these 97 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv /nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv /nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv /nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv /nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv /nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv /nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv /nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv /nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/y37smfm18fsf3y82w5ws00qa8cfib0gn-system-path.drv /nix/store/cz710laxjins4p2h5f454xlvyhxd2pnr-dbus-1.drv /nix/store/36rdi59h65dzw37b9nwsd3h22xgvk9pf-X-Restart-Triggers-dbus-broker.drv /nix/store/d5wav7y990vifvf36rawbk84glbk8z3r-unit-dbus-broker.service.drv /nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv /nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv /nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv /nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/b8v4n5mjnvp4na4jamc2m58lyphalw2c-system-units.drv /nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/m2k8zda8pv8xc5hh7wpcp8mzshlgmkcn-unit-dbus-broker.service.drv /nix/store/hlvl5mjwv0r4nsf5ny9rw06vqyln9i1y-user-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/24zpbp058cbyk9szvii77a2i0m9vy8d6-etc.drv /nix/store/rdnrxv2a04ws792wyvvrg6xwwwcpv1mk-system-path.drv /nix/store/xjhb50h3nrcg7dv6cgzg3g6vdfdwa52r-dbus-1.drv /nix/store/kwxpg8872m49xkp7s3gzp44z607q5apc-X-Restart-Triggers-dbus-broker.drv /nix/store/pn055kafbhbkc2i317fklfa77hwhb78q-unit-dbus-broker.service.drv /nix/store/3921dn8735naqax6b1r137mkmh77g2z9-user-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/p38ds1kkxy936lj1phr4wjzjyirp4irk-unit-dbus-broker.service.drv /nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv /nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv /nix/store/d58424m1bk3jxp9nkrzn481rdjl7nssx-system-units.drv /nix/store/fh9vy0nr7pscc2qm63zqjhnyrmxd9qly-etc.drv /nix/store/n8a880m0s4wa0nr29hq6pylal41ps55j-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/x9h0n6h9qjpz8j67kjxs9p58kg94asfp-nixos-system-server-test.drv /nix/store/53xmgr31x1zdp5ngwxydj5nrln6kb8b4-run-server-nspawn.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/r5yp49sikplw82svwi9jpgzr8r083yy5-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/wwpclabg4xlmyrwpwrjmyv0f60hjlwmh-nixos-system-ca-test.drv /nix/store/amsznx5749f035p181mnwzm33vhmnnky-run-ca-nspawn.drv /nix/store/sidw340179706sq5nn0vcgbiy6fiysdf-system-path.drv /nix/store/hkgi3qjkvz2480izgs9lr8ai8h0fvv9m-dbus-1.drv /nix/store/z96h6f3sw18q4p4p460y1478c2ix57i2-X-Restart-Triggers-dbus-broker.drv /nix/store/xxz15skk85mw7x9r5708zaxld7barxbr-unit-dbus-broker.service.drv /nix/store/63cmqd8g5f5wixabwv8v3c0a7pc09pra-user-units.drv /nix/store/gcn9b4wn0x93myydhyww8gai01bi0qx5-unit-dbus-broker.service.drv /nix/store/f4nsj3fcl9zm4wsaxazcbsfsfy4c99i8-system-units.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/nbi2zgpq4f28nn26kg4w9aj80cd670g2-etc.drv /nix/store/f7fvl61qqik5md7cfh5fxic7s8qj6434-activate.drv /nix/store/sfjipclaqm3i6qx0fjg5rpp1id7k2hgw-nixos-system-client-test.drv /nix/store/ap0ry8hklrm8bmwp2l8v6kng6np2z4w8-run-client-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/71g0bwqwbqii5rpzz6vg7h5zx11h5p0d-driverConfiguration.json.drv /nix/store/2ycfcj37nxaamrd5s9zdyhjknxmjskh5-nixos-test-driver-certificates.drv /nix/store/9jag0zy00jr65lakqdgj40q25fli20kd-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 75.8 MiB unpacked): /nix/store/qfjhplgaj6zn71pd29p28wxngj5l4bys-openssl-3.6.3-man /nix/store/fwwgviqhlwxaigb610fvpiciz2di7wjg-python3.14-buildcatrust-0.5.1 /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv' building '/nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv' building '/nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' building '/nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' ca.json> structuredAttrs is enabled building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv' building '/nix/store/rdnrxv2a04ws792wyvvrg6xwwwcpv1mk-system-path.drv' building '/nix/store/sidw340179706sq5nn0vcgbiy6fiysdf-system-path.drv' building '/nix/store/y37smfm18fsf3y82w5ws00qa8cfib0gn-system-path.drv' building '/nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' system-path> created 1723 symlinks in user environment system-path> created 1723 symlinks in user environment unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv' building '/nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv' building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled building '/nix/store/xjhb50h3nrcg7dv6cgzg3g6vdfdwa52r-dbus-1.drv' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' building '/nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/cz710laxjins4p2h5f454xlvyhxd2pnr-dbus-1.drv' building '/nix/store/hkgi3qjkvz2480izgs9lr8ai8h0fvv9m-dbus-1.drv' building '/nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv' building '/nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv' unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/36rdi59h65dzw37b9nwsd3h22xgvk9pf-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/kwxpg8872m49xkp7s3gzp44z607q5apc-X-Restart-Triggers-dbus-broker.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/z96h6f3sw18q4p4p460y1478c2ix57i2-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/d5wav7y990vifvf36rawbk84glbk8z3r-unit-dbus-broker.service.drv' building '/nix/store/m2k8zda8pv8xc5hh7wpcp8mzshlgmkcn-unit-dbus-broker.service.drv' building '/nix/store/p38ds1kkxy936lj1phr4wjzjyirp4irk-unit-dbus-broker.service.drv' building '/nix/store/pn055kafbhbkc2i317fklfa77hwhb78q-unit-dbus-broker.service.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/gcn9b4wn0x93myydhyww8gai01bi0qx5-unit-dbus-broker.service.drv' building '/nix/store/xxz15skk85mw7x9r5708zaxld7barxbr-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/hlvl5mjwv0r4nsf5ny9rw06vqyln9i1y-user-units.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3921dn8735naqax6b1r137mkmh77g2z9-user-units.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/63cmqd8g5f5wixabwv8v3c0a7pc09pra-user-units.drv' building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed building '/nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/b8v4n5mjnvp4na4jamc2m58lyphalw2c-system-units.drv' building '/nix/store/d58424m1bk3jxp9nkrzn481rdjl7nssx-system-units.drv' building '/nix/store/f4nsj3fcl9zm4wsaxazcbsfsfy4c99i8-system-units.drv' building '/nix/store/24zpbp058cbyk9szvii77a2i0m9vy8d6-etc.drv' building '/nix/store/fh9vy0nr7pscc2qm63zqjhnyrmxd9qly-etc.drv' building '/nix/store/nbi2zgpq4f28nn26kg4w9aj80cd670g2-etc.drv' building '/nix/store/r5yp49sikplw82svwi9jpgzr8r083yy5-activate.drv' building '/nix/store/wwpclabg4xlmyrwpwrjmyv0f60hjlwmh-nixos-system-ca-test.drv' building '/nix/store/f7fvl61qqik5md7cfh5fxic7s8qj6434-activate.drv' building '/nix/store/n8a880m0s4wa0nr29hq6pylal41ps55j-activate.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/amsznx5749f035p181mnwzm33vhmnnky-run-ca-nspawn.drv' building '/nix/store/sfjipclaqm3i6qx0fjg5rpp1id7k2hgw-nixos-system-client-test.drv' building '/nix/store/x9h0n6h9qjpz8j67kjxs9p58kg94asfp-nixos-system-server-test.drv' nixos-system-client-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/ap0ry8hklrm8bmwp2l8v6kng6np2z4w8-run-client-nspawn.drv' building '/nix/store/53xmgr31x1zdp5ngwxydj5nrln6kb8b4-run-server-nspawn.drv' building '/nix/store/71g0bwqwbqii5rpzz6vg7h5zx11h5p0d-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/2ycfcj37nxaamrd5s9zdyhjknxmjskh5-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/9jag0zy00jr65lakqdgj40q25fli20kd-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/9jag0zy00jr65lakqdgj40q25fli20kd-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> client # [6566548.353689] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6566548.359106] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [6566548.353715] client systemd-journald[69]: Runtime Journal (/run/log/journal/b8150c97bc49461cbf08237cde8c7eab) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [6566548.359131] ca systemd-journald[78]: Runtime Journal (/run/log/journal/3c9059be1c89499bb93c3893f230719b) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6566548.354650] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6566548.363418] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6566548.352396] server systemd-journald[69]: Journal started container-test-run-certificates> ca # [6566548.371331] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6566548.358817] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6566548.352427] server systemd-journald[69]: Runtime Journal (/run/log/journal/12a04e3829734abeb0539ccf84e139c3) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6566548.364063] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6566548.355001] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6566548.371852] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6566548.364401] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6566548.360461] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6566548.364688] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6566548.372371] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6566548.360929] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6566548.375643] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/3c9059be1c89499bb93c3893f230719b is 1.261ms for 6 entries. container-test-run-certificates> client # [6566548.368656] client systemd-journald[69]: Time spent on flushing to /var/log/journal/b8150c97bc49461cbf08237cde8c7eab is 1.025ms for 7 entries. container-test-run-certificates> ca # [6566548.375643] ca systemd-journald[78]: System Journal (/var/log/journal/3c9059be1c89499bb93c3893f230719b) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6566548.361281] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6566548.368656] client systemd-journald[69]: System Journal (/var/log/journal/b8150c97bc49461cbf08237cde8c7eab) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6566548.381880] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6566548.374828] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6566548.367375] server systemd-journald[69]: Time spent on flushing to /var/log/journal/12a04e3829734abeb0539ccf84e139c3 is 1.206ms for 6 entries. container-test-run-certificates> client # [6566548.375050] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6566548.367375] server systemd-journald[69]: System Journal (/var/log/journal/12a04e3829734abeb0539ccf84e139c3) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6566548.375678] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6566548.382038] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6566548.375754] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6566548.370912] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6566548.382103] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6566548.382541] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6566548.376238] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6566548.371468] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6566548.382573] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6566548.371530] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6566548.376266] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6566548.372110] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6566548.383148] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6566548.377012] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6566548.383170] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6566548.377397] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6566548.387440] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6566548.372141] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6566548.377414] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6566548.372658] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6566548.387860] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6566548.372675] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6566548.396616] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6566548.374604] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6566548.390118] client systemd-tmpfiles[114]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6566548.375159] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6566548.399300] ca systemd-tmpfiles[126]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6566548.390268] client systemd-tmpfiles[114]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6566548.399457] ca systemd-tmpfiles[126]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6566548.391248] server systemd-tmpfiles[113]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6566548.390373] client systemd-tmpfiles[114]: fchmod() of /var/log/journal/b8150c97bc49461cbf08237cde8c7eab failed: Operation not permitted container-test-run-certificates> ca # [6566548.399558] ca systemd-tmpfiles[126]: fchmod() of /var/log/journal/3c9059be1c89499bb93c3893f230719b failed: Operation not permitted container-test-run-certificates> server # [6566548.391436] server systemd-tmpfiles[113]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6566548.390525] client systemd-tmpfiles[114]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6566548.391543] server systemd-tmpfiles[113]: fchmod() of /var/log/journal/12a04e3829734abeb0539ccf84e139c3 failed: Operation not permitted container-test-run-certificates> ca # [6566548.399706] ca systemd-tmpfiles[126]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6566548.392594] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6566548.400846] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6566548.391698] server systemd-tmpfiles[113]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6566548.393365] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6566548.394248] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6566548.401516] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6566548.395623] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6566548.393726] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6566548.396293] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6566548.401857] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6566548.397130] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6566548.397241] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6566548.409037] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6566548.404590] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6566548.415746] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6566548.402103] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6566548.416330] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6566548.405765] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6566548.408722] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6566548.423557] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6566548.406526] client systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6566548.452985] ca systemd[1]: Finished Firewall. container-test-run-certificates> server # [6566548.409437] server systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6566548.411683] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6566548.441434] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6566548.441527] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6566548.441669] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6566548.442262] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6566548.453175] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6566548.453306] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6566548.414926] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6566548.742028] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6566548.454783] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6566548.742101] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6566548.446676] server systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6566548.749196] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6566548.747664] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6566548.749271] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6566548.446790] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6566548.754516] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6566548.747808] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6566548.754655] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6566548.446945] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6566548.754738] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> server # [6566548.447526] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6566548.747883] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> server # [6566548.737346] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6566548.747888] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> server # [6566548.737433] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6566548.743631] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6566548.743828] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6566548.748028] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6566548.743957] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> ca # [6566548.754740] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> client # [6566548.748276] client systemd[1]: Started Network Management. container-test-run-certificates> server # [6566548.743961] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> ca # [6566548.754885] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6566548.768282] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6566548.755111] ca systemd[1]: Started Network Management. container-test-run-certificates> server # [6566548.744162] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6566548.768312] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> ca # [6566548.768264] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> client # [6566548.768550] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> ca # [6566548.768317] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6566548.744511] server systemd[1]: Started Network Management. container-test-run-certificates> client # [6566548.795690] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6566548.768539] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> server # [6566548.744589] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> ca # [6566548.788882] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6566548.744593] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [6566548.745471] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6566548.773835] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6566548.928363] server systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> server # [6566548.928372] server systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6566548.928377] server systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6566548.928404] server systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6566548.941557] server systemd-resolved[93]: Using system hostname 'server'. container-test-run-certificates> server # [6566548.942612] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6566548.942667] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6566548.942702] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6566548.942734] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6566548.942892] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6566548.942909] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6566548.942922] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6566548.942933] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6566548.943044] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6566548.943122] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6566548.943209] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6566548.943221] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6566548.943243] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6566548.967683] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6566548.968321] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6566548.968348] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6566548.969026] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6566548.969953] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6566548.980357] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6566549.035560] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6566549.035560] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6566549.035560] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6566548.940210] ca systemd-resolved[104]: Positive Trust Anchors: container-test-run-certificates> ca # [6566548.940219] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6566548.940224] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6566548.940249] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6566548.952524] ca systemd-resolved[104]: Using system hostname 'ca'. container-test-run-certificates> ca # [6566548.953561] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6566548.953622] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6566548.953662] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6566548.953687] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6566548.953853] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6566548.953869] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6566548.953884] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6566548.953896] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6566548.953979] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6566548.954060] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6566548.954160] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6566548.954176] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6566548.954201] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6566548.967681] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6566548.968334] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6566548.968362] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6566548.969062] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6566548.969761] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6566548.970564] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6566548.980377] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6566549.038017] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6566549.038017] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6566549.038017] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [6566548.924656] client systemd-resolved[96]: Positive Trust Anchors: container-test-run-certificates> client # [6566548.924670] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6566548.924673] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6566548.924698] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6566548.937278] client systemd-resolved[96]: Using system hostname 'client'. container-test-run-certificates> client # [6566548.938526] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6566548.938610] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6566548.938666] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6566548.938710] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6566548.938733] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6566548.938747] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6566548.938868] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6566548.938977] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6566548.939093] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6566548.939109] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6566548.939137] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6566548.940217] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6566548.940784] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6566548.941621] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6566548.977368] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6566549.060893] client nsncd[189]: Aug 15 10:03:26.426 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6566549.060914] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6566549.060951] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6566549.060980] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6566549.036540] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6566549.037443] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> client # [6566549.067590] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6566549.068027] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6566549.037460] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> client # [6566549.073315] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6566549.037474] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> client # [6566549.073867] client systemd[1]: Started Console Getty. container-test-run-certificates> server # [6566549.037474] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> client # [6566549.073889] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6566549.058460] server nsncd[194]: Aug 15 10:03:26.424 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6566549.073900] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6566549.058548] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6566549.134253] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6566549.058604] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6566549.058643] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6566549.067592] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6566549.068104] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6566549.073225] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6566549.073858] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6566549.073880] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6566549.073892] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6566549.126544] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6566549.126958] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6566549.126958] server dbus-broker-launch[195]: Invalid user-name in /nix/store/lv2ybi2iyvgvw7kwymvj2q0xss6yq3k7-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6566549.127311] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6566549.133192] server dbus-broker-launch[195]: Ready container-test-run-certificates> server # [6566549.346118] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6566549.134582] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6566549.134582] client dbus-broker-launch[190]: Invalid user-name in /nix/store/g0ax0f4rmfxkcx9lnwf8gpdq0a1by0nn-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6566549.134801] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6566549.140391] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [6566549.346271] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6566549.039245] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6566549.040219] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6566549.040259] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6566549.040259] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6566549.040259] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6566549.069069] ca nsncd[203]: Aug 15 10:03:26.434 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6566549.069074] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6566549.069127] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6566549.069170] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6566549.070038] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6566549.070414] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6566549.077344] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6566549.078297] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6566549.078325] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6566549.078344] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6566549.142052] ca dbus-broker-launch[206]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6566549.142316] ca dbus-broker-launch[206]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6566549.142316] ca dbus-broker-launch[206]: Invalid user-name in /nix/store/jcywaks9vp2cnydrgh0aixldiymc0mg6-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6566549.142548] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6566549.145805] ca dbus-broker-launch[206]: Ready container-test-run-certificates> ca # [6566549.354796] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6566549.442688] server systemd-logind[221]: New seat seat0. container-test-run-certificates> server # [6566549.442826] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6566549.443797] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6566549.471508] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6566549.471508] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6566549.471864] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6566549.477964] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6566549.478093] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6566549.478363] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6566549.479458] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [6566549.443399] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6566549.443532] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6566549.444569] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6566549.478084] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6566549.478132] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6566549.478344] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6566549.478433] client systemd[1]: Startup finished in 1.390s. container-test-run-certificates> ca # [6566549.442560] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [6566549.442691] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6566549.443651] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6566549.452598] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6566549.452598] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6566549.452598] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6566549.472148] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6566549.473307] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6566549.478080] ca systemd[1]: linger-users.service: Failed to kill control group /system.slice/linger-users.service, ignoring: No such device container-test-run-certificates> ca # [6566549.478118] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6566549.478176] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6566549.588280] ca step-ca[204]: badger 2026/08/15 10:03:26 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6566549.590037] ca step-ca[204]: 2026/08/15 10:03:26 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6566549.592014] ca step-ca[204]: 2026/08/15 10:03:26 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [6566549.592014] ca step-ca[204]: 2026/08/15 10:03:26 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6566549.592014] ca step-ca[204]: 2026/08/15 10:03:26 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6566549.592058] ca step-ca[204]: 2026/08/15 10:03:26 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6566549.592058] ca step-ca[204]: 2026/08/15 10:03:26 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6566549.592058] ca step-ca[204]: 2026/08/15 10:03:26 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6566549.592058] ca step-ca[204]: 2026/08/15 10:03:26 X.509 Root Fingerprint: 90684bcb39b6e8783b3f83954046135bdf820e4b218433502254a072081f4e5b container-test-run-certificates> ca # [6566549.592155] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6566549.592214] ca step-ca[204]: 2026/08/15 10:03:26 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6566549.833990] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6566549.835403] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6566549.835403] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6566549.839543] server acme-test.foo-start[256]: + cd test.foo container-test-run-certificates> server # [6566549.839713] server acme-test.foo-start[256]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6566549.840337] server acme-test.foo-start[257]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6566549.840454] server acme-test.foo-start[256]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6566549.841038] server acme-test.foo-start[256]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6566549.841148] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6566549.842157] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6566549.842968] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6566549.843761] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6566549.843761] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6566549.843808] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6566549.844513] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6566549.846353] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6566549.846353] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6566549.867091] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6566549.867846] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6566549.828046] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6566549.829432] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6566549.829471] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6566549.834030] ca acme-ca.foo-start[284]: + cd ca.foo container-test-run-certificates> ca # [6566549.834205] ca acme-ca.foo-start[284]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6566549.834820] ca acme-ca.foo-start[285]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6566549.834932] ca acme-ca.foo-start[284]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6566549.835533] ca acme-ca.foo-start[284]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6566549.835649] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6566549.836448] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6566549.837890] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6566549.838924] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6566549.838924] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6566549.838970] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6566549.839754] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6566549.841373] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6566549.841396] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6566549.843185] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6566549.844251] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6566550.013101] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> client # [6566550.077089] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6566550.218296] ca nginx-pre-start[296]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6566550.218599] ca nginx-pre-start[296]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6566550.234267] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6566550.234611] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6566550.235435] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6566550.142077] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> server # [6566550.212381] server nginx-pre-start[268]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6566550.212670] server nginx-pre-start[268]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6566550.215411] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6566550.215718] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6566550.216850] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6566550.596882] server acme-order-renew-test.foo-start[271]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6566550.598294] server acme-order-renew-test.foo-start[271]: + set -euo pipefail container-test-run-certificates> server # [6566550.598333] server acme-order-renew-test.foo-start[271]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6566550.598389] server acme-order-renew-test.foo-start[271]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6566550.598973] server acme-order-renew-test.foo-start[271]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6566550.607273] server acme-order-renew-test.foo-start[282]: 2026/08/15 10:03:27 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6566550.607624] server acme-order-renew-test.foo-start[282]: 2026/08/15 10:03:27 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6566550.622635] server acme-order-renew-test.foo-start[282]: 2026/08/15 10:03:27 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6566550.622893] server acme-order-renew-test.foo-start[271]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6566550.622893] server acme-order-renew-test.foo-start[271]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6566550.622893] server acme-order-renew-test.foo-start[271]: + exit 10 container-test-run-certificates> server # [6566550.624812] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6566550.624924] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6566550.625317] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6566550.625553] server systemd[1]: Startup finished in 2.536s. container-test-run-certificates> ca # [6566550.592132] ca acme-order-renew-ca.foo-start[299]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6566550.593922] ca acme-order-renew-ca.foo-start[299]: + set -euo pipefail container-test-run-certificates> ca # [6566550.593964] ca acme-order-renew-ca.foo-start[299]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6566550.594023] ca acme-order-renew-ca.foo-start[299]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6566550.594846] ca acme-order-renew-ca.foo-start[299]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6566550.603978] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:27 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6566550.604201] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:27 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6566550.617892] ca step-ca[204]: time="2026-08-15T10:03:27Z" level=info duration="80.061µs" duration-ns=80061 fields.time="2026-08-15T10:03:27Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=01fbed0a-732a-4d5f-a750-226c3cff526d response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.618330] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:27 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6566550.618785] ca step-ca[204]: time="2026-08-15T10:03:27Z" level=info duration="599.98µs" duration-ns=599980 fields.time="2026-08-15T10:03:27Z" method=HEAD name=ca nonce=QkRhVWR0bFRQTmhpalB6bU5JMEFRd1BsRDBSRmpnVUM path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a2db7e94-09b4-45e8-8ee0-c87137ee9de5 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.619941] ca step-ca[204]: time="2026-08-15T10:03:27Z" level=info duration="852.887µs" duration-ns=852887 fields.time="2026-08-15T10:03:27Z" method=POST name=ca nonce=Tkk5TkNLQVhuczRsblc3eW1GV1pQQW1LNDVxTkVaRVA path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c16fec8a-9dbd-41c3-96cf-ae2fceaffad3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/nzIOZvqfFL1RxWxcstk9CGANzXHj2SzN/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: Your account credentials have been saved in your container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: configuration directory at "accounts". container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: configuration directory will also contain private keys container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6566550.620113] ca acme-order-renew-ca.foo-start[311]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6566550.620236] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:27 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6566550.621946] ca step-ca[204]: time="2026-08-15T10:03:27Z" level=info duration=1.596807ms duration-ns=1596807 fields.time="2026-08-15T10:03:27Z" method=POST name=ca nonce=YlEzTU8ydjZ5VHlaOXZZZGZCYmVuOXkyMEtYZ1pXQ3c path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=865fe60d-63fa-4be0-82aa-a7d284f3f74b response="{\"id\":\"Nhtie8NjBs3JTPTGxKHfgxsa6oXd2X6s\",\"status\":\"pending\",\"expires\":\"2026-08-16T10:03:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-15T10:02:27Z\",\"notAfter\":\"2026-11-13T10:03:27Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Nhtie8NjBs3JTPTGxKHfgxsa6oXd2X6s/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.679684] ca step-ca[204]: time="2026-08-15T10:03:28Z" level=info duration="760.963µs" duration-ns=760963 fields.time="2026-08-15T10:03:28Z" method=POST name=ca nonce=SE13Qm1WYW9pREo0aE82QVdhZ2RldFBkZVFyaFFhVlo path=/acme/acme/authz/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8837b85b-2551-4587-85d7-6e36b99fa4e5 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"Xhu6qFRyc1MoSIWmQSI5eLPLPEOEgyWG\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW/Q58snxIYtCWjJsgdjgpdLiXg8Y1PP0fm\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"Xhu6qFRyc1MoSIWmQSI5eLPLPEOEgyWG\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW/FHUBvBbqotQq3umqQzXFS35V6ILxu3BV\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"Xhu6qFRyc1MoSIWmQSI5eLPLPEOEgyWG\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW/PC71cPG3stX5GuipBHvKbLe5i8q3qiUt\"}],\"wildcard\":false,\"expires\":\"2026-08-16T10:03:27Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.679913] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW container-test-run-certificates> ca # [6566550.679913] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6566550.679913] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6566550.679980] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6566550.681980] ca step-ca[204]: time="2026-08-15T10:03:28Z" level=info duration=1.805731ms duration-ns=1805731 fields.time="2026-08-15T10:03:28Z" method=POST name=ca nonce=YTJ4Nkl0elozWElWSm5YQVZhdDVtcFhDOGNXVHFqaEI path=/acme/acme/challenge/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW/FHUBvBbqotQq3umqQzXFS35V6ILxu3BV protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=749cb92b-e4a2-46ae-bd80-7ac0560327a0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"Xhu6qFRyc1MoSIWmQSI5eLPLPEOEgyWG\",\"validated\":\"2026-08-15T10:03:28Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW/FHUBvBbqotQq3umqQzXFS35V6ILxu3BV\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.682134] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6566550.682222] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6566550.684646] ca step-ca[204]: time="2026-08-15T10:03:28Z" level=info duration=2.125392ms duration-ns=2125392 fields.time="2026-08-15T10:03:28Z" method=POST name=ca nonce=RUF5NUc4alRTV0xjQ0hjNzk3VGlsbWI2QlRpVk1LR3A path=/acme/acme/order/Nhtie8NjBs3JTPTGxKHfgxsa6oXd2X6s/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a505619c-2d87-4f6a-b530-4466e57d9dba response="{\"id\":\"Nhtie8NjBs3JTPTGxKHfgxsa6oXd2X6s\",\"status\":\"valid\",\"expires\":\"2026-08-16T10:03:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-15T10:02:27Z\",\"notAfter\":\"2026-11-13T10:03:27Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/CwQfbV2rpOf5a8bIw951UQx46rgxKDHW\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/Nhtie8NjBs3JTPTGxKHfgxsa6oXd2X6s/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/mizuZiVhb1J3b04vNj4Xxp0oHH31SfDs\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566550.685439] ca step-ca[204]: time="2026-08-15T10:03:28Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQBVdklqnxuyPBbzJ/tPGSDDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTUxMDAyMjdaFw0yNjExMTMxMDAzMjdaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAKZFKaZovrnJFFJ8GuHo9dNz7wtIb3xwrNeHN+NSKCYMZDnphmlOmWBJOI3p/RNqz/5Nw/H/STozHDCbn214cOjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUiyd9YhCLhQjhsK5w91+SKhfAkiwwHwYDVR0jBBgwFoAUcOLs8JRhlWgCgx4Cg79dhsOEqjswEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiA4rYcomikPn4gGGmBuDAMjW8Jv5QN6HcjxCb0JCYzjlwIhAP6eMWxTAgJs7UbT4QGhPiz1Jgcm8VWhLoVFyu1neWBK duration="534.556µs" duration-ns=534556 fields.time="2026-08-15T10:03:28Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=eWVsWWthZzdZeFhzaW01QTBpVXBDMEN1VDg1eFdldjE path=/acme/acme/certificate/mizuZiVhb1J3b04vNj4Xxp0oHH31SfDs protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=57afc55d-21dd-42fd-8e46-17547d31c828 sans="map[dns:[ca.foo]]" serial=7099909983397053199335418583659418124 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-15T10:02:27Z" valid-to="2026-11-13T10:03:27Z" container-test-run-certificates> ca # [6566550.685560] ca acme-order-renew-ca.foo-start[311]: 2026/08/15 10:03:28 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6566550.688071] ca acme-order-renew-ca.foo-start[299]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6566550.689170] ca acme-order-renew-ca.foo-start[299]: + touch out/acme-success container-test-run-certificates> ca # [6566550.690087] ca acme-order-renew-ca.foo-start[299]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6566550.690890] ca acme-order-renew-ca.foo-start[299]: + touch out/renewed container-test-run-certificates> ca # [6566550.691686] ca acme-order-renew-ca.foo-start[299]: + echo Installing new certificate container-test-run-certificates> ca # [6566550.691686] ca acme-order-renew-ca.foo-start[299]: Installing new certificate container-test-run-certificates> ca # [6566550.691705] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6566550.692616] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6566550.692746] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6566550.693765] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6566550.693958] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6566550.694725] ca acme-order-renew-ca.foo-start[333]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6566550.694873] ca acme-order-renew-ca.foo-start[299]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6566550.695877] ca acme-order-renew-ca.foo-start[299]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6566550.696805] ca acme-order-renew-ca.foo-start[299]: + for fixpath in out certificates container-test-run-certificates> ca # [6566550.696805] ca acme-order-renew-ca.foo-start[299]: + '[' -d out ']' container-test-run-certificates> ca # [6566550.696856] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6566550.697865] ca acme-order-renew-ca.foo-start[299]: + chown -R acme:nginx out container-test-run-certificates> ca # [6566550.699219] ca acme-order-renew-ca.foo-start[299]: + for fixpath in out certificates container-test-run-certificates> ca # [6566550.699219] ca acme-order-renew-ca.foo-start[299]: + '[' -d certificates ']' container-test-run-certificates> ca # [6566550.699249] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6566550.700215] ca acme-order-renew-ca.foo-start[299]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6566550.701654] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6566550.780484] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6566550.782511] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6566550.782607] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6566551.143769] ca nginx[349]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6566551.143923] ca nginx[349]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6566551.513305] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6566551.513521] ca systemd[1]: Startup finished in 3.418s. container-test-run-certificates> ca # [6566551.956499] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.74 seconds) container-test-run-certificates> ca # [6566552.407833] ca acme-order-renew-ca.foo-start[364]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6566552.409113] ca acme-order-renew-ca.foo-start[364]: + set -euo pipefail container-test-run-certificates> ca # [6566552.409153] ca acme-order-renew-ca.foo-start[364]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6566552.409208] ca acme-order-renew-ca.foo-start[364]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6566552.409765] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6566552.409778] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6566552.409949] ca acme-order-renew-ca.foo-start[372]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6566552.411338] ca acme-order-renew-ca.foo-start[364]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6566552.411351] ca acme-order-renew-ca.foo-start[364]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6566552.436202] ca step-ca[204]: time="2026-08-15T10:03:29Z" level=info duration="38.493µs" duration-ns=38493 fields.time="2026-08-15T10:03:29Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=8aa01c02-aa5d-415d-aef6-122590d0f38d response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566552.436445] ca acme-order-renew-ca.foo-start[373]: 2026/08/15 10:03:29 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6566552.436445] ca acme-order-renew-ca.foo-start[373]: 2026/08/15 10:03:29 [INFO] [ca.foo] The certificate expires at 2026-11-13T10:03:27Z, the renewal can be performed in 1439h59m37.197945341s: no renewal. container-test-run-certificates> ca # [6566552.436634] ca acme-order-renew-ca.foo-start[364]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6566552.437590] ca acme-order-renew-ca.foo-start[364]: + touch out/acme-success container-test-run-certificates> ca # [6566552.438333] ca acme-order-renew-ca.foo-start[364]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6566552.438926] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [6566552.438938] ca acme-order-renew-ca.foo-start[364]: + '[' -d out ']' container-test-run-certificates> ca # [6566552.438949] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6566552.439743] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx out container-test-run-certificates> ca # [6566552.441071] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [6566552.441095] ca acme-order-renew-ca.foo-start[364]: + '[' -d certificates ']' container-test-run-certificates> ca # [6566552.441095] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6566552.441873] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6566552.443109] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6566552.556759] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6566552.557021] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6566555.565914] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6566555.566005] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6566555.566642] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6566555.567471] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.41 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:03:27 2026 GMT container-test-run-certificates> * expire date: Sep 14 10:03:27 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6f078f container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6566555.950615] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6566555.952625] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6566555.952625] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6566555.957419] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [6566555.957568] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6566555.958499] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6566555.958637] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6566555.959260] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6566555.959386] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6566555.960200] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6566555.961081] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6566555.961873] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6566555.961884] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [6566555.961884] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6566555.962626] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [6566555.963844] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6566555.963855] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [6566555.965215] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6566555.966459] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6566556.345043] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6566556.346492] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> server # [6566556.346526] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6566556.346577] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6566556.347144] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6566556.369212] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6566556.378180] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6566556.378326] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6566556.438588] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569 container-test-run-certificates> server # [6566556.438588] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6566556.438588] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6566556.438588] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6566556.441202] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6566556.441248] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6566556.445623] server acme-order-renew-test.foo-start[331]: 2026/08/15 10:03:33 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6566556.447939] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6566556.448793] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [6566556.449576] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6566556.450103] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [6566556.450838] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [6566556.450838] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [6566556.450867] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6566556.451555] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6566556.451680] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6566556.452320] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6566556.452432] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6566556.453129] server acme-order-renew-test.foo-start[354]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6566556.453239] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6566556.454033] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6566556.454825] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6566556.454837] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [6566556.454837] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6566556.455613] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [6566556.456828] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6566556.456842] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [6566556.456842] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6566556.457577] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6566556.458718] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6566556.535351] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6566556.537326] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6566556.537420] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [6566556.368879] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration="37.801µs" duration-ns=37801 fields.time="2026-08-15T10:03:33Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=5c1aabf5-a4f8-401f-a611-079103dd5850 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.375325] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration=5.187469ms duration-ns=5187469 fields.time="2026-08-15T10:03:33Z" method=HEAD name=ca nonce=blkzTjRHZ1JvaENMYmE3UVduN1pibHBUcklVT21RTTE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=19bdbe06-1bfb-4858-a4d2-f9cbebc32737 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.377938] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration=1.489666ms duration-ns=1489666 fields.time="2026-08-15T10:03:33Z" method=POST name=ca nonce=ZlBLT0J6Yk5wYVM3QkFXdlZ5aUl6Rms5UHJ5U3pVNnA path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=a8c3e0ce-0fd0-49a1-9587-8ce7759abe63 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/frXIagR22zi07wfAeTzpYXVRre0VWKXs/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.380149] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration=1.218344ms duration-ns=1218344 fields.time="2026-08-15T10:03:33Z" method=POST name=ca nonce=cUVRdXBMUnA1czdnbUdrVzA5N3QydlRsQ0FqUlF6NHI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=2f82a5b3-5032-4732-ac6b-ac1bfed29c74 response="{\"id\":\"wvC4kLtOlrNGMd1ymq2xHTfc4Jjqxug4\",\"status\":\"pending\",\"expires\":\"2026-08-16T10:03:33Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-15T10:02:33Z\",\"notAfter\":\"2026-11-13T10:03:33Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569\"],\"finalize\":\"https://ca.foo/acme/acme/order/wvC4kLtOlrNGMd1ymq2xHTfc4Jjqxug4/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.438306] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration="596.574µs" duration-ns=596574 fields.time="2026-08-15T10:03:33Z" method=POST name=ca nonce=elptaURWcWVYNnFLSjByUWtJQWp2T0xKaXZpMXVkY1A path=/acme/acme/authz/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569 protocol=HTTP/1.1 referer= remote-address="::1" request-id=239957e3-2060-4b79-bd6d-64dc83c7dcf0 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"1m8sSs5F8enc2vDyAVbKdlgs7mxEvvke\",\"url\":\"https://ca.foo/acme/acme/challenge/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569/ALWkhZvFii23dzwsSWFVSsZCv1wRyLsr\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"1m8sSs5F8enc2vDyAVbKdlgs7mxEvvke\",\"url\":\"https://ca.foo/acme/acme/challenge/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569/TaE9hpTZzRodItT6iOcdG1qS9greShDY\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"1m8sSs5F8enc2vDyAVbKdlgs7mxEvvke\",\"url\":\"https://ca.foo/acme/acme/challenge/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569/sal5h5EBqM9uLT0MeiCpAD2TKsNFGHfs\"}],\"wildcard\":false,\"expires\":\"2026-08-16T10:03:33Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.440984] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration=1.442317ms duration-ns=1442317 fields.time="2026-08-15T10:03:33Z" method=POST name=ca nonce=QVcyakFXQUZ2Q0pEcHhCRHBkTTY1S1JVWjgwVDYzdlI path=/acme/acme/challenge/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569/TaE9hpTZzRodItT6iOcdG1qS9greShDY protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=887533f6-2d66-4544-babd-a45f76769abc response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"1m8sSs5F8enc2vDyAVbKdlgs7mxEvvke\",\"validated\":\"2026-08-15T10:03:33Z\",\"url\":\"https://ca.foo/acme/acme/challenge/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569/TaE9hpTZzRodItT6iOcdG1qS9greShDY\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.443906] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info duration=1.896532ms duration-ns=1896532 fields.time="2026-08-15T10:03:33Z" method=POST name=ca nonce=MTBMN2NjM1o3WU5ROW1qQUd4bmRkS2lBSFNSS3R4N0g path=/acme/acme/order/wvC4kLtOlrNGMd1ymq2xHTfc4Jjqxug4/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=1151ef09-4864-475e-8d6b-38fdef0f4450 response="{\"id\":\"wvC4kLtOlrNGMd1ymq2xHTfc4Jjqxug4\",\"status\":\"valid\",\"expires\":\"2026-08-16T10:03:33Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-15T10:02:33Z\",\"notAfter\":\"2026-11-13T10:03:33Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/s4OWwiBmbWTtUNka20QLS9Dhhvvhb569\"],\"finalize\":\"https://ca.foo/acme/acme/order/wvC4kLtOlrNGMd1ymq2xHTfc4Jjqxug4/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/eW9lTI2M8EWg3cgJSr3NY4yNCVEqrAM3\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6566556.445177] ca step-ca[204]: time="2026-08-15T10:03:33Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQB+5giRtL5SkRfpblfk0dvzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTUxMDAyMzNaFw0yNjExMTMxMDAzMzNaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEU76Mpvl9QHYkoirzby2yOTU6rx0+T6V+BehPOyUYjeEzcNKG8q8jj+Z5pwP6Z8+3HS9FuWkkSDm2Sil46VqUpqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTl2QeGC7MO8g8eEeMlI0h+W38hdjAfBgNVHSMEGDAWgBRw4uzwlGGVaAKDHgKDv12Gw4SqOzATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgJqiYonDpIqh58AjeDzOql9/RBALAEL3u5rA4G4LhQ30CIB5j6qU9vOj4p6QcjjF8byUf2eD9YsgFg+ZWwX7K+ks4 duration="521.843µs" duration-ns=521843 fields.time="2026-08-15T10:03:33Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=cE5aYlQwTHhSTklLRnBqTkx2R3FET2t1c0d5S1lHRTg path=/acme/acme/certificate/eW9lTI2M8EWg3cgJSr3NY4yNCVEqrAM3 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=489ceace-d6f1-4ae3-b84b-270a6f7d7f26 sans="map[dns:[test.foo]]" serial=10542320596853761981640965872600030655 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-15T10:02:33Z" valid-to="2026-11-13T10:03:33Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:03:27 2026 GMT container-test-run-certificates> * expire date: Sep 14 10:03:27 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6f078f container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6566556.913260] server nginx[370]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6566556.913552] server nginx[370]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6566557.257600] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [930 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 15 10:02:33 2026 GMT container-test-run-certificates> * expire date: Nov 13 10:03:33 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 43586 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1673 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 07:ee:60:89:1b:4b:e5:29:11:7e:96:e5:7e:4d:1d:bf container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 15 10:02:33 2026 GMT container-test-run-certificates> Not After : Nov 13 10:03:33 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:53:be:8c:a6:f9:7d:40:76:24:a2:2a:f3:6f:2d: container-test-run-certificates> b2:39:35:3a:af:1d:3e:4f:a5:7e:05:e8:4f:3b:25: container-test-run-certificates> 18:8d:e1:33:70:d2:86:f2:af:23:8f:e6:79:a7:03: container-test-run-certificates> fa:67:cf:b7:1d:2f:45:b9:69:24:48:39:b6:4a:29: container-test-run-certificates> 78:e9:5a:94:a6 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> E5:D9:07:86:0B:B3:0E:F2:0F:1E:11:E3:25:23:48:7E:5B:7F:21:76 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 70:E2:EC:F0:94:61:95:68:02:83:1E:02:83:BF:5D:86:C3:84:AA:3B container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:26:a8:98:a2:70:e9:22:a8:79:f0:08:de:0f:33: container-test-run-certificates> aa:97:df:d1:04:02:c0:10:bd:ee:e6:b0:38:1b:82:e1:43:7d: container-test-run-certificates> 02:20:1e:63:ea:a5:3d:bc:e8:f8:a7:a4:1c:8e:31:7c:6f:25: container-test-run-certificates> 1f:d9:e0:fd:62:c8:05:83:e6:56:c1:7e:ca:fa:4b:38 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 10.23 seconds) container-test-run-certificates> test script finished in 10.27s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.24 seconds) post-build step Upload to niks3: ok time=2026-08-15T10:03:35.967Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-15T10:03:36.255Z level=INFO msg="Uploading 1 narinfos" time=2026-08-15T10:03:37.201Z level=INFO msg="Upload complete. (1.285s)"