libipa_hbac-devel-1.11.2-68.el7_0.5> H HtxHFS ?*}},㗓(B@Tv|}e:SdpS9'8I čC eff641b85af0d3c91d721f30051ceda0629ce5e7$}NXFS ?*}} wãH_c@C dHBXw2b=l5x>9?d & E !(88 x8 8 8 @8 8l888(89:KaG8H`8I@8XxY\8]8^bdeflt8u8vw8x8yClibipa_hbac-devel1.11.268.el7_0.5FreeIPA HBAC Evaluator libraryUtility library to validate FreeIPA HBAC rules for authorization requestsSsldist05.fnal.govRScientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxi686 \ ; ]. :VhUVV:Vj" lb{ELyRUMAA큤SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS2c9813a080ef39aca65cca46a79e78ac6ac4836866f849492732d82c14732df85827bd1029a6f869886906984432a7a1692fd156831c51ac7f872a5917d2e7b75cd6f4eb01764f02d2f70c79c237ce1cf8fbeef874b661705c1f3dc3a21998529e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58b787da9551d9e4e6b50f1d2d732e9bf7d729ad70cc3081723b3703236cad8f2b3c98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830603c4e26ccdadadf00531a187aa4376b93bb54dccfe8b878bfd0916df4df3d3332cb41c619fc9f7f7f4f1a039421ac2451b3cb03697905f4e86be638212af2dc025a62e9e302aa53b592334b7d85abc65faa28ffe555ec539a5b6aeebdfb0b096fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c8ab7bd003ff1a3e51514772bb29ee7b9445d7155a62831f255a0a9aa884dd5315c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fd931848f71a066b1b7b8578978ae0f47473ba293b0cda30a6bf2e3e20a2df18852f72b3b729b00e09a0e1e36450b062178cd053a56d07e9a22112893e54f495658926d0f3dc348b5e0bd90d509fde6d32eb0253c7c65f236709275f81a101f58608ea90696dc3b45bf0f9754d8dc3f5b5a1b0ebd0665c942ccad76b6198a0dadbb6438d4a64fc46474722848bfc9c4019c176c452ee6c2d291655a6a547725bf41be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562be22fe1d60222ffbe971afb619cb47d8204ae04b807279e7ed8bce6e7cc59dbd44bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a45c30cf69bc111a4bbd1d8178c48ccf1910042555584c93abad31d1fb3fa6352215d7d6e5c85766905a85bcbdc6ff6a0471c8498432341d57983dd77e5b98c03d6b2861f9b329557e689d5f2f833ed2cd1b8187f442967c55494be58a4538245e0866f4ef1f24d454871307d0fb742cba798834b097e2aa11326072171d58a50b1f95633f010e90231ca96de575a1884f00fb1894d7f66af8fc368226ba9bff0339bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libipa_hbac.so.0.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.5.src.rpmlibipa_hbac-devellibipa_hbac-devel(x86-32)pkgconfig(ipa_hbac)@@    /usr/bin/pkg-configlibipa_hbaclibipa_hbac.so.0rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-68.el7_0.53.0.4-14.6.0-14.0-15.2-14.11.1S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456781.11.2-68.el7_0.51.11.2-68.el7_0.51.11.2ipa_hbac.hlibipa_hbac.soipa_hbac.pclibipa_hbac-devel-1.11.2htmlannotated.htmlbc_s.pngbdwn.pngclasses.htmlclosed.pngdir_306d1f7c2316132a5a1b654ae206deb5.htmldir_428d51024abba00bc838cf4c5625f90f.htmldir_68267d1309a1af8e8297ef4c3efbcdba.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pngfunctions.htmlfunctions_vars.htmlgroup__ipa__hbac.htmlindex.htmlipa__hbac_8h_source.htmljquery.jsmodules.htmlnav_f.pngnav_g.pngnav_h.pngopen.pngstructhbac__eval__req.htmlstructhbac__info.htmlstructhbac__request__element.htmlstructhbac__rule.htmlstructhbac__rule__element.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib//usr/lib/pkgconfig//usr/share/doc//usr/share/doc/libipa_hbac-devel-1.11.2//usr/share/doc/libipa_hbac-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2i686-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryHTML document, ASCII text, with very long linesPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedHTML document, ASCII textPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,K] b2u Q{J -#"H68,x@¤ MY /bt,)4r.30_=8$s dR)e/z:S/m*۶lL^-=^n=X( z=#j{YŠ9@AskxQ}>(g6LMW4ZڙW?Lc|~3GBm[ %>Su? JZ2`J_oD*ϱrTpdB3rTt^bLGN㚅A% ~E#<$ ڱBNͧhH!yV텧d :o<}w o,(Yy Vt?9 +H5F c4%hX 81^Iiʅz!TR7_PrQMBjSaJ"A,$@LICoOQ&OG;![<5CWA(CPKe!H&<0ǐN[%C?Rl.<*:8c(3Ѐ W(: Sv/ ex4`.̗ynQDvdZ+l.3$ّs v} p H^Zz!4J (_1!@9J!a ç{}^T\\ehIEQ`ݎM:m ޲?=}JN!/l85nOpbHL!'B\)[K0E쿩K[ۼk8k3fsraTH&<3E%]ՊIʿ↋u[>%6 ߁mVʟ3YK8[-:f5oF]&sK&eA~3zexbԷm}4 KtnPˢ?}=.p-)8`9[%֜WcxT^IK:@>(RG7zށf;.QJD|aYr"Ƒ:g1CRS"B7 u߁+f&, a3!$&?/xO=irq?j`nB@]rLNHv"!plw-tn'7uJg\f5+^ ]20fߞ.01#,#ӯPo!F;UN֓i6Fڌ uKxx"+4{=?#`ءf[x#56Y@.?\ڦ8U7 o-q/G_=ƀAs@@Jـb:[qpIMdrM&&m`Y?WSAP ]f1&ܓkvr8 ;ۤ`l5ž@0jcr=MFrM1eajt8( R>w)jnu4~tƃʵ@ǹca;(w2j_v^nfjN] Ȉ-;ai򬥧mN ^_foE)*9@ FFHAEaqsD䇟^9tMy/Cn.[*:w;37`56w] 5hGh!# U0i"$;l ˈCKccߞma%ޥ0VɻoP{Ovsx5”S GsB*KH:ȇe--g\҇{b36`!)zFj Gba80[nh%R-F'vTj6~R)&"tp){=H:Gp#sKɵh~Z5Z^`:\[Orf-}f˃[L3A5 0p勌n4|ssR\+ q-6$.{n5؛waky@@BK:L.˶H2~!"%謁Tכ>BɄo_3y*3e53ʭ7 oWs;F͒]ҁxk#[jsUlB| OsIWAM<[V:{ tܫ1 x׬ W1O>_2Jb?*zMgrx4qncl)! y,46 'уP:!;׃* ٙ:2-OI](hoFC% ο$[=\] ;{So:oho~1eZjvRƏΎ{ l-+k<3E~Q|3~+ Qb .&ă;ݔ% [|_GPNLO:.]fW+ěeTv$eT|/9OS63ft!rT1잣sfWU, 6ZuiK<}V|E,S/_f7Ύ+cm[8~ZQwcI(S.e8mV+=V0|nJLBY|;K#|éb_n+ܵjעa%हa;?CgĴHΞi&C3P<^UW7 K[&'̈́3>4<uo$ (P e='JX_'DkR)r*5[ L[zx1%.NC_}!Ђoo KK <*ĒPqqEyR#zD<Τ0? 2d;<$V0hasٛI6˟ydv}Kw|DZX_`-9!<G;'v'Si~{ExM*@"#=^J K@ ZL@Ag\ Cn rwmy^:@"uGƐoMO#0e>U;wF@ q:J_Rg@!J^ClAmገLԻ* S6M|W yw%J0z^'FDZ|qqŹD-ѬiBfXSeUbNaOKW#HTL/窸O=#,I atFJnn2Wpu8 ympբD\ݐ7Z[?js ('ԡOV1b"u1H!ExaF-+ ̃MJB1x&ި-%"0xi߹ɡr8d'Gn:T!w"HHng 3A(Q`wx%>k{p˝HT垭v]eiW{*_ l7.2(Rޞi @A8ٙf)t9xNƆܧ_9nG<."#f2ؘdM.[ Qh RNX] /[H9|V\mmںEcvj][~QmkKşPQHh7u B6pk,IJEۓxf%r)c?rۖ -n|o', rT>eIt̯ٺawo ~+ȳzUK$HfyfT.iɰoPT73:]AӯO˳U:WW/A\l?;)c{'BYl~o .ܒ@}E0fA%eDusC}g۶m˻Ie?4/ЙUh!r?:D|=cs2-:{l˶Rߑ6xJXbYF d.ap- z$ÎnXj)g}2(*N8 (uqF  +YBOrd=.ĮCpZ)U.Vu#j8e]#l es~0iLtˍQ`|֣dh/UR5U9H:rh#{q{AG4@J y@ӛIWG>h;='WmO4P"__=>*&fx1$2?͓ 0! Dކ>UkE58e~5I{Av~7'OWb46IRgŚ @52DV{dI=}%֑ͳ#6 +ĦqH=Y-QeĤygtoIĊ6EN5hig]B:._&B8ֆI̺?q@~v2L*0~7e.7U Y](X%^mc*eQX8#Rӭ4G"pOUF3NiZ \/9\sY|3?n[r_Sdnղw3MAۜZmAJ] E2a ͂^b9n gZ׼l /t:<@NjV16D6UPQ)nG6\2A^NF멦 Yx}/Eq]S"NJRl6A0;oF}  ')2V[ ` 6^5wσrYowU<my|A#Vg\gSxKCM oDzrXKg?Ԗme!J~U'7CUB3G 4H.~΅->0 DdR9l-j: Q}2OI71d~GnC9ZvĕXz^ɬfX^?C*mv Iì8kq [/8ޯ6:$Es@)B6>'7I=`jnRt)]˾r.a|[Cdjv> *7Lj Nh!g$F9k`G iW˟ D{sBl+!#KѻA$>[ It@ij-R GU` ںKH*U=N7><5З5Q](U:w0{]Cw S:mѬC8dn8`@RL%)I?5:BN3jFo?zpS0L'p 渟лJ-%g@ݠ1[:,1pub㴕mV -TX^iziN`tЬ Äh| cVҺmRtLu hZSCa}EB4p$PwJrbGcl_UyѨ't ٛMlHŜ`K6l/&L࿏&ݬRB`B[s˶`#=n:QL .|@W{+ l0!޾ %4ytv}Uel$7u7΁I2D&J8o v=% NDaO3%Si7!֍ӮvYW)JRlphhвS3cz,w '1sL;6>z\aPo#%vqy^ii+ȟTtݑ{@yۗd7۹ OC)i^&jepy-eQ'z-8p_d"!!b^&*3ڼ$eazBhF]]!!J23ἂ etD[گ1VqQF7Up[SB'iA56{nʽsXdܽp[ْzz,.AݏFefwpN'W*aN4a/u: 2)dKR2W_[~M2G_ xmPu#PR~ e:DRe!e#vdp5u{K] 3Y= 0ŭTd`2'K\1š%8l(VmgɨΔSƧ]cWͣ1Sh$U?m7!RD0鬮66˳ojUy: y˂>l>$ U&4`^{SWVKO?p8dGv[=HXdFur P>2_&ŒpY>PjM_S~ 8ӻpGIU=#m;菥·0j//Ok`5ey>+ YM,t_yRKLJA0"%s H: {7Z֫TuGG/suwjoUdZ*K{?qV:J" |iiYezbʰ$MDN[t՗eSYojH9. L0v>WgZ.R5v5q<2Š2{o4tr9ȶkc)S%dh\.|/˶.ٟ^{ 7+Gk< V+2馔tL1&\8Au?+^7QIvZq EerpKrBכ0XKghgGOr%P0 xSUwdL9H݉CyJ6E_ 6;Tf(K_ZB \,f5:s:FYQ] ŗ8<3q~43R_cV p!D"ԋ PD堖4v,l72\L tÈm1p;6V*+ivF$-ĂgtOyĘ+(_є_] G[D>ʴ]={!X=?ocΗz0%&J2XJ)? 9)^5h2۠$ ~ _4&}0f ytYjcrD )rʢ#0\N5^!=%t b?@q)R]|mЉQf# BRwCKj`Z[-ĉNs'9>#VOCLi_C!h_֓ɋj#t!'X\hlXN#()Dv?KQHigE@DD >J'!a$IROQj-y~k.>N;j5o{v IH/&  6JI^IP]J2NE]1$|[[}2ghZ'2_w2r8Emmﻞ6yT< U~C#uyZ I'LS>m@ɘS39Ajq_K|%oQ0"JwaT UhlL ͚t KePz)O}UWɚ; UF H^b1'\n#6%[8,`\<ְ{ٙM$yI@ +dP͵A̫pY8 -lZ9m\).-|PZh'rp?iЧ%:;ɶtq(f 8 Im0h>fn ȱEڴ[5Ҷj͒Ijp;M1Z&#io?1^# mE0+ߒWZ{çe;;Yl6!m~NqaxFƈ]D-dæTϿ-y9[¦@}/CjO\|f\5̤O/I3yҠvm+ߏ8_ӱZXotNu/i9v!'B@l{HrBK;s9oHDqeyyqzDN/io#}N&^鬊Gfh5Kȁ8.cbYz?-[xic>]LH;CM$nݛyJC Xui J7Ji(sfNv(,M5q_gRd-x|6p+(\S-)IooH *bE={5LG\6ڂMttH9biń& 3<{+(D12HS˱r!PyqiLyJ3HߢɽA$<|E_k=?b +tƲۍ|`}N86<<[žz0w/.M{ }cW(agtHEd:]A-Y4G`$r3ukHl@i3IvЯ'vjϓ{w9_UXPƖ?]K' [byQW3-"GjGd$~'kUWDr !.g34%C h?RL@U4~ipnTD̉&8BG D}ǨPۙlmPZM#au D?J!=0yboEWK6^eĦwqBD>&^S j}y2djܠ6OU(=Br6md@\zR/I/ /.,KQڀTX"$^+&X|pU<`CUh5n*K)6i3խڡ.WtKJ3j"$cP m {#^y4:)|y: $jtЉ$lZx 3./+Ȉq&`Nj0)O†^*%|} /#0_FnEcZj6WzGpWf5yM^,;6ѕjϊaSq}XxBGvT F!: FJX=Z`}B EX0Jr~DQr<a`\O44Jxp HOƅиK Io ZHKu&92!"%])\LeqAaeYgNǞ$~m U3/_WqX 05i* iZ'IL7)q2πiOE;J;nd1  g.sjb$w.mGTe/!]O BJ/S]/-NRp+iK^268).)Bp5Ȣ!*-U@װKqv3͛/Y~Rq*{gEAèQa`ѹ"($3scq#Hjw]f C]іH$V{伀ɥz8Yyτ tmM\jEİk^>-'e6llk QD]`̰*~saZzɗCXnH`GeXӬ=kZ3"gΙL[wS!9(;Lfpy_0pcr?qB΢rC1༱'L.6LÔ>λ[["F١+*cۚ7[dv{!\ޔ_e^3z,7Hs,Q_RJ'V bUΪB5"'^3bc+]뎖܄~Ydo>Lj=רǠc[W {ׂdt:q8D/^o^اZեS>]1T9^Uǰ-H5(϶*1abXT[qwD,7R aԩ+m ɸĴ7Zf⁏ ooXyǸgkξCh"/DM<2Ď'phkUZ篽̃$ᖃi`nự蟤 ? f:!1]gqXW7k4vW[itץ8l: Gg#ųꞂȪTN5`eVEˆH$fz݅c=`sLܓcVPtbcIΎm@`'"tWcd$Vz7I EΥ~%zwVgvniܷbI4l2Lx82T{X/Y&s"h H&@6 ƌTC`)Ab--#@RݦP۷yi02Gu?6KS4jTS_N'4uޞM+fC $ v Jy^7ׁzn#4,6)9EPnWWqXZ _3 ͐uZn&LbazEo,rܶ'!dRJP^H$3Ei84;eg׋!`A$PZߦ߻~-#uC O&Q0a@oyVX"yud]|6,P |WĎI>b*2.aH ca(4Il:0G$؏G&ic."g 3N8:xTӳI:!;@>&(@SgauseI :h (m?F* )!bzb[]q!.,=f~eL# 7>E7EYL 7i r:VQ ;UƛAP}tbbPSYqyhduY樍]w̢yJu^EvL\aЪمG6^G*xŘHl~*3络8\نQV7ǽAR".qQ')X nbn*u:*:Mw.C\h_Gvzs{Y5h=h]TRcA* 4RhT-"Eh7 %yMK*-"*8=;)>$~Pԇ^| XpS|>Tz4d3VaPiwc:TQPIW]͟x~ԉ!#eMBe}=XlZC5R dlT+L<ܠ=3GL"/"6$P1Jn"ĴUG[A솀ʪR KXPOM6.,Ia?߬gDCr(Zܹ:4R"y'25zm4P|LF{|g?-58ZV+1ېGVc!/R~jHOԈA5Y7%8)zc !'#m+Z3dYZrLѭ ;pVmΞ5WXpeiv"%5qHKX;ru^oYagr*C3P.{N,E5y,'$Nkr (k`CkۢEØQGQnqcʇOg <̓;=2AIӷ^$V;s$9 ~hƞK ƿ]DnR&`V/N+_-mֿA^)qx[ccZˬMU:G!n׆y,mX0=-g}mCkڝ&\Y'SS]JlkTH$r^&s6mLA?٠nM lk)VR)1rI57%p7rod]v0K=7wo}gQQl+ΜaYjo:g7^'MVZA}5Ch< W^;tÕט'5ϥ,$00߿cΓk$|>WWڍC!Ñ%El!yrEOU]`ɤ'G#6ە$eC >kv(D=a/_;Y5 .m#4iG1!_ޓ>5k{5s'=k;hyv&&. /.gSIҢ_FU#sUķYYTp]'[V4C?0r 'Bb0ƙd-][8XBQMwFE"bJ^0??C sp[Э=tvnHd33Ly*mtڔեrk!^kCHɵz]3pb la;ݞҰ(nDe x3ؽ:+0 "Y5"p Itˉpy[+q.Yf=HVXdZ `U]4bC5umEC7RZDNe%.|d֜37 8 A/$ӗHb*Ҕ4uOlX';/X6jUG B(SF 1k;Wx%FC5E5}[۫5'aFQi=\/،(v` eɤRX ޸`xyE&?~1Ik}F2i嵬btqsWuq`7T3P'e\MV`DplFA{ n^}1"A=jH(\8\i;̶6Ց/g G@c a|Id]ɩUZ=sp4\ɒ:cV}~ x~rGyVb0%{cQy(ݧ4Z|/DS6 h9ߌ+2P-ҥAqu Gdž:x?kʙZ XtBha) Nt@* WkV4ϛD  Hǜ JK{Y;HBz0(7FN@A)D\eJ)x>TcFߝO $k}Ƶy/^?Ļb Ef|lsFY Ns%}@= 5~ m^k! )IƤ֕.~ۤ_@[ppWA)u N/\ EhPWMؼ Mf_Z|oUZg(]fGiwMYEp0囓ځMFBg6 C"*@b8a!ܞ$@irҶ6T|zfn @ȍ 瞑kq#19B&:!Rz,mi[+֜q4Lc$ 3]&RR*2[k٬eW<}eůx LE J=rtOUTn-^ON[&v=W(exQSNY}*>)p2l* %1"@32n\6)oσ9γ[2.EMCvձhd#h$u|[AKywҮF jnQ/\rIr$bˉ(D @Z0?3iR.m94^fi"n;8t ϝzGoSjg.,A~w{jCq<]J 1?9kn˻.H('L!fe1})Yዄ+2&#5MnA;÷`V&l@ݣuV4 y!-pdGݏ>q D"DWd;'b#1Slo(/SI|L! K]솈d :b뱳uMb' u\^PU_ PX4c3c'Ph{CEUeKTVmrN?LU)6+T{C[JO?]{Ht-Qرsԗ1qnZՐ<'2 -xP Yp5$Gq¥_ fC~Joשq*Y}FI'))G\t3 BBY;nGϦN:E=<hy)D^ EѰRt޾vm4]vqPْB6a.62v26*ɔ冕6c.9li+t杌Z}mڄx- 6/R1[ r ./9#Ke!h(?I$DvVP b2 Q=>x_TG'8G#@!?dA| eG-A*B@,P!!D+l fle\D &abo0W}}:}`|ݍw>nc:Sǡ:X3dc9\#ܜ^)mzaYNU6TG﯍Hr7 / = o"&JrDzj( _|%_HgsSӿ(wdw )a{^5?.,̏@2@pʖ^,"YۨԤyLAn l;4#)4nOnj,u~p@Z91BɄsS: UuԪ2kZNe>@O_Zj/O=\r&~K1jصT:}`͑ @?4RBPY'p/$*7h=_( yc?K+}4--ϝV?-h&uw!BK]7K;;juKǽOѠ.m!Sw&~o|Yp!- ,8V e4|/b,tx[ g̭W-ɮt,񹧉}̟Bgi { HF.9jTsq~ EԻpTb+#$OVӖ'GMILK,v(4e4#b1CGfa/puݾ7'Z:}y3|= s Bʁ<rGe 7_h:EHYgy*UB͓1k[u[W@(bXtڥjafiY-69vY|n/)pjYZKҠ[e q9|qԼE3$CM36EVR^Q.{Aq$igDb#n[UW˓dX喇*X:ئМJ7:]战-3:!R!ݽ1C \_TLSudȗ\FyRo?VϬ(쟆pp{|6FSY758oG2)ߍ(I1qƺcLs03gFXH2'*☁f S=">S0) ߢrt2zjA*G-\q}y1q?n5,{j(;J3uXQ6~.Ǩh}'v%s=O&٘AƑHIr/?}'C\#*H7O'q"f8ymN$:bey=jck`kBL?ռ %R%1Wco1mN'~68f/1v>)d.kWH(77sׄKX'JٶLeSRZ@ ,W쯱g䋧ً%LNBc/}vHY&o k=_oMiZigr@7~֞MqVR=fra"){[lp4b4IF1]* )Wv>~\Tgyur U x͵{0zC⏆k ˆj-e" ͋]i!T||+v_.>LŹ 2hkW ʹ)lfA^ a`/iV}*\fYtgelh2X)[,W7;M3_/ z"+BɋԔ]x  BAʞ;O .nG|KCSPbaZ;u s4mMJDWQf`[QGР-Tj $yx|9G3#Kb'X1vJa - Z[:zSW?W2d[ #G*U~A}]T!!_''K uf93[#90]6}Q*d~}/]P!F pyHzHxdz盨 5Z P -Zzw),bH`QnC=ͬAKɔȖ$NZTqcW3رMcn8WH\?J9pG:!:"HV7T|:zn%9BCвAJٵ1:T- UgˣMbit쑆FQBiiIIkn/Z"ҩ4t`8-fֶ&zVHPd gt]zIZ7=E\{zQ 4j# >|l*_*T=={5qwzy~,^2fE2c*.)e(U-/;&P)sOt2a aN߽H@+qfK8RҪ))|iMX5AIaXHb `;R53k1E$M&D6{7W=Q  { i>pjHSWHЅ|AO݉P.Ȃ1ۣ[URQ n]Dc?F_k2TSr5Bf!:XF}LҒZ;m)ZnĒ J)̫G:sIY1~-nD GTޝ&NJz1"Bǚ sR`t[$G05w/nŎDQ; ?_bK#ٮ Ê~cURm`V/ 2Yp` 82IF( mݗ^ j[rIyvG5d4"VKۍ<xPCОÄK. 8eW1iF;OcgzC|lT 0ւʩUE1[0H\I wΉw-܄|dliyQNrgU뺹°;xzu*#>oްGJ>Շj]#Ib9ѥu2\h;ZPWvka7j_IK(ڠf& nմܵ%/3K5F;A?ԮC4+V*?~$fhXwUc)7K;[cZ5þl2mE;6mTy `6ޅ6r ?'<܏\sg<=M¶P^0o_g[.}f+A@] gV!KdPV',\!t0 rڧ壞Rrapm+ԕ5RI7#íj4v+ӡN8t_W x2 x&zƻ3ye*$5+g  \!׸mWFsbR zW.p1U}+>TLE;7`z#\$JZLQE=eO&rg0[Zʴ0HRr˰4~}s.奢B&Ӫ .+V3"67 0&ǕWU10HG4hUOL)+J>ǡ@AkM1dM ]3B)o৕K ƙ=wUpVd4i'Eb\_9ax]rOKU H^ӯ1~wz(avIZׄ"GZ>1}0@rYQPXNoN ULBDGl>؋/=|E=R8J}e#X<5:d?pD!QPcwSu9i I-ϛ)M# }S#cq5\{(`hg7;v',.3Er[MA ?:qk/֟;neᝒuJ!.Rikp~MKvQq}h u rfB24ѳ  vfÉt>7~0&_R+sȌ)* >yrdafj$@^cB*Tv_Va?s$)nP< >dE$D7z2\#<޸i]2vZ$6~R oOzUV52mSmT(|'wm܂'LA@j>_gR1fs4WGm\5jS'3qӏqK,7@đNd}6efnoApPwh/ޑ>KNQY*`LsAFq|t{@ev[jMhA"!C݄5)BSKQXfv: ~O;li;b%볗MGf^ܪ]}I抷SU?)<tF 0[;4Rhq"Z3\GRݔ/T WtNTUvgn_P-){ nxm) u8/'(@/@l8!I}ciԚLM4e8r<-®| 5:Hî)WhԜaE }4V&16yGܳ8n$jG҂[Uׇӛ8HHHg3V&WaRP\vRK)8qڦ"tBW%^s$HWaGb5Z[`';uǫ=4.҂N^&o*&cf|r(5B`,>4C|Ck4i'=o0VHdjAß=l=JB~31t9TkicC4]߇!ъ~6}Sn&6XCz _a@J$=8o.Xű I/H֧v'&i=1::{W(E q(zSKޣ8/( v~0JJ7+;]> m-#Z@ ',nR4s aPC &GUQa}Tކ#lia6ұ+Ycڠ<+p"a+~bA|DBku}[6Q.fJVDi}#A)T+'Ps6:8 (-ޒ0.YXd6}&'Nw @Lߙcϭ6/B)]Պ` BS⾋tF-kASϺh"qq\ [߃Vr0 SϡDQ;Q3k}z]-2曞CR&~pDڴX0dl6vⵗE k.nѕAY@\=XjiZױB(eo(8 b/(x0|@,1 5@<&]\yreLA5)Y$#)q\8pO-nAхt$;T:z$zpBJ|s^_ oקbEۓtPU; = : ը4*=N#Vf!s,~Wt$LytnQ칞%?G б /;7Xq,>cT}51` Q^LÇ|(g!h/A5--qP'7R$bYӣysb8c&m١iX.&˴3}cϩOz.lP73'8\MDlb  궊=`r&*D$,hb ;ax%~`cwz\d8Aj"r=/Xx{g`QO5Ƈu\&u?KElx!C=/߬sL>A\~{">(3Lb]ynUeTBM ^5u/dK˿ WvϷj` b68 汖 w4ϨB5rNƢ  %a8}`p#͹S#ͮmYC>Zzپȼ:uzz6 `{̈w/ /8uBv,ѵcv͔' _`\_['ˉCzfQLflƄ.DC)v7EG% ,q}J65 q~/{Ә<$`"qK*]J4 &EfQ-t7xf?4奀tωC:mtZWasiXv [{SБC D&Y{e"T[K&^I=4ȉpXݪdձwf<*+춢7=8/ULJLMzI 0L%g&zӟܸΒBo_}#G(įt l/'V2#44eFS]l ]0О>)_T:at伢jD v@ct8PCmD_ڼS lp!u vn>f^Xz s v Tˢ4 4N??A4LX|> rxT%zُiLH9-%A>7 /zVܲ*0,k8HiU^,~m uny܃,}_&rR`.v[&`2=j` (Ȏ#?3(M$F{'ٶ7?iz vtaT;7_3` f0v_g XD6Fzh˿kȗn|O(B% ;!b%T۟F?lb͖<qև<ܪz0G7^2f _mҧ(!Jϊ,JuyD00 ,[FU l,g*1K w7дȧԫL}lsV/;XW@=ee f;f4b[P+:'Q<`uBAؽ\_w|g4\M}x%N+_V @ek/՞QYlpuj&:٠Q'zszrKsz4uN ~spR sҝ2nT Uav4m:q B}鈵V23K%N ڋI N^-r 1nTΨ5Z^zCAE`ן2Y]To5=g T녔#Gznjֲ*r{=Cֿ.ʤNJ֣__^qyNɸR6z4 RblZ@)BHG 7nQZ@T򆃢+چ#53]OkTq_s'd >b]:$jƉƌ8'Vf \>Ao꣣!]]6ݹ3a6jWcIX0Bsc+RqϱB1L|]h˕(q8.%Hz1c;|DEq2S t3 ׅN)-835~z| $6aq5$kK_AQ_^3!y +^zW&ulR(æ(>mN|[:?kjl|f"^a5 Y pxV̱D}~( &tvawЂJFO%>HX)p_clA!?jla‘޹K;RwqWi UtVW;Fڈ]ھvRA̬QnP4HKk13jlMA]ú9MG.Zmm5JY} )0̹1 [87\d~UGSw# Z},xfKT9S&/ E8on74k&jBDf"$ɬFGḼ`R|yl@>Ia4&qcݸ\wZѸΑw[*We0`0]niuN7׹78-ucj*QBaY֑wry > zջ;z½lAA?GG~;P3iSπ;5: \/Sܩ.$!s{{xyʣUur%p{C'N}1ZrL>Pۀr3Y#~x~Bkyu<~@"FpQ w/ :g%[$iti3em&rv#ոd=M|H. ;x\ȑn=e; m', bVqֱJº'O#K ;(D`y#RH1+zWk% d~nbdMܹ0jXBVbp Cƣ?_#a ]Pmp[S}]f'Bg0~N$1[6ic仰bUd, $f^q*@F-k`:;R$bHHD(xP (Li&AwRDE&Ҍl/w_@ԿQ-͚ͮ Vr567qm)J^:#Яof1WK܆,EoI6'+f 盉[?L&lɓ }P%o%IxIP4j0+c ~I/չ+^ERHu.(m5Z(c)=[^ghFl^8 b/Ox8ZiI)!D?9ҋcAb1}܄b n} s}y'ϣgdظ\NusPeW}r[Ҫ`T }4+I9cSlNK:@& 2,_oG *ZT#.>d;`Ѫp$$6|Y|KMʬJ^FȚF?AZRrou D/nF(O! W{=s&/B:Юk<zd[3u0Ӊ߃N^#k2U\syn/ɥ,!G2ڛC6`WvDr5toCK\LG9gIdzW@C^?Ǹ1*xc%U'YąDWP;RQF[;ug&xua!Yu7qJ*x9U̴P3F;ܢ E3XC>b>7:pDJO6r3%Y>|Lc)ߛ|@({{$dwk*w +#yKU-r|̖ӁװpCCF[ ;UWuP02BR!E}N-z;6P` M*\rCi5s R'5痚G_ kja~k(pB7c=yd2*3n+[<^bHbZ-$3(XwW:7Ʊ _.<Ùt_J`Шqʪ}ݡ񳙢T%ˤ |!~tS3 ]+/S0*woؼ;E$#-L6}900Nv&ANZajRm3ͽn 3C}/i"Ҝ%oE|Z9@oqJY$Ko`cSsΥ$lK׉TK"/ uq 8p#W`H:fbVo& #٘d8왵yZ_/\yz9 5f-dZzqeUxj"y۠l; VB==7NGC*t.1f#JH@`"Oi c N697t@bkٕ9ZIW+;vdH ;;ѱc=:%cfiw/d Ňm~]+o,O!\~,Vu.yJ5KSA0[T'T+.k.r:ڽK v6(M.}B g{ tO[9FF\6ȁG{{r&I[|B κ,?̼{ [ Turzip03{A8qa&cQ Kk!9fA]uB1ܲ$xضC""^*mI@B>ݵ:&%M 9Z{ɖl|$_;`l+{"zf #NyH[%&0!!(yc!WewR4AP̭dҿԩZ0/gg[Z@뀮~ۈyS5xKC0X g}kݙPR.bu$gT[dmFIV ,1'鐶=r-ʺ2Wk).dD:Q0/OgaYP|m,6~#T)KOg=ׁ[GEAm1Rt:dS'|cMO'xx^m8qW.:*%w59ȉ OF۹R0Y Q2̬Ѽ܅qD?Ϭ{Zol=X }S'򊩽&IR bG bruqٍF4|._",ǐeof K$BA!G,.FňZ09_LDwZ9Bީ%ﴆK*鶎C4sO^7b!Z7=AH1VЦ??+Cq(^{szV_p/-> 2FD"92~S96_&B`]TOБ5d&dFi~rHj6wy_Lےf<4PomQ?tq?Y]ZkŵKDOty<ݨŚVĽzdnJ4 Thu.W(DȲF{!rTe&Z=C%s CUQ\-0tց<~9/^ےƏh#$IzDH3ޡH"6ǓQ&daY2f cOf|ˋ 5p5$ӯB#-,xw9_մS3'dE7KqD`憵I_TZ# xl^ \_CB>D1]ct8up/k/Bm"KmEp4Q,D9\]\T;"KH\;.㡯n blRL n ^~a/h:KoIEnW·=Av K|hoR% 8ra] o27q휉hPީkw2wf͕ܰ&#-j_USW刳anev c*S:oo,Ss}?D଼n;nES~k@roC^s] &H<]qgNx]Ci} (u6*e3je&D5 3 Ou;c>ozSDgWZ{պCa>G:[h]C.o~賉k,c})Qh|^jZ%xgzs'G#tehl׭=ovb9 |e{1"cp 7 F)a ȆrGzgo+޵E-< 8;dg$]ݖ[r34$&D˖gq% }d\;ʟkhDR_hIc %۹qOz`=?MB(xQ)EtT&>E> OwsZelp%A #!ONjt'՛ڇL*?`>xEZRe5Kz AUAR'+/_3s%SaRWW._ V<6{J=>`8:Wu @*-3ͫ Y5tBŇ#tu;-Eb\J ?U*@KPgNrqZaZTxQ iRs]{$2hmfADS mAZ]{>AZB: OأC4aD_[#W ]2??~pv9'!~ϜрJ0cH3+tʾU&9NGtLn_cZ{3'pGOg`m^{^|FY vCNlR)al\8Q.jkqĎ[@QpUd3+& ,yeޣgZc%꒕;Ǖ|͉1}f~E0,Q_8J{ ߲Үr8쬁X_,OM$ epH%sN`h)pͭ1&b❄9}gVOD0Xެn(UV|%,wOѩ \q /[߶Tjl 1Ī䜆"JgҒu.)0y$yx/R] kil+ pYqx{уI[Z Z ɇ㏫D28U&HiNN¬Z'Tw!ǫivR$vT8ix '*"LhMd+MPSb@\[O{s.r:N6I!A@9ȅ1Ȱ]g$ }V 7KҋP=> AHΚh:xvFݙFZ~B9*_0Ebq\"<)++˂_!K$q8s\Y8w(7O~tޑzvy+Y5O v~)n/~suzǀO[BHηr}揙@L&`|'Iؖ984WL):זUa<Ug1) M,"$[/ît4۩.zDvc)oxI 7h)6féyfw6Wam2 sg#g=7`B +^"֮,v* VJ_"*rqHF@7KjG9.[^> Ud3 [JƝoQ ك@q'qv *o]#s?飶&TB͒ݝΙamo+vi:>MY$B^d¸DyVÇՖbB!.=(0ZtnmKRs^c1QR߬XO,5;[>UQtp~xlۤvf߯s|Qc6C`L#|-T*T(`dNiF; u0"soǽqE ܰj+b# y/]WP2yq-~X}o(~'qR.%&U[Y_6|QTktdVJv0/sdjH p%i>- O٥c?doq"' VC_K3gˤ]VÏ!Uy[hCd'm19کv$c'{Vש~Bj-mHG@ǯ5\ܠ0moǗG/:Ǭ6pr;ٰny.$cp[ԳrW #`K$A KI)EE0~o**NII_5F!B mB(;|tIQp|Yt4Cuolk1ާHQ$`6Vòc }[Ԇ2D]mYXm|?L FzތP8塚CG1ל](xQ3?,WUh=yU &GPProij bݶ{@|}'˚c"m|xQA]ID7}Y &?@jt*#YԵ!50P8mea ;2DNsHٟ{Yg>#/Bk6tڋ-ݔ1lz!jCaX-Eij@W^mZzH7]Vt@+RDeo5*,a[ -hdA}Xn'~RIWNXqArO膧k3{qmדvURuˉ=.阰Ћ`"h_z;< *t2_A/.#K4O;ԣqr$\x,Rc9gGcԭa)Muݖ6\zaST]8V5rүOh.#I\nbg+t$Fg>;(.u?RgxȐ~>T_i14E)BsCXrNEaT[1*&UFǧ @g򶊂<%G\֭UյT1ۆR _Y߷@^~˅f} =>8/"@qk"6#[>.$di#CO{S"+Y EG: -reͷX$S&S D+b1qǸMRi&?PN(ik?xF?)c'mZGo.pmY_gt1Lؼ|Ŕ23H+ ފ_.;I!s?!\αrFx<2n8y[ĊwNjX .ˌT3sgn{i4cTEB8u3fhө՗bƯSi jPX-o IH7#\cSªɆ@h"EyJĵRp@ j$,E[d`;9 fl֣n#v[ؼ %! فc=L5fOGF/spC[ǰ)4D @u6  M8rY*=rR|ɛbMĮ!@6+JY+E /+".TY@܋עB=# D!rCBzSX-5ahN욌K0{67h|^MoόЅgb,X%0w7z[sSU[T>۷̋.6w9mC*}{ͨ g1(?a[X۫o}t\A im>{z63S>рBdAwGdr躱(,B n2n?D:y)a񋊶A3*u;<ӘE2’U}~rccdYM7L?JRmwE<,)D>蜌xI/7 nqOs==ljГ2@+L> $%Vu6߫2<ʂG6J,T6ݢIlch_mAba9W# XJ".gz+=^_kЭ:݇Lvd~T. 2[`A;*M&=7K%y癹r g<6Ȁ"Ix7֚"ymcBkjl )-Hvq)n"W$~2ؾ y#6W-:p;{ >'sˉ0&PZ-*D4Q).nѿISؾZOP[1Hkw67}O zNi )u.[A ``7K9" $/K (j> һ9pw ?mq?5EH6LgIöo]f-c7X~"O,dmUCLzU\J02g|+JG9^q?gC`*2O9^Ѷ }Mќ0Nup_y/C;:灸zX0uT&NL/cMce*ʛmonn.3sR Oh;DU<ͽkS_hҰ&9H: 2_"Pi,Bax)rޞ2 9/)PcY.Yj❭fW"(R^8JYڝybw66PB.L{1 k#C? KAгFу$YaYM$53\ԷdvwXC,AȥQy/IEI0o#v࿅ucWaJJ7>Wy2|:qU@0&v :F7D;( w(}ts|ȴپ,nE!#Vq x} YyoJg vKtIn0ns$^p*jsdC"9. жzݘa\e ~gEX(4yi%єsgݱoxM&]{PV?YVu{If A< {Rh'/JI;_(Q[X3W] rJT_:2\x47͐EzI~FVWeI4t tp209.2P&9Hȉ |DEXV[C%ѡʈV _ e_kh_p.Tt25ݙ :'-x{ȔϽQT\>zkl,k޺ F`kR'~%{)Zma@N 3\av=e!**"ߞOp!M Tq+1*DOn2XqeTyrO<`]ŰhdDnv%dи#q` 61,(IO.)sS "tNA m_T7PaWc4LlmsGyIu"Z9lŊezrSdK 5ȪhXM1̈G'8GSX3tl93PL\rS=G`6=. q9EN̬Ya u!AfAs?L2|>|f\XdH$ "}D$a|W&' U\2uN^렦E21#ي&qg@f* ChQ>gp@e95n5q`˽m~"Ww<HP7#՛omM_ŒPYMʊ'=on3ELц/\&BBY:= `1MQ2[J%CלkjO76ZL z%&7&|+R{ZQ S(6-ya~s ;^ٽHp*y^C:߄dsu%i(w$?mz\DǬN`'&<3J€3ԗ$k5d"gN3X:uq:0Ts{{JEݨ+acH'唭cvUO b: k&Y!v0 )\,q킫&HDPWN6,*V/sDwBڋ&W1 @|;u|f_7o=Yu~g5^ H51 H)ə{rt@sujxs/gQ?+C'!l]4woFl ؕkbl!UtUaK"!nn{74Tefh Ygvb rnԤ0NpaPaTrۥ q5tJ%+BB+sFAa5] eW`N0Sn%#; !E 5:Β[ Ez&e5!:L-cYN4E.{U}Q;v .4+Sevܵij3OI*3™^ :tMrߢ*u2ȉ'Z.g\$<5&Z8jC4 [ʌW!džNtSfmR'z񛾀1ƞ$ 6^l ‚Z48#'JtNp+U)K@1*@D.(S}S dzLgpE[=GLl 06{%GQMTΫ|אо`8y:>IX5?'e.bw]ߟ%_;i#Kr>NdƳܨ[OxxDisxq3MTɪw;{ׇy0]R~ђN@ s Q.I>Yj>T#('J*l9JoI-80l4JG~b݇S(k?,4Z%n6՗`Vd߄1rbs9 YJM+NsmMJfhRx`=b6]94 .\M^pc@kG.PIJ9F'Զd/t- ŌWOϡ y oV8[k+lOq™X*]¯ҺʼnQrج+JQW2vQWX57*uni͐YI"Thdizr|Ej'Z]6{<y&1;cwD{: &5# % <wŝKDkzNP( nF5YQEéAXm ߈$(IVxOw-6nPK*: XV(y88ذm Ae- F͡Ǫ M.WL_P}J[h(τXIih58KG9r{u˷.$ 2b7 Xo随wDUF!p`BCiUC 5*1WNnosqj2+P]D>-yV JnނaRa8&6Lgm]t^Ʋ@*N@CFJOZWUKOHlZ\ LE3/#Ƭfa액-<:c^$Xe<>qI"V 2d5hy3=*;Tӵ05u9q0B#}Bf!X)6!dBn:_ISHJ4]q7J08lB-hVhAnr[{A; +]XɍwE Amaxp_sQ|o "p̶$c [rLX{Ip#& dðY&d4NRd}m[Pl{V&?Һ13?8S~-1Qr;&˟>GYZ*̦XPV57hy,N (ns ¦l 3:CqȣZhadOK(N=HtR='/BblvTn#k<smLE,-×o{{E$j%zS寙_41Z l}LW;(t Ɋk1!0&c #~ x~`{BBK&3E_w@jҁi,LgXh Ww 뇠?c<`40J,dtElf%p e <ai;- >h''"9]nb=FQJu$bw MkUp%^W;9X94ʊn>aD1Sr"XyuN8\Vgs^:k8)K3#Y1:zTͳ$pF@|s9g;7MS XY2Z~ʉPz rLSHI|hH8?F#t.Q3F.4qź%D c_kMxឫֲPvšo_ BcݠpƷ0% (D-~>g#6>4 #j_Z%d ;!  X v8qIӬ 1'+b3tx:Y@'% 2sF0:_*R UZ֠ѹ>v \Vdy!FW1ϭ{\GY&HL=Dyo|[_E6H_oW*Aol d~VTaTcZgJ՗ (ݸ=Fo·x:DqtCmhl|g3<>'~PQOQ&ܥq!Z'm fN-N(a0?.rޱ^kѕc#=T.)np`U'Gh9 DWr"> #0oa@~Յ7[%^|[8_1fF+7 8X ش4%l1.ϔjmCMDd8Ri][8js>M/:$oe-Z1X4"8Ag/gWLq%=ges_b`mr0#+rrzw dܬ˝U[׹-x]ag09JyWbmXJkl1BMROp7P&c/k> JM< E.\w7XjH' 7?Ai-u␪R5XG9a5*I nԟ9(52[JI Q2TBNU 0৐}׷OFI;cxA|ڈ!B֦Ěj)NkW"6StYjg}l^ds銋Ʈ92U v(L\}Ō/C6Ά&(8E=l[5 >lدz␬GӽavU\Q<fpUQF %0eAc |̀$5>RX|2 Oٚ?D6²;_ bnU7's(,U% . fG&׸ mf?+]~Hsp`X<̾lu nPSõ1w돢nwȆuGr^NrĎL X_ mG'Myzcig)`6}y]@6H 7>3meu=U%n}/4IFRkNajjc R~}|A(e4|::Rj5y pfwU뷤v!1J*,Gٜ7S-4 %&"((wp-o۞ceY'1.͌K7,B {rIWV_ ITȒ$Q%MJ\瓉{)7'W~ X%&UeNHN 0}1<&)d+Nz/_0NVwD8u@kh1CrHmd~f&tPi(^_ˢ$a`w}5^Sf{G*8q_@i>@usP(,G =2^c=F?9.!1/+ ,psrc=XGX< 9N_FW|]>ަ%[+ny19,|yP8o"9v A4 `P!|7I늆$W<]0fuM~z(ȀHv6R!|$Aԏ%V.{P(c-MQSB~UftW·uG<*Yu8޹8zni*p[ł%V8$i>SPCzH^ *,. [wy{y84j̰oԴ!~ŜI ,Qe=u $2J0' 67آFzқEx5lXW6!*νF=ܚ!x2n8Jꔵ2o {jnFMB0&?[T9v<5kQKzIúKƉXn3bD1ERfUz5JDūf)׈j]0V<7fDžlMeB{`4P'Jr恟sݞL4dy{DdvXx3; ї]phXOze}x6ԇoK>sOmwØsZѤOo`LwK%sYe܂qD&`Kݣ]]XAl~;V4JуSGPun൦ py{*AQw1uӹr&:];p:Yi}WO%zCvrx}g6ZH9IgX%>p}EL5\-FsMPÄJiiDĀ}ŷl3>vC",{@?LWjo0`u!잯wҍP"HBn CsD& L:Ww(@E2`TWaJ#*}zgYQ/$-H>(V0 ? *[tUc\0D bo 3fӘ68_v7+ j+{,ΊX;dQ>,/[*ϥ lDuY4*e0Ȱt qk'7$: 2WQr.Rqk\wo7Xr$ 4vVKG@TBYk|!|] 7vcJ)쏣?FY?0dC^*}9,U '2_ޛropDND9xP2hy*Ӓ@ND+^Nr ϢV A=M|Dip>b s͛4G%Årpn'o:%'Z6#Т|=#ɏ?.?!%?RXB$F5ďό>: ,LnUI:# JENqF`>,R?ljo*! Gqqd^ќi~[msir;/Z[!o32YB5'B£F[E\c-^( _ ij/SQ=M'XzjMbK*N+NukD}لsɮ~l, >/c&HpMd]Z= e<2I<79. OdpMD?c»eOKұ6NL8ϧ ѸI+ OTenfa+ry7@ev`}R7`AυeB}}|~9C5|CJi t){hU\jϖ _v)J`9fD9a7ͨ\'n5hV 9gdjHjTfJ3R?׬6”!*n7PUd=uM- 0K#R(}c84 vTy 󘐘̝] +psa&U]nMJYl%͑jjJwMGhV?X0ڒ51čEJ{_Ny|imOO A˔ aO-j3l8 ,bxՇN(;v´rLٯb> ܮN~@Ʀ[AZ!({v#"$Vv 1a u6T: ?C[i<t.n|Bx xw[A*l7-[XbS}yH+t̿Ir+TIP:-zpjBuc儮Zu_Z@^ x܍K䒿2A?TzL/pwm}<%[\B(LkGlv3^298e@ٱ~hi¦}8gi%}<`k"#\lkE90 oq0x/Pd)5mf7&RX~~/(?<;PWA00,[$!ʎKsnέ.(fh2؎ҙJ29!BIތtU|3,%7S5|OUo:R9 A5pf*ޖ(ٵJ,; 'fGfyt|)x]IFL=>*ZT( 2bFbdO%3eeG5m%:+χ?u'2*NRT6\/l6@wa0a5rg=un43X=Ú'a/$$2}=F칕5Z ?FU*ߌ-uNGA軮}c4>I*[ #4|W_Sy *:amy^@$|,6U$uҋ?pH@#(-LH]6l$)k/YnեGCR$Q˂_W,.;Vy=v"%y_Xl/9ذyG@eIR@_ q4KOgWXz?̘5R03ɚi a;ws9>ɹwtT=ilV.U.hx@s Tqux3V/3-VӍ׮O:nW/M!½kƯPdv˫aZ}Oln\<4eߣ1oqB&tO&l} l3+JĔiɶ[^"\8&&;5u%SF E`*nieͧ>?8]joOX$R< 6oX-n0q@ئ'Od&6?(o#)YoMPR@ۣF6[g&Qf_Y7+(&tQє0U))sDK 4NJS&K*-OcIy}65.7)|q,Pz,Q % 0n&W}֣%SĽ1-2hw+uIl{WD#M#LZjGZzᱚ~5bE G2 A<&3cDDލKiai_$Sڔʶگ%貲KYK/==>C eР+ĺ7.Z{g&ӥ_6z:^}DɆ[W-kW T2j zk5͂,(Aoclf&,V1\yca(],sΌJ P/ ^DmT6@kzʐE?ף3SevS ]]ܵ.2,`X< r!]P ,G=JQs٨IYCwVj4YJ?r.|tB*UKOgY $djKԤ/<%#7RNurt{\r"f‹ gWZZ 6˫~Ɯ Ԧtvb9Fy͠%[\dқeFͽTv%/, :}CW7*rlVR7)9N߻_zD6DB㌮{Ch&BG,4S$!7RY@3G:1#}O_NFBw96F>~&gj5Xo <$>I]qZN(A\P抌?Dr{'[$eCgA 2"Ќ .sW\2chuaI/rϚHjb'SW AH?1s/:aWqc@Axtс?UVTY%nt}K`wο9,$@Ehw7GC(: ue+}1@Ղw+پ1!fBL/ˆɱ5BjJUcV+&X{-}ke>G)eDfݺF o, 聪EK=KAޜH0"[x17yo] ]Al2qd>DMe–:,~eDa޼&:3˲7+҈)$łՏs@Vq%a?o8AFSnRt^pW0dWMy1H V8?&po{@lGh6*o{DYfv3n^7ʅH}0L'D F( -LX@ql;fqYTKªyo#'V p aa|o3,UΝkq~{#g+n2&}2d%,/lu- P3qϣRw(^(,*p5ܳ|X#/APGoXrSgC&Wo77 _[_F.KZ#Uq J:NP]k+WPPVK@ I.s?'>8"O-8\&>e_ʡmb|v#řX"Z^iZs@Qv]U[6&Pg;8FBmdDP44CP&4ک|)d5eVmq=]-E6qkQ=J݂{WצKt"TC:;;"Z,Ge'>1:̏[h/"'2Sl5C[Fqq @i8Va-?\0NGl/B:hF(xLF è'E\;w 1OmN .y`KJ">s3yqgNA1zVۊUg<Q_ό{tfGvS!PX0p֞8rX8ćr2VyOaBwE2&NRp<+ c\hsVBPS =Ub鲛f%*/.2O(D7JF(ʐ*v^Y-g$H`Ng̞|sj(P\kS-źnXPMh7;ztG&S)RARnяY˨8 .<=u)̙*M˄*#,g2ڦ=YHm/~g-hzXZ?Q_\3@dP I> Un3 `w}ĭ,< »W +yǁ+"y I1h b:VhRN9{Ӫ|h󫟉hZn"8!/ՠ}IGqqKS}{3Ψ+ X؟+։(a_|ʈBXU1d? L}tkG̥p֟XzbFӟSt6L b?G1Փ/w_ MiuOT-S^PdS& }A O:.xS+/| %6dk_ D&U3 I/il8+vpfF(R}/ؗ<p/_ᕳJ T UiK,x6H|O8VRHy J-҆L;rteN,8N3NFv``e%NMU':yeF,%|53C*Zqj ^l6pU].1v/6Pde*+tzƉoB5N+3_8 RꆴC30]ؙ` 'W{4У)H!d8 ,.գ}N?k?Pb9ܰNOKMQqf]\z_{gQ!QiG*I}T㚪 MJhJL0'ܑRl4Țy QiU sf3'j*?7O` ?O3dI'N2 &:eH #Covh *&*^)\G}#ommp ~D񷜾)eUPWbc]s]%ޣ [.c#Dڶ 26Ej; `q r{H_3ik5B?(˓+pc@}-1ޝ7jmTeRp'^[t*ܴ>,A)9KL:/"}I+b+>ĚwJd㗖[fnI^UR(5yԡ0zr| ȷ8֥#ږtF2>O6to9H gv#6l" Htdϝ%b BZG2}: t>(.U#Υ,,,LV̮K-|8ƲLtn?So/^ȪuY1u+ ̆lg'r=y,2uQGr=ፀyEi|:xGf4,CCipA9ɸ뮷SQdphlH*KdRR͓sU##7&bmqC;6LhPP 2o:S{io["xy3^}w\ȢU=Z@\KȡxG96H2?$F%TxrAP'N,Cg? :D7j[,@~g;'dOQ< e6XzW0Lsƣ]Z-a}^nzuބ{ =٢Z(M_ ZTэ~nQ5w<A17+(7 -ɐ$@FEX=oR%h(W