sssd-proxy-1.11.2-68.el7_0.5> H HtxHFS ?*}}_IxGݢ]2Aʲ=HBvNze3Ps֮54c1f604a606c0d6156d6e9bcc078ad1b526af6aH%-8~+]m݃FS ?*}}f./ ꙐS3~0S+'*|0Re)><?d   >  <BL\ d l | @ DTh|***(89 :<GѸHIXY\] ^VbҬdqevfyl{tӔuӤvӴw x0y@,Csssd-proxy1.11.268.el7_0.5The proxy back end of the SSSDProvides the proxy back end which can be used to wrap an existing NSS and/or PAM modules to leverage SSSD caching.Sswsvmsrv03.fnal.govScientific LinuxScientific LinuxGPLv3+Scientific LinuxApplications/Systemhttp://fedorahosted.org/sssd/linuxx86_64ѰKA큤SSSRqe183795a491fdcb4ceb101e5bfe91d3f006e898a4ab51ff89ed1d94c5b99a822168958d5eb7e479b50424263448463ca86e8a39794dbca8e253cffc9e5b37b1c8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootsssd-1.11.2-68.el7_0.5.src.rpmlibsss_proxy.so()(64bit)sssd-proxysssd-proxy(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.11.2-68.el7_0.55.2-1sssd1.10.0-8.beta24.11.1S|@S|@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.11.2-68.5Jakub Hrozek - 1.11.2-68.4Jakub Hrozek - 1.11.2-68.3Jakub Hrozek - 1.11.2-68.2Jakub Hrozek - 1.11.2-68.1Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild for a proper dist tag, yet again, now using the correct build options - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Rebuild for a proper dist tag - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Squash in upstream review comments about the PAC patch - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1098608 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1097323 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use lib64 in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)1.11.2-68.el7_0.51.11.2-68.el7_0.5libsss_proxy.soproxy_childsssd-proxy-1.11.2COPYING/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-proxy-1.11.2/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0x95854d669fcba84149a8e6b5a4d56af85e8fbc23, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=0x811c85a526f71e08038c64325113fc800c5bd6e9, strippeddirectoryPascal source, ASCII text$PR RRRRRR'RR!RRRRRRRR#R RRRRR RRR R R"R RRRRRRRRRRRRRR'?@7zXZ !#,?] b2u y-iSqW2ob{ڹ!~5~JմzM虡aUx̻욅lI{+̕|B't4{FOM#︊LW+$dPy?Ʒ.L]S&n;;Gu _\:/ei# Vc3sȳi{ iuG;mˮvK@J$2N]ͼ zdBP/h* |cqCE`^<*^'&];P# ~+(K:k iqh§BG0#uJOPYpY ơk3mҚ8C!J:Yp dGp!0dBM.4Y!+㝍OpdF9X> hҪ(Ӣc26; uD`a($g:phQv􄵰w3HWQϖJB?LEn9{R]-ր:1:RD]܏;>v"x2\w!2O:مu6HXgO>r0H*sp }GNj/klT9MSt+Sң@4h(ĭq.S3h+v g*-t[ŤD`WokE ~]KT( 0p|XI䨌-ص](ܞxo4щOpﶂD^˯ϐ7SYQV$؝i[%E>23̒}|* .qycn`YnI3%7cT _[IN<`t]wYvKRٚ=-H5Lw%`ޡC )19_˻؀ƊDWEF7(̚Xk0Ԛ8eqH@4Tol)S[ O"n 6k'!{و 25{W붍}KCPLd`3m9o1GpVԭP߅ރdlSAT`_]9c`SUPz5MUf.W17JȉWґss. Z._]v-;I> i\mlcݏ`7xn38ܗ;ي~} E^LD{8%퀐Ak{U9 QsU'j1ťLoK'{IK}蚷|E~p$Kp)kgy}<{y%Jb;Mn-rBJyG)9)}rSCs1㜴&f؟9"0=¯\CȔ&I%eewQsƣg7/U/X+KZ*+o+'|10㴈I[hhPoX4C p ȯ,12o!0{EiC$ʎs Sc ]/%!z}]ңH1 =4s6H@no]1J}d28?8frl$IR(uM%\LoiٚU8w;% d3վ14?Dz j1MWji:ryE?4PN ,|gWRLGKt%w# 2è?_ۼScągB8Ӆz[FHRLc=kJWעuVtF UJŽm AFv-ѠL*?H\$)5:-k7#,p ~ sF]q[#e2\@#٘m0lfrw8".Wd&UZ75dތa`w>5T 9'T6;'zR=>KfBAjXyߊ*2MݶY1uiGhĸ}4/ Ĥ"g/G'T ,Cۨf[$ ]&9,댗ѝo}붋Lg0<&3 aN9Y#P!<n|ߊ0;-+RJ%S]tO&MT4Z"F_V<4S e(wfנ_YϚýHx?]ݨ#i\dNm"~Nn- 3"MkGrcm\ѹ4j݇'$Y O&n!Wt`.&ߜxܣ(6W7x\i$Xm0ji)\ik˚h}/kwA=e6z6\KY]e'P~Ů ^:/ՆO/lqs='{97 nV[@~Q~2TEDmOf QTQPԶ05&pCKTjλ2/wW%;HRF@pB_u {Jg+Ղa/!xQWF'd: 㟃!Rf7s2ߏ r*Tselkcͅ4u3 RN1nW6r:4H= Cdɲx ntD{`˃&BtB2} W0* 5WgӠޘn \:WZ`dsMp ?^ah^Y_n|] bGGkiMYc)1Ǔ?kFEH4Tԁt2,k<żں5qǾg,6c6>."gH0r ؜<c}#T}m#vHIZ 8%3N+66;7\^ZMR! NDdO}؞Jʈq~DZ+LM R{~!3|k3ь3(7>RԷ*F!]vѴs4c#x5 ZBu%ADLח \o8[]qowi,fUm*YqH<ؙ^)1 J|fN@0 L W@v.LuWaAqUn.x\XG.l{A2w(wVg&4ZOG j f]k(CFEfewz&^W)Vaz =BtiRse(asiG$HJ .2a|ior΅Hg@/X/_YSОu%{[/sLݽl4(|{v@KQ("tlj,iI!<S@x =H4dq^R#ȟ%&|ɂ"yhF7ފi+hde>$0mx%!9c[QQQt phP{I(]oˌ'y3g1T9rv٦Wt<Z=1z$}fW[uTvZd)W-1:T38*̣!_Kk=?hN/LusR3m%^  -հdUzQd@E˜US%P9O/Mִ& Yׅ1T'B !\T04GuwS|%\6٘~I9oMr.^ E$#lk hpӏCOz38~_F_O7[_D(]f5*(Uu߸wdSWBR+za[  p-s49z[syfcx>>@Ƙ5EDŽHV*`)n0IӤp8 1 ~t6⹸ )O9kI+4q9?7GPEDNL<~@xс[밇n2}&VL$h$}z%c_?+'Gzp*kU!8}Uߩţ@Y&iR鹑P|%X(̇'=,OaAIj!϶qXtbNyՆe=u Jdx|~ll\KR1i+!OtAjA!m!zCDmFwb'+)ˢeE}TxxQO֒ ~can}9KSVJs U##xIB5#yN,teȝn_c/)'qtZE<+N?^Bd8L!K,:y!jD@}9&zyg"?v?=E1yޭN}Z*5.IF B  9rL[&GsY'O;\i<ØcS<$z=*0Ts4W_NOc*xbLlFWOԩ 6xDzU=-M)Xk q7vɬvm~-5Lw@p@J$4]n j?XۈiK @QJ!(tt4A@ re"B x ƷGY,WRUMGBϡ$(!_5ЬS++SYe"a"zMjul_0.N]=#x9CS@sƒk>a<} a@:eQs#x+G^Aus)TQ_#rm@8Tv8۽37B!~O}Y9EοT٣AU/ ;X띛=S.ߡ(5.'aEuR\fz oVcA8Dck˩|6ٿzDBפ"hk / e,^%_G>x1Ō$iD ^V0I0'8}*JDq M]k"!W"̈́*M@ qu:NHOoHYAMUQ#+JPpC7Nz=,fRtrNڗ-.7d$BA]P4+Ƞx#2bNB75JcVtZ)%<%>RIP{4JIba11b|J<@]DX. 7V6( 2XprɵCJq D"NnAF`s!uב zA d?A*[##v7'7\]"ZQ:?1⭓ 2b'EY "Ȇ ?lK39TPhyO=zJgpF0CaalYfV}E_BG=2j` \9Y2 nD:kQ bGJPa(?o|,l)x&6L.M0/6hI$\c>pss]**ߔ]`J?NFUvq2Wm^>  I#QG4#7A 76uR.WHh|.B+;c]z6a@sA^\7P#~:V&ovgzLRŻ1h0@C1k;ۭzrGFXk"0i-HhauOV"y{4v[Z+Dg"BzD|^';fW] )@?ekѸMtNui )ŐNVlPVښ!wC=c,D9~i$wXB}'J؆^!p|$M@V_ &Ś1dN?Nt _ etb̨s1LOINфx̏gu(K|6ꭸ?MYlN縼xglJju$B2mx>ZydS2 3 _0b-'Xa]F2R1xJ<:љ(632cL ^N: 3"3A:c3;uC=;ȑsM=56?mINN^:$8Fq/9 :Ǩn7 1݇Pbfخ}A`\kF<IQ%]Jg}=%xO_R3GQ6|ԭMjKu @߬>LmOy 8L5D`pz 0yZEPD7I&lg+% 'W{=ir|,طM!fTcpzWQ YS? ˜lhgٓN<&ª;;AEs`D. 1<=S5Oߥ°6*#!*  8;'Ɲw ߸řNGY%¹,{5u< 6\+ e:?YӖz4/JPi_rw05eϫ q=jS5ZbazE+ Cnk›,gfյ~[: ?1ucdM Ի`7HXoЕdžkMv$:9)n=(k1^`rU$.d#: o,ڔ`L| G.]!S6g@5ŵ ~Պs@tZ9lfXi'NV14=|b;#AΎ-2L2/:-ǯن)#k" a:'e$0[no@<߭Y =weO=[4; N znӀ/ :PəX0|4[@NT*#}׿Tr; ZeRM[pi6|j& 0y%t! $V/aIRlAK\/6|{?e,MmʔoRom 4BГ5:NP6Zx2L^Z-;{ _H~R7N``gK@ pI8cW6^MT Ix,xAsC\"$ .2mz2Xowhf;/\EQD:м52I~&liyjK.5}~TޡZSsܿ' C= ٹgtli(Yh̫R~:= 1hH /[=U'y af M$oM<ް%sZ `sV TOrصS~? 8 \d+: 8C ΰ@"v< }-詑."NqGpL0:/!MZq!&֥*`H{,0Rz^d/Z0 IzLL![)0n'yuITJ.l}22$䘤1^;"t~51ho!)Rq(F5_ZDg*{"q#S`&Mq2S=ƈᄊ:Z8[k/_g?hX@] ZGSKefM$&*)< ï@S_.`G9< /hpO-{4~MIܕ̘a=9`h("|AU="Kqc0)@Lwcf|$ *X%Z5N0Wr@ch}8|y'-";V=n?DT,UjD t܊ձ0OLx".y >N9 ֈ&` :mT|idV Dؒsq~Eo_W89Y\IR9|u/fQmB/Sk!3" c(A^sG6cC~ꥄAm ՘`-wZ?s[=s^gkJƃBbQ7L\Q]{JXU["?@bφƓ1ϑgԶ.ip7WY-1+05{T`FPɀ %ySG^IB$|tm v]u 7#U=F'L# aݲCSGs*bW9ͭIt<Ň8:T6fW?lF#%|&kcq~1sI8٫qv,@o <]\~l^$An.)pVif_B=ӣЪ'SIX{ST9m8j%Ec9urx^,VÜԂ𢲉EcXL#,SzUb Mx =7<+Vj#HbO|44m(0lXzPԻUqBSRtV$r t ÓH޼n*ZU|= ovϗ9AvØ@ K?'%.6' 3D'}#i; &LYqR;,HxpnSDs(o\ދW89pmjd}P6X\< +Pr>} O^[|bzKCg?k|"'K*g,J|oa ;b$bCWTXnawE3҇;Lk2:[EAM%̪ s-K7 wVYL_@}9Y#6O'Cx .J`Alkx|lvl4,wG)+n "(%w=%==25Nڠ'3۽xDsFrU7iђX1JfHDFDsJ*3"gtB?0HyS.(J3 czR3A}T- JG\\ ojdtRŁqJeA'Ѝ,K[vY*,AcVzuS=s.W8{"T#M2+o~2+n 7w>(/zR9{~MeFfa)v$.KưYs];^<Bfɮx~IwrNrzP:y~t,ߥf͓i$ &gƻ_jQD*y^R^EjT肎D'axdPkTy.Do^h%A5xAٛf,7t?Nս}z~C*X@{ZUhY֏y92Z!{K-'O=H[ ✎-(.ټ]vF-"l 0~6!tBWPS7 <ϼ]k"? `?9o(5TI/KlS=MF62fE_n!t K E u Ln="0YRI39DE\NiuuU^M:h#hh3!`)$SGP?AcU m˻,^>"Np84hul$IQW,sY5 ќ.dv`ZB3-vsjc Lv]*@{-y$+W&BHLd͑u$ǻ{[Z52zk4o*( ?m5ğ 6A-$wxN'Y&/AI|A0-/%gulʖ@~-V'+4Ռ2D1`T]x_w>WP+ H]y<]&iif-|5z?H#`8&>&h!s$m1o`y(3'2Y&дSH(_{b؅6{39}}pn4%!rA_zŠrlDXˀG$. -|SZvb֜ٴ-Tl$g6"b[=݂UyGeGW%>М wP!z uh4RQxS}Vpu D{5r:3 |Q]-Oǭk)x?l&据+9 aJ,gM9$;RkM(woIE]sړv@ +!:g4kxs=n88}hņ."ygAٗuRr+gIШEdƨLl-jK ,<',R8ƌC٥q 5iiY^5=8= Sϸ]+M _WscPn-.t*3qe:\; 4`c8 bGmO-iSE'UtIES THft*\]8-Z.,9C~[w@ b1*xP!Tò֡PKm7Px}o{MIh2ًvA6PZBe 9]Wu%y;0e@wC7S_ ,ašugį ,95=yI୩ksT!֐b|X4]D%"2Dw1Zt*(ƫWP#9eQYH12R(8T MXVBa*Y[@C 4ϡN捁5Ϣ _M@m-ɪN]UCFm,߉[l̡qk_vkxL]s6Ki〨@k;f/8 1…1GVO1bpϥ\qؼB A.55sC>&,W+;6VzUpbMZ#^zTQZ~?E#MyQ{?N llQZGBFH10T138~ V^ ՍM,ac{M,U9\Sb| Ѷi_`>vU$XڴӮp@*aEt#>p_= j1.ux s۷Za(\QGWŇ^xT|-fqm_ hX8} ”{44!_AH6OM^#W3vˡ p;eᬻ54{CSCF7&vo&U1-S{Urw48;N^FAۑЅ}d8q cl7dэnElj';9F61J4Ze }D0²01A{^Ҽ+ X խejx̢6`^,-3`K-n;> 4>wm!f>'J: ~QK j\tbG B-pV}Kx Zz5o;fP)K_oZ7гF+/4=gt-'JgÎfׁnr9`"O(z gSf<;=M}*qyHb1:]-r?aAESѰi3CaULyAEg<}Z3UmOES-TsG 9s #o?+ -IJJ6NaRniQ^\yדW3) pw˯ֹ 60e˾k|:q]L9|Q+cXXGd+^ش6{PmoS!=@O4H{(Opxm.(`@Mw \VV,Xoa7%|P1l69Z 9A}3бk#wZ\aCvjW*B$?E[mN.RWQJK d1,)t e}@L.ZGfIr d;'ؓUULvo%R}LJe i{^ΒzW 6:6sj[%IIc8j߮1Le}dq>č{'s#J `b,/*I%T=!?uCCQDH2sB&YΙԎB -$e2dh9@dUĥy:Kl972t9{˄T苋떢$[1i4SaKͯ4Vճ~닶Ymy#  <%6<ړ,zHT0>,q*]9)^+n ԇKwF ݃ggi0B05^.7IMs=wU~C/C)΂ BlsK3j*ϲ$eRP6'R?sN&:Q9R)wy t8%QCF.gj:g6ݥL[w1RlЗz, A4g6J ٖuE9SZ2!X\9v'79'шQҲ-P'.*`vhab]@HeY_+i(*cƊ1(:Ksa]W*ot>yVpݫ> N?Hơyp>o'3uQ3ҿ y]çy 2Q8&Yaekb4[+DǥE/T}5q{XOOVXejdP|9 SAd]?PQ^#7k ڛA7;kC#GgR` dNjoNiŜ)9e'S?(1ԍu' U}RsoBא忨FvϞT3F>h>-qtm\sD/D]]ٓKj'n.TYZd7a"&#{c[ ܻ~מywőGiqq=bN_?1b:ԋ0֢5/[ l.no>v&Nmf< ^OD5|L?Cw દTNfDSOq(nP%BEo$q/_ڂ/ n*:c|MT8c0ʜI]GPH-[S8{a.T>iiP)КhJ{5K%LKS!$XV]%طxp 86mƇ Ni`hg,,>.I>WV-ƕ'>00Hw!:I sq Ri\(̜ t#C8dgݝ;T()*=x_@:o'۶mdYŎ\oZN%;jQY~rY y,]Nˬ7gcSbq*`Duąz9JmЙ#^zßjteu,6}]!W ~Ev~~)d6P~E~8B -'yQY/~et)XxLF ֏ɞjr>|sVo Q`b"2pen(w`g8U@mG!e=9_&L%c4]uÝU ~auޟy9\O^4׀LhK G$є5xV,HR 8:֙G _TL^41 0y$9Y5H*9T6Ta\ ʫB2SySi庖>Jt-)t`(-6|Amm c7b"49Owazqѱ,ӕQ!&I6*lk>7]l'L&|Gy8zh-r8ᥦkȾLx͍^,?{̊xáF`RC8ysF]4mVPn_9Cz!uqoX˰-S!ǐj T.[%DFxK}|"X$LAbO-+ Rk-߸b>~VM ѨIG)>v 7>{2y.VE$?nn KZ mHP$ C@h*fvK6aj;m-4rߡz7_s3$Y cuLR:(3Vke u>jn(%t@B|"|qhz"a}I=8'7<z0ySTRjf냽.=F:}_NP7X Q]-s/|J^^:K}m$]wVH- g˔ ȞXb[.묿"_Jz̪ETόLE>;Þ[F8"E"@22Q6Z)GkVIGǕu bv%fүoV_wI#Fgd-<#YR "gOLQ`) *aEKiZTRB'% n. =6J+xYz]0W&N%_ƨ0&۟@X(\]›sHs2xirCf7ë:|¥8W,)5VhÊ%\f:8߭>:* /|S^ꄇnvRf>;}Jk{D7?K(_3 k",[Zq_ѸUƊj V?TJ5\[B[4 ?]=FաMUI߁rqQ%<78>6f5h^$-TcWM&Gʀ:T?녞C 'A$ia]{ױ:j ȣxɕ9^}-evzy3py?gHV9I,xh;H Tc=H?#̡F.&M*L-bVs΍tpr&RWSڄDTt7g-!rbYi ~\,O؉9z!c ^D*b>_qBS(ڑnÁP:oؓм8wO?nJmd -}"cUD4beM0nXA.D#Y"dׇ~e!&z#Y#(k  uƄ dR m*N5 ؛ j9(9!w@mj=>ugԑ6ޖ|wݿAA^L2$ʈW|&- }HnwZ@z [LȫfA^dk޳\Н3st t6G9CMB2|͆h!kA o*_^$M3[jP^Vś?Q|F2=Ge>OU|vGyv:ycBZ[#KgUo*ڥ] lbޙQ`SbҁRap|ML1"ҽЍ}.*ږ|2ĊKoQ!6܍HzFN^~IqwZRL : "Au9u֔2 /J.c䨉Nv}g5ilIb=sbFex_:Vqކ~hQiY;n8`[@)|WE鈬 y ǹP#:LX߮O sր <(gνhJHSs<@$q SClV9pV;i v,W~ g  g?vTrCx==-_IOU|[N-{仚Ħ,iD[5#Zzp }:tHj` 7i)grvźi_sBw~hڼt)9k҇~,=@dpoӯ`gj>^7* $_*?2Er)4J79'sNK* gP=˱ ?odTtȔbO*'P-e4gz oJPG_t A}9^P/2yxw`JDr @b'N`񯉼 {KO oNQ;+g{s{Ҧt+SgS0f@OU*rB^ZN18Exnȹ*m*{f[aVUdBLuq;MgR.I[4_ nW# 6 }b; eyA cXZev3a$eNSbL,BivҸKq:I2eEq9,T4eܠx8"Oh8)çʢalB.Pzl9={X|z\ Ǣ)5Xpc|ߧ2<. g.>f۳MK_^语*/vy#ʾ8PJ$+BpjwΕsA4t}3uUJ YRD^͓5Gat5IrFʃL#"}h+]ȵƽTDmWMX$A 37jRLgMh%=v).)86rsaFof7:5EjD3X ifǛ7I$IpFv]N:8);%-_^fU/S辀(FO658@4Ctl tNrqqɁpSe9VA=䜂DsnTg(N9@z) a.p74ȏP85tH,A\ }߬?\տhSU\ h>*D-k,-! V-̊tl I (nWaL=VVϟ+ gX|,&%se糰|UTc}Sz"%Z!=QEMSCx%oS]V_SIe.f\p2xJrHmE=!H(nH(/{T]7z2~XffPi q>OʜwkP xm ?$Fa^k{r[+Y5B3J2`3\ܮRb#z(~ŵkz 1IqlY.8^-2Jzooz}SyU `,;#f Ak<8]=ZCc\ H(˳EC\6n;=Tr!Գ,VOuDV#((u|o}NӲ[6l9Pg'C7>wG!aFk 40`xzJ#+aԌ:sSR̂;.AG_B8XR>SӻѷSuIϰ7tCTW7quMzLQl ~iM3-UyjbCRy+ [A:;}{pHa^Z.e%ϲ9A,'m-r]>iݥe^14$Oݰ033T徏*\rtV y1'YJmF)Թ$Dتb[qK7|q%u0 U!F85K9~ƾzk(/e ?QU .76ŊqJ^p_53. N6Nۯ :A*q%\gSa!8A =)dJ4俤?W(4Q,yMKMB8TRSۿA2p%24p$̖ƃql"K0;AsĔ҄ݼ[-1ɲߛ>VB R8=hK_ڂհz VY #}jA켍{ f/aرhOAe^.h ф9;Kz[|1,o% !s|Zv^F>]y4;dQȉ(v 9U09 Ѭz_*JF QxbUVN3} 94Z kQ#մsϙ23yLo#\AE:f[5Wq@ԓْ S+:ƿl{S<.xȲsxF [_ *E ?Vpr[kĝښp~A+韣PEcBMI)a "|?uUjvt03vNy;q،+Hѱ˜:12Ԡ֚_:T67PTI>;~FMԬĭ"7yěH|!QbFҼ gYk"hyQKyo1:E'8sܖEb[ Ԭ]oy}@5{JWAMΪ|izU60 !^>:{V݂0nLmYRF`2h2.z@:$㜀gyCCOP$5Iz4kqv= fW$l50Y[_{#aB> +:It Mʱyo KWP k\B$[;. ^𖐓P1M)߾]AΔ0η`qȔZȲuL+s>8wi]# ʹfҞ yAE&SE|f8ŋ@鐂,tx13V*ûrv$e nKHv9zR z)y_)d?#dQ !8W>%`Fź'_Uک@e ;ıy*9+`µJTITmz 1F^;ՖsvOoB /P^OGaU9 ꔫ-os84|:+,@:>weTb"m z3J=*RLAy [bܩ@oK)FC&}QmJ"*QbˣYKcX{jwH辵2RC+Mه=*& ^)|Jm\"[_d-^<|šɔ̝;LכX6** UILBƗRab_.tѲ"?a}_P VD= {UQ Fyv;yU}9SIy`?y*g&9b|U@/QʕyPgHRcoafl׵%_T[9 2l]8]`IT?)ϤQk %}"!1:<:"ğ5Ngv.Xdo i_"J",JssO HRL]G乽?6m4\$՗91CnnAKF;F}}c. OWdJ |ͭJ 3h⨿ qK,Rn("!~Qek$pJmJ;S\!Hi?+iUψǬ2ftp.PzO`K~څ-u \0ʭ H4|`ѓM2̸E,fΐ,'_Lh[?$/P9BsYo{Q?yqG\eηzbVJtt}X^nsdє֔U,#)v>PSOyneJQɷ3/b \7$քO-?,Ig"_zLv.1U9d,dD{bn؄rQo ~n,q56t*Od>u 17f3.ȴW SwsV*|B'_-k-̀\"V -.JꃉW9QYH?5;zЦTnFZ L^GX{z$BPzG#ڪ7ƯEYtGkhtŤmJ@lj SNRQx{Q66r?j\61 (MtA9Е8"{#A`BḊC2hFɦلנA8vAvm"~nΝidͻ!?4k yS@0c,V2o͊$1`ɖ:5DR"a< Q$h6AIi.!]tx]:n3QhB`/n,;裌*;.ooapYc,R??ƬkCy@>18ȸ|c 7-K-| Qvdy,}(Ka\wsݴշtF1 ^`mD8MrgE{PKTd?4:M(1bV|Dd̝gaȈTI_Z`8ɂ3'64 @.sv)RT@o]ןk:rp. WC ȞES׋K@g@L<(ł X26G$RH=Dx4;y7ukGqhxeT ږ/lg3ڦN B1o,J#/;pX\Djq1k_Gl>K1ZF斯c mk70  ( qGjʰ}̽TQ"Mx$a-ae[Uy)B!'wIUY*l%y$>䷻bEtyԚpHġϿ.7`]pxCdk`TAnC5p tx0%nE, ( wC r?=Sw$pEP/m-H;@0>çgWw1*HkrK ])n@ N`S l?d?ʷo)Aq]0mNFr是}s77iӘN/=. j/*$CGhHI=I[=Z( jv"ejh]ܲHӲ#W5*GvM:푔Ip/, {|nM|L(OBuF|Bs<{ 5$4//\kB/}#ٌ3> o/I8U'k!'s BW~O5u-*±|ׅe(&^ Hhix_r|[nA Ƥ2ikto<0*7.[f<ڌ2x`_۩xqOPG 6Q[L΄~cY+]ܦ1p}AXV/mPYXyF'&2U(-ds.C1 2u*\5J*Y5vYTf{bm:mf%P2Z!wٮk+Ž+FIBq)cC$1[P23x(h,8!3v  Zx q9?i[8_t.R Ξ]SbK%.?l:$XRZ:bW:Vy|B>\KBD^=U$xm8J+\Q/Djq)U7*9p&bvfa Sh:)6ȤyNP %?:};w}%TBd|1L0̗uAC<ŧ2}oDqzKï92pJ4vexSe=6ߔʙND B.be[b0>=.w1uxz.!Jv j:~,\䂿#GmjPA˶}nW:4fb3z1*.;ۏ]!z- )ͽP ̈JcpʵSdva7҃[1 Y 6UefY`w•m0u6E:KYjzk3ji q#)G;t?c@dl@_H\ `Q&;__[wNփ?\O< bLj݁$.ОY4]Zk 9$WCdQ%ڈM5~gs!B#Y#7m*Wq> J) W7v᭰\.5GS%`( Mz*h^~n8ױ%L^kAš1j!+5lfDKve5uDwN`yz-w1F=JswkN ~QFv>q^<G7>y*آ 4ڮ#)[y>7Lʳ@[BǜT :mk CPՉS$;/u{Dl5!D觠ڹgL.!rE6y)-|5ʎe%Y_$pD2+ ݾ)}ԛ¿<]&JrUfrrHc([I /Nk>qB !Uqc1wԘK_~7$4rrXܺ޶n0R] Ɛt>Dڡe?=א*O\Y~ [jjwy9Ko*(s:7?07@5Y.=;EB @۝$̕Tftt?Pi cY*?[\Oa}ʻwqYq^0#BT=\Tq, .y8= C&+Y,B)`V\2߮˺Il ^ڷ̣<2scGRIO Cu-v8%pheUf| ys@ kX"wiz[e .f C-zfbcϥmӯ:7/S@H7v=qKXT  zuxNK7CooE<0A\-KPqn?;6HsivsH4 ]Dg~6OCXvKߔ0T ": s\߻+y0B'(/&M]] (vg8b&1c6,*k>.!$aIv:4CMcKLk ]5c]!R憹^82wt[wKEtw`h\M'v :~A¿wY1w0KܨdHU?}Oz}xĻI'4OЭyW PY1e0ͩkgCG6.i]zNL2z?K3OmϰUE{kK–M7];k̠ M)Du dKAtĘhog3:MN"{09PYC9QA6@l^Jv/; {Z}u;CoP_c$8["D7P_ LEHA別Ihxh&|3fS=ZmjV1GS`'@2&Q]vS::oneã~Kb 6;S21 ʞNmB淸)>&{Pyp2o)5u9n"NrɅ\}G+:/|dt)0jCd饱~auCu)r'tizsD!pP#}30|ֈmZɏCn5DJfΤ/,o-2u{j"pظwe䡏 p.>CՋ0|֡ Z~7 zOH@lg0*:bc+F6 .h I]1QZ@T+ʴuŘ.1NA6Q6 r۸[yGMuה7(`1*&CRx1" h.gB4&󃤔IY`ODEcz}ҁ&C`ka |~w!F6=ji|v9$x(ʹ@CqgAW( Eq٩h,}U͸-Ԥ:g š-HԯcpZļT׃'Qr{}j3`g Ro$J>VYk( +ȱk?&~]w@ 2̿ߴiI󓧶43b"D$7\H3q| UQTb-[sVE$H@!Ox@Iȳ ϖ8R'Z*|*ˣ˴sWF^O-t aH4)*>Ι9ytx; '{>:UAEL@[$K r%ϼG]mqMFK ݻgNw˘Dy-%RUW+J{+c.w)pz!:gZm0|J=Y rb>9(q5;hNhX@z8DxSGDL; 4#bM8d7 0ɳ#5IvynFV K/ۤbd1f>Eu|9US#3<=">9tirJ,m}v'R\4ҁ헢?NOp'B h,5jx;[E/tu3G+42;iCZ"j,%G>v7&D2^g%ZD /ΌLRMl -bmV@u?'LΘi fyz"ze N^ԀǸ"3,9ȕ3DžX'glKae5i`퇆`)*GRyڜաӽM&Gk2mɥ0iAyzNRrVK]tv:Z,6bv=]d*sRtAN27pZu%Gtfm mOj%2>NgL>=%}൛wǣwv9 B˸^08f,Ash, ڪx\%g=X-%Nxp&'@6zHDjk(D{QP@ bIntlTIHXUE3$\$%2ΆjWX\2K$4ТD%u5E4a4Q-kmg g KYaag9exIQ<וa(SjZvYpX ;Kwwجب3u ,4CK=j 3m~+vsTc>2hՃwz7?#% nN# Id%7LpOv|tjz]*L#% qBhՊ?-ܪÔƺ+*ͯC+r؁0 >\ģ@&MTiP6|Gd֓;}cz\ۭ8j;.`vּs9aka ꚫC ]W3] .*)J_},Y]m% ^}v3{H7K^VH_wShaB⎉@WQ&R3%(nތz֙&phRi޿k6"֒d]ӵ8;+ҞHUyԕXtw}Wtݹo$iӚ.C YG4_U[ q83FXH.ۧ;߂'!Cϳug*~, *#y8:ʔ=GhRRJr'j9΋3$ū03^ϴG1 B(jvT>H0l5/͖6pQ}!n9b(}]9@<6(ͤjYWT<]bq~3Ӳk[` @>:?T ^0`(dO&K$JXcntcyN|VYz\%|'CaН,O8Jzfw8l&쌢utŘ=-WTL9aQ﹊=GPQWmZ]vp̈J?IIheg4UL+ꀹp-&WW&#t kcuuVa{`9gyMt#v R&pa3ЋP|` CU'J녞't\d~}EC{E#n(g|] AI65[]2u ӑRIT\HqRí: 라x O]=b*!i!T'6D@Kb4u1Fs~heP(Rj/R5C=x6x 0ݚ<%Lda4~Gѣ x02ɂD/c~ȽdE>h96",<🾲"F,U q`,DU֜a-[H4^L8L6T? `ew.0oFYAK T|zPZc6!Ԍ>('ZjP9\{a.wkTڍ}Sɩ'YNՌtn=0#!I&*m|/՗]/y[,åGdY+p:m#@աnap)iXI\ϊ\b YqcBÜ4o<)C7?eݓCw瘷kD?;5 QHR$\S0`-<{}q\3Ax#o$}k(u⇇2 !@YUH?DuXOJCЧt6𺒚XIS`[jSK?5TAQjQl3]iۂ3@,hY@fXKF^,~\1XJy';W+@k;2Ec)+]t,mzז,;HռWBJbgJqYr9evI).VF*Ly 6FzC3rChҦ{'%+*]qf)EcG,=Yo")6*H8' | tI$#\dFТ5s?~tLNJuZߢ#Rl{|IMP>g$7iK[\ ~1r@?~GySOW>WOY*=Ӫn $k,7\tx>lyN᳦ΆW<7Spxô>wC9g2T8M4VsWJ 6l/!;[>1($Ej_Zf9 s(Yt* n$1[Px?tv KInNfyg7,*t%{%tLB 4L>ƠI$zjף>B]bqUySSl=Al9j,}w[s)HU`3qB̩pz{JyNr6^v%*lQK]2e[2 uOOg2I )C&a*mNZ#1bƄ{X}*)SUv2,o#!AwuW:e<۫N^/ta٦W5܊8vĉ h/4U'8bohQW,YsGj`0 [aݥib͓a7|Nok⛘F+ :gLAHSdZ-"*8 :RN yGlPݢ֢g}bq~%S!M'T]KG*/cS9veNt;3F#?㝒e#m59+LNoh[k ݆2F﯏6J}ZK? 0FhLE.Em yTdgM$ʀvɛ)F$'rV,kΙTZ~׏Lu4p ,wšF⒮[W{׃ei-ٱc5) 8cFu7mEr9sa<}B-{h&,;mٛYL]q^3w+QU<-r6"nLkmgDyk;f>s58(d& u(Ln6 T~,!& Z蹒̗Um"2Yԩx(,1MGźh1 XN7? |Pw`E[P+>A0 ^ZL 'x3󔆥ƚ`XeǙ5?{iYp8؂c.rcGIM=UNz$o EF]]ZT!(ل^z̶v,D_ o c7~Zg3At]&De)_I*jr#\H9qAA^*|R~/(K\58? Ru'y&O4d?N+ t]\ԯbaOl[V6FlIq/jxNɮhpa"/ikf{x8ذ~TV)i9;yx+.C'ByIt*j+}&py!,8X@i^ˑ %d4hwHYm[_J8Ǝme$UOv"3:3kVQ.=E{M@9(" .,ZL2<"Ů 0ҼJ_wYQOO]_[JcjA&Ul]pl(;Q-W|qE04G5}m IR#. +/j;oEE{wHۏj&EM^ZA E[XyYD%7n)#ea:e)3w62dT_A2'aÞK }f/m ۢUx+RD+N+ln"]:!jC~޼B=!1v"/4 9aa|s/:;;_"%KpTÊy٣Mf:"$X [œ,s?X'؝QYȓrQ/PoE@7|גTi/ #4p!ݿUibBU>s+#P,2>DfA#ɾL,$EOR1dvž-.Ϋ5&Х"y@HJп} vhlh?4pf#lv'/x^eo葬cbPCL _(RlJag8zG9DZI{hř W fK^YQ^N^McBr <߇[c8ܹ2t1-1}=wFsrU&ywEbg{"4ĬYUe;hӲsJQOS9)qdƚK8}ֺ9 AYHyhxqk'қb7x[t^zUi)D25twLnP5h;8& 9y^.5L4hR7Z7' "?ri~npv:W?n N;:gMaLRfR(:7H޹)7?%KMн/6񞵕(A8.U융lDH&{&FT9=Ku\[u5.$|Z©C̄Z/AaB{L^& Cu*7*&yr zSd7U֝ Q.>B&wLhRYGuLrJ~Y>y3/Ab"L. v_Vfs5Pn+4;gOC:řѮ]E'"zh0M ,/6Z3̺{0"h3HrO7k_txĬ6o&,a^&|yEx]B9I,sl)q=~/O[ x8T!, zw>SdvTlZ*c_h fۑPo|Ui($jVEܼ4>8#7sv6NUkX`6F`/|aRH("k TKn:\\g.:m9ΙSc)%& Iq.ڥԔ|#,AWernR{4s!E 6<\߄N^Gw$JO&x uJBʳ?9LP9c.CVbfВOa|pHQV.Rʘ[^?&\ Q hIxL<4d]O%rd k0`>U9%<rr$KvOaV~SJmP )UCB Rfu5_#N;C6@c1!5>V"0Tj`|U cM*Aʊw$Im&+Oc~IYDǢT*NA6ŠݙzQŸzkL{IuUz)i{Uv?;y; /NYWl!p;S4z@FSgKz oxC7iw[d0v>/D ۳)Ӷll*>4b$Aޮr &XB?[Xބ-4Q"q\cs]1gשPxб;*#j vRg7 @(zOuQsq +q 7c`}ө/lXrRM u|T43iޞf5J_)@kd,mnʢ4^$oH<{A r9\"փ ı# 4Y&++s %{Dq7Th]Up 6P@<- $c {fOȘ O{Ii 딕ObȐa%I niW1 oYZ@ې5/6 CnKpF]ٿ\?c{Y|vI܍uMOx7aMAUe "`Az!͖o[Ma>l?˷2k[D . :u-UɔO 񓤻x?xmf э+WBl*3sҍ %xZ=(|1DXuS|$?TV^n$L:~Eܗ|A.Ln4#w{]ށW.;~t75ޙ.›W4o]" (F F.HI#%şBnɳĿero(n}ăɉQ"?N|;_0vģىxLv}!RJa72*v4j^9GKgfcԥ6l69F-lʧ%=]g+Fj%1FVn)\Hx⼽d:4hg<cӊnm,$ [eӰ~tüngPШ&Aǽ̷Ҳ:/??z]5Jy @}z*:ݝZؿu,7XX9vQeQ OT'}F ;3"`;FYDEl[v+?QM%#B/i&XƬwv!"W -q চP5!tԥ,68eʷ6,|d̴9r6Dֲo6:mGtSZ m#@Ul5dH#( xԘJڕ'i P"8IjvN$(OU4lSYq6!xiCHʆQ#HaOۋ'b-S.w$ʎf'M_w8 [yX$XADhZQ*YAs]ͣk\ ׺atq^n'픜OΊ^ 5펃+Aoڎ_Ť{Vybo[m5+W:2%|cպNˡZQ@8 KoHBRgҀ ~imrMuh;'lƬf~Z8w_ibY@`ĐQr=Uqt _CQ diO㢳tը +v04G *!IJ[oZ;I{nU wzM'~Oebs8b@đ8j\ƒ4^g#0g"X(ʛZR >*bM ѣm(*3Jz T4M1Z`=}Įn=T=bz_8ay }C6Lmwf%\9L?UjbCp =4SSZ :e)Ly_CUb'fx(x[MGݧM)?SX+P  3\ta>*DNЩ|_j!mC'k̖&0 *y;۫Kn }I?'Ѫ Fydg/ Bpz`͓]z9aϔ]!Yo6SrFh}wwF} 鸜I ^vx?mXѢk'k Hi4f _έ/ls4CQ!s4TM.V9%ǿ7x ?%6S<)[g0s=imK(Kp*+V= m7tog 6zl3eNBO]%6wӡ0wڀ:R CXKL7蔢2^"ڣg%81M {ߟIw=΃b>lb+Q}`soBC)\֮u b [\ ;8 yh 5٢1u c䵯[ 9pFyĬkY iHwZuv3OG>bjw9nE1ű";́NŷmJ29kFytFi/:T$LW2J obЌW,BZrd͖4uH:6|̔Ts&l+6>8ѩ/F*_,ĠkuZ̅.~ƧӳLpVٖǑ7aJJ ,z:M&X r `H&Z+f+uŝsm8ZksBV4(0-uɄ 5 J:2:\VR6>e^V] ]Y5zOD Qg*Nmz8|#]>WSg+IvId%; #Iqq$)pY>NɤƤ7m-#Ƈ&+KR? Udh Us8~M w:@U`rVO齚 Lsv6!EW9<8Q̈́lxTʫeagF.ٙZtvw=C{):}.SE2/jm#8-$ Y}hup{םx-፦:RtWᜡ{M ̳YMzTq XA?"ay;;@}.RR[,LJ0&{x02]:.j6]d@~2 [Xnh ";zZm<{Cn"L?S6ٜfQj9bΈtb[1p>$څAqw[,flcPt=f*X@_V"X 3iQdhܣ]gy֡1V&cz,"QwSuӊ6YH@n5Z*mvzH~k<#8!>rST>7oFI6o>rL W9F]iQ,R@Z%vhEt-|4#v%Og\R8Q*mPCEx:{J_:f5zDO%&AUM=C\cMЬX\AI5%P8ؖ>-)sۂُ֨JZRnGH 4khjLS[ÏZQ V));6>`Wg}މ8b;5% Tw_ëӳq5 ^$ 2w^b@V '#:@=czu#De-X8~ G*H_vX+uREmf h<6_AZ">OLx!T#o_6",)< !H_A:i`3uâqvR+b9 iKĊEx8k.3lb#r0Y! Ș)4U hR*hKaؗ[Ϯ!h}_i^v-2J9w[2#r* fë Պ=5cOɪU<< rPG6-R\78L  56 hxHDYBHd ̘z(綟giscNs[M"'^c,[7?Fv%A( ސ&hoJeTA.9f?cX;N$D.U*؍ygO*ƀPo@z븱CM 9kfoOȉI7 Vvm9?j|ix:x=DdFydtymW}WBb fJN3OJ+3^˜˹A _ rՄr0těaWB (m׬TgnhZ#q!L-rcI]JRzzTP0U] nOvc*B֢5׺ft9҃4}h:BFn;Rme$'`zI9ٱQF1M6N yG35||dG=a[f*bWѢk<I g|d GDL8i/}l5Z[ծNäj ?^d|?$CT-\ܹY> kXPI9Ls-bڞh=#éD v\i56#;_(o2(Km*k*SVdh- CmOR|rO ˖ 2= {1^u?&a%0-=>R+> ,3 K> Rd=lXKieluy) s oE«) o*ti9{~G>` Ĝߊ&̷_SO6L.(Q<_txe5jrDjǫ wϸ7)u$2ov!/q[ E~)"DlZ!޲\ J>jO¼JGt@s, KI kڳ6gi^Cn2BBʵyOO#|LEOZ%*B]y)SI,g~Γ|#A ys,V21Tꖔu^EbP:+f,%THpm73}kU8R'e{v >L}ph4 ucP`i na%< SXuHyM w[(*WN?NQ$h('!+-%VNP't蹱iFr}ms#S%-N5>"+4WoA7v} o-"Qkl%!pct]r0x.]Ӛ_fV#],F,aMLwbsU8$ݽv* O?QQdP+$˨#d_vM VV&;2nLtJ]jņ:D[63~]fF#%icFd7YoSNZ2TXa\P lU *yL'[B.|~5G#;.UN4%M :'a O=2gc3J¬PuC{8E;lVڟWS7SdB(ORX]_Ƽ^LYeܟ$qSdN$I#:}lec={3(0c&y9?``5{Wܝ>E'*ũ֟ 1;*wk-v uViV]bU*S+Aȁ,_f4ij78rJsCUj9c? ؐ[ 4fkz0މt=^㘛09Y]vF6΀ GHJ g'aoS k6;'[pҴwP6d|_[o<(=M8Wo(.o/6a+D%mNE8wHOعή{=ֱaxO@6S2?gf˜a`Q{:8rSK8n7&X4GDQKy]޸«E#g5)M':#s?99WŁ=7#_Ym$2hGFw;8*xkQ]a1DtZQ+_ [fy(pQj1iLO}a};gx$UҦ4/-q_A(8VVGzp"<_U('P} c.c/=ld^g tBdkEq>@. F"Ɲ<h^PTfjD$oԭ@Q-b S'{!΀4_B(5/=+<;&;IR &ZlΣRR6wT{} seUFs ƛ|1g}wkGJd]#` &$?7 W |6 :w?kM]^"AѠH >N,~ Q jNqՎt|i ˶]I"F75+yQvBG0䪴[ri`;^+?QE,9 kL~G|f)!Vg&DDvz@ZtjMĵY36ͱKZh t@gg j5 x sQ^JWJ9t. NcA+PdWDTiC>qIPQڰv閭9?9b#s(R* ?,挖+7=DXzW0E4`BL|h _ǻ n]-t8 P)5|YKX_:|l%^/׎aI:g6i FF7ދ+M\ev-ԖZ*#3bh~::ە> - =O_(p iqC3“kXg2^ΰV>I"3hgL.tC"|@2rx*nɓG+<9yD' Rҫ"3iLQFNTanh924O<\\#%t8Z'Hٗ PjJYJM;:YnwG~  驇GJdbcGfjLXraҜDIe)l/GK`p?V 3 9,< ʍ *= 8;.Lۛ7RԬ}NC;D=Vx  ~l+.虬kS9jޓvHxWbC'Lq6ᴋ.r *'Ű7\1FZĒ?P^@ޱ06lylUʣA:8'Xa))L~7  z7;S|2bn+ PE?J,T*U~o,_h!Er=XiNLE(hΌe@9R]_x>ԥjsRAzLd)i2(B՞$T?פY>XXRtGk.߿1 Zp@c IPav6P`IbAx7UTv [0S6^׊"6=qI4']mAjsEڑD ?f*F!ö$UHgmM ̬c7(L,Ǒxس/ΥE)XC:/ԧB4Y4SX$ܚ[`kjQYX0q*_?XshFyΨG[Xg9qjWډU]@e&nx[F1;p_ +◈"HVZ8z:-/RQU2(NVbݼ8k#j9oWb q7ƚ"4 y&ZH>H/l! WG;% ]6݆o t9e*^3JN<עc =hww)7<(PPM $9YeOk|K8qs=mEq +ag2}UJpd}:o(m+[b.Y6O%ȓ?#Ea˜a|uD=_,+ߎyrZMF4N53i9q̏uMZUf/.`R'.\y?kp<k. Yr n99 v`'.¿h]t|zN4 >R55UZe h847̖kM{WlU :=Ij(i#@ǎK"-XwQҔ1K3i^ey7f=¿:sA!+2EMlK*$ DܹsS~)̥7̈́XƵw~ԖñjI8!υH0'%ǝKtN9 ͘w+fTˋsGfM1(Mm2m\?;AgL]. NQm w%ya99٢=Jd KG*=tͯW|?~iGŻp=ڂpz2<vMG9kǙ$DNHx˺ȋs /ƪ+ΣonK qJ}au] > Wb U>'kQedzt5F@1:]P#/-u} 3%B2j{[]qM (IK -uz 5bOh.%\m@lR>\tLg) AHij95g! 1u{FT~DBnG0\Ys{d%,0t]A>)(L=kh]<qK-ƩАBN*Y!W>~G'+ep?(9"6ĸNeƲ^(`R@) l08J< 9rdPz&й&}$.QnAosASQ1*WHv[J [$,<2[ |l˸;tq50(DXb_Rf0 jHX/~(eqgٟ)Y49FnQ{wz0b'@xa! :Uy cQ('7cr@ÚE# ;합VZ-oJ]Ƈv4xn!"}SC|io*WT8:9`ҒEv-f"cH?3-9J}:N˧< `P3vp I\D~2\jkacT)8{W?>ku ?M o0Sf4?%7l?p?&o2${EÞ ^pI0nI=V=Q1TegX|''LitPWokl҆xPGٰ+$ ;0LY퇒K.c>OAI O)8S}zaJHFUK-UNH@ lQ*?u!4_r[@J"$K A a:53mB$`e+h=B3& fgX]존PoD{Wn*I@#Ѹ_Vy䎷cM]Lx`ٰc1޵؊]lA$B;a~1}5owE@sqGKsi^*}?D&OWpjG2Ҵv'I3x [~yԘKWau4Dd-3-* Wlyw^67=7?n\)Ck k8* mfX5? UY41^ĭX 6p#~C f"( N,y7cJ'!+? 6֒)cUU/+pA%$YOΆWФtbL>l[ߡ=u +\(DPO@Z'w[\kv#$G8 φŔWeT-a,6Ǒ('E9hc F%88I3sKZ[&ʮ𬍰"ʺ!uL.cB@3^X>#qY3Y]|ea.er惿Mhq>S2wu̢ʴ6/rc#>5Ykaݞ11ptk@7& i5qZ ^&bAb;G(؍F%-r3ӗBo[tǛk%cZEܝY6gNu;ˣ/ؙhH7;WgJ7şbL`4CaЪw?j懃Y NZ7fC`?w@L ¸REmSndwVhrJRᇵ4-cݐ\0Ĭ/ Mx8gO=&-\1ڬHIJ;[w4$@pv!\j{<#Bc*{sLtoc7FHy qMe%xB X s[*qɔt C`Ę*.ѫկb# *2!EI]֐Q>ZO U3tqȃkFb̫=̛‚w:w]u'9zv޳ְ`{™+yJn},VT[F -i+[$~Ye%j>XT:`,Ia aVϨ\~BGi5 KK.=C&7Vg*#. c|vZE+]l F6a| 8{C@Md EyjF՞%@@fQ*"ʗB =$}X*&`"wT3o<:C2Oڇ`'xb[%~q`'A۠?Ϥ yaD%P';ì 8U霘nRcպ&}!enQp k r_ԀbYvvy-I{  7f)X$qIP_ G.Q+Ȁ$e&B>1q~vy& Cn viZ,wyNj8,׬wbjB/zZh0Q86Jz ì"KBEظK]Ņ?8tW%&yuz`Zh"v^baUMӘ PpBwGgQ 喋4mX7%1d]uHJqLT4$@xc1G/$5$ az Y~UM?j~b$1;eO wb~^A[9F?3mҼb`QnFo=մ1 p]!ox/)pQQX:p\y[zO!|+xwˇ؇Rh+hCI?R5F؉ l&Fފp2J3O ppLDAt~B] Uh6Fت bPm+?T(}L2kpYh;a,Fd{=/+2GMfg/ S#\D3E4_Da~NH: %xt&(xW[ cAߟe#h#^6 n2 볦g9N~)@@zcS1ܝGA]W:yRp]=n11([L5ի*-8?3> @.恃 5#uPt,)mXYVyǙhO+ÿAwG U^:gJQ\nOiRe*]o*M@FF(2O}|Qr/¢Wrn1/Okp)x%l' KpDrjzX;iD>X0'͆/(C4ۦg=4H!F 8*|Q|܌?>j["jI mY_&>&cL;Sw?FDQ jV@Aruy &mGepj~2 z'`XVCljix^<]Bn!ɸoĵw}I@nL-&l_+oxJ`vdljՕ*\ڇ`7)Z8DA=89A^;؍9;0)4bhd[7skLtWIfjf}KP`zصbn OaS8:_@Z2[|oL:7S?#h>ec VJXN\B#:؁AюoˠyÍq1 EK̔ ʨ 2Uh2F Rŋț&՟h S*r{u4,)<H${ .|n0ctWz4),pj`q_帐5DHH~W{V?<c4kʤ]վI~JVPVg9/~ SsLc 23Z_s%gуk%mY"nϛgӘPZ1cw_R| uot.֕a3)Z)(=e>&'"x64wT:f4yL` Gc$Jw "QSE#Y%\y,ZEFa̗Ro<p0$,R4fz[2R^i»N#G8"=@sih<-*` [Wur  M YZ