libipa_hbac-devel-1.11.2-68.el7_0.5> H HtxHFS ?*}}_h7mfOtyFdKU\҃ԚņYf027a15571773db46a392008371fe5aaedfe3e5a`-eRc]VԸQS=FS ?*}}8zUȠ<Ƃ6%:ן~Dk'ux>9?d & E !(88 x8 8 8 @8 8l888(89:KiG8Hh8IH8XY\8]8^"bd~eflt8u8v`w8x8yClibipa_hbac-devel1.11.268.el7_0.5FreeIPA HBAC Evaluator libraryUtility library to validate FreeIPA HBAC rules for authorization requestsSswsvmsrv03.fnal.govR Scientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxx86_64 \ ; ]. :VhUVV:Vj" lb{ELyRUMAA큤SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS2c9813a080ef39aca65cca46a79e78ac6ac4836866f849492732d82c14732df80e4f52a730b639963385afd4185e366f8c832b34b920480f0a7996e173e9a40d5cd6f4eb01764f02d2f70c79c237ce1cf8fbeef874b661705c1f3dc3a21998529e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58b787da9551d9e4e6b50f1d2d732e9bf7d729ad70cc3081723b3703236cad8f2b3c98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830603c4e26ccdadadf00531a187aa4376b93bb54dccfe8b878bfd0916df4df3d3332cb41c619fc9f7f7f4f1a039421ac2451b3cb03697905f4e86be638212af2dc025a62e9e302aa53b592334b7d85abc65faa28ffe555ec539a5b6aeebdfb0b096fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c8ab7bd003ff1a3e51514772bb29ee7b9445d7155a62831f255a0a9aa884dd5315c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fd931848f71a066b1b7b8578978ae0f47473ba293b0cda30a6bf2e3e20a2df18852f72b3b729b00e09a0e1e36450b062178cd053a56d07e9a22112893e54f495658926d0f3dc348b5e0bd90d509fde6d32eb0253c7c65f236709275f81a101f58608ea90696dc3b45bf0f9754d8dc3f5b5a1b0ebd0665c942ccad76b6198a0dadbb6438d4a64fc46474722848bfc9c4019c176c452ee6c2d291655a6a547725bf41be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562be22fe1d60222ffbe971afb619cb47d8204ae04b807279e7ed8bce6e7cc59dbd44bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a45c30cf69bc111a4bbd1d8178c48ccf1910042555584c93abad31d1fb3fa6352215d7d6e5c85766905a85bcbdc6ff6a0471c8498432341d57983dd77e5b98c03d6b2861f9b329557e689d5f2f833ed2cd1b8187f442967c55494be58a4538245e0866f4ef1f24d454871307d0fb742cba798834b097e2aa11326072171d58a50b1f95633f010e90231ca96de575a1884f00fb1894d7f66af8fc368226ba9bff0339bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libipa_hbac.so.0.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.5.src.rpmlibipa_hbac-devellibipa_hbac-devel(x86-64)pkgconfig(ipa_hbac)@@    /usr/bin/pkg-configlibipa_hbaclibipa_hbac.so.0()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-68.el7_0.53.0.4-14.6.0-14.0-15.2-14.11.1S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456781.11.2-68.el7_0.51.11.2-68.el7_0.51.11.2ipa_hbac.hlibipa_hbac.soipa_hbac.pclibipa_hbac-devel-1.11.2htmlannotated.htmlbc_s.pngbdwn.pngclasses.htmlclosed.pngdir_306d1f7c2316132a5a1b654ae206deb5.htmldir_428d51024abba00bc838cf4c5625f90f.htmldir_68267d1309a1af8e8297ef4c3efbcdba.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pngfunctions.htmlfunctions_vars.htmlgroup__ipa__hbac.htmlindex.htmlipa__hbac_8h_source.htmljquery.jsmodules.htmlnav_f.pngnav_g.pngnav_h.pngopen.pngstructhbac__eval__req.htmlstructhbac__info.htmlstructhbac__request__element.htmlstructhbac__rule.htmlstructhbac__rule__element.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib64//usr/lib64/pkgconfig//usr/share/doc//usr/share/doc/libipa_hbac-devel-1.11.2//usr/share/doc/libipa_hbac-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryHTML document, ASCII text, with very long linesPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedHTML document, ASCII textPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,I] b2u Q{J -#Z5ڀc,5)ɝϝiԸ&V/nX 75ΘgH<#ώ4Z%4nHHݢ+<-tL}݋hE*/?𧹛eY _rRyaI.M{R2GhCO.RTI$_1J@FIo8,;_ ]|Zw0#JsJ891P?O1FK#EݡJ[iSQ (Z9p kAprYICU#a!WYL-N oX^a:Ջԁ(%T:.M_պ$r6°na$j}c~ "KI)WvJKvq3Bh:L-ZfMˇS7qz[%` t~ 61 ?Q֦fk2#2b61;^]77 * #v &o)p{&ᎍ6<EF㽛dġ_:"W-)p;9D&)TG,"2͙?'SBPHҷ,Je8Th6S">pPqPT8 :ӛ:r(Tg W܋w7)-0ʜKL\6FéxL;*ݪ/GFI !:kwì]H~VY=V=xƋ=Ŕ U).C˦fZ+Iڞ}U([ "RQЕC^ilVnftV368aJ9b*jAm8R1Lժy^yԯ|šȀaob߾)sZ/T۷ 9Rdbϼ~OT+K-Nօ+&[̊PL16V0DܪL_4$fh^[aXr8Яբe㊍ø,Y>]e6a/si^Qܜj kߡN+xw9G&ENpF o@ZL}cҀ%a8L.E|HUhIRnZm:^Lczju |J] w1Rl\TDGW,f-tT9;W4.4)x'D\/hy1 ebS׻Bv]d]A5tͺwSOS3?"kX#+`_4,DyV9拙+;@ÿ6S\aO'8/0?M6ҩ.PDi?u\ykî퐎b |Lp8G8x핣v?}0UY2)c1=F++b0,U0x*OoV*pay +[Y [XEj@fb>rPlb*c@P #m*=m/QL+T'MlcN`T  "+A-p`mӮ/;'uh`NUA{h̉a8 _ϥ#gAqW7&5nXOӬܬQ?lDwZ;i*+sfIPFjc6͚@P Qa- c_WV C}D7/5͏vT|w}N}oGZu8?K[v)GUuۄp9jn(O ~፵kקrUYyC;\#HЭ0q}B\4Mji* M#aI=33WmV]NZTPo$TG:|ۍ*STY␿\@<G(Tb/4/A G /q\?mKެED9Q5TJ`P k/,Oj:{ޡN%nkO$Et}BEYck? h'q@n__c<3Ýˡu kAz>` ӗXnzfCSWIv"WqJ'ўדauǧnZufY]{i7xd9h{"u?j (U$AX䁗)Zݎio&Q!A#Ff`=(ЙpTQT^3'5v-nx3io"Mh .5N.wC8syf]lV vWw#2r"E}q}tIW?g zP[Cڞ~(n;qBGN`TBO9;M|[ ?x=(UG=?yPLPO釺&X`@F:gZ]5iŖBWnKxK =6vɺIфwOs?eNh2LV䤤mݺ h `=:_ۉARWXm4DGQC!q\rdO %jM߂t)g7)]*^@e.+s+ 7򃙓L)nc*Iv2-7-G]v_ܩkϥ,̨lؓECo;ZnFv{Nf.mcǪ=D#ďj=a`w yi-/I^{LF.}!3Kw$WRm)Wخ<s98qjGxmHkn EᓸA88;̒ϟ/}; 4%M#%dXhwyҾr+x;ծo[N=#0QzGxw ء$V9KCB"XI53ˎIJ $GܓhDV(»z-!3Uu0A-Sxp ocɋy\aaKøi ꁺqpuX4mj˯'O+MaNA}`޷!e꽮=I k:D3T:F8jnJGUc0ߦE]H*mC9_2'> \+I,پRZ " =~Y8Ћ1-半 A3\pmP^ ۽c4HpdMXIΉ(F7g)ӡ[q[KiK9[ت%'d>7D;}2' JtbM"&gzca~k{jqX'MZ# Qo3Zjk,)_Ͻ+80m,/TY20zIs= J,Jq +\5e?0oZ`è#`Y+ry4)w? ΐN蘄U~*pĜ,0(jfK7ͳxvUւ#^{h->0#ӫ^bٹ,z32r*(k^W^Tl?sm,r9F/<:1Id v"zB N*-nb^YߍZd˴h x+S߱1b Ɛ 㻦;GtS( Vɓר *q7 "8FEԱG/&C/d}BҐڳ?&0uA֨ f#F6 cvQԚ0XQ5%:2l8 8c2ZQm!=`8Ag ]>WٰaJ-|G~Ӷxc9sUViJU}D9Ma"=@Q ˶4;rUDeTp+l:P0WྪAhi{AwA4=g&C+y/GȒ~V9$_ݘj6hlG6DCbg2.8VJp/dsfr3#fͳ)Pm.XDǚ{-aMw-TX˶{ qb#D.DU0#i=n{ ҋɉLB3'xK̄!K6rC XbYvj,Q$5NqXIJ?&瞓F6 6B(-% @;Fo{QY}N_gjxhf#GQud{UTr$&˸)Cy>yo ${7tkR%PɁ:;Y} m6G5x@Gyaq@'gΫrXvOilKY}JiրƥB#Y.=@4VƯүNuM6 `QRiR5r>tAr2}ݛL>PM2M"ҵяD_T dxk*Yx%9ҐųsC?a ɂt{#< JU),mfJݓ֏mp i>)DS: zV]T(v}̢ P6a6Y;͋?ܘx*h (mLxM-ƊXwDs6(8Gm#nkXmpx $Y~#>]`dN-aO_~^be>JdHol)<6Nj+FG׎ a<E"G'cSɸ4Dv0YY APr?DL$mfx$~eJ;& z}4]/ne_S;ϻ=-N/s"^ @C>ݢ9ekĩ>) Ŋ/!0qt;/C8bd$ 1q)4y[~9 UO| $PX @mEޝ V))]േ5xeifҷ\%|TMUɵ*qVByl@e&H݀/ o\WVOѓx[+?:.`M ڣ,X۫ n|5#9:놝LarWlaښ6p%":%tpCc(3堜`ߩRde\//`zܲ-ӹ.RG"]8t;Q헖Z3-\?&uteu?:b%x_Ӷt0U'yy-r+[\ Ki׻rw)orz|Z+a3fDCgգ w2F$0.V8?wSw0 2 l,~ܲH~ |Xd|ؐMך2Gÿ0t.4'Xt E`:ߔlR1%Q%A^rkS`.8cJfb tIS)_Gu`j[r(y=6f#?hOFH CC(,̦/O:*" uEg'ܠ;#l{rcs/CElcR+K3L ,xl Fe~3{fCd#d}2+pOP!= ʎnFZ.b i$ XϔەDpqxpKqq\AT=ѯKpk6p3y)-}؊qmP&wA9n{ PÚxZ}H{@7O\ud{jn.$çe.6L/B7rONz4&BpEpIWy#^P>m;N@հ\rޛp6_i̽õCJA{H~aS&^}b+kJRb^r;3X]7J]sqSc\ X_mpEj]{x_T fp?cζ}`x,#W{>]M.јr-'tO wR=yz 8$\0GM=Q(ڼx9<֊⌁\p{8 WO77 ~ nkVT4v?T,yt7L=VF;) &fwQ"v=kdSjD񈵣{;`m^ Voe]`'xfT os2D|QY3{b0Y0awO3VwEg1P4cѓcS5hp =akV#m2ǐoUKz.z%/Yu y 潖E*iZu"3/%:5 s8%bX/ Ρq/2A{Ȍ  iFmeX dKbL!既a`rJ:_oxY̤7AY-H̰q]P ) JnTH1[ Fҩ6hjNIlͰغۧ]?lo5Syt3ǺCmwj+UKI5n'q +6oMŤXf %K1,1fuٝ`CFus*kP\ ^-z^Pwr\$[8? A4`=Z,^Rĺvsk1AO}cumiC2mj$3c8V~FҫSf,7[:dZSYӬVdYM#lj6M_80sV̲=vG1aiApK+)("~h)n~o)C^/;S(*;O|96f0k^G3r֨{z,ʍb.H6{ HRsv &x;^a^|C 3ݖ{2B`' 4`!K2@z@s}|4n-_@P\:q#YdLJYH4K)3T<~^f$vj@])q/Uy|SKJ8h cKGU4|(զT{ 5V0$5(!cL@:8U2ˣ qpw_بkPY0Ϊ P@v߾xJoGg('r-9g"EHΆ2RmV{/IT7G6oA*aR҃$D2 BξGѩGnf,#|04cjLQσ>5A|jUR :sqG5(;x=0m^\pqӧzEfT`)cR}~P. xl ӦΛ# Ī u̪ht^.u!si|lI&<]4:i<=ĥFoy}2 'ߎ9ԶGׂK/m$*D64ܰg?'3MAշl]xRU)C9RD9N:wb!(uA 5>5bw[^N:;$6Mқɬ(F4.ёHz2isNČ>po<$5 ޷S/$/:ɳ$SrQw} ƳF:<@ %V`ҚVwڂ@ʔ̫cD0jTƼRNjS{N"g`ZzW: &44i$jQ){:%6$)bZpqVo2h %U%ByωOkțbԯ +©݋t25{gSLw&&OY}d{ѫ墯q=nό(%z/^-.gfTސeFiXqHeA5'ŝjStڑ*,Ю=}.G;!xFK;_4|q̒&w^HYҭjEi6=c}G c U:- 0q%=}I7ovs?m?ބP֮~}/c~OeU^#Ͼӥ2?ŝvK*G1Ӡl_sڷlb~؉)`ZFPJw*yYN$x3XOw\Oqs.Ll5T_ KX, :;ǐ.QrCT&&kEþmf"w߻#K(|.ڙE`u[l<"V%^9 TxFQɽ/!2@p=rC3+*ޭaih3Cڇ3,,\M]{h$0Kȭ5i75n 8 <6ݰg4\q̴aRb ģ{D-K37wgvo-f2B5!*BgeSBzWv3Lnͼ[{6ܮwVT/CkT ڭ=,_? ȆB9Es`^sʢwNaʇ@ 'E[s?D0R]&q"XStx͚Fk7YF n$~Vqʌ3 ![(qUbskoSW~KiBʡk v.r$ ]|dNdĦCr{޿!#p,4)#Eg#RR:=UQ!L 7U9ͨtm3p-rv$yZ2 ڨkΐb*ꢿZar ]LQ3l5s'Wh> Hݷx ޱh[T6dqp/ k!pswώYAvK@+&u5 /G]}ks_D KdjѠ% A<4KvGqC93F؀?v1(Kv\b0rJ*6r2ڏbRHŞ#%%<+7wWy<ނbY:72(&0w y7Dqvj`4/cDq{/ ^2S)(E!t%;( #f`_JP1OoĞtFث($+DV51G6GkDRb[,C\i]ـQ6:ÅmhU.`itra QK9sZpMyr8m7tㆻ$8~̭z1I`SkǼ0AE(wNÇ)'re"O*̚ Fn=(Kg/rtDp|/`&Cb&C L:W%s)Tja^ d-P^l(f:B[ Vj\rU=—4."GC[Ⱥ֬D݆L՞!uѢ滼6^A%} EzVB}/B^6!ϴe"cVs"=:%fGá 쪙̄K'vmxCJ-J4UUVGJKZY\!XΏ,{ʈ^Tp( +.A ǜ+*ت\U;%DVq~+l's=&yS[D:sibpi 85#+Q^dt,r|'ʍdB&7"i~.s9АṱCO[00(7Q[>,ndzI|M·VGwWU- 9@|A2js!9iP/RUOT3.UwͲOǤsiz庞`zߨ—>3I\ gn8瘭*FL,_MY)49729lאU2-0C[fCGr/C ͐/za'տcnAq`ֈM?5Mݣ3-Esț B5zw<uZ3":(o-Żby6ȾX玒zu߇fnbM@486|i4m:tl_ EX%wlVCBg%6yrAD"@AE?¢}^^<ɻ* dHo:4|{ULY)K l v^9tgoOzd D/ ڇےE9qу|Nq?ЗTqưH]wƽ^ d?F?!?&ӝzLh <66Z3cM>xlY_~5v::P@*ɝpAoQ A(7͛n\~*: sJTeN0 z/:H88U7 :/td+։ĸgCVZ֓Y(S(f?cQX\( Mb;~tYQhs?mB78L/?Kka'rEvb*z‘N(z jԸcϬTtPZe(E0BZ4}<P\b71Է*Kcb'^]4*)H̀!P, ?3vq¦9lZcw/'|/_SrP8ֺ c  BPj-^.xם^ HM(-2VG57-h^$B6!\M̒ Őxn/%M5 ;eڢ1;O#A\U>Kyak:z9/bvIljJ<tUdwЋ``QK Ywhေ$#!KXD1|`S.bV?_ 5$fa 0eFft&>b;DI!௄ZS>bP[f/ǻ!RTrKp{f|RyaCqm7s-IvH\Hw aS[8,c,P\bAFg}@[O*[@rqb5wv,gVS4Eg+0g2^bkLP2ep]_K^1*O&;>VHY]-+i0IY^_O5 tЮ@n%8lfŘq|2<δ=0Hԛ|ISl/od|(ȀK pi~;M5jU2~ =S\Zk, Od U #9bWDv¡9S)UVI)jS@QDU6 #x E6j/cC'H*Pt}ʟtΕ b*O{O4/ʲikf :\.b(bC2Դes=ȢB; , yH3/?F-DžaVSpv Ӆ7R Fx?K[A]3Q!.2iz.'|ӽu1p1<Z yD"綦vѯ5pQ6IY,rJfm[BZ^^Q?zUj"&d~q_f2ǞW~I:Nֈe^,`jJ޻R~xL,B=rozCTR&JV>U0ȧ!T d|\v{vϦV8.7:I`7Ywg٣<ؙWUz1vKk<4j:X2ɋ' zȖ"/Lif CAYaw,/*zgwIEet@bAl{k 7>KG @%>b#diKW=WS:܎H%g@A %od ҭ#T;0QA/=>YA+vvB(KUXLkQe%^hpJvc$ȽK}*ƿLw勷J&uR?rj%5Ï"OKaȊz,%C|,YX'Q\"KM$EE^/5%Kk&VEˏaꟻC~z@: "|Cj/]O{YE6w\@jeM4wwq^8gd30eJQ^A ICu2Y֬qПKT-j3Ԙ= 1aAѸ5Dvľ@X4{<~"rJU`$[OѬ5_ΆCEqBNJZΙmLxn*9N>I9)f4ibgִQgP)9 fȹ (H”e'wZOÔ9#Qh[ ~'O(͐W:&ׁ:LmD"i Hk6P ~ )OhJpQPTԅ ް|`hkzS)Xh;Mx6*<լ\KZ6x:?YWFHp|r_ZNFT# -pOie +\294P{4I'iz%OhGW[swq @z#~|Dιg(*7I~ݱ?Se~ rwB(s:+\}$~ Go$cՁ-{c-lW¥MN8>.|]c6uKJm=|48Q-Kn<γ:uxQ&4֝G:GB \%EDYﷄlsUBt{ĩT"JSXh侓lP5Yϋ;%EU뙢Wg,8}q:jm 73?ny:5 8 ˶dhCFH9/|f H"zf }w9Lm 4X;{:B`H-T[<%KoV退xU*B xմd1k'BĆ}<_j0g27=eJT*ؐ=&qS;I {ցwؒ9C#a5oUB)kSAEf˼j'>ut d)h#d kD(GZa%|x'@}sdŔֈ4?G7&y(Q rVȸQ&i8wc3|qyL^ :NUi+^~/P5& ԗYp4f+OڕU;lxPPXct/b 6Rcr*gς> C`RX7dҔf 辕s} +Ϧ22g|DuaUPP fW~jCgSEZGe2G٬}Bv'eYæ،%`vs%o 3 05?l\,?9E^RkDЗ~w\AOtƘ'Wt#J~(K@ODB}^'Q_U]m¡X*ծIɱPz;0/PS9G|-i~2C OϺ:}^=e#'Bz4=*B;B~ ^?fS %kea"x:Y=[|`FK?AFIvX ӣ,$O+==c?ݻDrbcIsPYH) =dIT y)&" _2 t᠁h0kG*]q$L%9IeIjIoSIB_{;niɍhDMbFsë#TƱ 5ZK,SAZ3C⩙)3&&z`_g3;h@.vq’c^ Av/KTcU#/.XbJ@0\ B+HhuH/uVX9;/Ǜs~;yh`b irMp˾TɡCT-|8Ȝ>dGR{iP&̷;kƒxJKC/Vh_1&JtC R8ngrwؗC'9V@ee)Ck5(d=$ (#iꈈ+Ok; 7E? DuzJ}0}H=6aC1y){,lobpfIơ;IJװ0z:%i_1Y0V Tͬ-SJjEևZ mpuT[@kŴ>"9z # z~c)wtUn'B1*: ː5`z~AD`.Q1x]7tH+3{}by08@ɐc=={v}( f",'b M"Pf'ѷ#j pbxt+n7 A`oa%2WE7v!# nӿ,[Ih3tΊ}Z2zmeWuoEvӵh:ǓX5"ޮ?_y86ŽX Zx@ ")=c_؉VM. Pir1W&וp;<ضϣ7\W}F 眴_i.RE5EK.[Rep]uilu@fJ,BfXoUb |8ZF?=<lz3=XJ@6!ʖT04pޙmǒ鈢cE=:QGJK>v,Li=hׯ!&>6[)' !UUGzF9E9H'&}XۿķTM`@q1}qz* ln}{;pD(2(K .n`p$eqTn뽜m ݭgdNnf#a(' /e910$Cg?T.a>” Z66AQ]v0z)n.q(K"+Z*D?S1xDgRD}>C}SH楮ĭ(u 7N:u o>k| 1h)Iòh}ગmNU|V8َٹPU dB1KeW r\aO\`  ,È7\* )}#0CFd#nlψ 5NuM0샘\}ZfRP)rXx9*!Z(C+ |lqzOwvI`fP:ت}B;ۓt{ͿDGD!.H]#rYL5wGҮ,34EbQb,ZaSڎ"cc$AU{i{)l"ڠz 7} wB+c_Hf:Ge7pC?N`x}/qPXiD U 9D4p4_=Mj'@p٤nFr-`ը/)i̙H&%m{-8V,Nјr;z-uta#Q{bu{ ".<ߝ6u6nU w qB}m7TaX䛅o|P},sU˜ٻ}I|U^/Sa;v}*~5L=דCa||f.k.h0C V rǿL3j=-,)#%<. r_tܓ)Ӟ+̓Zx,_O-C&A(DlzA7[c_MS?"seFSwXFp9k0O y2[ץ_ jovFd;60'sU7%#o"WBE>jOUzQx3ie, awjB{AtmN2jFSʴHcX+;_+<`Zے8 !"N9 w> bБ=xn /q8,Xv,=Y"MK[ݏꑷ$9ð'EҴ? ԫkl)eK7+r{o=Ļa%׶($W57sJ+1=zG=uxgmIog|xR% 7k{XWEÊ0*ЀRq5MM* 5x y#;2TH,^rJTfzһF$\loɄ+-?}ϗ5l4ORX6$te~ƫ|-Ci!zK~;,[ ΀@-Gh(@u˯^QjY_,AZgLMR^82FF0DŽɓӪS "3dg00{-.*6k",s -4|Ž"e#KqEvcJv\\;D)wA#p$B">QHC<{oEX-TA (s0TKcanu;N7*lZHX)+6Ih]QW3 Qv-2aa(5Ĺ3Dkl5wƆOX]mUL\f\t*va6ú 7bFU2BM(ѝ7-i/@BkMqF2/j >JZy8NfB.ް%JkT;{:\ȤUsS_UYP\f'\3&4W`a^娭H~ʋf#tںVޣBN7̛ĒؗS (ŌCyne-fyZO MǒN}$8km 9NaGbb7?%;0< GyC-m\O;RU Pt<OKxF_ЉW1oj9EڼV12mX+׆|>˵_K%{dt!0 fPB k%/zK>@`s|eя! Hd_ITc-|[n8_ӄX$T2Ta|HƽӅEΑxqY+ -8 ;4#A[y1sx*>GQe B85蕡+RrM#AE%rp9*!ڼ^~ g+d]利 )O]y}@KˋV; 8d7;(A0!!'lm>667q)I;ܵ<8њى)" #%M }o@_)|I!'wT!}}VH:N6mٳXOUcahD?юLƤB3 \hVl!>k"KN3̿7M,J &Oay!xGet &)l W==pa NKH:ȧ7d"մT7r4b^yzzMCny()T;,VQ_?h-+ӵwg b=Ow+6Y?,NʋEhQE{`Zm#cH}he;ل ~)tPM~te"l mi?LJZv8N?%Mx\삕!sWU=FJb-T5ϐsB 9Ձg!KY> h1`r>[xJsBo{,@cwwRB"RY#c|Ў@()L`6WT̼_6mߡ7[;v~`j?UʪXH=MP2vbڬffXD~;K  Sİx,,/z)el$'\QC: O7!}URYy4 DR\)?p|J$g4@F0LTMaI?IzDF>J] rp`OĖCZK"P{i24~QEWv%c>1"]~Kh䫕`O"eHr\-`=zi |oFvÞGKRA`ZEYpƅ$>) ڦ Vb rш"(Eì<#߶Ry~u}GNA<>9#ۣzЈuɇML;jdjHU4?3A-ƕkgP0G9c[I8|N0y%l>e-{/}aΡt 7\[ CH <6„ h; }"vcdgB@LdU!oR_1u67Qj} =%4Q¢;(ae 1G?-Ӳͅ%*vVX[OI7짢6z!y1Y*RfA,O \զN.Mɩ?5WV@ny.h,%hp㒜 bL_s0nOr; #c7tKh:r;*s QANoomcl ƚr/W mgg;NˉhO,<^=`_WMI^YΩ/ac\iϾ铕%oF6T:LL*r(>޺[@2#+2ʨ=Є;kzj:$~R )D/m3R 5L\Ez*q8â޺Ob(D̘sW v}aAѕ*5Kըy$P7"uG?ͩqרaP,V1vS9\rcR )\/)Y^~Mg[vw}E8=L'+|50OGd{#_~El y=AD}"|f!ZV1GS0Kd!Reoxs5#3x1\4L*Bx7h/GV' ͟.u#L3%N6sy&ov*_-9ʰ[ EP>3\Wt~0cf멁L" N#9?V_G.ypZ?t+3!92: xK6x!6;N}t+=Iw\4/V_m0Y_6M"owe(PB;ԓDډq׵Pz0i{4cyxym]ʱb.Oal =4k~4ly'FbD?x]28+%dr4N7ws(%C۞)<5k `&!Ò=qUayl +6jF/pcFꃟhbXq$U(wf5PяJZ\#28Ye'em'k5Ot^CT-9U& J]HQ%} ͒ioE ;aRr#̈́ӟ@b:ps>wsf"uZG]T(e>~*O|n0k's3VU.f/gد'/Nl&}3cV)|!wH~#zwMd̙ î'Gs^'<"ޮ2GK޹_x,ӀV:ɛE$ŭm 1s60"2 2/V)M%Y}ų &2sr0{.=T'9$Csf"59gZ.7@Vw}NN˟*~IL%SwHx7b[E簩C]kѸ$UP6$jޫ0I7G1f Oez2 o*:@YH9riJLiI3M: 1@OMEԔ1nNKoMK}ְmڔ yI= a6W >˰e:lҋmp3%soB Џro)iMMO+.w!%Le?`(%p5c8DO0چWx]M䵚SlYzv`aXⶩL  Y7*Cszi/F{gܫ\\,*v&D{Q~M>ʹN߫٧ -ƚ.֍vM)1ɰgxlU)$[zSUĎ{M26]}!=FM 2'_4А ')y*)5a!Wp)[xTTur8?zxCzXuO+O`4\yuuk'N@fw҆gg WDhK_VLC+xWmu0m~J-/}v'$2n)L U_툀$̦ q 8졒}$u,g DD?)' p\&!o,n=QsA}IWGA{kHL0.k`0FXA4??ow2PH=cT}B[_y2hY5+_<4S2A.4QH&>g36:3D_)z5Mr2d5_QGr jY7wمBrӰTxC^&z+'ʊGa/\煷 ͕(~V{8t(̚^r?/%Fgx~  5t3&7I azy pbmb/"#jgz.O{&4M%C f{S9 S/R0,O֛'B+SqB:WӴ1ܽ]z œ$`AN?[؏<٪\Gky~ϭI@a+cxNs\){#@ر3DqdP'1pٵ/vb  jv!s\|IwmH` DRϯD[6ޗ^[Phi6;k%2Uؙ7XU:93ER$lZ'q>\KC\gLi1SF[Ż&P1fU͕HpJL|uya^rŞ> u3n$n.Qs^V[WP?PfqCؽyOYaڦ3 *_FK8z}W7:+*,y҃A)ujrOн%bLZݿ^YX a=hOq`%nfډͻ_lJũʌH &~32%u> N ]4.!> 7"ܫRbo-`#ؗ%:û{˄H9@_0]\̒LHXsx.z;jgZ&l&|fǭ0ԔY2QvxHL|_[?h0lt 4wwdY h%M$o)q`qp܉HBe1$OK(*8-%ze߮1,+C{!)1OzK|xq-`j _aY4ŚYtJzE!%ۖW􌮯2&7G%]Hg)KgVHךOW1 z-U;4x'ov{Kܩϼ"sTmޭ](/.bjҐJ e3ޘ0a-2_7$ W2f@ufp4zR<1Am95X34#\] ^SܲQi˄DUmv`0et%ML k^uDT~@[Kz\gHGKAs6* Cc6ɐ 6W}x&sBr/2O|!Cs@ A%Mz3;~F3ELԝg n@z٫\qypQga8rW?:rؒ $I ZRkkȫ1LX+]LwI"Ɏd3*U]sE9CnY }Z @c}l&WUJߐXsOHio%6J@?Ze5/>gZ[Y!a?LޙMj< QtpiIίBu';sCkULeZĶQgy-6ckGa,?GuTiztǒq+BLZ \+4$kc]u`W[.h\JΰkZXSoPjET<6Sr6b|~Ňz{{Ȝ H$ȨC4 |WUYXk /aߍB_c+ݗZP5["T2pQ$V5*Wr y I?VSG'’yx5eG㚝ǣ:o|`r]+:39FjJ!P!7. mq'!0>o 2|wI{ %Wz. bO+z/bYykR+4(kG$"+(W?>RxOQg%u Ceb"@ 4F>OZ\4?8z|x4mK9z1x?-!6SO6E@rz@Z(EzS ֡X?me꣝cT rE:G|ќy9]]疹T=4ZsxUϴNbe;KDja{\XJ\{aJϴ %7sߧ׸ mMV\`b.ܢ.씨䡂Ky~BQl xو("r}qBK|W~Cr, aC*a47S oGbKGCHe yOnt.xCoY[!H@le$5t, 5P[V:>1gl; L*WMEejX|(a.\X;r[U{VQ'YNaN%ڜjg &[v JhdcP\bJc[Uitvtl#\gql>AF1#<')SFW 7e{2Ә$!]@/} R j$)}\OfL#d7^uv|7MVMg "KƬ}l66c7m5GmV~SL-qoc# a]N&#CMKǞ/#K72@, @r* k{4ت\;vӹ]ʰ[%闘@N qqD$$f= kU4'xŸ쪥M䱖8ُ GHFEl(Lr?ԗZ/} ề:o89 DlQKXMɎb狼j]\]y`!PdWD~jz+k;ܿ sôǬ9e~ *nucyyeՒ;4+V#uXL8u]:r9w/⣥ԝF ,kSnrh2}=ғ$CûRmSa(su4`$c}dAH.& :õll]RBBZaޥ~,,,נPz4:GWxǁ"3K!  <'zq؂dz]:YC3;~r|} JJTǣN`"zG0x1,$}^|)%yipFw]Τ.i" -57QOj=: $k%?j\Rar\^8x]6໽2&1sz-5r ψB~M|ѯ{1iVMf7*e"Sv &u?] BغrBODf-/ǔAUzVd7Tfv~@-ϻѾ¨?@@PFV^DUpGC&"/L|y;:J[Q2?l#*ivK.ǒHԀU!1-\tp{|66]UJ;x40Ho22wa6id hUu i 1l:n4OkheBK\9.V@hܠރ!a|Zih_580)gޯweo,t}sML$;yQ)u} G/Y!Pɱa?+P17+aIR|uIo) Rt$Tk>iA.(>o kB1?Dɳ7bUVZ)7P;[S>GbWG Y!#RbdbNɎt?zQ[%XR2`iu7;F{8F'b(S4lܷm<bm~Cif_1(r|ֺѲ_ T\weKŻ4?n"lmC߆TX.$LbX_OSWELZkm:ܯ>SPI;&GrE% M{|UנD˩ (}w5 ]Jas0 B)B6Va5VӇ~nԅ#² #n"`B[HDfL[\Z?iWT6?s\0ԝKՙm`<[\byV%/c(nȗqj?%=[-UIAT_:8V0?*d&lâ[ K>l %ޮ>c47n-r&I ~TZK8EI4*kB35lo׍|-o &/2D2%Ac R)XvM ޛ}~*ʊCTL04g bٯ~* QjZ#E,ezZ3^>)av#&֐OvAa 0H&o׏g|2&<>@з YF$IM ԊADYk^aʜIyNK =0[RFkS}\}lygnކ0qⲛ77jj9F"mɧڶ̒qX (XBҔ*#Eåo*h%4 %c{T'*1Pe^g,j8}ABfH nM/t廦<աvZqAJ4fy:dQCYf:Z##AЛgo5mdNpE}M`8B5,;_#p1"G 9Ks jv:"oJ_;-B7eQ9g^z|ɜV߬奈gWā(ps3+*a~f#_gh^GԯB|uU o"ۯQkC쑣¹V(^ug7Ni>97Eҭzڄo kL[Jls3%FdO_ڪ6#~T s%IKm̐ <6ɭX ^2ƭsJRìa&(uH& 7tձUolWً%++t/,!Gd_rk|NO0T?Hղ_{Ҕ<-_!7VrPOT-1x\e ՠj2V AlxY^佾wjvgyDYp6 ܔrޟ%_G_RtFf10}#RS^ȞG*+؞}(('AT-,V&7;آv.˯_lzH`"mx&\dV duoYܼj-cUfSiUl&$r hrR6UmSd_?6r 0&(oTS6`";A6_"mJ!D T-֏|AL7LPfl^ARox9/7A2F?` ˂{a|>z0 uA#{WX߇@9?{c= jGl.qߵuhl= ŊԳnӲA8*+nѬKDmtC03TY@7'O.fMjeSݚ9v˜)I cŋ֨Ee#=JDJɐ`5p[XHP$&HkT6r[;s.wMd:u!";1d%$!Dn.NHOޯ`0\M D&͇Q>Ꟛ ܭ5D&s!V3Ƚ+0^̚sR OC8wO"IIIci'uFZ=Q+2)eWg5zoEpzHӎ>^Ukʖ%61r 1--UMQ$.z χdd)VT!0͇xҦG9ZU ^؎7w +1`^j6!b1ǿXw"MD4ӠFv<i 4{),]`1f^$IޏAd-81@9W53fuH{Bo: ?$scNaά`,$+ @(1N[.ngbI͈ǭZMٕXsPn?35Qe;Yw+:bX1^上yלVOdu1o~`Nj %Pθ h9ljMZXDZ|ct{Q?͵ݠ\ `Ӓ{t@.DP1iC%_Q9WY$ _8 bFHgY&3s6㸢Q~<J{zLX 2j7/=YeK 8Zjd&uBl޺/n].>(L2,xFB;͖FAh+`$gLLIp:&:ʄ#U/uy50g-cuݨpJCpQ@EsME[l>X)HT{'ݲ༏K^~lZ:|&ŃK Lu'?孀-RzZD2]F VU;b>l ]qr&t֡^/^dp=M'_V%Ђ!2Hlh@g]ŢPݪ{ Kz{'27"Fo3"bjY7 *([AYc~\v!ST+\9M[#ˤ̛"Ϋqd*ēGxJgjӻ v!F)궳JQ}UhL $Wٛ!ΠMOgXtbض\ I0 aH|/ ԫd ##fels Hb'dONzŵ.?ٮ+/fh5TM%+۠ r6Ǡ$,^xŒp9*~f2 U'"kj2hP`A6TKszt|ƐC~0ūhhUS{zLY )җC-qt0tExbĕ*̀ fI(U'jYftF3@ަg$}5B>ɴD/ !J~4Ϫ +~0 Q0u4P87i61)ڔЛr_a0'Rي~.ʴ M UZ KˠR1Rޞk܏I9$bBt$NMHkq! g=DxY KI>&AZ/ّ)Ul1Wx0E F ("s˶s+|ԋH_xn_oFjM0!-!T\Ƃ2`!,W}1E $D^mQē݉T^zzU3N9ߡx4NW]hd;t6R>ӁlxUwkMa@c&>jԌ>Cج.F :6a 6keA k+PF(AbR@Mlk5YM ȅI7l;3 ?]P(ݏ*4w9b,0W4 q׃S(aTSASܝd7".NF'K>:|r^}r溪 DUZAhMлuEyv+RQ/xV ۦxK!F׭-0=ѡzh*U;\h8, ݯ$ݩ,Z j]OW)AuԎcI_ҥ{L_cG=!^%p!C5>)}l~X'%frӮ̬`Jlɻ.FJؕfh@袶2YTq߭Xx\ F6AZ_|n/&fgeYe&˃dUtFc+ivx%/Erf^T^b>\i;O~*F7d@$$eB@(̕DJ7V%kj^"k'Ctr oz ECjO<ljN,Wh!Lěf 'BĢe:x+9a)0#i w?.F]` >]E$"؈w!WU/'i2ŦZfQM]s_ޱu|{]\yQ4T0N,M &jӿѡ@pCs"GMsqB/|E(Pܦf s@%bĤƊSbqKj`:HE&{ gvfont㰢R?`DϷ\m{1C߭!WPCs%R#dmEQ$p5ZXB+v8L!°Q.I1CG S") Қir ̓ܵ"ɘ->ߠīlU޾>C$U(䑁mE~~ UYo*: w>8dz4k=4IouWv:I#l=YU&Id)&q̠Q6I2H|M/y~ߩQqiN1޾"%ٿFZT\ >e4oB\E[7﶑6XH;\75FD18. 7ҔoF ͹w*CPs%tw1 P- oR-H.LDlm KRt;&xJeqN(R펵9WMjN%Z={і!_% w{&0i=B*pJ?'zڀ 1(Mn_W =8ܑg"70. '7vik?O,=5P;-ټɚz EJ-Ob{Ah-fWTR'ܑszo=*գ])3o;6@\6C^J 0ϻ uQ#fƩ.g}6į~J41 ?,:C/d̨;̰W X?\KM,`?mb_jgZ5P(wT.0hG{VDFbe唨7w8G$*Y]Jd,jet1Bz!tG&'s-5ruCPv1 JMoY2FO{'뮗H -hڛiֶ{WòDэBpX˚as1Ld'JVd 6 ]"a0給ea-Y$ۉS7֟s`5a%T#Bc=U]:0 VaskDuDí),?[DBZB Q#pJUZ^rrnDcJ)̰BXK2Vi54IR&3SSHHivWDDޫfCv/07ޓ7B& F_SmGiG=@͇@#z dgs 쫞h|^e5?U?jm|h:M؋i3rHHVՃ Y 0|XS } M3|L@G&țhEvP)]"CL>a 4iwq M~C#0 u_hYHA>z#3ngD4_u#6P`rߏ(c`ս,%,UH pdazBAf*%rv *۷': LfT]y1DMsOԀ6~!zgJ0PR+ e+r2dբuZ#> mSն5vSӁ럞{F˝C'PL_cp\ަ>frԆA¡~;L*&M% L âmnDĆ2%0B UiS?E}]k x=lɱOF$ODF[o ލTO)wOS:wq!_BBtc=%m% h#oi/ 70?~F78ju})(.OГkZdC!;h1eoI~/( x&I[/HfwWFJDn$(/M^OX}Kf;`Ar}~O2a׼a:C/DdTXrS]v^b |_.ttGT딀q#E=6F44:i>@?4^WbIUՏdfF@Z啔xO])Ir't\֍GURIkN5fk#D4\/$n"!wy1[ q7beGuZe~y$uD094Q/qG+sMs˗Mc0pFmn>!&TR & *tq!ۂsQc|H z5IJg!o\ In|`[PԨ=JE%>lW0;M!y;qeSݕGClNn#PҲ=8Y+y+\ :AS l ЪfZ|Fpv+/mhQ,M |%WzK/d%9lݪpt,ѤnUQAWv mnc^٥S`3Mr}Ԙo@=]㟣H=< -OQW~n?1&vyiLz* o ur;U\dJQ;p*cj"6 0s_2^y7i{79+SF@jRPﲬj #hCF!;umΣX=sҳ>~4 "W"e5QG(x@Ix:nf89+cS4q "ʝ!>X听glvo>}wl[[JzsCM˩E!7ylK{kcSnP)Ji6+ՠ=e:*|1tTľѵF\$mp,0W! #$lY&xQ3\G`7$8kt.X4C0&U@ yŖʊj*mEaX x1͹Tw`Zr FSx/OmYR_A:Q_>OӅU4U8ݍۃ;'}U: F܊ƞX5 N&$X~׬p ժXxF9oW (M>4B=o%R>!h˖U.al#?ᆱjԸ3>'uZT!' s QK͔XarH֤I'8ފeRFZCN9BJ*sK6^: >NdLčL^pN25+~h,|J~iY&и_nESodq)u P9ׂ׳`2[A&B۾gAV"ZȎi^ڌ`^"0b~箺}|3?u!omO+w9 J𛻩p ~6щٺ֩OߜOAܗ?v}koYWjW۵9(LQZbimw #;+cT&lXS]|w,@%΃DH";\[na믊zO#og=Ya,}= - !)LC4poHoxz|Jz=yD;S>n-pv`PhX`gT)֭eO,׈®,}xE:SYrCğµ%*DۘB3`La_Ն 42Y)ZZn-\sFÂPM}mǁrۦ}T:SU*.ʠ  L5;Z8h5 p2 n>netƾ{}gY=q`rQqLAG1pUЮ1i EJZ3%J+`)=mࠫKKf *gj#ril#[A* ZO< ڇ{d~w!yv.ð: 3+p?A=]4x!N& $|.qx>;P9+2tU*˩*'njn8`iG# ŴC_SBƆT!!.Yщu5`%wt/Kc͚1P&{U( +e6B}@>{W$f5[-E@do/l:M9ym-M}f]'TEg%ʧ"++>],)e(72$k17Ҕֱ]g6?GMITur&?kgej"{$IqK_Ģ1 ]HPdlxA4Ga{|:Diރ'^(; n=~?^;dO"f'zP56 _*͌,G1CO/_ľx]5DT8) ܟ ́U6$o43NsGfBmsGg{ARQՖy;6O^0GXdY5iO0 { 8y=[ AEծjVJWlp{ 5eLjB| d&9IczQfX& O38*ل2,ޮk~_v@2bӝdBhoze_& 9@Ecb /9CUWjyPeӪh&ܡޑ6"1Ni4B#uN>"M,ioYfRNo!ɱO^CHBtlu5F\09f{rKEJ]l2oߟtLMxn"ԯ*(`/gAb %BunLoysr\ͬZl9KcB0֒N6i0leRbsyx\ G,p5~OutfI `-ÝҺh Jm4=>)#Vqh C ö`&|V𱢈s"Cxn$c&BU ,mkO>G5Nw\ }bNY\URs+CWy Q`ȷ]<lizL}R8Xzbv2_z ; %$dcĹ+_Z]ep}?I)էfcM*sI2/p 4m Y-g^o2V(A:U0N nHStj"uڑMSN E-dJxI g()oGB"ehewG^Q&csS:>HU'YfjXT? #j#_E8~!@ȦaZu;X;zb?j]^o2l7q9A9]/s/%[='rιMK;sPjġcV~|\U~=opҋ)]j)Df(99#0Ff31ށռe!:QhMx_+~hlIϧ 79=MKHDv3AD2)^IϫwF86fPtjC{/UwRYKs$L9l\F*ULf&1bFfSڬҏˠpq9 C7nsחgo9ӍtPN%-2 cs0z,#ۧ+n].-XN'^Ťˮ?7%OJғHxxn%) _Fӹ:MC)&hXͪP `\MҒwU?sszeޝ!A" %AD(&w yTkvb?K`X)UϷqdғV# xmc}]gb$m'bpͨlXgٖ2> '`>+_JYA'R% # _B;ƨJ e` jD"Y$2gtʓ Q}!jAU 3>{"uzÞ?Sb$<mUnYQ8)*nؽ"py\FM՗PF{-|v)qzɎkvVo?2K=XRͪ @o`ۅT 7*a ꧐_g1375׶ko2a>Sl'JSu\j/d4{{ d|y 1S:xDrhlNKJnw oyuR @9>A3&DjO8BaU\ X`1#NB(&h2>~]8 P4pCR@unb1*/Q#EbYɾs-2XMP ކ5, $C~=\P0ZwX^!rd+<!H^#M ϼ|g1")KlT nfGՌݼ(زP|A?Cw5Dޭsp0e-<SF-\q@o>;~ ]V ޷ǧ&j]lFq(bөV-MD )t{[ C/d^{B'!efo@Ser[7̅Dɞx&L 4*FZ-߂(B;߂mHEP}`xtJ[{K12Y<3O{ȗ&@nk>(bk,}VO6Z@;فgRXRi 21"gj\r<<„`oR>h+n_X+syĹR T Ո,=2J'K|Q-C9i6nz"o,q$v9Y[4\fC*\1` &$r#a'@L :d눫6|u3R>,:B4;F,oXD: Ɵ/4 UըhڰO2ug$J59#hg"R@s^uL'{W۴+Z,슝E]˄ Yɋ>xqKXyt7bt`}r9.~oTwNq"#/:jK_NUByC7PO hr %ߑICVٙeP Y{tƹz8Zr$[RĔ(8or_mq'B~-Fn~@Sӑ[)Tނe;Gg$ͮ&= =-ؽ P43^^{T&Q&_'S(DKҴ&7-VwZge -ѴŚ؅?8R -^}*)Y:h45yg%R'=jLk"'EAj꣔vJrG7w'+"$6ΎJ+äB@J *vO&fU4qKx%5\kb1Qcl7 Ha aȇ,u8ʔs Mg؋"Km搜69+[*$0洛ݮ~L}~ Tӷ1 H+' D`5_DduleחP;i90%Mq[n= h 4k^ɡ֞G+9CaR\pLܤ} G-*gNsX؃!ΐ OHLdX)q֯TZQsǬ['k 3}Al#X [냅UɨKxКZ“=%[= bt]YcRߩ*tymI m?qB/Z`F'xY 1A@g4'؄Io.׳"TQi5,U l"iSg"OdUXW Χ01;%@F_OtSv"zGfu @TKk $+jܼrl&0]Nk5r kc;DKi'BDij:iV ƃJ~+c~mB!HbS(;F>*۹200uSO> d7pw\Z1ŘYEv7-dk!o _sFwTf1fxaFL('kpl|e9ryJ,m^8%f?"dSb$: ,{D/XżH)O4 _q]7"o&,jTas Pg$[W7S:@MV<82ne;4(ěbCaW+Uz`|x K\A*5bKF@++HRI{Kn&_N 6e D+ 2gFpYoMnhzK1I)u(r>CХnh-wG-ڐW"DlRBRјȘ5)]|Y=YfOݽ2g L|2y$j*DHƗqlwH%y:WQ87zGRfIOBkE[OPRnfR,0 6v7Zp,¶Br#hݭqz@58Wvmٶ@}Wg;"o,> |3Bg@}\:N$zMa{RQ5%!{u8j0x~_eXi ~_Q h?[T#bk6X8*&\3YppQo!H"k??K/cգpU~p j[-Jlp RzVp}a%e"} .h$H}(S?@9z>'>IқCL|2A<-<=glID@ϰV|XCgt-ހk,vgc #Yv}3:W9BDtZL9 BۋQ g_"!2D5:so"@PgS7TN^Ĕs++ijx]rM?&?K >Z5j{eЌ6}-yiOy?c2b% |8^vvϤLڿ}qlǁ>3\olaNRҺZɹ4ijKJ>wBג5i{CRq0alo[JvJ&bkh[f"WIt[ O»IZ*|ί&e{MGֹlp2SL&Fn<qꇎM {[0i.9zjϰ57A"ݬO!uGKTcg̝ g 9̜6v)P':GO0?;^$\*gk a>4ՄD, ;+"_!e+PTu"jVkEI0EJyU4XkZsDj9J(#&5iZaxlڣS>:S3 *;3qF|Nimbֻ݃Pzս SulՋPGoWKZ0S<Ǭ+fK_leWv v2LC8/4-I)z^?-q/UG R6| }'Q4p8Lru:t<:̶Z+]ⓕp@Vz jyjn #1(Hd7:}7s:2~*0%)*+'sťlTMp;e1V.:0[^9LvmuڤA,R[$7&Л:B0IĊ.ZCvGޥWV}h{g~LsFzH. ރa˻l$.13&^,uze.`䬧R쓷 C h)1ܝЖ|.Qg*MSܼ6q3{1s[*[ q ep)G&12Bz]$s~kL6&>?2|E>l|nA!D T힦 cU3o/)Ӳl^/8j ތ 86Y|NTҭEHxk-V S&t(ϗ8SB+c=aHArkS#"q/mͲƕs폇^!  nUT%{7{]}U} bMLorPS:D\k,]<#o/+KV\ RհQe-` h9j}W;RPT܉ķo s 6QʖD EFW0Dh/3-/kq#{dD'm+%Hw쵀7%Lڱ~F ,M%Xß /1#Cn8u|{M4\{>-!!לsqu)#ѰwxTX$Ń˃TAq%XbzR^&u~!m Tă<‡pJYЂ YBCs UZ`<΀Ac8)8,S`fg&Dfϡ%gd%A}MuZ;;P<5"RbΚpi.0Y߀>s }fϡ'מMazi}o!eqG1t4 ];u6s*/+n*[ ַ1S7Bn36G::^l]yOq3r_EIH-p #ιNcX4vnՃnwc,P[B~&.^Ik+^j{eUGSUr&(ASJWʑm>pF᨝t5+Xf&T4-S1bfиTARIrkmԴmk'GE=VKzcx'1\Q54_d#력,IoÐIj㵽l;+"r~߮(M|%+j \ґ|hPmIM%] rJ P3W(Œ#t[ߨww/dh yazՒEvFnf""FZOjX)5geqWG,Ѭ¨A?R+=x3n>4ʉp f.t}mHӾ^ `d\`uZsiD^4 -vk2x]MPLX5>I<&@ưR5V)<OK(mj: zwx\x-EM{fZ2߈B5x&ƱdxI0T71Of( Yc5gdQ%:X\TlHj9 rpcbh+: PSuq@U`ySG #n8pײ#t+)ԞLND7s_ǐauɯἜzQ=7*~*#H&C|3n/IDh%on]ZBm7kD{pS&9< "НJhz; 08'ZFq^-~Vgi:&RZoyZL#s% JTĹ7ך V8aӹnJژ8*'R`?\~vrY!ZGh ]rn5fF~Bl`q;DABk4uIs-n3x>6h2:7u-vWq.-cV^=fy_(ρG޵X/Ց 99DUe@-˷jz `ybS> t/t$Yᶖ٪k/n,*L]M}EJ&֮#n͚F5U|KZ^aP <'0P+ )?%=HTmAsb09|>yX=_RLdhFj`|Ä7\vmqK=]'h2nhC\}ihH9hfF3q-#^VےE?[مe ϑu -/t' ;bp eO-hm432˗lW=H4-5KD a (" ׂ 'pWZ\} $Ws>щ;=zeEgD>W/h[w{IlArz*g;jnRFN llR#ŦNLdpB"?&;H- e(.>ϩ ˆfG{)Bӵ5r98\eh-3+~nB7(t^BB}3JKx`N*JI$GD,=6@QHU#yxv,Xpw#so|"ףit#df|U?qPN)U2 T?;L0qupْ"^@i8N*YΒyQsSO yrԵZ C97RmԦf=ؑbj%#u\e_f pc|^r^{c)5,e… _Y- Yl{b=ߐ{- 8=M+po%F$,T'4Z oG U4{wob=}aΣS?Ic^|$g0mE8,v6Ӎz'nCpKr. QZDܢ6DY$DzoR$q l ] YcyZMn=EaD_.ڋ$tx_ >3/\ҮއĒ^~ Q!j-fPzħ8=^W8pꞋ0R>oaSGd}0?1\6jjF 붶D& +kׂ&Q:+(  ,8"s\mĪܑ RvQA0怪Q֢,+`.B].R}[@J@)t҈$8w4ؙd$I<nB뛶hYSh@Kפ%Y.;gж5D >%XF i >seDsׇvSubj8xբUo ~g G.v2gTĝuݐz 3/ߎ?)^H̛jqpg}D+"4`v_B?eP?Lc@fWm<(gGL%Sqbt LY]dj>! c!p37g!GA'lשx$5q^|,3BUț g廨lDeԮ $2>UDg2MӘf$4˴M@c*S7n`Y(%}R+&F󮏛!ʐt>2]^p#*kvHׁ>kT#BKObZBX1Hi 3^85Z 3H:,:+jco̡~-a q3tHJ:(HgQu8z^Q*˟0aRN% dT ,Ѥ~bIa6+1b[yvr58->l^" :W_#ɳkp鄂۸E+7 s*ZL 'F.5Z8V>WTnoŻ ~i?0l0`y.W/ЃF%Uʿ [@'zLc{($ZnYv5&28 ]{8gkf%{}'%B];wFC^/m2?N~ɮLjnǾ7p# ˕߀E2_>=2maK"T FJ>m"VդҝEكx!9i#ºnY}5%튇 ׶CbU~D}.Wa“Z*8d)L`S~YٸWvf;H?I YZ