sssd-krb5-common-1.15.2-5.fc24$>RRA4@9Л>=׮?מd ! \ ! 0Dagl    m t!(08<9 x:?GHIXY\ ]4^rbdefltuvwxy+הטCsssd-krb5-common1.15.25.fc24SSSD helpers needed for Kerberos and GSSAPI authenticationProvides helper processes that the LDAP and Kerberos back ends can use for Kerberos user or host authentication.Y.buildvm-11.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttps://pagure.io/SSSD/sssd/linuxi686S|?KA큤AY.Y.Y.XqY.y726f7b8597ccf130c01f6f9510b1fa5eddda7df4edbc8d0b641195338468cd5149d611c474948850cbe2c74364227a99c5010a473e3fa7e8e923feeb530730058ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootsssd-1.15.2-5.fc24.src.rpmsssd-krb5-commonsssd-krb5-common(x86-32)@@@@@@@@@@@@@@@@@@@@@@    @cyrus-sasl-gssapi(x86-32)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcom_err.so.2libdhash.so.1libdhash.so.1(DHASH_0.4.3)libk5crypto.so.3libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libpcre.so.1libpopt.so.0libpopt.so.0(LIBPOPT_0)libsss_debug.solibsystemd.so.0libsystemd.so.0(LIBSYSTEMD_209)libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-common3.0.4-14.6.0-14.0-15.2-11.15.2-5.fc24sssd1.10.0-8.beta24.13.0.1Y.@Y@X-X~@XO@X6@XOXWW@WWW5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.15.2-5Lukas Slebodnik - 1.15.2-3Lukas Slebodnik - 1.15.2-2Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Lukas Slebodnik - 1.15.0-1Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Lukas Slebodnik - 1.13.3-4Lukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves upstream#3382 - SSSD should use memberOf, not originalMemberOf to evaluate group membership for HBAC rules- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Backport few upstrem fixes from master - Resolves: upstream#3297 Fix issue with IPA + SELinux in containers - Resolves: upstream#3360 Do not leak selinux context on clients destruction- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Additional upstream fixes- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.15.2-5.fc241.15.2-5.fc24krb5_childldap_childsssd-krb5-commonCOPYINGkrb5.include.d/usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-krb5-common//var/lib/sss/pubconf/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=4423f69af000b402bc89b5a8514451af0c0bf13d, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=9d36ca053773a5be6c73c71457f39a99a46a34e5, strippeddirectoryASCII textRRR RRRRRRRRRRRRR R R R RRRRRR RRRRRRRRRRRRR R R R RRutf-8?07zXZ !#,\]"k%}}`ʛ`c䆨r.{xXNxnrS{N XȔ]|8'5[F)x4Q隞F_noÂYd/*jQm;cT'0ĥ歴T;4$,"ȗn9wp`((Ld8SG͛.sݹ4.TmuЄNiKHu'{K?N}ʝV13⌱2)+p¸vXҜ-i9vW(kPCxVϗQ|{o1aa d<(Hxp?fA[]N&{܅z-k2J65Dۈ;g' g, ,\ E-+]Ͳcj%h+bsq(P*%Y妶g P?1aZ^OF=z͕;l=xNdR/MDy5iۍ7>H[=p$_1d_Xwcp+ߧ kK%$oVfefFD ȇB4P:tq`;૚  !|Rh\*vdX^`RA: N1V$gt/ )7r8&ﮛPImxhGy$1¼ً2zMv\01l1x$l g箪,6urʁJi7 ڄ<;÷u!PhYk5-)H$Lh@uIDJdɏe;[*I$恹D\aEYHؗGC%**b')?IJ1e(:t޵(X E8)4\2 5h`NAoP9nKK< sŇ*JH5c-;ŋ:@Ǡ#[؞ XEv'XN#+Cm'9 %J)O D=G80`VĢh;h?F MNP!‹J )k S)`~v_,U~b[zi%52uEM2UT{*.?wR*!z@COÚZdGLEy.C>Rz $LH(܈QeP,jẄ~Ԛ<, 6.ْr,/+[c`5+}?ZյhJ{&~`秷KLձ#^KQ,Nj'$=EԌՇյ@`s (ݻtͣB #J?{ %>f7'x <(c&هHqOv}EA)2vdŪiz_GbdAl>`);nFN]  R7%Y{o)?FUs;ŧ 8Dc2Gʉ^È +^ebcu[H Q y2X ]V'l{5Uۼ4"7\G7 =խQ|~+X)FPa5N,"xC©)pD`nܜMc'#$n:!jZB@CYP(~Q<3LNSk<^uzbo knTM)ޢ^:够flu8:qԄ5T1t/2{};% ^Bb-DӬY-7'rɡίn|;VL6cɹ³kmȡ \5A *cOX7p0֢{cŐ6xBd>]z3R7;C#'3\ssc4_WmrlDPfPFuWz7g8= ϔ140~-2])K$$VpC3Vm&?経\tyh4:GO?olܩ5!?t0,<D]ˬh^cԛirDw!vS(~c{f{6]ak;|BkX.p=axMlV wy+ DVE:R SrM2ދ2+\ܿmF"^sd+9ռ PxMbZq;&)7[RF×^ q^WJ0p\\+ cs e)E0Y,F=~p*}l7v1/Ef<} ΪC!RvW׶Q)jtwrԞ w߉_%_enZ8&* srv'h7=cCTZغo~\a>yR^ $ߠ_Z@,v{ ̂! 0;v MR@&WF ~&;;g= ^[?&$7G1YN%(GUNe?=VA`1FlfOJ#~RTK\AVmǑVép-ᔧdbǮǙ|E'f>Ǭ jQ}+RG@"F|q&'$ԈpOQ9V41yb>e"p1ѣoҠGSI>PgUiSq-8]cag>xxZ6Mgx9dz^&/^NةI!a_b_lT<]^+8JɇPKU-k]=EJL~?ħG[L q\z'iX_卻Ptmrt'ob? 8֩9'桠g[RXtrqvbx aXVKTF)6;'Q\^lFj 568`|7Y =O/v*-tqM9 |8O ' 8~˘VxL0JYC;6"2i J.JG-twjV٢1{Y. EˏP>6ã q;>m5I: <0'$}B,ꭴZyt-k䗜j8? &|6UwPmbPfRY{F1juZw1<1L^:@bi;Eg#둨޼/?-gmf|@Ui2)nNc|` 똭Vra'GXɞtMgw;X&cFej|W[5!s$%F3P%CNM*#]2EGz\lj#y#H-yfL3 >@&RYڦL{7n9j1uΌfU@*!k %X(F#>j)έMŗKͬ7HФ\,Ơ]>mC6pp^C1 ޳u$^=Y=9}j}V%1|SKl5NjˊM8 vOv'rPKK9l/0Bs&HuQ#ub"meB-NuI;E0f;4R75Y ZYt{Hy''ӧOHҘ,unҽ-nwTƭ_Mݫ忕b:S:ul  Hq {;BT탾$5,2'T΄]1>{){( ۮ~jcOc#!G\˩/s#Gg=LoXhC?Ui;Ƞ`.5uTaKߧgE6l 5@0GNf>p*),ZvlDPҫ, 璿]]>GQقl 'l`N$g+?C\NZhDs:H?x~JP@B>Э(--Pg*+e}1c(|p@2 g]N4#&#P4I ̜ N˖Ԡ':·Xҏ4Qin[Rt2/>D6YR7pbl&r f?_cfCpH#12W7^['+j9#9㑼Ej6~]=0|HY9t7`>#|bkU&dCG;n3{*BbDJBV_cL6m)XyTf:֛6@}|XUՒ([`n*,2ME"JܝR̔I[ ٜ"ﶡvԄHc)@G]} aMHvBy0wdE T\nhhtyT2&#f= e\;,+ַAܼZZ{e_fGÂ]@i m=i %l]]|i3C&7`1`)Rn+ mqJ^nET4ظGdDFaN1s~iYh f}\HgUl! "4N|Viɚ)b9=MUÙƜ"ٚED_|xɹGVⱤ]X.w7NA_2=NJW6 y"bQ9o{uM[@Nu/!Sޟwh:V2f  xb0=Q.iZ=B*x5[ <%A[4IT]/ԍx%(b9un!E'ǮUX y21hlCg9\F_79 xTgixFoܓCfn p-m| W{VoiQ"^fŢ1VM ;݇UtOk~i- T < sRs-CSO +jv])3&;q2uGo9/:U[;ϭ=ᰢ:V,✞JzܴoE:(2V)[O" ͬC $$_kЗHڌ}cyEm T/@ -..% }Co˯ ̓75~a\ ~._^%\Y'GI4.ajH`k0c(͵˫Yv 7P!? }JDi]Ic9bBY;5[=3ߐz: B5e\?)q+;\jxql"-DmuٜMCmCϦaSfl+W@pMw6Iw KmvZ}YN9ޛ[`+ J-D]'`5pf>榌,nе(n|x,zd3oEz\S 9 jC#JJrGC4IFN>xND=ۿw;N `hK44,Q=%5oF^?jOՒDw:&23QF Y׾1z vG"z7C%x,w:)?%SǑQ_(Tmck64I6p9\Klk K"r\;)qBR-gF0Tfzp;"mֈ~Ϭ,{u!z9~BYdv!`*(eoQJ6fHBc!ECVca[eXl hTjumFOl_J+HS֣2%?T!pI3cmsr"ofq70Q,A# d!^}<#.xƝ9=yœQi?|SlXp{x\DHaj3g=HM}Z W7 ^7< Hs}VWroNݯ? LGExk\k(pYEFt p73aDV3mQl О7гq A ZsoR>DQ$I.3:vE3 wiY)ܹNCIoq1^&jCV*fYpBeܭA!^z.ܳFwW/EBvEyq%K`2ԥNIKCFu#'V5mz,I*wW)1>:[ip6L(ѧa\y7-S]y<^lIMJ~!xO3iqvS(gHfcwdJ,uhlj.w`9г`}"D~VZݝg( % 0EE+ pRD'{I\DAnMdT)gTа 45IqQ"N" qO@sNE{hRsP`J+ʹrY2/H*BxiP_G|YS6sof5ov.$dڃ" :?RaR ?AZ!&iN A6̮Azr]ިXx i3OCt6&& &cafyjqE90Fh[m'H}*fd;6[ַm5f^ugUf`Peq=v(WFZf3!_P bap VQ;r";(ScW A&eP)$^΅ q\gƼ{:kmR@)d܉fJ0OS zZ `Wh8 ݪ?iJ!q7s~ze){;LP V,-B\;dnCߠS#(p XNj Jx(#Ze]`ƮP@;f=t z<(RR"'w?2 KÅ#U?#+wIm665٢~%@5\4!AlhxM ph+xs7MJKsI9>mЗ<Ɛo}3ߎ[*H9sTdrZwνFO Dƴ'V ;-CyL3 {9Qi!~si`9?k jX̠hnx [pb Q0\6C[`RcӫWn/a  2%:Oόhm^uWӍVSGeV,D2GU= QC<\=aN$RXrUҊz2C@n8lao79o_HS ˮ0(oDՙ&],,3ڟA}fg‹8F.6n?Jƴ)X)$|t 79S>'3tS)+X)[h7d(*h#fL ?w'5ŕ+sWbYcY/iXk1Tpu 1x|Q+ֳo a,YqxpJfb܇v&\ ڙ I+Э7tD7~nچ) Krx|ofE6Ľ UY/z@ kp7p%dFS$q'Z,/YQ5ΎڤCY|HL3.?Iu!+1۪ީ H㛓ᰅ:@Ђ`E[ϓ8+g{x-4."3{?+D 0q%p\Ww{lJG4;A)t(?<*ddĿowJםvGp:52v6ax_BiDop]GDcHȣ=c;^_D)} 7l_8H-z2q%V9yyy ش6 A|8 bȑ>XdIȻZ>h-92zӏV[ 9I E!?%d iR: Y+r^yxO($$Ћ+~tSrHO89Z Rk%l?Vy$*۰[<1gHDE<>WLk/vHB>pTi 4wݑ”6`tHlN>Ac"\÷ *F%XY3.ͲZxn;C(q+an83`;ᰨ+Y2ܝU qۏbƙvV3Z?qb,-qqg,"KQammODkbȫׅ jIgV&|#cJۂ'ڛHʞ,NdC4֑FSFHsQ@得{J ;}SSВ=!|§^i{*)1"|^7JzچoWת\GN@'>ȵS^\.Amd_.<r)acƾ L35th jR=oij!< ē=~i!Ⅺh4F#TWx Z+ V?`+iLOsqfwD Ѧ*9 jnsK~#6L< {^ڊ}|i( `xopLRhp59V =Fk!EKk7 JP^%ߨyҒ31}ѷcDrnT@TX]?`N, ]FFXR0 ]wR3mv"ad9j1(f|5dw܁ yh踫驳T@MP _Ju֤/(>S@<êjM<)$*(̚[3K)`0fNtXz V\WA(O A^TV)2ܕrMtpaE7 ¼ Y_Gh%')΢Qu1-,^zU$ 2W3|zmwZ1 cgZR1 0>ח I{sZ@$;5C:+&_՟ety[F8[ vx8xd&x#i[Ug;Ø@F vMrLk?ϓs$PIc+Quk)i7˄qF4I]y:UP2"Eч揈kYP+Sɝ谿/8ݭ{NzZh99O>4rpJp32l)1e15\oJаbfR}^Ωs&ⷜ(HۈՌa8̫ O. ?ƞO.8iÞ /SB*~} =9^%Fkď!1_LIc : ˛>jpttV0\L/(LVBAt{L㥛YhA|zM{cF| V;N $ ^Dxnn^rbJtLh6eufh ) T$*ˮ&<"[ɹVhUw M TcV/F9kH"jWB.n,(E[SE28;u.M?3UVE~%!UA_UW3kz}1WQV)gM:;3ڥ ]-n=7 j w~>񏜮* AN]or+6mO^n)Gx;?ouYVΓL6!$sR`mvcH:łǃab6A5G83ѠJAXM_ w{j(:S" ȚBKܟƔ|M8$^W fTsҘcLEdj6)}7fa̹,J[߂sT98 hƿkw(?Ap5z$#TVŒxKdvzEX-ٵʢN4h!D >;yӳڀ-ͭ"9ʣHT<,uv0pO󶛬~{I~3ҧhU p1Mӧ'i`={eN`"\j3N@D~{7{]vs׵ [' 5E(93QGFZg&*z;Kڔ`D%瀿]H㠬]bg"T83JB3ꁿ$y&D&mk:s2]Uݐܦ(sx;ᦥX64U{4,]бz #݁v =[XƅUmD@)ҧipdX&M752&goHkp4΅xR}uxC]"C0A3,FC *u)I(;3 [8 B4GEէQ2z=ǍQB Dҳd6pҙYcfE^JDKg+qyCagS<aMд(DvB,w(é(B.fd1Yt= ^relBxz҉'Ea-j1u7*C?xlM2w2/߭I3gBD#MR7|).D\GX#s'S砿*OWkw~ߝc ;\f4]^#ՁnꓽYLjaYTY}fd|&_/ќ: @,ǩjO x22#hZvt_o-BS7 lh љ9`y\(!8͋pbRSⓀ8>I*|y7m "~`~OFy>ZaLB'Z?"ݟ t.BDT Ljz]Or6%%Pc 1iLEPcvoF-&"f$qO7rX: 'Gy"+rjw\oO7WɆ\ ^aPeؗ ^N[Q~kMTdioH+=Zsa=LF-)$oz$4JVع*o vBO] VU EG"\H _,KWb+%L: ?'F,*w@nG.PwBdn+“j,T[EF}bQ-DF*)爏UqۜJfz wS$VS<Ɵ_Z`aǗ=x^澙VKOC8yH"_hI]O+9iay%vj(X6 U|e:8v;]<&7B$+(")! ÀB-L\ eބgnn* R"}&,x-Z-mn 7.E9?= 8cUYi3ӗO1DfEjZ"3# H0u?%ddֻPOi'S|5a]=[HۆŧKtXg+ϐl̏_8Xg]8ˇEΛH}$pX 3QD]d.e$rLbN&`TYKY읇-7t &KgѺKB (߸׈FBq*[ $q{=Lw|~D3[;PZnz+g"1 U)r0kx  I}Uuc_VŢ%=/ml/r~}~'|*4=5ߞQaA9g^kŢܝ`, ,K^. kN= T g-Jt8E+X9%'j5t+]IP?rgš(5_sSFgtrw(k3|ԨE `;<'JVI"h„$~ВpdaUeMj6IONU+S_GF-~5-jP3tLS܅^ hK*jtz=y?9Y avd=4o.t/ĺõ~ O#T;ׇ,._87Vvt uCձ<oHΩq "%Ph3d@r'[],O>Ro =\uPxx(W0j1o8IbΰM>x鶻U~tf lx;/5N6;33  A rj5*%Xݬ)nP,Bb$,Z#޶h0vjf@da=s <*-亓ìkб~-ƽ=9kQ9 c\2F[q*ۏvFh0?Bi}*z#) <+&ͱbi@Gi2eᔤ'e{QK+pAղC<0ùRL S=4;g$ .}Ʀm.T Ah35[׫_MkIRp}OcJ oCDBS$zaU2r9 B{lq #SC(%0E=ZݓkT6ڿm!*~f ^\(z:~(=0ҫHa)A~.Keg< +7d n }l7?n 9]}Ʀ7O},Zy`=U !K6_4pՐZѵ|8n薞oV̵v="HcRl2yP9^8ido 5L3;tmnݽVH3΢ VWW*z#B5ɝIdLiV|-_~ *嶻7$Ku?'"0d dxjxx;!#YT+O@w;-GXT2UmyV5MST;M@4ձBaݝx9S0Ԑ1p3%/ה fܽ[W6?Bӵ:.&^#Zl$2i{\M7yW <c uH%e7hWIJl(!|`4H٪+S1=L٪ &3h/`(ƋQ؇ )5a s} Ĝ\XC _5u3EbS:He˜* Ku2=zA#t '|dBF%p{ٳQ[{qXdt/ nn @WRT/߅ۣ,1jD؈JPƹ60}T6gͼPv"Z R&8;fe%b' {Z}Vqe=Y\'Սe; zZ!~)($$M.s!iEX_QpjȎ@d4QE3ɗ!+P q~,%ڊJOf:bj@[u07ҿs[1`[ny!OT^Kƅտ \Gũn^s j0"_##_V=Gl^T4s=fG'פWIY0Soxk[IpNhZ^[wM1s!}rX`U5{A>`'W%sIEØ> }=Jd941;LߝOQ=f+0^./OOI7e v 'ʋ$^a&k)Zu~q}c2>Uoy&_EB:+]Ҟu")cv6=(*{#;Th́뱭j 4 ]Xv=8ꢥ ÛQ\Q64(M8CaT|&3 dcm S˝zr8$3Y "/GPz7׮e<ѹZ jV4+ (^|QUe-2k{ R Jk>qQOlJك e~Sb5ZX {b<#$U\cAa˧b(gUUX=qf8#Oڝ'g\1mʊ`STC7<4PC~`(bW+t#wA f;M`]dnw2yh5Y`iӌ;9[4-Rf3 FſvU"l\"BVkFҦ~σ\F ;r) $z[OyNNN1IGzmY2I 4ko-YQAmf#RhZFJU&6bSm6~ N>&g ^Oşy$d*'t~M"6Xn0R40*u c1{U47w^R\DqԌO1Pm*WANZs1*';QX:A?f|Y؝`J7L'd{*H~Y-;VִKY'K|/r)]]k\Ǚd S\{TiێT$i3=5SBsR!yZ{0ӔweX(bvCgRO)Sy*=4Źj qRGnGA圈Ljd+9h-ҙ<v|w@l$r'aRvT8$'%^ۀ L|*eTvZW _v5T{;59 )(R^}rjU&Y|hA,A 7C5R]qo!5Z%yovݑʝ YA9/ ]]`EJbvxaձ+7KkE.OY)>̈ (G_4H>|pkޮHRfOp~2>/lb^k,._NXU5ܜ{?yQ2'$JjEj +^:LwTy*y_9d㼲וb,BX M *Yn f|gN0}*j %\3gJu8A:4RM#A6`Ay|?L\t_Y?G;X}!}:ەAtH\+AD_S pŵyk)A&i3P79^_VqSp95: YYy6iD  ;r]s8I'3ɠS/RcZ Jc5}MwS0Gv¾R32:H/o# +6qE`F+P. +g8lͺS/}USd#sMorSH|E))1v1Ǯpejy;!Dlg NWM ؙMVjnQ%Ӑ LVb"o -khm%xȇtkG|?xԿP {S ~dX>=ÙߟXN~,H7P!0wg P)M^jۏqŗrFòa.UZ65Y(Tk ?xjxqSPhsDA8Ϯ`V5M MG}f=!az8Rn& + wJ|;w{ ۟] ?L+ :@)uFJ4k>W- r0(e]$HYM4Y(wO)r0#@ݘWx.\L 3W+ 8\*bf͗҄4 U4tIm{G}ظU-1Vz-AU>O9@,^ui\j5ԼHkl> pk8҃ӫۊ7Te"5q `X4 0!0ߨ@siZ<0yD0[.ǛnqߠW#D,ЭM[갩~4Y̔Ϭaح69 p:faLc77{; EW81p]».d`T [/^b-4L93q":D rd| f%>=j= vY/n?ϔ2-5uN'Ëu{mZ#@R"7E J. ZgX`0%sBh4_)Tzn^f!g939j6I/,y]M#Oqbd"{Ww]1(OrM>3b-[|- O*\s;)R^)B %KZh0T1XUׁpY/a8>Ot)wfc*Uyq;g^;Nߘ=`!SPʖ$ h 8}iTӰi_dƟf/P4O,JB{N27gu[|ܿH}4WLUs4/H XC%0R/ߧ*!sZbuvtA ƚ\pU좐B:> Dӄ*͖ 5r+ٱU*54Uz(q| @ۼADF8]oFO*8c@ MW&uӻ<U*YW^iZH 1AI?Z>JcC5UHi+NT4[NVI1l[ÞHMާD'Aໃuk[)~˩\jӬ!jlW%ȫf .qDqL7(kM ՠ${CM鎴|.W q.L34-cG}ݘF-+2ҠKvCNO>^$$ "\ Nc VORUPۂY(H$sJǚlPG QhNj̬UD B_x;|i v.`btm>= >b}x^Fdyd̑DtRjQc)#EQ V1v԰! v|s]9&@Ev"A|ni4YlT%\=FbI}) eŴ29Ҫq> WRY2Y;ARq ,OrAGmn1Z疞Mu,0>C/19Q)\݀^\@ !L=\&ӭ ɠ2Tx:#hў.V!Cۮ{|>j$90b9{`q}K~_l{C"ymO[-N%453mh <fNNYnsean`/n Kuͦ68ԒI,:*7iI\;bZ d0mvs")C~KCaszڟ ˤ$u(zrg-8 Xy@,͔?c'CF,kYCn'\qf&dD(P*jS,M0Io,2dҺIs8a#$]t & P< dI2)"6?<{BuMUf6.JfrHGZګuو/F4vL !5|{²^ty~>`IJ R;2U GP<ɼ6вhTnm=P Go1wE_m:Zq)[0tExQj '\@؞&A}֩W>MQT:ъT9N:fe[d#y\2tޏxVSu(u !cT=iz([ 6@~@sȁS0ˆ[lIND%y o.?62/$*dlcRP G\3C-_{}SBj!^河ʀqovS\^!ZTdU(񪉼?VG bUd#+K#v縺:TJN[gO2xWD4GLQ|͑AL{ '"Te8[%g{[&:HY~#?I$Rʿݻ_Cu t0]%_E%V9o(έ_%(zf_G>77Jgtz:\;rSjX_D-dy"ƇHslEң14}DC3/V1m94ƇQY#_􅞳[B㐄'4,c$_RM&H: bh7=[?9pKԏhg_7l1 B3%ӽzY6H?7cOLa2mG=ZB90/?"K?۴(<9Vz/K@CJl"iHub4Yt/rc5*ׁqoq, 30Lk؁ V߽8K(٧#X ^%JeXX*퓴͛Etht5WSRNPzwO0IUYFmV`0qDŤܒf2Tg]@آD8^䙝ufbWEфwVBMrץ:JcxkFj'#%O 񵹙9=aepik(by0 I\" Q[ ,WjH/!oYV5B:dbm "5_FѮ7Mu,`u@t̵*noOė}Z]ӿȥ4.!Stܣqn{B *AU{xx|rF+W絫xߵ#ktZv\tD)C;KV5lk-< ot<cj0OP|3q%}U1,ͪvvLg]]B]80[9罗l)ﻵ,w3\U(Ó Q7a D*͌V4FT&txDo0acDV>1S9`<n{)-ai,iPn H^Ǭ.6eg@Q#4Vꂰ#^UTXrYhZɋOLJ%~5`vU$|hy}+؍ es9,TNL"y}HG=CwR+YqxH-RT dՏ5[F?:3mBѨ5P,M6at6͜I4-DBBT6ZG,\u]8Z6g Kg1$[^8ڨɮ+׈ ׺ɕg-]?dZ\-uܮYhG@^3;.qeTO q}nq^f-F` B *{ aĮa/SU1c~&ME38>n(WvϛVWiLJs$ brYmh 9'=bNirz"%/h4Do:')<0:2dtk_=Ѯ>w&|N4skFBq$_tޑ|NkDý,EP8L!p"-H|\fF;RLiVઅ 6JGX'cԤgyaJjXB%z ?_fUסǕpc6>Ԓϲ]WϢ!`?1)74OP`N?{勁D([C.t0PiwU"ʔW[:%.J6S3ځT #U",Ff_WgLatPp(-JRg"6<N6ON*[#A)wdo 4":U䛠ay즿[Gc]+y&U{r]bU[P!cƐtPѫ ì3*R >.V5{ydE)I#<}dl'zIӣʤŔXbؿi7iij7  zIatl0I}9!*oa,n ֶ򁩁%wٟkw$j\qlHgخrS ` 7Ñi:Q ;asȇh9zL !w~r>&l*^LWJ˙=;D'ݻfY@j/G 38ɱ&/'B%Vs|4ilaQ:`p\E4c [ Y#xbJ` I*ypZ/!%`Qb{],Ý INJIV,O+~6$Ăe4LP.lJ-77e6tfv7BA(ؿoMpnhjM\72 U0zdۇ'h\xNDo=;[qL ԗ*.X*\bvBgY OYU, [qq&*MGW'XԼܱK W m8"д)YPMOZ;Q c@|CBL\KWPcܾNk1MO2}z@' e}Q τXM!Djsݕol ,]%L! X߷ႮHĖ02 Ra?DcC$Z= ;%kGr@Cҥi-e?ոأoi+>I@(T72iX{`hM]>6=n*Cpo.OFUhp9"X]oO&)xsp3#.ikm8d,2 7iL҉{ktOgT"AC ?~g] TfK)9fY/a=IN-3nUK՚=hvr(HMy>~\6:]@b-kY0p$YYPZNyaHGpACTӀEQ2)\9id~'{vmL Nga .T)CoRB78NhI.w6D)ϣ_ߴwŮ =*0/V.μ|*[ݰYĠKrUΈr4+_t\u'U;.yPtzu8bOi ߨ|ۺ<%LA}#˫א*ؚiƐJfb̴ϾSd|-_ $!PS vQ$aD I #ahXM6B^))kXKr6ooWn __/Ѷy{{,%s dm퍈";jYoH .gj엠V6qIqkOw{?Wm@ a,;|9RSS"@xD+7ŀA&Wj.l{=1|nծYJ[@e#2i%5#wp؈ ݽ["`̠h UW;?aot v:bTHRUMJ݉8^,!)uN:ݔ4ɵYHp%E n, ̒# $=#ndz']BsW a}&`S)X 3ı/|w(To'a*  vsHԸZۄ =ebAutM0PL2z>AySƺ~pRo9x_$(9m\>̔ ـn$/Ǥ\sRWfsk %G/sʧٗ:CVJ : r\;ϚLj¿éH>yfEQ(XDe _@8qˌi)+r)bv)߬:B>L,z/EpBzjo,ƦK~m]kl'*`9.:fpPR怤1H`z'C%=66Tm릋 a:ҘBKaDiD axv\2hXe6Cc9ɱw02c%TCS%jTA;tp?Ƌ ID <5HPiG{^n}N L)'cx׸Ae{D`s3e>FlGu\wө(=Cx=#=vLЪD{a_wpCl˥m#S 3&p_c-@0KY64-Z%'υv;>dƟqQpĴ~Pns碯5{ʱZK(w(j͌#HBFIZa] > X}{R6?`NO)w3?d$rx+NNaqͯ^Ypq6s7lG24?۔{ v- ,vuߩm]uZ 1ƣ"B&d x|d)C:^8zebtx)9F$gt딁"Kz{ 1ΡٓbRt4y_ͦ/܀8)']"Z')VֹObYl0 )Uj`Byqs@g?M<r n*z\ұ+SzHJfޚym~Vrt+@? X΅ʉrQ:Ǐ tȶa N4,~Oؤ5ם4K$qA؏G$K!{#t.;IxGqQ8x售`jJlWϘ[ G-L )갎jw7Kxq0Habmjp[gDRG0wQ3~%֞0:u1&Y7Rzb*41zJ`U lwpQ$g<3DUWlzs]p3PR RDû8kMc:F|S.rL݄|q1ƭYC5@VLɸ33i '"L逪,H<"]"Y ZE,31 `ZˉDDDzf~@(V7XagHneEoeL~}_V9| =h_ܯl_6,;㕅9hYJ= $*ƣ:C/~BWn1|x7MbҜc R⼊\ l:aW7rZbB:4tSt-3LMiy`MAoC[$&N|0JFƆAKH'D^s)-"4VrN^NwpHLնʸMFJ`ydccRD/+#T2el^^! Y!#.Q6S=COvү3q'S^B|:'/ i88:-99ո0/YŒ 鋿Lւ&,w[sbT_o21;?bF8IwDJl[5EKW8Yd}ILp/!sWWޓTdH= ܁BQY YKJ^ķ^r((f1[R@ aY6mRR$b6F ܮe^R.7$Sι-6{\))'ܯ@9CO,+\7SA튎9!TjE&Yùs< KwfBi9ń4*`/dщH&Gqg0{m`fR;5{0}6;*GJ;BXqaߏ/im1v&2x@df@*5s*}N&)| Q#@(RwS^4NsK ǖ~+0ftԼT^/E 2$_ر/8Gk㭌f.ŒXStiCk멣 DNs{t7Or ~p@mg ”!)ӄ|D Xd]e9zMr$Tm TŇ-MT@.l:QvNK8[ ureTͥc_'<5g.`s E'+5 ̦U rp !k|iYwiHLbNMXaN=R\_ΓZрź1c' @ CY#PDEV-Ɠ\tX; nn`&K}0i`)NɎ-Nox$&8POw;6`Oɛi*Qϝ'HGe 46O60-fƨtMTe;_MwHncF<k^'Sk엃59+ @f ,ˑ)hw33Gwqe14#{vkX EW:~>a?!S -`re=#ܔ^is>s79QC  %ƋJ_VOԥ@ml|3FCv;1HRN7|%E괙> mtytELѪ,o&Wmbŗ Hæ8 o0+<*GYFx@6GPwAB(R'"oށ]}5^"$r8yt8&x42%=>.JWp}=_[ٸx88$H"x)D #!m3#i~Ϧ"Dh7/~a] 1QE$3LE}tؼVfRȋ!14, ` hL_6! ae]1lC&fwsCτ<3N|>%ـfĝ;1bpgw`xS4")Fp"Z`Båtfd K$+V &'3zOiV̊=~X!}&iGdSŲSos$ ?2ǯwsZQ `z@\1*`ғ*"cMrv>iӛ ^hV =UՐ,u4̲~$FVn |GiN)7aWz3ml^{}T4ʇ W_iP$$˵4{ ΖkԜ[Y0WqZE<2,SFūtt0FwqAgF]zID'~Cg~;QwoѮ<.(OE'wcؕp"[Љ}*LMdV}e8iau#=&I P.$CՇ Dc,)J#U" McXq9mA$.<#Tp-$۠DgxWh8oYl?]zm{*R `nrUPՐ٭Ig.O$_u)Vd1:ZcؕVJ. W?3c5ӡE5,\tmg8c/y@'.dh֑ )W .@}kV 9fi{ QF_']-Dqe6#꩔,W.Ƴoۀ49kg|ВئJʍyMS+@'t p_b~QJ򢌈%^W&qm9Nit𙩂S Xñ߷O̠%3n.48χ(1 ?E'Y6fSO*Y3 Ӂ[iGSK1 PI[L-ACn+QEQ]OBT Yi`M>n+g~^q];vnUO]\V84\YZuR^ݎ8(:F"xI /v4} bVAQ!X,4R+IÚx!(;:O m(؂AJ4+bYYN4; f>ߋv;P4YQ` U0 #qĂ{jQ<2gV̗ٓܳy4RYceu <3.jʡ]˧ǸV Yw$g`(aRQ]jUɅgwi8+X3 (* =aw$-r{.ycDV!.0Ic2QOw9u)Z&lsbQxMZtz}NY|N2lP@5}CiUd}ZkB<YIK|,j]?BYr6(\C ,; Af0f'L .-5 "΀+G(I'H6$AAVV(-Zȭ:/4tݙ8m$(Ӱ.i [K<9Y7b 8X*a )_5T5SYaҲ2wuWv }bs5Oj17ltS/xA2uC kRG$aW&t@w#nS>O9,ŜzD v }K!OPYBkylw{[ᄚcFZm]"Q= ~';w}O'=%L L4t-: ?v/!ԋqsY3l"V 2ZQJĆBm\b٦Y0vqeg!6N/WjHL`MHhAuɚrN8ˬ s-UVC1{zv08-[G5x!P,[PC~y탡x}i`4R 6q|/ {K׍@\7+^[D,Hq'63=FCbVΩrPկ1l@$.z2΂M _t"@%dcֹA@/Õ 2m( h6*<ڲetƝ)rvlmQ(-m`eN%~6`lOz>N{lkiɉ2V8N[-ESlWpnUTdkU>N 5_jxg7T0\R Ć! `2g ׏)v1W2Rs07tTZnqlkWV#/C2El3fH ,М2L yV%=HozK1E_6(#Ύv5#NC{f۾y֨bcF 1#)Qj;b -/R;_K8@TL<=fD1.Sh&:%#&UD%߹0`F'G񚴠t64~x=8@!^$KB[#> JZ6.ʻGr#j5?O=% 0W/3y1Ej2XBJf ΰ&Qzp׺ ci?rm;'I lk,03mzNƞ*^;2Xp޼!F}7G³Gf7g_-+1[YbX:q| aɜǫ:sVBbp@[luN)01#iD%sK^W7D^#Z#6PԄal0kr' =" ~a! GLVRGX (i]HSvl;U!JM/$+XWyԶ38 y6&& y3S*3j/9ʡN5ဃ/˚==TwX֊jAzZF0g 7m:찟A5@B^hZRw7SD;%"' ]-cW x Ϸq5t7yo:-ba9s! Z4F6ނ.A&rdsx '$F3:wem_tRZqJNQ\ =Zꉀ`];7"h3ϧCE4ĄVByn3CkM\<ۣuCMO йuZf"r[J󇀥KrApVe&0/ DΡ̩z >[p5Buƍˁ:ubHp r㺀މ!qKn=a^(iTZo;p8:Y,,ʃr^{sɥ ?@\tחJ Vǔ\ 'V!̒N3 ,!uj]qaWz`2:&C=|R$`LGGf^Vо^ 8+b;No)smQSC<DaC2A{Zo͂MVƓ Hz-GdXkv.q='H}5[`lU|Htㅋ;\WRH[(鬲Oz('#Xd;1iAjH] @7EcB 8*q}x7h][MkYTV&Z\e|=fLNM[a FC`9%m[) 1lveRx:g0 Ha639/\,QHxb h/5Z,~^]ʔ WBk EdD8Fy>%:U_}qe9ѽ]X-I.rpJ,G!},LhI,_(ƂbYÿNC!(1X۪%&Wun(󯞮 l? Xg[j;%7^ Z9[xe:snJq3}UQsuЪ{Dx(hvq+jnD>H&hM*&ip#^l*aw-LKi{IJ'B`A$ MC5q  Q.'wкxhǰX%lBrhw*=.W1ϫhq WmtQ b9 wJBOtX3XdE]G ]\󀹁Ts* +4q!`:sImCSu~ҖvsE]\22^` ȥG4 IO>ayr:P"WFhxRPh:uDidLbFv6VF˦\!1ݦicӊLa;&=7^l&?H 6xU ,KG^^ۏ-並 tC2ΓS|NeZn2Ǻɟ$oq! R9sL{4`JPd: ~kO'F/6N]B]yRz(zI+^(*ݣX< 9MWؓ!\3|hW8TeD=N: 9so!JCT ZiT, $[vƛ^Te(:&\GvN"ٻt?-0*:1#nty׻hp *9 K9B10uoR!go `iR*}QA <ߞ@3d56,<_%{Aqf_ޅdz23~v3CKPl;`n')fgb>*dwh>#tTG0ۧWœ4IaqM? gtU?4TTjF(gt~#}P&`*e=M-B {^pM="nFşK`H/;{]z#h,rG PٗU/&}fG@^1\3J}4ƸqӬ$h*> *U0yƌ0g?9Ri„iֹƪ_ **-eWt/&)VL2C/()~w}~X {rF4{SS?9(H+} 4}6nb?`D澿.Șˈ:c) }o <:Sx@"v<a8W$pJGNp7zg, R.d]׼:.f`IV̪: @L.ws>g Q~.^>%1 %O7Ϻ10MarPd2܇cyఛLP=EՖ\P$LCf'*1j $>?nd"PS QN0Vwy=Sx6;j.u݇l| g;-޵9Yw($uʮy9^`WAƸ3 :wI[+4'3xy*L\= }ꙷiNYLp i ˠKp(81*90-VG+IJI(\=KøũԶH4gF0'1;ycd==xA:h&@6Ngf%%ʇg?q~܆ %5 d4}^t"1>þC_d[ B;8Zx±]ylPͺ"z\ke)vFD=-g$6g^ /QoĠ""X T/mW|\=vV\܀CͶvO"}z6P="U(iKߑdɐ97:o_ړnomS@E'R:XbtC, YE3vUbe; 69ڞȗ3ErufAef\lif*W ÂpdZ2vIQJz/dFY|h.a{Pjm@=9,;QG:n& tn##/BC%zxWjS>.Q1FR2a>L !ktjڟTXl95^F  =CT8z6cF?cP%Lf4JQ3_A1%?ҮDƸY{qq^n]'q/6@#qu͠IKyk԰]YaQT'̺2}wX^|sAٯ^mȏo)qxHP]'`:aDz`C fnioFƔX.d7hʝ|!wZX_ 1h?xTlTgR{9!g?Ck;GZ nY8r!mgm5jnuoR,BSo_Ǝ(xo);~Yra>v wi Xo'ZgMᎭD@ g$=kv3;Vķt PO_+VqH&FsPNחȉ=Q:5 ]&P%T 0LIݎS1ߞiJ+W܌lXTt(BQ3z{|+ ~Ia;Xi.c5aR$,~_Vu^-f7? I[Ϙ1B@;Np'u \{:YqU5=iZqRWP0uR!12dcFlU~JT3suָ-k,Ff 20qedu<ffo['Y'mUkj-ϗez Yxt, y`5C,RViԔCN៉VDֳ7ܫo&n5ıI?b>$qiWqea}Qdgw[쨷 )bzy}zX%57U3;s h.'<.[Ic! Vi((/툝pM9LIMlx s-zOS F E jՇ [W1z1lBu%MG42H~M\)݈.Z.ߟYҌ3..4vʸPw ֌ 0fPøJOɸAl9|( @ V~J=Ȫ ܍̟&J<6wi9uX/Ojd ?nK I%/h7BXᏆ`I 3g.]|\GTMRt3nSpEok/legI-O8wEAuaSQ^# u_|=wRb42Ԓڄ-: lԂqLOIs|%_ٶ^_MtJO=KĊu^4wkw.TX`⺗БOc+VA9; V:/f؂ߨZu pTOF70P˼iy:s4˪:PEKԄZ)wݺO.ɤdo\ׁٗrϮM /y ~1멉O6|{JN8NB̊@Ss&Ǟ½1Ics:U~GsL=XlXfk b`&sG[9dJؚrgvE}سϑvF,E?+7CǟS2}3¹6l`ɩ ɥzȺ7B{Eja̜&1;PDB KP,Gŕ!6oVo9$9_:cW΁uйfp.?5h2 wp,@8"8OKR='ei!J_ Ӵ]]+-Jlwi<^e-H.8%P/a{r*X"}Պ~zxŹj(ed tCZ hdi~`GGSq:H֚*"$VY/_n$VYe6(cl㒙̄`d 7 D!-^QY2c˫Bp,X$< jKxlC7@*2֤Q;if.^.~oӄ33k*ҟiI^0V%e5"}sGV3T 2N:iyEEl1MRm|&?gUv&ϑC8XQ/J9xӭaA[92p`>)b\8H/r*AlzZ:2!LJq_b#@HDxȄ=#I Q޲ F1ů(4Cݣ7vI2ettVdU / rZH6wRz"7CʢCm]UC/Zuj)m6%nBCvdZC8MC4yޔ8:I]^u֍+*VzUŇ 2ɽ3GDA\+='bV=jxJo70 >t6U(x@·k3#i0mSەaR_"Rz9BwJq6l u#ӿV|x=Fn9J߸,9h#q\K+(=*mFLzJq' p޽HDM9*%E0km \(1RF֌ h((k`B??U%սwvooT1x ( 1FZıɗauXzcJ_cyWwf0sbKv:Tʜ$Ĺg aC'i*zԠ#Xyw~e(3j&NͰ(S¯}O66߇%Ac_b S9к_dTV6HYUwm杂$7pT|lo+5%3GAag`)٬yQOlOi苫t'.`jL&PqXMߚj Ņ(]0ڟ5T\QFRB908^ -R8[D~eֻ>cbu+Vxb,%\s&J w)~s `t*5G[n.&ݭu|}á+j U#c.l?oޮBY3Zr0S9S^1A`]l4mnGeŖ%pK~ iL'xm#<r,2,zz498 :rծ"*V4H`M>wbsCNǨ%7֕9!պn7?UI>PЀЍS[jDn-I!a(d>7`~N:tY+&cKxWo?>$rD6L2EaYLl,|aƅ5㨽E{;LeT !ܠ_ 8W/Ȇ2X>)1_,(FTh'YbQ䓞@T=S[\\φD?"]!d_,"j،ڠdGWc \dCݱEs"a7$'b˷PҀ Ɇ1BAYw%cDJh<ul՗sLxELp W\hV4̳$¢O'^(_^-*zP+V ^MeTيOXQi0;EҐvP+GQFNى(]סMrY"x^QɇGXDʖ~ //S&cQ'ŶU&A']{8 ήxhv)t~[8}"~UɎ/CGt3*ixR# *a '(*. ;O֚i,IZ@ V:- FDQ]eL0/>OK ,k&v`tsI`烮dTm9άbII0 L rُ`{rv1_յI`+FE m_7uT=olȹZzgߚ͝TIW`#D:Mbg?`k!&G_LDFZ]]3kNp61Pѿ/d}|d.R_Yc "nuD+))Czf{H~%S-:j"]ՖCD^r koe[=p-RYp nO[5z0Dɷ\2If*R]ز]OzrbŒ CaҸ d]ZQ>ϡar3YV' zywۼx5(*h'i~%Yϟ7m:%%e4n\ 5x텅t 2R?TJdrOuvhnv)oGMp@kɷ+v!T>ݐ"1 @8ZݮjQA[w>?r%JfbO"Y}4ei0M0#8~JC8_ 3[۟LԪ|=͓ܣ#^9T o*"Jm^PfiuٞdA~S{unaCAV?[>(F߹{VKupM2H b(^ߪ}w#WrJ~d/f10sbUTe#k_/ _;mR-> e1pJHM吒zl7_7.;>xnX#rSL%1#Z&Y߼F)xBP **Dtɛ4cF{eO\c'sD?_;km4O֖릅+e"N;YyDi<]N>>-ۼCݙҰ,{_f@'ˋ~oޫ<\:0U_,mlИQx^) l7.T2YwKv40Z*33c WzrP$\myN }|!8>IwwOkbИ!F]Ֆ@\Aծ.cT!q<5FwFf\iK^k# j!TgZ6{(?>%Ul,] C1zRqm껫cZFGl^#SBw<`bbx93(  z;ͬ F ShDOȷ"dIIRp8YȱFhGe<uʗn ͮ8oJ%jN>Zʂ,"ʫ[ }]BAΣ jړP,| U<ln 4l'KG4QOH DRuۨ*wu3Hp~r.f)$^&k.\ ~L =P-D)1'Np7v"~h1f31<+F`bNd`ED>Bhl*lDWu҇f$[=Cp%AywQE`-l;EL}l.wYE(݊.JC׹UkjՍ,a0Qi. )#_4ٮz4JpMA*932ʘvkhq\FƇ]ÍX̪C;:0_әO밊]jsȔo?ll! 4G,'bgi[ V.,|+܄Zb} o9H2ͫ4IٜC8:SqU$E^FippǏ7[MjCV{TpZ#,9G.+qP&m{)/3 ױ=x|kˆG݀y[FbDe| =}ҮrQV=H/G" LhUp]gtj ]fΧc,9W U},&cQ^y@XQICsq<3rFZ8Ħ-S U/[[+;GQ5? By l: h>ZPš]W⪖݄Ef8螰ɼ~{U 6:|z?*vuǞxB( "cyt}\jͅW] |9,]1+xkuԙ.a.HP,5_<"Y9L$tzt;Ep@j̮sSmVxȽ}77@=Yô_l!h~p!ΛD&xj! {Oa-i_/4i8 VU] oղ*u;Ӛs0^ (R4)8٬NM@҉x+Ɍwharoxn-S+08 NV-xejqKζh}uzصJǡrQ(@Y^4)tG 8DvCKG[p|ss#KVlq}[Y#ء-gs eoN8 +$qQS`ѩ/b8=/?W$)RTmSM驈9̾Ul < p'*g LR.Bi뛶K\yuޏ2k&s >8Ve% i |+YzBVФ@Vu˹xK<@ir_ql[BfDwB m36!*gפ'JWM\qpI*ul9ǁAήpӢ3T_W Pz[G{(4É|b"^~"h,b8 ||sY8#W=^tp +1eI(]R9fǡy&RA=-\f0ZwJ޳IKKu7*.e9{.R|{U3+H4 s$'Z;6j -]鴕pNJIsbO oo sRuCt ~՗le^OEzX >+Va(a5-W]. u^mE|>$6F-n7˗ӗ>dюSCGgfZAyö)~)hpv9iOI>IV)P Р)]BuȸR&tm`xʂaŸɁ+0TԪˁv6&i%1Z;lx'Nnle9q+mcvGj]`s|`H1Y9Tg$<9hiaV!q}R걕rNk%O wFPnD $\VhA ՛T;{P80qVp`)tQ7Ww~G.BnضM !0Pn/|B>{]Fݩӝ .|+Bvh>Aײky%5!¿L9b9ETiiߚFs#?M'̥{gL5 _9Md?Aq 2_P?1ѳ}#毤B5p }M;xbsQP}ߑ8Z>B7{ "J{z|ox6,9,^ L2#tv@g?Iff^"?,3Q`ɔ(Өk۠ ٧%#f{Mz6TLXw*PM 6}xM/A v }`{#(g'Qyc9}Vq=dFη8Mz#~kxETx댽.Dr0C4TgV|=$VFy_0J3ߟ۬k^(/ox\jgP/RGϲ::,R]q`H@UTb >!<4*m +tV&NG|nqjZػ3mJx_v6y=% ,v˃g"5CKվ$p+۔ |dq4*B5/3J7j#!F]ehODF[SU98amM9e>;㚏2gJ+MH&ͭgκȁ'A䰈 y!~^5O2PB ;+d8؅.8%ޞ>+iBٙI87^dxxIgYs5 ;p7u] jG|W9̈́z4L連C'1%/t{_`]_R2za,OmZ I &yAWHqC7-)TGhvpUk**QYnqb=< Ďquz ֤DC-9k_&LKL`*;22WJA3.كEKNih Q_klKdvq ,F̃nIxMbH,s(kr&PB$쏲e?:PKNzۘH[2ݲ'O:_@%AGU =]}Hb6,,m\Z*d8VZ3ulzd8wC?ؠB$zj©HL!+*:mF @b.e#tZh1\c P['wF۞2jGR0d/*/O*4rPy:iPΨIJ9O VVaK),Vq%Vny+85M|yd>QCፏ$ )^E1ѥI5QTa|+aߛdPZ6.2yMhe#;zPw0]̞s~̊CB2'iSdOn;r1'ZA+r[fKp;}dNZ;j9ο0/XmC>fU RVoa'#J-f46_j@&n7FPj9OI n\o`ˏv7Q/\dDq?X?wK hͱ5 >Nn8JWia}edy~X`Ӊw,x@6oeU,-G(bBڨ(Y! +ڦUcnhq-uf\ ږNJ !$`ԃj5wDo_IwT6w(yZFL?GS2բ y0¿<"Av%yP;%4o=m0G|7??7u:^ ǂe+:LgES`o.c$n{7kU|oЅf Cɝ[X&U͑FpaYpPסy=kѹ עToH2~#FU"#|D`Us̊x*t\-TZ hc'pjF~'?R-4q0PPB`-(y+`+lH;a8M tZǒ9Bru|W6 *4=*aL >HșZ65 ts4l5:Vxol'\A'_j[r@eAaj)3RXiHE{Ƥi:V%/1Kw°ЫĞ9;)6vœ$)]NX\ h!fb^D6/Pcqr2EnZpRuLِ-kA'Fso-k<&G•QC]z! U ^x,ɮ>SʝPNusIlT CM<EFV|fmB.a3$EpFNW֬/8܅,*HE=uUakˆ(^cMιKRn;x+Kj1 }V GOOvŖrB3s#rߴ^Ad'%s;@<߰/ca)aX`5W@ܦm;Kڻ塴JavxZ2!ЭrjC7Zu Jg)>;]dBʓun j(ĜOEs,p vTZE׎qD|OiN=SzPզ_;I K1ح't1_#'$I)OtSmƕ'KcW8|;ueL6yv[4UtJq9%Yt:ځ@]\WKCyq{FYaa5tO麒 4 6Opˇ&cy{ L 1Q #$" :T? (a?@"leT̐'}K]zӶVYڑA"p[^ oVO`syh2l6=jk!Al^wkgZҕ}L>l2fy(Xs2~iVk4QeP7rz8ae +`ݴc֓a,­6t9ތm15-lRg_mAeE)WMcQ&p*Mk}Ї1xށf+AUlܪ1,p`va[ozDD-0l鿞;]h]iGU 8nY⊱5JQchAhx\q͌ e\:2 p2nx SJ\!%/J1si+`c\R- y/p-lFC5X"c2/ ]/=-P)k: />T|۵-tGy{\ĔVJM=#iݫ[}Pc1.([W7KOQs(0 E#b 5J ^wVx*l9˺v6ۥ!:j]q%t.Z1Bz4%_{u,܏>&WMޱA*hL2hE%Y#%ĝQjfA!o+HZptۮ%Sfl-T MߓȹM3d `5 ,Y`rԏyr3h`w EF47U 틸KiI0%gPR/H}8߸oXDnavLv ۮF^D8g4k_)P%Lp0ͽfS]f }7:瓲D‰T;Ecb9TӈM>6ے0)5E1iDmϥ/ ȇٻ1Q.qz/^]=U,=-1']qT(g3s:a8zq u$/6HN/>8X7JG p)/-NG/ujK窬/B()߂ڇ0 JߒP%oR֐gZ/r5'N2#;7_u:e i5N J]w=ut70\s4aK+ &GF,nj'; 礓KjQ!J+XgׯKz臼cc-B)&fw EAr'u׌;uux 4 RG[ІfFȤ7p8z.b`(Ei#Y lEĈsښ3s1LAT]\0 drí hhY'y2gkid% @P!a!|tmnI=I7){ݜ'֣xT`e\ kF/ ׂ#>ҤO!:#&RcI-)5"Š=O6Z^Vg:eԘe  `v=eM#o==xn\pHaiP2555+&z:>YNM @~J>ZQy'tSA +[f 9wl85U{ׇ.JݺT\֎ 4h4?ɽQ>`e#G= ?{ɥ|xAS7͠f'dN[Ui,8M {NqVMA\!0F8- SJV h#iI-ԋ++F 7>6lNrwu+XRT185\ */f[Gӫ VG8]MvdFu#vb?AktoVX?&GWt əBIF+4ϷwEU?C EGۙ-|ue\{-}c/G/ Mkٷ&6ؓ,D-X70~+,zߓjz?^ G=zM^wsg%.*-.wV .zݩdR1 oœ<(*?Z XV9^zQu[.y"ɻZ4{<ef1#trr,_My,qIF,j8Nc9v,!{Av[c/b|SߪXa=d'쬹?ufѲ[]kf\ܟBdUoQf>(=pT>;QUQ3&&[nvFR|Z?B)^8I*n d-s\2}Lem-)6TPDzШ]-NIɂV4|</E(A-X>@k+4r7ԬӬ駯kɴq>YR*9vjZtL#bX7֩|mm֩%h]bE5Ƽ3Ctwg} z{ .|ߒV~]mHycSԣtY!VRH_H bpF`>e=[ܑ\l=R i-mQe3SUm $8kFSjN̦v<[i_].QOx-k 'X[%eLj0@-#\IKBx"ly-Mx6#ɍ +01$ےG 5-5a W;㴻)5Kw謑F=((\á'. 9Svobh-Ea SOKqT?(y$Duo]M얺G[U`iEu"hl2tVz6f9>%wObbAkGSslIްW2WAxj v:gP+>@9}hAڳtSp"ϽHd"b=>9 biPi2e`Ͳ$u )+ zC (RO{z$T^%E>J*ic1 SoWśU`YL9Btpa6H! ȕ$JD,【h9~U柛9uwretjfC[o\=SD#8 *|nEЇ|`Ka'Ubtl]db hev4׮+ @z߾$Jn_NomdKe5|qbh}i:Ʀm̐lbo>Xԋ?ޤB2JTWΩ.rY= xtm7%,Â5.h>rk5B4mr)Ǜ}-`aL78S4WXF` @ L'SpUBQJ묩a9< r.fxsKWJ' @(v0/K] T}HU,XJ{E{Eo7pjH4醺+ V7 e!IqPEձѬaVs  ֖U P}IWelgG3Bc3Ё5D묞;],dJaWot8ҧc.)/Mk\$z'Brپi3(XK}3_Y];> ݺ㳘%Wn\GrTwKŕ1W ~B@C]6B;|vl?Ğ_1EֹΟ|hYR@"Fm)kTbtI>ۦdH~2fk6 (n{xbJ?)[g~-d-uyT>:&qg`C"#LvHlsfL*y|\s'DӻT"҈mu8g;&OGSw1@U&2e)9 >qJ W$wh!-blUM>HN_^W{ߤ g\|F?`( aI GF :!6l`LFdL5+ȥv<!8z1~8 v/:&Љmгo9/;;vu6>!경r5薛sd+NI%+h~: bֈG%lS"ڶ4j,-K ҶbTuSBCF,㵸 Ysw3$pʫ:o^DZxAU1?R@SaNc'(CRf`Of+Z7*t0u5`Y퐪Ǯ}Կ$57jwm=V> /vDU6O`V3MQBD/bdr|2٥k 'օ]_ΫRR@zc\!:U=vn˙(idf[*G]seXRݜ84&9_Gjp\S Is_E7W2pQy͉jNE.1Lh|O0oo5E߆f«^ 6CJ]DDxΥӇ3-[C*52T ;c)h\ByBށ̡EE**4aIEa0.r(& PVQmHܶJC[j<*q9%:knA8 syihc5RI>hY< Ge￴%x3C>n1PKjX.V=̬lهWk JZĞ5SXy* :Y4ʕ $lVؓjfn`Ƀ0C5Q^A&{]8B]sd&"mU7ìx E q,5BLE`)9^ե @o[&;w WGP <жGTH:)x*Tj5 ޠBF#^~Av{٬UZt#W+[ˉVnŏ|Mp4 ӬHRWCh8# ܹl3[$TFL,J.Vz$#"'j\c'_^ Q>R;~W)ӫ4=Z a8^t,:b>ibC{$0ԂtIH{"Aa)Pu;`:} f;?nvԣ" 3KkdjY\βs+}2b#7o$mkE8\wZƶ]jg[5ɪѤڽ?y)sWS_:k0x&6˶\"BYٔ UhysxQq)xȋ~X%ZGC@eP~ge3RG+ 6$XWzWѪQy}=l77#j{$) CgrCXڕ TO\5/#+C4XB^UO'o1]v4Am˜k0k%1<@x,}\Xj4N)U#*U sbEAF'IQ}֓~;X q9V[i D֓} r>Gr Q,<)`xjIP8n0E5i:/rxtSyH_۩s3G7mÁ/2ZT7P ma2K/UpIcL,^D-&JK. C-b~=%4`M )irl|G#2ȽebS}…] o?Uz.kn1.re4WG5됬mQغVp1Ӳp 3Y2,QF!3)33֝ȩra볛/KW\s"$ \[pVi^"_9{s@o8rW[jۈk4fI}H<UF I)A!*,h'Ak3ly TX륌j'dS8_f,AX`wh"$Å_>Ԑ/s>¤ȷM34 PE˶8H,%ݩzY:#G Rdq7Jj7!obr;,G@uKWLR[`TWa˚Ϸi:d#"),6MwظR{ou/#׫rtt& ٚdV놽w\'f:#TE͍ `Yo~êgیooNϤ%$5t@X.ErG9G]ߡIPN t٨W.oZ!O)E?*+h$(]ǜNy>\KlS~m*}t-{30wR+4\gW{b rO  :χ&~xҀ`ziK J;U'08&F' l̈́x4 5GL◡>tIlkͅ<S+;"X}x7E 6rYg>=e~FcmR!]˳&NQcegK]Auy|HVLT<`Ĉs-B{d ]M{+b)R3W6^\|BQN),^T4J{oBFFò)Pml6l~ I(83̮Eko,sO0EKBE{u}SR~'#3Lp殲Pq7ءΈk5xڙ&/_bpHS^e ߋ2k^&>`C}}{ ޭz[ Ets,Wk+%цA=<ʵgGn-OJ/m{B'ӆ-flԻy0M*#4)0)͘n=vP_;|L V=-&65N= J ϒUJ= bJk{UU5?L -mF+ &.P "9L{5̕yYv}% ,^3~*P0绘` k#ިQO1d m軶sE( s1D(lwBz>:V}?:a?G7 ZϩzSFӽ\Ҍ490۰c ^d%V@ae~ut+(^5m5R8_3\s%`^W# c@PAD V UpYP$ FGw[ED$\FJϷ: ' FpblN 4s99XgZ*A%IH-g 0Ϭ rerפP0k 7*5a[|% (GBHi ot77p!ҚbioU" T2iyکNTLk ͒ X0AC&Y03Jeq&,{g=CW)LTO:)/`еl+Rc&H/B\aİ'pR"߾Lӭ sreI Ug z@BilkL#Q̺4ғ9$$Ea$M/G| -r9)#~zg{Z_|QAt-گ"ZzVsZlZ7 ,& Lߗe ;Ԟ$wG)"#{.Eށ&/~-u9.ڢ騈ؗm-UD"b}"/bΠWs$jS.j G`ވ `YLjXe`;Wb9w!NfLOxw(R;at¿J\ u_IDb7k;J$|Gj}d~xyGGFd?Ҵzc d264.ws& s Mh.p$W $D%=t2vAI`>/tVcS4fqXl Ϝffo,Q-^2}'%뒸Jj0WLV}2}(Ar9o\~s^4l@{mp :J}4iC HFq$V~孴@+(HPAǍC+ K[XMjdFJOS <(+~R${۔aeYoI>LeDYJA9wJ? ]SS̬*zKkE K\ 9F,8aB#/-M7׋Fap}LDi4 BͧO ׆6=ޝ0[YDa PulJ'x#;qҷy40.瘨GLKQ^42' ,xGRmJWq"R/9@,qrd@.RǦ(»/b`l?FF"ǡ8j>]?fu2}-!Ӊ)ZZ:݈ĹvJMA'V:4e'AEbP4Kl&gqf }h:Oڵ禖02T.88 'pq>čD "qu;-[m1) 51t - khU%N.,PUPR݂AۃLwpnN. t@$lk㜈/HIa0]NƋl@2ymْs-R11HǦ6xX|9>%՗ϓ#G3> >;svҥZwo r(Pb58|~jk To^lYHbҿG~x@fGa(RBFuMo*0E[gIؙSb0S#Y]p;Ȧ%FMW6 5pѡ {!I",6)mŋf$Ia{7F6r7,z-|e@ \5𴫋t;0Zb:DƷdpˡ@2P \l$8EUxf+KXߥ-r w<4eְQIX1–jTFB2/J=[0SY;Jl /Ck8M0=W'r22PonzW8IBp73UE%\6V&&؄UmDcL-ߓ5p˙?>>T3 u;<0WQFF; f߀/RZ2S6 pWZ.c