ6ZE͵‰P9 AN\*!x&qOi{x'N*_;0)|13?3[R (< o94b8 VǝTZr͘ZCT/&Big:AW#9ݺ +]CcWbs=>.N;|]:m" -`v4MetnpiXHfK6L]!^5` Xm.MG:I>ǚDEX KU36=F@ǕY2axB/W߯$! J7E{Zȇ+,2W[9AIVWE$B2(qЯ]BȌ ^E\L<6%)k00 TOh _6xy|T)LsKzЭP' Ŭto8eYuonS?"n* 6@ IәKd0L9W#s, JWZJ!3b k>~M. |;b!IDp;'9ޜAx13sw-'HS.,gՓtls--/'^ h7w_GJ0_OtT薠ZPDV]n]4`7Mlv%*$G\k۞ bKW`"m#6FՊ)divO t;f]hmmvM';2Pج%iECO]F_csS:ozSFajV;36¨m|:3?^\/V+:a't``- ({DC^$|'(L 3 3OoB䪖]0NN1܍kiX-~׏XY7vIP`{ q1]hP뇄"$N."k䝄yZ ,9}?ԊfY ^b! 2|ԾxSr:wbLseKYA@c}d"9xR+"%.7.K/I1"žcvJxuzr[%V>[y69EEd&&[!7ri elc@e_Vp`:L%AY,`KR pBQNxN7c)4 GrR}Ɯ1&E弪B #Ç!: O~=Rm!(ӫ?0t&T)oMKQ'TWn&H15K )@>RbZ7è'JW/)*C0QgYoB#EШW ƒWnWQ~KdTo=7 X)?9:t:&fHOf?jr깴ןŠ3޷_{&4S҄ĞGf^ckwV=8GkHt4#1!w >1y XQů=9\Y oI[ݼSRڕdŐO":]d ȇJ"[aTCyuA|{싪{( 8H`8]ʅYNx|:fU~2ALk@+3;ŸEHZ0xG~%Xa(OfDib;Xr7D2