ipa-server-trust-ad-3.0.0-51.el6.centos>t  DH`pX Fb.cXy] [v7N&:N%mi> O[j7ȇcF +ye&`=t 71b4D"~hxB{ 2US08]쩝z\M*̇]6>VL[6ÿ=V/Uwϣ?(Db&nbLw#fwW9}MumgNg >޺? PM)[{Y O B ?l_Vh|Tv^LA6->( &i"אuz SҤI_ JTjaiG d~Ol]u NUD6 Wyw;凱#&#zA@o15W0x{fiTMcٺv2=Ӫz[6yh>8?d * s $<@GN z"<t    r  D d  86 6E6(89:7>_?g@oGxHڰIXY\<]t^kbMdeflCipa-server-trust-ad3.0.051.el6.centosVirtual package to install packages required for Active Directory trustsCross-realm trusts with Active Directory in IPA require working Samba 4 installation. This package is provided for convenience to install all required dependencies at once.Xhc1bm.rdu2.centos.org CentOSGPLv3+CentOS BuildSystem System Environment/Basehttp://www.freeipa.org/linuxx86_64/usr/sbin/update-alternatives --install /usr/lib64/krb5/plugins/libkrb5/winbind_krb5_locator.so \ winbind_krb5_locator.so /dev/null 90 python -c "import sys; from ipaserver.install import installutils; sys.exit(0 if installutils.is_ipa_configured() else 1);" > /dev/null 2>&1 if [ $? -eq 0 ]; then /sbin/service httpd condrestart >/dev/null 2>&1 || : fiif [ $1 -eq 0 ]; then /usr/sbin/update-alternatives --remove winbind_krb5_locator.so /dev/null fiif [ "$1" -ge "1" ]; then if [ "`readlink /etc/alternatives/winbind_krb5_locator.so`" == "/dev/null" ]; then /usr/sbin/alternatives --set winbind_krb5_locator.so /dev/null fi fiykkzqnqn4C(Np39$ u큤큤XXXXXXXXXXXXXXe5c7b6ab5382750ed463742fae2c2890339c7465266e84b42d280de6a05ae099da38b6414e3150deba179582c2cd870a0248bb8ccc9ed70f3b847c4d1fe144f2da38b6414e3150deba179582c2cd870a0248bb8ccc9ed70f3b847c4d1fe144f2c13d0812157e120f35ac5560adafa5dbf79b2cb72c354ab0f3e9f2249634b5ddb1479375a9a13bde5aeb323416bea50f562e1bb2460ba9f87ef73b5e1e387fe6b1479375a9a13bde5aeb323416bea50f562e1bb2460ba9f87ef73b5e1e387fe6078e37f606c77112d1f1aa493ff28b56b8f67ce51185affb26eb1922d8a3488c2c626b4195bdfa3d016397f169e71608674bbdefed99bf5d4e813691fb65da25860bfb6f4e75901ae8f0bfab743dbd637093eed564f31bf17c2b800cfdbb5697e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8550109f79562345cb4ee7465e7150b4cc528a170aa943232957792c4ea369c064ce3b5a96a66cf380a1aff4bbf8ae6705db28a9391f020ae366b17d9b957a8a2738f8c32ff48bae57e2b73c9c795cc211125ab1a65f13a2fb309e58e8ceda9ac910ba8e58428d1e320075d001f4cfe2c7e84f9e18b6ad2b6ce2ae9ac5d3b5b7888@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootipa-3.0.0-51.el6.centos.src.rpmipasam.so()(64bit)libipa_extdom_extop.so()(64bit)libipa_sidgen.so()(64bit)libipa_sidgen_task.so()(64bit)ipa-server-trust-adipa-server-trust-ad(x86-64)      @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ ipa-serverm2cryptosamba4-pythonsamba4libsss_idmapsamba4-winbindpython-sss/usr/sbin/update-alternativespython/usr/sbin/update-alternatives/usr/sbin/update-alternatives/bin/sh/bin/sh/bin/shrpmlib(PartialHardlinkSets)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libcrypto.so.10(libcrypto.so.10)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap_r-2.4.so.2()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libsamba-passdb.so.0()(64bit)libsamba-passdb.so.0(SAMBA_PASSDB_0.2.0)(64bit)libsamba-util.so.0()(64bit)libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)libsmbconf.so.0()(64bit)libsmbconf.so.0(SMBCONF_0)(64bit)libsmbldap.so.0()(64bit)libsmbldap.so.0(SMBLDAP_0)(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtevent.so.0()(64bit)libwbclient.so.0(WBCLIENT_0.9)(64bit)python(abi)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)3.0.0-51.el6.centos4.0.0-314.0.4-14.6.0-14.0-13.0.4-12.65.2-14.8.0XX lWu@W@W @VS@Vy;@VD@USA@O>A@N@N@NN@NNN^Nj@NNNNx@Nx@Ns:@N_sNI @M@M@MMy@MM@M@Mx@MMTM~@Mx@MfH@MdMU$MOMOMGMA^@M=iM6@M4/@M.@M.@M-M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Johnny Hughes - 3.0.0-51.el6Jan Cholasta - 3.0.0-51.el6Jan Cholasta - 3.0.0-50.el6.3Jan Cholasta - 3.0.0-50.el6.2Alexander Bokovoy - 3.0.0-50.el6.1Jan Cholasta - 3.0.0-50.el6Martin Basti - 3.0.0-49.el6Jan Cholasta - 3.0.0-48.el6Petr Vobornik - 3.0.0-47.el6Petr Vobornik - 3.0.0-46.el6Petr Vobornik - 3.0.0-45.el6Petr Vobornik - 3.0.0-44.el6Petr Vobornik - 3.0.0-43.el6Martin Kosek - 3.0.0-42.el6Martin Kosek - 3.0.0-41.el6Martin Kosek - 3.0.0-40.el6Martin Kosek - 3.0.0-39.el6Martin Kosek - 3.0.0-38.el6Martin Kosek - 3.0.0-37.el6Martin Kosek - 3.0.0-36.el6Martin Kosek - 3.0.0-35.el6Martin Kosek - 3.0.0-34.el6Martin Kosek - 3.0.0-33.el6Martin Kosek - 3.0.0-32.el6Martin Kosek - 3.0.0-31.el6Martin Kosek - 3.0.0-30.el6Martin Kosek - 3.0.0-29.el6Martin Kosek - 3.0.0-28.el6Martin Kosek - 3.0.0-27.el6Rob Crittenden - 3.0.0-26.el6Rob Crittenden - 3.0.0-25.el6Rob Crittenden - 3.0.0-24.el6Rob Crittenden - 3.0.0-23.el6Martin Kosek - 3.0.0-22.el6Rob Crittenden - 3.0.0-21.el6Rob Crittenden - 3.0.0-20.el6Martin Kosek - 3.0.0-19.el6Martin Kosek - 3.0.0-18.el6Martin Kosek - 3.0.0-17.el6Martin Kosek - 3.0.0-16.el6Rob Crittenden - 3.0.0-15.el6Rob Crittenden - 3.0.0-14.el6Rob Crittenden - 3.0.0-13.el6Rob Crittenden - 3.0.0-12.el6Rob Crittenden - 3.0.0-11.el6Rob Crittenden - 3.0.0-10.el6Rob Crittenden - 3.0.0-9.el6Rob Crittenden - 3.0.0-8.el6Rob Crittenden - 3.0.0-7.el6Rob Crittenden - 3.0.0-6.el6Rob Crittenden - 3.0.0-5.el6Alexander Bokovoy - 3.0.0-4.el6Rob Crittenden - 3.0.0-3.el6Rob Crittenden - 3.0.0-2.el6Rob Crittenden - 3.0.0-1.el6Rob Crittenden - 2.2.0-16.el6Rob Crittenden - 2.2.0-15.el6Rob Crittenden - 2.2.0-14.el6Rob Crittenden - 2.2.0-13.el6Rob Crittenden - 2.2.0-12.el6Rob Crittenden - 2.2.0-11.el6Rob Crittenden - 2.2.0-10.el6Rob Crittenden - 2.2.0-9.el6Rob Crittenden - 2.2.0-8.el6Rob Crittenden - 2.2.0-7.el6Rob Crittenden - 2.2.0-6.el6Rob Crittenden - 2.2.0-5.el6Rob Crittenden - 2.2.0-4.el6Rob Crittenden - 2.2.0-3.el6Rob Crittenden - 2.2.0-2.el6Rob Crittenden - 2.2.0-1.el6Rob Crittenden - 2.1.3-9.el6Rob Crittenden - 2.1.3-8.el6Rob Crittenden - 2.1.3-7.el6Rob Crittenden - 2.1.3-6.el6Rob Crittenden - 2.1.3-5.el6Rob Crittenden - 2.1.3-4.el6Rob Crittenden - 2.1.3-3.el6Rob Crittenden - 2.1.3-2.el6Rob Crittenden - 2.1.3-1.el6Rob Crittenden - 2.1.2-2.el6Rob Crittenden - 2.1.2-1.el6Rob Crittenden - 2.1.1-4.el6Rob Crittenden - 2.1.1-3.el6Rob Crittenden - 2.1.1-2.el6Rob Crittenden - 2.1.1-1.el6John Dennis - 2.1.0-1.el6Rob Crittenden - 2.0.0-25Rob Crittenden - 2.0.0-24Rob Crittenden - 2.0.0-23Stephen Gallagher - 2.0.0-22Rob Crittenden - 2.0.0-21Rob Crittenden - 2.0.0-20Rob Crittenden - 2.0.0-19Rob Crittenden - 2.0.0-18Rob Crittenden - 2.0.0-17Rob Crittenden - 2.0.0-16Rob Crittenden - 2.0.0-15Rob Crittenden - 2.0.0-14Rob Crittenden - 2.0.0-13Rob Crittenden - 2.0.0-12Rob Crittenden - 2.0.0-11Rob Crittenden - 2.0.0-10Rob Crittenden - 2.0.0-9Rob Crittenden - 2.0.0-8Rob Crittenden - 2.0.0-7Rob Crittenden - 2.0.0-6Rob Crittenden - 2.0.0-5Rob Crittenden - 2.0.0-4Rob Crittenden - 2.0.0-3Rob Crittenden - 2.0.0-2Rob Crittenden - 2.0.0-1Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Roll in CentOS Branding- Resolves: #1321138 Missing dependency package "python-sss-murmur" in ipa-server-3.0.0-50.el6.x86_64 - SPEC: Require python2 version of sssd bindings - Resolves: #1367026 Document and test procedure for running IdM Server in TLS 1.2+ environment - Require 389-ds-base with TLS 1.0 disable switch- Resolves: #1322059 IPA Replica-Install from RHEL6 to RHEL7 Fails - Modififed NSSConnection not to shutdown existing database. - Do not erroneously reinit NSS in Dogtag interface - Make sure replication works after DM password is changed- Resolves: #1351593 CVE-2016-5404 ipa: Insufficient privileges check in certificate revocation - cert-revoke: fix permission check bypass (CVE-2016-5404)- Update IPA code to support Samba 4.2 - Related: #1322689- Resolves: #1225868 display browser config options that apply to the browser - Chrome - Remove ico files from Makefile - Resolves: #1232843 ipa-client-install errors out if client and server time are not in sync or unreachable - Skip time sync during client install when using --no-ntp - Resolves: #1288495 Add userCertificate index used in Smart Card authentication - add DS index for userCertificate attribute - Resolves: #1293588 JavaScript error in ssbrowser.html - TypeError: Cannot read property 'mozilla' of undefined - webui: fix browser detection in browserconfig.html and ssbrowser.html - Resolves: #1296124 Adjust Firefox configuration to new extension signing policy - webui: use manual Firefox configuration for Firefox >= 40 - Remove binary patching from patch 0140- Resolves: #1127211 ipa-server-install --uninstall produces avc - sysrestore: copy files instead of moving them to avoind SELinux issues - Use 'mv -Z' in specfile to restore SELinux context - Resolves: #1222999 ipa aci plugin is not parsing aci's correctly. - ACI plugin: correctly parse bind rules enclosed in parentheses - Resolves: #1225868 display browser config options that apply to the browser - Chrome - webui: add Kerberos configuration instructions for Chrome - Remove ico files from Makefile - WebUI: fix ipa_error.css - Resolves: #1232468 The Domain option is not correctly set in idmapd.conf when ipa-client-automount is executed. - Simplify adding options in ipachangeconf - ipachangeconf: Add ability to preserve section case - ipa-client-automount: Leverage IPAChangeConf to configure the domain for idmapd - Resolves: #1232899 ipa-client-install does not respect --realm option - Allow user to force Kerberos realm during installation. - Resolves: #1276358 Remove /usr/share/ipa/updates/50-lockout-policy.update file from IPA 3.0 releases - Remove 50-lockout-policy.update file- Resolves: #1263703 ipa-server-install with externally signed CA fails with NSS error (SEC_ERROR_BUSY) - Free NSS objects in --external-ca scenario - Resolves: #1263262 Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Do not lookup up the domain too early if only the SID is known - Do not store SID string in a local buffer - Allow ID-to-SID mappings in the extdom plugin- Resolves: #1220788 - Some IPA schema files are not RFC 4512 compliant- Use tls version range in NSSHTTPS initialization - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1012224 - host certificate not issued to client during ipa-client-install- Resolves: #1205660 - ipa-client rpm should require keyutils- Release 3.0.0-44 - Resolves: #1201454 - ipa breaks sshd config- Release 3.0.0-43 - Resolves: #1191040 - ipa-client-automount: failing with error LDAP server returned UNWILLING_TO_PERFORM. This likely means that minssf is enabled. - Resolves: #1185207 - ipa-client dont end new line character in /etc/nsswitch.conf - Resolves: #1166241 - CVE-2010-5312 CVE-2012-6662 ipa: various flaws - Resolves: #1161722 - IDM client registration failure in a high load environment - Resolves: #1154687 - POODLE: force using safe ciphers (non-SSLv3) in IPA client and server - Resolves: #1146870 - ipa-client-install fails with "KerbTransport instance has no attribute '__conn'" traceback - Resolves: #1132261 - ipa-client-install failing produces a traceback instead of useful error message - Resolves: #1131571 - Do not allow IdM server/replica/client installation in a FIPS-140 mode - Resolves: #1198160 - /usr/sbin/ipa-server-install --uninstall does not clean /var/lib/ipa/pki-ca - Resolves: #1198339 - ipa-client-install adds extra sss to sudoers in nsswitch.conf - Require: 389-ds-base >= 1.2.11.15-51 - Require: mod_nss >= 1.0.10 - Require: pki-ca >= 9.0.3-40 - Require: python-nss >= 0.16- Require 389-ds-base >= 1.2.11.15-38 to fix roken dereference control with the FreeIPA 4.0 ACIs (#1112698)- ipasam does not support deleting multiple child trusted domains due to LDAP delete operation (#1110664) - Excessive LDAP calls by ipa-sam during file operations to samba file share on freeipa master cause high CPU and slow performance (#1074314)- Explicitly specify auth mechanism when calling ldapmodify in the installers (#1108661) - Add support for DNS classless reverse domains (#1095250) - Multiple nsDS5ReplicaId attributes created in cn=replication,cn=etc (#1109050) - ipa-client-install should configure sudo automatically (#1111121)- Rebuild package to fix a brew tag- ipa-server-install intermittently crashed with "Unable to find preop.pin" (#905064) - Disabled sudo rules were still active in the sudoers tree (#1022199) - Replica installation fails if forward zone is not present (#1034478) - Administrative password change did not respect user password policy (#1029921) - Re-initializing a winsync connection exits with "Can't contact LDAP server" (#1016042) - Server checked for unknown attributes before "ipa" tool version check (#1015481) - CA subsystem certificate renewal was broken on CA clones (#1040009) - Lockout plugin worked inconsistently compared to KDC lockout mechanism. Also, default user policy may not have been applied if krbPwdPolicyReference was missing (#1088772) - ipa-client-automount was not backwards compatible (#1082590) - Increase service timeout from 120s to 300s as some services are known to start for more than 120s (#1060639) - Proxy calls to /ca/ee/ca/profileSubmit to PKI to enable installation of replicas with Dogtag 10 PKI (#1083878)- group-add-member command reported wrong error on duplicates (#970541) - ipa-client installation succeeding in ipa server instance (#1011044)- ipa-join failed when doing a forced host re-enrollment (#924009)- ipa-replica-manage del always exits with error (#1005448)- Host and Hostgroup commands were broken after upgrade (#1001810)- Fix coverity issue in AD 2012 stabilization patch fixing memleaks (#980409)- Fix coverity issue in AD 2012 support patch and add 2 related stabilization patches (#980409)- Require 389-ds-base >= 1.2.11.15-14 to pick up fix for CVE-2013-1897 (#928162) - Password policy lockout plugin does not work as expected (#907881 - Remove deprecated support of the HBAC source host (#924542) - ipa-client-install may not obtain CA certificate (#924004) - Allow client to re-enroll without first unenrolling (#924009) - Enrolling a host into may take two attempts (#950014) - Add userClass attribute for host objects (#955698) - Inconsistent replies from FreeIPA to Netlogon ping queries (#967870) - Performance improvement for IPA CLI and UI user and group related plugins (#970541) - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost (#975431) - Add support for AD 2012 trusted domains (#980409) - XML-RPC server may return a wrong Content-Type (#976716) - Add missing openssh-clients Requires to ipa-server package (#983463) - Add an option to edit "Gecos" field from Web UI (#986211)- LDAP upload CA cert sometimes double-encodes the value (#948928) - wrong trust argument assigned to renewed certs in ipa cert automatic renew (#952241)- ipa-client-install fails to autodiscover on LDAP servers with disabled anonymous access (#922843)- ipa-adtrust-install and ipa-replica-conncheck may not parse krb5.conf correctly and crash (#916209)- Missing LDAP schema attributeType and objectClass after upgrade (#915745)- Significant decrease in migration performance. (#904119) - ipa-client-install failed to fall over to replica with master down (#905626) - During Migration - If Schema is unavailable migration fails (#906846)- Filter generated winbind dependencies so the right version of samba can be installed. (#905594)- Add certmonger condrestart to server post scriptlet (#903758) - Make certmonger a (pre) Requires (#903758) - Add selinux-policy to Requires(pre) to avoid post scriptlet AVCs (#903758) - Set minimum version of pki-ca to 9.0.3-30 and add to Requires(pre) to pick up certmonger upgrade fix (#902474) - Update anonymous access ACI to protect secret attributes (#902481)- Installer should not connect to 127.0.0.1. (#895561) - Don't initialize NSS if we don't have to. (#878220)- Set minimum version of bind-dyndb-ldap to 2.3-2 to pick up missing DNS zone SOA serial fix (#894131) - Stopped named service crashed ipa-upgradeconfig program (#895298) - ipa-replica-prepare crashed when manipulating DNS zone without SOA serial (#894143) - Use new certmonger locking to prevent NSS database corruption during CA subsystem renewal (#883484) - Set minimum selinux-policy to 3.7.19-193 to allow certmonger to talk to dbus in an rpm scriptlet. (related #883484) - Set minimum vresion of certmonger to 0.61-3 for new locking scheme (related #883484)- Properly handle migrated uniqueMember attributes (#894090) - ipa permission-find using valid targetgroup throws internal error (#893827) - Fix migration of CRLs to new directory location (#893722) - Installing IPA with a single realm component sometimes fails (#893187)- Set maxbersize to a large value to accomondate large CRLs during replica installation. (#888956) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-29 to pick up default CA validity period of 20 years. (#891980)- Client installation crashes when Kerberos SRV record is not found (#889583) - Fix typo in patch 0048 for CVE-2012-5484 (#878220)- Cookie Expires date should be locale insensitive to avoid CLI errors (#888915)- ipa delegation-find --group option returns internal error (#888524) - Add missing Requires for python-crypto replacement (#878969)- sssd is not enabled on client/server install (#888124)- ipa-server-install --uninstall doesn't clear certmonger dirs, which leads to install failing (#817080)- Compliant client side session cookie behavior. CVE-2012-5631. (#886371)- Use secure method to retrieve IPA CA during client enrollment. CVE-2012-5484 (#878220) - Reformat patch 0044 so it works with git-am- Include /var/lib/sss/pubconf/krb5.include.d/ for domain-realm mappings in krb5.conf (#883166) - Set minimum selinux-policy >= 3.7.19-184 to allow domains that can read sssd_public_t files to also list the directory (#881413) - Remove dist label from changelog entries. - Fix timestamp on patched files to avoid multilib warnings- Set Requires on httpd 2.2.15-24, mod_nss to 1.0.8-18 and patch to check for existing mod_ssl configuration. These versions allow mod_proxy to simultaneously support SSL servers using mod_ssl and mod_proxy (#761574) - IPA WebUI login for AD Trusted User fails (#875261) - Add 'disable_last_success' and 'disable_lockout' to the ipa_lockout plugin (#824488)- Make default group type POSIX in ui (#880655) - Write replacement for python-crypto (#878969) - ipa trust-add prints misleading information about required DNS setting (#878485) - Lookup user SIDs in external groups (#878480) - Special case NFS related ticket to avoid attaching MS-PACs (#878462) - IPA users are not available after ipa-server-install because sssd not running (#878288) - Incorrect error message when time difference between AD and IPA is too great (#877434) - Missing option to add SSH Public Key in Web UI after upgrade (#877324)- Update minimum BR and Requires of sssd to 1.9.2-25 (related #870278, related #871160, related #878262) - Replication agreement tools report errors with new single instance CA database (#878491) - If time is moved back on the IPA server, ipasam does not invalidate the existing ticket (#866576)- Server installation fails to find A/AAAA record for IPA hostname (#874935) - Out of range error when listing RUV on host with no agreements (#873726) - Tighten dependency on krb5-server to limit to 1.10 (#872707) - Default SELinuxusermaporder needs to mapped with default selinux users list (#870053) - Clarify trust-add help regarding multiple runs against the same domain (#869741) - Improve reliabilityof RA renewal script (#869663) - Add option to disable DNS forwarding by zone (#869658) - Update minimum version of bind-dyndb-ldap to 2.3-1 (#869658) - Improve information on passsync user in man page, command help (#869656) - Resolve external members from trusted domain via Global Catalog (#869616) - Process relative nameserver DNS record correctly (#868956) - ipa-adtrust-install does not reset all information when re-run (#867447) - Fix potential memory leak in KDB backend (#811989)- Fix type conversion of integers when doing modifications (#870446) - Set SECURE_NFS to lowercase yes rather than uppercase (#869654) - Add autofs service to sssd.conf before enabling it (#869649) - Add strict Requires for policycoreutils to avoid user removing them during package lifetime (#869281) - Make internal rename_s() call compatible with python-ldap-2.3.10 (#867902) - Update minimum version of bind-dyndb-ldap to 2.2-1.el6 (related #871583) - Restart httpd after running ipa-adtrust-install (#866966)- Add patch to override xmlrpc request method for session (#786199) - Bad link to Web UI config page after session is expired (#869279) - extdom plugin does not handle Posix UID and GID request (#867676) - ipa-server-install --setup-dns always installs reverse zone (#866978) - Inform user when ipa-upgradeconfig reports errors (#866977) - Certificate request fails when CSR has subjectAltnames (#866955) - ipa-adtrust-install checks for /usr/bin/smbpasswd, which is not required (#866572) - Instructions to uninstall are unclear (#856294) - Inconsistent service naming in ipa-server-install (#856292) - Improve instructions to generate certificate in Web UI (#856282) - /etc/ipa/default.conf is out of date (#855855) - Time synchronization is disabled in ipa-client-install (#854325) - ipa-replica-install httpd restart sometimes fails (#845405) - Improve error messages during ipa-replica-manage del (#835632) - Always log errors from dogtag (#813401)- Update to upstream 3.0.0 GA release (#827602) - Add zip dependency, needed for creating unsigned Firefox extensions - Filter generated winbind dependencies so the right version of samba can be installed. - Remove patch to support python-ldap 2.3.10. Fixed upstream. - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca (#864533) - Add zip dependency, needed for creating unsigned Firefox extensions- Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured (related #864889) - Update BR and Requires of samba4 to 4.0.0-31 to pick up winbind_krb5_locator alternatives change. (related #864889)- Update to upstream 3.0.0.rc2 release (#827602) - Provide new Firefox extension. - Own /etc/ipa/ca.crt- Remove Requires on krb5-pkinit-openssl as part of disabling pkinit code. - Add missing subdirectories in site-packages/ipaserver discovered by rpmdiff. (#827602)- Update to upstream 3.0.0.rc1 release (#827602) - Update BR and Requires of 389-ds-base to 1.2.11.14 - Update BR and Requires of krb5 to 1.10 - Update BR and Requires of samba4 to 4.0.0-24 - Update BR and Requires of sssd to 1.9.0 - Update Requires on policycoreutils to 2.0.83-19.24 - Update Requires on httpd to httpd-2.2.15-17 to pick up #787247 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.9.b1.el6_3.1 - Update minimum version of bind to 9.8.2-0.10.rc1.el6_3.2 - Sync upstream spec file Requires - Add patch to support python-ldap 2.3.10- SSH Tech Preview feature enabled by default (#825321)- Test for locked users before incrementing failed login counter (#822429)- Fix host page to display all data when DNS is not configured (#818868)- Make ipa 2.2 client capable of joining an older server (#817867)- Remove patch 0042 and add revert patch for handling which attributes are allowed in a permission. (#783502) - ipa-client-install sets "KerberosAuthenticate yes" in sshd.conf, breaking SSSD auth (#817030) - pwpolicy_find does not sort by priority in UI (#815799) - Improve zonemgr validation (#745705)- Make new DNS permission mixed-case (#807361) - hbactest returns failure when hostgroups are chained (#801769) - Man Page : Document client IP addressing / FQDN requirements (#768257) - Login failed attempts counter or locked out status are not displayed (#759501) - Wrong title and icon in login and logout pages (#814752)- Don't interactively prompt for dnsrecord options provided on the command-line options (#790295) - Validate external hosts added to netgroups (#797256) - Handle invalid RDN for container in migration (#804807) - Unable to use permission-mod to rename permission object (#805478) - Migration: don't append basedn to container if it is included (#807371) - Raise correct exception when LDAP limits are exceeded (#808042) - Notify user that password needs to be reset in forms-based login (#811296) - DNS Resource records: add & delete A & AAAA record does not work in root (#811744) - user-mod --rename with an empty string fails (#811748) - DNS CNAME record: delete sometimes does not work (#811758) - Delegation UI does not allow to specify permission (#812110) - IPA uninstall after upgrade returns some sysrestore.state errors (#812391) - Improve migration plugin error when 2 groups have identical GID (#813389)- Fix password policy history enforcement (#810900) - Privilege page should not have choice to list permissions by "indirect membership" (#810350) - ipa-server-install fails when domain name is not resolvable (#809190) - Identity->DNS->Settings:Forward policy: change check box to radio buttons (#808620) - When adding permissions for a type, attributes that are not allowed are listed (#807755) - user-mod --rename is successful for more than max login characters (#807417) - Can't specify netgroup host, user category to all in Web UI (#807366) - Permission names cannot contains '<' or '>' (#807304) - ipa-server-install --uninstall errors out when trying to start dirsrv. (#801376) - Should not be allowed to run host-disable on an IPA Server or service-disable on an IPA Server service (#800119) - permission with filter or subtree does not allow attr to be specified (#783536) - Netgroups compat plugin not reporting users correctly (#767372) - certmonger renews server certificates ok but those services need a restart (related #766167) - Set minimum vresion of certmonger to 0.56 (related #766167) - Set minimum version of slapi-nis to 0.40 (#767372) - Unable to disable or enable hbacrule with --setattr (#810948) - When adding a user with --noprivate option gidNumber should be required (#805546) - Fix error when no value is given in --revocation-reason optional argument with "ipa cert-revoke" (#808099) - Set minimum version of bind-dyndb-ldap to 1.1.0-0.5.b1 (related #805814)- Fix ambiguous error msg in automount indirect map creation (#790131) - Invalid error message attempting to delete config attributes (#791373) - Enforce single-value attributes (#794746) - config-mod allowed to add additional certificate subjects bases (#794750) - Embedded carriage returns in a CSV not handled (#797569) - WebUI displays "Insufficient access: invalid credentials" when a password doesn't meet policy requirements (#802786) - Tech Preview: SELinux User Mapping (#803821) - Tech Preview: Add support for central management of the SSH keys (#803822) - Password Policy Failure Interval Reset is not working. (#804096) - Set SELinux booleans properly (#806330) - DNS records in LDAP are publicly accessible (#807361) - Upgrading replication agreements without nsDS5ReplicatedAttributeList fails (#808201) - IPA Upgrade Web UI failure with internal server error (#809262) - Do not create private groups for migrated users (#809560)- Remove version requirement from BuildRequires on sssd. (related #736865)- Set minimum version of 389-ds-base to 1.2.10.2-4 (related #803930) - Only split CSV on client (#797565) - Search allowed attributes in superior objectclasses (#783502) - Fix precallback validators in DNS plugin (#804562) - Fix memleak in KDB backend (#800363) - Harden raw record processing in DNS plugin (#804572) - Fix attributes that contain DNs when migrating (#804609) - Wait for child process to terminate after receiving SIGINT (#754635) - Avoid deleting DNS zone when a context is reused (#801380) - Fix default SOA serial format (#805427) - Set nsslapd-minssf-exclude-rootdse to on so the DSE is always available. (#803836) - Amend permissions for new DNS attributes (related #766073) - Improve user awareness about dnsconfig (#802864) - Fix uses of O=REALM instead of the configured certificate subject base. (#802912) - Fix dnsrecord-del interactive mode (#807230) - Add requires on python-krbV to client subpackage (#807362) - Tolerate UDP port failures in conncheck (#802860) - Netgroup nisdomain and hosts validation (#797256) - Remove Conflicts on mod_ssl (#804605) - Set minimum version of pki-ca, pki-slient and pki-setup to 9.0.3-24. Change location of TOMCAT_LOG to match tomcat6 changes (related #802396) - Add python-lxml, python-pyasn1 and sssd to BuildRequires - Set minimum selinux-policy >= 3.7.19-142 to pick up certmonger_t type (related #790967) - netgroup-add and netgroup-mod --nisdomain should not allow commas (#797237)- Set minimum version of pki-ca, pki-silent and pki-setup to 9.0.3-23. Either we shell escape or dogtag does, we can't both do it. (#802832) - Set dbdir in request context after a connection is created (#804128) - Don't overwrite content by an error message (#803050) - Don't allow IPA master hosts/services to be disabled (#800119) - Don't error out on empty option (#798792) - Populate gidnumber in entries added via winsync (#798352) - Set subjectKeyIdentifier in SSL certs that IPA issues (#797274) - Fix escaping and comma-separated value handling (#769491) - Display certificate serial numbers in both hex and deciaml (#746060) - Use attribute name/option name when returning errors (#718015) - DNS forwarder's value can consist of IP address and part (#766073) - Store DNS global options in LDAP (#766073) - Move extension.js to subdirectory to suppress rpm warning- Allow removing sudo commands with special characters (#800537) - Ignore case in yes/no prompts when deleting DNS records (#800483) - Refresh resolvers after DNS server configuration (#799335) - Fix nsslapd-anonlimitsdn in cn=config (#798361) - Handle more exceptions gracefully in ipa-client-install (#797567) - Fixed checkbox value in table without pkey (#791324) - Fix exception when removing all values from configuration (#782974) - Set httpd_manage_ipa SELinux boolean - Fix mask validator in network validator (#802848) - Don't shell escape arguments sent to pkisilent (#802832) - Reorder patches so those that disable unsupported features are applied last - Rebase disable persistent search patch- Rebase to upstream 2.1.90.rc1 release (#736865) - Remove dependency on krb5-server-ldap, we use our own backend now (#797564) - Set minimum mod_auth_kerb to 5.4-8 for S4U2Proxy support (related #767741) - Set minimum selinux-policy >= 3.7.19-137 to pick up ipa_memcache boolean - Set minimum python-memcached >= 1.43-6 to pick up status check fix - Set minimum version of 389-ds-base to 1.2.10.1-1 - Set minimum version of krb5-server to 1.9-27 - Set minimum version of sssd to 1.8.0-11 (#766068) - Add Requires: oddjob-mkhomedir to ipa-client (#786223) - Remove Requires on krb5-server-ldap (#797564) - Add Conflicts on mod_ssl (#761574) - Remove BuildRequires on python-rhsm - Renumber all patches - Don't remove dirsrv user on uninstall (#797566) - Don't allow host-del on active replicas (#797563) - Fix invalid hostnames when hostname contains trailing dot (#797562) - encode Bool attributes used in setattr/addattr/delattr (#797561) - Migration plugin raises Internal Server Error (#796401) - man page for ipa-replica-manage has typos in examples (#796347) - Can not add new user objectclass to ipa configuration (#794474) - Don't require SELinux to be enabled on client (#790513) - dnsrecord-add does not validate the record names with space in between (#790318) - Prompt for missing DNS options (#790295) - Resource Record type options should be more descriptive (#790017) - Correction in error message while deleting a invalid record (#789987) - Adding some of the RR type from the "allowed values" results in an error message (#789980) - IP address with just 3 octets are accepted as valid addresses (#789919) - Errors not reported correctly when logging into WebUI (#789459) - Need option for ipa-client-install to not call authconfig (#789413) - IPA nested netgroups not seen from ypcat (#788625) - gid number: 0 and negative number accepted (#786240) - Allow basedn to be passed into migrate-ds (#786185) - permission with filter or subtree does not allow attr to be specified (#783536) - ipa permission-add does not fail if using invalid attribute (#783502) - When migrating warn user if compat is enabled (#783270) - Make ipausers a non-posix group on new installs (#773488) - Need tool to update exclusive list in replication agreements (#772359) - Reverse DNS rec not created upon creation of fwd DNS rec (#772301) - Adding a netgroup with a "+" causes ns-slapd to crash (#772043) - Man Page : Document client IP addressing / FQDN requirements (#768257) - GSS-TSIG DNS updates should update reverse entries as well (#767725) - UI for SELinux user mapping (tech preview) - Allow forms based kerberos authentication (#766070) - Add support for central management of the SSH keys (tech preview) - Login failed attempts counter or locked out status are not displayed (#759501) - Better message for error diagnosis while adding an existing winsync agreement (#755450) - "force-sync, re-initialize and del" options for ipa-replica-manage fail against AD (#754973) - Connect after del using ipa-replica-manage fails (#754539) - Unable to delete migrated groups containing spaces (#753966) - support bind forward zones, aka DNS conditional forwarding (#753483) - IPA needs a check to ensure hostnames 'underscore' is not allowed when installing a replica (#752874) - Unable to select dns zone when only one exists in UI (#751529) - ipa-replica-conncheck does does not properly check UDP ports (#751063) - Adding loc records to a ipa-dns server breaks name resolution for some other records (#750947) - Allow specifying query and transfer policy settings for a zone (#701677)- Add missing changelog information caught by rpmdiff.- Update to upstream 2.1.90.pre2 release (#736865)- Add current password prompt when changing own password in web UI (#751179) - Remove extraneous trailing ' from netgroup patch (#749352)- Updated patch for CVE-2011-3636 to include CR in the HTTP headers. xmlrpc-c in RHEL-6 doesn't suppose the dont_advertise option so that is not set any more. Another fake header, X-Original-User_Agent, is added so there is no more trailing junk after the Referer header. (#749870)- Require an HTTP Referer header to address CSRF attackes. CVE-2011-3636. (#749870)- Users not showing up in nis netgroup triple (#749352)- Add update file to remove entitlement roles, privileges and permissions (#739060)- Quote worker option in krb5kdc (#748754)- hbactest fails while you have svcgroup in hbacrule (#746227) - Add Kerberos domain mapping for system hostname (#747443) - Format certificates as PEM in browser (#701325)- ipa-client-install hangs if the discovered server is unresponsive (#745392) - Fix minor problems in help system (#747028) - Remove help fix from Disable automember patch (#746717) - Update minimum version of sssd to 1.5.1-60 to pick up SELinux fix (#746265)- Update to upstream 2.1.3 release (#736170) - Additional branding (#742264) - Disable automember cli (#746717) - ipa-client-install sometimes fails to start sssd properly (#736954) - ipa-client-install adds duplicate information to krb5.conf (#714597) - ipa-client-install should configure hostname (#714919) - inconsistency in enabling "delete" buttons (#730751) - hbactest does not resolve canonical names during simulation (#740850) - Default DNS Administration Role - Permissions missing (#742327) - named fails to start after installing ipa server when short (#742875) - Duplicate hostgroup and netgroup should not be allowed (#743253) - named fails to start (#743680) - Global password policy should not be able to be deleted (#744074) - Client install fails when anonymous bind is disabled (#744101) - Internal Server Error adding invalid reverse DNS zone (#744234) - ipa hbactest does not evaluate indirect members from groups. (#744410) - Leaks KDC password and master password via command line arguments (#744422) - Traceback when upgrading from ipa-server-2.1.1-1 (#744798) - IPA User's Primary GID is not being set to their UPG's GID (#745552) - --forwarder option of ipa-dns-install allows invalid IP addr (#745698) - UI does not grant access based on roles (#745957) - Unable to add external user for RunAs User for Sudo (#746056) - Typo in error message while adding invalid ptr record. (#746199) - Don't use python 2.7-only syntax (#746229) - Error when using ipa-client-install with --no-sssd option (#746276) - Installation fails if sssd.conf exists and is already config (#746298) - External hosts are not removed properly from sudorule (#709665) - Competely remove entitlement support (#739060) - Add winsync section to ipa-replica-manage man page (#744306)- Remove python-rhsm as a Requires (#739060)- Update to upstream 2.1.2 release (#736170) - More completely disable entitlement support (#739060) - Drop patch to ignore return value from restorecon (upstreamed) - Set min version of 389-ds-base to 1.2.9.12-2 - Set min version of dogtag to 9.0.3-20 - Rebased hide-pkinit, ipa-RHEL-index and remove-persistent-search patches (#700586)- Update RHEL patch (#740094)- Ignore return value from restorecon (#739604) - Disable entitlement support (#739060, #739061)- Update minimum xmlrpc-c version (#736787) - Fix package installation order causing SELinux problems (#737516)- Update to upstream 2.1.1 release (#732803)- Resolves: rhbz#708388 - Update to upstream 2.1.0 release- Remove client debug logging patch (#705800)- Wait for 389-ds tasks to complete (#698421) - Set replica to restart ipa on boot (#705794) - Improve client debug logging (#705800) - Managed Entries not configured on replicas (#703869) - Don't create bogus aRecord when creating new zone (#704012)- Update ipa-Fix-traceback-in-nis-manage.patch to fix python error (#697583)- Resolves: rhbz#697583 - Can not enable ipa-nis-manage plugin- Default groups are missing ipaUniqueID attribute (#696508)- Set min version of 389-ds-base to 1.2.8.0-1 for fix in BZ 693466. - Fix some problems in IPA schema (#692978) - postalCode should be a string not an integer (#692945)- Port 7390 is managed by selinux-policy-3.7.19-80. Update ipa-repl_selinux.patch to not manage it any more. (#691883) - Patch to fix setting gidnumber when a user is created. (#692168)- Fix uninitialized variable in password plugin (#690595)- Wait for Directory Service ports to open (#688934) - Mixed case hostname can cause issues and confusion (#688622) - Wrong timeout parameter in ipapython (#684273) - Run ipa-ldap-updater on upgrades (#688931) - Internal Error and trace back when adding DNS AAAA record (#689452)- Use realm provided by installer in LDAP Updater (#684744) - Use args for domain and server when doing DNS discovery in client (#684780) - Fix 2 SELinux issues in dogtag replication (#684269)- Add Obsoletes so upgrade from ipa-client package is possible (#684931)- Update to upstream 2.0.0rc3 (#680993) - Set minimum version of sssd to 1.5.1-12 - Remove SuitespotGroup patch - Rebase remove-pkinit patch- Set the SuitespotGroup directive in the 389-ds installation template. This ensures group read/write to /var/run/dirsrv. (#680201) - Make single line out of python sitelib/sitearch code.- Update to upstream 2.0.0rc2 (#675282) - Set minimum version of sssd to 1.5.1-10 - Set minimum version of python-nss to 0.11 - Set minimum version of 389-ds to 1.2.8 - Add bind-utils as Requires in client subpackage - Remove unused BuildRequires e2fsprogs-devel and libcap-devel - Add branding patch - Add default.conf man page - Upstream moved some utilites from the admintools subpackage, reflect that here as well.- Add pyOpenSSL to BuildRequires. (#670954)- ExcludeArch doesn't do per-package exclusions, use ifarch to force ONLY_CLIENT on non-supported architectures. (#670954) - Manually install ipa-admintools since the upstream client-install target doesn't. - Move a lot of the BuildRequires out of the ! ONLY_CLIENT conditional because the API validator in the upstream code requires them.- Exclude building server and server-selinux on ppc, ppc64, s390 and s390x platforms. (#670954) - Add date variable to the release to make daily builds easier.- Merge in changes from FreeIPA beta 2 (#670954) - Add patches to disable pkinit- Set minimum version of dogtag to 9.0.0 and add Requires for the theme we need. (#658275) - Remove unnecessary moving of v1 CA serial number file in post script - Move some man pages into admintools subpackage- Drop specific Requires on libcurl and krb5-libs (#658275)- Consistent usage of buildroot vs RPM_BUILD_ROOT (#658275)- Drop Requires on nss-ldap (#658275)- Temporarily disable building on s390- Drop optional radius package, the underlying code isn't there - Re-arrange the doc lines so that defattr is first (#658275)- Initial 2.0.0 build (#658275) - This is IPA v2.0.0 beta 1 plus all patches through git commit 4da9228fb2ac34adab8eb1884ae414236adb84fa - Removed some Fedora conditionals- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/sh/bin/sh/bin/sh 3.0.0-51.el6.centos3.0.0-51.el6.centosdcerpc.pydcerpc.pycdcerpc.pyoadtrustinstance.pyadtrustinstance.pycadtrustinstance.pyolibipa_extdom_extop.solibipa_sidgen.solibipa_sidgen_task.sowinbind_krb5_locator.soipasam.soipa-adtrust-installsmb.conf.emptyipa-adtrust-install.1.gz/usr/lib/python2.6/site-packages/ipaserver//usr/lib/python2.6/site-packages/ipaserver/install//usr/lib64/dirsrv/plugins//usr/lib64/krb5/plugins/libkrb5//usr/lib64/samba/pdb//usr/sbin//usr/share/ipa//usr/share/man/man1/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu?7zXZ !PH60] b2u Q{JXMÇatwʰf7h}2ڛŔ(U o4lj(\k}px wnϕaQtH1Yd㙃$qTs£tJ!S >$ *zhYyʻzDK}Em_X]nWc5Z\qrVW4ib_Zڛ Ng?Vԙ'•Wg13wUP!1ϭlQ<$(/Z6?OKq=.VZ׽3vo"bWO2'nsdnDasܼ/UblܼؔG!$Hf}q.X|R9~Βn;@EfZ~Z&VΒ+H*WuS;Ȁ+V0@ູZ]5*N} eY%,kB;Q9.Ē{CvȒq (gǺygnuj~`R5 ibK*w?8cP j -j *Z@6.x弛w4Ie@7OLLE"\-EqnZfK<wvo\?ۿL-ɾ2YjS\Izi}@DT _TZw]֢(Hv]CDOtg_Ae#B.'ԣ+L*hdk;R۲;SFff􅐚pY{5#P%ug|yaUd9' RV\eAL;A|r㭻>XQ,#a(3( ~d7l?VtļQXl,Ixv@FXgK`Ls \p515w¡B~I#2S[ѯ 1_v6 ;Dܚ|xWe{*&Ek"ku c;c+Jֶ i_ pVئS~]%N`+}g y&ȵ,8gnP/y>23MBgcЋ70 D[d}oHɗFFg!^ ^[.ܜf2oR\))<T;5@ԓ0+HG|-t唾^ D!n5~蟼 [FC6d;!SY$xX}['3n-=1@8Q0PħuUggU?@A>/oh 6lzjNYxcupӘc8l8Wq6c.R1݀⽚>͹Hu4Kަڙ9o!QӅXU3?8Z墨'1iDǔ_~n $7h"neY\^«50-5 s۰TdSodlUxʧU:56ɺjMS'!iK_< ;M%NZ*)<ȡme0ɴ $(CL\Q 7,dY;@Dܥ%|ŕ"+,4'<C9U1gقZ4傧N^o.o1~!t{7 zG/r0 EIszKB5a&"Q],A귛s*f bM6qay< 9as48ޝYy('D|7`"˘~ޒWƇFs çM -4sŚ&hlBt,bh/o<㰎6tiQ [`OB,|}΢^agp06 4m?Spt m=:نsYK3GrU5A2n׿7 fK F%& 왼 539>_r5auTkH K!b~r#9˟ƓY?ƿ@Ccke[A,UwG C22BEJnYj;0ZOmcʪ1DUj.׿1 薚u-4#>"/OĵP(ryp1t/1WrVX:9u>M7jq< 7WaQ{v.AFLA9} Slw߹A/\ 6V"ʾw״DY]/Ho%Y \9=[GA 1Z(ڐW}P hIІš]&hqZƍ̏654ܥ U0FS>)HЦ ׂ'ia^&D̶R=VD?AvQ#qBbA=nqmbPm1ÏەKL9___Өq|eQiATn"d[jQk*:.I `1)a/ِޢwp:-vhHKɨ͝9; C!gSNn%֞|fﭤD vIMw=<T2Q/@0#NTo dAB0-]DdtXB@Q 81NPGɃϓv=ͥOQ7HlS".dI5+Rik>Ͳӊ6/C.3"t%X,^¦`{ !=j,Ou }_8ҫWU.i# !aCv@zc=TLAk#ȿknx̧--C;~>Gډ Z1 ҁzG$8h8'p 밸3=(it tHUJO0޺VK\ʶ1z ZYr1z!iV<ۊHej*#=o2Zp- T'@2t/0czI\mxRw3Nl1 ]ͱN|6|*SsKJva-YluHjݔLck9וQ gL ->񤺇VH5t%Nփ+/c N8 ]n/n0iSO$v@I}_P*aay kOx.uIl]f>lvN:(8)1_Η!|܌Z\Ro*~x(B EP~ͷF:I"a.[1sNaI4 tBC*P$ݏKS;r=͢|^n}jNǦygn<xARʲ ɋDbRғc`K%D kȤ$6/a:P{?4d0/ C~RZrϷZ5QsY&~=?u;*[^]Z۠Gwq~Bբ# P3ď"o7'|r铣={m(b.6_,!MLqmd)ILGs2&,@'+l+LaJ$̵;l9LFy3etW?`YDد5õ 7狴@A 'P259+P2̽@m_jj \kZﮎ:bs50a61ye w LBd;(2>蔨w3H][K_˺ǹ>%79tY ;fDv'߼0 -##I?߇ :mqJwdJw =+gBUۖ`7q{cE(\pO呝` jAk oRf^q-c\FY<~1 6m:-Op`>m9i<^oՃVr~|jKYϖϥEE[෣@^[7Dtfqz߈`-)e8{^_ ~^uD%R8 N3Յ5d4nbs#͟UE+bRguh1vf/]> Rֳ{Eg_1th>NŸԧ,2Esv_iF~ А(!p\?} 1 جLKި Nxj&Vn7ᙁԑ3c+ ʎ:nAYS>%[+o{XEkYxND\#== qi"JNM/cJ-X LӘ^Y 2'n )!j8qMZ W>V31rV;;Gjx8r(N+c=+bÆxF*@E$CTEحp2!q҈z>rЫc*AbS 1;,:=ucB! mQ MwM9М Tϑض~bt/"@I"=u cHDԝۤ):f$CE(uȕ/Po iVΦ OEǵ;y:hGlxN@%/N?b#æqHa0nUN0M?bŸqoك<we-%y!_)xsiY)]λ a#ž OA٨@DӋƃ 2#Wg]]:įM

ʲ(f~&,@(*Ƒz f8+hodwc?ۆmNN&^HS㔨yolNM"M+@mth3_QTxLW+-+M0Tn;:"δ&?d]h' am #  ]W Z+TIbeF eTaU,oc<+Wd*vafr SegwJ"BLXņ3V}bje&ӒRKv!Pm4O-|p~E52邼g2%JO?UQ[PT\*B^6>B-6 B-x¶ o9QQuGT;.V = ˬW~!XY2DBl&abݍEɯYړ[UB*c*$W" 3A^snG/jaCkq9teisywoaU`Й?Y@V ǎi4߿굧q$$|ճ2{O+xӏU<\Ѩg0ĥ۟C D>]4^=˄' XI=ҩ8er'j/ B_b>d~tn4 b2!a!•;3r[20A9@xӣ$*C6nD,{GrB0·=;0' 2{&?=L`@Z=@<n&05=cD@! ,Ѿ49t,K"%čfK4P0% [<֨2Prk 6 b[eDϜHߧ ' oy\0RՙcNr9P*|2&#pue6NX2 C54YSi~kЗ]Y+Q) ;O^g[wB #G/B;t.&5[02]HO+D-ze^$>xKk L0dW%Zu2Q̀](Ɲ7YlH ?'Eݼ:Gi0Ov-6'VE֋kr9c5"t u=x[\0 p}̚g|2dA"t C_M'EX{t)32 m0 <(Ԭ8 be9`̜>bM̠?5 < ^fG =[Q{>ôn ڌrd+ǟ7ڷAZNZ/$?/DJDC&vu1!+z%M?gOP=?ebt>>|zcIsXMK7*4߃ۦڸKBp4l.G|?VRJ7vv&y\%bҨP tHEK߬UOūu$7m1\d|2qg ޣdR%9d`@sE"]Y `èƉtF:ڡ@h/($|E \-l A(o{ @`a5EUWU60f:(6(g8qbWX*!9MIxhn>/lBiN"ၦsU,e"olh}oYe-qZ[K6fC-'C/zafZۏs@@.h*s2lqq㾻 jKbx 2 >TFeoJBw68'!)r <0t6:/cF!->;cV{aީyB-D(KJ$׌ <2^,/ Iu*z{٣ϟ|+mii]rsj"h@vP[4t>; ڹ&;2-MRwoŅDgJ꽜 VS1 XhK=YfSn HónDLyF'ST?d6zvṯF^6G AGS) RA1\sKY)l}nJ8/uI4ȏ5c~"f}0aĢHت>SŌb 1m- ;m7ʙvY2 6F&4 f^cZp/3m9\mp0UFH5h>e&ȁѓFu䱜q0|1C{=zћ2ߑ<;B>9x&Uz} ΙIdYCHG)/Y:Ii9I pӆ{5%/tF\m' .m{?-Ov1Le'OpgzIDlg,94g[B`Y@Sc o`>yƭw|@(wD1Y[=̡)K. bCw05_όJuW[LP OU1(p?T:K٩Q!f?~͉+hb奏.s_ÐK݈[ OkϝkR*ЋXN!,45.bsZ$QjiYwTuX2Lp97}Ŝ%I*4RBv[Uj`PoutȤW ^-[-v9cFljwCt_E 92X&շP!+ V8ټ Pt,U:5k}>X|o Wk|L!}KQʣw8xWs?3 orfop3}+e⽮bWԐJ~<`a)W L(+ۼn=v$9ʖDZ6Q2.y|ንGG~G2ɶg W8~K{lqd:z Xq4A&#<S5y^FjiToC㶹M?nsr*8a8'T806(`#'Cj_ M̓\gkDWSLV:ɢQ,BT__CgSNhS~C؅,]d6U˥N(Ls43&q2py$7w{],Fz#ZB.律s=8m!.xY EZN}Vh2p? $p7.u|]l1u<-s3f5ژ'?fNe ^,0f;g{- Zܦ}ݘq:C50?r0ŔEZڅUXGL2P )VIT0396 bIڎ% l+3{J\pmA HUZT`*ŖFrYj !;Q 2 gj {˾?:#xcih_DDWbCU0NDegu|".M]]c5oݬ﹋ՔEu-#hEWCzʜ]%čB!ͬsә@=S̷hqmj靉F/!EA;\vqmP/~P&w#"{O]xov1M'd@u-Nyl&J/$`h.J}E_-R2mI=Ybj>1կ61et]?X Z-c˺Ze QpR1d=x瑊 hHѝV;}Ўz+ddo 4"[ BL.ä8RHoɃ/!]??Wԡ:Q_ =O5SfX1ؼgp;Hw+K1!#v(RTvj'T{O)Jr@i Wr Xs!g1ni `bV"9 ǣ}CZ3YFޱQ. I_HwۦzoDd0@bpm.rzM\^gXcoC֨K63ʫZ0NVzdl:,@k0gl e_Zs5;96-45Ȅ+bRj"c5CVln^7/evސ T E΀`xCR!>8P>Md94 KM44͞U7T\bmf[ -]|.k*Kb/x俨a28" _(5KbN|VTb 9403[MZm93΍=t"coT=U3I7ޮ%F 'd@ۦ=m8:/83P'iA nYM6M; a 7{Z2H/u_edBDQ =^38WW˄ ?˟\z!էM37r eWw dF ":Җ;A/F0E\{|h^Qx0> 7#x*g4[@"7-fXɧ_+m>2Uj*[r>1͞ӄۅy0m\OĐ/v=^C3 *v`+ ¿%%q{rыd5QrS|ot:~ J C _zFؚc5+g7Gi/%xWnvfo U^b$޵= BڱERGJ|`qS\:˼NF ,Lxʅ79{ew.?ڠ 5K\DPm?F`uY4 }&6OpZĎx8 Z  hHj9+> 6˸ԗp2(oКP$Pfh"fOǺLA^-B!F`3Toh9Og ^4!=y_DYh>D\*=ph^W$hh+{R)4 *ozTdG.1qCѤ@qC uoP@Hj.*rh) BIʷѥ!<l:%rtӨ+EWO d|}ZVW-:)Kyj&ΕTd7]x[īxϕnCRPiWhZfniׯ?9H?TJJVD.C#끝"bCN z=|Vӱw8Fhw7{ )0=s]5K{^PW@'5 Yκ.';Iq9SyQX Dn؆ҝB½ii ?m+"meϏz\P,)s٫Dzk%%iE0(ws_:wa!c\?!`[pE`aӂ,%蛮-lTa$ѡ*C;TF gPR3K>ی!17xNciP7t9bj.O_{X/"AZiTã{acm” >GkZaVwEWF铅W+rtA}~ lA-羛#j| ._d ~t Y?wV`A9dX$\ՀUIck+ dK >)A_[uvɅ즭dDM>_!֫G{`T$f#gahJ&h6b8-3RĵFd,Pnxx]Z.~<$ (%BC >1f3&t"4ᨂ!̄iQ\£҆CQA^|zҀx`6nsvS,j@IXmp}l%{'*ܝUX[F*'h&+ЬL|`Z.b ȧ a6DH1!jԖgBg,- "]#-N⣨vZIܚ#GMz%JՃ5n0S贷ߖwB-z5}nLâBt(Ol.@&g.Hտ4rqCa 7s[6'd {(u#65,̆/sϿA2bг,}u*)o]b NѢfՇQ1.Ꜯ/llQ"=4Ht6Qݞx4{L}d3n}X;"^R8-RTDes (B=יlR-P*Oc>9\GřE3h xp縣/Oy+Sdȹ3?eޮ%b~G'5'-ڇ0Ak5=eR~qrV(YZ`Iǫ6LtWR $yxJ0S ޱ>AuK{\AyZŃ7fRz)@꠷a쩨SO988/NB(K:՘-&<#_Yy 䨀~0 T++nL8'L 1zS˩ʝ66uj3_axJ1r5 uPUO T@ twG*roDS4}58/sa fN9":K!z 0KiYכaU9m[mS2nَFK)a= d5r/pƟ8:装>џF< 9ƅ\eY,\рcaBu\f-Cfe{Ku4 =+S'=e,4-4 .I\ٶ[nD>Ko M8G8# %җ>-8X H+];ẔMuOE+c-|s[~[яCBZzs 0`2+F=:g-]kdQyrL GɗT1DC-+41 D-p@jHHy\v+G'ys[gb#ۻj.(n MYxA!c6\q)%hao?-ښ _t,b𢓁h)<<7M_+QhtP[t=G1 %Ml"snc:V bU j5|$-(5>p3'@m"ݡx^Pk~!YF6&$4@'gÿ(xWthǴ֤< s59Zfc\QiY$Jo5CdX*x4a'm;LTw(2n#xo Rh5-M K;f(uB\e32WrvEd\iG`meWsf󰤾@~ =u&z=%Se9:ɖCS$W<3 f#'荢`,2Sj/Tx7<F^`}g(u{%g\$_D;MY$DVqxB kBzkl*. U4{Gd MxG>kwnD@d}iT5ff+9Ht i?Mx'?2;,`"` "U0]-W:S.ﱢՈ>,A4m)a} 2P]{rl(7&:/ȫS݀XϿDڜv'Ʊ2“AegbNS=P k@=32ىT- +V1b$odz XbGwWoXBͰYx'Zڧ-%OJ~l^A3&1|;2XJ]`AJA1\\|vT1kc9gMpk`uo$XMeE /YSW1]D%'F477*NX oɿd![l/q^zFܡKvL- tUu`"kzOԎ(Re$6OVUiw>}8k3.w2ϪV*<O2MeאnYl05zA@TPPY3U_P 78%`:f|hp$kƱz@ݦERNǓ\tUMƜbeZ`~*̯iAx2eSB2zUz*Vn6Aٿb;& ZJ ^} Ƃ.:{}2kT)$rZP޸y%OPaXeq@VȂ_>HoYNPtoʃq[l8E|!6. oX>>[ؗ sͤKmFfa:,%Z`8pq;"_D}:1>W#;\AĢ+_7- UCŇz PvlD +C`Xc~7+OAY:<ߕފXaɓ@Ǘ]QFe2A$I?6\,?5m=;0~?rTD9Zdû1C^~bq!iJpdWry'g8ݫV$S"9ї!}dGqq\2q`op@ ̸ΔLsĥJj7Nй':261ڂ26bK"Jh'ĮbX(֮IZY-OX3R2;|T?~UÙ^Jz E19F.n̞ٺ˦1. GI5ILJ?.2 1ۿ_SD^ÆN~z=w+&o+"4'@7T+J{ b_ή%zI}Wؐa;5ȏ=;h`1m3EǢ}]|z#ljUt1=3̉W ($E,m~87r\ۂg(Nj<:j@f+Ǩzz| J&ފ Go1<"oAmC `%JwfOajα n_KD.pL x^*wdu9Q_jiC.Ӻ>Qi6B*]oIk[ Nk]bVޥ~yP)=6TI,ϩszwK9 F htҞ?6,'s8QǸ(6S a)$7ow&oѫZYLG0-FpvL-n%Dcí孬GlIWft% :ѷ YJ)Ds4U@a>@?4nxiK~47 &6y 'N|dz-p`. 9(V" O ݃#D6phw䬘16lp wX?C8UdVtji1qOo}s$ӭ[yJ|⭍Î.a4pB HF,'*o1Z]JwkL%ovJg@ Ϥ>~RmG|vV5[.exVZ &t;6QmІ Y8E2dbCC^/A %N1+9) 8fS&o^L;E/SCj84gXiG ^Ge˿z7 l&wmIPny.>K>5 ?=?q|5Kv^ToPpo@zВtRJ-2ĵlUu/Cx10a )i9rkKznJߵJnЅ)]uo=P\5^MCr9JM '?iIh; v[!Em~b㛎Q.c|ѯcFF?MproyE*)RPN4DܜoHɡ#֍pTQtt~Q=T8)Sla91MO֕6ʼn6 ''No'K^9. g8VS]iدRp`9AM8Xđ*&%Ol>B `fVMh^8`$DͶMHڦn&ds2 %&Ì"T҉NW`! owԃ Lŋ)G[ Ƃ%=&~~y87UHQyR}vCƳ9jeCq<l][a``uN w6Б$*9u$TKa}d,2IGdA&`z8ƛIjі/j . v!tA7#M0bCK<>OO ~3!T BkIL.%4`*wyV{D@G G t;rO* . *FXDylJ9r+DA h Lf=DUqy{ e@żjlj*))NvLA'ӹvt OI.m 8~)p6$<YAp1/Y-iX2ϓ0$q|~5( YYMWd{]3x>18c{_5ғYfKh3OAϿ(Ώ@y>ކ y@}܁YُMg<> ^1A}IF0Wwf^zN8%e''9O߀DQK:~ѐhWyR`qiዌLDK5,0|'ʤ1TV]Н%u\SCIrqV0xQkքIG4~)5NPЅ-C6O]<1MN[1ZU%$, <<6>YFSGF#I4|=!3ۺ KB_zsG_rTjWs_s}{3觬C(Na)0,MNTjs}Gx>g.INpJ}&b9^ Ie[yKm nbc}kkssuUE{\X}ýЊ =?x\4Yِ7+J\و|}_w"x 8Vbb6aڱ]gݨ 54j9z5!'"~+(+G_.43j$rdǟdt%[R+BṮА֦fK[Q+J.c8u/ X?I(Q.8:1Ԣ)kyQG !4LGǼ%ܥ%yu0"Iu%b̂A5Y..r'5Ū;n5A<45?m%e@XEBn(膟diTg cJV31ʗόܔΝ,ϥ_,c (P`*]'(Vɇ naiD]gD"/>y@(~c"g!wrb9M9#cYp3X*҈&3A@bU2㩪Si=kݩ5ScۋukfV?DWXzWE0΁V0:ઢ*9(w'U=e=QR0K!M"`8`4@>jԙƶ[|.GGӉu>3{Mj,bKcF4 ljݽN vx؊<-0[uDd]*odMP~=HU˸>xnĉx?%Au͛=/+߁j2A8߳@WPNtN̨ /Cs=7I1ǃihp䒃?DL\؏?%MaVIA-5EφMlbZFYj2,#(J#Zz%圦 ˷g4 giR_t7.A0"W "o*AsgL/_PJ?ODßbM%M?~4~H/&6!p壊\1E\ a)3= -i<Xى- gҒW3S|#Rj=1E|*f;HD5 {Y?d?r3h.gliBSf[DHf]TJi/Mr2ɰF~a(Zɠ3T,G.tm\"{aX?P B-1q/*G|'3=NBDHz.:L !֦3gc, 9z{p5[ҊT$S@ l5LocSNkI1 )Ä⧰B2^ZяrHAo%!eq+p%J7i+E;{2*_k*X;8X)գ虵f_.QTSG<}V" U誳 \dd@wZ6(UYIa흢/sǖ>Kx*(&?^^-R@+k9g1끾 ̣?L=T+ %sI0j#!|Y7 Hn5ީ_Cѡp)?#wW+kSO3MT-|pF=bse4'(E 72HT߫5:SKVw:'#ϩt,7|r+|0< 4M9^}' |dXGOHxx9}ZAWsQ^x6:b_ ώm (cuBu۴cRꙕF1ȈGyUzD}Nge 7;?!si.t!Wq΃R{c]WUBŵf8 MPNkw}W37ZU&S3zKGObz'[A-AH}83kӌg=_ƂaR'j#6#4苫^%NEYxΫ@I/g|pA1qI(VӕXIqKs>WOhhXFcZ\6oMNޱV~b3,r>rf'C]<%1A]| *V7M)#JvYP_uyp"Tj+{fWdl٨f*Y0(Jƪ+(3FSE$V4ZȌ˄ۼ.'3*>vI_ICD\||Fvu֟>%^zbHk~Ppw"o_ YOj9'R bښ,g_5}qJWt>:(B㊷sS:1zωle:R 0"C8 EF6e{XK{Y~^/G\\Mduy6$:% 3,}jG+qy EB{!PB&hf?;bZRxdlg{QVի5~1r7k%YIn3x,i~~}L0ӆ΢fے6PF~GWy_Iq VfJK-Tmav:kL.5=I:wAch۰3VjW>jRDc M@ke8rmW}P=!^$5=5"Uh Gsŋȶ:vW|sA>80bW1:CmtMVKxDO `ʹJ,L!ցえ,J 4*T'HU"w\8@5]Brƻi*T/_D<yAӁ҂OG!XiePBGR+̋Y]3Fk.ZAx~K-ԺC F=.:g"k8;ljW H)/kBrl A` ß9)Fi^!fMjn{Vãt*} 69&P*OMKOC~RXW 0tB ?8 iyЎMoTaD|sC㻋6ًxRXot?4ԟH.>%PP~qpu4ijm4c:(!3ܾqm?HH 3dcٜej&:%&+a2GҊ\BG(Ue+b?d[ R;vUq_r-I-_$ I7 `Nɂӟvmr.#MiGJ5@Alj,[f{Xu_&g2l*}71C=I2=j D!l+i&#; LH`_UJ^$ћl.YohAoZ*LuJ$COM}TV˽C`E06h]J Dw2m3,o # JFg]@qA޿&fik1ӵ%M7(Z%B:oH6sé{~\A. *4k}L>q1A)=N 0x:.BJHaҝ :և'ՄBeu9?#iOorXql7ЇjF_l;`6dF~P}3ծ^+baaadܦ X]qʻ{h` {D๴]#JN44pylUR_%F5M`rgB7A8] hnFUy12>B^S~va1dXFS@N#FaN*tT7"l_tG1k9BLbQ9l҈!IplfK`Ur6EmYSc>i#mnYwk @~t^Sr }6]< Cм5 7ޥD1_lg7LJ硥/VgZN n&^ .P;Ws#`vdă4RpF9E 2k LZ} 4')X8 |$BǩR~?6u*sFTY7ܠ"撣ZrbΚy{}uDkyT}_5* !*#%F׫6Χbz)ޠWE{GX\Cm%%s5PЗ>KV3.HrmB?.ҖT斎u$} ) ,#&66':rDTD]>arFcң.O_/UlVىbe?ԁk~ ,(~t`gѶGPN\'ô%]ߒx@ U*Wc X~& e;v DiA2 tY+:o^uS8Ҕ,:"v㛫?-*jR* UJfo:UJo.(]ÔKUDG[2inVkM'Xh=Xn$ Ilw@F㇍5qGWlC~D 4ĵmےg`2-ӼZøF. Mv*%!J^V❱!;ʃeU, ؚ#ޞsUr[w c%eϗH74   (i& dcw_5> fiHJX(7E}wl;^شCM(L-.f& t2b\)ZD]S{\)ul(vda>λ*~п p\9P_3P}ֹCHÞHefKg⣘G@d9ky_BW||wsea;Hjh6(d)a!8?pyK`qSм6_k D]i^\ڠ5"/p ux2NHH_'Iߔ/I4pd½=}_i)ھ[]'5C`Qyb|VТ+?:[grooKS2_P6nMo7dUy h3 5Hʡei!M]?M;݃WȖFaڈSʟ胋)*S%V eQ0:y:K%S0 k\φ'(_fNwMti\xKяzxV.NV'ͩJLn,1Lk~R݉m=tؾlaME_RI&lov'4bf*>4[|KZ 7rwJ@]"X3ߛkCorr>-S}WpLXYg OlyZHF/?BląGU? wK۲kb-Y],܈ c#~0G1ӧbeoSF 4 +2PGWƪ(FGj5[bIYN QUHAV'zo7zn X`k@G`D@PZ2o5́9ܘ2.l +DWƁiA`Ӱ'|jŘьAN},QAToIB{h OglYRQhZ=:mAW@ sE'r֪Bl{ר }95Y񔯶#q!ъes '- !v}[? `fe&zia!oYOR/sS>±#oUz|]լ[FOdIwǿm͸,\G~gșda3Ȍֻ> 渜2 6>Z{ӵffop0XRo7^]c^O()AACYu 6 vVUf揱T`Wa-Mhf=J[?wl#pLxPuKZD/(mVbڌP>E  WOƱNBiPʺ!n} ΛdڃXkIwxm=Qm$m qahEފܥM`am}Q(ʆZCaO{M}Yؾ\H [i ;lJb>{LpY{  Uؓ4ow1 5^^UE#XXY U#ǁ73Qs5 D.ҮA, oDRO},nV#sG!lh3&_JЂ£cM +BuLE6b  ӬǭӑR1-eOv-O% ξM/vK嘙3h`/3gt Rm\(6I")'-lQ;64NVWIG;ʹIZȅqj~c_v,Uzed%k]1"c1h9e~ "}ˆkM޾td=?%k @& s_m|jZ4ɬo=ח3 yh78@ݑz,wKms)Β-A4x:NViīiޚh=#@u{Бnf+}ArGM %@llbf؁YH5)Z)y[me#|9:b>= %]4BYb?ds2p#n} OL%S4e!fT8,< p%jYe^,=̛h+(b^aK2¿k"5חq6f}2VҔw8辖y* eÇʄCvBA]}3_A?)1'!A,w9`R{6UE[̇x?}{'/ ̃3gq79ؑ~)LxTݿ%Rp`caI!a+<$3pR[N`4 vA!fPM$agh@{&af65Id[Oq!HZd h>ZdYjCɧ&QpqJ4ֶ\0ͨd7ӄn%s(dWX3#^u&G8VN)~ ~vmYJ GewiN|7)R~D|k$6l;Iroܾ_n zų=k9v_p l(f]7[j@|ڝ~w8#0)9_S)SpC{k C'2E٣$QaZgOD 8-&׹^DJ.Cm/۴u7/<LC"I3Fױsh1-i{@ ^H]&YgK~XP]ڪ~=A>_ yv[?_+Ҧ{Q(Q>ƌ|"v%eo>lŦ0,|Ql Zg;4_|G)(1cq4fllr,Si i̥�i;"J~=Oi:r*_{A%XA0 dǹQR]a,E|! zY7zE@&7J2XEۊ3WkOyroU&rLM6Ի8Uc.z~VÛPzkJrrTh/h$!Qy?yxV@?o"@m|t-4 3pw;M0mҹ"#zB ,-1"ڢ'ml< f븾(z'tI'ey08>';kNa;Y7x/o*cCF}IKkϜIAʰ&r M:8 e:iT,H#gO M F D5ve%*j2}=,j̀+qN:t~ѯ9;OTrt.|#$\餬~NjQRo[Xe cmd1rA6u""g+}m&^kJؼ<ե:,RjQҸn58 .)abS=X !V_Sa/Y kOU8<[T=}>8J⶟ze]#((̣ <.zw7Fߌ6Y'VvfSيPZH=1j㸙 3m]FeMNBD| mc "+VQ{:'DA m#q2X~?]_넂kFW=v4`y24:cuXq4"2ց+@Ǣ$cjj;wp!Tk=GC@j߄:o)r]`vy3iޙ3{p M o?,eYi`CPI@Lƫ^ Ehꀃ#"=T>y#! ϡd_d%d翫[pNE/k 骱2# qtcx QGUCR[`y"l6b|Ǔ귊)nyv_pI6ğc2UznuQEtUmtkς(ox&UMFB Be2BX Y=+$x9 (C 4ث'i`%xe+))nbV (x+BA]0D?n!f h|%)̌.u2o?)v"KDk0wJV=ƕ̯3[r = AN} E&y#:I)L*:@gf`ZD*bq|9:1|Z&i"L8 ÀTO(ϣD1zTJWqkj5_Wlt E;\߿ ~oaϳҵ$Ι7ߘ 6LUM(ī2q\ .08; IL敏,X:[T:8T@gFp|g^ 4fu"mae[d:v"8c;y{!XX}Q6NovD?Yz2Kyd/*H^ >M?²V4sb:Ժ_|W[#p֥fCfYwL_rD e:LD 0s#"!iC,~.Y{3㶤0qB( itf~ X;mUl :& _,jLpkQ :aM=.:STAN{Ԍ6{”K>}:qHZkNv|%VW)ֆq^ zVZ6SqՆc!Rǘ GV)"lHn%]j$[9bMÑuGqGAvs{)/FlDTb]p@n0ePܛ #\}Nzfl ǽruȁMQuBΥXecp`cDYIN+5=gݬڣ7d.&$XL!m*[xhtrk S/R>]P@?cm."/`*E-=ߙ Xw9 y  ^BlSoUO!CZ^>K4}L 20,F|QjŤVfy eѶC>@ ql/,O(1c$ߍciM Mt49p PLI 9[nfGfqm+EbV4F`p<.ށMlPQQǰK+lMxag7Et(g e#*re[h} sR!kS@ n^͢΋ 8.J^F`n H 1IW<lVLJl%2vgk*)z~g E;BU$*.jɋ^X`/,”['0.~d3C@`̡FOq/2aR8_Du3=U>S>G$Tet|kwUȠxVfRŌ%ۆrׄ.n6Ƹ8?%ہ׸RL%=IyMjʆ-@6t#d)|4*mRh6 >}l?J+[#JYgK/'<ۃC3|K"l _&a7fOGO@MDh*1v/=bO 3 !h"Σ Dȕ}bFG.pKzEq&??\:2׸&fm>Z2kK6%帮󵶄Շu 9{'IZ%mҜ3AWZ3f?k&NU@$KU£l}3KEk`{ !RP0+󖘤Ip~#Q d~>/&iHr *jah;Z]!Bz zݱKI0ҧC/k%RÑ#IQ=O$`{".Za̴^9n18UYz?Ir׿Oc/|E晅kZGM  G[ ׬%zl|" y,*[5bL4:5A՗ Uj@gu 4v̰BHH) 4 AlR)6ɾ5,9/6f <:@--JzSE$#W?EƧZL}*-*ge-/EPT`Lb 24 7>"Qռp#fү3?)\ΨJ.ۇ%t A!wRF3:*p0ݠD!±޹]?n[EX2&r5*b`\F.ů(!oS?)]!k`D_n[}.;HzJQ:=#uVHBSS'CIv Y&ԯAj3Vx30*,Kx^n}QS34`O!ޘUBimd &.K}!Iep*Sҭhc%KK<A]w9_::Gvy5+T4" kto،1J5a.gwQG2bpu5%X^pG{7n[ttrfLr9QńIWQ~!t\)U>Ĕ_b\hF :*#6NM;sw!4BuW8ӉZгnbZL &LO콱 ^=omB|h Vcfo|j5cOyw%1\&%u$H/U<9ǬjFg8^8 @S">A`K%,s{>aS \L <5i}5#xv1,V׽t&;R@HQM7 Db?\5׶1R*Inv0Vm:q?/FK_U+2نfd< [9C쨷??m.(ˌ]nm<=s7KXu6d@ЀyY ye͛T=>/r!8" {55Ub`-Y jNab9:/%-l]٣WpD;D:l;sȫu1T`N !'7{kNr Yhr!+"y]mQG alRӤ6= VYMثP3#2E}6=e=@=I{+řa "#J3(ԙ6:D҃5SSj_ȭ߭Rޔjyz4.Lo#ׄRXAkGR b{wm'j9U}%4F9ĺY+lc>M_ W?9mujDHo l!m8Ǧ.+v~gdo|v/իJoh(rX$wżrJ|Vf`#=\ x<Jd3,ǩڥ<:<`0Ҳ\K9ŷrZ1O ](U̶,}F2\z܄x%]!qؽOŐ|sU$(nţrԈ[yC!^ X5 '*\^O0nU"# e|E >;4؇/%uocL5*'n{ Jn F=J LXE =j\ۍv A/>-QXaXcځJ@]^lj7=̙Ae?!z 6%Nh6`c;-iHѓp>h2tLN=lVFg}EA|霣h5n9~*5XeeJG0ed2eaTxfԳ+p}ܹV7'٦ [F~r" ~㐫!h˫5> wJO(t]OzY`i -UƛVL5qZ ?[$ze"GlMJn|x5N5Qng~NY=KitI~ %EWt; ^Ea{6],C1Fň{?qM*chӑ":0zћM-&A]5`5qba[m ͓4:M'vF",Y-B-^V m`qUVxbRTE3gk$Ӄ+hſ(S sO.~⼠+s? 3-<n:إ p1K9P˘|x{NQD&O6k Va:ON0Ed_H1@9dA; z<4 W}<8v $./8FfvOE]^"i +乃 7F5H:6<B禧)>u[3ݲ9y8(Ŀ[ccg$=JVLMWBSd$Vޞet!6կ/y-hEgY{0x_3ڰp&/0G䞩0?IZSqB5Vh$d1ׅ`Df9l-x!ӍވwFV-VDYEԵ& 9LHCYROZuY8V[+n,v\swDGK5eT<+e%s}LB^0#*J]l GGY)u>N.vE٩UwJ*Ubx ng! LP_p9+1B~jeG|&8_[+rAWh75rhpo]zeۧV8@.3߃ra,H8*,ZsK#Tɡ>mCa(0Xx'd0'O60Wëpg7 [g[SrL8xWm((~>:sA* WBd%1.x5P>SxnRݭZ+oɄ3bcR uS+Lq2ab/) D07ZŢ5OȟLR "Fcݠ}wG~ݔYEd+7ͣ +~'F"ޫPeW" YA&&$Eh;bR'3wd(쬾[g}7ST7K$WI>g i.u7NNa=+E<ZkvBf躢xeuzXPHmg}7,I 3NqP&ĚCHlbvZ^2PŽ cA 7aOcUb. H?J,̟u ~V=$Ij?Ej{Hy>bծW$k7q-Sxun6Ahs+qa9]g׏M+q'rWi2S4 odX񁜂\}y?!qSس~[Bׂ6ug.z- f.tu/x:EP6t7QH)9*({L e21G3D w]/hq˜oe1CI𕈊@vnZ4q55;}m$)* 3\5϶\OuUqbh=rڧ@uxe}:5?aI_~d)6m8Pzb{SmrvOZOEk)|\S2S"kU BaN$2[ mzl vg!TC8ؒrti!#c{U SFiHrm>E:+bz άU4H\«l\ ܾȽ%2vBV Fm k=@X谚5m_"ƚ!Džz#BcY#a ĽrO[1Ay'RC[^EPsi[oog*76_L2¾VodÇ&[ ${cR}%S·8k4وE4t,k4-4OBM bxeY 4'~ ֪c`4Wia%3QY?4ir-&; T1{30kϹ U'.XyYrCA,F4&!,(P(l'DSY^Ĺ&<_$ߌqH0Yjn YO7SLMcPo~fNҪ߽ .cl$[]ZԋK% {17Y"A%leMT >vU24{wjYxLoT1u9n G46y1_܄MuϛH0~L_Zz+g25U'ƒ (a D{ ]\?꾸JT-]o3m=EAego{ /h`1}8{?iyFK`p0fBڀ{h; V렞t͒)j?*:[eڶn?PS#o>( 'tQbK_j4Va⅒l_뤢x4?]푋ҧ-,)+RU񹛹(n/CH>pÈ!(6,ɞcey^fISԶpQ9 Ō rF1"!܊z | Pl$N4Qys-a+0(2EOI`-M嚚refQ [QsYu)1%(2Qް]b 3qwD);‹7Gwx3|/Sy+^[9;'D]9Mm@ՂlXΓU#f f =XauYT9} TIM"˫/E }\R6" iP;@s\h{`*v)WĀL}P 7ܑܹ]E]3eܺ|R ,F⪫_tӦV)H'~.y`>>݋lڞr۸ TF@l8wJ|zU%O :sFDcnpoXƿFXsӉF0Wۡ3H'ȑ#a ª7C.0 zM[~љ@_8|=%mVmׂ96WT~$2wt"Zm\t/P_kÀ ܔQvArNe,6;=dT;"VgbYfTą/ HМjϥZI}NCڼ D'oH]=>A@>Ԁ֌MrF[t ~K!eIm'k戢5qEǦRI)> tjޘeA Dw64{Nc~&i#hgZSy%EÎc`&:UH>lfhΐ] ີ7eۿ׾nѽ uXCc9CU8a& 74q+xy AۦrE|$K}O57Fz5uc-i0{euS-]K# `SNO Kmx*\%Ƈ=1꙯fYpJi!9Zr)ʘ^&cU6; ]$y Jk]2g1:xx'҂{|O}SZT4ו7xCsS<Pc}ʏ<LgHϗ{8]?fQ-w2Y\=E=:5O)A.ҦO)ZMx?iS*: zQ/9vP*Ɍ~QvMZU^B*Q' }?>J0 n=)W}™St dՃ=OuL,W"v]420\8"ښb??ܣFy;d|m+?lMh֌1g GzEvYѶKS-LNn_&LeU2sfzONȮH e %zcLk2晑?<{nC=[D]%[ ݏTZT"c~qiF뭭ݒ1|5Oq=[_h#Se BkY], _k'AoIz?50ul2Ss+>3#hׄS-RDGb RŞ*)`;1Lk^-uUIUၖe>z?PR2^L ".p|=!w8VF.|9<}R-oq{0cg0JW9sjRoR]cP xqlI²}Dz>x죿rƼ`/CWiF3Pdooioɞ6~ 4ŰH3O&cAe@ςkbq.șȜavqBHⲺ Ď&i)6c@CAjd#EL66Y[a޹oGI~Ľ6`P=*o4cBJSڨWΝ hs, L!9n =}_\TmDE=Vu}mG еOZjx%q(j{Qko^j58˕hCY#yWёiA.U,<7Υv0khFMpjWHdOw4֔GTJI&o(a:|ZP44oOֳDU HWHln_fFi%ǩ*H {P9sRUPЁx 2gYLWH{v%Oݕ{Tғ2++%WX!Hyf=A~IU&'G|XRbQ0DHNJ ĝɑf`F:TWl7C)KZ lfQ~ueX<oEFAdKA6ܨ{5*ʨÿjNmkש6Sn?QfGxC q[Qyo|,%hN۲&-ǝ4,҈lmԍ9n1N Ћ֠({\USxԧŶ!]~lnh*.τSOmhcG 'Z Oe2_gcA;*BYP,;;56EQdRKJҒTʉPԉo&]b 1Q (jG.bu֑y.,ePsa(qj4 4D+O W`-I]T4o-~u+Y2ʺ 'p/^]*<Ӭyi6D"lTEKRh7=pSƤ0=}!qc;gh>l{q_:ˆIkIl\n2f4AZ ?@:}.ϘpDKn|~R4%?Ix$ ؈ZPa $>-.EN'3g!\6}9A)%raFQ&П+"D]?(P~hqbL3 6 '|rB+J 1yCgӚ]t9 Bd]A d]NbYI\gcQHt};F)Z}/޼F┲Ф! U4Rݿ)KXiZE*;TCG_5ne?$Ȱ&W~rЗ_dY&1vrWfW'dpDN!h kC̪Ht^7f,x88Y3 Ip >BSuoOkJ,dZoyRӑY߻H:оFJ&wIR{p:w87"{d;cĖ0J3 svaM/K%VY$-XK__WV% E?/BUX/-ёq*_5o38-[:4{Tfx/y8i|s<Ni $0Puy_5Ӟ,s` &=rZZn24.W$]KB{laǣvr#j #F>(i1|d6@gg>-*w5vݧ ۇI@o,e]lD >5geQncݽ" H%2_ꡔ 6^"rP3qܮ,=uձ( t`PsUX#mbԛm§iϰDхAg^o粦9$Ʒg~q/g<[L]Tz|eBcݸoLD:^hJ̢bYIkJ".mUA1.K5}ox42]G'4T jUx-6Q5WyV2CSߔgTjȸ kGK#U>^x$9E+#\i fC]hr2%I mzܵh|c9++ k810NZ8tMT} 詚RAsLͥ܃`G|#FPMeQmJO.V;/q@y ?*ʹZD?8$qrc>j407i!Asa5_秓Ú+d5v 9yV߀hq (=¥I%Xc 6>+'cX)!l/G@G(u*h\Ŀk܈>.j"K|e[[(hBdp/ۼ#@zjҭۉn40 .,/J/L  Q5B}SM?EOkG=KWQeKdto,%<{¤1{2WmtRgsޤYzl)jB#Q2= o<~2 Y |Cũ \ʡ.nn]1\#^&Fyt<2I;#S,ؾܚ#&0#fc,M`׬KoL&}sWzqj2~rq ]4g8 K 1w]aW^g'O>͚htו%6OH?Iw}Muj}X wqIL Vnr9=Zƃ%)$"[U_\Cf '&gzZ/e% ¶FM3:uOx&8߁[-hQ\3EҘwNaυ- }Ʈ!keW"huK@\S6λ8QZ2vFCJ6j)1IPxl}6@o!ONĿaږS 49Pɝ+kra H[ak+ ZcA'z"\uP矽l HưBä)jM]NYz<]EB۩Y:lO+E X^hϽ8U=_sLoY '"~cI+]F2u:K 2|}':ptP*NaVRWaګhsъn>n;P #1@tѓJ窧5i:7-[khFn4˻ht:1v)0ٍ#.0`]uEsB TįWwJW8)tU"]*p"F?}hI.,U:qKG ,û ,Ts[&?b_ދ ~v`-T&#ՆjCNN\b|Hgז݀FeB-*Фj{sfId*"7ɜqY e[7}zKIҵp7rv&M)Qr4mکh1bfc؅@/ԕ=| {S06$KK$h.1g5ژ[`qhS-cSOxU's;BMa)F)_@{묱CE!;d#XY'R,L֊sgDx 9|fZ[@xj*&-pI57Rgzʩ [vzϾd|"^ѝ4@aXJSM (ۑ@d\Lcap8rj8A@Y'/Ҁ@ R%<Am޾ք!!gn̄hLN{U>Y]Ӻ`?z[sZ;A(m%g9Tp7/ gi'KMb̫%S۽?zB:C ~Y(jFjPJj浟qNjD"8Z%gj>F_ R|Զ8w&$+z:ϜSwA48GgH> I$K1@7ե2HģR6ּ-b#&W mYp6?7KX4'k Qscp M;rD{ =ỏdڍ(Ajl+W 0Q[ur Z3Exn\{PyOwSHYD.;TC@.lYr#MHg s:ޏ&vjA>KV茼K[t$#' 9lft: }#i?Jmj? ^jFTt;-f f|tUXLh#YK0EQ qAF~<,h+%5ONm >p+Y j`9MA w9A?,R̜h8tEzSn'r_ jT%͘A`,] ǵUFe}3B8o]b d!9x8w.pnvX=/>= :bs 7la'Ǘe 'Ƞ\C`˳wH~.At_P7n207)B0b_Np$>2ЪkU !^iql{wܚ2muEWP ky# fX%NL'iFa0uq_<|cߦtjU)~&>/O%jb6/Nzm{rkĭYӽ.Ql񪹀:hEqrp3^v dR%1``"92GW HEIwZql^S(Es4/ufUi M79jD" 7hUCb*^X-D547GǶ ghF;2䏪*(BPը\ &K{}Aas μFu+p;gm')j%=J n#p;4Rq50 d$ XB[*UH U)/ 11m YrR㩢ȷ<??T9.4ĉk4Qz'RKP/|2=|.[3#+N>ؾT&=-)y1PKx+ah <eÜvNC-3֓_]hS;2N"^xXE,!f G#DߪY08UrjOtNN++MZF<}[\R7OZi7)k_. ,ɲ) .+sUμF8lƶ|b7#j[IMar- gfk:M+&^[?V{au`Ą읦9gCtפaE'|nSWfIǭ'z0Rt9*x*0}ja%Ugh'7ͼXw"b֚o+:$ä!K}Pg#-oc+c O׋DjA'*~XA/@cp>dB'HۇInJ"5plOуkzNIM)=ټ^ro,@lmo.`!{7\3ah]bJ_ +Ҥ'j'ZU^o*Gr<.qnҞx "InY@&rCX $=l{cI wp! TWϐyrbkE^kRt*uq&&:;+j?WGd:B"p[y!jE<(~OC-ň:lf_/BL~^W?tz,+/ #q׬=ֲ't{B1'39sdsJ dMPqusꎫe"?\@Ix,yj@M KlBj00&2((J⛱N=]! i mq=ukN_jx-- r/TfpeJS4b9U-3|H ^'2v?8P1;-*'KwGAz@QeʕDx2`KMwb1mL>s2yrnsKV?=Ƨ'[ٳ0S]U7.\ ,I)7]) m 58bߕi6Rn(P͙2AAk?$U`-?cF>컌j|ӚXjٓw} bˡ$NG惻 WY퐱=dd\lfJ:E%`{zp~]kT'8eЎ,IEpCaˌ%G*=9UAV@AOQJOs&<yg9gaDM}rš* (N͂82qTo;)侒hpƻP3fQE_FW&LpUK&5qWڜ*/l g9蘣 ZX `SߢnqdyԴP,ǽ @ E1s^V,y!׬+Pw<DimΜ!L ̶j$cs^'Ta[ oqn}|ڿ.W]n AR~$fd&kT;6IHOA9ZJQYT|kH\|5/8S]ZcSgtX!!G1 >\hCۨ'䥜$/pUG~0Y}Y) FvۼhB闽Ey`*~~r(IG@ڰ1]3 )ZPr8dL&;}lbUd}ajk*YP!uc1cz; 8 ƣ]ց+ t|N僂`b@"X}CX`>{2rV6/4AMM:r4܅OLtQ*Dqޠ jf{%KjT/dڏ>_`J ,q"x4~+C36֦^$kS\k>},L3 PrxLy4?&Nת狞՘N(K'Tb"nvFtv w@t\ (Mg6P Zw=FeOk32~c&kMѾTCΧd$3iŞ3Q]FC0cT́$4ӹgF)Lj2XwXYA-HtJ-`0nŞA=dLIN'+:lEk? NTVTqZuFhp1e>zb 8@v[[p1aDNL:@3z UiZŊ6P)5ʡQ{VR*4'^Wޙ] OXl48PH#j \@6>0upkAD8~FЅb:C!tq @**B#{(:AsxЎ}=?c8m $],xO+1KM] k3U6_n0C.Ұ%l#G{wYv MtLAE}~LK1QV2}plil-@ w: @D^!&:wQ'^=߮ةA Hdst! *ѵiR~z*a!c2fIZuXGss\rf*_0.k"OC 2 VwΞ)Rys yg˳/P?Mj~~|,$ٴ 04*6{b&YBu hbm־&;Ii ~Fh((Fklz`a y7A9i>_3` PJ MaG} 1-M[-wtF^,]ҹCFw8QTDlo^\+CUEZ[4h%Hdtq&Ԛ2_Xˠ^hY~h_+y Ab7eg֔q,hHH5{? ]t0!0"-/oʜ6drZ\=U;e%?ҿx7O$L4˛.ͤf׷qs["&Z<2#`E2*Y&r~'&iLJ'F0br>~l?5X }¶P:4INzD6|!l{y4;q@ ~ A'9NaDn#HUpd6dyWL\v50#C9BgfS*ܝxϲM?DF}AL/L*ۘP۞N^`d'Щ^lf5ު;ºk6+xtImw8e_q<-޺µ|n,B OUXjK5?T]Aو_W8(EôN k!>hb p_o܈acf܋)eWo3g>:2y\30f8_?Z9侞޿(%O=Ĥêk6{;dفEƳLDo:37zk-يKMAZtjpҊ(|Ge'm-KEt94{_h"1/=n{H=|%DfT=ջ^e-~n( I_-K*rg D6hį8$UzySˤqZQV9a*8Gw(^/Q`pZ/!>QFÞ|f^/G٠^8*=V ^_Fs؛)´,P/uz͹_Sϊ8n] ;zAc4#vg#D~Qcai5M2.,dc%!\kr0gеI|TL@yꩅ_Z}k>[Nu5>ӞmSIH`u6U)'AD6ڥ6R:*D81NxE[92Y߄-֯ߔQƷ Π5l#^FI"FCpY۬=0%qy2:rzy?X&9Dd2edt_50di"tzbMC 2V Yx'F p?td+ܫX6MFK }5 EILY/[I AJ8I-cejj8wkW[*kp[ߢq}Ex24n_G|np-0L \H [Ƒ{ 3~MTZl#c9E!Ih~N~92Ƙcjxp.c7PQ\*'_|ww̤˜%|.5|"MߙuJny#P(8JJ*9kat~-6hc$5 ,| 2q>PhL`/,d{tObޮ6爐T@gڈ9I`e;JWqbsT!ZL#јWÂ9oTO+c|2h.K7gDWJ,87FBEcOGu).?n7nƌڱZK.V`Ar#J[GLޞ_t-ڭlKg}yaqFf<t_rQ*\ipPFAΜ+@)R{vR!PUU> ЄmVx L-kx~f_IJBθU.lfRP z:]vؗ]ۨTH p܊Y Hm$D)òe ූᣛBzgjRKNfȜ  ,^3ͦ1"`}[ !fD`1$YǑ$37l(CCU7gQ8jV7>R&gi,qR5eGgl0Iz4O~xϗ.eضw*2MMwN]mmdTc` ^-ǖRkC+A/Yюy2A#&cc-xzxx0&I_ɟvx}%I }Ӑ4m ujI`}W\UpiR/p?Enh˷A0\8jNehd;g!S^-;7=ω-T ҹ=ՖU^Jh/$ڏ* Oj-A;<..XTEC04z~ړj)NoB7pym,ӵ*ANq\ qj\ ;Gtlԗ$`BU^ !>$Vz<3{k"ij([P\6yqK^^#iew_Mޢk0;70 E23E˔.A%fA"90=WH`J86@~k_;M+pv;`)>7"1Y 5SgaYU xaȏ_&Sr6gI:G'OxBBrg?2*^gs>P46䀏ђVeAoPخtR4sžw]yjڻ8te!Mi R/zx*xa"RztBƊM'yIgV{_YMıwF_J@?6CiT:#^[q Se{W3Cwnxwpw金c졮 n+ᦴ3Td)[+vSw g3AݙJАVmal@%2KLi%˼6)!Ȣ2*1p=9-3uTuf]ϴr|[ 8!`kѥ;Ǵ/J~!J$1:J)YŠ̶o7 y<"ڷ2q7^rQq(+]/amlF'M¶ԈŹWZ=(X5P(|6kx7,FGYJ r0-+vX;j좁0ŃeY5A jF?_RI mhx5뢹c)ASG -x^MKq,-&rrc>33m>%}'Ny*c;>U’D]O,dWn=ş:4M6s ރϠC-&/kHٍp7o~\T!,oa6BQ8BK؍;Nc{<;gQK.L=Get1?C(ݕY~ 2>\m=Ck>j$&%xPܓJM|: Y}JW΁RǢ#p.{{XDM`r) F#"l?㿨4 #Bw?7.Ky¥kCCjW"^mАƥoԁ絁S#;#W`^n+s% `B#g.'1 ԃjxlap%ÁXA͢Rޖ؏ =_XX@ oQ"U}W.> ѷëNymV.9܄pvh5 >2GBSkg#%::*`G;eк.Iy'ՓFJ9:>8+FՠdޗSCۓb"|]A[%2}e̾topH7zb^&7y@hXۙ(.XLxӴB=jZ%F̟AoBb;^iR(] c$a˫}4Tۻa ̊Q>Bb˜tAE|j[%e<:-#!nAf[a?nf\6]e(P`| JHo&$#pa!o*{p,ш 7u 2yרNxSvYz;C4+0xb?|O6.D2{F-uj؀xo:I-+-[ByjX #3wJ{Teقe X-c%yůׅґ7qJ ("f<x}8t'y zM :/ư*j- ׾a*kr3[8Vs^XuKF) S,y6Dhh\[(}vS0L"sa LGq+JPXVALPUji;C8·㝹.]R2qcQ1Yl\r=K Ip`4(鉘!b~")Ij[ND/}#R"aϩ#؝0mmGj܋5zz:3KjFA<_\26L 7Ky3py .NrӞe(Ez)" a['"CVa kĘX@qS&w nMɲn$PKxoR,fװG_ϊ0KU)M)aMkɤ|+D( Æ4ܻ*-ObD.z6nll3M~|]/}u~j | U"eַ' aG+&;kƬlA(d znUtI[:4.T.5r9Q{F< "WE.-2+ l]dFbX@F|ɎΎҷ%ѮAiPgBf#ʞ,yk,%1U܏9h:7Dd޵K yLGo}O)q ȗ^+;B[K#o0w{Ym}3[0YD:0X՟{Nj@DkC^ʪ3&7_C!'@ƷrjĬ®z2PK!]0IoBI(|^BUעrQ{C"PƅjD>E+S66Wqb Ku"(6(ýPAPSM"PKDo'lE8:Ha>fd33ZSOi0әr !V}UQug 3g !Epع$Og] %,BZ6doaBy784Y0P3ɸҀ hJFjc4PL.Tʩ|Y!R?5 ٶWCKwh[h(N%2u{=nϙkN*Í f]W5q-y=wt|M N\"W6u*^A(`lqcɄ!ll\ 7$Is꥙^d|MKܦ,SJXןϭn  me;,J'fHZ"QH9DwL| X#5pQ^nPERF Jx9zEUO_m&#!'Dmq) .|k488hr5}:hYX3ռU7A?gMn7;ߪ#O `CT-c4f$p(A{Agz @Tgkg3ͮq?KZ3{$v;f"+9ץT%I&Iv> L -V;%F{k6ИX G ʱҢ 3:7)O9rcI|نxNzoG8ΈGpYMKxAZ;ޘ QdEC963 5YNx|EE˖j~^!Y Bʱ6{lQ9{yX?s)NaֽkabDz x.g6LWܒ >l߽4,:ciZe<5Vv;p{W1T4;ڑNy혩@C ]EqV`I97JI1ld:QϖWKdv"p)bN~/*=vytŲGrQq|^~_ ) ~`TC |<|r' ɿ5T)"np.GUl}s:giJx}`y~gTuʵ y?snJ}3+#"nSoipca` 7g'b c6;Q=sɻG9$Wh{_a쨉5ɕh}%et2(h)\pW787KPzvPeGjoz[K~l+Y"úfp J&G7zqˈelk߾J3N)-ans6Ku ;% 8rSh`(`١ɑ;xjca+$"ΨS8'V[5alܣYyZ@Kl֫-!D;Obڌu,]wvM"GH'?M`26ڒ+f3fK8hj#!֯V'LER#yu_;7o^ cd>5\Ȼ;}Br;bnr? RlJMnIo 9!CZ>3};I}̇U+<-j #hեt=d qo6# .2n/8)Fcߍ 'H^&nj$b/] N@G+TM/c)GHI f~Ns%B,4܄0=ȋzvGC[o'Z%3熷^ܝBzK3 ~GGo\_N&ҊcuT@MG9ML1 V}&hR/sx9^xڳW\1;5Y 3hB4˝y)R8º|iQb1P|%H}w]p|%}6N\g^vA3wVx 5*Zv(AE%Qyh3P/|+t1"4Q(J¤jxۼ=g# 'ءs0~L!ޥ f%`2/R,1bjGO(Ȣq7o7oD4MeOcx!MߛWbB{-h{ڶ3!%uK&Wz5M$uV9οȫ0ATW4j_vpO5/AO~lhEڧ@RNr%#XB{Qr8M-TLtO@ QUyJB'J|:D+@ὬYZ`|wA2…aeMkbr"P(t"f6%~4,Y82H:>aM9jbUfތNj( TUF˝<z k4.tcaEve, Y ٮp*] Y7C%ڄa(a8{w\骇d#U"JF6L-jF9R:Ő;@Auŕ04oˆ8I Dh~m=7Ǖ@YN>-JGo8 KZ, oe^,x9F]"^)7 Wm[dkLLUcubCoֺ11sQua2Aڵ݅5G⼨V Hڵ*/Mh\4KLwpkUGXo(1[)$fb و02WH=![jʢF. YPd͙|F?), H>a[8 TH9g|-3s]2sm0&U7x7i(h֋(0k9|LDxO_Y!@j# m a4H%j 鐉*v*2["]՜%Q(VAk^b%\m XԃM`gPi,Ş(u0£ K*U1xLyٺL>0G~+Kuh5A^w%\^@c{4!xٺe75we&jyPeb,Ph<tȂh!զ u,q\QGO~$9DAJi XFAB^aMt8Doi$֩ !!Z&$(M|/ʎ/_ V|Gc%M Uk:ٹF4۫˃Rqr\|K +{64ƣ^ڃb!<Ҕ]t;]~=RE=!U[Oj" 6pKQ!cвҷx *띙Ts;vr:XV,ILKsOFPYxYHBH`0(T0Mo{%Ǯ-H:މݫ|Jn4RߟK3iGEAX 򠟶r5_(~έBg`L* dE Bz2 ~L R__sn=. X=^ >k,`.[ TP3k&@^=sd"5S2MRgGd@%yltnFK qZL@5Q["5f9RVGVGhp?*[VyLYZS\{ H{?*4%pb2ҝRܵVdR.#˜E3^fYyqՂIwQB6 T:aֽ#FۧKUDu eͱu7cѠ'Ky )J BɗucvNl>lPz$1'$Tq MȢs5>=Z*l䒲h# _O0=lڵ5x-pccmiϱYҲJw sbGp-p& |vǼLjE[f.?N5,$1ǜA~dĆ;Ǒ\ a׬5C)ت׳IFUR/uZ8Y?+J.4 etU0SAD0q*@x ƺ(ädt6p |U)@@7gzKTZsA,% u5yALjҝ'0ā/ BO}+ B@7cܚW"}o$ٱP`;_"M 5@EvhIVT&+iJd:ti9Oyb +vXDS/=h31&D' @ǵCꐐUtp윊!KB.>IlJAFpD'd|5|,]mF)H%t`p_f?.ok52()Mi}Y纵|MTg57;,HykGO:>Qq#g^(-&&,COCG 4bcti2B[)sAc,k'~KUk{8N Rd2R(``e`"[`뜵*ȧ?Uw=ӗܚe Ɋ hŧqQf\?ԙW^Sbcy]G~*#lNaoœ'q^)$`%ubl%D¾r6&8g DIu#1vi G 7tFQq$~[jc`11g/'xl[X`lh[[}.lCDgC#7M7!\G =7i5D_dS"ֵxoklȄ$#,'1FPBfVumQ珂"_ 1jgEͺbq(z0uBCI'r=Q(cKQ成LȫdR eFb!Oe*2vPά'c"QJr 9HBoy$x!Q sZnQ:.lqzR%Qq ^:"HvvVD'i#qetX6) 35 ~;tZg) 鎷Ԣ5EtCdY.6g;skȢa!>y(_s>.5L\o> hy2yYb?s͡@y;)rxVJ4c vo~$*_Ïth|Ti뇉1ax"" Vk?nIn Z#N>,yD&Q3DXBZ7?%Y㎜kJL.H:!1"+ ZH,d'Ag6v2Eb>#'H1aRZAbfFy>X] RkX-%-VcmJ}hۚm/k@%r$vYڽ+$آp6Yc:HH뎚"5oi:=Q_6ZmK"{%Dgyٰ"`P]d;o,"{MH䃰\σYK/pa6s&z q1̮҈~{1r%m彼Ґ>2nu;إCN\~?ߴx]J8?Fr[4)RddhrjʽˑR:& X `HNDߔrԈM7,X ȼҬL4@IϿH*7X- 2MZ:3jb%y6%㶵ˑzAp}wխN䏻p1ncG_xtB\9Ж҇ ڐH{@G%5Z{-$2la׀O׊>X{W^Ag}:iT:sKLXUUq1i5]̼Eŕ))zkj{S}/E_Yc/#>TChiJFS2˶a< oY2t֐gia _lF~tݷ_ֶ+kVt4/9"4{|A/n&(pp﷠a~{1"ɽIμR^bfs]H>.~S YZ