these 91 derivations will be built: /nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/ycl6gbj04ywcaxa7ad5ms35wranp5b1r-X-Reload-Triggers-systemd-networkd.drv /nix/store/2y5dcvasfw9vhxcmcgzy70r1w1bd6jg9-unit-systemd-networkd.service.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv /nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv /nix/store/w65h08jlsr42r550hakzyi58swlgmf20-system-path.drv /nix/store/wnvwk3gfb4ng8qg8cdn1rg604vxcrqms-dbus-1.drv /nix/store/576qhn9qds8jpcshzgwjn5npywqxr99a-X-Restart-Triggers-dbus-broker.drv /nix/store/6xk02cvfi6z3r6zi7bgf9318kph9p2b4-unit-dbus-broker.service.drv /nix/store/bg2q0gf8iq61mv1gj01gginggxx3yd27-system-units.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/jagkcpdv12hskq7v7vs296l7c68a3z6z-unit-dbus-broker.service.drv /nix/store/pbi89ldbkcsfqiggha99cx6dbbyrcxfv-user-units.drv /nix/store/jnyl778iml88p4gp105x94hf1sxamsm8-etc.drv /nix/store/y7r2r4njg0g2m2wjqcbl5yvgijawqsc6-activate.drv /nix/store/96v7gah6g5sha40460sf6d7jp2rjf30c-nixos-system-client-test.drv /nix/store/4azr58kl9a8imr4lj8x78r72qbfghvpj-run-client-nspawn.drv /nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/n3inxg61i0hax0w8wxib7i386bm4k4nr-system-path.drv /nix/store/wqr7p682m7b72s1s7ixs67bhhls43k7l-dbus-1.drv /nix/store/g11x4k5qz0wl1khz1r3b6q02ck119qdn-X-Restart-Triggers-dbus-broker.drv /nix/store/59pg5q5pbdrqkz2jq3zlqzkxa6wj0b12-unit-dbus-broker.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ixy0nzyzig4g1jsdlwmk730i0hl77xh0-system-path.drv /nix/store/izfvsznx4l2zy91ca0198wi5pcnvl8jy-dbus-1.drv /nix/store/j9l21xjm7gyzpkrh1j0cv2kq9bh702n5-X-Restart-Triggers-dbus-broker.drv /nix/store/9960bwp6z3jg719wnlq0xw9z8xjxbqcx-unit-dbus-broker.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/j3lmyghsa4g7nacl7gf67lvx5m91k2br-unit-script-acme-setup-start.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/dxhcs8f88vsb624k3l6b10b549cv921m-tmpfiles.d.drv /nix/store/y9vs2brijwc8c2b5mh0vxrsz0hh37z6h-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/rmxiym60q7p0pgy3rvrqhgl15ngv7yc5-unit-systemd-tmpfiles-resetup.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv /nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv /nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv /nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv /nix/store/76fhybzaqk2lx2v095ak59vb49i7k4sc-system-units.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/hds2l91x8x3q2azlsqlds6kx8z3x6wsk-user-units.drv /nix/store/9fdbwi2689gnsq32xa9r9fvyx4akzmis-unit-dbus-broker.service.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/p7zp904nb1cf9hdl8plmvj7iq2ihhhm3-system-units.drv /nix/store/yll38snw6a1hhmj6pkpanp9nnm8xz03p-etc.drv /nix/store/7pdffx5hvn2waildy5mx4q7151dkyw9f-activate.drv /nix/store/92zjk7dzzwv28hv2a1zjxn37ggyhkq98-unit-dbus-broker.service.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/p3yj69m55z8hw4vvinhmd43sp5shiq7q-nixos-system-server-test.drv /nix/store/qlgsipc1cdkfh0j3xf122qp9jgpa8wcg-run-server-nspawn.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv /nix/store/yc7nvj7w2f4xwcmv29m75ydijrjnvda8-user-units.drv /nix/store/p3842w03sn7v7k9sgsxi27hny9r5n9y4-etc.drv /nix/store/g7an32r2pl9g0lirwc3b817z6n8jcc46-activate.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/ikwsyzh3128wbpmr1ymbfsdwn726sm9w-nixos-system-ca-test.drv /nix/store/y97hsz6s5rfvb4wg3f563bicl8g43yxz-run-ca-nspawn.drv /nix/store/mja5vxv98vj3w53jx1sckdjyxs40hvyh-driverConfiguration.json.drv /nix/store/w3mypy2jlisngwn41q7cka2yb31qwdzz-nixos-test-driver-certificates.drv /nix/store/cc895jb0ard8hciavv1pd2vspi2rwgs4-container-test-run-certificates.drv this path will be fetched (19.5 MiB download, 67.0 MiB unpacked): /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixy0nzyzig4g1jsdlwmk730i0hl77xh0-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n3inxg61i0hax0w8wxib7i386bm4k4nr-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/n3inxg61i0hax0w8wxib7i386bm4k4nr-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/ixy0nzyzig4g1jsdlwmk730i0hl77xh0-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/rr3k22qcv35qb8krj0p5bp7b2yvqp8ml-system-generators.drv' building '/nix/store/wqr7p682m7b72s1s7ixs67bhhls43k7l-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/imw2kazzmfl6nlf52psv7h2vlnfpdxn3-system-shutdown.drv' building '/nix/store/izfvsznx4l2zy91ca0198wi5pcnvl8jy-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bx9ay666mdpxmqa49l3hw83wkl8bjvvs-user-generators.drv' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wqr7p682m7b72s1s7ixs67bhhls43k7l-dbus-1.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/g11x4k5qz0wl1khz1r3b6q02ck119qdn-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/izfvsznx4l2zy91ca0198wi5pcnvl8jy-dbus-1.drv' building '/nix/store/j9l21xjm7gyzpkrh1j0cv2kq9bh702n5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/06xj51r5iv0wg3sry7cb1b5p0arh8amk-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g11x4k5qz0wl1khz1r3b6q02ck119qdn-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/59pg5q5pbdrqkz2jq3zlqzkxa6wj0b12-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9fdbwi2689gnsq32xa9r9fvyx4akzmis-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/j9l21xjm7gyzpkrh1j0cv2kq9bh702n5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/92zjk7dzzwv28hv2a1zjxn37ggyhkq98-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9960bwp6z3jg719wnlq0xw9z8xjxbqcx-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w65h08jlsr42r550hakzyi58swlgmf20-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/xbxd9w9n98kxv8xai0cwa169x1ac9fha-X-Restart-Triggers-step-ca.drv' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/4xq1axfvdgf49msggmxqrmscqafczgj2-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/padyknikkjqgfy4dqzfv3zac5wbypxga-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/ridw8gz0dkhf4vy5c9afxnxknvw961ig-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/dvn31l91l8iqv893xdx8vyw0yvw7h9dj-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/vmk1fn6m29k5nzblx2zykispx7bilw3f-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/npxlb2shi8hbh65w64clxcsi09sn11lp-nss-cacert-3.126-hashed warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/92zjk7dzzwv28hv2a1zjxn37ggyhkq98-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/9960bwp6z3jg719wnlq0xw9z8xjxbqcx-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/sjh85fq2x445snq0kd66rdbikr113rds-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/yc7nvj7w2f4xwcmv29m75ydijrjnvda8-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/59pg5q5pbdrqkz2jq3zlqzkxa6wj0b12-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/hds2l91x8x3q2azlsqlds6kx8z3x6wsk-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/w65h08jlsr42r550hakzyi58swlgmf20-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/9fdbwi2689gnsq32xa9r9fvyx4akzmis-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/yc7nvj7w2f4xwcmv29m75ydijrjnvda8-user-units.drv' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wnvwk3gfb4ng8qg8cdn1rg604vxcrqms-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/hds2l91x8x3q2azlsqlds6kx8z3x6wsk-user-units.drv' building '/nix/store/579wix8gpv1kx7q5ilr3pi7y7bsjj2a0-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/7xx9in4vzx2fh4a7fz1s4wgqj1qf0nxw-unit-script-nginx-pre-start.drv' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wnvwk3gfb4ng8qg8cdn1rg604vxcrqms-dbus-1.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/576qhn9qds8jpcshzgwjn5npywqxr99a-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/z2id9fli5k6ymffhg4lic3ipyaiywxp6-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/76fhybzaqk2lx2v095ak59vb49i7k4sc-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/576qhn9qds8jpcshzgwjn5npywqxr99a-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/6xk02cvfi6z3r6zi7bgf9318kph9p2b4-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jagkcpdv12hskq7v7vs296l7c68a3z6z-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p7zp904nb1cf9hdl8plmvj7iq2ihhhm3-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/76fhybzaqk2lx2v095ak59vb49i7k4sc-system-units.drv' building '/nix/store/p3842w03sn7v7k9sgsxi27hny9r5n9y4-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/jagkcpdv12hskq7v7vs296l7c68a3z6z-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/6xk02cvfi6z3r6zi7bgf9318kph9p2b4-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/p7zp904nb1cf9hdl8plmvj7iq2ihhhm3-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pbi89ldbkcsfqiggha99cx6dbbyrcxfv-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bg2q0gf8iq61mv1gj01gginggxx3yd27-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/yll38snw6a1hhmj6pkpanp9nnm8xz03p-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3842w03sn7v7k9sgsxi27hny9r5n9y4-etc.drv' building '/nix/store/g7an32r2pl9g0lirwc3b817z6n8jcc46-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/bg2q0gf8iq61mv1gj01gginggxx3yd27-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/yll38snw6a1hhmj6pkpanp9nnm8xz03p-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/g7an32r2pl9g0lirwc3b817z6n8jcc46-activate.drv' building '/nix/store/pbi89ldbkcsfqiggha99cx6dbbyrcxfv-user-units.drv' building '/nix/store/jnyl778iml88p4gp105x94hf1sxamsm8-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikwsyzh3128wbpmr1ymbfsdwn726sm9w-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikwsyzh3128wbpmr1ymbfsdwn726sm9w-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/jnyl778iml88p4gp105x94hf1sxamsm8-etc.drv' building '/nix/store/y97hsz6s5rfvb4wg3f563bicl8g43yxz-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y7r2r4njg0g2m2wjqcbl5yvgijawqsc6-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7pdffx5hvn2waildy5mx4q7151dkyw9f-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y97hsz6s5rfvb4wg3f563bicl8g43yxz-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y7r2r4njg0g2m2wjqcbl5yvgijawqsc6-activate.drv' building '/nix/store/96v7gah6g5sha40460sf6d7jp2rjf30c-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7pdffx5hvn2waildy5mx4q7151dkyw9f-activate.drv' building '/nix/store/p3yj69m55z8hw4vvinhmd43sp5shiq7q-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/96v7gah6g5sha40460sf6d7jp2rjf30c-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4azr58kl9a8imr4lj8x78r72qbfghvpj-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/p3yj69m55z8hw4vvinhmd43sp5shiq7q-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/qlgsipc1cdkfh0j3xf122qp9jgpa8wcg-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4azr58kl9a8imr4lj8x78r72qbfghvpj-run-client-nspawn.drv' building '/nix/store/qlgsipc1cdkfh0j3xf122qp9jgpa8wcg-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mja5vxv98vj3w53jx1sckdjyxs40hvyh-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mja5vxv98vj3w53jx1sckdjyxs40hvyh-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/w3mypy2jlisngwn41q7cka2yb31qwdzz-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/w3mypy2jlisngwn41q7cka2yb31qwdzz-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/cc895jb0ard8hciavv1pd2vspi2rwgs4-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/cc895jb0ard8hciavv1pd2vspi2rwgs4-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: systemd-nspawn running (pid 52) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> client # No journal files were found. container-test-run-certificates> client # No journal boot entry found for the specified boot (+0). container-test-run-certificates> ca # No journal files were found. container-test-run-certificates> ca # No journal boot entry found for the specified boot (+0). container-test-run-certificates> server # No journal files were found. container-test-run-certificates> server # No journal boot entry found for the specified boot (+0). container-test-run-certificates> client # [5897180.458967] client systemd-journald[69]: Journal started container-test-run-certificates> client # [5897180.459023] client systemd-journald[69]: Runtime Journal (/run/log/journal/b77b3f5295ff476bbcb830ffecb40e22) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [5897180.466704] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [5897180.476400] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [5897180.477508] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [5897180.478311] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [5897180.485831] client systemd-journald[69]: Time spent on flushing to /var/log/journal/b77b3f5295ff476bbcb830ffecb40e22 is 1.826ms for 6 entries. container-test-run-certificates> client # [5897180.485831] client systemd-journald[69]: System Journal (/var/log/journal/b77b3f5295ff476bbcb830ffecb40e22) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [5897180.495033] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [5897180.495284] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [5897180.495372] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [5897180.496134] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [5897180.496182] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5897180.497118] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [5897180.497158] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [5897180.572409] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [5897180.573720] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [5897180.596116] client systemd-tmpfiles[151]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [5897180.596641] client systemd-tmpfiles[151]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [5897180.596827] client systemd-tmpfiles[151]: fchmod() of /var/log/journal/b77b3f5295ff476bbcb830ffecb40e22 failed: Operation not permitted container-test-run-certificates> client # [5897180.597101] client systemd-tmpfiles[151]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [5897180.598506] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [5897180.600577] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [5897180.601528] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [5897180.481357] ca systemd-journald[77]: Journal started container-test-run-certificates> ca # [5897180.481418] ca systemd-journald[77]: Runtime Journal (/run/log/journal/1362991decc841c1bed0989933f98462) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [5897180.489241] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [5897180.490144] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [5897180.490897] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [5897180.498518] ca systemd-journald[77]: Time spent on flushing to /var/log/journal/1362991decc841c1bed0989933f98462 is 2.661ms for 5 entries. container-test-run-certificates> ca # [5897180.498518] ca systemd-journald[77]: System Journal (/var/log/journal/1362991decc841c1bed0989933f98462) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [5897180.507957] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [5897180.509021] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [5897180.509199] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [5897180.614650] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [5897180.510138] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [5897180.618323] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [5897180.618440] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [5897180.618690] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [5897180.620022] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [5897180.620229] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [5897180.621940] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [5897180.632868] client systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [5897180.510197] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5897180.852390] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [5897181.118334] client systemd-networkd[179]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5897181.118437] client systemd-networkd[179]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [5897181.126420] client systemd-networkd[179]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5897180.511389] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [5897180.476452] server systemd-journald[69]: Journal started container-test-run-certificates> client # [5897181.126585] client systemd-networkd[179]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5897180.476504] server systemd-journald[69]: Runtime Journal (/run/log/journal/8c26515d841147c78dba4b6867cb6a0c) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [5897180.511432] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [5897181.126775] client systemd-networkd[179]: lo: Link UP container-test-run-certificates> ca # [5897180.572382] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [5897180.573497] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [5897180.591758] ca systemd-tmpfiles[148]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [5897180.591969] ca systemd-tmpfiles[148]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5897180.592120] ca systemd-tmpfiles[148]: fchmod() of /var/log/journal/1362991decc841c1bed0989933f98462 failed: Operation not permitted container-test-run-certificates> ca # [5897180.592332] ca systemd-tmpfiles[148]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [5897180.594648] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [5897180.482790] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [5897181.126780] client systemd-networkd[179]: lo: Gained carrier container-test-run-certificates> ca # [5897180.596677] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [5897180.483621] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [5897181.126977] client systemd-networkd[179]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [5897180.484277] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [5897180.493105] server systemd-journald[69]: Time spent on flushing to /var/log/journal/8c26515d841147c78dba4b6867cb6a0c is 1.711ms for 5 entries. container-test-run-certificates> client # [5897181.127640] client systemd[1]: Started Network Management. container-test-run-certificates> ca # [5897180.597598] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [5897181.127661] client systemd-networkd[179]: eth1: Link UP container-test-run-certificates> ca # [5897180.610345] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [5897180.493105] server systemd-journald[69]: System Journal (/var/log/journal/8c26515d841147c78dba4b6867cb6a0c) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [5897180.620216] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [5897180.621409] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [5897180.632973] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [5897180.646340] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [5897180.646509] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [5897180.646770] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [5897180.647923] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [5897180.850362] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [5897181.135699] ca systemd-networkd[194]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5897181.135800] ca systemd-networkd[194]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [5897181.143244] ca systemd-networkd[194]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5897181.143412] ca systemd-networkd[194]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [5897181.143593] ca systemd-networkd[194]: lo: Link UP container-test-run-certificates> ca # [5897181.143596] ca systemd-networkd[194]: lo: Gained carrier container-test-run-certificates> ca # [5897181.143802] ca systemd-networkd[194]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [5897181.144229] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [5897181.184336] ca systemd-networkd[194]: eth1: Link UP container-test-run-certificates> ca # [5897181.184426] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [5897181.184778] ca systemd-networkd[194]: eth1: Gained carrier container-test-run-certificates> ca # [5897181.250670] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [5897181.339707] ca systemd-resolved[100]: Positive Trust Anchors: container-test-run-certificates> ca # [5897181.339720] ca systemd-resolved[100]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [5897181.339724] ca systemd-resolved[100]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [5897181.339759] ca systemd-resolved[100]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [5897181.362946] ca systemd-resolved[100]: Using system hostname 'ca'. container-test-run-certificates> client # [5897181.128014] client systemd-networkd[179]: eth1: Gained carrier container-test-run-certificates> client # [5897181.130402] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [5897181.193948] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [5897181.329805] client systemd-resolved[96]: Positive Trust Anchors: container-test-run-certificates> client # [5897181.329819] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [5897181.329822] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [5897181.329857] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [5897181.353628] client systemd-resolved[96]: Using system hostname 'client'. container-test-run-certificates> client # [5897181.355140] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [5897181.355265] client systemd[1]: Reached target Network. container-test-run-certificates> client # [5897181.355385] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [5897181.355487] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5897181.355544] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [5897180.499944] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [5897181.364859] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [5897181.355584] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [5897181.355811] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [5897181.356050] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [5897181.364951] ca systemd[1]: Reached target Network. container-test-run-certificates> client # [5897181.356281] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [5897180.500735] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [5897181.365031] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [5897181.365098] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [5897180.500871] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [5897181.356324] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [5897181.356403] client systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [5897181.365422] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> client # [5897181.358506] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [5897181.365467] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [5897181.365497] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [5897181.365521] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [5897180.501731] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [5897181.360190] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [5897181.365734] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [5897181.365896] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [5897181.366043] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [5897181.366072] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [5897181.366122] ca systemd[1]: Reached target Basic System. container-test-run-certificates> server # [5897180.501782] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [5897181.362919] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [5897180.502765] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [5897181.401184] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [5897180.502806] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [5897181.402179] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [5897180.563280] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [5897180.564715] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [5897180.583140] server systemd-tmpfiles[139]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [5897180.583355] server systemd-tmpfiles[139]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [5897180.583496] server systemd-tmpfiles[139]: fchmod() of /var/log/journal/8c26515d841147c78dba4b6867cb6a0c failed: Operation not permitted container-test-run-certificates> server # [5897180.583707] server systemd-tmpfiles[139]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [5897180.585458] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [5897180.586855] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [5897180.587786] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [5897180.602408] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [5897180.608753] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [5897180.610073] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [5897180.622376] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [5897180.641190] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [5897180.641357] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [5897180.641608] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [5897180.642875] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [5897180.850367] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [5897181.141354] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5897181.141457] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [5897181.148505] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5897181.148669] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [5897181.148848] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [5897181.148851] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [5897181.149032] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [5897181.149446] server systemd[1]: Started Network Management. container-test-run-certificates> server # [5897181.184427] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [5897181.184728] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [5897181.184996] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [5897181.222602] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [5897181.347580] server systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> server # [5897181.347591] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [5897181.347596] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [5897181.347630] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [5897181.370831] server systemd-resolved[92]: Using system hostname 'server'. container-test-run-certificates> server # [5897181.372252] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [5897181.372379] server systemd[1]: Reached target Network. container-test-run-certificates> server # [5897181.372482] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [5897181.372572] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [5897181.372961] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [5897181.373016] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [5897181.373065] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [5897181.373107] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [5897181.373315] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [5897181.373507] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [5897181.373721] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [5897181.373769] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [5897181.373855] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [5897181.401525] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [5897181.402901] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [5897181.402970] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [5897181.404410] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [5897181.406754] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [5897181.402225] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [5897181.403292] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [5897181.404923] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [5897181.406650] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [5897181.425404] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [5897181.464490] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [5897181.518500] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [5897181.518500] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [5897181.518934] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [5897181.519885] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [5897181.521727] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [5897181.521784] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [5897181.521784] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [5897181.521784] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [5897181.549744] server nsncd[194]: Aug 16 05:30:07.602 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [5897181.549730] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [5897181.549832] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [5897181.549931] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [5897181.569789] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [5897181.571368] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [5897181.580573] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [5897181.581667] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [5897181.581711] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [5897181.581731] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [5897181.659202] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [5897181.425339] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [5897181.463710] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [5897181.532854] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> ca # [5897181.532854] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> ca # [5897181.533196] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [5897181.534828] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [5897181.536449] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5897181.536499] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [5897181.536499] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [5897181.536499] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [5897181.563440] ca nsncd[202]: Aug 16 05:30:07.616 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [5897181.568862] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [5897181.569011] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [5897181.569348] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [5897181.571242] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [5897181.572291] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [5897181.583949] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [5897181.584924] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [5897181.584964] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [5897181.584978] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [5897181.417909] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [5897181.458018] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [5897181.551246] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [5897181.551311] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [5897181.551383] client nsncd[189]: Aug 16 05:30:07.604 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [5897181.551375] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [5897181.569309] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [5897181.570346] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [5897181.581808] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [5897181.582917] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [5897181.582961] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [5897181.582982] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [5897181.672761] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [5897181.673829] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [5897181.673900] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zywjz6icib9dalgvfc8py10nxraz93m5-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [5897181.674278] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [5897181.681328] client dbus-broker-launch[190]: Ready container-test-run-certificates> server # [5897181.660521] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [5897181.660521] server dbus-broker-launch[195]: Invalid user-name in /nix/store/d1bzln21l9zpk9wvjqzzzfn8j065fhla-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [5897181.660895] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [5897181.668612] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca # [5897181.663161] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [5897181.664210] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [5897181.664210] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/3qkg4gk1x07mlwasb0fhmz2fqq7s6x75-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [5897181.664934] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [5897181.672064] ca dbus-broker-launch[204]: Ready container-test-run-certificates> ca # [5897182.048171] ca systemd-logind[229]: New seat seat0. container-test-run-certificates> ca # [5897182.048371] ca systemd[1]: Started User Login Management. container-test-run-certificates> client # [5897182.047466] client systemd-logind[205]: New seat seat0. container-test-run-certificates> server # [5897182.046504] server systemd-logind[221]: New seat seat0. container-test-run-certificates> client # [5897182.047660] client systemd[1]: Started User Login Management. container-test-run-certificates> server # [5897182.046710] server systemd[1]: Started User Login Management. container-test-run-certificates> client # [5897182.049052] client systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [5897182.049489] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [5897182.118123] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [5897182.105265] ca acme-setup-start[218]: + set -euo pipefail container-test-run-certificates> client # [5897182.118210] client systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [5897182.048300] server systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [5897182.118652] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [5897182.132076] client systemd[1]: Startup finished in 2.175s. container-test-run-certificates> ca # [5897182.105265] ca acme-setup-start[218]: + test -e ca/key.pem container-test-run-certificates> server # [5897182.096821] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> ca # [5897182.105265] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [5897182.117479] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [5897182.117538] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [5897182.125454] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [5897182.126875] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [5897182.240313] ca step-ca[203]: badger 2026/08/16 05:30:08 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [5897182.246548] ca step-ca[203]: 2026/08/16 05:30:08 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [5897182.250803] ca step-ca[203]: 2026/08/16 05:30:08 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> server # [5897182.096821] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> ca # [5897182.250803] ca step-ca[203]: 2026/08/16 05:30:08 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> server # [5897182.097240] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [5897182.250803] ca step-ca[203]: 2026/08/16 05:30:08 Community Discord: https://u.step.sm/discord container-test-run-certificates> server # [5897182.112788] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [5897182.250803] ca step-ca[203]: 2026/08/16 05:30:08 Config file: /etc/smallstep/ca.json container-test-run-certificates> server # [5897182.114925] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [5897182.250952] ca step-ca[203]: 2026/08/16 05:30:08 The primary server URL is https://ca.foo:1443 container-test-run-certificates> server # [5897182.117309] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [5897182.117469] server systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [5897182.250952] ca step-ca[203]: 2026/08/16 05:30:08 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [5897182.250952] ca step-ca[203]: 2026/08/16 05:30:08 X.509 Root Fingerprint: f9e7a116c83d2375b63fd0fee2b3f3d2c10fa91e7eb2213ff0482fdebbf2ec31 container-test-run-certificates> ca # [5897182.251431] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [5897182.251625] ca step-ca[203]: 2026/08/16 05:30:08 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [5897182.621483] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5897182.624305] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5897182.624396] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5897182.635367] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [5897182.635815] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5897182.636759] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5897182.637097] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5897182.638385] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5897182.638639] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5897182.640117] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5897182.641446] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5897182.642917] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [5897182.642917] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [5897182.643025] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5897182.644621] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [5897182.647501] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [5897182.647501] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [5897182.651423] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5897182.653919] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [5897182.688280] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> ca # [5897182.640344] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5897182.643314] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [5897182.643366] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [5897182.653788] ca acme-ca.foo-start[292]: + cd ca.foo container-test-run-certificates> ca # [5897182.654073] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [5897182.655312] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [5897182.655535] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [5897182.656606] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [5897182.656797] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [5897182.658518] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [5897182.659894] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5897182.661622] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [5897182.661658] ca acme-ca.foo-start[254]: + '[' -d out ']' container-test-run-certificates> ca # [5897182.661658] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5897182.663355] ca acme-ca.foo-start[254]: + chown -R acme:nginx out container-test-run-certificates> ca # [5897182.666205] ca acme-ca.foo-start[254]: + for fixpath in out certificates container-test-run-certificates> ca # [5897182.666234] ca acme-ca.foo-start[254]: + '[' -d certificates ']' container-test-run-certificates> ca # [5897182.704784] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [5897182.706315] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [5897182.944178] client systemd-networkd[179]: eth1: Gained IPv6LL container-test-run-certificates> server # [5897183.229826] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [5897183.230419] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> ca # [5897183.168219] ca systemd-networkd[194]: eth1: Gained IPv6LL container-test-run-certificates> server # [5897183.236406] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [5897183.237009] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [5897183.238365] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [5897183.233193] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [5897183.233541] ca nginx-pre-start[304]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [5897183.240549] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [5897183.241329] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [5897183.243625] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [5897183.769158] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5897183.771843] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail container-test-run-certificates> ca # [5897183.771922] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [5897183.772068] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5897183.773085] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [5897183.788584] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [5897183.788935] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [5897183.816273] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration="207.602µs" duration-ns=207602 fields.time="2026-08-16T05:30:09Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ade98134-0c87-4b64-be04-e593ac176d17 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.816966] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [5897183.826452] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=9.126726ms duration-ns=9126726 fields.time="2026-08-16T05:30:09Z" method=HEAD name=ca nonce=eGc1SXgwd3VuNDNyNDNDSWE1UVFwcmZ5MUZ6bUM0aFU path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=43550a04-9fa8-47e8-809b-0d655fa46dac size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.828880] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=1.687784ms duration-ns=1687784 fields.time="2026-08-16T05:30:09Z" method=POST name=ca nonce=MmtGMlVMaGRtUFR6c2llZFRMc0pGQ3QyV1BYc2xvYUc path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=11f64ca0-32c8-4805-8648-09ec9f8e2ba8 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/q2xIUXOKLNAxoSnditPAnh5efnbhCv44/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts". container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [5897183.829280] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [5897183.829493] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [5897183.832440] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=2.452714ms duration-ns=2452714 fields.time="2026-08-16T05:30:09Z" method=POST name=ca nonce=UkMxT3k5c1Zja0lPSmgzNnhjT0FYSHAxQ0hiV1hZR2g path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=85ecbf69-2af6-4797-9d52-a48061fa7e55 response="{\"id\":\"sOKag4pgCoR3mUJEVbmjxXa3ZJQN4czV\",\"status\":\"pending\",\"expires\":\"2026-08-17T05:30:09Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-16T05:29:09Z\",\"notAfter\":\"2026-11-14T05:30:09Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/sOKag4pgCoR3mUJEVbmjxXa3ZJQN4czV/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.891770] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=2.380233ms duration-ns=2380233 fields.time="2026-08-16T05:30:09Z" method=POST name=ca nonce=RFcyMXM0Z1k1M3VCdzF2cld6SDZNeTN5RTg3ZG1vcWE path=/acme/acme/authz/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c741bf09-e775-48fb-b04a-5e1170fe9dc4 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3cf1hcl8Ok0qRLhIig8C8Bfxo3UgqFWC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB/lgIO36ZewjAGc0kjrELuvJrRcKwzSL2k\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3cf1hcl8Ok0qRLhIig8C8Bfxo3UgqFWC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB/GIlpzEiX2HrMKvUlUAXB1J2VovNfPYu6\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3cf1hcl8Ok0qRLhIig8C8Bfxo3UgqFWC\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB/XCQYbJENKyyVOzA7ZYSEWlczdK9qB6xP\"}],\"wildcard\":false,\"expires\":\"2026-08-17T05:30:09Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.892114] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB container-test-run-certificates> ca # [5897183.892114] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [5897183.892114] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [5897183.892114] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [5897183.896734] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=3.843853ms duration-ns=3843853 fields.time="2026-08-16T05:30:09Z" method=POST name=ca nonce=M0ZqWm9GM1pCNzdlZFNNWGE4WVdOa0xROHNrOVdRMEE path=/acme/acme/challenge/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB/GIlpzEiX2HrMKvUlUAXB1J2VovNfPYu6 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=98c8ec48-d2b6-4005-80f9-cc4c1db97306 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3cf1hcl8Ok0qRLhIig8C8Bfxo3UgqFWC\",\"validated\":\"2026-08-16T05:30:09Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB/GIlpzEiX2HrMKvUlUAXB1J2VovNfPYu6\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.897011] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [5897183.897098] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [5897183.903707] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info duration=5.719999ms duration-ns=5719999 fields.time="2026-08-16T05:30:09Z" method=POST name=ca nonce=VlBzN2pFNlM1S1RwT3Q5V3E0MXRkZ3FnQTZGa25HUTE path=/acme/acme/order/sOKag4pgCoR3mUJEVbmjxXa3ZJQN4czV/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=37fa72f7-81cf-4291-80a3-188782e3668c response="{\"id\":\"sOKag4pgCoR3mUJEVbmjxXa3ZJQN4czV\",\"status\":\"valid\",\"expires\":\"2026-08-17T05:30:09Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-16T05:29:09Z\",\"notAfter\":\"2026-11-14T05:30:09Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/V9N5UBHdzyoi6y9JFqIkIGKVKzSKJJLB\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/sOKag4pgCoR3mUJEVbmjxXa3ZJQN4czV/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/0QakxddhBzySNzWTtnltarAj3r1IRJfS\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897183.905588] ca step-ca[203]: time="2026-08-16T05:30:09Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAPOHZfrPsEPbuYlm6L3hBG0wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE2MDUyOTA5WhcNMjYxMTE0MDUzMDA5WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARD9JS6Mp41fZECUOUp2fdkS5jql32qlrwQN4ITiXcnPAZcP5SaJLBDEpNU6k0ZMcyTWdUq2zdkzQprS7uQZNteo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFEwujtcxefQo1zta91l7m3dLnA4IMB8GA1UdIwQYMBaAFMqzJKDoxKCeD5gKbGUhXv4uk5DtMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhANZeQD8yL89T5uHcOlFP+Ul6jPeqD0UdjDf0RdgwB93LAiBRCS4Fqj5dzgvFf1ikOxj/g+isHiRDRed3lGUBe+m/eA==" duration=1.259937ms duration-ns=1259937 fields.time="2026-08-16T05:30:09Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=WEJhTkw2VzZDaDBTcWFKS1J4REtIa3pwTjFHNThmOUI path=/acme/acme/certificate/0QakxddhBzySNzWTtnltarAj3r1IRJfS protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=50d18bd4-a95f-42a3-91f0-94c2df982341 sans="map[dns:[ca.foo]]" serial=323705431446323844659305188198965118061 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-16T05:29:09Z" valid-to="2026-11-14T05:30:09Z" container-test-run-certificates> ca # [5897183.905788] ca acme-order-renew-ca.foo-start[319]: 2026/08/16 05:30:09 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [5897183.910107] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5897183.911791] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success container-test-run-certificates> ca # [5897183.913763] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5897183.914776] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed container-test-run-certificates> ca # [5897183.916346] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate container-test-run-certificates> ca # [5897183.916346] ca acme-order-renew-ca.foo-start[307]: Installing new certificate container-test-run-certificates> ca # [5897183.916407] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5897183.917945] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [5897183.918190] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [5897183.919514] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [5897183.919774] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [5897183.921628] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [5897183.921886] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [5897183.924206] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [5897183.926120] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [5897183.926145] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']' container-test-run-certificates> ca # [5897183.926145] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5897183.927606] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out container-test-run-certificates> ca # [5897183.930326] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates container-test-run-certificates> ca # [5897183.930326] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']' container-test-run-certificates> ca # [5897183.930394] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5897183.932212] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5897183.934505] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5897184.020489] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [5897183.749669] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5897183.752448] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [5897183.752526] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5897183.752642] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5897183.754529] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [5897183.773753] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:30:09 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [5897183.774058] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:30:09 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [5897183.813558] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:30:09 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [5897183.814087] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5897183.814087] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [5897183.814087] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [5897183.817560] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [5897183.817762] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [5897183.856365] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5897183.857039] server systemd[1]: Startup finished in 3.899s. container-test-run-certificates> ca # [5897184.024099] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5897184.024274] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [5897184.549838] ca nginx[369]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok container-test-run-certificates> ca # [5897184.550459] ca nginx[369]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful container-test-run-certificates> ca # [5897185.073384] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [5897185.073727] ca systemd[1]: Startup finished in 5.083s. container-test-run-certificates> ca # [5897185.551863] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.82 seconds) container-test-run-certificates> ca # [5897186.043757] ca acme-order-renew-ca.foo-start[384]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [5897186.046476] ca acme-order-renew-ca.foo-start[384]: + set -euo pipefail container-test-run-certificates> ca # [5897186.046550] ca acme-order-renew-ca.foo-start[384]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [5897186.046661] ca acme-order-renew-ca.foo-start[384]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [5897186.048057] ca acme-order-renew-ca.foo-start[384]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [5897186.048057] ca acme-order-renew-ca.foo-start[384]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [5897186.048488] ca acme-order-renew-ca.foo-start[392]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [5897186.051443] ca acme-order-renew-ca.foo-start[384]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [5897186.051532] ca acme-order-renew-ca.foo-start[384]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [5897186.099436] ca step-ca[203]: time="2026-08-16T05:30:12Z" level=info duration="72.961µs" duration-ns=72961 fields.time="2026-08-16T05:30:12Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=969fefaf-664c-4304-8772-683cc761b571 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897186.099809] ca acme-order-renew-ca.foo-start[393]: 2026/08/16 05:30:12 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [5897186.100056] ca acme-order-renew-ca.foo-start[393]: 2026/08/16 05:30:12 [INFO] [ca.foo] The certificate expires at 2026-11-14T05:30:09Z, the renewal can be performed in 1439h59m36.847011429s: no renewal. container-test-run-certificates> ca # [5897186.100342] ca acme-order-renew-ca.foo-start[384]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [5897186.101821] ca acme-order-renew-ca.foo-start[384]: + touch out/acme-success container-test-run-certificates> ca # [5897186.103479] ca acme-order-renew-ca.foo-start[384]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [5897186.104604] ca acme-order-renew-ca.foo-start[384]: + for fixpath in out certificates container-test-run-certificates> ca # [5897186.104625] ca acme-order-renew-ca.foo-start[384]: + '[' -d out ']' container-test-run-certificates> ca # [5897186.104625] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [5897186.106158] ca acme-order-renew-ca.foo-start[384]: + chown -R acme:nginx out container-test-run-certificates> ca # [5897186.108835] ca acme-order-renew-ca.foo-start[384]: + for fixpath in out certificates container-test-run-certificates> ca # [5897186.108875] ca acme-order-renew-ca.foo-start[384]: + '[' -d certificates ']' container-test-run-certificates> ca # [5897186.108875] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [5897186.110271] ca acme-order-renew-ca.foo-start[384]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [5897186.112627] ca acme-order-renew-ca.foo-start[384]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5897186.210583] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [5897186.210803] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [5897189.233892] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5897189.234257] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [5897189.236191] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [5897189.238739] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.67 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:30:08 2026 GMT container-test-run-certificates> * expire date: Sep 15 05:30:08 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1e2839 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5897189.851805] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5897189.854698] server acme-test.foo-start[316]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [5897189.854698] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [5897189.870108] server acme-test.foo-start[325]: + cd test.foo container-test-run-certificates> server # [5897189.870629] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [5897189.871599] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [5897189.871922] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [5897189.873262] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [5897189.873521] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [5897189.875580] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [5897189.877597] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5897189.879117] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [5897189.879117] server acme-test.foo-start[316]: + '[' -d out ']' container-test-run-certificates> server # [5897189.879208] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5897189.880954] server acme-test.foo-start[316]: + chown -R acme:nginx out container-test-run-certificates> server # [5897189.883826] server acme-test.foo-start[316]: + for fixpath in out certificates container-test-run-certificates> server # [5897189.883826] server acme-test.foo-start[316]: + '[' -d certificates ']' container-test-run-certificates> server # [5897189.888285] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [5897189.892983] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [5897190.380270] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [5897190.383330] server acme-order-renew-test.foo-start[333]: + set -euo pipefail container-test-run-certificates> server # [5897190.383403] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [5897190.383508] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [5897190.384847] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [5897190.432151] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!! container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts". container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [5897190.459873] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [5897190.460264] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [5897190.530117] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT container-test-run-certificates> server # [5897190.530117] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [5897190.530117] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [5897190.530117] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [5897190.539236] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [5897190.539329] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [5897190.561468] server acme-order-renew-test.foo-start[341]: 2026/08/16 05:30:16 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [5897190.566865] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [5897190.568927] server acme-order-renew-test.foo-start[333]: + touch out/acme-success container-test-run-certificates> server # [5897190.571128] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5897190.572387] server acme-order-renew-test.foo-start[333]: + touch out/renewed container-test-run-certificates> server # [5897190.574210] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate container-test-run-certificates> server # [5897190.574210] server acme-order-renew-test.foo-start[333]: Installing new certificate container-test-run-certificates> server # [5897190.574210] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [5897190.576335] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [5897190.576687] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [5897190.578113] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [5897190.578420] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [5897190.580066] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [5897190.580484] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [5897190.582521] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [5897190.584246] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [5897190.584246] server acme-order-renew-test.foo-start[333]: + '[' -d out ']' container-test-run-certificates> server # [5897190.584340] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [5897190.585868] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out container-test-run-certificates> server # [5897190.588883] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates container-test-run-certificates> server # [5897190.588883] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']' container-test-run-certificates> server # [5897190.588989] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [5897190.590868] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates container-test-run-certificates> server # [5897190.593400] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [5897190.431507] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration="61.081µs" duration-ns=61081 fields.time="2026-08-16T05:30:16Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=f36f55cf-cf76-461a-82f4-d034f6054f63 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.453634] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=18.140404ms duration-ns=18140404 fields.time="2026-08-16T05:30:16Z" method=HEAD name=ca nonce=cTUxbWQ3T2pyUXJEaG5HUjkyN1I5R1Z3cEdGdjY4czQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1ae95ced-1d1e-4ba4-8258-297971a52212 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.459012] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=2.394472ms duration-ns=2394472 fields.time="2026-08-16T05:30:16Z" method=POST name=ca nonce=T1BWYXk1aFhUUjhMOFJjTTB4V3JibGNLdVBVdkk3Z3o path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=2a6e44e3-8538-4417-9a25-fbb10a70a60b response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/jsVS6y2GW36gzEAK1CNealRqmvXayHWg/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.467149] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=3.564848ms duration-ns=3564848 fields.time="2026-08-16T05:30:16Z" method=POST name=ca nonce=Sndob1RyQmhpZGZwRjc2REtJVlNBbVQwQWVHN2FxUTg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=61147881-d4fe-48e1-9704-537278345d67 response="{\"id\":\"zzwNzR8FosB9xCEwPXNPqsSh47mOHEEJ\",\"status\":\"pending\",\"expires\":\"2026-08-17T05:30:16Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-16T05:29:16Z\",\"notAfter\":\"2026-11-14T05:30:16Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT\"],\"finalize\":\"https://ca.foo/acme/acme/order/zzwNzR8FosB9xCEwPXNPqsSh47mOHEEJ/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.529341] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=2.103068ms duration-ns=2103068 fields.time="2026-08-16T05:30:16Z" method=POST name=ca nonce=UnB4ZGxuVDN1U1MxeDFLMmVteE01UWk5dGVOWmxudTg path=/acme/acme/authz/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT protocol=HTTP/1.1 referer= remote-address="::1" request-id=fbc2c770-5adb-49b1-8e87-7576eb5ec678 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"MOBe3VPJGSuZk0ZT2aDTvmxVinqd3G9h\",\"url\":\"https://ca.foo/acme/acme/challenge/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT/mUyMzIm6xN0pemyhZkXbEF1RUOtOVU3Q\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"MOBe3VPJGSuZk0ZT2aDTvmxVinqd3G9h\",\"url\":\"https://ca.foo/acme/acme/challenge/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT/P4mRBhtLDOEZ6RhCz6Pa9Ex4NFN77rbf\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"MOBe3VPJGSuZk0ZT2aDTvmxVinqd3G9h\",\"url\":\"https://ca.foo/acme/acme/challenge/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT/A4S5crp3b8oFpeGM7Z90LM28oQCkc1HV\"}],\"wildcard\":false,\"expires\":\"2026-08-17T05:30:16Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.538610] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=4.297977ms duration-ns=4297977 fields.time="2026-08-16T05:30:16Z" method=POST name=ca nonce=SUs1cjRVTUtoSHhkRkZxVWRtSUF4bmpjSVNnZE5sdU0 path=/acme/acme/challenge/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT/P4mRBhtLDOEZ6RhCz6Pa9Ex4NFN77rbf protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=a25cef56-fa20-43d4-b63c-22516efce2ad response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"MOBe3VPJGSuZk0ZT2aDTvmxVinqd3G9h\",\"validated\":\"2026-08-16T05:30:16Z\",\"url\":\"https://ca.foo/acme/acme/challenge/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT/P4mRBhtLDOEZ6RhCz6Pa9Ex4NFN77rbf\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.554452] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info duration=10.326259ms duration-ns=10326259 fields.time="2026-08-16T05:30:16Z" method=POST name=ca nonce=TUhMcVAyNGU5a3ZQU0hFaDJyM2NPdU12WWVHVGFXVWw path=/acme/acme/order/zzwNzR8FosB9xCEwPXNPqsSh47mOHEEJ/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=35dd950f-8145-4020-af7e-cf127c9444a8 response="{\"id\":\"zzwNzR8FosB9xCEwPXNPqsSh47mOHEEJ\",\"status\":\"valid\",\"expires\":\"2026-08-17T05:30:16Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-16T05:29:16Z\",\"notAfter\":\"2026-11-14T05:30:16Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/bDazXqOAwBMx7sYfSzrujGr3siQd2ouT\"],\"finalize\":\"https://ca.foo/acme/acme/order/zzwNzR8FosB9xCEwPXNPqsSh47mOHEEJ/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/JxKz9f8eZJxxTpr4MiiIpOODYJkiVRAf\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [5897190.560745] ca step-ca[203]: time="2026-08-16T05:30:16Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQbSJNYEV6cdfoLYdMAJH31zAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTYwNTI5MTZaFw0yNjExMTQwNTMwMTZaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE9JJFDWt1PLKfanCrWVnV4ueHQRLFSxrazrX6XhuRLfOH6SpM7gBI6ktW2wF3kUoCUyLhpcC/rRzB8dj9iQjFr6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTTD72LcwN8w2RqN7piwyXDk46+0jAfBgNVHSMEGDAWgBTKsySg6MSgng+YCmxlIV7+LpOQ7TATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgCOxCqzgARn3GgBembr8jE0L+TRzPtbsCyJo99sbHZl0CIHxx3MgmUlnOvpoBFo56ZntgS1WQpaj0j29BETTDDjpP duration=2.917359ms duration-ns=2917359 fields.time="2026-08-16T05:30:16Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=MEkzb0tkd2pWQjc4b1NaUHU4d0pRSUFGMjlBcG9JdUI path=/acme/acme/certificate/JxKz9f8eZJxxTpr4MiiIpOODYJkiVRAf protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c92d8988-65de-48bf-a384-5e4cc741be8f sans="map[dns:[test.foo]]" serial=145063959006691589071742570934354180055 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-16T05:29:16Z" valid-to="2026-11-14T05:30:16Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:30:08 2026 GMT container-test-run-certificates> * expire date: Sep 15 05:30:08 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1e2839 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [5897190.756699] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [5897190.760878] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [5897190.761089] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [5897191.278602] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [5897191.279104] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [928 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [78 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:29:16 2026 GMT container-test-run-certificates> * expire date: Nov 14 05:30:16 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 60422 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 839 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.14 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 6d:22:4d:60:45:7a:71:d7:e8:2d:87:4c:00:91:f7:d7 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 16 05:29:16 2026 GMT container-test-run-certificates> Not After : Nov 14 05:30:16 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:f4:92:45:0d:6b:75:3c:b2:9f:6a:70:ab:59:59: container-test-run-certificates> d5:e2:e7:87:41:12:c5:4b:1a:da:ce:b5:fa:5e:1b: container-test-run-certificates> 91:2d:f3:87:e9:2a:4c:ee:00:48:ea:4b:56:db:01: container-test-run-certificates> 77:91:4a:02:53:22:e1:a5:c0:bf:ad:1c:c1:f1:d8: container-test-run-certificates> fd:89:08:c5:af container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> D3:0F:BD:8B:73:03:7C:C3:64:6A:37:BA:62:C3:25:C3:93:8E:BE:D2 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> CA:B3:24:A0:E8:C4:A0:9E:0F:98:0A:6C:65:21:5E:FE:2E:93:90:ED container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:08:ec:42:ab:38:00:46:7d:c6:80:17:a6:6e:bf: container-test-run-certificates> 23:13:42:fe:4d:1c:cf:b5:bb:02:c8:9a:3d:f6:c6:c7:66:5d: container-test-run-certificates> 02:20:7c:71:dc:c8:26:52:59:ce:be:9a:01:16:8e:7a:66:7b: container-test-run-certificates> 60:4b:55:90:a5:a8:f4:8f:6f:41:11:34:c3:0e:3a:4f container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.67 seconds) container-test-run-certificates> server # [5897191.808647] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 12.86s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 52) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.54 seconds) post-build step Upload to niks3: ok time=2026-08-16T05:30:20.199Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-16T05:30:20.642Z level=INFO msg="Uploading 1 narinfos" time=2026-08-16T05:30:21.066Z level=INFO msg="Upload complete. (933ms)"