these 85 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/033g30l2hdinygrrjfhyd9xng7kp0cmw-system-path.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv /nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv /nix/store/6bvn6r8ncl2pw95hxpzw8q1kqcyfw0h9-system-path.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/2a6ny6m944v24xhhbzmlb9qj1slvsrcd-dbus-1.drv /nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv /nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv /nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv /nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/pxvbxnmnihfzid5hwg1as30ffqvrwp1f-X-Restart-Triggers-dbus-broker.drv /nix/store/5k5s85r7xfxyrfs1s6b9iq30qaja5b2c-unit-dbus-broker.service.drv /nix/store/i4c9kbk96n2yh20v9fid7iw4v5i9rm7l-user-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv /nix/store/5d86k6ssj9zacpq5bk0qbkcr0djqvq2v-unit-dbus-broker.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv /nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/yzc23df7f1cwjrdqqys6d2x5ha9dfa28-system-units.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/d5qlwxfnmy68hryii7hqhczdf98an3yg-etc.drv /nix/store/a8djp1apd4d1lkkyqhqhp10n9ysnhdkk-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/xjv0mkv9kipn6mx9yij5r1lk9gq6fivi-nixos-system-ca-test.drv /nix/store/33hwdgizn8wnlkjilxdhwy2axmilcrjg-run-ca-nspawn.drv /nix/store/p8494g6nnsqcizp6nrcba36sbin26prk-dbus-1.drv /nix/store/rkshvywa287gi6c5l50y1icxbmb9ss9f-X-Restart-Triggers-dbus-broker.drv /nix/store/ns2hb31pvsxn1ikx486xbckl1jslvcx7-unit-dbus-broker.service.drv /nix/store/3l5yjrk4mhqlsx1wis6f0776djiz60pw-user-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/mw0fj6nq8bwhgim75f3156sknp7bdr37-unit-dbus-broker.service.drv /nix/store/p297gxm9yv6rd140m0c23i3msxzmfgwv-system-units.drv /nix/store/dnjs0d92c8xrsq9dihanha3hzrmmvgcz-etc.drv /nix/store/gqj1cjvbyjwaqs0vqhj5kvdscvnmmm18-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/6g1cjwwadl7jcvmndrz40mf8rwhy326h-nixos-system-server-test.drv /nix/store/kmxz14nv83jr85qfgryb34lkkbpm401a-run-server-nspawn.drv /nix/store/35zijhfr7yjh8s6c64f0yzfblg9n3syb-system-path.drv /nix/store/579hl1jvvhnc7zi1rmmla9p7n4nllvvh-dbus-1.drv /nix/store/wzk30v1gm0vz17j0iqn90cgxyn2kkahx-X-Restart-Triggers-dbus-broker.drv /nix/store/q3ib9sryk6s1n3q3w43w72rn24lqfr6b-unit-dbus-broker.service.drv /nix/store/2b1vccwpavm9hg9cbwxwcvbagm62wl93-system-units.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/vcdxcmd1dzjvaj2ldsdqbf9sgypfn1wq-unit-dbus-broker.service.drv /nix/store/ql1452l8vnh7k5dzyyjnhvs9hg8k58r6-user-units.drv /nix/store/3xpfj7f9rv9lrr4bymgicc0cws159g6m-etc.drv /nix/store/gi5is81d5cgb9kf92r696gvj6gbbw17z-activate.drv /nix/store/k687x3vf6pf20809vsfpi48p0h984r8f-nixos-system-client-test.drv /nix/store/kn2w7jnn45gc2q69wdx8il4h21vd0frr-run-client-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/2a5i83iy462bfkckfgrvdpliwin0gidg-driverConfiguration.json.drv /nix/store/c3m8gxy8nx05an2byg1vh8swsw1nxnyw-nixos-test-driver-certificates.drv /nix/store/4aihvp6llkm3ln3125sn2w3yn63ziq27-container-test-run-certificates.drv this path will be fetched (21.7 MiB download, 71.4 MiB unpacked): /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/033g30l2hdinygrrjfhyd9xng7kp0cmw-system-path.drv' building '/nix/store/35zijhfr7yjh8s6c64f0yzfblg9n3syb-system-path.drv' building '/nix/store/6bvn6r8ncl2pw95hxpzw8q1kqcyfw0h9-system-path.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/2a6ny6m944v24xhhbzmlb9qj1slvsrcd-dbus-1.drv' building '/nix/store/579hl1jvvhnc7zi1rmmla9p7n4nllvvh-dbus-1.drv' building '/nix/store/p8494g6nnsqcizp6nrcba36sbin26prk-dbus-1.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv' building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' building '/nix/store/pxvbxnmnihfzid5hwg1as30ffqvrwp1f-X-Restart-Triggers-dbus-broker.drv' ca.json> structuredAttrs is enabled building '/nix/store/rkshvywa287gi6c5l50y1icxbmb9ss9f-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/wzk30v1gm0vz17j0iqn90cgxyn2kkahx-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv' building '/nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv' building '/nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' building '/nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/5d86k6ssj9zacpq5bk0qbkcr0djqvq2v-unit-dbus-broker.service.drv' building '/nix/store/5k5s85r7xfxyrfs1s6b9iq30qaja5b2c-unit-dbus-broker.service.drv' building '/nix/store/ns2hb31pvsxn1ikx486xbckl1jslvcx7-unit-dbus-broker.service.drv' building '/nix/store/q3ib9sryk6s1n3q3w43w72rn24lqfr6b-unit-dbus-broker.service.drv' building '/nix/store/vcdxcmd1dzjvaj2ldsdqbf9sgypfn1wq-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/mw0fj6nq8bwhgim75f3156sknp7bdr37-unit-dbus-broker.service.drv' building '/nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/3l5yjrk4mhqlsx1wis6f0776djiz60pw-user-units.drv' building '/nix/store/i4c9kbk96n2yh20v9fid7iw4v5i9rm7l-user-units.drv' building '/nix/store/ql1452l8vnh7k5dzyyjnhvs9hg8k58r6-user-units.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed building '/nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/2b1vccwpavm9hg9cbwxwcvbagm62wl93-system-units.drv' building '/nix/store/p297gxm9yv6rd140m0c23i3msxzmfgwv-system-units.drv' building '/nix/store/yzc23df7f1cwjrdqqys6d2x5ha9dfa28-system-units.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/3xpfj7f9rv9lrr4bymgicc0cws159g6m-etc.drv' building '/nix/store/d5qlwxfnmy68hryii7hqhczdf98an3yg-etc.drv' building '/nix/store/dnjs0d92c8xrsq9dihanha3hzrmmvgcz-etc.drv' building '/nix/store/gi5is81d5cgb9kf92r696gvj6gbbw17z-activate.drv' building '/nix/store/k687x3vf6pf20809vsfpi48p0h984r8f-nixos-system-client-test.drv' building '/nix/store/a8djp1apd4d1lkkyqhqhp10n9ysnhdkk-activate.drv' building '/nix/store/gqj1cjvbyjwaqs0vqhj5kvdscvnmmm18-activate.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/kn2w7jnn45gc2q69wdx8il4h21vd0frr-run-client-nspawn.drv' building '/nix/store/xjv0mkv9kipn6mx9yij5r1lk9gq6fivi-nixos-system-ca-test.drv' building '/nix/store/6g1cjwwadl7jcvmndrz40mf8rwhy326h-nixos-system-server-test.drv' nixos-system-ca-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/33hwdgizn8wnlkjilxdhwy2axmilcrjg-run-ca-nspawn.drv' building '/nix/store/kmxz14nv83jr85qfgryb34lkkbpm401a-run-server-nspawn.drv' building '/nix/store/2a5i83iy462bfkckfgrvdpliwin0gidg-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/c3m8gxy8nx05an2byg1vh8swsw1nxnyw-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/4aihvp6llkm3ln3125sn2w3yn63ziq27-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/4aihvp6llkm3ln3125sn2w3yn63ziq27-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 51) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: systemd-nspawn running (pid 56) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 57) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ca # [6636193.011957] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6636193.011994] ca systemd-journald[78]: Runtime Journal (/run/log/journal/298b7eb350314ce4843a6d810f860315) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [6636193.013956] ca systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6636193.017691] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6636193.040269] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6636193.041153] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6636193.041791] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6636193.046270] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/298b7eb350314ce4843a6d810f860315 is 1.594ms for 7 entries. container-test-run-certificates> ca # [6636193.046270] ca systemd-journald[78]: System Journal (/var/log/journal/298b7eb350314ce4843a6d810f860315) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6636193.057408] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6636193.058097] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6636193.058169] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6636193.058811] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6636193.058852] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6636193.060080] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6636193.060098] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6636193.132171] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6636193.132363] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6636193.132871] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6636193.133076] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6636193.133690] ca systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6636193.134064] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6636193.145385] ca systemd-tmpfiles[188]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6636193.145551] ca systemd-tmpfiles[188]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6636193.145661] ca systemd-tmpfiles[188]: fchmod() of /var/log/journal/298b7eb350314ce4843a6d810f860315 failed: Operation not permitted container-test-run-certificates> ca # [6636193.145816] ca systemd-tmpfiles[188]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6636193.146797] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6636193.147453] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6636193.147832] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6636193.154960] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6636193.162534] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6636193.163127] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6636193.169784] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6636193.305217] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6636193.004185] client systemd-journald[69]: Journal started container-test-run-certificates> client # [6636193.004222] client systemd-journald[69]: Runtime Journal (/run/log/journal/d5a39dc455cf436a84134a71192919f8) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6636193.010172] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6636193.016861] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6636193.017361] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6636193.017762] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6636193.045243] client systemd-journald[69]: Time spent on flushing to /var/log/journal/d5a39dc455cf436a84134a71192919f8 is 1.121ms for 6 entries. container-test-run-certificates> client # [6636193.045243] client systemd-journald[69]: System Journal (/var/log/journal/d5a39dc455cf436a84134a71192919f8) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6636193.050580] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6636193.051127] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6636193.051175] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6636193.051630] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6636193.051659] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6636193.052241] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6636193.052265] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6636193.104411] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6636193.104571] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6636193.104810] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6636193.105863] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [6636193.132161] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6636193.132875] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6636193.145038] client systemd-tmpfiles[176]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6636193.145241] client systemd-tmpfiles[176]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6636193.145383] client systemd-tmpfiles[176]: fchmod() of /var/log/journal/d5a39dc455cf436a84134a71192919f8 failed: Operation not permitted container-test-run-certificates> server # [6636193.011986] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6636193.145591] client systemd-tmpfiles[176]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6636193.012021] server systemd-journald[69]: Runtime Journal (/run/log/journal/aa0cb23eccf047fbbe81ecd7ea63d80e) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6636193.146828] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6636193.013489] server systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [6636193.147616] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6636193.018258] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6636193.147996] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6636193.040297] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6636193.155033] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6636193.041210] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6636193.164694] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6636193.041822] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6636193.165305] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6636193.046870] server systemd-journald[69]: Time spent on flushing to /var/log/journal/aa0cb23eccf047fbbe81ecd7ea63d80e is 1.241ms for 7 entries. container-test-run-certificates> client # [6636193.172188] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6636193.046870] server systemd-journald[69]: System Journal (/var/log/journal/aa0cb23eccf047fbbe81ecd7ea63d80e) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6636193.305213] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6636193.057456] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6636193.058087] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6636193.058158] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6636193.058821] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6636193.058855] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6636193.059517] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6636193.059540] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6636193.132163] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6636193.132341] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6636193.132822] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6636193.133032] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6636193.133658] server systemd[1]: Starting Network Management... container-test-run-certificates> server # [6636193.134049] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6636193.145344] server systemd-tmpfiles[179]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6636193.145499] server systemd-tmpfiles[179]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6636193.145604] server systemd-tmpfiles[179]: fchmod() of /var/log/journal/aa0cb23eccf047fbbe81ecd7ea63d80e failed: Operation not permitted container-test-run-certificates> server # [6636193.145762] server systemd-tmpfiles[179]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6636193.146839] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6636193.147405] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6636193.147786] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6636193.156747] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6636193.164429] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6636193.165059] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6636193.172206] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6636193.304174] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6636193.487184] server systemd-networkd[178]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6636193.487284] server systemd-networkd[178]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6636193.492830] server systemd-networkd[178]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6636193.492978] server systemd-networkd[178]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6636193.493084] server systemd-networkd[178]: lo: Link UP container-test-run-certificates> server # [6636193.493088] server systemd-networkd[178]: lo: Gained carrier container-test-run-certificates> server # [6636193.493229] server systemd-networkd[178]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6636193.493524] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6636193.508212] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6636193.508275] server systemd-networkd[178]: eth1: Link UP container-test-run-certificates> server # [6636193.508463] server systemd-networkd[178]: eth1: Gained carrier container-test-run-certificates> server # [6636193.527982] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6636193.486333] ca systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6636193.486401] ca systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6636193.491464] ca systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6636193.491607] ca systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6636193.491664] ca systemd-networkd[187]: lo: Link UP container-test-run-certificates> ca # [6636193.491666] ca systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> ca # [6636193.491775] ca systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6636193.491998] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6636193.508109] ca systemd-networkd[187]: eth1: Link UP container-test-run-certificates> ca # [6636193.508181] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6636193.508436] ca systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> ca # [6636193.529590] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6636193.479755] client systemd-networkd[172]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6636193.479830] client systemd-networkd[172]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6636193.485073] client systemd-networkd[172]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6636193.485220] client systemd-networkd[172]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6636193.485288] client systemd-networkd[172]: lo: Link UP container-test-run-certificates> client # [6636193.485290] client systemd-networkd[172]: lo: Gained carrier container-test-run-certificates> client # [6636193.485427] client systemd-networkd[172]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6636193.485671] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6636193.485715] client systemd-networkd[172]: eth1: Link UP container-test-run-certificates> client # [6636193.485848] client systemd-networkd[172]: eth1: Gained carrier container-test-run-certificates> client # [6636193.486310] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6636193.512232] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6636193.649777] ca systemd-resolved[119]: Positive Trust Anchors: container-test-run-certificates> ca # [6636193.649787] ca systemd-resolved[119]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6636193.649790] ca systemd-resolved[119]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6636193.649806] ca systemd-resolved[119]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6636193.660906] ca systemd-resolved[119]: Using system hostname 'ca'. container-test-run-certificates> ca # [6636193.661923] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6636193.662017] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6636193.662069] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6636193.662104] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6636193.662290] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6636193.662319] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6636193.662339] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6636193.662355] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6636193.662459] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6636193.662587] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6636193.662708] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6636193.662720] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6636193.662749] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6636193.663501] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6636193.663882] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6636193.663905] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6636193.664396] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6636193.664947] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6636193.686156] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6636193.695458] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6636193.763495] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6636193.763495] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6636193.763770] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6636193.764308] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6636193.765117] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6636193.765149] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6636193.765149] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6636193.765149] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6636193.808529] ca nsncd[203]: Aug 16 05:24:11.174 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6636193.808581] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6636193.808630] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6636193.808669] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6636193.809457] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6636193.810053] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6636193.817862] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6636193.818346] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6636193.818366] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6636193.818378] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6636193.892756] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6636193.900532] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6636193.900532] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/v170r7aanvw71iqs982aylvfsa6z4fxz-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6636193.893606] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6636193.897179] ca dbus-broker-launch[205]: Ready container-test-run-certificates> client # [6636193.656505] client systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> client # [6636193.656513] client systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6636193.656516] client systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6636193.656539] client systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6636193.667693] client systemd-resolved[97]: Using system hostname 'client'. container-test-run-certificates> client # [6636193.668626] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6636193.668678] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6636193.668715] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6636193.668746] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6636193.668760] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6636193.668769] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6636193.668846] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6636193.668910] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6636193.668978] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6636193.668989] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6636193.669022] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6636193.686235] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6636193.686872] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6636193.687751] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6636193.699474] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6636193.778963] client nsncd[189]: Aug 16 05:24:11.144 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6636193.779111] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6636193.779181] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6636193.779217] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6636193.788534] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6636193.789034] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6636193.794603] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6636193.795322] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6636193.795348] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6636193.795363] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6636193.872513] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6636193.872979] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6636193.872979] client dbus-broker-launch[190]: Invalid user-name in /nix/store/dsv3rggvhlb190l1kvd28z29v7m7p1vb-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6636193.873272] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6636193.878675] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [6636193.997225] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6636193.652057] server systemd-resolved[112]: Positive Trust Anchors: container-test-run-certificates> server # [6636193.652065] server systemd-resolved[112]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6636193.652068] server systemd-resolved[112]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6636193.652084] server systemd-resolved[112]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6636193.663142] server systemd-resolved[112]: Using system hostname 'server'. container-test-run-certificates> server # [6636193.664088] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6636193.664143] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6636193.664180] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6636193.664206] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6636193.664341] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6636193.664356] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6636193.664370] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6636193.664381] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6636193.664472] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6636193.664568] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6636193.664646] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6636193.664657] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6636193.664679] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6636193.665456] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6636193.686195] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6636193.686220] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6636193.686819] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6636193.687718] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6636193.700149] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6636193.760755] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6636193.760755] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6636193.761110] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6636193.761742] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6636193.762621] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6636193.762649] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6636193.762649] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6636193.762649] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6636193.791336] server nsncd[195]: Aug 16 05:24:11.156 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6636193.791445] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6636193.791513] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6636193.791567] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6636193.792575] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6636193.793051] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6636193.799534] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6636193.800155] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6636193.800176] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6636193.800188] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6636193.871054] server dbus-broker-launch[198]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6636193.871551] server dbus-broker-launch[198]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6636193.871551] server dbus-broker-launch[198]: Invalid user-name in /nix/store/8ckk80xa2mi2j6ski3zvn1zk298j85mp-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6636193.871874] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6636193.877338] server dbus-broker-launch[198]: Ready container-test-run-certificates> server # [6636194.002926] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6636194.004818] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6636194.186675] server systemd-logind[224]: New seat seat0. container-test-run-certificates> server # [6636194.186816] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6636194.204252] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6636194.208952] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6636194.208952] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6636194.209289] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6636194.211293] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6636194.211379] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6636194.223792] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6636194.224942] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [6636194.183366] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6636194.183522] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6636194.184395] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6636194.210334] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6636194.210443] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6636194.210796] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6636194.210901] client systemd[1]: Startup finished in 1.579s. container-test-run-certificates> ca # [6636194.203511] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [6636194.203690] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6636194.204563] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6636194.212525] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6636194.212566] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6636194.241750] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6636194.241750] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6636194.242031] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6636194.249654] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6636194.250695] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6636194.359782] ca step-ca[204]: badger 2026/08/16 05:24:11 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6636194.363938] ca step-ca[204]: 2026/08/16 05:24:11 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6636194.368668] ca step-ca[204]: 2026/08/16 05:24:11 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [6636194.368668] ca step-ca[204]: 2026/08/16 05:24:11 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6636194.368668] ca step-ca[204]: 2026/08/16 05:24:11 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6636194.368668] ca step-ca[204]: 2026/08/16 05:24:11 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6636194.368668] ca step-ca[204]: 2026/08/16 05:24:11 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6636194.368781] ca step-ca[204]: 2026/08/16 05:24:11 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6636194.368781] ca step-ca[204]: 2026/08/16 05:24:11 X.509 Root Fingerprint: 90684bcb39b6e8783b3f83954046135bdf820e4b218433502254a072081f4e5b container-test-run-certificates> ca # [6636194.368846] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6636194.368909] ca step-ca[204]: 2026/08/16 05:24:11 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [6636194.621079] client systemd-networkd[172]: eth1: Gained IPv6LL container-test-run-certificates> server # [6636194.619936] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6636194.621205] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6636194.621240] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6636194.625378] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6636194.625527] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6636194.626081] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6636194.626203] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6636194.626794] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6636194.626906] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6636194.628119] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6636194.628952] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6636194.629797] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6636194.629797] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6636194.629845] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6636194.631076] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6636194.632454] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6636194.632471] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6636194.633926] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6636194.634725] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6636194.686071] server systemd-networkd[178]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6636194.615052] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6636194.616343] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6636194.616395] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6636194.620704] ca acme-ca.foo-start[282]: + cd ca.foo container-test-run-certificates> ca # [6636194.620865] ca acme-ca.foo-start[282]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6636194.621456] ca acme-ca.foo-start[283]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6636194.621576] ca acme-ca.foo-start[282]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6636194.622199] ca acme-ca.foo-start[282]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6636194.622317] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6636194.623127] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6636194.623860] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6636194.624611] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6636194.624640] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6636194.624640] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6636194.625410] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6636194.627125] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6636194.627125] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6636194.629280] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6636194.631500] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6636195.027509] server nginx-pre-start[267]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6636195.027783] server nginx-pre-start[267]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6636195.029883] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6636195.030102] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6636195.030706] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6636195.048719] ca nginx-pre-start[294]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6636195.048959] ca nginx-pre-start[294]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6636195.051255] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6636195.051546] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6636195.052350] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [6636195.262080] ca systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6636195.453594] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6636195.455058] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6636195.455108] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6636195.455174] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6636195.455796] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6636195.464479] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:24:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6636195.464659] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:24:12 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6636195.478979] server acme-order-renew-test.foo-start[281]: 2026/08/16 05:24:12 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6636195.479234] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6636195.479234] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6636195.479305] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6636195.481779] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6636195.481943] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6636195.482277] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6636195.482520] server systemd[1]: Startup finished in 2.850s. container-test-run-certificates> ca # [6636195.453137] ca acme-order-renew-ca.foo-start[297]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6636195.454619] ca acme-order-renew-ca.foo-start[297]: + set -euo pipefail container-test-run-certificates> ca # [6636195.454657] ca acme-order-renew-ca.foo-start[297]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6636195.454716] ca acme-order-renew-ca.foo-start[297]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6636195.455337] ca acme-order-renew-ca.foo-start[297]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6636195.465977] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6636195.466276] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6636195.481208] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration="77.485µs" duration-ns=77485 fields.time="2026-08-16T05:24:12Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=da519a08-9276-461f-ab86-0361a2c4c5b9 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.481546] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6636195.482166] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration="663.58µs" duration-ns=663580 fields.time="2026-08-16T05:24:12Z" method=HEAD name=ca nonce=MVA0OWVxc3RRazQ1WnVrS2lUcDJVYWZrZURkTXlSU3A path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b6422e0b-6cae-4ae9-9661-cdc860ca6775 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.483533] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration=1.022716ms duration-ns=1022716 fields.time="2026-08-16T05:24:12Z" method=POST name=ca nonce=TWZ2WDR2eVlYZ29ZVVB1NGlYd3N5RGxEQms4bTJVT2M path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=85d2a10f-c86c-442b-a0fe-a7d3387ad8a4 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/J5cRJ3GFmArO1Zj9Rla7amHxJCJvr9wg/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: Your account credentials have been saved in your container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: configuration directory at "accounts". container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: configuration directory will also contain private keys container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6636195.483720] ca acme-order-renew-ca.foo-start[309]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6636195.483834] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6636195.485276] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration=1.297043ms duration-ns=1297043 fields.time="2026-08-16T05:24:12Z" method=POST name=ca nonce=QThXeDl0M0ticEhIa1FqcmdlNU9ia3BWTU9PT1BVazI path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=aa634c5e-d102-4fad-b92f-3c0bc55790d6 response="{\"id\":\"AEOBwFLRIsW76QsGe7yWI8AqeCs9mMk5\",\"status\":\"pending\",\"expires\":\"2026-08-17T05:24:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-16T05:23:12Z\",\"notAfter\":\"2026-11-14T05:24:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/AEOBwFLRIsW76QsGe7yWI8AqeCs9mMk5/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.542926] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration="964.116µs" duration-ns=964116 fields.time="2026-08-16T05:24:12Z" method=POST name=ca nonce=bHV4TUhzaklWTEVKWmZIRzZrampieWxvWWlTRmExY3A path=/acme/acme/authz/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b0ab0fed-b83a-423f-bc76-975098bbed32 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"5GaQQWyPobvsoXD2hJ09O21S13uOzb7X\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt/dIZiiTgJFp3lfp56z3H30jHVhuyxO5aF\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"5GaQQWyPobvsoXD2hJ09O21S13uOzb7X\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt/acq8s0U1cWln6si2nnWysQ49nr8Ysc9O\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"5GaQQWyPobvsoXD2hJ09O21S13uOzb7X\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt/6FKo33VbQzrPY24njGXTDqMmnGzakzgv\"}],\"wildcard\":false,\"expires\":\"2026-08-17T05:24:12Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.543112] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt container-test-run-certificates> ca # [6636195.543112] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6636195.543112] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6636195.543196] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6636195.545386] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration=2.015456ms duration-ns=2015456 fields.time="2026-08-16T05:24:12Z" method=POST name=ca nonce=VDlOOVpTQVdaMjIxODl0cGRJc21xa0piTWVRR0V0cUE path=/acme/acme/challenge/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt/acq8s0U1cWln6si2nnWysQ49nr8Ysc9O protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=233ac764-2211-4242-9c90-486d48516196 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"5GaQQWyPobvsoXD2hJ09O21S13uOzb7X\",\"validated\":\"2026-08-16T05:24:12Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt/acq8s0U1cWln6si2nnWysQ49nr8Ysc9O\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.545509] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6636195.545538] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6636195.548448] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info duration=2.613302ms duration-ns=2613302 fields.time="2026-08-16T05:24:12Z" method=POST name=ca nonce=QUFJTklkQm44WVpzN0s0YXlFS2ZudUpOOGNVSjFBM24 path=/acme/acme/order/AEOBwFLRIsW76QsGe7yWI8AqeCs9mMk5/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0ec85e23-6835-4788-b7c7-0dcdb605db17 response="{\"id\":\"AEOBwFLRIsW76QsGe7yWI8AqeCs9mMk5\",\"status\":\"valid\",\"expires\":\"2026-08-17T05:24:12Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-16T05:23:12Z\",\"notAfter\":\"2026-11-14T05:24:12Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/oCUO3hTZSRD6XKHFvlyKHbxSQ4NLengt\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/AEOBwFLRIsW76QsGe7yWI8AqeCs9mMk5/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/a9SWWzoPN2Qa6n1CvzGinCTQrY52etyN\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636195.549081] ca step-ca[204]: time="2026-08-16T05:24:12Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQR3xaDDvu9x9XD4QGDZ53HjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTYwNTIzMTJaFw0yNjExMTQwNTI0MTJaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFBMBzEIgrUigonY+GMTmI2mMgCyqtXEmce/ScHdxPgwbv6HnEk6OJvZf95aw11slLPI1lC9xb33UUSBDSGrNJ2jgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUXg6pKhhFjJx2tfI4564jZEcGRvwwHwYDVR0jBBgwFoAUcOLs8JRhlWgCgx4Cg79dhsOEqjswEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiBORik2wt4uad7jerD/77pBn7O0ceV4a82E4BIf2WSOggIgUJ0LssiJAJuTAx+bk6aU5aUKjuvaLkyuztZx5UL53LM=" duration="439.518µs" duration-ns=439518 fields.time="2026-08-16T05:24:12Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=YmlQc1k0RTh5aUtDdUFKZHdNcm0wRmFhUzVBZkxWelk path=/acme/acme/certificate/a9SWWzoPN2Qa6n1CvzGinCTQrY52etyN protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=c41eed15-297e-4745-be98-108b47f6ff9f sans="map[dns:[ca.foo]]" serial=95020858897338131350789643053060486942 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-16T05:23:12Z" valid-to="2026-11-14T05:24:12Z" container-test-run-certificates> ca # [6636195.549153] ca acme-order-renew-ca.foo-start[309]: 2026/08/16 05:24:12 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6636195.552841] ca acme-order-renew-ca.foo-start[297]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6636195.553719] ca acme-order-renew-ca.foo-start[297]: + touch out/acme-success container-test-run-certificates> ca # [6636195.554481] ca acme-order-renew-ca.foo-start[297]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6636195.555021] ca acme-order-renew-ca.foo-start[297]: + touch out/renewed container-test-run-certificates> ca # [6636195.555716] ca acme-order-renew-ca.foo-start[297]: + echo Installing new certificate container-test-run-certificates> ca # [6636195.555716] ca acme-order-renew-ca.foo-start[297]: Installing new certificate container-test-run-certificates> ca # [6636195.555716] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6636195.556419] ca acme-order-renew-ca.foo-start[329]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6636195.556571] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6636195.557396] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6636195.557562] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6636195.558238] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6636195.558371] ca acme-order-renew-ca.foo-start[297]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6636195.559122] ca acme-order-renew-ca.foo-start[297]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6636195.559942] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6636195.559942] ca acme-order-renew-ca.foo-start[297]: + '[' -d out ']' container-test-run-certificates> ca # [6636195.559977] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6636195.560740] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx out container-test-run-certificates> ca # [6636195.562511] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6636195.562511] ca acme-order-renew-ca.foo-start[297]: + '[' -d certificates ']' container-test-run-certificates> ca # [6636195.562542] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6636195.563333] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6636195.564572] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6636195.658143] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6636195.660235] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6636195.660350] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6636196.040704] ca nginx[347]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6636196.041070] ca nginx[347]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6636196.423188] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6636196.423399] ca systemd[1]: Startup finished in 3.771s. container-test-run-certificates> ca # [6636196.508811] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.62 seconds) container-test-run-certificates> ca # [6636196.880867] ca acme-order-renew-ca.foo-start[362]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6636196.882115] ca acme-order-renew-ca.foo-start[362]: + set -euo pipefail container-test-run-certificates> ca # [6636196.882153] ca acme-order-renew-ca.foo-start[362]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6636196.882209] ca acme-order-renew-ca.foo-start[362]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6636196.882780] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6636196.882794] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6636196.882961] ca acme-order-renew-ca.foo-start[370]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6636196.884324] ca acme-order-renew-ca.foo-start[362]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6636196.884347] ca acme-order-renew-ca.foo-start[362]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6636196.905646] ca step-ca[204]: time="2026-08-16T05:24:14Z" level=info duration="42.61µs" duration-ns=42610 fields.time="2026-08-16T05:24:14Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d4fd0010-59be-46e1-954a-6d7f830597f1 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636196.905872] ca acme-order-renew-ca.foo-start[371]: 2026/08/16 05:24:14 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6636196.905872] ca acme-order-renew-ca.foo-start[371]: 2026/08/16 05:24:14 [INFO] [ca.foo] The certificate expires at 2026-11-14T05:24:12Z, the renewal can be performed in 1439h59m37.728531154s: no renewal. container-test-run-certificates> ca # [6636196.906043] ca acme-order-renew-ca.foo-start[362]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6636196.907005] ca acme-order-renew-ca.foo-start[362]: + touch out/acme-success container-test-run-certificates> ca # [6636196.907820] ca acme-order-renew-ca.foo-start[362]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6636196.908393] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6636196.908406] ca acme-order-renew-ca.foo-start[362]: + '[' -d out ']' container-test-run-certificates> ca # [6636196.908406] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6636196.909210] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx out container-test-run-certificates> ca # [6636196.910545] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6636196.910545] ca acme-order-renew-ca.foo-start[362]: + '[' -d certificates ']' container-test-run-certificates> ca # [6636196.910580] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6636196.911337] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6636196.912782] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6636196.989056] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6636196.989196] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6636199.997761] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6636199.997849] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6636199.998413] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6636199.999128] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.38 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:24:11 2026 GMT container-test-run-certificates> * expire date: Sep 15 05:24:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1b30db container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6636200.352863] server acme-test.foo-start[304]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6636200.354399] server acme-test.foo-start[304]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6636200.354399] server acme-test.foo-start[304]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6636200.358734] server acme-test.foo-start[314]: + cd test.foo container-test-run-certificates> server # [6636200.358935] server acme-test.foo-start[314]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6636200.359489] server acme-test.foo-start[315]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6636200.359632] server acme-test.foo-start[314]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6636200.360270] server acme-test.foo-start[314]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6636200.360390] server acme-test.foo-start[304]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6636200.361233] server acme-test.foo-start[304]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6636200.362021] server acme-test.foo-start[304]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6636200.362779] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [6636200.362790] server acme-test.foo-start[304]: + '[' -d out ']' container-test-run-certificates> server # [6636200.362790] server acme-test.foo-start[304]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6636200.363545] server acme-test.foo-start[304]: + chown -R acme:nginx out container-test-run-certificates> server # [6636200.364877] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [6636200.364877] server acme-test.foo-start[304]: + '[' -d certificates ']' container-test-run-certificates> server # [6636200.366247] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6636200.367662] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6636200.855411] server acme-order-renew-test.foo-start[322]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6636200.855411] server acme-order-renew-test.foo-start[322]: + set -euo pipefail container-test-run-certificates> server # [6636200.855411] server acme-order-renew-test.foo-start[322]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6636200.855411] server acme-order-renew-test.foo-start[322]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6636200.855411] server acme-order-renew-test.foo-start[322]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6636200.869512] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: Your account credentials have been saved in your container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: configuration directory at "accounts". container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: configuration directory will also contain private keys container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6636200.880892] server acme-order-renew-test.foo-start[330]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6636200.881025] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6636200.959479] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd container-test-run-certificates> server # [6636200.959479] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6636200.959479] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6636200.959572] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6636200.964124] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6636200.964169] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6636200.972399] server acme-order-renew-test.foo-start[330]: 2026/08/16 05:24:18 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6636200.975698] server acme-order-renew-test.foo-start[322]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6636200.976766] server acme-order-renew-test.foo-start[322]: + touch out/acme-success container-test-run-certificates> server # [6636200.977527] server acme-order-renew-test.foo-start[322]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6636200.978059] server acme-order-renew-test.foo-start[322]: + touch out/renewed container-test-run-certificates> server # [6636200.978836] server acme-order-renew-test.foo-start[322]: + echo Installing new certificate container-test-run-certificates> server # [6636200.978836] server acme-order-renew-test.foo-start[322]: Installing new certificate container-test-run-certificates> server # [6636200.978836] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6636200.979525] server acme-order-renew-test.foo-start[351]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6636200.979651] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6636200.980332] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6636200.980459] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6636200.981107] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6636200.981233] server acme-order-renew-test.foo-start[322]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6636200.981975] server acme-order-renew-test.foo-start[322]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6636200.982748] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [6636200.982748] server acme-order-renew-test.foo-start[322]: + '[' -d out ']' container-test-run-certificates> server # [6636200.982770] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6636200.983520] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx out container-test-run-certificates> server # [6636200.984817] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [6636200.984840] server acme-order-renew-test.foo-start[322]: + '[' -d certificates ']' container-test-run-certificates> server # [6636200.984840] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6636200.985594] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6636200.986763] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6636201.072501] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6636201.074574] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6636201.074690] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> ca # [6636200.869291] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration="39.354µs" duration-ns=39354 fields.time="2026-08-16T05:24:18Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=27c2ad30-ed83-46dd-a8e6-c45975e572ae response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.874822] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=4.416657ms duration-ns=4416657 fields.time="2026-08-16T05:24:18Z" method=HEAD name=ca nonce=STJrVHBnWm9nQzlRT1ZRalFoNkt6VlY2MkhLSGFMYzE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=111fbbd6-c967-4cf4-9e92-ab767ce47aa4 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.880705] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=4.976622ms duration-ns=4976622 fields.time="2026-08-16T05:24:18Z" method=POST name=ca nonce=VXRkWUdzYjA1S3B0djV3VVBJYkNVWEc0UG56c1lEWng path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=2f58dd3c-56ae-4070-903f-c49cbdb7318f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/5brljdTcDsHAUvEV8CiyNljS9zNmZm8J/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.885085] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=3.245511ms duration-ns=3245511 fields.time="2026-08-16T05:24:18Z" method=POST name=ca nonce=eXlPbHphcm5iRmNuTUlOUmxrdmNUQWtsaEdmbGFwbjA path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=85a4e966-8a83-4880-b065-86d95cdf59e4 response="{\"id\":\"S5nNYB1qG94ToXl0Xbt9zFvNQWBmJNG6\",\"status\":\"pending\",\"expires\":\"2026-08-17T05:24:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-16T05:23:18Z\",\"notAfter\":\"2026-11-14T05:24:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd\"],\"finalize\":\"https://ca.foo/acme/acme/order/S5nNYB1qG94ToXl0Xbt9zFvNQWBmJNG6/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.959297] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=17.06675ms duration-ns=17066750 fields.time="2026-08-16T05:24:18Z" method=POST name=ca nonce=NWZTRWpneGlHVWQ3engwaXFiYWlzbzNvcFFMQUNVUDk path=/acme/acme/authz/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd protocol=HTTP/1.1 referer= remote-address="::1" request-id=7c3feab5-e1bb-47ee-9717-19a2825652cc response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"8QTxrH4hkAV7NcungNOLRF2877w8pyuI\",\"url\":\"https://ca.foo/acme/acme/challenge/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd/23nonioLwP5ie162mcLLQRye1eUVCnY2\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"8QTxrH4hkAV7NcungNOLRF2877w8pyuI\",\"url\":\"https://ca.foo/acme/acme/challenge/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd/DgHncdEbjZELRqTtHTEzOAEQ9u8dUpJ7\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"8QTxrH4hkAV7NcungNOLRF2877w8pyuI\",\"url\":\"https://ca.foo/acme/acme/challenge/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd/5JPHCzZlxauEb43dwWIcZEUXAExUceKQ\"}],\"wildcard\":false,\"expires\":\"2026-08-17T05:24:18Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.963931] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=3.7754ms duration-ns=3775400 fields.time="2026-08-16T05:24:18Z" method=POST name=ca nonce=OXFDYmRIeU5pNUtad0NubVFwa0ZHN0Z6MXVDNTJJTzE path=/acme/acme/challenge/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd/DgHncdEbjZELRqTtHTEzOAEQ9u8dUpJ7 protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=a752b129-cf8a-479d-bcd9-e51d6a47b831 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"8QTxrH4hkAV7NcungNOLRF2877w8pyuI\",\"validated\":\"2026-08-16T05:24:18Z\",\"url\":\"https://ca.foo/acme/acme/challenge/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd/DgHncdEbjZELRqTtHTEzOAEQ9u8dUpJ7\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.970337] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info duration=5.438772ms duration-ns=5438772 fields.time="2026-08-16T05:24:18Z" method=POST name=ca nonce=OVlGQ001QnIyWWJLUXB3ODZ6aFo2Q0R6SFlITm4wdWw path=/acme/acme/order/S5nNYB1qG94ToXl0Xbt9zFvNQWBmJNG6/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=ba294f00-fdf7-451f-8e09-e9e14c137d36 response="{\"id\":\"S5nNYB1qG94ToXl0Xbt9zFvNQWBmJNG6\",\"status\":\"valid\",\"expires\":\"2026-08-17T05:24:18Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-16T05:23:18Z\",\"notAfter\":\"2026-11-14T05:24:18Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/AAukKRZxJYrXHCz6SWvPyQCaOBUqmjfd\"],\"finalize\":\"https://ca.foo/acme/acme/order/S5nNYB1qG94ToXl0Xbt9zFvNQWBmJNG6/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/EyFLvEwTIrGmvpSNSGtjbNrSmiENpUBE\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6636200.972264] ca step-ca[204]: time="2026-08-16T05:24:18Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQcOLEOyieiFSWUXROjC0nBDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTYwNTIzMThaFw0yNjExMTQwNTI0MThaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEUDWle5KqJTF40TzrtUoD5Nv4bz44a8RyU/w3qyXJSvcQVzKjsQeqpHR5tyVIRPSQh6EW0FfRLQtSnx/Yt5EQaqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBRvT7UnbKA5iN06SEFXxftnBCIvwzAfBgNVHSMEGDAWgBRw4uzwlGGVaAKDHgKDv12Gw4SqOzATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAMHrjIf6rXgmsOZBTfNxYSwDzjETPTQAo2MJfE2A4636AiEAlzOAnV4/GM2dyQ6JP8oEFV2x0r03YL9qa/M0PeBy5KU=" duration=1.177077ms duration-ns=1177077 fields.time="2026-08-16T05:24:18Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=SmEzR0VrWThia0g0ZnNmZ2ZOMzZ3Z1hFU2hxSnBlelc path=/acme/acme/certificate/EyFLvEwTIrGmvpSNSGtjbNrSmiENpUBE protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=378fda38-9dfb-4700-ba64-ae88f7bbf5c0 sans="map[dns:[test.foo]]" serial=150050974657254407352825947683604473604 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-16T05:23:18Z" valid-to="2026-11-14T05:24:18Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1008 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:24:11 2026 GMT container-test-run-certificates> * expire date: Sep 15 05:24:11 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 1b30db container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6636201.458875] server nginx[369]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6636201.459118] server nginx[369]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6636201.815063] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 16 05:23:18 2026 GMT container-test-run-certificates> * expire date: Nov 14 05:24:18 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 56426 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1722 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 70:e2:c4:3b:28:9e:88:54:96:51:74:4e:8c:2d:27:04 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 16 05:23:18 2026 GMT container-test-run-certificates> Not After : Nov 14 05:24:18 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:50:35:a5:7b:92:aa:25:31:78:d1:3c:eb:b5:4a: container-test-run-certificates> 03:e4:db:f8:6f:3e:38:6b:c4:72:53:fc:37:ab:25: container-test-run-certificates> c9:4a:f7:10:57:32:a3:b1:07:aa:a4:74:79:b7:25: container-test-run-certificates> 48:44:f4:90:87:a1:16:d0:57:d1:2d:0b:52:9f:1f: container-test-run-certificates> d8:b7:91:10:6a container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 6F:4F:B5:27:6C:A0:39:88:DD:3A:48:41:57:C5:FB:67:04:22:2F:C3 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 70:E2:EC:F0:94:61:95:68:02:83:1E:02:83:BF:5D:86:C3:84:AA:3B container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:c1:eb:8c:87:fa:ad:78:26:b0:e6:41:4d:f3: container-test-run-certificates> 71:61:2c:03:ce:31:13:3d:34:00:a3:63:09:7c:4d:80:e3:ad: container-test-run-certificates> fa:02:21:00:97:33:80:9d:5e:3f:18:cd:9d:c9:0e:89:3f:ca: container-test-run-certificates> 04:15:5d:b1:d2:bd:37:60:bf:6a:6b:f3:34:3d:e0:72:e4:a5 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 10.09 seconds) container-test-run-certificates> test script finished in 12.05s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 51) container-test-run-certificates> kill NspawnMachine (pid 56) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 57) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-16T05:24:22.743Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-16T05:24:23.374Z level=INFO msg="Uploading 1 narinfos" time=2026-08-16T05:24:23.511Z level=INFO msg="Upload complete. (1.161s)"