libsss_idmap-devel-1.11.2-68.el7_0.5> H HtxHFS ?*}}HUI>%Hcg\%XG {i e%7t(M/Ii >9(?d ' =lp 22 02 2 \2 N2 2`2Z2Tt2<;(k8t9t:IG02H2I2XY\,2]2^bdTeYf\l^tx2u@2vwx2x@2yClibsss_idmap-devel1.11.268.el7_0.5FreeIPA Idmap libraryUtility library to SIDs to Unix uids and gidsSswsvmsrv03.fnal.govScientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxx86_64  L : ]. :VhUVV:V8%lb{B UMAA큤SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS54ed1bceca2ba4ef1b83c1d335c9eaa8311fb76c64641d8bc2222110b6e7afd6b33a89557bbfdde5d4ba3345340ddd98f22c43583806dcde60b95717a7ad773b8450208aca394a866fc3662a2f1cea50b526f87dfc230fb7ae57e5554874c97c9e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58bc6292294e0157c02841ec691e9d6c06566e00e20672f61d34374e671e911d19bc98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830cea718ba958b5e615018e639ac8627664128fd37cff616e58ab818c15ae1c65caebdb4fe17eb9dd46e281705627956987e468d5063dcafd9ea77c325ebfc3fb849d8441899436f71194f3ef738df233a0e2d4e2310a7139d79ab526cd10f0fc26fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c8b337f5afef976edf631a6a912a36180e012eff5c6ac624b758556b454105cb3ec747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f7f4cfd6fbabb73260ef3cd39c069cb32bb45b9c5bc1ac5d4653360eed58d18622afe27d79f59876d710474fa6ec05050f8665414a58c2efbac74b35ea8737c3841be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562b88b486a219b4a8ddef802a89e34d7bbfb632cb50686c424b62e1aee0058ae54f4bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a4d63beff38c9e09409e657005b0052533d519f6136415c1800e74aba644e50a8d979185a03ebbb22980d6780bb63b526452b44feb80b4cc044da17d2e587ae09639bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libsss_idmap.so.0.4.0rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.5.src.rpmlibsss_idmap-devellibsss_idmap-devel(x86-64)pkgconfig(sss_idmap)@@    /usr/bin/pkg-configlibsss_idmaplibsss_idmap.so.0()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-68.el7_0.53.0.4-14.6.0-14.0-15.2-14.11.1S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0121.11.2-68.el7_0.51.11.2-68.el7_0.51.11.2sss_idmap.hlibsss_idmap.sosss_idmap.pclibsss_idmap-devel-1.11.2htmlannotated.htmlbc_s.pngbdwn.pngclasses.htmlclosed.pngdir_51c5d2e6abb8c097c7ef3be9fa53e57b.htmldir_68267d1309a1af8e8297ef4c3efbcdba.htmldir_c85d3e3c5052e9ad9ce18c6863244a25.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pnggroup__sss__idmap.htmlindex.htmljquery.jsmodules.htmlnav_f.pngnav_g.pngnav_h.pngopen.pngsss__idmap_8h_source.htmlstructsss__idmap__range.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib64//usr/lib64/pkgconfig//usr/share/doc//usr/share/doc/libsss_idmap-devel-1.11.2//usr/share/doc/libsss_idmap-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryHTML document, ASCII text, with very long linesPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedHTML document, ASCII textPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,<] b2u Q{J -#Z;|_9RԤ6:9XOJa7@]--V|l/4tI>QSC⡜17AZ~V!ENT%i* L:ɏfs<3E豜:^Nf/U~' |3$5}pvNU&}jҰ(1E0Mſ5)ù\YAAuT0*,t"o :PQW֬1xP4>[LSk𘽿sfo9s[0zX5>Iq12_5ᙴwi x4D/Tq%'ʸL-5PS?/Ւ.p܋o{戨tL_Տ -W -*~Lg=7 32_g`)ؖgINGY1o7PepN%VʁI+Z~^*&g)GP'ER]cu(l:1/R= ]1G2LJ>u.p(/,j9*;we! z'Y+v9j$%/nXPkįg> s _:z#u4Y{Jy@R0B+?;N=ZH_֑&YlT(g5C\|wiω1]uwDw߂$yͅBj~"l%gt\$]URUwU~3덨bJ5V [H;|m6 ꩵK9(KZ'%⽄kɼ$VPVSd@aVJN;I :?tS~r\-ZgQrkyŻC\~1j:Fl;?47['zɎ% Ѱ7^&|Y cO(*Yv0֞f9Tgg@;vRMwd/7dm>U#OZk֓5l:ԉ:2rUK,3 ?N W;K,J 4G >_M<޲x6v(HuyO/U;rgAphY-ϙDYb+'Ƞ8w&Ԝ,DMS^Wx7x&M|zz`jNC%,l~|lQ/qm;ZdcVx:4 =OԞED蓗P2q8: Ye<1{Ps-^"pb7h%;76-8&^#|E!LUUҗBOj$=,"v4t=s7GOˎ%{"7@+I l+ؔyʫfTIG%k cպ`%"?o=\f.WU*=`ׄQ8,l+OY; y粸@xgT2,!3x21FoGbZB~zƋ=cL~MqNVJ2" 3@Q?n:8\mlZAG&nI;jzJLߊ!n2umRTy Pnvo9_j((n;:_ mR5Phfky< 0 \/l0+RVIܯC&4Um=+OC즧NO" Ki\1C[clYyUR:{ tOI T0i4`ߋR)kўMFQb ҈s˛>=Sv.$1tRmSjtE5)e{CFm?|K~kgTPb*;{!8:s2Gu%!yOZ&46 cVA;p;Sd@R^ JہQ?9ߡAT2݅8Kc/w NL9D/=3)jJY2fM_mCE@0ձ KVWHc jpIӯO=Z^9 u5H[$mqQ6WJ2T"5eYH"uo w qh@: nkqu$GmÃX_qW)onbQ!ʍ[m=Ur_[s Ϻ6[;V;}}'pGVt|C>B3L e}R ci tH]+7;b) ;_x~asg4+o@!k="8Vu%vȳXqBU1kBpѝى$]L z]_d' L :>X c%6y^Kv_&R?E)^?* Ek ş^_`4}ᣣ{m- h׉VAƴ{L \ A@LbQ#YN5Û=-8.}@%f٦F`npx5~U. 7ⳁ ?~Njbh\F`j濒۷IF nGPr:p,tf4w#6"[)oUN9>\m{guDt ]WUBP۷bTzw$api7H s6% 7ڙm.E.D&I l+8)s}nCso}VZ8MAZxkU3GxP:ܟqɒkU[NCpx -"לg ˪v fjd=Lp2߽ߪ(exsE(PtxA JcTl:tEW΍ z%Q (RQLᜐ]#OD\We;$QlFeG3(_ΑqILYG>O9ow& pZ5܈Ifr_>sneN')FYkb3 Ч]k`$P*FԜTHGLp'͈iio5sgG㰴մ; |n/;f юo*0<(*u l6ܲjefrۜ8u6}+{.6y&_?KzY >MSmb)Gj#q*v?`.{(t%l='A.GC3i"#jp"$R7RFGΘJ_O/[}h:\ +I?9h(ihX ؿR3AVYMVsTזuhPr&b4ړ Ȁ x>`>g2U;ζk&z4ң!{N]].JrA(zEϪPTN>Bye ś|i'l;FRZR=fk:tpcXmnB[5bv]p^GK44@6‰XأD$(>S,G[5hZ8I, rVVM{JK"@N (8bi-fR۽N<g+uYfhɬn/2y[g 8-wDFGFI[Òle\<2\yGϟ!.NJ38"Y',0g:a%ڇ9x⌠aTe1 2< WEqԢ׹"h/Xf.a- cc+XYR])0X$;u C f I_7A|8Ft4iv^]ȡ$^V)IC.َ S:Y櫐D."|o{T=xQ$wy SR |Zfظ=4Ez}> YF!IO>Wy%,%;(IWZ/vPqQ<(/W`kvJ_ݱ9&mM>:0R*!ΠåL܆suS:㫼WLNl8A[-{kY^ks9 VsB-tMlyѓǕ4 C3k'XpHT#.O/+l6/mөB7#ȼbPDoS7ut)K"+ouXϥvb5-eA6*OOc.i1 Z V+s'W E堗/"0XGx)L]3Q9Pc7"HG܁58oRJҫ8.漒=*,ۣݡV*]u]-$XFr 1y_닂 ({Uri6g`2M8,K"Bq/lc \DC ԷrU&rYe|U $w!2I K.Fh5Ϯ"p5B `'0}.Q!^;s0|bTC-X)C.{b7SeCSlՂ Q]_h.r'W3-ϸH @r'tq'\pA{:g:.ceqȤ_F&lju er@Cٔ96%7V'> p_%KUխWY~yxl>m[z=U ol^V,`z-rU6 , XοyAM0M`:=kt*=eNGJ|c ndU 7C1&p=j̴lHH]5خB u2q*A1-=)?Ccef=A:Z}2K^`T'=E{\IzXmu9rN&6_5թd@Mܿ;7CDӾ)wFR7,?Ԍg}kĭ7<) VyZJJ^XcS #aʑ׼i Ioe+IɷpAL7QK&,ro55"A#y©5vLq'"gr[#tIC"#ғaubΡkG{C?)2(-@B7&g|}kp(] 1֦'F*`ǹY=pc4 `#jG7{1C}QvIF{[oSb!D3|vyN;.\$K6{oG/x mjW}GUW>Q־o,NiqV+Q!cׁܭi (RvD=8EX:A97;CIµfb*0B[;X'eЫ +[oϑ|:5eLE/?ad-֚*R} Z0' JvVWYecE,Wd w)"Ҹ$mqXgḖ*겆t5__#n '8dViYݢYʋύ}HJ6<ȋNćM@y4j4J)MaN&Vg*鼭:JM M1=A.R3zqYO: 4f~ 40X0v)x e`\U e|qg=$жP0'FLY`z"$V::(hMP20G j c~F!0͊F{(-@_߀Z&^mϛ΄MJLHWdnFSL`1F uu>gKE^Cޫ@,!^e- &PᇚN7)L}z Uiq9_ #~fMԙNPZUw/}֙38##7U=ȍx>L!%4CkV N:;Q2PpҼS>c;~X5TBIm˲7ecƦÙ WdÄd ĩR6gYd m}\lZ7 oOk]:)&119Z3t^HgH#_cNDr@n)ŏr$$ OtO,=fuEKZ"1*ex m@k,FgDNVq䨡D8Cp7a:ZH 5iP)sf .HctJĤJcuU[\pLPh6W'JhbY7$2҇KQjvsuyZgHgoz-gюRů=@&MĈ3}y6*?=2uJJ:/[2gr!vniP&c3L75A} >oNBrbxGHP -TvФ˚񎳙m2:逦~;G)꘢;bK;{Ȍj(Kc9q*mayzuڔqTȽ k,OҮ!TU'vק"nk`oV1ѧ%_uO< SfCl-12X)4䣐_ٓ ԵV"%>`]:|9}| k`.H]5{ǰp O]0Z!׈-mzQa4ŷwd|u`4miZ*w,4{FXbЯGKmYK6&e^]c~uQ1fulg31@Wx&''5Э-u7hrzoN U"fG!Oմ?F™,V}:֛j#B;h#QATgq"q9(8;HW' =-W.ޅ\q*[ƽIlJߖ%JE.)1S#]z$"ff{MDG$`7lQ:‘zl5~5)ݬ c&T.4a ׸; ;ֆ%'Bb%( {1=:q!5('ER8 \պ15fIZvnBQR'=WHZ׹f)O NIݳsɁ+\vEAcQݻh / ZAMSs"ԭVn>j fzۣѼ[iF>/ɖUxo6Bq)3Sw__DCYezE$}[ھR],E)GS0eSV8t|YZ. w09 PekA%M:MU_.T%,vHOMٚ pðO0*Gd>"`z~F d=aW X?N\U&mW,Yb`S,cSF~r>j@0Dh!j4seSF*wqm٤l3*ULob-(5=|9>АVLd!Ac~9bƱꜧꇌa4ʪK42|9:I;CY1>#r@ Хa0 > wў\QM74lâ4/H%j]N)6JYtrvݹ\z`k׈X$T[s)6s >+|+b7lQ\cǁVZ gF cc\{`IĄ6OU˳ = .Qj}HU.u*;m\l/FZD$xSqJEFHLQ}2Gf &>:Lsy8CaYCA%PsZ7We&KЊ{G kY؈Ӏ+} XE3LlRDU$n;j3Jlzs>LqP̔ EJF+fun>qC& RIJ,l9xK -=r=#7d SzԯZOX{g=, YsSNd:Nx}-FHe-h#k$x fflK3dtx !$:.B_~#HNz#F8]h h^η[P2ve01ɳ61).18 LE.eVmT &H,u=[6O@_0q\"[8 W\&n?v:'A C`\X  \=ܝ3L6,0'ƛ*;Ϭ FxK+d`*{Mp<CΣ{խJ"s$f(Nz@Mdrr V*6ugKhu|z= D#e 2hwFɧ l hӝ 1=0k~\7]P kρ}pd=Lzf0Pt!8) jy  U 4:*QI3!.PPi rl̸ 5^M:f6Xjzi_/xLhcL_i* POn܏c%FM$~mUyR;%I%,{gml*|dq|5)w1qޯػZf<"ȯB7;r\BښKbAk#N "ӟަ(4RNDK=~WcWP19RI}|hb1~[ܹS A C,j@%J@!?+M%dU3h~S|v.Wu0v4x7 ;tִ1X+x8g/ u8q]-3O˶g0E!"{3eL ngD-yIkI0xf`p,=@=cxqU5 Ek0#5թzԌ2nSDϐ^ oPz0RQ@k-% ᱶp 0 eE]@F#X?yCX`Z-9.I%홈E,h# vR+#ENel+DŽPY0uqOdzU%&1~A.ѻ]8J;_۴۫<23 }"pO*]~8c`:VD]íw|[.Imꨫc(I̖>IEmkf~*^Z|#sP񸦢{hjh>)K*@(KJ#k])\bPE>B6Zcɛ~ P.nЃG5ʾBVG#,]CL,*V?!ń#RQGRAN]_Dqd%l37kߋ0!⋡r _$*@kt-|րwANxpǣx|)hELuwCtBkA'ZN3Y/D1z3X3 )xC|ǓHQIQtwhIޗ(:- h+}:bg QqM:+*qyR@g _24`+_sp Up+Ք>e b)ϒ7+;}4%۩91>Nh/fXa@5ޅdaۿx7q%[Jwg k p0uWa/~Udx'+zŽgw9#k7<*y%ס S[ozfM.9 UMkh߄RK۝I% b^S7~}nnMeNToYUFDяjkωHD4ꝇց^QӰ^َGNr,@dVN+Uױ_2gHA NX/H:r+čv/qš;63dn#؆ԪsJx!io/J|}LS&47rA=qv#-Ka9:9I\lZd*>STaQ4r݀'wa2l~2Uz7/l$qUGvm9i^vV[{U }82f?-w[!_:}+ L]CI } T9t[nMo~Ƙ=r4FBQԴ%D9v/gJVL@ fXqv,^o UYF4"Kd,CҫN!IFJ Ijnm &#.L+Y8, @}|4~@;[T%tšA_1(5۴ҙu>|R$6gg]93+ >g^Ro 1pG|żͼ`j*!Ùe 2<3}gF We5mƍA&*H͜ 9`M.<*h4pU^^֮|qr|U v3UME~| BDO0iV:iw_T)^W?qXDR~yur^ +ܣgߪضe uF[9X}Z+,Rwh`;4M./;ְHw;օqpXP2;E"1‚ǸAf 0d\u8b?g|n)P%(FRw3M)1*jʠ\Z3n9,zA,dZZQ 3?doaOUtYMxRgE&Q%oPewQ[AFU % @uͦh_aѫ~h\tT4B$}Sw%YnO{Aį(QsŸ+@7Z vs w2^b8ZǾul硽E+"]}M1%[C 9 9c(B.s 8sTߙ[`8C"O[ D\dMW~:X#p1Bga;:MDSKPRp2|bJxUًa$ݎMg+F4="/QkC$l\Y|.FR6FxzMIu{klN7u4--gv-=T063CL۽ٵB/@4l),N|x]j)qvgo jNp/]k.& JQBfXEg7f8A/i@^xq ǵyA-0,(J qd.5G2qBY|Kxc%غQq-(=Hg}Svpt8}Q$'MuzFw)k .?tv0yz#Q,Avp h`?Zqk@^^Ww8xzs;?$Aj*u?Ҿg#Ү 8G v1%Aޤ/&kjI^R.aR#6o&*y֡h}n}^z,(!FLFݳw@!%iݿ,yNW[/q0UxD:ft(PEb~J?FUMRz%Sw|I!aLVZoIMK *$q*uYԭ+SA2rj jar#`54 .ޭ|ݎz'`֔c~8˕,Wß0OH u K^^Y'eFNAfn9!fP\M%v[ hqSaV H* ZU:RE5+X'[Pdg ݂y/o5>o-XMܭ uUߛ^i˨zT7~F,u(LJR,MD$TScxX魗p5M崤J<(H;d?`ϥ埬=aBjb43!glחM&Y+z=D\1%q̲/Z>7¼I2Pꂆ?C Z8C@4z+·m4w^?],a-Ԡ9ZQ?8sq7Hc3_ `B {௦(y>lTp6`j,]\v'Vu$GjQ Ybqa#):R0χ@\3 ZQ&'# 1fހ: I9:;8ä!7#D )r%0i= iF]?U>"Ȱ>n1p+.ݗSԏlj^Å-tJ%iLq; {wRqPV?X' vn{?v{_{G33;n@95jYܔ0CZ0J?Lu4i3?I{@٧1yoA[^+HI "؈t+ǠI꧹ﭱhnW|eh_ ŲFT<63㾄-XX-XZ `E3aTN5/5h ]m҃7#Zajg (n T"GWpf~)a)oqr6 vM 5?cfwCb?*⪍= 9edPv7á\FQnP}i]%1$]"$k'6@6%x(`$X/kFNZD3T0 ^F6ϜADj{;.9} ;8ro>J ڕ:`̫pً6b1[vSWH%@c3 VR/3F{Ҧkzjz8Xi{xNOC[`dғ_l33w^cmCk8^#1Nl0'eШu-s-7X-z,a' u ϵ\<ּE ʡxرLVJ.K698t&Jة'pFgX$a[>AajתMyQ( Х1)wPeiN۞!4`lḒ#aV@w%`8i<}9E6L8]VׂB rlckc>.mjܹPRm)}ٱds<36nv`̰WmfxM M2C*g9X&_Z*μd[S+m!hZAŸYIt{N oTv"gƹҙSh&<'P7cI>J薙 6M2cOYy[5CQC&jn6Nͻ@{2jKG?/Cr *07ŢSU`-*ܤD:FY8𦂳"Qkx-y![vQ4cGG F{K4U v\H'e:BI.PoFsg5,Q D9QQܵ3=ks׍ ],l oǠ~lQ+@gfqd(+ߎIɬVT'%MUQӇխ-4=GQ۝9xi Pe'H;L/R[ZU_Ԋq;QۤK!u7]l[H(ņ%[g̜6Ū9uv6im-EZk3L>J:j$15t+3ƆF5cBXsS@0H1H )FV)7)"?R˳jOmv?RùS7n^K,>B>8FN2ASUt?(~;:{"on9a͋)Tf@^"r/UfWK.gO"x_SXڄ:O$- ?V.[>3 s&xcA~DtqY0k(zHԕS>|sx׾?| Kj }.d_S>{?g,%OiDBx1)N.9~ okl+d2.]ܩnnzU8a?S?\v=~?$O(" Ќd͆F# bk$S+Qdar#Q#kq>;F,is~.WhhuhH#L+١4߼rZG?s8*(T;ƟZ&, a%[s@"ka[sQWCp2AU`4(}$`kN\Bl ԪMmzf0ǖeDν\ 0SE.8]AIf'Y;ĦdCBbPl4sp.z`.:uצzS$>o= VQ-\"C'(fh)_|r\9NelDYR 9%C|fG9Q?l "Y?m'Z7ubWYQ#R(4d'T_K cw7x]=B0Aw*5KMl Nł`U0Xs>#\!θn nkG$WZ`\muj;eq6PM>f8?/63]VBn1B({{a݁i9tamid%h(DF-krQ+wsބaP\ܤ]%@RIE;+'Nem= k/[s)YqOyqCN,C ILU<$w)Ȋߢ`$Z̒Jp?3fQ8)c 5Z+:щnCϽx5Hpe)^|oucd'yS)DɈ'\cb<]߱/ϸ(Z :aL%xDMѿF^nI+SWUd7HN uԟ{K6q"v@j$טˮr233"98Yy>oՏ \C;N" Z1 @x~3{1r15{|.2 ҷ/[㊇c4@S/ܟ?E*\g @P3gmu9Ӱ?1J%ϤEC)g۽ ]M(J@$$M冶T!7 Vi-o0ErX)r d͗FUܭjkSY)қĂ7YiC%*RmWc tPk r᯦g˾?Maי'Aﶝrn%*&߰IMZg{ihGCQLD]36_f3WhDE6;ZٮSI#5Ed$9b0?sy * }Ovnβ3i+ $j' >C;T6s|Nv,ŀgx FQ mmv92slųd֒ySr0'S'9kgOPʏ5ui鳓Qi&!se9c`ѡ!yKdQ0՞^DVi\1KJD+p#z.xON1ُ.WU;3ےqnlQѵ[5Ys"<9zTI(%2-.im2f_1rFS"knri2ׄh#ZHµ2;DwId~t&.#f^ N2gg X~|zW>7=k\z8MV^8g'5ą+" ;TLgژDxUV[b4||#S9[WQ!]jy)%@zJ.R/0 ,%`k&z j#N~ r=?]$` sMm3Μxk?Mts(/)4> B6…$j_ƅ(*nra=P/t~/qMP . 6?maLWͰq;v^l<^Ӄf RTH``^*T'o$櫢qkˁԣ~VWӢ`R]B]Xip_7hŚ㬍ɗet}9X-˫vӽڃhr(bajLl]k MA!s)l8Hϧwm. ˬ.v餰t,9Ł zi_ NT^,F-z=ۋQ2q%%-|:K&֢+"9/ a7~0x o -9:YFɄxo,= twvX5.W˕ӫ~ud'g,@E`+h!n$TTQ>UQfH:hs C遧,.g\ p7*^[kpd%.(&1YmρVkC9e'ӁJMsUs%1?3_ IRFCUߗ[ׯgI- DPi@D ^ow[p]`/$^wST CsaGɥ!οhE37J1NM\ZW׭ W {Y\w)PX. w';2W U}Xr4zmo<yFuN]k6Q[U nXP'`8s)p~7gfYNf[>Vq 1WAӂLj掞yf]@M7O=* <-Pʹa7FFO]|BeP+)sM[5 (|KQ(r`W(_j+^mϔnB5/2lD5-vah;'c-3_Xpw> u/ &ke6o.:X^ہQ+iLXXcv>*]gKتl&ⒷE=VQUrZ1iqupbq29yJxc]I઄Ć0ȅ߁S v  p\^P[.39: E4 B9ՠ*p] b`㮎86r#pFY ot gkMRf1Q'IAQLS,lIg6kj*Au痼͔z>L4;[}qF@"_2wi\/ɛAa#*.@+J yX.xF=%òHPXO&&h]#J3$=_s I:ب;-*[m!txwڝs;P~n5L fD'=K]$Ag*"!#.V{%? g'V LE ws@\`O\CSFY > 8nD?] :ky`A73=*e%- jk 9 dᙪd43 D&,Ǵ9Fbn)nPc1j$1GSνg>ΟPS>[eSItҟM%G}ݢ&rI'4T O+J}5]qEpՑeڏhCqG+]l*8oYu{b[z|oXt@Ny ;k7K|=7Mw2! 5^GU"{ kk!'wӟkaQ4GC\0ϊ?~j{?pY1_ D[/r>T|1\ ! $Po>m[,*0-*ՌD}S!)L#neD$"(\7X|SP}Pd>}/W#=qVBcoJAHPs3?2KŦ0$>yM˨^_fFóP(pFcv`gx2ƍ~ӌ%ƙayՈJ @?{Dh"7 s(hv+p úz LJ(-b@7}=wi_gLRԷZbwP+R[d>>̚}Q3w7t|vu#H PBpӈ%U"T)Z#$nBr۰=\+LLi[cUkۚїAlgc%\w{a>S27FA9o/'3zɷ q,5bjvexj/m]U$ :!GO;涮>W}|3Vpdj&*;3g`rWDA0I7fB] U$ {Dܿ#Ň4.LSZј9w Dvtq n̯=07J+NRpe \1}ʘ'fH!dFk7l䧥4F) md2B -D'Y8~oFG`p[ %mcYalPr*Ev(3yw3+0)1Ə#iZmET .gBRk͛w.X9&>w +O@vF=0"YK`x42zE,Sxy]Jy(^2I͛f<]mܖvHn´-`x 6 `FhI2RG*4x2!@i"u533#sԋ?ḜϏ7:ܪ 6LJ:R1Y/Q;N(Ꙡ3.'J̓R_Q܆Mx:۹>󲳱B]7BH Y|Rn`DkҠlr05Uhtrjqڣ9yLZ;t~pSdQQTNj_eBm1{n0t0.[|J/^zg"`U+Rw_0oJ. ֽ%[2F N9  sz4I~:i :~ShTG˔aD"Ap$r!ڇ #Zp46QWp* B. FOgJ}4|W`| !$pŰyaG%QYDSg/ ǤႥ E^[r ` MR$.]1a6g^!h+>i(-o;Fvݩ۲CiڢkD 2~|xJ~2Ng#DDT ~eAֺ6$u fhé-pX'* ƹR0r\gLIB=VsƍRztZ\(9nt.0uodM*V^KWGH_d/!|olz13L U;RqNK*)yGLo4`*~{D诪^% n3I+m m-"ZvoY辩eAVòۙ__W'o=CHE uN])0`uJ]pX7~Wqpז:ט+D.ZG)spy'uCC<'l{ l8ۈ9l٩n7G1ȗc[{FɤifK %=L3(IA?ŖHzArzsUa<~w|{%x,2if)4_Nj#,(Oc2 eYhU{>vC$EמrkbFtp/22?Y%]}%Y>M2ްcn!mZHƗ,v2̙!.Ѣ{3%nM10Ȼ~f@ȩ.gP_ƀa2lZFeň4j(cxhAsrTfTs-A3P:=<fDY,bDw]rmhM 'iX ʈIU tKFYJDr":'_I)_o}s%2#r\ sц1G5 PIqQ, 1^Fm/)/^F'>Bn PNPVx- g0Gq;O a2uo|ұb1⋼Qb|Ee]G{5)DxӠCFgJC8/Y5\ic\ 6ge]~A$pz7SS_ T@,[c1L ?%qX=5YU?&P%QY'i_8c1#/dBEvlkƟ`F5[e;Ia)ᩂOq!\\D:ƒc!=XdxſHxQ]qcM՟U;XjܖIVHjLJ^ZD*Rfϥ;"2 Gl%Xx "|gvfhm]\  m#|p)ZZŗOj`5+ppӧ*n;L$ӽ#V7U4XrJQ BZ@\U"ƴ]SБyx`czQ;|[O»J#<.Qs( Gdg ޶Rhj۔9 I:Zǃ LEJP4bD<YӐLǾ9IKY,f$ڹi>C4uQ(|Ǣ5Q]!8P$Ws'ZQ7lYLbg"9^{h5v=PG>Z~_ ѐ'A9 bLDcQig挩W_qZE*.iva/OJTsjM/.{"\H%3/&~խM0}C!?㬧Ŧ#Ł,PEf{X"ɑbbo%~]qEdIgj(s[ct[RY2$Eͳa 7qP2(Կ1Խܴk+FoSɏOD`)tNbkZxӎ9QjUzz  䜵d8 [_rm2vF#vɖT2k늒SH_4\6ӱ?MouPj.qѱz޿ m.IWfK-24µG:+l5ܼLBu/)/hw xUOdɦc3ԏ HNp|B!а b]!_Qc''7if0nWS]Nq\WP1 BZ0©疐̊TTnr/NȌ9i6urT* ls352i,EA)9 a:OeoXBی+H Nk@(S`gDX dZ@Q;fL5 (ل,qJJ0;YT?ٞvXNxk#.ahY7[ 4U?"WPnxM- +'H2>UYEм5<,AE{nգto75k5,e3-Bl 2Q, g4VA֌"X~fT_4j 'gfU%xLе{ :d^ātۅeba[ȺY8PmkPqE)<ϊfs5kJW馔1'!O25Dd?ly ʉ8\i1tB32n58(5st U,,Zݗ}:LBPr\m!w')8V(P~,6=(ɚ"LZQeUW 6/D]&Rܕk0Fy &(L'c+h Fb.x%>΁4*炑T#XJ g@/uPYK.(Վ7Iߝ7(&uo%aVo:uɥ" M¸}*(>):7UWAiJ.mUIkX Wh{9'/g1B@!Am =0_2囏ndʿ^U*-eLەklU^uH,d d$Dq I:THؙXuJ%7^KU-?lcџdɰ*xsP.G @g}a }u1xi[eaY:X@"X4nzPsvW"sWK=Ap>l Fc 9Fzr ;,?G6|mMD2jw%\::MpW9bUY2CXxwf22ZqEt6Fj=UK@pfСEv'D:0mpjcz8)8Pu;ڏF=î.oدd6.D/|)1BjwlWてFQh1U$|?rg|$7+]#1ڻ, FaJV! һS,B)_n?FoУ+@0 >۳ـ7YEoh3W{ Dz y>: I[6[Oq6)ܱ~ tV~s !~5@V:NC7~86Od6K(2ZĎEjC>bU`)pU,N{_nL`{ xY6g si9Vsu~b1qwQMk$1 .8!j)}^K`_G0Cx1dFª\*NN¯ȱ;˫'^a6g©IC踨\ SˇōxIdG i1-ʣ?E4%L[)> }*@wF8Ӈ"RfaN0Np-io[_v77cg:sHm# QYa7?)یQ;H'[MNނ2(2EopFFab2uzBaBrf>537B,K; jIO,2ϙioX1Zr[jz ()UC5T/ ~8`au,V1@|R]{߂o![QCmk=GQBLJP|"*+-y!6yE/odwZ3bW fk &lJڑ3fG:䒒"-C ƞ|kiZMzZ7 lX9I <pC+BfE"cnܢ*<بZy_툥K=hc4KFTjfH'$У怚qPNx ɋ\0Ӡ+O̦r[/>Uy~&3#> &+KK2k]YoSؽ_dBWtl䖜aW(gQñwF<a 8* 6?y(ҫo{$s٘j *%[EA pSµ=YJםA? mO0&g0eTB$^y 6`*ӄ[2c0؄@VخY/=uCi 1:.;fPCѼp".޷tv}$¡9]GV@NgQj8\ ,_œ[U0pUA>^M ^q@FAk=;4yM1ƘXN'FYcZ,Z,_ ^Zn]^TR&hDGGG~m_^Lg*fxm3Х[/\#%fnQUCBYVԛqĽ][wKAc1"oc@TB8TͿXn2J\b U@8 5xgHamvb]:75͸W>hɭAB&H̃_?z$ p;Z7qT5.㓤>2ip`mW]T2]ߨ%l, vuSy߆@-US?&q{r GebDz>F93W{tV-:O=i*gfa4F`wFAtxᩥs$b7 ry ^} /`xQ0(zڻ9tf+'R*z_6@ FGEn2ETOTo5-﷜ ,P'% g9Z~tHc:#Zo0-bQi(RF#QhINJy ׄrux*ڄh3"P^gasZnɝ^ ڳݑ(fET cmY1¹ k* ꤓ&ė՛n3FcH~UKuSP6>Jvd+}&f^]0t:* &$0Ϟ+6 CGnQ/9m؅B|VYK;Ǒ';N[n:"Jk.["*Z^[>@CnC7u;ƞsja:̌z^m"p3f߷"{tx!|yV.BIHFܥ$˸DaIb&!z}JDŽp!v jK@=#QgCϢ"gYs`ؠbگDк[$h%ÂF#%A8/E<u`/dށ7Ng{ ÞlzmE3` +]>Gp$kGpb)"QhxaF;kVE%Wy rw}MwH;*( ů5A7M˴,PL%’/,΂; WUL' *F1ܰf+Fs )>GèU'ʑҧCN}v г("X ,&[Gyϕ"|e #D7` }c59# o< s"Gk/uێIsr\Ej^-<=5@hzD=T-/H@8Hwt7ƍt敛ש_B.+6 (GByR'J.\hMEsZwH9 C^ JLA ]EFj"<6n$򡵇.~="j=t̺íl%p|LhfSU0ٓ{)xvY2"F?ɖ} p AWLDJTYN?KTh _|{Gu8„9LX8Yakb0D3*DқBrPӡc+Y~Fz/3|{mN=83ގxi|"1=oicbL^$[.<<`/?pY\mh xGf,C2Szk= #vUE][YFd2mݢjFBa엞 n2q3~lY-Q_<'Da]dBq.Hs`-uҞ^C;3(hAq/Wk{ϊǾ,<5E}H8wwtHwRնm͛:/2 RM)tScZPԋak%ĴC2t W]q:9MJxYsGU‚ :ꜲA&Y !sMwӅ:a9M ;TкyxxnS*GlR,Q:vgںsF \[vj)70&ztH_Y~v, DFcQ5֬ iG\Ȕ‹jP`CRpAT_zZ&YķgZh#͐[V܈z&`ӻ_'IAoN?J+.~m3W'{k\fn#@i Nގ-;9M&e %TUcQi5?.hGZ'e%̮ocخb9)?R@u" 7)_Svsr^yQ.7Z+2 R8™NѢmEpXA hFUٰ`o1:q~O^Rr=5KF4O4H5/zYĬfPn!Z p\$& x+Ѵ/& ^F.Ajqq#5|.ߙXQ X/G"C'0Ul#ksWƌ EI9FjkÊ`IiX`rs6x+(||1RzXuCom#$yǤ+S vx44y Ď9mF޸5a*vwMX"3\b zzP2?P*q n[48 {ELT]d;>ҪG:?˟9TC@yΦS{!:,fMezDa({p>_U'`e} hdٝ)qqpJ[Nm?+L#3Nt#6:{sј. M [L{$Biޙ.oEX)y\еP\%<,?.;aRuŞ _Оr,ԉwdO.U9a,V,v%NM|R5`%l͔cƛYR8ر+Ӱ^zrs\@*w\vWQ mZ'Bv,—ZKՎRr? X$D)}'7oixm yW# ?4E)LP$n~\k xRK4 [U vFci0䷸ -R1 1SU?x3*p [5mW%d:Չ3+yRzaWÓuN&fvOBp&AZwTmiYpo14Uzs<շ-o QJ \i.ױ쐞edqPу"5HIbT4]3qHC"2of?4}4(/H5$'DA(Eu^,9ʊ;֚JT5^PH} Iy hxҙy3'U"ZjP:w) Ow*ZU"&Nl!% rcsMB%xl>Ag`9N ޼[i|_**u%{BfHʾCR7!'jS~wLROr Hh:U :(;A[&E,DM{[=q-a| tW܋_dK|Kb*=rdyUEBFN@g/;W[9>+Y{C'zpu-yJ2ŔfGݬxyE@Kb}ΔKDj ǎ #3\ ,dTeQdsZs,kП^ ^u& x ָEIܺn9ش.#؛wwR~G2nظ&5~)Vqf}5mݩeHWW1`Jcj1J XߋfAҳg'1vGRP̕ a!YbF,cBP9L쀣 PJo 8&nvBʯmA~g윅Bj?y9vG+,ͪl;85?ϥ2Oe1cΦ?Ⱦ6n$R%+Jeϲh8c_tP~HxSr7wsB7F㖏_* .$ۏ`]w5wt !1/Ac?#SbDa,yty{u U)@U`;h >4:EڙcpV%C`ڱRƷFw\Ԏ^z0<4 qWu,XT4H/b#PY@i6ZE Mq7@*i 6w]=9L'(wuqQHﰔwtRڋ<|~U-wEX/iX!סQ|ϫ.?9} :ITbʹ DqIǞhx(zįgsWTv*:8e#7K*N/u<XadS&w= u,߹k/H,Dg|$ mYCV|C4cs)莸6qPM16[WE Fq+.&kHx;RTD9ypu &R2\VI;^O ډxi/}d/eo>>Bhgr-[KFcV2 $u6-?)4UYjSWQp/%OD' O]Q>Z;$쁣m dr"ŀRz'>w8K=Hܢ a_}~-,vnqtst͆Fr5Gm&i%B|b]8k΄wl[ !cK㣫 A TWe>/! ?Khŏ A]IBDؓ0foth<8>|PϒmD=}ͤ6-D?$v7vvЊr`pIc#]݌, B 4ɬc}P?)< c )rܽw+j*?|&*l`rHUMYw|W]O5 w0hhu,eҌnG Ws* <}z௦3"in&uH6*7Zm-8&X=NM26(k8oQwN]RppG1K@W? $~"83b[AӦ^ÿr.#"ѱ.5kwf*,օ[<+2k&1]=i",Ơp`mH {{J{,/]};b 0Qs$J^3:}J1!?2Xp[bc,Ghm73GrX؅@I4ZVzK \]WhmݱAѧ^ܹn'S6-/2~$2F~g/z͠QH34G̬%p*T }0`u(CJ9E,(=[m^0 2#`94sIzŞW)Wc6>^B b߷ c8Gy`/慒g$\Τ%"L_caӬcIS x`mfݰX +(jov 4nk9O$pQ0{+^ynXJ'I#݀̂݋"OrwoǓ/5AEj!h6$>5ö1Yл^^AHS#Va";OK˄=t~mq5bS5UiaY~R_ӞPߑf2{_1a %AO󣑅< T}t qBxڂ#FҖ_m4՗~ru"(8{[rn?-O mXYCŪ4˻'N?vvW͙WPXy ls2`^Y}Xׄn8TCcVо.@HK;Ö(U)ԃA%CkOW+UZcP:qqH{pߋZ?ykԳNҰ*VEE*T'{^}:'aĔgXM6zEɋ(WP#r'OYozԭ/KgWa#Wc`p<{ϽЕ*ep51:7 1 iC#ƀH2iѷzt5zgVɜmn1VBC@^^D_,cZ[_T)Z즌NijfӥEx_~}ޱ<T)mmUƏzP."M)7! >a pTט0be0υɑI G J? 2k]1h_loE<(S۸WG#UJ?|Hoq&5?v |Ov$e>,V2F\FwAj~ HAMA4we3 Ie~b]F4-ޫ o<4h0^Vך3ޏ^29"xz9y/|٧G+0mn(S۲}@xҭS?VLeJB?ͷOZCõDU-Dc#8"# {63&YwzGbo)d"H."XUvVrO5g!`цyjjȉlIӰNNUM`R xu&w13Nv#1U=~hIElԹڢ(@+A *՟ 𯲬c!K\Z5-ђp`_n,!P篇oN9^ՑNg:SKX.n @;68w%86?îl6$M3 *xtל`B.sR4YYd{3pEkQk|EU@ ߗ7!\u;#T&/FEKp9 !gc^?E<E#\: )<3%VTJP D(wC#?t ;X9,mJŻYH…<C 9R3ѐ|iƫg@(B{E-L,.ScmkiNw 1 'JhB6oڶbf ]> J($2߹+/ saG# tc6uK!O3Tc?湆hY WXOME!e=N&c B*&)~oeqkLA(`kwI*õ3 "$4|B<#MGkE @ֆqR$6Yy&Ri=> -Ӷci2P>WBȟB%hZ!tf,X̨ߦ͓>ZŗH4uU+ '"ȑeIk(y 8^ipۓ1 !gY89̦Ev(`k6W.:&65O1 D:YH bI˶ěD*'~TYbTC_ďՃ8X9]=/M?*&(ߧ!Q࣯c -,oPInsPl[Ȇ`^@ Zv <x~ ڜmq4:o{`Q7|!!OABW %!Qz4z_Y&($Ҁ7q+Z0zBbϐh8gJVw_>;+ۙYl]~6{M৶g,di5BM}8H$=Uje t\h[#$xu#^rk3yS$Q2b vM/ .+!|}Yo;4/ bX7fuҖ?(kUpL W+DzfബZgH*$Rqt_u@%p #~ _J30Ck̨`Qv/8 >BrFfo򭒙 a}'ӪTG 1T񆫒G!0lNow'2?Td 8 y>3?cVj!3h5"*i Y<0l !aܧgDOX2TvF' @Wju!Քh½P_DAUFe4º}5A N¯+5DG$_T~#9')aG-'ō43 }tڈ ȳ`bl.|) њs+e赥x OghPyE6rA&6Ҧ37ۙZFtyc>O}a,^_`MU=L(xbh:nA)-fVkiT3FӞ1*DOEv)4:5 `oa)lWD>kj4i$}$~ !Fa1qR6wB7q9 UEN/QAx?ިV%&G\Klu˛-EX6.gSNJ?r;]P>,JQc𖌘s!? lpK[ܫ( ! jTj8Itܬ^{bviK!Q4?iyLɴN #2TgƒUŪSli{3cMK 9 ?*h/ĝ%ZX%>aA v -s[ݬvn3)&Ct3T.w=Ůk}IOzA4HHW_ɯ^H}mrGy}Bnƺ h݁(;_RxJOæO:ӝvK9m_C$MlSt`xTՖld=3(>Q9}ϸ>{ C˛2~-ڢ]{ѝ6 㯶&;|T~´|3.@G&N A Y I ˮpO 1h&žh!BOr)`w~'Q_th6E'~ ] ?PɅ;}̟ Pуnc2(˂ӫg ܲL8 bbcV߾@.-ZW%b\N u_~Ƭ%EXRw}%cW>E(\NjNBk^$De=O/ስ?%p _AK;Z蹂I6?~݈Ґ:/TOǗ|Z)CxKۦ'8"1Zn}@qJ?dX >FKXO"9ZՄg7A1N<0iZiEBxEL@V`5}aSA3Q=TeHΘku?B@kV@}m +4gph P{2V*VJ_6N@71f^qA& ! XœTph2$5rae79™>D\S$$:ĉY ESI4ljVVS A_ZLԴsZ񴻿'.coҠؓ#h HDkԼ|wz5 =Cxg(}]j&af2#Ï"epAç?iS{XCo{y ? ]12X$hR|3]KњiuGU/漷4%]Lnk׎ʩWMkԺ9CA xT>. z՚\ $xf(WV:eQ w'eu.0O0eCW|XL-EqfCGWƕVR!2~n{<um:IpZϞGq9@B*-]i5ˠ} >,tdf8 ).[OtrՒ-2]n&{.@F5i@߄5z|8p9$-9JLuHA3Ux:hI{mb$7͈eIڟd*1y40JR`(V,ٗ$MOn:QdU˦:@F)кoxI'T\Lx1i=^ aMYsڀ4¾ߚd6Mm O>C!0ȊF\j]R zP@^S+@?/ZBDu@fR/s@ߨcHdPH+pV%ŲYx} 1hdFQmofz^jxV;pppV[ =_b }$J`l,<5 pO0~y12c |rv13r ͙ ῼaqv`% Vi{&^ԥrmZA+"Hw/~v 0$/ 7Zwl6W):mK"㵻50 TC&- XtL:WħڃigW=JlTE!٠iG!-s+\'"ċ>6uݬFbx$9GjM ;2B *)O;slԘS2}j ]mS BaSLrhIJ. /cf{Hz1w<0cm纸 ~N`yEqdMeSIdyw;OzWOeݶtڵ~}ٖ$"gi |:]J$f1hf8.2fg.cF5hb d)@(5.B-ޝ])_̅YD\A=b(JZ? }Zk];sp.MPE! ٕmw^vd f24c؆l`ŭU0'iD_5njFXdB,cE6$'"@h#VjT%bD03>!g%AE866"~IIEm7/9]>A+0)`Gl^g<+QM2ɷcrcZ6]y4aa/MfIXS:n6@ RE8H/rzzoک^ |Y͑Au$+b ͎9)Do]@xi'54\=26~:,W۽Fv+懃T(^ߦLڗlJ"Foَш۔&=yQ3OSee\~_cg3g ꯫Ӧ\KϳF BCھ`:4cc0hdRV{ 򦓐[c|Z=C8$|JYa2(Ot%0M%'KvN6F,KIn b(y6GŻPj @hD)PDil{Nk_䓟$K*Hѫ/%;^GD n& f"߿_ߏS qRD(!xjK6  BZ[ †']̇NWF+6RpMx{ V;C揝@vQْFdFHUGWu4Vq֍I[9rӖ=D;Gi'yT-"7`cYЀΎEmont1;NGYdTV_fR87ZP<2Rs3A7>gAяmL}-j(92xߵ!+U}^At,vF)Vכx7_') PP$|yr~ir_Fav BUXRSƷZd4MEHBB>WXlOEpŵQiB=&Pp=ᮆھӛ~ mƣ:}vi)Z:W\ttne^`tw2Ԇl-&tL`vlo&x bc'`Jȷi2J>Uv쎘;v!g"T9aFC46 :8բ&~!^P-"T YkKDX=DקC%첯[^˄/q ?=lH ha Pl*{WkI[/9S#gM\6" >\CD?f4\ؿ/ğI[ U"$bzX~ \;!ITq."EiW@h$MZK4t7@,bY4475yshא#SWYQat8,rV-LEB'[`K'貕"J+UpJ`TEb9SH+ ]J42)Y>})KCvy]jID!,$dOgzF( j>Xa]cQ[0,a4,`F#a^Wؒ699a"#d5T~FNrj_YM #$&#T-uFZxwVH08 l, |\ۂ5}ij\! T<L5g_Pp"̢q3G,W#RZ ݟ,9@#q8aQy-jXxfrkIE=w"=J#NN ÌQ>k%AeJZ&7Ӭ9f"8L7~s!z5wuSha栎&L4 XS]u1NLY4|$݋.5#?ȰrexVԋ'zA bHmMv6BO9B_[$|ʪ3UTUӡ/:Sd.'D=:hn(@&h&5gSӖVN[޽?r3-]Z%|\*2*]Ĥ{Dhk[ʹBm%1h.SA-`naX}֢۾:AW[;*P̭(ARG6 >ָ%8fJ* N>J ~(ߐ$i|<'t3iMA3ɻCvcVSk1Q`pPG/?@' :ӘCpsZ>YSI&Gkﲏ*=WxՑX*q&2u~Ǒd !s*x Hx ]wߕ$cl%ţOZXw[z,TzE_5\jBHspLwNS#ьSymNu|r+Pa-^dDPoUgrɕIS)AFobg?mGҵmV;\2' |E( ;p7<'2o:P,*id Fc0bKD{ hVoPљ>L0jH -#G|njKdҸHvP,zc5~a\~=g3"E]&"'R,&I1YbF'&rfkuͣ|([WہY`iȲV(V;BAWV(}A@D|`fN,iGԒ[_EX磷v:%J!fJ77O7 5QbV~MBCЉq>lK>[95H# l]z|!cl$537 %X)Rm\@B4@Gc^vN7MU#W#)&W麛n,Î8X]Z0YfѯX $ZuyFRT}`q ` jk%V %kUx\Hz2m'QJSϪ2#!M`E|.`4Z(J/?(񆬛̔ܘ՛VEXCDn@yy徻;2̓>unuƃ{YsŰx5I\u Y%뿹 cC6>QDw*J%f`K'ZX^?nNZ4[\/]C/h `p~% 8-L ?S.)9U8)ߴ>Zh|ڸsro|,~(#*+3"@H 62R1оBMܣHbT/]qٯHk 6͋G3QUo8K)MӒvB!ϩ EMȊC#3f+I^~Sr}1vc pOJf| X>k` zDȑ^ԏ<3:jzx!L]OcU_u?#gg?*~$mk?-_8c|i'qjC,i,^Q/'Ѻ^ L+7*f_>0j`8`U P@.BVS˛92-͌T-a3)GK坪W25N7}O ߄w;sXX)C53~">WeEHO@dH݆$ԪVۻ"1:V5xϪ+j ;OG.1XBMOAʏW3+[")kB:DQ)]L둤 L %eZw[OlSIPFܦqP ~8&7u46LјfSaH'r7&IgQ:@رZ 3Zݭi e]997ɷ#Q4"l4(ȍA +|iC4T-oK@uvE`+޿<ޅWqNn]Aova蘐ў eXо.8).S5u~HRs̫[[Uxْy楛,ۣ\l,"\&#vA?Yǜg[mʅTH1VʫBGch\Y s+5%5j^T]foNʨqoX{FߛG wܿF?90!`4bCaϒnjߨc۞p\K+4T˥U2P_:-F/7<͡9rTmgIն.]"?A>6+ &?@'RZX4k3- oe b^8YQ1glaw6~k>ocf?zAo2Ë:D'KEЙCG=뾪Ե'`U&c&sz^@r#5p$z.,hc@_!ܪh U~{J@%ap8%Npt)@8m(![^^  7",딣(-tWCv*⭷(s +jq<;OHh-,#x$lfC束=ö稶}΁0b"@O|)Z?5ћ{nM+ 5/|!3ipOTKG:v+:u(a_O:5F^KٿeۙXDn'|~ f^Dcj>t$t>(wb̷ǘ6yp}ǁTŻ\^.ӍOJr?0);D\PkE6eBu%x/oRYC3^ q+[iF#=Dض8A1x#:ꑾl5 pܗ@ϰv\kC+S?7"و'fXq):ڈl´UQyX#j/}0~WʄDp xa<3H6ˍ -9mO}WJwQ 4|43)z{-^(î)[u>@4 aq9 6+}i,6O: rm{;V;9ɾ_]1Z>e}G<\1wrۢ 1Zv/8]4rwCLt܈D^{%m"4*GH~EiN~ Cw3s&37*| /Z啕?ߛ2XyllH9w)bnEX8r{KUE,e2@K^G뻖mLxhqGU{wWHfnkHhЖ*MLpa"qicsϟWTᮘS#9ze:v }llEkhZf$#l$Ju5)4 Xhr=L&suf>>h#ja!,5\JT%Z@* 7sGƲO{EX2q NI%Y~7<:\i(m{ظ$DΪx*kDL(UXŇ/ !-{և\$:5ƀ0 ،6+VtiCٮM^Nq~ù_d<t%[P%]8>/a .f,:;TDUqh&/DOTLݘ?]בrqMlTY ӗd4S]x'ߤ!x,o7=a//|V 켔&+KR?2*,kx/9 y*} Jl \6łұJ?[x0r⌰W~%!!Uqit֠g#o%-حԚA52ml*슿-@=zqⳟ`)+8ž^%Q19PY'T.IyzY M {ߤJL~6TW6|<~sZA>3V(+>AV('ۻ8y zۑ:! >"z~L}J%^LF!feq1 WTVȵr1T F|EG4?]gjveLD6Eu1%gU)|zo LG IS  <;VRp>f#qIj.[ utBU!r<&E% `+/=mLdžtJ w.ӱ`uw{t˶Ғ.fnUy5T*XK#o:afܽ_~4^=~.8MI[0كj'I5ŀ)P xO 致/ar430/ʡEv7zu^j9VD? w^Mo7옴% j/#4Jt]P#Qh8ŽJ#:y\\ǻI{%JI@R#h2LHNJ[RNe?_$!MsװV"o( $Z5 i3R)Q\ WotmyGQ6<k[xg}nby'@@$>i2>dڴ#Nͅ9:īe^ˁe/vToS uxm5Pؘq ۋop#"4? $le0:FxL*MA{jrmYyl#]΃m@TbH !A (aK9,ÆLݨTxK;0UqcV $;7*4+qZ:6zFQ1IO~08AQ] Bc&U(C?[ϱHĩ#D o1JlKW<=&Iך:)^@[-P8IvW*S1$q ֈG-ys_t]W=HЅG $ c~v LZ mj`8n Xy(" cmileQ)ΎӺi`5&qN5ȁGڲvVFx~ *(s?Tu,LK"HKIe|_Fﱺc-sYA ]E>á?ܣlʀ I卖gD3- 2k͗"]K'N!Pf0QS*5˴zwOpO&΄x j>*f?Ƒz]7(`B PihkJ\ b |X5n}t+>R,k H[;].4=8Cj|U P|nREN{Fi4 V& Am^/Z0' < 9?_{ ִKzel5$cahZUIב1 }'`=x̟xd퉖|"i$t{#"ƑY0spk3u[.ǚq6x\Y"aI-;rsikиDpN*͜ qq4[^N|-hs,Ʃ ~`zs=VOVNRq?GCSYwMC(n@%՝TʦJSONVy1KAƔR~`aUrɤޭ֋ZG:`R{ Hviz>We;Q\o/ǑLH')]:'uLZ-1]io̺μyI 2 motU+(,/89\s@}9dZ[=naPf ox͐AAt1R1!4NorW~!uA܏g8)-G={yZnkaGl4,㞪 aa朁vނq@JK;a|x8r(?;=ZK39`2!jOg˪'¡.։)KKՃN& fg{.i~>IʴG ut 4&t ܜLv?c5 %W1v? rHhv17Ri|@Y#~vz! e[ 5l#%Z/`n u#xIWPEnD|'1ypx7$.|A"=–Ab[kZ_jažmtlo^z6N*PąmI(c%0^s/G0$@Yٹݗ|~ &y_DqD܆%_AZFnvEEE#{rEف;^?1^0cH =b:F?&/Ok%ԥ3H=pY!e͏E `0ʪ8@yȩyjg3vq1"di37-x٪nS41zQNެJnoUpty?] x^{g3 rP96\ uqIII4d "9kU园gr A)4Ceh -{DŽq+/]yLHS0PΥ<\:xfN[Θ ҅ʣs(lw8A .ZYc9|*E4᥹Q&gkAf)6l3#b#owݐzErteF2 92ɡYR8tG?<vMs,RE>>r3j'hO`C4$u&TD+\..?U#+ޫ[.M6vy8_4%1>r[>y3*H`DjOL9;h;*bv3QQPKzq.J+]EG:}Ǖg'ӶkPz(\*Tg3>^#`)kf(M"sWGh ͕3 _(W\|dvCSh@uY/Us@jI!'Ŭ!eb?~"(mu_tnC]}g& , q͢teLxL8LŔ9f5U0EM_ur\|o)O"_^sVZ"k>Y"Pݏڡ@fx e.?}_*V8V XKى'իjz2(HyQӉ-[6%,&Fn*>Ai|đ0Uetg|O"TI\ow[^$2OUH4Kӛ"@ cr3J*Hdr'b&X ⷏ֳG )4HQ~`ŊI:+Ұ)Id?b*V0OTc^ 8&]+#MO=Ԭf[P1&Hh/3Z{}E8{7gP t ZlEGj%3,S K B YnDx糝bCXNqs& =?VJB`c9`wY;!w%C.UIv;j_cz >s^VNb),Yá_mdz3IL"ckba{ƹ3nа _ 99A*aBYI!wqx3Jj Ԧ~-)i6#$m(շm@>1 $eYjt|GO݌s Wz\A7zʼnuش=t_1öiMwO_R1XV*\(ubG 2^8-9|m+)U*7Sj('"سޫa]=΍84ÛD&%$)7 b=4Z d_ 6q7ZJ_ƈMQ'i~Zi}oe1E*3ֹV-79U`Hj9hA*9 j Uqm>ZՏj*rrҷRFjl}tՃ+"Pt3Y9/D'VU9bahK7Q*A<"3vPɋ^{.~;e l"|oXyDn΅25F)ӈӰ*[iYA#bۖ:"{Jgul߾ A,GD亨MLY;5f+=& q]׽[L(LVh)0jKfTf&eۿ.`=}NITm<f OJ#4~}ove5CkN|]b~89t)5qc7,^4Vtn*}Tw0]ꜝܚ%qAA4mJ3qF-Y 9IJ`l ok/8${^}ʓG*13p,&x'ޭ洯-}Ev}cAM@z, _sVxZ&<+d 6 !g/v%Cvt"] &Qj5 AV6T4-ΏJ;&3FR})PUvWk';?G W0* =5$ן|;qV`C\Ud3Sg|=_ux> e !~fԌ2{{IxC R$Nag)Bu9^Fd,~>l\Ӟ\lR,~:%{c ^)^J :Piz(*=S煴t;&d)KiM2uȗ2¯9"5P@?Ͷ YZ