nixbot

builds

succeeded container-test-run-certificates default.checks.aarch64-linux.certificates · build #347 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13server: systemd-nspawn running (pid 54)14client: systemd-nspawn running (pid 55)15server: Waiting for journal at /build/vm-state-server/var/log/journal...16ca: Waiting for journal at /build/vm-state-ca/var/log/journal...17client: Waiting for journal at /build/vm-state-client/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container ca on /build/vm-state-ca.29░ Spawning container server on /build/vm-state-server.30░ Spawning container client on /build/vm-state-client.31client # [5661899.356145] client systemd-journald[69]: Journal started32client # [5661899.356207] client systemd-journald[69]: Runtime Journal (/run/log/journal/92b9f63f2c124e90947be02dd2e891c4) is 8M, max 2.5G, 2.4G free.33client # [5661899.362162] client systemd[1]: Starting Flush Journal to Persistent Storage...34client # [5661899.363040] client systemd[1]: Starting Network Name Resolution...35client # [5661899.363877] client systemd[1]: Starting Create Static Device Nodes in /dev...36client # [5661899.373076] client systemd-journald[69]: Time spent on flushing to /var/log/journal/92b9f63f2c124e90947be02dd2e891c4 is 1.810ms for 5 entries.37client # [5661899.373076] client systemd-journald[69]: System Journal (/var/log/journal/92b9f63f2c124e90947be02dd2e891c4) is 8M, max 4G, 3.9G free.38client # [5661899.384178] client systemd[1]: Finished Create Static Device Nodes in /dev.39client # [5661899.384392] client systemd[1]: Finished Flush Journal to Persistent Storage.40client # [5661899.384993] client systemd[1]: Reached target Preparation for Local File Systems.41client # [5661899.385112] client systemd[1]: Reached target Local File Systems.42client # [5661899.385948] client systemd[1]: Listening on Boot Loader Control Service Socket.43client # [5661899.385992] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container44client # [5661899.386889] client systemd[1]: Starting Save Transient machine-id to Disk...45client # [5661899.387624] client systemd[1]: Starting Create System Files and Directories...46client # [5661899.387658] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys47client # [5661899.405823] client systemd-tmpfiles[109]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted48client # [5661899.406047] client systemd-tmpfiles[109]: fchmod() of /var/log/journal failed: Operation not permitted49client # [5661899.406212] client systemd-tmpfiles[109]: fchmod() of /var/log/journal/92b9f63f2c124e90947be02dd2e891c4 failed: Operation not permitted50client # [5661899.406460] client systemd-tmpfiles[109]: fchmod() of /run/log/journal failed: Operation not permitted51client # [5661899.407857] client systemd[1]: Finished Create System Files and Directories.52client # [5661899.408935] client systemd[1]: Starting Rebuild Journal Catalog...53client # [5661899.409667] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...54client # [5661899.420446] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.55client # [5661899.426761] client systemd[1]: Finished Save Transient machine-id to Disk.56ca # [5661899.355550] ca systemd-journald[78]: Journal started57ca # [5661899.355608] ca systemd-journald[78]: Runtime Journal (/run/log/journal/9f3cd941fe8b427a834b1a4ca0c0e80c) is 8M, max 2.5G, 2.4G free.58ca # [5661899.356756] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.59ca # [5661899.365820] ca systemd[1]: Starting Flush Journal to Persistent Storage...60ca # [5661899.366832] ca systemd[1]: Starting Network Name Resolution...61ca # [5661899.367545] ca systemd[1]: Starting Create Static Device Nodes in /dev...62ca # [5661899.376150] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/9f3cd941fe8b427a834b1a4ca0c0e80c is 1.604ms for 6 entries.63ca # [5661899.376150] ca systemd-journald[78]: System Journal (/var/log/journal/9f3cd941fe8b427a834b1a4ca0c0e80c) is 8M, max 4G, 3.9G free.64ca # [5661899.387647] ca systemd[1]: Finished Create Static Device Nodes in /dev.65ca # [5661899.388367] ca systemd[1]: Reached target Preparation for Local File Systems.66ca # [5661899.388539] ca systemd[1]: Reached target Local File Systems.67ca # [5661899.389335] ca systemd[1]: Listening on Boot Loader Control Service Socket.68ca # [5661899.389380] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container69ca # [5661899.390307] ca systemd[1]: Starting Save Transient machine-id to Disk...70ca # [5661899.390345] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys71server # [5661899.366424] server systemd-journald[69]: Journal started72ca # [5661899.390795] ca systemd[1]: Finished Flush Journal to Persistent Storage.73server # [5661899.366502] server systemd-journald[69]: Runtime Journal (/run/log/journal/6ab6e496bd8143958a460371ed3463ac) is 8M, max 2.5G, 2.4G free.74server # [5661899.370381] server systemd[1]: Starting Flush Journal to Persistent Storage...75server # [5661899.371157] server systemd[1]: Starting Network Name Resolution...76server # [5661899.372065] server systemd[1]: Starting Create Static Device Nodes in /dev...77ca # [5661899.392182] ca systemd[1]: Starting Create System Files and Directories...78server # [5661899.384293] server systemd-journald[69]: Time spent on flushing to /var/log/journal/6ab6e496bd8143958a460371ed3463ac is 1.336ms for 5 entries.79ca # [5661899.412385] ca systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted80server # [5661899.384293] server systemd-journald[69]: System Journal (/var/log/journal/6ab6e496bd8143958a460371ed3463ac) is 8M, max 4G, 3.9G free.81server # [5661899.388599] server systemd[1]: Finished Create Static Device Nodes in /dev.82ca # [5661899.412611] ca systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted83server # [5661899.389276] server systemd[1]: Reached target Preparation for Local File Systems.84ca # [5661899.412769] ca systemd-tmpfiles[120]: fchmod() of /var/log/journal/9f3cd941fe8b427a834b1a4ca0c0e80c failed: Operation not permitted85server # [5661899.389400] server systemd[1]: Reached target Local File Systems.86ca # [5661899.413010] ca systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted87server # [5661899.390243] server systemd[1]: Listening on Boot Loader Control Service Socket.88ca # [5661899.414462] ca systemd[1]: Finished Create System Files and Directories.89server # [5661899.390293] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container90ca # [5661899.415508] ca systemd[1]: Starting Rebuild Journal Catalog...91server # [5661899.391099] server systemd[1]: Starting Save Transient machine-id to Disk...92ca # [5661899.416201] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...93server # [5661899.391136] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys94ca # [5661899.426780] ca systemd[1]: Finished Save Transient machine-id to Disk.95server # [5661899.398957] server systemd[1]: Finished Flush Journal to Persistent Storage.96server # [5661899.400329] server systemd[1]: Starting Create System Files and Directories...97server # [5661899.419419] server systemd-tmpfiles[113]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted98server # [5661899.419971] server systemd-tmpfiles[113]: fchmod() of /var/log/journal failed: Operation not permitted99server # [5661899.420148] server systemd-tmpfiles[113]: fchmod() of /var/log/journal/6ab6e496bd8143958a460371ed3463ac failed: Operation not permitted100server # [5661899.420353] server systemd-tmpfiles[113]: fchmod() of /run/log/journal failed: Operation not permitted101server # [5661899.422790] server systemd[1]: Finished Create System Files and Directories.102server # [5661899.424190] server systemd[1]: Starting Rebuild Journal Catalog...103server # [5661899.424943] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...104server # [5661899.428142] server systemd[1]: Finished Save Transient machine-id to Disk.105client # [5661899.432322] client systemd[1]: Finished Rebuild Journal Catalog.106client # [5661899.433316] client systemd[1]: Starting Update is Completed...107client # [5661899.445063] client systemd[1]: Finished Update is Completed.108client # [5661899.510364] client systemd[1]: Finished Firewall.109client # [5661899.510452] client systemd[1]: Reached target Preparation for Network.110client # [5661899.510669] client systemd[1]: Listening on Network Management Resolve Hook Socket.111client # [5661899.511705] client systemd[1]: Starting Network Management...112ca # [5661899.430783] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.113ca # [5661899.439439] ca systemd[1]: Finished Rebuild Journal Catalog.114ca # [5661899.440444] ca systemd[1]: Starting Update is Completed...115ca # [5661899.450583] ca systemd[1]: Finished Update is Completed.116ca # [5661899.516303] ca systemd[1]: Finished Firewall.117ca # [5661899.516848] ca systemd[1]: Reached target Preparation for Network.118ca # [5661899.517126] ca systemd[1]: Listening on Network Management Resolve Hook Socket.119ca # [5661899.518210] ca systemd[1]: Starting Network Management...120server # [5661899.438368] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.121server # [5661899.464695] server systemd[1]: Finished Rebuild Journal Catalog.122server # [5661899.466505] server systemd[1]: Starting Update is Completed...123server # [5661899.476316] server systemd[1]: Finished Update is Completed.124server # [5661899.524347] server systemd[1]: Finished Firewall.125server # [5661899.524494] server systemd[1]: Reached target Preparation for Network.126server # [5661899.524742] server systemd[1]: Listening on Network Management Resolve Hook Socket.127server # [5661899.525707] server systemd[1]: Starting Network Management...128server # [5661899.898081] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted129server # [5661899.898162] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted130server # [5661899.904749] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.131server # [5661899.904906] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.132server # [5661899.905039] server systemd-networkd[187]: lo: Link UP133server # [5661899.905043] server systemd-networkd[187]: lo: Gained carrier134server # [5661899.905222] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network.135server # [5661899.905630] server systemd[1]: Started Network Management.136server # [5661899.932258] server systemd-networkd[187]: eth1: Link UP137server # [5661899.932578] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...138server # [5661899.932628] server systemd-networkd[187]: eth1: Gained carrier139server # [5661900.001451] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.140server # [5661900.020296] server systemd-resolved[91]: Positive Trust Anchors:141server # [5661900.020306] server systemd-resolved[91]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d142server # [5661900.020310] server systemd-resolved[91]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16143server # [5661900.020344] server systemd-resolved[91]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test144server # [5661900.042125] server systemd-resolved[91]: Using system hostname 'server'.145server # [5661900.043508] server systemd[1]: Started Network Name Resolution.146server # [5661900.043642] server systemd[1]: Reached target Network.147server # [5661900.043742] server systemd[1]: Reached target Network is Online.148server # [5661900.043826] server systemd[1]: Reached target System Initialization.149server # [5661900.044264] server systemd[1]: Started Renew ACME Certificate for test.foo.150server # [5661900.044326] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container151server # [5661900.044373] server systemd[1]: Started Daily Cleanup of Temporary Directories.152server # [5661900.044414] server systemd[1]: Reached target Timer Units.153server # [5661900.044653] server systemd[1]: Listening on D-Bus System Message Bus Socket.154server # [5661900.044845] server systemd[1]: Listening on Nix Daemon Socket.155server # [5661900.045056] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.156server # [5661900.045105] server systemd[1]: Reached target Socket Units.157server # [5661900.045181] server systemd[1]: Reached target Basic System.158server # [5661900.047312] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...159server # [5661900.048743] server systemd[1]: Starting Import lastlog data into lastlog2 database...160server # [5661900.048810] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem161server # [5661900.050350] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...162server # [5661900.052603] server systemd[1]: Starting D-Bus System Message Bus...163server # [5661900.098437] server systemd[1]: Finished Import lastlog data into lastlog2 database.164server # [5661900.189421] server acme-setup-privileged[192]: + set -euo pipefail165server # [5661900.189421] server acme-setup-privileged[192]: + cd /var/lib/acme166server # [5661900.189421] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts167ca # [5661899.906971] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted168ca # [5661899.907053] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted169ca # [5661899.913733] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.170ca # [5661899.913893] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.171ca # [5661899.914030] ca systemd-networkd[196]: lo: Link UP172ca # [5661899.914035] ca systemd-networkd[196]: lo: Gained carrier173ca # [5661899.914190] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network.174ca # [5661899.914562] ca systemd[1]: Started Network Management.175ca # [5661899.932557] ca systemd-networkd[196]: eth1: Link UP176ca # [5661899.932906] ca systemd-networkd[196]: eth1: Gained carrier177ca # [5661899.932958] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...178ca # [5661900.006373] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.179ca # [5661900.022159] ca systemd-resolved[101]: Positive Trust Anchors:180ca # [5661900.022169] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d181ca # [5661900.022172] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16182ca # [5661900.022208] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test183ca # [5661900.043604] ca systemd-resolved[101]: Using system hostname 'ca'.184ca # [5661900.045359] ca systemd[1]: Started Network Name Resolution.185ca # [5661900.045486] ca systemd[1]: Reached target Network.186ca # [5661900.045594] ca systemd[1]: Reached target Network is Online.187ca # [5661900.045682] ca systemd[1]: Reached target System Initialization.188ca # [5661900.046036] ca systemd[1]: Started Renew ACME Certificate for ca.foo.189ca # [5661900.046105] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container190ca # [5661900.046153] ca systemd[1]: Started Daily Cleanup of Temporary Directories.191ca # [5661900.046188] ca systemd[1]: Reached target Timer Units.192ca # [5661900.046408] ca systemd[1]: Listening on D-Bus System Message Bus Socket.193ca # [5661900.046775] ca systemd[1]: Listening on Nix Daemon Socket.194ca # [5661900.047011] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.195ca # [5661900.047063] ca systemd[1]: Reached target Socket Units.196ca # [5661900.047151] ca systemd[1]: Reached target Basic System.197ca # [5661900.049290] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...198ca # [5661900.050664] ca systemd[1]: Starting Import lastlog data into lastlog2 database...199ca # [5661900.050733] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem200ca # [5661900.052142] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...201ca # [5661900.080681] ca systemd[1]: Starting step-ca service...202ca # [5661900.083167] ca systemd[1]: Starting D-Bus System Message Bus...203ca # [5661900.099635] ca systemd[1]: Finished Import lastlog data into lastlog2 database.204ca # [5661900.204881] ca acme-setup-privileged[201]: + set -euo pipefail205ca # [5661900.204881] ca acme-setup-privileged[201]: + cd /var/lib/acme206ca # [5661900.204881] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts207client # [5661899.891751] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted208client # [5661899.891840] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted209client # [5661899.898583] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.210client # [5661899.898746] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.211client # [5661899.898890] client systemd-networkd[183]: lo: Link UP212client # [5661899.898893] client systemd-networkd[183]: lo: Gained carrier213client # [5661899.899060] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network.214client # [5661899.899427] client systemd[1]: Started Network Management.215client # [5661899.899500] client systemd-networkd[183]: eth1: Link UP216client # [5661899.899792] client systemd-networkd[183]: eth1: Gained carrier217client # [5661899.900571] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...218client # [5661899.941491] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.219client # [5661900.034134] client systemd-resolved[90]: Positive Trust Anchors:220client # [5661900.034146] client systemd-resolved[90]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d221client # [5661900.034149] client systemd-resolved[90]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16222client # [5661900.034185] client systemd-resolved[90]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test223client # [5661900.056136] client systemd-resolved[90]: Using system hostname 'client'.224client # [5661900.057476] client systemd[1]: Started Network Name Resolution.225client # [5661900.057603] client systemd[1]: Reached target Network.226client # [5661900.057718] client systemd[1]: Reached target System Initialization.227client # [5661900.057813] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container228client # [5661900.057873] client systemd[1]: Started Daily Cleanup of Temporary Directories.229client # [5661900.057911] client systemd[1]: Reached target Timer Units.230client # [5661900.058133] client systemd[1]: Listening on D-Bus System Message Bus Socket.231client # [5661900.058343] client systemd[1]: Listening on Nix Daemon Socket.232client # [5661900.058558] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.233client # [5661900.058604] client systemd[1]: Reached target Socket Units.234client # [5661900.058678] client systemd[1]: Reached target Basic System.235client # [5661900.080901] client systemd[1]: Starting Import lastlog data into lastlog2 database...236client # [5661900.082885] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...237client # [5661900.085031] client systemd[1]: Starting D-Bus System Message Bus...238client # [5661900.103812] client systemd[1]: Finished Import lastlog data into lastlog2 database.239client # [5661900.218380] client nsncd[189]: Aug 13 12:08:46.271 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"240client # [5661900.218414] client systemd[1]: Started Name Service Cache Daemon (nsncd).241client # [5661900.218499] client systemd[1]: Reached target Host and Network Name Lookups.242client # [5661900.218593] client systemd[1]: Reached target User and Group Name Lookups.243ca # [5661900.206668] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts244ca # [5661900.208294] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo245ca # [5661900.208294] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'246ca # [5661900.208409] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo247ca # [5661900.208409] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'248ca # [5661900.235748] ca nsncd[203]: Aug 13 12:08:46.288 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"249ca # [5661900.236703] ca systemd[1]: Started Name Service Cache Daemon (nsncd).250ca # [5661900.236930] ca systemd[1]: Reached target Host and Network Name Lookups.251ca # [5661900.237139] ca systemd[1]: Reached target User and Group Name Lookups.252ca # [5661900.239051] ca systemd[1]: Starting User Login Management...253ca # [5661900.240353] ca systemd[1]: Starting Permit User Sessions...254ca # [5661900.250866] ca systemd[1]: Finished Permit User Sessions.255ca # [5661900.252445] ca systemd[1]: Started Console Getty.256ca # [5661900.252525] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0257ca # [5661900.252567] ca systemd[1]: Reached target Login Prompts.258ca # [5661900.319810] ca dbus-broker-launch[209]: Looking up NSS user entry for 'systemd-timesync'...259ca # [5661900.320588] ca dbus-broker-launch[209]: NSS returned no entry for 'systemd-timesync'260ca # [5661900.320588] ca dbus-broker-launch[209]: Invalid user-name in /nix/store/vd1mfhapbcl6nngw7x71n7cxgwkrw88b-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"261ca # [5661900.321119] ca systemd[1]: Started D-Bus System Message Bus.262ca # [5661900.330070] ca dbus-broker-launch[209]: Ready263ca # [5661900.349450] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.264server # [5661900.191155] server acme-setup-privileged[192]: + chown -R acme .lego/accounts265server # [5661900.192775] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo266server # [5661900.192775] server acme-setup-privileged[192]: + '[' -d test.foo ']'267server # [5661900.192886] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo268server # [5661900.192886] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'269server # [5661900.227125] server systemd[1]: Started Name Service Cache Daemon (nsncd).270server # [5661900.227236] server systemd[1]: Reached target Host and Network Name Lookups.271server # [5661900.227343] server systemd[1]: Reached target User and Group Name Lookups.272server # [5661900.227523] server nsncd[194]: Aug 13 12:08:46.280 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"273server # [5661900.237068] server systemd[1]: Starting User Login Management...274server # [5661900.237879] server systemd[1]: Starting Permit User Sessions...275server # [5661900.249432] server systemd[1]: Finished Permit User Sessions.276server # [5661900.251029] server systemd[1]: Started Console Getty.277server # [5661900.251089] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0278server # [5661900.251110] server systemd[1]: Reached target Login Prompts.279server # [5661900.337500] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...280server # [5661900.338704] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'281server # [5661900.338704] server dbus-broker-launch[195]: Invalid user-name in /nix/store/jv9ppm6bn4crwrlhr26v9g05j5n42z3q-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"282server # [5661900.339235] server systemd[1]: Started D-Bus System Message Bus.283server # [5661900.346201] server dbus-broker-launch[195]: Ready284server # [5661900.363666] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.285client # [5661900.237571] client systemd[1]: Starting User Login Management...286client # [5661900.238842] client systemd[1]: Starting Permit User Sessions...287client # [5661900.248802] client systemd[1]: Finished Permit User Sessions.288client # [5661900.250492] client systemd[1]: Started Console Getty.289client # [5661900.250567] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0290client # [5661900.250611] client systemd[1]: Reached target Login Prompts.291client # [5661900.319217] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...292client # [5661900.320595] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'293client # [5661900.320595] client dbus-broker-launch[190]: Invalid user-name in /nix/store/z18i8gax7zmfr2d22nqb67kfsfgm8wx8-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"294client # [5661900.321116] client systemd[1]: Started D-Bus System Message Bus.295client # [5661900.329752] client dbus-broker-launch[190]: Ready296client # [5661900.349692] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.297ca # [5661900.716357] ca systemd-logind[230]: New seat seat0.298ca # [5661900.716533] ca systemd[1]: Started User Login Management.299ca # [5661900.744823] ca systemd[1]: Starting linger-users.service...300ca # [5661900.758543] ca systemd[1]: linger-users.service: Deactivated successfully.301ca # [5661900.758633] ca systemd[1]: Finished linger-users.service.302ca # [5661900.775474] ca acme-setup-start[219]: + set -euo pipefail303ca # [5661900.775474] ca acme-setup-start[219]: + test -e ca/key.pem304ca # [5661900.776089] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local305ca # [5661900.797435] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.306ca # [5661900.799292] ca systemd[1]: Starting Ensure certificate for ca.foo...307ca # [5661900.887206] ca step-ca[204]: badger 2026/08/13 12:08:46 INFO: All 0 tables opened in 0s308ca # [5661900.891530] ca step-ca[204]: 2026/08/13 12:08:46 Building new tls configuration using step-ca x509 Signer Interface309ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 Starting Smallstep CA/0.30.2 (linux/arm64)310ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 Documentation: https://u.step.sm/docs/ca311ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 Community Discord: https://u.step.sm/discord312ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 Config file: /etc/smallstep/ca.json313ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 The primary server URL is https://ca.foo:1443314ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 Root certificates are available at https://ca.foo:1443/roots.pem315ca # [5661900.896907] ca step-ca[204]: 2026/08/13 12:08:46 X.509 Root Fingerprint: 23db61cf6c4c7ce8fdc3ba18fc7c7450d543937b459fb5324fa587e401287e34316ca # [5661900.897198] ca systemd[1]: Started step-ca service.317ca # [5661900.897321] ca step-ca[204]: 2026/08/13 12:08:46 Serving HTTPS on 0.0.0.0:1443 ...318server # [5661900.708648] server systemd-logind[220]: New seat seat0.319server # [5661900.708822] server systemd[1]: Started User Login Management.320server # [5661900.710824] server systemd[1]: Starting linger-users.service...321server # [5661900.754316] server systemd[1]: linger-users.service: Deactivated successfully.322server # [5661900.754531] server systemd[1]: Finished linger-users.service.323server # [5661900.787299] server acme-setup-start[208]: + set -euo pipefail324server # [5661900.787605] server acme-setup-start[208]: + test -e ca/key.pem325server # [5661900.787605] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local326server # [5661900.809107] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.327server # [5661900.810877] server systemd[1]: Starting Ensure certificate for test.foo...328client # [5661900.705822] client systemd-logind[205]: New seat seat0.329client # [5661900.706007] client systemd[1]: Started User Login Management.330client # [5661900.708100] client systemd[1]: Starting linger-users.service...331client # [5661900.753988] client systemd[1]: linger-users.service: Deactivated successfully.332client # [5661900.754211] client systemd[1]: Finished linger-users.service.333client # [5661900.755779] client systemd[1]: Reached target Multi-User System.334client # [5661900.756159] client systemd[1]: Startup finished in 1.811s.335ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 336ca # [5661901.152137] ca systemd-networkd[196]: eth1: Gained IPv6LL337ca # [5661901.291483] ca acme-ca.foo-start[263]: Waiting to acquire lock in /run/acme/338ca # [5661901.294913] ca acme-ca.foo-start[263]: + '[' -e out/acme-success ']'339ca # [5661901.294913] ca acme-ca.foo-start[263]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=340ca # [5661901.310812] ca acme-ca.foo-start[292]: + cd ca.foo341ca # [5661901.311373] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem342ca # [5661901.312625] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem'343ca # [5661901.313025] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem344ca # [5661901.314238] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem'345ca # [5661901.314499] ca acme-ca.foo-start[263]: + cat out/cert.pem ca/cert.pem346ca # [5661901.316111] ca acme-ca.foo-start[263]: + cp ca/cert.pem out/chain.pem347ca # [5661901.317834] ca acme-ca.foo-start[263]: + cat out/key.pem out/fullchain.pem348ca # [5661901.319468] ca acme-ca.foo-start[263]: + for fixpath in out certificates349ca # [5661901.319468] ca acme-ca.foo-start[263]: + '[' -d out ']'350ca # [5661901.319576] ca acme-ca.foo-start[263]: + chmod -R u=rwX,g=rX,o= out351ca # [5661901.321254] ca acme-ca.foo-start[263]: + chown -R acme:nginx out352ca # [5661901.324235] ca acme-ca.foo-start[263]: + for fixpath in out certificates353ca # [5661901.324235] ca acme-ca.foo-start[263]: + '[' -d certificates ']'354ca # [5661901.330804] ca systemd[1]: Finished Ensure certificate for ca.foo.355ca # [5661901.332518] ca systemd[1]: Starting Nginx Web Server...356server # [5661901.292420] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/357server # [5661901.295700] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'358server # [5661901.295700] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=359server # [5661901.310273] server acme-test.foo-start[255]: + cd test.foo360server # [5661901.310812] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem361server # [5661901.312133] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'362server # [5661901.312474] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem363server # [5661901.313588] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'364server # [5661901.313806] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem365server # [5661901.315597] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem366server # [5661901.317197] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem367server # [5661901.318906] server acme-test.foo-start[245]: + for fixpath in out certificates368server # [5661901.318906] server acme-test.foo-start[245]: + '[' -d out ']'369server # [5661901.319011] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out370server # [5661901.320457] server acme-test.foo-start[245]: + chown -R acme:nginx out371server # [5661901.323919] server acme-test.foo-start[245]: + for fixpath in out certificates372server # [5661901.323919] server acme-test.foo-start[245]: + '[' -d certificates ']'373server # [5661901.327032] server systemd[1]: Finished Ensure certificate for test.foo.374server # [5661901.330002] server systemd[1]: Starting Nginx Web Server...375client # [5661901.568189] client systemd-networkd[183]: eth1: Gained IPv6LL376ca # [5661901.879472] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/n62w6j33xfwv5ja839bysgmyj5j9i2si-nginx.conf syntax is ok377ca # [5661901.880056] ca nginx-pre-start[304]: nginx: configuration file /nix/store/n62w6j33xfwv5ja839bysgmyj5j9i2si-nginx.conf test is successful378ca # [5661901.924405] ca systemd[1]: Started Nginx Web Server.379ca # [5661901.925930] ca systemd[1]: Reached target Multi-User System.380ca # [5661901.928339] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...381server # [5661901.856131] server systemd-networkd[187]: eth1: Gained IPv6LL382server # [5661901.870787] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok383server # [5661901.871305] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful384server # [5661901.875907] server systemd[1]: Started Nginx Web Server.385server # [5661901.877339] server systemd[1]: Reached target Multi-User System.386server # [5661901.879748] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...387ca # [5661902.421317] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/388ca # [5661902.424716] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail389ca # [5661902.424793] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9390ca # [5661902.424910] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt391ca # [5661902.426167] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run392ca # [5661902.444732] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 No key found for account none@none.tld. Generating a P256 key.393ca # [5661902.445085] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key394ca # [5661902.473883] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration="158.882µs" duration-ns=158882 fields.time="2026-08-13T12:08:48Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4d5e49a5-cc33-436a-9336-48d25b3dd976 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=395ca # [5661902.474378] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] acme: Registering account for none@none.tld396ca # [5661902.476307] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=1.617742ms duration-ns=1617742 fields.time="2026-08-13T12:08:48Z" method=HEAD name=ca nonce=clBlaXJnbTZQdW42R1oyNnNXeW93M1VZMHJucGNSZno path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ef709b6f-39fd-49d7-bab9-33792e85ec12 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=397ca # [5661902.480201] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=2.785879ms duration-ns=2785879 fields.time="2026-08-13T12:08:48Z" method=POST name=ca nonce=ZUV1SnJVMlM0N2N5UDJMckcwM0ZtVWQ4S1VNQTR4VEU path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5856b9d5-bd58-406f-ac88-12bb3be5f445 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/4XG62dxyuZOJqKUW6LodAOoGi2QS6dh4/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=398ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!!399ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your400ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts".401ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This402ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys403ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME404ca # [5661902.480708] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal.405ca # [5661902.480873] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate406ca # [5661902.485313] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=3.749132ms duration-ns=3749132 fields.time="2026-08-13T12:08:48Z" method=POST name=ca nonce=MjZkQTNnVG1rSktXS1NLNGlnTHFmcUt2S1h0VmhNVzk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=81ec16a5-8110-4a0b-9c3e-72a850a4d159 response="{\"id\":\"p3RqDTrujDPJUk2C8tOjrmYHcAt2BHcc\",\"status\":\"pending\",\"expires\":\"2026-08-14T12:08:48Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-13T12:07:48Z\",\"notAfter\":\"2026-11-11T12:08:48Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/p3RqDTrujDPJUk2C8tOjrmYHcAt2BHcc/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=407ca # [5661902.544721] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=2.009387ms duration-ns=2009387 fields.time="2026-08-13T12:08:48Z" method=POST name=ca nonce=SEk2WENlRnhseGJrVjJmUHUzVnNEcUhEZ1k3RXNtc0s path=/acme/acme/authz/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3da471cb-fcf2-47ef-8eb8-d492293049fc response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"uxPi1KFj3LropERvNsCGw8fVb9JQG2zM\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD/GmCrwsPWTl8miFyKUrOFZv6MiQ79W18k\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"uxPi1KFj3LropERvNsCGw8fVb9JQG2zM\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD/KaV3f85V0BEU4AXi47zbrufQ8BRgedKy\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"uxPi1KFj3LropERvNsCGw8fVb9JQG2zM\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD/TqJPLULDA4xHIOhdstCoaLHvM3QvqE9n\"}],\"wildcard\":false,\"expires\":\"2026-08-14T12:08:48Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=408ca # [5661902.545180] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD409ca # [5661902.545180] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01410ca # [5661902.545180] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] acme: use http-01 solver411ca # [5661902.545331] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] acme: Trying to solve HTTP-01412ca # [5661902.550943] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=4.894268ms duration-ns=4894268 fields.time="2026-08-13T12:08:48Z" method=POST name=ca nonce=UnMyWWhGZzBpYXlLbVBrMXY5OEpSZUFTWEhRSzJjelg path=/acme/acme/challenge/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD/KaV3f85V0BEU4AXi47zbrufQ8BRgedKy protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4a97af66-18e3-4ee4-9c59-dcfd300735a0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"uxPi1KFj3LropERvNsCGw8fVb9JQG2zM\",\"validated\":\"2026-08-13T12:08:48Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD/KaV3f85V0BEU4AXi47zbrufQ8BRgedKy\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=413ca # [5661902.551254] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] The server validated our request414ca # [5661902.551324] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates415ca # [5661902.561145] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info duration=8.770881ms duration-ns=8770881 fields.time="2026-08-13T12:08:48Z" method=POST name=ca nonce=Y3Q2anlYMUhWbW5xTFZmTXJDbWFWanY5a3MwblRxNUk path=/acme/acme/order/p3RqDTrujDPJUk2C8tOjrmYHcAt2BHcc/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=eea41fef-9db3-4684-8678-527b3988db60 response="{\"id\":\"p3RqDTrujDPJUk2C8tOjrmYHcAt2BHcc\",\"status\":\"valid\",\"expires\":\"2026-08-14T12:08:48Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-13T12:07:48Z\",\"notAfter\":\"2026-11-11T12:08:48Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/TWIXTTEnKWGRpZ85P35hViomMmmT3WaD\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/p3RqDTrujDPJUk2C8tOjrmYHcAt2BHcc/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/r6iwkKY3giFITN8Lx8f9upmklJlb9GFu\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=416ca # [5661902.563707] ca step-ca[204]: time="2026-08-13T12:08:48Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQUoMpZVm0E0+I2365/V/KBDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTMxMjA3NDhaFw0yNjExMTExMjA4NDhaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAXSVr8uWVW+HxOAOVrdS8yZbfffYTHRX/sb7r02uAOP48ywzfl7AjLKbvJ2gow7mKuDE5B2TGF0Ss7ue8PLXqyjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUpLBpdyY0V5BAqdmHj8mJ8P6Uz8AwHwYDVR0jBBgwFoAUJWLuHFTwl6MTfvD9P0rkqJfD7TEwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAr6tuDIG8iaNRkwRT2rBzvxnye7z8Hc74sMmShHDYORoCIQDrmDxJaPQy5DFKW7mxX3v4oB63qtJpmJJEzhnJChQA9w==" duration=1.709544ms duration-ns=1709544 fields.time="2026-08-13T12:08:48Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=ZEY4OUx6cVZyRXVDZUZqNjdsOXlZRzNsTGlFWm9Hb2g path=/acme/acme/certificate/r6iwkKY3giFITN8Lx8f9upmklJlb9GFu protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=ab761d3d-92be-482a-bffe-834e23a04cb8 sans="map[dns:[ca.foo]]" serial=109677726151431191370383068607966857732 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-13T12:07:48Z" valid-to="2026-11-11T12:08:48Z"417ca # [5661902.563923] ca acme-order-renew-ca.foo-start[318]: 2026/08/13 12:08:48 [INFO] [ca.foo] Server responded with a certificate.418ca # [5661902.568342] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/419ca # [5661902.570358] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success420ca # [5661902.571833] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem421ca # [5661902.573125] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed422ca # [5661902.574862] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate423ca # [5661902.574862] ca acme-order-renew-ca.foo-start[307]: Installing new certificate424ca # [5661902.574862] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem425ca # [5661902.576364] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'426ca # [5661902.576700] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem427ca # [5661902.578174] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.key' -> 'out/key.pem'428ca # [5661902.578476] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem429ca # [5661902.579869] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'430ca # [5661902.580191] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem431ca # [5661902.581831] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem432ca # [5661902.583954] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates433ca # [5661902.583954] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']'434ca # [5661902.584061] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out435ca # [5661902.585676] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out436ca # [5661902.588709] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates437ca # [5661902.588709] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']'438ca # [5661902.588807] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates439ca # [5661902.590341] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates440ca # [5661902.593035] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/.441ca # [5661902.744867] ca systemd[1]: Reloading Nginx Web Server...442server # [5661902.412193] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/443server # [5661902.415032] server acme-order-renew-test.foo-start[270]: + set -euo pipefail444server # [5661902.415102] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108445server # [5661902.415218] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt446server # [5661902.416655] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run447server # [5661902.443146] server acme-order-renew-test.foo-start[281]: 2026/08/13 12:08:48 No key found for account none@none.tld. Generating a P256 key.448server # [5661902.443498] server acme-order-renew-test.foo-start[281]: 2026/08/13 12:08:48 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key449server # [5661902.486945] server acme-order-renew-test.foo-start[281]: 2026/08/13 12:08:48 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority450server # [5661902.487407] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.451server # [5661902.487407] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.452server # [5661902.487407] server acme-order-renew-test.foo-start[270]: + exit 10453server # [5661902.489669] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a454server # [5661902.489809] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.455server # [5661902.490113] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.456server # [5661902.490628] server systemd[1]: Startup finished in 3.554s.457ca # [5661902.748603] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.458ca # [5661902.748785] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.459ca # [5661903.269681] ca nginx[369]: nginx: the configuration file /nix/store/n62w6j33xfwv5ja839bysgmyj5j9i2si-nginx.conf syntax is ok460ca # [5661903.270173] ca nginx[369]: nginx: configuration file /nix/store/n62w6j33xfwv5ja839bysgmyj5j9i2si-nginx.conf test is successful461ca # [5661903.807940] ca systemd[1]: Reloaded Nginx Web Server.462ca # [5661903.808594] ca systemd[1]: Startup finished in 4.857s.463ca # [5661904.084138] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...464ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.42 seconds)465ca # [5661904.640760] ca acme-order-renew-ca.foo-start[384]: Waiting to acquire lock in /run/acme/466ca # [5661904.643915] ca acme-order-renew-ca.foo-start[384]: + set -euo pipefail467ca # [5661904.643983] ca acme-order-renew-ca.foo-start[384]: + echo 88dc4fc401a6091a1bd9468ca # [5661904.644112] ca acme-order-renew-ca.foo-start[384]: + cmp -s domainhash.txt certificates/domainhash.txt469ca # [5661904.645255] ca acme-order-renew-ca.foo-start[384]: + '[' -e certificates/ca.foo.key ']'470ca # [5661904.645255] ca acme-order-renew-ca.foo-start[384]: + '[' -e certificates/ca.foo.crt ']'471ca # [5661904.645797] ca acme-order-renew-ca.foo-start[392]: ++ find accounts -name none@none.tld.key472ca # [5661904.649054] ca acme-order-renew-ca.foo-start[384]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'473ca # [5661904.649121] ca acme-order-renew-ca.foo-start[384]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic474ca # [5661904.696196] ca step-ca[204]: time="2026-08-13T12:08:50Z" level=info duration="93.401µs" duration-ns=93401 fields.time="2026-08-13T12:08:50Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=81a73c1e-835c-4241-b69c-678f23a62765 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=475ca # [5661904.696819] ca acme-order-renew-ca.foo-start[393]: 2026/08/13 12:08:50 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint476ca # [5661904.696819] ca acme-order-renew-ca.foo-start[393]: 2026/08/13 12:08:50 [INFO] [ca.foo] The certificate expires at 2026-11-11T12:08:48Z, the renewal can be performed in 1439h59m37.250297092s: no renewal.477ca # [5661904.697056] ca acme-order-renew-ca.foo-start[384]: + mv domainhash.txt certificates/478ca # [5661904.699068] ca acme-order-renew-ca.foo-start[384]: + touch out/acme-success479ca # [5661904.700981] ca acme-order-renew-ca.foo-start[384]: + cmp -s certificates/ca.foo.crt out/fullchain.pem480ca # [5661904.702113] ca acme-order-renew-ca.foo-start[384]: + for fixpath in out certificates481ca # [5661904.702113] ca acme-order-renew-ca.foo-start[384]: + '[' -d out ']'482ca # [5661904.702207] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=rX,o= out483ca # [5661904.703662] ca acme-order-renew-ca.foo-start[384]: + chown -R acme:nginx out484ca # [5661904.707248] ca acme-order-renew-ca.foo-start[384]: + for fixpath in out certificates485ca # [5661904.707248] ca acme-order-renew-ca.foo-start[384]: + '[' -d certificates ']'486ca # [5661904.707341] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=rX,o= certificates487ca # [5661904.709160] ca acme-order-renew-ca.foo-start[384]: + chown -R acme:nginx certificates488ca # [5661904.712251] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=,o= accounts/.489ca # [5661904.833675] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.490ca # [5661904.834000] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.491server: must succeed: systemctl restart acme-test.foo.service492server # [5661907.868318] server systemd[1]: acme-test.foo.service: Deactivated successfully.493server # [5661907.868683] server systemd[1]: Stopped Ensure certificate for test.foo.494server # [5661907.870009] server systemd[1]: Stopping Ensure certificate for test.foo...495server # [5661907.872301] server systemd[1]: Starting Ensure certificate for test.foo...496server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.60 seconds)497client: waiting for success: curl -v https://test.foo498* Host test.foo:443 was resolved.499* IPv6: 2001:db8:1::3500* IPv4: 192.168.1.3501* Trying [2001:db8:1::3]:443...502* ALPN: curl offers h2,http/1.1503} [5 bytes data]504* TLSv1.3 (OUT), TLS handshake, Client hello (1):505} [1552 bytes data]506* SSL Trust Anchors:507* OpenSSL default paths (fallback)508{ [5 bytes data]509* TLSv1.3 (IN), TLS handshake, Server hello (2):510{ [1210 bytes data]511* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):512{ [1 bytes data]513* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):514{ [19 bytes data]515* TLSv1.3 (IN), TLS handshake, Certificate (11):516{ [1009 bytes data]517* TLSv1.3 (IN), TLS handshake, CERT verify (15):518{ [110 bytes data]519* TLSv1.3 (IN), TLS handshake, Finished (20):520{ [52 bytes data]521* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):522} [1 bytes data]523* TLSv1.3 (OUT), TLS handshake, Finished (20):524} [52 bytes data]525* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey526* ALPN: server accepted h2527* Server certificate:528* subject: CN=test.foo529* start date: Aug 13 12:08:47 2026 GMT530* expire date: Sep 12 12:08:47 2028 GMT531* issuer: CN=minica root ca 61c832532* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384533* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384534* subjectAltName: "test.foo" matches cert's "test.foo"535* OpenSSL verify result: 13536* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)537* closing connection #0538curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)539More details here: https://curl.se/docs/sslcerts.html540541curl failed to verify the legitimacy of the server and therefore could not542establish a secure connection to it. To learn more about this situation and543how to fix it, please visit the webpage mentioned above.544server # [5661908.416498] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/545server # [5661908.419753] server acme-test.foo-start[316]: + '[' -e out/acme-success ']'546server # [5661908.419753] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=547server # [5661908.435228] server acme-test.foo-start[325]: + cd test.foo548server # [5661908.435639] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem549server # [5661908.437084] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem'550server # [5661908.437388] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem551server # [5661908.438794] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem'552server # [5661908.439038] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem553server # [5661908.440839] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem554server # [5661908.442656] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem555server # [5661908.444305] server acme-test.foo-start[316]: + for fixpath in out certificates556server # [5661908.444305] server acme-test.foo-start[316]: + '[' -d out ']'557server # [5661908.444396] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out558server # [5661908.445802] server acme-test.foo-start[316]: + chown -R acme:nginx out559server # [5661908.449199] server acme-test.foo-start[316]: + for fixpath in out certificates560server # [5661908.449254] server acme-test.foo-start[316]: + '[' -d certificates ']'561server # [5661908.452602] server systemd[1]: Finished Ensure certificate for test.foo.562server # [5661908.457099] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...563server # [5661908.965258] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/564server # [5661908.968394] server acme-order-renew-test.foo-start[333]: + set -euo pipefail565server # [5661908.968462] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108566server # [5661908.968579] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt567server # [5661908.969916] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run568server # [5661909.028238] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] acme: Registering account for none@none.tld569server # [5661909.041973] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!!570server # [5661909.041973] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your571server # [5661909.041973] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts".572server # [5661909.041973] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This573server # [5661909.041973] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys574server # [5661909.041973] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME575server # [5661909.041973] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal.576server # [5661909.042285] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] acme: Obtaining bundled SAN certificate577server # [5661909.113351] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB578server # [5661909.113351] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01579server # [5661909.113351] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] acme: use http-01 solver580server # [5661909.113508] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] acme: Trying to solve HTTP-01581server # [5661909.122743] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] The server validated our request582server # [5661909.122851] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] acme: Validations succeeded; requesting certificates583server # [5661909.142833] server acme-order-renew-test.foo-start[341]: 2026/08/13 12:08:55 [INFO] [test.foo] Server responded with a certificate.584server # [5661909.147295] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/585server # [5661909.149364] server acme-order-renew-test.foo-start[333]: + touch out/acme-success586server # [5661909.151155] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem587server # [5661909.152255] server acme-order-renew-test.foo-start[333]: + touch out/renewed588server # [5661909.153824] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate589server # [5661909.153824] server acme-order-renew-test.foo-start[333]: Installing new certificate590server # [5661909.153824] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem591server # [5661909.155318] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'592server # [5661909.155631] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem593server # [5661909.157286] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem'594server # [5661909.157598] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem595server # [5661909.159010] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'596server # [5661909.159292] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem597server # [5661909.160942] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem598server # [5661909.162705] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates599server # [5661909.162705] server acme-order-renew-test.foo-start[333]: + '[' -d out ']'600server # [5661909.162798] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out601server # [5661909.164457] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out602server # [5661909.167376] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates603server # [5661909.167376] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']'604server # [5661909.167483] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates605server # [5661909.169296] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates606server # [5661909.172422] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/.607* Host test.foo:443 was resolved.608* IPv6: 2001:db8:1::3609* IPv4: 192.168.1.3610* Trying [2001:db8:1::3]:443...611ca # [5661909.027323] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration="64.08µs" duration-ns=64080 fields.time="2026-08-13T12:08:55Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=646ce92e-6d4f-4260-aa47-d2f2441274b8 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=612ca # [5661909.033797] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration="949.533µs" duration-ns=949533 fields.time="2026-08-13T12:08:55Z" method=HEAD name=ca nonce=SWNrbDhiV01rQm1nb0JuS2lwUDk3NmlyT3dZcDZWbGg path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=43329462-4bf0-447d-810d-ef544a29fa34 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=613ca # [5661909.041279] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration=2.666557ms duration-ns=2666557 fields.time="2026-08-13T12:08:55Z" method=POST name=ca nonce=ankxQjYxeThkVUtuQ2h3QkE2U2ZMeld6cmIzdUZoTTM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=ecec65d6-200b-44f9-b51c-de5ebf954cc6 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/ophgtIaAoypeJLQYAoaYPNlFNiAfIkqC/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [5661909.049819] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration=4.445501ms duration-ns=4445501 fields.time="2026-08-13T12:08:55Z" method=POST name=ca nonce=OXVnNFZ4UkQ2Y042d0pwSkZIVEs3NHNpZ3pqa2M0eDk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=afe7a768-9baa-44b2-a001-1525d66368c9 response="{\"id\":\"N79uqh2t9GIz5osGcCo7zzXMz3Gma44Q\",\"status\":\"pending\",\"expires\":\"2026-08-14T12:08:55Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-13T12:07:55Z\",\"notAfter\":\"2026-11-11T12:08:55Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB\"],\"finalize\":\"https://ca.foo/acme/acme/order/N79uqh2t9GIz5osGcCo7zzXMz3Gma44Q/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=615ca # [5661909.112643] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration=1.899226ms duration-ns=1899226 fields.time="2026-08-13T12:08:55Z" method=POST name=ca nonce=WUJkeHVROWFlUnFBd1VzZVByOWJSU1NJQjZWVFpPdUQ path=/acme/acme/authz/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB protocol=HTTP/1.1 referer= remote-address="::1" request-id=a24856e2-af68-48d5-902f-9b47515d5169 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"qiqOKq3R0ImzcUhgNY4r3O0OD4QlG2ee\",\"url\":\"https://ca.foo/acme/acme/challenge/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB/z9tjOUiKHTm3MkDv5ph5cMj8Y2XGfcxK\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"qiqOKq3R0ImzcUhgNY4r3O0OD4QlG2ee\",\"url\":\"https://ca.foo/acme/acme/challenge/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB/GAuTEdI0EgenE0q2zXpZjfXqIgasP58R\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"qiqOKq3R0ImzcUhgNY4r3O0OD4QlG2ee\",\"url\":\"https://ca.foo/acme/acme/challenge/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB/cUZLSrhynrbIiAqKSztmYOJ2ig7kRu4J\"}],\"wildcard\":false,\"expires\":\"2026-08-14T12:08:55Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=616ca # [5661909.122069] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration=4.620384ms duration-ns=4620384 fields.time="2026-08-13T12:08:55Z" method=POST name=ca nonce=NDdBcjlzYkg4NGw3dHA2TjM4d1FySWpFVzMzRkpnOXU path=/acme/acme/challenge/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB/GAuTEdI0EgenE0q2zXpZjfXqIgasP58R protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f439a095-d27e-47d1-9412-6790ddfb241c response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"qiqOKq3R0ImzcUhgNY4r3O0OD4QlG2ee\",\"validated\":\"2026-08-13T12:08:55Z\",\"url\":\"https://ca.foo/acme/acme/challenge/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB/GAuTEdI0EgenE0q2zXpZjfXqIgasP58R\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=617ca # [5661909.136113] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info duration=8.264394ms duration-ns=8264394 fields.time="2026-08-13T12:08:55Z" method=POST name=ca nonce=bkhxcnBocGNLZnhwcXdOb0tJYmZVcjlLMllUV2RobnA path=/acme/acme/order/N79uqh2t9GIz5osGcCo7zzXMz3Gma44Q/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=1f44d147-3616-4d9f-83a7-2e4be74ca6eb response="{\"id\":\"N79uqh2t9GIz5osGcCo7zzXMz3Gma44Q\",\"status\":\"valid\",\"expires\":\"2026-08-14T12:08:55Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-13T12:07:55Z\",\"notAfter\":\"2026-11-11T12:08:55Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/phgGIKeUuUG8jesOz4t1JH78Gd8IuxCB\"],\"finalize\":\"https://ca.foo/acme/acme/order/N79uqh2t9GIz5osGcCo7zzXMz3Gma44Q/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/Mb9OyKQEUgXKItBeVTyYovdLuKUGn5Yv\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=618ca # [5661909.142156] ca step-ca[204]: time="2026-08-13T12:08:55Z" level=info certificate="MIIB1TCCAX2gAwIBAgIQPNrGo1m7QEDnKBM2nPXeUTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTMxMjA3NTVaFw0yNjExMTExMjA4NTVaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEeZ+eOTL6Yt7omb6qAwaP0ZpdY2M8bzW4ZCtuoSWeLcbrNzqH10yrJ1eJjm2zq/iGxEO5h9/yl95X7i+kGD3uaqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRpE8eaJ3DEfAPzE+CNqdpNjK9e8TAfBgNVHSMEGDAWgBQlYu4cVPCXoxN+8P0/SuSol8PtMTATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRgAwQwIgNbSG7fRDFOWWNj3B600Q4MTf0l03dtXadoXj3AiDVCACHwkayqsdTE9UrIITaouyRU89Rn+k/eOoPwyB73+Ip5c=" duration=1.810265ms duration-ns=1810265 fields.time="2026-08-13T12:08:55Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=MjY4T0JFYzlpTlZ2TnRqNVJOdlJYYld1OWtTbXFLY24 path=/acme/acme/certificate/Mb9OyKQEUgXKItBeVTyYovdLuKUGn5Yv protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=e9ff3cc8-81fd-4fa9-b964-3857a6e32c3f sans="map[dns:[test.foo]]" serial=80889629321318096084149796614002040401 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-13T12:07:55Z" valid-to="2026-11-11T12:08:55Z"619* ALPN: curl offers h2,http/1.1620} [5 bytes data]621* TLSv1.3 (OUT), TLS handshake, Client hello (1):622} [1552 bytes data]623* SSL Trust Anchors:624* OpenSSL default paths (fallback)625{ [5 bytes data]626* TLSv1.3 (IN), TLS handshake, Server hello (2):627{ [1210 bytes data]628* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):629{ [1 bytes data]630* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):631{ [19 bytes data]632* TLSv1.3 (IN), TLS handshake, Certificate (11):633{ [1009 bytes data]634* TLSv1.3 (IN), TLS handshake, CERT verify (15):635{ [111 bytes data]636* TLSv1.3 (IN), TLS handshake, Finished (20):637{ [52 bytes data]638* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):639} [1 bytes data]640* TLSv1.3 (OUT), TLS handshake, Finished (20):641} [52 bytes data]642* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey643* ALPN: server accepted h2644* Server certificate:645* subject: CN=test.foo646* start date: Aug 13 12:08:47 2026 GMT647* expire date: Sep 12 12:08:47 2028 GMT648* issuer: CN=minica root ca 61c832649* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384650* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384651* subjectAltName: "test.foo" matches cert's "test.foo"652* OpenSSL verify result: 13653* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)654* closing connection #0655curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)656More details here: https://curl.se/docs/sslcerts.html657658curl failed to verify the legitimacy of the server and therefore could not659establish a secure connection to it. To learn more about this situation and660how to fix it, please visit the webpage mentioned above.661server # [5661909.337035] server systemd[1]: Reloading Nginx Web Server...662server # [5661909.341503] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.663server # [5661909.341800] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.664server # [5661909.861281] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok665server # [5661909.861742] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful666* Host test.foo:443 was resolved.667* IPv6: 2001:db8:1::3668* IPv4: 192.168.1.3669* Trying [2001:db8:1::3]:443...670* ALPN: curl offers h2,http/1.1671} [5 bytes data]672* TLSv1.3 (OUT), TLS handshake, Client hello (1):673} [1552 bytes data]674* SSL Trust Anchors:675* OpenSSL default paths (fallback)676{ [5 bytes data]677* TLSv1.3 (IN), TLS handshake, Server hello (2):678{ [1210 bytes data]679* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):680{ [1 bytes data]681* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):682{ [19 bytes data]683* TLSv1.3 (IN), TLS handshake, Certificate (11):684{ [927 bytes data]685* TLSv1.3 (IN), TLS handshake, CERT verify (15):686{ [79 bytes data]687* TLSv1.3 (IN), TLS handshake, Finished (20):688{ [52 bytes data]689* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):690} [1 bytes data]691* TLSv1.3 (OUT), TLS handshake, Finished (20):692} [52 bytes data]693* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey694* ALPN: server accepted h2695* Server certificate:696* subject: CN=test.foo697* start date: Aug 13 12:07:55 2026 GMT698* expire date: Nov 11 12:08:55 2026 GMT699* issuer: CN=Clan Intermediate CA700* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256701* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256702* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256703* subjectAltName: "test.foo" matches cert's "test.foo"704* OpenSSL verify result: 0705* SSL certificate verified via OpenSSL.706* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 38046 707 % Total % Received % Xferd Average Speed Time Time Time Current708 Dload Upload Total Spent Left Speed709 0 0 0 0 0 0 0 0 0* using HTTP/2710* [HTTP/2] [1] OPENED stream for https://test.foo/711* [HTTP/2] [1] [:method: GET]712* [HTTP/2] [1] [:scheme: https]713* [HTTP/2] [1] [:authority: test.foo]714* [HTTP/2] [1] [:path: /]715* [HTTP/2] [1] [user-agent: curl/8.21.0]716* [HTTP/2] [1] [accept: */*]717} [5 bytes data]718719720721722723* Request completely sent off724{ [5 bytes data]725* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):726{ [265 bytes data]727* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):728{ [265 bytes data]729730731732733734735736{ [5 bytes data]737100 20 100 20 0 0 643 0 0738* Connection #0 to host test.foo:443 left intact739client: (finished: waiting for success: curl -v https://test.foo, in 2.16 seconds)740client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2741Certificate:742 Data:743 Version: 3 (0x2)744 Serial Number:745 3c:da:c6:a3:59:bb:40:40:e7:28:13:36:9c:f5:de:51746 Signature Algorithm: ecdsa-with-SHA256747 Issuer: CN=Clan Intermediate CA748 Validity749 Not Before: Aug 13 12:07:55 2026 GMT750 Not After : Nov 11 12:08:55 2026 GMT751 Subject: CN=test.foo752 Subject Public Key Info:753 Public Key Algorithm: id-ecPublicKey754 Public-Key: (256 bit)755 pub:756 04:79:9f:9e:39:32:fa:62:de:e8:99:be:aa:03:06:757 8f:d1:9a:5d:63:63:3c:6f:35:b8:64:2b:6e:a1:25:758 9e:2d:c6:eb:37:3a:87:d7:4c:ab:27:57:89:8e:6d:759 b3:ab:f8:86:c4:43:b9:87:df:f2:97:de:57:ee:2f:760 a4:18:3d:ee:6a761 ASN1 OID: prime256v1762 NIST CURVE: P-256763 X509v3 extensions:764 X509v3 Key Usage: critical765 Digital Signature766 X509v3 Extended Key Usage: 767 TLS Web Server Authentication, TLS Web Client Authentication768 X509v3 Subject Key Identifier: 769 69:13:C7:9A:27:70:C4:7C:03:F3:13:E0:8D:A9:DA:4D:8C:AF:5E:F1770 X509v3 Authority Key Identifier: 771 25:62:EE:1C:54:F0:97:A3:13:7E:F0:FD:3F:4A:E4:A8:97:C3:ED:31772 X509v3 Subject Alternative Name: 773 DNS:test.foo774 1.3.6.1.4.1.37476.9000.64.1: 775 0......acme..776 Signature Algorithm: ecdsa-with-SHA256777 Signature Value:778 30:43:02:20:35:b4:86:ed:f4:43:14:e5:96:36:3d:c1:eb:4d:779 10:e0:c4:df:d2:5d:37:76:d5:da:76:85:e3:dc:08:83:54:20:780 02:1f:09:1a:ca:ab:1d:4c:4f:54:ac:82:13:6a:8b:b2:45:4f:781 3d:46:7f:a4:fd:e3:a8:3f:0c:81:ef:7f:88:a7:97782client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds)783(finished: run the VM test script, in 12.24 seconds)784test script finished in 12.28s785cleanup786kill NspawnMachine (pid 53)787kill NspawnMachine (pid 55)788server # [5661910.398700] server systemd[1]: Reloaded Nginx Web Server.789kill NspawnMachine (pid 54)790Container ca terminated by signal KILL.791Container client terminated by signal KILL.792(finished: cleanup, in 0.35 seconds)793Container server terminated by signal KILL.