container-test-run-certificates
default.checks.aarch64-linux.certificates
· build #239
· raw
1additionally exposed symbols:2 ca, client, server,3 start_all, machines, driver, Machine, wait_for_signal4Starting ca5Starting client6Starting server7891011<<< NixOS Stage 2 >>>1213booting system configuration /nix/store/33fnn37471nq9vvixpvp5pcz8i7iis01-nixos-system-ca-test14running activation script...15setting up /etc...162: host0@if4: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 100017 link/ether 42:06:76:42:a9:8d brd ff:ff:ff:ff:ff:ff link-netnsid 018setting up age secrets...19starting systemd...20systemd 260.2 running in system mode (+PAM +AUDIT -SELINUX +APPARMOR +IMA +IPE +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE)21Detected virtualization systemd-nspawn.22Detected architecture arm64.23Detected first boot.24Initializing machine ID from container UUID.25Applying preset policy.26Populated /etc with preset unit settings.27Queued start job for default target Multi-User System.28293031<<< Welcome to NixOS test (aarch64) - console >>>32+ systemd-run /bin/sh -c '/nix/store/fz6id67gqf07rkbpmab99wmxspx2f9j5-coreutils-9.11/bin/sleep 999999999 && echo 816fcabb-0ae4-4ddc-87cf-7b4c5519c5ec'33Running as unit: run-p389-i77177045.service; invocation ID: 8cbaa32b9ff74c91b4925715b6d3f6c734To attach to container ca run on the same machine that runs the test:35 sudo nsenter --user --target $(\pgrep -f '^/bin/sh.*816fcabb-0ae4-4ddc-87cf-7b4c5519c5ec') --mount --uts --ipc --net --pid --cgroup /bin/sh -c bash 3637To inject external network and continue test, run:38sudo /nix/store/db760w7nmr0a45hlfq8392a474f403aa-python3-3.13.14/bin/python3.13 /nix/store/x6z7fjvvivdicryh72s3czbafhpl69hc-test-driver-0.0.1/lib/python3.13/site-packages/test_driver/inject_network.py 816fcabb-0ae4-4ddc-87cf-7b4c5519c5ec3940<<< NixOS Stage 2 >>>4142booting system configuration /nix/store/cj6gdjz6sa9542b61h82cs0y81v1lf49-nixos-system-client-test43running activation script...44setting up /etc...452: host0@if5: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 100046 link/ether 2a:42:35:28:b1:2f brd ff:ff:ff:ff:ff:ff link-netnsid 047setting up age secrets...48starting systemd...49systemd 260.2 running in system mode (+PAM +AUDIT -SELINUX +APPARMOR +IMA +IPE +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE)50Detected virtualization systemd-nspawn.51Detected architecture arm64.52Detected first boot.53Initializing machine ID from container UUID.54Applying preset policy.55Populated /etc with preset unit settings.56Queued start job for default target Multi-User System.57585960<<< Welcome to NixOS test (aarch64) - console >>>61+ systemd-run /bin/sh -c '/nix/store/fz6id67gqf07rkbpmab99wmxspx2f9j5-coreutils-9.11/bin/sleep 999999999 && echo 31a4332a-d573-4077-bcc1-484d66e030cd'62Running as unit: run-p304-i77177058.service; invocation ID: 7856528ad2554c4bbe808332e5df4d9863To attach to container client run on the same machine that runs the test:64 sudo nsenter --user --target $(\pgrep -f '^/bin/sh.*31a4332a-d573-4077-bcc1-484d66e030cd') --mount --uts --ipc --net --pid --cgroup /bin/sh -c bash 6566To inject external network and continue test, run:67sudo /nix/store/db760w7nmr0a45hlfq8392a474f403aa-python3-3.13.14/bin/python3.13 /nix/store/x6z7fjvvivdicryh72s3czbafhpl69hc-test-driver-0.0.1/lib/python3.13/site-packages/test_driver/inject_network.py 31a4332a-d573-4077-bcc1-484d66e030cd6869<<< NixOS Stage 2 >>>7071booting system configuration /nix/store/z3m25cmmb2mwnwd2klrz00j8swl80qsv-nixos-system-server-test72running activation script...73setting up /etc...742: host0@if3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 100075 link/ether be:aa:dd:39:86:e7 brd ff:ff:ff:ff:ff:ff link-netnsid 076setting up age secrets...77starting systemd...78systemd 260.2 running in system mode (+PAM +AUDIT -SELINUX +APPARMOR +IMA +IPE +SMACK +SECCOMP +GCRYPT -GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK -BTF -XKBCOMMON +UTMP +LIBARCHIVE)79Detected virtualization systemd-nspawn.80Detected architecture arm64.81Detected first boot.82Initializing machine ID from container UUID.83Applying preset policy.84Populated /etc with preset unit settings.85Queued start job for default target Multi-User System.86878889<<< Welcome to NixOS test (aarch64) - console >>>90+ systemd-run /bin/sh -c '/nix/store/fz6id67gqf07rkbpmab99wmxspx2f9j5-coreutils-9.11/bin/sleep 999999999 && echo be629edd-c347-479a-8ac6-4ffe0b38a254'91Running as unit: run-p352-i77177134.service; invocation ID: ee2b19a008b04462a5efee53faa5891792To attach to container server run on the same machine that runs the test:93 sudo nsenter --user --target $(\pgrep -f '^/bin/sh.*be629edd-c347-479a-8ac6-4ffe0b38a254') --mount --uts --ipc --net --pid --cgroup /bin/sh -c bash 9495To inject external network and continue test, run:96sudo /nix/store/db760w7nmr0a45hlfq8392a474f403aa-python3-3.13.14/bin/python3.13 /nix/store/x6z7fjvvivdicryh72s3czbafhpl69hc-test-driver-0.0.1/lib/python3.13/site-packages/test_driver/inject_network.py be629edd-c347-479a-8ac6-4ffe0b38a25497+ systemctl restart acme-order-renew-ca.foo.service98+ systemctl restart acme-test.foo.service99client: waiting for success: curl -v https://test.foo100+ curl -v https://test.foo101* Host test.foo:443 was resolved.102* IPv6: (none)103* IPv4: 192.168.1.3104* Trying 192.168.1.3:443...105* ALPN: curl offers h2,http/1.1106} [5 bytes data]107* TLSv1.3 (OUT), TLS handshake, Client hello (1):108} [1552 bytes data]109* SSL Trust Anchors:110* OpenSSL default paths (fallback)111{ [5 bytes data]112* TLSv1.3 (IN), TLS handshake, Server hello (2):113{ [1210 bytes data]114* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):115{ [1 bytes data]116* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):117{ [19 bytes data]118* TLSv1.3 (IN), TLS handshake, Certificate (11):119{ [1011 bytes data]120* TLSv1.3 (IN), TLS handshake, CERT verify (15):121{ [111 bytes data]122* TLSv1.3 (IN), TLS handshake, Finished (20):123{ [52 bytes data]124* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):125} [1 bytes data]126* TLSv1.3 (OUT), TLS handshake, Finished (20):127} [52 bytes data]128* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey129* ALPN: server accepted h2130* Server certificate:131* subject: CN=test.foo132* start date: Aug 5 19:12:42 2026 GMT133* expire date: Sep 4 19:12:42 2028 GMT134* issuer: CN=minica root ca 17c5ad135* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384136* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384137* subjectAltName: "test.foo" matches cert's "test.foo"138* OpenSSL verify result: 13139* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)140* closing connection #0141curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)142More details here: https://curl.se/docs/sslcerts.html143144curl failed to verify the legitimacy of the server and therefore could not145establish a secure connection to it. To learn more about this situation and146how to fix it, please visit the webpage mentioned above.147+ curl -v https://test.foo148* Host test.foo:443 was resolved.149* IPv6: (none)150* IPv4: 192.168.1.3151* Trying 192.168.1.3:443...152* ALPN: curl offers h2,http/1.1153} [5 bytes data]154* TLSv1.3 (OUT), TLS handshake, Client hello (1):155} [1552 bytes data]156* SSL Trust Anchors:157* OpenSSL default paths (fallback)158{ [5 bytes data]159* TLSv1.3 (IN), TLS handshake, Server hello (2):160{ [1210 bytes data]161* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):162{ [1 bytes data]163* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):164{ [19 bytes data]165* TLSv1.3 (IN), TLS handshake, Certificate (11):166{ [1011 bytes data]167* TLSv1.3 (IN), TLS handshake, CERT verify (15):168{ [110 bytes data]169* TLSv1.3 (IN), TLS handshake, Finished (20):170{ [52 bytes data]171* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):172} [1 bytes data]173* TLSv1.3 (OUT), TLS handshake, Finished (20):174} [52 bytes data]175* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey176* ALPN: server accepted h2177* Server certificate:178* subject: CN=test.foo179* start date: Aug 5 19:12:42 2026 GMT180* expire date: Sep 4 19:12:42 2028 GMT181* issuer: CN=minica root ca 17c5ad182* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384183* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384184* subjectAltName: "test.foo" matches cert's "test.foo"185* OpenSSL verify result: 13186* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)187* closing connection #0188curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)189More details here: https://curl.se/docs/sslcerts.html190191curl failed to verify the legitimacy of the server and therefore could not192establish a secure connection to it. To learn more about this situation and193how to fix it, please visit the webpage mentioned above.194+ curl -v https://test.foo195* Host test.foo:443 was resolved.196* IPv6: (none)197* IPv4: 192.168.1.3198* Trying 192.168.1.3:443...199* ALPN: curl offers h2,http/1.1200} [5 bytes data]201* TLSv1.3 (OUT), TLS handshake, Client hello (1):202} [1552 bytes data]203* SSL Trust Anchors:204* OpenSSL default paths (fallback)205{ [5 bytes data]206* TLSv1.3 (IN), TLS handshake, Server hello (2):207{ [1210 bytes data]208* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):209{ [1 bytes data]210* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):211{ [19 bytes data]212* TLSv1.3 (IN), TLS handshake, Certificate (11):213{ [1011 bytes data]214* TLSv1.3 (IN), TLS handshake, CERT verify (15):215{ [112 bytes data]216* TLSv1.3 (IN), TLS handshake, Finished (20):217{ [52 bytes data]218* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):219} [1 bytes data]220* TLSv1.3 (OUT), TLS handshake, Finished (20):221} [52 bytes data]222* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey223* ALPN: server accepted h2224* Server certificate:225* subject: CN=test.foo226* start date: Aug 5 19:12:42 2026 GMT227* expire date: Sep 4 19:12:42 2028 GMT228* issuer: CN=minica root ca 17c5ad229* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384230* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384231* subjectAltName: "test.foo" matches cert's "test.foo"232* OpenSSL verify result: 13233* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)234* closing connection #0235curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)236More details here: https://curl.se/docs/sslcerts.html237238curl failed to verify the legitimacy of the server and therefore could not239establish a secure connection to it. To learn more about this situation and240how to fix it, please visit the webpage mentioned above.241+ curl -v https://test.foo242* Host test.foo:443 was resolved.243* IPv6: (none)244* IPv4: 192.168.1.3245* Trying 192.168.1.3:443...246* ALPN: curl offers h2,http/1.1247} [5 bytes data]248* TLSv1.3 (OUT), TLS handshake, Client hello (1):249} [1552 bytes data]250* SSL Trust Anchors:251* OpenSSL default paths (fallback)252{ [5 bytes data]253* TLSv1.3 (IN), TLS handshake, Server hello (2):254{ [1210 bytes data]255* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):256{ [1 bytes data]257* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):258{ [19 bytes data]259* TLSv1.3 (IN), TLS handshake, Certificate (11):260{ [1011 bytes data]261* TLSv1.3 (IN), TLS handshake, CERT verify (15):262{ [111 bytes data]263* TLSv1.3 (IN), TLS handshake, Finished (20):264{ [52 bytes data]265* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):266} [1 bytes data]267* TLSv1.3 (OUT), TLS handshake, Finished (20):268} [52 bytes data]269* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey270* ALPN: server accepted h2271* Server certificate:272* subject: CN=test.foo273* start date: Aug 5 19:12:42 2026 GMT274* expire date: Sep 4 19:12:42 2028 GMT275* issuer: CN=minica root ca 17c5ad276* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384277* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384278* subjectAltName: "test.foo" matches cert's "test.foo"279* OpenSSL verify result: 13280* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)281* closing connection #0282curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)283More details here: https://curl.se/docs/sslcerts.html284285curl failed to verify the legitimacy of the server and therefore could not286establish a secure connection to it. To learn more about this situation and287how to fix it, please visit the webpage mentioned above.288+ curl -v https://test.foo289* Host test.foo:443 was resolved.290* IPv6: (none)291* IPv4: 192.168.1.3292* Trying 192.168.1.3:443...293* ALPN: curl offers h2,http/1.1294} [5 bytes data]295* TLSv1.3 (OUT), TLS handshake, Client hello (1):296} [1552 bytes data]297* SSL Trust Anchors:298* OpenSSL default paths (fallback)299{ [5 bytes data]300* TLSv1.3 (IN), TLS handshake, Server hello (2):301{ [1210 bytes data]302* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):303{ [1 bytes data]304* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):305{ [19 bytes data]306* TLSv1.3 (IN), TLS handshake, Certificate (11):307{ [1011 bytes data]308* TLSv1.3 (IN), TLS handshake, CERT verify (15):309{ [111 bytes data]310* TLSv1.3 (IN), TLS handshake, Finished (20):311{ [52 bytes data]312* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):313} [1 bytes data]314* TLSv1.3 (OUT), TLS handshake, Finished (20):315} [52 bytes data]316* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey317* ALPN: server accepted h2318* Server certificate:319* subject: CN=test.foo320* start date: Aug 5 19:12:42 2026 GMT321* expire date: Sep 4 19:12:42 2028 GMT322* issuer: CN=minica root ca 17c5ad323* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384324* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384325* subjectAltName: "test.foo" matches cert's "test.foo"326* OpenSSL verify result: 13327* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)328* closing connection #0329curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)330More details here: https://curl.se/docs/sslcerts.html331332curl failed to verify the legitimacy of the server and therefore could not333establish a secure connection to it. To learn more about this situation and334how to fix it, please visit the webpage mentioned above.335+ curl -v https://test.foo336* Host test.foo:443 was resolved.337* IPv6: (none)338* IPv4: 192.168.1.3339* Trying 192.168.1.3:443...340* ALPN: curl offers h2,http/1.1341} [5 bytes data]342* TLSv1.3 (OUT), TLS handshake, Client hello (1):343} [1552 bytes data]344* SSL Trust Anchors:345* OpenSSL default paths (fallback)346{ [5 bytes data]347* TLSv1.3 (IN), TLS handshake, Server hello (2):348{ [1210 bytes data]349* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):350{ [1 bytes data]351* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):352{ [19 bytes data]353* TLSv1.3 (IN), TLS handshake, Certificate (11):354{ [929 bytes data]355* TLSv1.3 (IN), TLS handshake, CERT verify (15):356{ [80 bytes data]357* TLSv1.3 (IN), TLS handshake, Finished (20):358{ [52 bytes data]359* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):360} [1 bytes data]361* TLSv1.3 (OUT), TLS handshake, Finished (20):362} [52 bytes data]363* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey364* ALPN: server accepted h2365* Server certificate:366* subject: CN=test.foo367* start date: Aug 5 19:11:53 2026 GMT368* expire date: Nov 3 19:12:53 2026 GMT369* issuer: CN=Clan Intermediate CA370* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256371* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256372* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256373* subjectAltName: "test.foo" matches cert's "test.foo"374* OpenSSL verify result: 0375* SSL certificate verified via OpenSSL.376* Established connection to test.foo (192.168.1.3 port 443) from 192.168.1.2 port 46162 377 % Total % Received % Xferd Average Speed Time Time Time Current378 Dload Upload Total Spent Left Speed379 0 0 0 0 0 0 0 0 0* using HTTP/2380* [HTTP/2] [1] OPENED stream for https://test.foo/381* [HTTP/2] [1] [:method: GET]382* [HTTP/2] [1] [:scheme: https]383* [HTTP/2] [1] [:authority: test.foo]384* [HTTP/2] [1] [:path: /]385* [HTTP/2] [1] [user-agent: curl/8.21.0]386* [HTTP/2] [1] [accept: */*]387} [5 bytes data]388389390391392393* Request completely sent off394{ [5 bytes data]395* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):396{ [265 bytes data]397* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):398{ [265 bytes data]399400401402403404405406{ [5 bytes data]407100 20 100 20 0 0 592 0 0408* Connection #0 to host test.foo:443 left intact409(finished: waiting for success: curl -v https://test.foo, in 5.27 seconds)410+ openssl s_client -connect test.foo:443 -servername test.foo411+ openssl x509 -text -noout412Certificate:413 Data:414 Version: 3 (0x2)415 Serial Number:416 09:13:85:3e:59:3b:68:47:46:b7:21:0e:6b:19:ab:41417 Signature Algorithm: ecdsa-with-SHA256418 Issuer: CN=Clan Intermediate CA419 Validity420 Not Before: Aug 5 19:11:53 2026 GMT421 Not After : Nov 3 19:12:53 2026 GMT422 Subject: CN=test.foo423 Subject Public Key Info:424 Public Key Algorithm: id-ecPublicKey425 Public-Key: (256 bit)426 pub:427 04:97:bb:7b:e3:0d:5f:3a:81:3e:49:cc:60:07:cb:428 60:ec:f2:97:cf:e4:0d:63:b3:8b:b3:98:bf:60:85:429 d9:75:a3:af:b4:48:be:1c:b0:30:3c:c4:32:89:92:430 10:3f:d6:11:c0:12:be:a2:8e:29:0e:44:b3:74:ee:431 01:4c:9e:2a:04432 ASN1 OID: prime256v1433 NIST CURVE: P-256434 X509v3 extensions:435 X509v3 Key Usage: critical436 Digital Signature437 X509v3 Extended Key Usage: 438 TLS Web Server Authentication, TLS Web Client Authentication439 X509v3 Subject Key Identifier: 440 46:8C:9F:AA:2D:83:7B:B9:58:0E:53:96:02:D5:1C:B6:EF:85:58:24441 X509v3 Authority Key Identifier: 442 51:29:1D:72:4F:C8:65:50:1B:28:A6:F2:02:2D:AD:8C:E7:97:3D:9E443 X509v3 Subject Alternative Name: 444 DNS:test.foo445 1.3.6.1.4.1.37476.9000.64.1: 446 0......acme..447 Signature Algorithm: ecdsa-with-SHA256448 Signature Value:449 30:45:02:20:1b:81:86:97:84:53:19:de:82:19:5a:99:02:a5:450 f3:51:d9:14:24:98:b7:c8:db:12:99:4c:52:8b:6e:56:fd:17:451 02:21:00:b3:e5:c4:01:7b:c1:8e:cb:0a:6b:3c:89:4e:b9:c4:452 c0:a0:48:22:23:88:68:49:c4:59:90:57:88:f0:29:fb:be453454455