sssd-ldap-1.15.2-50.el7_4.11$>?T!b>S>;?d   = &CIPp    x 0d444 '4   ( 8 9`:m6G$HDIdXtY\]^;bdefltuv$wxy/Csssd-ldap1.15.250.el7_4.11The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.Zx86-01.bsys.centos.orgcCentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64\KN"I~J@hZA큤ZZXqZZZZZ187fd0fb146dbc271a50642b32ce174c727ac9bc2961513e7dcbf5464b84a0ad8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903b0f68cf3d01b9641d9197d7f44e11dcd588bf59e0e21ebb8d48280a57b0ff49dc22a1f0b44d30672f9dcede6e5a8227b9dc7cb81ff221d2e84624b578dae2c33eb7e690d03d17150a937ffab703f23bc6bcf8a3b747d9052b8ad1355819ade41fa65efa982a1e735e31ac552727852b65d910458cd512b00c8046e7b566c17ae590ff69c2d6627c806408c4a5eeda0d1d64564ab79a34b8ecec5609d4e0c20ccrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.15.2-50.el7_4.11.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpthread.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)sssd-commonsssd-krb5-commonrpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-11.15.2-50.el7_4.111.15.2-50.el7_4.115.2-1sssd1.10.0-8.beta24.11.3Z@ZR ZOhYZ@YY˒YéYzYYYYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 1.15.2-50-11Fabiano Fidêncio - 1.15.2-50-10Fabiano Fidêncio - 1.15.2-50.9Fabiano Fidêncio - 1.15.2-50.8Fabiano Fidêncio - 1.15.2-50.7Fabiano Fidêncio - 1.15.2-50.6Fabiano Fidêncio - 1.15.2-50.5Jakub Hrozek - 1.15.2-50.4Fabiano Fidêncio - 1.15.2-50.3Jakub Hrozek - 1.15.2-50.2Jakub Hrozek - 1.15.2-50.1Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1516700 - SELINUX: Use getseuserbyname to get IPA seuser [rhel-7.4.z]- Resolves: rhbz#1530975 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules [rhel-7.4.z]- Resolves: rhbz#1525110 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend [rhel-7.4.z]- Resolves: rhbz#1508972 - Accessing IdM kerberos ticket fails while id mapping is applied [rhel-7.4.z] - Resolves: rhbz#1509177 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss [rhel-7.4.z]- Resolves: rhbz#1506142 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) [rhel-7.4.z] - Resolves: rhbz#1506682 - sssd_client: add mutex protected call to the PAC responder [rhel-7.4.z] - Resolves: rhbz#1499658 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.4.z]- Add a patch that was missed in 1.15.2-50.4 - Related: rhbz#1489290 - samba shares with sssd authentication broken on 7.4 [rhel-7.4.z]- Resolves: rhbz#1493916 - Issues with certificate mapping rules [rhel-7.4.z]- Resolves: rhbz#1489290 - samba shares with sssd authentication broken on 7.4 [rhel-7.4.z]- Resolves: rhbz#1482927 - sssd_be is utilizing more CPU during sudoi rules refresh [rhel-7.4.z]- Resolves: rhbz#1478252 - Querying the AD domain for external domain's ID can mark the AD domain offline [rhel-7.4.z]- Resolves: rhbz#1478250 - Idle nss file descriptors should be closed [rhel-7.4.z]- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)deesfruk1.15.2-50.el7_4.111.15.2-50.el7_4.11libsss_ldap.sosssd-ldap-1.15.2COPYINGsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap.5.gz/usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap-1.15.2//usr/share/man/de/man5//usr/share/man/es/man5//usr/share/man/fr/man5//usr/share/man/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=320e128936612964b7a1328fb09295be0d0c62d5, strippeddirectoryASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)/PR,RRR)R%R#R&RRRRRR RRRRRRR*R R R+RR!R"R'RR(RRRRRRRRR$R RR R RRRR0?P7zXZ !#,`DLT3sssd-ldap-1.14.0-43.el7_3.18Bt  DH`pZK$ƨ+sBp/[ͧPb,>B tkG/]ƒIjy0G-F󗦪6/G}AY1LJn]v)G ucql߬=6w8Eh*܍I}ւD&L=| ){pQTX,9",)#iCW& 3($ȑA|]R5/nȠмPEhkQ.NESnZU*1NIRy!]\;&e57o"\n/[` Kk/cL"@8q> ^iV/G);3*QJ(BIEͲ;H'fmRrl<1M|{k& R(&SYkמ$/f?Q ;3.Ӫ1Wʹk-.WM1ު> .\?X2ڃV <ǚZNVʵa&ߠ0 UZᾞOZ)"`g)t ` |VW[m[]?mgk $"y[{iBk_ǽ(T|;Y^ *3”ZlރƎG*+ n4 n*9V LO w-+Jo]\yō1Qob, h> = lNItJ6} R/&/ 0`!рI6 2.&_!w]-aDeBZh91AY&SYRNiټVۧNooX4M iOj6=#=MCChjz4SCF@IyFCh=OP4izh2feDCA5ihESjIɨ4F @@iɦ&`ɣ ф !@$ 2G&64( 24cF! & b 4&AN*vJNJ)H"3eCؽHH%P85qqqM.{읮=2&cie::'ʥ'arT 4D!p x6NLb{X JUYj9ΔF-cfx!"9(F#@E3K,@52$f$4 axUUu6LiJF&ioY3TQ#p|Jw3% ؑЄ뭠)h@%IF!VfH.2BI!sė+ ,$kDJ>%i5"W愄^1 g 32nYZ, &zm !$ xa72o+ EЉk['A/R ksQM*9]iY$HaϚ `hB\ <e.WiaW>yTc6uDDF0R☙Qqjdsȫ?D5QÆrBB HY_ XE\Ezd94(qQ5޼9Vfv1m`ρvpt2m,!2N-W=AuQmd0$|7-лJ !!1S$u0׃4\H{}Fv#Kͽ"Pv%[6*Ќ—;6X>n6_cb滸Mdzb>KBȝRy+T򻳌 U$뛋JSc(K F1ұ-s%ik8V+lR-;bݭl)„P-|:rt.so.1s_debug.solibsystemd.so.0libsss_certmap.so.0libtalloc.so.2dp_id_data6Flibsss_ldap.so.debugq7zXZִF!t/ ]?Eh=ڊ2NaMg1(}AˉaJP6JkD-WzeF;.OָyF9,G\?U;ܖKbrzD0]}CYrtSo~&4\Rp.cQ#`wGvY[\| ZEaORwkHcz<|fj]GJ{hѪ4_ =8bG%w[􋺂yqp$AV&JZeŬ7+1;nqon]] t$$ WzKk+|ۂ3S/%Lx= d=B! n2$nS0lt~p_J5s.y3X ,VNW=Jl\ {̰nUJ`ۯvڂ@&z`׉7>/\\OQ> O[YOiSC\&Aى[sd%$iZo^K2#ŜB8vb"4Ml&l4lSm nl"0R ץINcdߦdU,u6_{߰`n:Y@E+w ap/-ےZ<5F3j7N%(ɺ0&jhJK]m[+ ,ryA @DڢpU"Ӊa+4=rwۘ٘|E.N{&5SL[sɒ~aG 21`=4([}]--ݧe~Om^or`=6ꮬ̬//؁Y/vy񠛻ifT`:d*Թݝ(7j'v]K+t8Ml&6x)2Qvv 1d1c_KEO:`p{*:>=̤S:dBigZA AFRG೾N㍝4~j{~8=ckEOVf89] 0Ùk<;Rd&}oҝ݉tNϥL ;ui, A{?o=Mmw>+Nc%;1w;*a~w i e8qp r(1Oƍ=m<{n]z*:2SL$*t"&tr#ܩ^uųg318랞 ċi_|W 6J&Ю]=S=8?=9*B`OV`ce'S1" >"//e0<90f'$Kf8`q*cUD'Y78&Ō;`}ӒLHpqR (%iPVjjLwnnC-2NhGS=U@u=v_=xM ,G*R_M<5 wl 뙾qmǃ9SbɃ RhUECMQă`5m]kF-\wnr C׷'No<G@[`"mˆ&3D2ZA\2c1r '{{ׯ:![Ћz!Z t` Ml7%c8^fbŊr#U.FN+q^1T \ҥzڎ@xFZPh\_3HJ`[)Oᯏ%uXGT+M X8;?+ 8p >w} n _AL! 3OM=@u@o2CSc. Ha߽fz \h7ɂDuX #-њo>_~L `3rP>}{HOk߳}`LݗYĕآuZxc0"^,<1cg ta}ia~X,~˄[;WW>q[ ע*L2'j ~d%{o ps= xn~2ͬข9.yBylGL&Z1I /jQ%dK@#Ãj*E^\w+M>314Aއᒩ/?6*HrWWpDfUӱ4dS3PNI4i4VT.D8$Mk@@ ֶثRpjJWi4^E*-5NagïdcgT`ؾst"%`!=Gp1/@xۻ}tҽ{^IG|jhleR֩ 4V^ȥ5Ļc0|dCeXxMzY#1D ;1x5GX >-1UTcTA)`8e*fn,"r`vzus ?_Yۜ7غȜ1m̥xy. 5_83FLy.$j{]Uv6FѶ3jY6 =imbfMu/!! d-yYz6s;NKP=A5R a=mo6/\1lnFwTZ9Kje7 sFFTAk+dC-L`[+ >wS\];$pt 9*?e 03 `vwcmMvFT H#Yà5`$s6>f]pT ,UT ( VAs©›g$g*9 J`-ɢXӨ6'3C EvDTsGd!x$k ә#?$b"-DgCB=r^\]e-q+ οY(:Tm5%H<0R{mꛧH@rV9|l}i)$2ua9̩tF/SJ1z,UNdL3e_Ҕ}Qzn#zRa-ulj;j .>IߢsC(͔ٻ5cք0p/QQa@Nj*  %/J K#鬠 /bqSvTg&RAMݠ_jEW2{Bc2S U*>)CIxټl2w&&K4"rl:]˾wFfUcBB3mKl2r}i`S~ݩ-%*jPpݳqѠ&d(&K'YD ivD;ۑ \Z9JWE<<7U9Dy]_7^US&IP.MMs:9,)ln/xe+9o/&I<_P*9\I+'ǻT{ez cm*(!{gKBk"O3;"˃#nbw\0Am^)@*i1͒!<#y;XaG];Z$wrM/U2xU,z+U%zz͟JR~~r|΁Zӥ?Nz3sDʏX=k6!wPx -k<` JOɌ d{;ϥӤh%},6#o$cucYkTeJMs *:*ý='!1@࿔o1)OI;ÇF)Ao8?YQiv&K-:`Mt9<.AequebLO(s)B:ˇu=д':*/y`o}]8岺֙פzN,_;nj?_m __!hg'|^''in%%j 쭛Ry=%Ab\\s EJKME]Φ2>ޠo@ᔭb',z-d@kr EN@`JҢo!62nNmT;ws%;o~FNZε/mjp待rkiMvb dlPd%O@uh-&sVZjkZx-n\o'&n]QQUcwt-Įu|Qֶ3^י7vs3޷[ޞo/QЯ'^ pX,jirTQ\ȣx\pjU_Q )UDN養2fO@)Ŗ`;sS6bE@jٮU EiR9n f׫JrLJy`aJiZᖟb'5y;.1iD̑I3x x57PFWK?#^ IEQ[l{ vj^c}SQfu Wyw WV|IBqk%ږ0r:9=|Vƽ W5jyCbkmRfIT:2ye/dƇt Py)A**'(Fj_soMy/CH3F+o_pX͢/ᛑ| uGu *ʢ )} ' ӅNJo8tH116 |*-/q:W46\3QLՒX7ם,28#ݳLb@_{i RbĖM |^g+M |WEPT_kۖ۸,*r u]P"eaLR Ut0&ʋ([&_ 4ok}n *W+Q"8yZ~t#T5(kcasyRB$H5.rL"Ĺ^(0n@xT(&- ӣK P8Z`uQ$VJL?/x).ɾ6XK(AE3unpĤq8Tp9L2LjlVhx80\[R:*3.CZ1폹y蕌.-HI4k+4es;HZ g83 8)la9\f_閸}+*(Ev a{:Aoqjtg!ǭ)74+ؖwhޤ?N^nl"}@m֣>MN?=ZPnd׿ùwAŭ=_umt1Mnܮ8wno]t=:=&MIOZ(zPHݪN W1o$4$|`;Jɶy?Ú Kxz:vÿmwHt gzN'm}:3:&V vAo[~lt(m{r qQ]I I[ t-G/@j\N8#`pa'Y=y,19XM}>64' |>|gަPD,y2sޏ{ڧBIy| ^dRbo3kPTeͶ})26'8wnD9[Y"~56l!fXpbB(EJx 9<4. Os%sF_| =|1FMvkMe6Q E6# ihJ.SuKO 3DvH5L@K:(hz9Y6>9D& >8 lC_3 s2`5MOinCe2S.7Pgztd:_hRyhJQD$frhs$ǵ}rxkDGt:G߱UbD"dЏ1~>DcR[R'31wԶ2))M-y;$7APB1@8%hZi]$_Wk\dhr&&aa y Tӭ}Ȉ*@ O,-JZ>tժdVGHrud;ޝ|R"fȐxZ0MZx-_SRc'8-͢BDѼcհ>hahCfDv6bӄ]1g)̢v\=CVE&Χළ2cTJ=U V >bM^4,oH4TiU5^(\mVznsQ{W;\FbI/ ђwIj*\2QIx2'1t6,sl7&Uww)aW93L3`|"ƳqltrVPY̓]csK."8'W9îTd< Oj yLڶB⃟VO8F45Zߞv]G$]׼;h!.6Ω(4yrvWgQzqɏ-򞔔i*Y#z1L,v5ՍjvPW׶klJe"7o3PnԸ[ 4H&&'m߲e\gq3@_[܆yw&4U㭩SۯʉW֐>fZ,ׁ!9ÙhmcЪivZ )Ɵd5t7-w,K0-\6pLhTG`93l6?[u\Ns +mb &[}frZ p(˔}v3km~n( AblpԢ{+!aVd-giP%ϋ<˚g 8N.٘Ѹn'\ ID@D5F0[TS]lrY ;SL;T5) &9XАTSchjg利{o6¶)[9&7wqj랥U\tf-W-'*  Ю#϶bAr^JBt|XI rl.L8 \mlfCﻠ`l4Pp.brD7x$|V2ib$v< X[ ѵ2˧$_NO_/Ŧ:';W{RqEE RO_Qr6.zV33ۺN4-qf3%9oI)R s> 78~X,c>tgRlLv6&@e ;x hؑ'#'HfxĠJ+;h7Q<>o5.Y <E-G 57>J3z7;by1+D0f@݋R 6}CrBvg!N삣{Z. F?`wFHl!*"MLxR\jᭆWgM&Llkq\di\09%睍wᯘu3;;<>9~GhWn Z X1ǭhݗzϹVI/xcUo=NDr#t%N}@~JH5ކVEc|5-9oV#;6)ug n } BTrͪ;/eJFrsa ZiԘz.&\]o#\AM8RHv][2+Vx#Ik|+)l犱ƻsv**4o2HSxB/B֥P|:9^f0$&(fC>x}];G | Fh 1E &lVD'-0+heUqꫨrO<6RzKq^}',߼|t-  ߿K/C\L?oE=nǷ}7[}N W myfuSUĥZAɥI/bp *!Pq J+ 6w/b?h[΢+rmF-[F=*e WϤ;5kZƩ0 ƥ\WΛ4MI4t,)Y: N~nZШbY O)HM$2gpL~&o(9PN^G<9GlqCJ^/ YӪsW29N Hens]-Zũ2ge`a:\@E^<}N۠2"kAS9LjJEѳCQTqc, nIhN^Xøc4 /.rAc̆UG Dùm-C Cܴyzi#Φ1n"My{dOcAqC'ϢUJzܪC0H{6Npe'YLW%=f%`uma+_EB/vFćҊ@v@{I[3&L-$e7fV|p׼ΰ AJ֫3DX1h)Ŗ`xQp2Zac'R\7l!2edo4OLǣ=_e@A|PO[o.eFRĪGPJ ϰQIϴrO`Vk{yI$*qhx=xׅz2E= ߵZ\CYX\ڷZs;z~`jRP^22(^kƥ ư 0,ltpϛ^CS{ 7z"MWgs1>,p4nbt8߂ ui xW7m Rgu)+37:,20cS#DC3]5d ̐zz4tЎ~Z fSDBWP{o$]OSĺkhS專z 4q,_NvBwrJ$,*d\ c!OJ#rbG% (zP6Jq'eR~UʑY|(&Q|HCV^zBTo"Ce :[Nzy64Q'ȼ{S:tN&z ՔIg_p:ٵe'i\㯜$޵ؽ"/ iڀXJJL(Rgm(eO.i2 1/bXZbcq,MW8혅l*B$gY:7#:J[*J029:~fۓýïx^v:-:.3BVMR8=CP&G?pfW(C_1έA'+o<*$^wcԛ>筻 Yu]ʗ}Y1#AĔ~ ŀ @R|"6XmdD;:7)8a bmKr֚]yJLFAl4zw|F(HmCN@5wb\nM*Ɂ7He5{b0ujO:H|A`"ʎMKO.?slRwk:ONmJ%SnQK3YAպ~ inB,ſao+Ë) 3E 9NU)/Z3%_EAگ1~P|n%q*0Yd)dgEmsN>hސ5(ϛ$|vgGʢ>QwL\%]cY|F>,3^{iaǑQ~/# Neu}1BuU[_Q^HVSvB[2XrٹXIf7}:OZ;N޼:nyMIYVi7ehQI3/.ē.9c~cxk2HќkFPO#NL9PwŘ六3ן[Ѽ.U5}̳ åAq9ucv7583ƭ:_v7{${S<%=8v;æj0rhv3P/  -f+9;JևYwBV֋KN1`Hʘ"ю[ rH%w8V{5>}^~uz/R Z8]i6v>PA|3YYB,\5 8-ڙ߫.QV2]jn[q(rKX&yBdB5fꡇigz;qoxwtN7'e.JI #BQ5+yeLa29#' j. qR6WyN%*aKvvvvܮR^u'^˝x/]ܩ/wNɗ-_yƫت8ݚvh>i|n?/ODa / }_DN:{( 4*Y]H*F H).*hr?Jll*ʴnh*4 9,[JG=4/iD E2ZHB2Xo#DS>'EY<߳k\ۊ}A;'JP̝0w  W_{ɿ0}Y~I$UbfYJߋa^9&J<<6*uhom-%xJ,'T, 2vӜ!TbafZidAؑ,}Q^5=LL¤tt0:;4?З]pmMG%alH?Ez)!.f-ư eK6%>^ hIzgJڊZwAbך&%qRff^a#ǡ1: j1MgPcNV%Q\XT7ݗ4&#/hE*dQVq >N2W/As~ƀ.HEK)ci0cУLnY4THvy^ qodxbNGJ۳ 3^럲$6#Q~JT[Ө=Bvɮͤ 4I8\g?=Oc^6mLQA7zy(eXw~*fz=W=>U"P0lg$qDVxVtU xEaSye9XҙqVQ:IUqmo[؋:v D( 3G +PI_SѤ>rz_IP8QHhz6h9c \ZstfJߵՒƠid iX`14WBFU, 95CCAZii<(2BRL&jDq8rP++VM gu6:٬*3o Ď XC*p J:DΎb3G8wWϴB8ap;f\g[4ClrCiяf{ndV\xӥC؅6n{hUVå9 |:*]5dyaU4x I%S9VCfm|B Vv`OjU%UQbY +\aˁ{ fj5h#\~mẈJ|^kЅ &@Pt %Y{{DS"ZHw"7xc)҉sAx0*پfl%7.!w,QR7(b<SpV!,Bz=GV wv^F#bcr%X$&egVxt"Qd w;ܤ̷o?W,y+2{gBLU,IrGhK< >9Y4DL#䁵g0۠E؍1r~5$K=RNSn&Ot$yOtM䱙ŵh+VizyzOac9+Q&e8` c2jmsRn++.cu"%x}Ň lAS~@5=e * w<IeR/Bdk3ƌF=}bq@؍E5@%<3BuwcM ?,JS2A_&1ǬQT?n=xӍQCӃ<'k rs6CѣZ U>7]8{{>oo FaR5-҅Qm=dy}Jut욣 U0'rƔH)EyŠV" iӻ圕ʍȸO\)Nͪw TY}X}Ez{Ϝng\ Zv fsL\0۬ s*z詈4>P>jxp;.~+JZ*˃\4,fYm!3b^[j}AU03QxyW[%LI β)7벻XB3UBy*Cz`ͪ: B<4ngpsTAu1*f;gx;<#ߋx&zFa7z6^\_If0nWh#H+qwm59 <4<*1h`֦?%G;vuy2pq.aFbOhǒNunEo*F2bmxD7]%rV u3b)VW@YLeA 2"]iCW,l97įJSpsiY<:)Ty'2]+>NJz8^r&[1H95jHq{@i bnR 2릅|:o%oڶj&6(؝ &^3%!"S iVGeALZLVY.~eGZf䨹AÚf/fB>-[))[&t$fa!PdW9? p*a L !䤁_dS%\9IB1b}Pv MΦS"S+eZL3l= 9+ BqMFdp!r%#6pҀJ"Ibh)Y̛ \ /X-;)+q'Pi]r7UpF@)찼<߆쀫Da=ޕ+qnݏ+\z>K˴/{O`a%&}w8)ʸ ^jY$ĻvLB=J̼͛n;XQq_rq‚ϽԟI\* e[;-z95C}E|'G_Hǻ P6"aVepxAvMW&1*$[N57-<?7k>Uϫ2[6u6.SN{=vm=R^:E{?߳XyqqPX^iMQyqH}6 Q6vğj/2= d[5d+;^Ã~gY$f'U\ri+zZXʱ8'mӶ`3l7UDf+8{H<|- pI$϶=mVeOe(N:?`nMZLHJxqt5+.>_VOMn hTnJab4弙fyW2S<y388YJŇK}®df{/'6S.ţe~;{M,%4^D[P^ѹ]Ɛ`h/6^͑cud-UW:nlnj ;w-_TI~ˢ*&5vo5<d^oMj4Xn7O~ҿ|?x7-_J)\KsGW&|I,;MR6c(Aމ0Bw(& O:A?_fV?4hRx= ["]|WxMMl彏7XgՃݲ|Gz|=Qj\ͦu[?亠.޹w꯽#+cc .o>fE釛)\unm?z+:Q/]>.btSSҤuՊ+ZHRA:J+g?G#o(x$O1PTfhSb|Q>C :(G~36Mm?z7GiEfk\LQCH|ۍ'[?~t=֨tus6cv߫U~e$zէ_ri2][ԱJT v㳃3;==Nԗ3>}uhvobCrwic˫Óǰܓ_h|4Y=~QnF%L}hudoK%땋DtT?Mxjсzj~%f +` >[[!$ʦKNBdõάOjs *=~|`VCO QYBQX"­wX.7 J#(2]8ӞQ= I 3i=WE)Dc\5QkRuvC :RBel~1@@rW*VYIm2xbY]|HOp4} #;WWWoM1?TÈW.oNPq\kL(*m,MѥNذ-/Y+֗X_cTaMzGA ĂzIAg(I`7 ?{*CpjsX㥆6w m\2Z dKBObn@|#6QBN оI'J$oq JApMy h>908ut@P(9B!Y*2gE`]wkj#}p8 \d#񺀜~|3AҶz1:+BD/f [{9_X~D̾LCc.LXM"Y6c7YRL~wtd%y#BSf o@'#˶JyHyv$nNl0JMn~X `@-Wxm"PĤo+/6buP~EyܖHm<^<<}x5#)ͨNU2M6–y%UN#Yu0yWGdWT*:L[B]A38(svM+PN疫Ye[.Ad UG^hRp ~]>9n;-silB EF0~.(\>UOɟΟxGfTH16pvd}&M/:fn"twRW-$~ ~J½Ӭ+D8z~n yfsB+NU2n0,} )/B]g#$;ʦIp}_rt;J1J_Zaq dPDB4!=Dq8]. s!|$T8rђh/yAQ-* mwLΰJп!CN bSCw&G'kYҎ1bՖ D^)f\K)Ɩ"ωMEC,N›5;ʢfhF!acB&HL˿n߸ŵT|[]--¬ R_'c2cE9Ԕ)OPCtIGeI}v5bڭfOf  6=L~V5? ˯OAx04hDd8+PaJgm_iԱxVEj/!㵻4.WQA.rݧ>bD_lȐO!5+f[^z*LdXBf"Cz~8l}+әk u)l*k?eqv ?fB  !1gWju PT5ﶌy/<0:GSF۷#iΧLO{=BV#g^F~;-3i*wVV<6qZ !\f lL+]մL#JR*b^I435V3|iGγ\(R+$=&De&'g;mkɯŠ)k0V)Gce_fu/" {5SkpCH/mon@,|/#3W/5rI. ј\+v4!e}$`LRb,kKS/6\X:B_/Xn\nN٤3ەft?Gh}tjcȿ74[Zϔ6tH)ڰĻuvN D|ɓ5*BM6_mڐ*q5p}@1uM>pYzo^C1?%cf:=ƣY<҅'QXBÍ@sIKԽg4;=7r:GO\"d=ƶTEL#N=2U㚾nѹ7W"-7Fj)J&[b!hIv$3ReP!-W.6!랴j{oGFT k4KUPq2'yL\: };3Τ?["G zQQ \&jYyaԞ.18/ӷ)M847[P*Y&9?_E_VU2=,ַ|(-7MaVsn({1s[b@O,MR)u::o6 龹#oOE+(z :?}i[:୮[3I>5oGPHfbB:7i9mv!]]/6#DL>$ q)\7 ڧHK,/s#pSzA.6nxZU鐷 cdxheqW| ƴ EDdcL (P Y@Y\@^cE|s-"MKTH!2+ߗ~_ɤ+s=ߟ͟N6N7骝(]Lzߜ[ڿ|տ{8AE۾߀F{ csLwgX. HvwZܗ @S6,_\;Vܵҍqԑ8m=p9٘/\Zvq-2,;8Iz4x \LCu2-w'i)lEn2߾JY$W: SQ^ը;:.}*r޵딻XHcK">i+޷W;'BwrC,j\H mp&"0M?2T FKk_Sv|D5=[nztgK=[pK' mwi6o{Hv7!A)=5#COT%I3Dl di2ܲ5Rp#^R$ Xe?:)iQ{#i`@(u< ݗR5?GX# 0.w!U`ܧDdD(u?D}zLNW,E1.n5=z QijSazIVgi0]C&u;S]Ry\gieDx_v+u[2ޟ ZǢ.\K:&)z!fi"sr X_<˝W| Ģq 9Is̀XSٵR ;>,Ԩ0B6%扉%w k!@eڕF.K]Izݦ9I\Ak޹7?)!#\gTː֐V#η6Jgn/`FwMɚV 6q :x4u@h"ij<æXNqZXF yTtRَC¾zAn=>4n zx' "#wl}Of ,6/FNe+_-B:W#ڹN:l-c=Z/"w 2u'â*]Qm]UeS=/j / Dd/ u*Djy/ma<6{q+Jdڛ:4̋2Jؔ0⅑3|Qmרüac ZG%lܙ,tB/#]6X"&6YR+畕Iif~h>d64:|PJ 9.8s;ʟos%%1ڐNc۹th zBCl ;RJ4<7ٖ9*KĿk:z&*yxpi7V.2E&GMk*׆vjR =e[p=nEw1 \ İsVCXEfk*[QK=4Ť#XI"#Jtk.(qg0cf9鼹BNI U?PPlx$A֫AlsV8X|' 0~sheQDMq5Y6AaCIj6C֏4ݕi"„3pz$Lsy0,ܳ$,C V,n~jo㐖RO7Kp;OͨX|ދ%n: KKr ~@O~HBWC!HB8q9)VM^Ӎ 1dU*&<);( %N9+6Xt`P2z_㰥*z tYqn/icK HF1P/Oh:;va"XGVkTdWH"fFvI/EwJ6}jhT}NCVI` Cqw; })?C;J[yp  hcY|ߵ +܃=WGg4W)$AfBD[;l KpP@؀ iqg;mf%n{Yf-C|砼{8 q]٬0 wEG^:^l3AWbtQ"f g zĚ(sQx? cS)0A%_C q[ i(?h?Mly4n^EfRC?uxZf3Fbg(:j#qϗE U HߢXh۝cfyJ+x9sqxx[1RQ(}l7-%B]EApP ƅrŤx8R<3C:N sjK z%'km4!t!A(ߞ#u5/0pAŐZ n%uo]`zp4ƾD$#갽1ض=X\m(.]n/5lˠZV}~Xv/(.i@4 7kmKE0)c&9@9J{:8ך_XThm' 209d}Ikmˆ zS\-XL_ MnhέDZ@^ 2~ 2 J%q\Tavy@{!Q{a^ Imk7 c޻~bƑ!jgd[vPCANd;Z$Ց ^wdn{k,I$,MHA{݇EFHL4 ‡ z*4ghk+WC&UeVa%f7ُ V$J FVFZN- S^㦌J&8G{Jj+hʹaqAW}K_4!#c%- dl'D.w=I@H?p{)#E|pxYq BZGrcw64A|>X j7Hɝ-- qk^ݼ<7Xhl.@)sd˻@tHcY0XW;E:hzaWarzؾRٴ݅cur*̒5LZW2W? <]Yv" \cM = 7v}KR"SVAUŞrf;a滃6 ‘^|c (B&>}dGHYo9Gyc?Y9 ;Ih?n((^ .z|^6@Wc61o\I6`ir y5JS<v&W%ں;T};8|`c]~n&E>,qVG|{q(Zy}sN@tIL?BsCm jamN vMQ,8E̶iɠ%Hg,XЭgm1JZXw*tP1(aȔ$ qcB%Ô42dǂlH jc 5FP6Z'Өrd]_b:nXvVbhP3"s[!ERY\"8G@%`Y#9:Gy&]jghx]B-2I _nj{=,Yekc8/@`"NY<:Vh"uN/}zVi XqBh䟵@~4qadLt\=ȒzC?ߞɃx[r# "&;D.N:Z3u#8949f{OO4,XLB^J)G|oiae}0[HU3'lYcV&A hbc8n+w kҠ*+SLUOң)PаP6t O `ՠ%4΂!I:LwVLPH(=˽.xj4-&٥$18 rm3V{n4NLZ$x1RʱX mq2Tǃsck~<dlaՓ/Ԭ.E&B3UHxO&3j Ll?>|d^M菈OZVawDkVmخwQ ~wK>H1(ػ2圡3Σy7>{?Hnlo/chHp/a-}%n%&z oqk῏ۮ]Da/,]pdS.{Ils% 6vC6sR k'N_e6B%Ac|xuB?`Iiŀr.?;w?'b42G+2,I_[yj^lHX.L$k}F|ȼJE8 3}nM( =l4Jͧw ]Kuc>lQ<[”C*5O"SRSdIlyafwU 쮤fhMmg:-ny?32|?W)b4'i49 :l4rY0 g۸q". 7e&5dv,q- [pm ^Ug "mޤ)/s{,X0k`}.L?.H˓'`5+l ml"oqA'juve5~!ia^,vIeQuoSm \O:ή~1*`ev}lg \( ru!M{X'AeeIUAf8HgǞU48cP@Κ>"e~&"bZ=B/؏vHCY;*WnUXh uyhFڹH@d~V̺M/pٞjy}A$z2$uvF]见L5V|  Nv<W.s/= B)ŁݍL |1/gUFZ T(z 戒 Zw>,ă#xnzײ9]Sq ^#U,Ȼ+O;"lF~@9`I>hw1j [, jŀ%iPxmjmE;Js>KD7%Z"tݼ/մP/b( ӶWza8k0UബT34 dmX QV=0=6"ޅ#FW7(:H9ɲ))ymRIB\[|`f'o""wP-kkahM3",ЕČ([4\MYw  +6z^ OC67sae|cst(O`S5ʸ GCO<1@y%/MIs+I0LBoKJj2C z9ST\0*|bH|Se =i+QıuH gФ̖id`+,ݢ .Бrވ105HCt/O髽<.kM婋ycc^gsjVR:X)铋s.0zsQm.[~bu(p۸٫2Š/(l-..^8)xĶ -Џh&5 Gq8X$hK%#M|\9Ir=>nz ~T KuʽG#}Uw9܂CSÅ֭XWt&UYmŕ7Fwe[kF[+OOHGu>XV1lDD) &E˽8یr.j#_0h{7g;AJ`ABw9d-:;oԐ6C}s* %*rs7췇ٲ-3<+rʶ0UGM*nц T Ԓ͡хe9#97 UE1 Uv|Qn;K{ImAJEҋ$6( ),بrEjƴVt'9#vqFMs(Na<=H-mцPa)ZM[Ϝ.fÚd!aJcW bCi u Ĥ;0KgV f.[甍'o̼T2/ gbL. p;^NFQ$ykR![.&{-3 3ԍrN+&@LH(H˛ W<P絜]A]Lba7@HT7:K˟}l"4%]\HyóV=vISh}uzT[YMH R:/(GE/ mϾ<EM }`~ }N!AMаa>ț"WW>r;\;x=FͿs\< 8.p6%GX{ ]֝Iy߼gMG#>9]頄r(kve>1/V=_x-bd츪bM6b,2.ȑ'g2Y.ق hv ukP$bLkjwV=6 $,=ݽݩwb\8Jj]l_\T8lFRq &0p{~U=;\07qA/a_~a e~ٽ_vo~|l/W}ݑ5)[Zz^ ~(`LNy|U.;uhlt`̽ 75S&| 2،/{K$XCmDTiV `rꅩ*[Ɖu,xaTzJ\9gfl|rǵ麖J4OoFPć{|Q5c.t܃Kt3uCbq UpF Oxvl.ޘ,5x{JlS;}q_m %]!/Ip,HΎ)iyq7@XFih)"v=s3$Z<PzwWNom+1O!`(&+٬4E{ L#eZѵ{~i/HY-7:/ҏS59>IoSՑa l}V0}!d)!PfCog\ڥdu+~GbtQ4&fO}=\ܝH:aLW>u睅2MT,M`K $%#Q.~B3^yy<=bJEL^fzvx3ut|з;܅tpc^?7DܵsNSeM8f6T!jߢs7]ϴw[OWxxPtٱdvu JM|M 6JB:֢=VmI0z}/eZAOh?L71[ g4af vP4Xh9\˚H!׶ d [SS3Ñ|`PT^6$*ɔ1t€q?&WhFyeYAd++u]~/*k6]rqopѱ\Į]Fg ~ ¾$"p7Z1$\4eHKShom`L#W*GJoUS#2i𻯘r&L^w_m@S|_gi [VEьsŜ%?tXqӖV#sz0w 3[z&ʅc^0v op4 bR WTbit} ց*n va[01n<128#/Z,[{W uNbnO +k.M?fYl 39$(X%qFTdǼ64.6&@na<0+0~{ |\!_+VHv|k02eEt{ ye¤taH62HxK힅x AYO=ȽUK>РD iHVej4+ug,)ǝb5GL 5)x|ņ1D{pQM: 5e@Lcu{a:ê7zQg[q^ZaF%Og[;g[϶>ᣇl?ysrĊ` .'U?br#A:-eX帼.ڱBbtwe 1.jbrN3]Z b5!j,2AYZqlwt *QtuVuJAa7ZꁡH3uNE7o_D]{9i"/{պlE8P"gQ7{Q3.9$O  8ruqL! "@K =6 %-zLȱZ~gT-\XXmqFN+%_"+Y>עCVvx0po} ^5} E_>fVl FOLz P1zlG1ى:DSa <Ȗ4#B{GP 3] 잾mTq "D&;C%]9 C̟RGP,ɪ8Yepahq5**~H8jz瓕%?ZN`0g|B(1N[VZql0LU\%r (O5mMf:ԯɴ8+Rl Vˤ\/HxYUȠ7ŀoUxM  e kb!KɏJ&d1 + A'FH#(t 4XN]z=R)<`3V:W,YKVVآf2kJV+5:qUSYD,B5k@q{&,~*o6aRVý9T%9aXSڑ ]4n_qh uaAx`|]fsԎX`h$lWQwsz ^x`?G!zq|w''C?aQO%~x?S:.Zwo/_rР:*]8dړ?K6 r]iPj|~{IYk07fv8ȇ*ӿ?f[4StdԼr(V$୔8| B'͊}|F[h4Cb^b{b'&`K*yF!>5|eo.!8O 55]3 oNSfi#!M.ŵvo}npJu&LDe"?T8^|dϑwgG:0@}PKݳ3ҥiw uiO-ˤe^#,?8~7CJEIv)r{wD? '@8$YxqXScT~ErLlig`w7ªmvq.إߩTY5KDDR;Ͼy,VlqT*]{Ov=*y)B&ⅱ3 c%:jeEdҹJsmR&Ma#N 9gth7;ߋG8h}=<{$=+["۟A\tXJ83S"36#FpQ1q;i;}gO#ۙ8W|N{_odoo|Pj%DN^Q K^xكnXI.$@N'D%JLoJ%N:m{[\[)c| ru ?H83i':&Mn6vd,eSqwz!}}'>eƧ/{6J&`/ jTa귷8]:=;8RչH$Xc $(cx,1_m #JxqkJ,9 6'=Ë܈ r"[-S 4sCzZ!ƹIU>sۜ4Jح@ Ef@9o^i OC&WȭԹ*JE4aR WDd?wO?H9GsIeZ ?Ѹ"ŀ`::ᑠayEIԉ0 # @ W(ûJd*cc:qY XWG 8tBz8y> 䭬u n ‡( Y)}ȄJs3zJ o)w) E '+ZV!إsG͑(.){]yk2h)^(@ІAH}ECmr eקrȤւ0~mƔvLkrQ7Kkד~ `QL hJr"v~6v*XI!=Dp`фAtkTOVeg`ݪgrź׼9XQ4]*)j3Bi3Oi0#aǚbD(Yp3$8)qVb\ZH+i?$Fz3ELBP%[|.n'ҧwAMl.$A&:DLMA`b*6϶l9*{ +pLۏ7v;O='{x#=0B L&5+0l:2dI)5h.i*jvâp_J? !*% LFVbH FjʂQK4ckMeFj0{/y.7;¡em~Uspح2ajΩTB3ծ6R"Hppcq1g4P0[g.@TfŕΧ]ao"gA~azcZzQz_šf&!bRJ@ n _bHIbΈn6@}K3ij3djՊJJIrY A0cK<a k-o--Ң6Et<N ]*_xl3qHWS}߿>,R).fǑt"1#]#&JP^.Seò' M /GC~lr2Xm]oH%G-piScM,s%Se}GK࢔U# .EUdl@@UmQ Bʮ 2n3p*g)QY6j9oP8*h SB܂V/o) @g.kV9SP+.ba@ zVݾ7k^ߕ,kGy WR0{U87g_)=Raα}=wux@f_<<#[xΎS!f:S>5Tf pH*9#Nj #I;oxtSgWZO ayI=\Y˗3Os/i떌˘15xkk֚D- <}DLG_ʬ\ȇ]9V jyawePAbysu[9DZ{{ 'K<{X"Ų۬J%eqRߵL|;eSЈ3@k#fkGl"x:T{Yw4Nrā/k9(U):[դ^ ܒUu>Pe Jb6a<)g]~'^ j-aGPN=58HrfSR,bÕ;pxPv308J*jP /T[uX3YXe֟{qU65 85m)Ѽ4jmk,K՝_Ezen:̊8?ۨH `} /3jx`ll +*5J&392ϣ-Sևijh+Nٖ%zn.JM}vSU/o?A$̊ %"^LSHQ!Bľ - 4GDL):FkOlh; ~dS,H1+NTalV Ry5pmSq[ق| ! d!T_,?X`]&#z SwU{jeo㶖Mar/'&߉r?[3b<ڢx 5IA(o|^^"D#(ŔTl~^jOˀ?f5oí0;FHH7)VY\Th^Oݽz.8uQ[~X!N֕=RGjF7 4V,x-+@!A@_RO7ޛ{l/bվQ#|}w&{_:(? X}H 6 aȄ` 'UpiA AjmQry^Xz1םw9RW.ڣlb6Wk c+}~WQo",_1gŭ^KW]k~R~\^*\=773"\+&L‘ZΩٳ|1j['{e yvI=5vW1PIVHLn EIJHaͩB,$.k Nbw#X,ڶK]ULJ[uf4E׀|m㷒M=K yO/ݳF̌N+]& x2^QA0;=?% (B\aq| F>{.r .[&Mb4%_DxգaZUׄI!1GW GpAX8జ2vW yWd #u=|Kb=V(zc܂O0P*߀C&5V n[3'.%l WiB >~ѪVO43@ԬlP+q>bXZ]b jHMT$ip >}`^.0gL3eL 7@n\XՆP:Êyw~/o,f9**0Q{[42lD u\i%+Ű Tke&j[_>b< hb\y}q3Kg}s25WYuCCs]#>I ;Rt7_YDt[OK@0I`=JCpw; ׿J`沬UzDC[o(ϫh'K'Műr][unoo~tmrjGJܱ pSz}X0)L'└SO+%$OO˼[盾pV1oj19F#W tFEs$oOv»>0C}wwQI>k\3A[)>/м6Q*MyJF7'j<ލ-/y3ZݕTPx8X Ovj!E""9Oisӯ}sD]{D2fGyp+ueO hm5(hd@> ޽ ܡ$'dTA[f]x{ _Ybk01:Q1!#rE~H dY224F٬ЖpOUEH|>!i;9gg*)3 q* >Q pO">lj41zOԎ] ^D օjI`{.*v,7׍8G_(_\:TjŵYʝ{Kuosd]Gޤ}a6g>-:QRMp_RLny4Cr&ZJ^KT+1;]/1+}R#w,;.f_j /@&{jTlߜĉ>Z2AXdȂM\ҼCGss6zCXRli˽OYhnUfdE^2җ(+^Ue'[;(2΁?ρ;8Pr.3˹o6yָK؟:> o1Ი]%yՍ]|a9T-\j' ܈L##TrrG(I//8{K8Pto*$x/]Zb0e7CۦmZ'AV扖5ĩ"6zih ۣH΁$ͱ馞,,) J"ְ4( 싏/saav~?=1h@C*BSA4c:ݞ)4a',[-bTq> Κ|y+v()l5V⺭32秎ą05o"L\A>$H Ht 8Ai2C`v{8^6BݗrӢ+Yrl $PO5 H -yfa?؍I ela:K2o-6~lT IPdmpO&7MWFE "&JRꑟ5+G*T}  #%\5Kmvۄ}o`^!3d 0fvo떯!j͟^,.5HPwb$(7Sc #^ߧ%k)PD2>yzK#-.z4~ ȥLČ;'~~`"YG@s7S !!1#&!.-"ԭL6%@f /ʋMY'XëuqMd֠lza? Fq٭ܵup  yG*'䝗?:5ǿg4َ|5+bيQg|~^Ʈ*ܳ*2´4!`82  ` >-J{BmKA/s ?!A툫"X|Ud67:C9^!tw6jM'72; @>֦mf.\|aRћBꤌ[*:ZrPΪE+f_V؀uXN<wa:qwQ $PsEgh|m}v"꠬rFσ&P1(cbx@۲1p" >NxPJ7CVl؅B#eƂ@_$ydUg[Ps]%а\‘[["5BKX)fzަ1׀Zt| yuک$+MثɓA1ƌȩi!̴:X:"Ae 1 66Y֚#yiZbaQVm<O1gF~q M伖N#q*qL-Z>hw2I HzfIaio)wJNYYʪ .2\`'og;FcSzJM6n&NO>N(C"ϟ{?n(ѻmd# AÁ%i٨slyB^C#/ ų\ U]Bn~ݟ9vI#DiRDtf/ds_Yt Ւ DW$?OnVŌ)v%I1,#tѼO*.Cgc1A[$q lD@d%I+X:E{ku%WP+ܿ4Rǚ ؖ+\󪦃5rICZs.h%A&F3̣.-Ep;e3ä-ѼK Gz}VXKiK)"1߰gY\[8vyLvJB|ۤjF4SK<$3m U䗱Om- Ԧ~ D#|ְ,(Zx f KV&w~SBYSL(+bZWkJ`vYaAběVW+*E:V'.A%Ul[C.0c{q<&& yv5PB) ]_#ޣU: .cDpu]٦闌[E*YM%<fWyJgac8,s E ʰ^yu`^5JvuVcCN࿿={z`lrCkʬ8 }J):KsUw=3BGOxcTrIX1&F/߱A١%ޗȵY,B &S ++5e{UUvǂs[w`hF?6TdilڿpHBWez;XD͛Gfuݕ6f Dm0Y|͈mÓߟl9i%' /!xKOrC?\7tSy{VJ%:wh"TZs?x{r$Ӄd` CTF$>iB43 x9<7FWx! k lvofvup%GnN1RAIFJû }yLx7=NX"HJ''bީ53( @N׺źKqG~ ʳ %:k%n -Vntr h)ԨRS oJæ y7J NEH|j"#bUo"b#cβxPi_PHZ)T%:4X'dqn̍b W͂K>TQFs[1-vt2% - Ts;`e,"JV0MG^Úv#:/̰ <43zփd?kwqŷ\†+A{K% /;JJ1^i) OPk ^ Z4Z}l g]KfGOgMÕVZܝG5&Yh ;@ ؆V6Г}涞܋[$8,yR!{~Ȟꫡ/jqCCe̳׮ H&z.%cABZϰ6BUEAUȇl(V)q׋u?ۗ|#1rȲLȞtt¨ 3jn"Y!fP]T`A>Lֳ&6r3P=i2;̖4*7aD 604ӱ(..'ʧ#wԑ:f#f -hRTjHzrsu*=q][ny"fU+N^r?In=&8kI*u5 cXusd~!6_0[@D0'6'b"di;/F._9R[}CZ/>7sxN{,}[I77J`qDR7v6r3O[fa49nFla}(ly!i{+xJL7qCgϓFo)%#iZ=)B}0_,r*3*o|p|\Q*3 M*Qzs/H#̔ !̈dMօCϥ{Rk>"y/4a;c7̖/䅓{A22f/DrƮɮO1 @]e;msk (5 { NV5GH  }JeufQFe# L'[IfYv ;0{]Rdi?-?7`F=-| `;9='oؙ- >,N(KIlAjL H\T $fg,yVR s!U`Lb|{8 ) "hTr0,2Ӷdm*Bh, _24Q,#e!wE&ުYu6I"51-K w8:-WzYP!+Һk75ʠ&jJ0qe/k˷4PcT ӢXdD'WE#LEޮ>[b+%>'(7B2nHpV 7Z7TrqCzsi֟qt0ܱ Lx$sCiRQF9WaYV)\2GK _eM\0W,U}j޲Ah$\ĒH8~srx|4Lw_̐m짦;A6k."*]viIMH3`/yk(~Am> &\&-_=An  O탼&n0g}yNGA;!RO(FY?q<ŨOz4|=:wM WF91j[g݌MTߚ_kŭMMӽ(w˽fQy1>=k F0:bo2gdS՞s}P$vofsk8u ?u[X"i -Q;~TR͸w(9ѬuUw~)(֔}Q3g5!EPR,ןyW>uh3\d hټ2>.iW)9Al9hnko5쭑Mt7/A=DeџH&Y@ыgFc%WPUmzOhЩfp$#$"yseqAXجWnzۡ͢\Y+*Wru-̞{ԏ>@/gׅ2auFBɴzcS!#<[L ϫ%lPw5ge6wyIdDv3+)]=Gb\zͭ5h{_.~mYx-ZQŌ!/C&0`u~\Zr zKo]~"`q`UŔCK(]bG6fd)VRa.!Bg0lc&w?cK29Z_ 9%-W3$MlrАp7|NY5"mtjsi^fBЧORf{v "uf51 pJ;1U"쌹MS&ivʟiUdz1d6紱og^7(zxciwS+MؐfZr|Y}`OZ?y{#Ȇy<_#:sh.Ĥ׍-o5#.#_=▣0ױ;rmv1,ש9h$3|k1[|yC1Pw }D G/qrˇ]JZ&MI*1C]3F{s.1<\M ~3n#lu&nz {1Y3d%mOY(juad3 ]J|̭J[Ry%3s%r96\&6fΥ]ww`P&*[D{G/?61w~ 0ILM\V]!CeL@AD#  c%s|_+"FF9]tttt.^ {Ar/H~ WI%ɽ$$/I9a9chi čeM!y^$_~v^?xj#)Vɶ|id+rK n[ϗ즧RJRrxYqG<}ɺ'U̴ۮf@ӠX;Ӝ%*(D ~&% R&+9;LYMi-H}y5{=^ jx0ɽ $ Wiʃw8$ lm?( 3d"3O%b7&_LEdؾ2~OolFs6y,VK*/&iJcߓ۸}$˃4!zxfv.w[L_G؛Fm 0]#,U?I/ VB$#?Y }fzy%eo|4&,We-%x"ri Y8a=yHĿPTCTmm:0+dxS$R!"ӉDh4!%}XK!x}e+}3N em r$y[0FZf>*-qM\SW !5 ܊+Jof8}VSר8BA:͌r'ZR=ԝyqŲA^ 'nSғDŽ :2tvbHh:n=E ƆzI1M 96fQ( $X 0D:+o3pc}^|~؛̭X@}=rVߜ/Ql5>ckoR+}aNv|EK;5Y3f \"2 r^6j72~ ,7W~2y7O}yK#}ptrt=W1lb/7E-S \[ Si-c f?(cC%rY TȆ9z95ZYH 3shE(#{a`#9,>B2)Į˞w69ɺ*M捯\ [>V0t3uKS @ 6"є{jxI[I, ǵHB{60HApu\/-ٽD % R ʋ.E޿pjݟLkKz0q~{"J- zbqĵKTp%cD7^/^$ɒi*J.? s( F?#+ =]m2m.Z6Z3PZB_%asv pEvaGNWV*ڪ%Rv #(֊!ʫH{EtUc`ys"&RLK%S` BC b 5i=g=tنK=;pK)NGgLWxȄVU<5>*mJږ7 #(xn.uXڞx~ȋ"hd*=]`ԻDaP3saM$ v®+a*G[J on!>\\̘h3@KfO׷p>ӿKm8o΍Cڼ5nӦ#5QuoR:O#dti"(Vݲll{ u޴9-Icy0l283;C  Sǔ*^}QS8hqi,& \dp tG߭mQ|lQLYD d0Ƈʼ-^^["`ߠ~(tp9 ^jzA-i^-ֈu_d/ۻ_n?|W?_=}ߜn?}㧻Ϟ>3}dxb>MyL.{ T Y|ff}B~G'kPs)ye=n 0۟ͺDzB@xo`j]Ơ+oBe ^D zX1CtMS'dθzl[;5~4⮲!YgP;တX/΄4-lЬPtF͓ab,`v>mNi2$ƉzM`1*uawK5kq+nXca) :ACqhye0.(f6ĭ Ն'ݑ *bOϓ,#7a.r8{Zmg:׸%.fIBb'.?GWp\3MeZ~v 1)F'! f^](1yf(ɁQ$D*&_)/?.46YSJn Ii7KFJ]ⴀkLז[C-¼Pv͛kZa hKMO^zQ8Fhۛ_!gS-J0a]fATF 3Dٳ(tɴ]i<D(RQzL~}ΨS{Tes60 zMo3vvMKڷ0}]/aT<$-Y!~ض`K1ͤ3ÑADLV 3acD-SjLG#3%[xSO*ѻW㷇'-?}?E#/ X<ŷ_']R>Y̾lR^X~M4L OK呵t\(zgBТ}ab C *4?p1H  => }u!?!t_=ZHR&>k ڲ9< \s6s2&fb:QZ /&Yڃ@Z+L"e nP}VhEInᴝ{/*gafʛ8Db  i3#gj$B=[]&+ '\Pa,Àc>pRtT2GiϬj:=H2'MRgR}>2)OUfG-դB?3fywAU~lF~ܟШƧWy C(habhNg0>z4_lSN4shkEr9fw(hPx?NF"}Xϒn3g^OVKߤ|dGbVWM5o])Xu;FfՇfmIӯ}/7W/GߘQڬ>`3^%6W'ۊ4:崚&rwe4 J8 Cu7o?)'672$&~cwW]QJ:p?e_"͏Bx<ef\DEQd02W:=eic^_q](UXqwO_ `lt`Tq A1 8xz8x~x4xZR⥎x҄457:5֏eēf^9<;3X>9YŮ}?ڻk]Zbb"miD慜X+a2q}9+ T3-A issS{ }E4߃G'Oca\V|sbV9GUU$˸iN3P*[(#Qwb?K[HVdDnT**D"6"5jo@"~T6>7WgWb|ury5?]k1ݝʭ>14kUCg9XB[>Nl뙲w&i04X$WD&:*R92Lz񇗣Wg'W^aǪC! B(vS!®L!o6SV$:"Byr@J$)<(%4h&k2CcBE&῞Eb,!9 AsdVsye0&Wư@& G>:W!bWwb~qH6""lX4*+b,QCDdB"@7B@ TH؊XIwt:9eM#*'5`I4#Q$leȁ`;'  觷' i$$Ij65@,NIئtj иG% o?\a r^KJJg@N@'@V }ӗ++]mtz&)b&$`@<"z@HNܻ|y*?=:& (w= Yc4UY]ͷBa&l_p^nF Tw G$E`p|g~=(Yc|q%@$0 Im Slr04vFL`׋&kӱPIVB -oqӄܬxC@>.sG"ʑ"{IQ2xN,YVOsR:# Vu>[:Aw?2;1ˍw~_"H=.]=V7*vז3JRX^I7D6|\.VE`G=uƦhk_ /`Iǖ~ KQ'>eHD( pP[kҎ VXZ7j~0s@8^Mbg{dTSbzuX`-ȕb᥆°4dBd3kX ÇX#DB.gm-nP)Q Wsx. 8 Y !d4-x>|v'AQq8n E2hܱv]y׸k'V?eUmW,T"ަ/mJ] a^S"c5zFjӔCXXDx-JI{ t2sdׁ-qpaBG^>usO@M |Zf}Fna4'2`>j3=E4XRፓ?W5WƸt*Q+`GCQ/!{PP O9Lڢsh㈅AAwHu,gVd< Ԇw2Ed dQAn!+1w f 2I[!/0W]K};3l|b cN1$.CPa7G?3r(G{wi1lYdnFa  0&뮍E-.َYI2dP$xp5-4䯟ρjr 8 rG)2"WZ0]NU6wW֡i4OZ`i^5ɵk! ]X*TW7N\.MTAF} ƞ҈X IԾ2Lt2v22%"ѣ NmʣSH?d+CIlulD/EBmc!|Ʈ lwbzrS{_ڱ8O]cxE[=/V${KlkY: pc*Z:ڏܭ2| l*/"=g-gD)O?D =z|fؒpu2~ H:6jQ d`+0Utg-9uuBB;eZQp=Q&t;Q"scwcK [#q.M(@_eg™K٩}"I'-&!e]1˽/ΉhX8~@O" -{bk}DK* E Gdv;0o**0-OƱcU|*9qm&Ha&EԸ!ȠYgXX:4T#ऻcFZџ>,ZeߒJ9 '/0w27:OMVZ>;#A:zLU68T dp!*M*q|k% DnЬZ-os'mmkRh QXe(_X<l XOA]sM{Cs+2YW"bӬO(rP6,Dūv]_F 3J@M 2)Z4W2NDo:"_+:V_4-Zo}gk5"tJ_|s9nsW? ':O @RÎ[`=cw}z%b[,>Kpk.pʔ;vE`Z U;aO[g ZUvܤF $z2HneUN}r~:\M V~&ӨP;EQW<Ӕ>%ٵFGb 1qqU5&6ydPȸzM$`]5x`hʬ>mt$^Y׌u}/wً:˭@AQ1iutp4d0q+ y zľni]׋v*I2JJYU:]i)mvGMԕ9ҍ//}.#SL! ["m6Jhsm$G2ܓqϳFc6 &Ѵ@^Má7/{N4&չ-أԞs&\7q wp{[!oE f2Mgڒ+D\UIv&l){ <SԅV5::" \31Z/ksK!{фJS ޔ-24qpMϴ'Ǡfc'e;?4Q 6("; G@0ܱK}AMS|^jB̹f%3ՍWQ,Z%V7;ITۙQ j[tLrANp_z-~; dDR[]0a~[XGեUWhF88$I:,!:WVMh?w6nẍ́8 jb/x0kL-ey˧#jw ˓v8pk˗Rj֒qwըsR6J11"u C5'۵[R׉90Vd8=Nkا%3žs">։.(سg2'};7:-Q᪎YeK7Rئ'3`o+_B{s=@r5uKn3`كقj_sSRE>ۛ\b_3c`>G#TyJ]̑ \+ P\ad''Kڸ#)uJBr0\ h Q-K?XK+=`m^j 6]P;FKű>]P-(ހ^;b_mV]'Ξ,SAEpf̝6B銏BX޽OuzIY63e'6^, FIw$wB?~E\>mSuHw37O_罫{%ʙ%y?MwOO‰Nu݁lWȑ9A5JM}6PquNEm_UʋZ^|ss/G҃eJwh3 *ҹA5SC ꀏl|F-ݕ'D[VsTf D3Xs7 ,T5+/wA+~"ǪxŐ q8|")<>`VwI^-!n=yN1^'."WD䝕b:9־MWv` 0D㉀ƨ象v{]‰KʹPvH[Yr 0k. ~;HϾC+g_+ Ŕ}ޤ4~N|6n~bEny=;/^{@QOJp}0 3!|$E0O(ٓ'f^֍:nB #EM=|ݫJ?7H JtA[a/1΍7Q*l|Ro[DF pJk4WKJH]%]8u`Xr[ < o=ʷ<,/f4!'_-'0/ɣ Qp@E1aQPmw1l7`- ,s-H,1}sX\,rxn~2_T+]2Z~D$>+ vPZwY͇A+B¼!͑3l,ctwו7y'Gֽd,N>cRx}L@8),<5X%{r1r3 4!譝"&ں d+|&IiQOվڻs 5c';)1$ajcpӹFh+mVZ0}s]c7;mx?+BE%8gbcK a2i;}uEĭ`s4Orv8+9"b TsA!I&N ,yHZ~mڐD=_qkzf!dK=>&.I?Nۇw1UgU4O&Mgl#ːB 0$Ev<+h$m''5ɼ uV$h6p'WWۍ`\um?.;a799ZgLqhڢVRly=Zm?l~o`+',)r4JP/ )M'u^H&Pyi$% slp2Q}G %Q5-$꛳hu-8!,.>BB} &Ey\ 参$˥QS`vPKGjBpжJ(P I2V~SBz/r6.̷aZvW %gк[px(-(\_PI%C- JS['Ev (Y I=U we>/&~Dh&-`r$a .(p12(B7;`ު9UK34@L2+rQ$%pvO<7sj ټI( g( c`y sˋV54°dRK!_:NeQtp[ⲐE^|N`$ml6n errqzb2➃ک&s\&U]%ˎHUg ~*0иϰl!Byp7貎|u_ M">Խɣq`ˮ@$9()\|6@BU͠YXpb8rNyw'q-)?sɎãXeb3m׊Oq\ͮ0wQCd<.g ,dAoqvΙY "`1cIC(KsE,g-L$q!_`VptTHGEe%$8??B5(433"O; LI9V`/ޣ͢.&vq!!ƕ}H-{O@N* ZhC^.R!W t,CHئ U []P\:xa΂OC#׆8xUHneFZc5`N7z H"&OKMr^}'loGձp@0 d⣅ α3$N< /XrU3ђ!fʒ1L]Jwxf`SS7O+)I÷LjW{Ri_Eai \s?|e?+ȋ3lqN#+gPȱ%^39~X\C!N dgb}c`&^3υiLC'-]\j b J\2) hk$Q\WTT8R|6(0D xin_KBڲ7x7R%+/+IQ"`&JiB%4 0*)1wwş;8MHV/fihM:& ?w?Nj<¿FZpܐcWce Js~A=MU4=ҡ6w}O*p]z]x(x*Fō!zPR(`GP7=V( R^WCK'U0Ams Cu:9P=Tq)eTLhsi+j2r4qM.2omTw+LC]]z#L9p:Onۖ2PK˛u-)syt.$)pfWUxL AUH_*ǹ+艙$H3{`6 #3(IiNjy 擎 H_4ͮB\\J7\s y>P{.&S5W1g؞&9rlj* -J9&W=NJYe.z+Tw'E[CAim(z`l;y1utļ$-lV2@B6Ș?ݟ582G\D`b|'bNT ~DX<Е~|A=0W*OMq%Xϊ=vsk;U}!εEiHƤ圃;Ѥ^EU iRAhI[W!0pqNܥ~d9|-YDҡ(n6*f ؋7ylvg GdI{D4Jqe.2;)B%)k%Y*ǒ\E5ʼXI*Xxd/6-b$l{HlcdTNEILx>@tbLx%j JoM#"kT6*^ФZ7dknJi[G#h蝅}t}" & o!ՄQ%`%$ S,˚IenK#E$E5C!!b|z}]}T =^Y ) JzQ )$y1\1=pE1̤ h,ZEj# 3mN&എJXo)"tC3Y;zlSCcRxEއbd0n \Xn2ULجW  ٠^bI8(پؘbd 6*(aL-MS#VzwC4YX .vllK]닸Ego~WkL2B*^tn GE4"GᑫlMu_ zm"UjÒN5(R) 7Jքg'$ӍX3tAW..>~hw& r 0ZI#4xb:=n{5EIzђdRyWY M'*ӗ\ 6,#> dTy(*:k8=KnGwVտ-gczC[7EټĠ&z ks-S2Q(hbWXpPkDU- %N~yb9&Cٖ%Y(ISEK{\ Xp z Rx"nJU0|Y$wADٲWbmKlDoڎl9mw4QCXrU ̴!c`If`/ R1̧@tYFU GRsm =[/i&.αM܋}|/!re]\LWSέq!:-0E( 5&a;~w_dOWR(!S`(bԂ*suFuY{YzG5uc?=_W 2Jҗ$LxMӟ@< %L5.mz\ |{#t$C[[H&>4m%.|Iɟa Fu y'g|ŧ]rp}y dD@Fb7l NG^4bP֠oSh!Ez%I[nH:Q-0͖v(`k;bbn Z6z4Q?eE1Щ(RKp,WH(G%87q]enPpA`%;1t=%F֥eo(YP!~͒rK uR,EcL`ЇX&QM=ir<-Uj+B&1'S;jJGEMj!*Ga㖠uP9Ó{Ӄ㣓4,$2h~芸hziE; K!\&8DeB0Df~ޛ&L%ghŽXZ_Q0X/_XҀ!=[?HN:4pO\5N_G`ok2/Ҋ"I+Q7+?ͭ6HV#y+nڛEۮj ~<p"W&&ٲ ppd0'Ԏ䈋OosX[G)̙kdgŒ8>xղ 3dO] F@,&g1o ?)l' ~/R60㛟d1}㈼@N!Ʉk)pҚoүfKJl&:Nb) ;.;06l}7iVĝ%o^hQٟ8\ZHBAw ヿA ,_zz9x\ijKnRqS]J(~gMeâd(fF䤨1zT%=x}4#no8M.oA^XG8 ',pù9m*Dt.(,4N=F#a+眄TH3a5qIB 9we2$%G2 GjT}gݺ}) |]S9x`21ݭ UZ@'KǑe3Kv}'췩~AĠ؎U PBXHF2PD6%G hxɉ™==$ RS0է8P "%]ls^_Ǎxb .Rv쩴}ɌQ2}[LB:Bm/VŜZW!XLjG4ݵ62꧴l+UF8m9Q&B};c㻺8{q޷++oWUߨ?A0T[ 4’[JG;[}*bFwē /anރKshj"AڒKc=Z^R)ۜt}^DaDC1 ( 9Ƙ Z%2 Jfx|J,JGJ,NĿȭ@9=꙯_I7nu~݇_o^_7׍nİ q^uwsḳ]m2Yggm-4=YaK~%L({J$1\r͟@+ k(7&$W(P䜔2{2"*k3M 0Xo%h:ܷv;Ezn]MOͫP JWӜY?00F(J9, Պ;s!ᲢA`+^0j)[\Q+8ux a,T:ŤPX~ܣ#I+#11xDjλwf-{`;)Ղ%[H (:jTyiauGPx2)/@,8 _QiJX1EBrM3gD5dj~ L敢#x81`ݺr$I;qri4,sJH G`UqkZt"D[e}}|rzEp:tG 샪8 089P?P. H Tr(Ts=/koyEFO'ZpӥW{oG@c!F8m9Dd $> ~ U'Z2W.'sM0iKnP b$w@Z-kąh !t7 vۊ`sa=ɂe(D-:2U&bn# S(Xۂ4<Ǜ$˶u q."c"yss!(qb=zwͧz|?9ׁ3|){x~?)]U8slQW(>g']9![LzLRta`kݚ6GG1ћ55,P-[.#:N} X$19A#Bz˥%7 ht jo_$ KkĶ:i*7tYRzE0i Qm7x. 9u7SdJTϸ'HU/E,U[na<$a'CIR:E(a>/f*ĒעI T13EɊV4< Ⲕ$|Tb<*xͺO{7-rz A`dj`>bw9KrvF`/ 7[6%Tv SA[@Kk#TȖ@:嚬8b2]LPq 7wv鹓x-ѥ;)Ұo[v2\3, xj![L' =YVV'  >ɯvk' sXM(6L'uNPC@_OD~Ŭ䐂.bs/z?6-~HG'YBZ(L?lNt9_إ!W6J62\0"wR c>]$M.AE>8nt@k0Y99p!h%Yրk5>LG;n~/O ?t%{ ]ˀ0V (lWNU41 l&)Hc]XjQp-=);rAHRTf$R["ZA ta%D i;2< Xaz'-j~fJ^A&tL]30U9ynٻ'[gOo[~ts{Sx{ky`9[xB9D] Tk{2# ΃|fl+64WMѐ Agsz!l_ f&{ذ#\ YCD,"'],&o6:ha(θcxMjٿytq&h[N ZĪQȽ߻>4kAc)z /%/?+v*+xE%0_/Y U߭W}Jvh&eɡ-] em E'%'BSd ^=Oˋ/H%^) 6an<8Ng(4|ưDv.Mn'd9 nW Mpo Q*('+]RWݷ?98%~yV~>~joO^==~3.J#:=8b Kwֻtsׯ]̬U_\5 1a ΍",'/} ><%L|Eq1[Zy xG_B{g fYoK1g 3wLji M˗ &3ә'Qv/2TSi[ 27Fđ4:hBC^ElҰ@7rl"&&y,BrW'h 8@=[eМ_,Z rM, @&˪Nj ) {jsha'7l.fag>BƤ] o',~Fo\ ㇨=:=\ˊfuwUS?x${nbcci57ms=7Ӎ^_|o7nhnڍlwl#Ͽ}ogx㼝}xrT׹'?bkf"% `lXvL0=\-VvnyrƎo9USFHH 7\}ݻȉc\}YYk=l浨sP4QeZܒ_vbMOOOEVi'Rt0ZtZVm'\1Ϙ4v܁Rtj#EzC Ϫ9qݡlP3L`4w'NL9qd[3q7G_ zo OO"I/<_kAO>vU`:}v:n.tٻͅF=[~\4ssEp^o?#5|h*7(K;\Q\Nw~~^?| /\w!;TKqP^86o5-4}ܮ./'B;K0˃G&Gw5z4-DjYthf,AS~}],Dd>6:|^;zsa_Qg\#fܩwu*~5 $W_iH;R^7ٸ:~P\J3'Ow^/<a:zF?߯Ls}w_;_4s0y?_N4u]>[oF w_i8|%N[?_g_.|į60xu|z*8OY3eCL >{ށ_4fϏ5>E>_K7`S2 C.5؆_E%[l0ww,:`ER|+z{Seբ V:rjisw Gtw<%|!FF/7h!掔 nȭX4A]-#Cʫ !P6< VP QBܴ nÚ˜z{6 ыJ$^LV1pG_!02\(^8WIl3E؂1p!ItU[7b -LZRMy.4w32#qMaхB8{U8?3JYCKf-Ø=Riߵn2=pMRXy,0|>VH(@ @ A7_]tɵqtJ?K] ﺇu.۰ᴒ ;,$6?I1q1hhn#UaY"Q !&*:؜~I%%V\P<16he/ 3/gM2ZIL@DT@ad\Ƿlz`$MD kDha=אݲ\C"_V$ 'pj0XZ.ZX'$Wlſg_"|'N4"Cu`ϔ6RuZH"Ն8;ё793a+%qPn|D#>BNC_OFdޭ+n15~ ́KZJ! v^xh?NN?~Ǐѷ~)N!~c'fEaEOжzFx TLPɐOgYz|{k@;2hfIr6D/bdlx=ۀ8C{*(ÕvcJ!g6.>] 7k÷=ؙoVxG₼{ϙ?/)C}oI{V|~\6#c˴4IC^XmYӳƥ weݹN;OuU[q-mQG{lM5_LXV%>ޒ>o?.e1zҙW=_?G{]|ҹmo ~"UO$WV#钠m_xT!o3{myb1:Y+1Dgo+|w c?69:O.~'|"|%di3':[P4x[Y)m_Áؔ8?]3.Yj\á %['}:PXhG& ؇w/ |1o(PfD9JX"zqdxlTo.6/i~OrӦz= %x3p2z`562 '=6P~>4 :pl:z1ʼBYRoٲOri;ϰdِad).g܀ D< ,Bnf4O`+> y}HN,&7 ,Na7Rk^w}7v3WŢ+=oUT/wYAEb^Gy]^Q!΍Tq11I~Ff3g,?1yg3f?rNȡ=( G'ߤ lK^ؐ ,X^il(\4\?,%u :c7%RƦΎGdR;V0.}Ir IT~t3݄Owrڮ/|7Ɲ6k}>dk $엨!]c_~RUj:WJ-OT@5mbޖfI{6VA}AXǚ$gIL|cy†nկVn,'o%5ԋaSGz-S#qrde'vDn)%NT$6hXzgQ5/uvq=k"6,0rqSΆ]Hir=Ŗbڌ6R~ "H'.XO*7SeIBjy2PwI{ㄋ_#]7a!v⩩_\hTfH ,SqpE',50ZH I;9@_l?& extLN'L $禝yAmbj$?Y\R~LpX 9鲆VZ}ldxbG6'qx]reJ.Cgψ?DfaI.șM\Kg(ŸVʾ!)T9|hkYi^zN予nGxYp;9`(OJ FxIӋN z̧R5̑u|,o|A_)Sx9nS3 ۃVouvLt'|mA\L b>Y/S6;EuvݓY7xCqs_ R3"$LV/*k Yy _TP9ujW:nX @>UV|͌wZ'eқr>QPRLjl&v "mg[9$Xjfms?ȖRbpI|ڮ&VK̨gl;P')z0 >dS(ޯqSZwA*X1OURUi.CH`(B$=ECp Jr?AH͸*Ǖ$YxQeN)a! eZR%Q΢ۏcHMWj.{&nL­ܵq#s]Ji'DBPnG@ } @QEέ+ѲIcR47FWp|G'M,3cf"WX/vB{@ꡒ ::9iӪm/$PWH>z"Ny~QVf!#U^;olRs3CHֳn0&Ybל%XR ؄ZJl G&4B:qliɺJdȑx 'qQߥe]4x|Qm[vVhCt ,N)KxA} {*Ra*jvuoXx&&np>N)TF'2f\gUJ>)CFcYqCA JN Pl:_rdn+ccS2+fѝʦ0X?&A/ P &hO ģ DV 5!ϟq¢=h!LYhqan_Nu ?d\}C"0"an6V3MT?Й}Kh{2=o{'<9pMZ  r)YqEP6@ tQ{pp?{;Ax?^AVr? l~HT6C"Wj1'JFʮ~{le+)ԛP7- z#_CäQzjYv%,[180ruYq& LF }gӕD{aÚ^B GjkhÊ.o6{Ԣq"X~vb 8SҰ1ixfx4A KћGT crY T'ZBW]g>U؎ހ75`cg$WŁa` _Cқ_^d\!` lT]L␐$.5GOؠ-CR(L<#IǠa=dtgN84u_H8\4gܖ<ɕNn %=mmar;OIS\Lg-'װL T͸DT(sM`';-KIS|X,N~Yj.q&*xb$NQ{%T"cї歉U(so+@Vz2 L F52'!# `ʀ{`$:R!(-HڎWq2]$n :r2iԉ=a`1 ͌ctBK =#H[GR,PT=dک}ngP q异™hx vU^jvm~n!16BrQXԡ-x,޼H/a9r˚!(~ S/&30U L.Xj2CXV,IxQib;;Fpj>e/C'& 7Wq7l|?CtYکp/r1Slez9_͘ !7S8+# Gv,ɔ,H>Z9e4ntڶ*9)0;YD.(C{8Tv`WIL\ͤAgml%2/Bi)Czs[qx^e1Y=X/!^j/Z#4r3,31(1CY]o5KR yIiVbăƍV!e.G/ocW/ 5˞|&\t s`ʧ6pt}QslQ2{_tv}by 酧}ƻez,l4i'}yp*֘"ZageI`UENoXN /xي]1wҴj5ճS9 "gi;x[ 3 >|;GwL[}o2ie1o\סz2t:<&@#o!f4mdvR%~F#ۉNcv CO =nKvуg*m]UBoF4^֊ *iFgN|jƲq -UN۬@f #D 1ג t"d˴HE셆V$'TqظȊmK[a&Ffnvs /(" ])8^M%S}v8J/߸)m>t|V0QYtJ?DDQ#PvG>{K27K\"4aQNǐ}i5Ȱ^J'Vh @_C`*vUA@DIA Uभ!Qmi*nr!oR6yļSr!P @Z(qrԖc`-O +X:vr؊a@ 'ZR\v3;WfM>]n0b%yR@n@%\MaGӝݹpzzo0}Qr.llFl63-e}xKSRP@Si@ yW jب>yVUclo<^z¯/Ecd4vX$ vBVf%,CwJ$i0,^ 뼢;g] HUՠdrF;'OsJux_FS%9vBIvڎlk@s.[f)ŸHIC7);\&V?w+'!4/Ӯ[5k EF26pf҇32]>,߉όظZ)R^[r&čpFDŽԴEٸ!4)# )3>nB38/ ]"+j}CORm`0߆3 _<\F1!dC y hC1pì9t3s,pWc SnáX*TVYhXOfw\`bZ |$_愵%KqE^3wbf2%A)"Vu h e3#}RKKibD)s;YrA~8x~:B`Rٔ_Lr?y7*:Ysw$YO>@QBprR],w`>V!@Lj E9쳟 be$ӑP$߳*rwEDo̊=(% Tr:IHflnzC!m&XŽιɷrq!` @ț3X w{̹Uow+/#\`;˛:fcBc?Oo|9?N<-5Bpm;ߕJFt.쐐s=w&n cbc|8+pָ7f70uPSFHCIC̙m4,&XGX<3 ̾P 7w) v*;. Qb/Υj'+'rn ҪҿJ7NlPlN+ks&C/^Gf~ ؐc8 bI!d4uFRv@O3dC¶^/ PS^J:|N#V2Yc$0C̑׭Z'YfW!8W/u[Yc(0SfNJJ OjOjXJ"#aU½͐M?m^BwTdsqt/J^CFN (H49RF=bI(crB>|.|;Ԉ0aD̺2d}"@Y6q]L_C3d8Îu 0@A߷Z -j{[oz_R:EM:/ ,YN1( qgrM/;IMWa+Z!Lvs8Rl֢"e5ja }adgYYK5ߛI[`e1%bԚhPXw4ZRyɔ*I}ݡ0v| `:*˶DU 0$VM6ja_-늬8YܱᴂS¸q`h{Jf{̃"o;Z!5^L_mm%1F0v;mQJ$"7ti3.mO'"zs .=7}Z# Z ؜*k;ݍ@ #x54qe!P~V:3?Q N0+ra{q)Ɠv $  ?skbnPUl)nL0Ji5VPoM:U-:V-@mdj- 2mԫW'up1#n!pN*^C/uuD6P5? o\}2mw2iGB;QHeiLxtŒq#qmss;1T^A[had!7PInqPS]]5\7$`5]pc[4eRnY7lJ椦q]+';2(`ssT9j"^njN5!9,.LJ凁F b),e} fᣆCvyS q/UUE2ZFZd )_CīY]Jj叕U xRxPZg} %-?,0u ͽr$mbI R&ߪ'+`='Ói`lP5i1n~=6^ZSQ?CJw]_l@#~3A7iHg܃+-O-q=;!@.916N)= f̚YY0 94B0{T5Z9)2Lj@` Ui| JQ;YO-;D#:GMpyWn3m))lBY/{ϯG/#TO0YU\qru~K :a(e}u:KYa{t0SvWM4@c0CJ5-ݘհQ4r na=e88ky#8rbpЏov3y;i&Ǒc%7M܊+F k2ڈȘۼt `B͈9 Ɛ+Z! Fr*ԥ J(qjC`tFX+ʔu50'tVg6!a9ه<9oDy;Ϩ ,(Ø]Qahwc09AlVՎ=vatKViWrM:"sD%M[. ݒ\Th2.+T, "ոΡ'(V*Ö'tnv;i&F8mC=iN3Kݺ:t8Rxg Αٲig>(hZtjwѓaCT>'~;ZǐS^9Y'ª)U(i n#@3Ub~{?cww▯u%wBM\zz[sn D%IVUO$WbˀRH@/Բ|.Ag}\TBHT}ͫt,jkZ8]嵄8N̕ kz6GnO$!s@QQ[[8!r:`ꝑTdAEԈ2j 7k/a:k//g"qc92úüϑef%q@8PKLYo·]:<a{z䛳qx-B+]]H{E1иDpǑmM҆"&hE⯛lYh{*#Qv,,w:Ko z=#SzŢ?v((PQnu NDvjy΂\z*CԟG Ɓ-207m`p^c͌-(ɣZEA_ t{AMQTߢG≐KqIdofrS]ch\oy Ni!鴖>q AqdVPÖLP`f)Sj> ZUɥ?iY'=WjejsFo8Pұ*{^7jUoԗh$ I[ VR +VҎ´uA(iB L|wDtHZRj6@l5R%G|[J!u"ݸjΧ$j'Y+m%H۝}T&5FGc|'f~"6/$,Pߏ^|3?V3Ao/N}R cm!U9˖ruk ~n`BYbR|6̟6, 8_Jy-u1xp r>m}~Hsk[#D0t)+WCC.9j3gTLHfzƟ$N6f1m޽ɬ`p36qA'2$',\2EbSc6 Ba eV>/l鏾Ϧ_'wg)L}N>Mظ`F=eYf F9/ǍboN(=f> ,l<њyfUF`5\ CT]YfݕR0Ôow3}"O*Bk$Nk0Dcw&yLU+-m-J/;G6x`owz#?ݴF nUag 'R=aܭX :w,NYZL+0PA/ sK0A<_Z_\ˬ/J2_>| z|sv1X.F7;"__CM5FlX#edT7߻]{qF6 X7̔ tA`1pI`9ΆWXQy6osO^jڍfܥsZc(|\MyCۜu*;会Ad]@UZ:@R9TUTU 1 b[,6j&:N,&^5wjst\]Pb(MUVd|$~_:}󏊰28dW;7cyޘAw@P/fH.' yrn"* Y*ʺsv" )p/USnO6Z&@0`u$I'&:iڀTzҙ텉RcBȐ׏>L4$}.t60 6$:d\`0ƕǾl\ 9r ߹ T%Idp+7mhjnܐZukD`[ ʏwk4 Xrf8@w(r&;P ' Oc*aQ16u<.&OW6>α^ r W+J.+EB` ;(n!@l`֊Fϵl}P+~qgmAw!r*Nz)i$`JޢW)O5XC>@j@mv I#QPv\F.5gh2M9+PǪ~ 4oT<'l@JN=lU37:3BzJHx[u/&$]kt${6WH9h V\9QcҫQ@N_ 0yTɖ?od틊q(w竺\f%S%h4˜]ɶcdҗnۚ{<H.+(y YA%x*JZ=.Z);O[xԣ"DԂd/=ua3ۜh搾l@2 DRÆ\ns^M,+P }d~qϥPmu-ǁ1 IDܠp؛i##ޱk>3O 9A.JZ!AvD8[J1وnC;fp~ݳ$q* AGP\Y<-T%66u+x '::q+j!-(Va7P$٨CDa4'j=&/RckwжDlpa~=/@~)~X5f+;veƣP,Z5ij) fɁ@s"0T(@kzmq3 -ݎh-ug+dSgzCk 4; _Z~6M_Oq1ԫb㺲Se]+pQqsd[iAcCFFOD'a:r {ڐ,~;/y;l^}%6(sڗg9+dݵ7MdCHtҎVFjQR#%1=aE y획֋&%4C/XF'BN; Td)8Ėv4ơj}SaG֚lUIl-]MنWyV4ݠ05L? bci FG8C<ؑH@bR3l)m_<F?x+z'E&=prT\LզayT_U5aJvl7«Z{':[GnPI2/$9L-1o6X"O}e_?4u|4Kf\3lδJ9Wn?%SX =eaOvf ^F7d ,4ySU@X;NSP15OZW|u뵳ԚG~5Y|]W3lah$SC}{j']}RmX7B>홿R&{TYnY)~$ >g'>{[v F^$,Qwɜͩ =z6*U@',BZϨﰇk6Hbhۤ҂yxZ*2-H=.L-u}i(.ؾ-)Bמ9:ݕx'a ![Ts!9sIJwEnIndX:fNBP [JaCLj8l5.B[)=2fG~} syANfvp͌uŏ<*% YـEpQtQ^XtTD5{6:wZ ^r6J;~N-#0Dڡfȿ!|j6z߼k<f ǚomRZuZo _xdG+%R-t}1I&rz F`8>ew*nG5cor3<@QnPĹ\8,)AwT{)^ER(uﲕ3>5C`%Hbj0Cv&Ɗ(g? (;[VCfw<%NDk7H%+jhe\ΟͱFZ5QZ(X6jɶOP⩩\2WgZ|@^ӽ25Bꖎg27=(!Bh8F.ݴRq_۱AMV nM\j AlؐmZz[nFsT#XIrD^!q % eu 琝zq7T5ujY>Ho,Ѝ9mY2W⬇NUDL$ hr1yf{[7,aQj#Iοc>(ȄS [pd\_&z\bve϶1s#c"ך{ 0iUOF emcيo8,vi6gW+E@xmqG5qek{Ĺ5? )Ac^] VJKז;NVlYe؃!*I\#&8실P7 K>$ϩ֒a:~*391zUS"g cX̌5>vutp!\?k^}F`h݌^qxFd(Q5ns _L5H#t)qi։n.BjV[ݮgQvh.|Zz@_HBjMz`&rP*vȒz P:4To7-B -2Xd9OF孌L5X㰵̞~QbJw:DL3xYo52ཀྵYș6D_6qpQ>9+ՒMbs<Ҽ?&`r!|ׇ ][$gW{[x(rۗ_?|WoAU(s_ ;YwɈgз]Z>֮%l^oJח+t'%r.U_[2pwc tes*3C%`*UiM^y4z23:ͷ+gqF#TnU kJ9XAte-9WslqֽX\Z jeWK(3Z-V$`FGq&ډ陃g9x09v7o}7ߚ9x'~ÓoV4NHbH >7@$~a%|7' m n,N?oF3a`}p;xEFu_ a8z$_kЖ,r -Y  k:!md/u8rlR:#_zi)bՂ=d6ns>>Df:<VxҺuQ&7!f}JN}M}گiMLe6N%˜Ĝ![FjdY.tmS6(#yoi+b9Tsځ5xX j:ST7! QX,כsfop\WC[EC@[\^| L*%Bw8<:!5=Jc3~%/ƪoR*]`I15O)KZms+UeB&`G|bo^%!kƦGbUyX?&=xX?Pv=ĤhJ%lId"{s62=⵾ܪKGI 1ŤJڳmWov-9V򚔽 ZMX(;:  jbҌCCxKϞm$dh Zk2KEMfҎ;=ԡ|Sϖ4݁i#k4p6NGԄPZHBSGFM!`zнUf= k6hb~HJ*)ԽwU)6Ύј9fW(-tDWIkz&VۆeN0F q p $Sμɂݰjz!N"zB\N ClJ))\]Nx#\Y\dQa9<|kle$A#%$2rJ2S3I(>wws/Tch7=D#;m4΢P:W_R2)?NۍٗEZzdjiv_ PT鱽Nb}Wf(g/uS$cEc~Fޕ )t:4sG;t6 G"FTjSkeO][+]o*h3fdK7P#@lJӌ'9-dTH-Kg'r*ZS, i jӝ!Xh ơ)%FRVF[W #"6Xx$WY%Y:h},lLH> Qm;cًOG'/^x.w=B_;9 }JWOp!o|!H -ȯ(._i9Z=1dElM;Ch%9A($ 3d2 j@@,!u?ixU@8.V=!/UF6N>&tW%K˜:[vRK*WTʇ{_a/5 bW,}UXrlچ퍴zIX/gM=`qw>[k/V*,Ы{'Y%oC=o@0w׬hA!Qai9 e07}݌20[HY(xj~JȾFuvFzɯB3A gD,\ ٥1Oz+v?kޭZʟjGe=i-.P' ljk᫳t9R>BStnU;,IΊ fl]ι+[9\x$עÇ^i͝3Sg.ʙM ZRNt#D<&vܾ:\old:ik"|