libsss_nss_idmap-devel-1.11.2-65.el7> H HtxHFSssb ?*}}1bIj0$jӄAYCa͊{b0a8a6a6048830285973952b1a69aa868ee4da84>۬1Dϋ4W)FSssb ?*}} wDCd_6> x /2#ui7a2 >9?pd  ' Elp -- - l-  -  - ----\f(89:EG0-H-Iט-XY\-]ج-^fbdefl t -u-vވw-x-y`lClibsss_nss_idmap-devel1.11.265.el7Library for SID based lookupsUtility library for SID based lookupsSgswsvmsrv03.fnal.govScientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxi686  ]. VhUVV:Vlb{$UMAA큤Sg`Sg^Sg`SgSg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(Sg(ee2e3302fbe2347bbf238ee1f0e030bb96c7e365cafba16635cf314d4212592dcb8e9c2b4298882de6cafaadb0ce02b903189f327577ae575c25462e741bc69c9e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58bc98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830cadf118767b2867f0753f884dc9842e871187216e9f37b437d8449c6fbf1fe4acf26f9984427129dbf136ad68404abe3c52decd0ef41954601cd3be921d84c0540ce7ac7fc936ccfb68e16b43bd5c481d37de1c330b4608d0777f76e3e4cbb066fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c89a556815830dff0f70856f6aa8a473310a8283a20c0b0d3b7c82da1052c7821fc747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fafa5366248e6a0af368dcbb0d295edd55318438fa41a7b5d2a8268c48f3b5a9641be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562b4bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a4e7730f1afd382186213e2b97cfdaab825ae8749a1443a9bb59e1f4124913b09d39bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libsss_nss_idmap.so.0.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-65.el7.src.rpmlibsss_nss_idmap-devellibsss_nss_idmap-devel(x86-32)pkgconfig(sss_nss_idmap)@@    /usr/bin/pkg-configlibsss_nss_idmaplibsss_nss_idmap.so.0rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-65.el73.0.4-14.6.0-14.0-15.2-14.11.1S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-1.11.2-65.el71.11.2-65.el71.11.2sss_nss_idmap.hlibsss_nss_idmap.sosss_nss_idmap.pclibsss_nss_idmap-devel-1.11.2htmlbc_s.pngbdwn.pngclosed.pngdir_06ca70fac75c5328a11c0a0527cc874b.htmldir_298e78ea0a17452921a007d47610eb05.htmldir_fc2053b33a81c70c42c8deb3585b95a2.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pngindex.htmljquery.jsnav_f.pngnav_g.pngnav_h.pngopen.pngsss__nss__idmap_8h_source.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib//usr/lib/pkgconfig//usr/share/doc//usr/share/doc/libsss_nss_idmap-devel-1.11.2//usr/share/doc/libsss_nss_idmap-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedHTML document, ASCII textHTML document, ASCII text, with very long linesassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,W] b2u Q{JZ:.}f1ʔ)sB]zǹ~vfdGYj+{l7z}qpz??v΃1^ZJpT,83tB|T#(){d &z#c{gFh> Ruk)ǪD45F9N,h-­E'ÄM)h,nQ@2'௅[ 9yaUg#]Gv@+H(8*`hj@(rڜf]["ikJ%0o1оdD~R[͵#mSoSb`\%: ~8k W67`,*[bc a@1X|?8,hoh1X$VQ%5tQLC_T;<sqQȾtLo$5.G78̼RCs,ü/= ]l֩vCފs@BS"X?/F=ǂz|ޗ'*$lFxnP ~Ra3J\>dAK32"|MwاqQジ:m㻱zoL6G8Nj4GefYsoeʧ]|4?WPA|<^ ñk{8RēNPEEAbwWCt}Wc_-K6Njbߙm4P >x-0F1/+0!k >MF) TX)*5@rYyٿU 8~K㶹Ka?,rKGwxYV'w6h)Z u#}"HmXxS9]A ?:BK Q<9O: vl*YpۿznU'0kOK@ڝ d^ `s]gL1Ou61pt(-ɛj_\B<`1%ѓMLhufg4|& ǷS…ňnNý6<T[G/B~t~Y&}h[7!NJlRBzݔ`̲BIIX24{kWxBMc< @Ef, hZ>2]Ԩwo]z=[z2ЬAfuA=CSa݁i*JG(BnĄw˂5DIj }dhZ<*wT(=BeY»%#7'qhLl&qR5tG`!#3](%`+cאV, tm{$hA;(PGchHSL$R6rg5w-m#dGM ) h[hCoc^pH֘뎛 zP#C_v-Y~, m;Z#ѩ5Y,Y%,(B1ƒOGۜca-Czǡysӊq^'[۴ay AdxE@PazMtt mhk.޸LN%Q^:Q}8H~m-a"ywԄؑg3!R8ZVJT̪7VfPƊ"nuijy:[iB;@QØRڅx7zT"pUbu[D~gmc ضCD >_׌HD>.-!ه Fi[*[< x͚^<(tEqDŬV\Y5&y6MB蓯hXJNCG$H#EF!œ#odf<c̿P97v1/D&5r yǿث=/8n?57%0PSj5w@JVTlf+ySd_/Z{G9g.lkz=hؐj CxVXD,|  WU2cT )4]Y̪e/#Mtj`K+wZ)7^ڍBR7R5h2C bn*>u^{ EӽGYiT&l? u3B% hHʏ1?EohHkZf]GeA q]BJO=Ao)z(!j{kѵsqX"S ԣ %Q? $c#> yXߚc$yo3;E>q3&<" }{v7 YXr2zSL& Ul#e5w}fD-+4;zَhŪ+3_fLQ@g^2/M!Ys5N?BuJ4yለHR )_@b6 ѩfbczׇ+ABh&ŤNL5Ⲱ&B?͉LGg %F{cpu}%^+Yb(+]͕aM:ۻQ)%,{: q5#jb'&coț"l̜ADq& SH)0 b%b XmԹ XA64 Tc .aVNW4"x\GӬ-폋2 8 ]QnZB+ 뵍)vs!`nUt<)[AKOGhpq#)2VnИ;i)ʽЧ sBtj"Wfqzuύ+K'p%g mTL&_v8NnlF΃V_ TǪށ} rFRfV1 -K ˟Le+, V:+NϫdZxȒ+y8O5㦾OԽd7"Tnz\^UiX|Y'E59{:DQEhwvZ'AM*!iڼF12p{as{Uc$s RKbV+1CgQD"Bi ~ZN%W!uh!hA /avQ hF+WL*-Ly[n8F,I y[t?q (1plIǼP![(S`k^l1Tܝ%.Tzy;CHj,Sc<艠ncX__nw!5Y_sS@i(Zu=r~W<4x Y̏*9Oo;ң{OZ[=7hO[ cD>7}28Fգ ظ?!qB^ M:Ez2ǣ fm[@D|rcz\\3nゅ/¦*q|?* Y\j ʬƈ$;g64DZd\^Faю{^@lC{sS6JOQ^zP6%9P ϥ5LLfBm1ΎȲo(~2f׍eqW~OD,H5 e|+侵Y ]ߞMFd{vDqǞY  sX59Tfiγen`^zi_9râs lvnK;0@ʼn=D΃A)}*D,Ƕ?(*rbe0 vJ D~S1vrNcU-Bt!_T4xH8`\$j' l%?E)>SJnTtCeʼnM[ y&vk ^!kqNe#䛈8V\qO{iEV@R٥e(:WLbl q7ZX1_B3bS`?@eXϨ"\_?˷PVotixIƟ g)VM[1e(@l0!Юe?O7C00_{[Ӕ6$jA[:=)WyBeC 0Ͳ.I(k;sHYJ\C<&R`uLWـ5޼TKTWe!ڞ ^|APtN$J d$ eW=<mW@rD#r Ɖ ?s'#Qk{S {oMpp-~RVՄy,P yNh#a/tPXB>J{nv31rqɡ&Yp={LJjoMf}5;= E H!KijPYB;2rg7FAZW  N6EZ2%n9=;Kh-KM2U-wLSޛS%9EMeORyM:>w6/ڳn)gښ}%w{r'~Ӻ|7ژ̤7WA_|MҗP;QjnC_ Ь-ne|};I^#o`9oPT]3r. 2Iff!f`{7D6T|0#9TRsfUSHP$݄IR>dK.fV-``ZemM_B/|XPmfh3ejj[Z$%3/F} f><>r ,iod55cir`v T`nyj,,5shme8|F0]<v3ry#jxn@sqO.HJVD' QrDѳ.)?k-vIK$Og#~U@eTZN -w4={|hNy0ƺ3}ɿ?PSDɲ{nzz2!I&~ J"S,O 'Ų(u BO 'l>S~jrxkafsnkͺ`Fmh8xʃ+KP"v; _Qgcno^~4|ɍucF}ZsXlf?{CKԩЉ-_P}-ᣛ5NKq=̵qԅ:=F OUTrmM 0^-ż"um:Sb/H'gOZp sMm9&9cAw->lBtAX+Sp?y$P"4Xڲd.ԭ\H_+="8?Y*- %)Q=sZPC[^kY5<6! q.@/!k"K"=jwbGROC4`k30NlLTvTxjݸnhNTkrK@O\1Co(Lkfh#b]ufìKgb+)Bl5_ o?6!o @aTzrߩ`zCvePӵJ:p*nST -]2iB&|ko9$5= 0@ۯǣSJ9ֱBKq3=HUQ z%׮Y#n)S@<iiIvD(U $0aP^.nM U*{ Gs9ņh]v뚻$gBpМ/iC{M,v6 yL~qF_#PLd(?SY4rJvŬvϿ0ɚ#PT>u:S(ɓ⓬ #CɺaA]+g}KQGr|?`bRw'-TFN/r|hZꈶ3V&8nb6 ۃm1`ɜxlܔ͘ ~k5@͡'()tߍj3@/0+Cm1&%UԪ49 CRHRb: NiS_Hkw*yT&?٤ nw_(aч7"UVo9DT/ۀAS_ej '#2W 3MßjwT&b~8ߌh-![2|Ar$ 7?n|4Җm;{@:)޼-Feo0@zv3LOs KuNvo~%۪`ER|? (!E( Au]d<$-X*o m2hML,u1zdЖҬ!M#Y)tY 9<_aw\p3"ELw(_c,sk݅D1'Kt~%]Bʽjꑙfg vLQԵ"Ȫcr]x8,<MʱilI'ΜA}ZD>s:JMΌ[MD†/@%F\_iObz,?+H,[jLfX=/j1L=ge~ڼ"!WnMe3**CL_c)4-Q #ئ+iנ22.YfLh2͜n]و J }TܐX=g/K,wno=ID#}as[)@S?H(W T|I d5S6fP\dd65eTD`&ȗd{YȓH N- 6[ ۖ:eQ6`ڲN{j&q:yA0ǵ<`|c4lfA:Ѥ9R#Z g-ӱa&/2tBmMBhݮvc_6$52yf|X ς q*}U y}լdcYIlW3sՈ"A2F ~-$k!Ez4]/ce졜t8,J$z=q&X5_ц;N =!Qg*5uSD-ňǐ1 :QӰ2.:yv̦hƻF>6XWJ+9d\cl %Cv9Xz X͍f$]*ZyO7ֲB.jkH+KE;/7+D5i&gP^Q}#GNLAa;zñ᫂'=}f峭2E*''Kܑb} vhݩo Ztl(3)$DLDBhA[x&+ K6v;dKd/O(5kc[ZTh6!2<<;=x|!)~?^0k>x%dClEMWM 2.Qnɍws{a/߼12Ubjat g-ͽu BR푀&#2ľݦJƀz|AMVpy܀- `TzcTP[H1;Rþ!tncIV[| mR nr<KKM*IL@`y]HIX/ѮZZEX?6Shc!p 2_Z9)@$V&6oSuoNEđh e[*d[̭Jߊad`[zҽtAWR܍C+tnZV#;EЦ {:fy{?>؄}p/`H B2vmc6`Qr~xguY"M?2.^TD]si\!A 0~zA9f=hJ y_I.5e3{aIH^?s$Ld q3db$ՋUaOML#LB'ʜVY?_DŽHAV,OPTaЖn[nՌ,*rCv t<7QўȲws/*&̿W#(ѣ~ѤlF)`h+?#>ն\'a#.zY .qdT2E~ζOj.?ypigU~=aȌBC˻[/qo8(I a n9Y$"a J78$ `M5 J r τsp93'!b^字1]X==!",$"jLo\R!F@ӱó eDNVFV$>nZBU ,>^/yJK)"~OSo%3} $:2룞ϰ~c\@zgqD1<9v񷬽_g% /0ScPWP~~zXhJv7cF;e܏uY)O?*/^5`%{kNrJc',Vv|`0@fTs8%ө&0͈cZz|V8t gщv呦DZJ |<>ΡU0fs2BAނa WfM.`g~f/ _Mpqq*kHh@ (YۼDzQ0k犌Ev^Uu 7ᓏ[mT[/ S&n˲"mvAvΆy~F"d #lm$OQAo,K Xo͉';eރՆڔ99)Xl7hRD>He Co؈ќx0[kUmCg#Ґ2 z 5VRUiԊzKٖuz ʋ*pF>Ǡ.s-3 %vgB YC 㸪_ur6p3@HLdaievO*&U67-lŊF9 vؑedfmZqnc\` ÐNzN3^81Aǯ?CuIOw#>.Y0棂E'jiz.b6]TuY Ub\-Жxm?yJ^aq1frM qvK@G 80#ro/=$rּ>@]XCZĞޘ6D^oA=9s4z74+M~];(PN%2L +MT99AOJ=WA RV)q ڌ7v}?_sVzhe8{vC[PȺPXuzݠ]DDJVH } # Km cmlV|| &!\͐88՝΁8>oYvbN\OEaw>c ^c %w 306&+}YsȲubI4*&_/)DDd|U.YԝPmIy =V8f&;Uϓnh@Vy+=zp3[_kgW3B $ ݨ}*aD_44_= KO*U;uMX#ڟqcOHP= ^s%4TMذo[b Pu&^8|\k|w>"cMJjC CFK*{;@٬XO5vmNUlwNxE:?R̊F"Uכ~TqDP _L8/ʰ$aTGBO V!\ K;^B~]q%@F Wlۅ~Qx/[7޽eRTt@VA4LOÄVt=Bގe|mw+؞]N':#.$jZ GqcxtDF?\vkL9U>CR#w۫UdE~\WTjc樸'6FCj):`@uYTGI۪& j)T0Eu/+D18ERg*W ^âDb0L!gvO @`X\|/v-) QC0O~x^UiL]UgBkat F'oZ`3Xn5 )!^=2`eÅD>/\od%3*?+^ycR.L&cJesAku9Sv;EU;U.tAn:hdoU$s=f^ ƽ9<-<ɆDw9? ٞ=KoҀC&&0oW(D$"UDWg{-,A>j&Z=́-_"!G o hTvz(o,r̕E, Q>~v07wCL[Mi9PGM.H!r7k#ssTrר,bݱ& )ٻע:Hώz`EBCz4 >w=f&;>"& fԣu Y b5k0Q5HLQه`9-Sx8@L/RC(%1/Dx(DC!R8h{{n?$pnϲ<Y"0aé~,Q~Y!*e=y&]d Ƥo1%~QE0$_SjDeJX13wƇIwq~>t;4~82C$HZL!b!K.ͫ[GZ'lA,S|BjUk^jǢ@+x?n1RY}b"Q7v%:jk?kBc* %ytOfm;VϫV+"G@ʕV=ة;6e; ZϫEPpv :=7c$ړ;05<1:Uޒq:^"&RyXb nT J ?2F?-tf0]J⌮%G÷UOf F  P:9i4P]bϽIܥ﷋% .o'ckSn/㔿֠FLLh-^Z,&q>8pPW1*ȑPj D%x' i>VYJ󙅀̓P_:2k `J3V*M8H u`ƹ-kOL@gZxH^d !}Qtr HO,H1*}N9Sׂɷ߅vق6v_Sd5V l&˜$/Ą'g]e,-¨qkS@uA&G=}% P\{G" ۷F2͢4eI)+M3P̄*'?eT7Jdt\E}n$m6^* >OR#I ݢt8gmBk>'/>?)oHoYKg$xc}+$MqD侰z\Y ,/anG8\}օ2}G.8\QI!yZhk ]خvVk{%A,ł!8&RS,8?'C):TƁDDZ(X8D`{¤ŨwJD:o7N( qM Xft9U#-ijިgbJHFA sl.y~ٞ.?%(/32Wϙdg8p4UXe>F|sH']R>޿ϔOxC51 lui,T$d Ci l^ܠOnU1w,PW6y<{Xsנ*A`^ KEGXe|A8I h $">B2<>G kdžtb*3=wKOKٙ:V,n])!C8Ͷ´c,ϦvnuF83W߅ĻIH]+D (R=X??<͖Ԧ5dTf1zIs͎ *`RUGo5`'m6ٌ7˾ h#F?;!-|67tl嬡]5kQ?F5jr}բ;5OG^ Bh7`}%=!1];n4f\ZOq/ նw̜{l#3Sk~d uӚߨ{)@hA-vsaB8u[JQȢasğ(⠣iWӗG@:m׃]E6c*=`ahNY(S{"je.xe;KGNet=mѻ}-1ʮR7ni lt6w:i}ayu7TU&W! g<虹ՑE-kДyOTrs:3 s Fpsɤ' [>x* 5`#zñQuRp25Mu_-{Xۯ$-/qf#Iysrx}g7PO9-vޟSvHdH諯7xNz3z4dj>)ENq3*ܿ,_gV!l6/LJ j *#C'Մi'F5#ZT[>w߈w()K?;]٫D$@ʝ).\ɾ,mmqA3P"7D2UDwre8n#h eoJ0{MZA8.gu|01Nϝͼ2Օ]~wXO|BC6ۋ7;?' ]AIm9CV!>.YQA`sW}&\]ӃjahhO_Gk:~w3fI0ggolNePA: oɑF+5y V ;L>O Ⱦ?\-S[-IW`[/2S}{ Wfh_!rh4[)h:nfX鄁p>$J9KCSp@8lWG >Me jV3ĠUY ڦJ.]R8p)Sy UDՊPqypaP̙2+|y{>7fbRLc2Qrwc[YG~{ͺk)"a7iz||dL @OO'g$TK_>`+uLFԩB7$~3:Vc Ô@ssҕϕt%P1q6&M~w1AEgBPBs#A{OuG;j^g4@/EfB&C;Ќi$0^@l3jL_AoB+mq3֧7 #k$[!ŬV}I1* )IU +Oqb>'3R  lS!mݫ]r@q"\dgf_s[oY{}QxHHx2$| &mD{?tY,t@fV$Z y(2艑e0ND `}.D;*΢a1 /kee~Uލ2 MH/3Tc@iuj  W9cT [" פLʃ+S 8s=)L65P1%&ʹ1&UOsji|y8[QgQx?Q1ɕJNyɐ*JR.+5MGZr{c>' 6Ph%=[#yno:p2AŹ4aĝ>B-gQ,1m-pW7>P3OLd#K _yN?/`;K%@Z=~דT* "]z*-A4NS̰ KPAl {.c {YC<@kG^z=PzzvUPD#ϴa#ϓÝ/-_K SquK9c3o"G1wqnq*#UntrԒ8Kx.aYS<Łei]4R^pY]]ƽcX'Ύ\mn#lavAܭ?"4PusNe*f XabeR ֒@0$g[K()D:UP7R~ߦ!WTXRWv`|0V琼7J tq2|&&yҿ]Nq< A8gt3Eh *se"s,dЄ~A\Ajqvg+@)鯏B4'֮u9F.*F:)!:S(П]keRTn0_7h4[_ ?xՍ :/p#L޼c#]&ЊWD'#m$<4WjCo)xCf#l_f݅">!$#m)ݛ_m:x^ɵKV>D.,M,#ʚgcU;Xc<םxYJ/l`.t9H(/+~h%t%7"5j-Qjf)eRC\tJdޚ2,4P&c Lram+gɯ_>d<Q6&[gU"Μ :26CDw9BgИU}6dzL0Xspĺ°4KUQQˤ Axd`FI/uSb]2ύn3+ZiZ"dCP2S#tOnOVC\3s9f#Tj g4aőˋƁ}Ӽٌ Qt?&!|ѣ91K 5qv%TwIl'ma d+oSj=+=n['Ȑ{6XNv̸mF&3OvV\q+R LxgCy"P9 1c{`G ?e,trAfAOsdǂ*l-J# ܱnh3AJd6zv> k֏bD -U0t`f`!LoLJy:.79st2ҜR*$OoUU (:}N̾Q \Z*mѥR2z42gٹsʰwPT2YsҭhR] Է[cnP@EzWYM20`Rqd4 S# ʌ[*r`v|7QlpZEGϩh1w6f^Î^Iy5|h/+~ݠljo#LmN$#nmd ]5x5wr aD@*qMLB}tmn]?'6B!0 L|Ŝ}_Lngi"3>=L=ֶ'TbzdOIu&8I\A3"Q153%̆ Ԗ,BV/ClF챐py$p}w'evgi)yppbDV_QE4Tr [*0-+r9 6ҏ{k:ԨV`MInqR*s"ભ_Q ~\-僫3 8CO=&K|2@p S@8$h0U|('|m 7ʣ4ǵe š?fX]ឧ)0PUl0 SԑȽ*#=b 鸰Ms-TX-v)ON;' Dpb}}n6 t >vPϔ"aN]YjY!4p[FWͺ1n#:llAjߔz?{]:NnZmbQjmJ›]U8q@*C1D&囲)@ #,?VvZDO6| `Z@?6uA{lɽ!,̂ Ge #/ w]j=A\_ pnNس~4v*u6ّ_"a)E@}l8 x ̪xs/}߾k W#v\-FI }Y&0Q;ݥ~8AHÔ-gNe Ρ'l92%it ߯@}Cv$ 8Wv-p r `p7f8 APK]D_6i>>xEo˨.v_=]`ܞ:ڮ a ͪ.,¡׃.@{hH^[k!/8m_y^%bl F H0(PE)QVӧydW|A& ':Z2 `<,ÓED$rdC`\5*?t)`Қ\eEDwnه=pԴq#6^~=:SW J,FfX"u}޻}Ox7XL'D!2YNj\V::olcjU&Rw\w|CVi}"]>q" uS!;\1<Ļi<0E [{Zs,[2bPGɗ &X1ÆuD hN? q?#e/p8y4|g% o۹h"@q;aiC6vt|ќu64D`)ZA ;okA5Koyo%? z8Zkv??]P%|K2;oTa\Q_-~ryBb-qslß\z^nHJb`_$>٥2=7[ze\A# oݷ~/u6,AޙF1{ƍe>55!SMs;~B$NN /TG,*>] ɏĈAJ]1-Ab4|(Y К30)Z-VTi`Xedب#ERWjk`:I,4u8|)f2 O}FE{L怃ccVXxvVE^42#yDeX;qZ<=/cjK&U&\h}9kŅG֬/G9y|o[mQ|a|,/,m 8*eḲǴ1bgP(IPeIZTj R"-nU%AWgeF׮8*Rq+=CZG`.N&t!C-A;A?$Y"[Z~?{cpPt1A/haר~f!aHx5 wFq(fYiW6-W[ې将 5"pM 2i=?LTG ˣ?I%& YV_0bs3_Q6P}@L-0%(H O׸|?}8:.WdtK772gRcv"sA'KF rWALښ2VWnV\=J@-2ާ΅ d*0]dX Í6K*t QgēWgKE],(}j`aPuiڝU$Bx[ D Yd/֯էnYQgs°65ȴvM(Ћ9-( a3}e7Np1CZgQ',1.4SPp^c;,X#m.jW>qB`Z r\8w> >u;4їj))RWz<ɰ;i=~t-"26'rn#h^+Y5u%j^ˢ)|[6ՐC,6 g#pPи 0Aqi^%2YME7VmK?:d\x{jF~E&%P 5t9ta{VSu=>u6He2uwwS4f<-/3ȨYմƺ 5@*pgw`ˎ)ݨ]v0?Rr<~ǍE/fH~+E2DE+s^SlŶE`L#z:}XK*;tC݆Ca!3z /q~C[msdDq ~2]/Bhi=T)my gOiW~hg g e6"|Fq1W[F0%ܡ"R_ə^W>#\j[~u`v Vi%.&\TV%D'^ 2]n}ǼfD4 Pr!HmfΦmMy6.ds)0W8#0Ln`BCR~P+e3zzyK'-mG35^R|X;d=j[h֤\&Y5P!M.6<v>SCZ? $c>72҅>12r' ˋ~ݸ¹8aIgpsiadM<"fQ>y*6}mg^SVahT@Ch.*w II ]aU차b O!O';Ɇ;Z$enaK-͟\HLt:.`?*{Jaó:9i,x}$|QdDc<tپuwZf[0bA*rNWX(TC}]$XpՁJ 6؛ #Lpq[v ѯ,iFp  #}C+X5Є ifgHH\nX=9`0]ˑby)-6Q[?G% '~6ׅsػ˥A^CGGwUjQ/!TQV1 H֭WIo> \׆=S&4]shJȻx 5O`rsp^7YcƔe*df XZfΛgKAœ_mEm‹{cCS)PsrRox8rzYfsOhN&Ru4Ol .ig_.CpuH"2oA^E?BR[ 2dRkВՅ_-/ڮ>peD_Qa!Ng݀78Yz(tE;tmp`N>d"xw9 \ /Syk<ɩ}o@Ѳ4.u arRՓQ#s.mIpvHSXu,B1,إ?Vf|tB/<n(nfT=&ˇ`Pq!l͆8]; zn0bٱO0H\V!"Ā#XtF%W^+l@䋡2wo 1Tj;kK_w(e\_r>p);bi~M:6eW+K6p1cX;ٛčq5kmPDUZR4HRPA:[0)S$W\O֗fR(XMKM%ÛOXg3-&LUΩ>? VVMDx*:{zw]saȩ kؘ_1L"ֻ`3TYuR0Y>1{#ϯ}yO$f0Me*ꮈܾlbHy77 +0Xy$Eˇi $CAԲ9u"Ғg͝c14q': |*w45{D54e0dڟo{@?Nb>A6:EpS '6t2Ҋ uys+wg} ыdn5_;76ۜH~5( SX9>P%1v1kN 1Z >,G>* Uv8.fO 'WRvC1EH b^@8ǧo.j.n p*c4F=Lʚ_dIP˦!i]mWPRqR(Outw/2b?vBˊXw>4Oe me@;$pFC|tbheyB.j?PHy)3/ `|P|KG{:,qe"ƛMRKIqC̨bVHd/_jES@)_R!k(u}ψ$ɴKtN5j) X Xd{w/3%HxԿl~os _a "xBfSaBT%O󩫏O5)t U%<}lVȥNFg 76zؿ׷zDi(}` H6&ĿD guQhg(,ls U A"YuB|&Bz+83}SI,$'s"ɞw|e?|Odn7S#gx4r+WzEzAǴAPEB+ wө3٦!#JH@?3s=D^كo28`ĵ=vXݛI8UgwzM[4m:"Dh x}-Ci޵к7$qf'nu g}1{^Uk\8Za *+colLyRCjPFhZccq@ Qpdzyyz,"=:S.|`GǪH)np?s[wp(aN4thబ/r"%&o&G0$k1:RU5t9J/^< *pid Or& =j{ި~g}j.BA }cjlm~-[/D,"F񂝁u5d%"O/ yX.wO}bu߹ǃ~I<1?`@ |tk)K:NtRD/odbYb}n\HV*Mn A_X :+ې'Y<9QvεѾa|֨K,x)*='&WÐg~-=&.(T r]wVU#.Řr)Y<b/O{P.=QQNqP4}Jg$s:~iF@GtoSGpF_H,;l0"(ً8B>|@d m2zأivVCaRnP/d/Xīc|U#-YD4fhz,gH1Z;Ɯ@ -Ln9)" <9M`4b[j oJ5\%r)QK+_p0T}qlbRuZO:Ya6|g ",7Ȋ4n7>\+jHSНo.1h7T1?';@9 [YhR%U)mR4pzNmTT 2ݯ _`Ra4c;C}˼c^x&G`Kbq́јR85;hr^hՏ(pwl3=4%}~qpsFK9pEcPJo8WNǞG/l"qg@?أhkQj @;5X+)~@c Tnl,p?,-k+ wT8+|cr_3&Hٱxڨ=KvqU=֪&TbsP{^W XN41gbFױQKx~ -h"g`cibG~ft'׾Askm,[r.iy߫k\F'-:腞}`$. A}H$"jgO0= 6A,/X˿<؆RERZZNO(-)(={\|qίPC8:V~.E4 ȈϦRMۙ{Vmjp^ lDG}jۼ܏=EAȋ\(EV`Vc4 l:zK< Pak>P4 oΰL]Z*a?QI#IOσ,YE8;DeP$S-lyoLP{02*#<;YQ?A *P!ބyaLG.ZOP4kLQ^mÓ0$ 9gC#H|`-lP|jH6?)sSqC\sQ==;GT v);!^P/cnk0U}T} 7g81iarh@f7 U"5S3ݼ^F%&N  SͿ!;^t )Y V d.ޚ=m,U g['?l Ӹq2L2x sפdnUҎE0l |f\>"(Rvtz?IYEׇ!J!}ݩ>OsuP㒃׏GT{=qhˆaL\֥R0- =4˯FN*eOf :3+viNj) U‰]|%|dg[Sþ B.G E[ M >葮onV:pލGcj]QN>0'E|^j6dIf[)HMFEz J1iJ ݭugٛU;a%  22|QD .-USm[s={J2^nmNXr[I|@Vi3 u?yv|nQ́.>v]0#؟8Lxĥ샩mR x.YJxEC}'(Лeu],4!O7&hjxX5ޒq* :6T1TSZ\h1.4~HoIGxwSB:/IΉd@PeUdw?7z9돀 U W+j|^E*x!/)-mɈ:ɭ9+ó/3< mm('WEopZ dexK3^h#2cY?0E.EhF]J/vS]֗ -)z6ɟd8פO! [Q Eh+wbV&Ihf0t7 ֒'Fjϕ=2uh4 2 'rTka-m7C{cYd2jkj)DfAA(Y=e{Qq<,hnFCGvGPIU88=^=5 %-űSϊKe ɷRKDnx^3 )_j|k<Vy}8|,Mdf +leu{r7!5Er4ydk-KYUӱ"XR,UL"wd%) yH0'w4FԎBhҸ{o&ͷP`(ժR/m\5Oz5F!choߥ!.vJ#RHY`H)N,xE_3,re#sw\EҤeVN%6}LMe:d^$㜪e~"Wyv U=?T%AZM+ZjpVc}Xge >bڨyt(WНd`7}%~W6C0JÁ$PXC.JȐӫɹ'΄ūpB- daY-wh W@JR1PXW$(9v^\,w@_"2Fd4S>GOO]ARY>T䍛oN"6l7o]J:`D| j{T2ןXp[M-D()iY<KK=qws\#=.`vm٪x[;U[/ǀ =+=fd ܪ?v2DERU}B󹣝T[Zlj!rh8DDP ^p;Ҡd"r5tC!{6r E#qvICCMPK\ːwbi'Lf 3\U 44#2\@.{@<5 'vq@ )WM@?MhD^9""CpF*yDա- ;i5!U!1!88 j2j x_%S3F6a8w1֔oӾ@`af+0"u"!@^HFIl?IiZuv۹}AVυۚ4UupE!h9ޝu]GyCb4BgrW'?م -@ ߗToeHܘ^;$f C<|PZ;i!7 ɐrq.o `lF#EwsuTrvoZR `5[bTvWsNDoG~-/24e7N .ڲA ' l4`۾rCf_["@qыԩ;bhJO=t|O\K>\a76DћSfxRv"1j*!`"oQfS)萲.``!)6lծU7B~; J9QOZiq(R{ҍ`/Hc cRI8VEjaa$f"pM)A2'A5foLߔ,IĢonq*QGJOB3ߵiP.IG'kR4F'! eSL5BQ8Nt~>t6١OIFM|ϧiF0dt;F6 {81p֦T=!a2 GefCJ \p c$+RGcٱ* ΩR4ɇBցu(5$B,μ>RyNᆚL_#!Dj`c*Ls9%[f)L#y|$><9d`Z(3zhG,l.ҋkqu*ĆӍznm T XZ-\+LVcw-Vv+~& ^k8JhӝL`u3 }EPw׎]#3uoEVE5] :^c?oR,A$n!Y 3@]8_ b/u@.SS(b)lYmf 秕bܖ/T쾝/Dݼ-'R+1 MyeB,^0{Lib &M=-9w GysY5Zp(Wp?^B 8Zm]-&{^.`۳rbJ"_bN?3<q|KTm_aUuA{ꡑiN4i_/()P]>x&P5A}!s'_;gGx]cƁtP3dMI$,^BHm;J؊T0怌岹mWJ]VX*Xf~ 5kh 3`y_G$\l|Fele(U`qS̃>>/sMT<$/L^XV/yn~^``S\6O@mxMktsG!G;b3uaG%'681 UY<@*WXYꉔ/xA/u_}o}P @cP̧zqf_fSJDM&^+ RJé纈{Tq}1SA|sLE7%d#vDɐcZ$s0y۞bGyTB`u::Wwkà6;f&^Irw*#'@iqt(=pص2å"Bz2g7JTnٯ!JnܮT޳ہqCe! K֦&8Ho8 H4j;O>I;?qCkW%o2RڛSag4u8T׫"Ԣr6IV5v;do9[F >4DPً+H1Dͅ>?b$ؒuyV*1%~NygyLAξ%>lp:G"f\eŘ_-s|08MsPJ"aQ7%%'JP!1Zׄ5|`:^hliPv*:OϏ# ).>b,ҡ:BRX־@}4pO+ ebF`f/({v_L<"/v27Dtlh`$C$A_hK}PC]$;hmֳPmgWV9z`rA"؍-a᩾0Ójua2 u,?>Z/7WO*x:fɍ,R|9KA5xYۣze͢_\jՋuI 'w ky#k"\#)[ fO 4Pdե2w.铲v4wft_d0̘Q;;7Yw&< uo#G=ʓZOsGJZ4yr+^u)oM_PF -զ (eϟ@ĦD8Gw[ fK\}s&6c,'/vSU⼄*WɫWN4z+P#M Ceah4=jTҙ!8&U.-@X3b>մ6 Ly}JH6((VK o:TuJKJV<"E 7L;eڀ qBܨ=*vƬ9yDfh ^3/Ѹw%1J95i-\so6O]a]N:^ia⣪P R#_XEp_jSNY6t+#"BE'LԱI^\F7cb1?FyqՎitZ+.GO聮WXT^YfY~Ϯ4gy,ӆi2Iȿ7iQr*'>M*]')4T0Ap-t|ʷ4 V:qWhxQ`![Mx[# cX6>xe|T J.\;σzpMt'j[ͭr`65zp 2{q ܸR%uX77}߀:Ɋ5BցȌiÈŤ֝ZvJЏ@ϋkEvQ8 ?t)ϻF{L},bQNn_Tȑ8-\\>󍓙4&VEsFŜdP0rF_iqpK1i3MMVvL%s o]ۤÈmeL Rٷ!$V2[^\Jj/кa[ý)4X>.J-^_UxۘP&Ine$vA{*"Ń a Y,hVamBݕ; Cr3L' 8eK‥(J]R-xxD[GMջ\z [+07,U5s0SQb62DKz)V8`KSMt4NIkbbZ(0'k$jh?: %I Y) v矦zfYx< )6u.Ô͢hZ*@HDU&0,%1 (YoSr*.cT?N_ qe^plq7^vܜiN=2o |R~!^m캍0hei(kwuqdy{ZJ5ZS;?X@B O@=,YG6>Ko@8}HzKz!gH4spiR#l$*rux=dUC"=IoeH53d3!c[#:1RE6Z|j[_O] ^/*SI~h,0:ڪ?8,x K1jSaDsG97fld:JDR` V baC[D+0٭ YVV |A)![m=_q:13DžxqVzؼP %q(Y\D@-ruo'SHQ(*x2%<%a¿AL5,KfSh#RQ 6D유 }C9$?&O3[9c:Qt͑%ޗfCpm]儼r>mAQREJ_@|U0+G8j>If8OJ-O)sŻ,H60!Z]B')2&kq7 Z㮰鱟4s-lJE/I["|p$GyQ>!`_c"|vn|7 Sݛݛ m7Q轍HGXD- z@NBU{0Nh!|r2V2X>˕g+ƶ0:ǙL(qJsѠ˫E%R GHfDBH)1[_oG:AuB)`ІyPILLFWcB_4 446=1_-68_.!"s_ L=W9!WuCLh9Wᢜf%:?5d'"[iaPAp7_Z8Ԯߢ*!(|!d@bQb)?aU: @Ly|zyȈΈRj%bˢ]K V3  $F|rb49Z,ѱ^{T@hkָսSF.ͽ7 GCSSˊ .{OT*F^C渨twuF,JMQO9F TTKD f G~T0M\@$N1JkҌ#"]uQǨNa& Y{%?Uw2qu. re avvyk${ٮ]׆ RjK⤮RZIW Bb_Y۞ "ӹς>5Y T%Y#b}3m?J\օ@-51fub$U@+X#908vĽZJrQ$08PWaM`1yggrBny5w럁]~|ium:}[9="pcG9؛B1C0@CK?TK֩zE5wӰ4X_?PȟrV7i3rvש~*~6!! jmE͂%KHk~>"z.P 1͞0wtzQN!pC%ʱk;#ۨY!4Gx 5N+ R+B.:ǖ3^C7`ce\O A 7իyljLP,,ǁP@N2ع(T{_UPӊR|I^V$~b\6lɻy *jBBw^tm8*"ZhI\ZA RuS^i`:(T9tB`"omyN7=DDf)U%ppg;`@fo[ 65H[a)%J%T mGvIat]c42`6X5BcM Ǿf`k?t':]G8HfX4J L[%Tvj1 y=A/D9479dt^{Q{w@NNC)dB~~4)ـng+Ho7!o!vB֓x[+3)9< X3qpR6#N8<.OaMaYDj۔^AFO~l?G;W6ŏg)CLKWfsC&xyݩNiMAC1[\u>d#9VVU̸Xg`T:1ssZ /v?~,,q<,t/l)`,ޯppr*iJЮ1_>9%jKOZJg g$Vv7WQΞ 71ʠB_.VlDmƎh@P4 FGQgb*'K`1HWvJ]s}dg1|,;硤zz>+!y˯\UP+\/)ZkW5kiF&VUJ_jcn=ܵxzeyM "O_0nJ*>n'Xe7:qMCOPįi18Fe& [[!qϋP^q08 jr0ڇDhvR:j⣤ @c2EBԩ-x3! r!To!tgߋjv ])-ϻm9 ߝ͇KߕE A5WacwL3ƨ7.fgl@_1c1^Klcdy`.p2u%sWCN[DZ!6cE#e < RH ZEYN]*q:\,桩 TSQ_կ94@U uU*j8eL 8J0ђ%JbNņ?-܈c>e5d YAS22MTz)y=!IM= _oG@N=]dU"V"v<,ċ[H,g1-8GUICe!i"LX|1DZ>JTԿkB¼+P&-JGzR '>͓=5Q*TxX)xB&Tϭʓ%5 (y-P챜ATey i;P m<^C lOl=@.hhW ͍)K aճo!eLa@[ /Sa\V RCvY|hHnP/6r I২) ۡZHn31a'e_?R,)I$-s/}Ky+0BlS';H Zjg52~F~䒧WOo~x (xn;2ǟFůudhdNq,T+_9^u) %"y:{8'C{5r!o+aAot}%/eKR7bQc Fex o ~{*^/\Ö$m8Z:pHZvP`DUpXmL-I$!qOP`J,UvFŬVNj}Rǵ坼",ڤ'/ʋ8Sl1\>og2MgT(4t*Ն*e*%Ґ Cb uÝڡgs=tvhl(i; (68q;<϶]d1AϕE^.(S#%[!`[@\Ұ{ܬϚ6=!lF\K.X1O2t˄kY/q}| sF o- , jqR't4Z=P(4e@i;5!y> /L όpB@>*QfIX`dËgE4{Ǣ:"kP$6q3pOͲH'=Ó*dNB khOծ[rDn+Z4hViR OwW)Z :"[Q~|/`vM묙a`~3[D7l&9r݅%a.OGS^q[JL!:lі̕ aXo&dwNd t { fBK *ZT$QcYeQ  .zSSɬԖ/B5,ȬF# D^nVe?55fPƋm 1*DXͰ#fj.}2ڱ-T=I7֧onGu\72fWXcY, G a:KlW : b,*z"+5A5CXbq)bP8\rdlge'#.@3yҵ-zQHT]fQֹq@Md.!#s65߂Rf [*`W-2͕!6e9'5"$eJB Ng;4r]TTO2QEԧ^,lwVߪ-|\47MJ0ڙ x5,)Db2/%a!թmmr^GS,(0$WG-Zۧ.@K7602=n l!gL Don_`0)qJ`4:ʥ~\/yˊ7ƋNҦf[ ULA]fOHi l<Ͼ]`?s7v+ z¤E\yS}a>WE`+ǻh}m@4}2 `m XD匧@@Py|إmE'#gz&1Dݞ~ow[C֋w۬+T1Ix{=ը"c{z@{+p@^Jɩ^5!XOU\uH yi$kYNV <[:*5R>)WC[[NZk 3:,f ߟ3` jG;#>%ou_gl&oOT,o Fw[TK*b}G}C c _&wEbк{niO\$%*pc`tm">JcCޏiD&@m Ub?f-4AŃ!byПomxqT2!Av!m_"" dٰtZ'gV \:FRH NYM󲡵4msLH &H!tfo2Yd'70Tv 0dN|cJF6+H%g w8I!-i  KV}a~a|C۾ Glȧgʣ0}ղ:ʏn}/8w6|앤WWbFǏl0i( pGFCD\ *0OxT")yo]\!!s` ^ qqʗ>1tOJV}[J g}3|hAv;Վ~qFN@UvR*>ڡH&c]فg Yf#q O 9DhP dٔxO <^Mҳ_ &ttNB4N`,|:ls_b(v\DD9\q lxRYHT"}h%K]#¬3_}O7qx\/s[? );( GNm 4<22p6zBW/ *yqnp0aTn2ZdeA-36~*| .9eɎ'ku /%juS'VMS w\{p=w%XmJL<8(Bl.DHN TOҖt }ayKXt6BMӅjIu]MT:]8e1ŒsZxva? ˖iOީ82lqWuN;M@-u(J"hԥ5?[%8\BK5y퇛2aQ$wޢo~lxMd0a_ckk%I(zBF?u,B':,͑DծS&fuD4/ΎP.ֻ=!R'MdiSO1;fَ#<ۆլ^ѲI:dHc΍ٍ"܁- Y3Uk^]w$P2B kg 3Oi3Bӵ,+)K߾j'D%D:y)>P*m? 4'ʬ JQEMfPvNdXY꣙}(Z i3w +l~TJg *(ʬ)9-[.&\ۆ[s O+e"n7X"[J1D%p땣=cu_S^Yנy@$@!U& q(9끃XR(okv!;z|^M%E$SwЌU\_ %7jh.*`lҵyRߞ>I5y/,k;> (6Zbu݈ӹ]Ɖ[(A UhĒw( *X=e)Sa =eh(L^1,m`.Z63/G=2>> 醽-K Mfȏ ibI #F֊3[_6 h&<m!@`_lKC>O"SOXY'u@ԳX%|zf<^CpF+#[@]*@uDBJH9 6~ G pQR-þ4f&y'ioM5L(<EK zȉHa`*! VTqe+~9h*rhb$1ii _Je`^HK|}D>$䲚.E2F=2ޢ:8lOy׸t z X' tf))ኅUż)7M mQ˺YF&H58"D/[Jјlz!S&e8g#dM;CsҺCVGESA'R;wKCs)(RYUR8O9kG4b?67$[rUQV-m)_s#ϧ㸭B>4eHgb򰐀ɖ}̘Xօʩ]~9E@ ߩ]A7)\j\ɰ-g|h\$ Tc@WQȭr]S^; DjFѨȁLj?zn(#OiHa>GYNXItfV+gǑoQVRX?SL?%(:(z-  Jٿ0QLђs+4/En&h ` YB74o" WQ4GOpX3Ӈw(< d:q7q,RCWa `=dK%e0ck dFN=ks5mmAB28jpoGR[$v{dԂ0eHw5<##BN8'[4#$ub -W\w#Ʋ,^$ɱv>;rs bo`?pҎJ=RŮfZrE9a^JjD;vtec3#Jrһߡ8qߎ'r3kڑ_-5Uךϔ)f\ QȴlI{H!V0NPQ+=)vat05pyN,(@j^#Q3Z@n.A=^b܈:eE)F ּFi ½ʘTa PwUӂ8&U# Պi<?#ȭ>I ;BN GD85Y.Bn1p;ΘR?30)֜G1 -&MػQ骼T*"Duיm6,cܼOS 5A$C+c笮;^ ^W(%?~b 1'f٘G}%[YlSE. [?2ǀ;?l|j` |;wU H;߷؈nDK|c:ת봜DI#ljQ -zifzilI^ |B=$UP7'\ ~qJ[_1W ̛ꚛ^*+LR} FB6-UAaHYC/gm5ېs!=a*2 ~1n^ИFZB'>ͪQe4}ŒD'4j{yz2ʸgi Udi<`zQ6 IoqI.#vàBMbD+N:=}ރ3 drNbT O#y)%i?/ M.j{浕Yx,);4uXƠ 䀈H#bs+(ݣR—pc»n;Q"զf)mMIѦ"J9[ 3 !ŋX%80”mrNOz'[bcuL##8})56F$[Ʃ&s6 hE#Ǘ$X7EibXrO(AS ]O|w-["|X 'Ԟ۩s(6Z:LnGxL- Xi{e>;>;Qc~Y|HC@b̭mOڹT4s>uK<F~Ɯ$~ }XHg{dTs?pVe4E ߵ1U0jWԹ,9:ox%r5bȶ\B22 @9Q!ܩISz\BG4L֏8f3j#_f ji@qv$*DkMm;gqۋF47EKƕfʧ׃FfT?LSUhQTg%XH(2<{ic3޻朜?r•mcy&*LjV)4K/:!$އ0$o=ReX n#ҶD1"ᝓDgGfMXk# Г(i#dLJ-6}\4$^1 ߶mgk24ϑ(ĿqHZQ7Ss7UAt;2Olu[$]Sĵ#/*hL=k&tս7{ќWT.BqdH[[ 1xyɈT,p:GψQ2´Z,v53>Xg~ gp8~ƤڪtI9Z~I9X8YZ qo3'h)U~55xcC }zF> X:F$x"> +Lr{mX k}@g|^m}"ؿMECs)DFP~!㥕Cbvʐ's&(}O6dGU~Nv3k8RׅT .^S\9?zBb6t sG?Q6)lrUlLbzO4E93kL)8cJ;Y,k]B|}c+D8Pѣ+ǣ:Ӥ9Β0te>ӌTW4M>eTU0<4 _Vb%%nI@^4"4O9Ne\P /O(ۻ$JC>jbuw\o5fO$},A3>0}k#cl`!Ŏڕ! lVT1%p \Y/!ema вj/ԀYM !Q}K'BmLOg  U#=2(-(>ve n3`ՈX?myd8;5#LRmb0/+~6 ?}6SHIޫ>ee?J5qnH-唙 n2՚UPZO咮udg'S2HZݻKKv-C1(H&mF@)!̬9#ߦIT Yh[6=+4Pae-6d 0̀c"CE߸kIezK'4 #.8sq{,MvsWW ڃR2p>oa@9,겤;bT`ݯ2) z'S_]|Uլ&ky> Z o]A(JU'%q6M_F}A싯,1?u2(&Ev4 ȑhzGoPLbS2ts=9FsDqF @p1_=ICA"<`]h-ӢďNyE)mĮQe<\Ze6B0̸̫kJwN zh@CtnU(\ +=YР-;s/s 3uྐ5T[y~}̺,2!M*P v|cS w%wGˆQdFEheܣ쨊׊\v@_j`4dC 3UVۡsb%L RԒR~X[>-& g9(>豮]&mOE)ej;P,pV:+1;蛁td!c6ͺO`ș~V>|SeX-pfK1w5'K爠NR^{wz d"i w] Y\2)ߡty=mz{|\:W'0:~M93O}DZU*DKg2(]O>ʰ1o8K/Gz3ry_K߾`"g ag b#K +{m17Z$*qdm|)Mڃ|0Lð'X9ٱZa'jUGw|i9`Qm׿bݲ+A"N=.Z/DXD7u24Ճ Nr%"p}M9VU`lDna=r2] k&25%͕xP3.ur3ŒJ(3tݚ.&2JiW82_&ghA7OMPa)eh["/*=B/Yc{CdQX%Vɏ&)x{ڇ*l7j r-?0~>ZPW1Yюni-EU]V3P] PAtA3: 3P05HLeS R]˛r:A<8 8;/bZZos7VCT}ٞߏựX׆ -jlNNYvIP僵F펼b|Ed#k E8a?3u5ֈUZό$a^q7'j$[}Xd Xdw?N>C+NQ-ǛhPx2R4bmQ Ejn'?Q3^Gܛ-iAzS̻3;.3 JםKC_Z//-]ȼg͟ډjtA?څxGQ>>_EWY he|,s2s֔L 䝙dK@ [x!8LR,Bw'CBxwx%;tw.=(8 mEj"A=J%$W[$(`"8Wi;4w8}xSOfe6"XaqFU5xo: g žCVJiP|z4S*w2P9 #Ts YZ