sssd-client-1.11.2-68.el7_0.6> H HtxHFT[ ?*}}s< 3iգu72Y8lO\yVx[OM+W ce02a0667af72639ffcb8f8831679da0ee9328434m-0 وFT[ ?*}}¥40w'pw@h*;U/eNxОٶrF>;?d  F 17@    j |x< `( 8 9:@m>@$G4H|IXY\ ]h^ bdکeڮfڱlڳtuv\ wވxy0Csssd-client1.11.268.el7_0.6SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.T[V sl7-kojislave01.fnal.govScientific LinuxScientific LinuxLGPLv3+Scientific LinuxApplications/Systemhttp://fedorahosted.org/sssd/linuxx86_64OP<)KD>l A큤T[UT[UT[UT[UT[VRqRqT[UT[UT[UT[UT[UT[UT[UT[UT[UT[UT[Uc01278f41fc63cf2bf43659cd484ab39f0eacc55fada96b5482e320d04c25ddcd3784702deca11405126e97cacfddf0cc7094f9f6e379090181e77ec87c5b61edcc8a91724c96ee34dc1955a14ae1c9aab393e5a426f9e424015c968685b4cae7ed75ac995f0c7b758b68dc8e33bfe8f65fcb9dd56f36107a62ddb495f3491cd8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc58980c186cb1159b92ef171dc21fe305fe9e798e73634405b9fd8b3e7940e05864a0b6a3517ce379b4f16c81b9922e16f27a0768e3120f064e4ebca34ea7fa56ed4f2fc4176450e7b91b14d2ff33626738a5ce0f9c43b68a956cf04150b96dac5dfb5985fa1533086059ea400b8ce258be6e241ad044c5ed47707b2d5abf96403812cd402da53145857e938a67822a52fc0dbf7292b75ab289c76e0c577cfd9c181928e5f61073c5855a5f4957228db5d2d2d9a279030217600ca6550ce5000b90a3a38133c024713784083ab9854f6f2b0755209df930e85c810868b749132536be5d411091b14a619edb8ad1891b1e20be35ac5f58b4ccfffd164ce7ab2c87898c84bb3ab26e1c161ec469b16fe0b0a294d1da5fb9fa394b802cee75f2210f7385df12167aef0c911273506310b30d4ddd51966953b8fc501fc2ec26dfb6d87a4bcd95a6ba487c11f95bd02a0576b33c06f5964b0796110f20ebda06757e6b78rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.6.src.rpmlibnss_sss.so.2()(64bit)libnss_sss.so.2(EXPORTED)(64bit)sssd-clientsssd-client(x86-64)@@@@@@@@@@@@@@@@@@   @ /sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libdl.so.2()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam.so.0(LIBPAM_EXTENSION_1.0)(64bit)libpam.so.0(LIBPAM_MODUTIL_1.0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.11.1T=@S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.6Jakub Hrozek - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1152200 - Error processing universal groups with cross-domain membership in SSSD server mode- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/sbin/ldconfig/sbin/ldconfig caesesfrfrjajaukuk1.11.2-68.el7_0.61.11.2-68.el7_0.6 sssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2pam_sss.sosssd-client-1.11.2COPYINGCOPYING.LESSERpam_sss.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gz/usr/lib64/krb5/plugins/authdata//usr/lib64/krb5/plugins/libkrb5//usr/lib64//usr/lib64/security//usr/share/doc//usr/share/doc/sssd-client-1.11.2//usr/share/man/ca/man8//usr/share/man/es/man8//usr/share/man/fr/man8//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0x1a91f6589d535e756b2b9b9f9f3902fa47b291e1, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0xa1752c73d747e17511d266b74b968a05afe1523a, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0xf21fe78f725c95d30441832ecbe2243ab82a619f, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0xe9ed02eeec22e622e62e1fe49925bb1a18e2e7a8, strippeddirectoryPascal source, ASCII textASCII texttroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text (gzip compressed data, from Unix, max compression) " RRRRRR RRR R RRRR R RRR RRPPRRRR R R RRRR RRRRRRRRR RRRRR RR?P7zXZ !#,] b2u y-iSqJ&|> TjTs|ܟNu#آ_^I;6m NG9Eӕ钞ղQVNy:btN¼G5[rb1y,e\ λ(4p8*ARܱX ŨH=T{>_2uA틫]?x85/J<,hmE @oiV|cNa`N솏+۱̙5C=YMIevwA;`{ܛ|i|鵪w7ԉR E_[BDs`sOE0i/bBn!c˅wcq)EXF=֨ ڗV#x%D6ekM,s6 4G? D@e_GgA^VF:.rXJNhqnO eL5nP^% 5TBO#XVCJS7:c׿*I~℉WGRVCx_"Mq!pRwhQ{^%E6dWP'̈́B,Q]2 gV8\k).skuŕsl`L|j;DSҟB7.٧ .싍!DBC~ k@ (Ԍg8XC=5F~{ɍ[Ť.B?LfkG5*}O?>*%C)X`lv| ._:x>tȜX9ň Jr7O;Ur nN@#;s/(QtCܿ6uov,@$+r}MH'OVT2*@bv|7Fx>y2'긠wJ>fec||]Yf;]_(]*C{-My`靄OI.!z]9ơbL\/!Z)\KT i!v۾4nCyb&8O3E Y"!$(8rEhImyHe'sꃥm]Sſu8lW>2lm?rcGs9wO*c< ad4Lx̑´ 筆ܝ79<AqL.~dLJ@HL_љ]U?khh_1*"8!pCA|/n1UbK b>1~4/LG2N+0[NpOIcE`›jhQl(1e6qV^k/=WEO5UO(]QK6bwE &b=dL I@]CJa>JM1 8?Aps]BgCh<f3?FdPi&4 q]CVQoH5-Bhײ3,IP(c0YB8\ҙE5 ST+QlM!kN"s?M3ӆYr4R^"Foم8NkF) ~/o ǺSԄƨy%V7`K^zvgy,Ә45H|[KSrUeMϜGd[zS#bѨ;mBb/o1`\g6f3Eybz~=c_R +# YB-;ky4Z [("r""=nR5a)7CwMzw b~Ӳ7N¯ >$\9\3Y!or|!jz)\:80 ۵A{:!Mԑ;a8V8sgPlJK6 Ձ^䪡& Tն&Ve{ 4sz>h0F,fɆ< h57lɔO:uY+ )&R商GUΗ-HF{r7Qpϯfjc m& <咰4^|421ޝ I`ǯX2V43W\\1_)Q$^mԩ?Ugt̥cyi/ii<#גP(~5tU]X8-\赹#!0޵gK nb9]:ʙFk ;#))8ɴV^ӿXёX@7eDeAn!yOnDVFws9WܯXT~Ztf*{4o-6݊.])Ҋ+T Z Gc|B'>иT;ݙoɖ cvxfP0:(F}I2A= ѮT/*l`2^*n<`8*˩K)T:X?Ofc앥u!1l4=}nsCLkOi. Q` F=ck(T.BTO9i_ ~X>tx _9mj?wX8w1m+ʻ#z]uR6Ėw.;mljBIR {IǥT9 d3% t'7P乘;0fx6W2Qr\K/"YE+7!a2߲[}R2UЩ2"7:}i-^j"{~,ҕxl,+cO:O}V f1myB\+[eQ[tJ–RVDnf&W@PxDOaLEO+ s`έo7RSl'\Fyďi>I]EG/53O/-kPFe-̛Ct4́Ka P)\\-H},:: S+ah9ip h9u3o)^r5ݓ0< *F(]rpY-ڈ.?ntل&5c\m(΂n*p6 c[A!e>&iRqƷWO'.bvէ' '@\-Wjqә_r'ٲ82ݿ*V`o@,D'Tw4:pnH%/A$cγdyds CX50ܨ4cΒ1J(2@zqo6uľ"xT7"yZFܵ$&> \M]QSh!uQ"Q5}.9ȴRFKn52/ řJi4ڥwԳo  e ֠W~R˒꾦'3k1PY0ަtT~}zcH-T:T0|vRv`jvBl/ *9FC5isWKsI%ur) 3O+27V]'4ZKf§!A=é6=\ke;#5q^ao;<nlJNn'.U_K3kKJȝ鄞R˱|^=] ;_ڲ.֣/wB>n]ycϱ#)R tAI!M&=ͳէGabcç>,b~,`B`f#6J*o>l+ΟZ& d[P}2gqu(AљXiA<VEElĞm&% N #)/-MU8@k'Ok:G E2Ο2/u&%'4&9 5/8)Rm6\!ϖ?̲~3vJc%Jw;QL"c nZph> vB p_Z_F-Ni5Nw\1d.W&~ U> _͌ M:1~8+qNd/Ŗ|hi7aW}nTR^l?V- /7j֊;a?Ad!Э6Qj7Q$8B+i::O 8{rF`AJ=p} D7 .b魜S}+c6(c"|:I3|[F-$8>iUimFR1<9)K>M2Dq)erQĩ˛M֚R9wWd QI8ن"0UCvӜX xo<3qTQ)6Sn}B}D3:Bq&Q,oBah;Qsyֵ!'ST5` 3^DV-vD84 c>e3DgFdrLSo])Gۻu@tqrWk6F/ڿ˱NV0*{1u:) cﬕbd@PR0_ tun?gq{1c .O1hJw`aì)p=:GwM$I"HOeRex1(nFvUG8\j'M&EXr2VW3)1tM )~6s1̺*!"KMr˥CAG?O "ꪡl?Cy`k'50(s KE E>xﳃ'j3$-\Cm;#׀ tҭ<)3I:[ =z?7Q{ M@\l4^^czR3coJJ5K;1R s{ ,&eug$T3͎ܝ*#FמJT=['i8OFXMXI2CTCÆ(K짴{씋^>$|h{ .QsT5nl:g7 ƅhqۑc~Ӌmvyl28|)*tUIȁk~6NI -,o{VkZkBte@MgoT7gFqMrcnǨ)4u\hDZa/4GHec1y'pץcr`Jj@U5C4Swmҳ0#[;&.@q૚?8`IW4zu[2O] SRIOO弤 2#EϕVzugș =P!QWAX(F3C!19L a;m?G LJI=k[]ŋu?>B `J:MDu}w'<˭w7Ggu,Z9pl >-Wj;eY}j:$cёxf?5V^r11]0sw=W o֗G1$T5wMҤjdRE:5ѭL0^!kv?ޓ!ӹyf3x5e,TA>X]jOFFivV&{޵&lXD)e/hcbisۈzw|FQaM?ߺIC4e;.U:66ѾܷR+E/W[w7bq 779Zu~ l̓,r`X_/xDpG%.-c=(Ì}-H)Zdfwr},V#HY$.)ֿ1"gqp?eIKƜĚůY Q[ՔȆ\o@rdDՐn%~$ݸؼW y4g@35ʁ7ע*BcϺ*jHdWݚkM;W,q6Rn?~6CFg>W$?VJ?`y˩uƢA5HN[d" HRǜ*~x@UPݗ? U^o(` As!\z fP z՜%7Vy00taurSu#sX~LΤv^%WG9_EPi`yɚ]F_oF[ V}s(2U+QٰFנ=r;|$:HR )/;؋wELa!كs %)O\^OH57: wƴ|ϸcM5p[ޡ?E:ڷKLgrvF*H.^n)"ڎfkF !F*A/`v- N4hJqtH@|#̰ 3Rʅ.䐹w{lRP\j?"lh 0F_fÔ"N47rVk16( $ 0@7m8k)^E5j@2ˤ42*'Q׏?oI c?*errmwBZZ wB j&+m]mNS$}" 78Ms5MH`~xF qT/R̛~}욼v2-Ȥ-h#$ rN*by]=i6L7LHLuv!O`x'Sԁ 6NZn4J׀3~p{i2a1휯,nbbg.FmIi_ϳ qzia߁`)o݄\_^Vu}!++^!lLfgO hL60ugZLF:_QWq\TT麁bdL2S=26:\R43c&ol),["#MWW m&|UUu[YT%@9wzQl9 Sȗ%Y?FŘCA7 sw AuU/ۤc"ɛc-3bqk5x )c$F&2,i}q-I`KwH}>/#VЎ-x\ } l(7{~W;9_xLE]r^w]Pex_V_%^ƤcA0C#Z,Dr[P 3e%EKbĹӪsT]gۏ<]PgP0~U4^KFH:9.xT/L 4JiiHXIfbcCe]4rM*|8mK,m7h@:N|/9иLO2jplDr[ i~4Ԫ'w,..}#bL}k^;\2/m (]'ъP@.x#G&u)nc=_ƃg|P葸s,/6zf-ϫߠDNw7ˇx \!I:-^~\f7!JIYEc Ep)IXeť|5zlJF-ta4˸~Z鱍.,& \Qv͔\ZY6|,*M<*2h;Kua'MZp,c.@ E! p'7m++!W#!(1oEͩj=Ww~p䠚puyI}.)?SnBлO-9 ;Εfk>c V nhNAX-e W H@ű Qn󩾸;a FoOGh95 G4;d4נ88fZAe a>Y1hm `k&CפRĎ[/U+/oyiS94K,<ҾLa ∽ogQj03HDY/Z Eьg\.F(&zˉ$ |^NTIy Fx6k#9B834J: /UcD40ԕ}!qٞBVyK-`<"I,=@HB6,g3ݡԴ%r(KF`R>ΪVhAxXe@YҼ 81c̲;2y9m ӦK6@m"o//V.= E6.AFz1j^Έ&z?H57OH'nx{ltF)Nqt~!䥤{#~_p%f&. 7/aC?7Ȣ V胘-{$ q\% C#l v[PCЛJ"B A\GC|@"3Qےw"as}Fpb]S*Zr;8MWYbǾ7WB7o D s.Wr(hjcF1{:y)QKK8q}Z꣧)K|ЦDΧƛc[ } q2?!}8Wnw-| '&Cx1(RQzh n#vXDߗHoCA䱜&’YX,M1b'_RcJ_7S uʼn7~ͮ;5fapP~=\!EoI<>ÛLýY2O^"xlcd}m[x(ņ pspɏ$;⵹u N6F]{5Ɂ]b(f(UZ:KNtã[ܵcX/ԟ>y}ꎉ1*C"^->D<]XN?a&;u̹v; f0@ܦfy(l#;USksp/ӝ=ǥ^Pc`w]s7*0>w֣HT=m?q,) =4]LcAGYJ9D]aH!];eHXdGDXt7ZZ@fMqh<f](^|ҧ- >D!a#*`@`l6# KZa|_gJ+L+7Gk&0ϭ$sh~b"jƒLX&MwS=^E{ZʼnT,<-DqۛDԪbJ`\>N uBNgG0(v+`8@?j9:5P:/ZVK9X:H9eXc%‰X`H*0ɤ<,?/Oj{UNEbU `~4ZS:5{JJ]),(q5GEGi.cV݃_T}\YkumxZW ~_#}qI!l#,TwIoT bչSgZ&(p~$J{0d~3.h } cw|M*d3EG ,[pLU$F6] 93-&L7qɦa'UD8a0s|QOӚR(0/tP'COp5Ц/\oll >z 8ơ3PG)eOʆ0"D+MRtRS.MJA2&OQsHWb+ +EA'i\t?rX'cLNc?]WHcݿ_?X$Kt$6b;ish̩hAՇ -]c6(gq[KGA%^Q}M9} qu ܸclBHeXm΍rs!ֻ䷤)]ϭ;Wd?h5ǦL^B`+_u3 RrZ` 2ȷk\fbtQp=`[`&3Z!Q;h KpealuizcnWFYAZ;)n&v_/LKZ0v\XWɒO>X[#*{* ߜa*bo6E~:0cYw$gHeKo[@8%}E+ƜH="% %SԅS++z1D8`䳥"ro_O}=Ǎ$M֑k5\;33ѐ[+3 {B㍀p,2ݦ7r(*dJ^CAxl\f.78/$v\9jcyS-%j7Z~6;/jeB0${`ĶiQG?wŲ=x(Ye3R[#a[.L I\9snH}/5"yosD+"yh&J&qY6SՁdIR ^#P1,IE>RPu7U a_CÃޓi3y!G44i3z=JVyW ka(-} '\$F8kXfrFd|C݂kF.4KcP(2Ok t{B3b^!&{n]CmU^QDv&a!T_ܜi*Á*D8a>vQC<; PhD3?U sIЎ>W:5G!yl %T|Շ &YiUC kW$RlHs1:1 -]eJ4n+XTe+G +B۞R$m49yl1xHxNxȁVM[KJgsXnθ% dWw~u~ٚQZ#)YD"` >rr `B߯G.u"˫RN^Cqq!k3vgH9 5C > h]}@n%,CO5zGuu$Ov2Y55Hk'#~V;h)Ţ88ir.KyFET Uf;ϕ|; ~ q/x#d[ҫY ՉgG~fH<==sv2 pjVs P>ڇ'&~jք#ܛW)"CzO qBZ @Ϩa9t'F8|u#z(mLsJnM" {[vFE_WM2b2Q%[ I<4ȁbgv:@U!a mJ+\ZXqCsFjU0WN _1wxg:\5ٰ`5[4Y_;/fv)Hyc߈Gլ'%wE=7>8`h^ZDB;$Vr'Gna +sdo)vW؍i1DDF&<~$RԦ*6pq@?>:U3F#〚Ywnd%U$ yYX=*~ivqR_]Vx8#PsMm7tۙXߙT0dve?52D%#jb ⭭'xmvj=b$; wG$i+T=P )=!kt%~Uzk씬:|[LS_%̠0>|e]IIz5Gs\zlbuSa6j2C8UxzlΠ6g@< *84Rw[66]tϷ=A{XSpRdF$y0,=fn0on}lP_=58 ͑Gs*^Hga,BD׫'3.F*[`Q靘 .6ž<i(7m}ZUA5g7fs$u>yv_s|T)t/$G<\L٪ckH }xf~۱ -O$yU!D ,cWnPSN' ۪_y\|Ua[+ ͭx.X~ !?Y;H./$VCE+r94|+@!`1@ZV_zE -.W]rRص'B$cՁY3F9Yy.<9f?3^^j|z< .ʬ+EXZZ'Gg?Cϱl1?j\P Z0_]a">и?8-;*+hT_Rʺ(L9`"CUa8d~~ z&b '0uѯhJϰDSrHJϻG=HՙB Tmxߙ3ckGH:^B"e<=e\w{"\l/FlsD,$6 lWgJ=ozA$'&K~.{Jc!J5h\=XV1*3j8U_|аϻEukW˳=;B>RdAeGo_b"(%0&>b/\>_X#r`2#3Gr?B{˳F0.#]}ҳ2m]R%([΢bLía͍U@1C4D~ xk]g]P.% κbB;Y" 0oseeí1B )asE>pdfY (!#N,&Ss vzq8 ׂ2bWzCVM QbJcd]1fԵ.tg/ŘwڪG`0i*8 *\Ay]`VQkvnK4Wc}p;dˊH@@Z/2drq'++7}o*zZG[aΊ@1{6=@w-V(-y|8*JZcbTh&vydun㤏qo$c<$XUդ2!YTjuP>(O \/}"Y]H(bM7GHKJuR1sԌI9KͺLOM-m  RiT/'PޞѺ{gnt<%)xB&G:4Q=Q_}\**b6BFw!1' SG|I*d~ś?}k8A誆P,J"@,X ?1[˫9_W"1컫MGmBi H8arZJos7JK4h6eiͺ1 {Bq@q41${B4z@OO|k:2[->!<⎿.34%s3P*HWv0R{bP`V 1_3px2 P]+&DzjȆL!A$6V-21VvcH"IZ)0Z=Z,u9A]Тľe[<* }¨i/jQSLtZ;e6a YPC,>idY:FP!\HH<Ț]ʥl;7??ƈ"OI>8^4u+u ?};zɦ~{3sk1c1`9 'N`SR?q4FoA!H3O eGkUX D@qlc3 V0cRVGT1#rђ?KEchL:$Ɂ C9Ii"} j-K[ssq Rݿ:M66yۃgWf.Ah$02P2}dZS-$+C2Zs/0bDV()=d*b?($(TE %}КnW+ 5.^> [B\d3H~ߍ0U^b8`oA8$̧5 ~l qutZmLUj鵋u "*E_ʄ98Kb` {>f9`D~£힕"QFW f=G+el#\~ȦK 6f`y ~`E>\scr^*s}hO_ZR{(9 *oLX={yv4l̑ғ+A2JYd1O$qvչ̀NQ P[@1,fmN VMJa q7rn;<謝ne4_XQ2X5?WLTh'%_Nu@k@ۡz\s`z+?y~eץ̇s ͢)6] pIfXG^Yag7RJIc-\5'8- @C4*v\Ve7/hDGb-%o??JwVpMs9D!6SF-3e軆*k =C1:Wdm,'$t EVh["\@Pgm1~*-!ar@OfdT3P aeÏ !tɤů!lI&Sx5̖'v 6,a,i.&zz%eJ酄_(ml]CP3Oڹ@ZeZ̋欚0Д; }p-[m' 7wμ44VXlr ]i~v&P>No$UΉGX>JXIϤl={|jV)_# mۯ,6aᕟMLd.n""J$[ IԟwR}8Վ=X~#-+L-FUtfS)/-aa`•,ONSCqBG6k?7Tx=}i:4pd-x1;ec|jn^px N:7XEz,n^bK x`! 2|NSI#)CDJ~3 cSd32)ijG,Uo>޼-Ġ+j^5/w#TKYΓp{83'#ïDU[!2+˱ Utй02?~*yАA搪K [ti4zRE&v/K_l7#Lnay)h^ym''=zҊ\G03"I,;Gpr<ẃ~UKzH8{?t+$omD4q-4 @f)`?$ݭ2:d}iڭ T-@ڼrvhyuv q7 JlI-Շt$|~]{1 TQ %4xp펖%<4Q[ *\fCۿ3*>AI8Z|  ۶`2Ǻ3 -5 c!  D/am~xܗzڹ< _BNf!Vdt0{\\D;S,sa4ys2_&%S@髭tR%DH+cߕȝuOTAQHCjTQpt+LALe yvPd%—O41~;HImc"6s9h)51Ɩ 5vZbSLk>*s)BgYUOjV4hN/16nUWGbLZ%n&UP*slMi1z=Dp %9d.=jԇuHHuc l:K^3~l8Z5HE&qu )16l%`Hy՛ 9'ByB+6:ĕQӠs[K -_|" oy7?nʫ00BtLvݻ!*&t!i>3.'6ݧ)kQHߝ բv2J5Y1†3aqoŝsjD#ZI5v':-6S̃]yCbNq!Tܿn1Ҍ\Ѧc n@v+pE~g-.BO*]A~%Դ,Xw aY|&&)Έ^0p7\k*Knћ`Ez L~RWw3tZVʤzus8&N~^ksGE O ቇи'׊ƇaZHJ#R7YMc&].X;"筋ǂLJ#E:wf6/\| gyJO{'YYģ ]¿U)YMW`Yv >096X}<)gaDX9${$c]L~EL ]٨腈LzB[<<ȒnQʆp(J9y»o8UV0tRW=ϱCFQ,7+1䩌){H9zϰ'@x{5!녹4_(&dPQ(a)bx"VAD.=!VEũ4R aCz/~l™Yg]_Hʔ 6qr(| ShB}RRY!+ V~bl@52Yx='92MXY:_4 ?K)+Q=$ڡߎ^ݙD5`i,Q7uܡ}C4O7Y(ԕWogg;m?3i'rϰ4YYy{ sT[XN %Xl\g4EXOy`Y\ݐZ<]y`NWڣDǏ8"FbN?JvTh}QnSD=e'zI/S^S7b*$#Y Ph6A_~qw{~ӱ`f= Ivn')mc6@QZE^O\g_T;@Lر6sq?57+;$@5.à9eb=~'j,f̺ 9 m[]b[gƸ,.8?P7;ɥU㾠N`)0Mԍa`4DJ+f Ƹn1n;X! Da(PmUv4ѐs,$X;ы7MUؗm/{t`|ɦ)&~_Skdz0h-Os ] NvYkdvq:O We^e%0D#ݐhJl*a숗62 g4Bi3I` f T8ƫ!o5L+/s^1mDt2IϿtT %1n#º\J~ڻ̀)sS&_7a6@%p6ahy5=NM9~KdṭxF}]iӮd̾}v-Hh~qwdK!`) A6tl;}ִ)xM_ ɇ[)Uww?'-IW[}Y_W Mx=#$ Ϋ>.7];{BgEzet6P8%1cgcIFʁB%sTja d^bWj>Y8: %XLƮL쫻 >b]wBGg̼S? Ȝ4EnLZ75 n&6kU iK1 ,' 1,ڼCPW)Z b זtfym[ڜuEnLѰ&Yzy jݵVJ1Daư|\[U+aJ-(2> /YM~v T fk8uꣶ?ZX_!Ა81zlY[)5!ؖs]m)g_݄Q\EMpatL:Xg 4 *dɔujPOG>~<- |8]~LHDx "c_3 Lq5AZq 3EVS ZRL:|اhnܚIyt6KS=`+8Y. Ťl a5Y&q!uJ_Cb=T{) vcT " _͂UqV/[EU2p006NX2K-%3J;T6P+x9K"g8߫bO;9%q5w?'v_|Uƕte͹k{]TO2p^ ^nw+ fwZ4YѳS0d~{л_4(,4"􍯏Վ߲?&s.Hw]x3R:[]eFڜҜ3GZ^wH˽Z}pxZ ] v 98 rJz9: 0pkW$L5A;*؇T]xb_ʍ/ǴAF^/Ju^ gq (o*IjS,ԩ?%W$2ab#&@X:M^eXj'{焎#.([TB;LPFY ~da>ġ1H9wՓ@/:xLl%.CΪ8-<yj7 BZ^4܄TՈ_?v`X _d1l,m,@v|p5]x,X0^[Jh [ ,$@hPU_5b0L]xZEksyRH/#H7D"Ƨjg70@NOq9pgד;wl39̃WZ(smlZ:޿V6 HM1?< 3UlUd"8~?"$d*ݱ b.TRk t_@7Du|N+"kbݦTYGߗ.:'gXsRHZb{# '@9sPElͮ ۖhak?ZN9 Dg]3TODßnkd9lAXH#]]\6RV|49'4nLEMNd\f_ۍƒWkؕ2f0KΎ5"*#wƩ/ ZVu -S.Eg,5kSi]pH*š^ %J/Q ӻZE{mwBPxHW'GFIgY/'װ?A"^#w^8GF;awbr R!?/x{xc$Pl/)#]]7e%^X{>WǸ;h 7jL%d#Fvtd#@PP;xpig S)#wZn1`nX6+-qH^a=vχ1ui)k`ZȵgCvgnr%]@z6]%7P,JŃ2oOO@n.JoGD t/M )L "م:.2sͷlCg1[XQIjOs+xlk-`|"OA*syQ1]=o2z٘\%[/=TkjD5;)jJbM"H?ՃP1l] s:Q5mo 9%[ ˗HMy(Pg:BG1!Tጔ=FO(Go˰s^e"ϯ9̎6 !Q5/w\j[lFbC|KġvkmHT$/u2iqTBHWXB"/Ju!4$# j]mDO-V?pnzCW{T)J Zmec}#筁Ǽo^k^, mM,QهŬ{ %b`.Pk]L)\Q>Ůss%{xQԸ5DlB +1V>Gm`AtSx%ehHߡ2OݵW/b_#$oj65XzO,jzJti>j2ɝjJ CFXB꤀p˸TusDykv vJp0yC-㾻X1R7Ρ{A-&_rjky˚ XjKf_ǥ{C`hy (1h TؖW ʨiK[SGdL:Hzq6~lJ dJ)'&=p3v"bR`cO-=isXz \t\ ,6ޕNNϑ+]ZHXF$6 5 U % Qu=M岆A};"P\G2) _ i"qv 3z n e-ߡ kY%P@7Zv(w ;yl* 9L D}΢(suew/I-Ր;kF uˆ +_eI 9%M|ΐs͘z??N$KdEpz-׆cHv(CQ@|(/Lɸ#X)RU5P N[^ .U,Ů7' )Ȳ-u6;_u:sKMV/,sіN|]kPbOik8DC(nhZRe-$L *sHyozdFB1t#NS9GQ` Sِv{y,!:!o\-Tbu)VQYg"0 ߁'E ?[~j/N6L.d;-C~+Mו~RgN&beOt}cD'~l)* t TT ~iu/m$2YH0Whɔy4a^+qºź1NHPTɊ\DͩLѷ{3lu-Hc@XnO>EuD8uxC.DŴ6r6gvA~bv~fr&JA-.,?%3CSܵ{ J| ľcG*\<6o>@ WW>C`9Uo ,h=u>Oq yS`?k-p ;Biw Uա*G>ӄG91 34xpV̻3DGbIR[JPq$5ߟ,yB3e1y!)Uޕ@^ bUqkȷ7bvjW5~\i?v(+ߧgcI4ѱPU!; s=q&QZtrb>/[94]?U, lqX -j_WC&LO}+Y3tx㱣\',q8D:"b %ɯ2;z4} <>Kۙ]<KjYC#E]?prщ>dΠ5|& rAr22ם@rcv<ꋣM.kwPZy02;~IR®xuts bY Doϩ  F᫣r_P= Q6'&Q40٧s-e";RQ=31ÓT)"lԍW0uϔY$%P;t1a\݄)F UwEVcKu*Z6UIFȨe_c5)I;ZVWxdtn.jm%_BsݬW# kFh4ZZ+n/ˇ?[yoNK}.[Ξ,9ˇxx++ZyF:wYҭ1l|ihXoy'Tba( SŰ6PXqaD?Ia 3 0 (D, S@)+Ṵt ?sKnA$:o֌a-+}MVegicB Z0 dHꔨ>XiqIX~R{4^\b u-4Sy Kf6o&n\"\ZE1gAj~8(R0@^K~) l@ԙFĖB+ȏ4"[-v J,!K<ĵnb4-bt0"Nsejڬ(#~HZIF4Ǫ%ے3Jr! :sP7'1Nc ĭm'qek ;1G_zd/wB雥=;)1SdSf:P6gYLz +UM‡_uX)> XxӀ̝/TvDFI8_{E&yY>~t`:${:Urݞ4鋀0R!c53P=<"ZE#2`Lf n3Q\/lvn nǷb=԰,6gi݈sjF'.)H[!( Y.fmYqAD! JyۭrgΪ0y6 f(VD^W{ц\ X|+. X5re *L%!:;s&L;ʾDF!G7h?lVݯ6|eM+-5|_ l3 =s~qL/!ri.`Յj޷ڟnqƟ"YCzXƓLwY苐8CE].Oǟ Y ^/ѥ(_D37K108<+ w6Ë:l$`݈m?*JM`;3@X]QkM>| Sc6q R!6#}|WQ}RSx*7K8x$` ظu.RUrjVp h_]hqWv֔_<,ڤ.DLlFWb ؗ9.9ݻC?ɸZT*hN/ f6jܭbR& u[y*梟MyXZļs sKޛrN>\ w*8A P{5X1Os8TsVmAb40C얹pf9!z$wb}LcRM%4Ip]A$#*Œke@igd( K-݄G&I(N wgd榚7'˭;"+.k#CL{-@``CbĽ4[ĺ}֌XsǙ?/&\EғAx#:.Vi$T%k+}*p)E3p4_N,;}~8$ŌkVM8faԷY'n5tuf}k Tk02~|sd|ZKRdԽFJuѠ;!}F?yUY$9,R~s|(Xpݔ399 ncVت%!o[n.–etoxaaپ?3)ȴK (<ls^,E"*!!IϜ#(hQ O%RcG5_#ɼ*C"+Jy.hkjB+>LU (8q*m\Z4 -2v1mddcR ["EVa+2[m{.ࢾC:h5ZDu&YG)bq9GwZÙ/|"3-,{3>E M#Ftt=t`Pc\epc g1X1c7>ȓ~}A$䋈$; L쇼c8L5{4؜/(X6g8T^命k8Nh3dU@~qxb(Û5N^+˸j[V+$b!p!E+q4:DGbp/p%W.E{=6Oʥ. ~5$Qo%.+`QTПElWa w$q.ش۹N%F@qQ77'I{򭎔\guA̉=Jw&^"3 [>Xr\p7p,hH￟FBſȰ/34h̹iȃS %;惊y@4c*kã]fb{Ar/Hھw;;gF\aD{O]]>ض?.k8?~oF'`d3o;ry\WI5մQd]cU(e D6G ~"r+>s׫4HUC͑>$k<(]n`!;pJ6vФlLL;F-PK֋" !)><80]iU~`͠ڄ8:ɟOb'7mE?rG ƍe3Só{~*D Wj+yxo.981w9nzvĶ ./; [UB?ԭ[F1f\Xtz!뎻Tqْ((Trt'$EBV0y "9e/syK25@Vf*V&~ O͊ Pi NrykAFuCLv#{&̀c*LW弭wG)-nOQXJ=r4% +ϓ_&OMg0Z WF2'H@ zı ߭1~jpB ؚ>~9$"Df%7 "F܏|M~jŘDUc%hno91oЮ {#)[tjw?v+f Bɺ[TMbi-/L܏|`,l?c#!7&8˻^-&Yhk[& ೰EwHнVA,n 0ƕz ^T=y\2AZ`oeAL0;&T=ÍuR~0c˘Z}mNŸKppBd]($ǔ:3{"YiO *6.dƍ{r6,hIv(XNe@\ay (:3vc|ΑY2~|w*~mCR$틛}x_y>`0Z+/{ F$ߞ\!Eܘ>ޝAi.he׿t]'æ#ѝk~yy/ꭾSXBtS/|72g_IFsqܒf+>.T.h- R=c7ڐ̳k.k.n~4 1)FupoXh<; Vž4X=P/;zJ%Q)T0|caX8h)o Zi|L`u , X Kx$ 'e%\)F eȈ~t0"֣f`F#%yX%n0ʝfN3c͠"n${lqd&$_!eW8 {AG-)V%{=֕В'*`ga=T5}J:g?a*N$q1 Pzgjht*|2S}h2󘊍!H5ʷ~e"2>X 8.ꍛdL0Ar nYA)h3MiSxz Yy8'NؤPfmv795I많m`(k3xHRTҧgR"0dSi@i 11E A% @S B"T0u!' > RH-&j/ )AJW1|*F( _&9՜ +8%ͽ•y2,-3GaR+찫D\h)pD|MIO Vf p;LӾG.]DJY$gUxnzc?J6z㮟}F혺W3a;l=-dCΆ) )lDFwKx6=ܐ&-Im2M@5+^.~N܅6!o.%sw4* u]Ek3x>4DtGǛ>ZrNqX;8TqrO}ɈPX>&|XeYDј2ʒ A/c[qKG"F*p~^tLFj쵸.ƞ[SJEy*3/j)49KʡLBj=)UK<j`@%#U; _5UeQsѣ$8˩Kb>j*5]0U)簧y,x9_Of<|r'X#{W; >uн6N ʬ93mpvCX'V.TSV\@u'z솒 OtÐhn Q1+ Lj"՟8Tuek.ڒSY~(O2 e`iމ3pǀ[>]4~s]#6GXG);\&k#麿0D{#CiN7 PQ:ElYE|ĕucaAwi9~xBޒ!=MW :Xڡ ЛF)S~/93+^zNh\7Xr+H W'9Bcv-H B\e&J^2j7[ƄgRQY4Ж#i9ð-?hK_ |.c+D=rHYBua0fQ"O(ߤ3? 5B}H-I)G ^{ji, ^rugaPO5WG%]]mZ2 |{"r&ZouQmZx aMwԸI eǏS7QZƻ8녙1؀F-MUht*ө Y[yix\(&*1saiǻb$z:ѸEg:i^ELY)upcKQ;4$Mb?Xi3E_VB1$FտeO/[B5$b(X>c;Ѯܩ=Y3YVۈ$ >}~̖iBV;K~.ypY;bf]܅׼199 ;SҥߖB? ^R"e:oMNXcLRC2ꛗQP,1 =%C3̮4K &^i4y1̶wNvA$> ;XPb{]Ze`8-&5,(T@ظ/|^ 3y@AN3 kpUK,{pi: |g$g@?g{0k=<xӮyyswܪEլbl@x *ЙtZbGa~>5`8k%hMs$M'&_lxG`13۩Ɔ1H3ȟGm9T{  hRe;7tNW& %asw-̠OA^v@.!:)伭55OR0HwνO~Ҵ *Ӯ&jdoF(#p jl!>0$)#̉ߵaW,؁{#=p oIL]'|ZX1ٓ8bNɺc{$L]M{0(mG9CM nXaJ (R,̒ n;~pC{MYͼmF~39$Cal/Wk~f G dz"aChۡ}@+ډ0nĖ4t wSZMw}f'E7sp$SuY wXc?,/anU>G;\ EPse>kX7"Ğ6P#xrHɁWOmGN]Q7/Fޫ<4g(;kejEwb+ȢsweKXX Ҟ+ID}h;}?:\i)'Xլl1U0&8nTO:-OI_1|:%/gVfIVf-g'8>8* WF6GOИj?SOf/F󍄪TAUO~%@ O*M6N3c*ϧ4[3n3]Q h}Ç?˙[ -rF (Xj5%G\\l_?b9X2rJۦ)m9.xЕQg[RXBYuTԌm'qd[(M6PUɬi7ϔƈ=ee?.1gf `'n}*a;n5D% #{Z5SǤ܁[H^`Pb讃Q􏘲s~țXH.Lыu, c*6 ΨRi/Yμ-D0> ͆~Ly}ӛn`!x0}[0e9IERW<>2y%I1ykp\w?ڋoB0%tRؽ)LrgQgwL59ZEXa$x\{9qB"( Un,gZ vHF>\PsS QvIs (8< oYع; W$ ^ba i#x35{4扥ְ}?%I,Ě#f'y) G^)2+LIխ7*ny<}[`*ϛ0ښQVH^c"I0Eiy%ٜ_A9QdY%ԤWn 5ov0;l]^t:\{z{HXI0TcQ2`R;mQ1-߹}FhT/oՆV, C;&>]R&ѵT# G9,OskZXkME/e'ۼ` PчE97`0y!%9KkC+v K<.~w4d4] CU` G}a?VU=d,$(f gj0.C{9=aPSt|` Y_Tʬ}eb+ ٥(DѲ̯mr1 6QFNE8 8ۖxuiȲNc'w5Om Q.(XslMlgz8hf/PY[5IƳ[{E 9O[R#)r$F) .J{fzPǬڑ4d4t/\+zaYnrz#jr"c +q3UU跔lfaZӒfPz'. aropI7d܅roƄt$\ӗ[A|4%bRɶ7}7b~K }189g9q\X˘"V&ms孙ΑmRZgm}mcf w!;.D;}3QLyp ksRշK ܦe,>&4̵WIpFIf2XdJ;ͪI %3wpm_R-T%_&7F| ŽT{LdFbP_7OR^|oqU+R)Da||SӴ®x R%xq0[B-n;5~uD8tsB9Z8@pkkȮmkk$Au&u% pѳ <U @,2Sz`Ȋ$Cb Vq3u{F>L"QAÓ(X5pƓR5/,@׎~ꉈ0\ [Ξ+֯PG2o&QFE\[jxiJeQ㩖*ߞC'[TB`8+ US (r;6"lD&|5d̦L慀χ2J|V^q^0Me0wߖ=N_hx[ƯVJNPAT͘41 @Bwru>%L2x)@ϔ]<5,rOGP6*۾-p!OP)1i. 71-za1Ӡ(@d*RH|v΋'ѝ6Wm; eD>GDxgˋI>yΜ+~;{_rE~Kk2){4 Aea 9e|Ӊn`.s{I+ŷcrMz4мaMLOȨMHS)6TgunXˡ}P7uݲ~} R w =>1.-ldB{-$jd=#aFa :"ӬԢ;< h x~!TKqF]DQMh> HXر] |M W 4<^] Y[7 x$9_7U6,oT,LI!C̄BVIqg?2@HJL_kɇ%,hQW9Y);;Nk{[g爋ORl vdS7(Fvxb>/a&\Pm6#m1Į@4 (T ?1 31:f&d:}kI sY$֜#[nOx@b*ڪ<`& 8+?~X_L81 /sGU,lΘ CX`ƣgؒ<]>YrH6DT- .'5rl2{r{NRiMlqԕ⯎iY8>4[m_D[4"H|3%TXBWYƿeZ J(k 4Z هk 6J#BG@#@of>Uɺ ΋d2ػҲսN]j8rVa)SLj+x?䈅6nvX Hl 2]C-f\wPE!#ɒf;VB;7M50՚XovROKf5_\~ W.~!W3_s@?mU!<&2ܓN?GXH9F-DɓgEH] 4*iQ`U)2⥍ɍܶoצ͹TձWˎ Ձ*C]ǴA UB؍6gMKk5|=jE<ű@Λ=9?3Py2cvb{jjRe0/"` RB鉸˷TUw:wμ2C.H`.bM:V]3ej(u^'Xa4vqxVlC)=j')u [O2/iWci4?(>%Tzuhлtܣ"L6Wj(1}h9Bg&ɞ8EHH/Db f'7l-4 tkµc) Z{G,Y;~ X&C'T"b&L 3` 2aQf(GX̛|X 6v݉~vZ{hDcn@z̝Wlӫ>*F<,G&%۵l ?UQp(k{"@?!FXkERe&GѝA”(39D@ʹ |h/lJo)1W/ƒG_ o{|= @T'G~d#{,ޠv;BۊmCuqDZ;<;R0_k$cO\X]CR'15 Aowβq ->0tg۝aA,( I> )ؒN3i}D^rv&c$]][\؟eLS^٢8I~i .-mQ4.F ]ӒhS8t`u(@]k0t6Ss^.v苤"#;(pAKwʥ=OdWntZRҵu}1t*_NTk=윏=Zt/tpvD&pNF{I;4MƣXmv(5E\7}tj(U7WKFRޚBr<|n" U6F.}I/xM7Qл1"V0?J!P)5yO8U۠D;zOz#םuv(P>)Pdz)B0C$x~FE9!/ -1rB4eʚqKBrc).lh7Qa.v W? v Ŗs& uEלz_ɭ'%$ PzfC{&J2 3El3̻'zAa+&ѝߧO6g-4X?a# $K\FY6 MHf0F#+!|qu1Ip$EE;9l%fK&!T:n`)x..I3i 1*Kǧ pD/Ս>B U}v?Bh4}m\0 fY _uct,Kr [w8)$MbHL<)R+"p͙r܉2K6g{~1cѲR[WIBuR5`(`>,TlHj:kL Owa<^|_*z܃{ `lK/+_*OAWLRDOXU%8p? L]ns`3ޗz2џ@[:<`84@{%wuJ:;ȳ+rZz UNڵb$~ Y! "Љ*My:#~'$vz8S+ H.kJ\\ևMEz[OWRMy`*ߔpnۍCdnw"}L1jĀTտᤝ~B1QQm0nO (Iڰ7Q(6(Fd#;_i^M(_L ;F0صt$[DxXvvcT^Zf96=e6a2:qw.'}N9NgҚԳ#(cNXL:Wx H`b0Y}5alφ `0X/+h;7ߏܗi m$-T;H7ۂ0&yBww2\[FS:@y8lLK<˃\f+4.Ė|stQ|\˜iw``r|m5[Fh?tSm24C\(0~VH1?x7xF">hw7Ͳ&d@ P6A܁v\G57G>L-i*u~a*[9OeJZ%$f4$c@"N06z@HD /akW\J!lmEy5N.\&R85SU1l.R> b_u?RA?ζr6JCy4 * P]lBp֦)]VaY.?[ U*{e8]FUp?m"zeNK|䉁u"I蹎!2i!p~p?q4aI|Z`Q"

~O  | .- VJ2P[9ϱ ;/G-|Lk?fBp•e% @"Ӡ? jCS jN -SĸlίgQ5Mv @B:..MڏN!qTh6в2=EY/*%Coȗ-9v̏jUf q>~j:EBKy}TU;NˎHv, U 1+ ԥwƗhڑvSˎ7iK'$+c}U_ -NjB >%Ե<{:Yp#K4n~!W?/-lW5pCi{*V0tHR|Z䒨{V wQ¿ʸ(fчZ#Xh&iG+|~Z"A28J'mU;fle>%wWi$g [|״/UO;.޼Q+O׉y%v+,E8D MmεyZm\9 3ZD{o?t,0vC,گvmUxcn9XO@ T CQg0b|P_%L.BqkH5#-J$o 2߻X^#P[ǽvH}ouw ?G}IUj0ƢW!T7*G!?c9y0zqkgs{)n([ M$ܜ9^7k!L_*0zs[)&2 _ؔM&lqˑQȣ`mK&# xmr0@I~s{Akq(AptQuJK'Q9~+/a G*_!mv,Z؎L a+ɗ{˸:u<[TMg 'Oe"xUl`;P_+ICn$Zvӣ}N`-,^:F`V'=S7`ƽnni; to%5 $h1! ZX&Jux uŰ ]  OZ T ZƘ|SæUyuy01^sX˜ fJB!jzD3>= }uXlf?a6 ~@zGa9^g[ʏaR|([lGiֿ( ]jBdoNC}܁2f=W>WB9*w&sg j7 z)O1pjP/MʍPwI FB[ۨ':<jl?:xىHBgUf:y@ETCSVusNz{5V;,,<]qd N_́-sKVy`7(Ƿ*Jߢh(\:,8aFrtG '}N颲@YX!*4j֢6鷐RZWҝn9Ѥ3!!a]bx Pwe4DKB+imBZ'黤nJbbNV寇QYQr:~W K`!W.h|[O["3CoӸ}pm9}5pgg~6ePE˿],1u[P.ߊ%a&47~h8b%]?BO.*C; [j=x#;Sk 9WgqnV|Ņhogs>O{kIG( qW_&[yHiF`x\h E5~{j\\LtQV>, ET,gGvΰrUcbzSBс gDS6&q {o"Zn k .%ҌcFcE+I[F\oF$@G.pt  "YV,r#9FBb޿fvIZ#V^a Pb(_Tr*J,(O(x kndaTtˋ|f +CH^QFIa5p4_p 'ezj0F H .XC uX<ҭ ߉.?99UT/O'2};U_0rr`b /bץ:_8k2xxtde,W ;@q.'oMqA}4f[&dyMN6U/U`AQZLn {Ij$klNs F`މ-JϋiLj_ s)BZs.TrXbu⡒`c0{WE/q(/u_L+>#.ms7u3ʤewYhLp,3eTAlS$64H |Z@?Cq_EUw'F^}d:<9K-%B*"QAZ˂ZO#cޥKM;({'3|&7x X̭7՜pB6e 8]wg=:=Wߗ5s̞ XkێLwC/'Q2߮9a85~6Xjqv)OW_\$|29fЯiE=$lӓLH~XIFo./Jzyڄ*e3Gf`/尣Ag0Z !Pppm}8M>lR6Tiq2Xg+2RUMSHxvWz*>5)(EJ%1P˪ˆ#+5Ph(H{/Ri~;#2=k&'91#<2{ZjsY (L劐ؖf?CS~`NR99Xƅ%Qj~Ǔ{{_=ќ"7n3s),=LJ/$,TT }aNUy(/2M-Ż1s;;4+XlݻeF%Wqnq280A9bWHVd%R gbv } *ĝ&}F'x>Kܳ Ѯ[;xF)EcP$$űfKO!,MX׊.? A +B@ . B8 y+)5 2%IMY?ߕt>$RM# QtΩN8v3xC8BGAeT xnoZ`ٟY(;lfL)^GS\-"~}u̬0o֠`OۍM`'O؃1/W 5h`ljx3mOOu,18SG!#sVr7aQcp|Z B)E?Toz/ ]bÁ;2F[-$$wω?7.?)fZG%ēv ! GO* tDiW/I=;=E)ۉjI7 ٿr.6O 0Uà &8Vc~>7@D0.HUlr9*)-$V2uF]r_mƯ3{((%jaUdP37Io!3HQ5.KB7^E G%nw>VS/\d`yΦCq;? ,3[[NM΢ʇHX*T2@m4qfϺ=` \EY,&Iӆ5qjBP 3~v7U633;Z=w6ƥ^ᑸe&*zl&B>(SBV7g6_4iNv f姰{[LXц1P N. ^AN}F!!a< bi2T aHdTzD D{X  tKlW&šKWip* R B6ڄmlĺb7DOݭ3\M+oZcz۰Y.u[^KǽEY]5NcΡU(8h۩-bq]C;8+?\%#_ \~gem9˧0Ag)?78#UX[(v"^?燎*B!ruO`ih$)ݙȄĞM4} >7hG5S”5[fp20b.Vhݖq,j%e/¬Ub|kfe1PG/5h@CN@\e:oQ"e}h]8NQkBBT-۳(t FC47`.>;9$,IzNNM\^ ~ֺ=]0}岰MŠ ]ۢ)PB<9]f ۪2nM!}+S^3ғsB <>ԺpG;fJGig0ׂ8`vm%#E Y7ptLMa,nh HR]^*S_DT[hA3 lp:_\TO5D4DDdoJ'$POeoWY@Y5xwg#odYyG|(s| ȵo1O7+϶ʾѨi%dTsjsA[/J}$,UEڬ-ӘM/4xLܴp\4AQa؁}JWTS2q97nڍx2$&0(Ɗ!L9c>r_7EZ@#CfmgXk⎰6'XIJ-mܩeFimiI>Ďcf}61pS~XHo1ݎAZSugǏ*H E5"b !%vx fJ$zIA9>D3>;{E01t) D^onF+gwpXV籦❂4 V%>5J>9J1Tz'.4n]QG~222(:'O IH.HK g#`ϓͪˁgB̯5} _ZxE+b~!t$ IdSsɒ!V]TDpBYSicW- af~%2Ch"6H'VKohUٲK+>(z:P{T1guUBm"PR L[DmfP-:Zb<-&߳>:oF/bKq%9Xb ēZ?`o`c؃a؊eS i-Bj"Rij&͍u?e i6{.75^D"/1^|2xjNrt! Q0Xa:XSv1,ZC}V{H>6Ug) ;cIZc|Ho~cB *d́-_}zD͞?x:n1con[gKcK8twk&g.,0ї?U2$ szKnn!pT %柮6fJp̨3-<ܺ2mߍm)'1L Ncud ;`y0,ZX!=ROJ^yZdJkR>s%VR+cl2ziW m \*go6PB)ia. 9;n!S<%l4:]&4LCi0 MJ }:yŚ e&]y$n@%!elhHyiSI#yf̜=DY!q`A/TZʟ-;5 Rt{5:8@=^ ],0l Qjڀ Z TQ Shb.LlJyyTe咱kC2|ُBRٮ[Cwy RhrFȴѵ=# ~X< l_#zZƕ'X= B,xp 8go q**QkD;l>zuۤ^yQs 1t 9 U 1Q0GYkU) r!KHB5냾a)d"KY ]Ӿ Bxd.,PGއXVJ1<8JcyuKhVFZz͵sSzQ);fPg{QȀ<ڬEỴazάa)2WfgIBjqr:_+jY;5#'ӑ h:x| 1A#9' e? OA; sUa8Byފv˅*N(vٚ%ZU1\k#Z빱[ PZ mf}ApUַIe!w0D%[/[sl%Yص4IqsZ=K-`Wfp`[ZOS/d_a-K`V~2K k"H9uNvιmN&;u8W['S4`xǏI:UfM#ZYNɓJpBk zhwa U~bDJF@q:ֽ'plOp"[*Zۜ]'T :C!}*A5|f}k q•J%}lN7  Fm-,iq-wz╕2x)y=J'Q~l4=CTx}ùLYK7X$j֮JR  "0a :@0=!]-Ɂl 똄>Gn|2vx`lm|y9Y.T"0Q=㒢FY}i_.=|A w(.NXė1YH>~n[awos"Ʉ_X,2$ͪbRs8_Lw-K\EԪ7l1&aPe-9"Z@[/|ǃ $*пiQk[Ao;{#sD)O?S ?O>?<֓agMa2=2rjizϥIImGTervjHFh=dϞ)yaȹDŽI vsX$ITǽapW3Ut“:۶P$N.aG:_%${gs^{F7r?e"Y@R[?tw{1hQa{>#Q*Iש ٍ ~.UY:ƈљ.Cok]c6(3Y"|'ɸc891CeHFGw%A&Γ;)B6p|ި:F,#XKGAX7)Tg/ ܡ|7,c@:6^]MElŌ"qO*z 9ҏiR0?[2>И'fGaCspSW5hKiP..˴$VMoㅍn bbJcNkN0K\RFPэyP3i5 /|} 1uW50kApiud $qd mfŊmH~ʒ屠YAlmbd^52+jxmI1MIpG'nAO9aTOp/2=kxZjSǹxL*FMg'{ɱk~[Jg_z5HURu> 유!/J>F_} ]'j)P5gltV8363ixTw {O+(hҩN︘O#=u`x؄R'#nolKAٮWksR?)z[ϋh8t{g`n j4IXP ?[ wrk{n^^`dKX@<cI *߇b*0 ÷1Or# 5Y-s}J 4uyET0nاe(+qA}&<^6cVwX6}xJGpElj= Q?NG&CTBDŽøCՃ𒚇CΨЄ36h'$pypڢڌb{yl`yb>ܮ:Gw܀{~XXDMpZ> y9|\M9*OZV11{m Q,hYeTD">"-D>'1w"3}8<.9/umNJ3SzqpV*fVp" tK(AO.KT*!l#]:_ BaXrU*?%~^||Ox!^`[LK`= dg)I2Afq ^ޣ/uR䆃dz3O5ssn]FX K${+n]rN"9:.S7A$tʝNe(k󳫑\ fDVEՂ^'D;նLo ~ɂuAtɛzN/m*'9tW'`MZ/TXog~oP|ѹWGHr=ΡkbS=ꗧS:8V@8]/̦bL<;JO[@:vMԋ77}"T){P-)# D tU\i!ѳh+o8<7exY+8etO-cI#0JngTc4 (i5}Яd rTy)rtTH$A{һ'ͭRT=g'KN9 In 39Bnڏ_GK|h?k?%3kǰ/|2c27L* ABP!K˿螋g|mPn jqgKUMDȃ-9uvצsjV" 9iH3ͮs1 6C[+(uC;P녜Z0PQ`yQe * v6NF6ڪ.%񒬘6`CCw_GF? |]/}B{=doKŷD0@k*Mk׆iY{Jt(bs<&*$ޠFj72 BbX~i= ޯQC=y1.hZ%6(<w-VHDwp#P^5{8|29!_q;ۍU ia3OD2p[n/4oc\kXM\eD3Vvi(qO6 .` _*eE4U1SJUC6 ho)(r.#<đX-j.mLj!ry ͽш1Y @r:v %]#V &iuq% ~{ %3z<~ HAaʔ !}?\O0 'HLP>$ #{kb,FS?k9u?{6?0cR-풂! u]QvLL[CXjX 9ioҁ$,q(\F|Ԡ3ŦrS}!͓=]?h`{[׏6#)y*KV'"$M[:W* 2  l YZ