these 97 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/8h5rr0i0j7lfljdpphjvls77dkvzyzhz-ca.json.drv /nix/store/krn1hbzc8nnnazg9rqzh9j0lyhnslphm-X-Restart-Triggers-step-ca.drv /nix/store/39ddhdig5kyqav5p61sj42ypa9lai4sq-unit-step-ca.service.drv /nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv /nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv /nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/gq4y4apnihanyqjwd4jbb5k26dkag1mn-system-path.drv /nix/store/waggpma6jkik9i2lagk84qmd68zsfgid-dbus-1.drv /nix/store/jx482j8wlagnwfgwph885kphb5zk3i02-X-Restart-Triggers-dbus-broker.drv /nix/store/pznf4491q9192a8invxc95fsdgxqldvh-unit-dbus-broker.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/9lid7rd5cv14j4ibsz1rni7nq23sjmf2-nginx.conf.drv /nix/store/6a618i9c9kii1ys2h6n00p7lbvzpzzyi-unit-script-nginx-pre-start.drv /nix/store/yphvnz1p7zprzp621jlr311w28va8yrb-unit-nginx.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv /nix/store/8cgaspmn3fjns1snxhmrcqypq9f7n07w-nss-cacert-3.126.drv /nix/store/zq8pj8b7jqc7sx2s90r78hxf5bc4wi9i-unit-nix-daemon.service.drv /nix/store/6g9fnr7q79y1f479561sz9vzrpaygna7-system-units.drv /nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv /nix/store/ldf12jpgb6ccimn80bk8xkfil0nfqw0b-unit-dbus-broker.service.drv /nix/store/8pkl9kwbppwzl1mmhzz173l4svxdx318-user-units.drv /nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv /nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/ancsa1a1gilcd5bk8fly0hpxrmmh65vs-etc.drv /nix/store/135cya3sz71gw6s6nxcvrsg5hykxy0y6-activate.drv /nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv /nix/store/ghcq9lqrgrnqlh5c76ap7sf5hc7llzjl-system-path.drv /nix/store/cf3qw56yjvv7h5bys067xfv6lib795pa-dbus-1.drv /nix/store/1lmha6fj3z5xay2h2msrzaavap4iham6-X-Restart-Triggers-dbus-broker.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/30dgcx7ngns309s9zwb1bym9z81minvl-system-path.drv /nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/y7zva3x9hij22x8qxzpgy2hnlg2424ml-dbus-1.drv /nix/store/b6fx8wml019jdpxvr3pj2q4prvbnv5j3-X-Restart-Triggers-dbus-broker.drv /nix/store/gs9a38v5m90717sj68ynx5x16a6jnxvv-unit-dbus-broker.service.drv /nix/store/cn10b8gph2h0bj1iw99sh9zi95fvq3cy-user-units.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/ppg2qrmb49q8rjyww6d0kxbf46cyx72l-unit-dbus-broker.service.drv /nix/store/kn552vj2rz9x6fqmjkyg1g86hf5fcg32-system-units.drv /nix/store/m17b9fxn49y2ag1mdpzsxdcs2qjklmmn-etc.drv /nix/store/r42q8r4vj0wwwj8n6pkc9h919qgs9zg5-activate.drv /nix/store/syvlnak4xhvdw6zbk8hd2sgalgfpiwwb-nixos-system-client-test.drv /nix/store/8864csinzqvfxq2c69ahc7gd01caw08i-run-client-nspawn.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/gig3s6lz6l69hwb5f61aw9x5maf612g5-unit-dbus-broker.service.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv /nix/store/yhcbar8dsp5qd94y2b7l9mf7wzapnqg0-system-units.drv /nix/store/q2m4j8zsryxcwia7fynhkjj17rfqd89w-unit-dbus-broker.service.drv /nix/store/ykwdx0z9vp0rjaj4nx22bds4l1lyzai1-user-units.drv /nix/store/wsnvcca81pkgxy173aaqkqx3hplffaza-etc.drv /nix/store/adm39m87diiw4mgfvd85mmkcbiw8801x-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/gwsaf89l800l04zw02mqnsnryvqvvpx0-nixos-system-server-test.drv /nix/store/8vsqwpy7nkw2q1jxhhd169iwy5bsv0k6-run-server-nspawn.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/lc7n222wp7nn1mx8l9szklqgvlfdkg14-nixos-system-ca-test.drv /nix/store/jixi4j8g1v9bh82xj8f1nkd6bi702f4m-run-ca-nspawn.drv /nix/store/w5vklc0nxqbwibv2fyiflbcbgvng7kij-driverConfiguration.json.drv /nix/store/d5m4ksv4fjfd1sdc3wn6cai9wwr43nvs-nixos-test-driver-certificates.drv /nix/store/5hvs88v7yq3a4nganlas02fq3pf65k04-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 75.8 MiB unpacked): /nix/store/qfjhplgaj6zn71pd29p28wxngj5l4bys-openssl-3.6.3-man /nix/store/fwwgviqhlwxaigb610fvpiciz2di7wjg-python3.14-buildcatrust-0.5.1 /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/9lid7rd5cv14j4ibsz1rni7nq23sjmf2-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/1d3j7hsfkvw9p8lljs95cndmilri60h0-unit-40-eth1.network.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-40-eth1.network> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/56w04cclrff8fgm0b3hj9vycva9dq9r6-X-Reload-Triggers-systemd-networkd.drv' building '/nix/store/8h5rr0i0j7lfljdpphjvls77dkvzyzhz-ca.json.drv' building '/nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv' building '/nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/y8m3k26jb9msg27ylwskmfl6qsnsx2z9-tmpfiles.d.drv' ca.json> structuredAttrs is enabled building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/30dgcx7ngns309s9zwb1bym9z81minvl-system-path.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/8r8s1c0w9hkvn6apijqp55dbw84fsm9i-system-generators.drv' building '/nix/store/c7vd4hp5lr9i3rk8mk2ap0lw26gss2b7-system-shutdown.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/8cgaspmn3fjns1snxhmrcqypq9f7n07w-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/krn1hbzc8nnnazg9rqzh9j0lyhnslphm-X-Restart-Triggers-step-ca.drv' building '/nix/store/bi0cv004imhn9mlq885f8iyqsvfbi3jd-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/ghcq9lqrgrnqlh5c76ap7sf5hc7llzjl-system-path.drv' building '/nix/store/gq4y4apnihanyqjwd4jbb5k26dkag1mn-system-path.drv' building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/6a618i9c9kii1ys2h6n00p7lbvzpzzyi-unit-script-nginx-pre-start.drv' building '/nix/store/zszxpq2xinis7dknnwymdyaiy7yyah6j-unit-systemd-networkd.service.drv' building '/nix/store/73s710jhrl9alx1fkghkphfggcyh5qpp-user-generators.drv' system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled unit-systemd-networkd.service> structuredAttrs is enabled building '/nix/store/y7zva3x9hij22x8qxzpgy2hnlg2424ml-dbus-1.drv' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' building '/nix/store/yphvnz1p7zprzp621jlr311w28va8yrb-unit-nginx.service.drv' building '/nix/store/39ddhdig5kyqav5p61sj42ypa9lai4sq-unit-step-ca.service.drv' building '/nix/store/7x4mi3gddvq0bfdnmb8l3q824ikbxr5c-unit-systemd-tmpfiles-resetup.service.drv' system-path> created 1723 symlinks in user environment system-path> created 1723 symlinks in user environment unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/b6fx8wml019jdpxvr3pj2q4prvbnv5j3-X-Restart-Triggers-dbus-broker.drv' unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/cf3qw56yjvv7h5bys067xfv6lib795pa-dbus-1.drv' building '/nix/store/waggpma6jkik9i2lagk84qmd68zsfgid-dbus-1.drv' building '/nix/store/gs9a38v5m90717sj68ynx5x16a6jnxvv-unit-dbus-broker.service.drv' building '/nix/store/ppg2qrmb49q8rjyww6d0kxbf46cyx72l-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/1lmha6fj3z5xay2h2msrzaavap4iham6-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/jx482j8wlagnwfgwph885kphb5zk3i02-X-Restart-Triggers-dbus-broker.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/cn10b8gph2h0bj1iw99sh9zi95fvq3cy-user-units.drv' building '/nix/store/gig3s6lz6l69hwb5f61aw9x5maf612g5-unit-dbus-broker.service.drv' building '/nix/store/ldf12jpgb6ccimn80bk8xkfil0nfqw0b-unit-dbus-broker.service.drv' building '/nix/store/pznf4491q9192a8invxc95fsdgxqldvh-unit-dbus-broker.service.drv' building '/nix/store/q2m4j8zsryxcwia7fynhkjj17rfqd89w-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/8pkl9kwbppwzl1mmhzz173l4svxdx318-user-units.drv' building '/nix/store/ykwdx0z9vp0rjaj4nx22bds4l1lyzai1-user-units.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/8cgaspmn3fjns1snxhmrcqypq9f7n07w-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/i6agzdvxgp9j4hw8z7p7vs3y053k97vl-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/i6agzdvxgp9j4hw8z7p7vs3y053k97vl-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/i6agzdvxgp9j4hw8z7p7vs3y053k97vl-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/f2xwbqkx3vckxf8ighv9mldg5chh8i9f-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/f2xwbqkx3vckxf8ighv9mldg5chh8i9f-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/f2xwbqkx3vckxf8ighv9mldg5chh8i9f-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/ypnkzbzqv021rnd020f09q857fg1582w-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/ypnkzbzqv021rnd020f09q857fg1582w-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/ypnkzbzqv021rnd020f09q857fg1582w-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/x339rs69crjj01r7wxzbnyk1smqvyayn-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/x339rs69crjj01r7wxzbnyk1smqvyayn-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/x339rs69crjj01r7wxzbnyk1smqvyayn-nss-cacert-3.126-hashed building '/nix/store/zq8pj8b7jqc7sx2s90r78hxf5bc4wi9i-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/6g9fnr7q79y1f479561sz9vzrpaygna7-system-units.drv' building '/nix/store/kn552vj2rz9x6fqmjkyg1g86hf5fcg32-system-units.drv' building '/nix/store/yhcbar8dsp5qd94y2b7l9mf7wzapnqg0-system-units.drv' building '/nix/store/ancsa1a1gilcd5bk8fly0hpxrmmh65vs-etc.drv' building '/nix/store/m17b9fxn49y2ag1mdpzsxdcs2qjklmmn-etc.drv' building '/nix/store/wsnvcca81pkgxy173aaqkqx3hplffaza-etc.drv' building '/nix/store/135cya3sz71gw6s6nxcvrsg5hykxy0y6-activate.drv' building '/nix/store/lc7n222wp7nn1mx8l9szklqgvlfdkg14-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/r42q8r4vj0wwwj8n6pkc9h919qgs9zg5-activate.drv' building '/nix/store/adm39m87diiw4mgfvd85mmkcbiw8801x-activate.drv' building '/nix/store/jixi4j8g1v9bh82xj8f1nkd6bi702f4m-run-ca-nspawn.drv' building '/nix/store/syvlnak4xhvdw6zbk8hd2sgalgfpiwwb-nixos-system-client-test.drv' building '/nix/store/gwsaf89l800l04zw02mqnsnryvqvvpx0-nixos-system-server-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/8864csinzqvfxq2c69ahc7gd01caw08i-run-client-nspawn.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/8vsqwpy7nkw2q1jxhhd169iwy5bsv0k6-run-server-nspawn.drv' building '/nix/store/w5vklc0nxqbwibv2fyiflbcbgvng7kij-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/d5m4ksv4fjfd1sdc3wn6cai9wwr43nvs-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/5hvs88v7yq3a4nganlas02fq3pf65k04-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/5hvs88v7yq3a4nganlas02fq3pf65k04-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> client # [6819644.909313] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6819644.926737] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [6819644.909345] client systemd-journald[69]: Runtime Journal (/run/log/journal/2e9d75a0179c48e9bf95be2d1f027581) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [6819644.917659] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6819644.914428] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6819644.917692] server systemd-journald[69]: Runtime Journal (/run/log/journal/677ec5a353fe4cd491fab1bde99077a4) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [6819644.919848] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6819644.923225] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6819644.926777] ca systemd-journald[78]: Runtime Journal (/run/log/journal/eaa7ad3ab0d44d9384ec16f42946fc24) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [6819644.931996] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6819644.927566] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6819644.920252] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6819644.932546] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6819644.932646] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6819644.933078] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6819644.920614] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6819644.933522] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6819644.933109] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6819644.926847] client systemd-journald[69]: Time spent on flushing to /var/log/journal/2e9d75a0179c48e9bf95be2d1f027581 is 973us for 6 entries. container-test-run-certificates> server # [6819644.938215] server systemd-journald[69]: Time spent on flushing to /var/log/journal/677ec5a353fe4cd491fab1bde99077a4 is 1.287ms for 6 entries. container-test-run-certificates> ca # [6819644.938314] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/eaa7ad3ab0d44d9384ec16f42946fc24 is 1.204ms for 6 entries. container-test-run-certificates> server # [6819644.938215] server systemd-journald[69]: System Journal (/var/log/journal/677ec5a353fe4cd491fab1bde99077a4) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6819644.926847] client systemd-journald[69]: System Journal (/var/log/journal/2e9d75a0179c48e9bf95be2d1f027581) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6819644.943866] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6819644.930811] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6819644.944378] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6819644.931288] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6819644.944443] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6819644.931354] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6819644.938314] ca systemd-journald[78]: System Journal (/var/log/journal/eaa7ad3ab0d44d9384ec16f42946fc24) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6819644.945065] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6819644.931867] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6819644.945100] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6819644.952244] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6819644.945748] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6819644.931901] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6819644.945768] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6819644.952748] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6819644.962936] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6819644.932370] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6819644.963921] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6819644.952811] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6819644.975369] server systemd-tmpfiles[128]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6819644.953278] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6819644.932388] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6819644.953305] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6819644.975536] server systemd-tmpfiles[128]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6819644.953779] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6819644.932757] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6819644.975650] server systemd-tmpfiles[128]: fchmod() of /var/log/journal/677ec5a353fe4cd491fab1bde99077a4 failed: Operation not permitted container-test-run-certificates> client # [6819644.933944] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6819644.953801] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6819644.975805] server systemd-tmpfiles[128]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6819644.945292] client systemd-tmpfiles[112]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6819644.976790] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6819644.961742] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6819644.977443] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6819644.962335] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6819644.977893] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6819644.945471] client systemd-tmpfiles[112]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6819644.987258] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6819644.945624] client systemd-tmpfiles[112]: fchmod() of /var/log/journal/2e9d75a0179c48e9bf95be2d1f027581 failed: Operation not permitted container-test-run-certificates> ca # [6819644.976970] ca systemd-tmpfiles[131]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6819644.945779] client systemd-tmpfiles[112]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6819644.977219] ca systemd-tmpfiles[131]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6819644.946850] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6819644.992355] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6819644.947714] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6819644.993119] server systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6819644.977323] ca systemd-tmpfiles[131]: fchmod() of /var/log/journal/eaa7ad3ab0d44d9384ec16f42946fc24 failed: Operation not permitted container-test-run-certificates> server # [6819645.001844] server systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6819644.977485] ca systemd-tmpfiles[131]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6819644.948275] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6819645.021335] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [6819644.958510] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6819644.978804] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6819645.022259] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6819644.979731] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6819644.962584] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6819645.022561] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6819644.963417] client systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6819645.023566] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6819644.970191] client systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [6819644.980369] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6819645.087747] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6819644.989305] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6819645.011912] client systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6819644.994194] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6819645.012047] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6819644.995059] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6819645.012241] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6819645.000591] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6819645.012932] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6819645.030236] ca systemd[1]: Finished Firewall. container-test-run-certificates> client # [6819645.087734] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6819645.030338] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6819645.345423] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6819645.030479] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6819645.345498] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6819645.031146] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6819645.351481] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6819645.088016] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6819645.355158] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6819645.355232] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6819645.351629] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6819645.360473] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6819645.351721] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> ca # [6819645.360622] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6819645.351726] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> ca # [6819645.360716] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> client # [6819645.351869] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6819645.360720] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> client # [6819645.352173] client systemd[1]: Started Network Management. container-test-run-certificates> ca # [6819645.360880] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6819645.352230] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> ca # [6819645.361155] ca systemd[1]: Started Network Management. container-test-run-certificates> client # [6819645.352233] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> ca # [6819645.374300] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6819645.353140] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6819645.374311] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [6819645.374530] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> client # [6819645.378953] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6819645.480508] client systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> client # [6819645.480520] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6819645.480522] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6819645.480538] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6819645.491567] client systemd-resolved[94]: Using system hostname 'client'. container-test-run-certificates> client # [6819645.492532] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6819645.492583] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6819645.492623] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6819645.492657] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6819645.492674] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6819645.492682] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6819645.492770] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6819645.492839] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6819645.492913] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6819645.492922] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6819645.492942] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6819645.493654] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6819645.494210] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6819645.494924] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6819645.522610] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6819645.583717] client nsncd[189]: Aug 18 08:21:42.949 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6819645.583823] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6819645.583883] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6819645.583926] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6819645.593646] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6819645.594175] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6819645.392486] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6819645.513287] ca systemd-resolved[101]: Positive Trust Anchors: container-test-run-certificates> ca # [6819645.513294] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6819645.513297] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6819645.513314] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6819645.523654] ca systemd-resolved[101]: Using system hostname 'ca'. container-test-run-certificates> ca # [6819645.524503] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6819645.524548] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6819645.524577] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6819645.524604] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6819645.524727] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6819645.524743] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6819645.524756] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6819645.524766] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6819645.524847] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6819645.524919] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6819645.524997] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6819645.525018] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6819645.525042] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6819645.525707] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6819645.526037] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6819645.526061] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6819645.526459] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6819645.526891] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6819645.527500] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6819645.535911] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6819645.588099] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6819645.588099] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6819645.588290] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6819645.588946] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6819645.589732] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6819645.589747] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6819645.589747] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6819645.589771] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6819645.612865] ca nsncd[203]: Aug 18 08:21:42.978 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6819645.612984] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6819645.613067] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6819645.613118] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6819645.380640] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6819645.380728] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6819645.386212] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6819645.386359] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6819645.386434] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [6819645.386437] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [6819645.386583] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6819645.386834] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6819645.386864] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [6819645.386996] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [6819645.387434] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6819645.407967] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6819645.557641] server systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> server # [6819645.557646] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6819645.557649] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6819645.557666] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6819645.568095] server systemd-resolved[97]: Using system hostname 'server'. container-test-run-certificates> server # [6819645.568899] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6819645.568942] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6819645.568974] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6819645.569009] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6819645.569150] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6819645.569169] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6819645.569180] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6819645.569190] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6819645.569281] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6819645.569355] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6819645.569429] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6819645.569438] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6819645.569461] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6819645.570110] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6819645.570438] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6819645.570455] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6819645.570786] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6819645.571353] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6819645.600689] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6819645.656237] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6819645.656237] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6819645.656237] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [6819645.598955] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6819645.599546] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6819645.599565] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6819645.599576] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6819645.667002] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6819645.667408] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6819645.667408] client dbus-broker-launch[190]: Invalid user-name in /nix/store/0p3a4ggxl5y5cf6339ffi3wc26bgzwg3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6819645.667657] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6819645.671078] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [6819645.902195] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6819645.656988] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6819645.657753] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6819645.657782] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6819645.657782] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6819645.657782] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6819645.680475] server nsncd[194]: Aug 18 08:21:43.046 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6819645.680492] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6819645.680526] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6819645.680554] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6819645.688124] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6819645.688439] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6819645.693014] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6819645.693400] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6819645.693419] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6819645.693428] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6819645.742223] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6819645.742662] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6819645.742662] server dbus-broker-launch[195]: Invalid user-name in /nix/store/s27w242hs9z1hj38qmfv4wi81w7n2l2z-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6819645.742976] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6819645.747168] server dbus-broker-launch[195]: Ready container-test-run-certificates> server # [6819645.911236] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6819645.614178] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6819645.614825] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6819645.619444] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6819645.619908] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6819645.619926] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6819645.619935] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6819645.695620] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6819645.695998] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6819645.695998] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/wy9bgq3n8vq6g5xd6f86m5hvmsz1r4fk-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6819645.696243] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6819645.699460] ca dbus-broker-launch[205]: Ready container-test-run-certificates> ca # [6819645.916750] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6819646.039261] ca systemd-logind[235]: New seat seat0. container-test-run-certificates> ca # [6819646.039349] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6819646.039872] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6819646.046761] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6819646.046873] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6819646.060028] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6819646.060183] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6819646.060183] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6819646.066217] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6819646.067052] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6819646.114269] ca step-ca[204]: badger 2026/08/18 08:21:43 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6819646.115899] ca step-ca[204]: 2026/08/18 08:21:43 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6819646.117726] ca step-ca[204]: 2026/08/18 08:21:43 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [6819646.117726] ca step-ca[204]: 2026/08/18 08:21:43 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6819646.117726] ca step-ca[204]: 2026/08/18 08:21:43 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6819646.117726] ca step-ca[204]: 2026/08/18 08:21:43 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6819646.117804] ca step-ca[204]: 2026/08/18 08:21:43 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6819646.117804] ca step-ca[204]: 2026/08/18 08:21:43 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6819646.117804] ca step-ca[204]: 2026/08/18 08:21:43 X.509 Root Fingerprint: d451ac62691fe48bd68b77fa04e86bba5977f6b85e2c7fef05421f1e9ca2439c container-test-run-certificates> ca # [6819646.117868] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6819646.118085] ca step-ca[204]: 2026/08/18 08:21:43 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6819646.061140] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [6819646.061304] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6819646.062348] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6819646.067975] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6819646.068071] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6819646.092713] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6819646.092713] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6819646.092943] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6819646.100334] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6819646.101543] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> client # [6819645.993194] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6819645.993370] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6819645.994205] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6819646.024390] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6819646.024495] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6819646.025113] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6819646.025210] client systemd[1]: Startup finished in 1.380s. container-test-run-certificates> ca # [6819646.453124] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6819646.454948] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6819646.454985] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6819646.459554] ca acme-ca.foo-start[282]: + cd ca.foo container-test-run-certificates> ca # [6819646.459748] ca acme-ca.foo-start[282]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6819646.460362] ca acme-ca.foo-start[283]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6819646.460513] ca acme-ca.foo-start[282]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6819646.461125] ca acme-ca.foo-start[282]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6819646.461248] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6819646.462241] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6819646.463044] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6819646.463829] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6819646.463860] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [6819646.463860] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6819646.464899] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [6819646.466317] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [6819646.466317] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [6819646.467805] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6819646.468708] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6819646.521412] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6819646.522725] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6819646.522725] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6819646.526911] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6819646.527139] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6819646.527687] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6819646.527818] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6819646.528469] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6819646.528580] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6819646.529369] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6819646.530118] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6819646.530932] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6819646.530947] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6819646.530947] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6819646.531984] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6819646.533263] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6819646.533280] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6819646.534683] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6819646.535435] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6819646.873675] ca nginx-pre-start[294]: nginx: the configuration file /nix/store/0wbqmm9zicdxjscj6hi57rvxarbzv9ji-nginx.conf syntax is ok container-test-run-certificates> ca # [6819646.873910] ca nginx-pre-start[294]: nginx: configuration file /nix/store/0wbqmm9zicdxjscj6hi57rvxarbzv9ji-nginx.conf test is successful container-test-run-certificates> ca # [6819646.876940] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6819646.877220] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6819646.877982] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6819646.936386] server nginx-pre-start[267]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6819646.936646] server nginx-pre-start[267]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6819646.939163] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6819646.939432] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6819646.940129] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6819647.165086] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> client # [6819647.229078] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6819647.287930] ca acme-order-renew-ca.foo-start[297]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6819647.290423] ca acme-order-renew-ca.foo-start[297]: + set -euo pipefail container-test-run-certificates> ca # [6819647.290489] ca acme-order-renew-ca.foo-start[297]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6819647.290575] ca acme-order-renew-ca.foo-start[297]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6819647.291330] ca acme-order-renew-ca.foo-start[297]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6819647.299751] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6819647.299929] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6819647.312546] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration="111.841µs" duration-ns=111841 fields.time="2026-08-18T08:21:44Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4de67069-7a4a-437b-9a60-570a1e545e10 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.312978] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6819647.313527] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration="563µs" duration-ns=563000 fields.time="2026-08-18T08:21:44Z" method=HEAD name=ca nonce=WE1hVjN3NFo0eTE3elNQOUtPZFVFNlFkRTltbzZrSjY path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=18efa949-62ef-4469-9d28-35acbd6d315d size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.314975] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration=1.064184ms duration-ns=1064184 fields.time="2026-08-18T08:21:44Z" method=POST name=ca nonce=QWMxUW16UDQwT2JIYkc1b3dxSzdDM2RwbWJ5QVJ0Uk0 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ef50ea55-c88b-4c25-922b-f6846a060873 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/35kIEXeFhnLQtHQB6yYBDyaaOiBL8i1S/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: Your account credentials have been saved in your container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: configuration directory at "accounts". container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: configuration directory will also contain private keys container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6819647.315205] ca acme-order-renew-ca.foo-start[308]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6819647.315342] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6819647.317028] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration=1.536393ms duration-ns=1536393 fields.time="2026-08-18T08:21:44Z" method=POST name=ca nonce=NjhtemxQRXBqTUkxQ1JYUWhSVEs4c3ZhSWpVMEI3ZlE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0f294504-5927-4232-91d8-714245bc1285 response="{\"id\":\"eHYZUdCmC1dOPqtM95s74NLUMDZazQfC\",\"status\":\"pending\",\"expires\":\"2026-08-19T08:21:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T08:20:44Z\",\"notAfter\":\"2026-11-16T08:21:44Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/eHYZUdCmC1dOPqtM95s74NLUMDZazQfC/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.373895] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration="720.197µs" duration-ns=720197 fields.time="2026-08-18T08:21:44Z" method=POST name=ca nonce=VFRnQ0daY1g1NUlsRWxQcGw5WUZIYlg0dW90ZXkzazI path=/acme/acme/authz/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0bf532ac-c466-4b9e-98f9-7b075fedb444 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"bNdBHD81j9dMhjgsYtwqlu1D0q4ZWNs5\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX/2EMbfC1Cldw3zjNqH8J4jGt22bl9l7sy\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"bNdBHD81j9dMhjgsYtwqlu1D0q4ZWNs5\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX/atGMH856v1WkN6s42D121IG4Z14Jwboq\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"bNdBHD81j9dMhjgsYtwqlu1D0q4ZWNs5\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX/8uc6JPyl6kEPuNjdTMUkHKTJMUTzz0jV\"}],\"wildcard\":false,\"expires\":\"2026-08-19T08:21:44Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.374078] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX container-test-run-certificates> ca # [6819647.374078] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6819647.374078] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6819647.374154] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6819647.375782] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration=1.376061ms duration-ns=1376061 fields.time="2026-08-18T08:21:44Z" method=POST name=ca nonce=R3NGQ3dRakg1dTNaTTFOSldJNHVONnl0UFdRYnF2YjI path=/acme/acme/challenge/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX/atGMH856v1WkN6s42D121IG4Z14Jwboq protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d58e8c58-94e2-416e-b858-7270a708ec69 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"bNdBHD81j9dMhjgsYtwqlu1D0q4ZWNs5\",\"validated\":\"2026-08-18T08:21:44Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX/atGMH856v1WkN6s42D121IG4Z14Jwboq\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.375902] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6819647.375947] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6819647.378440] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info duration=2.165218ms duration-ns=2165218 fields.time="2026-08-18T08:21:44Z" method=POST name=ca nonce=RjZKOTJFZVdWUnJHanJ2am92VkVsNDVtWkowWkhuSWc path=/acme/acme/order/eHYZUdCmC1dOPqtM95s74NLUMDZazQfC/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f2a5a79a-2ce9-4273-a3ef-e300ef63382e response="{\"id\":\"eHYZUdCmC1dOPqtM95s74NLUMDZazQfC\",\"status\":\"valid\",\"expires\":\"2026-08-19T08:21:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T08:20:44Z\",\"notAfter\":\"2026-11-16T08:21:44Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/4qtaHJZL82ccTmTIynUZf6sqx2ld1JBX\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/eHYZUdCmC1dOPqtM95s74NLUMDZazQfC/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/uYjIaPvHplX9QOiKJx5UKudEl673Vbae\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819647.379108] ca step-ca[204]: time="2026-08-18T08:21:44Z" level=info certificate=MIIB0zCCAXqgAwIBAgIRANdLiN9fB/JWOsZmXVcZ/YkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE4MDgyMDQ0WhcNMjYxMTE2MDgyMTQ0WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARN+nU/eGlEp5sUCM24dkG9m0mgLsrWbkkTUdT0hkh02ea0dMTyFan9zNZjzhhoUEJkJMrUdC3yQY3CqIOYfMUDo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFEGt6rwfGQnNl6bdpDt7IacKHYOzMB8GA1UdIwQYMBaAFEXfNw+4bwQ3ifvoKyApXbDcdwGXMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgfYIQrFxxsA9/KDf7LDQVO9A/9Kl87IZtuxThH8JgDD4CIES5yoUF3vKj/7rKeo3OmkbnD1YArMfnFsc7Q2IwfVOE duration="443.285µs" duration-ns=443285 fields.time="2026-08-18T08:21:44Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=REk1anpMYmM2WHZ1N3VqNWc4bjBIRGhCd1pzc3E3UEQ path=/acme/acme/certificate/uYjIaPvHplX9QOiKJx5UKudEl673Vbae protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=c2230494-3227-4931-925e-e939dc0f01fe sans="map[dns:[ca.foo]]" serial=286176217463144044871692359148349554057 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-18T08:20:44Z" valid-to="2026-11-16T08:21:44Z" container-test-run-certificates> ca # [6819647.379204] ca acme-order-renew-ca.foo-start[308]: 2026/08/18 08:21:44 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6819647.382117] ca acme-order-renew-ca.foo-start[297]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6819647.383137] ca acme-order-renew-ca.foo-start[297]: + touch out/acme-success container-test-run-certificates> ca # [6819647.383950] ca acme-order-renew-ca.foo-start[297]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6819647.384543] ca acme-order-renew-ca.foo-start[297]: + touch out/renewed container-test-run-certificates> ca # [6819647.385310] ca acme-order-renew-ca.foo-start[297]: + echo Installing new certificate container-test-run-certificates> ca # [6819647.385310] ca acme-order-renew-ca.foo-start[297]: Installing new certificate container-test-run-certificates> ca # [6819647.385310] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6819647.386081] ca acme-order-renew-ca.foo-start[329]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6819647.386207] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6819647.386970] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6819647.387101] ca acme-order-renew-ca.foo-start[297]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6819647.387846] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6819647.387968] ca acme-order-renew-ca.foo-start[297]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6819647.388812] ca acme-order-renew-ca.foo-start[297]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6819647.389674] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6819647.389688] ca acme-order-renew-ca.foo-start[297]: + '[' -d out ']' container-test-run-certificates> ca # [6819647.389688] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6819647.390520] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx out container-test-run-certificates> ca # [6819647.391770] ca acme-order-renew-ca.foo-start[297]: + for fixpath in out certificates container-test-run-certificates> ca # [6819647.391770] ca acme-order-renew-ca.foo-start[297]: + '[' -d certificates ']' container-test-run-certificates> ca # [6819647.391824] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6819647.392590] ca acme-order-renew-ca.foo-start[297]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6819647.393732] ca acme-order-renew-ca.foo-start[297]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6819647.421052] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6819647.455840] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6819647.457797] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6819647.457886] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server # [6819647.331690] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6819647.333006] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6819647.333051] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6819647.333103] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6819647.333645] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6819647.340926] server acme-order-renew-test.foo-start[282]: 2026/08/18 08:21:44 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6819647.341238] server acme-order-renew-test.foo-start[282]: 2026/08/18 08:21:44 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6819647.353714] server acme-order-renew-test.foo-start[282]: 2026/08/18 08:21:44 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6819647.353869] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6819647.353869] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6819647.353909] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6819647.355582] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6819647.355673] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6819647.355852] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6819647.356053] server systemd[1]: Startup finished in 2.703s. container-test-run-certificates> ca # [6819647.823250] ca nginx[347]: nginx: the configuration file /nix/store/0wbqmm9zicdxjscj6hi57rvxarbzv9ji-nginx.conf syntax is ok container-test-run-certificates> ca # [6819647.823436] ca nginx[347]: nginx: configuration file /nix/store/0wbqmm9zicdxjscj6hi57rvxarbzv9ji-nginx.conf test is successful container-test-run-certificates> ca # [6819648.242891] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6819648.243081] ca systemd[1]: Startup finished in 3.584s. container-test-run-certificates> ca # [6819648.519424] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.64 seconds) container-test-run-certificates> ca # [6819648.903510] ca acme-order-renew-ca.foo-start[362]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6819648.905156] ca acme-order-renew-ca.foo-start[362]: + set -euo pipefail container-test-run-certificates> ca # [6819648.905187] ca acme-order-renew-ca.foo-start[362]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6819648.905240] ca acme-order-renew-ca.foo-start[362]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6819648.905939] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6819648.905939] ca acme-order-renew-ca.foo-start[362]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6819648.906132] ca acme-order-renew-ca.foo-start[370]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6819648.907451] ca acme-order-renew-ca.foo-start[362]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6819648.907467] ca acme-order-renew-ca.foo-start[362]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6819648.927910] ca step-ca[204]: time="2026-08-18T08:21:46Z" level=info duration="36.208µs" duration-ns=36208 fields.time="2026-08-18T08:21:46Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b776dfee-2493-4c92-b120-d03b2597fb65 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819648.928134] ca acme-order-renew-ca.foo-start[371]: 2026/08/18 08:21:46 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6819648.928134] ca acme-order-renew-ca.foo-start[371]: 2026/08/18 08:21:46 [INFO] [ca.foo] The certificate expires at 2026-11-16T08:21:44Z, the renewal can be performed in 1439h59m37.706207466s: no renewal. container-test-run-certificates> ca # [6819648.928323] ca acme-order-renew-ca.foo-start[362]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6819648.929692] ca acme-order-renew-ca.foo-start[362]: + touch out/acme-success container-test-run-certificates> ca # [6819648.930612] ca acme-order-renew-ca.foo-start[362]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6819648.931372] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6819648.931384] ca acme-order-renew-ca.foo-start[362]: + '[' -d out ']' container-test-run-certificates> ca # [6819648.931394] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6819648.932338] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx out container-test-run-certificates> ca # [6819648.933581] ca acme-order-renew-ca.foo-start[362]: + for fixpath in out certificates container-test-run-certificates> ca # [6819648.933601] ca acme-order-renew-ca.foo-start[362]: + '[' -d certificates ']' container-test-run-certificates> ca # [6819648.933601] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6819648.934567] ca acme-order-renew-ca.foo-start[362]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6819648.936063] ca acme-order-renew-ca.foo-start[362]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6819649.016989] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6819649.017141] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6819652.025764] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6819652.025846] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6819652.026393] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6819652.027124] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.36 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:21:43 2026 GMT container-test-run-certificates> * expire date: Sep 17 08:21:43 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 7944e4 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6819652.367165] server acme-test.foo-start[305]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6819652.369285] server acme-test.foo-start[305]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6819652.369285] server acme-test.foo-start[305]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6819652.373824] server acme-test.foo-start[315]: + cd test.foo container-test-run-certificates> server # [6819652.373972] server acme-test.foo-start[315]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6819652.374779] server acme-test.foo-start[316]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6819652.374903] server acme-test.foo-start[315]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6819652.375539] server acme-test.foo-start[315]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6819652.375697] server acme-test.foo-start[305]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6819652.376571] server acme-test.foo-start[305]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6819652.377380] server acme-test.foo-start[305]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6819652.378188] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6819652.378188] server acme-test.foo-start[305]: + '[' -d out ']' container-test-run-certificates> server # [6819652.378225] server acme-test.foo-start[305]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6819652.379015] server acme-test.foo-start[305]: + chown -R acme:nginx out container-test-run-certificates> server # [6819652.382113] server acme-test.foo-start[305]: + for fixpath in out certificates container-test-run-certificates> server # [6819652.382126] server acme-test.foo-start[305]: + '[' -d certificates ']' container-test-run-certificates> server # [6819652.383774] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6819652.385256] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6819652.749546] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration="39.825µs" duration-ns=39825 fields.time="2026-08-18T08:21:50Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=4f672c97-95f7-4310-b983-6b654b5c4fba response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.751015] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration="421.373µs" duration-ns=421373 fields.time="2026-08-18T08:21:50Z" method=HEAD name=ca nonce=ZDRNMHByVUpQQ2dzOXowRFM1c0t2NWI0cFZEczlDelc path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=27248733-7559-4269-8a4f-3c24908b0a6c size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.752632] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration="807.05µs" duration-ns=807050 fields.time="2026-08-18T08:21:50Z" method=POST name=ca nonce=dnFOSjRqRHdMSUlGODBLQkNOZVd1c1RVcURQZXRoNmk path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=57662c95-6dd8-4bf9-a4d2-cf91860dad3e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/Ge0YCm7IlMZWNwVORwD9U4NdiBAfejF0/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.755313] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration=1.244634ms duration-ns=1244634 fields.time="2026-08-18T08:21:50Z" method=POST name=ca nonce=R3VjTmpDbmVjcDh5eVJUMTB5Mk5heG1SamJVb0NaS0g path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f2c5b48f-7136-48e7-9eb8-7da57ac66c67 response="{\"id\":\"FwnBKDFEu32RkeLunohvDeoiI3ajxD20\",\"status\":\"pending\",\"expires\":\"2026-08-19T08:21:50Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T08:20:50Z\",\"notAfter\":\"2026-11-16T08:21:50Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO\"],\"finalize\":\"https://ca.foo/acme/acme/order/FwnBKDFEu32RkeLunohvDeoiI3ajxD20/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.812943] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration="529.798µs" duration-ns=529798 fields.time="2026-08-18T08:21:50Z" method=POST name=ca nonce=WHV1NlhJb1ZBdVZWWXNyZU9NSURPSGtDbG1YWTFJTWU path=/acme/acme/authz/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO protocol=HTTP/1.1 referer= remote-address="::1" request-id=844fb869-8f36-42cf-a772-d88e0538a014 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"2owH9xJ7I9OHfVykIdrLypdZxxM7NdO2\",\"url\":\"https://ca.foo/acme/acme/challenge/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO/Cq7LkA8UWrngQi3WFF693gEYHkpGoCNy\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"2owH9xJ7I9OHfVykIdrLypdZxxM7NdO2\",\"url\":\"https://ca.foo/acme/acme/challenge/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO/w1pTMjoai79us3h7sVpUpeoC13pdUBnT\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"2owH9xJ7I9OHfVykIdrLypdZxxM7NdO2\",\"url\":\"https://ca.foo/acme/acme/challenge/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO/19ywPF3GZ2eh5CPVxcwi7s7v92CEtf1v\"}],\"wildcard\":false,\"expires\":\"2026-08-19T08:21:50Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.815381] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration=1.528479ms duration-ns=1528479 fields.time="2026-08-18T08:21:50Z" method=POST name=ca nonce=RzY4azcxeWVWMzVCNWkwcEpQUHZQN0tBS0l3bVBMdFU path=/acme/acme/challenge/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO/w1pTMjoai79us3h7sVpUpeoC13pdUBnT protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1d5ea797-61e8-46a5-9e23-06bcbb83496f response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"2owH9xJ7I9OHfVykIdrLypdZxxM7NdO2\",\"validated\":\"2026-08-18T08:21:50Z\",\"url\":\"https://ca.foo/acme/acme/challenge/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO/w1pTMjoai79us3h7sVpUpeoC13pdUBnT\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.817940] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info duration=1.68893ms duration-ns=1688930 fields.time="2026-08-18T08:21:50Z" method=POST name=ca nonce=S2pwaU9MTnlJUHNnTWljMzRyRURuTnVld1BTR3BnUVE path=/acme/acme/order/FwnBKDFEu32RkeLunohvDeoiI3ajxD20/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=9411ec7d-788d-439b-8f2a-a4672281a8a7 response="{\"id\":\"FwnBKDFEu32RkeLunohvDeoiI3ajxD20\",\"status\":\"valid\",\"expires\":\"2026-08-19T08:21:50Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T08:20:50Z\",\"notAfter\":\"2026-11-16T08:21:50Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO\"],\"finalize\":\"https://ca.foo/acme/acme/order/FwnBKDFEu32RkeLunohvDeoiI3ajxD20/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/BqyDpgVCr64f9C9PL0L2W6gHB48mhnMR\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [6819652.819136] ca step-ca[204]: time="2026-08-18T08:21:50Z" level=info certificate=MIIB2TCCAX6gAwIBAgIRANfqXwGgCgnTOMtGNozgnUkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE4MDgyMDUwWhcNMjYxMTE2MDgyMTUwWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABCDwdy0PWfRyq8r360g831YdT5Shl57AMB5hXpsKSVsxlSxy5AQKsiIv4QqEFrKYKqHsgW1ciaVOHjyM38l8Hd6jgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUmyJmohlHb6StPHhezwPEqz6zyUkwHwYDVR0jBBgwFoAURd83D7hvBDeJ++grICldsNx3AZcwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0kAMEYCIQCMdx/pB54hnmYhwjTpKFu86LkgiZ03GZO3CSmJm7OtqwIhAPu3zi9w5kidDarGV4CkaS/blS+Nck2+p7a8P5GJlY11 duration="466.749µs" duration-ns=466749 fields.time="2026-08-18T08:21:50Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UUxoZERVaEd6NE56UmtJc0NWY2MzV2F1TjB2Y29NSkg path=/acme/acme/certificate/BqyDpgVCr64f9C9PL0L2W6gHB48mhnMR protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c62f106b-e402-4ef7-8efb-2e612bb84ed7 sans="map[dns:[test.foo]]" serial=287000943516324308989614411237463989577 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-18T08:20:50Z" valid-to="2026-11-16T08:21:50Z" container-test-run-certificates> server # [6819652.725110] server acme-order-renew-test.foo-start[323]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6819652.726744] server acme-order-renew-test.foo-start[323]: + set -euo pipefail container-test-run-certificates> server # [6819652.726776] server acme-order-renew-test.foo-start[323]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6819652.726834] server acme-order-renew-test.foo-start[323]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6819652.727680] server acme-order-renew-test.foo-start[323]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6819652.749779] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: Your account credentials have been saved in your container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: configuration directory at "accounts". container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: configuration directory will also contain private keys container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6819652.753046] server acme-order-renew-test.foo-start[331]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6819652.753196] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6819652.813165] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/s9o5qgHYXyPVH4ECmNVM6eQf9qQAHrUO container-test-run-certificates> server # [6819652.813165] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6819652.813165] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6819652.813165] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6819652.815509] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6819652.815536] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6819652.819254] server acme-order-renew-test.foo-start[331]: 2026/08/18 08:21:50 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6819652.821776] server acme-order-renew-test.foo-start[323]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6819652.822706] server acme-order-renew-test.foo-start[323]: + touch out/acme-success container-test-run-certificates> server # [6819652.823463] server acme-order-renew-test.foo-start[323]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6819652.823961] server acme-order-renew-test.foo-start[323]: + touch out/renewed container-test-run-certificates> server # [6819652.824642] server acme-order-renew-test.foo-start[323]: + echo Installing new certificate container-test-run-certificates> server # [6819652.824642] server acme-order-renew-test.foo-start[323]: Installing new certificate container-test-run-certificates> server # [6819652.824661] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6819652.825360] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6819652.825491] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6819652.826172] server acme-order-renew-test.foo-start[353]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6819652.826277] server acme-order-renew-test.foo-start[323]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6819652.826920] server acme-order-renew-test.foo-start[354]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6819652.827029] server acme-order-renew-test.foo-start[323]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6819652.828065] server acme-order-renew-test.foo-start[323]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6819652.828821] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6819652.828832] server acme-order-renew-test.foo-start[323]: + '[' -d out ']' container-test-run-certificates> server # [6819652.828832] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6819652.829596] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx out container-test-run-certificates> server # [6819652.831073] server acme-order-renew-test.foo-start[323]: + for fixpath in out certificates container-test-run-certificates> server # [6819652.831073] server acme-order-renew-test.foo-start[323]: + '[' -d certificates ']' container-test-run-certificates> server # [6819652.831111] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6819652.832168] server acme-order-renew-test.foo-start[323]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6819652.833440] server acme-order-renew-test.foo-start[323]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [6819652.907658] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6819652.909585] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6819652.909679] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:21:43 2026 GMT container-test-run-certificates> * expire date: Sep 17 08:21:43 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 7944e4 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6819653.262229] server nginx[370]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [6819653.262519] server nginx[370]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [6819653.600126] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 18 08:20:50 2026 GMT container-test-run-certificates> * expire date: Nov 16 08:21:50 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 38198 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1630 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 2.06 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> d7:ea:5f:01:a0:0a:09:d3:38:cb:46:36:8c:e0:9d:49 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 18 08:20:50 2026 GMT container-test-run-certificates> Not After : Nov 16 08:21:50 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:20:f0:77:2d:0f:59:f4:72:ab:ca:f7:eb:48:3c: container-test-run-certificates> df:56:1d:4f:94:a1:97:9e:c0:30:1e:61:5e:9b:0a: container-test-run-certificates> 49:5b:31:95:2c:72:e4:04:0a:b2:22:2f:e1:0a:84: container-test-run-certificates> 16:b2:98:2a:a1:ec:81:6d:5c:89:a5:4e:1e:3c:8c: container-test-run-certificates> df:c9:7c:1d:de container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 9B:22:66:A2:19:47:6F:A4:AD:3C:78:5E:CF:03:C4:AB:3E:B3:C9:49 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 45:DF:37:0F:B8:6F:04:37:89:FB:E8:2B:20:29:5D:B0:DC:77:01:97 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:8c:77:1f:e9:07:9e:21:9e:66:21:c2:34:e9: container-test-run-certificates> 28:5b:bc:e8:b9:20:89:9d:37:19:93:b7:09:29:89:9b:b3:ad: container-test-run-certificates> ab:02:21:00:fb:b7:ce:2f:70:e6:48:9d:0d:aa:c6:57:80:a4: container-test-run-certificates> 69:2f:db:95:2f:8d:72:4d:be:a7:b6:bc:3f:91:89:95:8d:75 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 10.09 seconds) container-test-run-certificates> test script finished in 10.14s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.29 seconds) post-build step Upload to niks3: ok time=2026-08-18T08:21:52.432Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-18T08:21:52.964Z level=INFO msg="Uploading 1 narinfos" time=2026-08-18T08:21:53.672Z level=INFO msg="Upload complete. (1.294s)"