these 97 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/0asgxy0080qzxdc4bf22n8v99jmps3kw-ca.json.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv /nix/store/5sm0y28aacgsrvxqfq7f4l7lcf07a3ai-nss-cacert-3.126.drv /nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv /nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv /nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv /nix/store/y37smfm18fsf3y82w5ws00qa8cfib0gn-system-path.drv /nix/store/cz710laxjins4p2h5f454xlvyhxd2pnr-dbus-1.drv /nix/store/d209859g1k1nl5kbvrh37gaq5q1nwa7d-nginx.conf.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/a9ygqgnhpqja81js47zq71q9xrlkpf4j-unit-script-nginx-pre-start.drv /nix/store/36ahrhp291qj605mljms2g3ql6gsmbiz-unit-nginx.service.drv /nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv /nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv /nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/36rdi59h65dzw37b9nwsd3h22xgvk9pf-X-Restart-Triggers-dbus-broker.drv /nix/store/d5wav7y990vifvf36rawbk84glbk8z3r-unit-dbus-broker.service.drv /nix/store/lrlfzsdb84cpwz72miycnwn0s93v0xrn-X-Restart-Triggers-step-ca.drv /nix/store/gl11b5h255418ca00wplqkqxjqdk7q0n-unit-step-ca.service.drv /nix/store/mgixw9ka9fiv11fapybmg8sy09k499vw-unit-nix-daemon.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/gsx3czd454ygqz9w9559a3ab1qjbhiv7-system-units.drv /nix/store/m2k8zda8pv8xc5hh7wpcp8mzshlgmkcn-unit-dbus-broker.service.drv /nix/store/hlvl5mjwv0r4nsf5ny9rw06vqyln9i1y-user-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/lpplpfw1a3g7nspb8q15ynf692gp1cvg-etc.drv /nix/store/19wvc91gsjwvhz6z4wk55lcfbimzvcq5-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/ak650nvg7hdlzzyml0bidyl83bbbbwfr-nixos-system-ca-test.drv /nix/store/9vy7xn3xjihisbc7a3rvzkblb498bwhx-run-ca-nspawn.drv /nix/store/sidw340179706sq5nn0vcgbiy6fiysdf-system-path.drv /nix/store/hkgi3qjkvz2480izgs9lr8ai8h0fvv9m-dbus-1.drv /nix/store/z96h6f3sw18q4p4p460y1478c2ix57i2-X-Restart-Triggers-dbus-broker.drv /nix/store/xxz15skk85mw7x9r5708zaxld7barxbr-unit-dbus-broker.service.drv /nix/store/63cmqd8g5f5wixabwv8v3c0a7pc09pra-user-units.drv /nix/store/gcn9b4wn0x93myydhyww8gai01bi0qx5-unit-dbus-broker.service.drv /nix/store/a917ndn0p471dpspza8nv5ihgr3wjpsw-system-units.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/jgvpizxmdl383q8xr926ghyv0rzby5f2-etc.drv /nix/store/gg0jqvfmpffpcbjg67i69fc2f85rqxgn-activate.drv /nix/store/fnlbnfxsz6v0rxjhng0fzkbd7ib3lq7r-nixos-system-client-test.drv /nix/store/cl5vdw1lxwh2xzra3gr2q5d3mal8cwfd-run-client-nspawn.drv /nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv /nix/store/rdnrxv2a04ws792wyvvrg6xwwwcpv1mk-system-path.drv /nix/store/xjhb50h3nrcg7dv6cgzg3g6vdfdwa52r-dbus-1.drv /nix/store/kwxpg8872m49xkp7s3gzp44z607q5apc-X-Restart-Triggers-dbus-broker.drv /nix/store/pn055kafbhbkc2i317fklfa77hwhb78q-unit-dbus-broker.service.drv /nix/store/3921dn8735naqax6b1r137mkmh77g2z9-user-units.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/p38ds1kkxy936lj1phr4wjzjyirp4irk-unit-dbus-broker.service.drv /nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv /nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv /nix/store/8023ny7nazpffwr2q7ccsnn61h16qr6k-system-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/vnv0v213nnwfml39dmfbhgzr9z2xixik-etc.drv /nix/store/bwxhkqlj9cinqfqz7k98kvz06w3kw5x8-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/b2mfgjv2r7kk1x9d7iwxq3xrriyyvqfk-nixos-system-server-test.drv /nix/store/mwgnjj6jln81nq2hvsg9khrl4p4h243q-run-server-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/aims8afg4lzn382prk4fprkq9p0nq6gp-driverConfiguration.json.drv /nix/store/0s6a9m56hjpbjkzsjdba00bq37ixp0xh-nixos-test-driver-certificates.drv /nix/store/izjg2d5jf9vfxj0j06ccrmvba23rdzh8-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 75.8 MiB unpacked): /nix/store/qfjhplgaj6zn71pd29p28wxngj5l4bys-openssl-3.6.3-man /nix/store/fwwgviqhlwxaigb610fvpiciz2di7wjg-python3.14-buildcatrust-0.5.1 /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/d209859g1k1nl5kbvrh37gaq5q1nwa7d-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-40-eth1.network> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/0asgxy0080qzxdc4bf22n8v99jmps3kw-ca.json.drv' building '/nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv' building '/nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' ca.json> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv' building '/nix/store/rdnrxv2a04ws792wyvvrg6xwwwcpv1mk-system-path.drv' building '/nix/store/y37smfm18fsf3y82w5ws00qa8cfib0gn-system-path.drv' building '/nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/sidw340179706sq5nn0vcgbiy6fiysdf-system-path.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/a9ygqgnhpqja81js47zq71q9xrlkpf4j-unit-script-nginx-pre-start.drv' building '/nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv' building '/nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv' building '/nix/store/5sm0y28aacgsrvxqfq7f4l7lcf07a3ai-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> created 1723 symlinks in user environment unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/lrlfzsdb84cpwz72miycnwn0s93v0xrn-X-Restart-Triggers-step-ca.drv' building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/36ahrhp291qj605mljms2g3ql6gsmbiz-unit-nginx.service.drv' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' building '/nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/cz710laxjins4p2h5f454xlvyhxd2pnr-dbus-1.drv' unit-firewall.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/hkgi3qjkvz2480izgs9lr8ai8h0fvv9m-dbus-1.drv' building '/nix/store/xjhb50h3nrcg7dv6cgzg3g6vdfdwa52r-dbus-1.drv' building '/nix/store/gl11b5h255418ca00wplqkqxjqdk7q0n-unit-step-ca.service.drv' building '/nix/store/36rdi59h65dzw37b9nwsd3h22xgvk9pf-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/z96h6f3sw18q4p4p460y1478c2ix57i2-X-Restart-Triggers-dbus-broker.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/kwxpg8872m49xkp7s3gzp44z607q5apc-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/d5wav7y990vifvf36rawbk84glbk8z3r-unit-dbus-broker.service.drv' building '/nix/store/m2k8zda8pv8xc5hh7wpcp8mzshlgmkcn-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/gcn9b4wn0x93myydhyww8gai01bi0qx5-unit-dbus-broker.service.drv' building '/nix/store/p38ds1kkxy936lj1phr4wjzjyirp4irk-unit-dbus-broker.service.drv' building '/nix/store/pn055kafbhbkc2i317fklfa77hwhb78q-unit-dbus-broker.service.drv' building '/nix/store/xxz15skk85mw7x9r5708zaxld7barxbr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3921dn8735naqax6b1r137mkmh77g2z9-user-units.drv' building '/nix/store/hlvl5mjwv0r4nsf5ny9rw06vqyln9i1y-user-units.drv' building '/nix/store/63cmqd8g5f5wixabwv8v3c0a7pc09pra-user-units.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/5sm0y28aacgsrvxqfq7f4l7lcf07a3ai-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/xn7qng2n71nqsr1amzk8ss4ibblclgqr-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/xn7qng2n71nqsr1amzk8ss4ibblclgqr-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/xn7qng2n71nqsr1amzk8ss4ibblclgqr-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5l35lwnh251s1ivy8dpvvcjn5pkwsha7-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/5l35lwnh251s1ivy8dpvvcjn5pkwsha7-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/5l35lwnh251s1ivy8dpvvcjn5pkwsha7-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5q0kh7b1izjg799494h80rzlfgddq8lf-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/5q0kh7b1izjg799494h80rzlfgddq8lf-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/5q0kh7b1izjg799494h80rzlfgddq8lf-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/29z41y5y95g7wqyks2kbfb159snq7xvy-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/29z41y5y95g7wqyks2kbfb159snq7xvy-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/29z41y5y95g7wqyks2kbfb159snq7xvy-nss-cacert-3.126-hashed building '/nix/store/mgixw9ka9fiv11fapybmg8sy09k499vw-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/8023ny7nazpffwr2q7ccsnn61h16qr6k-system-units.drv' building '/nix/store/a917ndn0p471dpspza8nv5ihgr3wjpsw-system-units.drv' building '/nix/store/gsx3czd454ygqz9w9559a3ab1qjbhiv7-system-units.drv' building '/nix/store/vnv0v213nnwfml39dmfbhgzr9z2xixik-etc.drv' building '/nix/store/jgvpizxmdl383q8xr926ghyv0rzby5f2-etc.drv' building '/nix/store/lpplpfw1a3g7nspb8q15ynf692gp1cvg-etc.drv' building '/nix/store/bwxhkqlj9cinqfqz7k98kvz06w3kw5x8-activate.drv' building '/nix/store/b2mfgjv2r7kk1x9d7iwxq3xrriyyvqfk-nixos-system-server-test.drv' building '/nix/store/gg0jqvfmpffpcbjg67i69fc2f85rqxgn-activate.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/mwgnjj6jln81nq2hvsg9khrl4p4h243q-run-server-nspawn.drv' building '/nix/store/fnlbnfxsz6v0rxjhng0fzkbd7ib3lq7r-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/cl5vdw1lxwh2xzra3gr2q5d3mal8cwfd-run-client-nspawn.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/19wvc91gsjwvhz6z4wk55lcfbimzvcq5-activate.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/ak650nvg7hdlzzyml0bidyl83bbbbwfr-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/9vy7xn3xjihisbc7a3rvzkblb498bwhx-run-ca-nspawn.drv' building '/nix/store/aims8afg4lzn382prk4fprkq9p0nq6gp-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/0s6a9m56hjpbjkzsjdba00bq37ixp0xh-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/izjg2d5jf9vfxj0j06ccrmvba23rdzh8-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/izjg2d5jf9vfxj0j06ccrmvba23rdzh8-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ca # [6480159.189213] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [6480159.175374] client systemd-journald[69]: Journal started container-test-run-certificates> server # [6480159.189166] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6480159.175418] client systemd-journald[69]: Runtime Journal (/run/log/journal/1b7885c5477b4302bd2440693e25fad3) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [6480159.189263] ca systemd-journald[78]: Runtime Journal (/run/log/journal/f4ea7e9620f647e0bf9c0c183d62a52e) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6480159.180986] client systemd[1]: Listening on Journal Log Access Socket. container-test-run-certificates> client # [6480159.184261] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> server # [6480159.189226] server systemd-journald[69]: Runtime Journal (/run/log/journal/edd01c6c05f9475082fd31883e8cc0be) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6480159.195167] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6480159.216693] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6480159.205715] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6480159.247242] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6480159.218773] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6480159.219526] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6480159.261534] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6480159.222581] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6480159.224083] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6480159.263442] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6480159.219993] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6480159.265944] server systemd-journald[69]: Time spent on flushing to /var/log/journal/edd01c6c05f9475082fd31883e8cc0be is 1.668ms for 6 entries. container-test-run-certificates> ca # [6480159.224523] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6480159.265944] server systemd-journald[69]: System Journal (/var/log/journal/edd01c6c05f9475082fd31883e8cc0be) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6480159.230632] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/f4ea7e9620f647e0bf9c0c183d62a52e is 1.551ms for 6 entries. container-test-run-certificates> ca # [6480159.230632] ca systemd-journald[78]: System Journal (/var/log/journal/f4ea7e9620f647e0bf9c0c183d62a52e) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6480159.252648] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6480159.253451] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6480159.290029] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6480159.253537] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6480159.290800] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6480159.229188] client systemd-journald[69]: Time spent on flushing to /var/log/journal/1b7885c5477b4302bd2440693e25fad3 is 1.418ms for 8 entries. container-test-run-certificates> client # [6480159.229188] client systemd-journald[69]: System Journal (/var/log/journal/1b7885c5477b4302bd2440693e25fad3) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6480159.241276] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6480159.242170] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6480159.290880] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6480159.254180] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6480159.242263] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6480159.242954] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6480159.291577] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6480159.254213] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6480159.261484] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6480159.261508] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6480159.291613] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6480159.242994] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6480159.244060] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6480159.309607] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6480159.261931] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6480159.309699] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6480159.244088] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6480159.310861] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6480159.261934] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6480159.265082] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6480159.284239] client systemd-tmpfiles[143]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6480159.313015] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6480159.284483] client systemd-tmpfiles[143]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6480159.328485] server systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6480159.263558] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6480159.284148] ca systemd-tmpfiles[149]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6480159.328639] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6480159.284367] ca systemd-tmpfiles[149]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6480159.284647] client systemd-tmpfiles[143]: fchmod() of /var/log/journal/1b7885c5477b4302bd2440693e25fad3 failed: Operation not permitted container-test-run-certificates> ca # [6480159.284500] ca systemd-tmpfiles[149]: fchmod() of /var/log/journal/f4ea7e9620f647e0bf9c0c183d62a52e failed: Operation not permitted container-test-run-certificates> ca # [6480159.284690] ca systemd-tmpfiles[149]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6480159.328830] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6480159.329820] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [6480159.338661] server systemd-tmpfiles[169]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6480159.284879] client systemd-tmpfiles[143]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6480159.287463] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6480159.289205] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6480159.338893] server systemd-tmpfiles[169]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6480159.290246] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6480159.317562] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6480159.287525] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6480159.339063] server systemd-tmpfiles[169]: fchmod() of /var/log/journal/edd01c6c05f9475082fd31883e8cc0be failed: Operation not permitted container-test-run-certificates> client # [6480159.289656] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6480159.339281] server systemd-tmpfiles[169]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6480159.292071] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6480159.323702] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6480159.324646] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6480159.342081] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6480159.326192] ca systemd[1]: Finished Firewall. container-test-run-certificates> client # [6480159.311696] client systemd[1]: Finished Firewall. container-test-run-certificates> server # [6480159.343362] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6480159.312458] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6480159.327065] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6480159.312768] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6480159.327406] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6480159.344147] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6480159.328645] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6480159.336833] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6480159.313879] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [6480159.316799] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6480159.327809] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6480159.329384] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6480159.356801] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6480159.386944] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6480159.365266] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6480159.340079] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6480159.366488] server systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6480159.391309] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6480159.379241] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6480159.395395] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6480159.863874] ca systemd-networkd[194]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6480159.864511] ca systemd-networkd[194]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6480159.871944] ca systemd-networkd[194]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6480159.872191] ca systemd-networkd[194]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6480159.872298] ca systemd-networkd[194]: lo: Link UP container-test-run-certificates> ca # [6480159.872303] ca systemd-networkd[194]: lo: Gained carrier container-test-run-certificates> ca # [6480159.872504] ca systemd-networkd[194]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6480159.872864] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6480159.874228] ca systemd-networkd[194]: eth1: Link UP container-test-run-certificates> ca # [6480159.874368] ca systemd-networkd[194]: eth1: Gained carrier container-test-run-certificates> ca # [6480159.875209] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6480159.893683] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6480159.877498] server systemd-networkd[179]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6480159.877587] server systemd-networkd[179]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6480159.884470] server systemd-networkd[179]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6480159.884644] server systemd-networkd[179]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6480159.884892] server systemd-networkd[179]: lo: Link UP container-test-run-certificates> server # [6480159.884895] server systemd-networkd[179]: lo: Gained carrier container-test-run-certificates> server # [6480159.885177] server systemd-networkd[179]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6480159.885488] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6480159.886511] server systemd-networkd[179]: eth1: Link UP container-test-run-certificates> server # [6480159.886822] server systemd-networkd[179]: eth1: Gained carrier container-test-run-certificates> server # [6480159.886968] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6480159.897300] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6480159.914603] client systemd-networkd[178]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6480159.914685] client systemd-networkd[178]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6480159.920639] client systemd-networkd[178]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6480159.920794] client systemd-networkd[178]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6480159.920883] client systemd-networkd[178]: lo: Link UP container-test-run-certificates> client # [6480159.920885] client systemd-networkd[178]: lo: Gained carrier container-test-run-certificates> client # [6480159.921066] client systemd-networkd[178]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6480159.921352] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6480159.921416] client systemd-networkd[178]: eth1: Link UP container-test-run-certificates> client # [6480159.921571] client systemd-networkd[178]: eth1: Gained carrier container-test-run-certificates> client # [6480159.922396] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6480159.941843] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6480160.173394] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6480160.176088] server systemd-resolved[126]: Positive Trust Anchors: container-test-run-certificates> server # [6480160.176099] server systemd-resolved[126]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6480160.176103] server systemd-resolved[126]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6480160.176121] server systemd-resolved[126]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6480160.188716] server systemd-resolved[126]: Using system hostname 'server'. container-test-run-certificates> server # [6480160.189890] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6480160.189974] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6480160.190047] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6480160.190091] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6480160.190317] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6480160.190342] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6480160.190361] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6480160.190379] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6480160.190486] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6480160.190553] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6480160.190652] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6480160.190674] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6480160.190702] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6480160.192838] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6480160.193622] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6480160.193664] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6480160.194601] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6480160.195629] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6480160.209413] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6480160.299510] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6480160.299510] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6480160.299926] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6480160.300501] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6480160.301400] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6480160.301436] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6480160.301436] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6480160.301436] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6480160.331838] server nsncd[194]: Aug 14 10:03:37.697 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6480160.331875] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6480160.331936] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6480160.331978] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6480160.332895] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6480160.333298] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6480160.339482] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6480160.339964] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6480160.339989] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6480160.340005] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6480160.425612] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6480160.426123] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6480160.426123] server dbus-broker-launch[195]: Invalid user-name in /nix/store/lv2ybi2iyvgvw7kwymvj2q0xss6yq3k7-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6480160.426435] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6480160.167275] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6480160.135240] ca systemd-resolved[119]: Positive Trust Anchors: container-test-run-certificates> ca # [6480160.135251] ca systemd-resolved[119]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6480160.135255] ca systemd-resolved[119]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6480160.135277] ca systemd-resolved[119]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6480160.147529] ca systemd-resolved[119]: Using system hostname 'ca'. container-test-run-certificates> ca # [6480160.148677] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6480160.148771] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6480160.148829] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6480160.148870] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6480160.149126] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6480160.149152] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6480160.149173] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6480160.149190] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6480160.149313] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6480160.149408] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6480160.149511] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6480160.149529] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6480160.149559] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6480160.150891] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6480160.151601] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6480160.151629] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6480160.152337] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6480160.153144] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6480160.172780] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6480160.192172] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6480160.205743] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6480160.286817] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6480160.286817] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6480160.287244] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6480160.287898] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6480160.289024] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6480160.289077] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6480160.289077] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6480160.289077] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6480160.317752] ca nsncd[203]: Aug 14 10:03:37.683 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6480160.317878] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6480160.317980] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6480160.318041] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6480160.318822] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6480160.319211] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6480160.330371] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6480160.330935] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6480160.330963] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6480160.330979] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6480160.448980] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6480160.449479] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6480160.449479] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/jcywaks9vp2cnydrgh0aixldiymc0mg6-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6480160.449782] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6480160.453465] ca dbus-broker-launch[205]: Ready container-test-run-certificates> server # [6480160.430037] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [6480160.442761] client systemd-resolved[111]: Positive Trust Anchors: container-test-run-certificates> client # [6480160.442773] client systemd-resolved[111]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6480160.442777] client systemd-resolved[111]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6480160.442803] client systemd-resolved[111]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6480160.454627] client systemd-resolved[111]: Using system hostname 'client'. container-test-run-certificates> client # [6480160.455597] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6480160.455649] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6480160.455683] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6480160.455715] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6480160.455730] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6480160.455741] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6480160.455836] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6480160.455915] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6480160.455994] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6480160.456014] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6480160.456035] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6480160.456964] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6480160.457347] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6480160.457918] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6480160.487803] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6480160.560940] client nsncd[189]: Aug 14 10:03:37.926 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6480160.561073] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6480160.561134] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6480160.561173] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6480160.561846] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6480160.562222] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6480160.581808] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6480160.582347] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6480160.582371] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6480160.582379] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6480160.683998] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6480160.684614] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6480160.684614] client dbus-broker-launch[190]: Invalid user-name in /nix/store/g0ax0f4rmfxkcx9lnwf8gpdq0a1by0nn-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6480160.685049] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6480160.690052] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [6480160.813303] server systemd-logind[224]: New seat seat0. container-test-run-certificates> ca # [6480160.838043] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [6480160.838204] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6480160.839312] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6480160.813503] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6480160.820717] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6480160.827920] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6480160.845546] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6480160.828031] server systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6480160.845650] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6480160.856654] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> ca # [6480160.867403] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> server # [6480160.856654] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6480160.856885] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6480160.863305] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6480160.865378] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6480160.867616] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6480160.867616] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6480160.874512] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6480160.875606] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6480160.958158] ca systemd-networkd[194]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6480160.993642] ca step-ca[204]: badger 2026/08/14 10:03:38 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6480160.995893] ca step-ca[204]: 2026/08/14 10:03:38 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6480160.998401] ca step-ca[204]: 2026/08/14 10:03:38 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [6480160.998401] ca step-ca[204]: 2026/08/14 10:03:38 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6480160.998401] ca step-ca[204]: 2026/08/14 10:03:38 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6480160.998401] ca step-ca[204]: 2026/08/14 10:03:38 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6480160.998506] ca step-ca[204]: 2026/08/14 10:03:38 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6480160.998506] ca step-ca[204]: 2026/08/14 10:03:38 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6480160.998506] ca step-ca[204]: 2026/08/14 10:03:38 X.509 Root Fingerprint: 85abd9a0ec732cb66824fa0911d7b6e7fdd7e783dbce106d488c9254319a01ad container-test-run-certificates> ca # [6480160.998635] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6480160.998768] ca step-ca[204]: 2026/08/14 10:03:38 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [6480161.013834] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6480161.014028] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6480161.015068] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6480161.022112] client systemd-networkd[178]: eth1: Gained IPv6LL container-test-run-certificates> client # [6480161.037094] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6480161.037319] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6480161.037656] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6480161.037784] client systemd[1]: Startup finished in 2.170s. container-test-run-certificates> ca # [6480161.286443] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6480161.287748] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6480161.287800] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6480161.291769] ca acme-ca.foo-start[282]: + cd ca.foo container-test-run-certificates> ca # [6480161.291930] ca acme-ca.foo-start[282]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6480161.292900] ca acme-ca.foo-start[283]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6480161.293175] ca acme-ca.foo-start[282]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6480161.293702] ca acme-ca.foo-start[282]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6480161.293820] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6480161.294973] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6480161.295893] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6480161.296946] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6480161.296946] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6480161.297020] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6480161.297902] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6480161.299614] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6480161.299614] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6480161.301692] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6480161.302504] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6480161.284417] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6480161.285859] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6480161.285880] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6480161.290391] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6480161.290601] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6480161.291112] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6480161.291238] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6480161.291831] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6480161.291954] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6480161.292884] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6480161.293693] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6480161.294990] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6480161.294990] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6480161.294990] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6480161.295894] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6480161.297719] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6480161.297719] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6480161.299374] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6480161.300499] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6480161.777537] ca nginx-pre-start[294]: nginx: the configuration file /nix/store/g0dx9m7v0w84pxjqh9php3sj30j8ghv0-nginx.conf syntax is ok container-test-run-certificates> ca # [6480161.777907] ca nginx-pre-start[294]: nginx: configuration file /nix/store/g0dx9m7v0w84pxjqh9php3sj30j8ghv0-nginx.conf test is successful container-test-run-certificates> ca # [6480161.780795] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6480161.781083] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6480161.781915] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6480161.725091] server systemd-networkd[179]: eth1: Gained IPv6LL container-test-run-certificates> server # [6480161.734823] server nginx-pre-start[267]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6480161.735325] server nginx-pre-start[267]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6480161.738131] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6480161.738528] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6480161.739690] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6480162.202750] ca acme-order-renew-ca.foo-start[297]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6480162.204186] ca acme-order-renew-ca.foo-start[297]: + set -euo pipefail container-test-run-certificates> ca # [6480162.204240] ca acme-order-renew-ca.foo-start[297]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6480162.204307] ca acme-order-renew-ca.foo-start[297]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6480162.205066] ca acme-order-renew-ca.foo-start[297]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6480162.215517] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6480162.215729] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6480162.227389] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration="95.941µs" duration-ns=95941 fields.time="2026-08-14T10:03:39Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=358d4658-bca1-41f0-87bb-563266c0429e response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.227673] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6480162.230640] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration=2.873622ms duration-ns=2873622 fields.time="2026-08-14T10:03:39Z" method=HEAD name=ca nonce=NFdqTEJmMDRxUDNaZjN4SU9NdjdJOUxiQ3pzdnVYV1k path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=bc001f1e-88cf-4030-bf18-805aaf962105 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.232584] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration=1.335595ms duration-ns=1335595 fields.time="2026-08-14T10:03:39Z" method=POST name=ca nonce=VHU3N0dKRWxPOEkwb1FNMEc1QjlFc2VLM2xEN1FhYUE path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=fd8145c3-a598-4300-928d-bb05f0e26efd response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/RzRlymv9WwS5BqLdwKKrh0rQdfqhY2jv/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: Your account credentials have been saved in your container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: configuration directory at "accounts". container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: configuration directory will also contain private keys container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6480162.232832] ca acme-order-renew-ca.foo-start[308]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6480162.232987] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6480162.235717] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration=2.489628ms duration-ns=2489628 fields.time="2026-08-14T10:03:39Z" method=POST name=ca nonce=RTlWM3VGNUxoOEQ2ejU0UHAzV05INGRKa0pxR2JwNmQ path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=18db0ee7-ea49-4624-b0ab-63548493ade9 response="{\"id\":\"jjX1oiXCwlsYEV3FzmLSBMobAQsnv2Zs\",\"status\":\"pending\",\"expires\":\"2026-08-15T10:03:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-14T10:02:39Z\",\"notAfter\":\"2026-11-12T10:03:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/jjX1oiXCwlsYEV3FzmLSBMobAQsnv2Zs/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.293588] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration="959.547µs" duration-ns=959547 fields.time="2026-08-14T10:03:39Z" method=POST name=ca nonce=bm90U1Z5bHI3a1BsbVBPVzVacFYxZFNJRVM1TmluRHQ path=/acme/acme/authz/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4669b779-0698-457d-b3b4-6087905bc345 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"SdldCMeWBRopIRU0EHn19M7nzl2mEto7\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw/A7S7q703dgWnuNVqZnKfKww1kXrejZ3n\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"SdldCMeWBRopIRU0EHn19M7nzl2mEto7\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw/svTuzwYm77vTX3nSIIooqcZCKvsSLQUP\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"SdldCMeWBRopIRU0EHn19M7nzl2mEto7\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw/8LMxH5JeoPV18si9ebl0ApZJEpNftPrh\"}],\"wildcard\":false,\"expires\":\"2026-08-15T10:03:39Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.293847] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw container-test-run-certificates> ca # [6480162.293847] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6480162.293906] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6480162.293906] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6480162.296294] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration=2.018001ms duration-ns=2018001 fields.time="2026-08-14T10:03:39Z" method=POST name=ca nonce=RTFGM2FxTEpXQ3JtSFlwNUpaV1VWd2U0VHptSnBaRkg path=/acme/acme/challenge/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw/svTuzwYm77vTX3nSIIooqcZCKvsSLQUP protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c98fbaf5-901f-4189-8caa-65e2c27c5469 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"SdldCMeWBRopIRU0EHn19M7nzl2mEto7\",\"validated\":\"2026-08-14T10:03:39Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw/svTuzwYm77vTX3nSIIooqcZCKvsSLQUP\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.296527] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6480162.296586] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6480162.299676] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info duration=2.587722ms duration-ns=2587722 fields.time="2026-08-14T10:03:39Z" method=POST name=ca nonce=VVZmMFhWQk5QUkdJNm5IQ3hsZU83SjBRS01VN3U4bDI path=/acme/acme/order/jjX1oiXCwlsYEV3FzmLSBMobAQsnv2Zs/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=51208f0b-ad25-4165-98eb-3e4b6970c738 response="{\"id\":\"jjX1oiXCwlsYEV3FzmLSBMobAQsnv2Zs\",\"status\":\"valid\",\"expires\":\"2026-08-15T10:03:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-14T10:02:39Z\",\"notAfter\":\"2026-11-12T10:03:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/QbVr06bZvKbvtAV4QaqHdtJ2xwwmF5Yw\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/jjX1oiXCwlsYEV3FzmLSBMobAQsnv2Zs/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/Ytni737GmQHAufBYv8E6hyemuXUh973E\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480162.300692] ca step-ca[204]: time="2026-08-14T10:03:39Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQRnKm8llpfERf/P7+7mDZmzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTQxMDAyMzlaFw0yNjExMTIxMDAzMzlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABPOabY81epxYcDpGy0850Oa0q7PLvZnw3Qxc5cf7hvex21FJ0BmwPU92DzrDM1JULytVyhnsglKAFI7pBweVNeCjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUqylJBQAyN+of0en5s1LS2iQFuuswHwYDVR0jBBgwFoAU9dxH3K3j82OJR2ClYlYUT1GB2/AwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEA6uZO8MLOdgNd0nSjVmojVsBCKLfFZTuJG71CcNfju5YCIBWCHlIdWls0TahWjdT1ztfResn4utXiPuozXLfuq4UZ duration="604.047µs" duration-ns=604047 fields.time="2026-08-14T10:03:39Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cU1LcmFaWTVqanRpNURiMG1NakZPM3J4TDVHc010elU path=/acme/acme/certificate/Ytni737GmQHAufBYv8E6hyemuXUh973E protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=8916e403-449a-46b2-b3c9-fcd903eb481b sans="map[dns:[ca.foo]]" serial=93641267627698306002077447209219053979 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-14T10:02:39Z" valid-to="2026-11-12T10:03:39Z" container-test-run-certificates> ca # [6480162.300887] ca acme-order-renew-ca.foo-start[308]: 2026/08/14 10:03:39 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6480162.303245] ca acme-order-renew-ca.foo-start[297]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6480162.304537] ca acme-order-renew-ca.foo-start[297]: + touch out/acme-success container-test-run-certificates> ca # [6480162.305416] ca acme-order-renew-ca.foo-start[297]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6480162.306006] ca acme-order-renew-ca.foo-start[297]: + touch out/renewed container-test-run-certificates> ca # [6480162.306802] ca acme-order-renew-ca.foo-start[297]: + echo Installing new certificate container-test-run-certificates> ca # [6480162.306802] ca acme-order-renew-ca.foo-start[297]: Installing new certificate container-test-run-certificates> ca # [6480162.306802] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6480162.307605] ca acme-order-renew-ca.foo-start[329]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6480162.307778] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6480162.308460] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6480162.308677] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6480162.309712] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6480162.309864] ca acme-order-renew-ca.foo-start[297]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6480162.310871] ca acme-order-renew-ca.foo-start[297]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6480162.312349] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6480162.312371] ca acme-order-renew-ca.foo-start[297]: + '[' -d out ']' container-test-run-certificates> ca # [6480162.312371] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6480162.313414] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx out container-test-run-certificates> ca # [6480162.315040] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6480162.315040] ca acme-order-renew-ca.foo-start[297]: + '[' -d certificates ']' container-test-run-certificates> ca # [6480162.315121] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6480162.316326] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6480162.317796] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6480162.429492] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6480162.433040] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6480162.433176] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server # [6480162.221853] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6480162.223486] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6480162.223527] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6480162.223581] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6480162.224257] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6480162.233520] server acme-order-renew-test.foo-start[282]: 2026/08/14 10:03:39 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6480162.233759] server acme-order-renew-test.foo-start[282]: 2026/08/14 10:03:39 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6480162.915757] ca nginx[347]: nginx: the configuration file /nix/store/g0dx9m7v0w84pxjqh9php3sj30j8ghv0-nginx.conf syntax is ok container-test-run-certificates> ca # [6480162.916124] ca nginx[347]: nginx: configuration file /nix/store/g0dx9m7v0w84pxjqh9php3sj30j8ghv0-nginx.conf test is successful container-test-run-certificates> server # [6480163.249312] server acme-order-renew-test.foo-start[282]: 2026/08/14 10:03:40 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6480163.251182] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6480163.251182] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6480163.251347] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6480163.252717] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6480163.252796] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6480163.252936] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6480163.253118] server systemd[1]: Startup finished in 4.378s. container-test-run-certificates> ca # [6480163.308648] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6480163.308830] ca systemd[1]: Startup finished in 4.432s. container-test-run-certificates> ca # [6480163.739754] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 2.62 seconds) container-test-run-certificates> ca # [6480164.085695] ca acme-order-renew-ca.foo-start[362]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6480164.087402] ca acme-order-renew-ca.foo-start[362]: + set -euo pipefail container-test-run-certificates> ca # [6480164.087460] ca acme-order-renew-ca.foo-start[362]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6480164.087492] ca acme-order-renew-ca.foo-start[362]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6480164.088132] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6480164.088132] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6480164.088380] ca acme-order-renew-ca.foo-start[370]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6480164.089719] ca acme-order-renew-ca.foo-start[362]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6480164.089719] ca acme-order-renew-ca.foo-start[362]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6480164.110518] ca step-ca[204]: time="2026-08-14T10:03:41Z" level=info duration="42.981µs" duration-ns=42981 fields.time="2026-08-14T10:03:41Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f3d71faf-870b-4666-95ba-825602c25580 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480164.110768] ca acme-order-renew-ca.foo-start[371]: 2026/08/14 10:03:41 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6480164.110768] ca acme-order-renew-ca.foo-start[371]: 2026/08/14 10:03:41 [INFO] [ca.foo] The certificate expires at 2026-11-12T10:03:39Z, the renewal can be performed in 1439h59m37.523637278s: no renewal. container-test-run-certificates> ca # [6480164.110898] ca acme-order-renew-ca.foo-start[362]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6480164.111727] ca acme-order-renew-ca.foo-start[362]: + touch out/acme-success container-test-run-certificates> ca # [6480164.112676] ca acme-order-renew-ca.foo-start[362]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6480164.113282] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6480164.113296] ca acme-order-renew-ca.foo-start[362]: + '[' -d out ']' container-test-run-certificates> ca # [6480164.113296] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6480164.114170] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx out container-test-run-certificates> ca # [6480164.115634] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6480164.115634] ca acme-order-renew-ca.foo-start[362]: + '[' -d certificates ']' container-test-run-certificates> ca # [6480164.115664] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6480164.116367] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6480164.117600] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6480164.197773] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6480164.197946] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6480167.207023] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6480167.207104] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6480167.207755] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6480167.208688] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.36 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:03:38 2026 GMT container-test-run-certificates> * expire date: Sep 13 10:03:38 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0a3724 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6480167.548089] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6480167.549904] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6480167.549904] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6480167.554504] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [6480167.554655] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6480167.555574] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6480167.555728] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6480167.556592] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6480167.556771] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6480167.557764] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6480167.558604] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6480167.559678] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6480167.559703] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [6480167.559703] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6480167.560602] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [6480167.561823] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6480167.561823] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [6480167.563380] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6480167.564620] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6480167.904943] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6480167.906729] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> server # [6480167.906779] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6480167.906856] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6480167.907697] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6480167.929032] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6480167.932089] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6480167.932209] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6480167.992396] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA container-test-run-certificates> server # [6480167.992396] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6480167.992396] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6480167.992396] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6480167.995249] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6480167.995304] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6480167.999292] server acme-order-renew-test.foo-start[331]: 2026/08/14 10:03:45 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6480168.001646] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6480168.002731] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [6480168.003486] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6480168.004024] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [6480168.004727] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [6480168.004727] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [6480168.004750] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6480168.005407] server acme-order-renew-test.foo-start[350]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6480168.005540] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6480168.006205] server acme-order-renew-test.foo-start[351]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6480168.006322] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6480168.007268] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6480168.007374] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6480168.008131] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6480168.008924] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6480168.008934] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [6480168.008934] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6480168.009716] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [6480168.011179] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6480168.011195] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [6480168.011195] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6480168.011979] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6480168.013103] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6480168.086989] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6480168.088795] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6480168.088892] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [6480167.928795] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration="35.006µs" duration-ns=35006 fields.time="2026-08-14T10:03:45Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=456066b5-6d93-454c-8158-cdf5f723152c response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.930528] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration="592.125µs" duration-ns=592125 fields.time="2026-08-14T10:03:45Z" method=HEAD name=ca nonce=NFpUOVdKZzlwNEtDUERRRjRtSTJQV1p5YjlIZlJaS3A path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=a0ace942-081e-47fe-93e3-e0fd9f1b7082 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.931933] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration="641.919µs" duration-ns=641919 fields.time="2026-08-14T10:03:45Z" method=POST name=ca nonce=dGNTZVVieHgzQzNwREFVUnZkRU5TcGZmNVhtcFNjMkM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=ba4ded52-e205-472c-90e9-561e0665367f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/YwMrdAXRRZjbmiLcbKAXOcsP2XjQzHzK/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.933928] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration=1.202314ms duration-ns=1202314 fields.time="2026-08-14T10:03:45Z" method=POST name=ca nonce=QUhqYXVjM1lZaXB3UUdxZ010T3NFbTJzVUdWUDU2S2Y path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=5de280d6-5f48-42fe-9e56-8d00f48664c0 response="{\"id\":\"lN9FK0Sac5urinHH679nAkHT4f7KW9DC\",\"status\":\"pending\",\"expires\":\"2026-08-15T10:03:45Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-14T10:02:45Z\",\"notAfter\":\"2026-11-12T10:03:45Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA\"],\"finalize\":\"https://ca.foo/acme/acme/order/lN9FK0Sac5urinHH679nAkHT4f7KW9DC/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.992099] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration="574.151µs" duration-ns=574151 fields.time="2026-08-14T10:03:45Z" method=POST name=ca nonce=QVB0RDlxVFJJSmQySVJ0WThvbEZxUUM3UUhJdzVyd1k path=/acme/acme/authz/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA protocol=HTTP/1.1 referer= remote-address="::1" request-id=6788513f-d1d9-4218-89e0-a93d1289552c response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"W84xCBy4uBgTRLvzdoAEIuadXJuRAz34\",\"url\":\"https://ca.foo/acme/acme/challenge/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA/TY5vayD6wniiWm4PQgUs44yY96MFobrQ\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"W84xCBy4uBgTRLvzdoAEIuadXJuRAz34\",\"url\":\"https://ca.foo/acme/acme/challenge/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA/oY3GK27m65vCFcohlSZY3WHSlDFhlxaa\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"W84xCBy4uBgTRLvzdoAEIuadXJuRAz34\",\"url\":\"https://ca.foo/acme/acme/challenge/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA/Ps8GbOWeSSNCpbinIvBBV0daEO36YsQp\"}],\"wildcard\":false,\"expires\":\"2026-08-15T10:03:45Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.994996] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration=1.724247ms duration-ns=1724247 fields.time="2026-08-14T10:03:45Z" method=POST name=ca nonce=WlBtS1BERWIzZ29pczdqaXNGWFpRRUswRkp6Q0RLaGU path=/acme/acme/challenge/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA/oY3GK27m65vCFcohlSZY3WHSlDFhlxaa protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=3cfe3b9f-e4c2-49c8-a306-83c9edf55b8b response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"W84xCBy4uBgTRLvzdoAEIuadXJuRAz34\",\"validated\":\"2026-08-14T10:03:45Z\",\"url\":\"https://ca.foo/acme/acme/challenge/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA/oY3GK27m65vCFcohlSZY3WHSlDFhlxaa\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.997969] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info duration=1.750386ms duration-ns=1750386 fields.time="2026-08-14T10:03:45Z" method=POST name=ca nonce=SmtRZ0tOTHVjbGZMYTVHOWZFTWpEVFVIZmIwMEJyaEE path=/acme/acme/order/lN9FK0Sac5urinHH679nAkHT4f7KW9DC/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=1bf1df4e-e224-4ffe-8975-309b97d32cc4 response="{\"id\":\"lN9FK0Sac5urinHH679nAkHT4f7KW9DC\",\"status\":\"valid\",\"expires\":\"2026-08-15T10:03:45Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-14T10:02:45Z\",\"notAfter\":\"2026-11-12T10:03:45Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/h1wiAiMepdCtQyHuUFMb7SPxgG6FQajA\"],\"finalize\":\"https://ca.foo/acme/acme/order/lN9FK0Sac5urinHH679nAkHT4f7KW9DC/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/jo0Gh7ZtW6VpTWLlobqWJCPkJewnR3Lq\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6480167.999159] ca step-ca[204]: time="2026-08-14T10:03:45Z" level=info certificate="MIIB1zCCAX6gAwIBAgIRAOKfk76CwYfGeruMsP9x/uMwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE0MTAwMjQ1WhcNMjYxMTEyMTAwMzQ1WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABGs1lWo5+acNnyeVupfVEtWIwipvQnOlAAfQdocQiny+2BwDQEwTq1pHjXra4KxTxILf6EiWHVQNTVq8u9bpoRSjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU5VDaK9c1ppuCTEtM/snpfOXEEyEwHwYDVR0jBBgwFoAU9dxH3K3j82OJR2ClYlYUT1GB2/AwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0cAMEQCIExlZt+6qGPd39I+F97blGnuqrIasUac1bZm5xdM0IObAiB2coD2aOgi23aHU5lj10FA0aG35hWfmSJBpFVuIi5XEw==" duration="416.955µs" duration-ns=416955 fields.time="2026-08-14T10:03:45Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=THg5Q2VMcWJKMThRVzFnd253SDhMcUhjUGVHYk96ZFI path=/acme/acme/certificate/jo0Gh7ZtW6VpTWLlobqWJCPkJewnR3Lq protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=2fb001b0-fbe5-4be4-8dfe-64b4537e8a26 sans="map[dns:[test.foo]]" serial=301234098855927654515708020905628270307 size=1352 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-14T10:02:45Z" valid-to="2026-11-12T10:03:45Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:03:38 2026 GMT container-test-run-certificates> * expire date: Sep 13 10:03:38 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0a3724 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6480168.437772] server nginx[368]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6480168.438043] server nginx[368]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6480168.781916] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [78 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 14 10:02:45 2026 GMT container-test-run-certificates> * expire date: Nov 12 10:03:45 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 60630 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1876 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> e2:9f:93:be:82:c1:87:c6:7a:bb:8c:b0:ff:71:fe:e3 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 14 10:02:45 2026 GMT container-test-run-certificates> Not After : Nov 12 10:03:45 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:6b:35:95:6a:39:f9:a7:0d:9f:27:95:ba:97:d5: container-test-run-certificates> 12:d5:88:c2:2a:6f:42:73:a5:00:07:d0:76:87:10: container-test-run-certificates> 8a:7c:be:d8:1c:03:40:4c:13:ab:5a:47:8d:7a:da: container-test-run-certificates> e0:ac:53:c4:82:df:e8:48:96:1d:54:0d:4d:5a:bc: container-test-run-certificates> bb:d6:e9:a1:14 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> E5:50:DA:2B:D7:35:A6:9B:82:4C:4B:4C:FE:C9:E9:7C:E5:C4:13:21 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> F5:DC:47:DC:AD:E3:F3:63:89:47:60:A5:62:56:14:4F:51:81:DB:F0 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:4c:65:66:df:ba:a8:63:dd:df:d2:3e:17:de:db: container-test-run-certificates> 94:69:ee:aa:b2:1a:b1:46:9c:d5:b6:66:e7:17:4c:d0:83:9b: container-test-run-certificates> 02:20:76:72:80:f6:68:e8:22:db:76:87:53:99:63:d7:41:40: container-test-run-certificates> d1:a1:b7:e6:15:9f:99:22:41:a4:55:6e:22:2e:57:13 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 11.07 seconds) container-test-run-certificates> test script finished in 11.20s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-14T10:03:47.771Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-14T10:03:48.122Z level=INFO msg="Uploading 1 narinfos" time=2026-08-14T10:03:48.847Z level=INFO msg="Upload complete. (1.165s)"