sssd-krb5-common-1.15.2-5.fc25$>OEI`N#>=^?Nd ! \% 4Hekt    u |$( 89 h:@GՈH՜IհXոY\]^.bֈdׁe׆f׉l׋tרu׼vw|xِy٤(DHCsssd-krb5-common1.15.25.fc25SSSD helpers needed for Kerberos and GSSAPI authenticationProvides helper processes that the LDAP and Kerberos back ends can use for Kerberos user or host authentication.Y.buildvm-armv7-11.arm.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/Systemhttps://pagure.io/SSSD/sssd/linuxarmv7hl#\KA큤AY.Y.Y.XqY.9ea3cabc9c25b12485702d1e4085acd2b51be267926ba437770682b3dbaceaba0c16f64477ec4ec4be1aea368f3afc26d26e489f20a56779f17856c94886895a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootsssd-1.15.2-5.fc25.src.rpmsssd-krb5-commonsssd-krb5-common(armv7hl-32)@@@@@@@@@@@@@@@@@@@@    @cyrus-sasl-gssapi(armv7hl-32)ld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libc.so.6libc.so.6(GLIBC_2.4)libcom_err.so.2libdhash.so.1libdhash.so.1(DHASH_0.4.3)libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libk5crypto.so.3libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libpcre.so.1libpopt.so.0libpopt.so.0(LIBPOPT_0)libsss_debug.solibsystemd.so.0libsystemd.so.0(LIBSYSTEMD_209)libtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-common3.0.4-14.6.0-14.0-15.2-11.15.2-5.fc25sssd1.10.0-8.beta24.13.0.1Y.@Y@X-X~@XO@X6@XOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.15.2-5Lukas Slebodnik - 1.15.2-3Lukas Slebodnik - 1.15.2-2Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Lukas Slebodnik - 1.15.0-1Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves upstream#3382 - SSSD should use memberOf, not originalMemberOf to evaluate group membership for HBAC rules- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Backport few upstrem fixes from master - Resolves: upstream#3297 Fix issue with IPA + SELinux in containers - Resolves: upstream#3360 Do not leak selinux context on clients destruction- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.15.2-5.fc251.15.2-5.fc25krb5_childldap_childsssd-krb5-commonCOPYINGkrb5.include.d/usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-krb5-common//var/lib/sss/pubconf/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabiELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 3.2.0, BuildID[sha1]=c5439584f765e832926d3361c16cae3314cf3ad4, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 3.2.0, BuildID[sha1]=535d2c1fb25e02f8f5e4c8198e4e3a0225f6e264, strippeddirectoryASCII textRRRRR RRR RRRRR R RR RRRRRRRRRR RR RRRRRR R RRRRRutf-8?07zXZ !#,]"k%}}`ʛ`c䆨r.{x'Ҙl,٫@*4skӒqp٥9W(w((`T;}GDe7"|B~إ&=CW7Qw[HW`փH/ue܌̿2Qu3uk=bP8}>xT_!i>aǮ' 4r%m2~%zB0 -+}EGC/Vϙi`NKsD{N.Qh ˯۩:a|{@+l#c`q!X-\ u(޴~=$\.vP7 of;LLV#|+fcv%P-m<҂;Y2]TڊM +Y;<ڐWuA#[*oiSO~D#oVW:Kj Ԇ񱺱r)Gr_mN(_?Ofp8rh+J# R$Ie)2snbl/\7e7 ,vV;̛it " H^gzMSt܃/ݓ{KV'R9$_;RS~;\uʎ΋~ .HP@=y#$kmAN̑a23tS;Z )H=+N(WHeU8~ԟsŚFxBI :H^Q|neق Е{_$o&%m:wnDhzPqÎ]xg 4W. 4RdG /@-1z ^ a1O-ǙRhͦ]~"W}3 ӱPui 9$#cTj Qa͑YQ!9 'ȴ˺[wI;29ES዁@~8ncC Grzo"ydSIk"؂vIKN9O5F([gDHr<X/n rQ +yPY 3q oa:^'5$&xP^~8:+t_V YBLHUNM*zke>Im%`c3iԠa:cԵ%AevSv ;,i|fۓQwe?|I Y,Mߍ[9hg.@5/D]Kpr>Ί-731OLڴxlDJ5^oٶj^#ӽzԲ4,db Y#* TZ?C*/˕,E̽q' aiZ͸*έ wޅf%#. ŷfK/k+c6 &v*UVr!d=2DcP"62.9)A)zRno%/!RGaꃧd0),:_yi (_(.::zmLTv[Evj@ _8 Ѓ<ݜB i~xϨ:m%76UnTo"TNs|s i[n:_ gɆGbJ# ֈXχ퉚Jk0L:U.qۑu] S?4) l6ǟ+?Z錳_FO~&pzckC+[ѨTHGm= 5(][F[%JhoLX޴ѦKg!+֢gyS;sRp RlW`lyW3ǚ[pwmn '4zaqݴx={xUmA`UYuqB8b:JE:nI͊۟"T!JuKk#ke;damZdD8=In09J`wg6tӋ=ݜqf~q bI\0.o& XlBhrExo#˰b RPP z96hWCQ'Įoos5 ?=uZ K6pJك\eKilc Ւkr}_7\:)STQ9A =LF@Y*|1jbPr`Lg!RKq''ڭaCP̻&Y7E%'F)20W Ԛ;;9-#)XܗF J%&BGTm>s7d=,&3pEoz}mǒ@db@C@{خ޺SA\V}P!- Z&z %[rwCdJ4L5qA$ QDJ\–ŏw*Qviizv.܍e\v;#5M iBY]]C W}f+L~g.&wWL^|w^cf̈tP'$ # `e XTzHԌ gbm$ڄCh(} 5M*B^ŦSQVZ>}P8\خߒP/:$KKPrSO333 <" THR O gPBU+TG"/=C,MNʬl#xX?"P0* bЂ}ޭdhĴ[p+DS.$e]gTxLB';c|w {k7"A25X罓Q@`Ѵ[tj1񆣴Ҝ5Hs.BYpAQWo^D"!;1w^9qNn{ :#NNӁmBrXeA?TD :?eE˼(",CqL?@P^ v_lW>`ujy` 0fS|;6 ^?)nc@k v{),ŞG/Y*M Ɏ)SBkAT\Δ+PQ*ʧ d ¨X/7 MA+1FTsDȄP$ knw6Nk$3)8.gdc$i0D$9a,\HhӚ\Sٙg[ѥW!k,}2L2ŞKto1{A[vIu-2O<ȅ9E3h15Lf"),!})-w\d&=RigP5[ xfPoY׌ BUk Ĕ^ <14`%~=ʒ Ko&&7yq8DCm(xQvUEųu_(1sР~48be( {]D!Kc.B|Tc|$yTᙪV_c∊-L^b7e!t@g$tU .}6FI7?F+,<Eh\\`魥ަUW\=}i7 l:V g^QHG2gѾ󈈂jje >-9KX&q{ʂoz:C )Rdf'v,VNCY:M#'ό#?+Wn=\Qy16!ꚨWbG1+L밠:9=bg&Mӷn iުS/H1㲵~m%OwJYH9W4o+o6 aw"Tm)yg4.*fQj!־-h1oJSʴlkhw3+<#l (N@Ugba ^e5R6z-yz#y$1s1BDžn'́Ҥq(8ä:;?!?duJ ƹȸqx><./v>sk*{?b>sSz? -J-7̃KFh>,M^mHNZR mc}KvٵіPw1/e4;,p|PXOPX}~xbm ۲l~%=Luf Н[#r}ϗϋFeiglĉ5qrXtCL-?Ǵa Eok^4MKmz|6q9%[97lEdQƳPF%B5*Ͽt@?3^l$Bv%VepM fF:MH3ٕ_ ]dJ$&%cY }Scҡ#Z5sѴ-R];2رI eMMsYZv' lJZ.UK)'W4I*3_kr SqUʹT ATGy j՜u't#|ߙӹaVK,f_XP֦kxyKM ;S(|IN~4 7 H9ձj^?-,[j*^ǃ ld[KیY5o`Ӌ[icgO]eYn̳Lb; g.+ ϶0k4o]AEEGXU/;nq'3џZuN#˓v\4iY}м\Mh_8{$j2-+>ㄩ`mwpk$ ޶Hyh^2EZmHx*u~C^yzvwKEHZ!s3i7R'v4K:*I214z #|,r>7#r6+e)MUoS;rl]'SުC _I-:b*謔DyD{+|`mHzY:Ad^"d(/͡x nc4UUbq~)fevˌD7꼄CG2=b?k /G,M/0#@ݒߩaRz)hrZk$FT̲o:76)G HzHe-BxLI7J.y@x=*|EzѥFQ]C=3bVMpQ0rA+rqj,ՁI7t3<"=V=0 h6xIRu؈0CsNDagql,~g`,U>,ݬ/m]Q-_uڿdizI^7MT&⮬EI_ȹafwTelt, ?n0<#jZ3nXHtlػ* ͠lsZ~nʙ2A 0f"D4< P۲\3 '+s+@˜B #XVɻm٨/,0_1qܳk yIEZ)^V^0fF7!xЃ]w+[tnjˊm,C9 FJV#ލNV[(8ӵ'k>49b/Ɗ2bGƾvE˙OM5=/fp:1d)s@'ÖcCi峁<[9%`g@=.gHAKoN8i7撃= "AB@kCLۓWDbgκ"L9'>;F)zfwmԊ.)V>.^swC?mOHvpOHmZ?1Hn* u>ü7A 6lf'Yҧ1tgb{.S\%VGW{n&z)1ʰ}mG u7pȇ3):WWeesջ.q{ǷT4r,|`.@ 6~h I'd#Pge{DW zqaO7Se%mG.1|\Zcy@N/38|WtvS"O&Ҕ[_#.XX11/t_hqa0 3DiZ+,o+ W}$k "!EZh'[jE=v+fTp%%˔% pvTYWˮrrvrA]7t:]. ԌX]D/ao(U>~pH 3OV`yO@3n2bK~0szC^ {Mnnthե7>kkE5YJs3tSN8)@gf+R.l5D xTjg3iY,zLy85WI 2/lᘴ݁U6_ڄXV&iΖ׫jНټKS.P w}Y !SGʼ&AaA)J=rxnjMZBbQps|u\b0%?OGxsdX/ J#tM,N_ENvS#sdIfz l5͒R -" 悵x_qfHD<Ƙ\M"H)O`PAVKDK%9lOȗ71'V ac)+ƾ;`SfcԈMAs65٢y^@7-YBě~Fքivh, cb4fN1'2y6(v9Q?9Նpe[QkFoB$ES{yp, `~R=CxU'FՈf%gGE=d˖{wΊ'M`9~Nۚj(ji[}ϙ֠ljj=xMŞ?54ԙ#GӐxdGߞ;N(tvA{CıFY";ڨ(2}jYlnNT5QhesB%-eFD!.u${ 3G!e`3ӳ & F5")cA\.B22)%3OVYܫ\**3&J: +o (5H<<8$}}?Q|o#=\߂Ecr6dL6Q"hZѨjR0 * ftJMgNhn:`Vʁa !C==ћ/Ⱦz,65WaU^ Sl޾(mfSP/HIH_|cEE;} }j$ ߨW1P8yb0@g?tAO#g:b--֨7)Y)&P(gUeN̫'TQLGS鞟 ܈*tդ;kӟci%HB{ʳAQ0 scHxlgu_B[p+ivM\!l}KGEIQ^oZEkaĂElC;qmfw ijo˅ͳNGESWOf/B$?n$v5'UljZ"[+)7W?yEBKcݬ^|yS]+ўCcRX3g&F G8>[8!f[ZWo[XjvNV_y6﵋6"~WwP9 ɴf;;Vd# 7A205Fks|ƻNNm:uE| 524Sl.ʠi0ɍ6QA56hl IMdztTD( `m/*^`. xg+eGf_F4rrUD1똟2Ma/S;AFH,8E&P<|ݼ$+X ]*BT6NL0FHQCV>0 h&9chl c5σJKXi'+o= hP˚soք6D~í5p"h0ٱU[ܦ~ e"q&ш.qA%8En&IR@JAoQZ`:.:_v,]'(_H\Γ2OCX'8'T/[|921 7^kӅgnIpq{j7z@GjzLTEZZ{e^+M-SI,u@\\6?Xw5B[Y=qo,zo4vhWRA@;Wb8ώ\%,һ /=sS͌79c7.¶]o U] C۠*Ef#AiTyg0o+يUvK#9d"耛sNB ^_q:Qt&N[T>\)Maqx)P5]nȒ!rD/g$LVRHlRU)[!&bP4_tnԒ{TnY͚\uL}|futDŽɦƼ svrx&öhÔg`P` @nJD"9֕If7aL (x #5W,)ZB`^JÖ^Һ%rDps]w)+wW )A|!bv ̕'y]v6*r1,f ic%D "%2nϡܯcWyFrh AN[|`bl^| اbcDF`eGDME}lG@1|OH=@棕KY F { ~}vD) ۱<#X)EqIZYgKv_ c ܛ{4«N?1[\S|{"e_>z&I+[I|Q#m;|f=ڮ @=L*gDSe^d: AY;.RШ@1WF%r+>Ŕ5 |5B]|YӔmݽI<٫r$],wo?=j?}ȆHJ4q\s,d[iŁM$T5}}'cJG&t(nR}R]dJ>"I2`` žե݆t5{r z'Fu7K) _d{O )YH7ݞ&NI}2?Zۏ=EZ 5MxqV~LjsY `O˱_Oˢ l" 5pн gq`pޕv+F&pTNGɴ?oI媽GjVSԸ 1+izѰOf[\E6p\uP@naӐW7e4/z-K,^q (6}EĒwov iv%T"]#w\ \Ԇ-s.}P' dnjU @N#7.k^[w,ӈRH|zѳz$3#,2uܫmt^a7Y=ۚ`&~wbKեz xrk5*/ D̨]+ -D(?rN`:jfgE⃋I8ذO"hB1;cTl@Co#--=!?_ 1Sgm d>]>-O_j/ ܱ5E.eAʏ %ԯTܱ BWÉIl=m2t_L AiO(%fV2DZ{d~=ztm&WVig/iyRk'ZʇT,?T^sy"/- jZ ~*lw s.4fZ)PG؍pk dڰMd n]f\(2 UY-੫wʽņa=Vf]s ABZv)2{\T!+K |tl"(#͑ӘSn-+޹lUw؃۹02$8%lEI~"S]Ua;22њ ϋ>z _й+൭D744ajXb~SDrv\/qr\vE:_G{GOWlyX@6Ld")dN# Y[CHhp,)!橴 AQbȭ"ZP2r OЏ?c H^Ʋ0XPl mL@P&Ak{X T%uɼrG$T_P3K$T}LھT=^*P;{B`oRHЁܟ~"P[-Q؍mex+Չ#;8*z;l3TRޒ 3Yn O{?FPlHtxE`&t lf}ѫ2r~XM瀱"?aڝz~1#_WҩO,c:&~sN?Ѥ.h)+.2w4,e3%1ArPo_G;+=E8\k^l3bHh9_'޿)aTb( w;fXشNz뛚P&GNʖi v=^ nF/Y'.4rv.||=xd=dy b5o[р1>\T6)1RS9 GNV O*mV"U>1e~!ǭïN/B9zPmk7;%q,0{Kщ)sK1 J/Y-:jUhϺlCC}BE), p4e;MHkTW~H9vo 0s1x@/Gz~4m/l3s F';UfҀ{_ORLiQɍE*o"- {:Iՠ;I&0Z!e$ՌAJ&_Ai[)/6wΏ*}bt >(T> NohQU^qIH,kbْNiF.m]S>BإNoy[ EVwLn⮰CLb!ȣI 8W;M*bq9H J,c2JQgz9Xࣱo4'+o9,%S@pngb @I(.rQJlqq|' JY'oDWO4yljiU)P2;|z2^S'D%h°:J(Vϻu g]c;5K_d(n|K J*EY{!{leQ " ʏيK i"Җeq4lXF6)LmJT'xtnZ2ev2s-QL-A~nͽוi'Sv]#e}&'ط3O@@\$Yh3EcG&GTWG3?ln?*!Z͔i!_GMi1ĔS!Ģ[Ş{*YЂ+pF25C膿~ eS,m_Qxel]O:dM( 6xSKFQPh^\uߕ:d1}((DHk׭NwBQhP swceWAܒoNo$[ VgYnqZΫ3 .&GV2tIv[0=c[^5-NW҆ st2.bOaT9,qk"ےId׾0wul@4_3A1c{@XiB<_YDmK\t #pT){26x&-hZ^EjcV'sLK7Xifhs2?1Z-ӻ"~~l@X ,'M)W8&bN1LGh5d+lG3{@_?`*He>]2whTj0e4ʫ03 Kf)F(&\{Z82*3׷!J_J󓲿}سOϬc7yEf8B֟Z[5Wlv".CBsg?uy"6ut 8FbC{@X:׊O4"T~tZ$ 9R=.Ã9I7|22+(PD>p%xwMAb>oz|Vgbf4EQVI05GFvr3@=V!&pk5^#B3?041ŃW%HnkR@7sAz"ZIr!:UXv+TZN9SBQZ@̀Ѡz1 G2?/}nSxo,EE*94sqBjE(M:lLXOU w5HBpZl_4!,эdP=a 50BH+Y2_:|"ҙ$ɊbsGe=RB^^ yfhNRKB%U~k< &ȅ^O:Y&0lU7 Mz#a/HnfGuxGX}zj416,t*_^.oRo{2`2ѫwZoVL=@ ` c =7hX'Be0\pQ|Z @4S!;Kc,%10.fU'N{nM=&lP ~Om=mUJ@D [}翏EB_~^ x#E+Tko69X'z6ŦVٌ,b~[b %x`n7UEnG;us.&--緵㣺T `Jn4/<;x9JD4zƌ\i{uUOj5\Í@2t!W4l5~YB*hٰ;@PˁV;. k8s QcNPJz~ݸ7vǼo'.K|0q/UeFثQ> o S|!B7$ ^'S*D-f@ΏqsfGM=]i2΅pUcҪқw{֬  mW3-+8I|^؆<(jMU  ss`}RprO'YCK k%c[m(TXc0r1I`=@4I,(M/ⷁZr*+%D emR~t!sf~K,0ͥ+pRx!pNкZ$0JۘR#+xhs|u?/ =J7\"d{`k2q3'ւ;sSQƒ?K$*&\*bdИ˜Է#їy\ojӫ\]> SoAME7D3fL[$a<_hLKZ oS:˒.*X_7m:O(쨏9/Y)P.d ?m2kvxK^ ȼM.n죃7 [aÉkn=ꦣNȝAgTNwei.98GMe?FRLcJ2K'ŀXZ%-`MfQ & c`ij,*վC )"IZ*}pӆGU(ٺ{!6 ɗe$ڦu؜}) j,IT\EYi-mΕ]2f{12Sn^Zs T`F+@VR41R##2sYLSp Q$߃ 1L#;jH]-b,]n_ d`QYst{( %n|=Ƥl?h>ƿ Qּ,&]v5A=vS;Q6<ѡY->է`մ;.@P-~IHt@ɋMv7³,2\ԢW~^O[/̱NcmqՁ,*?6@跖:_;_1q2.dґÌ:yǫtH=+̬6AWD ^!B+UtT2۸6dҮ7w5*r2OeߢݞNǩTFV3XğPr3QGb>if53I}ڋSi1?D K' 'ߨ V- },-?qwm$5' +D[|OS RG&d)~Y=dF!c%Ƴ1jрs.c sUpHg_yOʷ?<$t/G6Urh!}dI-iqjkkJre*1K, !yex'~Sbg 9僽rlmq\/-`?2UqՆ O9ܨedFr3xlͣ7mR憼M8CujZh=AQƉq% ddnzÈBǤKBmԈ'm$>ڐBr9hhcxguDVG~tsl7uHLwlуUd S>WD*@9b @2jҭ`^=ѝI뎤XPmJ Gi2̤>1oR]Xt\EaQ#͵+B(Y+ կjI xaŮ*6/WQr܊ECuG-N?rtSUiǎy$)RjE~Da9ngz#6ArL^wmjyy(& ʒ:Q?dϡ-P-V.ICfYHEbJ+I[MHTS? Iĸ("8ldּdJq"7\q7 —rb렝vVPs%-68|2ԛشlPjNHJ>^ }==yһ@N_k,E4|B I\ӁM3]$j95tr%@"o>\20sSZ%j*$dSVU9(_69+pD%9,A (7tӵOAQS8eaҋt:SP$xoFQKx‚HXG,Lsg+-P @ߦ}mPkCB,\2Q~2+06SeFr``,tAkVXf]SXqb"dI.P9DQ={ɮ܆٪u*mC^WY>gv_,f04_U|J9>Vp.NК4˽A0?0e Z-W0@ F&ZݼǾãL*>mU '0bF$J:٩IpQ"߲6 ?ۣFs%<^գ=f ժ-}_( vW6tJZ8⛞M ;b#SH7EI)wH)am^18WќuѲ9=Xv& !&(3*y j`dY{:TP%G<:$/`\&`ʃګBD}`aYuM밹Qne0Pmjy=BzHKRcrI1vGPqy/Wv.N`,|'U,:GMSN()%%/Y;s>R<ҏ k7ѹP50,ᶬnS˺fw  i~9}x 1.Pˢ='pB_D-$Y\I\-pխ=i\[pa?{~ l$ 9{ii" /P m) &u]~o'oaJ3F\&Gmfķ)e=gz;᠁laL}`ڝG̈m>>t[/ZiFRTVW?6mm6WhDru ȁ.X]%o) Fo79>j ƚe-qҷMDR@W@I7o"eT8eG*[5(Nw$c~&~ZM)rQ:d ('n`n| Ŭw#nzwqWVZY+Lx+é5i R+fEao.ϡ#EQ=$(p gg>@d !n}PpZΞ sgP6xC`D86Qg9v+lp귷DRhօLп^|F>R] ٙ^ }=Q5H,vɭ5Վpf0bDDL>o! c8~,@ ,aWdpeeM EB^D$˹K¬!( ,jD2N?rh ԫ%G:&?VMb2k.s XbctIWqכGA'l8"qv(@ޥkCFeB5UM/=ةeiaW{k#cE?i'k "mq.+GAf |\}O&$@9Zܢ.(?92c%G4Rx61Aؖla@30<R{lU;7쓴6km@g@ iQ=&) N%'G(!#\T2|yV}kx+]U>ZPJtpP?2zw<>ݣ& e²/ ~snsۖiE?#*R6ʷjX;PS$$;upoª)7hs5sFN!frkLeT: 7pj0,gp߶ٝ^1BI_=g3V̔:Y$q;FyP+Y mR:t;  e rB+fI”$ds v$aY.g &_ЂZ( M|P_4,rvEΐdɪ=X3&zNt:HD Ԍ6]2x>8 &*8gԘw| ?ZTC1lf|T+0/}Lu^: ZaM[0nߦ(*F.⟏zݜ\nHtQzGa6f.-kQ8)K%ッnsxd!,p 0ϸلOe8 {"ʴ+؇ Lc\llA7:U۬F&IIP#`*dUyM=w~6n%˜_~e 6btqB@>(vzhlx JK.!ɹt0?:J K& _鰕,$L@n'WWerIϸ;б꒾2P'bV $g (yc@/RJiQOmMzr`u 2cJvn9H(hxVSوj\dDB(JC7 ǟ* 5k fr5"ƒ6X?U0CH2֛V7ț}U lV40TKBb #O#3;;UFtH1|ەWlrXсy/(]ʷ+46kJP"UlB;tȳ\/ U/hh}Ո ZkE8L^g۰GR3)l\0B(AjRGj-&D2#~ ?8.ag]:BS ܱ c(BI`*>Y -XϨ'Ab XI_edNG"!אָJ7ѾglL,4"BfT&g};$x5@MY, e6%T3d}RH|6: 8+$2NmOrsgwōZ\In)|n8;HVUAO %P*QcP.qxYKלZnDss p˴zg=iCkvlx{ﻎymxɆ0ن<~QSֿ;8v4Zq$F15(eCvfq_VC#qy?YIH km)ǒ ;{e1`KaOCfk])'6E\ >1.[ :{8og8bnibopSE13"қҫPH}L>f^J2fkrji2Y)`"XW$p۝G!EcY`wʺH 1U{K8 ٽh4rРAx4I7S9v\S;Ӡӊmzimʏk-͐+ZlTJiDJװJb&jrd6 q7npȲClڃN;;}z2b 'X3AfWr۱Gf6+)ʅD/4^d'nt(2UAe=D- |ÍmlvF/[ӞE=_4F.S:({$W,qFFQvM4PS`Upvcϓ.C c/1a_E<5Y KH`}%a;H/eܓDHb<*- G\fFwW4Kh*E_|#z;h}tj {!iǀ8,hd 9VMCLZՊd"!LkVܣE"aTFO|;h:-@0 ㄔd$wpI#p,1z~rq]6{"Cugw$@r">/~)`K$yvdcĽ/A7X_PNyP?>N9ܓSskCUK'-(RPG-0傒MV<9*ACcfD=X'{U|S4 iSg18"4"\́* ءYCq>KM-QQTOp^?Ѐ$RD(Ɩ3/,4պ/oIrI8\se_^?Y.5] Bԯ\2C5+or|wN.]1!F-MݢDtןD:zvi]`ʒe\[ENؾiBm~)TA3${N ~/""oW vŋNEp L8l63DGSI}ی|(zZ Ϩ,!xhao5í:[oDvV bC~sD[gxIreҔ17e"mUɆأ;"R}>cf ].D֡!zzSxxCW q!9Rw>`Nv7RͼzY@h*\'8M)G[O5~/fY AgmDԹУx<wQܨ47jt]š(_QEQhE/rA&py/BH = _Ѷ/v\/A;`g܊e䞤"@En-fNb#e59 u>dS,I4h [74>CMv0KJ1{ ASi-k9:S6h4jrU.|Rj>eR{cnDxxdJC=aDi8lZ,<0},q'&9ga0{AzP1yyt 5*D=ӠL=#ҹ@fD0GȄ272%,~ׄQ>hv=AM ϖ,wX9 F'%EI: J9PW}y6+nEM[M繢Âʊ˺4T$Վcމ=:v3?̞cN4rSTA)[1EV VX%joJIw79Ds*@v?TJ EVZ0 QxjZ-GB9:0QnI1 ^1MsHN=Zk޽/2)%d~md]3N)Q /rП+AX 2;WprVݛ<\i[-dv7jt@ޢϨ|KF݌i.jmjQ蓀ź jK3hr&?e(3Cº@bA؂,&Wl)CĐ>[Q =lLz,i[ۦx0९bn`7V /6Q<z9Aۋ&T_QC$}XU+ZԬo $\w 'NQ|C{,Rϸ`^{2)oɮ6y5*n@D&<*P OZ}WwhYҁLpa)3IN/9}K- ǐ ' ~u2 XSKN";ΐx{V >E)`ich{yL̙868u}x Dh /yh+S?*!j_$XW {9{*6 Ld`r/Qae-$̰\X؏p HAoigyH-`GP`CcThF`)3$G\BKY&Vۗ1e*6i% O:nl|Wi;-wh^ij?^c?|_Nیy{!iKo⁒mfNZqASݷbҿQnZ1=\wRG[I-)!ܒw&.6~h!J`*Q)`0{v \PN;H&%U%:K%? @ٞQ4pσ*Ld2aDu@<z$U~L2,"_ƌ 4mB$e/,?A2l-mi0&2aƛ} BWbmdfgN??oYdbw܊ ?GǠhIlmjEOLwbBo$vh}pI񝳣 ;7r4~̡XM? gdA7P0g0rOEN6@g[^vps[͋ȿ@D$]Ҝo _go 8{ fAV4`FD$q)qYf^#f<:YOQ2 g?6\>&=AKя<(.6Y a`K(AU+^^ɰi t6 ?p'f}pֹ ښLbIe(9?ig4 Bs+l!FdȄB b3 #0@}ԅPj!y;CA9Bn2cJN=z7 Dbykː֒9% ۨYR@(*Ik%qQF%YꪾD!YB%Xl_ӊ?,72eU؊xR ݺ/E<1$/a㯥 '6Dra.: 爠wQxNގK:GQ64.y<@ DV/XG[܇% &7@(4wc2Z@U̸[ǹg;w/.^\^h^ԼG;L=;*n檇BG9]kk} aBC ՑT'>9:fCeZ{:#ڎXvp 8iP\$$ rn CQ(^-bU|P,I`WhF%MmZQ.}:vU _b S[Q3aO`E.%BS3,EoANiev.g&w:e@]mU2bSW5aL">!e*w U~fgU6-xOGՒcI&E*U#fQ0`5c&Nď|0񷿻n٣T>oɉ)G2H;XmߢdN{ww4P;$/2O# s@x cOykWaHn^۝M '\J_CCjH6FaEj8)4KXIoz鍴vM oFgdEƽhnDuXKaL 1['B=(BQe]c| Mc(:z%FZ>4u13{LJBTo?IM1jKwƌʙ\m[-0|ө E~qmX(WR<+EtR1ד`2#E|vV_"z/(eIGW3EH'bք="w<ObxD٢^~z3ZVf"gNkW2. f:,Z98PM.>~Cӡ+\>8k%S9MYYظCTbD7o+,ݦw bh940_B*!|ͪ﹤ۘ=-dBQ / r;8Zb&Yfv˚@n FeJχ\# ^Tz\7KXȞ0f{o /};x/s~CQhlR;<蓑G7UM  WdХjJً-je䝰 E x*n-Y~@mhc,%]'" AsC;hΝ0s|cyz^( ȘQ4j.:G6`q7pl S5ioGH/>!׽J'Ď'9c-39*z_jM$i 饜$xdvAtaA&S)޽-sM4n,z8%H[, #ˣ^cu')my^,'J ۉ0D(K"~hl^ލ xxʫ6yMLN`B]OWa!cD mMnť=YaΫVό=Wi%>g 3 0c4gd4|bV!˘7xT$`MxHE# M ~0AOxk=%W9$3jO5mQ~No9AD48]z x*@Ub>pء_Lz;YP.\{uP}mA&<0.V``+]E}ёOy XL!qģԺ =L`*%]M P$E]>][7}pD$edAR$H`&԰#YdMZ D%Q{ HfTōXjKN{&`QUKžp!DL4H0Kf)kVcb;戞%l#~cENc_.:^<7IaJ٩-i/?h/[J@ Ce~I%̳.ɴe.ךz:v+nu"U4[f 4/#&[R,]+I~g9a( ʟXkԁd^$EqNpu&lZ"{.={E=lZvJ";q˲ E S%:]UbA$jB uVXPhk99A'P]m`1s=8z J˪#{v[pIgVjplܴ;THiRI[laš 7I9S 0\GeH乯slݢ#y!u_P^44(t.ge+SR$%і`XF[+(̓" n|/=nobNT<LW6Xg;1QQ)`LǶȖ]. ;z]Af꽌"]4i Nf &m<(<Ѷg8Z޳НWK!e Z 4|b5`27K.NL46'\/.X8|245\&p;x{QG!U,ȑ VYzP; ȮyElKb0~ƊҊ :m]QEM-tc%s?VGAFOa[ YmmҶ(٫bġI06ڳg ' "ƕRfgXM1ot!R|CP|G8ޚ e hTgCĀZ%2 GpAIhDu,9}@O l"Ha2{QV3$#U^X]H =y,#XHRx%zҌЪeᄀDqLnQ3I%h>aHb[CA3jZن CI$ZPZ`)tuƿ(J֤y A(-@o EbWgpJJ'O^p"~M! AK0)bwCLjMp4ՉfrWĥPG#7Zv%uԠ{n_28 vER2(MtjQwhIIz}rxc[( #r}suS|Mf=h :jHr! BЙ%[Q۲Ft.ћRus;8\MalasJЬB-rPȣ xK:' #6#e[n*Ļv#/-5 션5\ Hy{c4=xHq}D?(zԨ%:ppaY|/"xfE^,að~ ~qD2f6o`ď`~|YLMCn1)Io/V\G8"}I@us6D[~=VEЬS}kR3P7;# %-Hg6Bb~"ʧ'f81 y ?!d}~:RvÔu[gנ/kRgBfLms)YY;#Iͽhze6،QHƂv% $J͝M^RR_emV=1yO͹sr09"3U[__7t2z͐DyA[O{c=!翏hbuq]u2.n~ D eF?ntqXxr$ J{(X2W%u;ō 8*BƂ۵/q*8bAN%,4"/DH7)vpu>:P،>+$%} y&jOAb>b.T7"O43X=~U*AkX,2*n [IKҘ7NWAԥyMh_m15/}r)kaʷB@-& Yө3*|Ljg`>*zhحYK% ө>&w8> 2gz P7:^KAwZ">?sia:H [MuRgËWov32Y]#akf0B=j=PN$|[9i2Ά#MIýxB hϧ犾|q1+0 ETEY &琪8] uhXՀҿ~k^'*;Hx;m_KkjAKfbqAQLg*ӱo"h,;JD:Y#0^:|X#"=+fr'  SN]Č\ݲg&m{  ;=Cw뱮) ɨJ>&}9 MjhSCJʙhq 1Rӊd-*#zy=.@a 4PNLfsk焹c?Gw zȑx9`ؿ>Nكm0+fZ>)b"zA |[pfD> G16 ?C!IY:ymvO-^̾_){.M\ 0)xtS<*S |ZY_s# ڦK4 *[X3a'Y' 'wpo;C&ﺎDQApA2lHm@$yWoT {"|sMDMBdkYܬD.Mm3(){U62^Mf j~t⦹Rr[t^gAK:uګ[iY&v)t JƲɢ։>+&NDxV@CRV*&T)aL!1bbX>cw0R?ZcX+G̀aRj\A=bPadcUJsoQ9upcXȧ6`0;i)&6 ː%Ovy ťmyֽI2h =[D'Zad'#%3Mbc$MiJrE߃‚ Hi'JZ)WߒZvԿ^kW` 0^I2M. fUP6z7:nB_*C!yW ;S-C8Q1@#fUM5J+?gֵ?QW2yƍ)㙄қ9/xFV$?,N3A5C"(p=ɊcH:<Xb|\Y,zߎfZ8bN/BEnG([)Х)]bEyqvOFTwsA`2*kbi{K&ҩgB\'Q?< e@G5I &W(1{"'^oR8g;ba; &[&+$i[ablw]Њ7 zIscO D3l ~+PFRN'>ѕ)PkWa n}V}@ 0Kp2}ivI8 b[G.5+c` =Wc  x!&Ɩͭ}PjFa_k~y8W i-"l*bĬ&#QʝتTs?>k@Yx= u1 ~V@97bL H4t걎>sAqf+@ٵ _c(B{Ll]ax s*mk{rtu]< qWU`)S}com;]순~Sf+BH%rl4\P"LXcC<=:%gktDmR!u;oPKԑ#m"-CnN2OQDw7gF'"s L tH5U=9m(ߧC9V4}S嚛X;SDuݼ䗕!wj9L`h]YO|N!6z-ȿJ0o%N7)MXqUvHZM6dln* *kIeŸ'6*d!U ܫja>W-m_̙h4y2u+s]#$3Wӻy@0OZ] x.;;VsAR8q?afMXܜ!"N^A<#.wB'}Y#`~)*(H5C"k٣^~)k Z=QfZU`ywmA)QP(E`Aէ-ghS@lڧf}{)nG @RHvS|kU{-\c"^Ck ;eCJݬG<`4^vPD0ML;=?LqMqͰ]lERq3~H-Љ"ݱ)a'+m,'8/rK9\26ku3 D7x%I&@ Lٰܒ@ \avKN !qn !0\Pj9Gdz^˒<4[$Lj ~ ;0=)q0=;ɢ>gF\"lG7= kaM-D$He1{a-v#γk[~;HQ+)<: |~9 6ąp½{:Z]Y W|@IAKC j$NR 3@QʃsV .JtEB".(܁I Wo  sy35#d=Jŷ$X&ΣYci܂:qe6frfK!peBZ=;ISr\| c:nLrp*7{GGNj9s=̊`TZ]J;Z DIa^j S:瞫Aw*9Xsw*ϴmA*)7~6 &p}잾p(,K%$gOjPci~O[*2{u=EĦ'#-onNXh;‚@ Qس񘁈f \Rzn?' o"!~r ];9({>U)xON˝ۄJ'^2~Ʉ\ %Iٱy~7L_xA 3ufVieH؆/?.)^]@k~f-Nk--o/N{ 2eOm_ WfIH;*~'ӬNnqOeШsaPѨ$jĄ4~Y~:E]f$e3=wv[=U Zo\Dpv/B!Kw&H)nR eS3T-P [(&%⡝}O{6-)ժ6>%w:T # hs-)*By}VtU;%4D>8."z5Y!Gv2.-0spڇ)9$6[`HESu-Ԧ@d#ܭ (.i2vzU,+g 7^)$hGK/(:!XłX3>.BkG=F|&f0_Rc!dmB;)GT(0ϜGs8ER~J .9N@Ulapxé+&|Pm'rne+~(ttjpl/[eFϽ\Vu9JLz [ Pyy ÒwˊJuye(~nj =v "oO2uXT C+o`ps(-stKaniW:P~QmGP&oc9]7s WVi>onZw٩sxQ9%F#K|OK%DJqFSBWFJ/`vxd5͗(':#^U+D)ѸqS6)tQVONegkЌ퍻;+$'ʺZpZd";OCzhB0s@fTEf%HΛSP*%S7)^xǬCV9,Uy#u+nBu[飘?Ͷi=4pb+__ =P0uJbR2j6- ]mm jwv_`|!F6cK!?,!#kvjqt!E$^K^nƫ[ԍE a5#ٴe`n)&׾,][+ђq-qE^Z7 g4CgOEp(Atop*t H7MJCFɕGSnaB7"7bP:;V/_i:]W4*ibZ>'ǯ 0͋ӄͩ?t׭@kmϿwEwـuxW;/6n3d3}p$K' )v< hOq~g9FQ%M/n4Y1Wa6i9$PNXe/ 7LA\ڲrN!7rq5}r)ry|Qx[{Br%wIXu/2czүO =T7a&qUCFzYa!XDB}*g˸m(y/D7IH2Ay!έd{wq?Us[~B> Ȉzʝp@^=dwvcJJ L߾s/yeOg b7stW1x7ʂ@8ncȔqsgln8K{ IUl'Z^We]KU=-uU 0)byVo+\YVj`kl!jl'ZV,rrbf?eyot L{d\] @dW Ŷ5|d;Ӵq7{Y:Y&p^ur0J:+"tB= Ll};ӂ8Kg1^5 *Єt=hP=yW3z}6I)Fv*PjHv/~ƙDE835}J!CG#>sj:K%K_iRC&DQ1Cj35^a-ޔ*8ԐdcE4oC I #M+ EDA ,N<T Ýi oDn8,8vQwnMQVI5+q {@@THOb=!lkAEX4U-Z+z|3&ekEimF u^ȽMWK+{Qm O.j{2橗Efʏ jc n9PڠÉw~TSQ]*(I%3[RSOI ϣ;=q{gf;/69TF4fڑI|E4}Y1:xhwΜez0} {Sy-uA QK`;MfsztƂN^/כvEݤX5 6MgNh CJȶ%NUVDy)ReoR*}TNB- spȢ ubucAЀF|˅m{ArPx=7Ҕ[I88~#i*H QM@Qt  L@JVqmcJ60Gb_ [No쾄7b _`'sNe6vΩ G]˵-t2"6X.}\SAξg)㄄DGv 7B#]= Md$eNo PjX*r66Ǡ_>Vvg CEyg+ 拏*V3}cd«ɫ wOix,ϗ|)mHiME{_H^xsו'!N:5ZGV9>^&쟆EN2L1Q/`p:( uZ1}@82N, ΞNs3 KjI?/ٿtX&Bm4BCXL{$w Բ&hsQ aD1C-d۫Y&@7y2/}kDגTWRz+@#潴6*ӳ,@x/E:Jr|bA gBë8R1oZ$dx#B{(è&1E}8 31yz{UWP!sNr |3>E/m'ZmJN+tWf@" ~nXZVP.sy-Յ3={GPUv*(@Qж.k3p%pVo\-һg&NX׷Q8@xA&=vdќ.[UfVo-`O8aoOMuv< i"*nn֤xq@j  u׹:o!б-#Ұ^0'<)Qg?d 9>^=:ܥE휶HFDDUӉJ^Q-5 ]|%ԕW~ D~*IG^asĕm:h69qܿflZ9L74ͭ iŜCJc/R(Wcn5K*vÁDh*rt|\M!5-)ɺ|hxv7o=;|KBάC=)Ber~d!0|QF ͅvo,P(E>:4X ;g7QH| l@W.|J2;W=ѵDTFBЀךfm3fpkLD¯(@8jϏ RcABۂwXvkֺL˷Y׊l 4^؟Y( zM^ZpnQ| 6GAg:'H&%jzt`{ai*2~'3$Fablq zMZO#|kJ}"2mF@9g~O\.ys#yV:ej5am9HZȍ2vޠ5'B^PV *Sw5L?NN(Fh-(y7qHFBT#<ߥq%YV.rrkG3 gt{}kLm^:aXZr⌵^DG)0, n{ @ACm!US콬Ux'H;'6M1UirY:p.kRw2M(a&Jt2'^[jD U9 KkҦeY"aL}z:/5\SٲauFy.@>]j'x9yzMRO>QL9/5Zyyh),]Bލ.5(Г]_hUl\$aAD `:|^c$d$qXlP' -1JaC$kw 1d~˵9b\)GFr3r-`fVp͕cFJ`,|vq_َ _=oj ʄ`5";VW1lCYݥ8Rsq輤0GfEo2 @&Ϋ)9)Țw7tE/h #gm.(@WPp<(U]ly& yq@´\;%[SGxTNO%c$gs//u4=PbhA=gζg ?rÁ,Rvݟ^-n.=?mKup&eE/kЙZ;ELHմ|6N*5l%8zu+USaÊ?\6|{1<"@y2< >;"u/ךqC{SzL\N˕,J8#tS~C[?:J䍤HE16NPʐ4Ib~퓑+w(ږa Ξz:Cpt~эL w PsMֳj: 5<~\MV׬GH87jkU>Fg 4]VNLwKrG8};|"15hvC[V:6ce oư$fa P۫潭 [YIhiIK 2jݒ)FvIB\gmLHct9_ fUib[D@`'sSDȤL P+GZ~M7 fW8)z[>[)-;+P][Y^Q< 2pu'/aC>pTFK0Jcs/Y<Ȳ"fթt6qQ@zG;JMbCɮlHĢ/>-UI?cAuLyP$1Tk~44EEh⹷RUXwJ2+ܳ][ ɨ;2o2xG+Cw2 RM7=8eU&7!1mЇt\U|2I}@riϣJT^RR/t7F+ɬ *Վڨ9O3D/OZ‰.` W@mA)lvM[s'lhL,{O@7wq@xz ߼~Ǜ%Q)j65e38o4Yf` vV׃Ye€皞l hƱQUO#/_`.:Bf!p0C-/z.O_ \_v%hdk6>֜:  ƺhr&l@F_IL^ۚޢ34#ܜ׼gy_~]] sd2f Bd"p΁}o"!I켚k;$j|b@ ϦE _ .73$97L/;fIgw ڃQv.u)ip.JT!ӎsF8Ӿ= XC 3JNo҅$e/_ %w.:{?`-pPj9ӭoǛOo0cI=ay 4uItN&.BGoû}U bpiJt5"cAS&-m9q<-)˴ḿן~ئ&5[\*"b}vT^x(bmV-6^k;.XwGƄ)$pՂ}APSߏG5 xSW۞*ArC]Bd}pױ&)47s4\doiLo)# [[ #_ZhH(MR^}%;ޚpR@菽5WVe 7t>J1󩹶\-s,A=. n4JQ+*O`hkQv}v<1p}4{[dhRM-k1ȥf,aAL޾ / gv _"Ђt@stjgm>jΞ05*D%]7mCFء%. kIYO 'N!i^w?ۃBƽ|L})^ՕŐ\i)t5d'gD,D{tcsT`؜n-_Tb^ %[O.ƾH&;kUpLjDfYZsI&0v|Vc [pjp֨-woKijgĩ{O 5ܸu}VS~҇`䓴$qT~Xd- cV \C9ǙQ<a\}:y-' df&:'* H0Xy:GhO.VT^@lcZ`zމk.Ko1J)w+U2١(ƪ^{d|>$JWQmxveU[ <+f#~9K0 ?Wd~{1Hu~a֫!(zd.:L 5uY}_])>JYcI 2<,Y/'_nW:,ˇ(702;ZLS_(Rq%(d2:j5=lOXaHZT9|9A]ZGd^6,8K!뤣}2vYgg4]+2ہJ JCBE[8 6g$qkQW'2B:zNZ)E tQ1DH  13Xӯ|S@ӈD5o:~3Do\(եF",^R/tHzy=3)X tMf9uz!S5 oa}HxF$#Zku GU $M=.(t;VaS3u'_?9~UE~( hCPuLx36_&pS*Qɢcu2JEe"&·a̚*Y m;zmRbHSC$>%N8&\CT%71<wYPhy LaS;pYsʕ\f@eԾNASb InkABrˑtH6|G6q9l3*tQ3S22T_Ȉ@nx3smB{? &~tei;gC#.k.toJl;5s¸] J #dwK1sL^py^ڔU<0zІ<2o-2V2"i E7L{?.T,ts~oʕGLt|&d88@nz1֑?JFt+Xf6N Fl#'_Eqaв:dĵs*G+~d忐7m^ӑθ;2{)Eyd vEفӢh(%+oG}$^Lc k}8Wf] e}jpR>cF/,qi%u[jp.Ps6p$|C?(rI^ QvzA{gחUV?0Ew$P"G{%wu]x\P ;C@K:[U~f,2R!3Bkz腸 W!vL7veqNj{>ffT#b5N`ԇSPxB- lAWf J/5OIq: yIb"]XV! < Xҝ7lx->-a& ZX-dG*_6 KzOtق`B:ajF3v"C);w u;Ԕsy|aSY!_qΐe= +QN<ـF*)T[ l& ,> '/ -`3V %LjY}:0РPޜV,G"FG e5|P%Twi)S3vAu\6x q+gdD0tץR{Uo!{s$rVfZ FB\}P! ϖ(3 ^)4SSs&rNf:*W_dx nǶo>Q;D<ٙ`dazl1?X/M9Veo#C 1&4)\?iݬgHk-y38xݦ;;$O7MyG?U:TP$IJ!q02u'R@n[[Q . *9^A8oIPbc2BˆdkK'r(WP.XdC ߵ ЖUcE'EhΏLmx/]GHI~n#s'~-| :+.ikFxUɸ67FR&Z# DF9Iyً QnC}}g񫤥$ fT>A)z=ഡPi3ű1{o`NZm^W(jP)V aB㼖۔ "o|*&R kjJRiEdϪSL=d111o*ʧ|eP:fytɈZӤ(Qθ\>?A2t#Y30T߷]_z[tSI\.5)wAGKVҟ7KW(nSvē/q]BBO>evxX+ZxoI[:*|5V1% UT.& t [^r$t;!/8EҐ1;,eX+ce779~/܂ϔNwJd s_:ޥaNҗXm4=YJCByQL $wU$|Bgv*ϵz6AW5Bp;9]ԉ6[Uyx}g^=Zc8} (*fҍނ?lYfv[+XVغ*9KM.l[(&1菲F['4FmLb֘y__'o_IH>Nx3'/ݐE_c-YL6g#\<˼t#Pw5PfrmZԏץZ P#|ou7G-Y1N;kEmz.^|/PUvgioȏ$Nhu5aCg[9N]`\7S'q†d).7e(R2!Im/DȠVJoclFc!ԓhڊJZ7ԅ)EEK3WG^F x xFno, u^Oo4+JBp*_9f^t|. j Wk./2y "8@8σJIy$R~Q|W/O7["zm,h+Eni2o-FF>iCa}VAY/j>Q~.V|=]R6d{ǰMXIe>!B` JHy.IPAtz=k+V6,5aGw =: Xۍ! `swg9@7}t5^hr-SQ-A'&pq_H&DT^'K!(c$IZe5RKPйHkH;;6FƵ-2Zo,ߟ{ w㦜F5= 4^nIE6rk'5&<]mɵ3m@gǠ roC0)\ڀQ߈ּ h9+ =VSEԔXt"LG0oVo?O&7X?;< )*M3T9煛&2|ywi/*{?@\6 TxWT$L&m%峀Ck_l آn J8uέ}|*>@@p@,S~: ^+X@[t,XaܦH&•WT)Mvf6EB"$;~gOވ̇{i*{A}iL]s!TBNW6%7 }Zݿ4ۨ+ig02bc_ekLwZo77 `Nv` ]Wyw@H T)As!cdxehݺHUkyY^ml:Pˋ.t<"|h4Nt={w=(}O%qLchHf3J+,~glܾPV+4S7tg^ݤI1J91XN] /Bz+\ (72"TPe5FEkHF(d_^B6c{֝U^K?(zIvLϫml?oamoǒQĽ*Ag5YE" p\ U}Z1m==x~nL2@.,N– (e' ]Y ]WBt5y`7hӞ(SvV֡eC 7l-t}/|fy #2_-apY7`,"rzw?" pսRIlx }Df3(t봡 a`9FPs– Z&0oé[Uҿƀ?% I.LrB#cu$ɹ7K[uώ?2ٯ2#42@_J;`[{rBeTW|TA?v%H˜ 8+.H #0NK-Mb I󸴦H)n婲dknSԋRK-L)dy ȧ4!Y$Bg :Je|Ϯw6OC'B{,GFEe h{%2}sSýYMv9|Xޝ`\S3ytg:_Ǿ,=k+y3~ތRي{Fo!:=.Kk]Ӵu "At2Ðe˂z&A=&rXдS!q[L{_z@D 8S DH@ޒ}#K }Y'D1(_P#J/2xj͡@dYq`ˍoΕm+1yCfIh#=!]ܞmX:&W]^e哧'l1";YT#Za|k-iā͵}4 J'1dCoMYUŊyMi^6WT iqx1TehFrBM#0}% Tmgx0H+F99K#0’"lzm͇?ou,AJP1'9g-ˢxruɖOB.9 kΌK:n83'O9NxG6q85tpz  co}Ár c{EU5yFAԮ+@N͹ES\b}7 ؼKߎ4R|PYu?o}ĹA۵t0>g755e40=sF11%pž]})bUbT{m\P\d[0cW@CBO}D 2L\Ӻv}ᬎOS)4B.Mb U{t}@PYjjh\Rzsjy'2xm .Kms&ESĕqT 8s k~5˻ !]n C)l7Rw})qhk\K/ѹexs6'~1bQD̖18& ;D5jm]ݍY ݚ"j #ʢƴI4kۼ)Ď#(툥SL'e0$f@ (kp`ݬM,o!3a>^A`e!C[(L_feL>,;Ih JJ23d5hlx S0EӘhkV0}Tk|{LܷkcMUWķ4ed9ǝ?՗«_],ʞGƅB kM⬑XuW-ȷ7>wkkёxgLlN::WcrS|)s}H|* a"cdʂ134lխզ!@L暯Eʿ-00ATlʺw OI\0j [ypmQ`m \p3f n' .o6!ZBx>w2qTgJI,4fpGB;D/ BZi+IKʑ0WKeItynK,$=s ^\(_h#$8?j! H?e%ȵpEC2uFjLQ,sF [juλp=hљ9AM> #9\^4yMsݵi/ȿp38#fQN͊%:LA$dV!`ugս.#V%npM$Z 򅕑E1US~bR9cG;Ai[v`|n~&ѥ>Ј5jb]6U 6Zߍ:bDbw5(ELn`@N+IM< Ϸ< `Cckg˭& |Z?y~z4&v!DTسv37rTU&➚HFƼi`!_wK^(%71Θ \]ԯʷ:VBCx \ltd|qF٤D;CJnq֔4 r (&<3 WU2PǑ8U \MK&TNq [sqd%22:njuMBp?[G-xc\ɐ¢S| 斣3BRJܧ}\Ab[Wm(qPߋkE[oPj^P˫nt6:A_ ]= ƋG.=%P)AT H (x8*j#'INZ#aS]Nu>.}9sJ8#=PnbcPp>K$嚂I7, 9MC dH7ӳݛŎt' Y$ɚXͩj7$GAݾ:KeѢ,4Fj/ԛXZe39L*}&;գ@gZhiޜRuV04!k6R>D U*b5t*'ԸȱB*i>[ġ2yr8 }0u]9 S 4DŊ>DΚMڿDu̕ᐲz19=˥ͧo `\c(6-`IC! =*rnҋB2~ϕ k4ͬ0?;aJ84ʃS,.{KZ)|DI,[Ǵ^9]챦Y4UhK2OZjZavd9h|X!r28ټ[~6]ϔ^:3PA:F%ZÓDSWΣ}^f#}$vPbH[j@0eTǭM_x7zElcS(PxU恅H;dzk&dSL0z!fQf˝9!V:^>Bn@bE"ڏ) Sݑ}t\d=.)sT.ŵ`E\JIVW'~@ZZ yybt o9p'hqΨ/(h}GARP޾4T4Y"~mzǖ&8*;&N ؖ|Ҍh /FQ;|!/.jNpbZ{MI)yom> 'stC߅JHhw }}ḑl;#,5+>Q?lHܮ/׽?ut4hEl#r } ,XrkI(@8bV]5i8%cpIٳ99e6K,E|q{Wt\QZ.zVG,Ș[ޏjF{3bv{4C8c^ϐH8T ̲|i=0Q 3P&јL̰U3*D-k2ɣWU?C}꿨@I+YK6Fb]Ԡ~٪dXqu,MZO<[8]Q6n ƗlEOyXce=^t'v J fg2RF@bj%B֕Ew1FrC/Tv`re}5C9~h{r~1{'m(;@&γΫ'=Jm "C wW(E.j }"T JQ;+HD)_6bF=zɾBAfI8 0@9,pKm_]CCsi=)/_dNgDW .1;%:?)?hX}Q46s5:6¼I# 2#Qz0;9bZ {o˧B:47_eC6 ZѰY? AF39А)7Z{vwCU4eC.î;IgG\0,܋)Ǻ^CN'QqdZ0!_`԰wla-FsSİ:M%3zE +)D <۠ǁuoﭼnv/Omj7$)n5ϵT8g|{ kxt`a Oݨ.1كʭVUˠ~]PSzyAN#B/ OG`cwe5gcv V _f\qSl}|8KMRf< [2_V*.`d1_HScN}v!1'C첅~v$Jtx0ب7E 8 Vڙ;ۀԚ`An87_*IǐpOHiD{=3=-0[0ٲ6QShPXNzLUXc,azTTNҲ`$6<U>ܙ焥WΞe~隖?]¡ $ XkaV-i6RDxcRXv<26k)`5F 9erBqSHrguD'pzh)k#ly`+ |0v}u2D ̈$ q w{R~v "|"65#U0 vyK,a7!%-]v"U`CtO QNOb;|R 6Ɲy%X=w~ Sp@Fdg֚TOC3CڰPJC-ZZ=fvH]glJJ&)띂Qi|3?rL6,U@%J̬0^оs] .3m탎vHr}/Q=x "EZa㐈7ihq,{ Au.w.dlեo+Ld4:ռ؉&}U%f9DL eKY2&TjRҜzJ M4E opcNcox43q XY|S h/W{͓yr3^G ) v VMZ{HVߦZRC4^&홻6k~4#"C_πVJuɏЖ`,x0̚)V>.E+-C[o!'93N&=N6("xwS${+iE:h0yX*nۙ7Q>ﬢA'+(Ix y$e݀o6e*I<ጫOQy$N7hRmr"H{0e,9&sIO.Ut*V"oٕ*˒ł-Kc~ƨ L4O[89aĊ+dFiӛJ|jBVљL(rHG/GL#)R>/ VBSD%vߗa]'h)322Vфm\_V^$ILS<,؛T$SAYv{?^d^"ҿ'ly-@\d|*KYnW KI͆+`t*D0ˎgb2!Fmo2`Jp'tSN=Ȩޝ+ <d&KkD=, ٨q|)4B=uΔel{ElMkou/^f*ϰid-|0)O "cFpV09ЧB}τ5Nry- d b1Hv)w!zS0M͕(/I?P>|D&A CG:,i߃Nnx(.W _a=!53a!Uo.&:" Rxe0P|ٰBh5^. cp<g[i/Bw)8j-igcu%'H+'5ݚ`8NC(ٞOo`dكmD=/mpOIg}k6vo`rf"^VDڔV;~35$_Uaةsq7`6%PFbK(iN%QRl:췚Zpp{h z$ۇS59v)(c~&K.5'MIeﮘV3PlG̽6wmCRɜ XuE.A]#ſ*?. dٴaaD8-9'LJX j O`?w_lm;+dYQk&jvxw/ya/|\I`o 6 da;`"j:XKsqiRtbe+Pp/|G'!3NxDKm]0Tj;m Net5lNRBPsZ^Z4'Iͬqp|/@jlKMiV_L'_M 5T]> D!#t;J~h? ʾN%Cx}SF2 u] 7CHA#$BqsRU/%P#A3Ϥ xٙ']qwsG68*ש Dswdž:_}pY3]WFC )6S.F)b8Ȭm :{#4qHFٳ\i;]x@),24W1QPq6`LisPKW9_Q{ <і>F''zl9|Pgt8p. = }.|\hU'hc=g~f&}{pI]rLzȥjH%ȱKUOTFF*+7\'ߒ]>ukO];F3ńY3iY.;&#H@|~z{Xe}It@!th-~h3\:} #ꟍ[ם4<\p@Ļ2Aʾ*f?F vh7=z0cΦEN0S5V\XA, 8-I{>̞\e6 ol3\= X^W88F rl5<ڹK}T/)*s?ř5eIpa{p}np)n3a+ݣ(olr-$AiEAO3٤vB+d]:N*u{VHݱGTj<$Y-ZswKW#.HFܫ5]ש^Њ)lV&O_})fSZ1 OnWvC?QΡ.ˌ=WD8Bɗ̨펋{$k'z6l#Axf\@D{߱>Gƥ[71(V!Z$;Y= 6兄M3/=XkU!9$*z|@{@udLk}|)%a؉2 xzȿ2GirAh;`P6%UGW&Lm!_XE!-"vy2hw۪rk61H]H;:skB%ze÷>'wo"g1 S7NNWE(Qic3Kr6IlhKL)-+hKOw}<\lA"Mi;m3 #bR T$i)qi<%|,J SN1f-MH52 ')CF5vpYGWrBGǖ]]ZB6cd2E#h塰)//,J׶p^zukF(Z1U<LLȳUZsqᾄX$<֥Zի A СaAJQhb!}8-Mw)IFͼJm/\};k]lMU]jxǐ18O-^:곋REAz>1>oCsvPEּƊl1<7:"sT&4LgR)_~'Gޑ5 5ŋ2B]-* @ڶ YZ