libsss_nss_idmap-devel-1.11.2-68.el7_0.6> H HtxHFT[ ?*}}"14R-M.Pڄ ?|+뻫I 17bc49811edf5c54803c4ac9f5c5df9630087d7fǸ YFbgOU ǹFT[ ?*}}f곴G<5d Ux 9TU=F,>9\?Ld  + Ipt  -- - x- ,-  -  ----l(89:GG4-H-Iޜ-XY\-]߸-^rbdeflt-u-vdw-x-y<HClibsss_nss_idmap-devel1.11.268.el7_0.6Library for SID based lookupsUtility library for SID based lookupsT[V sl7-kojislave01.fnal.govScientific LinuxScientific LinuxLGPLv3+Scientific LinuxDevelopment/Librarieshttp://fedorahosted.org/sssd/linuxx86_64  ]. VhUVV:Vlb{$UMAA큤T[UT[UT[UT[VT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[Uee2e3302fbe2347bbf238ee1f0e030bb96c7e365cafba16635cf314d4212592d4e049e8ef665be6b5411ef573d2bafe1c5c9c2088f99b9c1aebf1975f201554d9e7ed0ef70f99bb7f763a48ddd95d5990e103bb145eedfd0a76d19c122374be2782b30d237bdbeddfde4aed01f007264cc116b2d4be2f398a7cb74ec7a5bc58bc98c02adc57337f58c40aae15bbac05a3ccb364e5adb1d610a16452e92f17830cadf118767b2867f0753f884dc9842e871187216e9f37b437d8449c6fbf1fe4acf26f9984427129dbf136ad68404abe3c52decd0ef41954601cd3be921d84c0540ce7ac7fc936ccfb68e16b43bd5c481d37de1c330b4608d0777f76e3e4cbb066fe0931ab7d1dbf653c841b6623ba29424a594a0399eb1da83895f569d6291216973a2aae66bbb99f2b57f2ef160182825fa5305444511ca1eca4e1b0b38528bba0983534deeb671b855f484d2736a7841a689645afd0908618d5fe81b8e09c89a556815830dff0f70856f6aa8a473310a8283a20c0b0d3b7c82da1052c7821fc747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f840b2b0c6ed8dba0d3db0971f00f72afeb5c98dc7c677a98f91fd632c422b29f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa1a6ca13a1c87edcfbfc91317896452c31a9d49c4768f1b4b46ac32e0907e00a73680166339ff62595dd2d2eed3a79fb9fa0c2e8250e89539f6d678aa2e5e51e26c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8f5cd4cb41607a30d7820cc20ea76b4a3b8f57d3d2b7d102b58c8e13ad95e83aa178feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d78feabe3c5c148145751813bd515c36ae5a63e1453778550ea17a16116afe64d3260ddaa44856ba63d14621f2436ed9d3cd432214c751968a95fbfc0ba3e8995c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fdf6fd4e35ce1205eb3af2dafa276c6ba2b8c5279299bc2e8130c43946e8b686ffb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e19fb1bd95d3ab84076623479182c8493531bb685720e25eb15d3f40bef58482e191c555557ca84ba3598f52c281780dd7e22655db21ac383712e62d4540a1bc525c747f2fd9b8f530474462a6bd9221bc4800b145b441e3720ad0ba1817740db8fafa5366248e6a0af368dcbb0d295edd55318438fa41a7b5d2a8268c48f3b5a9641be88ac0efcea8e7c62a8d2b1662b2245ebd49abf250cfab234b2a94786562b4bdc6a72666e1b300fdfc5ecf102714c9fd57df76fdf47139f8dbf8ae59863646a30bdd21a49026b2a0f553e7944593d3cf015fdda29c71bb495e68c77e88ec1b7711604d6cdeaf3cdfd661fa21fc5bf18de929671c801f00415eaecd35abda3a04665e9dd0ef5ef2c6ddf02b4a12472984485adb027fd12ae6c60ffd203b1a4e7730f1afd382186213e2b97cfdaab825ae8749a1443a9bb59e1f4124913b09d39bcba0c183ec442cc90fe27a2dbafd4e1c791aff374b5326ba16880a16d98269abb731904dd1f8eb00aaea66bfef72d5252931d84cc01cfabde3bea854b5b145ddd37bdced843340e0679b6b4e7ed2fe318fd0cef76d160543722e0c3eac11f901ae15db25905dca7a17b81c6d51869fd12ea569fc4b072d217786b4b4d73bde4b9bd9425bc87b33d6b1911e6398673939aa2f15ac505b9a1ab029b8452dd0869f392daa28adc942272615ff2db16bcf084f01ec9fcc2f7f6a632b2bba8c4689a8f6c574cb1bbf474ff6bc90f795cc992d56ba4c2340bb4ef235e09853c94b4libsss_nss_idmap.so.0.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.6.src.rpmlibsss_nss_idmap-devellibsss_nss_idmap-devel(x86-64)pkgconfig(sss_nss_idmap)@@    /usr/bin/pkg-configlibsss_nss_idmaplibsss_nss_idmap.so.0()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.11.2-68.el7_0.63.0.4-14.6.0-14.0-15.2-14.11.1T=@S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.6Jakub Hrozek - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1152200 - Error processing universal groups with cross-domain membership in SSSD server mode- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-1.11.2-68.el7_0.61.11.2-68.el7_0.61.11.2sss_nss_idmap.hlibsss_nss_idmap.sosss_nss_idmap.pclibsss_nss_idmap-devel-1.11.2htmlbc_s.pngbdwn.pngclosed.pngdir_06ca70fac75c5328a11c0a0527cc874b.htmldir_298e78ea0a17452921a007d47610eb05.htmldir_fc2053b33a81c70c42c8deb3585b95a2.htmldoxygen.cssdoxygen.pngdynsections.jsfiles.htmlftv2blank.pngftv2cl.pngftv2doc.pngftv2folderclosed.pngftv2folderopen.pngftv2lastnode.pngftv2link.pngftv2mlastnode.pngftv2mnode.pngftv2mo.pngftv2node.pngftv2ns.pngftv2plastnode.pngftv2pnode.pngftv2splitbar.pngftv2vertline.pngindex.htmljquery.jsnav_f.pngnav_g.pngnav_h.pngopen.pngsss__nss__idmap_8h_source.htmlsync_off.pngsync_on.pngtab_a.pngtab_b.pngtab_h.pngtab_s.pngtabs.css/usr/include//usr/lib64//usr/lib64/pkgconfig//usr/share/doc//usr/share/doc/libsss_nss_idmap-devel-1.11.2//usr/share/doc/libsss_nss_idmap-devel-1.11.2/html/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu    C source, ASCII textpkgconfig filedirectoryPNG image data, 8 x 30, 8-bit/color RGBA, non-interlacedPNG image data, 7 x 8, 8-bit/color RGBA, non-interlacedPNG image data, 9 x 9, 8-bit/color RGBA, non-interlacedHTML document, ASCII textHTML document, ASCII text, with very long linesassembler source, ASCII textPNG image data, 104 x 31, 8-bit/color RGBA, non-interlacedASCII textPNG image data, 16 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 24 x 22, 8-bit/color RGBA, non-interlacedPNG image data, 6 x 1024, 8-bit/color RGB, non-interlacedASCII text, with very long linesPNG image data, 1 x 56, 8-bit/color RGB, non-interlacedPNG image data, 1 x 6, 8-bit/color RGB, non-interlacedPNG image data, 1 x 12, 8-bit/color RGB, non-interlacedPNG image data, 24 x 24, 8-bit/color RGBA, non-interlacedPNG image data, 1 x 36, 8-bit/color RGB, non-interlacedRPR?p7zXZ !#,+a] b2u Q{J*#Ѹr;M7%rS=ԵcaZ< \h^F)U.u `z!R'E@Zg᤼Zfwhaeke GE&AEljY*(y|F#8CC‚!mOљ~ԙNDL]B3174X;CfSd"Tv/O/=U,Qa1b&Ntզe YXCd>a$FtJ|`L:TTi${Z \q' ]}u;g.#jhֱEA5:ju-jRRUP!'ܲuOsf]%Zůu@[&,L$!A$ܭ @@XAR]UiDzFWs4kO 5ZX\;ksE %2uv"^Ir)beP3<&X- ~|λݵQqUFo"XFzߦZ|魊 a3A[i"~'O8Dg| 20IB* ]B%_ H ŝbt6:fd\n^5 (Qg/2\fJ nc&w$ن ݲ$v Hʰf1-$'n| N{ l "Tx*;?۳‡} ;Ay vY+4󚇼3Z %j]͆6o$5?ۏSc?`U#4B}Djgqp>ҒLw8HޫbSޫb5'yH[,aNF@*'>Fpyzߖ~^yXc..~VTL/ޭ+ґ +c.2GݲG`LЍk4d j@⧍5OA|A~LWbGpVG㹔 on,+ՓxqoY73m8"R4FY^F`Q=#Wm|"a?>7{e$T*N/3z *gD8Ġ73{/eZn+~CȵK +'t%\Tq?GH7mHRZߑqb].+6 &) >aa\l^$ЃY1畾zt/^X|W҇qsFGm.ծ1MAL-Ud;B;3=d!Ta]uBAh^cdgtVs1 Pڼ,2{ӯxTZA]ʸ_ŧ( ]W0yɅ {l ˞$Ѷ;MsUYhLp]`Ū7, `@M*2Rqd2[XbIH/[`>.\*Ŷ ۮY5cr( 4.|N𢻪{gb~6}d+BO.f>5+ qN u_/HAKJs5Rqx0E$OTӜ `F2]9ŵrQ|go=;F8Q4x<#u`T9ǩCxRGɹ>]9fWb-CMeMޚ Gڄt3$П֛aTHC-EX'( LBBƙ6vmR_<_KO6=(m6GTnȹu$!W\?%`eX$95iS+:f,y^zVwwПcEK"G Z~5JuHZWIqh kn鿕2@,10MWTm? 1W9/eD7`#K(lXϮT >ɯ5iq$u5 V|+Ciំ?(S>o1o!u' [Bψ\˞ancÍy8`WTᾙaoys1 d7i~wݨ@=Y 5>C7!ߺ "eY;rȀ7iR q&: }lB *x!oofC=;(-qN8{mғVo5`zT-ٲP'?tIץ:4;.e1[ (Ъ#댰l!c)aq֡:V‹}^$)Td'hʈSi4-ǎ__V$y5܊Ά2DtcOjE NbK:fV%t>~ l.#h{o^%OdA[=KoT*UcYu]:u HؽdƵ:32,}ק~wQ|FMru4l$No6J/58i?c*%~Tft0-Uwnݸ=S?K8T[ykv3%4?O@ _?^gyx0/u|I, 9.a{Ŏl+mhHt"\Vgjrx( `|A5dހhÒ@Hڙx3qVL-:n p>AOCcID5*W14۠vh6L%] 78 /ӣ0he#)/P;i-*lS?M M.k1*|7XCGjA&f-^00Wp8 V>ήsVO3#fW]J'<&B;'ܒ9Rt ~>4TzJ6p eIε2ATb|B8=&C=gLϽyua _t1Gh|gҵz7C'/ ;/e) :ý~2K=.3"MҞeq3/h8KJw \4 ݹⰕw7I^0zb)72'CŹ= \,͆ڔ{b~X IAA+cZ82ƕ H<0WWlEtr)eK^8GOzY{.6ǥsu6BzV*[xζik;慤W,~c_Oڛ7 VE azPU*SJR?l5F29]QqU>s$Q2Mv(b_H`=+r::YrjZ]RF &%jc%{OUl1)VtU {jc"/4 _#Sd 8-sI\?dȵ<4 FL˰9*`J[RB~ApC+ǛC!%л|L+SM,CkVsCNY4c[lN1"5EX+ wf *M+CL`%uP,N`k[0mZ@_-T~@3K5e8 m.⊵@!cXѧ-a< Ѡo/Z6 f=>HfU{Gw^7 +fsqnwIGj'^Y6EZ^ rOLїWX&bu]0[ӽV6U !aIzq-5K|4)>&Ń4ا")|wQGhkvKr6y]@1sf^ bwE+gQȡdJ# a/ ]c̆V}Tkl{&ơ9eR8zvF^eJgZ2Y}* .pE2fKuCu$AUTw&+v bhnwغNVqTiE<T|= .AG'D?;*}v9ceo4ؿ8B)`qg`b+ 7#?Os_,4hJ1>j /4媥a͋Cؔ=²as$%׻U|JQfe@sɹ5ߤj zjg n2K x;urX󿸇qUe]jnc#n^q9[ j~X hz9Ic`I G N; js.̖FęQ7y#k9dip4&v24^N@'y@KQ"zcpoG_},ɴjf k:H)nPJ|߬n+. ۃ){ؒThG;̛cVf0[Qc$w dX>c9wl0)x!\QODd--g in\j75S^S]^WȓACPQ b!dwr'xo@_GO&N\QuH}^hH~o@ݯg8Yܜp% LBЇ >U!' w1%"7d#iex %^ow/ƭU8Vv2ix kch'dmwZS n5;2߮`4#ݏ{m[ m;*Q :oW3N-(2z >BPl"ۂ`I. 7&v<=[pw ^ I~y(m%ٜ@B)N'ֽEԁ oCUW^RK"WSlRzX=rj-EJҬ:*3Fk||ID-qC wX.5W.e(ijN.2es"㐭WX7HGǐ/hjbq:X"qшpPOAY &j^!ػ ]I7ޓXB,*#q<ؕBӆi1Xkes]c1Tԅ.kW:k".@֟z%Rb֥LzR/V «(l[EDm5]94 Mo!3G95'$ƾi9n+ifV`6;G%Ca5;S h~ p_ 4G7Lt5 ]|}ԃ;^/Ɲz`G(/ S_÷$k1|̓ gl¥,~ǮZ$>r1^,Zt TK۵uQ&\%63,g FWHX#rpW)8D֓\$QYdt!7 2)8>C*+}u <ɨ)YA-3IZ"#EZ,XQݬo:3sRwR6)v@Nd^yraU]ۗ` kXuL, T(t:~hQ6n"U=#MDͫ.@v9+b;TO$ xDs"ZI R6x_WXqy12+`Ջ,hZ5N%¡ed>pYJFD͖g+fJ<+vN[]*˕7)]P5K7]&ViNQ;1'Rg@J+j[n*kȻ66DUP25\tOoh9^;p@,JgIգ*Y1/Ox/&1֐U]_ DX_w-o3X=mAO`29Sڊrɑ19|].rf)n,s%aD̙2;L7{ZmN#Z5xc(X6Xe8EHSGc~-ru-e~3kd1=bhۊH$L oHI=1qXg%C壢")ިۊ SQ-4tg`|ƻV o{K*ްCpWKdǛgo e}GѩW)IXDi[ؖ+YbҿUME׼K܂ku4EApd_}^8. #PDr<ќ/IavLŜHF_ )A(lnVMrfpNg@`D S5v$)`5e)EWV$!t}G2~`^xJ;r4]Fe [î{`F6q]-69SGG젅{}t=,-\C 8+W_"$ayхƹ 9E\_w9ŸuO0CQL>ĨsqIpuʩӾ8l(I_RfCoթ$lHD?W g[jO9ڎlnH9GԔtL%+G8p?o]H ncgӢ֙B䕡*:oSЊXRojdAJHQlE7Aѷt@]VH_H(;fMPǮՑ.M2tgS4&V;WCj2X7:"IҬY .CsMǢr-uuH-~bX~DQap}i>?8(,LkU֡oSk{ -T ~cc,5qZBKq] ) *DJKib)+ S""sTs.fsjqeO""MǻPO~ؓ5p\}~Д9 Xs9҂<|}PBSmxbŠ =`KޖfmUB%'[5;(լǕƹ =J4#WwqsO3Xuv}9xM%g'b;N(‰tve QEL%&K,&.ᄗacIȸDn`z9upo`o\`6 rz_YGD.["H/Cvc5i0\Aە:~J8Fd\̵DRoQNq:Maa!0liJôQ ՞O3PjC{r,H2ϣ7d)hs/YG['X [;>:;(2iP&}1d@O_.;䧰;H5oNA_{/ 4' c ;LE*/9+`bLY3g^b:uN8it FЂk%n*43dpSt%FSzY&D1jfbl]* P[xkяB⮑"xW,kȩT͎剐x=%t8!?`1|d?(% "8vp%g2[qTpuP%M=1v/NAk7tlcS74L<ř'F'}B2󫈄 Nx2zb؂Fpt$< - u_(3КxC?|OT3muhܬQ5ŅlK{CpwT77< x"l4'YJ{Zu @-D?ιܹAٔ҄8b^LD/L| zyK-xfH<9Ļ+>E+2 H`^˽ua!tPe<2{D Vpm_ <&Ak "3:S(dj~"JfYl"m|UKEώJ˰BN,$6PTg0!P wPѷU5O:V {<\4tf1R:*@n#zaCy qS|H{ 2SwZjSFɼ;,_$8kM?)4cysD$/7-elv=wҳ4ЭĖ9o:<{TLƏGo̧V>èdudc(^DŽ#!m%"\3G, :0MԾ#(_ Vf zK]w7~:ƟW">Ӆ7''B *43(-*Il{bXX9@CyhЛOVonv [?d ۍI#- `ɂZY5UVj!Z CҘk0hPqi@ N3722l(Hvt<9zГ֭:cT~WLNNbsݒODOelo`Mapz==G{eO5.qG ?ڍŒjlCve)zªe\#[֫nEy R <~ّO~8B*Zx2 8NKк!ω鍉Y>9&dsr@ʚӗɷF9θ`sQ߭uVgD葹Q.l92'JsL\u ,3 Ea!v>D2Ԗ[; Gxh#ckDZ:`\;[*@Vw&\K:UoO:EUJ\q1~P5ߐVʌy_,Q $_EPB]) X >=<⾭Ŋ [CBe)O7wł>\Cv7xK<ѩBN?fT.{^D ̮ K4@I@Yote4W"[A;. $R 4h+; {ZUe{JѺN&CWӈœǩ#siuDcyJ/&`۸/ҦCPtQ_[r^z&q?#p~FSLdr|up9E[uIObkR wB{]b Ekԙnι3^p-i(f8[rv]:i3O&եcJiџq%dDy&_q;HT VE_c1nWagȃcuP.:/-Y |x~N2豱x`yh-ÂnT|LY+~ss2ma@sQsn2vk:g%!fZM۹[J9&0bԔ>J:v湱h9A>neuݙ8GtLjC<Ԝes=$DS^F+'a1̔:,u]nPʑ_Rjvpfu6$fI@"OERvGGJqАqRt`a={t !C]'4 (b2J89XN+o_q%X,SwrOi'%x|1p*8t[#C oe*#| ς|*uC֩GKz]9}#PnvϏIib^Ɠr . 0XVNE}-}Al̷ah  04l[H튩tלppL>|`r ٔ`l~;B7Sqigr#Cg{bU6&XIwTTDR )jhv?2\P1l^mkEZ./6t@<9>{:Jp]O˃ 練ڧR1b-yQ;eL% /I"J>=h*7%Bʥ@spNȪ#=` #u]z~.*O0W9 o#L<蜥n9h{L/Ё6ъ\pbD;4> ڧZլ.EfP*;`1(yeY8m]vB;Ê\fj͟$IE{.+RC28As;JR,UOYI´X\ Zo=U78:E2 AvKVf?]Ln)iw-{;eZ) c3C-Ki!L)uWDNulȣsҴ)Y7Ruc7VhC+ ,~o@w9(Ӥ!>¶b#V{ČY.)! N?2z03UQhJ-c7$૗_S3h-LM MzLo{fdƵqhvTi”XnyXVhEt4=#ذeqL{NrۯMcu+cHW4 H4N0.:Cь =$CQʣWZƤ`# Ci%KhSB\:{'w^aPR1Sd$rYeDh0v㢀@"Թa۾ ſuIBl(; 3&A{`3F\'Vܡ!`jciǠ%A-zw|%0ءkL,YOҙhWv\a lhsef(B=Dwj$+bNҲN^PfJu$VzJY j V,.0.Ir?O`vFtrRx=ۉzzYZ>bl`Z8s"„nHD"3(J6=.?=]~w֦ː꬞h(~D7ׇ4\ZR5|bf/L `àu1cI!I"s끓al=PDl:o\冩5/Uu[8Ld7^1j!6M3FoP bSaN+E7A#)|{BludaH+|aayVmAL"0)`{⥆đljQ`uϵte' 6|[%S nS /]g|K>;>`wPQXJ#Ǿ̴[ӗgMGc l6zZRZS^<k8S>4lGAccI=uJG.E7%DCzޢ TY@{<#ڒ3e报ӎmG5|,0>܉Oܥ@E_ MjR>*qhҕd i^ iUVe{Ϝ`#yR/>!%G?63))9 B vhobFaְD}5!5`1oۮT&zQθWgY^Sw߂c_T#Hr.HgP>K_vMj_ zsH8 ۠-f e%YWdU:-q58Xy CD@*Hߙe(Q͡DѨL1kD&i[qA`Ӯ߮~<\>rX})%/;]KII\Ԣy* hcfN( ,1 5;ϷR>\ܞ1.3[bq%_:_[lY-rfHi.WKQUV/O\Fb JӳqVS]Gk+ KaP2;B $rO2L%U6VȐąA%h 3OzfPZTJCi<ޮIɨ!(yJ)JFŘ <˅Bi-ک:M{uwawg 4rrh75,`yO5kV 4 p|_7lK1PO5-8 yCR =F<5 {"cdDIE'хnl[P]0eLb,{;6КVpoݓzuܩ r(N,LUe -ogqjm,}z g8֙o1+H̚]h4loG:%p)| o1\?G[e6- _/Q u8F 1#ސ&RLMgf2g~nv*QP!pν~3p+S]PRDkcpUyqcpspiz4$s8$sk*\}$ٻ& وueͅ)@oLlzPcF3sG8z'1e_xۣQa.(?÷c=uzxJF:JّO#AN+bp6 lt1&0Иxk[xYPeWDD]LMkϿIqclH^äW'b;s|ce.xn{ğXZH4 Fے_IR*i;9&f Щx5`i;+3MO T?k47B/mQ}&r|lSr?||[[3Gm ejfL^Aؚ߲4pƣu}'(I[Tși3a!0YᆳO;YPe4&'=uPoU,%NU^Dl4҅ܘHaΛRI@O(Rʶhv#3Xr),#\6=1b jGljXAd1MGVivnّΔW#IׇPVJ2WajH_cRKU Om.fm3|hAixzo?qk1-#A]U'5w2ӗv^&(LڱRY@W/aKQ. ZPͺ G4O|o!`Ί/I>󜆒˝NPD:<_{5a_lzWz-GhDy@ss?:Mi#r?9c@(?b kٔ73^-,"&ٿE:‚ ~E:-yh( L~%!_v&Q5gA' HΈD4<jӽo6"B-EtZh)v2+ldgggC3$ywDao ZxO __'wƒDO]ȝ+ dؙs˨G %"b.+No,|$8+S>'Hk~r)B$'9/xUQf@/t:O~F2ŒHw|nĵKt6%?K(^^ ^r?%a[?s@' *lPcd6ukb$ %1{i^RT#`\&VIX6902I!㪊jU(afV3&M]yjc5 -.h1€YGV`ΜЖ2̃sf,vVA4)eTAG_&+os˻kȭg߉ŞC-jo%'ޟTYAh@|YP}`ZpGaմw" 'nY?6dqKmC4@ di^>ky);U؄ݷp$Y&'DŊCpqCӕӘƫ6+u*AC߇_иXՠ"(na~UJ!xϙq UOΊ az"S^{U= íoRm6$(RŬ&uc.i` 50'+V>uXM??;ìIO^Υ2J@p&x(QTj|Uùwuo&kBM*8h4w| 0(LyfUy\S^OW ߩ4kc9_7>r~4fFe%pwݹ~g exW׵ڶv7'/A?! o?ܔV˳5EAw5_;Vn"CaQŌ tQ69(~ߊ9~dPmDN HHcXZ)~h}7u}g4VXCD&W-rO^E Hˇ&L#ؾ7m 3ݏ5ۆ?8C:!Y5pf|,:k.bէ]>DY&:{E)0 X圖@j8p%wv,++Vܘ-6Ah ǎ:380F%,2Koc%0˹qeÖzz3MGR2ʂ2Ɓ;8{j$I*a \q7=|M<>@qf_><,N!n,ByA%'\۶oPw4NX?n}-1,2"cސᯙtxzvfK-fAi4@>ݯI֞_!M',K-u諞q2d܍W*K7>(3.m!X'tz_Dk[w.V)%lwtHW:g/˃)_2$Nn)K)Yv|"67Z L^USK|RLuL 4,z1drIr};D4ث\­AWw ~1>'m;ݖ%uR/WTp<̻|Gk'%fFi1|Y{~7k6VV$?R9TU]TYULTTI) -E[0Ʉzit4 `EͿ/xɃf^χ>Z+#`=*gK,XjW7UVN OF2ijyΞsK) ZNk_T?W\b=Zܡh ]XP&[MѳvpterqE*&֍@3+jPB:#k@H~ ͿL^J4( 8e%& ݱlR\W9/ӛ _dz%>+lĤ]IZI.ƪj_ 7gU4TC!L-A/9?{.W;ˊ[h NMٛz{H]tQ.CH0zhIܷY(﯄n [rUi9huىx6/NaDzɞ#l-M`7^7uL`E#ع[hMАm'Z,m"UtC(#{VQ+D;E]sEPA6uUNL#rYa`h3]؟rR5 sxi46x}D낓OZw@"8gdBAu,WeB(Fu؟%cK& teچUoCSWd ~q)8SWcr9R:"b[ca"<8f5Zʗ3`4e-Uk 2ϼJX1|=zڴon-M, uվ ¾HFLO+:J3.[̿}-|'䚜zpyp} Bn;"/ٻXOx㴝0y'de)K.C-t˙7ā `SRXPt>/t4zS 9[1O@hۼ7Qkۂ*-ʎ6 -layi @,qEi|##29;"ɐQ.R*E 5blҒaFܠ5ω^鹳pK _}βbّ魤?S9`1X _3BGKG=wƈv]x4z 8pp? nOz @v%$ [i0B41P/f{>[\XL&}=soE 9]㈵@yc^TlDx7>; /vÙ_&*$uO ļ9ulQJLO35|| ) X k:ɄK"f2rZL6~F\:{%7".hGڂHN.MbRUZ{Mъ2|w*cl)RVw8sM wI$ͼRծA8/;I?_O%`j?PnDb3uUPI닠6* /Xwbgp$ܒn˕CN 9_,6r-<#a9RW#nss5HҨD_H0Wv$E֭Xѝxv[Hsj_ ;9دH~ 2?=oB3NL6qRB$ڥOC޹?P?S4*}8l>ά'aȧr8/<,s61sd"2+ջҝQ$ha:zi2O{;bI>`uq>b_- $|ȥ2jCPMf]Xǧ)YK'LO0ۧ$9.Eɒ9xV7N!/k8ƃHVr&ZC#;SM7Cd/3B{dɴb;\߁gmo#g7sAC*}nNT@DUJ=2N)ԲF2i`e<P^dxj{2S.fE*q 9薄zuqvFy,?!ۿgybKJyn@?\:>r-gUBԔ" czQgKp|(K<ףAv.]H~aкαADF2ږ9)T5|Q6v!aTb{t::Pm~ɇp3BeTEA2_e ޽P0=;z= }{0c9Z/J16H<9w0Rӑ,hA::\)b'9б3x4хR,} !K2kxZnVƇ9:j NzG7DnUd(է-2Ⱥ޿e ,Gބ9&ZJ{S خL o{&g p_B.QH4CW+ kKn̓Ǚ0[^'mJth 9ܠ[FTWv9=gX,A!Ii!:o_ϕ%#4rv~I,m D.y"yH^~;=(^ħ4B'#&zx~m46:&]R@k;oVIwt[AQ/?#EZU'Mp:txV~x H9*H1JX3oT\roC=@S.[]F#glAݰՒ6mp4rPL ]'T|rY@?O-3L ltuh~=|Ƭٹɧ]nd\ \DlULrō%c`^hݽ!cIϹa:QL&Nnv)mYS94HdӼ$kn0F~!bFjOYR0nt"H+B%@6vy*|­2Ջ]#5R%f&sgM0עp ;G(rEj# vuicr,/4 -LV#Y{Bg: ³cd6mW  tJ`O'=gZKl{ Ǧ/pRi ZA[ ,)'yԘ2 r]LHO.Ca6*׳q $1m .aPPq{-^rȱMV'q @~4e }Pv"|2C;9&HPCTޗ;W9Nߔv7ہrD^ >]#H7iqi6&S2ŨyHzApR#Q zWwDQ(;;&Vx*;/áz@kxlc ÏT&(+ozn)-*yaǐ3rW7+3̖3E37AtNbwRH(\`UtK1~4*17`euRrV12̝<M펨Ikc#ԳB>78MnԩO W*݌iZvˋkߕ>hP1msK_uՃEXl;2 ]Ў~(n/hεli~gSN&^R3TP٨`)U5%Q^cLOMf~wcyc׋mەq<,ȴ9cdrj"tft=,>>VBx$dD]ԜAB?LeUokl*7*;YP"¢6ر=Sm%!(FV$fUrMz(̧{KīHU &>Dߴrbr*[HUvIԨDX#利Ip]kB3rxu|hE#ᗺϗcQW܋8ttlOM:E~W PtOC~M,6# Rij˪^$!ʠL؇"&Y#BٰgLs R=(n=);i(Ԯ+> lmΆO(Fh'$4׭uUy`9F]x919oS(UKFg+]CA) o#I]Ap)XT3qF+۱K)@|u9dIxIO4\#<ܛ4Æ8an 7<g^fBX&Oi}saL%ZdX~*\\)Mif 2 iÈ"w1]V~sնjh+]o)fǭÎt{}4%rK Fe{ ql>I2>Q56+!ܙgtKu6;!k%/b}r`)ΦbPfCs]:st 㑣qg/$QmiD97s5|db1JOE*41$L qؤ>ݹÚ ,*2UD;j>6R/ 㐴oQģb+O7!+(kѺ'|kW]uyCuT!J}†3B}c7,h:qwM>ƑP,sp z{a?yY_׈xdi+skPS7L[/Lq* Ry+i^r21Ifi\yF>=upƺp MA2\a{ lV6rjm`\ t)Jj8d݀/jKC)p4A9><8AA<3edP+E/{U&-x̺J5ʷ:Ԡ;}wR"$IݐLڣow\d+E| y?{>f =lS r;7|8lNGKx+Y ]T Q[B?gppz.SڂUxj`Q 4ۨlϢGeU1"WaA.ކ $pӆuĥO|jn" RFk4U@~Q*'f18ZAy͙B \c^ջ)v*3вf*uw}]-0>zg;MpX9oe%vM3y]m[n3eq[掙dY4T$Wwwŗ'(f#\c|[S5g5eWlQ_]c#-.@ܕp+z:fVs$jrIYRN /1#1t1J5̨lJ"Ļ%?h9S;X$|N~-m4u;l:7߷S56]m='8LZv$(xR ǂ:rZ8$ΑhM}`J")uL/ml.+I)vG@R/>qwӿ4 f b*B(b1dBtx, Y K+νwd&x(Uk`d1֎M&NXt ֠_t8W7y&R='G;4x?O&NN=&$R\<.K =n.8^bQ!Q=́' &ȓr9KCljjLE[{-] aw7SK1=? dXd*o۴]-?"$=Z?VUpVcAUCD9&JdkH`Y^IqbP#̺`i]wFF E$U,Q^)zSiaIEΤ!Fn_>b4ubŸRN|+~Mk lRJٵcU/dٗĸx6"ބBrTzY ]Қ侓cAng٤'a27Z_N}HH@b 2 xlcZԏ bMet{ǩÓV$Z:ux!UzK\dkЋC6+1B'3G0Ն>̹Tqǎ\RܲLo+ԃo>'O nѧ~yzӬA/a KDPh\P#'iS Gߐ6 e w&yJH7Xu;٦*S;a!ZςUbp%ROM)_$+ ą!P2`:ZW,~jtauA]i9eE,@k3-~àq1NpJaq&.:[=ݮ)1y7|0pNJdCi9mtxEM eĂ~/ǭ!V{B8״ZKk?o5\MZMVZ~=癚OMCNUKxy̡V=B+$.JA@$+Y"ŗŠs?P\ =cPm@ E$CdYbLIzlr#'0O@~:|'_E[}^;\tNu5\&xF7|35!&{%'_)$kjQ&C_2qټopG"D"W4I!m럁eD_B_8'b|]=s+%tѱB`p(&,/2{sтU4yBZ߭iR828^LCퟹwE"Ex iP7Ӌyf$Z]^{܍?RD{H;@tr{$߭}\}sG=8ڕǿ}RCb{9-Z(yc] t y1>5$x'i/hi {8Fe|""*ҜCТYkJB•|*x$<8"rlEzuC9NsQg"OT{V NDvPU@= ^9V,zO9hV M[u?ǐz:HIl1.j- Y2kn;܄gh?^trUO4VW(HԚnÁ ˩]%$g#4UH m-Z!bh qb`Ao)xXdQqT.;H ҽYf#?lhb'. %,[ eM%19)RqW$Ӿ;qйUQƭ=8gX۟}IYXjg{Ȏwfp#d۫P?YՈ\'_9$&Nl͜NbQKOpIB9H6D]a n;@9\!VCE2VQE2[Vm|[0z Bzd84bY5jkamnf'5Vje .R9HY=N'kYJE~>nvdE= Mr b18Nc]ꅑQǞa;k]ba)SY(+r 0ew_\N*ben"3Y.pSe0, /ek4Ѧ\|^DE F"#hوd\ m5ڷ Yn,`iHQ{}luH"V\\g~g`c鍙] 6ҍ@cm6τB!gjo2( q3~bEm^#=؆= h^VdR_&ar[ΊJ*5 =&'8UrE%9KT}|0/_a;WT[|jBF$kxF|2 _K9{yd(䖲MJpqGxL^ X`5J-4j̰>mɛ 0(A mQ7E;^Wv!]e}[?FMBF[6#2q 0O7v z+_wq,}T ={h 0kFV4VJ7&N dM̶3,(t7D73|=5",_P UyBl^@6b5y=|tW$>J7}ٮA:U{/@Լ~H#M N]]8Ȉɵk{i0*Mӑx> Sd6ߴtX{fu_9"o,XYMDJ5r@c]e2yZ{C n*ːe X2/Qa:f2B_ŨotSm 2_L@Ih&dE{!N:Q lϗwu;Qwhϊ󞲛h ;otkGċh*H$њY :ʒhbÆqB d9o೶52hv-/D^s\R :#Z=QBQ^ =ܿؠң"ڣm}hh_/$#rVD4#5~~} څM1>r7B#ە<УI;w13h:B)ŁSuD$%7؍:߾/GrGϱw.f Wذ{r3[ Q[ŝ]Xj)°ח9g=O@ da;vr.{r29bP$GU)E*>Zi˰de ^͇diMqUI?+p[(7$[KR:ؒmuU}v&jȬg#| ~YSs7|* $8  s9&a*O 6pUCyڮoMAߟWJU MvJk60{r$w?AHI% =? @:Q6L1#&Xm %(3Bz6^ ^)eYsu[„up\9lOdH=ߑ`Wv" ~X:C15icp%Q3[7&d`O2pħ߆"pA^duQ, *(JD>j톩,!`ٮ pq BE.PXtRsWs K̘nF>ѡzuGc.& C%Z&+H IQ6y")]Z~gШ6n x{$Қ"˵&-^oWa߻~S>k;4q{&{]86gįoV_qPN-,|ֵ'b  rqΈ +(*?Ta";pQ2a#΢u W hzqS$~ZkhBo:9]߱|Ë7:g_*}0 hNKาB ÑȖB{z#̱7TB̈YX>4Fb`QM*:+䪽H)k>ˬp<$t 1ko%dMw+Q0oųәج%O&֬!>9BgrQ!qy,ي.dZE4uިR7ev]45o5YVvÛI-5z9 овA hh{BJJcWu,8| Ɨ!:!x//O8^ ȿwWd{#"oI]'WyT|,HJFK=Ӈ8v9ҞZ~fQ<1Robs a:{WoWxڮm{_Fgt$L_/hI9;"=U}oF1xBG_KVΚ[s %&1+zy\ݩ194 50Mr,_i3Poض;v8"M?|e<{-(8mq+3HÈiK_KWb[c!2o=r+6X8R@ZW0m$e.#gIz!.\J Oڿ|]gkv/f`&Z)4$inw: ቯD>uRގl̆ _2;{IM,?cSa -:5ܓqE!A!@/5IC6w'ъLSE;7&q|5K!P(=IRάC}g&~8˧@N7 cPpP?K'#_<ywߊ5==&"`nsZy]^>}M 7a&[:~/C6}Lhn$7rʞ*ɈD1R 7Ro<l%z;bQ^f6l-1ǵldNYC[x gPl"Y42T0 XJ:] Q,b_\"/]!+'˫1^+=8wiƓsr( 6!mwI? $"G L;)qmeYgb#qcɎQ*J[voΩcxHg͢YXz9CǍ=Բk2DҫbK3-:좍RA!ϝ)8ٵIX 9>\,] z;Qq)Řk#İ$Hn<`եj,7R7 BR)df^>X;WvqAuս/z]E‡Kf`@A>!dmve sd>ȏ1MרhoW#q`Av`C6Ԅ7E+ ZiDsXfo9H3?)k>opb]n{}pթ[嬤CaSf _ «}%oJfj ì>YͿE6q/ݮՁUVo)N'*WO]CM $ ㈙N%wd_Z<i WW| #|6xs\IEA&LIKQJ pN3`ݘHؙ &' ҠM3':jg^oG?SyycA%)3FŊ{?* [JQd)VzlITwB`/TEm$'h*<>,g`#3[;<`^G^zx3[$v 0mf@3ݟ;4`I0s1D2;s]U۔}FøuOS (kq} ㅢ&-(I`ҽS^̧@=f2m|xu˱q֫cHU(tq'q w.^h}vOC8FOz=l~d@kke cL$6/FbAånRJv]²5H+FmHdV/" '7$NuCm˿Qbΰ2ie߾ "] XtvF)$c(ӷ:HJNYm<'fe 'G$ &Z~H(4p%{8Y`L¡ "Yd(DEqA3U#,h e E5m,B%jSPSSWSAE/^͞'/l*&·ٱ[;Q-39xjoXz$cVJquƺUwQ$rsQz%. (Tn 4zz'G[}J6GOy|/𪕯0BaF j,0\eH4Be# [G>zR-J[jtUǍ(0SP uXKhi\!lrֶi`~jEr}Hɿj5]wW+BWVs 菧q֊8;Mjt}fY]C-BNx1XAe":DO,;8O|cHESoxk _ðG\'pє x;nզvfgTo!(yB<QAO/x_nyԒ嶚f(JԈg2- yDJcipdZb e+0T_ I&FHh~R}mCJ`Zߴm#g !}|)\]G)`2vƔ 5NM-Oaa({pd Ϳ>ݰ]]%RP1W Xp,_7I6.,\*FzVW[ Sں~yd;tnP?O*U/tl[xryؘv0yxބs@ܷs Z Ν)Ix[䂕{ Cq^SחJ,4RO:MǬ.N?29ɋzva!#l᫈'맢ĉhT +#u;80P+:j@+L[zԇkn l;M@I| QQ(-TGpؑM̈~ {OWmDt+ilD)IB|<Ўb $FEoqd dU=q<;DV&%7e)eM/]Ǿʻ@#hxXiKݚa6-8=:9"*:O$_xVS\B/eHdQp0Ԉ g:zy dLA.hzz 噡|Ӷd\A>)Xf_ڍ7'ؐF`aӮC'{mf͍eۃX |3 Vz/|J/Y$KkatٰQ1J~3 H 0ay!e!z[iɈS[n#܀ 33ĻI7l-H@& 'T!PX 66ox~ ^ gէ_"=Ĥ,-HT Nۈӗ~(,/~ĉ^(k(P f=tn|Q!ᇻVEbP62W3+fz~60m{AN hx#|i]}024ˡ`]@6 *V4E1cXf762戉Q<,G*= S#x+Y2  mQ@OYzy*Ts;V,k|:g\)SÏiV45dX£W8fXp''CӔHOoa^Vî ]ޭLeOq9.A2o7ciP,9ih騟dz/i s>HQA[I>f@M; 3f ?5UBWzx`͵#:$H4Dz~(k n^y! gu6.6tU N^]-wN_nTziےjL5}uqf9KwOVy+ӹ1!9t_+E FIW̡<m~Ӹ4x_![LIf t;[KQYHgj1}_-!/9 +MaxnJ.ԃq lĕ 0g6–;Үٱ>"Li_1.rrznޓ U?䂨i<$Ul|F9Rj({Za4kӲ:M _<ǂ&8SaX:FN@έ(aαJy=DT3I~㔈M3!Bّ f+tm]7`LuY40,DÆIFag͆&ycf&9ɉu ;JIY@Q0>F<.9挽h=e})1ӠJu_fu"JG;QJ .:1xv IR0ţM@( /KҍSйtɶ_st@Ӄy4%['ZFq~wYX+PgDoG!* t~`d6y Qx_bhWH*G)!wDBE+3 XM\ў)͠W VG?׆\H B] ^_VuIp迃F Nnmêժzt<,q^m%*H, lRBG'~}-(F:N`aZ&Y?0N]|LCq萱,^3>輬߶ KwG*) 038g/iJj821) Xt:C]D Mt./hٖH9e .?@_wN$P~.8ty;1P_Oshtnʗ[`WlP sƖoАT2T~EԌ^WV yJ5wl[ڐ }MLXePw_VZ>?HoGC~vNHd|]px8-=hԺNC;j g ^? uv>Nh}n Jj|gS1Lo .dkzkE$a:PuRk[ e0+&~\qJ*"sI:F ӭ@kôL@"_)n:bC>9ԛ.q3ue 'U{DAF\Ztz*XDJ"FPs,U:Ҭ.{u[m@_}&QP6R_ zݝBKtj'}?jIB`LrAPH66?J:V6Ky%ʹ[eI f))F]!7I͹RL錑x|ɺWZ7ͳ? Ƽ D*I`vGk^/;(=ெb9z6'{tbZ)5A+1Y_GL=zmAew Xw4'"Sw1Ѯ 3Z,)/ A޴HWBM n@ntgП|dKԢ>)=נHڎ@pf$Gpkt|ȑ=δk}\Xc tyB)FϿ)> SSz˨N@u释&|a xia_J{h#TŖ*#PUߩ{k1J7&ЭM,c[=K#fǠ<&ߐ|]SV8#%c%TO\LS:-dl"hQ}*HOa FԸR#gɼ4na3n!(8:).^NP"sשUy$\ePӁ)87 ѿ=_Y `J ;2o5)Pq;%;@]N䨴]0P\LG pۍop9J][3 G5?~)#3J"Bql9X)}raɩ2ċD[5WBiX?Qwd$ ,i-~[zmanT| -x;hn17 ~moLB˳oDg:|r:uP(`cT6oeܡs]&\jYF7&9~E=ɦXKQrԎ0b/͘r$:΁$BkidxĀzMP?sѸ܇@x@ L qV@ ]J$A A]NSt:(SsKIB(= 1o`wZ+ d*3OM b@n)3q{άv:PWQ1Jiy.a6rT!)鿍.g;ﻻkҘM6Llt-_j)xhk-l L#u0֢#|' T?oV<Ei{5uX%{M8A7tJ="](A?reC˴Q$#AugU8[UVIǿ[<b8P"S*Va7@2!%GB]IطtwE Kb--ȄsaSNX`UHԎBSwu-R"G :r12l 5ie*Jr5ƣDbˋx+Gp3QSd=o\*8tGd/dcS#efFKX̚JўLe(%R/@=D<>rpxa} )zS^:SMŒؙ^~;~iǧe}%v-"ٞZn0 #d,d6>-R:a_4Wy(9B|@UjݶX{̻X\rx!$v#fNh0}đb2A> *r mb;_Naq)|[4EsMj#7><ֽ 4|4ҴOD]*F۷лK{^ܣX$nmZgAtٲ` rb:45C TZ*CqÊmdP0u'Ƌ0Y˱.b?ʍV!TM{pI$9\EKX矊f+9g}嗅#]IӏK5#FǦM9ŦgGTYRKRPkv7ޑ.=S~[F]VlnQ5MVIzD5wάt7J%G=N-BK-۸hNn8!T>QXflp؅x!IR( {+Z*lb2`;D0zxN _7`DŽB{ 3aKڔoc_sIcO[Eӥ*T7j7*z.R'W~L j LcꈽᱹF)^FQeԍ_цkm6cHs\Q)|7K}{sֳz7ԠSꄖuE fX@>h W0"O }(ɀȟ:y)zCus(촧Pj:~=΁ & ȓd3c{YMnb0k͔wr-*ȟ[&3>+0 {RN ;!-AoU kO%^{WfavrJwoΥMSITn`=2lO[\z,\VV]`:rm8h?%$HezqNrLkkMYcnP-<@; h ,]mٝmK9C)Y \ިqyc@ ݹ tC%Y3t%yynآƧpfcwH+ãqZw2Qi !Whj$Ca_kt/pKw-VDyAnnߠ3a()H;ZC D'Q;'u\PhNB^7 gힽs9#h7 n,z/ J?m'V)jEJޡn$U M`A 6j̓Ag~svO hTtю+=ףuLoy7J $#뽿v!"ѲtX %\Qe#8̚KS׽O$c`sgHC_GR"~hx$U(8n+l$ĝgfoZ]F"' :QjL!q+C}vp0bޱIW-#?Z S27S(chm^X† &8xIDm%6><σ\P)WHxLԘYC9 b2cǰX\t֧3DhT͍p+6!?`7#iPpFidJ|NvLV36Y1PD'?B匘"ƓY"BֿMR$ u@RG ѝo0Ͱ=&LsM,sW)Vc;fwtQ _jwBVoV'0?I~ ѯ%V/*~#- Ug(vV\C6X?\J.傘mM^5Fvȟr8U)RY&9^GSpIOdfP@&y8W棥x<].URD?=WF1GXΌAա/H._Ѵ8L>(Fc"\.!yu+@+NpD\k:V^{n} ~ s̼gX3.X"^kz@gZlS gl >hj┐r(J ^H6Y+INj"t80;bW#3MM~CaAp^ewm;;|24(fI<zf*h2nһaDT(#?&T=ƚ:vR g'DIDvDSC}pj!' {GF,.U_IFIb'8Wn2yAS^;ؼ2E3@cMR}59tm;t DO'!q!t6EBoHX5)v(L(8SSWHLtA%7y]d^z5hl\_oi?)j Jpj}Ib@^W[3Qpҕ3]VI[s߁W\a3qM첬*:fH{"K0! Y{«x]GW$Fdv+jsJwͤΦ֐a̐)L/|\]ˊUy9DpPA]InLQv{"Rݯ 6 鈀7{]lKʼTipؤ[ѓP!S ?}qEaߍrLxfC% NK [-lVί"IFs⧹bo;5CH(֧]_ynʰwZ* }~i{, 5NFfYPvLۋE/nqV9w+Ӊ\9>mL)8Fhhۆ,_!X-%gt8'eK_:w~F듶Ҏ8ny`ʥۜF,7@qȟohVn7vۢNHMx3{,o)xQ2 :Y+׮O)^9#Җ#'hV[!.Cʔ B1fBw9eѼehnSfwTy} Fmm)49;E*4cy''V8ޒQ LC! /iH$_9Ϛz=Uɧ&z7?s`kBT \&1taeҿTe ]bGRతD Vd자0 %hOBGzO.B?*Nk(6]6KlkB +Nr ,V[7FZjKz|J ^NUP$_Ԫ Nn6"_-/˔dd 'qUYd8,f&چ%y /j2{$$2څuNpK*]Rw#A:}f:XWP?'^@: ^՟eCg['̹88t+αV:c:7jRN|^qDKH--L^X2Q̴)80![ˈ]#i/rh:URA:٠>Q}D+ǏhKӻ/5w%=΁[ ]C;y1>fZR'{aj=\/32^2dc4&z֬ gp\%7&x3`3xy B5:,JvMy;eZS&PFpRwi"iDJ-I63H cշC65W8y/@ vڦv 3RqX3,آHV?bn2`iD@'wl=Ha*P9Kx6N0 WMlijBM1p*5)/RM4_s. јXe>>AKZ;5ٳ!1ԑ`Fx(j[7Rԗ$Pd58&uՕy!"5H2Xn(mDLӪ'ٯ'EL=4; 8cZs٭kioM~U5 j)oeYa|t' K|ʑ\W̔dKg]=wIa+l҂h|oD7Zop**ӫ@?"BA,M>4`=*틣zj.cys$,-+ج{G^{@Pȇ<$yCVihdYlXzC;Q .Wk/X%Z[ lo Ȣ1OWys"0~=D.[HohC=x5/~B6Yh@fp2{Zٚ\ꖫPonKuPjU-8YF)7rQ1wDV'_\l@:SZ0\7_(S<1Eÿա[L"Ioqq(X1^1BgZ Ih_7{‚`r c> QHZ"!Xte늚kVKJ~J3MiR6W XGeE?_Y/>m3%)}B"؅@(g)p6݈b4"zĶ5ؤXŰZU2y&RRpEKǮYc-^a1`QݝmZ/Kd'LW?JXeVԼ>| V<TsMKf7ei."j<aT[ \]Ck ]2DVTwGl]leٯ DS|lg%'= hHW-2d='5r,2+70)VF'XVpxۂf5>lEka9?n-Q=&`"V9y3 nCP1"bb** f$C_Qy%54:tDaR1b0<9JBGVfFN"Y-6?ê܏X˙Km3FZIcEV%2M]-.'$Ѽ-/H>{S~D)sj5`!׎ƛ W) ӬD͔COFJ911&UE*6r.'" 2rYQ*Z:b1\8/VtqIgg1fIMq&HI曀O<@E>Ppv/L%Lfyڧ)g<<6^F@}L[LxȒќp 6wDRw`q>[2c5pgm'.XZ*.: ʺm8 +fΤņ0KO=:[awJ:,y0[>iD5)am\ոTL袤V=bf\q/sc0ٰHX,b[U 1'\aE5n?:8>IMRAE .gC86sG }`KJ[ߪ/$ސqrV?V;5:n&`D'1`Q[{=De&m|R-+-Q3/OUY$_]f=MQ5nJ6NQa-Q `3?NZY %8y͠f|7h|s[޲![ˡT gϳ 8bWG;,H` D/ $`bBײWo/7R-Iyų3iˌ0M MfIx_rlqEuTHiT"MG`XBPc6kZ{mݽg'T*f {eP~Ҩ'lT7¯=,BU4F{܎XGPaU$B:PY׈/HҒ9:4IPnx\VkP֎#IgS.jpq/Sģ17Bn*6$v\rI@نqY&MF7NMX}|?KM < pWIe1wxJ6DŋVA0[pH+┶'6N2dYHouZs>SPwjN;|mD 45ًUn=Ltăv5=4WyMtWD 1 Ǝb)KQ &`ЖLvYnɲ A!y#`|&((?̞Th0!uS>W)hpp"J&z7Q hdsˍSl6e V5<;JcߝMR)T =VMc$z Z}o ڹYk^",iWg!h]2qk1^Ytq̶&*ϗi.sTU]'}v$ZLFzh "qۙ:L^ h2M_J^i&7nEw&!FUd9n&iսپ+u T{ha2!%\\գ(PH2VB}ry)cF@АImCɜ5.V5;K}KBO$H. E% , dO@+hΑZ>9ۜVC=-Wl U?9)#$Cqxct'ÎcRHjy׎.=1:ӑa_(^~'V,`[`bqH/tU_fS&an)5&Rܩ>k_+ƚ S.Hj_x.hܰ'HX6 &bY}5#&D]3#B`&NK $+2tNrŒ*Uf;o!fXǺݒP~`QĶ;.0 b 3wӴeW3e" Q'߬#}~K+o7EÒ-CF!1|l4u `Znʑ9{g![E\jD!ȜEZzqjyAfdr<c?׾ 甒DK,AKAB{~ՂH"9FjEʬt^(22fcÞIHIH~N_Ly<)XmFѸСզ$Dس8u|r)YՑIZ,۞xASSor]:N9I{yHo_{ULnl,.؂3XEb=+,I=<"6ੑ$8'Kg6l 5i1&bh kcG,Mzyy[5x^ z=a/# .m5kv;P'jېtiٹj /Bܵ@WҕOEZ8" "DhkYM$/e3$c+w(sjrmOTQ:j{CnW,a10,i[La⳵O8ږĝdvjz;зhn s= jc$̉F1M ͆Wyي{%>WSwqUk\]J.Wq*5n KYUhM;t3C|<r#U-ezDo}D>ﲡ)?"BR9;Ƿm0$K X-*-*LXIC[n iڷ6!LE{Ok8~o:!@UV ~a\YX $OI*+|>%L+eRKpҜZjM\:Q X_#6AZ|۪0FEْCf|$ؚ:0!Dō+yYwaeE:e㽔13?I~a'pI'2h T#xtsylT<ſsp$pPFEB`;u@Z42_S(-g0Cx[@k03PͧHF:/s g4b9elԀJk.gd ա,+폢C:^LJR߇'3r(t 9'7O!̺(qWEb#1̣d+(IڒtL:W( :C NЌBM灭/?%z#-Vvr}N׷/(WW ricmv'ѻ}z} ɼ?pR3M޴|/0Z A: m2PMD$˻ 7X@/Vz'feCJAGRc᭠VDEiEP}VnE˗k +Rq/[EE=Fӫ$ n~ !thYXfڛ.!Tr%ePc^ϳhMi\ѷ~|3;!(x8mCv4d{|@8(2prӛp\/JN>VVukl--a_u#ZWذnnt_?DO6_"w+ׁ`6F9;UA#$w2k7zk)^ ȹ~7`tJ%zGwIDZÿL/ ((U)F>9OnQ4GrXޞAJb=o }TOy x v{˪IܦK60RY/<\ymVǤm( n-Ѣ/[e㣿 qF7n~x?+Y89W}!E`k}9/*}P2\# n^/9u[J(!9X @煙O5Pɮh·