container-test-run-certificates
default.checks.aarch64-linux.certificates
· build #393
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15client: Waiting for journal at /build/vm-state-client/var/log/journal...16server: systemd-nspawn running (pid 57)17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26░ Spawning container client on /build/vm-state-client.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container ca on /build/vm-state-ca.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container server on /build/vm-state-server.31ca # [6018449.685220] ca systemd-journald[78]: Journal started32ca # [6018449.685270] ca systemd-journald[78]: Runtime Journal (/run/log/journal/0c00c0b60f55456e9a56573482876220) is 8M, max 2.5G, 2.4G free.33ca # [6018449.691351] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.34ca # [6018449.700639] ca systemd[1]: Starting Flush Journal to Persistent Storage...35client # [6018449.684997] client systemd-journald[69]: Journal started36ca # [6018449.701633] ca systemd[1]: Starting Network Name Resolution...37client # [6018449.685053] client systemd-journald[69]: Runtime Journal (/run/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2) is 8M, max 2.5G, 2.4G free.38ca # [6018449.702364] ca systemd[1]: Starting Create Static Device Nodes in /dev...39client # [6018449.691378] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.40ca # [6018449.710312] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/0c00c0b60f55456e9a56573482876220 is 1.506ms for 6 entries.41client # [6018449.700715] client systemd[1]: Starting Flush Journal to Persistent Storage...42ca # [6018449.710312] ca systemd-journald[78]: System Journal (/var/log/journal/0c00c0b60f55456e9a56573482876220) is 8M, max 4G, 3.9G free.43client # [6018449.701608] client systemd[1]: Starting Network Name Resolution...44ca # [6018449.719729] ca systemd[1]: Finished Create Static Device Nodes in /dev.45client # [6018449.702349] client systemd[1]: Starting Create Static Device Nodes in /dev...46ca # [6018449.719974] ca systemd[1]: Reached target Preparation for Local File Systems.47client # [6018449.710307] client systemd-journald[69]: Time spent on flushing to /var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2 is 1.446ms for 6 entries.48ca # [6018449.720071] ca systemd[1]: Reached target Local File Systems.49ca # [6018449.720811] ca systemd[1]: Listening on Boot Loader Control Service Socket.50ca # [6018449.720860] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container51client # [6018449.710307] client systemd-journald[69]: System Journal (/var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2) is 8M, max 4G, 3.9G free.52ca # [6018449.721745] ca systemd[1]: Starting Save Transient machine-id to Disk...53client # [6018449.716695] client systemd[1]: Finished Create Static Device Nodes in /dev.54ca # [6018449.721780] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys55client # [6018449.716979] client systemd[1]: Reached target Preparation for Local File Systems.56ca # [6018449.747203] ca systemd[1]: Finished Flush Journal to Persistent Storage.57client # [6018449.717066] client systemd[1]: Reached target Local File Systems.58ca # [6018449.749178] ca systemd[1]: Starting Create System Files and Directories...59client # [6018449.717804] client systemd[1]: Listening on Boot Loader Control Service Socket.60ca # [6018449.766014] ca systemd-tmpfiles[139]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted61client # [6018449.717843] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container62ca # [6018449.766229] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal failed: Operation not permitted63server # [6018449.685364] server systemd-journald[69]: Journal started64client # [6018449.718706] client systemd[1]: Starting Save Transient machine-id to Disk...65server # [6018449.685419] server systemd-journald[69]: Runtime Journal (/run/log/journal/540c6d0dc03647e08e21ffb1bc9863fd) is 8M, max 2.5G, 2.4G free.66ca # [6018449.766372] ca systemd-tmpfiles[139]: fchmod() of /var/log/journal/0c00c0b60f55456e9a56573482876220 failed: Operation not permitted67server # [6018449.693117] server systemd[1]: Finished Apply Kernel Variables.68client # [6018449.718744] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys69client # [6018449.746373] client systemd[1]: Finished Flush Journal to Persistent Storage.70client # [6018449.748314] client systemd[1]: Starting Create System Files and Directories...71client # [6018449.763512] client systemd-tmpfiles[129]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted72client # [6018449.763728] client systemd-tmpfiles[129]: fchmod() of /var/log/journal failed: Operation not permitted73client # [6018449.763872] client systemd-tmpfiles[129]: fchmod() of /var/log/journal/34488fb0b15a4686b12fc7ffa5c0e7f2 failed: Operation not permitted74client # [6018449.764120] client systemd-tmpfiles[129]: fchmod() of /run/log/journal failed: Operation not permitted75client # [6018449.765656] client systemd[1]: Finished Create System Files and Directories.76client # [6018449.766867] client systemd[1]: Starting Rebuild Journal Catalog...77client # [6018449.767799] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...78client # [6018449.779497] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.79client # [6018449.787434] client systemd[1]: Finished Rebuild Journal Catalog.80client # [6018449.789515] client systemd[1]: Starting Update is Completed...81client # [6018449.804454] client systemd[1]: Finished Update is Completed.82client # [6018449.824465] client systemd[1]: Finished Firewall.83client # [6018449.824617] client systemd[1]: Reached target Preparation for Network.84client # [6018449.824834] client systemd[1]: Listening on Network Management Resolve Hook Socket.85client # [6018449.825888] client systemd[1]: Starting Network Management...86ca # [6018449.766652] ca systemd-tmpfiles[139]: fchmod() of /run/log/journal failed: Operation not permitted87server # [6018449.702922] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.88ca # [6018449.768283] ca systemd[1]: Finished Create System Files and Directories.89server # [6018449.715648] server systemd[1]: Starting Flush Journal to Persistent Storage...90ca # [6018449.769411] ca systemd[1]: Starting Rebuild Journal Catalog...91server # [6018449.716644] server systemd[1]: Starting Network Name Resolution...92ca # [6018449.770159] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...93ca # [6018449.781691] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.94server # [6018449.717144] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed to spawn executor: No such file or directory95ca # [6018449.787637] ca systemd[1]: Finished Rebuild Journal Catalog.96server # [6018449.717170] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed to spawn 'start' task: No such file or directory97ca # [6018449.788652] ca systemd[1]: Starting Update is Completed...98server # [6018449.717206] server systemd[1]: systemd-tmpfiles-setup-dev.service: Failed with result 'resources'.99ca # [6018449.798903] ca systemd[1]: Finished Update is Completed.100server # [6018449.717258] server systemd[1]: Failed to start Create Static Device Nodes in /dev.101server # [6018449.717405] server systemd[1]: Reached target Preparation for Local File Systems.102server # [6018449.717499] server systemd[1]: Reached target Local File Systems.103server # [6018449.718412] server systemd[1]: Listening on Boot Loader Control Service Socket.104server # [6018449.718458] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container105server # [6018449.719168] server systemd[1]: Starting Save Transient machine-id to Disk...106server # [6018449.719202] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys107server # [6018449.725040] server systemd-journald[69]: Time spent on flushing to /var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd is 1.834ms for 16 entries.108server # [6018449.725040] server systemd-journald[69]: System Journal (/var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd) is 8M, max 4G, 3.9G free.109server # [6018449.747507] server systemd[1]: Finished Flush Journal to Persistent Storage.110server # [6018449.749467] server systemd[1]: Starting Create System Files and Directories...111server # [6018449.764382] server systemd-tmpfiles[127]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted112server # [6018449.764606] server systemd-tmpfiles[127]: fchmod() of /var/log/journal failed: Operation not permitted113server # [6018449.764758] server systemd-tmpfiles[127]: fchmod() of /var/log/journal/540c6d0dc03647e08e21ffb1bc9863fd failed: Operation not permitted114server # [6018449.765000] server systemd-tmpfiles[127]: fchmod() of /run/log/journal failed: Operation not permitted115server # [6018449.767275] server systemd[1]: Finished Create System Files and Directories.116server # [6018449.768519] server systemd[1]: Starting Rebuild Journal Catalog...117server # [6018449.769254] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...118server # [6018449.780490] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.119server # [6018449.787422] server systemd[1]: Finished Rebuild Journal Catalog.120server # [6018449.788629] server systemd[1]: Starting Update is Completed...121server # [6018449.802802] server systemd[1]: Finished Update is Completed.122ca # [6018449.880237] ca systemd[1]: Finished Firewall.123ca # [6018449.880873] ca systemd[1]: Reached target Preparation for Network.124ca # [6018449.881351] ca systemd[1]: Listening on Network Management Resolve Hook Socket.125ca # [6018449.882371] ca systemd[1]: Starting Network Management...126ca # [6018449.958691] ca systemd[1]: Finished Save Transient machine-id to Disk.127client # [6018449.956510] client systemd[1]: Finished Save Transient machine-id to Disk.128server # [6018449.880268] server systemd[1]: Finished Firewall.129server # [6018449.880461] server systemd[1]: Reached target Preparation for Network.130server # [6018449.880681] server systemd[1]: Listening on Network Management Resolve Hook Socket.131server # [6018449.881766] server systemd[1]: Starting Network Management...132server # [6018449.958693] server systemd[1]: Finished Save Transient machine-id to Disk.133client # [6018450.382114] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted134client # [6018450.382232] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted135client # [6018450.389137] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.136client # [6018450.389304] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.137client # [6018450.389560] client systemd-networkd[182]: lo: Link UP138client # [6018450.389564] client systemd-networkd[182]: lo: Gained carrier139client # [6018450.389743] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.140client # [6018450.390105] client systemd[1]: Started Network Management.141client # [6018450.390200] client systemd-networkd[182]: eth1: Link UP142client # [6018450.390564] client systemd-networkd[182]: eth1: Gained carrier143client # [6018450.391168] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...144client # [6018450.446730] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.145client # [6018450.557694] client systemd-resolved[96]: Positive Trust Anchors:146client # [6018450.557707] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d147client # [6018450.557710] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16148client # [6018450.557745] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test149client # [6018450.580199] client systemd-resolved[96]: Using system hostname 'client'.150client # [6018450.581557] client systemd[1]: Started Network Name Resolution.151client # [6018450.581640] client systemd[1]: Reached target Network.152client # [6018450.581705] client systemd[1]: Reached target System Initialization.153client # [6018450.581758] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container154client # [6018450.581787] client systemd[1]: Started Daily Cleanup of Temporary Directories.155client # [6018450.581806] client systemd[1]: Reached target Timer Units.156client # [6018450.581941] client systemd[1]: Listening on D-Bus System Message Bus Socket.157client # [6018450.582063] client systemd[1]: Listening on Nix Daemon Socket.158client # [6018450.582162] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.159client # [6018450.582186] client systemd[1]: Reached target Socket Units.160client # [6018450.582221] client systemd[1]: Reached target Basic System.161client # [6018450.583315] client systemd[1]: Starting Import lastlog data into lastlog2 database...162client # [6018450.584254] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...163client # [6018450.585528] client systemd[1]: Starting D-Bus System Message Bus...164client # [6018450.635260] client systemd[1]: Finished Import lastlog data into lastlog2 database.165ca # [6018450.382115] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted166ca # [6018450.382212] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted167ca # [6018450.389133] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.168ca # [6018450.389305] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.169ca # [6018450.389521] ca systemd-networkd[195]: lo: Link UP170ca # [6018450.389525] ca systemd-networkd[195]: lo: Gained carrier171ca # [6018450.389737] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.172ca # [6018450.390166] ca systemd[1]: Started Network Management.173ca # [6018450.390267] ca systemd-networkd[195]: eth1: Link UP174ca # [6018450.390582] ca systemd-networkd[195]: eth1: Gained carrier175ca # [6018450.391728] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...176ca # [6018450.446807] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.177ca # [6018450.565318] ca systemd-resolved[106]: Positive Trust Anchors:178ca # [6018450.565329] ca systemd-resolved[106]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d179ca # [6018450.565333] ca systemd-resolved[106]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16180ca # [6018450.565368] ca systemd-resolved[106]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test181ca # [6018450.588968] ca systemd-resolved[106]: Using system hostname 'ca'.182ca # [6018450.590339] ca systemd[1]: Started Network Name Resolution.183ca # [6018450.590420] ca systemd[1]: Reached target Network.184ca # [6018450.590482] ca systemd[1]: Reached target Network is Online.185ca # [6018450.590521] ca systemd[1]: Reached target System Initialization.186ca # [6018450.590710] ca systemd[1]: Started Renew ACME Certificate for ca.foo.187ca # [6018450.590741] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container188ca # [6018450.590763] ca systemd[1]: Started Daily Cleanup of Temporary Directories.189ca # [6018450.590779] ca systemd[1]: Reached target Timer Units.190ca # [6018450.590889] ca systemd[1]: Listening on D-Bus System Message Bus Socket.191ca # [6018450.590992] ca systemd[1]: Listening on Nix Daemon Socket.192ca # [6018450.591096] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.193ca # [6018450.591114] ca systemd[1]: Reached target Socket Units.194ca # [6018450.591146] ca systemd[1]: Reached target Basic System.195ca # [6018450.621054] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...196ca # [6018450.621938] ca systemd[1]: Starting Import lastlog data into lastlog2 database...197ca # [6018450.621985] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem198ca # [6018450.622908] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...199ca # [6018450.623968] ca systemd[1]: Starting step-ca service...200ca # [6018450.625314] ca systemd[1]: Starting D-Bus System Message Bus...201server # [6018450.386565] server systemd-networkd[184]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted202server # [6018450.386658] server systemd-networkd[184]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted203server # [6018450.393505] server systemd-networkd[184]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.204server # [6018450.393672] server systemd-networkd[184]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.205server # [6018450.393842] server systemd-networkd[184]: lo: Link UP206server # [6018450.393847] server systemd-networkd[184]: lo: Gained carrier207server # [6018450.394059] server systemd-networkd[184]: eth1: Configuring with /etc/systemd/network/40-eth1.network.208server # [6018450.394473] server systemd[1]: Started Network Management.209server # [6018450.394533] server systemd-networkd[184]: eth1: Link UP210server # [6018450.394773] server systemd-networkd[184]: eth1: Gained carrier211server # [6018450.436956] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...212server # [6018450.448739] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.213server # [6018450.565690] server systemd-resolved[103]: Positive Trust Anchors:214server # [6018450.565700] server systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d215server # [6018450.565704] server systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16216server # [6018450.565739] server systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test217server # [6018450.588693] server systemd-resolved[103]: Using system hostname 'server'.218server # [6018450.590130] server systemd[1]: Started Network Name Resolution.219server # [6018450.590214] server systemd[1]: Reached target Network.220server # [6018450.590279] server systemd[1]: Reached target Network is Online.221server # [6018450.590324] server systemd[1]: Reached target System Initialization.222server # [6018450.590532] server systemd[1]: Started Renew ACME Certificate for test.foo.223server # [6018450.590572] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container224server # [6018450.590593] server systemd[1]: Started Daily Cleanup of Temporary Directories.225server # [6018450.590610] server systemd[1]: Reached target Timer Units.226server # [6018450.590741] server systemd[1]: Listening on D-Bus System Message Bus Socket.227server # [6018450.590850] server systemd[1]: Listening on Nix Daemon Socket.228server # [6018450.590953] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.229server # [6018450.590973] server systemd[1]: Reached target Socket Units.230server # [6018450.591006] server systemd[1]: Reached target Basic System.231server # [6018450.621054] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...232server # [6018450.623108] server systemd[1]: Starting Import lastlog data into lastlog2 database...233server # [6018450.623157] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem234server # [6018450.624046] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...235server # [6018450.626857] server systemd[1]: Starting D-Bus System Message Bus...236server # [6018450.642235] server systemd[1]: Finished Import lastlog data into lastlog2 database.237client # [6018450.674098] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.238ca # [6018450.641102] ca systemd[1]: Finished Import lastlog data into lastlog2 database.239client # [6018450.770640] client nsncd[189]: Aug 17 15:11:16.823 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"240ca # [6018450.674321] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.241server # [6018450.674653] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.242ca # [6018450.730006] ca acme-setup-privileged[201]: + set -euo pipefail243server # [6018450.720644] server acme-setup-privileged[190]: + set -euo pipefail244ca # [6018450.730006] ca acme-setup-privileged[201]: + cd /var/lib/acme245server # [6018450.720644] server acme-setup-privileged[190]: + cd /var/lib/acme246ca # [6018450.730389] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts247server # [6018450.721031] server acme-setup-privileged[190]: + chmod -R u=rwX,g=,o= .lego/accounts248ca # [6018450.731444] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts249server # [6018450.722024] server acme-setup-privileged[190]: + chown -R acme .lego/accounts250ca # [6018450.732972] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo251client # [6018450.770823] client systemd[1]: Started Name Service Cache Daemon (nsncd).252ca # [6018450.733009] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'253client # [6018450.770878] client systemd[1]: Reached target Host and Network Name Lookups.254ca # [6018450.733009] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo255server # [6018450.723553] server acme-setup-privileged[190]: + for fixpath in test.foo .lego/test.foo256ca # [6018450.733009] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'257server # [6018450.723587] server acme-setup-privileged[190]: + '[' -d test.foo ']'258ca # [6018450.755813] ca nsncd[203]: Aug 17 15:11:16.808 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"259server # [6018450.723587] server acme-setup-privileged[190]: + for fixpath in test.foo .lego/test.foo260ca # [6018450.780523] ca systemd[1]: Started Name Service Cache Daemon (nsncd).261server # [6018450.723587] server acme-setup-privileged[190]: + '[' -d .lego/test.foo ']'262ca # [6018450.780675] ca systemd[1]: Reached target Host and Network Name Lookups.263client # [6018450.770938] client systemd[1]: Reached target User and Group Name Lookups.264ca # [6018450.780743] ca systemd[1]: Reached target User and Group Name Lookups.265server # [6018450.747388] server nsncd[192]: Aug 17 15:11:16.800 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"266client # [6018450.781441] client systemd[1]: Starting User Login Management...267server # [6018450.747465] server systemd[1]: Started Name Service Cache Daemon (nsncd).268client # [6018450.782583] client systemd[1]: Starting Permit User Sessions...269server # [6018450.747533] server systemd[1]: Reached target Host and Network Name Lookups.270client # [6018450.792303] client systemd[1]: Finished Permit User Sessions.271ca # [6018450.782467] ca systemd[1]: Starting User Login Management...272client # [6018450.793472] client systemd[1]: Started Console Getty.273server # [6018450.747592] server systemd[1]: Reached target User and Group Name Lookups.274client # [6018450.793515] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0275ca # [6018450.783412] ca systemd[1]: Starting Permit User Sessions...276client # [6018450.793534] client systemd[1]: Reached target Login Prompts.277server # [6018450.781062] server systemd[1]: Starting User Login Management...278server # [6018450.781999] server systemd[1]: Starting Permit User Sessions...279server # [6018450.792075] server systemd[1]: Finished Permit User Sessions.280ca # [6018450.792895] ca systemd[1]: Finished Permit User Sessions.281server # [6018450.793228] server systemd[1]: Started Console Getty.282ca # [6018450.793995] ca systemd[1]: Started Console Getty.283server # [6018450.793266] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0284server # [6018450.793286] server systemd[1]: Reached target Login Prompts.285ca # [6018450.794041] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0286ca # [6018450.794059] ca systemd[1]: Reached target Login Prompts.287server # [6018450.903116] server dbus-broker-launch[193]: Looking up NSS user entry for 'systemd-timesync'...288server # [6018450.903958] server dbus-broker-launch[193]: NSS returned no entry for 'systemd-timesync'289server # [6018450.903958] server dbus-broker-launch[193]: Invalid user-name in /nix/store/lxnlg1wvz5bx4xfzc75k21l11ngxkyck-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"290server # [6018450.904384] server systemd[1]: Started D-Bus System Message Bus.291server # [6018450.911476] server dbus-broker-launch[193]: Ready292ca # [6018450.911413] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...293ca # [6018450.912606] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'294ca # [6018450.912606] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/mfvkn1zwby5692v4kx3ynjdz34b2lkq3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"295ca # [6018450.913040] ca systemd[1]: Started D-Bus System Message Bus.296ca # [6018450.920288] ca dbus-broker-launch[205]: Ready297client # [6018451.000333] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...298client # [6018451.001139] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'299client # [6018451.001139] client dbus-broker-launch[190]: Invalid user-name in /nix/store/s0a40wv0lnwiz13r43fk318ri3wv536k-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"300client # [6018451.001522] client systemd[1]: Started D-Bus System Message Bus.301client # [6018451.008375] client dbus-broker-launch[190]: Ready302ca # [6018451.456334] ca systemd-networkd[195]: eth1: Gained IPv6LL303ca # [6018451.466466] ca systemd-logind[230]: New seat seat0.304ca # [6018451.466675] ca systemd[1]: Started User Login Management.305ca # [6018451.532513] ca systemd[1]: Starting linger-users.service...306ca # [6018451.535534] ca acme-setup-start[219]: + set -euo pipefail307ca # [6018451.535804] ca acme-setup-start[219]: + test -e ca/key.pem308ca # [6018451.535804] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local309ca # [6018451.545619] ca systemd[1]: linger-users.service: Deactivated successfully.310ca # [6018451.545747] ca systemd[1]: Finished linger-users.service.311ca # [6018451.556109] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.312ca # [6018451.557684] ca systemd[1]: Starting Ensure certificate for ca.foo...313client # [6018451.456210] client systemd-logind[205]: New seat seat0.314client # [6018451.456446] client systemd[1]: Started User Login Management.315client # [6018451.458011] client systemd[1]: Starting linger-users.service...316client # [6018451.542230] client systemd[1]: linger-users.service: Deactivated successfully.317client # [6018451.542404] client systemd[1]: Finished linger-users.service.318client # [6018451.542852] client systemd[1]: Reached target Multi-User System.319client # [6018451.543052] client systemd[1]: Startup finished in 2.298s.320server # [6018451.460516] server systemd-logind[218]: New seat seat0.321server # [6018451.461098] server systemd[1]: Started User Login Management.322server # [6018451.532513] server systemd[1]: Starting linger-users.service...323server # [6018451.533769] server acme-setup-start[206]: + set -euo pipefail324server # [6018451.533769] server acme-setup-start[206]: + test -e ca/key.pem325server # [6018451.534143] server acme-setup-start[206]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local326server # [6018451.547357] server systemd[1]: linger-users.service: Deactivated successfully.327server # [6018451.547437] server systemd[1]: Finished linger-users.service.328server # [6018451.553905] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.329server # [6018451.555940] server systemd[1]: Starting Ensure certificate for test.foo...330ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 331server # [6018451.840204] server systemd-networkd[184]: eth1: Gained IPv6LL332ca # [6018451.897314] ca step-ca[204]: badger 2026/08/17 15:11:17 INFO: All 0 tables opened in 0s333ca # [6018451.908085] ca step-ca[204]: 2026/08/17 15:11:17 Building new tls configuration using step-ca x509 Signer Interface334ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Starting Smallstep CA/0.30.2 (linux/arm64)335ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Documentation: https://u.step.sm/docs/ca336ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Community Discord: https://u.step.sm/discord337ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Config file: /etc/smallstep/ca.json338ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 The primary server URL is https://ca.foo:1443339ca # [6018451.917215] ca step-ca[204]: 2026/08/17 15:11:17 Root certificates are available at https://ca.foo:1443/roots.pem340ca # [6018451.917354] ca step-ca[204]: 2026/08/17 15:11:17 X.509 Root Fingerprint: f9e7a116c83d2375b63fd0fee2b3f3d2c10fa91e7eb2213ff0482fdebbf2ec31341ca # [6018451.917856] ca systemd[1]: Started step-ca service.342ca # [6018451.918134] ca step-ca[204]: 2026/08/17 15:11:17 Serving HTTPS on 0.0.0.0:1443 ...343server # [6018452.153175] server acme-test.foo-start[243]: Waiting to acquire lock in /run/acme/344server # [6018452.155902] server acme-test.foo-start[243]: + '[' -e out/acme-success ']'345server # [6018452.155995] server acme-test.foo-start[243]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=346server # [6018452.166623] server acme-test.foo-start[253]: + cd test.foo347server # [6018452.167017] server acme-test.foo-start[253]: + cp -vp cert.pem ../out/cert.pem348server # [6018452.167986] server acme-test.foo-start[254]: 'cert.pem' -> '../out/cert.pem'349server # [6018452.168310] server acme-test.foo-start[253]: + cp -vp key.pem ../out/key.pem350server # [6018452.169423] server acme-test.foo-start[253]: 'key.pem' -> '../out/key.pem'351server # [6018452.169655] server acme-test.foo-start[243]: + cat out/cert.pem ca/cert.pem352server # [6018452.171376] server acme-test.foo-start[243]: + cp ca/cert.pem out/chain.pem353server # [6018452.173064] server acme-test.foo-start[243]: + cat out/key.pem out/fullchain.pem354server # [6018452.174598] server acme-test.foo-start[243]: + for fixpath in out certificates355server # [6018452.174598] server acme-test.foo-start[243]: + '[' -d out ']'356server # [6018452.174671] server acme-test.foo-start[243]: + chmod -R u=rwX,g=rX,o= out357server # [6018452.176142] server acme-test.foo-start[243]: + chown -R acme:nginx out358server # [6018452.178647] server acme-test.foo-start[243]: + for fixpath in out certificates359server # [6018452.178685] server acme-test.foo-start[243]: + '[' -d certificates ']'360server # [6018452.181783] server systemd[1]: Finished Ensure certificate for test.foo.361server # [6018452.183282] server systemd[1]: Starting Nginx Web Server...362ca # [6018452.209734] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/363ca # [6018452.212233] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'364ca # [6018452.212350] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=365ca # [6018452.222927] ca acme-ca.foo-start[292]: + cd ca.foo366ca # [6018452.223319] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem367ca # [6018452.224389] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem'368ca # [6018452.224621] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem369ca # [6018452.225805] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem'370ca # [6018452.226046] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem371ca # [6018452.227473] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem372ca # [6018452.229582] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem373ca # [6018452.230375] ca acme-ca.foo-start[256]: + for fixpath in out certificates374ca # [6018452.230375] ca acme-ca.foo-start[256]: + '[' -d out ']'375ca # [6018452.230469] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out376ca # [6018452.231860] ca acme-ca.foo-start[256]: + chown -R acme:nginx out377ca # [6018452.234351] ca acme-ca.foo-start[256]: + for fixpath in out certificates378ca # [6018452.234351] ca acme-ca.foo-start[256]: + '[' -d certificates ']'379ca # [6018452.238856] ca systemd[1]: Finished Ensure certificate for ca.foo.380ca # [6018452.240357] ca systemd[1]: Starting Nginx Web Server...381client # [6018452.256142] client systemd-networkd[182]: eth1: Gained IPv6LL382server # [6018452.818795] server nginx-pre-start[265]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok383server # [6018452.819159] server nginx-pre-start[265]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful384server # [6018452.823796] server systemd[1]: Started Nginx Web Server.385server # [6018452.824201] server systemd[1]: Reached target Multi-User System.386server # [6018452.825523] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...387ca # [6018452.844971] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok388ca # [6018452.845414] ca nginx-pre-start[304]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful389ca # [6018452.855195] ca systemd[1]: Started Nginx Web Server.390ca # [6018452.855587] ca systemd[1]: Reached target Multi-User System.391ca # [6018452.857267] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...392ca # [6018453.519817] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/393ca # [6018453.522508] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail394ca # [6018453.522587] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9395ca # [6018453.522702] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt396ca # [6018453.523780] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run397ca # [6018453.539355] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 No key found for account none@none.tld. Generating a P256 key.398ca # [6018453.539745] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key399ca # [6018453.564661] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration="115.362µs" duration-ns=115362 fields.time="2026-08-17T15:11:19Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=07d1bdb6-3420-40da-bb73-f24fb2962b39 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=400ca # [6018453.565109] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] acme: Registering account for none@none.tld401server # [6018453.499002] server acme-order-renew-test.foo-start[268]: Waiting to acquire lock in /run/acme/402server # [6018453.501739] server acme-order-renew-test.foo-start[268]: + set -euo pipefail403server # [6018453.501819] server acme-order-renew-test.foo-start[268]: + echo ad12aa6741ce4bd2c108404server # [6018453.501935] server acme-order-renew-test.foo-start[268]: + cmp -s domainhash.txt certificates/domainhash.txt405server # [6018453.503168] server acme-order-renew-test.foo-start[268]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run406server # [6018453.518981] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 No key found for account none@none.tld. Generating a P256 key.407server # [6018453.519484] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key408server # [6018453.548931] server acme-order-renew-test.foo-start[279]: 2026/08/17 15:11:19 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority409server # [6018453.552427] server acme-order-renew-test.foo-start[268]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.410server # [6018453.552427] server acme-order-renew-test.foo-start[268]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.411server # [6018453.552427] server acme-order-renew-test.foo-start[268]: + exit 10412server # [6018453.555568] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a413server # [6018453.555677] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.414server # [6018453.555952] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.415server # [6018453.556263] server systemd[1]: Startup finished in 4.294s.416ca # [6018453.807658] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=242.3725ms duration-ns=242372500 fields.time="2026-08-17T15:11:19Z" method=HEAD name=ca nonce=eFhSdERBY2pIR1VzaTZnS0g2N3U5MmFkZjF0RWcxdWo path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=856b120b-b8de-48fa-9e8b-37a3e178890c size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=417ca # [6018453.824430] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=15.95838ms duration-ns=15958380 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=bzhkelV3ZUxWSXlSUlJ1YXAwR091WDJWbzA2S2ZlMks path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=79b0ca4b-e79b-47cd-8e5d-b110b640fab3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/mrHSHzOj2eI6q0KfSsHNsXv7JDucKUdE/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=418ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: !!!! HEADS UP !!!!419ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: Your account credentials have been saved in your420ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: configuration directory at "accounts".421ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: You should make a secure backup of this folder now. This422ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: configuration directory will also contain private keys423ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: generated by lego and certificates obtained from the ACME424ca # [6018453.824791] ca acme-order-renew-ca.foo-start[319]: server. Making regular backups of this folder is ideal.425ca # [6018453.824928] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate426ca # [6018453.831062] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=5.708439ms duration-ns=5708439 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=QTRyUm5BUEhnRTJ6Q2NoMWcyM3JKbmM2ckpmOVY2Wkg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2dfabd68-428b-4f60-91e4-b7844c7a13d3 response="{\"id\":\"9rkczlUdigqtkHZfmG1heQoQHdk2BS6E\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:11:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:10:19Z\",\"notAfter\":\"2026-11-15T15:11:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=427ca # [6018453.891518] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=3.482608ms duration-ns=3482608 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=SkJnR2dJOVNGMXVDWldFSEwyamxFb2xIWXozT25Balk path=/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0d4771aa-b2b1-4061-abd8-4e6397203368 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/tqWUxpeJm03mHaB7JGkhnsAzN7pxMPIM\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/sWs8vCPqPd781dW0J0XQgaIl4zWHgo4b\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:11:19Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=428ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f429ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01430ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: use http-01 solver431ca # [6018453.891868] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Trying to solve HTTP-01432ca # [6018453.896051] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=3.583049ms duration-ns=3583049 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=WkpJWGhJcUNtbUphYmh0bUpiVXdPUFo4RFhXSjhPTTU path=/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b82da9b3-3679-4fd8-9a67-b9646050864c response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"9RShoRvfpwkKtcWvagWdWVNjZ2JKqXr8\",\"validated\":\"2026-08-17T15:11:19Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f/oEKoABisY8mIEq6PYfwxvF3WKHkNbIIY\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=433ca # [6018453.896297] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] The server validated our request434ca # [6018453.896406] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates435ca # [6018453.906916] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info duration=9.588372ms duration-ns=9588372 fields.time="2026-08-17T15:11:19Z" method=POST name=ca nonce=WlRDWGxiU1NCM0dTSmo3dUpLcDJyOXFJOE1na3VmTDM path=/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=850f1255-1842-46da-98c9-9b4aaa182625 response="{\"id\":\"9rkczlUdigqtkHZfmG1heQoQHdk2BS6E\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:11:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:10:19Z\",\"notAfter\":\"2026-11-15T15:11:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/plDfpSPNTyFF6hHo2TvliwW3HSqxXK9f\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/9rkczlUdigqtkHZfmG1heQoQHdk2BS6E/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/MrWKjNIT4ZA9j0SMhRjHHpM0ORgA0eww\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=436ca # [6018453.909349] ca step-ca[204]: time="2026-08-17T15:11:19Z" level=info certificate="MIIB1DCCAXmgAwIBAgIQc+teFoUxEg6BkArufgawGDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTcxNTEwMTlaFw0yNjExMTUxNTExMTlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABLJaZE5k7xSexo1/n+hS+9U2njXUv2bTX26eqh6E6WjR/OZNlFnl94YS7s0/1BqUCb1MykGfwbx6KZDPjgM1+qGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUSni/sIKBNdDM2ryewPSED7QI14kwHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNJADBGAiEAsoJ9LgdnJ2362MgN0gQY1BytWQUDTdzv1l2uR2QRGU4CIQDjtzKw09cWLsjKV+5TL8o5qemALc71riisFnxRwvX52Q==" duration=1.585502ms duration-ns=1585502 fields.time="2026-08-17T15:11:19Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=TDNCbFBVTnM5VXBMdEx3VlZnekFHNEJlWGF3YUlLSmU path=/acme/acme/certificate/MrWKjNIT4ZA9j0SMhRjHHpM0ORgA0eww protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=4ff9f41d-1bf1-4e60-9aa2-0d559dedfef1 sans="map[dns:[ca.foo]]" serial=154083317607764157389064850371670093848 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-17T15:10:19Z" valid-to="2026-11-15T15:11:19Z"437ca # [6018453.909597] ca acme-order-renew-ca.foo-start[319]: 2026/08/17 15:11:19 [INFO] [ca.foo] Server responded with a certificate.438ca # [6018453.915365] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/439ca # [6018453.917337] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success440ca # [6018453.918938] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem441ca # [6018453.919915] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed442ca # [6018453.921416] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate443ca # [6018453.921416] ca acme-order-renew-ca.foo-start[307]: Installing new certificate444ca # [6018453.921475] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem445ca # [6018453.923798] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'446ca # [6018453.924255] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem447ca # [6018453.925721] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem'448ca # [6018453.925982] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem449ca # [6018453.927542] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'450ca # [6018453.927762] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem451ca # [6018453.929324] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem452ca # [6018453.930892] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates453ca # [6018453.930892] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']'454ca # [6018453.930960] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out455ca # [6018453.932504] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out456ca # [6018453.935240] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates457ca # [6018453.935240] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']'458ca # [6018453.935329] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates459ca # [6018453.936648] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates460ca # [6018453.939391] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/.461ca # [6018454.087980] ca systemd[1]: Reloading Nginx Web Server...462ca # [6018454.095580] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.463ca # [6018454.136297] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.464ca # [6018454.869087] ca nginx[368]: nginx: the configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf syntax is ok465ca # [6018454.869417] ca nginx[368]: nginx: configuration file /nix/store/y0w3rf0mygndzvcgy9cmg2mqb83s730b-nginx.conf test is successful466ca # [6018457.002254] ca systemd[1]: Reloaded Nginx Web Server.467ca # [6018457.002549] ca systemd[1]: Startup finished in 7.728s.468ca # [6018457.496416] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...469ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 7.20 seconds)470ca # [6018458.818954] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/471ca # [6018458.822309] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail472ca # [6018458.822387] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9473ca # [6018458.822503] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt474ca # [6018458.823531] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']'475ca # [6018458.823562] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']'476ca # [6018458.823974] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key477ca # [6018458.826187] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'478ca # [6018458.826224] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic479ca # [6018458.864145] ca step-ca[204]: time="2026-08-17T15:11:24Z" level=info duration="49.64µs" duration-ns=49640 fields.time="2026-08-17T15:11:24Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ae403cb7-a276-4343-b2a5-5dc0e57f97b9 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=480ca # [6018458.864568] ca acme-order-renew-ca.foo-start[392]: 2026/08/17 15:11:24 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint481ca # [6018458.864568] ca acme-order-renew-ca.foo-start[392]: 2026/08/17 15:11:24 [INFO] [ca.foo] The certificate expires at 2026-11-15T15:11:19Z, the renewal can be performed in 1439h59m34.082346401s: no renewal.482ca # [6018458.864994] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/483ca # [6018458.866664] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success484ca # [6018458.868063] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem485ca # [6018458.869163] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates486ca # [6018458.869190] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']'487ca # [6018458.869190] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out488ca # [6018458.870610] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out489ca # [6018458.873797] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates490ca # [6018458.873818] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']'491ca # [6018458.873835] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates492ca # [6018458.875264] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates493ca # [6018458.877240] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/.494ca # [6018459.027620] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.495ca # [6018459.027826] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.496server: must succeed: systemctl restart acme-test.foo.service497server # [6018462.054316] server systemd[1]: acme-test.foo.service: Deactivated successfully.498server # [6018462.054476] server systemd[1]: Stopped Ensure certificate for test.foo.499server # [6018462.055496] server systemd[1]: Stopping Ensure certificate for test.foo...500server # [6018462.056892] server systemd[1]: Starting Ensure certificate for test.foo...501server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.99 seconds)502client: waiting for success: curl -v https://test.foo503* Host test.foo:443 was resolved.504* IPv6: 2001:db8:1::3505* IPv4: 192.168.1.3506* Trying [2001:db8:1::3]:443...507* ALPN: curl offers h2,http/1.1508} [5 bytes data]509* TLSv1.3 (OUT), TLS handshake, Client hello (1):510} [1552 bytes data]511* SSL Trust Anchors:512* OpenSSL default paths (fallback)513{ [5 bytes data]514* TLSv1.3 (IN), TLS handshake, Server hello (2):515{ [1210 bytes data]516* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):517{ [1 bytes data]518* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):519{ [19 bytes data]520* TLSv1.3 (IN), TLS handshake, Certificate (11):521{ [1008 bytes data]522* TLSv1.3 (IN), TLS handshake, CERT verify (15):523{ [111 bytes data]524* TLSv1.3 (IN), TLS handshake, Finished (20):525{ [52 bytes data]526* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):527} [1 bytes data]528* TLSv1.3 (OUT), TLS handshake, Finished (20):529} [52 bytes data]530* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey531* ALPN: server accepted h2532* Server certificate:533* subject: CN=test.foo534* start date: Aug 17 15:11:18 2026 GMT535* expire date: Sep 16 15:11:18 2028 GMT536* issuer: CN=minica root ca 113551537* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384538* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384539* subjectAltName: "test.foo" matches cert's "test.foo"540* OpenSSL verify result: 13541* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)542* closing connection #0543curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)544More details here: https://curl.se/docs/sslcerts.html545546curl failed to verify the legitimacy of the server and therefore could not547establish a secure connection to it. To learn more about this situation and548how to fix it, please visit the webpage mentioned above.549server # [6018463.002169] server acme-test.foo-start[313]: Waiting to acquire lock in /run/acme/550server # [6018463.004744] server acme-test.foo-start[313]: + '[' -e out/acme-success ']'551server # [6018463.004787] server acme-test.foo-start[313]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=552server # [6018463.015267] server acme-test.foo-start[323]: + cd test.foo553server # [6018463.015622] server acme-test.foo-start[323]: + cp -vp cert.pem ../out/cert.pem554server # [6018463.016875] server acme-test.foo-start[324]: 'cert.pem' -> '../out/cert.pem'555server # [6018463.017092] server acme-test.foo-start[323]: + cp -vp key.pem ../out/key.pem556server # [6018463.018250] server acme-test.foo-start[323]: 'key.pem' -> '../out/key.pem'557server # [6018463.018462] server acme-test.foo-start[313]: + cat out/cert.pem ca/cert.pem558server # [6018463.020303] server acme-test.foo-start[313]: + cp ca/cert.pem out/chain.pem559server # [6018463.021737] server acme-test.foo-start[313]: + cat out/key.pem out/fullchain.pem560server # [6018463.023208] server acme-test.foo-start[313]: + for fixpath in out certificates561server # [6018463.023230] server acme-test.foo-start[313]: + '[' -d out ']'562server # [6018463.023247] server acme-test.foo-start[313]: + chmod -R u=rwX,g=rX,o= out563server # [6018463.024609] server acme-test.foo-start[313]: + chown -R acme:nginx out564server # [6018463.026989] server acme-test.foo-start[313]: + for fixpath in out certificates565server # [6018463.027034] server acme-test.foo-start[313]: + '[' -d certificates ']'566server # [6018463.030167] server systemd[1]: Finished Ensure certificate for test.foo.567server # [6018463.032614] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...568* Trying [2001:db8:1::3]:443...569* Host test.foo:443 was resolved.570* IPv6: 2001:db8:1::3571* IPv4: 192.168.1.3572* ALPN: curl offers h2,http/1.1573} [5 bytes data]574* TLSv1.3 (OUT), TLS handshake, Client hello (1):575} [1552 bytes data]576* SSL Trust Anchors:577* OpenSSL default paths (fallback)578{ [5 bytes data]579* TLSv1.3 (IN), TLS handshake, Server hello (2):580{ [1210 bytes data]581* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):582{ [1 bytes data]583* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):584{ [19 bytes data]585* TLSv1.3 (IN), TLS handshake, Certificate (11):586{ [1008 bytes data]587* TLSv1.3 (IN), TLS handshake, CERT verify (15):588{ [112 bytes data]589* TLSv1.3 (IN), TLS handshake, Finished (20):590{ [52 bytes data]591* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):592} [1 bytes data]593* TLSv1.3 (OUT), TLS handshake, Finished (20):594} [52 bytes data]595* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey596* ALPN: server accepted h2597* Server certificate:598* subject: CN=test.foo599* start date: Aug 17 15:11:18 2026 GMT600* expire date: Sep 16 15:11:18 2028 GMT601* issuer: CN=minica root ca 113551602* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384603* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384604* subjectAltName: "test.foo" matches cert's "test.foo"605* OpenSSL verify result: 13606* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)607* closing connection #0608curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)609More details here: https://curl.se/docs/sslcerts.html610611curl failed to verify the legitimacy of the server and therefore could not612establish a secure connection to it. To learn more about this situation and613how to fix it, please visit the webpage mentioned above.614server # [6018463.908422] server acme-order-renew-test.foo-start[331]: Waiting to acquire lock in /run/acme/615server # [6018463.910773] server acme-order-renew-test.foo-start[331]: + set -euo pipefail616server # [6018463.910850] server acme-order-renew-test.foo-start[331]: + echo ad12aa6741ce4bd2c108617server # [6018463.910964] server acme-order-renew-test.foo-start[331]: + cmp -s domainhash.txt certificates/domainhash.txt618server # [6018463.912402] server acme-order-renew-test.foo-start[331]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run619server # [6018463.956197] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] acme: Registering account for none@none.tld620server # [6018464.039826] server acme-order-renew-test.foo-start[339]: !!!! HEADS UP !!!!621server # [6018464.039826] server acme-order-renew-test.foo-start[339]: Your account credentials have been saved in your622server # [6018464.039826] server acme-order-renew-test.foo-start[339]: configuration directory at "accounts".623server # [6018464.039826] server acme-order-renew-test.foo-start[339]: You should make a secure backup of this folder now. This624server # [6018464.039826] server acme-order-renew-test.foo-start[339]: configuration directory will also contain private keys625server # [6018464.039826] server acme-order-renew-test.foo-start[339]: generated by lego and certificates obtained from the ACME626server # [6018464.039826] server acme-order-renew-test.foo-start[339]: server. Making regular backups of this folder is ideal.627server # [6018464.040287] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Obtaining bundled SAN certificate628server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm629server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01630server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: use http-01 solver631server # [6018464.110042] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Trying to solve HTTP-01632server # [6018464.118019] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] The server validated our request633server # [6018464.118133] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] acme: Validations succeeded; requesting certificates634server # [6018464.135089] server acme-order-renew-test.foo-start[339]: 2026/08/17 15:11:30 [INFO] [test.foo] Server responded with a certificate.635server # [6018464.140965] server acme-order-renew-test.foo-start[331]: + mv domainhash.txt certificates/636server # [6018464.143060] server acme-order-renew-test.foo-start[331]: + touch out/acme-success637server # [6018464.144707] server acme-order-renew-test.foo-start[331]: + cmp -s certificates/test.foo.crt out/fullchain.pem638server # [6018464.145870] server acme-order-renew-test.foo-start[331]: + touch out/renewed639server # [6018464.147431] server acme-order-renew-test.foo-start[331]: + echo Installing new certificate640server # [6018464.147431] server acme-order-renew-test.foo-start[331]: Installing new certificate641server # [6018464.147431] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.crt out/fullchain.pem642server # [6018464.148804] server acme-order-renew-test.foo-start[371]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'643server # [6018464.149126] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.key out/key.pem644server # [6018464.150565] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.key' -> 'out/key.pem'645server # [6018464.150835] server acme-order-renew-test.foo-start[331]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem646server # [6018464.153165] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'647server # [6018464.153480] server acme-order-renew-test.foo-start[331]: + ln -sf fullchain.pem out/cert.pem648server # [6018464.155942] server acme-order-renew-test.foo-start[331]: + cat out/key.pem out/fullchain.pem649server # [6018464.157517] server acme-order-renew-test.foo-start[331]: + for fixpath in out certificates650server # [6018464.157517] server acme-order-renew-test.foo-start[331]: + '[' -d out ']'651server # [6018464.157599] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=rX,o= out652server # [6018464.158970] server acme-order-renew-test.foo-start[331]: + chown -R acme:nginx out653ca # [6018463.955690] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration="47.961µs" duration-ns=47961 fields.time="2026-08-17T15:11:30Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=0c694dc0-7b5c-4722-9222-c522c2be6ffd response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=654ca # [6018464.032539] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=74.180942ms duration-ns=74180942 fields.time="2026-08-17T15:11:30Z" method=HEAD name=ca nonce=azQ2SkhYTW83S21RdHpoQmhPQkZyRUFhMVJGYU1lck0 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=96515ed3-e29d-43fc-9897-d5f5d867bd64 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=655ca # [6018464.039116] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=3.235325ms duration-ns=3235325 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=Nzc2bG15amlSUmNBbklKRUFsbzRBNDBUTDVnQktMcGQ path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=17717c9e-7e97-41e9-9cc4-c2236fe34db7 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/1XyedUjwFTFAoUev7vkYbUYQIffWXjH3/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=656ca # [6018464.047308] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=4.205818ms duration-ns=4205818 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=dlZZQjFkQlN6aGdFSEZ5alZsWUxaanBoNHQ2SVRCZGo path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7e5e192b-57cc-450b-a9e2-3c62449fecc8 response="{\"id\":\"8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:11:30Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:10:30Z\",\"notAfter\":\"2026-11-15T15:11:30Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm\"],\"finalize\":\"https://ca.foo/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=657ca # [6018464.109387] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=2.305592ms duration-ns=2305592 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=WGF1eXpYTUtJVzNRcGt6b0FtbXNvdnVzUW5qelY0Ulo path=/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm protocol=HTTP/1.1 referer= remote-address="::1" request-id=01add973-c190-43be-acd8-89be5dea4263 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/qOWVX2F7dLu6nx5GteUIiuaGRWS6kOEE\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/gsex4fZFYJpiXPIEMWeiQ93ohMgjnFYT\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:11:30Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=658ca # [6018464.117579] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=4.074576ms duration-ns=4074576 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=UXpnb0VFWkE3WEZGTTFsa1BUeXo4RzlzR0U0cVJ2SDk path=/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=e450a18d-1a30-4e38-92ea-68d726b04ef0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"xgqz8WbrEBz7KRerTUMJimBshHfCeD7w\",\"validated\":\"2026-08-17T15:11:30Z\",\"url\":\"https://ca.foo/acme/acme/challenge/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm/yQbDF4AqYKYOypS1A71W0c3peB4S1ZvB\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=659ca # [6018464.129239] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info duration=7.817307ms duration-ns=7817307 fields.time="2026-08-17T15:11:30Z" method=POST name=ca nonce=VmRqMDJScTJ1Y1NoSDNSUnVwNUV0aFNzQ3E5RXBzMGY path=/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=7b6239a7-428c-493a-bf16-d683b4b5d687 response="{\"id\":\"8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:11:30Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:10:30Z\",\"notAfter\":\"2026-11-15T15:11:30Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/j4NIYOLGQC6W4MT7uFMSqCO0ySVCVQbm\"],\"finalize\":\"https://ca.foo/acme/acme/order/8xIQ7oGedjdwvDBeLA2PsJ0ad1i1u1Hi/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/UR0FqcFT4ioErPgaXtejTEnfW7yiv4it\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=660ca # [6018464.134619] ca step-ca[204]: time="2026-08-17T15:11:30Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRALKZo0DnNND4QFAOSy0+yLkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE3MTUxMDMwWhcNMjYxMTE1MTUxMTMwWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABBjkrQsomOf3wpwWNxLQceIeGrwP5DSIToYLMElF2UiTbXKx2HREPj1XXyN8VN/R4PXrY39wfinAF08KsjTqruCjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUlCGtzyikyv2bCIc68C68QAUYKUowHwYDVR0jBBgwFoAUyrMkoOjEoJ4PmApsZSFe/i6TkO0wEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQC+B89/xWiiZpprV+qfgJRwNTmODmT75yjLTy/UD11FfwIhAKkhnP/0P/LYwPVxj+1uKInf0BmmDOo9L1MpkGOeEYvl duration=2.087868ms duration-ns=2087868 fields.time="2026-08-17T15:11:30Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=R0xkRHZDR2lNbFFyOXJQZllzUFpRVkVIMTZTdGVPWWs path=/acme/acme/certificate/UR0FqcFT4ioErPgaXtejTEnfW7yiv4it protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=4aae9898-e220-4c04-9239-33862b1440c0 sans="map[dns:[test.foo]]" serial=237400315843993538382245390548335511737 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-17T15:10:30Z" valid-to="2026-11-15T15:11:30Z"661server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + for fixpath in out certificates662server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + '[' -d certificates ']'663server # [6018464.161527] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=rX,o= certificates664server # [6018464.162901] server acme-order-renew-test.foo-start[331]: + chown -R acme:nginx certificates665server # [6018464.165685] server acme-order-renew-test.foo-start[331]: + chmod -R u=rwX,g=,o= accounts/.666server # [6018464.305748] server systemd[1]: Reloading Nginx Web Server...667server # [6018464.309493] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.668server # [6018464.309702] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.669* Host test.foo:443 was resolved.670* IPv6: 2001:db8:1::3671* IPv4: 192.168.1.3672* Trying [2001:db8:1::3]:443...673* ALPN: curl offers h2,http/1.1674} [5 bytes data]675* TLSv1.3 (OUT), TLS handshake, Client hello (1):676} [1552 bytes data]677* SSL Trust Anchors:678* OpenSSL default paths (fallback)679{ [5 bytes data]680* TLSv1.3 (IN), TLS handshake, Server hello (2):681{ [1210 bytes data]682* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):683{ [1 bytes data]684* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):685{ [19 bytes data]686* TLSv1.3 (IN), TLS handshake, Certificate (11):687{ [1008 bytes data]688* TLSv1.3 (IN), TLS handshake, CERT verify (15):689{ [110 bytes data]690* TLSv1.3 (IN), TLS handshake, Finished (20):691{ [52 bytes data]692* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):693} [1 bytes data]694* TLSv1.3 (OUT), TLS handshake, Finished (20):695} [52 bytes data]696* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey697* ALPN: server accepted h2698* Server certificate:699* subject: CN=test.foo700* start date: Aug 17 15:11:18 2026 GMT701* expire date: Sep 16 15:11:18 2028 GMT702* issuer: CN=minica root ca 113551703* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384704* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384705* subjectAltName: "test.foo" matches cert's "test.foo"706* OpenSSL verify result: 13707* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)708* closing connection #0709curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)710More details here: https://curl.se/docs/sslcerts.html711712curl failed to verify the legitimacy of the server and therefore could not713establish a secure connection to it. To learn more about this situation and714how to fix it, please visit the webpage mentioned above.715server # [6018465.133014] server nginx[389]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok716server # [6018465.133374] server nginx[389]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful717* Host test.foo:443 was resolved.718* IPv6: 2001:db8:1::3719* IPv4: 192.168.1.3720* Trying [2001:db8:1::3]:443...721* ALPN: curl offers h2,http/1.1722} [5 bytes data]723* TLSv1.3 (OUT), TLS handshake, Client hello (1):724} [1552 bytes data]725* SSL Trust Anchors:726* OpenSSL default paths (fallback)727{ [5 bytes data]728* TLSv1.3 (IN), TLS handshake, Server hello (2):729{ [1210 bytes data]730* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):731{ [1 bytes data]732* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):733{ [19 bytes data]734* TLSv1.3 (IN), TLS handshake, Certificate (11):735{ [1008 bytes data]736* TLSv1.3 (IN), TLS handshake, CERT verify (15):737{ [111 bytes data]738* TLSv1.3 (IN), TLS handshake, Finished (20):739{ [52 bytes data]740* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):741} [1 bytes data]742* TLSv1.3 (OUT), TLS handshake, Finished (20):743} [52 bytes data]744* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey745* ALPN: server accepted h2746* Server certificate:747* subject: CN=test.foo748* start date: Aug 17 15:11:18 2026 GMT749* expire date: Sep 16 15:11:18 2028 GMT750* issuer: CN=minica root ca 113551751* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384752* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384753* subjectAltName: "test.foo" matches cert's "test.foo"754* OpenSSL verify result: 13755* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)756* closing connection #0757curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)758More details here: https://curl.se/docs/sslcerts.html759760curl failed to verify the legitimacy of the server and therefore could not761establish a secure connection to it. To learn more about this situation and762how to fix it, please visit the webpage mentioned above.763server # [6018466.843826] server systemd[1]: Reloaded Nginx Web Server.764* Host test.foo:443 was resolved.765* IPv6: 2001:db8:1::3766* IPv4: 192.168.1.3767* Trying [2001:db8:1::3]:443...768* ALPN: curl offers h2,http/1.1769} [5 bytes data]770* TLSv1.3 (OUT), TLS handshake, Client hello (1):771} [1552 bytes data]772* SSL Trust Anchors:773* OpenSSL default paths (fallback)774{ [5 bytes data]775* TLSv1.3 (IN), TLS handshake, Server hello (2):776{ [1210 bytes data]777* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):778{ [1 bytes data]779* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):780{ [19 bytes data]781* TLSv1.3 (IN), TLS handshake, Certificate (11):782{ [931 bytes data]783* TLSv1.3 (IN), TLS handshake, CERT verify (15):784{ [79 bytes data]785* TLSv1.3 (IN), TLS handshake, Finished (20):786{ [52 bytes data]787* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):788} [1 bytes data]789* TLSv1.3 (OUT), TLS handshake, Finished (20):790} [52 bytes data]791* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey792* ALPN: server accepted h2793* Server certificate:794* subject: CN=test.foo795* start date: Aug 17 15:10:30 2026 GMT796* expire date: Nov 15 15:11:30 2026 GMT797* issuer: CN=Clan Intermediate CA798* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256799* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256800* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256801* subjectAltName: "test.foo" matches cert's "test.foo"802* OpenSSL verify result: 0803* SSL certificate verified via OpenSSL.804* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 36210 805 % Total % Received % Xferd Average Speed Time Time Time Current806 Dload Upload Total Spent Left Speed807 0 0 0 0 0 0 0 0 0* using HTTP/2808* [HTTP/2] [1] OPENED stream for https://test.foo/809* [HTTP/2] [1] [:method: GET]810* [HTTP/2] [1] [:scheme: https]811* [HTTP/2] [1] [:authority: test.foo]812* [HTTP/2] [1] [:path: /]813* [HTTP/2] [1] [user-agent: curl/8.21.0]814* [HTTP/2] [1] [accept: */*]815} [5 bytes data]816817818819820821* Request completely sent off822{ [5 bytes data]823* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):824{ [265 bytes data]825* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):826{ [265 bytes data]827828829830831832833834{ [5 bytes data]835100 20 100 20 0 0 848 0 0836* Connection #0 to host test.foo:443 left intact837client: (finished: waiting for success: curl -v https://test.foo, in 4.21 seconds)838client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2839Certificate:840 Data:841 Version: 3 (0x2)842 Serial Number:843 b2:99:a3:40:e7:34:d0:f8:40:50:0e:4b:2d:3e:c8:b9844 Signature Algorithm: ecdsa-with-SHA256845 Issuer: CN=Clan Intermediate CA846 Validity847 Not Before: Aug 17 15:10:30 2026 GMT848 Not After : Nov 15 15:11:30 2026 GMT849 Subject: CN=test.foo850 Subject Public Key Info:851 Public Key Algorithm: id-ecPublicKey852 Public-Key: (256 bit)853 pub:854 04:18:e4:ad:0b:28:98:e7:f7:c2:9c:16:37:12:d0:855 71:e2:1e:1a:bc:0f:e4:34:88:4e:86:0b:30:49:45:856 d9:48:93:6d:72:b1:d8:74:44:3e:3d:57:5f:23:7c:857 54:df:d1:e0:f5:eb:63:7f:70:7e:29:c0:17:4f:0a:858 b2:34:ea:ae:e0859 ASN1 OID: prime256v1860 NIST CURVE: P-256861 X509v3 extensions:862 X509v3 Key Usage: critical863 Digital Signature864 X509v3 Extended Key Usage: 865 TLS Web Server Authentication, TLS Web Client Authentication866 X509v3 Subject Key Identifier: 867 94:21:AD:CF:28:A4:CA:FD:9B:08:87:3A:F0:2E:BC:40:05:18:29:4A868 X509v3 Authority Key Identifier: 869 CA:B3:24:A0:E8:C4:A0:9E:0F:98:0A:6C:65:21:5E:FE:2E:93:90:ED870 X509v3 Subject Alternative Name: 871 DNS:test.foo872 1.3.6.1.4.1.37476.9000.64.1: 873 0......acme..874 Signature Algorithm: ecdsa-with-SHA256875 Signature Value:876 30:46:02:21:00:be:07:cf:7f:c5:68:a2:66:9a:6b:57:ea:9f:877 80:94:70:35:39:8e:0e:64:fb:e7:28:cb:4f:2f:d4:0f:5d:45:878 7f:02:21:00:a9:21:9c:ff:f4:3f:f2:d8:c0:f5:71:8f:ed:6e:879 28:89:df:d0:19:a6:0c:ea:3d:2f:53:29:90:63:9e:11:8b:e5880client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)881(finished: run the VM test script, in 18.44 seconds)882test script finished in 18.57s883cleanup884kill NspawnMachine (pid 53)885kill NspawnMachine (pid 54)886kill NspawnMachine (pid 57)887Container ca terminated by signal KILL.888Container client terminated by signal KILL.889(finished: cleanup, in 0.44 seconds)890Container server terminated by signal KILL.