sssd-common-pac-1.11.2-68.el7_0.5> H HtxHFS ?*}})<,q~wj@#A!"X6|]KY}X9b9e63887e69814c1a088dda067a77dae32c863LeYDttȈFS ?*}}P 8v%>3eti5T vPxa;V$>9?ռd $ V  .LR\h n t   #2T`1L1.1(89 :=-GLHXIdXhYp\Ҕ]Ҡ^bdefltuvwxy,ոCsssd-common-pac1.11.268.el7_0.5Common files needed for supporting PAC processingProvides common files needed by SSSD providers such as IPA and Active Directory for handling Kerberos PACs.Sswsvmsrv03.fnal.govScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttp://fedorahosted.org/sssd/linuxx86_64rKA큤SSRq9038e8ec80c1f3e0b1de23a42aba72b646533c6da477dbe55c62cc3f24f8e2ae8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootsssd-1.11.2-68.el7_0.5.src.rpmsssd-common-pacsssd-common-pac(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libsamba-util.so.0()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.2-68.el7_0.55.2-14.11.1S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.11.2-68.el7_0.51.11.2-68.el7_0.5sssd_pacsssd-common-pac-1.11.2COPYING/usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-common-pac-1.11.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x623af7b4c8902e4bbc097941d12a53b99c8c4064, strippeddirectoryPascal source, ASCII text,R(RRRRR*RRRRR&RRRRR#R$R)R%RR RRR RRR R R'R R!RRRRRRRRR"R RRR.?p7zXZ !#,] b2u y-iSqW2s ZFqOcu&$;?8xHMA.699n2 o`ő1Fr(S`\q#`Q+j2 w\]܌;~i]fZB{)qs8v}%[j؂^${oa;bٽb5i}t]0 lN-jn*JԫU#sKof{8!Y5*+ZCI{ؓ 82; ]{*[۷13eZ,u ]Ի8Ԡ #m2,cz_@݊; QNXhX7bv`[b#l:,P[.HA*ZΛ8N= <. &PW$ 89N@JK?jzǜCF*#:%! \=SKG^8{m- pSƬ9ÃmzpGO5)Q(f$%*3;5۱˷{NPM|?!%n}hq6йT#'|W>yTCOrŽSH;bm{ݣ51|0S7^)@b *gRZV?8\axlX~[\鄖t0,[ \ou C։Ry ,v8JwVe!8mbFR`(1 ,CH Ԃ7En 5xf--B^ۦ2l V[ZQ~AJ@04{[*@XU~a=-jkdϱFꁒ⾞\r\B6+J OW##JCH@" r`7-Co&q2UQW6a0NRvDagQ𑕑ħx?8G V+2=PbFTz:Bfv͏;[S˙ދ;vnYNmsTBԄ@+';@-W&X\ X8Ur/B:Bj6C (WH mrQɘ=*Pt/'˂ (kr*ku5Ƽ$ u7dnp%kS,c!GwQxw]-R緝gn BCS2UYI 3SŚHEl m>¸W`fLLnËMx%-!Pޟ.x{d Onu1?AV-^N |RAMgCGvsF)tL._mk_~iuVhqЕ8IQ~X5$ᩙtt_~fd*BD7*vK%tCa,܅|`ݽpj&2D e &jcȕ-Q3(ZD\Ob4'jh{韧2/bbl1Z`pfpQ! i<*'f{+ [Qܘ]ct`C >mFG0s+3,<^yxձs3Ks& y~L_59t.+/ OȧpZaќtoynj~`LZ%ZS pcfBVW Lgɫ"@v%ƄN$"\a$L!#ݳGKƩd}g@<{UB2ǭp6Lz +DtXՇoƷ )ױ.1F]mM"=H#5LyFt䔼0t9n<غhoXVޛ25o(_t$^qWD 1>r8f iJ[4є(ӢLGq( ͙E^*,,PvJLZTy|n왨q^ZHfX_ fxSU#bhJO!?"ݢr}/̚")"͓So9[Xk:җ)N.Z89E^m 5/G -oow_6q}lE6,Y.kbrxc ̜b}8 pS?Xm$*e!_Zo@6ըbksslW:Y~Qe (^]MLsN2ɊР[h0.DŽHg_:]pv&Qdq-QcmCGo(\rpX)lrñ>w (> /3!2_0pzE f QQ*b_.Um8$ހ[zcn{@5gAH J+r4I tp٥G֨9{Py(-̃aD}}tg#2Yd&Y_1SeT~{2蹕whㄓ(r<4ͱ f}2O9q,s &>@i9d LG=yvV`ߴSdMqi=LPΰ$Ol @xT/|4a#Cg+yX }[T%A.^jguT)F?m-~~ ލo8>eE-$T(V}ݲ+I1ЙP{͎&*";*Hr;|T>Uet"blL)&(vM2T7UK"HVd ̩W# NP!{ZqI@:60^Z|L3ǝxs?u*RY]:OA[Zwdr T0/U&d #+AW8<1F%р|C 9Q_oYF^5Y6?Eh+?˲g6s0nCͬY>V%I~s·DT1YXQ.BPhA8rC'ooDwWS#eW^$QTGc",I08}Wo8qܮ\0;M2R\8ڟEq|/O\kKybuR$P]c:]7/`tl:NbLzE ;HgN3MfZ▩eeq2h%͐*$K(k$jk oCtCQ 9 OB#I9Koþ](/2O!,RP{M PUW-!v!&u!: Nzj|$X7a\4#V"c|WKٿt̡pF Lk{—:](wՕNN6Ζqc~ dqP}6yB`P͌.`R^M`m29]m ˇ1P9:Mo쇼sBDlY (yF`Q9I*znC6ؗӀ쁣@C(4`R!TԁYV$VUٗV\Ӝaxhil˺ b5<^;uDc/P8"N̞37WJD.@PxTzӗ wKrQt"cj˙0aR/`6[ ћ#u nPeej^]*-Jt;^6dAAhx!Ѝ;]ֈqcEȽ$X.=ͩc.Uғ?^HvL2>8zªIKi_nUto@\i *)% m2$a!ymh !P"Ԏ7A}̀c<-U9,*F_+bP 67g+Kd0^Vg&C1'>ز~ )ߺ`SޫNR*wi݄c6ꔳ18nB/P Pä*Q 1Ǐ3HKužQ9QY:/? e-5$ܚ# .Eć߳\H񫵜N |ڊz#OomNRfvZ5.<*5TN2p̴q® qA~/[_%%Fϡk2s8ynD42{nl8kĩ'8F4ܷc__U:<. 4^Be-q@Ȋ.uMEv]nKwџ+MO I7ȨB(҈"06؀ (ųX EiϘ>\ }\Mx[pWxBة#4(@3Hl2soxdW҅nK+ebjAgG(t؀a 4i]6$ jC=ɥqi6 kڷ[A4RKK1\#Ef>:H&l}V|Y3'h&U\wcf)r(ǜ7`XG3Al NXzD nea~Pڎ .c+B2mܾzNqpSrqM ^w+ƛXBEE߸'BCtSxG B EܦmU-+a3wփN۪\|i EAJ261۟J/{u7Z^f<,j%we(K{Az$.^muRPmDz5! ڝ5@TgB[#_po x֡Fn*]>R\u?OC7j+7+[tnk:SгE\ŚrUl. wun]7șAU LbGŻ?d 7SrDwѫ2;#2-NέVDbW1}?dY.MvX|3>ŧy:ljF!(Jm. ouΩfu#҈YtٰD. MT*2bJ/E.EGKʔ"_釼먹ZD9jkbG`z&i15%Gr?m0"YWoj`"w I W-&5jI> 1d֩[ F^4~$qR2W%NrjgSvm؄ޢ#,M]b}U#j.Չ2ᕮ h>Ĩ #hx͚d@lrY(_s+2@OP`qSoy?9f6#5$8}nJnB0cxo k@c-+K x(tM`7/`7-J ꞆL3x(%BMg 'ZkXzapveh(L D \w]<Sw92L^g#CBDXQJ&O" "IÕl~|gi<TC o>"&gXDzJx}S5-#Zr>p{6c \v1յ᪫%  gڰb yi7ŽݩTl$\"*/ԉOdm': J<ڰQF "ъJQEKuY<\m; . HhMz:gƩm8pu$1`S1  |sYA;e&acVyPR\)G<5m%5n~Ƥ×8}րԠ|Xj-a~qJg;l=tv:`nnf(*Pift |,P9t dCPY10I`룮S~#ׯgkZtdLm1"д|#ulm5hoͩ ѕXȘbej&Xmb'␊t|Уz=]5y'Ι>@ܹK2(4DbU9{ahݏ5 =Tuy=GS\k597@NgL "RgnSY ӥYeTn;Svij*<(A=FYpɤ%Q{m҇hU3IhzAZ!wVV#Z$*3\+:&+{a[Z\酀':wۀ[P9s_.ܑ!iQT&Omgܐ>t!Á>jڵk-Ӗe݈:|TǞd`S3tԼ*먑Hl^rx`^ÌT5ЉB|*0τC*<ܓ<3D&#ZQ9}h3%(O+1KL-|s72TdN BX}3vV(ZQ>B9dߋ`}>aȽc1bcѩԌ5EtEF^cfL av`S!y8uQJYwtZX|~Cl~i%iR . /z U3QHCsoG Y. ?멟2$yDsCK>{ V{H{zP6-SWݾ-ƂRf?ӈ%^x 7y}q?d<Of=Ml4kpuL(K])KooVMxw ,У;g (OBByP>6+`PA*TB:e_#{i6R`g&.n[81XM4ʈ<i4\rNpav fl@%PBBMhĽ̦n<ד6#{4@st_3*g7-2!(I-(_bYMSig̻h]z[{IRek ?x$BL3cgcgM ">(qh(5)xmG t`%m,O_Wyt8*\ThH`sw3pɥWT`Yݻ =2HBdz^0FTv07MS6@w8% ^/3큗d w .*R@y"X4N2!μ/%&jC)2;Z3YK;A֝z1 9qSj>˨U^=mj/nʧXgZ, N~tlXJ{T~iX%?Ec@N~*BZ]M/^͔82bi`!U)Vᬆr CIk%)5 Ӱ!xcda< DgxD5hvټyWd45k1ƤnqTOf۰e ¬vViL ړsF{FʤgddqR5wC~PBźݴG[[Y)'8>[Уޡ؈quiFT$t2"EA;$6;iGv>,gp#w|^EƋjF@,h6wobwEmߦS%uhYpȚ9 הQ3yqXChR3(2jY #'G/1E` D&i*w۵lg;zN. vOՍk-7Ƹԇtae4vT" L|!GxeMnN"LuZ%R`5.Do7;^ImYu=&t.^'?8Zp'cD +iS;%߳kP=YZNWTl=˯ oS/FR\ZfaTf hVk:cW:j^e`]IJ"[2+G_lO kLtZ2rY!^jJۋ([jh] \ѻ>@ueAW>CxғLfI#581qa3> w~(3ƴ.VpfDfƊdpbF#KJBp2ıyqc'׉ߢw8Ac3% $4Z*Uݧ{}1(+z=k FpP:"*)a:쫙+~˔.Q,0ePfBOG_dh uO]4SM YЃW cxu81  v*ܜ0flmr5_:dL5_N׭O=!yw%^lJbplj7K.ĶFyPYsCUbZAfn謳bjZfiJlXh#?sb4mIoa;`I[JK>w B+IO#a E⟔gH8K$Y󮬆Ե2RGF7U$tgL@ĉR9_kkΒ=MRkv[rNnoE5J;7-Xi؇i>JDY=g҉E^dxX4jpsTJsij0@JE vQC9R wRE29 ~Y}?t }wuCQ/94=;폋r6wm3 B P=] ΋^f4 Y84Fq*" )^"Rz6GhaNdU,9*twC}2/Q R^`g; J%OR=der'/m4{'ˊ{SqmsE7ЭHez=sYO)c9,lLɤJ0V 1sMP!L7Mb VxȓtD;ws{^6"x lm9owB F92<&g:D꼍G"L2u|!^-,*-w}iuiY"0$f".Ɓ"NͰ8Ui4v˘Ȳ(Ⴜ(x&S>Rw[eF4K_'yݨ N ĥ9lm:ZvNz}ࣦ:=4uZGxDB1 ],'w,-*Zojz(Mv⅋&O =O2ͩ:#B<4G杳3$@uw5: qQ..CDgR$Ltih~OUZ)_V^֠FoEzByJiӺ?9 u9h*|Ey,d9R=OrM؊=+S?\Ţ?"q:F0ʱ"'zNFH_ JBajk1üLf7}2hmVNVO\E3,9f˫A}r0a,%Lq~ԊKNiPE5 df|E^}8gFAbgO+.NiK3-[66H-KBQ*ݩ꺝p;ړcW lH%\#'i%@#>bV3 YfIKyr#]vZh ާkŀqT'OK`"I${ 5ʺcGjs!@xywX9u d(ia+) D4,I?_lTGpQڋI(FAA3/yYY$: KVVoL0Hj3XFN?^p*;4rwq%Qu83Z.6F2̫qIwɝ+ ?b'YEVHtrvX&{y^FXToʒKc%e\ټx-G{L#$0fbO"k<˒)'u4 j*l |0D~AJa J'1dI6 f?+JCx67gu1"v)N<ݥ_F.pE/.8[zKxN=)Ԃߘu~"j٠0pˮZ %%A.›*1okch8t$X ă55t?!.D0^?wgguRMx8vWg?ВUL ;,糁Q[qt(҈ƂQ+}{eV3ВL5v¸*|3Y@MI#<" LBuv5+Tk͖[q3Q~ nX౮X8bjqs3)ZpwWHq?Kģ7,kL h-c-OG+m@5ʸQosjtK2 2k!x´up[H|piє.,*Iy/H@0; jxbˤ6k պ[[X`pz2kkݺV}K[hKˌÖ쏮7Uc&ukLqL> lwqOs8"a2;4& VNr)i,Z҅jvWp +2#P+(݊>ߺb:Ҩ跧E\ߵc'VX+{{cbpwymحB!ͭo8?yWiw \ i'-?|mH}i0Վ(y(UO|~ ~ N`h4l:g cnu r봏yd˵pp,Bn'F*0B䃑bvV k<#]|:5|HQ00-LU/`#[PO̒wwj&v,R~_/@͙n!c `TX?"FxcٴTmKM-RaqUZA<!K=\ r\cpGU 5 B$HL x1e;?UP\2$A=՞4xF EX5$bw>h}f>ܖ܁n_iN͆+l[3(ޓqVAB=~fLHNeR]?YwdK-_ # }X<ҘF[z[~` R?FK1y&)x@d}/mkro)}POoo =m#*'|P|Ν3-iMTcʋw \1JNN~av=3 LBݞ!ZxԮx6U*sfe$}n dI<NenFFr쪘f7)_0 ח"0HtG'⫑Y㋠?uu*/EjJ՝gZ6cQER$/8g&dO-P2-L"6j tN8 ]wGqZ}]LS$>djzLMX[3KkY+Nc!vAhضčőnpe肐 ȎvkFҤ>u(1FnjM۫gk/-`(Gk5vcK9u`R(a_x㉧[ Vz~^Ľ]UHVB;8}1ڼ!U)3軅q 38 xk?0>.s|rK9P28:NzAG͑pU4*$yU1?!Qg x#^4_x q̩Tjm&IM!D#%ra@<͹I4P}y׳XkwWcF$rhH #‰(.e,y^3a(ޚ~n#&]i;r0)|{!J8UT慤C@  !5X>{ʯḁ,m|t꠽-( %'IMٹ '&-n zYΉ5O˙/.c dXPyq7A<5 HGd+ÀvkFo\-2sɕ RҮ);*iEYŰhq"+1{G!q]@vɉwIn瀌hyZ #M쫱}9qװ}gLVӄ5mHB]!"[]3k4"i{P WͣS~*<hZn:DJC ˵WI@oVs;^|o!q8?E099&aՀH-$^-81z-nN t#` 砂lf.9 Lo'u C<9 V(ocS${M$v֡gyz}<`,=K`Zɦ̠*&@( )ڷR|%A|ŕR_1D߭}\Ec.xKxm),Ŏ$,F*]"2v2oy٩Yd٬y(KɚLz 8q-xOe:N}ٹjHjЬ@T W Ȼ=d7]GzK(!BEw2xGukLSF-}Pl)T~er~Sz}rqRNQ5p,jQ5Sde.&в7ޫ9Kz3sSUH~g"Qx?L કN9TcMvsY'ݯ܃G,a3T@>fNPLxYi=ī#?x<#ag/$8lo.7D4U61Tx\RI ΅ f0:ZH.W644]Ea`U~EOi2GTH ҒQbn·*V>op a8hn ԁi԰qd+>]mK2 rYxMcG0"3 +THWtt.h?VMyoL751so6M@%5[iBBppvM{φqoR659<[֑ΝQÕ{f'l@Y1^;$ ;!q\7VAA7 t΁鄳+e? x mQ~aAOW+Dk?vh'żhPp _}fe=OPڛcFG£7ӭm)b`[\fY|=jpZ@Lmݵ"ܶgHipљBf3Rrh N\%#d81g|77"@?fgD[OK ܱo=by=µaJMTK ,ۄ3# )]L٣wz^aѢN  {hmMz+Gg.2#mt }''=KFY\'FnGB'AD~Y*hzJ$܈] EJ(>NNnԮ!'OM׹9 p ܚjȶq2*oe62zK~%{2eN)If8y,ie:i-pH 'խ;xlv9^]nsPHݿFi,^DD=%٬Ӗ=wrVr5\\je QbԒ8]f1q6KCCO}3 Cr[FTΌuvRyRY.袛ru=yW3 !I"da߯ӿLOc_`+A"]0iɾs!\޾Oi 'w5rokr-w 9fV,Oy:Hay)ӛ*hg(_$;}jkr k(uCC?uZuz.~5VʃXo<*HGJY@Յ8}6dh&-nL?ahZ[u1?y pKɓx`CK:}mcG>q)1)@813No5}@Uj`պW*u 3oabM++9ܘ77 T1DP(kiE'7gBĤt{O*j)9N G>ЭHVF$zT R~@2iSm0C,{H ē~3jʫ9q #n1-6֑s'P^_8g:4M Ɏcwh- _/`ړ}C^7azMS>,O`x5pH”vw2Uכ>(b7W,KWCrMJKeהJrQI<6nf"ƌfK@i&b|ZngzK\G(& MIҏԇb-Ӷouim ~@P/VCK?CnwQ{R Kg< >`Rxޟѻ7B$KJsJFw/uGze&:|"Q5 Qe V} F-'ШVha݃%81[K,k 5EdTC@(+xm#2íO_y)/GQ24=uKIZ!*#*y Dv<,"`Dz/MLmq9t^F)8*|NMϯE 'Mz z8K{猻 Z%;d-u9g0G]/c)P+mKN%5zP"]Yu VW@~Bi_׷.je?gvpP޳> Й6}POccR&.(l6`W IC4ը( k=NYrb "i.պWNckfwmdM K<~E><_&idP |[/ X>q$|[IJyÀ%٣' 9@'LR~mq )yYKv[9sh4Bf0b/@6yHZ,l?jpNʊyq) ӍUh_ْ4cʝ  C(r»ωXSPnL]X Kj~]4Tc řqf;} co&JK{ե=cz ;v@HyG ń;|nFkqXn9LȸVj.0 ;A 0+gPjQ$O¦bsh$%Ն\uQ^Qx*cڣ"sOx۳g xBO~Z'GRi{B)+; uieGmg;\2Z_e6'hDڭ!|'ʕQϯGO?.k^Sr]X׶!D5"_gLDHE"KoZZ3h"!N~䀖Θ`eN !mݦ/DD8bz#@W[R B/\ML:$i #ް%ް>w}J Q# .-kRl@1pAW 9r`գ/q>Y. s-2#1r nOS1j} 6P/_! e2$3?H&,ZwK7d3="fb(y*uNFHs%0xI GM|Nmu^)xgD+:9ٞODG+*eyշO}݆x7pK0HUq+C+rtunN rrdm(-IP$J+֭?k_yw2"(5Mr@A,=KNƇTˬPsz eyUkүՆ\hi>5YWʦ#%[n[|ՂrdؓqXڢӺ?vgIEX0;&H~z@S1* khMm26nH 6AVn*~A'i]]0ʕATya^+}'S^LPΤ86=iM'f]DFKcEEBNl1<'N;׎Ts v0~,ya<4}#SimXd,--zh"H*fPXXǖCX}1I!i ~M:(8OH! {'Ic& nKOIȭb-^'H{ɺ`FRN)v8~Mlx9X._PE$bs<|"Yl`kCwG * ? %RD5Gfr6\z2ղX.1(g'Ћq._景^USɸ$?Neja^bgy&;>xď?0^w:U㨏}M`{%9H?MC ʋ7k5Bz<hv`Hw i}aú.?~qK:izx1KPatw@Il>  )m:;߰3A1X-ihq ڄh"8pye $#Iߙ|S5'pfP5(' }h~HDN*oQy k!}>Lkz_f‹8^Nv qvXҧ,hM١eq q,ma9i\;s2@}·#bF;X>MJM'ISs6iݢuwYyMP3 s4[S)-ĥfY#i汎%@sǫ^n?w+ M2i,xVdK|%Ւ&`BJZ"O-JH`\6A$.%<:ߟmD[Dɏ<;ڼFkbNxWgӯȯ>A"نYӘ:o͛Cd qB'Lͺͺ$K\[תI`'Lf;nr%؝E#V, aLٱkи{'vɪ*qROƍf/:Ra\AHؘFj ɅLE ܔ \1fDFF:o Yqa譎,|@%SBqt-#`:/ucahq om@BQ 'Ӂv<\̍)l $#*d9'h= b\~{q.z?28xRF ^\ $}I1Lj}ж?e?;RD|ͿKcy-.Nѧ+YişbRi@!'uv$II=EҥCUCt%nԋR I00kxC[ noջ%px5`Y6%RȡF;~{Td=AJOX^*c=.֜ ۚ<|,Ȓz@'J"/щq,!ncmZR_kQ 'aI] G 1U2 ҋ,(ʔd(˻]ȟ7µ&,RfY%1my%daV%fBIY}@y"F]( $Tzcpuvk'O8+9fjl#9l7 Jν_YPCEb7%>1#q`FT}vM7oŒ-(T5+o$R04qY@2<5_19:69b7ɚ,%uj$|&Of[@e><螷uGʲ &j=u 6ʨl^UG)hs[q=Ȭ K;jSw. xՂ뫭V R -.HE_%(EIC ks)6zH6be:ً_=iV{X#924)1זϞpLbgyQ դ' TA`Eg4 M]Nu7_ZٟEjk|Tl*.E[xVux>\{G~t=.dxg^iy# r._S$6]E2El0Yگ)I_"PExy4/m) 8'叵pO Ђ NC`Ɖ$qڨ+t.<>ikOR'k-ʚ-<&<,3XmVT/BTw<=~9"y[>\ .-fYA\mիΣo^682cmAΓE$A!L *OYNcjrDUjV6aۜ" CDB@-ƺKI>vG/T+dp/2&ͦ>G}OIn2~E>PHDkܻ> NR}s`Wj<~&BAe;^BpWąBLBOBroIUm vʢvhT@I.t޽ic B⾹.f ƫLMݭ2S \$UrUϪbPplNFj9A6UaOj* @ƃ9hXv`ssSoLaC޳r)c6C:%"B$f`$0pV4@l3)8)]SYŃ_Up_\c#f  z5 -EɟjKj U]5cq8FR0q &x& d/bN",=ChDrgv<ӹ /. X=t0/՘&f v/۰[YD,‰gP#:e>sToy_Qee?_$}fk={@|91gN{jeQZ_[WK4dR*o![;7~hYv}`Gf,䚁ʟަ1M& T7%WϵBϟe[UAi:Bu:5kpxۓSa HSU*rj:d]PFc-W!v'آKVm)<.ŧΎμ6 nyvry C(QɌmۓ0v\":۠Q726W0x1) CDXu_d*vLTO6ydjHq9YIU9?7=P# mU4Lr^1 l*>Us[=e=#G<_\P>}&>CYҥSk[7cAU׉\薰χ`4=B!L1q#6QT Rl:~Gi\PC іӇ w\V,@/`ڶ0 )HGq^ MWm zPޜ)u*}5 ~!{:0i6M@sН}β>>Ϯhr1 ٝ2Ъ P* Lm \PYl@ !ݗ*n$ݠmUFKx$e#"/=[Um A <)?red|_[POŪ|ZeZx#A{5UL_YIs~JXe)0B!)=/nk1P5hvQ,뙨A3 j~HMMUl2fd%ܽI](*8lD$9h{8=IŎl7W֥e~Olɧ GxPP6;"?n.aϬ\ۺϐNdžIcJ3ԡ0*伪*MR=px9> / B<zH8Yx/enCR*LhPP{C?1qӵ3l-`!(D0xO2 7}r(~=9>oҠP?ܹ)@N0 +3c:~o Ů j-&5+:Gͅ\l.0?oFj@fO ifJ9΁ Sy(6|Haw_f߫B0ár~l3g-d,uY{iB{x,:ЌX*h@RnS}8+cDX¾/!8 zS9܁n3J3m( ?_C0-^IK08$JEPXDJrOV:3-vNO@:Nvw}?J`rC 0.'2Vi>{Jm@hTsU ]~/┏hk= тB]ڰ7+}>"~l[-{|cDQ6$M!Ab|]!Hŷx,zhNc723'Z,hGC-,}cM bŧVۛXՓu~Q˴iXJēIB ʺO%4J8CNi.>͡A$1i8 7G2:jj(JAaVZK{iyovypͮdr"e*b@ ykkyү'm4Z8ANWpه'pw K8SXP 15_URm%α.g⛌sʊiZA*ߖetܭӵ)*Cu(>ʁ#<<.JvӤK茲 ;xm!6cЈ$Q۩o*bN1 .LjWeO0̠>PqZmn>Oʚwhh{0 )_袜_H2~$xӕTW J4.ƹUF)%q010>"R/¶#~]gxRH/ 3AT$^K"0i~s#JL.m},15ȳj9"qo?-3K@( ScПX*`U'M̑ްH~;a!Y>,Lݬ jZu3Sk#o?+XO^۸d*Bm聹=&ʾWvIֻFÖ4|7%Bn'xU؇FF<jFWݨRwM Pg- ART[Z͔Ou5C"b,av{qlFP`9+XE͔hS/ G)?"\݊045uX*(2!LJ'؝~4ԑTg.;X 8IHBx 9.~L5'_qi>)m+xx%{y*Gow4kB&v"{O3Ab^+ޯbOyQ -w?}I w1KU : '%0hȵsǗ6o*%f]2F&RZX["N7d?^ƏKPWQ/ӻ~(8#֘RS%2^Wχ%hB[dk[Xm圦{!\_Of++C-l!g`ۊ$QA%|ވwqXsUP2ofoZ$(6e1;Pɶʼn82z}޾P]6L-9L}`0 2,a([ã[}yOǫBbJQ(@a nJb5iL$<ٔRss~wd(8clѷ b[Ϭ,/.5?)KZ`5so&~q ʣZE,?ǔk14xxlR.e>I܏_vPEWHeUgaQs6[U'MqfVRu㮏ak_mŒXXfۦ*Uxr/L;7:ZBwޟNw,Ea=ع2yP-6#D )&6$4xv UEo[o6] >e.$LDRSR6UV/2Wަ)"jn-5h*7??j]lBÈ%44 / >-)yQޚEKrEI)nte:FivؔY)gV3Bq^*,j GqPC9{vTK~BnyJ}HZb7U0Si@;DDe(7ɦ2Jlם/L?\鉜}@n[a+vl+,O~ Sɲw֙g!:^)8F"/ pR5tH9/R@l.ut^&8k@oA$[7۪RRe1"C/hđ=I|ROoE}@"3sY-WZ,$r.HxVƻ9(YGAk,nVĎW4K\P+ B` T\c0u-)47mhGPHj.5c_a*ڛ?4c&T7$}?{wJ=( w0jĞ,mD_Y~6E='u*|M0AcV9\$#[a'{|N|>Q#_/_.uXߘJI .3[1lT>L)-c#c̻ w0^SJY66?5"ϙF0ӟNț.#jA922yѮ6%zJDk}`qQ0A7V;o BM21Ō5`nmMTE8V&亯WEk[^M+)^oBm$NglbJz1 fsMTOޗ~bPoB"0Ey7.+̡3\dt}" EZ6}2dXziIvL6zoyep@k(;@j.' äW2fXQJAyAVYfR|'l҈&65$,&=rTxY㇂sXAAd^CÁW*,@o=rSم6t\)VHz'XpVex1xS9=\O. m`9m;1.MZݳT/AcJ Ċ{~3M;Ƹ*C3j $n]oAGZIMa~9.rM #݅-FY 0 J>(/,'!!H$ԝ]qvE͝g&D@pv'hNʁx \ND?2!>L0`6TByiZqR:@RTЁ VXCL<k'3q][ƅdHyyy_H3w=T8{XB7q|BYV;{ (dftśC-:i^6Gc%yR'wN9ڛyq:+[h̰dugkaSmpim5AsRfI?_Nil,puk_!?g⧟ Oz-/vAw1@f7o",*+屺s{O~/JՆY#.~a8(& FSn = JBHIuaOV򏍴ܻ-5uಿRwg@XPv{ÝkJ\Вޥ܍tp )b3K>)e(2Y%z2K3{g;Kn`ː0"Xr 7+LfɺsGW,]}p.SX$:{8jNM(*}tܵvEց`.$. $pPNEcGg yo0$/2t[Ȗ&OK 1TOoLurA9ܫUݙC k n/-w9M ބ chBXmrhWrtR\wÖ]PsFPմ(ܜs>6i8_nQG*)@y)3Ϝ(I d0Dat T\ |B>߆djKy8 ]'eE`R7r,N`LQ/Iw 1\}=$Q`up/XԤoARIan! (]o_̸[ų]˵| L;igdm]&r<Ȱ֎6U8G+k5" ^ Xi€THʛpr!am+\zK}vAw-ճH*7{qw:I%̒;gp1nNRi{ GpG2-Я A9(ߙC140+O9,|ZvyWGN x+)f>@^k^Uj)ȿֶLh931AOLp|мz b=_$"\SU1f#p@ n~^^>"#/p:۞MףTBU(<[-*K1U#eN'g)UzB~]|K}俸^kp,ТXO@uOjH䂪w v eh: TTIZF'NIOCs 1Q(#b7|}L:1~Xغ{G4"XTxρ%F͌y-4ӓC5{؍I"' ɍQ2~wJ"UĩcL-=M")U|ct]g~8O3$eMѵP`3BB0'b- 7aN&v ≩C]N4*yx3I0HochT=FLUfū|pWfPQw훂i3D[*vm@VA)e@`j1Yl s%!/h7tA2eW}UjufϴB)* GLMtst[x? ֧8MM!_c? -eŞۇ9.|*/OR4dGFγ| ԁXg PCaKoD 1 sW=g,)u^(O{hm:M-ripU,~Փ~&Do|=z:/3U\ n9i0.a=Wb#ccXkw)4ᕤhY=e\l.lM,g !\Ht["(A#@)lGc$7BJwEاmN>Cc-椁"]qĜ~MwF\)u\~$og\ӕ2ٌQ )x fWYh9Js,EDsp t34?UrY|wo&6%(O 8͖HF ȉy4">r[Vʄ^s=Qd \ RUv~wb#.1QV^F@/*U7EN;ng23&.ì#Y8"{#N[gotV qL7[td>YW (ܯr2/;"4ϛ viao:pCQ£Ob'!茉~Z[~V$y"'"|IKXO_3f>|VOk P:y Hgh摀7ӥ^ >6k8Qh}0~EɁk8iʚ7 ifʈްWlFXЎR**N'z(B5V}>面WIoI ZGs[yZ&xIfO X|j}q[ 7TytdgZWcjح2onH:/]RzBVr³uQ:uG%S4,u8w?\Q&sTyul ;А?#gg6rWRQo؊3ݶ !pǺUJ\iQ Dp^[쫅^yh30W'1 uH<뚨vp( H(SܷD=#)19(dj'hwaP߹ais R% {ù@YFJf*NLC%-Dp%kEe@gPbjR?!bvyRt'3{kr ! YF*NaSL_W\MhW-tld8e=ܐ>F`-s'F}0:Bΰ"ȇG? _?AT/hpsȔC?HQRy,%]9F.1SJC Wc3F>(}CD"5\b9pCޛ\I`\Vi$έ؛D@/+E͑6N$jYFfͮ~#¬2|dRLkKuaW c{z{hXe8^'ʂ,#@ZJhaofc[)H4yJ,ߐItLi8u0Cb}L=89Gk\2Hj=Mr;4RÅݩ0qĖ$o3QL!XKftt6@[-xM`[`KhxC=黑ãNTS U V56@;U*R҃=j9O8GKh}̆"J }>C}?K` gů|HP+K [X! "7P>uşa|ErAMVESMhmZTeF+-Oc`'4ONnm}<  8=أj7prC(B_}*7Ô (o@L~暦f gUFbmu̪6 ݼ0o8 SfAS&.}Dk7]d% a?窘v)i`rrpBဋ9}9 %dYG"Z^T/go'gg^u@xLצ t1 =M"&1tMcP-pZ\X/ǔra|b?vcӡ#v$qtQPZb?+FUYF3&=;Ip*YSJ% 5j@:T[jz/#mټ~^Ryґ4 bC \'9'UN-JVK@Qޠ\yirSIA6JJИC'ecqFo|=&+1^Nŷpb*mF88* <xYb3wE8:|s*lw$T%` $q#xd~),> aJ,mOqPw!yw6K<'+vr e=¢[r5iuVvX -aHvO6NR>e0z -}Q7a<>ܭ[]x&MIa ;{ a&%Y`^[>!n!I2LԎlLsGp`_nj Fd!2@ukxǒ։4M12F"< 3 et%kI%IgDZWng@趯=>X9O( Fth%cjB}:G 'XtEF[ogR6T>S$TS˚~?# &v^ݎ`U62'k4U.nx=ߕӠzabӘwjVYE)I&DP s!zD UKӊBR]X mBi>?*\6"L&1L'R(߀e+a1GG3iY ;ᚔk5Nd@8>]-7. qVGt>.?cde+*Wi#-Ve2 m7s5{Ll4Px#6x ,&#:qLa&â=X3SʮvEsAZg|ݛp,=\8ռxdrE=Ұ]HB!ͱeָ)H2l[R#3h=Rh)s8q갵QW 1C{2$6!̞bQж$żt~I7.U*Y;Bz:O C|S Id,wR跗9?T[0˝t wx!"wz?~N4"dE]t#22kmשHz#j)oqzf#^L&1.h0M3)$w]>jU[/4mR4Ztt`RDLjtLЁSf{y&E"d(& T좡Zn QH`= D[y7Qr[w%xhy)ϩ%:44 VΩ}+=)neTjX'IT(Ei"L#!KdimH]ii+ 4(gyfCquP?JmZ0 ]y΄ӛ'RW4=P 1L}&ìnjG68 nr\VR^oB5HHu:2KƯ'6MnƾyӏnˋNʷy !C)h V)dʥߜ_C]?< ږjҖnH 1{¿iz\DDM+ɟ/jyVV$ݥ"=w-An'~p;boj `%: f-0v7qC &M_~ =/ls_̈́& jCOc4[mv 5Kkl'ϮYF+~+%B49\26T>$Jx_yHs6>Tc&%ƽ4̸vf<'G 29hXE· !Gcoʚ"֦c˻%eH)+qeX|#.2VǚV5qUJ X$*LHze䦚ffM'XT j\V"B]A$#+U<(<}%ρ.sR{:!qTiWr {th^+{s}T=V lp"B.ei[V/-q/ljuҒ4O^QۿEklt)-6$. Fc*r s> F!8pKMٻq5obPFŽB`&jizcrc7l)3[XTqP;fJ)鐗;ksE2)nu]a/[?_0.aB R]bPx:)`ZxhMü* ˠ 6]=j'`hbSԦAEXYŊi]\6c(JҪ{˰1ĶEѷwN?O^۵gъb6gB,Ҁ6P_µ2"~lhaN:사DúsB ):kCS|Ԕk G dIbƩ1P,OOGpzy@ μq2^M./am0͚Abzv$DT`eRL4E\0wlftؙ&Zy@%I'G HXzԥy,25֒LN7ї}Ye1d,;b"4o_}#s4;\7Zv\sZꌛt8ɕüw'8K*]5u)J} Sr$5A0AG|vh`ۭ2F#xm48oRnst`e3n9jD;wēFY$*t^j wm&X!8f1T`,:?B'VOmoe،;iI*(Ÿi:M2N4.@6PikbeJp%CF"^_nxM \݉Tmco\an? mV݅jq 9ϩ/Phȃ;ɉbנ?+~GΦ!RKr3 ǻV,RT/@yJuUBnaePl]y#3GxإR<Hh7.vԤFؠ{Yo Fо|Y?3t'AVdijRwQK{LYX,5tH^pynN+O)=0D˩rWZ9A}lԧcLy`\l Dh~DU჎vU *JWAyx jaݹ %T7'%-78ƃ;-i|Ҵz'Z̤AYΏ g'c R:P"4uО;Ca:Q`Za=9[Fbg Qlْ/Gce,Xo5.(mIluUs B,[]C_sMex:a,#:F^F.xh"x ӱ2֦"x?˸q|C 704UwƘW&VlaFl]E`qtX+PS9 ’ٟXLtQz~e- ,U*BSgXXcHV|QZ^Κ Eq< '>NWPivoԣ6 f.tˀ 0;9TqbjguJysv0 Adدo.~jf:~7&"EY^=;cP A+ƈWBשF-!9.ĽhnvjJ+ 3G&VR(/es>؃oN̔;cab`ѩLAqҰᣐn3tT|6yfq~?I+]H?VM`={?t?l#>.cu>1>A8wi 7 U-60K JItK}XR?&3ȸ' s]6w?\KO:hUdښks{5ipv~,_<v3ofmuLsO[,M; ɿ6́g+1UgUKS02.$btUa}PZ&ҡgDEfo8gth^b¥@p)ɰITev?2KR%r.w"G5 n^Y݉O̾l~)>^F#i,O'Ŀ'}u-{nC!b&ڜjbA_2T'vg(g`mQY>a|jÁ/.mTW2t{7`WdEY۸'|[i^xر:ߤ{9wBݿlsRY>n'N pv_>V#AHLѭ`0"ΩAWtwo_+#G8%ʇ4Q'-D kUr`t4^77 *$T2FDsd^Xx`ez&EKG=[ӕ)P*jhv9ƙ㽫CB< `VZl܍XF,(q9JD,e2inUIm9 n"5 kg.dvTzlb YS2(fuRCNh|cEܯ),~2`.<卯PyBkl#ɖ_6Ƞ\z(2uH\ .x}$F(uP7V-(ma=(>U+1egUwN ^^Pl[~TF)uZޖ @:9&CT 暀Rk8v _ǂ}p 8'=[W^5WnE8Mhٝ)CvV 8hK8x:d'xSzX`E>.siI&~8-. jfqɌ Ç{ PDMEH%T*͜LgP풩蓽:™Z[Hk{=#PkV KTe0͊,s5I˞ zNj6Q 2۔Cɮ0@ CVJcv5!ԩۅ_6㔴0Ds@ w+R瀦9H}ZBQOē-S3h-ٰ\NK_ϺS= )0/ix[ 4xt,~$Mtl̹F.WxIfȄBE,6{ZהŊzIA|jB{w[;ݢy.*Yf xMβć6BCYy8@{e,fNJ~K{:U4\ YXYPO:hgqB=^J|Uv5ʷުQQ2g }?IwYX'46ͫKz8[ J,=T[ފܾ?Ԍ2+l|7n䔉r,VFrtEGvnҿ_sr4/1'|ɔJ!znn wMJ5=\J~I=rQ<ڒrKY![1"$lLhanX/U !ūL.KRb)ŭ)@\E=X5k'QކVf"zd聰S^_U܏umDFZbX͌W&}!:vxW$Y {! 59, F*޸ݚ F5@4.M^F`},* x;`f&͍V_Z X<~CS\ [Z}ߎ%pN bM!'.  2QW=?E *orakVЧm5Aa^svn??Y*\U]k4zZZa_cȻs4ٰ4`6񐈧o{*5!1Ecļ콉5G&?G,Bhg!Thw.o\@-OpW TZԭINjg[* f_h_:l=qc0jZ.,*_K2&kA) a^9_,gҗÆ1{K g#Cf)-q".w1Wf'"Y {.ȝ\I>OW4 [=}J?9\S fZ<Λ> j}6c/[-6'vZ.sh"`pZzHLdTrupQzr5ٚ*)"H(B*-Ϫ!#x[L$]_M녲t@:,W,nb?X)E#7jޭr`;ZAWzEhrkxkDA7IY8rϋRɍm"dQ͓sl-8?BrNߦ{Kg`_MRsk'}pwGNf"+{֕kZ݃6=ALXiNyr{A 3w̩!Rsf !i^ųמtseFD>t'D_Ǐr"r(xh+"fgu~Ϥy'[!=4vH96@NdN-N*^g^lf4a•6b^A pUŧ$82imiU)ܷ2Ԓ ʽ_r>{406 K_ ={:n] plcq&s5?Z[ ;M3XKG nYj%iC ^vĦf oY͋ρ>gT~"8&#_!۶qs9`yDd ]Y(/mVe^ ; NرX 4?w"`lLe|%fֻ T-T'ಳ6;OYmc&XYAUɨd)l_82Wnv% ""<o>SS떦شMW&ڻ:G@Z%Cx}(rػnF4"0~]ѱmNǺGI+a$k =%@ib+Z&$pF*5)GHֺL0s>&060ן.<@  U w =[X>kbAb#RJ_ZN_Sp[ܢAٳ8j#jfTR4x\ɶAUC&WP1w!FQ]co(n7 D|T)JvF?KWJUMӪp-VD_Nױ␧w9Њ=`J|n_uča{+1y/2J ab[tˉuEo?QQqqtN2/D$b!BeVa&V6"o8pbϻÀ;/va^:)UΫKA5MM:{ND"kGDkRFU;v" ?B1G5As*`<KwFNj-aW\F\NǪ"!Rhv ò2N 8lA/Aۏʘ.qv h`|ESqPTjyڎvoWPi'qIm@-qbJrV?gDVޚ8HapCإxP.J"'׳z|N@0If>fJ{˝ @GF蒢NKE-;pJɳ- Z/*İ糞#PL|3~gz{ ,kfYZ[0N'1.mmD<-/*%I UD~^ bG C " *o-]gSԀ"+ǦVr4oOMz;ùE&6|f62_I;2yľy=Z4d%3virχ_ycѪQXGlAT#(۔[Jxad[k`-yPu+@[o/usڀ@~U5͹w SiTKIta-"x gGuU nZ'uDz/P>*&~G|eEbTZ#/hR_v\m&zvAjt,Νr" 0EYVW#Aaq+‹ &VU%tFC/KB WϟxJ3[xT Ԥ>`GVh(q#ܫo} ]ޯs3UDhNMXcutX=L4-c(HNQ ^N ( 8{B٬fwcc BB`me$1׆/A[stKB ^goFs L^m:90-׊WDB3`eSv)OP*uRF 7( D; =:n((JrP({ǏG~/0/y39V>C]gC'Vi4ܛ  gxN'6DžI׷s3o@F)L1sK:H]溒nHw] KCw1L^L= &+ TSM$6|#KVvDp#V2YeǯWy`P*rS_`!:Jm&9$ut{˴w8{bDA怮,H W,u冡_SF. ߙ7(ЀkI IHNw]&r Se_\؂fPt(ELԴ! KϘʶXbYoϬpHd(s@бnL][.!\IͰ%p„3dtk,ӱU%LR*xzS,fkp >w`3UD3.@_|ַ5O]U0,V!}_9q3/'3JUHPf-$q/Mhuku2\]Ykuh xj#lX$Ѡ USL>H5x CN)w h$#qsAvgjDP:ٙ+܌ y}Z7*6ʦ'Hd!4Mϡ tx=W 9ZFdzؑ٣ed?59B_rJN\a02UNcX_T'Ʊ*o>VG5FWQ/a.JOL%sY>^jaICTHSIK..a{ y^GSanl_nnCi5. `((}N{ z&DރK%.}Pj2;7ȚK݁2򳡙h'oi)DHfN*Kj3B%Eb"CN"F!_VX>ZOZS8"Ghl#~ !|``4(242y7=X135څP))ofM_z@gX&x-g3+nB]L'KG&O /Sg DVtUxNAo V t' >Gd0%9FS5S8I' n:$"j!Aҍ@*忆 rOif+z4齑9A[CGsrtCMg1 Fԯ6`P g[2q<_ ם!K7CDb*J_>^yn+n6Ό]G)ubA0Sf<@YyJI$3 j%e)-qu4VK^觳1EcR%k V-N Qu TsƲw7vy0/'FAy1ٜxd|>gzku: ~+^uSTd+_6i*#Bv.ITw fS B^fѢ :߽-`#M<!1l,*ph؟WH-[ EJbr!E286p[b2*b; ^q4t7T uwXwjrpϺ8Ĕ8:!4øwK)qV+6sNrEx6 jY}0w^TY~ivmFAϑD8*ЂZ9 tmLTCK'DGOE3Ţw\oG/T a g&ұ%1d,2.DcF bNi pxQI @ H`"6;i'tTS.K o2=@-kǑuj}hۉQ0Nο̵11Gm$|CLq?gV7L%i!D & 9S CL5Ef䎆թJ(m*zȟdSmx=[+Wu",բKܑYnKN'& ?+pFćM+t]N}}R XRA‚Z@43B,-+t@iv{tpBqz㊂P5>1@r^sO˓w Z keǕ+Eهa><Ϲ&u!3"7.ӹͥ j4H#Bnwy .rAA)_8Q[ze I0@%&6J.hG;Ӆӯ1 3:ª3 8 !QuV#OQ<%J;A|ν7Xm$&@\SB7?R4[ۻX\p D?y:و휭$+xOSn"~,/( o|)p@gM nYՠq완+2HcJa~Iy6`kǢ+@[%3'@PLc@5ݩb<ꚰoP&#49[+I3Oww&)yq!R&ǭsݙL$Rv*禙"+p8P8KCu^+)ߣ",*ٻIa]d<*J7pyJL;yJc+NeQr‚3-@|nuNXw8'>܋`q:9ceuljDnn 3FvΨRƁzd*\ħ6'䓄9A(؟Z 5E;lv[ >+ G晏&6zAXTǷp۝hbU){9oLHgPAC["q64&B_/xԡ,Z3rvwIB8P!jUJ$A, 2ovYPis%q' d|PX L.g),SҀAc*s.mx~x1uO5PQ]쫒i63 3{VvS;^OfJF75 PZo)*v @_ý;N+7sRN%c|`|2E/ DlOüBg=ofG Hv!Ny?O^#MqF^򟑎uT :tpc [^pFLRx 3 !(:}s{yyb⥫fګbl^eX*IvD"ͪ)>KLB&Rբ¥*rHb Rr*d@mc{:5aW̟۬y)[lѱL.h]p>mBg\<"eo%5+ LcW_R77`QeTma# ]J;lbl ӸXr/~Gr߳7!5^ *6)nj J@xU667ƃ%t)ss('G6g)Ӵto-WTMqBDV>;߱#M qJ'1@Nz<< #bm׃ (bX3F%[)!T m(4_GH]̶'H[ ؏+X 2%ER5қC+咕S94RV =3m3D{#>*;FsF>8Xo4RDa-BYb5XFr 0z 4n{-2@/x"^nOES  1XQYT}6m .b }fLkEtb)٠kAN2A'* &5U_ ڭL.0`>4^CS'߾+C0$Z6ؠ##MP%SA7CanzL pj(O5/8J-UNv;|NQȀnn HL}5MyXG'¡Z-L!%)Slnj֌0*/)닱Vf[tfD44T]Ѐ"; C;|3Y;Wu= $أ>` šs:e^V7XS1O_v=Et>8ȒX/F98Jٜ0MV|0pWvO3wF1ݘ*ywfY:]!wCR7rIڀ=;*y[@_.iKAP6RX -)A`m36&M'FxBDl(ܸ|­!@%>R u\U J%@SÂ^&@,ZƘҏ ..,˶C?F,'歔 RP/L(ç( [=! RP|nwc~tD=Ko"x !?`&Q~yRA6A|x'Q`=nj֪<'BiG_lɥafF9":a%l? !Z3tj,`A Y7- EL]g IDєeeT #:mWBhL.5Х<7p*\<1Z&u/0n#usRߜ&`X `2cYY1D+צDd 1YC6RGP|-' Dܦ(~htvaP*cZX8ᝥ }s{w/s$*Lf  `{(v))hY,)ے!R]ԔC. #Q󃟺7Z_G`we0tHs}ǝ0g˯;F|? '\WOpK=  L5PrLرKMϏVF,ʔpobsn)VJKCdt7 ))A)x0)FO_]R#VGѴU Q\;/ ̠z&\䝿>B 3WJ <+-#F" `55a-ObK: !2R uK%aR׃p̶_H=.A!jV١>*uNgvnCFJ=F%0N'Ij ^n#Y`_s\uyijD'H4>`J,$B$oVڭ~"8"pFn,ׂ|&`^RY|/*j #&|W=̣k}tcZu\'1EYBR_d&D)UF4w80=d?K;QӕjMxE^[_LJɶ̈uDCT|3Z*$ ǬZL*ѩFzĚq~W/X$rDނsKO|eT/2q]Hiӊ[ruTװ@ς2Ti67z#06(s6Ƶ`L%vf& @~4-~*b3keB t9i(0F"8ӬPS0"7`m6ޏk~B >9+c ڋT?blJMNAa*^Hb1!YA_D`cNM_nW `t&<<Dž~(^S Nq-x=q79;ux<]~A-UB:(7t/WQ7{i*Uo`8"d!ps8&7J@"/MPP2߮A/-ٓ7oOj6]x~6"O?rHb4qu9>v+bmp,^ѫI;LR0R&ߚmlt1tS_ l/ڳtu) k(*qãJP6+c+QoP *2Rr+);X *&n/rPwA6wj% Cm\nsˬn3Jqlx炋G7 _!nzdbXvIz'Y&bnYC(Y4{}Ԅ,i{e39 #(Љ2xS)k{tqr=9U$hǬfmrFAW+MP$}'mQ|- |6ꦄ/鋹Ǻ&[ 6SP3 \\'GNۻ)b oER+/Ǔdz.frPP`'tByk僻g4&L|}oۡ'GE80.F@҄Ҷ%m:qJۨqKu$ΛM(lgͶ=@MўlLb;,kȃMQs (ML[ oܭR^;H_:|tuEHیթ`|A@A{q}?gw;> k6.(VmXJR !>+%A GYwyث?$f'k6+ `]U% cه@ l3>}<3y)kT(C ] aZ|1~7[J2n^ge@4`(YNv>,/nvQyry7;%B!0ptg15qOLV4J!T$"ʹljx; J:C ?\63dBBp#LFG8=G}O`<{,?|fv9UU*VJsӔ-3B7I堞Q3 (-OKtuZ"~A+6a-pʧ6\%?LvcDIS\6W?I .oyغ HAE""<]]PD]^9/*}0qY}֬sb}mᇵ%]o:O=0]̋ѱ~Mkq@Ev0HW.RMX 4„@\l gRtx0W;FY ڙwܸ?WX c23ڦmU+{}X(߃w6Ͱ/&@{2Db߄b) Q 0;{D(: U A5AdI%d)gaE)1}F.F_tӻwmβsRCkzm}~HZn JBIB1/VQ8R%*4Y$l2T= D\7v7RL%'XP, n\W&7\md:ё$?gN|3TĮɍ` 9159c l?,MUnfh?qx'}\`Mec<7S۳}Z\oK*9 0 u>tA9mլ-ZIIB/T֎D@ujPٓ/9N]<4X}܃k#^ͷ\LdyrZ]FHrCHlFDa- G  d 3tc8;q,{93s'v|[0' /VՍtn* s+7JPɣAZq[ڐ!Ϣ7‰<9dq 8Vh` =8jv{8٫!TB]bF%lU2j3ؗY{ZsVSᥟoE.75Ѻ.ds둨̆~_D3A@aPӔ,iWs6ϫ<ʮ+`ܑ*{X6azZq.bF !$hT T{TϱCH2LC]cß\z֥w"dgP\s .!$/d2|xC߂[@lyLsibsw;$1'DA28kn`p9ΚeeRGjV&n!h(cXE~oV?ų3G8PoalՉu/X3|@h&U7Y$flL(cBҐѭSU1ɨmK>.]s^9p޳>/[gl?iv3kHةC{f^`CNqbEFs:)[%Z_Ź)lSF3[~BoY~1>9:FixsX 5AxxЯ/QtP*lvj`:ǡ\%Nɨ!,?[Vgt [YѲhfG9e p_/K|lXYP̑tcb@[*F'ux(8^\NE%@h6m T`ߣr{=.AOG9fv7{lԬ#h2,iW^첱 Sh7%< kKx9$ḉ8\{ɨRT߻`\/j ai82nZ2JiN pj5}D#'$ oVL\ɼ0Db`MN:ďG4&sÊlX)1a.^^QDQ亜3un P3m!u\g|b34Ŗ(Ɩꪌj5;_(9Bs:lSoZ1 )VzhAG@RUJ06ZN*3p ve sl{ ~|3D-KPߒN;H&l\!r.w 8pd9-*SZdrݘl E~W>hL؟iFY|oZi]RXyKCGշl9 N}ȳ >[:t!'T+Ee3!%^JS2*8*Mar=JaO \ԡK ܑ'l0v7eդ~ \||JD^yI+Ac! '66۵t9H-HmR j{ϟ24Φ_dX)\,b S~/'0%/Mg[z*Uom(9__M5LDTcP>ORcPG9VzzWZxl;,-#U"~Vy0p"2A:w餴MZ#:4[A?^_eU%`q.IX~\`OOPT.*"aI0IAt@l揇,M˞p$m2{n[6m,.҉+՟ϥ1";fg jJIR|GT 3  ɰ@^QT]j]ڗ|v:9"g(~-NZjVMVOly{hƄ ՟լbϬיIC8TR0^[,yA*L72M$g%O eཧkVLTcW*)8hm$BG߰akE15,կ :7/n8WdqLfɳ .ū-H.`\DCƋybQ,Apzl({H>Ma_I+U75gN?D@>"~`8:k;Ԕ7p%c\E^('4FM?ZZMqVT~5J|v(0`88٢*xYgk(}6t^l4:TWfpl8HˇGGmRf  "f㙶 YZ