sssd-common-pac-1.13.4-4.fc22$>4W9zI"X>9̬?̜d  R   4RX`l r x    '6T`7d77( V8 `9 T:>LG HI$X(Y0\L]X^ybɼdʘeʝfʠlʢtʼuvw˸xy2̘Csssd-common-pac1.13.44.fc22Common files needed for supporting PAC processingProvides common files needed by SSSD providers such as IPA and Active Directory for handling Kerberos PACs.Wzbuildhw-07.phx2.fedoraproject.orgmFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/System큤WRWwW\I6167780147e76517f6e4edb013e66748ef6628badfed10f098551ebfd83004b18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootsssd-1.13.4-4.fc22.src.rpmsssd-common-pacsssd-common-pac(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @V$@V @V @UpUUU4@Ub@UzUzUzUL@UL@U.RU@T@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.13.3-4Lukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3.1Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2Lukas Slebodnik - 1.13.0-1Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Lukas Slebodnik - 1.12.4-4Lukas Slebodnik - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - Gallagher - Gallagher - Hrozek - Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - Hrozek - Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Additional upstream fixes- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - New upstream release 1.13.2 - python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Additional fix for relax libldb Requires- Also relax libldb Requires - Remove --enable-ldb-version-check- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 -{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - Do not crash on resolving a group SID in IPA server mode- Rebuilt for Fix release version for upgrades- New upstream release 1.12.0 - Rebuilt for New upstream release 1.12 beta2 - Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release - Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - New upstream release 1.11.2 - Remove upstreamed patches - Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - New upstream release 1.10.1 - sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for New upstream release 1.7.0 - - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.13.4-4.fc221.13.4-4.fc22sssd_pacsssd-common-pacCOPYING/usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-common-pac/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/, for GNU/Linux 2.6.32, BuildID[sha1]=fc3e993db281c5ee48a7ffb461c64650e36ce360, strippeddirectoryASCII text2R.RRRRR0RRRRR(R R,RRRR R'R)RRRRR RRRR RR-R R$R#R%R"R!RRRRRRR&R/R+RR*R RR4?p7zXZ !#,T]"k%P}z'Cg\:>D5@FzvUx7'õMѠ "EP5QE9jIDJٕy+\[lEH E] W y'N +nPq%~W9׉HTw T_1/;_*_`AfvANքq GFrlnȡ:'a/vȧr2vT1x.0.;|g6yOUUXX1jf1}j.g4 {>a+@8THQr͘[_h O#P 拡Shv*J#*^gMhEHP)pñn@j=H~*jPC9 > j`/->)$ EBu$L儭[_VJ?R+w„*NT# ?ivo.݆]f/lS^%ȀXQ0@BϊlzTtS-p^1 _t#>CN1b mw+1 Dڿ! "vzvk!zJD~ڭ!FbPrv6~vȫ@+>)3 z €q DnTV:thMY|6r[=(>u^thrzt̀/\$"ߎIc6z[ۧrV& Etצc:0O}-/ TI+ą%y[$"]8 ȱ;i:_h0Ev?">f~a,Npj]"*>af+v%M'_ԍ a8PCkva倞rС{ZվJ:m:z"275"A_-hQRN5K?A] CpZS$?/:ڼ A@B(>_3vrMoS'&0`)P6}?Lم{M]&~INO9]wI ۑq."wfj EZrvy>Iqb81eHDCVRGl)Х0r G(cu79˂ڑrf@b|K}C T0qМ_5f|. Ͻ0AMx倴QU:vբvQ Z}\X'&/}8J*Ruҧ1>#)@CxlTVR`6'?fWN35]-ٽ##+Ϲvvl(ʭ^U9-9$"Ρ@1{LT=S^0̿Mv{_g| 2?7d)Ze\6|ã;"j9MyV2m=q>"΀h 0|K] ~ 99VBPv0M#͏9UczmOw).ˆS{ktiş*Ҹ" a䖌@D62jQOc` -\ZȧU$: ,zwQUJ;bR"&KB%b5 JR,߸H)е,zGHNuxXDPҹRbGϐ:Fv/PJHJx1dr+ꩣfDu]ٌմݫ/qOs!HYKs(E_':ވt@0=;ߧOb\uv4a Z恝K_Ӭ\ -Y5 YU0SRžz,,Gams:CX*MCϑ\g gy5(Nӹ\L9.FgM|EƬ/9/޷Jj셼Vn]EmԷ7 U XNv@]Rc朏Qn4O]!7b5yJfQ˴_ϊ9 j͓ekIOnvɶmq+wXorX=38['AjKw-=Fncf!Nldz |~^/&'.ʹ-, Z\My;66ZKBz ߵQ_1}"}I Ql [HmIzu$D߯;Ӂn?uKPN,N]CaYAV϶.…;{ FAvw--i)S%fgvwRV\?*>[ff~ɰ$d4ki7WW4*j6ajLGS09~^ZP ;c6~;Yo48)-#2{(io蜡fVT,MrΪ]blq'n%mELf! 3-iR4nmG4˺Kܤ&׆x\]bꝊVڿ,FmM"uU@&oLiۓB2ACνʯff( Oî WDhOg@\#kYNBBH",(!Fnz0BMxSM()=? B-u쩖[eq;AFz@ ⸒ށ&~]^WբYO.95TJ+m:}5\-NQ='EO io̵p.l>d¦G7lmvd]ll] b@SƨC*< woSN)pyn~%kS #_B^1U,L!ùmv}{XĎ*- ^9b͖yckvtzZOI LL}#f%-crD5h "TlVvH-4؝ߵhs *Ur ˖`vZ+k1Nмg]4e cq.L }q .AD_hdkqA+Yi̳)GKG.qTF1_N,+RTo7Z %fh8yh%]Tufq2ל+] N <>ҀKvX`ޭd⚾-kWהQ?Q .bI9`F V8?K^&a7.C+?7]_qt;NJrPcq̻FËf,*pVROHf@A!wK8~ᲖUupz_1q[ qjV{rf ܿ,<;`ڂhbg\ >a~:(oFP<8@msbJ'깼Hɭ&exՑR\qo,3xhf٫1[nĘ(Šju? *ZV-T93Dx>UEciw%'Ly+a# x9R{R al:dj=>H +!n*sGn}:pzf͖ҝN|Aq&m+8r {У hX(D 졀GS &%Zխ\ѧ坚ws\je9- wa(8ɀ%U`*~:>&̃) s{ШbHz-OaD0Mv1 /xIK,/6`4\jEHi1e^O.*KYNٙ[R^dpZ\S#g|9]èPcIAw[]3[%mdN.$ִaW{..BvJأ :Ո3l2ѡ0T6WTit^&S/ST:KYm; 6}@YA+G6 aN0YAfzn8-Loǔnᱞ7gb\URga  ,;6D (b`F#XOb8{8_:{>V!z0F4ϳM_vQ`_2.W/薲:$)/S8{\9Q܃(`BUCU_cx5F cYQRMջ 'KXCP:Y4 ^5S;`VVʙSj[7dyǛ@ѩ7y("-jfG 9OsARDO9s[T&jj\>9V/6Yʄu5dH3 XAb0ACӓ)&xUVĿ$? }QHs~ %,B>)_I|qfP̡ĪsA<ݑF_'HLh{h|^}ȸl+8@EZ؜+ZAL+tĄC .g`+0pV*9&u5_֣EG܆Њ:K+\X&?/,MZ3oh?K4 8 3ÈLVG3d /Q=X=;# +5sU*\ ]懕TT@:u+0%h}`f&Iմv#o9זHaim=2[c6.Ԫ4~,W؞ϭL'Iŧ_kPZ3[?Elx4<ޞ0sڭBCNP Pf=ifeߞbN_%K Ev^D 9ٺ&;ÀY`V-zHiLOr>o1PXPC} IhhpE"YeQo3ތ0]FahiƽRUP Fn/̐"r_!qͻ'>0q՜ /fsv[}^G=!F3*?9I0 1(D7\[mwn:kBeLC\? f |o-n@HbacSu#3 ~JskFgfb"")'1q.GjoK`N*tO*T\27A\_w3ys(t<d,HN}sa 'F@p?D[}ԱXe Ŏb,TO69G*ҩfKFIL$5RUK$U2]C1͟qWЙ@2.8$"ό.ߨhoMO-3VR6H&M@jD[Z@䫴?c-V?!njAGr7IG=m"=α5`Ã<5/`ZSNeIGKc.xSOfhqt?90B`̮#ۼo=ș93CJ7CdВ=,LHX<@ zxba>]{]FY*~8yJm更18~ޯ?W"ySXjq@?j>y=9-۩jf}['A[Jghfɬf} }#md fjׇv:Zrf $ZK> SH dq=g%<؆ ;EoT!qv5V:P߱\q$^&OHv[QkEjI3ďW g솤tV%r,szc}^0"G2CI5W-ud3 j#@߀ҌQ@3-L' =gfKv]dXWH ]VW9j<3zV %7ErL&vvJnC^2S0ȼvkWٵ+kB&5p)hY{C9RߓLm\}e3[O,ـ$~C9Rf_FN2f&{KRqJνhE4$?&-@Xj:3Mf8CxȄba3K)hMZڬWCŦ`Z D(I!2(fcb˛'D_ec W+Q)9\1JCv+R'_TEȼ\!ٯ` ^7pNPrUs $ }αD8Ct+ֲ͑;qfOZ۵is۩"="9M\1࠵.L*C G*>ց{O(3ٮs4Z1ΰ_p")5?^uUVѬXkޘ;fKs$Ó;uţr~C# O0dGo_iSG棆#spO"u')md~yyCBs7&"iʪB~ڂuɔdd#C ˿\8OT?,:L"CXgV{ h@i׳Q#o큤 -cai8"Щ l[XUTűk~$bTʃEKl_ Ӱ7NhqܗMXi~dZnl,qÑb)}@TST&NGYX]xeE9ym=L wXsDY$̙O;x|JȺa2|L "y'j bN! G/ wc#oiǻN:XxJz̀E+![ۚd>XyY`Po:*w~'sxoj*$:r1j@Rl"`5'*p;Zj f#(Z&\aKV7qH `ĊMÂYPERz#_ȡ3/ B.Ǻ+Nր Sqc쬆QWیM<'L/%)/O:aϙ>?׎L)W̿\u@I02uOvk>-Oɘ[K'PxkW= ".%4lŁ1yʇH(d7X,|;>ff-wzΤ'@Tf[Fh44k>Á(q]9rVC>z'-}FZ{ vXQ4m7{e%!\cy QNӟ s^-c([\c71yKmŽ" Q%^iJLܳ>2k8 ,[AV<C*TZV39Ҍ"9CA/܉9t*llivh L|`Co*,dy^3G$C{vT[>>jyϺg@#&0%xg;]a9;;< )yU|Wݘɋlުs͗F^S ooFwe>? 2D]x&Z:{D`! @F~V!$;e6讁SyׁMo#ᰱ8"wCDi^s IB쾼:I~[:?ݶ)t?H{~ 90N(BLݗ\1 o^4d!#]ٯCoxN XZlj3W,𞎝q0 K{ KRZy ЦUZ ? *x ?Cu%^ǔeU|AS]nݍ"Ejyl*QwP n,'7=%;NRZ*EGo(H7}F \2mq (A.ѠE2Nf}GjW~GNoZSHnWSz=Zx0HfC`zCs! ŏJ2_vN~;|Vi#Pn15٣:X2=von;%\."}U* O= WEΪKHM,\3'kG*Yb|Z8y(B<\:Tą&ŃE(!~ؕXY:.(tŶ..`#mo@n j>&D]Nr=L cd?d5(‹LCUˋ :Û[blJP֚/WUidYjQCv| \<"FChPEtĮC+ -&k zWM\rS+i qzߟg_L 6TM@S6 s0 9p)n\b o{h0ب">MFP44MqBCJ,!4絡0*PVQk9 qz7r1w-Pra.$RN닟M&#}* N\5:4 s c^ wC˘GܚzOskoQ`29 KWdNHpXd܁E +6HJTԏhڀ!Y n+]p9D2OԕZܠt(vx\1mɮHgH+dCcA]]j۰ܷRӅ/1kqJod凪MY_*x69nmϠ۵=uS}F0w0 =6Y6 6+ M,J) P4aD.1*̑b IBoxj`CT=`mQJd`w~m/;e O(b']v>u&Oˋdm$3n %.zPvAn-,8!u4%v% Dk2 7y br &3#o9 e e>h` +QG1L?S[uJU % Na&0_CZ qWw$Z %ncɔι%1Gu@`'p ĂڰL7 7}i(7ֻ[.]4=~TrQVBw0r.y%prܘ*d*&^Og*U4tqL:B{+dzVO1 VޕR䢴Xm[$WmYW@tZ >pb 5! \||p"\] (Þ`KN?yd7WУqi6Նqil;a|Eao3U_ϙOpzU %d@ 1muɶ|b;Ȫt5eX.4{Ӛ2l#b0w^Ƀ[.SY6f3#\ғ"㰸lCj JO%uvt$b%O)})sS)ƒNqtOÆub|SoA>OhlL RǖAؓ8G7I{抻c_r7:ӀySWa#TUf&c‹҇~79X[vbvnb_`հ1ňԌc]p5RqxWB;ݪ?A0D!}^wr#]ݼn\א!Zp^*#Vm9.$\efT='5Jz3\,[Q xO,:>mj_6ww&Q^ `E+'6ZC+3Q=>sGh+ͼ-ڔF Z wT:|]m‚f pp\<9]r.CP ljaI- 7M^"XIqWIf]@pn l7KDYs*W0Gmud߻JֽE*P^ωt~߰_PPQ Mͼ.L:51uڄu1X`÷=׵}=s\B2FA@F1 חDY&%&HG?u uiC\N^OZa*%B9u4Dt3(`q#/޻jvӬB17 /.y؅,`q1U!̬M_R䖦|JAVٖ6XVTY0$Sɸ[B; jڥ^&稧N Ⱦ 7!G6f'R}Cp6EܡXMo_/t46+gZ*vae:˷Q^=~N6u$ }{ꀿAZZ8Kzw%w :,͏}j cc"Y26.|ĶVV*,*ٞ6rC=tfDay(Yhu-z @|c-nPCJi$ wtDH{]C|v3]V(ɻ=Xe*D) * ) kEZ0X*ZVZ!.lrOXҷfF{~L~ IJ/V0+UJ>W o *$ pT9qbCDg;f*$B7nk( KXxXgFlKTzD`Iic*uH@hO6cHx ޜ+ D> UusK:2QgЀ ĬaGZr'_SS3۴]XD{ic࿭9` $47x7'@l$[bԭ0b8/.k"wǴf5NMA}C~:6ǂk5b7.ܸ!+LmlYFQ +ml$^jqU!G)"-\DΪV1["Rv1;꯲BSQ1n82Šך$z7N4*]-W 7'"'U( ux(\6Z1 :?]z1í?*_ciNY3,rּBjrgQY5޻=!QTM< t+%W휌 ʏ,wF_U2}!:\b 4H5B &uc( ~v6sN,frA`#{0ۓi'V.$ƪ'-nS^t1H4qqB{m65cup|5 shRiN|wUjH=6^נ7P]2(BjSobD3Ul-d=9iY m,mo榦E +]ry*|1zY;)SMCҞkxp꿒&؂g4Vg;o %(]~o'$5N~"N hs~z! (1V6r:jiz+c#$G9q`ԥsS]_>B07qΐ} ؠPFCkZ8 4N%}+YNTRđϲYOB lkqWb&/O2KCj n~ B +;+#= V-x9pg<{T|5P sq {|oifj7Z9⑩i0$DN3~b{ߣ#z@P .K#26 MתPjNۡW?pN ߗ1IlL*N8 Ȝ'3p>ϼ`}dĉ0%EJBtmG}CIR̂??ޅ 곦yhR>y` U;zQsP)b1Yi<`[Ơ ܎Ι\g[N ;\I^#v]RzvDęO[йtkdagRWy<Rd懷tCV̸?U՟2 H!Y\Hް#Hn092{fM;F,mEo)(c+);z^ҚKe)m"vߐl,..ԧN*鏠 b:!ЇȦ%%,h/1ڪ+h߬ti؆,=$EضفS oQ:Epӿjw3#]d9늁⌄y,tQ(dh7R_hco\~H۴°_7d.frFj0m2]zVb0]A LJ1ݑ:N/X @m~ąiL/{}G:pl,DdҹK+G҂cň'ڌ Q2S;8p%eL,e"ҪANԨԳK5AͺZ؂3k"6ނQk@>؋'oioWʍ'>7@%oCvDS6Q{  /IRdij 믢ڶ2W2%-dfʤ;*lh2 2I:ŝz .۷ch3͐eg$Ӈ++{ZbfaCt3v<$m!4 "G ?UdT,!ק0!^II%XZ+ vng<`rrPdbK^'ySWcQeMOz^*Yq*6_5 [9-Սȁ;QH[ƫ4`Ń}IVY{xc2OL+M҃4|*hWdC/yK 0@:{C *=p2v;]2!W>Z 2׻b˶jN0dG-:s\M8z,:XX)Ar|,ܙg9:z1?kFF=gH݊Ba5U>軪~P y"bLByZS[5hYoКPϫr!pdzj?_3JZvTRRwK(r 8VkxXn2TL,[nBl9mh9ML7r% D+-g!?}NG͞vI^XLkPRv-9ŒTu/Zq2jD@ϴiAjL=䬹hUg%?L;IrHN v ؤkTjmª}Ϻ섢RJnZj>V}te˛asg'>"j=?@i=Vް/r.b)'֪(MD ’콁Am>Ǔ+AtxX]ca3+Ń ^ ].}Yҥh Do0$>Ay걺s 9n"2lK+)k+34r$qp`qi+E_: taqW0(*y7@6ˆ  Q:C(HJ8hhؚ>Yq?!~}%FqH~Q5۳Bӵ:6' x1Lpiu6̉*03+06v*Ta7S$[^3NK9cs-ټҙȫ+l./GU9kL@݁mǎ'P`Q UN帵qYZgp1ʣ @ML`|ϧVnoPBʙG (ڜ<~ c 1Y|>_{p١zJS|ln:`Z24@5F8K0Y43dѾC@p^] 4 Tt?'jTrrwMQ q,|e!j٤|{^NCu[! QU}d[2 (v_d&)PY>d0sM1&:KֽSG`AM[e*p): rq쉞Yy$h¾#)4 02jŤ>IU9ބ'Pxo2.qQY;3>˦o[{鎓Z.Vu Jk~pל5*ۗYT0bXUBbutr؇0SI8F#E8$ڦ]w'fO za^~rz7=hSږh~[`K}ˬpmvZ"W&K,SgOu9aXt) vٙ)MUoHƔ ċؗߢ=SGʰo,KVgp:)kȮ͕~*n\ h3j|[֫ \mT)A"Dƾa=z4~4>Y/_q{Bcf6'9k [J[I7$kʦ0 k={,X<@D܍\ɝdnyEVu{DQtIGC}B :A+ةT=hӵıR7B2E&˘4e:cq۠ok\)m*!(W.9mBswrXN./ʛ4O қT>..(ӈHf6o;(庬3ZYL &Of1e^T %ly5(oYh,u4o۩Ћ>r%4nN!6 [2/8U.@Ӂap@֢8 r o}31!HONn(-ZRYsےH'r#7??KIR=cY/hl!nJ\GHMM0yACoaN(*|>AI&{僕vE5cjzѻcE W$d(Ϙ" Yh@;[ [qCg.j:|W]ݘِ|ܵ@`nԃEŬe~Bo&=H?gb9cT:uO|O'wPϛxPyy?ڴ:b|!EJBDpڇŅ,VtѱXe般g 9t3mY }.WP+cq1u0"¯RTFF|<^+i'b?>m ˓됔>z9E~eɺBYe0I (( Dy5blR##Cޡz+CmۈʍA2Հ +4(?$3UjE]-\oX kKx-wwmqgl3мN gWW~B;>{TG /ȸ ֨`ص#JO7pH2AR& _Ju [x:o<>S!KYK>q8S&lbu)\}MB}"m,6Eha 1| s &KHK$9ysӫ8WcwbGF6WU5ߕ>+#t !|рi"h餼ݪxۏ>_֥T=ݓh潫dn0ߡ(= o+$kG^DGwS0tډx@+'Gf>mwz֦ID r gݍ gR#( L KX7ZH(T",<7y2m T(b7uSb)w;FR~ +c9;ͨnI*-QRTqR:"7U[ 3@N?2%bˀ|% P_XJf}Lpr>li1eX®XzYQLw" 6C*Ӝ6{#]Rit::%b){AK2ryz`p2@>/Rq l0+d)mFPU@=DŇI( 䐡K@r kAH07|Z =:u-AԴ+/7#d]CBJ RO'P[AZd4=*nP(" zjaԎ +JN*WUC*  թdq8/m;6[=9*~3 hn d5~(WNUK1% -_%ɕ7F3.9HAn%*%S|58ʁ:gDʱ.ԃc~ƒ/rJ/t5L.k}]!HI(XMغԽIx16e6]hxShAxsw(GS%qdvo^yc"$4+oA4i8S W7Kأ})W)@^9XybmmUZ෴.)j\,X'o^K o8xOү݈7Vs/b޽~3~=?tU(kN5(`x[oK7Mk]c/u\ *8[f&BQHKV[+z+ӱC(%46\ϡ1Tq ̖]&Vfb2_AkWc#MA#0ih}ZP`C<6HaQʉ^Lڋy)[4.^ {f0j^DR`H6(d/DBt)FHG" ܡ1)J`}G`2rM3k6{opDTԝk`@@ 7u)ysLvwo~N-=\rpc77bopQ[܏)OG" X~P;瘯SvhZhX*/h2*Ӕj9 ."Npor(A*mmCPiy9Nh+E T鱂 Ę9:/"$ =$)Kovs=QF>E W׺vd )rD(mD-p "0$ <-x8NtHԾ dBB^}7 ;g4Rk@uU2]*oUxh/Z py|u\2 lK$8@9տBM]|=4Bv=v\-wW\PzX'N4T65 ®&\tVV-*;ݹE+q3nb^"<,fLն1p2hMz`ң'fw~W`fW=ߣ(v8xpq3Qd7t:\F:}΢r韂OgC%.%.Xƌm)n dhy x<ִqgEБ"0O)l݅%=yOk34D{#/#ajeעb\֝+.$ B:M7 ޿؋Դ9ClD]uTɝQ[]*.ޥ{u )*(5'V)U]ߪs;p rSVÇ$|X8'h)KHJ@{&}* еwc |ySg>ߤ+2 e$a*>84osO[-YQRtuL':q$lfjCI ik 6]oܻ}m7Kdjh L(*.l\n*^Pz8n.oDh|ZZm7`$h&Be)z+8qL9'p6\(}Ĭy>봸1T]d\hYW@qg*x9ݞ-qNosqV,-²{ЍZLx?7q B+3炥oY,K/mZ]((X\`ԹX;TKd~r'%َ|Lam#Ljqr2r- ij%?B'zT1 "F>¸XAX^oX7@]$AW[Cx6T|#c@ACѥcj{k-v'ӯq᷿$ɉM, ?fyuR t .X 9ٿ_C+R߬49W4=DWw LƈhBi>5˧p45T]ENZ5Zc EsoBc:叒O)[^+4 MNe iL!V|:(y%ceHʲGrc &= ]q즊e~hgA =ѻ9-w8 86" dAtm{۬L#c]P\F_q[Bƽ8*eV 0O5/-I]=(hEw)-o Q tTwG=1{$0[7"b' W [hղԶ7~Uc6z$/?N_PF,/ZyO 5+^z!98 I1!Vyx ;GcXNxocUB!ZM(y#:t0g7"p uJ[V5BR'\M|N (1|)8[ Kl]O; gfZJR:(* |0i+4DCkwI0z±3^h1!P$,T\$Ue m)s&!:;19 {Sc |502rń@ݳAb[GN_t ̗t4$,Ev 4"QJt9:uKQ ysQByj/JćFZ\td+| vP:8lD̉P`ߍ 㒊IhB\  ?G5:NDg`΃k.mmYgqI۹bd(͝%Rp;F9a(V}V|!Kv88% Mn_j4D sCG-1QA E+GdSTS@٦?0Ç9/d!}X׎zIYJ+wπ!ԛ}/ wR&xt?pJL\_Pf5a~W+KlUK?:˅?* 3ѡI(+Չ6r3uG?ǵӹх?CTy2:u}z &h@zd'XzZ`GОw*T2b)Q"筬kЉ |zgUByHP,0}pgIV( 3G#~1s&Fzv@owM3LLe]l N$WU=T@m A0++n軋}Q^7۱Hk/)/g9 0 iRwi>.-N`Vͩi tdf\^BGrzD| Ѳtա0:KBzAl)*ܨCTYoGuUתO#AO[A2Nf>UZ51H$O]agޙ˩ays[-^B'bi?&]`.jZ\% tے VhBzZO3h͂jwF4&f@[26;8~YW/4 n7R#HG? J_ yl#^D B. MMȖ9^v8HLjVwXu7:@FԾK7GLJ2ҊSG |˦s' I{'8`c= %ܙI B?W4">ήH $q1C4V!>QtQ9߇^ t; V4^CHi*FV:Zj.S-1by2-eF>Pjt` C1o/*p8cpň6 ZSuxJZƛht

l ãZ|k;@|x=c~ĪC>*Aњqb:_;4 l@ } yʥn'a#o4' />tVGn1J*yDHAL|&G>ep=.p׌#j|0|-:`r[Vw.bE?=H7QjOn+ֻ2Aw,78Nbz:9j.DMXa(9mbD۝/N6*!GQQEYdPsq>kO2&5#*Y /%h{ڻLUEmwYc38t_2;i*kVTyM*uy41tY/$\RۺfwB\ %z+ImX3#t^BFf`ϔHNܨQBLa3 wK4i)1KFAE1?sU:܈%NrRR c#Il@ e#[%N~I\O^cFuL]Aydt1Rm9S,2h)ObcׇN}P(PC&d2efzoE}l#{ (2VnoA_=G5=&i,_ DDiIZ/RPuhWCUC2K9IoRgd${zEWzÔjyYк('{gFۆtOKaԪ"rfҿ}OvQnCS=Q5q6;ʛQMpú-`5C-p۞Dw61X՚SrirQP4k 9$]-jvj%犎o?ǧt GL}?{%F!x۞܇+B'НlF|[lfDWٷm[f߼W6s<]u0z3|MqҺ8g*@;qъm p^R?70dteoPEw` %wA-kRbv{O88,n}(WWR>P5]ltqɧ+䉆#3.-R%1m ؙq2b8l`XӌVi{[oYvb_~ OTZUj?b#&I"E} Hf!=H$6~կWʝ@Sl[ ƞ5©/SBOH0F6M $vs͠N(:ˏOR?jE YJ3 9[&+,]z,{S4aBAF7|_^%\$plN:9se]iǶ#c@w:yQ?+f 00=]_Mbdk*q miNgԼ[›'9:JYm`*y' D8l{A/r;fr ;nO6yL);Tp )my̩.)8,ɩӀWT^6Ή=h6Hoz2G3ޠ#h9reV&rm]V2>%nwԉ]O7f6CB<0s ,1 5C0r6ҭL !$bl}gN^9Rzp) ?#eπrR N2xʞ]+(q-]4©|4RϮs`nک9bhYЧH-2d\(@ A! TPTQ^†+Sޱ1 DL7́oND܂7@"$na~bwberHCZqIg$n5bKEXkX2ze;~ovhu=o2P/Pic=.AA>(l83R0p=ؚlۄ{nOzd%Q)1 TMe fU$A1> Ί:&*^2̲RɦETXfxZ#;w\cʰ#̄VFUW.\k`دjk]x6M$,D31 6y%rLnA<9##v`}nJ`x:+ `ٝĻ8` W1tJD9TG;hѕד?P*_;S]~4BcPq,C=^=]z`9JD u }y˥Cbcr>< 8n>I| Cm;A{UO(:5#̭P 3Lu.F.jQ@ ? KDP)Bh ĴJ|1(b%^lbxO+!i(:aWWEL1tK}X7lߌˮS& &WٸZ+iY[Vў,:l+H躱[so`N /M^VgA|B1j`/L2+z-8\*:+8&xe,I~ˑg.?'v?I[8nAӚ;X< ?yd̓9헉<ÕiR'ozdbqo%m0*hHf{Fl_R،EU_[p@ܾjݼ$ɛ9f/psq92AV@2QK!b$W \5 }L<ؠG_.7:$4Y[XVks]x5{vOaN1y58a=֔0K6ͪ:K}G+s; Ck@\^"a_\{-=mXJZ)hȟa`vMjf00a=nDХ慸nʤW ɀO{H`ł04#5XmK}meމ*v@WYMpN랛\.T[LiBm=`Nӎo^>9tQDkbqCrQ݌oGnu9e%.z-2AS d-ߝ8>!̉m-̛{Р-\wYڇj V2r SN?@>{\Z)X o8*juIBX1h ;m?dܴ6$O!5Yy|R^>',1I =n@ cp|lm?R'ߖgꞗщDiJh:ۻmyKK3aײD@s (vEe f{FS;϶e3ʩ-?K(> ?!0E6= m@:86UCtw!Q|.W g6}D_~P "ЯYl+r+܀}qR'Wb3.h?mޟ,Y"-]ӄ@3ZBS *&)J10"*7U@9 rWb{s/z>\R/Ŋ%PE$P$tl.6w܈r쭇KGrlHvIN~МD'J8h/"Q;eƨ0+葲{ +~ޑí]^4{!B,K!:G" ޴[zisGee6UIy\E04PCP_XE1)MIp]!8rkR(oRF0%㿏!J!ʇS.7ggl6л ޝy[7-[ &:4 L;k} e`(_Te)|g}2J}#AL٥uxv*©9J "(K`VެA,@\Dtl2Pm:N:* /sݰ*ЏX᎔u˿ 5C"u]j a/e3kEz-/0h5+q~P+d.N$[%_fq)'3N=2>62;ȀЄTsz>;v!B)ur",5A$\7"P)R>=nx\]t*}BSL|&7/Tc];NyS.*!SEAL { Iܹ1W8CF.eBނ|7hت\]뎢<~*\@-lV09)z%aA gxwιqA2UgؐĎMHKV$vFlO {EVޖOSs~FhjtYd;gQ2S~Z0嵱 w *EVEH0a>{KxD҉ r塾3jWb- ;ȰC$>/+%CG.-NܷfGՉj.Ԗz$SP3)%;E]~)9 (aŸ]'XdOȿ tm23!f9,_1Y+ DMؿFf f .}Yx@=K-).IٟO"*G&cMeYyt1'8U:U(t<)qtS>:\R< #_e-Q(ѳiot; %GJ ^a$aChnV&]mnD(ij,, L~%?Jg,Ρ{LpsĘrZ- 須a{)kRA\"&{$OK4MCoI-:HeIU̚X+-R TVu`u0'wX7>Dݚ}O%\EcVΒĄ̯AU ė#+֫^y rNPUkX_aaUN{%i9HW{`e>A;]k]ZvV-y ,Ӕ qţbdr5B[i!r5+YގKM*k03M=71VU"Fϋ Sp풵}$ O!MS^Ing{W˳ErIZv2Lzu+ϋWb1{8``,bP/E`*Cuz6)]gf8KQf&QQՄw+{.5f ]A fSP=}T>u3/(R Z'Eҥֲp O!xίle;s=*8njdMM9OE$\=TD1)VH'J|ԑ%%g0Bļyscz1pT\*H[$x$TzُhrU'3U3DK nWҮa7#BrIĸg?Juo Su研a ژr}Uv+ջ{"t^Z r[H 'H*:Mbga p=$[R{%ĤDARx0UGڎ5}O$FoN]{ޮ0CWAG7D#Fz)PA'}F`$0|fJ^ R}\aoLm`r|LD}y)0 Zё>*Ik+`zChl&.NnU;m*dMUI2P$&AGYG-;|M[_PbX@/չ#^*6N39Y'wZr%zRNËGl2>P8*Ϭ&c=􋃍L`B 5 xz1t=Msxʹ9(~S4M}HMtjj0E]s! Tii̮BwZ $Zo!Γ y@0س`޽tѶ(nfX)Ҁh:6ɇՖfLg)o%ں,P@Fw*$KvA62n A GYa0% yᗢ7d4:PP"s3oBCVz V< yAC9tvKX<џ'HNe"ft14JNQ7٘YRSH+T?UJGbsS7{Ru,FsH;'hhCt6S`C-$T2hzD+x UAzf+jb A*Ҿt[tiϓ: =Q}1̅s%o85W2d?ź>_h ]UrY}f2K.p1I#nXCPs2NeղXs#ʣ:NIy"-r7ޥ+q#B^DYKك"raS72R=U-8T ~A(W2Bʝzh WX:WD P|\ʼ j.1yf^4_JwmPk{NL5Ԋg/I7~lX{VPߪmK(da8@ %|_bw G#I jɶkØpf40yR{){3Vߌ(h 2 S xėPvA=]1iHYEGRɗ.>}ᩔ:B=NևۤWL}~);`cCK4 |O CȀ$PnHTWE-DE8qz+lYw ^"{Ĥ1&V]4u $Z8PXz i8K7r16Ÿy3S8xcnDmD&-01 g@*?ؠqk^ubes v.Z-נQq+a'~!]u -zIKJka࠭vګRql>$͓+K kA};`>3XF܌OS ZK=Vў\:Bo.@uEًDʿ`^`xmӝ`I]waV J5E؊"F6f:5ȚP+Y*ŰKݳcCӌ ?:oV@ov6{V y`6fuPH;A'-Fʴuvq 8.2̖>!$iI&d =vn⼢ >lr^ !hi<&~+O*γx"-~Y؎c^qK] '{v;Z5m#K&O` WA[o*%(q6*O\r-0;# Tf Z+T~.vG=ᅳ7¬9NM|ST~L/2 lZ ASA,ØT\aXr nɳnGaL@JӑAfZ@pE!US|#\<" %k@QM!lnUgHWlfs 8fWųJ`8aMuH(y/eϻJ*4{ xf!򘌺E`[zo7Ɛ U!B/ ˦PcX :zl>>!2ex-Na2Fni"<1Ð ˏ\̋YNC3:2֞/q~W$5iA-lAy!^Y1 8p&\;t\Z4laWCZL~o!}Qk#c 4(mK2cl13F(d&MEP 1c;sEha97P8A`M.$HggZ&Fl:bW(T?+svb>u3x|;U]"NK*s ~$*JA%>T3Fx+ 8!KvvGz!{ l3>D@U$,>υ`PZFdP@LF-ruA葝ew*Uʹ6")#.vHDpZ)zYJ-|7=$'`\#ߑ {@yĐnyc+Vn5d[f:Cd8\?#ıڌSiӫe8V-\6!WQ+6^{;b:>W ushi՟Etfw^MB6׭C;`_k%D$E9e}# +0ߞY ͅnN=M91ݾ;M˚|04k|bfYK2 XakqKkvk|0dBz]B1ۂ[k+gJ_8+l,)NK6P Hp!3l`C&χnۢDϣ>XfPx) [\(bVt,+IoGz}mO-g6m ٝqdhX]A?ޓZdG`RxW-W:1 +ɐPp>S\=Jh`^/IG29)_Ff< qoj\œɏqFTGP\4zpU[rh̲'Qp^n!٫td.1ߨ=gX*WW+gg".`|ŭُ-vs|O#a>9ey1Sc 3+nZ%FMsd1a<˗o]ځhy] rJj7KGQjWQ;6uv2??+ցʩfh"b&cQqíw9@_Q@9IO{Ďrw }*Ic9t]e~ޢ#9q&'D}nQ"<1J}6‚C/qfruCD>'XYn'Z8H2Y5ř]x1[$"x7nkznWkz2vA")ӥΪ*$NJ@=.=P-ja؅u/waOș`|b ƦԐ͕G|J`,CR ]knI;g']JXM#(LW(: &-t/JQ3fc~Y}XIƇW8&kq evY BD`+Sҋ*41@ 6qb(]YV˳c{;ܑUv?&hX3avX0`P':r%P!HDH9k3'lPٍ1?Wk{hpx{#*s :\?m)N<*H% %J19O=`Nj[ɮSt<:5h={,]~3gLSZ_5I~UTEZf"ϬQeפ2nÄ'kHfOn2S9IfhT b.OEhYI|~ ⮮WWS ,nW5V⸏L:or-8k`&8 6bM_l9P|pJ=KEL>`%@iRr PI|<hQ"8%ԧ#ɚ?]]X*M9|J #S91T }9IC\e[{~e~w|"ʽu}D;䝊y}l,#\ :k`A[,#%9Ѷ8![x PgH1pmY>0*7iuuO&a3VNNivz}(M] 2fսݗʷf@L@w`xT&j\ǯKσl柾I3:x"a(j9a\t(PBL'^# HK nﻸH3n`BoxX \t8er¼6DOPRt\jO?uIhzw h][2) ] cyh)L[\0 g.90 ]Ĥ;ߺыh;2`}UƩ̱^N0Ywn;5fߴ%I $R9̑(rblcK2DMq [(isCͯ-rf/GCv1)GCDF.]M;|9^熇hb=MMXtzLʓbm1>O^^NWy `l~h_.A F`i͙yKh[thr=f=|0uP|o\B 1s{QdnnBnV}5"LB<@L  !"`ʽ eƲNܕ2jrF4amL '(ZHzš#nfq~$yT{WKeK={꺒D. / чMY:{O{Vi|0B4ycOTN۾qRw/F]߂\5TJ&6,G {IЇTdMYw&BTfO;tu98 Mp9DkixR$$t9r_AV{<0->BR(>'3"?LHa\@Ԡ0H: X{}^+ԧԟ-R72_\1(,/Y ,trEh,=63FHX۲޿(sj}56ћ/d312[HJOJ#L٘_$?c 8nM^̬urWt/d>>{۹Ջ'LcWgq_ 5 Iswr INH}zեZ K(3Vc3Φ8z7J.$$mݑlIWs+t~h{;"& sQ\caJVGOポ't"%y+ DHc[%Ɯ9hZDO2pOap^"c,kLJ^hIh:"F=-k/wۊ7'E7XF"=3is?S|1xx ;jZT 45\0ߔçpe3!@folbACVIyg{<b >Jݸ Ysr +Rr&r W ;_iJ6çrK/@jcΞ qۢw8ƒ^a-QW)~C-ꫥF,tTHyV#OK1'#z<{Ft1M(Y[Цv(GaGmɔhT/U ?U?>]`D\T4C@9NA 4ܰKGa2⩉\Qvfu+dX/Mˀ; Llt.Ws`8 :6/kb0=4x2??V5{qnr|IݥJ@0s{h%;G v`A{ 匛ף" wDv 2$,h GmL)_JtmVtG(s:`9=Ag֌34 _Dnq荣[CKxqtU^BIdKE uxڛk:h2HbV'$Ln~(C=d!YKAjlM dKzTGzRݳoi# dec"dT`G*r+}1Nlࡊ7I" c=raw)_1,;*wΒ8Z_a"9o{+ÔǢ?νeb}wQy1EE%NO0aG'@ .%w+F8ple5ɕoP{ MCx[_*!"0 :B틶=L㜞Xh=JCh:o!%%B(pQ;`$ )HOb*" J w}uYlۅSJChLRSרyS +&mNѳhnې+ԃ"B>iB=Q[v_o˒7)Z.˹( 7e_#=s~\;*D攛/ <<.'#ַOcGnqnɒ1 ddF`Ƴ明$U =!~K(]73!Zٟ!j{=YsT%/D&אˬ3* ӕ_Ml2zoMQaE鐙fZZ5!u$g܍-nm1Xk@]!y qVWs `]9{s+~\=y vS/J{ԌLV*EW nՊFJ*Y 󄡸65|HTt&|ZhJ<ȮS42(0m`]khF뤙k9>f<_}q.$TK s<*-ntT (FOÆzt/I٨{ Bx*b_ɗ6g%VF jQT(NRcI G˫$1uԧ]I2oS@#J*][$io9Ⓘ0lLA͙1Ѣ.xDkq*+ 4d{tJ= u*tiGη =\Ѵ>˗r_̈́0@Hj#%EZއ6Hs?r@㨵as8%4į>&+R_L}IyyFŻ0H)%7SIѹZEQ Ӹ%헹ahMkph L"r_&쳠LCH \LHwNm %vO[bLԔL':`+ R HjJtoi GC&nM*DHl;QH9 02pɞp kW ]&O )Cl[)BuΚ8n,.OD#U8>.+%/~b_9TXzB=8˓9ܘheA A`GI322T9зULV#ih' i/}1l|#Q8I|s9kY~.׽eRP./땐PX1eAп]/bf=%sM&ͱ ;eEnñ O+_?cnro{*Amr%+@϶ \if7; P32ʙD,8w,+ DdQ"!zJq/Ad{S bP3ϳ,a8=3in