libipa_hbac-devel-1.11.2-65.el7> H HtxHFSss ?*}}ӂb%*GT"DqX1SgO_=/m0d7fb7b650fddbed697aa3ef5b31d341a57687f7hiXK9R=MüFSss ?*}}ReHO’P'-{oNnCBГ8< x>9?d " A $88 t8 8 8 <8 8h888(89:IGL8H,8I 8XDYP\t8]T8^bqdnesfvlxt8up8vPw8x8yClibipa_hbac-devel1.11.265.el7FreeIPA HBAC Evaluator libraryUtility library to validate FreeIPA HBAC rules for authorization requestsSgswsvmsrv03.fnal.govRScientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxi686 \ ; ]. :VhUVV:Vj" lb{ELyRUMAA큤Sg`Sg^Sg`SgSg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(2c9813a080ef39aca65cca46a79e78ac6ac4836866f849492732d82c14732df85827bd1029a6f869886906984432a7a1692fd156831c51ac7f872a5917d2e7b75cd6f4eb01764f02d2f70c79c237ce1cf8fbeef874b661705c1f3dc3a21998529e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58b787da9551d9e4e6b50f1d2d732e9bf7d729ad70cc3081723b3703236cad8f2b3c98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830603c4e26ccdadadf00531a187aa4376b93bb54dccfe8b878bfd0916df4df3d3332cb41c619fc9f7f7f4f1a039421ac2451b3cb03697905f4e86be638212af2dc025a62e9e302aa53b592334b7d85abc65faa28ffe555ec539a5b6aeebdfb0b096fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c8ab7bd003ff1a3e51514772bb29ee7b9445d7155a62831f255a0a9aa884dd5315c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fd931848f71a066b1b7b8578978ae0f47473ba293b0cda30a6bf2e3e20a2df18852f72b3b729b00e09a0e1e36450b062178cd053a56d07e9a22112893e54f495658926d0f3dc348b5e0bd90d509fde6d32eb0253c7c65f236709275f81a101f58608ea90696dc3b45bf0f9754d8dc3f5b5a1b0ebd0665c942ccad76b6198a0dadbb6438d4a64fc46474722848bfc9c4019c176c452ee6c2d291655a6a547725bf41be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562be22fe1d60222ffbe971afb619cb47d8204ae04b807279e7ed8bce6e7cc59dbd44bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a45c30cf69bc111a4bbd1d8178c48ccf1910042555584c93abad31d1fb3fa6352215d7d6e5c85766905a85bcbdc6ff6a0471c8498432341d57983dd77e5b98c03d6b2861f9b329557e689d5f2f833ed2cd1b8187f442967c55494be58a4538245e0866f4ef1f24d454871307d0fb742cba798834b097e2aa11326072171d58a50b1f95633f010e90231ca96de575a1884f00fb1894d7f66af8fc368226ba9bff0339bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libipa_hbac.so.0.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-65.el7.src.rpmlibipa_hbac-devellibipa_hbac-devel(x86-32)pkgconfig(ipa_hbac)@@    /usr/bin/pkg-configlibipa_hbaclibipa_hbac.so.0rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-65.el73.0.4-14.6.0-14.0-15.2-14.11.1S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456781.11.2-65.el71.11.2-65.el71.11.2ipa_hbac.hlibipa_hbac.soipa_hbac.pclibipa_hbac-devel-1.11.2htmlannotated.htmlbc_s.pngbdwn.pngclasses.htmlclosed.pngdir_306d1f7c2316132a5a1b654ae206deb5.htmldir_428d51024abba00bc838cf4c5625f90f.htmldir_68267d1309a1af8e8297ef4c3efbcdba.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pngfunctions.htmlfunctions_vars.htmlgroup__ipa__hbac.htmlindex.htmlipa__hbac_8h_source.htmljquery.jsmodules.htmlnav_f.pngnav_g.pngnav_h.pngopen.pngstructhbac__eval__req.htmlstructhbac__info.htmlstructhbac__request__element.htmlstructhbac__rule.htmlstructhbac__rule__element.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib//usr/lib/pkgconfig//usr/share/doc//usr/share/doc/libipa_hbac-devel-1.11.2//usr/share/doc/libipa_hbac-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryHTML document, ASCII text, with very long linesPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedHTML document, ASCII textPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,K] b2u Q{JZsԈG`'G!n2)0F+9Th^ +s}QB5zl&RhIPh 4o%?֑itO0ZcX=\Å1M$dX]?6k*8Pt-gk?1 2M]5I/luIUr_N'aY]/8Pbg(OdA4G*dֿP#ʟav,Kg9'eDL)Ju4/ReJqVS$s~za酨k~N$A#er'JPt0E mwL@ 4O<<Y~ 8:S(u iyCrRXҕc2oTY3}]HAùqqMCrQ= KS&58kֶ++tiÞXp| VSCznDE8-i;;67o#?߶KaH,Xe6Kb-u"& ?(ZX)f u0o5/pMcs qԥu!'=ٓ*Pk7`3r(U®DP7w^l0ay~uM:\ rqA h0lf'=ϣa$Û/\d11,v=k$q^u6cӑ) Jԋ;5g ,lYQ+#8u+sJL6v(; YکwAxr˿8l{tlɑ01.+i:uBm.gL! !y\Wr ȡ|J:LE%fxlNȓ^ 9f*@—(3Hت亟̛샯9P?c9P񴿈Ī^2` ׄB%0T_#XWXn2h 00bh!=OMpm_9tgDM3`bbdQne͊c>sM R:"ڌw҆! {o3c0Wv{p%9&Icb2xkrzD~L^`߲IG[)*TۚKy#QF@~UH=U*r/s*-+èE &ohNOV;,+m. 4ev%eB#*oaiE"=-;+Nu1kR#]Z+BY)Y4xch)^`~#ADR;4 jI>Sng\'d%ô FesƠKyydi[ sfn"%0=[r<3`uYb[?Rc[ )󗶞PZXD%ӷf}M,^>6\K&J^YMox/Z-ۚ ~/#tɡ%8Pt쬪I\M|7P i$0P: 4/xXџ|04мn4/ƯomTQbod *sQ֣$ڰf?hTiw*\(8.I`su%>Q}A)4LvI _eAZ )w{"Ï.T B6soCvjq0,EȸABaD kNcuh(0IS; UwN,U?=-PV,,ϔ *zbS.Nn,m3RcCƠϪGhOj<9Vk BH1!  w;s#{f߽.F bt<ޅ'> vX-pPџCp,ߊ0~IvaVt[bK3.dV$I aXYjkquf7GOގASFSuImKp`O rV\+\Y/PƱ[&0iU=`9hB76e@)iʞ}7(h ,eDع:И9R<0Wez۠I#HSb~;J \I!ޓԎ^= 0m$'cV'&X9VN#B{LK\)&CNb ϊLbw_.C(& +? mbi9'@[KU]Y(hZ̀N<6/9"ǥ͘%64eUڹ=Jq ;{iz43PȤ_hK^4{oN+8"%&)kh410K"?G~Oyc(yRK4[j_)L+ꄛ-xL0Z᙮ q:~`R0ޠ e=V3\WNЬcM n Bg:ԭ /`ϐ4kJNrq^YZ1dp Vo;Sw@uE7>$ /ks+8NՌ 0+\Jͧ [9E>fKmvBubju1t >åI.L3Ҧ&R Î+OW' #tTMEDjb/cvH;ůi'P0fo> 6I:%BSA#N'%O+oSTUJ[\x=u\"S8xbGR2Ag`źIx5>QTjd "r =h泟nDAg{n `CfZmLǝuX'|%"8 TaJ0 @uZt;I]Vo$k8{DAڔyzզD69Jv`gvU5Pb\Ox( ջ}_{:uAV߳g0{X)]tva{ucL.fa8$/wTN^Ŏzl^ uq0qe&vf9|>卵ټvA_Aq*2'wJ.h"Ĺ^kBr/l-$5Sz&re_(m2%5]s_z`" t. 6ب/ M쫅ZGns)zAPSHϬJ{n/eJ`ud"OVNSJ~ 鷆HŲ BmnZ4/=@$ȸR_5ϣ~q=}le?Z3=?ච- lxꄿVO$l%~7>lEb `I0ڴ w*q$bjú>nv8[ YAdI gG@=LAkV);,/vû~DBQ\= -|sjbfՋ;jwE%$Rٵ` (Q$_$ϾL0P-X1Ѣ-DQ! xue{TsZƸ)/G՗8 g{êC%%L{9 ]r`[- x9;h0kX9\LNN;] fV*xUqJl ^VWy[Tkq1 4;M; v(9ߐ$gQͬ?oRz =S/ !2vwe ^>\KҤM9bt=/[헯5u5ɝeɂ1by31uOs='-̎8x͡>-!<$\qS'!|e)GDZr2(#k;sĭ RBmvUu&'ٙuB8bz\HqGo:.08Iާf/kŃǜ ͘!£JD0k ܙnܸꈻLBJk7 :Pc@t(z0~l'/ ۦ1[ }P%z Q2xttL NI5Sm'3Y+XGsy%U M% /(Qz SN,3+w3ߚ+R3zSkԋO wPkkS@m_X;o}K |wFܫ24Ҧh!f Aap A]+ *"ѲZ #{O߅(Xx>fd&xYꄖ!Zw(5%\s]B|["eVn"h=eXpP\Nt N ,ߏA'P̫FtJ3xw= gV:O‰B \zo]B}!ii\xMۦ jAةj?Q!׿N/+'n=c|Fȹ:t1!b,eǬj_T[EFCNj3'>v%N:!Vw=f(̓|\MQz޽/ s4 AH~:{rsN% 3APE}B-tKm.nk?6{ !ȱ&<7_!Q~%@@wu6{w v̈jr9'hR!is/v` 7)AD k EMRݪ'/D{`~#E ux Hk+UZhoDZNӱOTN~Xy!fV ,FӠkH%eb0{ %6a"J^ E!Vy *݆2ZU BA痥!z Xր|Q[ʟLJfd~)3M-\XbBgB"YU uzVY^qHl9;e;hd}KnNY 3 ć?-0C^mZcVޟ濘Ǹ OM:CsKq}IY an!mb2HI{FЙTJ(Vᄌ=P`F{2Jmt$/}& Uƪq?P %_|Eg@\R.WNs:Wo/ "#w޼7)EB Y c3dLԿ0X-oe./ ?'L>$'!s#*YluK ݠSĺ;V`tڧ1?C/^ i`Aj!zyȢ jvK+R.Z.x3y) =^Uhvcr Ro;cY]Q>{vDNٛhp|8^tVn:|~ϣcV_šDcIe~T Y]SEn^:UiqAH2j<+@0nʺ^ iS^Ge.?v!qB,PͣLHȷtxF1]~>/9{7 7쿒-n rLW))$M[4Kr;٥t @ !tMF_y &e?W@/`Ng CD>Om|6Puif(޳IA_į5saE Ӥ]r'L6ѿ"_^ielg M 4gR5.tGZ^jsR/IE+6" #~Ś˞~ m0j"qrPg9=ƨŒw[8GV 7Ҡ =)22$lN b." )/p_ %#_ }~m-&&(^ʧsjЧB&ҿCO,)l01ɴo3HtKUZsBʥҾS;(4{[gz[k[UQuXjZ Gu+UIIF[Np9+YUTlp`끜Si8 c>n2|joL,1ItSK[Q!~\Gd "dnCCiok,5g޽en4"i22u" v :8k OPWBbe2ߊI\cڌƗ6]ϋ}QR('gcVRш/v/P4= u9@#Ʊ o%[N{xg̶)~# +Wc&rcSkX] N WWGR9Ѡ`G f\v*dtb(!bq>RlAJtCXd(@֭} 5̯[~mLFXXvSO}~s*>4P5KQG'Ʈ}Z Rn=RC7jjA_9C`x7ĶU*5W/Z{|"Y:qiTp.mԨy?Ƹ>:ijg)Ī1p+v?ռPè,7nKDAtĔ삆JWs?Rg*lA`Jɼp5tw`߄(nfn:-n1ϱ1f7:j̣4an)лQ2 $qGTj]ؐx>4#vuͱ8krN;`h"p1%$/d!%B/`G)0C![?Gc2^{&h}ȶ Ory1[Xeb9et}:LpGO@R3(zCt}lo)8phƬ9 i{IPg3<3ꗡxAOW42|~qQmZ!2`uQ:a%Y)$5Uw`Ah nFG{4* j} 8\F =s?W=KxMs0@//o;q@A_"1!nwUB`AP&jI>'ɋ]JT\; dsD{s!8!7XNmE "p<(2h/hUqC; 3A(Lk}&FL@ΞgqvJI;A+F;Yd_Ӆrf^$E8 v2Ye(JUqܦv2ݶ5etM7bAH>ܐG$BHMB'8Gm!LbZ|&|)핻QD\YQu@aQY#6V*SrQblyDӒDAW1_<,#0T˾N%iXZNZ& ^S5ui-T9ÊA_"u$q[YW- 6%0Vq/FcG6S]6 GwwstpxlΨ)/O%ZLŨKFGCܟ\nVWԒD6 !Vg,ߏk<boVqpfF %]Z@k=JܫaVL߉<w`SLU |=$mQ툎Lp0J8)E5 WY.q:?~x_!+ofH30o yrH!M( oO$*gVĴ"V-ƭ3Ӕza3^}~^)FI~"> 0 #(!&q{ݎs* ~ԙєXAiI~K6 lO[ o]8awvnA gA83uz$OjDi&iVѥM^P-W(}.y[=86~Cri{ByOkH\|&O.*<2GqK( dm]o .d6~b^ld02Os84aȢCahg6ItwJDtxf"&|G [Nh13ڶCZwP_147qIhK`b}#/*3 ܹQ%}֪KCsbhY!P?UMT p2f.lVw[@g&E?ۢ@a~\C+'^@{p_ G?c5/Tٕ~>|=˞ϐ"-K) H+R%ya c_m%7G ׽wI>m|[ uRbY9or͵ 4+TIPGH9 +1Q> e F,{ln;^=-cXǑ[cu-gA ̍`)E*Pyb5nLa @#*ؠ'MK-Ĥ*npb}Ա3C_4KN;V.Ӈ iߦuLO^07T*C +_kl u;.Mx+ N5D{ a!|k XEê-l r/(Ji[sG vB/ y`qcx"qc-8 ☪sQ':`f9f ^6ZJ- >+ U8"{~Pv? K ]wUJ!5R_rլeE JX,fꌁ)HHfR\Ugܸ:ޏaa UM2 ezq=; gZAC, xIͲP,AzQAprT1,èփgvҲyc0),5NS^ieJ"qP! % "2޲a|<,9bzTtatw3'%Y#OƉC)WE5YCy0 LTqTmTY?0;CB[*NXGvHg\9aEaT/K,#SZ6|259ɇe^=#Q%]Ckcgiʑh%N,#Smy>Svº-]L`h\&J·@L<;f9*9=cx )GZf׊kHڈ~(G[+1}yx:@U*d@3H@V ?*-{gPMq21[68?%C.[1e{+(ra P$S\{0 '> ?KQb\, ]x)` wLv~n@ ޣ= +kǞ+BRr"Hޘa׀lt!tIpұKlȜvs= !~ n;|E?\OkΙ%ukݘ? Y<75̙+z1@󏙋!urBRcO_gO'JI 1>bɸ)b KdgګP$H81 , Ⱦds .LAi @2[B89UODBn"s+b:3#KAc US4Pψ YKwݯKBzW<^{ߧ 8w:1mbz M%kȢޫJcHY+)U8g'@x]3V6Q)/HL>- ?mfO ?yA ,´,gq-:?`["̾\Iߢ&7F8X9@a"ٲ#.3SSTBW/Δm昕#:>\p۟P˜Vls4Lrh4yK.P Ugd%1ys'W^ꛍ?hϤ#BG[_ZɝL ONbR< Wv>/a]Ռg$/!A+k€9qԣ/$ ~V ȼhAM~U)DCz`OzktǏ:(b__HDo=<$Ž)PЋ-׿mc)t:qBr^:`9V*6u c29nx˵h*GꭤIsTl&zA (wx-j u+DGC_e|^~ܲ^"0:lLXug$J҉2zPkXݾ)ު3hy%YaOmx$:Tkh%EoftC:@x~KbT[Տ҃ZoSCko$ as׼;lcѨq .A!ނ5ȆĴجꑴpL*2}/u3u dݫ>o Sw9iLgeZv!sX[P{,aq" Tē_}M1xύW> ;ї,eu|W;qǁL[qފ>:w.٩BGRp)T\]Z3_Sk4 ?;w)> OxRJ55Zjd-K^ɹ3T))a8@ߗ;MLpӓ={6 HuځۭJF9zcgf1`W_ѕDX3LHJ19\)nc>u.@g:}Nq8YHtPrH-lY"ʇQaS9J8@C../zC@ ӱ9MG(6\@[#P+ 2ٮ-Qq @7ECĞF{9N2&f+iBysĘr 4n t `j`LX;2m"ת바6APŤ i+hq4VI?ELFI6g AX$g SBfP 8`a=͍HI 3d(C8/E 58SMQ\[=KHFۜ9= -fCD! 0ec8 Q2{px.j/w!U[3{"Dn+DH7St߅²KΕC-i؂eT]polpv*w*@7\p8oSqY% EZv}LDڠZzӀl t%nLaGA n?xrI l4ʚ yVԇ"~ `Ŧ n+dB]CR>b6 EB.V)&)&K!khT =Et&,aNUb;ZܠyWkb2JtNhc>ne4]Cwܻ<V(%LAK,ª` Fy% "@}Cμ~?]JxB,+>\8u5_ɑA&S7JG^mf6q{pu#;lۮ 3{1 >KPPa/8~pGukgXb hW:M,Wqj@}}K+ŕAUA^ Ep5K%e; qoqXk r:a23,>Jea1Wh+C;SoaFGgHv(yE GJ?),E#\=^NKrA}OS(z1wqJ5 p>ȷ1[ `f*ެE wL-6Dm(&`@𬩣1V[R%Mx\ؕX~'y{tTTG`o͍ BDM|,Mk]I|BBZ&5dmU&ksjeSb"˵݆f-C2JJd L?/u,]Cρ;zmPO,e4 P_P;"bU&e\&}iy'o2M<4))!k\%zqNuM]/̽a`hVku5h}ʼ-3џ-/9kĜxIHI(+wHܺ1+03³x _$9-X 'HIFQOǭNg zjRP ߯#귉l0?)l(CGn19RO Hֽ#5 m(P.oP2J}FK|ݡG]lSLm܇~B&Um?`r~klXj4,%_J ،*θe[IWͨwcOK7y:U dB@[$5(˦\k‰՘*Uidt}.&˯4_*!+6Mg]J(}T<~Щ:g )|V(͒y`]Ӊ7݀ a 3_st7XNǞ`YUl_A~ӹ&RuoTW^u2sDVZc ‰.*H@F˿9 O(@.It3J/A*Rj"$m?r*o s!ANBwPW:6K#`YfY/O˫s:l $wu f/D)'pĐLJ+]g$?j xW(-A*^y*Uhtᣧy\z4rXvpb,=TĀ,:a$\5Ȃ*rF^n&sD QS2Bf!*n֘d`%aq{ACŦ,ç^<Yuz]^-VD5GIne{puwƦ+߿I͎ "q w˖F{=@ \͐+3) /5|(lmИ#D/Հr=vۀ' vw-EeZPbMGaѲjAրjmµԳ6+kxpTa]EՅ`YA]60Uِ ,o>ƖT p;ҸzҬ,Fe~. lG4^qQ/j>X =^"C 2>lLJ,ڎѢAHW9,<Yكwz*kN}jYrȉz(㙟qi,Hߵx^ IfIn/7dEWo ]w*6Je6NbQK8$KN hs5۷Bd0ӥXTKB!~^Դ'ϓL%FKT84DC6GM)0N\ySѾKNEdž.ztG\c)ْFh}طm9 .(z2D&WO>o;#6娹AFv[ad}`9bYp3W53 +/&V^ 7(p!:5䍥e |ppbE ÝX4Hi۰AliܭS\^.EFPB]oبl ɦݝa͝OZk:#~cFrx%y}‡n\D4=Ƭ>Smp #@d9YD'ѷmlᰫ.ef5 ZmNGpl$B'ӊV A`D0&EQ;=$^ZvTpK=l;pM*}#QZ',uJ>* 3 uVÿ.R) uU "27/7͇? 1Aqrtm$ }"=NYjzٻ!zmNjBF[*%jj(kaG8@#3ڳUZg!f7o6ϰZytKg]| PCje ČS \N}YQ_zBf%p`տf|+p#Aѯ0~DR|:PmﶱT{oؚbu:(`Oov!KJH1':tSDuu\] U!*%;}g جUMWR¬yq RGU8$YVfnzh1N)_.dF~Xq%Y/+KsVՎݜP;uNG1SFF]WhE% ;,ICBw' h@l(kbsfB7;v>@ ʒKƂ\k..1|.}L1F͔Obhcp%3-!"bl:/\UA~,)4o~(R{ڣuBKL~-2"pgqlAL K$ ϳPrO#la|AS_"yxCBr5e9ۯ{#F<̎԰}{4 ՑC%^)վ-2*4| /G(7ILPuDtXYTՉ;MRb( ڃhUG|%/&8)B{. {$TW"j b;\tOd|q6Q40 gd2JOy'np~s=%߄\#PXӷ-+? %hi:݉L縗HI/S#*vXӸjՠqGWWYeBvjT]~pH#(ZXwm%'/=`nmZ; vpn )[0{Wrg ")p-!%|ѵ.,n/ƣ^1Ӎ"}R "!")T1hlQ;Fk&:Y3aQN< Qن|L[W8l AA}l%8Fs-/JѩE nC]ҒRZ}$o svL}>R, 9^ENPNk̵kScQQ93eu)ɇPDoʲkJiZ!Y] vdR܉# ~&S-C/o7P9$zV1-%T OEB46/֩Ɵt l͔u?EO/Hq\SB6S#VÕ 7}vƬ.m9}E'J̓hOrZ˾'٭jCHzdlo9rFJ &R4nKK!pJ N1GfWu#1 iyg)c}O,!s Zlݲa/)ni|Bux*t5eݾ50yֵ2P\k4]–iHVܕ[ 4$z1C0;:"Sx47cXHfxzLnfr6כpM?x6 TMT/ `K<{&=f7|QW;Xz_bF%p<$>H>x7ޒ`2z1Sm}JAPNF22v7THVā;`i8z6xPsB(. nM}|u?!27iɔ Z -1 Wr?4x{Q-`9L{Gl׫!˝_)7:8$My~8]A! C|ѵ3ֆ30#`M} Nd`ǁ;Zg/TX$ORfTrtB67HSh['>|[oK(@VU"|swJ{mʵgg.kHE ujuvϠd-^tpga998!M蜋a2IFvVS&bJ|R#@%Yݯr }?iEY0 gzyh*"}/gUYlx/E{uzZϰKCdwv'+ZxKJsXnżucˊkG- ^G1Elxr WEA`LDpU,ۗ:E0|hK-ĥe1L\$5>MjJ<2$KYE蘞܂=+j~t3C(ۮ6c\ijU}µ,WyBt i>IrՊO2Hk=BJ8z(:`VULWqJ}2D 'fC2иA0=rjc PKJ%= "hZOz^PJjGEx@~H >NhZwA'T4(]_|RgBkx6 %wv3X{{y2DBCSub8} ED!IR,JM%=^<IzGz4K9t|E%\PV4ˏmlUQ0M3NC] lf*VZnSo[gAR|| &v1~U臩ܫS8MŨ[Fe׍OwF1zǔ24c/7d 3l][]V'wZ*+U>{fdV0nmϮ`RCgtbT&z[*K?(SB֯Dn\uy,kT%bPp2hy-f})Ti k5?B<|9juܰS6dNgm G6YJ(UhۋP=[ijWs23SREm)h#RL\!ezؒkIzTW,>E6E%ӤczӸܥc6SZkvt?iB8Qayr.K' I[yrK[t͐4sNI#$ս&j6 "0G'az8rzo/Al2.vӬơVF*ք_l-xî[n& Ap4허-@w.gڂv?htޡC3)Ь> (1s/Dm^9; @s1}ϬDS7HpB&]2mb}5 /ܦix>fG?z޼vC5W$@yы-;tg/NG5V~kgBip|zژJ[3gy)-n3k]ܷTʀ YrM쩏n5ڙ0yeg#tcX׌\q +_ZC\! 8} ^\ʭ'rW3Plk\hm[wc,’ժS{"OgRҴi?>揱Q\)4R0u"  ;%g\s \<]8ݦ`+k ~}׾9}Nu{2FR۶ e$x 餠#I.u΃+< Q"91x:ݭN i{}ZC3%nz+ɰU2 Κ]a׸~"X?֙abW!X%{'9.Vn48LAq*/1@JI5ی%9v Ja~=it)Gb /,Z*yA|@7vg7DXSg#'VRbɘl +$d {`9oB%&1}"61g$%[./ 7OM7e`3r.BlX\CͳflA,v$Bŵ${7e%0$F &n z-+ob@NږAY=TMQ4MR#.Bb'l ɯ?;zACĺsQA0B<9+Rp0|2M>)t !6'r i)gɞC?^S*Qg\nإ'1"Nd%C~<Ξ"[~on|R fYrM1t>FauQ/_wo, +nv7+8uҝl!sڗJ^LI.͵Sa>?dߌPw&AVX?0-\Aݖ᧌vl@֬LP.*k A/r?qI\wcIu/{=i~WA|ORH|BakI4G&51 Dm72 ][4"@StSh/u&% S7 }_ֈ rMv߂P˲IIY:V?iDOYS5j+z:LWgȦmJ*md@XQAw%l7qskaJ:`O`ᣂUƩe;v )R[4t~8WD ɁӬ: vW%$=ߝ2 ][L ݥ[qZ fx$VbkKgS4; #NUy.vfzu`9֏V{=T]r'ğl@2ffi[ ȷtuLV/=oQz|vq?G~ϗxԌ~ƈfM0aoL5VɸRΐ?z_05|P~}uq},RDކ+hP(dR:?w7ɏ!=Qj8/e\Cꨂ3U开8#NBO,d:-֚#!H0jm Ƀ w)d{; HL!BKA,,=9{ sSV j>VǸZtVvIGk3VlMיrwBJҺKR_LJ!%s gqKo\'ЫS (,ѥj(Ӝ=RZ!⦂ݝhͺPaTY[ ͮ5:F?aUKsH!؃zp3/Rr4ny4Y?pH}8n%}ڷ>=iO D$?@N뷪`;bݝ܎8h]YvaksYg =^#3 K -yr9^ 8&jJ=# l@! 4( Up8d I"X8>+De8#M]8M k"`d\gNߒ<&4=Œ_|[YOF9O5y#%jӑܵ߯"s鄧W~ <掘yn_%8cp$=:0n~n{نk(= ߓ.Ig?萂n}8LO"iͬm@ K׽?w_mv;҃5(c`|qrƯ3w{Fh_'wi,CKXMKоh]&cnH?*[XC ,(]4OucTps*Ш-hiM'77rB2T?g&NN6E907!76w2cUO6TO^ķ>+\**l@p[6Ƅ|vcXd`IG w+f9clG8:H*ll}stW?Ve:[P=;X>]ɳ kD M(Jep{H E`¶}AkbC+VV |6ńٌeD-Uڵ1 l3sVȎ>Ж k%\w##l!CkP[(e4{,kUh0(NE/BkN48p޳>gF;҉U:J&uĩl؂6 ЙtPFN{YL5ַ &c×&m2KWnˬ:kz U~<<͓wWZ])Wǻa"h=7}u}PrvU`/ x /&`1- 6^#j,oY O[8'-vvNC͂YĎy"/99@$fjj,6#FБLkB!"H0x[l}P^." +k]5t ΩȿB ?uy9#3_"`>z}NV.l 2a41U!71J,B5*䓶ȩr`  L4P*-x k=1%;X@,a JfwR0f;][Aw8ٓҹt-z2uZ f5dq SJ$0N"5A3*R^(YIt&kA9 eM=Q߻/*^:Fl ]$z0) q;ۆ RU;B,OYNmζOzS[Ā*/&DK*z]/cnbOh;VO13z\J%$IZ 'Mkov5 4cܳW? #!0mi-Ը#Ե> $7?Ȯ"l&b/*tN mq} !OO~w}ikiKg p͕JS99pXUZJ5n8>uq-1hWҌ#9ؙ|p~K vњ*e!`f.Auĝ bcE;ż.le|2Rj ~|rܲ../#Sat^ "l0X#S"~%z H)9}spk&̓c)*V(,8[鼠h;M0tYhA)hޝ0ݤzL1idҶH'N)a2.& gE@TN0hEYōmȲ!BwBL$$o$kԻȠ`!㛢\Xt,nUt[+a{k+IHm%A9Y}`˝UۨI6W f8>80EkK0_X=x5 uB?I7}[ JWz2>«EPgGO9BP}2uEr.D0^2h !I1%,f\()h^MՏy6~e.!49+jFYԌޭ`ojB?BjO ] w2ӊCKu An:ZIסp)aF?=꧉vƿiXD-Gl* 4:G[W@e''|z)en:Dv]{sAxݡ<6~ ]3@'ndۙB/7QoۿIoΑ"z J($-[.8b@6'Xn|F3e:Њ4]xɘU^|,sNJf7dS>z0^P8vdDC _oUKD#IǪuXmYRGryk e7>m"0X'޾OКz2v:rrX_p 0QYیw̏|Xbc29O:aRe|Q4]rꭙs(t=mKn}uXk4MI_9~S=Rauo&@IZ?w"fhuߍ W. *}-[D%yHX^dԱ TXUzFmeU F>'iܺۖvʥЋY DYTY|;Pn#VBtAt)7Gaްn5XmprloO➍݋߆<.,?;*5ڽ#rZ;{fMO* I:+.Uiݚ1OӀ/KsZ2.+!f򞂺&X5@i>bRh.aq

VX0ɘԩ> B q`=@Ma JmYX-Iw=PqUZf%B6/Jıgy(wK3ߔ`4̄Ix5:اuda \ 6QA# g橆 `SRcO+ (Zށ?mŌ@^yۧQL{'Dy2.?q'U{h .wAп4t WnߌcRĿ\"; [(A,!t%G[Y@ 90Kwb :Y1z&_agÞ.,G![fluw&x%wohI>jl*uP݉[>}tm_ж."[s$Dxm>6U D<(%"V*+Rc 0`R:a㕌 iTX[~ 3 83J >{eޤ~Ӱ-:8@ =Y ye+pP w? ΍:+7>%&_rOF)ؓ^B} 0QJ jOɂӑSgZU!|b x-c+=ΖAV?;CLu%0W+Ae"Ōe>' aCҋRv'YΓ!IXn /W&U[of?s-?D7ztPqHi6^ xr ͎N=`T;yړXwxOCF5<1Sbr(5O!זqy#APVc4ށHmd ٴP% ?ۙ"Df["o%̲$Xȹؿs/1e)qbh,%nqI L-Ye_C<E'/+ΟΔ1ft"ov'8-{N!m{Ɉ-)W6J[EMCC#F{c^̡^fF){.Uu9uc$bȯ| r ؗT>k^r Zv4ejb]F=㮮9$SQP;\ȍF^{Xmky5 I (0oK{zaIi]kyla{u |sN2솑 &Z"d mz~ɿ9"qΌ5R$ZJ&r:ϧ-/J|paO[$=F/ *(z|0k:]rG4XյabIopVLΒAO~k1$_-ֆy›q^ ϑ=݌]'CL! 燚zM(.=IK)ԢV>20QB ?fWw-d c*X~7FG.]["6 ?a|JO?Fe1-y$ZdZ*E\6O,~oi̔ڍsL/{lW,X.cD|Yڹ̭Dṕ}U^avm1'wdG։OVnL?%4$43t5>ćF ?OTns04a9gv3ETz*fYwL=gqPETϖr@y z%Dup[+- T>T]2&JMeT ,ǶiJjE7Z}#֋TT 2sL;?chi̢CZF]E+Xߣ<8'^;vn0JGMò^SY \W8)M׳Y0ќ~@䔃@t& P6 x:N&K2lI.+Zfv+˩ZCsUN!ƕ Gi c/\-(SHKo~]*||T}H_wc8xm3:cj ] 5`E jA ve >Ej[_JubKHs~#Y qYA&RACVg8>Ͻ*ap5C2mgT+q[a1ΐ 7-l.Z@&s.V%_q%#؊:BpXdT Ub@w=k"hG_#Y8naN˼1*Lr"RƴD՜;0CF7 P+5!#dkJ4)Z ~!Ir{iJ55@r.}, s)1y v f8+ itgut0v00/c?Eb`*$Emi|wrd%uQv / ~i 1aͅi"=ϗì%=[eҩXtFY H.zn~?a[98č#JHɢ)^Nf9=&|<Nk(rUI2#qK@]6!zkc\,옴hI揘IT ?Q|H+ZM;(yj`pZ-`vY}v=0Vc1|16-kv 61xb08<{듖ݕ.7&-"VHПe1TzxEEco!]6!GrPZ?[*^- 0MHXԛJ <Erփo:R{SO !_,>Z[y80sHC9 {" @g_+eC/ʊ>.BSYK6@Z[I:da&yE>t92RNuE6߶ZAK%EopD$]6ϐHX/8q^ 55B(/D_&;PLA˚u›괍\ح?7݂R4F]G؞=ld,tG8"G\mnH yi®=)`kK6o5 e|i;NxJ9vr_lNBFWg_{VJ2~K*4 Ӽ8=|/xmY+gmn`RQ.9pݢN2e7<4&Lcbv[,[S8,|MIC ]_r4dTL^.@cfaLk48i>R2|j7t&"P@T~D{}`Z HG=|ͷck=Y\V\8ߵtW\__GpgÛGm be+C"-=;-ae5t9Ћ$ +/ݘ]ܼA5m 8x0㘇@A5*HF[$%5]ov%9 >j)8\ϥ=S=-1VM{ж7LT͔I¶ 5 <@V6|Ρ"C#Wgu885@ *9KdÿalPzYT@NsI]Bߤq'/Â1,#14MOYfYhŝ\ˡDMwudZ,c\9M@~w ID?٨Pӛ=dG4Ϣrv  EbX>7:M|cv#ROTve.ɸ}3J;z$uk~[( ˇ:l;RYi\Аci]'W."Y~yU_V\x^5NylQKub0JZY"=!]ON!g&VhRnT؞j+u[{ꁉ0 ,{TvAU24T$|p9;sVCwN*N/G2Jx "?ˏg}\Q=81#AIOd*{˶{h<nK8i} Ü?mV}|/f| "gl:hh$iKcYXxA' J1sc˕(g7~>w 6Ϙ|JI}3s\Bp=wGtWvEI&Uŗ@,U0dg0VT+^nX3Pj˪FI}Hx]Lؤ:\7n'y xӿ&什W&ϵ!)i"RT!+%eS<@9,7L:QtM^G]g&΍rܩ Px俸8\b)qJ *~C[pah|s%E\@$>"%|:ߌԃ%w,Nqc*IJ Tlin8aaC(ŹEyDrTDw~J-#ߍۙ/^c.5"8,)5urY5u-@tS~1KpL~9ɻĠ7QGi5(|qG;nBJ4]Y'MI2)jls ] {qS.kŠg2K.)ҐTt}LI|IVjs15/"pN7UΩ *X>Q5~[VFi .$`~"78:奿~yy'seb0|\Iԍa,.\%@G@/U~μI1baV1ܐšrz.eXf}*[ dZ)=ѱ5 dOis4lcaT %xDugV;8Ouca1yCIO@ ZY0}߳΅05FW}kdQ12^BOBb4 !sSSv.K*V8 /h\OΧ/eA5纚=BH(KicsU_p钣T HŒji) p лSB[g ͕1Pgҕ%/D hT@žRk{n +Zݨ.Ei1n ȝ,. '`Q)`J+p7qd// DF+ j"ARt mkxv)K c լbI{`1vc3_S#;9)F)`VZ<@!_U{Sl] wDvu f6Yu.نK"GI*puYRA#3jGN&Րy"A m͇>??V OlP>;:eثc]?͹ *qM0 ,1S +ZdV14 O l8 r}ojVTe]8TO-Ѧ$dvHaJ0ԉ p(Ս>J߄踋ߋyctF X$1aZ I@'F3_d "yq}!@6z٫(t03uGU *i ED;E: ׀x2ƺMmqТ61TD\2iZMxf#o>n8'Sh 2jEpU/o>F}μ a*zjT\ 0O65W~k2nCOьs6I6ϡh3(1:\y/ @C̬ync'Tk,(.Oz#y%nvsKVؘ3G^;`&2W;~57WF\Iv#90K݈]WjiGTܵV)dC'5bW FF#~]@5޾!o}MKȃմT,rd5Ov\o ӺqNrqra;;%2s̴o5EIKȜ^tv3Ç:VHr0Kv$!T,fU8>-[;H+(ѥW9˪&yyДX1LrW p+_ *:&Xa¤xEH6WП Uս\ۍq%"уgOq j|Vf8$d}JJF-v2&7)_MS%G7Y]K<\9`/z:AL'k Vmv*n(1UIYu㰪nwA4]eZWe@}Ҭ|," %n *$,p2~>NfXEc1-l[k~1)ԧ(o$`f*M !v5_IIYkRœB<9FbrنF ɮETM$d:jܫ,?jk<H"|fDc >7ҷ mP}4!F8~]jF4a`l p' ^M\|L?%G<2j)7Ejew[|}ﰕuxv4 Zx7>QWfGG'2Qc6 nг $B;^Z8Xs]%*%{S˵;e* ǡ:o!qS9o($AĆ=7 Kt<|mrlʐ~VGJ={Tږ܊ie W= 9s")R;̝+tz;HTW\fϥ|;Bޝ&wܒ^ r"ORL`I/GKb^MPu*>OT-KHW݉,$:?Rz[ѷn~MQߏ E G+(oSoSqHt?R; sւ ޶ֲdb_di5o B>M~Lӭd$ZRr}41tl\o$}ht@|M3gٴ:srn.|DH.͵B{ơb(뎨9,i뎸N[ 7sϐ5g5t~/j_*7!$IiSWd>eUeHY GM5p)[[0fAbVո[eQ55 PVM"D/>Rǝܞn ׂ_A7AE[&Coxz\򭆻r|#7rL3\1~4,MY@Gyܻ귢p=5MQ>EH; RP:'4C XOF}Zunz5e poҞ+!9G ]Kėt65H 8 H蔈y߇%Yɬּ}QFm,q.$3:քH1)͋'gEqrx,r+Ā:U*q,y:{kzZC #h}(D)<)FXLϳyOP&;8bA{4֊bk8uHR5J8f 3o"0iخĝKT> DzwU& }j$A.sGx]B%VV!Z/8j9R89r:4г 8?}`LܕP`;g|Zq9nO#q=(/$g.|*w%cF%Q9{t(*to27TIwt9$wwNShXGO|]̐g /,4rhݷ-MD|OK#uȝ}$=(U/Ww Jc 91jO`D@mC kFqy!N}]?k;g낃3i#NniKtA |xgϼ_1!n~b$ ̧8*(6SDGeJ<@7 :Zr̸vx0XLhH\&:2yl"8C ~z@>hqZ2d@d[Px!3O4K8a "̐xy+8#ɤZ۠ et!dNF'wN<k1X5#u5yA#rΎ> @V&'jB#ӰR18s8a Q5=/GC5_M9co-Wyov U7?B|g)>vbSGvO6UU 6dE_!SЋ/haAs|okEy;zw!h ak[!aYNxn^R:$=gpM5Jq};=vRz9]>R{k[ v~yKR -5^؞2Gx8 6C"{ ^XG)5iW_…gn>QMax)? #+pV'dw}!qV+//+"G邘RaN8ӟ{TƍqL(W? R~=Dʶe@"}&$"]ސ ȩ}ɻӬ Џ3\jZAF[Q,wCSg>ƎOx) y7Cuݧh`T,{XgKv*$˲$T)!,WHAUdP'>7.-s!!A95ꛯasbϤRQ7*Fz 5k];rJme6i8y+ maI`_YiUTzH^YD#-`gY9SA% ?QWu9#tSrbQ#0 ]|w}- LKP WDp{ ^W|Zr t=<|Ltz"s[1T9a{j$OMJ.m_XO]Kz ,xJC0z{mtR{z0Vb({>sf?N̉.J*`ֺ^;q%8vRϠ% K4EvU17ce[#uGJ.(agzg?>0V^v~&%Z(Z'TL`^h*(2U(ܱ&x#$־C`eNw&R+T d8~ o;㡖wڕQMUđܴo19c`plM-YR+kwy7O(=$>w~Z4 ² =~t1?NWFuF !xA/]]tt# '9fs̪kp &Cv:o_/pW_oD@>e }RaI꾨 pt[3bb ruGwZO2mWpf<u_j79b6]AG)->B\3^Qy3e 2tX3K(qYuŹH(CwiqN u?V~̳,F68MZM7H0j8:ʇ6?@O9cKP!FDɖϣ6T[,+v|sUD5ww~0rR>^ƞB @ έm1fƙqmťHPwXևƉ%C2Yh0@K5̃,WZ7Es$~\\{Ǫa~kR*}\ !D ̓d% 9÷')Z*ZW +h!Yb1`=IOY؍{bJbXuϽR㚫v@AbdM}_\vzVF~a&`w.,tMx{)n̥|XK^ۺpF_oy|fPz403R =A+,`1ˌ 0wo써2i(1%D0~/w0Cw?Lg8cړsG*u)J[$?n>7ohbcZz۶u^AgŮFS |>酒GW<`Q[ȳHE gnJ[`pRc}`&gqǩ-<}`IK7JNyJ^ln`lbU<ܾZ!n;P_PޱpkxG]w02ԘJ + ӗLheVX02JP*pNM߶>D(/M8Vnv!L6a=kdqt[/]Be"Hv;E7KG2HҔ}@d}d(=g܅nn(MaW:EakַCtLeg4E-j;W-rv1!~n+fn+3Q qYM2_\xWGNEwB0%+EB%}(΂jIQf*wZ5y_Y  B.鏍Yk]9#@dL4^>S5r^SdoTۼ2%}k[51ѫcޛ>lȫG8|M?Di%¬JܳGLd5C0QRmf՜JU`}+(668b@ecl⋾櫻"Iřkq&3i7Rk5Obu(u+0m8`%a%a "f/v|.'>"YOA4ʐU.i{%G2c|y+v#xP5^q3l.by)80*|&O&;!M hi 'QRR<(W:1K=TN -ȧZgaJmvjεƸ ?c'pP.85rTU WId4w,4EQ%ʾCPEWy~CJ;PAWu`{]K~^v `Jj#2QzԳ(@ yW?:PICIKYfKY{1 hEp]&̛}9H,35R|2JTwX2ֽon2԰yDQr/fΰKBԝv.\uMD@.~CL f5PPwt#EuzJ&Qc )JhOx׭׊2쿾v|iy#3g\UZx 7NΰCmhS$͐z,sF9Ru XݲXOY]o9E, KD-()GTVs.4ٸQ! %͕l[uHf51Dr6aŗ9[d{^LT}PBN@s;: )(N4H|rk 1$R' I-\JoZ,?ikPMJkIcM+ {4.RBu], 4XD|5%3MN|Cbia! gVYMP!da}rجc DRT"Z*Y97V.u_ܝ.k0M_Z&> w]c`^E1ux3? y_yG;2 S fX㴌OB/^{*ItlXmiܥϣSѢH8T 9-糽śu$"bZSh25e+MF'ӮJxϹNDYLj4ůhW|5q:bqqĘFDā' i%vhWC.(3Jw4?n"X7Ȟ]@+z-= ܐ͛JbUGZB7U/.zJ^QV 1Hk8Ƕ-C 6IC? pIԱ$X۲O׀5m($N o -_.u1dǤ$b&*¿seI0 ];{ɏǃg@9󦭍@^.;#[U#(${IwNѸR#\5CY>Ԙ3U)!?=+}BRMЀ#r(n *)l8m[ w*.vd洊W1(.w1GG&a}tQV^6Ko)MwMnRʜ+kMl[LnZs;g ]ơ\ؒd4 dO繵?E]7T•ؚ&Y qzq(r;9晱wvD>]azs _Ԫs W1 Gw6+34ugd &! i _N4#p5`VOD֨Reu\r (zKPTI1FcŒmL;LUZ x2=fwrmtxu\}hB#wLh/Y\{:jr>_P<913(:z@kw Jp-*/G"ueP_L18: 5E-I >ثV7G6O|W.B5/)8067* :RZ|7KgP +spڙ:I7cj\޾?MmW۝1o1) 1R= ҾPv\Ԣ3(g@>i䙹IY+x!.;weWs|)2dJL@y?ө^,"&Y\K0-Y-Fݕw(*%Μn^a;o/jhJ4a8V} sGg%:%7;'V65Ix-|f0sIY oV' ;P@={5wψ3444ƒ5j"0ߠ(+(=~Q#'6P3?6OSK R HsMO m#<3ES\rjWofB)^5)? ըj=o/E逺⋊p^p5 =RNJ+Xx7jt#g U`^rx>lv~ T Dy&uh,(HNj跼>w{N*%#85q@1B"w<:-z*ąK֦ (`0:-+8I9A[ɹ eȞջxW>`yQg& ˍ"rZ6uz1Iv`F%YL&dm2P(6_Qdܿb iJ)*L4W_|&b]V?ҩJ(0\0-}gr,:FjtՕ.#&ckb^Io$6$5t]+Td>H(&*NƈZՐ=.񤖝9y^`yx\CJZ*!w.8QI Ut'_r|^lj.5(6˒mIBC+ݶSS P6ƥjqnr%- `R@Ҡ. uXͻlN_)Y ꍖ,ޢx?Mюǒgo&h_j[9 T'$S K3ED-~*pZģi϶<=m\Î.3I`O71r)1H[IUYPrMlFFbpra(b}gؤf1DE~x^g#SCE0$VD{Y lNW@U#[;|࡭qT@懙wa0`)o8i (iҊ* Q Qt-Ah(Y)2FFc;l wܲ賱煉dAvsEµ>hQ:70-%&!^̙x@.su* S\7C,s.'wt3?[}gSh}6d 'Wԯ̤cb$8LLKѬ7RF6kE=`l~0LV,ÛAKvJQx>nоFVs3o(nNd $zH_=k#{Aջ.&Jf8OeaDi;Q+D֗2L9xa Vj>P([/kL\?W T͛2E T mXe Ek jNE9z1{ P:ODIZfCqqg܆65<?nlKㄭLtq*woɳP+,ui0&:UF4be_SX Z`1FACD 9p?` ֭I^Nnn3~+bH汄$U\`V4 D`݀qzQL/*v< 6q^)~%-`T U3X2>,ɏCߔi`SMp$Vv_ZENְfTS0_6i=" DWkRgtY yBü7vZ@ (8I?SNQm FjF<: 1^>O}G*+ v:X{y0)hnͻ;2辔zы ˫Q󡹍>QB)D( @^ >V- Y€eP52Wy&]48|U*3%|_Ik4S|Jiy q<矆՜\Ñݠs; ׈~\d[s: OP}O2 WQ}9w;Na);I 䔷.:Yd M`'76sU{ |5&fxHR$K̯vAEh8@`͏0$ϓz-!$){ tD_%)|3 c)黰dy<nysu;n =EpE킈m^iT㔒*?L];eaT%1W)SNo~TУ]_"(`* JUUx}|<:eo\MOx{BD*+^~qB# eh@>tc=REi az{dyUNI{P#ycYjKSt˚D&y51%8:g/L {38>;+G#'/$@H#g\IJ6~n(!p;\, &M DžmW&k^ cg7m?o_t=sKQ'{)SZZ`#rY:6JzB\D8sGF𲷧h`b:\XwXןMYA'Ors4`fDޥ4FT7d6j **" =G֫~lc\6+SJFG\\Iϳ9x, FpU/Ǎhm;T^*w#RIN?|׸tOi)FHw3 ߳mtMkyZZ7CXqS6 ?bV[P~R}dSb񊯐g]B!_T&!% F@1'Gֿg Are.:ɣdV.` LIˣ sbBK o_W|Cq x#4L11֪$m#_NxF #ۃwHnB歃﯆=MHFRu[L8(ߞXˢ153\w ;Qk b;Ui Y쉫D*IGa4c%S&eֻ/(lSؙFKd˩x;ϱ)SjDLF ݪk9i-J1i?~_ctvygy2BP1i9@`u_|L%.qoRzbҰz HfN ЌQr9ooӒ"cf!EB>m?7Ӛ؁G R~Ӎ yp*[m=^{(dD)rqx9`(k[gunQ{c"uBLKx$*IZ!gn/(D7퐋_F9 /Q0N4sQbϼ1jxݥ1o*ev#l9@H-Tbh, !|{IsoB)jCc2a~,]@Nك\fPm:x*#B;{GPV9ΑKw}hžݢ.kKЬ/ nLgS=xJ}34kw\z6g>M+;9ɣijo%UbQdBhujG2yYwI"'q08%m>bz[+BJBZo%C]B׊;(4ROʮ͑A+,5.f`vOSi WEW~hU&B Պe;)LOC;kXz7` MZ6:=NfʃSj4쭦Q/n8tN{j1N,ҋk9ˋÃNrUe*…*/ݱ'3RgiףKr1vh NTN, %Zb{9OƅymG LLd7 t>;u 5Suځ!wB\$RMr53uhLta΍ R D!A_zʲ9N7GtVCIf{T $%$꒵aֈ}w8t[e~ua3N'-Û|Ḑ%xT_1$hu?΋Moe3?.ԌR\k?'F1sT Aq[rퟜ?%͈sbj_O\RE=%LY {GS5=`^t4|5 ?&TmX7bT!2M߱ ~=9e%d.SR= EDq&l.&lFc%^ ¬l . hc]^ʟ2˹`Oj΄.Kak숶!+tXN9T5#GHcVJo`n7W(}CS`«lX3wW#L]77Fe_n/>S ㇬!9"'hGwޭܓ..(4ɍD$r`sqnOx O|d2cI$ZJ#?Ě[jb&4V.^tNۏ"u·".x!z$ xڮf^] LJZw,9G]-!]sW^H60tiPoÂ֗粛>2AҮ\-Ǒ\EZ,`̦}mo[`d8ފ0I{,6d i[ *E^vT dO_ rY+"e/sEnM˳sT27nPZ1Lz"=A6F mcڷj|LQ~EBOD%̽{QM=ƈAE`mn-Jg_f0F({^?$҇nֺ܀CZU5ՕBUP',1ĢuCc}En_k!;. s8t{T?ʉ%#r&=?aS5+͟6Kֺl[(oMBc 39wrXHf4^߁ `~RDhaQ8?vke+Ɩp;6xqUX&޹7 Ҕ~vVND-}/6E u |MyQR{?a ΉvTv`Q]_tWE-,pU| z#~dUO@A` ' {S9t$}}(`NTO7ڈWgB%mAF~6H@T ևv .*oe R؎nO1Hh_h.=%C]r8| 4VCWbQ<,p0uj3cQDWf6?.'%ЗUq]xZ#ɲgz^/%Pt.2EFC]>d+X0Nc{j~ϐ27c9*/3)33To\*.\:HA6JPKc*KF#$s_j!jUǎ!r&o~RUǂ>UؿsSsTCSBj>=v>n qP.]w,Q?6mo^#+bj;  BS2]KߔK;Loٵg9O%T0iF8/eR[Yi(g-b)0Uleꍬom揕A.M2IKfĆgd&W3jƒ77MDn~i,OlҟOL:niAqe[ؤL9 ZCuUQ$.\O#8Ty5֥%>B=.xSڸ[OTWC0ߜ@&kC1y..w|lal:3Éj[s{-"Ŭ7JYShԇfu&VHNL4',`R;Qh͍qϫ.P/+Ƣ*!",cڭsz(6il]>D^z.{ψ?xTz~W <.MW"gƦ jer6: k H%.{nPN~2պ/K t#ިt$#rD1ؽK)RW\+Cek/Րl1!zsWTBvnbvq"ݮC0YS!Rޘ`p=D^M9͐D %^65%7&\ ۤe-wDC E @r\ qx5MP~y 9JT¹f[`tzvGj>5lɯ>앶s?\7&-pk3;Iu;+`A9bBj1mjz&KdH *fI]Y.-Ceÿ1K\[g*y{:uWuko%XBB xH9|V3w_-|*Ud kVȇ 4 o[ȦY "pJ=KQz!XZGW8nVBTPΝ@bNwV:ILk,/H~WJo:)7u+!rM&ֺ4 Q9s6{t:^N皞ez8\' х%p6RearЗN,6Zc! RU)bF1l[xך]OJ Ʌ)?6gSHqa2OeV8aU$eoh\J6+ @L5wHwg #㫝\7}bpEz{g[CZ3IER^~' ͐\yYvYWއpJ":,KQ!,JY|4"vˆ/w3>Va:v^2[pÏ=@*':5E`}isDl8S=0=%.,gЎzQylh"G[o(Wh2g~%D ϥn}zbN™\fc%7qg ȫ}qqx~2 OTG[]< v٧(%ԩ ntߏx8¬d<"OV8`,~LٹЋѝl뷴 ݘzvzHZ`#6$P-vAWd^ɽ[.gCp4g<5G*CQ&d7u B9)峷5 Lń%ܞ*f5WU,Ȣb>.fZNI&, RMAF 45=gU u4e }n.a^n镵g k?씠JUAg,;m^f*Jw Qj x7x]q1 qr[9̮.@L3c4sw "$>͐m*y}zOtb/N5|ߏDƬ_bpؤ'sK<#+L&Wr خ0;S#hLY*q&Zb}6Bjgog55mS\ B]q_d^+H.-$!Kܧ=>j*Ebtpu=ps5ߦw>BJ- ;֥z.;Ri',yq#6h(APV͌aAN!~1IʋHO[t^CbʙN ,.A=Tq>b$މ0o?#+]zaܢJH+3\[$#X5)ʒ3er rLo8ۇL/`~'a281Ux-V2_]!ڄ2Awq% Nj@~S}jZ=e ~adrA,zCi;I(# 2ICr&D"';ߵQ9c[}M;zrY.egi |DL 2 5Gy-xaʄDNN,wU'e6vsxǶ zr`4Cg{Ƚ _{hl xě}=vFCK^ȉ(@=Lcȡ9͏kv*9O۲(oQ5fD+(LAŻDޚ ֹ{ cDH(޿:gZP,n8umJɸWcg1 c1ApE,8 {9 oOj zYZ=m u跺}'O.Pz8jXFWSH[@X7k2Rr mxPD<0[2 :&ΐAq !{CVH B'q({3d=~s&C :X6O(edni&$pe¨M$8K?As#=ZE YZ