these 85 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/ghcq9lqrgrnqlh5c76ap7sf5hc7llzjl-system-path.drv /nix/store/cf3qw56yjvv7h5bys067xfv6lib795pa-dbus-1.drv /nix/store/1lmha6fj3z5xay2h2msrzaavap4iham6-X-Restart-Triggers-dbus-broker.drv /nix/store/gig3s6lz6l69hwb5f61aw9x5maf612g5-unit-dbus-broker.service.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv /nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv /nix/store/07baf9hgh5w3l4g2kv1avd8czgxhmwp1-system-units.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv /nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv /nix/store/gq4y4apnihanyqjwd4jbb5k26dkag1mn-system-path.drv /nix/store/waggpma6jkik9i2lagk84qmd68zsfgid-dbus-1.drv /nix/store/jx482j8wlagnwfgwph885kphb5zk3i02-X-Restart-Triggers-dbus-broker.drv /nix/store/ldf12jpgb6ccimn80bk8xkfil0nfqw0b-unit-dbus-broker.service.drv /nix/store/8pkl9kwbppwzl1mmhzz173l4svxdx318-user-units.drv /nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv /nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv /nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv /nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv /nix/store/pznf4491q9192a8invxc95fsdgxqldvh-unit-dbus-broker.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/m8qyz3z6hl447s9vv76al7f5q91cj819-system-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/m533q9xl6k1z172rmdsslzk0ygqfgbzy-etc.drv /nix/store/dqi8jnh8ilgj9ik61i2vf3cfjnjvai5b-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/215dgxsc3i3skj7zkly8m4i5y58y65z5-nixos-system-ca-test.drv /nix/store/1m1i5rqcfvlnl5hqhhir4vzj1w2fw6mz-run-ca-nspawn.drv /nix/store/30dgcx7ngns309s9zwb1bym9z81minvl-system-path.drv /nix/store/y7zva3x9hij22x8qxzpgy2hnlg2424ml-dbus-1.drv /nix/store/b6fx8wml019jdpxvr3pj2q4prvbnv5j3-X-Restart-Triggers-dbus-broker.drv /nix/store/gs9a38v5m90717sj68ynx5x16a6jnxvv-unit-dbus-broker.service.drv /nix/store/cn10b8gph2h0bj1iw99sh9zi95fvq3cy-user-units.drv /nix/store/ppg2qrmb49q8rjyww6d0kxbf46cyx72l-unit-dbus-broker.service.drv /nix/store/d62j1hafqa6mg6sbcyrb7byk8xa8jnpz-system-units.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/2jhqbf9085wbq17vs0k6qcadi063m2il-etc.drv /nix/store/70anma4l6frz0ky11v6haglwgca9qgic-activate.drv /nix/store/zm0cihsyshm7q2zfp04jgq9727qwnjy1-nixos-system-client-test.drv /nix/store/2j9z16xmils7rzcd9qkbdls0ycysc71q-run-client-nspawn.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/q2m4j8zsryxcwia7fynhkjj17rfqd89w-unit-dbus-broker.service.drv /nix/store/ykwdx0z9vp0rjaj4nx22bds4l1lyzai1-user-units.drv /nix/store/g4kk4q8jmywavgdy5xa5ni7g0b0zcabl-etc.drv /nix/store/hkj3p5wrdsq7c0c3hmdv764ar74fa186-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/f27wpnqb2mw92japikwx8bxi184cjy0r-nixos-system-server-test.drv /nix/store/8a4lz2w92ph24331diimf0vqy5bkkqjz-run-server-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/fg5mx7wjpf62j63hkmzdgriy523fqhvz-driverConfiguration.json.drv /nix/store/5l8asdxa4gy343qnm51v1wig7mbsa9d7-nixos-test-driver-certificates.drv /nix/store/fwyw021b1wkl1hjlnah9m0nnbzdigx7b-container-test-run-certificates.drv this path will be fetched (21.7 MiB download, 71.4 MiB unpacked): /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/30dgcx7ngns309s9zwb1bym9z81minvl-system-path.drv' building '/nix/store/ghcq9lqrgrnqlh5c76ap7sf5hc7llzjl-system-path.drv' building '/nix/store/gq4y4apnihanyqjwd4jbb5k26dkag1mn-system-path.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/9yqhmxgjzkn0cvm9nm7wy099xg1wr0mx-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-acme-renew-test.foo.timer> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/cf3qw56yjvv7h5bys067xfv6lib795pa-dbus-1.drv' building '/nix/store/waggpma6jkik9i2lagk84qmd68zsfgid-dbus-1.drv' building '/nix/store/y7zva3x9hij22x8qxzpgy2hnlg2424ml-dbus-1.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/8afpvpn1i6i8b4yd4j676fqi82l3df0g-ca.json.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/b6fx8wml019jdpxvr3pj2q4prvbnv5j3-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/jx482j8wlagnwfgwph885kphb5zk3i02-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv' building '/nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/xq3dh13zf2a0bd5z6v4gh6ccvc3d31nj-unit-script-nginx-pre-start.drv' building '/nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/1lmha6fj3z5xay2h2msrzaavap4iham6-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/0y5dvjfxknxdymf8fgl8qlmv4srvxn2g-X-Restart-Triggers-step-ca.drv' building '/nix/store/gs9a38v5m90717sj68ynx5x16a6jnxvv-unit-dbus-broker.service.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/ldf12jpgb6ccimn80bk8xkfil0nfqw0b-unit-dbus-broker.service.drv' building '/nix/store/ppg2qrmb49q8rjyww6d0kxbf46cyx72l-unit-dbus-broker.service.drv' building '/nix/store/pznf4491q9192a8invxc95fsdgxqldvh-unit-dbus-broker.service.drv' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' building '/nix/store/ir77rykhiwsgxfd1pbdwpfbdlj4mg3hb-unit-nginx.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/gig3s6lz6l69hwb5f61aw9x5maf612g5-unit-dbus-broker.service.drv' building '/nix/store/q2m4j8zsryxcwia7fynhkjj17rfqd89w-unit-dbus-broker.service.drv' building '/nix/store/pwils17dwb8ahzmi4lby64mlbmk9bkch-unit-step-ca.service.drv' building '/nix/store/cn10b8gph2h0bj1iw99sh9zi95fvq3cy-user-units.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/8pkl9kwbppwzl1mmhzz173l4svxdx318-user-units.drv' building '/nix/store/ykwdx0z9vp0rjaj4nx22bds4l1lyzai1-user-units.drv' building '/nix/store/v1hp9jmkrxhmghl6q506r979s686fvlz-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/0pcg7h3g6bbjnlpb5mmjgz07fdrw26ld-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/zczkj6fzghss644rr24gpjm5bnn5lm32-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/48jf034cvqhxyjb8wrai18rfwr2bppf4-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/zjpqm91ra42i8pjd256ynm0pn5zf7maz-nss-cacert-3.126-hashed building '/nix/store/rkakbjc3l4v5ji4vkwla6kdvic1pyjqv-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/07baf9hgh5w3l4g2kv1avd8czgxhmwp1-system-units.drv' building '/nix/store/d62j1hafqa6mg6sbcyrb7byk8xa8jnpz-system-units.drv' building '/nix/store/m8qyz3z6hl447s9vv76al7f5q91cj819-system-units.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/g4kk4q8jmywavgdy5xa5ni7g0b0zcabl-etc.drv' building '/nix/store/2jhqbf9085wbq17vs0k6qcadi063m2il-etc.drv' building '/nix/store/m533q9xl6k1z172rmdsslzk0ygqfgbzy-etc.drv' building '/nix/store/hkj3p5wrdsq7c0c3hmdv764ar74fa186-activate.drv' building '/nix/store/70anma4l6frz0ky11v6haglwgca9qgic-activate.drv' building '/nix/store/dqi8jnh8ilgj9ik61i2vf3cfjnjvai5b-activate.drv' building '/nix/store/f27wpnqb2mw92japikwx8bxi184cjy0r-nixos-system-server-test.drv' building '/nix/store/zm0cihsyshm7q2zfp04jgq9727qwnjy1-nixos-system-client-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/215dgxsc3i3skj7zkly8m4i5y58y65z5-nixos-system-ca-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/8a4lz2w92ph24331diimf0vqy5bkkqjz-run-server-nspawn.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/2j9z16xmils7rzcd9qkbdls0ycysc71q-run-client-nspawn.drv' building '/nix/store/1m1i5rqcfvlnl5hqhhir4vzj1w2fw6mz-run-ca-nspawn.drv' building '/nix/store/fg5mx7wjpf62j63hkmzdgriy523fqhvz-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/5l8asdxa4gy343qnm51v1wig7mbsa9d7-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/fwyw021b1wkl1hjlnah9m0nnbzdigx7b-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/fwyw021b1wkl1hjlnah9m0nnbzdigx7b-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 53) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: systemd-nspawn running (pid 52) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.01 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> client # [6757718.690207] client systemd-journald[69]: Journal started container-test-run-certificates> client # [6757718.690254] client systemd-journald[69]: Runtime Journal (/run/log/journal/09d626217c094e02ba7fe0d6bfeccf1b) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6757718.706731] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6757718.731006] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6757718.732474] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6757718.733346] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6757718.739888] client systemd-journald[69]: Time spent on flushing to /var/log/journal/09d626217c094e02ba7fe0d6bfeccf1b is 1.491ms for 6 entries. container-test-run-certificates> client # [6757718.739888] client systemd-journald[69]: System Journal (/var/log/journal/09d626217c094e02ba7fe0d6bfeccf1b) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6757718.795282] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6757718.796199] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6757718.796290] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6757718.797056] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6757718.797100] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6757718.798105] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6757718.798130] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6757718.818343] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6757718.820015] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6757718.836497] client systemd-tmpfiles[144]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6757718.836694] client systemd-tmpfiles[144]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6757718.836826] client systemd-tmpfiles[144]: fchmod() of /var/log/journal/09d626217c094e02ba7fe0d6bfeccf1b failed: Operation not permitted container-test-run-certificates> client # [6757718.837126] client systemd-tmpfiles[144]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6757718.840362] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6757718.842272] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6757718.844757] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6757718.859039] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6757718.869599] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6757718.871150] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6757718.881598] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6757718.882611] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6757718.882795] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6757718.883020] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6757718.884410] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6757718.686023] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6757718.686080] ca systemd-journald[78]: Runtime Journal (/run/log/journal/63c8274920f949e2a868f52be27bf758) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [6757718.696777] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6757718.706028] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6757718.706847] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6757718.707511] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6757718.736752] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/63c8274920f949e2a868f52be27bf758 is 1.823ms for 6 entries. container-test-run-certificates> ca # [6757718.736752] ca systemd-journald[78]: System Journal (/var/log/journal/63c8274920f949e2a868f52be27bf758) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6757718.742081] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6757718.742302] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6757718.742449] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6757718.743156] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6757718.743197] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6757718.743851] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6757718.743879] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6757718.818343] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6757718.820044] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6757718.835264] ca systemd-tmpfiles[150]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6757718.835469] ca systemd-tmpfiles[150]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6757718.835609] ca systemd-tmpfiles[150]: fchmod() of /var/log/journal/63c8274920f949e2a868f52be27bf758 failed: Operation not permitted container-test-run-certificates> ca # [6757718.835822] ca systemd-tmpfiles[150]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6757718.837878] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6757718.839454] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6757718.840164] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6757718.857494] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6757718.860945] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6757718.862105] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6757718.876088] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6757718.893266] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6757718.893929] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6757718.894243] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6757718.895400] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [6757718.689648] server systemd-journald[69]: Journal started container-test-run-certificates> server # [6757718.689692] server systemd-journald[69]: Runtime Journal (/run/log/journal/6e809ba2d5074b3092243b81ff98c1f6) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [6757718.697183] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6757718.707690] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6757718.708646] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6757718.710206] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6757718.734692] server systemd-journald[69]: Time spent on flushing to /var/log/journal/6e809ba2d5074b3092243b81ff98c1f6 is 1.967ms for 6 entries. container-test-run-certificates> server # [6757718.734692] server systemd-journald[69]: System Journal (/var/log/journal/6e809ba2d5074b3092243b81ff98c1f6) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6757718.739254] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6757718.740080] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6757718.740191] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6757718.740913] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6757718.740957] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6757718.744066] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6757718.744094] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6757718.815168] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6757718.815921] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6757718.831598] server systemd-tmpfiles[140]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6757718.831792] server systemd-tmpfiles[140]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6757718.831919] server systemd-tmpfiles[140]: fchmod() of /var/log/journal/6e809ba2d5074b3092243b81ff98c1f6 failed: Operation not permitted container-test-run-certificates> server # [6757718.832604] server systemd-tmpfiles[140]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6757718.834199] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6757718.835497] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6757718.836276] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6757718.848210] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6757718.859640] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6757718.861030] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6757718.873439] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6757718.889919] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6757718.890513] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6757718.890807] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6757718.892579] server systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6757719.417366] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6757719.417486] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6757719.424502] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6757719.424667] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6757719.425047] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [6757719.425051] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [6757719.425241] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6757719.425596] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6757719.425648] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [6757719.425850] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [6757719.426711] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6757719.452594] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6757719.438801] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6757719.438885] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6757719.445538] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6757719.445743] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6757719.445847] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [6757719.445851] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [6757719.446073] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6757719.446407] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6757719.446474] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [6757719.446639] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [6757719.447111] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6757719.472524] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6757719.454772] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6757719.454843] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6757719.460529] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6757719.460678] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6757719.460753] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [6757719.460756] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [6757719.460903] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6757719.461193] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6757719.461209] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [6757719.461336] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [6757719.462099] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6757719.493663] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6757719.686005] server systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> server # [6757719.686015] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6757719.686019] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6757719.686045] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6757719.698674] server systemd-resolved[97]: Using system hostname 'server'. container-test-run-certificates> server # [6757719.700040] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6757719.700111] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6757719.700152] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6757719.700185] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6757719.700384] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6757719.700405] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6757719.700420] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6757719.700436] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6757719.700548] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6757719.700633] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6757719.700735] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6757719.700749] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6757719.700778] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6757719.702456] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6757719.703106] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6757719.703133] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6757719.703685] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6757719.704900] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6757719.736949] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6757719.835891] server acme-setup-privileged[191]: + set -euo pipefail container-test-run-certificates> server # [6757719.835891] server acme-setup-privileged[191]: + cd /var/lib/acme container-test-run-certificates> server # [6757719.835891] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6757719.837723] server acme-setup-privileged[191]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6757719.839231] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6757719.839231] server acme-setup-privileged[191]: + '[' -d test.foo ']' container-test-run-certificates> server # [6757719.839231] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6757719.839231] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6757719.852008] server nsncd[193]: Aug 17 15:09:37.217 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6757719.852082] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6757719.852155] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6757719.852203] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6757719.865420] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6757719.866523] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6757719.876596] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6757719.878726] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6757719.878761] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6757719.878776] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6757719.693696] client systemd-resolved[109]: Positive Trust Anchors: container-test-run-certificates> client # [6757719.693705] client systemd-resolved[109]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6757719.693710] client systemd-resolved[109]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6757719.693726] client systemd-resolved[109]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6757719.709473] client systemd-resolved[109]: Using system hostname 'client'. container-test-run-certificates> client # [6757719.710732] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6757719.710806] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6757719.710859] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6757719.710900] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6757719.710922] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6757719.710936] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6757719.711059] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6757719.711145] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6757719.711240] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6757719.711252] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6757719.711282] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6757719.723466] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6757719.724663] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6757719.726141] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6757719.741742] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6757719.851787] client nsncd[188]: Aug 17 15:09:37.217 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6757719.851882] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6757719.851966] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6757719.852033] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6757719.864456] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6757719.865514] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6757719.878186] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6757719.880099] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6757719.880144] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6757719.880160] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6757719.684090] ca systemd-resolved[103]: Positive Trust Anchors: container-test-run-certificates> ca # [6757719.684104] ca systemd-resolved[103]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6757719.684108] ca systemd-resolved[103]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6757719.684133] ca systemd-resolved[103]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6757719.699632] ca systemd-resolved[103]: Using system hostname 'ca'. container-test-run-certificates> ca # [6757719.701037] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6757719.701126] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6757719.701176] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6757719.701230] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6757719.701433] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6757719.701464] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6757719.701495] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6757719.701520] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6757719.701629] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6757719.701717] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6757719.701841] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6757719.701859] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6757719.701892] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6757719.703476] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6757719.703932] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6757719.703955] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6757719.704678] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6757719.705326] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6757719.723379] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6757719.767061] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory container-test-run-certificates> ca # [6757719.767086] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory container-test-run-certificates> ca # [6757719.767119] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'. container-test-run-certificates> ca # [6757719.767171] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6757719.841434] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> ca # [6757719.841434] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> ca # [6757719.841841] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6757719.843034] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6757719.844987] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6757719.844987] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6757719.844987] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6757719.844987] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6757719.966615] ca nsncd[202]: Aug 17 15:09:37.332 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6757719.966788] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6757719.966859] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6757719.966898] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6757719.968452] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6757719.969556] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6757720.006733] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6757720.008221] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6757720.008257] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6757720.008274] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6757720.177983] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6757720.392419] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6757720.392419] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/wy9bgq3n8vq6g5xd6f86m5hvmsz1r4fk-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6757720.179916] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6757720.186656] ca dbus-broker-launch[204]: Ready container-test-run-certificates> client # [6757720.161909] client dbus-broker-launch[189]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6757720.210240] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6757720.386918] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6757720.386918] server dbus-broker-launch[194]: Invalid user-name in /nix/store/s27w242hs9z1hj38qmfv4wi81w7n2l2z-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6757720.211474] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6757720.216648] server dbus-broker-launch[194]: Ready container-test-run-certificates> client # [6757720.387014] client dbus-broker-launch[189]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6757720.387014] client dbus-broker-launch[189]: Invalid user-name in /nix/store/0p3a4ggxl5y5cf6339ffi3wc26bgzwg3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6757720.163728] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6757720.170053] client dbus-broker-launch[189]: Ready container-test-run-certificates> ca # [6757720.574189] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6757720.631291] ca systemd-logind[226]: New seat seat0. container-test-run-certificates> ca # [6757720.631444] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6757720.648521] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6757720.651379] ca acme-setup-start[215]: + set -euo pipefail container-test-run-certificates> ca # [6757720.651379] ca acme-setup-start[215]: + test -e ca/key.pem container-test-run-certificates> ca # [6757720.651665] ca acme-setup-start[215]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6757720.661202] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6757720.661292] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6757720.662357] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6757720.664485] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> client # [6757720.623435] client systemd-logind[204]: New seat seat0. container-test-run-certificates> client # [6757720.623981] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6757720.625200] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6757720.656957] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6757720.657100] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6757720.658234] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6757720.589435] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [6757720.589575] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6757720.590870] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6757720.621301] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6757720.621542] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6757720.659998] server acme-setup-start[206]: + set -euo pipefail container-test-run-certificates> server # [6757720.659998] server acme-setup-start[206]: + test -e ca/key.pem container-test-run-certificates> server # [6757720.659998] server acme-setup-start[206]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6757720.671179] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6757720.673048] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6757720.905821] ca step-ca[203]: badger 2026/08/17 15:09:38 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6757720.918565] ca step-ca[203]: 2026/08/17 15:09:38 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6757720.924519] ca step-ca[203]: 2026/08/17 15:09:38 X.509 Root Fingerprint: 90684bcb39b6e8783b3f83954046135bdf820e4b218433502254a072081f4e5b container-test-run-certificates> ca # [6757720.925064] ca step-ca[203]: 2026/08/17 15:09:38 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> ca # [6757720.925092] ca systemd[1]: Started step-ca service. container-test-run-certificates> server # [6757721.277114] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [6757721.290935] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6757721.293132] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6757721.293206] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6757721.298574] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [6757721.298956] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6757721.299787] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6757721.300015] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6757721.300965] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6757721.301151] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6757721.302386] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6757721.303765] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6757721.305197] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6757721.305197] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [6757721.305289] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6757721.306825] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [6757721.309215] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6757721.309215] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [6757721.312355] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6757721.313952] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6757721.229333] ca acme-ca.foo-start[253]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6757721.231181] ca acme-ca.foo-start[253]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6757721.231222] ca acme-ca.foo-start[253]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6757721.238494] ca acme-ca.foo-start[279]: + cd ca.foo container-test-run-certificates> ca # [6757721.238937] ca acme-ca.foo-start[279]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6757721.240020] ca acme-ca.foo-start[280]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6757721.240239] ca acme-ca.foo-start[279]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6757721.241325] ca acme-ca.foo-start[279]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6757721.241530] ca acme-ca.foo-start[253]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6757721.242666] ca acme-ca.foo-start[253]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6757721.243682] ca acme-ca.foo-start[253]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6757721.244679] ca acme-ca.foo-start[253]: + for fixpath in out certificates container-test-run-certificates> ca # [6757721.244729] ca acme-ca.foo-start[253]: + '[' -d out ']' container-test-run-certificates> ca # [6757721.244729] ca acme-ca.foo-start[253]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6757721.245634] ca acme-ca.foo-start[253]: + chown -R acme:nginx out container-test-run-certificates> ca # [6757721.247773] ca acme-ca.foo-start[253]: + for fixpath in out certificates container-test-run-certificates> ca # [6757721.247773] ca acme-ca.foo-start[253]: + '[' -d certificates ']' container-test-run-certificates> ca # [6757721.249866] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6757721.251169] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [6757721.342101] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [6757721.683765] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6757721.685046] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6757721.786827] server nginx-pre-start[267]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6757721.787220] server nginx-pre-start[267]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6757721.790515] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6757721.790784] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6757721.791486] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6757721.686844] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6757721.688082] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6757721.714452] ca nginx-pre-start[292]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6757721.714974] ca nginx-pre-start[292]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6757721.718305] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6757721.718726] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6757721.719970] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> client # [6757721.684738] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6757721.685895] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6757721.686111] client systemd[1]: Startup finished in 3.375s. container-test-run-certificates> ca # [6757722.189137] ca acme-order-renew-ca.foo-start[295]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6757722.190511] ca acme-order-renew-ca.foo-start[295]: + set -euo pipefail container-test-run-certificates> ca # [6757722.190572] ca acme-order-renew-ca.foo-start[295]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6757722.190657] ca acme-order-renew-ca.foo-start[295]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6757722.191437] ca acme-order-renew-ca.foo-start[295]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6757722.208447] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6757722.208908] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6757722.224454] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration="90.321µs" duration-ns=90321 fields.time="2026-08-17T15:09:39Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=cf0a62a3-86be-4ce2-bb71-31ce8de47f5b response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.224876] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6757722.363735] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=138.949401ms duration-ns=138949401 fields.time="2026-08-17T15:09:39Z" method=HEAD name=ca nonce=WHZNdmNnb0NjRjVGQnZMdTc5bk1iN3JQck1vbHVINkU path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=1d09d405-857d-45cd-b308-a26a1fbb60a9 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.420227] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=55.660827ms duration-ns=55660827 fields.time="2026-08-17T15:09:39Z" method=POST name=ca nonce=YXpxME41cXpKbWVvNFVOMk93bkM2V05XYkN4MkxBeVM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=bb14aed1-271c-4286-8f4b-c87b7942ef59 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/1pnfEqHjWn9c7084WaSOPUL6ZT6A8283/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: Your account credentials have been saved in your container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: configuration directory at "accounts". container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: configuration directory will also contain private keys container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6757722.421261] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6757722.452671] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=30.90584ms duration-ns=30905840 fields.time="2026-08-17T15:09:39Z" method=POST name=ca nonce=V3hKNmx1Qm5WdjRoWkxLYnNlMFhjRzRRZ25BZFoxaUw path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9f256711-5de6-4fec-9c2b-ab79a5fdafdc response="{\"id\":\"vFyWn81KfJWg8QK83SiYCg1jfJYPVseI\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:09:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:08:39Z\",\"notAfter\":\"2026-11-15T15:09:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/vFyWn81KfJWg8QK83SiYCg1jfJYPVseI/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> server # [6757722.267800] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6757722.269344] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6757722.269401] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6757722.269485] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6757722.270274] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6757722.283123] server acme-order-renew-test.foo-start[281]: 2026/08/17 15:09:39 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6757722.283365] server acme-order-renew-test.foo-start[281]: 2026/08/17 15:09:39 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6757722.306649] server acme-order-renew-test.foo-start[281]: 2026/08/17 15:09:39 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6757722.311082] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6757722.311082] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6757722.311082] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6757722.313189] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6757722.313295] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6757722.314034] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6757722.314388] server systemd[1]: Startup finished in 3.994s. container-test-run-certificates> ca # [6757722.530444] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=20.819467ms duration-ns=20819467 fields.time="2026-08-17T15:09:39Z" method=POST name=ca nonce=ZDdYVkZ1T2FTbVJ1aFNiVGNRWkROTUhvRmZuMHRuYWU path=/acme/acme/authz/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=10e9df51-dad1-47b7-a27a-b91accbb08bf response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"MEx9RwK5ZJKaMDdbt3qgkHFkhW3kuWli\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS/90UyO3OO3VFhZ0SbaWrxVGfC3Yjx4bqH\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"MEx9RwK5ZJKaMDdbt3qgkHFkhW3kuWli\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS/NW4cEcfJ2jq9EUuwtYY8IAhMU8DUXaIk\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"MEx9RwK5ZJKaMDdbt3qgkHFkhW3kuWli\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS/u5hLKmzY031i2f9Nz1bO92N59TlVV9jl\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:09:39Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.530768] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS container-test-run-certificates> ca # [6757722.530808] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6757722.530808] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6757722.530808] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6757722.535247] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=3.970136ms duration-ns=3970136 fields.time="2026-08-17T15:09:39Z" method=POST name=ca nonce=RFZibXJCSE1RY1VIc0tIc05JN0lVNldYY2lpRGVSRzM path=/acme/acme/challenge/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS/NW4cEcfJ2jq9EUuwtYY8IAhMU8DUXaIk protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=77febaa3-f26b-4a13-a398-acba1117bff5 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"MEx9RwK5ZJKaMDdbt3qgkHFkhW3kuWli\",\"validated\":\"2026-08-17T15:09:39Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS/NW4cEcfJ2jq9EUuwtYY8IAhMU8DUXaIk\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.535498] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6757722.535556] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6757722.540876] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info duration=4.799999ms duration-ns=4799999 fields.time="2026-08-17T15:09:39Z" method=POST name=ca nonce=RWFvanFndXIwNnN1bFoySVNUY2k1WTF0R2hBcWpma0Q path=/acme/acme/order/vFyWn81KfJWg8QK83SiYCg1jfJYPVseI/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ba8e59cf-e031-4e4f-8e6d-fd5f632352f5 response="{\"id\":\"vFyWn81KfJWg8QK83SiYCg1jfJYPVseI\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:09:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-17T15:08:39Z\",\"notAfter\":\"2026-11-15T15:09:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/SfXkaq7q3DDJ41tPVICA1fn6xSJe5RGS\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/vFyWn81KfJWg8QK83SiYCg1jfJYPVseI/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/utKt00xxhdRCj0oHoThOfOy2aQaPRD5S\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757722.544113] ca step-ca[203]: time="2026-08-17T15:09:39Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQB96gTaWsKWX+lvFQT3+Y5zAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTcxNTA4MzlaFw0yNjExMTUxNTA5MzlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABGWpi/lpKzbinuaMlY20Q6IpOzUFo5ct81+TPpIgw8VgXpz6xMYqVmftJZhl47uHtuLbfFe06xVqtdHOKCYd6jWjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUNT5AdH61y3ib5SOjpZQv5hVqeSMwHwYDVR0jBBgwFoAUcOLs8JRhlWgCgx4Cg79dhsOEqjswEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEA3r1ScpxMB2bf5qdogBBj9kMmq2b6q5A2KiuWbv74xvcCIC4JoqoqgZQfoS3bmNvVzE4Ld6Lk939TOpcO40s/y7Dk duration=1.519061ms duration-ns=1519061 fields.time="2026-08-17T15:09:39Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dmhvVFZCZkFpbURveDdXeVRDeGpqemowMTZSOWd6Vk8 path=/acme/acme/certificate/utKt00xxhdRCj0oHoThOfOy2aQaPRD5S protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=aabe6e34-50a9-4e02-8c29-344bcd920465 sans="map[dns:[ca.foo]]" serial=10460537210467398069469962987269757159 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-17T15:08:39Z" valid-to="2026-11-15T15:09:39Z" container-test-run-certificates> ca # [6757722.544245] ca acme-order-renew-ca.foo-start[306]: 2026/08/17 15:09:39 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6757722.549290] ca acme-order-renew-ca.foo-start[295]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6757722.550882] ca acme-order-renew-ca.foo-start[295]: + touch out/acme-success container-test-run-certificates> ca # [6757722.551804] ca acme-order-renew-ca.foo-start[295]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6757722.552449] ca acme-order-renew-ca.foo-start[295]: + touch out/renewed container-test-run-certificates> ca # [6757722.553507] ca acme-order-renew-ca.foo-start[295]: + echo Installing new certificate container-test-run-certificates> ca # [6757722.553507] ca acme-order-renew-ca.foo-start[295]: Installing new certificate container-test-run-certificates> ca # [6757722.553559] ca acme-order-renew-ca.foo-start[295]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6757722.554313] ca acme-order-renew-ca.foo-start[327]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6757722.554507] ca acme-order-renew-ca.foo-start[295]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6757722.555478] ca acme-order-renew-ca.foo-start[328]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6757722.555641] ca acme-order-renew-ca.foo-start[295]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6757722.556431] ca acme-order-renew-ca.foo-start[329]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6757722.556581] ca acme-order-renew-ca.foo-start[295]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6757722.557492] ca acme-order-renew-ca.foo-start[295]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6757722.558489] ca acme-order-renew-ca.foo-start[295]: + for fixpath in out certificates container-test-run-certificates> ca # [6757722.558513] ca acme-order-renew-ca.foo-start[295]: + '[' -d out ']' container-test-run-certificates> ca # [6757722.558513] ca acme-order-renew-ca.foo-start[295]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6757722.559351] ca acme-order-renew-ca.foo-start[295]: + chown -R acme:nginx out container-test-run-certificates> ca # [6757722.561336] ca acme-order-renew-ca.foo-start[295]: + for fixpath in out certificates container-test-run-certificates> ca # [6757722.561366] ca acme-order-renew-ca.foo-start[295]: + '[' -d certificates ']' container-test-run-certificates> ca # [6757722.561366] ca acme-order-renew-ca.foo-start[295]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6757722.562175] ca acme-order-renew-ca.foo-start[295]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6757722.564333] ca acme-order-renew-ca.foo-start[295]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6757722.676127] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6757722.686205] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6757722.691150] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6757723.296339] ca nginx[345]: nginx: the configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf syntax is ok container-test-run-certificates> ca # [6757723.296589] ca nginx[345]: nginx: configuration file /nix/store/65aqcgcl2nyqsijzynvmaazhx54f1mff-nginx.conf test is successful container-test-run-certificates> ca # [6757723.720410] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6757723.720580] ca systemd[1]: Startup finished in 5.378s. container-test-run-certificates> ca # [6757724.105104] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.69 seconds) container-test-run-certificates> ca # [6757724.504602] ca acme-order-renew-ca.foo-start[360]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6757724.506503] ca acme-order-renew-ca.foo-start[360]: + set -euo pipefail container-test-run-certificates> ca # [6757724.506567] ca acme-order-renew-ca.foo-start[360]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6757724.506632] ca acme-order-renew-ca.foo-start[360]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6757724.507463] ca acme-order-renew-ca.foo-start[360]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6757724.507463] ca acme-order-renew-ca.foo-start[360]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6757724.507726] ca acme-order-renew-ca.foo-start[368]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6757724.509325] ca acme-order-renew-ca.foo-start[360]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6757724.509374] ca acme-order-renew-ca.foo-start[360]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6757724.531378] ca step-ca[203]: time="2026-08-17T15:09:41Z" level=info duration="37.932µs" duration-ns=37932 fields.time="2026-08-17T15:09:41Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=611f56d9-a41b-448d-881c-87b0e7a01ed7 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757724.531632] ca acme-order-renew-ca.foo-start[369]: 2026/08/17 15:09:41 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6757724.531632] ca acme-order-renew-ca.foo-start[369]: 2026/08/17 15:09:41 [INFO] [ca.foo] The certificate expires at 2026-11-15T15:09:39Z, the renewal can be performed in 1439h59m37.102791366s: no renewal. container-test-run-certificates> ca # [6757724.531762] ca acme-order-renew-ca.foo-start[360]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6757724.532933] ca acme-order-renew-ca.foo-start[360]: + touch out/acme-success container-test-run-certificates> ca # [6757724.533825] ca acme-order-renew-ca.foo-start[360]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6757724.534395] ca acme-order-renew-ca.foo-start[360]: + for fixpath in out certificates container-test-run-certificates> ca # [6757724.534395] ca acme-order-renew-ca.foo-start[360]: + '[' -d out ']' container-test-run-certificates> ca # [6757724.534431] ca acme-order-renew-ca.foo-start[360]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6757724.535223] ca acme-order-renew-ca.foo-start[360]: + chown -R acme:nginx out container-test-run-certificates> ca # [6757724.536937] ca acme-order-renew-ca.foo-start[360]: + for fixpath in out certificates container-test-run-certificates> ca # [6757724.536937] ca acme-order-renew-ca.foo-start[360]: + '[' -d certificates ']' container-test-run-certificates> ca # [6757724.536970] ca acme-order-renew-ca.foo-start[360]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6757724.537822] ca acme-order-renew-ca.foo-start[360]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6757724.539142] ca acme-order-renew-ca.foo-start[360]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6757724.648119] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6757724.648327] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6757727.661504] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6757727.661590] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6757727.662808] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6757727.663816] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.69 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:09:38 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:09:38 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0bcf36 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6757728.302127] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6757728.306747] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6757728.306747] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6757728.320230] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [6757728.320230] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6757728.323440] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6757728.323833] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6757728.325787] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6757728.326086] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6757728.328237] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6757728.330755] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6757728.333197] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6757728.333197] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [6757728.333197] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6757728.335106] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [6757728.339819] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6757728.339819] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [6757728.344107] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6757728.346907] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6757728.955073] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6757728.957494] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> server # [6757728.957564] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6757728.957640] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6757728.958636] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6757728.993454] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6757729.042164] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6757729.042441] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6757729.120587] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI container-test-run-certificates> server # [6757729.120696] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6757729.120696] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6757729.120696] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6757729.127718] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6757729.127718] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6757729.137228] server acme-order-renew-test.foo-start[331]: 2026/08/17 15:09:46 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6757729.141274] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6757729.142624] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [6757729.143973] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6757729.144704] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [6757729.145517] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [6757729.145517] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [6757729.145565] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6757729.146720] server acme-order-renew-test.foo-start[351]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6757729.147008] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6757729.147859] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6757729.148041] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6757729.149186] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6757729.149432] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6757729.150454] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6757729.151748] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6757729.151748] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [6757729.151850] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6757729.152879] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [6757729.155235] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6757729.155278] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [6757729.155278] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6757729.156597] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6757729.158315] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6757728.992302] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration="51.257µs" duration-ns=51257 fields.time="2026-08-17T15:09:46Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=b7ee0808-10e7-4abb-b81a-2d2c457d0f94 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.037650] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=42.886031ms duration-ns=42886031 fields.time="2026-08-17T15:09:46Z" method=HEAD name=ca nonce=RnZqWHRmbzBGN0ZuSG91Yk15NDBma3dQZkh4VXFpRzQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=aaaa2db1-27c6-46c8-8727-30656176bd9b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.041764] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=1.575907ms duration-ns=1575907 fields.time="2026-08-17T15:09:46Z" method=POST name=ca nonce=Q2tKSGdYSTJqYnpKYzhYNVlUaThmN01BRUhpVzQyVG0 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=dfda0fe4-ee78-4edb-bb5f-c79e0ff68d35 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/biMr6vR40o5dCPkhNStHiwmxjqzYsyFM/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.046013] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=2.55437ms duration-ns=2554370 fields.time="2026-08-17T15:09:46Z" method=POST name=ca nonce=U2c2SndoUTZ5M0htOUdXQ2ZFNFFheDJDcVFEYlRWcUQ path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=ddb2a5de-2ed1-48d3-b3d3-d728162ec81c response="{\"id\":\"Jznc4QZKUY8fKV2CRgf3BL0DSWiHSqVw\",\"status\":\"pending\",\"expires\":\"2026-08-18T15:09:46Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:08:46Z\",\"notAfter\":\"2026-11-15T15:09:46Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI\"],\"finalize\":\"https://ca.foo/acme/acme/order/Jznc4QZKUY8fKV2CRgf3BL0DSWiHSqVw/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.119342] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=15.142115ms duration-ns=15142115 fields.time="2026-08-17T15:09:46Z" method=POST name=ca nonce=YVJqUzY0aGlySGk2SHp1dlBVdnh4ZEhsdkdQOGZvVk8 path=/acme/acme/authz/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI protocol=HTTP/1.1 referer= remote-address="::1" request-id=75757393-7ad2-48cc-9445-28d68a3ad484 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"uw7dvaSiwkEcCPec2RuLqNYQchCn827U\",\"url\":\"https://ca.foo/acme/acme/challenge/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI/saUGgA6FKdN3sGaHXkSXLHbiha1HwQJZ\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"uw7dvaSiwkEcCPec2RuLqNYQchCn827U\",\"url\":\"https://ca.foo/acme/acme/challenge/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI/yiwHMVgepDH8HlPsPKMfKaCq1YEm8L8n\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"uw7dvaSiwkEcCPec2RuLqNYQchCn827U\",\"url\":\"https://ca.foo/acme/acme/challenge/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI/ZRJUeH4bCbn2nJxewJMLSlMD0qk8q8oi\"}],\"wildcard\":false,\"expires\":\"2026-08-18T15:09:46Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.127268] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=4.806281ms duration-ns=4806281 fields.time="2026-08-17T15:09:46Z" method=POST name=ca nonce=M1NnaFA3OFBRTGtOQTdtcTRhUU9JOVc0RWxYcGlCaHo path=/acme/acme/challenge/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI/yiwHMVgepDH8HlPsPKMfKaCq1YEm8L8n protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=53e921e0-9244-4e1d-b416-40c07bd25ca0 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"uw7dvaSiwkEcCPec2RuLqNYQchCn827U\",\"validated\":\"2026-08-17T15:09:46Z\",\"url\":\"https://ca.foo/acme/acme/challenge/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI/yiwHMVgepDH8HlPsPKMfKaCq1YEm8L8n\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.134502] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info duration=5.303948ms duration-ns=5303948 fields.time="2026-08-17T15:09:46Z" method=POST name=ca nonce=ZEJOZVcxVHlKYjN4UUFrV3dJbGdsYlJLUnJ1alpNQ2M path=/acme/acme/order/Jznc4QZKUY8fKV2CRgf3BL0DSWiHSqVw/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=a7fe745c-1313-4693-83c5-bc14cb3ff85a response="{\"id\":\"Jznc4QZKUY8fKV2CRgf3BL0DSWiHSqVw\",\"status\":\"valid\",\"expires\":\"2026-08-18T15:09:46Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-17T15:08:46Z\",\"notAfter\":\"2026-11-15T15:09:46Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/yl3tBQrJEyXbrx0DXAZrO3PVA1L0ahzI\"],\"finalize\":\"https://ca.foo/acme/acme/order/Jznc4QZKUY8fKV2CRgf3BL0DSWiHSqVw/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/qm8HQ21CIX9hNAC7bloRKy396Twl2px5\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6757729.137003] ca step-ca[203]: time="2026-08-17T15:09:46Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRAKnqhK9NCm0eTy6dW9KhpOAwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE3MTUwODQ2WhcNMjYxMTE1MTUwOTQ2WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABHCHO+1IJxNbqQeTubdALzru5rR+VQrM+9gL0TNonaDPjjL1LQeiHF4VATTMC/Ob6d0EoL8VGneKdjmMt7G6yImjgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUGZDwaFYndvCCcAoFTySs41BfsFQwHwYDVR0jBBgwFoAUcOLs8JRhlWgCgx4Cg79dhsOEqjswEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQDus3Jx4qPDOiqXUmaoel2rgwGFTxXvksXWkPQIPS9uYgIhANZkwaRQTYWmsgBWG2dHdC71WYuQrZ7qZ0wzKPoOUxdC duration=1.276543ms duration-ns=1276543 fields.time="2026-08-17T15:09:46Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=amxDZXo2ZHV2Q0ZaZ09OT21kZW40QkhVN1ZzSHoxWTE path=/acme/acme/certificate/qm8HQ21CIX9hNAC7bloRKy396Twl2px5 protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=fd590c27-54b5-4d7b-b3db-0b1476e695a9 sans="map[dns:[test.foo]]" serial=225857219919387004514068911617573233888 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-17T15:08:46Z" valid-to="2026-11-15T15:09:46Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1009 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:09:38 2026 GMT container-test-run-certificates> * expire date: Sep 16 15:09:38 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 0bcf36 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6757729.259293] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6757729.262763] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6757729.262905] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6757729.768635] server nginx[369]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6757729.769034] server nginx[369]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [933 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 17 15:08:46 2026 GMT container-test-run-certificates> * expire date: Nov 15 15:09:46 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 35356 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1556 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.11 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> a9:ea:84:af:4d:0a:6d:1e:4f:2e:9d:5b:d2:a1:a4:e0 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 17 15:08:46 2026 GMT container-test-run-certificates> Not After : Nov 15 15:09:46 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:70:87:3b:ed:48:27:13:5b:a9:07:93:b9:b7:40: container-test-run-certificates> 2f:3a:ee:e6:b4:7e:55:0a:cc:fb:d8:0b:d1:33:68: container-test-run-certificates> 9d:a0:cf:8e:32:f5:2d:07:a2:1c:5e:15:01:34:cc: container-test-run-certificates> 0b:f3:9b:e9:dd:04:a0:bf:15:1a:77:8a:76:39:8c: container-test-run-certificates> b7:b1:ba:c8:89 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 19:90:F0:68:56:27:76:F0:82:70:0A:05:4F:24:AC:E3:50:5F:B0:54 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 70:E2:EC:F0:94:61:95:68:02:83:1E:02:83:BF:5D:86:C3:84:AA:3B container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:ee:b3:72:71:e2:a3:c3:3a:2a:97:52:66:a8: container-test-run-certificates> 7a:5d:ab:83:01:85:4f:15:ef:92:c5:d6:90:f4:08:3d:2f:6e: container-test-run-certificates> 62:02:21:00:d6:64:c1:a4:50:4d:85:a6:b2:00:56:1b:67:47: container-test-run-certificates> 74:2e:f5:59:8b:90:ad:9e:ea:67:4c:33:28:fa:0e:53:17:42 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.03 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.53 seconds) container-test-run-certificates> server # [6757730.230596] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> test script finished in 16.96s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 52) container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.24 seconds) post-build step Upload to niks3: ok time=2026-08-17T15:09:52.955Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-17T15:09:53.400Z level=INFO msg="Uploading 1 narinfos" time=2026-08-17T15:09:53.470Z level=INFO msg="Upload complete. (615ms)"