sssd-ad-1.13.4-4.fc22$>lY7sm@><|?ld   4 (<Z`h     2PlEE E @ D I( X8 d9X:?PGH(I@XHYT\t]ʌ^bDdFeKfNlPthùv̘wx y$QhCsssd-ad1.13.44.fc22The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.Wbuildhw-09.phx2.fedoraproject.org8Fedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/System<K'8BA큤WWWW\IWnWn199bfb90d48fd20f0bce2ae9b51f3fc4d42c3c7b97842a5270c1206476df0fcd087918a0e5256a636c82f3fbd2d3f530cf2e0a1b3b7fe0418fc06f84c34bee128ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f671bec75623da35d61d8920160687556058508c5d129e4d5fc339eaf1b42eb858c1ae50cf8c49b3447d6f7c945697dd938f4741528937426ef784465a6fcedarootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.4-4.fc22.src.rpmlibsss_ad.sosssd-adsssd-ad(x86-32)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @V$@V @V @UpUUU4@Ub@UzUzUzUL@UL@U.RU@T@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.13.3-4Lukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3.1Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2Lukas Slebodnik - 1.13.0-1Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Lukas Slebodnik - 1.12.4-4Lukas Slebodnik - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - Gallagher - Gallagher - Hrozek - Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - Hrozek - Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Additional upstream fixes- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - New upstream release 1.13.2 - python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Additional fix for relax libldb Requires- Also relax libldb Requires - Remove --enable-ldb-version-check- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 -{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - Do not crash on resolving a group SID in IPA server mode- Rebuilt for Fix release version for upgrades- New upstream release 1.12.0 - Rebuilt for New upstream release 1.12 beta2 - Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release - Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - New upstream release 1.11.2 - Remove upstreamed patches - Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - New upstream release 1.10.1 - sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for New upstream release 1.7.0 - - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.4-4.fc221.13.4-4.fc22libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gz/usr/lib/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ad//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnuELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=50e28397930ca6010bf2cffcb589907deafc861c, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/, for GNU/Linux 2.6.32, BuildID[sha1]=1b716c73a68b70437c03dfe1a938c0acb7356a17, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)99PRR R=ʻÌxL׃YLi{Bx-ò ] 8(0S3~z$n}fOOz 1pu; U_5oG7.?^nխ\+ʘ>r~1OX@ܟAC{ U8kA"go]e5 Qldi{IS5aՓ35;Q@juʓ-P@R(<AxELF:#ձ5Ή0FƤ\q#&X nb_'L6@=Z-Wm3q֞S@s7 dMN7}`*UgpZ4.a"-F7U> ).>zTѯ6Mx!b1>A-:K '"zUY6v2Ӯ0“eH@ވh1d1qyj'2T|/= m((ĸJVB(I3qM>ibz`k1hqOY}^}D!ʞTLQtJ"ud쳲" 8M.PI$UB1*m @TpăK?de1kPv-[tZ,k4; 6A1jlPKV\n.?5~,>n/A|g0.Dh Ng5D73M-Cn(D .9_c[q3Ґ[8yKa휴P$y>wHOٝKK>CV+E޴h2lǗTMnt"pk[oD q$_@GkNg {vyϧiۨƧ0mfqI.~u*@"Ta+G80$:DiEG5})gİĸM<\$>!IģId{1-.nI$/jZB[,4u]x]xq'Q @eTߊ1WCd&d6wAܖQ2;i{.̪Ԥǧ[SvpӴ ,gFA3`V"YȽ?/^DgQ] FMjhSƊ!?$/Ma^6 f^g Vs$(F5ޯ[$K5,"\w nXjFz(q յ "kRZ;MHN I]/ o(ʡڽ|VF!m-QSQMϫa>]{JШ]FA cɤ!!wALf2n5hS\%8v#)wX zwd@WEcrGcoO:\'l C#@I-άIjs'rEXr_U,_!@rH*At ɁIP~m:(_Rڽ8&+Z˸dVԍYtఴ#[^x"Dvg/#{:S*dL'U^!%:> jf˄^s %!-=ndBx{C^:;ܨd2Y<4c/9zk]PLp5vgOL kè@n]p4N~",{౿?,(U7kn.֘R;']p$ണ HS ]9"4U!p\ ¥1/T-uPP5&n/B!ym;zodm, T90"_le@{!;PӃ. ϛov2S:UQUqf2uzNkL"͕iQF ' y3. {\s_#yL+"y-Uʟ8 Zk\XS3XQ컆 ՚@ .pؑey" pꛂ=ul5EYjAlKrk'8\'$OEOsaHYޜ։vArur1SV%)%Сwոܵ!hH7q]_pZAK.S(څ4R ._bGIc.*Ԛ:ޣ@GXF\uDVH/ڡ)T|"h-2Ⱦr>BW f~UA$&S27VGi.[XU%Y&jiVPb^紟G foPR&G2_ȝod, JJ1(M^?I7⸜Wp!3y2/ܐa= [DI"\pg0 Ȍ19~3xCVؓdT3 7E+^<)gѮtoKFh 0yMA3"]ZdI;#| 0"(h!|Jnʝ#Lq S1/Qvw:{gDXp <˕/DFk︻(; rwb )< NLQm.lҁ2ёVVΔ ̚`eKܔo$i[۲hxxIP' .2#nKuvGP.想 gC^d0K.$MH 4{|mfZ,#6 ͈q}X!br# $ݔc e x̒SVN(r,h<+`*PcG;֕nH )[3 钹0c#wl^V)*Ex(R;g/f9h ^3Uϵ7B'?v["*” ' DEeX7kh1;K,"d"0h24 Wn={2'u #k؁8X2|Lp> o< ? f`[d"&OIYܹ|ڥjU '_1wdlH MrxKq4;ņqy(Q(H8NG ʅ.mJ)SJ*2˚J0.XW[zcs4gp1΁# (L.8kϥcP7xyq%HUV_PοǺ%t$Gƭ-ST^ 5b=8 $i0MNBeǎA }Ox*e߉ YsF6-=\6"eqڳ)i׾"Cgt, H`nJ֯ŏmLɸԛ*Sqh if&T냏aۖ„H~ 7* *y(8xmZ9e+CnKi! ĨhcJyO`b4;=ߝC6lS_ ('P  OvyP 8[UjV!:%>,ք60mKL3/nK͔vn^nfA@a1BV⾵ Ҍ$AS"co' 0 !4t7dHNP,> ,6@%FBH0W'ƣW-=V oYS{e<'&5p]Wٽ}zAA^gW5 z?Zu=s/:j;-RE?KHs$ 72g/Kj*00E5I{n,T;WZ_^pZkL݈;wn@ {´=-n8>ϡḇԦl Au7 :-xHY)wyžLk,(_OFbNM|oƘjk=.Mrq:;uUkn>~)oba"d ˸Drwٛ0xVRY}A 尷$p2a5K b8,V^aW3H?wȟHDm\[)pS7В#5Fy '#Pg:7(dN#_ݑKpf;,of`35nԶmT5.x4EJvS՝G}{2pa2"Y`Gx5.su594/k„Xq@|Ne5Ayd>J!o)Fl`;\&ս%%'-b)끉hi8G0\()?p(!2~Ob@<͋=[ jX``:G<\H_ 7xcWȔ"A)uKfzP0U|X1UJ)3S NG;R3D?ݰ0PC2f@#zA"j{M}6+$++[\g$ `pu'I+Ԫ3BҽK9c`eLsq32Xmkm_j9y-Kx=k)St5sLh_ UfQc%ӴjUwB2j⦟žM87N-\`=-4_@%AA qdVhEF0Z%%dTyz;;9`/<0mnd4Dh݊,{t`+57ߌrjŲH4/La> ((N b 5906Y`1<ؑ]mbӬ%6'Jش #j]FH wjU٧& ~30<KUPWiͿKgqnխa1;s?I ?hd n~5?Ɋ9[IAG}AQ#o,Ov2kEoXH^sIvImA> qӍ_>_n!hN͝tD͓eR!6krhY!rf+oTMbΧ>F7i?1[_Q . 2 -=:*PgOˬ4кӗ/>4ɠȇg=̟; %تު-U nSIL-Cg,QA,͹Sole޺E?&>!wX%U1 ~aqN(BIӺz#~"G(@sSny/|nݬfU CUVmNbnJwk0&ǂvF|^/Iøö^OTϳbs6F>Rz!jJGhd^iUAשώmG:|odgƺ]1dؐpWOFܫ}wH99{=^6!ImIFkT ۙZeXe9c sUA U$hiL{X?: bP޳>f!x9l:5"t%uEHt|?CD6A&@SO*iQD'{JflVFva~Fgn?Vja _Qi!2E|fbp$iN߆vUtYgg"F?Ь)vQ?s1]8¢`a3o~%0ޒ co[,b;Zx1ɋr3@wݏvP^htql?%vXѳ8?A'cVzR0d^H=Սhy9[V9U4jDB,s/uTsJ 3ķg :V/c2 Z-|3*^ȷ:](sa-R4nLE{ͦj;+s1lUg= ^AB(*y]m} !/N{ )H#ɟ& ϒP S(<((9O:WGhv CmKS:p)J!~ S`x|tl jytD8x79 x|݇?>BS|vAuun$?R-'߶[ɅJ#?d5aM8Φvn#hA$vQ0]Ajo7IGsy~,KgY/SEȯl >7O]/%f .nc@@#*[6/ 69Ď\2N )v !eڝ_:}eǷJ`mZݸ^'d )xNLd°Ŀ?U7(@ D4~fDIzki g:n Fm)kλ59M鹰P-z-s \H>phԉ?o]'=[O癀O{ULu{㟵 o3?mh 6T\෴#`,މ%%#z*pysv } rC@jULQ#/IZcF,qbM*ӄ^^M|ӏU{0]wcv;~kaboKǽu鳅@Ϟ96ܸ} ^@1.$:P ).'ϸl`6KŒ3\Бr6K6-/V53G#fE2_6P@Q?>9NAqk;ʈ1?53sfdlMlfAʦz*1jm.?ɀWÇ쐔l`?RQ#Ȅjk$s=>JFx" Bx`Rzͥj<xLS=lM!=1XwNg5# q2#V vAԎq?`7ZR!'(\ 0Ͱ+W6U!!$mxh_{8|sŶ7'*>贤pNu)R5Tr sӛm\pMR&3Xd=S aH,P2Z Λk*;:FǠF/~> X cHQ:uq5]}]lqಒ`=M\+E{j;YbԦ+i!0A@8/sKߡ_O+ %Ĺ 8'n(f-AQ\9 +0TZI 7Jx33&C]PxSk3#Bfjh~uZc~wr7;vcbrHn̊G̤apmǿQhXTTgB缯0مަ\\m$j9t_UpcfP}  Flַc%Eku3"Z]NQ=SMB. gwezFUue!|^nqj0ykHH%t0!dh*BJD]V$ahY 6 J*򺚉\"RlfjβFVb̀?pxaƹ[Q1/Fa`tm*e"<ܺDkKu_۝=SC(ڨC:E۪YgqSL`1p"!lVi*W* $`E]^-*?sHcQ.-ʷyA~o> ȋO˂&^|F/ĕx| BB{e ڟ청_$a7kN1$%%PٵWRѦiG;E"NI6,=mYIiHW^Y[g$F ^. '5hDӃozʺ1Z`?ԣPFr,.Dfܬ&K\KV4+n٣ff& {:egᒵ 6 vnl!Rqf[[5*rU.xB #b{~GA bPժPuɢM/}q?}+`5 u06||VV5Q'!\WH%t暲 |Cv|?+ c%5QA;.zwAFT<>V(Blu]q_du r9$jSGe/iQTj]|@ z3c*Bo< /RWKmH&\uOH03OK6"?] gBH#cfl:KqRw rcbpX8A>4=N1ςq0ĚC﷝5vw/й&*9aYao枩JI&UTm{E'An)V5N^`9P',}hQ?2ht͐ynTg us2l|l_40YA$+&9F} 5Z=V>I*>bEiZY7wm}|(փSmF\˖ [nj>W_=xX |G0(s.ٚ(kz΂O12XS iشI*dAR괉hZ$RiE'Z@/|B0D*$bӪ;є_] L֘5C"7D`:۾ܐ}M\b 5Sc~H0 4Ե`r-+"4)Ǎ9BfrMH_~"{ch'?)Zĥ-_?/f\~ ?9*f*D.o=J`hb+ OJh>XQ1̽+[2Ȋ9aF$ē&Z|͕TX6\·ueHD<AN([{~WTtӴ.Qp}=fS+'/\8=jMΥc>}YwGƢT%fu KRkP1,npU#Z Mu;-lĖ<_s'| +c)h[N=LUX*r\: M2rcJrOgkD:p*x.4fW7_*Kc )дJoࡐìrZ,n8b+x1KF8GfcsMQB ^hؖܔP~?㣸 GӲ!E@$=aDm$>+I%wI ҳFby,yx eCkzb2t 5_ĄRARFQ2K@RFbt9:dn䏠 C2Ce]N-{鱚}Lsc]}of +`7ՏK tE 0wh(mE\@tpeZ1w $7x5׀wSА&iPVb!WMbTaeGٖ))wٮ>kxThWB%M&Aڲng ?9F%c^ן$eDQ"NjhץօN*'WBk&evTߡ')u74Lؾ.Ж2Y8`8PjwN¼6d[xyW;V]z\"Y6,}ZOcV \v auN Ldx v5Kwq"2 =k,NLhEWߟ[1dC0kn}siNnvfoxiCH/l Ez֊da8i[! $d6vױȝ)`]K<]K\ўͶEG's|1<Rz} abwK{_b,u]+W|HZ,R`2ݱ>QRyKL?J@Cˮ_A[&Pwb)Ȏ 1d4ډ -Lbl,z\fQDSzfTUYJGC}:hLXӝ dB Fuo+8lo;1gZq$OhG/6ቲkY$JY:9Ԅ"2a+V_%LE MX[¹Gg^ƺ\.²'aO4ҍ:Ypyl[lc\G)EC/I>ӋR̥J߸ XӺҸF׻v۟:Ah̃A5^%w_qm@v~wffҶRvj}#ʫ%f{+-|Ra9?JIe.еP)2IKϳhNG\&ۡVHiOf?SkK,v 2Ta&e/pK_dG#[7"]M [C3P Fn7V7Y#+T WW3UEs GQb^oTaҵk `5ûHD5b}b%ɖ0g#-l1dSš)E7Ŋ`8%PSG݈]2L5t !DRDᅻ@Ikra+gƊ^y֜ձ\D޶MsњϘS 8VC/r'&5)ix0s!(Lrb$hK*rAU5%Exc$>$W)7v',Z߿#[-} L)o Śxd}6t%b-Q38lJFIzs?wRt\1fem+0svʶaD1.iƼxrвE, A+i|[}w9&ʗGF7 [݊:n$7HfЩ3tkm>f.AhaYs:v]H< :td3A Erн,gmd&i \]Y iZI ҨEqIP$YlH+Q+22x,?"wgpTyn":yUF f q.UTz[:&{: |*&5J}&s"vDӨaL hךXH/dKҳ*4K״{rfM~)*}+TH] 3#vtް6RNI$da_a׉8(08Xpq;vҤegUk["FV֚R}MPs2jz,\m"`~h? H@&uBT8/Տ?=\$;n]~$408CMq?ݪռ]/L5(y/#p9Je`VMQgr'7=FICzr4A@hgvFQ'^pu _+y|9 yDLѰ1:"p"ǃZYoѰ4%b-Twg<Ŏ1`PY u@~Wr@} `*aOZЭNm/[}!q+6: q[7MMV;18)[} :gcX+[.\JeG5 S%';NŽN/G dCAW"tOq? 83zێZUHs*0jQ //G2 =:,'ĥyqސ2Bx7N+|e ;|?-9<3h`UόJV8o^[#W+:({.]'4ThWm(t0 ih"$f%I `՝P{nߐ٥r%?t@ww!B;t&܄Ti0,-A;Pp\%15! θOUe%OzA9 1"QT9w" ER^\Jݑ+ボ="_!ܐB9ZڨƹQP_qB_8ҧ]03|<-/do%!S> !Զ)̠-マ ^》)%*<"eiP\h$n0VGDЃrrGsiVFDxڦZsoB3/ nJ *woMIdB\çu~ ]~Mx+/[W䤊M\E'h5etVX4/x(ɏL!<.Oe (lН@@C|+"R VA'CpNnZRg VIg[[X|h1O-p$5@+ɌgvMڹ(*o?58`7#13Y,x=IܲLS+ౌG;Wσ3އDdKN')U#;jYJfЉ&s^v㓏.Dg鞚ˢw)!4jLw>ܥentsC5NGP>@Vtx3Da8xUd4q83|LJX2m{2fLj0/qgnV9^NOt Y۵]A:bU;ZؑiSXͮZľ>?vV:ѣo,?)neߌ1UXfʱ(9zF# =-G|`ajB x6SU]L@Zvlc!_8g\T]>|C~!%@}( Zib2ێ8DSrA^e'3j&:Ƌ,1Eye1o/?XXCF ibt*g R4UWdZXzzY{W"} y̤0 :H~Eh(|nO,Wk`ARJ}#QqtSGa=r:`~qE6ԍŪ~@a}Pm9bk[Dw!SԈ3{6duxrqTnfkȖ,(~`T)Z#AGPc9LU17=nk:R 백;? 1*cL,?n*hٱJ'.)J(B!*y=|"5e1T9Q8ue,4XlL]36HN)j/YQߕW=_c=[3i`kPs^EF(HY'W#-DH%%`<7tĢh]m%r(*l;aaUTT-K?t3ΧX< x8ޏ6W z&ή'p1w%߯`$(䘨<1gFs:*SC^yg*s!|D3F,q\UꨊC*~3HBEkkhC*__([;QJW7ք,jqsZ]VYz6ʺ]=FUIX۸p4D F8ŭg3˥*>gPKY/};Q,AЃm;u=m<%[YЉ:iׁ?5s6WAribFn)7F˽`,6p+#YA2Xk1"t/7ϊSnr]bADVGM)lLv=yPZ~W) L}P^1'A~^}X7d.k먪JyoQwk}4dn'mV.Ǜ,R|!`~nH'P=LhvW@GhN@q=v aa~'>@O!ľ˺9Ye(o'u3)NAztr{u7s'= eh,D\-tlUA,ʗ;Xp3&_p΄`^{AP襝aRqC5\X@&vJ<,ՓEzoH@j7ZzD%[mcKU+*kEpS OgGY1zĒ OVOqM$t"mAB^6#D)gzxGOcYX@6Œ#q/w=s.vt:rwrw;#]8 jX;'dEG!LB[o&Fbަ=nYJ3H`$-O#Š|چ,ؠYS;Ki뀄gbP(;HV5Y'^<##W44iv\xeDsa݅V{PQW[ 9ghW^$9.P0&:i ZQ1.#\* 8_iŔ*xXq @Jcs!gӮcT%4G iL՛]#i]qLcbB|yԿ1+jC ,vX>'_25tr{2;j}$6ً:<ԛ=%&¥ N2ޔ\Q;rmZ2Ƕ\ w;a0e.J2u`l}Mdma.#^;;=|i7eFW}ڛlH&}B,L 늊X@>~(.D.Ȭ,1HڔsPPٰd X%7J KZ5P/R[J3? Wٟ3Q^ Q,Uc^濿OB_^=&}&oX Dt8c`"ĉb&̞GGw[{ %,& U6}zw8DEE¹cB;;e+s&$|TH pGQسʅY,a0>Yp\vg-T忌UkFPGvjkۓ Ȏ*K GNdٻ2)|%f(&z<ܗL8O.ӯ,1Fg)$_c9^-̻" 'J t:u$K&LR'%ZXt!2,|g>$9$Ug+ ?Փ#댥V}{/;!CwF|y]͸0H:Va+-q$hTоE}e|Uu c=(jxgA*8a_P۴C3߿VhfҞ9Ci'eEAL׀ e>uߊK__*C?S3mNp4##Gͨ0E._/f9=6ˁCpuu-4xx*߃d ~wf+NW0YD }hud'ڛξAM!YV`:FgѮe-7Y#F膛xSb}'no:Iˇرs@=1|am^>* yNpj]WmL_wiJk rIdye_R'[9b> ?cV745ЭN͊G(u~[?J>"=D'ng6nٚÏ,w8oݾORZ1t,1ul̦HM5{Ȯ -7(yBkiM X*ERa/5>zJPP/-GJw^NwQ*jh@ OX/ts]\5 Tޑ$,1:Y: 0dǢRL{)O# hR&-.BܴhNpep Ѣ`OEa2-*&&3;;q^/wR`J2\`:)44eB/$b+"öӫ3c}<~`Qn(y-,`*GH ˟$6#/z/JfԻ.r0I/EnյXC>gE:;pEqYr+R8 (5Aa H!MW6j$ğ=y?Dol!R`DW$cJxȭoPݡk[NcVa [حf̖,``b^'GRGB]'{=wO2R!̻3@CؙxLhq:e^HkA'_I ƪFAyQJsiax騶 qIo<~eX$ މ;ѼjGq)T8O՟#Me+, &e[)@&a'-0l N}&%#< ܭe+*#&L3,EK+Ry/ׂbX~—@#Ҳ#), E$px5lG^|') UL5B bχN-(P,I-G݋[J SB(R4 σԛ.n!^`㮝ҹ$|A! XYYI#٥$yIJUO?r\(b0c¥%{ǥҽDˠW+aMFVH'3Wc@]jSSoy۫a0 G{V_zUEBsT@=xdtf2%QllR+fHhFCOThX֒dQ¾QV +˲PJ&uu3>|CU-bIIJ]Ijo(Q@+f # 6*pӞX K6Aw=0Nb[K[ƼRvK""7~'yWkag ) fH@d\!ms1܅ 83sŵn\&H%*ӡ{}T@Kc8&"@w3 ]]-vg \r;G sLX&=6_ zzԤn⦶hDj0ryawiޯc,י <2MJ1i)`8fAh3:) :315X~ F-rF⡇:A._D rAKH"!a[!+QP"o{F@T4wYŚCPйMbX!R|D4+')پR鎜6Q^",Fe0E51<8x (n`֝gda>gF6?y1I-p9i. 1^:}A"YҬvycp?EԒn> p*-*}Iǃ؛ ?ܩ ;~@^]i c^Vh#\"ޘd*y{F/x,&j9;Tw}`B<1b>rojw=k8/eDQ?1ֹ=vǏ֩k\a8;NX9D0?VFtXEd?s# hX7/Q(@l\a䔰)DQ1f\Oz q 5'Hɮh]x}dG G팕{]ޡM'2pB~oֵam^ 0gv=`YȨ6T?ԨQ%kV]/y:򽓥,0zVA^%-D7xﺊLe#,j_`97+PpAA%GQWaq+\2=Tmfo:. JUp5oUyMfF}^xۚ}HG|-FRJ'4qÙJEJƵ.%>udЮ 7;4cpGKW`5uK7B+@MGz&:;X35yJ)uEl3#gc~9W FA e `qՆl:Uo_*}8 ٪!SDli1OYis8Q^jR|߄!+z:f\=3(f]J,Dkaj&*}0NÀ 5l ~lyl_Y΃szvQOR90O'c؆7}oгzȺ9%bD:ْ,}`FofO ?Qa瓯K窅&_eѰ3y0'lt 3hB`C{˷^{?f w0Vnos%M0U{sbL6dshvnh9Zd'nčpE-vuYK*B*}ǾZ%4+넖 /`Ą܊9܎gμ'|g/T7GcToIid\L\;K 3mUw|S!L# BA|ɚ&%-(㷹NxWXiX wtbl S >=~,(؅mv{4g4~>* G%o~,hu>l Bfpe5\>D9++w 9eƯ6Ty+zYi3 G3N5m"Ĥ-5B]FEci'=HXxrc6.\U@ N/t?r+OCmQ>&Gnjf;R_ AX&gH w>+p }k$ r/ ߴEZyMU Ut,tq oSh^iL%!6 CE7G~"B RykҶ>\!NʵP+ :ra.B1ggO}p,Px,Գ/?gFS3ЙמL~f-ѤGRq4JN>Z| ` xǀoa/Uͻb|FQL('`QaX(H\z?̾V`/A$8<^ o~CIa3rA/ uB- KnU }CS{-eK󝶌#r5ʳ(#ȄXxՕߑNi+yҀ ތ Ks<^*o^qY HF= |\И5nw=QJn'.f.G#-ɬm-7+h,P׹֌IzUqIDk~p^H/nlW2AަKVӘC+@E,C`v$G {JN@!ׂ''7|~Fҿc}} GcoL@"&cr2+u4Y]#Xݷr Ӡ$ׁ!ˏk{'4@\O v7M8nΙ^\m,b $ԟwzP";6.%^ z~ }T});aŴ <7Ximxp+y<8\2{ɟG3cWz.QG# YNF y^GDYcǖa=Є?>t83|O(4st[Ӵ{JT*Vc@?7 nx YvR3=ٿ=SLYtarI$1. Jhsۉ\+J>a1h`Vň9N{|]?V纄в.&S,1ANk*M ӯەjEaW{< }E#7(CXɡƀPGq BMW_A` fe^H<ߣZ$<$9/ek`׬3}Cwdm״@^,lGł09g2֕i;^{4zE<B'Vo6tct&unz^xFTh(8%]/u{\O)I;8l's vwyͨ=C- 8o'i/Y@:,3f d^b "Cx#8bݰ';5oήrُ;Lب!o]ZO.\{[I/ΜV5:[$ћ6wO>ʟAQ1-`?TٚPk:%BN)E*p$R>,myR댽qAo_'#~^4 2d|%MȬ)ʲiD&:@m ;ea?Ї"jp*Pͺ#3għq'☳8L+^Pc^Gkd/s%55}=>nF+ Pe8y|8Jh:@ F+\Н*!hn~P0~۵TkaPCV]&=;X=PES(IeWH}m^eh!d$ ' Bb&ǎrջRt /22_IZ@}VHat_ǘ!Z_NH%YJNE9R+05OR5qoٷ3[Tu,Z!{h q3y(]ꤊKtl0e:K_!s>-M'3D9'Be'=I~wdtw\?G*•>֌|Tt* \zK[e?Y.1*.ZLPhU:^Jjȅ39۷[w |[C qge[Y=_7ޑGC/d\A@Ϩ6.Y(yԾ ݾ+? @qE3X;* 5dڜy%RXQlf 00̐` *Z:Nv*4Y,YZR_37@̬<`Cy'IApBH ;3Ov}.|Pvg,v2H#Daf@؃>?cTn{u%>v"Z}9E+>",P[m!!Ed1~հSHrCI7#+ gB:ވ $ WI]1BmxM5 b_PabYŻ޸vCWNB_#\)t% C#{IM"<{%w(N`$95M+p>S}1kcrPUqڊot-((=>σ9R+>\YkYT*t%~?VdC9ʾ$?X*]Sw{;soKܙ02Z]9sS9vZà}F9"W*ZN>p 0znMկq2_ђ x3\DV=m!Jlq'yv5}^}zLty]BovWِ1>wWd<; Уx.p([d.L?Wg;Wxj *.I ERvsgyQp(b;HCWy:^.,ڻNPESXo/eL5VH{ޤYؕDX&R>Ո q})T}20 4/ӕXf%U]eAgwB7yC2dH1EF-eEc %lZ'8cՅhGQY ` evo`\f9 Q5APZ7`6PtIXTF 3#tC14 Ovם'c!׾k~U7sD.ޠ w߁6Hi[{0I0C){d91fu2MsG\rԬ){ŘP;,|ZI,эQc[[6yDƕl(u"K޾,񀹶~Nk K-SV_kN-n:B #: Y\3or_  \5VH1*+>q>wU感5P:ͩH6*vք)y07>o){h_UO\#׫0d~ T OOho<2=~y/y2Ρvq/{_u'DLE7a`8?|NI<,kF-~ fnj*{oI4 bqvn6W S&~!!3Ayeh8ohhykiD,ήUT2v> Ҧb$=Meal͙}5^ ՁOk+dd}# uwڍHQ7qvK!lWқ#)/X6hy(Y2l"]i`a2|~ zA͓c{0uJ&0umJػb2 jwzOu/LUn%S-VHe‰gV i)FMAkݍ@p0cG#aFW׀ԡz|dy6Ҡ2T'K@ KPTz@3=]ONl3s“U QMG28Ί~I`:%r>S OLsg*g]^xE5<SI0u.qk?JU*#;r/Stm7øVCJ8?*uCdɵ{)~Ys72Tw1]C"H ")4(xBP5d XbAA<]Vt % Vi¿̇F2XPz# oY(,U15H@x,傤[:#N>¼ktr[6rC8m5_.:Hg.U^AB)幙]vF GyD{}+?P 2vV> b#u[`OK>e}3q<+Wom,S j5c?XlX) oZH+UGZ Ϧ|G@ h7, CuomѦ2&#B߫ )&5N_voF1=  f.7S\D"2f˚GEd`+49wPF6߄pc0δ 1| ݟ~tu:MuBV ׏Nf+k&pџcnҫ"{Vkh~@ b!K U4^Ցo%N-e LXAwJe~mgBI'[;I#ӯW6.a Qg-B@3nF)=VV.PFS QGr7GFI փވ4.W;\h bKt16ʛPU #ob@#;_ {!XrgZ7ʧXWGktm<;VNNaO%~#CKAxd_[ygexV$-E!S2闞r83uܖO,T?d%wM6(MA#E!WO??-/۝ ZGsTڗ 4dgR%C!Q(驚΁N/K7x%ڢbev㶻0D̡MsJa, o5e;yݥtrK[l2=TM@Df;X2B6xC "N o|y>xp*7\'yj6j+MV֩fPl\v6C %#x r,mdH#Cj4I]|uYXmXjb4*rU""wh ϒ‰&p4EUVQaKG8yn|^~At&X5q]JeA~+e4n: SR&kG#/ ե|)9KU6(v1Icƞ՚뿒kiswvsd$}Ew *XJ{DL YirD#knLᄤv!!-)]Nt;6n\Ŵod~2$A +p wPpbxC4u -G^xz G7RBrjߣI Y|E?kP*^*ޟ WV\2xM{i.=ɜT3|k'Er])5L>Wq',ֳ܋B{)a,OPm|ԓR:ARnQz8O4ô}-!Ė^^#  TZ#dOQ}U}8+PET-@>r MS"%zU7!-WhcFFޔq>Y0\BEk)XV7NT`rUò׎m%F|+zRمnoS1sխ>XrEr]s< YBcɃRUPI3OoRCV1K^WV[/i5`ZZYuk)MC 3Ie)Ԧ ^RLI ! t1Anl)nݗZPJCj,6z$D_ށIZ2+5nsW_?ؔDFFԓD:q\o}uī/E /t&qFsU3!._jAVo"g( ] >/w1k "w4H0ÚUgz" ׈d-8mVϷn!#l@~HD|˥Z $o"W^ܻLo1 =qcd-l6acH)XoMWaB+JlC.?Irϲ ʖLBvw/(k)L:4~\u?>j3b{_ۡ@ ^I0RO@UJً,ৄ0~ gн%&r`wOAŸQ?Y!u\*EO٢G4=Q%9sdFZ1PJr)Ւ;h++U҉~%OO*'K/*Q:L> DŽwľw_&/vԭ1 B~·-^—/rH>q%v\r=?U2ʰbS a˦ݜwY?Siv9=^rӫoՌb$!'r, A~i h bXރqҞ-%SuN##Tgdu=U-jbXڟS!;5ؗ lrwl3b;;B{ZTK5#c=8KosY6 ,9?CE=Tawi~F8U !pݶ*+RXI2qBF3%E o. [;57AJD\ܫt`ҽ=g|par{'wU"˳t haы(0<= j8q"rGq4(w;#BʕRjYAB@b0ԣJPwtwbefVd>hP߰M8DNAG;|b٘#hep*E +MuO kۉ;\'6xTdmf{>"3r;:pB)n0Q諵^N%@JTWI#&ڕfZVF4j8Jm)V+yB=CQ18D-'sdԍSAL®fWWU4BSbu;=rMMË48rnc|)_"J `ũ5!Y-PwYK/Ƌ&I=Ro.0?0xC5:J3Rp{@"a /H+$0˜KI!2u^`H$\t=EEs{b M#̜dm7wn]:ɖ "R,&n;RwܕƱO#R MO/JkO ET.dX s[G-i` C>1Dw.njD&# 8,d. Zef_.$POa7a]iwFri}#韖UaY&QSP=WJAs2(4F(*|HvPl@< 6,޵ ug,rP겄K#͓!F750Gc92 [2@ Yv$e=USȔ*7;F )'H;x+EI#j.I3 *FgEG* sXc]$X p~HՍF0&.M(,i9ȍ4V<`0i¨NZS/V/ZHc#v5e.UD"=ONװ$GIO@`h[b-qG`bDHSg3Z <+SߎJI%O] ONj]?uE!4)M9?!!&O#*&HC6A|r &0ݳ ~^, P=mq}|q{IW]q" BP欞Kw fC3F< gByGk!Cy U"SUDžݝxV,d8K,:+ v7qRVw8<5zZ"$O5L<x4縋bX2{⼰} "Ր`]F;N? @u[&9Q8WE.j&T-Zb]1X++[ްGYoL`fvR 4ќ6cQ+V7 : _rQ jq,BZ v(/P\$¡^@AP03bqF^^#1qSb[)=[z!d P,\`9m,W `T9ʔB9QXe31& fɜ y_vY Qݜ 5s4H$@l6t~g.A5%jH+! jsvUT*ri< TShFr1q=iE# qsl@:4I /o<Ҿy`Dʊhˮ2:D-1zdQvTh^Zw{>_̓]S326GsvBԔWW-G6Smv:h`nym5*7(kKW'p)PlkD[xQٚ,/ }ͣ+>SZa?[SvEF9UU'ex1 庢υu _ճ.}Vք2TӸ+ʂtct9hM h|Ζ脗W7yھ=Nh2)S:[=0AwePvӓG{Q"|*kgL`d%Ùfi_3FYJAg?0fS^K: -F pL5`DU*DTho_YGH?&)nF>rjp8hd)G(QBjxt@ˁ"&"\U-Za'ckڠO@dUjawf|aҐ@$N^$כ|,7ՠMZF#"> Zzb9h~fN}L&HְXL~ˌd3&sPzک$kvqC#pkd`Yo+4h>{:y^h]A!4[zeg&poj5N˛K晎}"=3w߉}s71oN:vWtSh}.sQ"TN&%gdV㉡gI{-/?gG Xl:/S ka>òڪnah{^x& W;xǫU0|%A cgbg1C,MpCϟYWJIտP}{\56z`MKhQ#O-l|@4p}t{v)-R)_gi[|9dn vsRe3%ZZK|>RF\4ِKumħ_m6`xh=htW ɱ`{$n$%@nh|k>o4R-~{'U{/Z qqAϦgu{"[kOC8zr1ٔbD3׻s6UJz_/؅O/!jU籓KԒ7RY4 TP.ϰo]x l.6R r J[{x.tH1XR-~z!W5^$A+90;x.!6FC/;/收@i_1~mXi˓_Fʼnn$#Ne t%AJvMMmIxB.:p7!2/J"םk^ J*x٨!Ie)\sz^zNRfsέx݋6:,(D*FpI&w&@ ̖"zFFdhr>7vBb`U;'Kw%1!>a7]}9m޻8)A8guw(G3odjWj}ݸzbR4Z$}=$W~B!F@IНhS-Uq]w2f^_*§onh9fORnl ۷z/Bo>gK?!'%4Q36b5$' hi!5 dgZHz7MfHx&x[Vγ5ãK.וbXSj(I3Q|!,FqױM]!|Xz$wY aVʇhzx"@,@G0EaVl=)虝JS'H67ge>ho}63Sb/83/ia29G˕ikD-<ھ7UP/^6OXqCw 0%u |/X&̛>xi M۟3rw X/YS KIJ[٣7v诞1ӇP ,\yYGF#>YhK gf ՌW0p<6EaPVvseAC2s/ T1aQ^`|g4r/ݎܰ9"GJq =gY#Rs!]༂Jiy&yvFH+ŰwC4gg؅m'99*^q%x' uVs/Fk{L@tQ"-ZI@ .8Tvka0.f|/kʙ %=&=]0h q`nIZs]EGݑp:8 v;YA"w c7q^.`LwF]RP a:*NHxn/~0xP>$޽DC&ѤSൟl# $yJ| lm:?4$U.*Ub̼,[YV[ƚ ia40xZƒņx `t{)ǡtiD C-}1ChUW_(ՒNkh B}'7cJlx;K!#;U-O$-mExwZjH<\mpx덛G+6R#_FӀH(Ig1:V픷GSish;LWTVLje#A -C)K >0XXȑ4!J"jUEfM{voӆ]11zVDn?;Ce.9J*UXLJDDrotHЭ^uس$ 0= ]\L=LR$`.Fzi';f6U5V-d\<[2Z'0-<鳁-݅ :ȝէ ;Qpv4]yB,Ev37pĬZٖ{s;fs(+t|6 ?l5 ioPd44mh2:U F|$&`UdJ_\"Oj:+-(G!JTnl]U#rb!rJ0S#欬pOU40]  v=$m#xu2ސ~9KqK<na\5-8"D`tEe\Y v_RΟ,`*CrLFfwTh_ȵޙ} d>Xq"뭪 sWhoӮwFx:Ty0\T]_ާt%Oi~ 4=׿K|@zy8@bNPH5U-|16d tx d,{{,>}]3"J)p%2XgUQQ Q%/Z ߬e#2UM6B7 ,ԖuS**[<}ae)PfcH*ߦswF&g=/bLvY:| 98Vk,G-OkK&.Sf]sn#7:&X(Epܩ{;Tb\ {5?~w`e\̩8ې&NS%:C)(1 Gl|Gy KcۑR'+k:k2l OU8$ޘ8f 6N B9vulꅞU=˕?@`m,oMʎda1aT8|X_i}@n^ȞR$Wjk[~#?z<KE<\x̬1M[XG]n|{xz9}߾VC3%igOo4a:1f켼'Ի g_0~BO|a>m2+ ;2SV$:e #}a , .83|k{78,YXm/[ 9HC8-8O(=pq?&2;&rf%z5FɝG#wVQ:Go& p!cyt6AK}Ӎ+W2xJk?9T߇rI|ޔ( xR^J΀qF@Κ=t"yJyk=?aus5X0('oyPY,o=)n*yJLqrYW/;OΝH ~q렳 ;&Ie'^Wl+䑣Ks@`|*sqґ#ruFO1g|_絬՞Ʀʥ|.F39hux":;@ ]LOTI^k":@'u F ѡ-8 um{*3$==q=◈%RhaO/ oqcٓ !ؙ?4iNn BJ1kŇi4vy+_MA Lu<,?F' x>[[I"?K3=tux^3ȾyT#k`ԛaspc @]Ce׮qV}P˽#XGPjbCj[_Q)| 18113  F.Fz0/"ȹK^I.}+$G;$*Ԇ+髒HSә/Cvj!3 WOfAY=E ,~ͭDF@8#'<}%%g+xFq\>FXjK@Ub1aAe"Q 2tjk}rT#SBMlL 鮂V#ncT Ȕ_A$፲gkɯ$h6;R TD`}ꊖ؈>0._MTԺƋ:YFp+1Rr ^yDwwxi8>P5 PW8O۹WkK~Oߢ߃#8ѧqvM-;۟q\3m PtZ9XQP~rĆ95C,GzV*F{AUtyci(.it/tV͋D]ź=yïu> K > &] hn87-{d~;6KcrrJZGMءY'vKPQ;u|a(d̨ؠc.P䋹py U9"r$Jߖw`q+TPy:΃湩ǎ:ʢﭓ=a:n^#fRlB\3 2>CӃM/`D@u m\EmGߑpUk@0zlفB=cǐeL 9OL-t۪+z[d{pt .,suLeQڷJr 6o7li$/e%iZZf]AZG-6Ghl]@6<$Hj]_ hhBЦ ubL\TL"Vo k,5(__ٌ?\ (M<ה7|w 'óq)0;0$1 1f !#/7r&hQk!z$k6 z+D]wЮ&B|sv۷T*_!q;muR|̻,wΞ; Y`i?kb{RcrEel:WgjtPq'ݰSL>E@t9Bo}n;1 Tv@W %OB)_~z$H y9"_:㦷VñB1 9r.2Sw:c&y; cH߇1,P`4):֌`ʖ:GkڞYq2$ [!:((E))+X (<X4 1\۪[i ǎŧ䍽-NkMkLshēIڇ#(UZ"c#(;jaX" \$K9붑/mTJue<p[nc]4Tsɕgx~c(2pJF]b_o<&³LjOǘ=]Ax9YnJps8_IG4C T>㪶q. TvK$(@ <[}~}pv{[g`j#2:)Y1ja98j7|`Pj2H|Kdx١u^ S5e0eV˩]{[֜(MmYSO8 'P ^awN[ :[r:np&oTnC҇z(Y {")l]l܁x ty9bV]bUD.)BW@ .v(~ƠƎ5. TfhԵb;M?`c9.'fI͌{^:^f]O?=)MPf*ccmKRWQX(\t<h9OOH :)YS=dj0Ym‰ AYDFE8oBq.0ڡԖ |W{ =#o6*p$k~+h,&7%\T+] Mli47Kض?ZYj,ƷVL{@ƢE,Y/Rl$5(EY݂9yFqYvz$\|vNÏj[g2YPy ~@5RqHklE2_3_*YZ3$B/ *u meψܮ%e_9V!Br>NBqLIږ/9u6% "pu޼~>BU5PZZ{.g[.,ȝGLkhG}$B,\f:B8}v ͋%s+$_ ǏgVY'00p"=g) ƺUzsa _8?8{bxyۿW/ W1kA^{YEeO c\7Ksf苯H-2c;}>0U,^x Q՝'ΌGRp kޘ%e-vk[|`E.LvO,&:5Eq=zRV@*:7C}pfеŶm aރC=]ImZzCP&2h\T?Pnŝ`٦-\s 3B#IGȄnM 0u A|?1_Ɂ|1ӨKڇZq7e)3uh9 s0q@\q ][ tVa![B%g/ x32zWfAb%ELZzѾ[>r>~IwO-{ l97 cVh#]ۊ}f͖!V=pHo85+4C@͹c vìw0 #lg6H% ZUOWƤ/R[--å IDznn x ݸ8zKF榮tlQ7bHH:F[ZxZTʸv5]yŐT9>mC._F)ϟ ]q뚏vY]~ u9>{R61?FByO; ,-`^S ZL=7}n/2D zSWm*Ҕ_ 4#,N#|y%TT9؝CoXV9Js)d`occoѸ~Xy|*Ի:W5tIuԧhu݇J6T$AeC*7M7䝘hʞ7 +9KBx[2>8~N:d/@:Ek %cיj$l/mZqsiFZ>,>uko&PM lQ-^(*aО]@ˆ,(D]8f8v[cRv)xFt>0G/Pf1[`7ux`tkeLg9>qn͐/sm /О ڭLE.+ {ޢu pbD0WHgr+ G3(A؁ Uzyӡ`0xre ,ou/#qgū4vXsN`mRzgӞ!9 >j~5Q ee%VE>_0%FzXC}82qؘ?)wL C[ ~2n*`G@7'^N}"%.RJ _FSTI Ib  '|0"&qx6QDnnI}>)P)RqΊvr@,DE]n\_pdMrSPڅ3HFb-'PhZBj:@:NAW/PsQ "3a0 (1i%PJbWqL:Vu[O:g|CefBż׎_1U3#z\UʈҘW0@(#FH2 59uu/bc"0*d03UE2(?p en O짃U$5-cMǨq6u4VsY17i\Ц=J$y&̸͖I`L% DpQ[lpwG-J~*@nl|h]"Lx`>{l=R3ԭxbЫ CWoC X%jP~z` 3涖33VnIva%(x^[sJ m+z_Nz46w¥x n9< M$2Ԣ>)zzqصvA|԰*zLyEWvv3u8ʱ >[A(g_$싚G#TgeWqIG:m;lWIխ 풟`]Y7-·TWXeV J` %_@ѳ[iżrlbc| &>K3֫kgձ%GMUKK"?˹ 3|̿Fޚ]jc q[Z 1c tuJ2nq;pkT/x( QKL4Z.'wQP:sĽJ0 Zjoa5j0ƼO] ]WϓzǴs^ Wҭ~g-L򻀣 iU+Qik_z<ۋNѨ\%xFxttvdYׯ$;ڤJ~s9+/bLtxD^1[5 ^>9X~֢iEw_,fW8`R9 ~ݹԳoG7',AelpzAiÀ/>uۆM}Ē*zߟ}oq}FE1'?!!ZM)dWJ*%{iRy'@#[g..ID=Tr;5bA(W`*'o*0Gc&1%1Ι+"0KG(nk8!Ƈ#Ӕ2XS}}yHaO Nc>YHB'uCƀOp-CF087!N.@ VpLf8֐/sgڣt X` :&"cӋ4r[,7)?USb40YSp&{Gdhn_{;Z_|w&$5%#Mx ~#S{Jxq.`Ip  ! `{tԊ-= s<|`br4Q9nS g47AL PvZi{Q*8FJI8R0q,^m'CW|J{=`h_3@P52@$(Jw Dm[͑:j̚GfSHBly,'[&侻Ʒ"T'DB ;1]-hwin̑k(ˊCR3&me#8Q%~G[Z?t ,GX{H dna*Q 5R I17e9aƌ;OnH/TZ%9)FbtCL;EjNm9/>#5?^ ^}t\qf>ȓd<qJGwj3~lT#"^$B.1ud:t*F8S#3=yL Us)f&@iB̒U"Xύh+#/BLsI7QF*ۥbꪑAMh=B12`+)W?>ya}g !ۿh\*tp90n#ݐDVoyOC侊BIF*t?J-D짔}0=TnӏO?eTEukmRUp4CF(o$^@ N#3F6t:i=`kXUUo(oiC[P" Z깛W fN! \Ԋm<ܦp`iO)oPG:xĿcL(<KmWid^?`Hc}ZSI}I|+j+=t-~DU ԯG%fk+֊a*R h0rwAu-zTM1:#i^}/:;NYoF'5ņ>E~6%[a꩷y#'Q'!yS 9i )1bF,dΜ3'Zq)Yywä y3[ J|~Ms%d޴ˀhd ;gϚbHYb%W 6Eo ;w7x)%*680>p$x qTdfs$w+=a2ƙhguaop#1x~d ʝ+ei*D '`s Z$f ݗ\PD {KK}%>Y`Cu|-rKR!~}Mb?Kʕ`W(uzlΎo&j 41؅Um8 g 7˿aqOk$jAH:E5y.dº˸lbT`!2$H_:7A6`c05jl3F-ik)9xnC$#oB;ٍ]Mp,CæP g;jUbI92iGGnz9P>PExsm. 㵇d|O>jEC4({"FB%[ٶHL. 5m!!?VOEx`<@i( kotָt!p)ayx=cGKi_̩+%5]~Ypi,MZJXڠS]i.>+?1ܣ<ny؝ K+xGܠ{'۫δj |D_v?sb(s&H m:150a0/ùɤTdpi"(L Xy(1"&zm?Mhg-VK;9_'z[OHeqvOֹd! ոG}/0!pX$;^ 3 vM} r9=WjߣW4q2h4; o~CgV.لڣY!#\84U Vη6 O"GyZ_MwaY*fUcQF קrM0Ua{rZ"mzzcYaFHSA^0 J}pͬs͑C.ST^im">Fjg("?X/vLJ wgD{}@\^|jv껾"IP(bVw6m2), *Z(轱$d _%S͝4538\Z(düٚUs r^vDo-c?VM*p="!"X^OF8ζNN8@!z WVygGP%?^; ,7V}9 ?M;KVR9iG`x 'zs(rvE0N^c}_6i@gpl"nqh­8{c $M<ZB̝ܮy T@랛aXzcj6koa^>@~qPc4Z)]QWB߶JY<ݭpՄ6 {F2Peտgaj2୐!3ƄBb(V;` G[_RC@QQOjxF!lg +~,9qܧ,?Ta{-O H'Cn (XZeǰLNzPԍ$1ֶ3"8=9S٣_}~4Bmz ̤nC>e7.#gI B8ۅP.,gAe KX,2ҧ=}7~qʹ}TSX;m^^o\,[@=ښL HQzXb% {I9&B(tV30Y,7@qs8Pq]/x cj4?p(+8D6G>O3iM[ӓ5A#V8*sWi:U`#OLlx2ʓq,8nWc .Vv1ʌ%4H02"ꝐGx0 ngWxAVD넯tй7dQw;vO^5x`[rwp A|40,4#иxjn \Ĭ& ~%=.&':2:ۋsU=P)OiN-cMX8^*ĊpYێnm A.g4Q: FOCREމ}r|?5q&qUo-HX)>nL1(X&9W_\;k)f92yBDťk'Ҧ6 {āEDqHě'>mPMMRSߕJ G&W{Dr9bjf+:o̶^u\hi@d`NiW@IdWWߴ(W*~.Uleɰ|jɴ(]5hW,9M˦]qE:+2r(; *' ?%OTN~0*j& #qsW2_c6-e[JKCT3<|a柶GQh~ +$y|p?:P7(O9BЎk'9UsAEiպ {衙>M9bpU)W*gˆ+dK9X3SaqrХLjj|ƨkb nWW4}֌īLɒx ?T8(7(9* GgO]`ssY#ظY'+Wp"*͜s(TU978Z2W7EК/=#_v a.|]G 0*xGn/>՛i/çˁ=Y[m27JCdO&QRFj-R%f`J N5ĻKHtx؏ka:Y`P4" ia4Wb FTz0T1l`tohyۂӸŅ=~Z\fWZ#\ _jq4͡Dwp^1S@ m"ka`]ASE/ ȟ|DMbUE?,X"c fa۝2:M@sb'dX@P3nnm莃R--aK]xQ#6cF`̎ E 27("e TZ]) $_=yln8ze%ȅӕ ΩDi*2 [T0.⺎78ԗDZ|pM[S (Z;=5> ]B2XwLw)o63|JFkd޽L89 E+2m ׭"k;d|Z~ݣnTb"c xh-#3P8̿O=b!s| 8tqR!Yx/tHxCY1f?A"yZ ڒn9wDtHq)U=TqJ"GZ*?TD! THo$߭B2 F~T ^ACژ謜y3wi8_cK3$5mSP਄,xe4A5-Hw-(uKCȏ;/r$kR˨t*`EKJύ.Yz)"[ B?opK)P4ynQ oԄt#"o coz8vЭS wEn8K:yzXzQ0=Fw.ܛ7Pa!l >?T*1=bEn{؊U43HnȮ5++x$(>`"ySC-Abn D*bSJ"C^enQ6g| T*g9X_ёns#[N'*sQBvZJ1KBᅲ, GȀ!W}ڑ57fTQy9hm mP:Dע dupUlp KF6@ ()}1ģjO[Xȭ)>fOMc`E^ruQYCꄄr)^3Đ7m]助 -yp X0"_Hi!ULcUT^'LI0܎ Q5(ea>oY*Xw-ڎΔZКfn3$mk|*$T 'iGH"GQQg~eqA)^3YZp'zi`TBj %RYg,fhM7ǁ>} [hV9æ5X-7%1yPΧi(7tt=9`__cBy+' FRVhT}\&qHcyVe{SV ,O l0t졪;Z?;Mᱪ@_-ț,9w`}e?p}o'Ll磋ȥڂw 2-:YſuE2ǡjnǧ?~uu'7 PC%A01Ug0ua 'St"7-CBӒY0-j] гOz;K&&KYxK^eT]I.>\k|0eJ ʀ_t iT[ i!|l@tkrdzIf%sj\=f%a\@MI{`&}=㼨eKA('~ɛS$οsQ!.8)s4ދq|جL76BwX}P'\BV*ʷ N=3R̓dCL uaSFTD}x*,^m7e1D~^g/p]-Y]ny6,Ʉ?x?Sh9ebVX{&_]Le*] BuɘK3|T-5Vr LQ+{Aa_,ekM80MSXڷ.Cn [3 U%\0B2uWq~_QsU [|(=\ւpFK UZڜzy!a ^}uzϋ }V"B96Sʣ%O9M Ð63~ P$q9lWN;[B r]8P@ү(w:iٓAlT b7~e_1mV& EzEH_3Lj_'2kJJoeeGh4$/1ya /}`pGs*vk拮^c|yrP5X%DQq<Yjp k.IϝR{asN8˛1e< Qn!X"D}ut'\m(؄K}Lؙŗ/BCBSgJ*_?#p{NA^qU x5߰*ysu.SޭМr1v2i\(- ۫J OhNJz/0Nx++H"g o5&jM]r`S8vvCF|ҟ̯ѳ:=i3%fP8^hQ󝫹VٚAʝ~!?j) C;v$gg6s!?ڂ[D;g~l?,Ig͒_VI;tWsJybnYij doFJ '%q{AO\In-Zvh1U}\%(=Rtm*3ءd6 =[c5JʛKៜU QM@b䁒Gw}i,X_ahp'녃Je&Dx,SHQQw1iuLv ɰ`̩؊Xp)Jexy8#s~MAnQri؎Y8RƄPB|ުͣJC> -J$|RFܥ`Dc\Ow9rPuq!f,TI4B&dE>ϚA6`zwL7kDQ6%6jЍct&NίƇ>H/5 }KQ+-zѲ=ѵzdG2xsܯ*m0qY٪ fm,Hd<ѐZ$/ukfOgǭѵ ]̬jpQC%Tc]rYf,/U>mh,DL\)t􀀾K" (,ulE{:rKosչ.+D؀ %&pT9<]~{y ~uӈIR>;8H<{?`HQԏiGű'`aăb/DŸ%n|h]x}ZJ1$ZxX=Fi'druw2*}[&ZfmߥEMs:(ªڥU` C{HfZ_fcytN +",[="|!B7s3 |ŕ8 9rg8)PRƠcx ۅw2s! q}NOPvi2UޤεÙ`yX|537*,sQ97wKUw֑w&|2R\ {w6~@nB*{479|q~@3C@5C@ќ[8KBfk47sАzt^ﵙ/tЍYƟ?PAC{uZHGej7$]]v1No&1ϕմ{ѩm jlOs(k md>Ϝv??`z`H z>i[>ٶD.>Xy:h[?ul0aḿ[])#J: Qk!YҮ<,ƀY`My'F=dLaS_JT ҙmZ 7jQ]M'Cm(KX p o\T^x{|j߃yC=(fjOuC7j(Iuh| ;\Wp-b|ٽ۠Vӭ*H[sYO^)Ŷ֗tZ1SOo\­.),u6LGYi$؋#<2} nTDwY Mt2!ƾy21&+U8r}}sTsQ׏55OJCxxi7gx.ȩ2-Ut Q\K%'<8|-";tv@|nؐOT#)3}m;`46tfӉV Jsx;P5lSH/U:.6d~݇!7|#ҝ"!*Ԋ.<8;Eݱ_O̩T/gEmN^ͯ@;!!<ǸtH9ݱ%4'G'+sb'wZ\]ztDMZkp`yFweWƇlT޽lEpk%a ^]f5y]5.o 3$30/aQkVG]ۏSPNURK4,^DS Fu2B kJ 6ኩ*nJEn95.}`{nxRchqSfk9LP˽F2 -5|;*c zkk]͑Հ1[G^ʇQ|sp!qPʔ=޽aE7w{jӼL~5oqC~Ƌ3]E[rF_;m}[deluhkm dk8ψ(鱃>׍ϐK\R\BSkk"R=n$ɤQzß5 ټ@!o'w m/O .BK; z' LY}p F^HZCtĴpOuمMӪ1ܰ|? cK4MB[ƓuCl;+>$sA0%f iִ'M4I2#&2mk 7#)V?xsx9ZRor.w- ad~ϱIB<3 O<#oy?A/qc%S]xk4g,Ut;6j, of\ [LM`Š`jDbgzk(4 }XG]A&PݬB JY}dӹM"8 Sp2,j < ƕ2 i>-)Ck]IrAvœ`,}nKC ]ofVSxzi9qpD{67J%Uwm=q#Y=5OA=:3D!Z\$ Vi7mnzܪ6 2J(lԩsW1;E%_ȕ3V&p.VS>`ut-M{} 4CV}L"ي%sP-)8G^{ ;h/ɽY02QuS]GVsh-N`1o3sB+[9'g/abttjhkq덦K~1€AF)k-^QǘkG` fdZq})ĶDbZ)g/nʪNY!|*u;Vp\$oJo"f $sё옧-QπG |JLG]I["&2-aX%51{aXl2ϳu0+ S.C`GfX h[cZ AT>)yVtd0wY`DPBݑUu )H'Jc6C[]S)P~͛Y1f ИbmmA/w>?>|] ;ZPƌz쌎(Tw 0I'JM)WM (4P "ϷRP#7W60UQeDXH<Uynn U{*Ņ`B52yĹGBŝY]ݲ~ӗI/j!$>@Ȼô9f\ï۳[fXav:. ߈hŒξB͔E+2-FaҠQk!RGL E@+Y;:˿@$G-.dacB怤8ه(3Od Hr4OAV:BJ֊0=NDڏa@Օ]6ۚ,f9I@:k]=X(yR#]lǠ"ΊIEݖE6^ >!~*qNj·dh"<#1f_;l.QVPop]e? < Ie(@Vll{ǡ#O#nN`Y#LEI7ens^~#7H]cc*1kR 5QXP׫\\9h\Qxb +ݩoV !|0顭$5K O:g?Lex~/ d$@v}|’axT>GuN+͐c?Ч*_l$NG1ߩorAbj=CyfusLާr /bԤ{#Lmt7ܢt'~[=a+Z+RV\f*7xi'Ye)EBOdƓvcTD^P&yZ-ë-"e"y,28X nxQQD8$ĂK '1B Xh|s'g$Ka݀Τ&4K|F4@NeBj!]>OY]voGaBĺ;ޗ* Qh$\ 5X,4"=N0Bhrvhzcay< TeQq;=h5%Ż?[?&v&Nr!v$fCbcp OhD b)mq*P)vZ۔{OqLifEԼuIOi>6ZFk l6Pm;$w73XUQ $@FEZmp7>6c5֓׬f ɵ|4Q'r^|nϫ: NI놾a00./usr/share/man/uk/man5/sssd-ad.5.gz}sT׹+N1DJZB=aɀma$UR]uߖ:tmfL2WQ@ێf峳j%#G३3Gđ#g8s?8/ę\"Mjh$V4SVZ7Dj8p>l:Rg*Qoy~CB+Y\εjգͤ\G0_GNgJ,#b$G UBKzi-QNժgpR%fјQFsgkJRO`T_%[5g+uԫ7F(?wAx ˓⽳g/jIy/SF15,:_Ij7/}"l=1^lI<g*͸( !0dΓ;}@k w% x!nI* )e_W`XδC+bme5Py!*u>C||kKg{oÆo MlDt Ƒ˕@(O߻Y%#w! ?]e k-Ө+0 2sSnajDo:xh|ٹL~Xt( =bR/NO*s- )2D~#[w ,KV7;Ԧ-QLH*<-,y'O;G+)?uH$8>1Sn]\LDgoI٘?/gR ؔ;Gݐ<6Z.v|W"G]M˥mv)y[bk<U(D֊W/>4Jp *@bۚ7 bM\(Fu1vJ nJ^z 5LEDLZTfSZC,P"!%яLf%㜜TryWF KL%{)&}p&`/Bx#O">P 0ڌW8e(HEPgZDCT)⮢†q4gN򸄔(+dPθ{t ?m'ƾkx͉i(!@jZD,i%Oy .N@Kl1t 5yʯ;X1F҆Tʢ.Ĥx]JK ӕt-j4`/Nwg`\q8K_*amGH6 aa՟V-h3$ȰI@1QX& q )9B\o/"-Bo:!L#2ǤHs/e<6͟ ,"x Ohbj2UUY##. ‚ ^j=,#(D"ye@y( E%>].d"2-쟩Rq iEH8p%ܴͮ I-7~ķYy q.UYLy%?jNO$QV$5˟($y$)ԣο?Hh%CVhbՇzamZTbghtbJ$WAć Cvkg+Jˈu\ڎ2kD yYcQă}58^7p{C&2y֦j/5>Y`Z$0=$ CM q#R XR7I()@PzmR#+u:%&i(heԋ wl[TQ \)\륨^r@ǰG;Wg' r>9:sR4, *U|VXB }:&N̹Ӱ -B˞vRu5 `#aFR̀[ިV,Kh.)eR#CuAuWp -'EƐ;K-EsE<)hӄmq6"AKOom̉IP%Դdqʕ~XI%[TnO?+D&OYCU*YSӥz:VZ "D|Uг8r%0I YT|J(` }Kk>tKrfQ`6?T鱎A5plAۻ' aR}' 8vF";M4c:rw7l joe8eaͽs4f&$l]/ (kgEEh@ܕ"uN,%O OɈs*86//9ªX~KmB?;# 0 ƓcxkMr $ːD$x>%OAQ-/9}AI0DjgtjX;n,  `Dni)y8iIZnMpbB}۲&0@4%Lo2OWZ04u($MBЛ̿AmQZS Y|A8']14~ hBj8d&(qG!2~t;'N^&$`@^AG>xZSp $Y/,5d SlZ KYcnZ+9g"Wwm3˂wOG58kCb`K̹Lr1Y ZvU02\sȴl{ъ1dБHp"I=-|=| l_y7S:^\.vv}tKw'>-6 9xfv/?+O\1iףZ?\U%qea XkT2y[:MQٲjgan!ƀܺ)ݖ |>#opֺXXSq, 9'Buȉ5ˤ&okzZMPeleXDIL?Ζu].XU厶% y|t*;r)܋,bY껗.qPYFm4zMMƼgX'O'~Meyֹ\+_zO6iS Fv@xiCtDxᫌ* [/Ch!ʽBAun 1Lqˢ3 -N\g ^436I'(h+YaK: "Wus+ݡ(1hg`Oxk]|1{/r_H{Lq[3/3SDG2;rs}jN_u>qVIxȑc1t]:E@xNPIoK In̘N"0gn9*s1}|.~iڼfN1堛g>[˗m[;GBh>QH.,%u}'sS~DCN,KwMs}DD&*2LUbFL|xO δ叿="'*+҆>60r9^TLLK@X |#6#3!}pw 7t̲(!RK/-yyE݇Ja=tږy8ߢkFC `lLO5!T'ZrǽJq>U-ibY,0i$kB" ފt8vg ._Ⱥ07G9 0+?:Xa;S>gq>Mٹ03qFC?lsJG_d&Ԏ3ю IQ,%Kd΍T-x\db|I1VoCtp_ 6z.ԚRg!g}m>jO4!=|NSy8JAůҧ=כZk׬1lfbY$SZ%RTgd8^Τ?nƴ|ql\U%m ‡9a)-զRğCR%! ֢fWJ P~]jFplƵʏ-@'dL@F+kbUXቌF!49"y㲲(H!vz2G.)?$AA䤌#qI{v+^i% 1I 2K=l?k}%%4+/ʷWŤxQiu%+?}eәc3xo}6} Z Cۯo11jAx15ڐF$Z /v*\] S{r`+6"@u6u3Q8on{R]W (4scX*wLuO-I"c4"£ Se~*\wY>cڛƶK>áAxhYb׻?GT"SQoCXBlq͂ślлð E2C=iAŨ߀Țd^v9m,iջp2aCΙْTN*X>)ZXҪNKO@veJH]x Cx6\9oVDHI7V+|3x%?6Dm3tıt/W [U M(((2#PI)Z [ T&1}Ϛ˔NDn'v Tt\-N8۵s(G>T,}"hY`7%CIVDW:T6tFM3tfyeN9pMQs-Xs0=U B<:_ [S[-MY8gcـ=?0ZADew8YdH.ZtRkŹJ=j5IޚVl,?fX{ԋD):pj8PVLS)vh5o@K3DָU14U_Tߌ"jIgH'Fqpw9{汦F+i nY`>#` 􅠠؊+3_o@GAJ!SŤ =_~18=(WiK}<W(&R*kK6m^\P\#UZrNƛ%?)g8f[o>::Q1x9Dc'k&WtUۍS^N/'VZJn5T+_ˎ0]n:4N~.0 A3Lieu[U{vrw''/O{W%㪬nMX U*[ \:pBQ[P9eLܧ+#\6sLX;IuM3Y=@߇J9"{Y"UUt M%[2֧sLw89h@<\Fb0gAE1ؔJYA?͙:W2vC٫x]@K|$ $;t,8CRJfJN*j"M]'GK66zsG-967U{fw ?,|mQs/y3D 㞥c)׎U#?je9ܴerՍWfHqȂS8^*_WlcDT걒(t=ȑł|-IѤ%AU4;WjLy+; q/Ԣ+b2~Lr͘NkJHLVL$T[D5%$9rVOsya= 4VS10pJNvnqKr:UR_yȥ͢a6s9N}^َ7q\OBm9C T@"{(Nn*oz0iߵz1.?r8 g729=/FèV>M=MZm5]3 cӲHADU7sT_^ǼC?T & `t F"lhx0Z2=4mbl"h !8X)[aUr~VPߓb⍷F߰TjW)7-}yR|-?.b-K% mM2tiEBz*gpo@ۢl϶t#jXy":C$rB2uYoi0KQ/2zfZKOvN}w 7ؚWqqLB'8%&~^;`DM]('<5~Shg0گгxjX@PiNYя0ϖ:n0O Ðn|-*F'/xp yRM0-'9k1i H3]װDQ6vÀYH&Hd&zصpʻ/&np[Lk:,9,w2` :̷k$!h !Zk E_`7WKsX8`AI)9vmpPʉcv!&)(>Ta%kUqШ3$֞κuֻAMIkZ P7| >x!8wݜFbR7.-_ABX Gڡov2Zt0F?dw8V38MM"/[(pё{F-Ζ^$EM_;?tfar46%$-:6.Hf\/iX\MKu3$v[,iWO2D8MQjjN[G#Z~VMdOhF U1hU>b0jL=\=&NB={:Yz\+ZYv_-EBUr =`"k1Stڼ:i|+T?dRS7IdWEԷ(`X\EXJ,i/1|R7Mj;qݏƉn7}xPGZnJy7?X8_1aø\'f'r~6Cqz ?P]ژ.zDzrbt+|c"XYP-ڎe nSwys)fI ֢T4MK?U<9d6č3<T+`?-9 Fͧ{{jW sV2O9l~ 6t⛽}=U}[ЫG;Y39ED\^:V>T=~ou&a#ȟT9rO1/w }cO/+ȗ ;h"^6O6D^x // *=J$Jr`_mRZM;GMwۈ:#ᔗ.NP *= Ƅ0p>Qw Yص+ LܤU_0Kkl&K>Hl{c6;{u!T[퐍CS{TNs6{TP*O(Y[3`5m[uEߔS a~kAC9O%sS^=f#K_EB5%s|ut0L 2pVfŬKòu|B=[§A ? gu8 iFO492;&c? <ݗcvU Yp.i9=)GQS5G)Vٹ$z>2u(J*wTgFRti{;3@O,|Re>*(֮lLajq8 Awa.G%A+k{ACyS jJUpa i\Z%alUyXjo>zQim3Q;Ⱦ61tt [`k'imUc~m5Ǖsq6:qP8FV֐M$ 3*2񨖡ʼٞ`ǁˠF{${6[/3iJYÉrdwsg2NAl`i+[c79Ֆ%=YSD_9$^*P1+c g,>c y41f1Y)p:g`è\g &kI2LApp֑PU-nI0ހ|pM:S[]&P.BN_ k z[J/C}Z_PrEt9Xjo.JNd,4NJ&wW$8>5GoʐqqdT`TX&rBM \h:d&/;,T: JBR>PmP,F<*nn 2*몶 r=惯@Xun 킍²'j]*qN6D٫=ۖ*>Avٜ5a0Є#p,~rTQK.01O1I(>Uu )5E2!F60sб XP{sm!!h0q2Ȑ&^z>c ޶'fp"}BY@(sU~]LJeeP̒>_mŬvM1`ߐuM]} =1?* sϭt*6zb8"(*pUluӁvıQ!Ecjk&"M<>ʒ/cE?PyX1AxQ7itf"bnNV~&Td{ JKQ}Ռo&\OFThVSgqtE?i4Rc`BL_1yJZaqyB!`V}eJ;j`&@8d (' :L ކؽ2k|].oޔT To7 n`'&V%6 GX+W'(8$ NMf;PKq^ݤ"nr_qU15n[FMb.JR:595|ljc'!oq'|kj룯8F,)\i$\L,?/2=W6$OV?\I*`5(0 dž㝂ބbYf-m #m]2pIHfTx^NWx\Zd7ay勢7M t'9cL{V o{Oa>/jg|: .q,3@l*K 8j2%R<#:۩d E)އ1r+o;b;927#kN6}kfJz_fRǜsNi&WsKҐJiY19.9^ JXi7rŒ&v%xyse%\!ksu@fC4"VT꺨eC K됳goהg~Ti, i`aN˿m[qHY?˃,\)g§9TS={fuSM[3I$*ElY;K2U5ӇAc t.|p{']*}q/~'BR ]0AAT;_`-rv*;ʿq-­@y9acKdE#洴Cg=¶&T4)D&$|7p8Ue+Yuci{k]݅*1DAPTJӍfrc1*T L=,AWW!41DxL.ǁ6|>:48%J\o^b)tP 8ZqB_uxsS ;5*w> ~{/uժ\vBVL֋HA»!h n_dqf?gI>7*Xt#J!x!߲kPਪC"U j4$iQ_93qB Hͩu:>ҿNJq,xq d$ιV hX~;T ݫ;+:9n vr*4VVKFh,>~bMaQլ̴[r +Q ]+F!ղ fbԦNSil!SWO/l̺i #%_t,s$$v~NKp"p2~6 5޽gi)҈GQ)v)g4e\gڳj\>m&FT*osɵZ4;4<͎̔i8`T+wQmV9€zt%ln+ 'M%F_o3)7 QM~Ta"Z7HΛ8?9tV}ɦ\;zfDgҜ=(9Kñ0707010t?1"NHZ=A1H'P%97zaն YZ