sssd-client-2.5.2-2.el8_5.3 >  A aQU]U&5asV˙خ~Qxlc:1Le,w*#LYWnYDm`k$Կ[-beD |]L |6́6Q6#@b*೉Ruk,&=+{%!A+i2'D5 =3wUuU`TdڛgrkZ+6`24AA8n[Cɵ ~Re@DmxQblwTGBGCur x>gJֻ쇿~-^24-$-!d38593h ˸BVhU=[,ݱ1 UU[<j#k0XM<~#IAH _/O6&:鉈i&W>75eaLAnQb. &{q`b:<mehTȭ|PzXĬv_1I_!zQ_XMSRڜu 3Iui4188611c1a60b7b719afe68b362ca198e0ca00b75056a3cc0fdc122dd96a4567efaa83aefe806a1a55cd3d5b85cf6e467552e93c/@aQU]+&4F[dՆw<{|sitoN^1R-0meKUjߪa%QF˛wWiS`+b:-O :wJ?hOPg񾮢$|.^Fx8X![ye r6Qr:;<Ě^d|\rbEbpAh?Xd  D %+04'' ' l' ' '  <' ' ' ^ |'  d)){)(89\:g>m?n@nGn 'Hn'IoX'XoYo\o']p\'^s)budvevfvlvtv'uwX'vw w}l'x~'y~Y TCsssd-client2.5.22.el8_5.3SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.a6$x86-01.mbox.centos.orgCentOSCentOSLGPLv3+CentOS Buildsys Applications/System /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib/cifs-utils/ 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib/cifs-utils/ fiD'>+#<0,_=X|oPK =  1 AAAAAAAAAAAAA큤a5a6a6a6a6a6a6a6a6a6a6a6a6a6a6a6a6a5a5a5a5a5a5a5a5a5a5a6``a5a5a5a5a5a5a5a5a555384fbe6b709992ceb978e283cb45b1bf48fe07a205de95d6c6a48531abb4eda9c249fdfc4d8b45baca272b631201193fc39dbe78186a2566d813023d01d440cb4d8a5a93c1ba138b7e9deac2a01f864170f3e1fd156d48ac777ade6e4826c9bfc3e01bd0c6227771b92169b3d52e2c1758d6cf6beeed8c1342372ade3a09a58b46d9866147db9bd03634cd9bcb0543be02413b7932486a09cea166b7e6e82c026a3a02a5c581f023c6fe63b64e79ca81702f9f0b3b901b1f45220c2d050d9badda293b8277357a18d228c4a26c95291637a6d1438702a05228cabf01628d3d8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc5844e51ada045c01974b337bb4789ce0b8de0847bc0e93d1fc32fca132dfc730bffcde46dc5dcd66f71f572e7a9f95d0c5997ea376fb01188d6232530b9f82305c384530be2d123c35b7cdda6dee04c2afb55d99a87082383ec2b31f0fee3403637b626cbf7138943ee3896dd329ef2395ab412ef3151c9b66d7f7cdc4d4c8772515bf6f4633b02199bd51cf252a37d4309ea5aa5e97ac9d8d2e9ace4377c2983e571abe199ab37bf40cb69dc6f97f0b8cbc4376557f38006f5271f93c0e00e0a026703129a0f3ffe74442fa231654b99a2961b8d5b00b20d0265d490350bb68c696a3459e907f2b4badc6762fe4084fcf269115ce3d1e44d12a1f7acf517719eafd5479bc37ac3210fafbb051cdfaaa9caa5d050186458564ac396afbb02039bc../../../../usr/lib/krb5/plugins/libkrb5/ @@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2.3Alexey Tikhonov - 2.5.2-2.2Alexey Tikhonov - 2.5.2-2.1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - Gallagher - Gallagher - Hrozek - Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - Hrozek - Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2028828 - pam responder does not call initgroups to refresh the user entry [rhel-8.5.0.z]- Resolves: rhbz#2018440 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) [rhel-8.5.0.z] - Resolves: rhbz#2016923 - autofs lookups for unknown mounts are delayed for 50s [rhel-8.5.0.z] - Resolves: rhbz#2021499 - Make backtrace less "chatty" (avoid duplicate backtraces) [rhel-8.5.0.z] - Resolves: rhbz#2013379 - Lookup with fully-qualified name does not work with 'cache_first = True' [rhel-8.5.0.z]- Resolves: rhbz#2014460 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing [rhel-8.5.0.z]- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server '': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with Rebuilt for Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for New upstream release 1.15.3 - Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - New upstream release 1.15.1 - Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for New upstream release 1.15.0 - Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - Add workaround patch for RHBZ #1366403- New upstream release 1.14.0 - New upstream release 1.14 beta - New upstream release 1.14 alpha - Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - New upstream release 1.13.2 - Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - Rebuilt for Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 -{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - Do not crash on resolving a group SID in IPA server mode- Rebuilt for Fix release version for upgrades- New upstream release 1.12.0 - Rebuilt for New upstream release 1.12 beta2 - Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release - Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - New upstream release 1.11.2 - Remove upstreamed patches - Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - New upstream release 1.10.1 - sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for New upstream release 1.7.0 - - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%&'essvsvukukuk2.5.2-2.el8_5.32.5.2-2.el8_5.3 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnu directorycannot open `/builddir/build/BUILDROOT/sssd-2.5.2-2.el8_5.3.i386/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=de4e7e58c588defec684daf0e7b8da64ef68d1f9, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=cb717d7e1cd0088a3dd46adf7f72c0b71125fd50, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=2e0f22dcb1a87af1916c6833492abd30daeed788, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ae972b3cf2e9ceaff0d0af9babb875cc46ab2d49, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=506a3f03798f39fe8b694ff8e87f2148e4775123, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=ad622c2902b1e84e21ea4066be03ba5dcda33aae, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=7aa355c30c39e11d985c4ff8ba437ceb758ed6d2, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) !.=J  RRR RRR#R"RR!RRR'RR RR R RRRRRRR'R RR RR RRRR'PPR R RR R RRRRRR'RRRR R RR R RR RRRRR'RRRR RR R RRRRRR'RR R RR R RRRRRRRRR'utf-85dd36d7c1b54ef77604c6fe3cb52727d698ecfc12e7a8c9f80c46c8c9005986a?7zXZ !#,] b2u jӫ`(y-7Z/G\V?X4c +#Y e"BsOŔt ?xf!,[6˞J#ٱjUq55tUCAG]'-XLTX'6 {^QcpaHM3*`L* 29*_I,_AÑ{sMBqcqTI)L.oƈ"v}@Pl-.g5F(8ioihtS,Mhؿ3FҲKX+O V&f(ۮ C!2T줣\uΏ]`YQDnuX66VݻHFIC ƙ]sUF.^ĄDH JQw ]Y8x)9T3dckg t ]qXp5fB mSK(2?u1xM506P8D+ Q~(T{X>(R`xqu`;nzxe4 I~0owH&Qp-y>r\X4-|aȐ#E&0h/^U𮨟`(% U;ƦE듬WHc=Zgm -hfhUQ%W*MT{҇_׹gnOAVlq24&' ls_!$a$w#lT;Mz\WTPdVdyM9(j&YӞ2suI&MD>Mz8P]@y6oa0keJd~N{yt"w*| W/47YpՁww,{Qu\?}ClRp^Q5p0љ[et4ocskc()}]ZUpsP,;[WJb:tE[|nҴtެ*!/]A?쫷ۋOo`UmKr!W*Zƌ5w?m$\8qs%B!4%:n=p q!)b LrO.EHxlEh&r4MȮ.z yDa)F3̙8xfܠbla@;L1T"1Kj (@6جeJxGzzWw~yCh[< gKz[8TíR8fU2+ f^zzuķ*g"**X g8]n$+vqJ\ cO{£Oʧwۡ5O79#Lru~4_s& O=Ig\Q 1^cn6u/~ 0S,3]kE,SeJIA_֤*.N6S &{)ܜ\\ܔBǷny(oVU7Dӹ[Oeeқo6 j<4zGU& L"K7@;/hEe1SJs#TxM9.Cjjga]Vc~=@|L} b8-LloCojIH݄@=;sq^d乻r .:Cd^ : R>J'㝰Vqz4@gY6ͫKpW(|Ϡ=K6KվRdANR )rY Y t8bih}֬#piOTD;oP ޷' a,VwUA/nMw0W-BPǑ<1i/ ɸמNSLŠW076!2nNDͯA~yqQ1!H~fǢ,1j.s[ybmI ^W=tJEŝ? &\Xзaا;Xwz5I}\Ϙ?⅜l"[t]>+W1~ RivCy.AƸ]V-KEヸxS-g9ʝvoCqp0sYxim&,FO:\o?eh,-69~@)SS =ii>g7p|U9v 6knK+;sI(5YwE1Z֢a0( !voHȀq_] u? =`lI&Z;V 4i]8h*,K41Aߋm؈{&EW q{ղM"~R| 5Ve?n/e=X= Zg)*KLz/8 rpҼKuEu0I{aޭVDq GrsF& a︂v̾^ʩ$)`eطnNPXWւ ?Ia~cAUg,rwtUKZF}H9>^t5:+MoDku2 g{o bpCunA?j/M|^LTM SGA@m2uk?6g=/US'ЍC0xORA YfbBR>'?T|i3^>dܛj4-@6fhDL= SZ{}MhC",AQd;*Lr #6bφFy5#22'Oϗ|O0n̵fZ3nd7 *~A[[ٴ0?

5f%.t*if^gP:H CA?-}Od&Գ)όcߴY={UN8^\z"e) qN&) FGlƬ}+#qY %-G#"9\߯hOSo}\ _0jƎ\g1hҼJv6b(hkK!=Z V;:9% 2nz6ׅ_ A.4;{ujmpגdGwv+ >FLq0}F "WW,ԮgH aBF,H2ܗ=8!`RZ% ^6~Wo0T+vos0L M`UX1rjCͼ˖k{;tB{fNza[lnC-  +.OGM&44I 9jLXlia2K*JҤځD_]`m`9>tSИyG|+(u2J쒞_"-;"ciP #n hXz]:7KrHu'HXoUAS~!jhjE$?UK‰$SNg3FmyEpS"M[0nr/l;7:4z/O`nMEx X7C[\bqcu |~Jt:<ŔK*%''@ * H?B^>c!i=e:ϑ| J Λ0s }},b9!|6oܩO%4 ˛Zf*qMު:~<-/6d#ɺnwAq|!N}P'ZVIocF=ƎӇV=Bb$@s]l "ﭲmn`T?54"z[#Uer/Tg[[0Jc4G_u1JJ- y*$*kP l@~/JSqF96( WVk6|0nRY F".Pb v2U<\chMyرB<twSizf U(e v^fgܲ_5PֆQ-T oey{roM'#"s1UQ%Ihy"*zC=~n}za"\ɣ5nDpl-hoɶal5~eo2WX̵| SzA7Io+,`2Ȩ[XBgs(V{HPl'.\콧ڗX6괥u0:Xv+E;'+W g|62-ybA?;H1^в c5^yz'ahp3&p^AcP2R^F4; \MJTM`ojp^b A|cc=>5> ?Վk3zVbNRNg@/7JPW2$tʑ8@ʦL;gXYYt=X,H&fknhE>bl>23?OadɼT!IN wʑ\`\P$U`+(g?e}$OG.BT{kkIA;+vܑ2P)d"DVo$ڨ$ad#daYڌI"V6oc:oL^3f >\s2G0Fm #q@GD_`ٓjWS:[wjڵ7(}Cn+M99|]#RvQPzj%MƎD -s-.20d \}~>(Y`:=(*c.aT`J#t-:p_F'7V ,;m"uAh 7UJ{13+Z!ȫeڦk<i˽vAV䠲ܞr<b$aż6ᢷ,?~:wq"T􀄖m4UygT^]`3< 7N^8O`iC;D=L\'wM-ks%[+1 z.K~z`vf=J b4pkFų' $7qbo5߲WGY”b/y~wUY42N{IG.^|L&ڵbTa47WC4W ku_r[BE\Ԭa\\ĊMa{6Ooe ʳ~t)`w*j䑵l#>)0'sMt$:-ˁ*7ff9/:')MI#Sj1.s˅o,0aSǀIjh45SBGM0U3*)&IV`Uouk  Ȕ`>\ȯ5+Jڣ UpmUUiw o[ ;bF_gw"K NbʦF?@b;=)J阱/B!k ߧ/~zQ|@ l_$ڏkWktLFV7'+X ʻ+/&:x[g@mQ87N'o%dI洱m @,C[v[!&S4z5l HێB6r|Uh|#X,uV AL|.V;'WOXmōe Q܋̈́.oC+Ck&8I9 ]7Vӊ9;@R o[M1]_=|Rɮ7/y{<&zao9޵ͽ!H zE->4xuap^ gl;=o35{[!ZҎ"BI~2B8g~Dz"1CJ|3z+?Rqs액11K :k}Umv $T5ruΛZuwR t>wDt9}ݞnxItnm@zMLqpbx-적Y$] ˰zQ3)BX4x[ajܭs{lBʄ#=4_=Km60e0=Ptᦩv.GjM6?r_ H_bL9t;t,\kyqD׾]H׈6}:(ƨJu ,[iu%.>+롘8tSDv+彮=A 1cuci,m? +lBxmMc IuAg=.Dy%uu ƿI,ަ ]@XU `~D Sf`_<b﫪m$ h5Sz<;Y0^Lg ľ+w0àLNDp&|kdz[L@}gS:6O~pFC}Br*!Tkn bg<i^$,z,Ϩ.w8ʒㄩ_\?@B~ ӵ#!= %}Km[}I=KPg^YG=;,[`A"zo`%]NG xŀ$dH+߬65-&}MZKaK0`}hG2(g튃s'`e]9)|Yqn6(CS*n/ʀbnbhThK;a'YC!_RPv cGԵV `wO`\T(_T?Pl 471E]yfK@ڦp!H5&Dقtjc0 <0G'[ʼn*7}){"#Hl!l̑ՍJG^ 5FCb$̽`$9juȌrVQGT^{V'BzRk9<c?;f`"4{ !$u^>Ae9J6`D_[7++@X"__z6elEߌbSZgsSlіmWJifUC"p6 ูV ׄl+Ǡ\htcvbgiE6(I`d-RcRO {S| .<R'n\[H3 ]=X-Ė[6cW,btO[k,ƑvW見/޶# .vGکϴ) /3.H2VG{xAuT )M1J ccYKL i2rrD 6XgSk2gMwǼuǒt&gTYχS5p.%*m}RyW Yxq9O &3v^\> BbU&"'.H1i׻l8}kf-'hK!!' R7ƓeAi\ZVAܐbyi$F/JU,i*=7i V~~tL4%@+cs@_} cŴCOp=y_netXj"N&߉_]+eK Ӱj:b5z<6T{=g$؇\IO3dA@[DD|l͸D 8ȳ,ym_:'#J3ijϦfR=K-kwm)O'ͯd8ԭYEI؋aű>`6x/IpXnw8Xՠoys~,ehNԩo-Pb1q Q2<%W]ew 5a 6;%˔JWp=kJ{̬ϵ4pNϱ\SSc5L#>xD2TEs9/ŽT+klBX7\g[ƺ ! Om֟ƶo7F,]މhF2;fGӴ{0j+"~nHKW.*.Q5ixC5hJ9 wwU }SǕ4 E=<%dOϑpDQ!soI͈piӖ8S? $Wvs|4ʦHNL6r#O)"um߰$ #vK~xȣ[ew6r*!3jiTè).#u!׆oH +]O,Ɩܟ+n:V 1SBEr(_l*Ԅ]Ê|'fn=;lY $N@(nAKk=(BŦo⺢"γ>#bC(WW7O 1BT$rdS`ON$N3Yf_6Đ(3M56ɩ2֋Lj!fDQх(/DuI-a4MUgw}]b~N<+Qv#Ufd pWh|;woG}@^URM(>u 1|JJK88e٤IٝE*7oʵd͘ǭO217afvg%.p*NPorRC@ .$/:N6!=v0V|ٷ(0f,=bgG$9)GYV1.1V-_s gW؆'夊]‡\V'q%yG@YLDj$zvy)yO SkC.2 $fPj>k6v`̦˨G0LgTPd1U.FЅ'ӮU0& !_fW/Ibh|yhUqD +96*>ސ#D`XU TߒE4h7mguȅ{ 5eV} Pd3TCḛNnZˆ]@R2&GlӱpD3{:UchMUU0_h=IvmS31HC'NU),.Z]$}hMی|1Gѥb!?+Ӂ e“E 26'Bv]gXgaM^R FkY⊾x\ʬP^ j";`dQL#n>g8$7i")ZY^y0KF~£#cTAqΓzӗozD(⨹]W&3$TĹ΋*MI*zRB}"ΜL~ ‚}FSn{PMI}LghK"޼D9NK;u_uc~aڱ9椹qGge+a-А BOYw mSr!qD9 ضV;䏢E11gL﹟Q!2H_#j )ݗa8ӈ&QZO2E=XAH'|*6V+b7Yo1 s]{ٔ8ՀgՊP)(qSr^C7le4+z;V;̾|@bhH: aD*1' KeYVΑ,F+'/n5;CUzX>NS>}&GlZAħ X8SϧR̝i=-ivd1hE4%"Hu 9℘z:Qu \D,6 My(hLC$nқ`z'B|5p3_uykyUE"~0Pүp]K $gU{v¤7nw5 `n!#^.y usmΧ+AXk-Bf|!eƓca;㲌SŐvӜ`b^]R.bPAbab~d,'Qzg{~,1&|Oc==,Z 0*fGDλ'V u^~]]I=wf|f7Nsp0pS^!m ^/9X>GOvG% $!t/IC}*F, L'$r .T.AINq3twσ^IJ|01)VyeEjl ,׳ž׮4ǩ/:/}AN2jÇ!٥ Bnmm2K f$p~PY(T!uua4=Qã2۾# L:ڠgݦRkVRL6s*L}\ #}Aᝋx-GI K]r{[+Z!,Dp-S. $nCDU((Kjc #lsj06uN1@WfۯD(!V1q.eߛ CpK{>A0IO5 vPQص$=˸4H&ש8-j_Bmo 6ȖRZA^sG]t,DqV%U^fPv+މ]qMj׎#H \*; @DڸJtӖ%O+we}$DѠܱFݯ)#c*WOohMށS>Rvl9{~]U%H.Kg?:ioTb§swb3}4J#d-9j(?*oL44ؕSP'l#- J#pIPl= Ǩ~|)$M`2@NT%Zf?7ZXsZQ -t&;3M &*-76Y׬wjZ~(JmT=* 4찺'D!HE6/IAzg&'+o#( [ 'h&aA50"/lH&Z񌞀vrxgKs*?̈́5ϔN498.Ǝ-ac]L~XAX ?Y+p»ex2:Zk'w շkk/x$> 2CZrSseg$Wc@|WAScwe6ko&w׺acAPpus[&8TY"rrˁWSMWϬL[CMeX.u7B9_IeM?ZѮlL1w"7 UݭX_%رB`gp\ҦNd\_-W'Jr稒/m;!|Ȓ`b.xrb7MPDYґe,,2G:݅΍[pLO- Yl?ɰ^&+ T cRIߍOf) A!hR@mM6,'k~ȘƘ !Ǩmb ӑ{,.ἾژRPWlYe΄V(sț*>j&_:a$ABG)PSByKg H(fGԼG3jH]эv_U5-YvVbPw.<9kD(>NO$@ ϡ[N@H ="iU fYZ5-d TWh o)P}Jg͗$/u _e0뺟XW%>ư&q(;Ȃv0bNihR 9L;RbZٯ3ȺX)'O}E&qʡ0k;BI@f{kƚO4MΣ lՒRnʼnFN,aV2 Q[Ƥ}.Tda6F"&փo;5wLyިNs &hgs+)Q] UX>GLꥤS,=6-~y+Gi &7k MLi0 DK(ӿ 3qeU]: CJЊA: l`_t:{&Y)@l9ͪL]fiaPBC w&SC$ J]ހ&p`J<:TgW\@;5M<cMzmb㐀8lj{GMH|fpP񍜲TslLxtk9Mq]ހGeeT(n1Ζ3ɳcfn*C ڏd8fU$DId%MߘHMwPkn&ڈw*2r=[cY;p\"//0_(4K.5w/͓CçX֢D$-͙Mkb"{֋*[LY|ʼnNMI1G٥Qw# 7Y&с0WNM}("w2'9\BuXZ&:N;qa/CVtW`”:ՄIsu$R6AFAճ:9чI6"6Gll i 4\ǎxs}$,ΞU͵1(8_R{5g'ވ}")]vQJC.9_ !D~&2⨦QFᄝ9MIOn'=4jeVBa0mx ?9)xQ i`]:XjJ@dbEb^'@"icc+VZ$Y7>;X!nzG^tIYL߭:MIT"rjxU/rݹMِcet.S%(.l7/Mp: & 66flFXPHxB uiL 2]Wa1 Q">)S a ؐhB˒(v"$P8 ]ȇk\6@Η;bAF ztx,hyǢbᓺ KVteh8M#`N2up}rLg~WJ.)ozD\1v'Kh]pI_q7;HTr=r٭< 堕/g h*~Y(vZ.DT ^0VKo xl55G.PnT-̌P^fQ#0= :Y7lߚs<{5cBmڻڒb`I^q),C /oh͍|7h",0Rc27ZOۣ<72cfH)^k{nԚ'ǓHZ--f)tmPQY<7&9fv t>FҮW F Ɉub 4x(-\ N4NW[]huS,kF%`:7tŴaa6#4sm= 0lĸĔՅj<&%֫IԘ@Ǩs3JKk'+(^Q?ҔT3p=bu+@T>S're_`o?ÇG;wmq<^u P^>Z\FOf)@*W_4@NRؑ+ }s3gNu,kv-V<,$ڬ~b\2>;pt^+QQ¦)sZܔg%.̶A9.4ib, ԝffTT/H.ePjuv%jif-Dn*)E\({ Ki2@{;I]Q__Ջ9wPGՇ;~SdVMyEJ?QpXMGX+;>/(=>guk`Vv x#rG6)Q}Ql?5[]~5G{Yz^H4ᅤE ZͶP܊^zo0;Lm}fsaHv'x_iHb<3xp":_}ߐUARxog)ڵYk At@vlܿ9#;p힮&CI))*wbfIZVnT=`w& k)f6oo(( {uv/* L FY#hoy,_V.YpfMTyKPEN]*nPb -M9u>#0Om>F2 5rjp3| 8c|V#ïlOؿQ80u /h'uf;^mPKnrAOdBO|m載`;'O{JXJ#I`/!X]!,l~)AG!\T:њQrͽve.K-|J]Ot[ R,ۏx4S*S)j\}uhxg,rῃKyRgB_g mN*mQVwS#g NSs(tئ S}G>>G Go.J\7}IG-״!Fk;(CpbJ_>)]=ng}1|1J0Ϭ~pF#$e|wq|u.f6 :jm &5:٪|eo`ҞK̿bs}q ):'o tQ@+EbP YB$XMDﮂֶCjQCtxJ6L#x~㘚>;}$|~mtYe튶߄ӷ\n`/ynrg8rb% <}Y*gIwjU8&H|Ҿl1}ZFf2APB/al;Xi? :9=ݏ7Z1)<[W^3sƃ`zV~2xpPf0{}a#r,uסc;Oy{H갻/cDevv7*,/1 MR-)d;LE`2Š M/Eز.CM2#ɲ ccE9r!2U4~Aj彯!t6U4pA_]Lod*M!hْi{>NޞmaѬ\E9?]q_#a\}gk[#'6L پs0Lc/u˭ 2,@4kCOVq~10~K(H3{x gBmdv+YQ' -PGb}# S:a%/K3Y&%íc|RawHN~a_J'`jyqtkZ࠮"M`S)b5C%=iPJGsy/{ DG׵n:nd~D4iBwXI4w9)-r0`T":~`Qб;yTXS4NN+ ?K* 5~Q6" bG>ӛFB3[Z2D'W4mMȑRD {Wfj<dȏ7b(f0B.n}YH^[({w!m |S瞺 (@?Z5Bﹸo80*1X;kr56X-ΉΗ0]B910rh7yS":/1z6 n94_Mv$JmRoU5"@ &"U,8USQP"Y bByD2H rs[UKܘJ wqKjČ6X mh!a1_#d-9pIT|lQ\Y3omQq ۽FjHl"08n7750@j_G|Nfmo#8զx]Dr%b IW`_D>۵}SXps98 2t1Q]XYL}qrIJAJk4XRj=D /U_ƾDpddG3to~ZFF)CZrM S :DVF7v0kE ڐ?sy _[ Z ʇy>n/C uU趍žɕOkWa9j!SgEq\͘Yf@atb,k5̼z= U(&5ΰ։{XZ{Kt반phk tYɲPev|-I`)*D7ao.;j2^ OwFj.r?/;o)-PtV;(SaLgWyEJg&~pFU{Y7J=0BqT0v@~t\hky.kx] -ԘUv8MZjVEo,Ȥ1lORl?p"_P$V#,ZyNV(o"%IU$2S> JgGeUtgx{ԻzykBoR&{yZdjD/uBK9V (N-=:poM6,A/#tB۫R:6=$yyg)" (2c{4TvcV:@:ituȌPP|2a~c,BPʴ0s="q kQF zU:ޮGpA*E\vnUHX-(kyPCqˀ$0wYؔƘ]ٻޕEu8 ~-vEE0x}0 m3v(>]Xi[ o[gp+7TT928Ӣi~cv)q-bsI՚f g`lV~]Yԅ,0A%z 88T&Mj<'@L%Qf-OBE8U# ~ӛ!Tқ!-t6؁Ԯ7*35pJ;Z.흇FM3iBj`\. *-kKWEP\+%.SB ͖?@)8q (<.)Y z 'Cvywb|ۿt-(g==+AX/PL6G;‚P)_< hV|=~F]~bC`߉PV0w`,Ѻ^!Q|GA'D2-VnE =|?s>ɞP;alE?r?տ2dwy1ia\p|HNa6%G1 WwA>"`݀}KI{ޅš^n'mFN6Ç԰cZ9j&,S ܺ_}SLvlO;KF &3@h4\9G\t,qL댬6/!lᶂiUYwcEhWbr~L_׶]6Օv 8]0,/G'eUdEaY tkDK/9*ܚe@v6;'7_=O/`AA.h^2k N4p7vۭIIhX-_iE$+p۠B" pT>hjR#ҭPX6*RV@uVڑ0DE^U^n"q t#grU| "kj%yOA-Xvp{xIs5ds$PBPUbr%ge&:a1ÉwIזFsK0al8&ƍ1x<3>.D-EreRݥȞlk1ßn ClBg^-pm@I  xz qdPU?R^Xd{&+ VR~/sUP|D.]Zg,ZuY a$Y&όh Nfs3˾V:7"qb]VI-]Wr'pčz.* GJzvv˧uh*oCH_׎6aD>7#ye<1}mƌ;L613b_CXW3?eN$6S8Bg,_BP縸3!>nkg`'tޭ]i NX*EB5bʯ)|'_oqJiҦg!{ѺX.FyG6ң]<ѺT;.]M< ^ ߢP'?SC@'/ <`L2- 5A5axΓ) GNF5ߠ|NDm#K<|lItkTrl7։a1l ,2kDJv YK<\N6;EuܞsCc5Qvr4 <)(\׬|n{7"YY"lK92'!}Q{s=v|Z~БRq^6?:X{+KK1S1if#v!r@Z~b7X*G2&8;Aг-'[Uݏ7곻ei] 5*7nP2Lߴ]*DtSsY47s'GU bKOCPUm-A(O>$R-HLpI$BK2x=iZ}0*=[F[NZ=OCר ˦T`?Zu+hIpʇluO?v_Κ@c3?Uqڒ(PqCq)8A5 LPyΕqDI`+dL'֦i? ]vުq5 %"#gBW?\We~&QXjHtE",sLs5CIcK]]/P5ڮ+ E0ߟQurڨ@i\LppP8ݯ tWP}Ygb 3_%>q3<ѐͷ K!Vsf͔ZM唴=YŨ0dcuw3+p'~]YDv@@ۋ$|%'¬4f?D`ni },IPf~:$%r/P,S>>M$ZVV̂l4Fd(u44<2O)owzcZ3+j.tA_L~;h QHL * n ?ńfew#+jt/< RD@TE6ۂ`w{?.O.ͰE.o wnYcBK>RQ{U%"!Dq6lCMcLR!^-)QFanQ4tJEN$/ ÍdM7dfhrHE[:iވ  ﰙ]Y0J&hf`(XGi ;^]k+3!3szא{vOIX3kOp9v qd6ż,/I8S(Q-mA!u7+ם ětv)#1q\`Dw֔yʚxljA߉(&7ue/h~,zg`.J;;r4QYFPM9㩙 /Ï|JUmF}s7Fp G=hA30Vj3 0dIzFסie>g,5xӲat ,SJ( }ȿC!a.KMO+.q N1_:\ބ+@>!9݃j#(l6n^0H%`8@!CI1V3Q-7t4w|8]:ĖU5Ϙiq2UT=+|N~Y}U|-Vl"p6apM& zfv"9LCAi1o!0ճegՈ%U|Gv^VMtb7\T;ج8 6Gm THO>5 4<ĦL u\K aqozw˶<1qTT:C똷 8ew<w7_QJ4Hy5i` 6`%Ԭ`B;&3e#HjhO4#׃~&"?N𝿄5-\@t*DxTozd)AhTtͱJwwVPy9?2UпFߥ^ׇb~ῴNل(KԻfU^ &{i7Q!R6W(Ў$3"E"v] ӎS]m^V75}&uΘ1W/85.+x[%ʮwXZ}-t%dZ'ۧMxRZH2yKlb[ۓr7OlSk@"dc ]}Q]w)FB0BI ^|2­ـ`.%#&iy[0H"Qu=pܖy!Y4U꩕mu=O vzSN (|g/Qq$v QhT.r6 CQ)Hт/YIa+ v*N{xO?[~dUsD_sfMZz:~0WLepb ,+'vjoט' CUARNAs6H2LDt,R5ؓiE`xWJΰ p:Ӓl،t)2pg[_wQyIi*̽2@wz)GGڈG1N4yo;1ʤgX 5~x(Mp/6ٷbM+6xqղF96'8y`\4uQP3:10zӍh.Tpp8O;j`hբ(W/vMD^ED NF_6)Zl}ҵjhs>"4rϾYv{ 'e ڄ;Пk-%;0,GKR"ڂKm[9T.57 c*Z?S`to *i_a)Q#~+3H? 26gf #]U5u]59r>'9&BRI]I>x_Kw,_4`(m)Ixe45cpǝex90zo;N={`mJFٸnۼq!5:*C&6 % _4}s)gvM΢V &̼%ID+lÛ~EO*Ow[KԀo*/q˹tM<ﲲT36j0hH@@dU 2jlm}*l8wm x{z<CMVAoJA@Q?ԟ֒Q>+8-.")-%<k83{!<TtL. q 7 z zjhFןZ|Ti_qc;Lݧ8]9V ;԰_S,4T 6rUf_c,Q#O9]mΗ]\7;R~7'菧^Bx>Dspi9zx<eF5Mu}5Ċ WA$C$@C*&robyB:(#%Kļ5Zڮ0iaIc0" P񒬐YXAӭAas\FXNk :F JCpuK4biME5-%%,XZmɊȷ~ J׼ZaBƇ\aHlG5F;뎁sl-50܋!!fZ5B,~¹E*H'Dv)~DtA ~<2@ :U̐w&?O]{ 7ĨI=ȞUI]9鉝4x8&kCNp]|n][0n5',m)ĸgQ/Ì An[=Tߵ*̛~N}-c ' ӸdPe+` 嶰&ztA&h2_~h袘iLD@VfF0!N2}C23R2K&?-/xNsÜ5fI >M+Z.P#!kobxfvswK$|xhaSSy,SۨSyem\=CHtKڞ?j/Dc[vC򮫮P (pfYf.tdFOგ갥CC #&KU aYnNMx2YNJ ;+H`¹`AckUiiFxaX@29k*YE,u)j#}"ĒL}#gk+F> - ^Hd5컸;9C$Q^F9@eM dz*=Qŏ-2*"sAWi.'0,2ސշ!<ݎ_>4k9\6ҝ{q4Nl_]cyoQǝݹHWbc:U.&` KkGDtYOyd-=|\ 5ER ɯb9iLF0/cqZJAAeO]^_>JUj8XkVO$לFړk[T.,VAm:=LUPb(V EOh? ~ܭ&TkP Zviă&e) B+91wNoe`Uc?I~FoZ^x) g\ ?V ȌRBt)*aM'A> w)J^86&c݇Hx]S#< )ri~}i.*@HadEO3zwI!639?$u;4=;b`r]K-3'RŸQ[Z`E:%#h3$6Ou|K"dBWijN cZ!2殿w)n{1E 6=Mgѝ{e\SFhuk9Ξ(HO)XӨJ&=amh8|Ӷ*ΓjΊ\~eBg@Dz;R@cFIS&Ms# + su,yEZ#ɅGhHdA5 :,?&Ydx-TGS& Q[rY¬ѮA] xM&Luu^5N :>bXk3ٸ_{шLTt^BCzE}2ھX8;%ya!ڗOKW\% ?{D[aɯ}/)=d,5lu~{"{L9M^Y.{FO-k=XdP9QKA}EǪeHe'Q ֥=URRH-k5kC2egU۲mhOPE:cE:!i3yK' ̫V1ZTeޤ&wNW^Fz u\vD׹da{a 'z}&:BON:5‚mO솺l2樾 ĐU4RwKkUOfXz2$)?R nUQ瓄~[~/2eBB%="}Ftbe71sUG\54Sf&i?/W2M4^wǣ vFMc5$%+'ﷱJx?aj9f$, ZKP2cy2+wN|N7=<·xRЋ1WvWeW+cvge`7%cyɑR6П>1mQY{ua'*б.1S*CՂ7$)߰F/&<?.azk#_K>+v 2y\:b`a-bh:t].ȣ"?l`-+1i%cxf:/q<+w꜃aZHvu-}9,fL\-;# !9̠:G:Ck; jtyvմn# nq84<`$<6BN?M;v2#~s{ I%zǖ4 (أcm\A$;0iU#DV%o} .59q||P V$I4]'^yܰFF"@t!GRAj*9z5{v\|k}j?] RV·(ʜJ ]*p% EvyxŽUhP$9r`rtM 3=YvZܳ9\\N0 tǮ{痖XX,GiG*Gp6%h3ְFr*P~6QQ!lJ90"@I&2L=[i)ne*Yӗ>}I.&( U0Y$< U0& 3g2m{c/`#O: Ҁɒ>,>U-4;7\ӊ&@C:Z^Z>d=I/+E+ǮOzfi69n~oBpygol gve&ڱɚWe#yu@՜N`p"T"ي#2Rb2&F|cћ/EWWOR+ؕv= Tl#uo]).gMkwqp&o$0!s#=@aITG BVD@.b&33bBr%w5=Aw9bh*e54+T)KǽSc(%} fg4{-#*Llp;J˴}1hy,x]e^ Tdw#o$e_E1Xc!(WT+W?.>S 'ؖ9Z76S)/}e'iv1jWy~ r@P9s}Xv-Mgeי:о gUw.XbPe*}Q{.L6[1=5RSnhSQKО?~cmZ&{T26Y{>D+82 %LNC2#W#v2{Uwi )<|KCy:WʝvbowPA]k S2gS҉vKo0u? PA뙙m唱@ƪD\he#F+鹤j: ɿr}ţ[# ZHR&aBJh8s8Nb 75dWkʠ x*QYʞVDaQSxy h鍸.?\oPlļU>aWL:CdF'Qi7I0J 'cNۚ !' 0 Ӣr&󿟥1yH y%R̒GPӞ )56 ͨB|^/B:-6_ "rVXDmә90X}>&~ -YVVj1ȉ5;qSptUtt;=mq @vzL"zۻ/|§1-V(p69"+Pm!݂rih;ah Ԓu#Ы[⥣'6a4EH X$K#F ֭;feROvM`R`@EmQ޺IɚL{* :KJVoy@=-+h D7 l ;'ykB[be5z{#(F,Q%>6ݾ^U~T\chg#k_x@l@AdU{WMꛛBe*ɭDaۗ^·[BmY+fJ#1͇--,>2 櫨BQ Ǧ-&DFp2dҦl`b2 oX ?>P0w)E=y-TBD)机) CyQj2@5qS0RF([] ;ǻWs:7bXv~j* ;5W8WLQBcRОsS<}MZ{9xT""xgs=xD\Nkh*ѾlF懏/\=AT6f~/t5u]5vtr* FIA h؛>9vf?jpP=ᑃ|)h5{L Ejp]&"L{ ѣזb31"'.ngBVcnoa,FdMS$*g'j MP<( "lf9X{r3tA?a;{@P&{UՖj~A}{ CnTUkGRd[A!\| N'ˢV\ !K[uA'XHv2JXHc8$%izjMDo7p PB/JrCK!.IQ!:4FŪ<ߙ»w"אfoղѨ-<5"6+Qh)R)JŒT `N}=XMaHf< d[nP|U/^y4t1JhL'"gh*? ٘"FCL@c<feqN7>-#SF(FR%ƂFPB *3RT }GM.B'y,`>Tv~mF9* XxXIŝ5r1su5d} #c:„c `@?J6w$2np*q$9޸kt" {H#'[ɫKtiѮX\K5R%Ym'W +%@wzs]ZڲT>ATL(+:F1e*kJ~g`qI8cnVdyxfײ7ܙ ]PJddZr'B`GpN5F)(_&٨ZVK,*g %0[AzAmٶMr9Un}΅v/(|_^aٝQ"m2v7>0C";LELW^Gz̜ 3Z3QUe@^qdk ewQ jwfTQDxhpcL>sIA%\ u#tv+;h0!CRl`+! Z|w Ȍ2u`rdJH]e(j3T@=נ ݫy/:@{c4 tmlPy [1i{"tc?pEU_Ұm쳈mh9||u9=6 5"3ToU;hGuc] sXݰM/ ,/sО.cx6\^Jrz EvyL'CA_tpq܊ Ⱥb&|.ADntwz$ 8 fr_ql7)3NF7{{3 w#qmo8p_-8|,u3(&@!"~(ŵ8MP1S^3夸52ZcړMJ1Ewr<*N)=%̙^h-% ՁRo:o xyH%Nb1&{ ;*(4| 3`_[B)H0%aЪ|sRT`"BwI9~E)^mQw郔PDոhjF ϯCz' F\v| s)43kuÓm$l[x]%W=PO{..ػ"fTD#OUoj399CVfӐZfV Js≯oo51MW)dJ ƣq{\t f/r 8@"(,9#.ctҹHa?eRIDD_p;+2,@Ny X!"NŋW P F0ٌև"p;{7\Gd%xo s9%̑"!R]ɥ*kJژ'=yC"TnY3f4TkTF͘|S${)9{r]t1xNUWYؘ޿PeMm~ oS [2hE8>A4HPh {fR0_0Mxü_* eln59cs'KTbV+7Ƣqa/1xw,;DO㲧*$`bN=%c'bmOz2C.}-*Ǜin5I8҅D_}׆V޿-p.9ANC6 +c~+D% hsq,s+K?OX\4\)kjUfX'N'@|e*'\%=o&k[&ORd) Lr84JL,[t8?'.׎# 1fc &Lm§SYHǪ"z>oP(&#QA4%@+:Vn3MS3=d}_%I/QQ%e~|㩨EˎdvhȂZ33:w̲Kx.@fmm}m۾A`Μ10 Cɺ!MLXR%0s1EF<{(̷lvT&*=cBXYseMϜNf<ɭ޽s3P,u MR~!/nr@@R|[?*$Dy ɎyBO!A+/ε$KS4=N;Ez|iRa MjIx1E;ܑxI,TDt>@"ϧ:H8jD:n*ZFfj =LbNĘgsNR.W[hf&V"X׏KzZȶF Yp"+Bj|nPv,irYaFn+9sж Oъ8Y;346 :7FU9P~= x'u6; +:}YM b73| j5ƌeaOt oC$G31xjt#A><gdѦ/7l&0Cyxp;^pM̂BH.,kenp[sX.#Z)e@?`Z$jL}^c_If1b8u1.r'D\n_ l{AfIGU Gf}W8Zo?E "ȔϊqFOŎD{g l“1= 6LDwNxJ4a|? )'20Xhz5MQۈ{:a҂?l 2>N!V^;VwÇ)m`Ȧ*&6*LDB IGS3yΦKP-H>o؃%%ux:]eT1%|Rqt=q) ( "}CeOlԇemTc=+[ H.K-q\Y9d#E FRKV^2 AB2: aÓlNc5v*S=/!{&Nn ]4ݙ~*rp_'d~Yx1G-}'p@Y=AF@u2x=@Xӟ0Z3% H2-bMp(4/q_8w3ovU6 4Lxjts-T$Dr _vi(dm֝&ph '3 fBA ¸LcZouVY䏪fbQ_}tЩ.bUgc@Yp`NHrBXHW'&Xj׵.7Z8ݦ:;Nl?"\Q0q9\u;07ґ CE^Ig$[Je=݂3bYUKal]磍Ozf%KoX[S7M8< GmpI l&XS!}<Ÿn[iőv4oȝ$͐0y4.6_ݹ"V*wٺzo86x5K(t*HIf;U9t4%K]?9Py8q=hby i2KM43UcmTRHqXrI$g]h ,cɆ{)6CWqM3AR>wc;+T#f׿ɖH|!h@k^?|~ |`{@_J 0\'B 1  "v0 `1.@ɯ!hΒ57ekMOcק- ˫\.A@h#_&k**\U`3"Xk:\ưySΏ? CuHw ֏,+bHDx:^ (\y_AAvctB_i`LQ #Wc6Z#F^{{H4-Jq-֝lXωQ :t N0]e>{[ckvvmh\b5[E# GS` s9f(x|M}HLl hNsuV_)bauXge-_ߍI$ ] < |[Pǟ5ԏ+$4&XfQa5r$BK$'OgJb ^ms 5S#ue,4:$x"[ז&Q/o0VΧn;*JhB C ݬưmҶ0ԪoD[))wx(z{9 PLQ7(d!"`gXX:S?+.l*;%Z_"z@}/F=O.a1ssgK#/ffRo9"e ͉4FT3ǬqͲ n7lӒۮ{U@q[Bs 겶 ( TL<*h+yn'I:7QyxJ?bp)V#qȻP]v"QQ~Ȼ@cja>V/d\*hu,Mp QcfmgskV>,F8jNw7ti[ؒ@vjŅ_4':dڼk~aC`-ۥjt.Ah›UEA*p, [-uJ4C<0GB|]O(ߋإ\jO|oߴtI_%+ ?ac8]R=S85_ӦxϘGHqw|R3&.x ǽZקEK{8%}U+̊'âGC[Pǟ3|2"QC&ˌ"Q:MHlYe<=@1r}[~bz'tw ] *Z\xۗT[lSyIC"~}a_Kki9nN^\:Aѷ'ҒF^ <6 :υ42(6A;ol+98U1NWG]ZV./ٵBqQ?☧fd؜KG© !%lقN%9"{DQ'[s;js*@h L{TMm v~hD mbxw_!>N=tCbAp4'0m2e60c?9NRj,w.gL9n n_ש*4Ktc7~Qv;jv@ܰ"axqomw)yyriSP-kj44H0Y骧|Ҭg-X1M Leޫs[LTIZ>Fԓ,~B2ܬW2*B$_*^!Su P*$x[I !?ixO4uPe ΋.*f\(<-N1'\ajqA*.pQ{)UmSҨ-ѕx;r]8* 8٩J)CKHg&ZTx_#y^0r #.XMDN)W7=mf>3$<[WoE\,1r,+f`CM5nR@() 1&'vM[bMRRl{[?#\YoKrI\n9T#m+W$\K30Ce|@Q0Sp՜k\FpGڅnB/SaMx?B Z XNbi nPXC'onlV;zvتRgQO}P}6-Zfj:F}EzK2v4 Kwd֝C~@Eh~04$f LH]DHB6f'cJD/L3.jg.gIdH CQrm&da=ɦô>|ud8[ٵϮ|/cIzϨBTtzJ[$ZY ^e05M2 Iu:Xrˇ:Vy0lBl-%lߒJA>rVZn2<=U$g&Z!&܏8#Rd o,gRil UHׂYbP:g"x"mgm:FAVaMy Ɣ, O)- oL;'Y]CZ+F0b4]y4[-w$Mx)]^.|lC!cj%gJ/7&f7 1lu[m(p]L5u1yyĭSh.:Q;z)$;EGKb,N_yb@6֧ tVafsJu;2^nnh*Ҙ譌8ٮ@ ^@ ĊϴP&- J8ybC;4" ]WrB!yν2ۘњ&M;WW6w)CP*:f<#oέLk(69iAnLԝ0ւ#!Cy'A[ SMie?  3/ J+18 Cpt xp _N"=?~䃎mCbrϟ#p#rkJaRi]IW,B?p E3(HRdxeNJ%U1%jL^@3ÅͰm2`ςemJPˣܔ̰PGrBrRuY`BV)3*|'GU\VPPk { kް2#c !A\k)PهFe,GFnEơz^ k7w+FYT f_Fݝf%#87A{1~8+B_k̤!i)0>cd~nnLܻBJd!M5,Yq='Q弱 -$ȉCp^w~Sw`S>=š R| ǤGN8m+p!8&ZR͖)2kWI3PXncO4qկIn { =R hTjU;?GD\ݚW y?1,>8Yԏbm|5:9Oq[M8(D=FXk63+wD7LH&-@gu,Kr lf I!'DbuO}/fӵkFLq_Qúcp l?s tHUagyK1[ɩEZى@}[4O W5*Gإ^jYƥ!΅x%)ӗ,z{:Y1B3\,nж=G#FZdQ_'kmm43YF}"*[΀S~;P➘B-^oj  +9 jmc%xǃhJ39)eTW<4=mE_^ra~Ԕ ֤}S%?5PJw%(]Ip)nQ|q.#"(+ISVTW!pB(҆u$&sP YCyGFgؼ ,w"[5Ϊ&kU?>S9IZ%Ǻ1I`OE) ?SK* 8'`nt `mDO;dƋޟ`t1U_RxN$iNVfg{V$x--~>g'Bnu3?!&T\zW8qZ3x1~rm^?],S$]lCT$ d)hbg7T`Nf@eշl=+y.TA=liڞ22!XCչH~9^MN3v E@􁂈J31"TIc}XHǞA)ML6~[)Z Rn+Y@:\0Olܴ3G,h́}d"[YهG4ӱ/]ZG^=z\g2Ыc{oUDԯxfޯngTBp 8(KQ(97㸸}iTރduJM =(LݼjLTMhώK) vb ACBj<H.[#󕳀h6i^@kGtrPon\]y7V ->c S`:ٿӒÝDO0ZyۘWdc^^?aG)i3o_-tC}w4bǦr/#е^$*ԓkeKh'vaw@Sy,?%|$+cϔӘC1OL@-vr\AR(pU)؋kq3$>F11eJm'Y|veǹ*0=gB5 PK c?]0Vxa*uS݋'*d;ndU6L{RtINfyMAKzr WHJu,^ID^6~}?Rxrkj$ߠ]4i]`U@F|K_ֳWn CF x񫭰ΩOR7,ZM(.sęvڈ$M:=3 [@T3"!YT8 ;&Na- hG'TUz'f>?-Pm'oI[>AvZ+Whk qYGz~o,)qDO8G&kFVCSp!h;/#SO>I}A2D: N]Gue?6BOwvsS2svx1¢ d+GSӳIpO oNzbj" AB9[FXy'ZK1xbwJrnyvlU38~ "U[ ȭ&L.YNZr=M{ؽ# Qh828'e9I** [ۇw%`ܟK:ִn %H!XBUg&YNIFX{d^Bi&^04^ܩq{!0Bp(koգ"cI$P`31_] EF/[טp$\a$sp]b90=SKx>r7= fqʤ$-9$u4XϛAjǕrci#tuTcΗw^*-<ڻ.$&o%8?<9RVeg- Rx}=3&C#^FX1I.13$/5_Γ$3*q5Ӣ'eo{;I:P'hUBD{q\0Z9(v #0ڽqW6 "fk &b] .#) WaҺ(kxftS@R QG֐7$cBL^nQ֧Kr!'L1i2ݮ=ؼ.2cɨ΃tf_;rWo  5taxMt>'hL ʲ@+CeDm{m( 9C4 !#9,{OnL 5e(?-ߛ*o|A(َ|Ӂ$Ba͵ty"( U"-"2 jO HIL9xf)}@/[֬fSe]~ Ϡ v8}!6N~qk'l[3+PcYdȬ,UfZtʑNܱ ?&#֞Si@PA0PA7BY!_Ę7X H5"wnbZX;9,1856f!B^C]A~C C͜5mRjȦKIt sdĤ ג }5[T'{k#v#䰃pT!TeНM%5ɚ[^眢2wM/+mgya/h*4?|q"۟p]ӫi.y;*=d~,vk} z"+ncD3#ۭV'"33Wr[S* q4(NbiSPl]frbݔm_9+4BJN ^sY;+y]t *904#%1vtB:\1;lѷfpP`Qi!gx*q9AA q~^ RIc p/KHl<#Z(=e0No>ᴸhnm3s\1$Z^j+ p݆//h%ۄ."JPz + c@I6`yIa^l ",ѳɐ9p(GliVO%|wfi5ItSy Xv\~MX%S$)ߖ}PJv( 5dcǍ+4`"!*î2ZJN25ds>Wo|$L%*^ [ v60'.烢cHc(K"y)~*SJS2猩`1 [K?R0/^U; ٞz(G"8ϧZwT~ZW-۬d.{|x:&olgm@qcֆ(qr+ȳC1FZd6UHcawts'Ӯ%/yCS np4'3.eّYgW跿BZ{3![YcGAFO3H.#&|7U^:.'w YWxuѶ%H:Љ}%&.չ =}ڑ?oFYGw2jpu(s~<=ݐ^xa8x;hn1Ȼ/HK2wm[/>"BXw 4C LB;!%ה͗Kdxjo]ǰUrJ-:jEGL{< sQ$rh".AC)S;)ȼU=$O؜sKvAχ/n(,k&&9K9!?l8)wҘQ5OL I;9!6rs@pc Q%ʳj&J8# e,^Dv͘oiҖą6/Nzl'̸&*In%K{( ;v߫Od]`nԼȋ&F{iF47;՘$ 7GuewlZ ĒpK_gZL'&= o`na9S)0)ۮcGu=;^לV0A8c3ǃ,o6; Xj`FYw8&2+,wB*nZR{?"C4S60 B$´B)d[l`W$y7_)Ѣ?(7@jA۝rb96:Q|sLG6;̒_6DvE,<=2zRGރGhiK| ISX@LDC!6^Qd0<fYYg5yó̳ECι[jހ+L`NW%s;zw8,o-bX0n J&%<D[U20jə>/Y'ī,({Z}]Qykhn@uLx/Ō (8{ RbցTln_Erw?bDz_e} 5Kbb6y~}tמ9urlg[Ȃ!i &]y[cEjv RP3ޑR&eVjx4AK1[p/g. z4q8]0`][uZ֮V}y^PU Hب/1,J|*ݻP wp`粪0ATY};P9P]" g_\C_ʰϒFmrzVH,Vf:z Q6eX7vAx%ۮ\dcm:|4$B@N^RMƟ#ZMHĚP JnǶqDl"ehǁ؆/MbV|}r wZi?;ɰ\s_c=9q]X8Ns7cT\|6Ԏ wfYF,>_,7Ds"{K0wܺOfُq#gO1Y(lO:Pg6>rSIxK]?f4XzjD Ϊ#.v DVߠyy׈c!C g5P:|R<$)D|ÍC ˹񧸇II܉!"k$:?v)"%t2Ge6\lв, mc@9,v0`D-2nq=]D_'s'Mv\+4*_;6\)OYTR*H -Jx(]JU?Fإ)TsED"_Ai$hNξjy`ү[5qth:IM#yg 0 [D=0D8sCaQ oݢP[_5A"ks;g(6\Y"nN܇%yъ+t|G$B8fZ3=& 7?|X OIuZO!@Ւ C\bKP6?3rvl[/.Dmءs32*);>/?SOΆDNSS@s&w"H6N{wj&0C!n +xf!#!e.2vR礆3,@;1Wm0vnS4Qd(!5]h͹acte+1'~SЗq}'׍` eM}|_ە:jvۅ=|, /Z n̞6edw0 r1"NB&w"%zV-C˙Dlmz^]p?ZW4bVK0##V  d>| JiwM˫bm%Yȅ*iC*/lL%iGe9:(XLc :EV6vn=_::F3:t\WP'vTB鋹|a1:m9fp6]R+m>QO*AwY ^8%.c뙏ϾtYBXI3 /Hm#?@u Q&6U^Їc7c-((I悟NBYMTЏ!ܶS4bzPwn ȣȳӭ=*4NF qP_(D/G3yLy8txz|ObH_y iJ3`uć-f8{7EC46gGV9vRv3ߙ/hT[KjçH{X/aTqDW o(wh»}kNA*!B"2!'ˆr:;kr;ixDe9#1)[: ,2P=3(oGVpg2fl^ *]ds NMj꾨TݗE"h^K BS;DS )9O\}' + 1EF<َPg4 aQ?mUSjyӣ%ۘġ:6uh(A? 蒕7zm\ 4kEXi]ϬfǔdeA'aXp(gNX!;m>;yUUXүU's:fQh\նwDC،JȊqjJ2,)gLk]QOY-Kmp2$$=٥ ۯ6a3T3|AOV$ O'NqW9r uEu1Cx?BdK!hh=Ƶi+yZVpk?Jh\'2]% ӏ1jWQ_f]kqx7Bg!mU-)2t ;}<9Ujǎ&7JXP^#h m_04X'>õUkxOQ*sF Ub-z_ DSSb-Wx q̌?AjJIQI_Oc'ӝd)%fS l=/WzoJ tLȏf'[,(wϫ<-a v#EMȎome(;kuEz!.Jٯ&Pݨk|/^.m" }rwxi4+H( CT"N| :܈YĀz %Nh+?CXCؙ3!cD(XDkJE7eEAvtb 7zu[Sx qr˧)/(H\iDUa7٠@kKS ԛCmLMjMɠdpKxzM.kptKW*#4 hi8I&o1[w0ʽ[+4} wsВ2lZZFq/W}ePjGsդIS?R9|6]{%dukiuue4jU2_6 ?Asa'xD6%jSW)B/g)`g Լ}1 ScJ`~tdxTKĸb\8#s *J/7k9iT~{T ǝ?vxd37|X7_`e`1YS{Sfp>?c';Aq7/S+i&R1E/V"mh<}"_ϥ.}cp݃} Qclv j3rԵuCmZ"_+*InXZӍze:mEFa@6 ypp*](WEeE,.|B#)@m0G?"' r` Iy`npwIC lPv} eVL gUrLc8ÏpNu' l'ි./ҖŵNߤF_!NQ4rgCM)Z{"zA^/'R3,DsWHO=_PUSZprvG%LYz/g8=K#\.mijV򕃙}{8EIFGeg3%oS\=SMŝ<֠7')]ډqq1֍O Z+uo=<,wD~F^ɦv=Q1G86.`M`%Te/ZR MWt0L}4 qw:- 蕿^ gL쪢ٝ[W`PqT (Ӳx`ΡW\u8x8/ &;TKA?8p4 nrn=Iλ]u잉 a,TYYBEFl~DȾ&3E֍`vC-FWʒ[2]Çp~w xcGyM}4*2[aQ<3GiíTe1RU,'#+~ʙ^i>S3 !;/db <'_`7DQaQ.uWa1luavt۩{U3͍a9Q+JT$y`䧱YP?e)_~?^^eF3QY9 f5v,(fy2 ,m.xwd W{<'X0zE8%ኃHG<&+ f/ FOr7P/M)PK$g5< YZKq TN'αaq|u }:b9a{#t1EVK=) cM?9. \u|->ɤ o4S9r¬.̹nKNص%z嘈{w{qdn֓}PhIL8mk`|acKoLvc0|7Xi3hS Nz'< q"Y/f>Po䞨4y.:>ZnXA2@#Ž#re@M'ZcۦQph/sC ąGvW՜uYrzOD~bcl3 þQ(-Qk WJl"]PZ9c Mgֵ!d+1M/$VAj0zaVN]qw޵Fv|7!O,-+/HApϩuٲ+J D5cm\+pd1[BGZyO2#g<Ջ2r j y ,UV3#t>u5pbp C[AʷJPq}M/X<ܡ3u>1di/PHk)qՔCaqМ~n(933U6_-x"’ M MARg(Ĥ$K'u5)g.o4̬]("Ϟ[꬈Q.88 X#LMR`ZZ- t83yhJRZjV|H`URnd.Q}pOpbzt`ՌĨ?*~mʑq&<7&j%^FQ bDY'}δ4&a=-9T!Җ\{A'š]>E˞H{/ROC8K`>4R`?EsbE_G-D+):DEg;Mlf0ʛ5iP,U.av ZE$\"µ4I0@FZj1 4]kmu)bJ;b2x_|bKzGUS?aK8F#HOgI;Gŧ%x'N;vʺ#P"A%MP DE %$٫?l7 iP-`T(ΔcPj#6e.`~19H8c:&('@ gJ|Àݶ oE .?9t.sE'4nzR|3 KZޖapIXP(69A­YpNh! ^r'pؐ RY#=ĀD3{?3AA_wf5ZFKIjBPGuXXqdfJ]S,&^-O# )(I\VKs(1v[!:U8Y|}G|rYls^4Džr5 fP8x2X1E-o(,ǣQF!%R`2a*¬2p SҜG]\ݠɼOIaS͛KlUmqvb' \Iuu\ "$$,̫ccӯQE~eifb% vU`lYݠe2$Lt/F]ijpǞ Cc zfKjEIt `# Y."ċ[N YM5 izkA{JïApr|~\_F9AP F%A8XqWOcpđ3OF>)p8ӫ+U]MYׯCVuU]M EU_M@r\#H- HP^kN8D!E$-[J5MǪ ^٤:!l?]mYAt('lɮ'ϴ]﷡JaU] (:)4/vI1R=?0Mډ4s^֝e5uEW D =X*}X=p.hGA hHӯk⽴ʡ51;NXߧ/k[=F5+f[pŐGyRU*O\uQwo<čCc";ċ\v) IUod>n0ۦɟMvp@L"z ڂ$bqJǸHmq>#d,΅^޴(w:;L)ނ3< [RS\6Z:}s+ dJN6!z4Goa5bo,e| exV)P?o`L(l׮^0Q(/VzpFR/"pzSטgh3^)4Gib5|H2$nEcp!u?K8:8!.VF6ȟԀ!ήJ<ޤ{tJXyޠ1ck*TMrϭA b >чFX‡Td:C:H705QԵ\ 9D VeiP鎌rqbpr(Zm3VRNۿpa yBQZZito%2/({´SiU&, R~pABpR}䓭z%Ϯ^'C{z! .3tj*`#0R%NO<⧳™gd40p tB Ƞ^-KLNxUy?6{k {g϶3V>@ҟN*sP\G)9%͞0RZV2eȑj;4F^Gr*/<7"v\[[~5HA~}CÀ]P "+ g&-hUЯx/Y8S6g8xQ&e[,>>J];O]xM-,yG # Z UI6wCg*-YpBq&!'Μ.P blE{Cc}k?>< }=F2]f"SDZmE[uoDpAё_Ta#K"89NG-dS wbrŃed4en&DS_ gz2MDbA}GN-%M 3'^خomzQU~5;f"p]aQ-%GlG[ g<w",3-K/C«pj1Th -Ԕn4 Uc"Ws) GwOGV {P2"-\#Rg6őehl;} ~`*JY{-<3P ?g@eqp~&070HAQ%9kѼPQ2JPkkTpe-wS$0, s֧HBml?хܑ!wE< e2ՐyjKC޲.Ia΄B{+ݒ@P^wn)mܼN@a%.@qItoasW5oNWq$es_&c7*v\YlC`y7uo1lTiB2?.QZ"pR0tR҂vV_ EmKГсw'(+:'8S-%vĻSM$A8.֣{|lŸl- EG2@6:}@#@hE#tkUxB6+pNUaIW. 3Tq:C>2s3 Y>%I| 6^WUg,(c+&+uBR:@Tۂ"22a=uM2x&>ߢpa#SCcGwa9B ʉr+b$Eo̘\}BFƭ/#NxK;U QP`DSôPXμ3Ti]l٩xξq-D+LL풲, Y6vqA Uj=m9Sn?1s^ES,ǵ2Mm͛OH[>\!<. ߫E{%K 'unY[gq- lT9ez~m~FuCJoל8 Po#ج l6tls^vڋzqF'畀{S~ WA@/ cx2WLl\{vq8`_3mIl\ @lRv 'Zԗ֦H_k{PQlEŸuÏ3L_ F/xՎvK+:vPǫwb ,!M>Ccb5!  ]P]Ưڡecwbx%iI_`wN#9WX:.VΉ۫FHKxHM>{[uwcs=.k.~tfY7[ ?yGPe:F'~e~dw2XA|a_>%RV:B/*ef2%cѼweA|X0D93{Kuy* ru0REɓ3%,ޜDfƨkbpy&^˙ ߺt7O.L6*mR A)Xa~=Br9ټ')D،qI/j;6{ x;(k byF62>E-s♳נwm7,N;jl>uI+&`]eWcU& OAaa^j a( #*LʉДڜiaW9vMۃ甔aHִļ:'2+/w!_7sm C\.r~h^ `_WYϐDV4Ɨ@|D& M6k ~21Q&Ʈ:Q U2āaUF\d%A,pƢGG* KX"X?/ Q0/ bVS(f\PZM0+:?60DM$x \TM i#0853GeMPL.N͆nX<`Ye ̡ʰ+j2zjZ|݁tuu;,dzYnFG~bq 0xZk#/)2p')D{C٦[Uj})U}u` 1M9P\+ӉrEOIDžl'ϫouSRCEIalVQ"tg4ŀ4/o,{4oFU&j˺"lmUH̅RK/mAzp.46 nM~炂Ճ%ch6Ѵp8UW9Xo1:V{Qb>7*)ldʅ`ڍIuMQUob# j+BK,>d1l>` i>v)R=B߷>p:۳Z!vgŒSYk1ʬIDWŧ*ŸB=gW~<΁eG/Q[5N-r9,YKp_ᢰvK[X2]]=Q8NFU7_ G(T"QGb0fXtK(hUE/׉MJEaR.\rKz֔]s삒IW ,p HTZXoS|IZ\0FTEǁPV`Y5RZ1 TɲMZ12dj"^685%)Wl!﫴+UX?ˤ)4Dvf՚>^]Bz ~4yb5ε0Avġh1>]!2f=gpP \SQGXtZ~_Fe0Ti bX-jfټGzb@[L_Me4WK.Ȫ*_MrYcs $ޡ]Rmʹ#l6{n^|A5vgت2ٔͤ3V̹*n[Q9YdF1& -EݡY֠n55lHm9A Ɣ'8)71q͂}Fzֻ$2۹$ggSick향[Ar2u+17}F\YBIW8 "u(*?x ]\m$ƿOv|5M~[QHj,mFyӞp˲McP"){1pdN_;kڹ0!ͣ (VQ%k>7 8V.o y;߱ 2i2n`\9ڎrv6]`t0aC(.2XE|*tK~W8?{{ ge)@iUҊw6'ysD N\?ɼwxځ)xkf3E ۚrמ#{7 ͎N&.}#[}$$J I_Y0J!>aG փDV2#a# jFF%.}_a.%{ 3_ <~_(~WbBT/njm{8`4Rc{43TϣXOk_6VL;Y"qHkӱ.ZK آ`cb h=쓐+V(L:&j%Y8!>GPis8!{:Auxw$ z,H&!H m i+M$Qb$bpGuXUc^%P7vi O73nnXESzWQ5+V օ~~9N(Rv`onrT IL/ё'JčrmWL+(ztkD]S(Hg드e9|:GX5 ("[gGsNHq~,^Qw@5CH1E%= o&s5?bލMM`,mA 蘸PDGLRdHsE>(Syh|Un͔hN|\ZD"snG{`^_WP_~)p'9 _X5{'4dBlS5r (0J5TP|99Ӗ胈rj5V4i}d; Ÿ#yWVCNw@G70UPY jb>Wav҈e#L&,8H 8Dpchb3)[g.Խ<&ځRd?haz?"NTE*{_C3?M E0 ?OKa(c]QMI#~*6g  ) "Il$jFS?_h%va~PׂŲlf+ƔjVsry0AeMq6t67MdI\?BU4)h0B gљ);WO8&-$nmutx@`8 y< &ee)E;)"$SJ4%*8DsM}XiPu.A]](ră`s^kPiue\ UUEr=>{u,ylB Nvrg?~[vtP&G,$b`%> nPQ19"ÐyEo`-?RI5`q0 3X&1עVe:tzC}mM{Cȿ0 tRCSH$%Oztx%h`$g:rw*O_J|ìنDQ[t4JcIs(EUXT]P,gMP8* ^+}t*hъI9 ˮlPl(c*$t\IȥRq 9D9B|2@,,ɛhVEAcBy()ٵyWg$sdo-Qm[>O:Զl;azO"?%k6WKbGQeWy]fBM*rY tkAcy${t %qC- !r. ϘY?̫Z# }:![| Ӥ}vKWF]Bܓ ;+K/YE@PŮs elzj`VWwZ{_Ln Y֦el Q 1g )&+{m^J&6jÒͧ6#0 SX]= FWgg8IWiᏓS~ɨb4f\d$}C؍u oyvt|.ds~U1,^qA=/B7蘒K*}xSw->mAb{9˂ʅ.bw^I3SR]7ݜ]ED=Z>5,xAm @F0*kC1iQ?A,C%fvm }@hLѮYC]v\"@V^Gv I!S<-z c'ylȱfq4[^#Gn O]0`MFDNeKEɞ*|ͯi6("R‰&BY8<>k_6lž{q|uɅLH&X(8݁_^Ssl&fY90Ƽ+mbwkѿ軈!zcl=NYg< ll㿎 8${Z]'t_w=| YI?1YDz < PM%E~gn7]̿I4b+GN&:xM~c sb]<}Ƥk/Yu( vhG01F%=ZËl[Zzu(>1Wio|N\lOiqZ8r̻KL:u-aC тFj z"q0rqX2DڰByga3FrUii_jL읎[|mfj `a-)r`԰$"lw -qS ?o20ӽXJegIj`Xw{vQB!3 !MnMGEB'}7;]. L5IqWP2!Sf5p[PȪpo ~{B_1 -@c2*u r晗Xt[Vh/ĸ{Sc/{fxRTIpvH<>,wkǡY`U r+/'M֓0fHa8WZisTmH;"UY=')w_b5ez-9懦/KKDt %{5l)qi!Hl*@C\oK"M۳)9+N`76"@eড;xV2$Nҟ-M? cSIy5"0CJi& -~)7t)± a>; u chGٯ##4{աJ Fhj{ru3("1?KӸq~92D" 8>¶ejDfe.Sʀog6p8X4V;`]bF"1FA6XiTGVXaD9-:\Aoj2Ą@kU(Wн>xz _ $IPYdg9:D72FɬSN<چlw/'lB4taWcdc[Xc-ߑ˺KZ$kfVW:l1 ûaXMEG2(uؕhaB O[`a!i%X*Kfۦ'~16K~G#OjĒH#mj%Jϵ;_!ZQb_o'd{ Qk{V:Qc3a)u=i =ܛnq m8Gr?&PA'Ɖ 1khtϼ&.YM$EoZ,6~"ρ G֝}@y07 zzS{{wà 3C?@$q./}enNh٨ _:sIAgiu+%>B2?; n謿굱@ Iq?Y @PI)L%?Z"zb8VEVٲu$=(%VIMQpCAjpFO,7+ w;6LpF&oT4U*q|'˅G}2+͑wKIAR\g%WQŭ]n5D/v-V.>%yȋR ީ3܍A)5h2=Uqdd_$)wzLQL >89lڌ"=H,qX5J,r}ƵS[ݮԸ]qdoO곝_N9J~;#C]^J9lPMYA_ )B>Se\*@LEXKus* ДPR0j5=@p %]tO>^sndʼ,lE3RMT_M3hC4\\˔J4t{iD*40 b_yQyV$^Ը:Me`?\K)frm}Q]b1 ")/Qf&1V;>M$T`NY|y*hD96B[鬐dYosV츟 Oqx-Zc*FT6VbL`ج>)>b[0hH̄lfp! (>gGkG| P n[D}q̡ҫ<ȷF<~:_G>%ꥉs乡q!#KS 4z7W+D0:*nl$_ ]ߘ\Hq2o^q9PP2?&j0ЩX/:{PNvrSvvr x{KU#;eOfBFgԟڬWhJT%&]<ݢ'CKbzRN[>!rF4B]!_4܇ѵ\PAw6ziC㫿,ZdtQ;JO׌^'"&~ _mʜGuH&U!' ƑL61\d.Ec;דhμJ7R _(ni]970c\*Ishk,%|z$KHIHˡQ1վK/NMB[\tVHr `z̢Y B@(-K ] ( pG+ڷ8HJݱ}h:(Aa3jܞ s{gJۿL&khmxT$" dx&Tc4-Mxq 4nbkEf6(uFۇyYϫ/̬mCa3 }~a@+hӴ-sX4.1H=TUp F -0>R)q^97x\2(< nkK p`q|1K};Z |L&{Ddޏ%T 30Ob4Sd` v5D#q; yTT^ ;5zJ0rg$\f1-i)C)yH ,S}*2 ɨ9lIAex%" 4~h ?x/1Ė2⾌TNj*՜O:vdVCg٩MLc#cB4(_K#SQStG}!5힋yyjKOsO_Gh'NhϚ Lu{-Ah 6!8rBѿU1( Qׯ=h#ݻ'mdfBhv6PYL@6B\Rii /C\/<8q#8EP 6=_TsdX7ûFu,u!bOmPEjB vH8oz1U Ů%D^ޔC9 vkǽn6+m * A<Ӂ5)gDY엷=vU'XAڒ0_.l8tޑ pw|}Z(^Q8zlUG\MZ®⹥sWnD& s+%Zpn)m$&'D^!$pB( +4ʊM%h _ˠ>bb?!3C%M UaclMiح cG-L[*AGe4S*,m],N7E(? OAl9q=TKENK+ dՀĽ$^NCN.'C!uf3|!;D eZ@qp<z#;RB *+QlO-aNSCb8J i:[` o4 Lv ml9AdUwc7LIn擈6ȥiS!P˱`RfUzGp/ 2 (z/JAō(A!TG?\WOOAmn$=4~r%/aۉ 17gsޞ-E~,=X ݷ%ivox;!e~a #_n&)=͝ k&`+fȐ#}b 7Pځ-ًF&f8IIDbہ!:*s:Fa}`͟آwSԅԿziޘگWIch.Y#D@?)xm'Df.R݌!=0cd4w<|auxF vY"xi`az0b?3)X0snlXB75fB8Hp"#='Pғcz]W  O LB$H W&*__٪re+y!!&;Ȝ $fwhpy^=I,^>`3 Y( OwdI`rT5QN ѾIK sgou0O[Hvnv3pCLOTT%76pHR-ȳ siQ\ =f[+6K͏&]J{ 1mɑ`g/Z-=qZ{7j%J`#C'[p3&vN?j5ڐ65N'NgeX/}4d&xUxLB T$2S#fg#Gֺx5ʓRNX3UOs$6LE0c։:~E9}l֍zQmbU9 AVu@1*?*. OJ66 >e(Nv6DRg}LJ i?9H7H,S+ZRAq٢ fk7#5="I)鷔Z\ Bn2w<8}fN6#9|sw(Y^vR7%h21͘kVh~1>xx`oUˉW uX 8~#T8Q7_$ZE\Qܟd!PԚw .(."ڶ"gP쬴iie]4p`o{-VB띨2PSw5Nbb ]+g[z6"3*L˘ZzCʴ*8%x6*Xe8rߌ.=T:\:4v[l&8eu=J.9 ~o$0M$7`9c BZXwtCޭ{yp.ԜQ^6F"ȱrOʷ[x"-&K(!xՅYj_aR(9~E'Qĕ6TjHܜѐ~wRr5w5gJdOgouHֵvGLCS+;Ւ-h&Ծ4D" @}Hs;gWmhaIF{xP짔Q, "VXYÙ&eD䀏R|190\QBT*-`SP:»[)7'1EE$Ω7j2Ipb83'N g1÷qy VZMO5׭ik)yٍEGU" T=M0"_^== V@I QIKCX+ޫWe||ԞfH^'Z>b^fc޹n+w%C[=c~eXj۱g9tbt%]{O* ˬӯ#ivy)Vnk-ijuq+SNOj$5F[^ȎWzwɤ(c0>*U0Oڇ.l^엎d#dpL\}OzgFL,:& Cƕ>-2HFM}FQh ̈˷i)D' { }s[-(ZTc]ˍ78ԙY|:cTqaI-'^Q7xQVQE92B,X٬iDf;GPcQO;, A?q3+!ȉ%{nJOsSzi,=[ɲaCtA4O5KMd!<nLYĩp,AoVѻ2K=qקIxՊ =hV4V`K][t]CX2h |Z-wufEHn58/N a5_Lq<>Z?Q'#*Qv W@>*N ۨWMO |bzՋ=HEhX dh?fXN:}5+=-v; .4_j<5ͯXY̽׭ O>\7ǹs%pR(j7W$|*ǭޚ[qZe]g ]J ? s_]bknmRe:hxVxc/ޘp`n5n*>``´Vwe{.,Iu QtVLt1~=%GmTܪeqdK37F1d}Ԃ&k00OF}6%`;ٙw +&[O0(}/,sQbkv!YN,3/56oHhLRM5uM7a3+TU7f?C"(|m$f/0V ǃwmtn阨wn4m+)K 823q$MhX'e8T,|ukEKB/w?>X^wgT&@lPOGGNp~fNLd&YTDp qVfꂐz5mN!PRe;zl"#Zt]\:N濝2N\u0ʄ%Xv ŞWMhחdۯN,[S<pShj\1E 2 w ;iPռIfyb#29w"}0>%T0&%,) _V=N1cT!’uaʑ%;ɐ$[V5 ΀ ~]¬>!ubYakpgǨ[:E p[[vGHb &1rvCϦ]Bb`himԘ9 ôHZΉ⇣䚉u~Ig1{P ܻg ej%!5/ѣU^tMEe ΅䬭J}KE0yYg Z8#x* .mΠm-*_)E3!i0:~ɎҖ:S{šx[QeU12.r۴[}Ksy$b#2*=xOc`uvRuζs$*5ߋ\фq𽯒t71R{o<)&}gU9BEUQ5Zi.7Bx2p7ޖoR"6 U\`&a[DfTCo<̳`_O#,|_ܮ Of;h()㊂(:)ryi;"fnuʆz]4ƹ3 ri"h(x|V8VϞކe{9.PR[=z2~ &.vt| -zϘY(ƌaA|YP ]C}DJY|in$fT,jr떀dOsMw%sX@[R IFUM#4HMΪ)dIh(ߩWR-ˊ6$,Zgֲes=;HnKw7-и3 jۦwUgu3 *JCBHeQR$pП^^}ovTLċ%I)oۓVj>-ѹK xdr_V(OΫ^w%}zR! ̰\Bݽ ο.DUDA+Sz ͅ =])wV7  HS_\کnuk3 qx77G{7MHp;,~=+4*UsDrԐdBt+2Dc X#JRt {O 4CX7U A2@ЯeYeV93ֲ,0EjdtZ4:Se\U9|kv93PO; $3G FvyVBҏxdZHhGd6K{e5ܞBY6o1 HX$cFAD tZ@ؾ{^>,a}Tdl+ԍb,;vz!{pE]xt1hY$V&#UPk)T ץqۦZ6cD6L(s UvVstF cw{ȳ`p LPw@,Yf1G@ >l.QJ˱u`v7"?ܑ͆&ٵŻ|c} B^54'T$g|F%/Tj·6VLw?yUX(W+=( mx8Sg=7s!b*\as 13`e?GYK^5Xq>d7X2 VmspG>"'W=WF[{=pai|0O]Dm dOM>;8Si͐F: k#D4$̌_ nL6,M3wl/h4{Xz.D9HvEd| z>2 N Ay\݆|-1STޢgs?/#t2 Gܚc[DۼE1thAzK8{;C312VGDzM/&n 4OD`G mI۹lэ u8tj -ۥ? eDĞ+&*2).SZ ~\ԢV_fEO3Ź;l_\[T`M  yqXVK$;V*iG8(4M2<Y񥣙qԣ64p[d93LM11i\qթ+DL(F.6g֋_1QwA`Hj"cb,fMQ5z o g $6 {pELqΪTvkA ڜ[4yͪ嚟*ĬlIbWn4̴A]|UIv_5H<<γcŨ@Z@gQc;zK>ܸ)wA,=QvsuwCvlK.򲓩IT SJC( ;muLeMGP֘Ev&Kn1ɽ0O+!l#ڮaL*%Ϥyh%GΐXˣzOO7M/(1 k=-Km!HU,kO;Gڕ~a yܵfkcTX%=_IJqv[CeV@Žo=B'1~19 ~Ä}8Ò+߾҂A׃ץe諑2C m'3{іim᠒B8€ɆL~ ͹MS sMV&hM5O9}qSrκLC_C8BG$, &}d-;Oծ7j|@ַUb&]IB*ηIP9f0c(ffNb2?i@Ap PhTI洦q,s/gg_x ^&qxvqDz~08M [V8^6tQ"RH@L3r_Nm%r;,s0 VҸ8U#X];pBO:KU&LYW{LHzkJ2M9 Z_8<",R.wretwz8BQ팣E^yG-B_#cXkjƲ+0r"Me_M3z $ehZX];O %5ds~KokPr7oF`l|dhgcS&KggOA?->YBY QnpE[4gI ]tt`*G(( D2Sd#—v hyX{P{G֑̪lIBڂGwKs -}[WA ~\u6} |?Zi@^FIךlby|%k2&Y YW/UC% loD줆峘'Z>H-M{-Ne-= M{\k-Ӽ[p-kRP֕29NZj@%l9`t0Fk7upE8d3Eؾ*i@#er8--hT4"Y׿$F}رTK1mtyGbX9TYO0;BR1s49;n*015~j]rS9ʠV>̬'-%w,nhjd6{㮲oW7\nRC>\Z%A+mCl_F X`BIr[VA3ѩ$1!~/PQb8<^| Q*6o Gg`;k9ȀZ"Pգ:a$PnJ8m+cބGF!~/|`:P3R/0ly*m#4hAzZ 5כ3 MH`xTۊi%[ Ysc ]WE I.͉ 䜸Eɹ̤Df7ǯMtR> n5Ǔ#b v1Fȱt2]LA#S-^ML ??n#N"O$=wc&ڃVE% fkdN^y d?qқk?U?gց:?ӆƭ+&%m_xRHwrD7fO̽O aNʿ?:RrMciֿ&n!#j򩝸)S?tV B0=%uJ޺- I,P S9I^b5$ĉ#*\Ʊs=pE3)@Ⓙx0\͖fO?UɆ? 8f$f\m b֋42 a!W<_COyE XZTb$o%U+žbc~7ɻD!,=UEϣ*A`IX?f5']y-sI?ؠd9>*Qs[h6Ծ阕ZXs_Cw¸j0/՜9#&=k%,{HCAĘGn!^0iuԸH_uA-p]a!&lw( W ܰ [~Xio헌\FO^cٛ0+:Y<ٍ͐\e`K*Ӓu 0K?9c{s/0[=. )~7gV sf74줤RY> ;)[OvJ]=/4U2qw@S12IA@mËM"i}uXC{:D]єS'_X%&7"҂r%K6Ha*h꓂>4)8駌#(ɓ.qx>2FcH{i (.NyAE+,ulӯ]2ƈ#cR%r4hR #!p} &$?z5 nܖ+80d“Za:LO XMX0i8`qʔy@i7$5 FOuD3쨏,[{#o<Ο!Gvpk TEJk̾fj h$maVߪߡov2ub%wvP~\~w^#Sorl'hֹ5J+= ֛75z'1Y~^i{S#Fk4u7@3,‹g<[#0_Kmx/L&+D GT\z &p|ozĖۥ =Ky y/R sVuG'a+@;ۙ}S1kagwJFSE#_ "C1(ә{#@3Dqa^*x~뎲;i^ԃ.bpjN$;xysAIVLx-fir*%i U8x5RON%4;$ewt˹\cQUSon㩭A(ٽ9>4RiHv2$mp6^7sG{,9oՎ-?[WG hEFߙl܆!H2wjYR4m-KԷ3G@i5j╚rkT$ GWNSR҇(#enu-"dHt`~E?˔t5'J?Rc nh h/we(2>yz/]2_axģk}`(*?Fnp쟫>Eٝ~+n-s$|P[kw^@02[%v:*L]3pWCnk̝-vEƒ`^u`n*vUyzSlsCf]Snx؊u[C>܍BSA(Cҝ%L"ԛuj\%Ji>­I;4nBK4ЧLٖuI&4L flʌGst`3Ywk\s'SRVμ~(lC:F٧Q)PWU#6ᇏL4+X"6 k4ɻi/wZ{Ղ+t$'ְoMq[` edX,i1Kс>u|<+m+3( VAe#` ˷'WM-[BWQ x X@©x+O/${eb4qA &3EYx:zX7l/C+B"+9BXH;NDas|?SG@bh9%Zk uE'! M8v$märtgF39gLtڕknX[Z|ٗ+U]{t *)G]nI:`_Z}Uh^zݩX m e"g?&  uYZ/E]]Mc=C o'8=yXQJ+$-RN2o9oEz4mt+͐UW a;U CJ$y5#V5vdd9]tSQ^>rIWpgUop"л KsWb9M+a֛5TЖs;k J{׻b]E&4i8zHgdD OgBaŌ Ek?Ί|ԫ0YzNl T6@D~qvz#ϼ˰iȂ4e~hMR :ݢJ@!h~fX^K 0Q 6mȖ#=1Fhiƥ~h9ׄ1| [KŰX<׆ W9_l `=Gp_,>w {5z{i@@-~l 8m̓X?{"Z BIF^0UILv(h8KL|Ŀo%Ql'\A= :aU*@MhA#mjAͳip2*ȘEc4x/&pH`$G8w!W T.hwhPVb0ꖥtK}"TŅPAA+Ykl}ѷTGN|q ?&UΠWhҒh6>8gW\ʻ[Y'o6kB W [l?38%49l1Pƛx%%!`覤S&!i(ʷ hUKDF(#D' TMwF]iALkѫ_!_; dEƩ0֌ְAv ‚]b}>Nmc?}~s5r7c}*z>;1bN; f~`ݬ9ح#'[A}'C ;hoV:bk3'6AO `"gwaXB&9`\DCTtk,1fb(o?=NJⱳp5:L-E7Y#E3Qj$h^Ol&}=@ tY sN =biϴc`ê[& Ox#lmW3q;r2XuHa8hY73YsôAʗchOހ#Og D(W4*Iͻ`_qz?3 1l$3lI2S' *^ ~NiBd_ھZCp.ѨUoSFw .-l#y OMlً߮5^.DC٧0@n l8J!/}hI3S M b4D:.#9JwV;JB;=S5^oH ӗ ]dT()h\~*7CE4k{Z*"ܿT?5ÃD[ng;c{{&+AT4 sz?=IXH9t?&BI+( @ߤ(Q[CRk:uUv>#юM1WqiWӞ ZW/p McS,pLB(`P2jd'R7KjMSZ~l=G2W *?;I_ypV4Deэg:r&<bI^褒M*"Z30NNmM]Zy{qM@*#OJٕ8ċ2sq/AMr[p1nsL&r#f\H<*ɟM&A4V}z}. Ϫ-ŸRtB M۸6,Ο`etbb<~wADQK;POmqξ+m9f ví[V`ɋlJ*#v-iM/'3/]nD Qܼ5ryjtxb)H>'eDiK  ݗ &!Q5Y >u&_oKUbsS hj~BxRGwĨ};X~6J'0"Fbq=T^ݷximh`t?$!Axܺ%y$R۰j#/L@gbriGbY5R+sH>iy} n^_r,51,0)byFp:kks>*[io_\a{` d2LH{XP`7[B1G7I,DV<qdhm'OɻSU#QQq`>V&`wnYRg! f.1ʬrkpoi-v94O<e+p{e+3?ևO([Rm Z"n5飩M"2 WbWx-&V*r+MQ;ܝ@ *=;+-A)gDspЧ`_޸\= Hp= $a2fa5Vˈ`kgAm!_`V1ƒv^c$(INgie&[Oh/Gb B~?N9`#DIgչwгfq2Cc@+s u?#`Rr2p)h°F3 !7|Y' ؗObtD]JKVs)ޚ> #;$^Dy>9\,Eb4^#e0x{:/ncݍ!.qyMg_{JoZA+s͡QIkTJ)ԮX4JA/z}E6VG C|t8F[&~d)%~Jh,\/ǸV%ʢF~rL{P Z;|R=O[YI*\Ydc"6d21jYWڡc.mǥF:+hx٘ER9@4MN$uo RNocAƇg7CXKl?874٭. ?"MszJ\a PB-6L}Dܣ#z6{U֊m/ǂ eI᭞S $ KB9VnBz&Rm&AK ?X4eu7a{0· ^FH<8Dg;A`jFx;8ro 0.I[pϊ"-N(V\GûAQ'y3S恡q^L0F_޲#NU|}@K0x`6Ϡv>ִdRBT'2>:mha+јH-N$:~i[Rd/D>. ߾yU4=*L`G%7O6~ iEv't-2> o-т43؊T'nG\&-1kjLd*($wAk*e|.K4hŊ03R>w];4ZS\ChV“>dXĖRZEB5!횵R ]Ձ:RMu-#Ds7u}Qu`S g~n|ȟOSHD]*.'GMoDt)Eۏۮq[{_DAGIm >I\&y=MV |eBK֍ŕ=n ͔g _2x!B3xD`nwqjelZ4R\B5oLxGZgYZ BG!AT\ӽ%BcLr&!=Ow˦$S40n5ʟ'ICdWKTd:}!.2iFx(E4;۪#Ri{3?azn )`sPy߲gйmĀQ|+-&W )#|!5[H YNyMB,v԰]r)}Dwp/C(\svwMPܺZNuj^.].[QW|wVр'Q[UT8B;_|y<>p:q.~V݃ܥqra>WW aO5_Vb&^4DoO PyPYx Y!! qOXIsIV&}7z$қ^qK2.ƚC,llϳ)mi/_u==̘֭,Ҕ6h52U*Av׍;+HY,Oⱋhhrĩ.ȯz`&/'1^O+f\wKpLZAXNuWҰ{|r}jn-nl[ilto"t0u2d GyK9qK@^OJPHV`T%:4c7ΐPY\ \͜ Upv@nKp|W,(rS?rR&q+-MJ^<򗣱^) S 0a peى2B-C'nU4dP"ǖZUeye>KxՓ]zy߯ #!Vl]a\UG~#  j@l_;Aj-ecZGnH5mXz!oajapw6DR'V̭ضHHOA:Җ0ʐp"6ño/[Gn-V/rKm~m!ܡYS"Z~0d>6@mS%IsצbNXC'8 gr\eR3K(YKZ1!I͗z'[4#םPvrrsRJ=֕< Rc$Rp ۞`e]xѨC@Ǯ#)vGծRdaC;j|ʜp+ A`.,czkDCqG^{Oׂ)CLAl?b+i\A]pxdϰW%)|,ւ5͝#=g%.odqky N59=Bk"7xOɜN\;mvpUׇzOdc';i"P i,!r+L~:5!*նsR*ȩy&(L1&D{*I ,VXdwDg)SG!7q_>a2=]lW `BwoQE.n~q_xoluGݺhoOws]#U][q:AL*?LH(Go=+E5,xJ %vC}i6J'Ngbv׳Jb8qEyjzߕiqӍO`i9>=_ǁT>AO<$lA!u-]ʲC8m*#ZRlm~Y A?[9RF!M6K~aTv8;y VU6aUWZk֤t{<]p(’Fʔ6 gpNP!` M|g$sWZ욹SannfK=Z z1֛XfKutc݅B(ry߻M@wNbSB 3M[DJ&EPT</!9,6G1&d|t5a5獙րRnϊM`~5?26Uc| $Gq <5Ӆ[ijilw\6+QlW_"9&ЊG CnX 4 O.CDzI%WO ^H嶺;#>PS!ldjXH2gԫU-]5j2(J<./*wO?\i?g5qtOl4jG}@.7fZ ziƨQ_B6Q+J8~}tȄ1J =s$PpPh Ir4"Cfmv[NעPiɗ#7Q аV\Xt /1g8<ɠjvVX?췆Ѵ`pImR^u(W&IG1rŏ4E؂^_cdi,\ňǢ]pAvDc+VIܿ\Qio,J'^S |Argʒݛw7BA: 6_ʰD|jRHk ¨k ::'La#o#1>}(ȽUj a PAuj; X|Պ5=cqHG|VQ%Z< w3՘asm  ipk]ƌëPNؒgsf.$y$[Iai_7S2=0i[?=>mcϥt:CNnc .Sƨδ5M gEI1q@|ACdxs+Q^ѥTR C 6{=-1E*QJ*.Xd^ pr%P{Fq5 U@䌓;,Z[giZ7 .!)Xk.ٸ1$q'u{fU`Ʀsqz8g=^V7 $Fd{6G^vkCef#ryP&^D8NitP뀎_qXw;Bۮy_n/߳^olgjHҍ!_v_pגf7o8?t9P<(ϭK'rt }8&&Yv +_vaٸ5GbGK[$@5 BR3ѰZrkӥ;cz ʾ(OS`bZǰ|@l9MM1_6k$S_ m:'ٰ`;azYw׼Э&""v٭aB[cfˆ'cDT,&P >X)A(tVϼ"= L1x-ŷUAI&ie"9xz=Oosw,1cPv?Ӷ@ A&[0jogäf`,'|œxn*TIP2Ң=cZ#R/`V!>"l=COOiZY߱?$> tRs']b TWbz%6i\Շ,U3t  L>o3^j%AtE̴#:1gups)l)oAY4auTU٬noˡby"Uò ST[Q& r1&ӹ|)9S, WW0۩ӯ9ҤHoie N!\ܕStsJL&*uwpD?^n(<>S L ~+ɥ|ڂ=a7H*[(K&[8} 0qcȿHAmv!B,F:&TOnZ ,/w[{ˌDƪ%с\˕a@ Rr-aԡ|i^=FdfI 5I W׼c*ĘXXmz Ģlf]0-K:;ҦӔ5V{Ю{FP~Cl x ǹ_H4@0L8AϗնVJ*MX%QWA?qUL)Ӎa'[bIH5qF.yN*j[t}z*tYPcBH?4.WͰwX5l$wOtW;p$.J'O,WFJ Pͷ[Ķy}?wTTb$Z|i}R'Y3ھVi"#F;W+.&?[f`f Jl潠X F.!9IWRf&ZЁV>Qa5D?&C)MS.RxW^UxjV]au2zmWgȞoۖIݶ4SXmt⩰yWIJ_ B^r]'aЉ޳@p)ҽUZ= /Fpbl<28Q@H %+b2a#XC*0J2jhH"YY'HX%:E0&~ǓJ9@o)GۨQ%[c#+nwʚWosL+Ӄ 9Β{bS !FRnQLAүDͶq~ն>ܡ_pXkBSdђ݁~(Zmb9`6GַO?8C?.Ӽ?^<4:#rZ0o/y~-(J6S 67i#ٙhʼn"CCzRx_HT_򵏂5~EJ `I\,n1I3oqǕ2|T\05xeo`($8dӽf^I#Xc}c"ƷE%%lg#% PAˬ5¼1~U&ߥz>dI4ڵ=> (n$__T@;*Etr9::aOLJz` k[!]Y{́ո1~DuLH!4fh>Q9btF2Ax}ÊG c=h.|21Cx;b lxؓ}P%*k8Y&Γw|T`ZFi.3)Yq#Mzff Ŭ wnj?=W2R5NLmꋹZU^eޫ|Tj|g]:]; M*< rm>DStO:Y#,}$sU\d` -.BUD邟qe1& 8;r~9Bؐ&tDh\EL;t;s`8˟1; T&f:.XgWu jn6GCxUCO9fz?>IথuO_مL5qWi|a,FA3$⿓A1F8=-cmszu[U$(|I>%e\ 5LB5!a@E4ArQ!Qr**#2$ f>(qH up]bY9v*܌%XNмu\"( gW"9rkZCTELAnP4ƨjHj!7G=mw'xzec8skj`&}^dmT2*`ϲUс&30!5WA1#! ܋w?7%KÈ؂ 4IxdzR4Sb'b{})@'\)6pi#3ËYلujIX(uM/ž;b^dt](QUT0 1ʝg 5В25ݶAJ/х& '*bQ(x~iL2^mA-Ne}[#GvN!bnC ^W)iQʀP !47*tLB"iYvEB6f 2Q-,@S P~iqakZ2:Lj+Jb(mh_!ԝ$oƥ䌢=#A0Fv$`n97y%mpv*,kw+ Ɇ>L ŊBTPO;'8|q`~'#fڼLF<2LO*&լ Uk1ԭyZfgWO6dN)jpE{YLʻu3U\ p<3 rH"} ^S,L%铼-0ٖ3,Fz9đ~a}>#KGM+:,٤iځ+<(z Eq`|cfFLmj| LKs"jщ1,iz A͚!_Ƥ i5ںsR|QW0Ӱ< +ܘP no>ڦ_b #,R'_okO<.W5ز`ߝ}Ļ09v0Sn4}.G4bv!H3lXCUk16S(vӜ~Cߋ',xΧqU9+7&-Xxe问Jߓa}PkozSi_٬V| |o=Xio 9’4;<)MLGYuiTg^ܵRd26f`iȘ,1J(YnĤT4PK~+hꃐB=:gbo0yO.?4϶f[6Y%1HaR$$Ű UQ%n0ӘE/iC~\1M-|^! hC12Ł hڄ6d %F7ʇ[z&붾Z]C"tt&w_Hzmp"JD`ݒ@9?6V<hjE{#)h",xV?#M+8