sssd-ipa-1.15.2-5.fc25$>WE#ep<*ҧ>@R?Bd   6 (EKTp ~    7ZxJJ cJ   ( 8 9p:EGڐHڬIXY\]^mbdefltu0vLwߨxyR(,78<Csssd-ipa1.15.25.fc25The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.Y.buildvm-armv7-11.arm.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttps://pagure.io/SSSD/sssd/linuxarmv7hl0hKA큤AY.Y.Y.XqY.Y.Y.2217d22981d70b82e5b7853cd608981720540f5336f07742cd979eedfb1a82d01a16adb0cbe4396ef94e870b24bee47817abf9c3e19250ea44273aec305d290e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90375eb321a321d069e83b58d17e01ab4d882f060934c3a512d7c521bbaec496e5c9e4092fb845f695cbe5c3dec6fcd424406531fb38734bf3240affd4bac40dbf6rootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.15.2-5.fc25.src.rpmlibsss_ipa.sosssd-ipasssd-ipa(armv7hl-32)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libbasicobjects.so.0libc.so.6libc.so.6(GLIBC_2.4)libcollection.so.4libcom_err.so.2libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libglib-2.0.so.0libini_config.so.5libipa_hbac(armv7hl-32)libipa_hbac.so.0libipa_hbac.so.0(IPA_HBAC_0.0.1)libipa_hbac.so.0(IPA_HBAC_0.1.0)libk5crypto.so.3libkeyutils.so.1libkrb5.so.3liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libndr-krb5pac.so.0libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)libndr-nbt.so.0libndr-nbt.so.0(NDR_NBT_0.0.1)libndr.so.0libndr.so.0(NDR_0.0.1)libnspr4.solibnss3.solibnssutil3.solibpcre.so.1libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.4)libref_array.so.1librt.so.1libsamba-util.so.0libselinux.so.1libsemanage.so.1libsemanage.so.1(LIBSEMANAGE_1.0)libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_krb5_common.solibsss_ldap_common.solibsss_semanage.solibsss_util.solibsystemd.so.0libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0libtevent.so.0(TEVENT_0.9.9)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-common-pacsssd-krb5-common1.15.2-5.fc253.0.4-14.6.0-14.0-15.2-11.15.2-5.fc251.15.2-5.fc251.15.2-5.fc25sssd1.10.0-8.beta24.13.0.1Y.@Y@X-X~@XO@X6@XOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.15.2-5Lukas Slebodnik - 1.15.2-3Lukas Slebodnik - 1.15.2-2Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Lukas Slebodnik - 1.15.0-1Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves upstream#3382 - SSSD should use memberOf, not originalMemberOf to evaluate group membership for HBAC rules- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Backport few upstrem fixes from master - Resolves: upstream#3297 Fix issue with IPA + SELinux in containers - Resolves: upstream#3360 Do not leak selinux context on clients destruction- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.15.2-5.fc251.15.2-5.fc25libsss_ipa.soselinux_childsssd-ipaCOPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabiELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, BuildID[sha1]=c81bbb0d1cc179df581060855402ee0cff86733a, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 3.2.0, BuildID[sha1]=151cc0059b90abc999f65651a3cfe04351f3e082, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)AAPR RRRR)RRRRRRAR R>R7RRRR,R9R;R+R&RRR#RRR*RRRR-R?R3R@R2R4R1R0R!R"R%R$R R(R R8RRRRRRR R6R:R=R5RR RR/R5RNiA.q eAwrq4ia!@[R>a*NF,?w) }]z}/=جFm(mZ+uЃ Xz e1T![²ǙQ7O"d *2ܢx9KUMD ;׻Ym/ 7NwUlYF} 70uj9`xwVE;T1vP2+09Dy2Xd"j%MvG)T OK'wH,aemb2\ X':&ЦM] ~̒Oq Aޒ#C{?8WD'YZb)4yuErSMK7m1"EH8䟎TӻOw':f7z$+YcرoD_{O yP0vt>R5u|h7oW]jW-չ]Z^:jʵ6`H`,3p#VktAхWҍI=P_wꀇ pY9{X9 ?̟nm^|ԍ)YBZ[/T}*k[gVvȾP2!!*/e},xԎ@A_-nfNsX7bE$cS'䳱/źx3|&goI&?=D?]w8y:#M 'J~4TN?olM [*"4;% ceT rWpp1>NtVf==?+v "Gd{ Ƥ~@.3R`w_ ,Rkjjڼ( kԋ5oVw{(o4[U c8[,ŖcD&fyq#ѢK!Xq|MBG91{N?hIRP}ǜfve,v⿉PΓ3 M+ZG6Xx-4ՂP}Їb-Cf2i:,"\U:S:Tz#`Ct fuZmloP:XWpb뚟KX\W7y@Pk Ï^j:&HV6*.m[ի#f?q.݀pbDۖzofG >> { ӹK-lzPaT,i>@R$ZLh'nұ,D/*$*[ʜ:[(*cD70A\.;Ҫh SJc{,9t f"5v  ;{;GfO-^Ht{½kϦ~$uY߱~nly;[ˍإLq02|IM!#N;7eA0-<8.d4|Lp1?])#_p/|~1؆ڀ0G, depU<5à*i%:>蒡@zƸ-vT͝ۈ6m_6.L;}m]Wa`nm"Z4E\\wwDc۩ (N+㍾~r$s1ĤwvU/z 'ePđ8):mgn<:%9eAn7 eg_sTcZB]d7HNErwl?MڤIz"bȃ s[-~k]ϙՆdZ٩AݥfS -bovô MfeMd4H4Y=Nt} zt ;Sap]<"BorǝV/4uW4ppNd]|da V[ڳpt1NV=s?}e ux*MtJtMw0n7di dvRku[ @MY"6MR\rn{$zcf]4룅{[wen{zAN0}̖sښg0D`<@̌G5j`8-Oh״I8, h`Уj_j{lɚ >(;z^g\:ֺ`kE3c i< cb<x 5|]BTgˎ ,Kz衙l: -A1hD8Z!^ MMpv,XҁPUAsO(R4 +,5RQS@FWshLҀ,0S pa5Ok[WкB+yA iG)@Ň#Q=AGIU*nVY:15Uǐf7'w]nӍ A4\GkvaIZafޭa60C܎m\iwE%g%a5_y Va+ |F`K~Pv0tIY`P,LGaZB؅F/(V:0c UO虋Npy8 ]չȕ@s+7mDům".DG'%* FSaڶW[q $7T\&T0 z bǔLn֕(8/5MOvbsd 1r},oΕo; eA,±HdOH~'|vC6(]BB޼~5.7bCBu|yst$)M\3}2FZ'&,`} 'fChZvOLleCٹa8xxu u(7 z=L/h 8-Ȓ0YaMR|xz䤿|/PM"08ʼgeo 6/x8u#ĵxS3>t}Qh9n9 %M NHSM[r`;*ŷkpL[\Uda"d7h .Dz.FLKaH6*)bE?f3Q׾#*PoukҾį@AE_q &Rv L76 <ժVU\/f6У̛TmEU`M^`1)E0gFJF**X|T,gkn,q񸂦merTF##X \D:H@mɠ_H&jy|Yq0v+b\},0uې q3A\s[PI'0!] jn2%p=qkڦ2Ph"Z݅\dѴMwq)Buv?G}t*U(.^"Ĥɓc1V+Nyvӵn)FuےU6g,EOYjhi+zI8='gWSʕ& c h-"2blXZKϢݧKKXğ-=$C9aJDv.0FE8!wѽGAeKBo$7ْ&j(u PnMJMU()[v)%˻J >H_9B?pW ]G47=ovBBܱ`LbvbAܞ=!ynRKٚ"^m32 rH|@J2-*Xo@IWevv1 E|gGS_N?fYn8uS|(}9:&v&ZIlUZ=:߸ܘ-di;R(v̮7hj/M|Ap` 9<bݠP <M^ s'M'7W 8m}1IeQW+؋i #cjwXQDaUFt nIElٞmH͖Z]9-0,j,PvH$i>'Qw{ x ֕Ү"R*&J3 =P<,֚}? x?S:ZoKMNV+ZxAm,6@w.P0$肖yV(jBjL 8o!stK/ *pC5Lw{n8[3] |fyˊ } +E[ah›5'KzHՁVVz;~p~E" TRPvY=lO\`kEfY{g/C)]W퐮Iw&Ɛ٣=4l)Iޔo*+ (.Ж8&<9,M}|)&sPC.X-i0Ա ?xcZs:]R4XoZRLwz|B C,yK9Jv?jkf6e1m(u)nxʴH{0AT '̭i"n?;QըVtZ)PFj Q%'}lčEWZUCOHbcTRF $Fr%F5uyZp`PzVS?c]:1bD539-0]1\~+QۃO5(gBq!5(ћ` hz.Bn"}{քrK$ FW\.ƚ 0 P@Mi7)LňlҧeJoR =[+J6n,Բ_i4+& (ﻡưv{ߵWQ~F=Mh(UDM0 s~!,L͐ԭvx֛u~H!9@)j:!PM}Wj(MLAԔ Aű}â&!h \RuRlq0fdr>wRm!lS8(]/1vs ww;V a%_/ 'RcWIT< ?Gm7uv"),{j( Z oAx C%]QrUM|Kԡ2HK3Yn3YOԚg%%h.Jh_ƇhZ>A|h&܈8S%Re\X8/ E/ĚBH 8D !.pFѺ9 'Q v1/8[A!:̟Gd$?7ZiVX/P"m"< #dq;oJeD0'#!ו PɚT{bhdTH$ YR =Ԉ0Z*0D* BKG/v( d8(ؕ4O9ΕrC SAXSE {'K ٚ@vbI{mȏΞR;6wkmd@Q$O؝*|V Gawuuf7e@pc&_ É4hGD-#PpХ66[߃eڠY*'`FjH[V;4 jh(;$OfCWߵC:;'@ҜEy.]ԌԑxW|B-aC:%Mwf*Oo2X5kB7 otȏ}R=~d+1l^L+PMmXZe1Q3R )ڰ)TbGsG O14Mlw 1aǡ+#Gmy;If<) kMY31eݏ5w[yNPhSEO"JX]>hWE(Cm -զ8v7g5rd-VFu[~BiZ8x\S :?,".=gw֩t]dȭ@Vy|v 7+_8g<?/ #`ФcB=0Wpl r'zʼn@V?s&Y2(ۡؑ b_3= gQ_!}}0c4DݍH[_9H0ko|(]y^lqi%uAM:>ڈ u@>]ՙ]$/oXNexyNnZ)ƺVIr70i4$ yɮ .KʭWO@F>Bl 0B9[anOT oEV%.!Zsv ].*f<5y;_Gg_"F:(3[BgAa-2䞍Y5ATHLE|nS ژeUbYe=BDNZg9}xb# ߄yz -eӶ|gE]~3^ &ZU%#7PV&,a* qM/TخCJiTQFZ4郏@ΑG|Yd庤,T~oNȫBs"o2=2&lbDi"wܷ{H:$?6U:`KLs#*5ۈ@uPN`_`rJ s z0pG y^ pt^ĹC_A,#Dn&#avrkeE(2b@\K|>V9Yw Ue-Vlm/RFڈ,iݺ\Y̢T'ɚoL/do_=sE{/C _U6Zz@>ؔf 6.,ޙ0:KMJ,n)Q+eA`M}ж Pc_E=ohg&@:67cAR1YBI˨ڪsIp2@ ]Ї&opYabr~J֍jC_u]g* vCF/DZ{Xl?~qԛ旖K,a.HcЪd?H>U8 w{&3{r.V.+?/y~ql=#q#/i3Q>fOq@{:6"rrƊu !"0p'$Fi0gi k geD:}ɳ4dN.6e/y>8A!?☢7"KZ'9WܞFFrήN>iFP^6AW!yDV#@w qTX]%gvt 0|$RPQCvy#YӹEhV矠j*TBQpg⡶r!%xcM> 2+YScHf҃wsX#iN(Mb4Oa"*)qooAgT -pq_9Nf9]X z/`k>]WT=*Rյ{dBJ浔 ρt` S^@W8NxVgM֕ذx{D[ JXMb[ʝ]QRLZ'֚F#O51zCM'=n\elATZtH`|%m9<*]BۢҳLGh(9HdD -q ǔIKìɞ;6%[ fk͗Gա?L xꆒd'ϡ`C/CŘ,E#{ Kd%B@kǐقZcYGs5)<4h:01"{)/ܣ,U8ǂUGF۠_`5'aP~I*r R^V))ڵKH ~"]AH..QvK;K}JK Ѹb\p]z`v+ Erfǿ`9AwI(@ |A|^xj+Sp%꧁]+B:3i/@T rD +ɳ1xt !CDNfn.`8P|lGbÅhL^lm.S U$4Tuegje/vU$"ԤY4ՠ@o2}D8~$8#P_p>]Sq̭iv2 cpO+f N%6׎PY՞ʮ iVmv'+͛Mg>p\A ~Un="Zc'؀2X-C贒}cYYu#4j8r]k1=l 4f&|o9s,?}EMɅSxrV{5Jm sI,]`#tsJH.>՘vTd!tܪɳmp+K/񄍌_bN>uh Pqk|H3?ȠplYGR"x*GNO`X+{ 5qXLBz߲/K4[6{E{?G߹7Tl\iCM%N/|ΣFW%"p1/jKtfƕYeHPÌ@tgU ] U#鹳t{1*wZ(NQ =@-!zb[ gj!=oYKo`6Y 7md)] -xJzE}&s*lTJ myZ1ϳ]tQX)]-Nom&'TRE@ 9@UgAƐ1@Q&K Kѷu2Gt [?BxbIM?UxOǀu]@M}%uxːY֟_YHi73F\/X;Ij:эXمa<#j6QvA3)R)L߰ iv\6@%@|9 -}.-JrY\~WXOu؞y5Ք21&AcLUӅIģ҉V W4f:(=lC)k%?AAZm8d}#.Z>*]a3@Y`0N4iZѫpkU{~(&,GJkp(c CW5Q1VeˣQuG0I ]/1M-Xbhr =2:o ?ʬj$4|wu5"GE#wܪG|r*V1YoqS*.C` IcĎ: u\x.Ʀ? ~3 qR/:½7R8tGmV!mݛ%@S*$ޕlwM??g)l4(tE={ꅡkH{3|+ Iԋ&.E/8HPg&R.@c.$u^poub -/p-0ritAax'oq 0^6@]^>LJg¯CPGbϰk$tf5H)l8fx-{o1@"+X_7 ϦDK =AZ1 AQ|a@ZtpAlG\};1*F1&?"u(ĝF,ܢQwRY ZPY ӸƱ@r(b02^ћFB)Z { SzqkC94BԎXFnl1)9Do 6`nD1BvlY˙{|.9D"5*߿0q K̃7/*c/w|MMF7`af#YІ~[Μ=(}ԱsSfIBRȹ'\tbxg<ՅGj,y2Zݙ0dbB+-?ݯeea)f" ɤ]nkLb7Lk0Emb¬6өVx8BQp2b1 3}ٌn_ ׁ5p{!,R=% .4J.o՘4-/rj`k#A]$uQ"DB4]c>̘dU YJ*K3͜,J`"it&O!xN84Ս&\+r_.}=79Ɋ3zLU^GYbASBM>٨$zpr]Pm1ˀe$y4u^/!8?p4B ɍJzgSP%yU^mdqsO񶪪EE$g9 c{&[tCyl&Q`k3t`C08rmG]g \8+>gͧW$%:F>f<z?ul Qgh1QW&r,;M51 ;Q3W&TB :)yB]Bgv? Tu0jr<-y 1 l/9x/{lC; IGE^F iF]t(uQZKE=uP^r,nZc碏 JМt9`w1Tf3d [Ryd[dR#s:y2,wף͟R@sLn,1IբO!TӄѽDȼߗz%\#؛Fl$AP3ud{$B:~ mm' CŎ->*IX7>lguNS~Ec >qk `# Q> IJ'+V{5;D%?auw)Kq)#"lٷxe#%29sNtHehÝPưouc Q(SP2ƺ#"j#*iGyBIym˕>$T^`N=F30*4X]0_F$ox'pPKa؋l%ZrR7)}aAn!fO,.%Y7_#w<8hI7v5XnձV=Z"<+ |V6+i)c95)6UN׌tfGQaqG[t$,DI^˥H/E؏l(-W'])[ 6eG"a<2⛽ myņ"M J7LbFSՄw,io1U'B5GS͙30s|58@qVKo] |P"1 mv^<s"ߺZ#MeayN;s UvNY;!mݖT̂Q|X4I{UjoJC 7Pc>/~|>Я"֬i.OGӆuR iA? BަWƔnG8/à1`pxKîN9 @FS;ӠC_BU ldY÷J) vO ]}3DYcqwI>U·Tn 8 麞Ƕo]̧^ޠ̢{'=w{sOaDUԃ9<_v| ,ѿ:+y %$ɩQASv9ٲW94KgvY/6Cxx\Rr }'lΫw~SCch'J1:uc恏:y(.Dۖ21yBI2[˩#)7GUth4?IB@8b7'Uj YY~ {g{D0Eȣ٣*ʏLI~;'\5'wy*/%!ʺ + 1vkw(`QK{ytL;73ZEDžoaA%?gkfȱw_Rm *c-^_a(x?~2,CUv vzG<?(;!və:O5O;;I%%J˥ dJNa,B¤\^t XeJ`ۗW>!;jD|mkHg`HԪiMۘSm+I"iKkJ4C%QU^Xb5o/lj1u SxD - Fn'{:yxdlvɿ$©,sN;*&<@mk <,e(Z@O7~$sM;HC#71XYb 83j5CEK1}i<^f"Êg:7Pi*3r9&~miH14whx#\ 0=2]Y`;qy*`O:0[oy5SˉziD>mCNr&Ri%ZDix4O [9Ds'cbTy`m*QA_~5iw8h/lѠ1?ZU/} KT8Ǵ'rPh^y c2OLuV0E3`<5(dkܵa v& O7+R:3"dE](yARP=t5!.T3s[SyYje[fqsVK q$7yGsf!C2k8rXkj Vz<GѠm&`vCTkeu8ƅI1g:A59-|(ᄟM^wԍ`m:) T=C% tkSskX:e9T]2Y; @z7k!Ú+ j7wa4xyQR~1WS|Th'-k`=٣׏h^(3H'̇+N'Xt4U>kkP>4&%rzUsYtl0l)V{sq-mMԻqKҺ5K )^x0wAn+ @]zlv:GĜ][NWmaYfQGЎ6S9}RfcUWT:sx?5t;Z.g%Y;wN]Cm &G%g8|8'iXZ :M(sK(vhD)ݷw{* d- 0bpU &[CE(5}匤m2`7!>&LFlV C0b4`stuӾ~E#SgJ;3*kE\pd*@ABv^ALr0 'R6DvKd`,2w Ϫ~Qh)&6/hafSlt&O4_%[$!G1Dɿm Ƅq|\` 1jUH '):[lJ(f" qcDݓquXX-"Mr1Tt(-U}ho+SZYjዖl _)Yz/;$P IME%K>Yg)P|QpcrBd,j ,֕q ~g2hÉrca\Fo\; q7d6LλRTI=U~Н/h-!#ARՉzWay/3-Z} ɜ2q ֗4 ڲA55&ѹ [zAYA@_EIa~?;'MRp-D9>nl=+?ھքcQ q7~c"ҥk .0nzAcEcH̓?#tZCd2Y}ZA=3HnhA\*_|ӊfݕ/F %=Vy]Q.d2gģx %axٮ(A&\J԰;oK{g;T$DyD=pOCyBp Ɛ>ڃ1\b:?Phm ,\2s^0+_8 :)I? q+'R%UT/ S @RbRJѯ `aƌoV4fd*-a6F&bKm:|\s %qMGgDBz\''uncj鼓"9E R.!TZbq{6Rīm1HUSq Sp7A~g ΄^D˚zqm 7fgG&fS٥V2St3at_Fxp2ʎ-侷ȿ>BKʊpJLhLJw(%U]SHR N_ҐI1;LISx<5M 餠ÃHo =jql@p;);EՐ*U=gG*#ŝ]=ɚTuTU||v|2 k "T =HhǥyUCygwj&>uJ2` 'Pҁp+dQ#^ecT u,o*{g4}E\cTH;fz" .d㯻?_q@[/5_0DdR"9q]OӤ[ gs]hET‚lτ7諜Sj9>C&k<^ld6 P\*{ -PãG UkH;ÉE #rO33V4\rw`7/f=` 9tclcvtz9 I–%b NmEuicw9 rz>nsoiVY1* j %q'Dח*hPFk -~6ˬZ/j-m^'` DEq;6Wdr/]hgEq|oοx[Gfo'vb#ɇBJk]d Ey_ ,pR?u",~&=rP[1]CI˜0=CQ##W~ykpx-rט!@US؄]8𾪻5?gy}HbQa%[p R_C΍҈?3/ I78T-tF*dy坘E $ΨrNRc4R1ݹYV-̶\l4n9#YėڡkMBV{w4zA A7PMCHsk(3h&$qF97 =E  yS3T+ra iXAPu@F55*7XjS|eV"VޜʱNx9 fm7 +0iCu=zC} ˖ǓI\^^3$rv̀{*5Ynda,11AFnTIPAJ3fآ'69;%חbmHil\j9!RN jFdQ`* !y[~/:+t?T_Z7,Q08 ~o5Xs^ C6kLHI ԯg0Cx8{;Wme;oV>86)(mxͯW{rT+w%4AM Jv:HV/W^|'kf=Yu vߨ}' Mr΋d)FUꋝ i'~p0!Hd>U'{ _Ԡ$r"C<ʉbr!({y$p_#'(8h\uA*lѵ*?bJtQWh|Fқ?&F9Ex偀bVT!trb#u;tZ{ɩBr/,$,΅rR !ND+JxWiOEșJ!lf'A5\'cCP'єlƑ)?xQbR$2LU/{C%L\[˰XޫvpfD>d kfZbhpӎzS{g“8|YXg,X+M2YW!QQ!r{ld +~?-TuW8St< ", kM@\kbW3wƟ&^N[XaMί9il; k:S-حF,Q6@Lfjֹ`HF+!ͽAMDsH)s?S\`g\,b4m8#VQYp\#i^ f9 G3UG{Z %uթ7ٳ t7j|x`{mTv( 1J@#@8?"W BJ*hm݈gB~;D)&3 ɥ34,F ;Xsx-7D kqCEo'a᳂Z{ݦ>mg;߰XRz1GmH++Q\{;mg/HXt^/k%n9a saX HВDqǸ 5Dܿ$ڕ|t51"4" 0V #F'YHӞF=j=YBW#W6!ba?ư4r®q\g-~ J)&- 'oȤ\J"iSP*6lqz"bm5lϏ?SǨ?h.xpc6``[Bcsk#{Lig|RS u){3p.ֆGDdO=J|U6FŕBYA ĺ[kNgtWIf2{4<=N]=nV9&.l&U?s Ţ_G!3V|k% HyFPz ԞR$^ȿj]v4FPWQ MpܾNT@w\(BՍXG2[S1[6V<^twX)_:-?Lo*z>EmLXk) hζ}BponcEfA<nK ۴:ko@}$La Y'8=0!3ZQP, RԺ,SZH(NЯ"y-oL4l]KHw9BB/@[^Z)Ol.-1)C0tu=)t e'Fqkg2{^]"m~Bi{ZRQ+Et|"B$<|ezD&B$TpMa}Wys_Qla8_iпc%stJiȝs3j< YLiְ5^ < Q̬[*%ʼnaigK#oMzl?d឴t7>[LE%* HƄdhwt ܬ $zxb]ɦ[򒝰zH:}-{Nzp(׹5^@x"o;IN"^AdMLc %;LNQ49·Qp2{De } uy}ƀKBtsŷBo(ՙF*H98sC}@u-'m2|Q lB'LsY$ o7^nj| W{hkiBJx'iDv~k8X!iU}7>&TT5~Y[Ts{18/7p2{fݛفDR\8 6 $'}qtteKS_/mbCjz/V(f -I@niJҺ( #M62tsY) ^hr lai,%|ð=]M|H̺PVv^IȨw?RNqwp#=wV'Q~v mvifV/V)J>Mӄv5l$jYY3|6 5k76͝8Β~#;8y`'37s<+)k-z^7t||d̿_$86'hȾ8y=bUfJ=Ir(B[/~ K0T)̔˸J;:m9cyc0bֵ+@;X!JxM$|L_`)]@p(|V%x.)K~yKz*6{PbJ5!КU ދ0іjJ1sD`8OY$rIM!|f )b%QIEhe !(z<6RSKp^uS\^=!,d $JO.].\^e@hWa~3D'] Sȑ6^LgjTOSW] fhd"JvQ$Z(3)l[}׾ u%2gbS3*\8j zhW`Ӭѽ>u\& 0L;%M"\%N4 -@,`D2cd$C JBlSORY?:sӬNڰyl*I#Gy"Oрms1'=yTm1S(Sfq*52&:x5s,7vz80zM 9All4%I EN-?w@ZJpAמ'X?fyx*0O7z\{4qCl0~'ˬt0zM0KGIQE3@$b*Z/m/VX%WEO P+G?"Ϛ{$#yZZ"oǯeL}ټNJ+ˀӍ5Sˏ/ a [+]QWX`Z[`P" ߫F7EZ|w~y2yZO'E,YiQ]-3K( Sě3.tEC:!0qP7|r.F.TW,%jjF6pbR"1_Sh,#m:-PFӦzoM&ud k-,fnR -k 4.3KA Ij]IyTP,q5BԜ{_L^D^TC9A/]0rI KeeJAAJo\3bI%yE p8 iK 9 .kwgcn* wj*CMY S}  02[:86hgnMzXI9GcTaB ƀQU /_35`!CqvƜ˒r`إ+Q4A( _ ]b#jEMV )E]#/+ʩcy"}:v=(/G ,VUMrϮ3M׷2[95s~TCAA\; &vo$])-g6*ƃ{ n#[}X++p&Xu p Z`gW:ӤmFUS@x%Z*\q"B>ڠ:_BY9%9$Oi{(}dOc/2>I> 3[A@QY/،~Ie%M8pQU^dF=.qAG3^ އ$\ F[i8h%Ռ؎1xb69a:jdh _}ZX& Wސ5jNY 33݀4l@I<ۈ4t&Vo)6mY98a.^im3Mՙ+^Tx.DÈK1 2/w\NA's2!PEm)eSrO æʲ_3XIJyO)SQkۣ- (wSe1W2Blq+wfbl k;8u,_$~PxB>'=d/V 56CCAQ;S)6Q@=<mYc*x1-zxx97 Ծ&_Jl34bl4TYE ;s󒕑Ksc$U8u~y ~*51 ١QL3֥ݰ7I2VH~ D_A5Z"+ySb)]ӻIZ;3f^B?eOL[-Y~ qWB@Z2atNp6N/y qBЇ;ʳ)> _u_6bh^kHwkH$&LH8qɒ.VKz$ڇG)UpJ96y&쟭Z{)y8w4s^ܗE@"5,ɩ76EPy ka3?F}Eݞ8L' -΋+ezp563Q^PUSB}4&L~9,^RIde2mq58P#\̾AbF* 1'y#8;URj tROaab$ҿRǕt%AǪoq]jYF}a6QQZ16Z,2vW"|5|w}\^Ww @(~F|d _k岟aIⲷZ4/9ϡ؝׳cE$T\R%SkjrG3oEh.M oϹs_roh -ESpc0Wf+TnUmҾ/&-)p~hHgMUHjEjz6NΝO< ,h72R

RAw.ko6LxÂ(?˜T:p\H O6U 0%BByqɊU[D9/]AaZᱳDcP+ ud^N}fЖ{ޤKgbsҧH_ƓLwS#V9o."b^%HÁzu[.y}Mx8yTc]sfȂηs6 K 䪟Ҷ9K{+XVny M+4,(f,bF Rg|ݤl'ċ!##"m4\[Gz\ 9=-^dMk6C%l1bq:Hz˽-7]:.4~G.&Sg~* C\o4޹~Uo3Vkv㈄ݘGoW0WI+ac !_r\ nF _c%#WrnrA$=WbR5]㔦n\ma%7$H*ZL>/i &쐬:mHi|T!<ǔ5jf43Ҙn= &2}YKG5 Ecs=ֈyg/5!qmxmDeiӤ.B^Ɛ\~g^8z>g&y_➧L2DiEn.F@Rn?!gJ>C_df{/|gNեe#n¸IޡNtӿ$k(F=wijп_c[3ˋʸ,q_&a~tY)rE> t9wnr|&vixw"ȑdU s3E K0iݚVUldE9CQ%GyNz}Cw#Қ&X]}z=8<_FAy-"Wg¤֬^ rf:5S%BQoa{O#?ۀ 1;ÿ1bX! 7ԨVSGqUp# 0?B@:dkoîPEga?MZDI m;T\D#8"ۑ6^t)pqia!GxlX|zǎ[[6PS䤸EDCHK۞{w)!$9Y7+ ' ndew=-2C5 la]R720ia9nZ`D%gώ~%uWY%~^ >J<":e6r|#đ  0Dwhn:.[JR Rzj2it"bߛ_2H̸4рLw[y.'#QR⚩>RC'.t%PdnkKHehgX#U!$e*eҺ^eQk}WՏ· eOK% Z~ XDHF^/&ۼ򸅾'\+7.EGv%Fa qbb~T\#w6Aرemk۽[1>3BB])lgR [gYtw-Bcqѻj;l{2M@ wG,Yhp}-V= (Pӟ>LUґh ѷ^Lk0{~k䢻|wOuQ(ŨR~?yؘ^nC? 9 'FT ԽuSGtfGbxil!#kzm#=$6i::=W\J va>n<8S{s4 "V?<9/J7ҹ!*$;r'6Ã&\vBDؚob|XƨD-6 &4`,㞾ǫB ="3M#gj++*K!Ar ;NZmG]$S`jz`hrD = ` e3|%=`3 Щ&uz$I@OHcx]J쭤 ed68M7d>!y M K d0=o#!L'yus׍`OzQ=,. l2&[Tl&^ug1;-5 boGuO[P9qhn@fj e^oM>Zz19e7B~C[iguQ1 1}YܑyiYy0nsAni[:ȇRmƿ:G`rʖWh4r#TNfڳXVdv!] d5Q'ڣJ(dXKL}9PerO0B`DwyB|Gl/a4%#;jR.2jJR|EQ ;q uwuiP95~P`GchPgEΚ 48ytPoB~( 5"[1wT>&,xm@A|dC'geE∮C0.vO-NЍ]1B!.`]<{<-I$ \28 'R|GTc~Dtg 3,OJfNjJ[]V^oJExR1љ'+)s?^;5=cD/HTj# 0Tx $qѿ=)ǂ"QψPY0;v]AAs~pF/>9w.xtpd`V}WLXņԃ!"E.8U[dƥߟ=cfZSDAWg,gX֞9/!G85n'Eњ~6[Gڤq_Y{$ʵR{$ W֬?Q#gơ0 B< 8q$EuuCy=b6B6o2I%W=ߨ^ȯdd ?lM 1^d EvQF&8!hD& o 0%#xAU6Zuqt%ύ㗏o~TQVfS̔ޓ${\eI^~OLaqxeMSyz؟^̅f4Ĉ4D#a iH/rr+Y5[ZUͫkWsp|$FjeNңvBuGmyF VvzU%7Ka B .ץlY>cKpUzu8܅O7(7b+uP@?C'zv]ƀ1͗(̿'E *:ko6T31k" \l/ *34w$á*Wܩ :-q;d-U`ﱙ 6mĽHՃ7YԚqW헎p|1Pty`c.@Q A/xZ@Q@7JWd6HqG`!͊=ȗ]Y ujiK5űBoXi2K¡6c!7  <_1&־h,# xsbGADxz:[/'\?sfh:9>:DvL/0f{7BǛ69Gml5xcV/4w*+GL@쪬ZHيk_CnaJY#:AgH<Tj۲(]e 3Pyh))y #\􁵴cJ.۱yu8L͵ҽuOqa6zbWS&G9n[%!綿q"=@.?aZ/c/$ L×U!]̓-/fEC ; ذ3hvBعϭQ/CMCc[)*{]L$㰽ޜW@r{pi~X9H*m2 p'j j'V_o9 /e%%8ݝ֘s."-AFR(yRtQr.kyxt:۱M;AlHS":cz/+|Mw3=U Wak8C,`lLS V@6^jYo!6_i p|z}ʟOJx|?P,׵#7hyσ 1U旣 dL% ('Wz}mf.lwkb]RB(! c;R1BcBM`E0&ۃ|9I䁵7 詛˾x$8IH;t%jor 'T@:XeDU{ Zen/J1>G*}z%L'&eNZ]Us"V:'zC Q>!1ʅwK> o˕7/T:ܺIG@6vgp`μjqV;͟b ftOM3>EWdCf( 6݉o_FtcХR0C<waDR۝I7W-Ǣx da\leƄ{i4Ʃ'0Eۆ'jI^>j`UAIjT(}rLRH9~he1nKOr/H8t.{fb(d‰,U !.Lg` 0Cdmw@XX) 6@&UxWÖj[Fh Y?DɳBr5 <5m˝Pn<&7֏7MGY?i/$4ĺ4MWz!A[ n%|w؝LITaIꢽxDŢ7RogY@=ym߅<i- ei=%Ԩo5Q`yylo)ڴC! ,7!:MGiU{2c{2*@HEBOyE N b?x{1>?2skcLi1B˕Yo+T|f pu"'/"# =(9[iVP/@  gs7m/Z3/DX؃ nƬ1[/ZY=p,ma \E7?Ύ&\4LG:]ϱ@>?+|ÐԌ]* [̵5v ;qqW ЕiGI0ːiBˀ 1WmY'fNV>!vRw uYG(#[ SՇdrbs)+˵|Y6ȏ`&Z:6 -,Mo)#8;){䴍_ _V](_{3f@R̥綹i oiiU4tQce#Mn+8sd#sdWndާD6.A[h'ƀ+R"$MjhFW"n293GOv۶Xd4(<0A:gch5PVѯկ,%]5BbI!|ɞPf#|s{s!R%ҡ Dn _F=p zu"^7Lpn<YbIV &U4&fjXAD]YD^L,~ .|!Tq#Lɸ\ciXIA h8p<1T[bܫQ4](bJ͹BaKRW̒ZW ;ƺShKВVlu$&'1&?JtB˙3Q@%یWh@w}g҆z6T+Kp=:Ρ8z$FAЇ39Ok[o{RZEsy%x٥*iSS*4)%-ɜӎ;*bټ(P4kEƋH'q\Rjsk<* JڹE pd&;:uύ'ڼNYN5Wjv:V?|mUcِևC:[֚nXa-lj!reѼMnTүA+˓aP;mni2[LvԬ. & )>,r6q~.I$Ob:o'辕5YUc r't[ΔkcF WXO4gE]^e»_/S͚r*؆9>yN׎޵0 DW@FmS 4D@cE8jlB/ .IjN']bD* wNHJ3e瑓ng'+%W 3|Ym.C %QXѿ~.$Z8؞HOP l}֫_085j9?sFjޢs<"^04Q7'T(G9DXA_tfv \k_[t߷Ž‚T^I^;iƕ5a S hBMdUI‚5<ӓdb;&XYl}G+`O> NOJg¬_=ÐBDkn\mT| M xA%l.;N?WB4%٤pVR/%Z{hŪbv<_myKoѿs>μE=m::ׯL[C%IFQ舎6T HO]N˅7a1`,|Y4eH*h[Q;,z64Or4s`6m]#/Aou!L׎.p0 srHH)[ST!Eq׼}\}iȅE3HKH,-(lfAy̿qϓ eO 3b'Db.Q\ Oͩ)+Sޚ:ҟ&/Jczhac!%S2T9ء~Ze$ xC9ZcGaIrE+n"YMPfol6tZț'6u8R/igDwՏ.!X|.k\S8\:@Cph_miǃÁ1Uy@]{ؖ\As ClL-Ö\\ 4aϘ wvm 7@[uC̫b})RFE.z9a]\@ (@-\Z a U@g 8~a@%u CVjPfoAG+):ɒ@1q Pw0XZn->8/GZah5 !$)lW^hr) ܨОE5}2y&aG8-ӺWKHǁ82b#e Zxc 5]-`}Ul\z$ƆX\w|<"e`n ,c $廆--)A-+r ;x/,wR>ҍ¹| 0Xk*c)1o}oq..GN1=:!SuŨNu\Εe`hXc* 0{u w>؋YӥtH7TGSFYl;K 녶3撰Ҹ {QzJÍ _lr/hecP7c}$NM@ v&P%8y2 -Y[G?KQ<"B76~(%T6=TҞ)Nvas%"g`*k5<ݤ326!14}Es ޑPXo1#e)ڧ|ڡ/O)*`72Q:,->Moj'kD㚇~8#ضm(cƐ Oh]_/A_aM贕u{s *jpF%=KNȭ.2ɉsKs1ig5:(&f =h 'l|N,wħրA={,KiQ ڑ?}dgrQJ3kϰK PRI3Ć;s-}LL<*8s_x s ٲ}+Z#HqPa>- 496ا"ֽ˿|AVާfh_Vo[tQT?l'?.K 'w]+L]`ȒE-aȧ 5fĐ=q6݀+Zb^?={#eEA6n$[bN/2Fij=Ѣ_ĎP _KFOL@$J`8 bYtZeQjFC3)G͊EҥT  )]i0V֛^z ifQ 0׌yו`xJ`TĘI"YK0cTQ QkBS@TRUtq@^3 QOe5ld<{V7Vn~4ss4N@Զ: -Jh`Y^b ,O^> I2V^|QWFmnN/볼 gcE37;?7+4WYkXqKaefqSO[5JC`}Fr7 > UzzdG%D^c nE齪LpS!mL.ǻZ,d:oo @䫰fw;^9HHuDϲ0`.n )plJ|'uR;ط6?VEɊey&h%k&)nQ± =As:%u=+jK\ О(UZ>?9C]6<Ƅ1[HT6w?xv^Ps+𓻎q0\S!('cQ' Gr!0hogO ;KX[p*!Ш0h5\Q^}:mhZ a)+Q>3)7U3Y1 E 4a2Zv5^gs[|/"ө~fZxe3e@Ѽx~qOV* #@֪i$$T\7 %Ci<hAJ'^d*0@b^[S taJ 5Ǚ2@<1/%wЇlw< ~n"ZCR:jQݕ6Op'Pm;u]hun 5bLJn>P=fDB z_1u~ AALGba~Fj&LVe)5rh3?9#Ql+J A,bb%?)Ut i>8VKede*"륷edn*T*ڰ?D^2U +% FIZz'c;P!(PWpYnmHϹI lK(>ChDzxV{nnHrIhV93X3;]1nÞЧD Y*t zԁx? ԮNY->ѹq @+>JIu5$-2V NXa@R(#6uԁ /;| T+~wkߤ41:JpWfT[ĖO)#1/졞OI? KZ 6MEٝkB gAj(}4}5\%=ӑ]J YL~&M/ѱ>W_VDهq[ނ21&- Lj'HPip{Q#L^L?of:lR^Ix2^+:صH~)e#6BT=;\އ1%aVO r+`4غ0"Ts,ҏ/`֑m2b,$b! %;NkZP>8G4xeHv?c*WNyO,*}UpN^Gؼ @X ˆ.E w:sC! _`_YD#^ΑZ+DٹՔWK1L/|x*zodf.Qcz%P4 yArp /ԡO@n&W=Gȉ53ywV9FS~=K='?Ӯoa|jv:Rg-Ft!WdzEwo~F9+I9FtXfNvJVϒ{vC6n!>"rUɗ,i|I*bo>]=Wϓ/CQy[ˀkUpw;ԬG]; ѣ}=XFc[Rn,KZηmCgvrwXK7DO ѥxk^¨6o&4#d$7#؊V\t L#H Ye!VGbU>ѭ ꜝ\[LJq~l=e_.T7K1HQw2>9xTV. ѝG_.n!ɘvј| "}l~rz*љKo"'σWTk!)69n+ g?zk5wl"1n]wXHa[.)7)lr8iQ$v>^ASs"5Zr̅2)t3i٬lteou'x. 防Vi6@CܤiUfz8f<13tiX =1kFCZP@3Ӿ1R#ghY[Q^# /4kЩNoԭEJ]:,s/|-"Q,:wD$O,*Fx\f^%EHj1JcorqSz'BScoӾ&X(wBaz@o6VA=g%)Y,*ocm t_?ePrG{+lH:* :eвL՗]J">~h?VZa"a0h[ѧmn!OE}$NaSLɻ?-}RUO(qk,-ILbmfnٳA1cRL2 m`v8sab,qyV$L,YɦN#BaW@1bpx$ҎSWe[qBvwoB/Z B(䋁; ~'RGa w7ʛ7IEsQ BcR&ԡD?X _cQgzl>DδHȸ00nKG+ɶ7szH& V<3s-/z7P^Kq{%4`)Y8!&R}v< "+8V]kP:sY\B lq6 `FWmbr뱯bj4g}OKͣ.8 z$#x$ҷ]:ߢ7JI ^'O>K1Nz`S2R648й{q*[O&ܘEɎTHE؋wdwC2$zEfJ\.U+I1u5ujSQ):{Wģ ⃴sLw/~_ϑArx_y1`E?Y"F eM#]I,Qs*w]@.c*.V޹^==Usʛ<2bBQNRbFO[( i;es6H,:g@k :P)g|2/ȚkXap]сD+[rA}9{-\pv :% Fadk@c)criENLx9`y~<ί,,~[nu ]CZk~ t`lA"f:2Ls<D0z;XOj۪Z>0szCl\.Kbopo#F@2uuxԌ0_I6NOi 4ě;Tݽ?8{Ei6|銷v`sUfL,*H󞪋aF*|.A{Jƛ\R{{Z8L"/%,q;:|𐨇Z/Yږ&|O̴!OW^. 9rQ OĨSv^}{oà'GZ$K3Ri;>h3p*vvbHrn,azW2ďkr. ~'ߣ}?^ز a'>~PHCrsCw63. ;L3l=l)84UY=+39";`jzQ_BcdhAKȔcW #t*P.K$ 6-Jp+}}qw~NKc>ҢPQ:%}]lgrQ~Чƌ!#$@ vNN jGhm2 ' x 7aN;lt" e :ߟG|0rr߿V fp{rJ=TVNOMA8W-!&*`@9m>f"a^FӅ'J\}9;4)Of!pÕפɖn\%YaQS3 Ÿ^AMk@dEVܰ!;aТ> p|6g8 *J CjH4s\l, !qMJiw%֗d'& \M5-Q6EM3E0:ʞ|`>wg->s` |DhuUA٧%ҜIJ]AD^ Am٠065XNA$6Pdz2Bz)n*`C\`o 89x>C:wK6Ǡm,-&m_ ?>A-W*QsGZ*5,3`2̖CJůH`˻A\[Z-)ޏۧ#NB<zmi8QmM+)O"cZpi $*m_>'g2V&'m-m.h_tzzjBԊU V*x+ mŶr>J硻CY}ԉ-V&-;6Ma<^U`Ŷ hcTX`5(lO1:N&,M.l~NX>Т rE\>um%ShYywB%t*FașўWX\w 5?y|~d\CgYfJwC\;H,YAX$U`?';.V[!_Kazgh'r: FD po*.60'6)b?j:m2/C\-@3[z,1A)s.E zwFh?c_ %C0)3OW6Lƀ^R] ۏa*(\~u2憽hoyM̛= P䉵1m}J)%0Gk 7 1 |vBha }@C6ş>URKtRS#IS0--(=]9_RnZY:qǵ2D~ֻFjF,4l-BI'E58Q0uX[#$ I%BS'V?}uԿ¨iJ6ȸaOyy;ϫH/pz0RGLPQ~lהOt2bQ7wB`/BmH B e;WZau41)({f$vթ`ό&1 աgTԄ1,heOcV+c_]ZFhY G>fump.%M5"@43nK?1Y)^Q  lBMu-L{ DsHm ,ufm~ӏ z0g 4*,O$4ٱؼY㮲E=V3iͧA#×e 'ʴ,7`$ $Miϣ2 = ےi 3Ɍ98oyԒFIS a&x'Ca|4n}4eOX _##9(O_Ԕ..f;uNfSG# pܟM 60_bNL56P+ݗa@sr@֠emf!'9Q_qg Mec$68!@ iS>rˤRdC gֆhxas2O9_CtC)ѩo-ߝtG0Ng8&PdOsQ"lksFi ҋX˹^8=MQ(%U\_}qw(g6Cs|Tl;I?:xeGG2tܼZ'^CΌŊiQna*:ݪBLj?Qil|ky0RcZl"CU/-,|#1^W|M7a -Μ*赃݃uοuI"=ǘlq%aRp ~똏MiI7gh[A,de,-z%;00s_dpYijiRIJ$]rgu`bsGDbh%D|D=M[jͼ ?ӯS.nx\=Vk28k<2P\v3779s_B40! tvΦpV$>*5/bGzJJ}m sBM\MK)x&E`QOϒPBy2joW'ew,ͮdP~Pb3>u d>=My`0ʨ编vۉ%ɎFC`Ni|N08`DqKͪ>R5)Tyy)1y  e5ڏ? gSjBf- Y7cNLN>mlȈ06wmPـPIޛ~&f"R=-CCD z f[G_giM(Vq:^2mvphat$LXT{?.C}䐧EA?KaE`eWW-P}Pf6EӃ&Y53bҲZ֗efO )PJl-ۭ?jDh- Mq|&S5 3Ka՞I~m1SY@WۄZ&arу1i9Hcbr Pk["m "T1(L{Ɔv K/#WSWDZ <@2^8PlyβD4k(=а ΀īf`J=.B@Cǿ2DBA^˟ѯZЛPm.J3kujGRE00q2{\ $^hE>[oK5r.Ukp;O)⚷UwsCN迨 < WC}h_U;rOӧiHYD Gd,џim{'J ~p ?^Ԥp-VJV?y")j vMO%6E9I! wMAm ,@m b!W}lA=0sMZ*.-PI̔9XL N[]&\i꾮B壈pct{]zxGmXgZAϓo:E8 c s ¨9Vɬޟ#~Qo:@;s82$[5C# [h՛v[^Fp>05MaKc & JdOg"\CϭI/ >:'@Lݥ$KN{~lR&H )&^"Xga$6@̃]T*sNXܙzP}%DCHQds+yA%zcުqDOG0Xè0ꕽ]\{.\+^웦}[R4w x8A o BNeJBҪ= NreObo(q 󞆎I7tHκyKȕ"Fufx9ѸW&ww]Kϗ\H.GugZ.Ge{xAf=5j4x1jAbXȑaͫV˲6븷^݇5fE#^2 0'{, YPL$3YjXk٩LLxMݎ7{>ڇ4ξ DaϬT3h;{ADssYhހH<"yT Vt] `pl8Kr{.Xd]p/gQ̮s!ΆCEp Gǽơms" =g{m#",gx.Gr+)gkrM7X^T'M) Kv.a0 T@Փ8k=`|*~n RQp][7|u҈N.49Ka۠qSeK^!t|y̴j).=a0Vv>&L?/tozGُTl|W]/6ed<*&E|wT?v'f>iz 韸ֵKg^ +iݬBDA)쇋,^UguWkgN2t8Nk1ˊlv#J=Vڧ:X6jSZ0ѩżE%{ofzOU_+t]MjUY6a`Zg)f3,N! |8~7挷aF^s!o~@@b&B)b5o| ;.u#e-:D/oQz^l,Xxsqs3|>ԥL&bR=;f" i#Vl:lKZD){n_/nt3_9tw¯~0Bmk|j[ QC\b$ \PAM 9r0N'3D}2srs)VX@<(?!zl?'>e?gco2@󱒨^׃&\ t7t7?lfL\ 9ʷ"}aհMzE \dUNDw9YA~v2PA' ;ꨒ=&wAVykg+aiiɇXUضBĆ7H[߃NcjC l0aP`,ŃfSx x9q isC&ޚ21l~?]Xdf1|Q@znUgXjJrʹ Yqi.z_sKDp 6` ,!aM5Lc(TR|m%ٟTϑA"M 3n"%Z]Ŧp„a虪秵Rk2K7lWӚCZE)%XE02Fj=Gc W5:wzPuѿfZNt a[AA!H=obX(d6ZAX\c\ľ\y!@k `Kaa|OwDSGIKMvm^3ASj<=yR ra/G=|K|%B¯dsMkm '&|FV;1E\@r_ԕNZ9cmTRĞLv0_nD+s|!gK Q|2EKWiҖ#tSsa[T #'?.߄|5ޝkO-G3h7FxIwIA1z[spaـzy<(3cdވ) Xc`sͧLh+'ZPrnpxNx^ ~Ⱦ I! }/XG 7mI `ph W|H 0e[VpCYg`؊$mD^շ;~|\bq:pSDnwn܁i1Wp9_ܧJjʊ8%5^"d}"]E_S(tǎ@wݙG[n59 v!gd@X,P8`.*X%&t)qYWwcDL~ۈb>ߛco͓8;][6@2)gn&Aq\OգA;_64;D5?͛%cډ &yw`rӬ#2}1F  X!pVzmRцD #ډ|?]+E}gWoqךͥFD{:䘾R`QHJϳ U9!N_g !~s6V^-v/~]{X]ԇuT[ca#dWe)T!ioWxH p"= UڂZp煥X&Ǖ)m*X!FMq7D L*]̑y-d`l].ׇy T?׹ r#x+E0a֩j u|H}]l[uD(%g084Ip1+̽- Үa\6=psi赝M g^%ܯ \$mV `F>ݕ+YukTNdK9R!wڷL^ }omFǥ~ ^ĹśnF1Fg20kRQ- joaC[ӎRhdk,QܤteEA U y5ĆQnBa_FlC!5J"}*ZqTUVaw7tzD!^+$sTuO`Nd7( V5M&IH\^# 'X}ԫA\'eǽهjT@d~4`IsaTGv Kpw#:Z*3--}L]tLsӐmݟ c?DNӬA ls^99 nUՑ~ԃf@*%MFJ5Fb`C =rr92H$w F%uPك?vccY#١$˲WbV 1t٬i)2WNV;6K\{.4׊e U%#GVG鋟{GNoAVS ڛsNZ>I읅07nAp.:%If;jF # ]f9a4v g\^Ѧ+_A7zePӾKZ፻v_|[!,s+|Y^-3?娔5X`ϰ}6c) X@/`b&!O';czb.vD獣hDEjOvYjau9%Y2;FJ L$ƧH+ l[*S \/gp;—<.ft =hטT,<³T>Oš!8Bdc ª47ֶq!IYɓe9F=FZ>o3p݌3ϩ=?b e_2ԊC_5ڲ7 L7Q46 aAs^؊@,L UY8Y#+0I-u2hjHղR-\z2.|k|ۃ((qFn;wݧ!}R^~2<['%+Umc5*Iu1* ŨxKNSBu>:AoCy͉N%_UԻH꧃ݚnEh̓}*Bl9}WxriCbz*8$JrŖ^&]F{{\? E2|v riD5U[3Wݜ<0苑''bW/?.a!`X%]zC^yszsܾ,\d*_ mE}KFN-'=Mer^bNYG qE7 p(+fDe~fbvCLgVd0B6aixV\~`0NPfMW83xw5ljD g FZxj*B?yIB1[Ũ:%69Z_~ENqօ ҄2A;$~?g#+wiC\-Psʰkt| [*Ƿ9@n$c{7W':4, Z$''E2CS#/DYy`&AzQxCVv,RDD4.FF*,#B(L4n# wUE  FxH Tr5A` {CInlžS-oX}߀^O2Ӽ_PRbKDU? BjbeFʵ=]1B)x.OP Vi=(>:N:3Dž,,$!5'Ao&'j@nBӚyްW,u\>M, v6~x?e11̵OgAnc; ?۽Vq.YfiJ6 z"e5jwL`(de3uu[.m "-lrK+. EkMJ|4?swYCpAgRCޮ ?H"H-Ў*juQJݣuuM:"0U!5# ΐ8*<7Bg˺!KܖgP9%hs([B ⧢O<\+[q}nJƪG#J(róm"onT |Q-XZpuk Z1Ɠ60.nm<|z} Ն"2;*+qR98Rq̂NH nlkxQ BaI@) dv\X`Q&jXف; *hVoSiF* Obl<<uMݔ:6Q{+Nmg@lt#MiaJ əW]dZS7bY(g§SdTo'c 'z$`eM5`l}`jIW)BL-)QIlt vW ,R0vZJ ,a,D(V y-ؑM}dGI!ryN6a HD6v6}-vrxJ-u8n3.:@OO]3* G0GQНwJY@a\bECÇy;r wOR&D6h [xL60n%NQ[1m9E&CiqT46X_n>b,O^1Y\/ӽF"j>Ǥ|A^E/ : $$Yz!vŝl2*8m&5L~}LhCB|ř&999..w)ˣ:v |}"jAFOWG\OaOΏN [~?/e)IEQq[j:k|ݖ㉗9fѕ("2I6!fy{QXD5lkLx[q#DԐԷ4,N?|Ǘ6vs˥m{ _Jm7;y 4eYV[xm_uGs9-@| n@ CE6uh C}U$diB&a l@ C"@7/7 yPNֽ`؍bo;i g~iUߝIeTS5:}<(J4ݼO"Ox sJWj[d\oT.GPQ3Mzjc A TduΝ'y: {5KRN#;Rf-JE8X%[ljO_F숕*[vG k<#]:DNݑxlkՎ6Wx2Ijo'NMFW`ه}~SaenE-m(I^]me\~-[!kSu0j3Fu( 0J-K{}ePg(;#i췛vLs<]WtE:~<VAGQ-lsq)vdVi9+-ҦJz!@ hu=û~05 -[\&[oQbo-n㻛,~ۣ2oE =k!ƒ1|+X6k]otx:ܟ}RpWua!Xk;}}h;C1MO ?5N9[,>hg;B|/w1[޾>2UVR΁qex6hw@-]nS$V[pvfߑ;TUmb0讻vg3@ah(7~g Ķ?-WPmÝdwr{@cW S/pj\a/pJ '.i~Y73geGs\(C#2㱂K,/*N!Hsk{형ʅ_)OZmwqC񭖡oL64o!c$‰I-(&~L{J)F>Puisu^W_7*㿍\@@X&wi݉ue$H(P8:h z\3;8/}&qPb޵!ƄsY";p{[]0ٽ7yw0Uƌ-ذrzL|`v|9`wό"dzO1=WDw-b -lV؊QVz^ g1Zt{LǁuhKW2kVeTՕY&`] w~(PL H!K('*cQir40{w};bz|iz!gJOG(Yɍmf䀓%;igzIQbff{M1.IҊLNN۟I|bC%V]:sA$K ?~ojG ƪFyxn"M~2Oz}✗17.ӝt |{Okg;?^#@ &2}~~ ,}Hz6 8pt~]ÑM ;.  Ó|߂ufoeoð}烋-.?]屹Mq K)Qf0SMYd6`(Mep8mQp NoG 4L?LAI0OcY;96Q4qA8m븃=p:77*B@C>Z_cHqq|xM_6+Dc;a@0 VH ]4!- SBj@q'&,%܇%һLTjY[Vqp1*W‹NIyݿ xt ?CSXma÷ h*C{ jGAo Rc6@zvb_$u_x굘nG0A_ªi>.~FEJf{5bЎ&# k*,bL GEW@AB˦0=N̋ cĿC 8 oD _k/+QY9`Xf [RXU|khkZߪݺV_A+/>U"$,5wOߞzaV\<{řد`jS0HH@c@?5uVգ8E|I;jBrÇVD l` xQ'9pZ Q-LD_ۿ ڰ/*HKp`E>&BgAG\:%$ @k=﷣X1~V:.#6PH$@SmГN ]d 8SDXnپsIbb]Co4Nid<<$~Cӿoӏ/} W`<߆?EHI}qA5R(6ݷ463U9ը遄5>7b2#~>i y VX'=2}o72RXg]%zb-*q[d3tı=ioʵNK^]B^Jֆt H4Q ClƑo0"p>%q4ψDŸ^i]H=H \.cORH~w,QKےՊaOHh~<:sS+>%I,j3L7NQt16LdndL#d :AH1mQ"}T!M.Jb$_о?'}XiI0i0.R@)9PP5 Nq }9#OK%|z(Bдaծ|-@fH+L OP鲢-utV|L˖9ʌ;)5Z'j1VMb"$X?#+al | {*PR'%[ wLhn dCLKi,Å @ QON3gA|@0 •Sψ׈<'Im"uB.?Q=;{$$HnhF,eRat/دp QM+dxNk,/0^X@>pcUtR$,w^ ] xF|~ 􉤔՜PD¸0:yм |dbC@)GMjC$'>ڱ< Lv Rj08!wq9Zu;y(0j2M3(`*G_a(|6Hp)Gh??0 *9RL3rX4z ^x Z;j л4"ѱ~DI,~"9'dH8ih_>Ep1a,)$#B&)Ev=m`*^cD ̡اD[m:cS(l,;Ces\3R8 "\Fpx%EcZ߫G{_TQ(+E\C7t &Rt"@ٗcwQ`!1+`α[䰒`P϶ƥJE2 2FrM Pn(xQ9H2Hr#b( ~Ȧl(骔 ZRy.o١>zH,8g66sAw0W Ewfَ"}QvA 2 ?BVWT-3F<6^Ri䢻8TyBVvQH~Yl"L#T3}:d3U m&0F\Q,8A:7 sR.ɥ(eRl% \c@,dmLV*!Zy.aUʐHgYlrTzY5!dEYx=.\]<@U5eJ90(+Ӻ*YyrCf8+ .K>fj \xƁNV.;TƮ:Æ=#<%⣺3}ERundӃ9P? lXwQq VY_0HNfToH AJY 8 N9pޝ0ϗm 1'ŰVZy"eO2n{83Ag^,RU;+S[t|WSb!rA4H 6:7 RĨ;f\zXaedkk#5Usy5Uō C͕ Q/W6m^:ʙhq7JmeovVޒn 7L;̯bz8B8DDjS1~IU#%XT#: C uME_`ŔV \an#P1~1[̍3l>˼߈naW:-.FޔYfIšUS ͲtDT0 u{{;H:s=׸[dch8K q בvZ-ƣ#̋,&R|H' 8TqDnٿ܊@u.1NO xo:EլzDQ֖#6|v*zap+0xޙ~3kH >v&;B<vtt|!Wl&acr$L(qf3IVW`hE1RM]1Ro>In,4˹:ft'l !334dYkȣfwibPl(RGsؽV NJ7 Is#H3O6@.XyrTf1,Al+u7왒bfGyIyNEd, if<9DMjJx@>Lc|%6#1Fb 䤛MSTh%߹pSɥk[VzMeb\FA ,aJX`VosX͍;8v*q1] ~ːܻw =m%I/Qe[G x #.]a?p(Un;a/!B..Uh秝e#5KO0J&6b) jFjw!J9m;u)9 UOSnqӮZN3͓]ެYsVLx --{[9 q~Pn!n.l/[tl@[ ,2[TϩKeFPPOx̗M~^0?RTբIt|kLdN1 0 U .5܉l;2zȋRYA9KIs[*}Rd].gl>瀿ד%d|c{ogS=֝6Mrr89lPKVM;ď)mXI&zy`(%\ڷͣ 3㲉yibI0v #Li0t.ȷ*)O2R40sr. &c q#51%R%J̤Dtoj#EjwTysrsAf8svVD8DZYZ_b Sc[ B2rW$K|6(ї9$Ζ+ݓŠMZN b[v w?tۤ=zě+&V, 3'ˌTb”N' ͔oCdaû֑( < a8Lߍ-kl]fG&u+_])P1-#%*r2B{6@EơH_m)Oq] DB)QȻ2`瓢j8oSdgN$3X|d EXV߶D#uY5)@,>,hUFRJ嚕xNi,{?-fڎ~pMdx4J#E" L"0ٺh,\2[=oLj9$#[e2ΗUԹvȵx#Ϩ}ڏcYvH-[:O <:4jUN^U~1fˎd&|Z6y~ ( 2e_MMuiǦ%kX.V!CPb!u@; YZ