sssd-krb5-common-1.13.4-4.fc22$>(N-*PbǞa%><˨?˘d ! \ ! 0Dbhp    q x((849 (:< GHIXY\4]H^džbdȼefltuvwʸxy-˔Csssd-krb5-common1.13.44.fc22SSSD helpers needed for Kerberos and GSSAPI authenticationProvides helper processes that the LDAP and Kerberos back ends can use for Kerberos user or host authentication.Wzbuildhw-07.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectApplications/System큤AWRWRWwW\IW;60f9435999cc4a6c42ead78d508d13d40a38fe581af473062a85aa6a178ef86148329045b83085e5658eeeeaf2d139925099f43cb4bff34cb20f6503a2ab1a1a8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootsssd-1.13.4-4.fc22.src.rpmsssd-krb5-commonsssd-krb5-common(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@    @cyrus-sasl-gssapi(x86-64) @V$@V @V @UpUUU4@Ub@UzUzUzUL@UL@U.RU@T@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.13.3-4Lukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3.1Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2Lukas Slebodnik - 1.13.0-1Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Lukas Slebodnik - 1.12.4-4Lukas Slebodnik - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - Gallagher - Gallagher - Hrozek - Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - Hrozek - Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Additional upstream fixes- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - New upstream release 1.13.2 - python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Additional fix for relax libldb Requires- Also relax libldb Requires - Remove --enable-ldb-version-check- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 -{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - Do not crash on resolving a group SID in IPA server mode- Rebuilt for Fix release version for upgrades- New upstream release 1.12.0 - Rebuilt for New upstream release 1.12 beta2 - Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release - Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - New upstream release 1.11.2 - Remove upstreamed patches - Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - New upstream release 1.10.1 - sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for New upstream release 1.7.0 - - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.13.4-4.fc221.13.4-4.fc22krb5_childldap_childsssd-krb5-commonCOPYINGkrb5.include.d/usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-krb5-common//var/lib/sss/pubconf/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/, for GNU/Linux 2.6.32, BuildID[sha1]=775b9e0b20fda1ca20b1994aeaffea302d53e274, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/, for GNU/Linux 2.6.32, BuildID[sha1]=85fddd8d8049423b8c479b4e849500274c4e692b, strippeddirectoryASCII textRRR RRRRRRRRR RRRRR R RRRRR RRRR RRRRRRR RRRRRR R RR RR?@7zXZ !#,+]"k%}}`ʛ`c䆨r.{xXNxl]zaX+A`{ͨ@<L7OqּZI7){NGYoحH 9Y^e7chv{:e t SQ_ /iB\35E8(7- 3P(Jr>mTs?kԠI,b% RLfCA*[˷X`OP*%8T]T`lHr#p{nǮ l)N!}/2ō 0S~4\1 `пMXfI'/zx(vʚ~ ?nI _Ƕ_Cj5$81 h :O0tTߵN ۔>GvP&-B#/-{.fA O*E3&`|=II8}$W62ׅ|g=dJ"~K,0Ii|+9PGTÖTr~ĀG=▤S^X'3)޻GA{wOu&)k+XtCVF⹲(s!'&"QFW⃳b-hW3NhqLHV"_浇*?~7>B #dNg@jwHqԈTy_iX/1$1"R'D@WP B1S|aj,w4[_|M @.H'^8r_ŭ();ZNp^a"9WuN/-̳/ɻaiA2;hvJ24QJ^6H?VM͔!.y׎ -CP{MAS Wo-UQ+RO趄h.8}DfJ'(JO*ss7=;#5x&ZM@0= ' - ni p[Ja4lZOȈ5Z觬>*?I<l{q]BL 0{ZӽMԌ/n]=G\Rυ(5*vV(׍̺`('SOQYKL'!&?k6PC_IiTWza>f}֘ruRڦst-n!ꯒj%b8n>utL0 aanƺ'YY C\ؗ vÍ ŨY54M`)).}(6]:޷xVi+IK R&L m7$`Um̐,W(V${ D0jg+lЊ,+ f RfݮD#j$yOi>iX el kex384Qy糭+0gm|i\vE/2i`筣{ޞ1<ګ%SZGt@ܤbP8U }nh6zF1{Gc߀^|oDeDnܤ⎱ ġ?pb||!n% <ƪkJxܔbR _p,v8b7T͇׮(hkF`%N,^t Z 26;?-?W&,K|RVC[Lch?wm1#D#4TǾG g6MlaX|*dw-cV-!!Ĺ1P'!83J"/fZ|nˎ3r_8i=~ $bUMp#+YfJe`zljj`-'-@+{/h8pAOhvՄպXHΠSq̣ 3J3e֣D=/{J0Mj- Ad15ȲI5- V4!:[ppFj(?vYt#FGڧk 夭px4 P# .} #Q.5N<4>P p\p:ܔFGK iY @r΅@ 7Ci]U߬\zvok `K+HN[n(=F\UaA/*v/4ʁuR̈́ev`) d_YGx"KЋDI׶zk_za0DPIWq0SV[@sMPأA*NjB&et\Fa@HkwX9M.=P#`k~+hBN@x̶y:PW0!U[q%َ%N|Q!f7md|p&F_/01u$r*DҾ/=@h v qX=>]FH n2k _{آ; 옰 (sK^4BǮ4=%̕ Ē"ZV6Ӯ9qEzo;Di=()~fguf*9|{>^zU ˑ"S0D!;7Ӻ,z緭m f' 2dgP^\u_bkȍu鴰8Gu9< [OɰG.NkHk"h-\2FSΧW?7H ȢiPfbזYu `r[g~苪[3R UhTv~svFV&VE|?"~F^6,*LBC J~$choz a0!gf)ڏ6H$: f2e6i 0üB?{G]tz#U!N'>.+ SY(qG$%>_tPm)]۰z^ ي,m[J`_f*l JBWpqꍵ~jH/%KHZWL X7uFӝ: vëW\Dd?TB ő;M'O=]u1Z@pei*lf!6f.i o´r-CSRx>4Ofٚ~3ch ҹw6h;)wM";R((~ 1;)&ɄrZl" o|o:g  3c$D^s\5` `؇ЛΟ:&Gc% gHoM'/_e\O Įx #/Xe˘9toJKGy VDp11u޶g H(I*~`xS22Pw~r!?]'(9gSF"_KzFyaPizom}I$_XwCd,u.b&,Z\:aU,'&+ Z5 -36{^sJ9ú l-{0qzqֺO1tcrNJUr=8=J%1(ۀ0Z:pL1V3+U9jBfJBv^NyỸ_^N^WQ!dU;=Y괸ʮC:qsJww(Q$T3L>"h@8$' Ow fćS.ezH(tC^tɥp\pg7+B' 9mAje_sVPI8/enEi-CoBH祃<@c_@Q"ex  (!@jA@R9Wx`w K}A}P(y m/BZЅhEhmi#wyäB~402R)[eғݪ-p"o3,yG%)7:LT?W*NY3QJ9pRH(E._ݏE&'r@ ˰OUs_[Ҕ V|}E3D:s):h2`>>=q cCu[I!e fDLhOY_c v~7]t`%y+2|j|LSdWt/+cJ.:na= u[d4G\y.o\kP^/\]~jpiHۻoB]WKnJ.ʍ9S Цe&;'<WU_&zh8(M#-\& Rcu5"Aǃ1;KIBprw")VHoaD{CuN.sVQPYJxI9 U+%9\U%`IbmN@BZK_qlD5HBӈ VƪGB }*VӲ3zٻ|ؗEBB ֊oԄW7;R[>|_Dz+. %BFnʌZ`_EDPj,24PO|m+V|οC%܊MQ\4BNptZ %LH 938} ~MV+UeXQf̀'a3tBl_]"b a^©f7N@+gH(giPƄ! CV0!otTS0:>MeIIFfjDN,w${\V,<>\֙x:bKIhS[ [T-2q<6,P*-pRbç΋̰!a ak l` hRWغ]\F9FX_]馭.V ZȂEyKӈm9l-<#k}}jftО U46Gd"ٷBI/q"r8xQa/ߕo=ɒi~0Cި'Num.DId}Ŕʏ$6!! 8Pcnz@u u Ulc#z+: An=-p|}! w @b0$-(w2~?Ӏu7/;9a&|0 %ޣC}yNZrlHugGRD&Nl8$6<uRHTR~b§7}Q*A~oY ,&i=~ry$-Go03V/Yp0Oxs6 bVw~a`bu,[&f1TS]w%ݯcUiuar#RobmcWB As S;0+':I xĨSwz,y~wQ:G+عJ3+IAVk]JLT'_ ƝJîDLרR8/}04Օ^B;==՚1S%c{@jӎg.wF'AQ"}=Tu5'b&2I P =7-NaQq)۷"i+%TK5џ ׶_}l*b> 8;U63ͩ:Mbp04ɦIS;M ^z_1 _]· *CLFqFGI 0Ecp-#>&awr5k5`ݧ³%/C-롥 _9^ߙS)Э-5FvM Hv*x٠He)*l,Sɵu*UItWD\. Ud`PP~ص琕:2_p;EJk=PQJ{#9M)rY͸i|wFXhzR"A[|6I =N%%|xAw䍷|`WI͊y'P̾b7UVjZ*%шqMƒl5W<օ`I5‹dE#}Lo"w#?s'[ @+yӻx8cBj-Nѹ.<&̻Oɪ@i¤8j)ld$`Gư{dh7ZN :i[Œ[op:@ybR-8CHYA$6gMg>Z*+cELiI*|;{F @rn X33C:^-]vR"er*O5ŜjB4 C^y~tĽ"b۰BMf,^X[OTѭޭb]8Ah~ZyyznoQ]oE:rW:[ḯ<X0ﺔFb&JyvQ,5 oh<-P|ݬpK&yCPxO^Mu ,/I.Z1ndHg Kz\0IJO|eòl@x"rR={1nJ3pq{؟=bK'G}w!w5pVI>?~Phk o8,5&]z&`4N_&wkh2bxT$Fؿ6cSPzu +3IOc7AW43I9T| Cr=ǭwĻr.M''bx,VbK(LJp=ҽ{Q$ ! 0#/B\%䝐@wA ܟ12Og;[K6X&''r\/[TIaTR"'Xӽםb4jwdHҌ0`vttQ`0GQ_R}{OXx0cF^%UJ+BaI\Lo푃QxsQID6L5ԐޒV\,11]`:E&Z77RֈdMOgNVoZaSk*Y٠@@T[^nj#.|WN`EEGCU)ZhGx(Z8ȝT*Ʊ"dI`k1~xwCm51e70;)@x^nё8n`*ZwJ?*K )x-bN0h9~1}2LYu~l6]hh"Gz+23ɔ,|Wdd?$=*,kBu ly+w")p!Ow'<%%&#QKr0yQdw}vAGs>G=Djw\z0sa`Fr [Qh%dv_soOpgݹ CB*z)8UԈ)j/-"# Qt$TȰV$ZoK b%ҹu+hMD<9 [s9UsX؅\3`d ZU;B=&Т b @aqusEg&z5խXQgNSŁLq4W3m`Zk.MgL#8|»Gw1o4Lq12 E?F=d= q.?``%]U ?@=FӖ9J}eVΗ֜lg=4X[0YBv?Y.f, a?[߯bzUOɘq1>U/=fiy2M9 YOTvF3_Zղgߎc&yQcs nB`ĎyR{T}Dtpsk>zwkse8m!1nk.B.#ppJo/_nI ^ACbL_"Id疷Bi oa/l#Q"-@(r4l'RXE:~vcBŠ(F:fLJX8\? t~{',>s0ľ+tiZņs$BԸ1 b"))oLOzM2)clLMko]Fn{Z>F)RO ZMG1?C@}yS#Ÿc1Sh$U)EgWV[2[njz{ڈ:wקS19Xa8 Sgf@Xw\qmAL r0DXrZ2kA!i_II#ۅ+ ; V sڲn4Sed$^"8_@k/1^]k?S3f9)tΉ/>,C/h~vE)zV"LFz6z_$- qz3~%xn4sc|DǽI>O٩x{aI}+V/Yavb^Mla&񂅙e/AI$ "b }8+P- E`M:HRfݘ#E#)f h߱Wq^*z2iB+B*Ǖ@ FzXoo9*X"TL 0 ed^~Ē)&k%8d/#r\Ѿ /`w+#b<^rOmASူUJzϗ%JU¸IhBi3*{P-'x+z9:R \;QNY1 ٻx,UdH|՞][;ty3pTX\ml 2% AұO51/L\7(x fD7-Y%g] Ɯ[Zi y3q!ߊj" Mަ,0׻:UxUFUȃL"GlJ~d1*/7#7ﵷ ꬁ;v/xTP% >t#Ƃ~l7^#\g4Pp##Sʿ0Q岫:~/ :bϗy”,II 3 XqZL^N_ E2٣МIz[*45v\.!폷o^x? (xtN_D#9Mm=9΋^!^˫@D ]-:(Yr> AzMGxŊᒋKJӜ +MH2SDž9;$ vҊC0鲤ػ\(1%;K1=;xeE`R%E֯)9;RN ;5n/nRo$Ms7> п ;M(d QK`uL]) #: 4vl4%!NDru V& a~D{_'mKU9V.}z+M'~%"(pYE# /3dbΨI08U*̆]0pGzsd:s3Ǖ]pˡ>#B ҝc'xhAeVU1]$:٥7oVƘߘRtIujWzDKewqdSģ|4@?DIUB[xwlDtg} KǞs? iNݡʠa]}i 0zot-4P_D .mٽy2:]F 4ÐCE8O0&y xAuHb̗9q+Idk'"$YwҬxxg: 7Ҥ@;m$_ xݮP?> Al\ݮOkҡs3;`MA,ΫhHi{ψ$[Z2QlJ͍k4L(2I84cܙ/_Ս`Qw.~PyD9mbބ|Evײta7]>3j|c+B툢䲇"P]jwKdaL(gБHkծ&5Z">}~6N_O.Iӈ?bѵXHy3qjMxZM W븛&z,uϵJ9.k>ɧkq5_ѐt ջ?S}~yxF3*+y{Z*BTsK%LioNjrSg('0^^^9w0R#IԁjN_qo 5(6]Z34XdnDr3 !FGC@S)W͡dj胶`~Nl:* ll[Ž I5[Vu7q;qѩ¶. EޱˊUwa-N0z jw>\ux8BR#4R"9(KoKG2&&i520Ak,[2j%<):v5i/m>(y8 uJ^JSϗ[4odnU 4D&;U|3>J+GPnUVMJwVkTv.e 5FmI7MyT+#h#@laِ$&#\:?ZP/# |ҟD#}J^[X.E>8Vr~ZgC[eS[fThl˵tMM'Q '䄛[p޹Cc`hz wQ\ANcbuQH99&FIϒf$r!i=s7ts߿`ښC[ɤkj 6>8QBc|M8 )=5b%tƯ2Besd)Rj~^% "r12nd5a4c0x?wȌ,CrAwYo=GCvJ_ZUmO7cx\J><޷VS9.+5 F | kyɨ#=kqaPO Dj~QY%SK*RO> } hMNYOoY ڨfSc-ԦF*uі&݌(-5V>~hgC >%B[bЏMJȺ얽 "dL%6݌(?OG\ rW $bXa/Aج8zZGD4Qנ띗oU{w+pgMLJonq{Ӗf1(m~ Ex3|ޣlMҏTeuFg J7ҹ ~h>[u Ձ5fI'Tt_5KGM}kLw*XͫKaL)ea ~~>,|#3( յplF 6?t702ac>Pzg58=zfȤs_0/'`) Ͳ+Qf\|S?DN ڮ(AG$F -k6|=dkdy(̻H/ EtKٖʬI[~"F^+cRWJGOg獛^_%˂()x]gwv9/s(q;Dzٝʇ(i{(x RqPҭ]]Bw~C$L 5tGĶ ł`cljtK˖*4i!JMi3)5TeU_ $9Ȑ}I\a5E^6B;Yp/=r:YFlrmfYQvrIiw`*K^2jl%U9E6duEPYlꏈ@P*:cQ"1|XpU]vr)ndAs ;-ux/cG|]M_%Na 9H  )N|ܙt0 N M/"(S^ܱ:)4A{Y3#iXy-m}}U3&ac #h>` 9ٸ 踡y7,Mr ]-x3XkKL^ $M(ZWH=_X%qE3Lg׏+kf7?5IOU$W[%GPހ)*< ?pE!ScNU |pПTvL&{\ˉb#CG3Kc:fZ@x0*IVѻw~F]oRD{Yv=HeK.r0fHq[JBD%CSB3{YRfNa7nNkö62ep2cr72ܦۻ=N+. δRJ'{ |OӐ%,ԑ$bXWE3)i%" Z\UpCEpRl))dj z"tJP o<[CRjm r;~V}|sf+3vD7\uxUm;Իw(Бk=YCe:0)'1άwqDL0P=do㩕TraW&dp@ 俹=y&Z-F:v?ֽ[f{VjaT3hQ&EG1 4H -jKX@MI;Ԫ+99ڴ+3% Ziobj&h/`[,q_S#J)y8¸@KmEitZ@ ̾s]kX~oqHqx ~ P̡9aB=l ]س'`v^٧`SlʿB=U[YY@S\;~jklKtII1;ZE:*3PJ88˴` 0^5Ȟ:@6wY7?Zjp48o:rQy4ZTU]^{g.qUY)BsƔ '*W1v[?0gJ*b&_/n>K0Bԣ!~qG~SGg@#&_ Vbjs#6+#MeBd<c[-cÖdLU&Ȗ $GN殃 h$\ʹc22ޝ\D:|sןlجeY'_q.PNڇ{f/ >f-e^ S2Q/Bqw: I:,3(pMuéF% pʾj5"s i;)xظD^ 9% >یMC g) w##󑃎YL %[X/9H(^ Զ͔L/n#yR<;pEjBLU,_sT(V9 ")WG}s9T=vceA YMkLL qYq/M1~*H%(mo-gKnLN:TG?m%SЮB K|e E/?3=WoG2]to&_`~nlWI4tMOī1( 7+nj=D9bV\A)zg{Ν'KiYxF謕Vg_w2!#g52(R'qQ@‹llw'n5a u\LvfѰ1aS/[؆*D/ee:P?>tˀgVޢ╹9 L/kiv ^]VIxaz &GBy̖J2r.8 P,jg?sb'j"tOj/g"hkRm&p>и^z)sIطL.~wn1Lo~dXKbTAn3پQB HfCa*7cw̰b*inh_4&N9Wt*XAXb5G܇*fB?T'BG~v+%gUY?&4?` 飭/Lb`>`e m/ǏXU1q6$ >DBv.NAǟ1h~5&<iꏉQƳq-0^5A ZI껪߫.EpIUKBX#%UUs@_Q+ilbftӴ? F `vi܂J/L HM7k#4:ټN/6M,q9ln$jvGA!d9"ǔI􇱱Gm[&bPu*Xx8t4vAUSӣtr1wU6۰?j V:k& -cMVv7+e5saQhȾXmG]F47( n#؁|@8 'jx0*fdɇJ տmt!4ѯuNMmX34%LP t8.1Lݻ` G9&hAmQKR1Xlc;B<+܀`pͨE?GV.w9i=A^UcY}Z`-8AC^L]`qŎ'&8=ĥXoK\޴ fM !ԆX2Ou4y2j0-B!VIB'̈́[@ȉT5>fPg 2^fH+TE Bdth MsbeuOVW?jeP2:kg-d,!]cՑUa{U|.tL"/^YŰOR'A ӧ%GFs ,5Z5 ]5%UC f_߬+ _a\Zzpsv*h]Z*ٯ9KE BS2 gv ]gW]PKrpDh؏#ȼJ7}&U7{+SL^x3$ԳJ1OyY.C{Evs{ڭXaҀ>+-=o?{XǜI Q:⯨S$7T"0}LO^FVBֺvNguЫ01PhD 4 ZdvT\W>hф?璢6Ep-}p w86BZ~]LO/]rՏ C ˉEڡɭhD%e .%/]Zdv QF]/hJeE?/l}u㢕I` 2/lԋy FH[n]m% vFB|F~Smw!B¦?q2oXsԺ.Jk6?zv!yG' ȏΠB{/_ޡp]m J*a1W5a+Y@ 5w"LPjE"fkK.@ $^ $|&>/¡!WgbdBq6eR!j"L7=ngB@90x;a14ήmln<Z]*b\E2%|j0EK"B4GX!1yk|AGmX fB={ ӱYxbcV@5֬?߇?- .)Γ٠fER@toc$%ق݌b4}n5K׿PЫ$/7*UDs!ttJM,y2@t!0(L#+~r;,$w1񔛫}1†`"@0:CHxZ_F"eXvS(DL8,x03o*\uI<-UAj}Hdh{k\k WNӬ(`c' mf^Mxͦ 0d'yߙ*2%mFN*@!?YwÀREzp! p7ZXEz~)P7.CJuYtK'O#WttC|,ASdĦ0zzkD ̚Ϩ=F}[^6MipC;V[`ͫ>!5-iE$ Cp{AꀋHFkׂ1|Nh8bHֆ-q5'Q $;2ܬ Y?uvzmuK`6D׈ CK6# #Xaq|e_R%4V3|ې+/CD>LXN "{q3feiA&ar49j;6msnɪ4JTz!־v,WL2dݼ` mJh]A䦈CڅTº 269S H˭w>#ֽI`R{N-pzm㔰L|N'5L|b:a/upBNݠ-MC@`ʬƟ'\c'bzxQ2N]*M}~e c̺jגؽt66&ہ'h>_c|>[.Ȭ`=+Ϯg* ;5<'c\ة]:VNj,?~oxx?1w&0'`f`p hp;C´Hr̲˻,ui^[PM>lOv ~+gMh#^|/DP皶02o` Jt԰o"nC*m >m!1ql2 !)\Xwf➤B84ؑ6cu\rPdAFerCWZsn5OqH p@h Y? r \IDC^Hzs qȖu!EOjA~`pp .-.ڼGtCs{<`ETv@z0(8=2Rf-]>ҙt瞐k+#? :#bM[^y[ix:LpqjmM'^_-+=F.4nG^7\ qƩW4k-y⸶$2?\Qx-#JxM {`ԍ: !Ό5A\cJ(J|.\s"Z'~v,"Usy:Yo"WhkӎUyn] !hz5XMWȢ7KE췴Ej" h&x ?  z2#(Ĥ'^+  +)YZv =?N-8GF#-ITmv'>DuJP.%s&t{s&v4+ %j:qC]"}5[, ."Ov8r,*M=SlSI#v>1;6 Y7ܫ:`^8IHխ3a3u4O [k>Z? V1]n p;O!b#J%>/WuMxyk0([^^J^X#QqܸG$#nډs#R 6 13_p'Lg Pl~}6~~ajrv|BD_B#>خ;l#{̯PkS-ocd 7F̲ ϼp.`*?RtJ3S eMK<qzG fMXPh xi"dh_}0j 6Vj#YO~CwDžȸ"#n E8#Psd ү~t+c‘Nj^sFÞ$Vo`e_yd TL0_\ ;4l( ~8;j-ܐ\[Y3A'#-UYc52hCBn "V_b/ XՔӏڦ˙)|"oItXm~w26z7FnwsoW} 4wMZgݼjm ht'Z+An38}; i8OKz47Z x=E-P). (ͮZӰka Q\WD"Q # ' d40 c2m9w,R `W[Pwկld5[H% n;1Pds1Y$l] fmr,o&/s^ztKn[C5[*ځt$Y%`k .˙ p 1 ?n7ʶ|ͻyz' FPIz4H6/f\NE0}w \H|nH@65 TUxՅЋ币'z!tpK}S#i!7L{By^N ך&I  c[$K>KfF(BQu(,sD3u>cr (#]Nbإ8O"E+l.\G,}1:Tթױ/pxx[ H0ٗdlL5_+8Ss;jݵTLsU*wC-ޣBP_=({-& MGli3(pk~I$ u_-]9d/r q@pCh VA@Յ50ck4x0*AϘZ,"SOXCQVCy PβD7OZ7$=:aS5֢вA.M+m =yrns[V ֥xOaFΙ]8x.9*vRDhK%]Z}>gRHy£!Zl wrQllE1qy b0_ xM#<^Aϵ w8yKsRtEh%<< tw"W 3 8:_P\OHb=!jS,>+meT-q"// 3t"%LU$dXN.!Ֆ:Ϸ8z7;:8=793S- MedL5'54eNK"@J8҃}/Z"M_ h 82C1M ' И 2dtA+zcʑ`m`Ye9ѴQَp룊 R},s;d6Hn\:n$kd]2?fҰM-#SHBNxRV QbfFFdOj~ X&؂"-}q]4m30"?Y^PAv].n1]T1oz2ӭ-[_E+(Oc3-zc@-k80]{$RPPtbڗt]d?~sdwTj44g $BuO}eZ렏k ˜8VeP+v gqE"ҵse3ɯoW&@fLɫ̤> V1W+!0U_#x8,L7ϼ[E1v|@~s\ 2!=p@RI8EB1u'^c=+V2F/=&!-NҐ w ׁe lV?KVT ǃGaў>eVUFV 5|ǥl65I'(f:S9  _ 8a }x\|aqz&) Pj+i* Lϔ޿J1S] xtDz7Z8Voj x\V+̜Li!X W ] hI+(gWI `A)KRl.r4^%AAHT8<|heC {8UI {v1t:RJ&O^"٬,2> 쁸;N)Cжw m9 ڲo@DZ<MWcw vҎ>oFM[WB)E6_/`M}alxAr RS w zC֯]W{Ut~n8|@^0i(#t' YqM}!Cb d<1ܩW^#^4yep(vO)Ḫ klW CHgl.@3"+<(U@RYUwq $yOnYN}B h<@|+H|ZMoT|NP|泃=F"MV)! H dqݎU~ܤJ^KiJI,'mYjzr',0Qvne5,H;t{(_NsŔA-tx7\$ۅQq2DxTOr˓TV+{"PI O>W hqD x\Xq?9$ml gbǶB]+qzP/?&6K],N1fE҃ec>fǬw.1b'0,ZB,O1W1KF`CMhɎ;c%cjf:Sn08)fL8bxeV&b8?ja0p|&U-A+XpH4ٍo!?VKZvN=TyxY`Z O 8a.><+6j_э LLzǼo179U_z7)>IǶ"fy"}DZ%7HRJ#fa/kO#&~:]_C-+.&orY5~O_Q}ј|5@:rMuxL)2BA?m㯨YF3MpQ&Cyנ{_°fZbΠTZ\:).SeANˋKF(|Kc f -2]dC(Zs#a+YJ !PhT|Q>/{ҳ9gnZX֚V1fUl)3obX#[|%p'iC&omA\p~$ :ӈ$3:^|n9+D~3@\F;2B3N(/s`U Z0xfVы[j_t%97Ⲽ8!4he)v35kw~YcCŬGgt4rWmP߂Ji#T-~RI{@xMC8ڞUvEFN j`=[I4ױ tD͚Dk?Vv/ő9H(3u6`w8bCKm9 Yx~-a.-^6Yj/;@k'_cm(gL*/.@bu#Qi.0ݿc_*' CS +$zMȮ.k{%';,pouY~uZfm4V*V>e|9nmo_Ҁ+H_ "7ӶUPmbo;~ tI ٣GJXAc6o)8+e҃Pe@6H@Ɂj3I-w9cGqqGzOχ%KXb F6Qnxx!STry1ȓV&=Bg _֐w*4@I;mNԬ$UO`^ B=vUH_ zw2y~m]yDDx׬ 81h*uܶ,7]RofSEnd=DNp1gD>Jj~37ȭ3hB7&sÐj#B=i&Ӑ~ 4-9s3wPTx& !ΙԂ\ޮWӹ]gѱخ:ıP'(TU=хhvV,3\>q[+!k`oZN Z2LyB$EpдB9>;(}:p$t\8|_ T~a:} |)@3m1KOpY+^4(QL@Mdѯpzg}e2~kL55#E?o1fH93zJ0"(wjEAn7`J LGOں'&U0*T,sTZW>. gLS8Чg(-FCHWBJ;!`Lv؆o|rOݧ8 ?d*F|-d1U1AJމ wX}8 s>F@%Vwtg7.pҡ7J(0*^FO#:/*c.@Zl^RW/ |b`-r8HK?`U` 9)(|ؕE>|Je "*%zk[@zʘad*U2F 2P\tGEY7Bk۠̃Pp1^Of'dۑ\x}X4 !-ؗ#;cb#eygL+>IaNE`yO ՒOd;iPAXݘJZ[cF̃!Âxã~GY6IϦi4sʺ8ʫxv=HPlAd.j*h@yWl|B!hб_s+ѸTΙxc=5os"!dW~^4NKT}EY0vnm'36%LU[$նROxL--Р޹ Y vٓgIUOa=gj 5F-pTũO<Ο=i)u{%l=HHpOKҤk *`A9Z0w[/$DrJR9U_ڙJImΉa[Tņ^.TSd`<ƀt /4U^râb%Lz/0CH"OQ1!G. F]N׌pd]f'F 2~2Dd79@ \KՁZcxdO:Vj(zaL JF3 ɜ gmY6/ěe&lP Ư]m<"49^Rf+:V >qDq笌-n`HXG3o3Do}0 48"E[vTi5CR5(ik8X-,YAcX8`&T1x,V̦o 2SZ=JHHkK=jtFLNʵܤ 7øSrsˈjr #gR lv籉-#jLb K]MO?X…ΑIL LR+øL]4ؼB@ֺZ#YKjVO-3v`֐(Vcc #+H!n.xǛo . ës'bE$kKaRy“o l-\y'gZ,t(5XPG# !hpuCE&uxMrQ30~ !B9bZeR 7.1uS?RL Ӎ?B.Ugih> .wbakDc ganڃ-"F7Q׋5KD̸;Fg;Ļ,#ҴDD\Lsr~£;xϷ&@ǩ*ZDV [}%PI{*iNFM2=lG\4M!tE04|f?dl߈c>"!p :u+`U7QqSkN<̩!&%]cF %XX 0+l(r!'J}u o˯2cѢxw0ncxo+i_wݩ+%HyDV} )MaF/Pf,*O_>9 ilUEq{{`MC3/R{jBLI|dvTi6$T1 4g/z!8Q}\mM VwS""t1D{_yF=_M8ZjC<6{]ۛ 7[[!!VF,:Іt,ܚo<َrx9VFg( @tl~ڧ >vcLFm4I,fFr^E?ҋQ(@R*3TV$񗕧0hEH+q6hV<^ Md`f$ۥyM>@i:_4=MIhWHj\%zgvL`lPA' $!>IK(*(تKpH;Nُ\߭LL/l#XSN cߟ[?jiR'9OY}4 bh΀~`Ksid}Vv4e̿GonPNW|W n0raݬ鏲Ur0Y%"pOz;o8 6Pus@mt=LԏUG~-qCf9 #HM_?k)_4R+gرjiw~B jf, ]=[eXB! ].ɷ~1:B]f^"kjb om|f+ɑ5i]}6$P ;*pyUjy#N߁Mʊ-deo!s7)tpf/Ku<_(܁E?^DaW-W_3~>v gt:R8$DS~m*aѢ _?DŽ"Y*ScL9.,0Bߔlϩ2Ce6ku-A,a85^z Mt*p'qUGBx,Ǵ[P= ?OGG$T9t.<):rE?m8fSTP0#G >6) arPh閭Vo2_-WcL8fFVw:Z=/ȃƴ1H*'j {6'~k,O7S^:PfJK d[%V%&&A1AڜoD\B В0D&4 Cځ`|=d8w>9ÄF6=oᜋ=V*Iqo%~O`;RSeTNUkm}UiQ.\ -!|\]ɗLGGF]=< e|-Z|II<w(1!3MpewqkLb]f0jydv/QT@ n?'w[jz XJ z .yjPtkQiI$$lZc/E4wO]KcJ&S8Yظ[܃Er<ê>rl `5_4e;εoZ.}N}LNJ?ZT$uvj:f_]"0_!HACkM }j(ȽnMnEȬ⸷ z:vH4EO-zy@ d:x&#펕]LG H&ta6~,JQ@ƻ1 = .zr{nX *3 Zp1Tmw_OE9oNu"GnTk.4>a& NnK={pf VjlH5N oVsZ24lѕvq!Gݗ,!BNxH˲=UOgus32 j:=XL/#7OimC\\6wsJ|,wqp'wG8B|1 #Le4_ o\+P_Sz,[vR:Tɉ-缀Q9򌯴`T%l$Ŗ ^cW r[;ȓ܁lO~9n*<:Y.5[GuPp-騵c@X|/t$FfTxw~b% OUA懢] W5 'CFI 2i1qU:C8UG EIi[Kc"1C2!V'8@ue B6_dHq $"ؓl_?JU'g[9awi?lFofrE"fCLټۦtaAhr_9FzinF6\OƠV  #Ū$7 zb.=p-YS?YqԻy0lwEu˸ҲhG=,%(HxC7Gz4X̧b҂^v>*!yQ 4,:oHCc8`1x=<`1xi̢jgxiʍ+! F\FX:ONI/ LI_oTl9t#ii> 22Y .? TۗaLdIr^B vf!qq -Th1@"$ bX|dFz)? F!, ^Xt^@ŋ04!Q8&brh^}a?V8G61NRgmd F+qCKdHNzȏRJ}qA ,n cǕ˳Xڑkm+LnGz  V1eN%@J|+}&zR,~6" i uwfWH/jh/Ar9juc4lhJeH٤^ݶ85^3 TvWv)uC?P @sP]mVa&NX-2Bِ]Ÿ-wt8?7Ul FV<"hWΟ>x:G.C? KO" 'd1jM~@UɨQ'+[+n0,WP̪ z*%\#F̹Ϡ]7R>A\4`6 O"z0E׶-/5y e;F @ ?VBB*:D\(sj"mz3@EtK{{~:>~1eCpXqBTP|) A^O8p,@p(n;B>8[(4YO4=ph ams#YgI#+ᎄ1$5SM/)' HXX;j4K'⾈}M0Խkʝi0{tRڭTKxvz膧/Ej1t,sn!RBP{g-cra4bXNx`&h$-J= dpYc4E"Jf_+p1UȲ[YRND[u?CApoD3a@Z P5Y = 9A(gHbT*_3rhp溤؆g~L>Ҝ?__-yڬ64MBC}+w4xTwrf\ "FbRRTiMI.kt::E֏w쎕&V/KT~seVҪb |YL- 'M.'RoYJjwO !J& N|VH_$B^ڿRD޲Sd3\h"n2!D]-Xzq<f5O4S :sh\a8DޓԏKMQNkzDbPs OH+qVYь;LJ-T"MT=ӱ LA0%r7@ U||ΥM5]"&ߙK `cItDW ",Pnra\–"`eKLȗ)=mc/Ǵ>E?>m9l?7 +s`<04+C[7v"a|,V";5Gl|-³h!녎n UqC3ğ7rg4:o72'di:xwbV}_eu*ԺmO5b~? wxDb=,#eP\61!t4ڴFvEn<3Qob' G(,7%,|YƬ&&8"w,[@xҕeP5eZCR| K GJFFB4{*>!6ABӶԉb<`15#eo|E&5&~yk^;Erk4֬?49?I}Dɤl:Aֆ g[Groҿ)\Suode32 (H ;>0xDc#X\w-YOcJyķ[qGbwl|Y4NahJ.ZM%# |IJp'm;++[r?Lx2/Y,fSgU<(l( &Jޘ1#c}=ՠÎ& #ڠ$)ݪUu&ba fbmcU=qu`PIǔTNWR0D۰gaXA+U_`iD/jӃjKu 8B.<:gWSeb l ^57yq5 0CпK %_o( g !|NEF'+LKLpt7~眓CA^,Q8sG(?z- x4*M2awQFNH8WNe4Ʒ xt/T'6ا!'O*Vm2xA6͌ E hhheڥnL">Ҭ8s?k:T^I\w&V RŰ#jCacMSS[w*n)z#f'I*Juݞ$v;9fd oKѹQMMR㸶 M“}[š-:E;O\:}-)NnK7!2'NQf6 4c7238QVsSޝ: <Oڄ7oؖ16s} \B6 4(e\$wg#vɀGĉ駘]C@6O|Z1+1nWDs\v ZFMg. X2t % ];ʉrM*A) * _z,PstKOf9_b-Kmz:*t_ܼFtnB3:ˣ!X|3v&ojqasض_U1~l Fmlӯf}YRˢu{EFA_A3>z;> ֞fBDz131VG6\|8c,AwwI1Z/t-8vg@kն'dT s^ ]G\ʷ;B'zRk MzR;{rL Ǹqa?fqeS 2Ɔ#A T;<8lwS[#0%)dQqP9etқoԣjC#agx[*prj YmqYΕ.COH55@V܁ygpIH+y ehYjs$*iE|'@;=v|9z30^Sj %y?֝*2P"٪1^Ua׉.ްg7leB@?ʟd:eUWd0D$8"5.G0@f;u,8d]7Zt)A|ǻQQ&eNK]MBB_S!Cb;NU{zST8]q^.c޽hWOBS誺դa5%} &,χHE+9h# S߮ұ̜Yg_3d]]? ?|m,2Sb8ٝ(&mVbZB*K1m)vWam:0סh% i=bnN^IF&p)HRrХwd=bU `_efX C]x]2_g mpA=? 틴̾qg&rߝdю!EPVrT@!IyJ.[+:WeV_Vdz.l=?G>A}6)Vtz9$_^1p-qi3TąQ_ R|t"&:oBhț/>Iӯ]5:{M>Rjxvw|Dq+'6k~ZjF8n_A&@w߂EyyzקFN!F0כ@w}X4Tym_Wm?nw>Vb $ Mt/oza(C[, Қ2$Vȍ"5OS"bu;6+;ԉٽ?7c芚Ippr2eE\ 3hl `zHF{g%'4PnO.*jQ=` Y{Mfq|e ?\:ph7ba,<5`6.:bl9lJ~1܃iդ)њ@ՙi*c`1tLL^B<- :svm#Gd>g^b©qql(&q/jw>j cH0/ͧ>6e(<}؝=5C,Zxuԕ"ZbD|u-c!]lאivĶEe6>F<7OLjYOe*u@G-/_U [Wo*}[X8̥H6pږdzoa'¯#EhKJTtnBRJ/΋;wBo8 "R$#`jG2[>NbG Bɻ|lQFjpa,J 3*%c dG]؍ 9oCk~"3 %bMںj9>o\ 8oUNU9޽9@i f. S+K"P[(D^ ! pj!|HYp"}EiiB6 0 PU4lǘ}(@vgR: k¯GmXUk_Row0 b䟏ZB{b&ɳ>zwKCn cW@qU!=kTc>\CeN7`SItO֦I`?4Eq~-b%!~/ /8` iI==ԭNtgy|Km36B=wڍ(mb#\9;=PlU PSל47Q&ùƧ̸JF+;ibQh!.=`S5IW].H\UمQS89df)1`[ЍB|Yno.j1O&/ ,a%^`Na )-z-S7zI#Z,TS W(SC dMTI"@ZB)E腢%/Nq:L jedž@4:$.FG&Ț].ăsPy^\Y4NC󫾁s]aE5O]w\Kh+sO=@)W҄DRa)G=^3.̪ V>k1HHP M@z8tA.3"#60&bBO~Ij-(l&Ai2+1<>iG7L+rMa-YbFXރbj_G ^mLlY'\`XX~cd=Sk1)P"^eunyVR:c0'uc3r;Dl"?g{/T7%ŜD+2mL#*Lݬ:rF5 3Hpu2ZCai_{`ś{g Cr>nNLh7.OB짶t# RPߐ!v #1dKnG] c׻lV3W} o\>IGi2#g;a-[mR3f|UC\4N5c NhfYUF[6xJ ഹbaCn&ju^h1N>qmWMQQ ?&G7\K @qP~zk@jڊFey֫IsX߽N[tҫz4 ú2c4r4ez7sȭڅ#Qk(U*7k'(qFWe.zZ_X2EX>B@PNtgHYtE2TN4dܥe3SWbz ` Q1UzkCj$y,%x2)dǏB!ʿIZ QX5&e0 E j5RJuJR90=:$jqI~.(`[~۳@by Ab(?R6s ˾'rN_4q_{H sk7[ʈ7`MJ Sp,C6 Mbg DS58`)xVrke&qsMЌ '*3z|Yڈq3kmV0Ntİɰ[%[뎴Iڀ0jTFs=M 7oB CN-=e#S"_gU-T5j.Û:6eEM@#6'$|(-,p0,bevRnH\r?+<,RIaP:4Z/O94}ud(a/|J_Y!w*}Y '-]Grg2Jpmm[cs^|_DiަW2spHfh5) 1->my %OXKKA?@,_d0ɡ4~@I$9c?mH6 uX$˄|+9tFhQ;0ڔ-5$^N~m58ǐ$"]Syxn"MimGٺ|:gSKBW&_pC%iL0E%c9nAT(>$M6½A%L)77?{l7h_djU' ?P0$˽{2IynpЯW8x5܄l@âtt+쌜z5|;p|XٓV2w֖4tҮBDUԐ3'[(fbEִ 4wI`u_ [8UteU!W:lrDSY 3aQMH JUN/ =#牪ySyaJ^FW>v d_l D\NL,/+#u o8V㏧b;gJ+n@ 5lʹ߿LjKn% 3Û{/fv퐟8h'Z4]iV ;<~&B&$=*ғCFh$tR U5̄٠QWG MʰNi.ZSnQ^e: >3Dנh8Q˄"rNG\,7YUז+?WR 0!OQc)Gg? 2\eǩ[w;yIQ%S.u^QU9EyʿBc,%7MƪqO2w1&j)6o:X~M؍9odVǭ޼j9VmkZ\c:~vt)e^Rd[]r"NsaFm a|YCǂ:sW0.t26zO98JSUw!d9bp񔁯RFm EMC]M^yI8?Y.g*VX[ƿW׀Ez>E4j#Y`|@]~WuϊOx*qW73Ae|׋=pymKKF'@캈_ԬRt*FjbWGƸUYE>G 䗓bVZճ>9s@˳ՈCcw[7Ջ8 ;hG̓®CQIKd2=:pn׳#Q\Y5\v>$_q4 j##zH+Gl9=n a"8z314jdlxl>|@ETpY %=[1.`fC>.g' ߾%PVjvyrcRt 7-,{\m.iLo%Uxp ,5Z|{ GD?,iP,E}2RǺ"!96' 8~jDrЉc jA@6XXX|N?}Gr%+ނ3VpOL4;f{MM;Wx_$_]<~HAy`l%LƓNA1(iZnDaNyd;|ÝWX1m*'Vɣ?{ %w=]tM2|n볨Q]lh!)U}bVTvT67@l[_!{E\hQbzB`ҵuNo4diiSMNغ.~XU]J@Y85 {+ znXX6@0Mjmx_#E;WGs {-eh$+}m7LGZZeD=W}s\jbbq7RCC^IzƏĭ|>~[KuS7>t'FPscUneI> 6'Y9Fd&_ͩ5f!45sڷ:oSp=:t&A]pv ruV$rxLEAjU5 5ZzzV e]&*f`Bݩa =c.͠Dc4с&)yeLqoţ$Wzojo!r.a9Tu6UѠ>1m.vXY ޜ;ftO>Jc:Js,MAXH׮6!I;d<[aZ{$qGLbֶHWVF̉OyBl,1/6E@Lxǭɝ,6w,Dإ$1N7|%bZ=E&l|. l֒o`Sx٪=EĎLҪZ)]zs}kkݘT+ApV%vi1a~mTa~} @BZ(\|t}b(pіVJ,|25PkLA M%&\>C,|qdd4@hOGcO۶(ƨE?%1M &!&}Z$a ab4LkFD9zh|@RdbZ$G8^8_ PKZ.wڣ%DS.F'p|@jf,;`b7rڼ St[ZL__VX~3L@ݙJj 'BM#qIRH""Ur72? #4ivy;:6m'QUөt}֌vZ7@= (6:)Ҭe*8p٧C-+_c$(kڮ/Bx90:~bSo1w 2j`tzY\@:|1dqq#B=2}r ̱09axu2FO*W7\X\1@?XAc~MƦ|}ۢC?Afqh B G&81nz&&%zΏtB.EϷ|'y"7-Fn@jH7(=t}r*M3,S^(Lsv=gQJȝWX)ۯ }"a} !Lh:_pij PD=0ń|YvE6\RpNRn #JV0a2FITې1YZBY*_\zaIA_;ԨIMUA\肔R¸Zp(5L>(!HI#u}`$Z贄 a mg{ \F]3N-EޡA+X@Z5GVgn=^aRW3m.N =4k1z޾2tQ4@]Pd1";Sy~\Ŕ=;}E{5:9am=%LsJUVw:م)v(U0M)l8}CDSyP /`LR5#7$=i`7 Z RU|2TzU22Tu.^؊etI/rGʨ}fOCYs3 B$!@[|=3} * c,sle[~zx];1jU:P"~27*R` lģ4=o `w"\vX :$r?׻&$H:f('|^қ+ê%` a\le!:ض4W(_hTZR>s:oE^.2Zz,s4\u知HL];o]g u\VaoK xώǐH'ڧ9XCeD.{NY 7H@hI95dyz0p}Mn-(# /D™/{-uBg3k=p#Gѹ'l`)b4[b7J/Hfh(!r'N$?f &N%OVcS <$T|"c~2lUA!D7OvdLKպCTXNn<=!d2[B +0TT#\lS/~o0 "OȁF(jƽOH9ɞd/r M_FP)mTͫrxӍAJC(d38p$ F[_駻m`BUܻ#5cYYֆ&/$Na,q(SgdEd[ jrVwG̓3rGv{?_8Ǣ4'"6kE BWTi.(qXemNVJSl77~-gdf%9DK)X02&??(bdB2E`w|i.uDɶ*#v$Qmm#>SޤaCZ`VХe{cY@ 43z nBɋ-U5w:oJmRl~xqtCA;jJtt#eua jVؿ}3T Dqa0/|:;[ڭzCvte3a#0$:Z}ß1EÎuDA=--C3 $qJd(/M3SE֊:e^F Qzx>S׫-Ol~4`5 $Z2?GSChwE52N鷂+A߳W ı 6Ih?TXIH/YS﫩S,`άW~ҕDHp;${~X(&Mzug5_Ww>2 v?ڢ{5rșLuM~ZFjUKXe FB8Y49EB赩FY"g gdzsʄhkm$ d+& aY+#BQ||g흍dzGԬP zzsCu\Y{NtzYY݌cvBWjL#D{c2ٛckZ_?[uacJ|-qJ3hOKAL u~SVϠFO/̶ރq/ZdQ^SirQ2!cJ^hxHuryMJM] ] g`>B28CIئ^Gq솯6Qv*4KB*V[p[~!Ȃ4cw;8T`ۅt%0 7+oE0MNRR/Ez ޏBޚLJXP]d$jm+XᚄˢiINfxpjjb(˻hvUDa6C"QD6. * Up̆<%"5 A~t()cBs'[C^yx l se҈>viS }JqhL2,vf 8yqG^mjJ|%'I3ŝΈMtR"C;2⸬U wϟF%MxM@8eՂuJ i7meo;`$̯^De[7(GΑy`XTcwE 4P\36⚞q~֡:*["RIN8Jn1Ut02U`3Prc#a/0] xxf6@a⾬^i$#CUd"F I8ɽ>3rnU?ՁT,捿a <,*UN*\t ؈t]R3LL,%GTǘf:(ȔbL Y'f֭>h!pb" {>T| s vaTJETtQE}.OKÄ[!ԊB2\ v^ج6ipL;P=u=|-I_h.oLb͠=zPjyVuz{0BA@зD&$:VKWo-" B]>o3LA(qo=QL*H@2R)ܞ )w bْc3@i[͠L ӄ53Erxu5t}86a-N23^km(}[W|L»4OjYOޢdP~䌚<9]KV F>O HckY,uCaek=gW8x1;0.1U*NDsLå:LT>:*1^i><0vq;QGST]XHz:L9}4OEW`Ϡݵgmn$fEhxlؤ-`i1z5&Jhc5\nrPm3H;G!S}dx^ p %SJRi0^ID薜ݖ^;fҤ#,eDi?%qN,*_yIAXGD!,m4iٽ%$C<ʬ)pod05Q"Vp[ć  Վ9M^z-+}V.W`^2}D(y4OBvi;o:g6Lmjtv'K9kZ?I?&[p,Elp!@>-~>s zPY@Vڊ͌N0<ެݯw×.;[=Q/3}ptlj6x pKk8z$!sw1{r\chҶh奆fB\pBx:ńcwl78sa<\C@Hu| S_ێ#\h tt2Lؑdi Ty7+ξ*e$K>p+@d+ ½VI\Ur''r?vVE]6~6P0ρ犒簄Ml%QtD +:v뺝OdZC"c92mW,q C eR?D.TcW9ZDa lZE_Q.ߓ ZW)%׃.8lNd&&d9O-Iq$ t:J tO! K^.^d-#n#ڛNM'SO2ɏ'D,_$}2OvFv}r|ahUcx@C;!\ ' Un ؔ{2=|p } {dwϤ9, R*yA cVƷhNg3~=OwVeM1 ?!E\?q^5>|=vE2S(h.tIqE64m%fV^S%(xZ8+UkmmNV+/qZ||8N'^ZB569eX8T/0L//8bP'*_\0B͗!,Lsz^+#\!ڜIےDؑ>jAUan$Srn4H=P5b:^/" `z>\0# ,C4= - 0M}<0?4^hDc2Ghd4 qy;)gy (J;wNaB;-RMzLCNڔK3 l@ ҃߅9"Ѹ:|DnU֜u,CN^tvThXДCи~M & 3̺n6+WDE1>&b FɽÂWO3-'x ;@sV^їFC;e{ۃ+rd*+ܻ-&81'&\":sjSM=G붑DW o|oO|] }ڣHZH,)[N;%[uabߋ 1]>? P[N0NW@J1A3Y؈ #+B6@ao^HUO9tDMv5GH_-+N3H%bynW WHwUj[(E%<l|b}Gsw3x`'=Ȳf>8tLpdZ~*g1#^6Ť㼙&BvfM 3f9Po}M=їҸw+`AVPr,h;~+_؃T1.j *iET k5DQN)d f $45CW`GD+6`YF?'_"ԡ: yTlIXynCA_m֕ph] &E1A o['WZ ʬ#|땥V9=@EVkսem*q(=<؈)'MTwn$'wfr~9ZTt ӹ֮L:߄4^2hnuxMߡ:]I v +gfef2-S"^>?ZTan~tx=BZ>p/+֒ږJɎ#RLNPuhǸ`(}n噭f {aD9nrν9ܩ4cq+z'hl& />uqʣC|ԧ)EqLvAmqii7a#܎y$+䑐E\-NC8R.Efji|f)b\MTkw2wZ>f"Mrhd]جSOe &K%35=6+ҍٵ]hwBhc>Qh>XrZGL S?,\q.x-\|P.++5$Ԡ{kStoA-^o{ʭج I6s̠v<;LXi6 ս/MGKTƧSz6:"!BZx) F2_fH?8 rش=hyo;Z.T%~H`^v+/PSU{C8]5 ~?h|$Q?,gUL}ĝʓBJypm-rU>"Ya`TB!43[g]#S7EpwLr,ev?/NRω>v&ASku/?orbAM֦lAʼ#,y戳ŶiR{P=:%2HMɒ ֙b`K8xp}O:Ԕ8Yq1(o'BJթ^-^Qeo2蚺OE0nW ^?F'*Q]8_n$a^G}]6f 'ɔU &7Jq_~/1KOCR6eCX.Z^_)LO  {sm uU#hKvXuȪ6~@!/rG&hw4>w*+^Իԩ|*F:?lo"{!*Лd<2L_tlvX^I%]I~3`w2v>A!S-M˷[E]c9Pl$ ^d73Zr~sagA7+Y*ݛ^XO}!K:zcD\dhiܢ$ǣ|Sf3TPhJ.a))Ѵ~}I VN`[~ʥR,-`\;\iθ\ud^.-Y{?< \׎Dpml` NWoO~82VϰUszw-?l_ (KQ7ĶZJVW@8Xi\G#bm [T0,:ٞGƊr3hF(n5=ne7mMrެeҶh>>vBBK8 ,c&[4rB V וpĤSV #d\*Iz1iIZL  1@*n^Ԓ|9~J(7಺^50-O!.c]Inkܝl~7E`c!ÈId012 աWX>:L `܄a-`M?p,w7wGtNtG8I9΀Y9:xQm`Ί0w \xC{뇺<;WilJfqٷ${C;CPH%E.:8"YОȆ J+R$T~r ҥ<ީPjb1/C ֟9_3胦gUt+[ҹ*֠a-@p6bd9e&' YR& I }Fe3m;_gfUw7]SF{gDͤT^ٟv3iEXվ#pMk,ҷ2J6ĨD?ok%LKY[wuFw&dJy)&PA 񜈂Z_;x-`+!$ȝ? P^e<+Tĥ~lV."蝬C"%" a4dLRS@ʍ5Z|*z]q1M(bdI[;|C/;S!j N^?&]-np=uqH2ӭFb*F 1#*tEE=M|-+r`p{7nnb6le}'V?!KdS>y!wR.s32j2W`cօYZ,Z-ռeC[RV=Ž53%4JzZIv3?nUL`O9S[/G=%Kpv%'4/[ M qJlQ碑/0BSWo06Q޼Q?΍#g;~\ i)u32_X)n(G!GtY<1@m31x-X`XQSQd n.\_y7 <̄$ۥA\进>&J `=(;bZ8'#23{"K{Aǹjޡ};=b븎d R@uW!|:I%/gAJ'fR*ȗsgB팒sz*n1B{r%msE W! 0BHW-)nqeBu)5QX\T:S:a l6w3KN,t 95߮ ]qH 66.Zד #`tu BK#ĄS:? ^FDgW`MkA>j܆B_"d@xR ړ( Vb gyn G#BNKn,H|W]!&(48*D,Bi5Hfpy>z*Az110ϰ_MJ};-,ldۻل΀J8v!4џjW3oJK\6=_l Gg BqHyQJV_zطU}ac h]+h kL9?GGc(i$#8.lJdCa8Ey\`kk1,l^2)Ov%3Ƣ6_}BBvyt5;f1r4Ō[&zG st^!6_ʥyƎ)}Ĭ:m]Q5ox7Bƻ9hK0B h>+)xڊҨ#< hko;LFag o_'ÒOcCPjt3B>B"*)zR0*!$ <4nn&$oyZ_>o vP@@l1yV|s:\LnDY2{!!N?C[}oeY؜'Ill3?z'5g! @wʜqO=TwMK@u7&jY" Hm41*g)p 'ʌFِŏRAs:m@W#J H$d<&&Nt{(}Z%Q 628.ʿclvzI^arԦq=)yuCU\"h4uU@F vUygA?,(8Lh`Pzd-KEHv˗ O8~z{JNAжn򖷡_1]T 'sY (8ݼU;WW0;xwyj۬ 3/N @ȘŐ2~Zh!a.} lrʥhn ^!9/dN~2Ǝ`%9Ԣ/[3-EtALe0|oY(ͭh5Hz(LrLFHΩo,=?O.^@azXRaigm(? h3zI/(h.(v r"c5ЩCVWv΁uޭ$WX.sUq`Of[RƘ4* ˢN$( eLWMOðbpuy{0+N\}Ol5xRv{D¹ *wղ:;cwO9Ymf s)Kj nK#~wDhxi5[ Hk3VrwtӼA/1q<20 pL񫞱$ʴя32ag7 wyDVFppώ> W),`)q*`niʈ#UU3A) s>\F4Xh=rE2:aIwCfQ_fEaf.Q`^*h}U:d^܋Y&;oИTB3.#5!:E"̆na&]ȎܔZ)ҐB5\Uȍ?QXZq~31+,{,Tjɍ;$)to2jCuj"GѵF%Nf X҆H$f;WѦT2YkG G(b&VnBS-yG)LefٌLYXmh*^- ew} T9@qhLl8 OXga >މj5P*TRJ~r37u4exHa6Nf1s>uԾU-ܱh+w't%N1DjK6fM[8_:b-é\X=Rfj23uh7draJHWA>Zc.v NɨYCMJwhvddtWX>>\P7\&s{汕ݎ R@[S6#q "o_?!6:.Q|3D2~zѶ c#&=ܸJW qr| eNLu[kg/? @UP.#CHc֋ī y6ڦRX9ĉ>Go2 k,уABs[@k-d H%Vh5a(._djWgW޴rON-zi³ӮD;OGn7 S\;*7{! \/xPR,'D>LLbyj ~^kYn[5( S{9Ytv,uQϟxƋ3bl<#f wxjG o,(ahjAVi%, /£®.wgK`&2OAj1Nk'h4;B‹ q/쀠3_z@/֔N&Kv T!$J^$.q<)Ց hf Wz$O2^M=kzY@3&/+6V_IG .^a%Ht hH$]Ȝ#3Rf꺍q+8 ;xq87F #ͩtgq64A)&9CFQ [ "\AΕpDY=^+Cb|;~ZaKl^{&*dBU4sJn&~?0_ 1)Ɖxf_x-TPn_M]WZ7|Ub_;OLiRd.J)nzG"ua .7,Kȑٓ?6 NPTpry{$g42|!+$!@r an4Hil1bL9ѭ'zp3Ë]?"ߛ)VT:xI`/%yX5[ ڙLZ[ %*Ջ~7)۩-/}f\BC )cHIa"P/wC34DA^o8[Zjifxt Je.m :]A̘jU Ա?MD=nG-ضQ cE/٤ *Vڝ.=~wR繎?N9  S;MĦ} cLP0J7xxѬn)f-#Wl }