nixbot

builds

succeeded container-test-run-certificates default.checks.aarch64-linux.certificates · build #410 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15server: systemd-nspawn running (pid 55)16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container server on /build/vm-state-server.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container ca on /build/vm-state-ca.31ca # [6104564.499469] ca systemd-journald[77]: Journal started32client # [6104564.499690] client systemd-journald[69]: Journal started33server # [6104564.487880] server systemd-journald[69]: Journal started34client # [6104564.499742] client systemd-journald[69]: Runtime Journal (/run/log/journal/bf1d1556c15042d8a85b79243df5f90f) is 8M, max 2.5G, 2.4G free.35ca # [6104564.499527] ca systemd-journald[77]: Runtime Journal (/run/log/journal/dbcf7571945c4d0a99e3f3a792ef2a83) is 8M, max 2.5G, 2.4G free.36client # [6104564.504183] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.37ca # [6104564.504145] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.38client # [6104564.515231] client systemd[1]: Starting Flush Journal to Persistent Storage...39ca # [6104564.513163] ca systemd[1]: Starting Flush Journal to Persistent Storage...40client # [6104564.516281] client systemd[1]: Starting Network Name Resolution...41ca # [6104564.514039] ca systemd[1]: Starting Network Name Resolution...42client # [6104564.516994] client systemd[1]: Starting Create Static Device Nodes in /dev...43ca # [6104564.514719] ca systemd[1]: Starting Create Static Device Nodes in /dev...44client # [6104564.525556] client systemd-journald[69]: Time spent on flushing to /var/log/journal/bf1d1556c15042d8a85b79243df5f90f is 1.627ms for 6 entries.45ca # [6104564.522545] ca systemd-journald[77]: Time spent on flushing to /var/log/journal/dbcf7571945c4d0a99e3f3a792ef2a83 is 1.537ms for 6 entries.46client # [6104564.525556] client systemd-journald[69]: System Journal (/var/log/journal/bf1d1556c15042d8a85b79243df5f90f) is 8M, max 4G, 3.9G free.47client # [6104564.534924] client systemd[1]: Finished Create Static Device Nodes in /dev.48server # [6104564.487930] server systemd-journald[69]: Runtime Journal (/run/log/journal/37bb5471286049fd81d9ef6030eba584) is 8M, max 2.5G, 2.4G free.49client # [6104564.535651] client systemd[1]: Reached target Preparation for Local File Systems.50server # [6104564.493586] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.51client # [6104564.535773] client systemd[1]: Reached target Local File Systems.52server # [6104564.503294] server systemd[1]: Starting Flush Journal to Persistent Storage...53client # [6104564.536616] client systemd[1]: Listening on Boot Loader Control Service Socket.54server # [6104564.504321] server systemd[1]: Starting Network Name Resolution...55client # [6104564.536668] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container56server # [6104564.505059] server systemd[1]: Starting Create Static Device Nodes in /dev...57client # [6104564.537594] client systemd[1]: Starting Save Transient machine-id to Disk...58server # [6104564.514427] server systemd-journald[69]: Time spent on flushing to /var/log/journal/37bb5471286049fd81d9ef6030eba584 is 1.754ms for 6 entries.59client # [6104564.537628] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys60server # [6104564.514427] server systemd-journald[69]: System Journal (/var/log/journal/37bb5471286049fd81d9ef6030eba584) is 8M, max 4G, 3.9G free.61client # [6104564.540143] client systemd[1]: Finished Flush Journal to Persistent Storage.62server # [6104564.518480] server systemd[1]: Finished Create Static Device Nodes in /dev.63client # [6104564.541006] client systemd[1]: Starting Create System Files and Directories...64server # [6104564.518758] server systemd[1]: Reached target Preparation for Local File Systems.65client # [6104564.555713] client systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted66server # [6104564.518852] server systemd[1]: Reached target Local File Systems.67client # [6104564.555897] client systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted68server # [6104564.519617] server systemd[1]: Listening on Boot Loader Control Service Socket.69client # [6104564.556043] client systemd-tmpfiles[116]: fchmod() of /var/log/journal/bf1d1556c15042d8a85b79243df5f90f failed: Operation not permitted70server # [6104564.519656] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container71client # [6104564.556254] client systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted72server # [6104564.520618] server systemd[1]: Starting Save Transient machine-id to Disk...73client # [6104564.557968] client systemd[1]: Finished Create System Files and Directories.74server # [6104564.520656] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys75client # [6104564.559134] client systemd[1]: Starting Rebuild Journal Catalog...76server # [6104564.539739] server systemd[1]: Finished Flush Journal to Persistent Storage.77client # [6104564.559964] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...78server # [6104564.540740] server systemd[1]: Starting Create System Files and Directories...79server # [6104564.556214] server systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted80server # [6104564.556417] server systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted81server # [6104564.556538] server systemd-tmpfiles[123]: fchmod() of /var/log/journal/37bb5471286049fd81d9ef6030eba584 failed: Operation not permitted82server # [6104564.556719] server systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted83server # [6104564.558242] server systemd[1]: Finished Create System Files and Directories.84server # [6104564.559463] server systemd[1]: Starting Rebuild Journal Catalog...85server # [6104564.560308] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...86ca # [6104564.522545] ca systemd-journald[77]: System Journal (/var/log/journal/dbcf7571945c4d0a99e3f3a792ef2a83) is 8M, max 4G, 3.9G free.87ca # [6104564.526902] ca systemd[1]: Finished Create Static Device Nodes in /dev.88ca # [6104564.527684] ca systemd[1]: Reached target Preparation for Local File Systems.89ca # [6104564.527815] ca systemd[1]: Reached target Local File Systems.90ca # [6104564.528954] ca systemd[1]: Listening on Boot Loader Control Service Socket.91ca # [6104564.529006] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container92ca # [6104564.530353] ca systemd[1]: Starting Save Transient machine-id to Disk...93ca # [6104564.530397] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys94ca # [6104564.539328] ca systemd[1]: Finished Flush Journal to Persistent Storage.95ca # [6104564.540455] ca systemd[1]: Starting Create System Files and Directories...96ca # [6104564.556214] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted97ca # [6104564.556412] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted98ca # [6104564.556533] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/dbcf7571945c4d0a99e3f3a792ef2a83 failed: Operation not permitted99ca # [6104564.556712] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted100ca # [6104564.557890] ca systemd[1]: Finished Create System Files and Directories.101ca # [6104564.559621] ca systemd[1]: Starting Rebuild Journal Catalog...102ca # [6104564.560490] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...103server # [6104564.572110] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.104server # [6104564.579855] server systemd[1]: Finished Rebuild Journal Catalog.105server # [6104564.580982] server systemd[1]: Starting Update is Completed...106server # [6104564.594940] server systemd[1]: Finished Update is Completed.107server # [6104564.633573] server systemd[1]: Finished Firewall.108server # [6104564.634116] server systemd[1]: Reached target Preparation for Network.109server # [6104564.634372] server systemd[1]: Listening on Network Management Resolve Hook Socket.110server # [6104564.635606] server systemd[1]: Starting Network Management...111ca # [6104564.572132] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.112client # [6104564.572064] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.113client # [6104564.579780] client systemd[1]: Finished Rebuild Journal Catalog.114client # [6104564.580949] client systemd[1]: Starting Update is Completed...115client # [6104564.592250] client systemd[1]: Finished Update is Completed.116client # [6104564.640136] client systemd[1]: Finished Firewall.117client # [6104564.640249] client systemd[1]: Reached target Preparation for Network.118client # [6104564.640477] client systemd[1]: Listening on Network Management Resolve Hook Socket.119client # [6104564.684420] client systemd[1]: Starting Network Management...120ca # [6104564.579785] ca systemd[1]: Finished Rebuild Journal Catalog.121ca # [6104564.581676] ca systemd[1]: Starting Update is Completed...122ca # [6104564.592239] ca systemd[1]: Finished Update is Completed.123ca # [6104564.684278] ca systemd[1]: Finished Firewall.124ca # [6104564.684486] ca systemd[1]: Reached target Preparation for Network.125ca # [6104564.684715] ca systemd[1]: Listening on Network Management Resolve Hook Socket.126ca # [6104564.685815] ca systemd[1]: Starting Network Management...127ca # [6104564.957059] ca systemd[1]: Finished Save Transient machine-id to Disk.128ca # [6104565.198190] ca systemd-networkd[194]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted129ca # [6104565.198299] ca systemd-networkd[194]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted130ca # [6104565.205285] ca systemd-networkd[194]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.131ca # [6104565.205449] ca systemd-networkd[194]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.132ca # [6104565.205617] ca systemd-networkd[194]: lo: Link UP133ca # [6104565.205622] ca systemd-networkd[194]: lo: Gained carrier134ca # [6104565.205826] ca systemd-networkd[194]: eth1: Configuring with /etc/systemd/network/40-eth1.network.135ca # [6104565.206186] ca systemd[1]: Started Network Management.136ca # [6104565.206493] ca systemd-networkd[194]: eth1: Link UP137ca # [6104565.206676] ca systemd-networkd[194]: eth1: Gained carrier138ca # [6104565.207487] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...139server # [6104564.956196] server systemd[1]: Finished Save Transient machine-id to Disk.140client # [6104564.955737] client systemd[1]: Finished Save Transient machine-id to Disk.141ca # [6104565.247706] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.142ca # [6104565.414053] ca systemd-resolved[101]: Positive Trust Anchors:143ca # [6104565.414066] ca systemd-resolved[101]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d144ca # [6104565.414070] ca systemd-resolved[101]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16145ca # [6104565.414104] ca systemd-resolved[101]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test146ca # [6104565.438370] ca systemd-resolved[101]: Using system hostname 'ca'.147ca # [6104565.440103] ca systemd[1]: Started Network Name Resolution.148ca # [6104565.440196] ca systemd[1]: Reached target Network.149ca # [6104565.440267] ca systemd[1]: Reached target Network is Online.150ca # [6104565.440317] ca systemd[1]: Reached target System Initialization.151ca # [6104565.440546] ca systemd[1]: Started Renew ACME Certificate for ca.foo.152ca # [6104565.440581] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container153ca # [6104565.440602] ca systemd[1]: Started Daily Cleanup of Temporary Directories.154ca # [6104565.440621] ca systemd[1]: Reached target Timer Units.155ca # [6104565.440758] ca systemd[1]: Listening on D-Bus System Message Bus Socket.156ca # [6104565.440882] ca systemd[1]: Listening on Nix Daemon Socket.157ca # [6104565.440989] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.158ca # [6104565.441008] ca systemd[1]: Reached target Socket Units.159ca # [6104565.441049] ca systemd[1]: Reached target Basic System.160ca # [6104565.442706] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...161ca # [6104565.443704] ca systemd[1]: Starting Import lastlog data into lastlog2 database...162ca # [6104565.443749] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem163ca # [6104565.444941] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...164ca # [6104565.445943] ca systemd[1]: Starting step-ca service...165ca # [6104565.447384] ca systemd[1]: Starting D-Bus System Message Bus...166client # [6104565.210816] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted167client # [6104565.210915] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted168client # [6104565.217802] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.169client # [6104565.217976] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.170client # [6104565.218228] client systemd-networkd[182]: lo: Link UP171client # [6104565.218232] client systemd-networkd[182]: lo: Gained carrier172client # [6104565.218442] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.173client # [6104565.218885] client systemd[1]: Started Network Management.174client # [6104565.240435] client systemd-networkd[182]: eth1: Link UP175client # [6104565.240896] client systemd-networkd[182]: eth1: Gained carrier176client # [6104565.241491] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...177client # [6104565.274747] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.178client # [6104565.444938] client systemd-resolved[96]: Positive Trust Anchors:179client # [6104565.444951] client systemd-resolved[96]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d180client # [6104565.444954] client systemd-resolved[96]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16181client # [6104565.444991] client systemd-resolved[96]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test182client # [6104565.468151] client systemd-resolved[96]: Using system hostname 'client'.183server # [6104565.210529] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted184server # [6104565.210625] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted185server # [6104565.217802] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.186server # [6104565.217970] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.187server # [6104565.218173] server systemd-networkd[186]: lo: Link UP188server # [6104565.218177] server systemd-networkd[186]: lo: Gained carrier189server # [6104565.218392] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.190server # [6104565.218821] server systemd[1]: Started Network Management.191server # [6104565.240520] server systemd-networkd[186]: eth1: Link UP192server # [6104565.240567] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...193server # [6104565.240908] server systemd-networkd[186]: eth1: Gained carrier194server # [6104565.293538] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.195server # [6104565.453069] server systemd-resolved[95]: Positive Trust Anchors:196server # [6104565.453087] server systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d197server # [6104565.453091] server systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16198server # [6104565.453126] server systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test199server # [6104565.476421] server systemd-resolved[95]: Using system hostname 'server'.200ca # [6104565.463279] ca systemd[1]: Finished Import lastlog data into lastlog2 database.201client # [6104565.469739] client systemd[1]: Started Network Name Resolution.202ca # [6104565.493899] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.203server # [6104565.483219] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.204ca # [6104565.588596] ca acme-setup-privileged[200]: + set -euo pipefail205server # [6104565.484124] server systemd[1]: Started Network Name Resolution.206server # [6104565.484206] server systemd[1]: Reached target Network.207client # [6104565.469830] client systemd[1]: Reached target Network.208ca # [6104565.588596] ca acme-setup-privileged[200]: + cd /var/lib/acme209ca # [6104565.588596] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts210server # [6104565.484258] server systemd[1]: Reached target Network is Online.211server # [6104565.484295] server systemd[1]: Reached target System Initialization.212ca # [6104565.590471] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts213client # [6104565.469899] client systemd[1]: Reached target System Initialization.214ca # [6104565.592069] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo215ca # [6104565.592163] ca acme-setup-privileged[200]: + '[' -d ca.foo ']'216client # [6104565.469947] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container217client # [6104565.469974] client systemd[1]: Started Daily Cleanup of Temporary Directories.218client # [6104565.469990] client systemd[1]: Reached target Timer Units.219ca # [6104565.592163] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo220client # [6104565.470119] client systemd[1]: Listening on D-Bus System Message Bus Socket.221server # [6104565.484493] server systemd[1]: Started Renew ACME Certificate for test.foo.222server # [6104565.484523] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container223ca # [6104565.592163] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']'224ca # [6104565.625164] ca nsncd[202]: Aug 18 15:06:31.678 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"225ca # [6104565.625738] ca systemd[1]: Started Name Service Cache Daemon (nsncd).226ca # [6104565.625809] ca systemd[1]: Reached target Host and Network Name Lookups.227server # [6104565.484543] server systemd[1]: Started Daily Cleanup of Temporary Directories.228server # [6104565.484558] server systemd[1]: Reached target Timer Units.229server # [6104565.484671] server systemd[1]: Listening on D-Bus System Message Bus Socket.230server # [6104565.484784] server systemd[1]: Listening on Nix Daemon Socket.231server # [6104565.484877] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.232server # [6104565.484898] server systemd[1]: Reached target Socket Units.233server # [6104565.484933] server systemd[1]: Reached target Basic System.234server # [6104565.486328] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...235server # [6104565.487042] server systemd[1]: Starting Import lastlog data into lastlog2 database...236server # [6104565.487080] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem237server # [6104565.488705] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...238server # [6104565.489978] server systemd[1]: Starting D-Bus System Message Bus...239server # [6104565.505939] server systemd[1]: Finished Import lastlog data into lastlog2 database.240server # [6104565.600041] server acme-setup-privileged[192]: + set -euo pipefail241client # [6104565.470250] client systemd[1]: Listening on Nix Daemon Socket.242ca # [6104565.625935] ca systemd[1]: Reached target User and Group Name Lookups.243client # [6104565.470363] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.244client # [6104565.470395] client systemd[1]: Reached target Socket Units.245client # [6104565.470435] client systemd[1]: Reached target Basic System.246client # [6104565.471788] client systemd[1]: Starting Import lastlog data into lastlog2 database...247client # [6104565.472847] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...248client # [6104565.474194] client systemd[1]: Starting D-Bus System Message Bus...249client # [6104565.494412] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.250client # [6104565.495673] client systemd[1]: Finished Import lastlog data into lastlog2 database.251client # [6104565.618201] client nsncd[189]: Aug 18 15:06:31.671 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"252client # [6104565.618337] client systemd[1]: Started Name Service Cache Daemon (nsncd).253client # [6104565.618412] client systemd[1]: Reached target Host and Network Name Lookups.254client # [6104565.618466] client systemd[1]: Reached target User and Group Name Lookups.255client # [6104565.657231] client systemd[1]: Starting User Login Management...256client # [6104565.658926] client systemd[1]: Starting Permit User Sessions...257client # [6104565.669035] client systemd[1]: Finished Permit User Sessions.258client # [6104565.671112] client systemd[1]: Started Console Getty.259client # [6104565.671155] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0260client # [6104565.671177] client systemd[1]: Reached target Login Prompts.261ca # [6104565.659122] ca systemd[1]: Starting User Login Management...262ca # [6104565.660083] ca systemd[1]: Starting Permit User Sessions...263ca # [6104565.669044] ca systemd[1]: Finished Permit User Sessions.264ca # [6104565.670206] ca systemd[1]: Started Console Getty.265ca # [6104565.670257] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0266ca # [6104565.670272] ca systemd[1]: Reached target Login Prompts.267server # [6104565.600041] server acme-setup-privileged[192]: + cd /var/lib/acme268server # [6104565.600041] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts269server # [6104565.600041] server acme-setup-privileged[192]: + chown -R acme .lego/accounts270server # [6104565.601537] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo271server # [6104565.601572] server acme-setup-privileged[192]: + '[' -d test.foo ']'272server # [6104565.601572] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo273server # [6104565.601572] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'274server # [6104565.630850] server nsncd[194]: Aug 18 15:06:31.683 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"275server # [6104565.656619] server systemd[1]: Started Name Service Cache Daemon (nsncd).276server # [6104565.656759] server systemd[1]: Reached target Host and Network Name Lookups.277server # [6104565.656813] server systemd[1]: Reached target User and Group Name Lookups.278server # [6104565.657929] server systemd[1]: Starting User Login Management...279server # [6104565.658920] server systemd[1]: Starting Permit User Sessions...280server # [6104565.669049] server systemd[1]: Finished Permit User Sessions.281server # [6104565.670213] server systemd[1]: Started Console Getty.282server # [6104565.670258] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0283server # [6104565.670275] server systemd[1]: Reached target Login Prompts.284ca # [6104565.820840] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'...285ca # [6104565.821618] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync'286ca # [6104565.821618] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/xmd1i3ap1psbjjd8jjb61sllz5bs9zdx-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"287ca # [6104565.822070] ca systemd[1]: Started D-Bus System Message Bus.288ca # [6104565.829794] ca dbus-broker-launch[204]: Ready289client # [6104565.833840] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...290client # [6104565.834635] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'291client # [6104565.834635] client dbus-broker-launch[190]: Invalid user-name in /nix/store/piinrd6zbwzw47v2y0bqhk41qbb61bx6-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"292client # [6104565.835013] client systemd[1]: Started D-Bus System Message Bus.293client # [6104565.842320] client dbus-broker-launch[190]: Ready294server # [6104565.828750] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...295server # [6104565.830347] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'296server # [6104565.830347] server dbus-broker-launch[195]: Invalid user-name in /nix/store/4rj948lgxiawvvwrzk5fv0hp8lkyx940-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"297server # [6104565.830814] server systemd[1]: Started D-Bus System Message Bus.298server # [6104565.838041] server dbus-broker-launch[195]: Ready299ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 300client # [6104566.403752] client systemd-logind[205]: New seat seat0.301client # [6104566.403931] client systemd[1]: Started User Login Management.302client # [6104566.425417] client systemd[1]: Starting linger-users.service...303client # [6104566.443210] client systemd[1]: linger-users.service: Deactivated successfully.304client # [6104566.443293] client systemd[1]: Finished linger-users.service.305client # [6104566.443686] client systemd[1]: Reached target Multi-User System.306client # [6104566.443833] client systemd[1]: Startup finished in 2.453s.307server # [6104566.393907] server systemd-logind[219]: New seat seat0.308server # [6104566.394123] server systemd[1]: Started User Login Management.309server # [6104566.425418] server systemd[1]: Starting linger-users.service...310server # [6104566.438001] server systemd[1]: linger-users.service: Deactivated successfully.311server # [6104566.438285] server systemd[1]: Finished linger-users.service.312server # [6104566.489284] server acme-setup-start[208]: + set -euo pipefail313server # [6104566.489284] server acme-setup-start[208]: + test -e ca/key.pem314server # [6104566.489939] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local315server # [6104566.496173] server systemd-networkd[186]: eth1: Gained IPv6LL316server # [6104566.508617] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.317server # [6104566.510463] server systemd[1]: Starting Ensure certificate for test.foo...318ca # [6104566.402965] ca systemd-logind[230]: New seat seat0.319ca # [6104566.403159] ca systemd[1]: Started User Login Management.320ca # [6104566.428244] ca systemd[1]: Starting linger-users.service...321ca # [6104566.441528] ca systemd[1]: linger-users.service: Deactivated successfully.322ca # [6104566.441648] ca systemd[1]: Finished linger-users.service.323ca # [6104566.503694] ca acme-setup-start[218]: + set -euo pipefail324ca # [6104566.503694] ca acme-setup-start[218]: + test -e ca/key.pem325ca # [6104566.504271] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local326ca # [6104566.522245] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.327ca # [6104566.524061] ca systemd[1]: Starting Ensure certificate for ca.foo...328ca # [6104566.716283] ca step-ca[203]: badger 2026/08/18 15:06:32 INFO: All 0 tables opened in 0s329ca # [6104566.722953] ca step-ca[203]: 2026/08/18 15:06:32 Building new tls configuration using step-ca x509 Signer Interface330ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 Starting Smallstep CA/0.30.2 (linux/arm64)331ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 Documentation: https://u.step.sm/docs/ca332ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 Community Discord: https://u.step.sm/discord333ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 Config file: /etc/smallstep/ca.json334ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 The primary server URL is https://ca.foo:1443335ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 Root certificates are available at https://ca.foo:1443/roots.pem336ca # [6104566.732356] ca step-ca[203]: 2026/08/18 15:06:32 X.509 Root Fingerprint: e826ba1017ed9c6d1e80bbc83d56e54b4763fd0cf6f59c398a4f0b383416ea71337ca # [6104566.733667] ca step-ca[203]: 2026/08/18 15:06:32 Serving HTTPS on 0.0.0.0:1443 ...338ca # [6104566.734297] ca systemd[1]: Started step-ca service.339ca # [6104566.852223] ca systemd-networkd[194]: eth1: Gained IPv6LL340client # [6104567.012123] client systemd-networkd[182]: eth1: Gained IPv6LL341server # [6104567.221738] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/342server # [6104567.224434] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'343server # [6104567.224555] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=344server # [6104567.235314] server acme-test.foo-start[255]: + cd test.foo345server # [6104567.235606] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem346server # [6104567.236784] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'347server # [6104567.236998] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem348server # [6104567.238170] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'349server # [6104567.238373] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem350server # [6104567.240032] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem351server # [6104567.241675] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem352server # [6104567.243191] server acme-test.foo-start[245]: + for fixpath in out certificates353server # [6104567.243215] server acme-test.foo-start[245]: + '[' -d out ']'354server # [6104567.243242] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out355server # [6104567.244996] server acme-test.foo-start[245]: + chown -R acme:nginx out356server # [6104567.247358] server acme-test.foo-start[245]: + for fixpath in out certificates357server # [6104567.247358] server acme-test.foo-start[245]: + '[' -d certificates ']'358server # [6104567.250609] server systemd[1]: Finished Ensure certificate for test.foo.359server # [6104567.252144] server systemd[1]: Starting Nginx Web Server...360ca # [6104567.250100] ca acme-ca.foo-start[255]: Waiting to acquire lock in /run/acme/361ca # [6104567.252578] ca acme-ca.foo-start[255]: + '[' -e out/acme-success ']'362ca # [6104567.252706] ca acme-ca.foo-start[255]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=363ca # [6104567.263613] ca acme-ca.foo-start[290]: + cd ca.foo364ca # [6104567.264061] ca acme-ca.foo-start[290]: + cp -vp cert.pem ../out/cert.pem365ca # [6104567.265213] ca acme-ca.foo-start[291]: 'cert.pem' -> '../out/cert.pem'366ca # [6104567.265486] ca acme-ca.foo-start[290]: + cp -vp key.pem ../out/key.pem367ca # [6104567.266967] ca acme-ca.foo-start[290]: 'key.pem' -> '../out/key.pem'368ca # [6104567.267235] ca acme-ca.foo-start[255]: + cat out/cert.pem ca/cert.pem369ca # [6104567.268808] ca acme-ca.foo-start[255]: + cp ca/cert.pem out/chain.pem370ca # [6104567.270677] ca acme-ca.foo-start[255]: + cat out/key.pem out/fullchain.pem371ca # [6104567.272338] ca acme-ca.foo-start[255]: + for fixpath in out certificates372ca # [6104567.272338] ca acme-ca.foo-start[255]: + '[' -d out ']'373ca # [6104567.272338] ca acme-ca.foo-start[255]: + chmod -R u=rwX,g=rX,o= out374ca # [6104567.273845] ca acme-ca.foo-start[255]: + chown -R acme:nginx out375ca # [6104567.276159] ca acme-ca.foo-start[255]: + for fixpath in out certificates376ca # [6104567.276197] ca acme-ca.foo-start[255]: + '[' -d certificates ']'377ca # [6104567.308362] ca systemd[1]: Finished Ensure certificate for ca.foo.378ca # [6104567.309959] ca systemd[1]: Starting Nginx Web Server...379server # [6104567.896911] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok380server # [6104567.897247] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful381server # [6104567.902172] server systemd[1]: Started Nginx Web Server.382server # [6104567.902592] server systemd[1]: Reached target Multi-User System.383server # [6104567.907186] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...384ca # [6104567.916744] ca nginx-pre-start[302]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok385ca # [6104567.917133] ca nginx-pre-start[302]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful386ca # [6104567.940454] ca systemd[1]: Started Nginx Web Server.387ca # [6104567.941244] ca systemd[1]: Reached target Multi-User System.388ca # [6104567.942801] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...389server # [6104568.610869] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/390server # [6104568.613308] server acme-order-renew-test.foo-start[270]: + set -euo pipefail391server # [6104568.613389] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108392server # [6104568.613514] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt393server # [6104568.614568] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run394server # [6104568.637357] server acme-order-renew-test.foo-start[282]: 2026/08/18 15:06:34 No key found for account none@none.tld. Generating a P256 key.395server # [6104568.637670] server acme-order-renew-test.foo-start[282]: 2026/08/18 15:06:34 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key396server # [6104568.676733] server acme-order-renew-test.foo-start[282]: 2026/08/18 15:06:34 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority397server # [6104568.680498] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.398server # [6104568.680498] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.399server # [6104568.680565] server acme-order-renew-test.foo-start[270]: + exit 10400server # [6104568.683331] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a401server # [6104568.683424] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.402server # [6104568.683964] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.403server # [6104568.684344] server systemd[1]: Startup finished in 4.693s.404ca # [6104568.633002] ca acme-order-renew-ca.foo-start[305]: Waiting to acquire lock in /run/acme/405ca # [6104568.636169] ca acme-order-renew-ca.foo-start[305]: + set -euo pipefail406ca # [6104568.636261] ca acme-order-renew-ca.foo-start[305]: + echo 88dc4fc401a6091a1bd9407ca # [6104568.636376] ca acme-order-renew-ca.foo-start[305]: + cmp -s domainhash.txt certificates/domainhash.txt408ca # [6104568.637392] ca acme-order-renew-ca.foo-start[305]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run409ca # [6104568.651908] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 No key found for account none@none.tld. Generating a P256 key.410ca # [6104568.652245] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key411ca # [6104568.678408] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration="177.722µs" duration-ns=177722 fields.time="2026-08-18T15:06:34Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=14e9c87a-7cac-4dd9-aad1-adaa106de735 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=412ca # [6104568.678873] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] acme: Registering account for none@none.tld413ca # [6104568.686508] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=7.274941ms duration-ns=7274941 fields.time="2026-08-18T15:06:34Z" method=HEAD name=ca nonce=VlMwMnp2WkxYcFQ1NkNRZEFPSGthanFpOXRNOW9SM1A path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=e00427ac-2ab6-4e17-92e7-576fca1a6cd4 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=414ca # [6104568.689869] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=2.569196ms duration-ns=2569196 fields.time="2026-08-18T15:06:34Z" method=POST name=ca nonce=Z2V1UHhqSDVtMUp3UHpmU0x1UVowR2UxVlJJNHNXNUE path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=befb77a6-d229-42dc-93b9-32aceaec1c1c response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/CuFzVqh37MpsvMbgmDthbKDIzAUtfHIw/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=415ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: !!!! HEADS UP !!!!416ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: Your account credentials have been saved in your417ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: configuration directory at "accounts".418ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: You should make a secure backup of this folder now. This419ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: configuration directory will also contain private keys420ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: generated by lego and certificates obtained from the ACME421ca # [6104568.690536] ca acme-order-renew-ca.foo-start[317]: server. Making regular backups of this folder is ideal.422ca # [6104568.690669] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate423ca # [6104568.696440] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=5.162112ms duration-ns=5162112 fields.time="2026-08-18T15:06:34Z" method=POST name=ca nonce=Vnlza2lvWFFGT1hNSEVHc1BBcTdDTUV6blFEbUx3ZjY path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=5199385d-c448-45bd-bf9c-1ebd5a53bf49 response="{\"id\":\"EIB1rw3O7GRLq5nINg46TDD5Fhzh8cbb\",\"status\":\"pending\",\"expires\":\"2026-08-19T15:06:34Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T15:05:34Z\",\"notAfter\":\"2026-11-16T15:06:34Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/EIB1rw3O7GRLq5nINg46TDD5Fhzh8cbb/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=424ca # [6104568.757479] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=3.887534ms duration-ns=3887534 fields.time="2026-08-18T15:06:34Z" method=POST name=ca nonce=WjBVZ0lHNkJvT2dWOEhPSU94TjlReEVHOGhXWjdmMFI path=/acme/acme/authz/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=43d56e7e-0ff7-479b-86f9-ce28cfd39de4 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"XiK5Awp8OavGKItp3pbDjQQh94XHdHcL\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ/3YC92QLyC4xVMfvgZ9Y326xyvvgTZ7U5\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"XiK5Awp8OavGKItp3pbDjQQh94XHdHcL\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ/O1uDKoD1mLTsCfkzU4Vcsi62SQx8jslW\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"XiK5Awp8OavGKItp3pbDjQQh94XHdHcL\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ/AEQWjmTqFAQHlQVg3Qjc4JQ4HpGRj2Iv\"}],\"wildcard\":false,\"expires\":\"2026-08-19T15:06:34Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=425ca # [6104568.757903] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ426ca # [6104568.757903] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01427ca # [6104568.757903] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] acme: use http-01 solver428ca # [6104568.757986] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] acme: Trying to solve HTTP-01429ca # [6104568.762914] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=4.26986ms duration-ns=4269860 fields.time="2026-08-18T15:06:34Z" method=POST name=ca nonce=dGNxYUR5RmFHUHhKdGJKQkxMcFJtTmtVWVRLUzFZODc path=/acme/acme/challenge/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ/O1uDKoD1mLTsCfkzU4Vcsi62SQx8jslW protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a65c0963-0405-4826-8cc8-949156f5fb88 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"XiK5Awp8OavGKItp3pbDjQQh94XHdHcL\",\"validated\":\"2026-08-18T15:06:34Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ/O1uDKoD1mLTsCfkzU4Vcsi62SQx8jslW\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=430ca # [6104568.763169] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] The server validated our request431ca # [6104568.763237] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates432ca # [6104568.769413] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info duration=5.381595ms duration-ns=5381595 fields.time="2026-08-18T15:06:34Z" method=POST name=ca nonce=b0FNaDJaT0s3cEdWVWh4a1ZHT2hGZzJqZmtncHN0Zm8 path=/acme/acme/order/EIB1rw3O7GRLq5nINg46TDD5Fhzh8cbb/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3b32ec1b-d10a-4b57-a41e-19d432a7210a response="{\"id\":\"EIB1rw3O7GRLq5nINg46TDD5Fhzh8cbb\",\"status\":\"valid\",\"expires\":\"2026-08-19T15:06:34Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-18T15:05:34Z\",\"notAfter\":\"2026-11-16T15:06:34Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/3K1BhI209YtlzOKzS6lBG1Tf2Yq4X8tQ\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/EIB1rw3O7GRLq5nINg46TDD5Fhzh8cbb/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/QYxZFV6yQH4bO7BVW7I2Xe2Rk2SzdzPo\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=433ca # [6104568.771086] ca step-ca[203]: time="2026-08-18T15:06:34Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAON+5CF0JndObfj7dWtB0ZMwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODE4MTUwNTM0WhcNMjYxMTE2MTUwNjM0WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATr3XaOwK0StCOCl1WuVDM1cuAVbA7z8bKUc3V4oodntSanWU4rGN5DHm2SxqWhumDkkJOCCC1J44VQWTAbEEkao4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFEolSLkQLiXCABDesR7vSdhnVqVDMB8GA1UdIwQYMBaAFChfJ4LjrTvWp16TRwqeRcBmW5VsMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgSu9o/mOviR8IVD27clkZeBrHjmFwJti5CQfP9DSizCcCIQDJ9pDNH/7cWTxAF246r1MY0ytVUONueKwZsAsjC/Jn5A==" duration=1.104575ms duration-ns=1104575 fields.time="2026-08-18T15:06:34Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=bzZzWFJ4Rk5NWFJRV1dKMlRXNDM2MXFMUXl2YVlUeXU path=/acme/acme/certificate/QYxZFV6yQH4bO7BVW7I2Xe2Rk2SzdzPo protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=644b0a86-3669-460f-b41c-44c45168685c sans="map[dns:[ca.foo]]" serial=302393611487217050710742088925290025363 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-18T15:05:34Z" valid-to="2026-11-16T15:06:34Z"434ca # [6104568.771331] ca acme-order-renew-ca.foo-start[317]: 2026/08/18 15:06:34 [INFO] [ca.foo] Server responded with a certificate.435ca # [6104568.776842] ca acme-order-renew-ca.foo-start[305]: + mv domainhash.txt certificates/436ca # [6104568.778542] ca acme-order-renew-ca.foo-start[305]: + touch out/acme-success437ca # [6104568.779967] ca acme-order-renew-ca.foo-start[305]: + cmp -s certificates/ca.foo.crt out/fullchain.pem438ca # [6104568.780991] ca acme-order-renew-ca.foo-start[305]: + touch out/renewed439ca # [6104568.782415] ca acme-order-renew-ca.foo-start[305]: + echo Installing new certificate440ca # [6104568.782415] ca acme-order-renew-ca.foo-start[305]: Installing new certificate441ca # [6104568.782456] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.crt out/fullchain.pem442ca # [6104568.783768] ca acme-order-renew-ca.foo-start[347]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'443ca # [6104568.784010] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.key out/key.pem444ca # [6104568.785537] ca acme-order-renew-ca.foo-start[348]: 'certificates/ca.foo.key' -> 'out/key.pem'445ca # [6104568.785802] ca acme-order-renew-ca.foo-start[305]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem446ca # [6104568.787373] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'447ca # [6104568.787672] ca acme-order-renew-ca.foo-start[305]: + ln -sf fullchain.pem out/cert.pem448ca # [6104568.789325] ca acme-order-renew-ca.foo-start[305]: + cat out/key.pem out/fullchain.pem449ca # [6104568.791063] ca acme-order-renew-ca.foo-start[305]: + for fixpath in out certificates450ca # [6104568.791086] ca acme-order-renew-ca.foo-start[305]: + '[' -d out ']'451ca # [6104568.791086] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=rX,o= out452ca # [6104568.794222] ca acme-order-renew-ca.foo-start[305]: + chown -R acme:nginx out453ca # [6104568.799120] ca acme-order-renew-ca.foo-start[305]: + for fixpath in out certificates454ca # [6104568.799143] ca acme-order-renew-ca.foo-start[305]: + '[' -d certificates ']'455ca # [6104568.799159] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=rX,o= certificates456ca # [6104568.800710] ca acme-order-renew-ca.foo-start[305]: + chown -R acme:nginx certificates457ca # [6104568.802942] ca acme-order-renew-ca.foo-start[305]: + chmod -R u=rwX,g=,o= accounts/.458ca # [6104568.955515] ca systemd[1]: Reloading Nginx Web Server...459ca # [6104568.959501] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.460ca # [6104568.959829] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.461ca # [6104569.689140] ca nginx[365]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok462ca # [6104569.689140] ca nginx[365]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful463ca # [6104570.734615] ca systemd[1]: Reloaded Nginx Web Server.464ca # [6104570.734843] ca systemd[1]: Startup finished in 6.711s.465ca # [6104571.221057] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...466ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 5.60 seconds)467ca # [6104571.921134] ca acme-order-renew-ca.foo-start[380]: Waiting to acquire lock in /run/acme/468ca # [6104571.923671] ca acme-order-renew-ca.foo-start[380]: + set -euo pipefail469ca # [6104571.923746] ca acme-order-renew-ca.foo-start[380]: + echo 88dc4fc401a6091a1bd9470ca # [6104571.923866] ca acme-order-renew-ca.foo-start[380]: + cmp -s domainhash.txt certificates/domainhash.txt471ca # [6104571.925095] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.key ']'472ca # [6104571.925134] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.crt ']'473ca # [6104571.925653] ca acme-order-renew-ca.foo-start[388]: ++ find accounts -name none@none.tld.key474ca # [6104571.928720] ca acme-order-renew-ca.foo-start[380]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'475ca # [6104571.928760] ca acme-order-renew-ca.foo-start[380]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic476ca # [6104571.976762] ca step-ca[203]: time="2026-08-18T15:06:38Z" level=info duration="59.881µs" duration-ns=59881 fields.time="2026-08-18T15:06:38Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6848d2b4-0aed-4d04-b895-d3391e3c71d0 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=477ca # [6104571.977239] ca acme-order-renew-ca.foo-start[389]: 2026/08/18 15:06:38 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint478ca # [6104571.977239] ca acme-order-renew-ca.foo-start[389]: 2026/08/18 15:06:38 [INFO] [ca.foo] The certificate expires at 2026-11-16T15:06:34Z, the renewal can be performed in 1439h59m35.969665323s: no renewal.479ca # [6104571.980203] ca acme-order-renew-ca.foo-start[380]: + mv domainhash.txt certificates/480ca # [6104571.982659] ca acme-order-renew-ca.foo-start[380]: + touch out/acme-success481ca # [6104571.987074] ca acme-order-renew-ca.foo-start[380]: + cmp -s certificates/ca.foo.crt out/fullchain.pem482ca # [6104571.989267] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates483ca # [6104571.989267] ca acme-order-renew-ca.foo-start[380]: + '[' -d out ']'484ca # [6104571.989267] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= out485ca # [6104571.991060] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx out486ca # [6104571.994471] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates487ca # [6104571.994471] ca acme-order-renew-ca.foo-start[380]: + '[' -d certificates ']'488ca # [6104571.994632] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= certificates489ca # [6104571.997200] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx certificates490ca # [6104572.001956] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=,o= accounts/.491ca # [6104572.154220] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.492ca # [6104572.154421] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.493server: must succeed: systemctl restart acme-test.foo.service494server # [6104575.173097] server systemd[1]: acme-test.foo.service: Deactivated successfully.495server # [6104575.173266] server systemd[1]: Stopped Ensure certificate for test.foo.496server # [6104575.174212] server systemd[1]: Stopping Ensure certificate for test.foo...497server # [6104575.175879] server systemd[1]: Starting Ensure certificate for test.foo...498server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.73 seconds)499client: waiting for success: curl -v https://test.foo500* Host test.foo:443 was resolved.501* IPv6: 2001:db8:1::3502* IPv4: 192.168.1.3503* Trying [2001:db8:1::3]:443...504* ALPN: curl offers h2,http/1.1505} [5 bytes data]506* TLSv1.3 (OUT), TLS handshake, Client hello (1):507} [1552 bytes data]508* SSL Trust Anchors:509* OpenSSL default paths (fallback)510{ [5 bytes data]511* TLSv1.3 (IN), TLS handshake, Server hello (2):512{ [1210 bytes data]513* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):514{ [1 bytes data]515* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):516{ [19 bytes data]517* TLSv1.3 (IN), TLS handshake, Certificate (11):518{ [1009 bytes data]519* TLSv1.3 (IN), TLS handshake, CERT verify (15):520{ [112 bytes data]521* TLSv1.3 (IN), TLS handshake, Finished (20):522{ [52 bytes data]523* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):524} [1 bytes data]525* TLSv1.3 (OUT), TLS handshake, Finished (20):526} [52 bytes data]527* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey528* ALPN: server accepted h2529* Server certificate:530* subject: CN=test.foo531* start date: Aug 18 15:06:33 2026 GMT532* expire date: Sep 17 15:06:33 2028 GMT533* issuer: CN=minica root ca 084f42534* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384535* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384536* subjectAltName: "test.foo" matches cert's "test.foo"537* OpenSSL verify result: 13538* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)539* closing connection #0540curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)541More details here: https://curl.se/docs/sslcerts.html542543curl failed to verify the legitimacy of the server and therefore could not544establish a secure connection to it. To learn more about this situation and545how to fix it, please visit the webpage mentioned above.546server # [6104575.803321] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/547server # [6104575.806922] server acme-test.foo-start[316]: + '[' -e out/acme-success ']'548server # [6104575.806922] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=549server # [6104575.820827] server acme-test.foo-start[326]: + cd test.foo550server # [6104575.821334] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem551server # [6104575.822933] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem'552server # [6104575.823473] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem553server # [6104575.825487] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem'554server # [6104575.827887] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem555server # [6104575.830722] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem556server # [6104575.835542] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem557server # [6104575.839717] server acme-test.foo-start[316]: + for fixpath in out certificates558server # [6104575.839717] server acme-test.foo-start[316]: + '[' -d out ']'559server # [6104575.839717] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out560server # [6104575.841868] server acme-test.foo-start[316]: + chown -R acme:nginx out561server # [6104575.849850] server acme-test.foo-start[316]: + for fixpath in out certificates562server # [6104575.849850] server acme-test.foo-start[316]: + '[' -d certificates ']'563server # [6104575.884528] server systemd[1]: Finished Ensure certificate for test.foo.564server # [6104575.887967] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...565server # [6104576.669784] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/566server # [6104576.672584] server acme-order-renew-test.foo-start[334]: + set -euo pipefail567server # [6104576.672663] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108568server # [6104576.672785] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt569server # [6104576.673827] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run570server # [6104576.724060] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] acme: Registering account for none@none.tld571server # [6104576.746333] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!!572server # [6104576.746333] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your573server # [6104576.746333] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts".574server # [6104576.746333] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This575server # [6104576.746333] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys576server # [6104576.746333] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME577server # [6104576.746333] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal.578server # [6104576.746333] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] acme: Obtaining bundled SAN certificate579server # [6104576.846553] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/QnCPKSyyAohVQtVh4SHPWZygoptug69G580server # [6104576.846553] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01581server # [6104576.846553] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] acme: use http-01 solver582server # [6104576.846553] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] acme: Trying to solve HTTP-01583server # [6104576.860241] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] The server validated our request584server # [6104576.860419] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] acme: Validations succeeded; requesting certificates585server # [6104576.878555] server acme-order-renew-test.foo-start[342]: 2026/08/18 15:06:42 [INFO] [test.foo] Server responded with a certificate.586server # [6104576.886649] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/587server # [6104576.888856] server acme-order-renew-test.foo-start[334]: + touch out/acme-success588server # [6104576.890680] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem589server # [6104576.891877] server acme-order-renew-test.foo-start[334]: + touch out/renewed590server # [6104576.893492] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate591server # [6104576.893492] server acme-order-renew-test.foo-start[334]: Installing new certificate592server # [6104576.893554] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem593server # [6104576.895155] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'594server # [6104576.895934] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem595server # [6104576.898981] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem'596server # [6104576.899403] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem597server # [6104576.900921] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'598server # [6104576.901136] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem599server # [6104576.902773] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem600server # [6104576.904492] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates601server # [6104576.904513] server acme-order-renew-test.foo-start[334]: + '[' -d out ']'602server # [6104576.904513] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out603server # [6104576.906065] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out604server # [6104576.908759] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates605server # [6104576.908804] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']'606server # [6104576.908804] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates607server # [6104576.910247] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates608server # [6104576.918862] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/.609* Host test.foo:443 was resolved.610* IPv6: 2001:db8:1::3611* IPv4: 192.168.1.3612* Trying [2001:db8:1::3]:443...613* ALPN: curl offers h2,http/1.1614} [5 bytes data]615* TLSv1.3 (OUT), TLS handshake, Client hello (1):616} [1552 bytes data]617* SSL Trust Anchors:618* OpenSSL default paths (fallback)619{ [5 bytes data]620* TLSv1.3 (IN), TLS handshake, Server hello (2):621{ [1210 bytes data]622* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):623{ [1 bytes data]624* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):625{ [19 bytes data]626* TLSv1.3 (IN), TLS handshake, Certificate (11):627{ [1009 bytes data]628* TLSv1.3 (IN), TLS handshake, CERT verify (15):629{ [111 bytes data]630* TLSv1.3 (IN), TLS handshake, Finished (20):631{ [52 bytes data]632* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):633} [1 bytes data]634* TLSv1.3 (OUT), TLS handshake, Finished (20):635} [52 bytes data]636* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey637* ALPN: server accepted h2638* Server certificate:639* subject: CN=test.foo640* start date: Aug 18 15:06:33 2026 GMT641* expire date: Sep 17 15:06:33 2028 GMT642* issuer: CN=minica root ca 084f42643* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384644* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384645* subjectAltName: "test.foo" matches cert's "test.foo"646* OpenSSL verify result: 13647* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)648* closing connection #0649curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)650More details here: https://curl.se/docs/sslcerts.html651652curl failed to verify the legitimacy of the server and therefore could not653establish a secure connection to it. To learn more about this situation and654how to fix it, please visit the webpage mentioned above.655ca # [6104576.722444] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration="81.641µs" duration-ns=81641 fields.time="2026-08-18T15:06:42Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=2ba41723-0bca-4c4d-85f4-01a19930ee9d response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=656ca # [6104576.735256] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=9.567733ms duration-ns=9567733 fields.time="2026-08-18T15:06:42Z" method=HEAD name=ca nonce=UzZMVGlkQWZPTTdnaGFYSkpJOWtjcXJiTEc4ZWJORGg path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=3c3212c1-34f8-4868-9fee-8e07c9cbebad size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=657ca # [6104576.743365] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=5.594277ms duration-ns=5594277 fields.time="2026-08-18T15:06:42Z" method=POST name=ca nonce=a2R2Y1MySWxTRFZoSTNUbmZ3NTZIN2ZqTnRZVTMxdWo path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=02f16b75-d361-46fe-a362-23e44f016b93 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/Q03u9H20zIkbGn0QpG7sj8piJgl2tCmn/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=658ca # [6104576.754901] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=6.545611ms duration-ns=6545611 fields.time="2026-08-18T15:06:42Z" method=POST name=ca nonce=cm5OUGZ1UnBhbjBMYzZxdGZ2aWZMdDZwMG5nTEtwTlU path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=30acdcc9-4c4c-4c33-9143-9a1fc57ab1b3 response="{\"id\":\"06aQb9Jd1U2tSZPnyAeiLKbFNhDznrbL\",\"status\":\"pending\",\"expires\":\"2026-08-19T15:06:42Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T15:05:42Z\",\"notAfter\":\"2026-11-16T15:06:42Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/QnCPKSyyAohVQtVh4SHPWZygoptug69G\"],\"finalize\":\"https://ca.foo/acme/acme/order/06aQb9Jd1U2tSZPnyAeiLKbFNhDznrbL/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=659ca # [6104576.843673] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=23.237404ms duration-ns=23237404 fields.time="2026-08-18T15:06:42Z" method=POST name=ca nonce=eGY0SVlNTUpNeU9WdHFkQjU0SzJ4YXpOZEZyMnBBWjU path=/acme/acme/authz/QnCPKSyyAohVQtVh4SHPWZygoptug69G protocol=HTTP/1.1 referer= remote-address="::1" request-id=4dd656be-ded8-43f0-91e2-bfab82bb0ab2 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3Utg0tpbpLCOsmcaxf8J50OSSUJRTDAx\",\"url\":\"https://ca.foo/acme/acme/challenge/QnCPKSyyAohVQtVh4SHPWZygoptug69G/eKbT7ASK8qhrSCXYdePZoUgnFnfSA8yT\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3Utg0tpbpLCOsmcaxf8J50OSSUJRTDAx\",\"url\":\"https://ca.foo/acme/acme/challenge/QnCPKSyyAohVQtVh4SHPWZygoptug69G/5MZU4vwqRxIkv5hScWIw4WnvghJPhPrr\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3Utg0tpbpLCOsmcaxf8J50OSSUJRTDAx\",\"url\":\"https://ca.foo/acme/acme/challenge/QnCPKSyyAohVQtVh4SHPWZygoptug69G/CB7h7rL5wYfk14cdLTiQ2aPOo4NTeaDZ\"}],\"wildcard\":false,\"expires\":\"2026-08-19T15:06:42Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=660ca # [6104576.858970] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=11.549881ms duration-ns=11549881 fields.time="2026-08-18T15:06:42Z" method=POST name=ca nonce=VEV6M0lHYzd6OXVxcVhkMlJ1cnhRM3hqdWpRYmdRd1E path=/acme/acme/challenge/QnCPKSyyAohVQtVh4SHPWZygoptug69G/5MZU4vwqRxIkv5hScWIw4WnvghJPhPrr protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d9493492-c306-4b2f-ae3d-9b67b51cffa4 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3Utg0tpbpLCOsmcaxf8J50OSSUJRTDAx\",\"validated\":\"2026-08-18T15:06:42Z\",\"url\":\"https://ca.foo/acme/acme/challenge/QnCPKSyyAohVQtVh4SHPWZygoptug69G/5MZU4vwqRxIkv5hScWIw4WnvghJPhPrr\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=661ca # [6104576.872695] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info duration=9.909738ms duration-ns=9909738 fields.time="2026-08-18T15:06:42Z" method=POST name=ca nonce=TmNCWlhWRXFBTGk3dHBpV05ybFNpeWMwc2RBRk1RU0Y path=/acme/acme/order/06aQb9Jd1U2tSZPnyAeiLKbFNhDznrbL/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=eef97566-07a6-4a1e-98a2-c673a4075024 response="{\"id\":\"06aQb9Jd1U2tSZPnyAeiLKbFNhDznrbL\",\"status\":\"valid\",\"expires\":\"2026-08-19T15:06:42Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-18T15:05:42Z\",\"notAfter\":\"2026-11-16T15:06:42Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/QnCPKSyyAohVQtVh4SHPWZygoptug69G\"],\"finalize\":\"https://ca.foo/acme/acme/order/06aQb9Jd1U2tSZPnyAeiLKbFNhDznrbL/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/5lVbSKUSDkXAqzwQanh7JwqQSTe2jrlE\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=662ca # [6104576.879687] ca step-ca[203]: time="2026-08-18T15:06:42Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQUgWi2vWtkbMC4PbePEUd+TAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MTgxNTA1NDJaFw0yNjExMTYxNTA2NDJaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEXTTgWIvLWZ6M+douyeXehVxpAw11pUw+mFgEO+kp7XtnBBwKbs5FeyKdVYzwk4ZGvqPKQ5VFmHd0Qt/+fGAg9aOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBR9muqvOQ2yYNyDfxXS8OPxfrdJajAfBgNVHSMEGDAWgBQoXyeC46071qdek0cKnkXAZluVbDATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAJfoKUILlyDlQHZ6i1zD0af8r6lphpqe0dlC+iK2y6d/AiEAv8Fdwxm993akOGgRnwPp1R5JGKDpOhz6k+K+sj8LltY=" duration=2.467114ms duration-ns=2467114 fields.time="2026-08-18T15:06:42Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=eDU0bFFoMnpicVJ2aEpsNUtzV1NVNGZPUUtIUkR3SUU path=/acme/acme/certificate/5lVbSKUSDkXAqzwQanh7JwqQSTe2jrlE protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=74fadfdd-2305-4e03-b2f0-fe982085c9a5 sans="map[dns:[test.foo]]" serial=109025960236784655014826621266498493945 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-18T15:05:42Z" valid-to="2026-11-16T15:06:42Z"663server # [6104577.096802] server systemd[1]: Reloading Nginx Web Server...664server # [6104577.101507] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.665server # [6104577.101746] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.666* Host test.foo:443 was resolved.667* IPv6: 2001:db8:1::3668* IPv4: 192.168.1.3669* Trying [2001:db8:1::3]:443...670* ALPN: curl offers h2,http/1.1671} [5 bytes data]672* TLSv1.3 (OUT), TLS handshake, Client hello (1):673} [1552 bytes data]674* SSL Trust Anchors:675* OpenSSL default paths (fallback)676{ [5 bytes data]677* TLSv1.3 (IN), TLS handshake, Server hello (2):678{ [1210 bytes data]679* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):680{ [1 bytes data]681* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):682{ [19 bytes data]683* TLSv1.3 (IN), TLS handshake, Certificate (11):684{ [1009 bytes data]685* TLSv1.3 (IN), TLS handshake, CERT verify (15):686{ [111 bytes data]687* TLSv1.3 (IN), TLS handshake, Finished (20):688{ [52 bytes data]689* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):690} [1 bytes data]691* TLSv1.3 (OUT), TLS handshake, Finished (20):692} [52 bytes data]693* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey694* ALPN: server accepted h2695* Server certificate:696* subject: CN=test.foo697* start date: Aug 18 15:06:33 2026 GMT698* expire date: Sep 17 15:06:33 2028 GMT699* issuer: CN=minica root ca 084f42700* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384701* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384702* subjectAltName: "test.foo" matches cert's "test.foo"703* OpenSSL verify result: 13704* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)705* closing connection #0706curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)707More details here: https://curl.se/docs/sslcerts.html708709curl failed to verify the legitimacy of the server and therefore could not710establish a secure connection to it. To learn more about this situation and711how to fix it, please visit the webpage mentioned above.712* Host test.foo:443 was resolved.713* IPv6: 2001:db8:1::3714* IPv4: 192.168.1.3715* Trying [2001:db8:1::3]:443...716* ALPN: curl offers h2,http/1.1717} [5 bytes data]718* TLSv1.3 (OUT), TLS handshake, Client hello (1):719} [1552 bytes data]720* SSL Trust Anchors:721* OpenSSL default paths (fallback)722{ [5 bytes data]723* TLSv1.3 (IN), TLS handshake, Server hello (2):724{ [1210 bytes data]725* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):726{ [1 bytes data]727* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):728{ [19 bytes data]729* TLSv1.3 (IN), TLS handshake, Certificate (11):730{ [1009 bytes data]731* TLSv1.3 (IN), TLS handshake, CERT verify (15):732{ [111 bytes data]733* TLSv1.3 (IN), TLS handshake, Finished (20):734{ [52 bytes data]735* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):736} [1 bytes data]737* TLSv1.3 (OUT), TLS handshake, Finished (20):738} [52 bytes data]739* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey740* ALPN: server accepted h2741* Server certificate:742* subject: CN=test.foo743* start date: Aug 18 15:06:33 2026 GMT744* expire date: Sep 17 15:06:33 2028 GMT745* issuer: CN=minica root ca 084f42746* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384747* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384748* subjectAltName: "test.foo" matches cert's "test.foo"749* OpenSSL verify result: 13750* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)751* closing connection #0752curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)753More details here: https://curl.se/docs/sslcerts.html754755curl failed to verify the legitimacy of the server and therefore could not756establish a secure connection to it. To learn more about this situation and757how to fix it, please visit the webpage mentioned above.758server # [6104579.338009] server nginx[390]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok759server # [6104579.338413] server nginx[390]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful760* Host test.foo:443 was resolved.761* IPv6: 2001:db8:1::3762* IPv4: 192.168.1.3763* Trying [2001:db8:1::3]:443...764* ALPN: curl offers h2,http/1.1765} [5 bytes data]766* TLSv1.3 (OUT), TLS handshake, Client hello (1):767} [1552 bytes data]768* SSL Trust Anchors:769* OpenSSL default paths (fallback)770{ [5 bytes data]771* TLSv1.3 (IN), TLS handshake, Server hello (2):772{ [1210 bytes data]773* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):774{ [1 bytes data]775* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):776{ [19 bytes data]777* TLSv1.3 (IN), TLS handshake, Certificate (11):778{ [1009 bytes data]779* TLSv1.3 (IN), TLS handshake, CERT verify (15):780{ [110 bytes data]781* TLSv1.3 (IN), TLS handshake, Finished (20):782{ [52 bytes data]783* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):784} [1 bytes data]785* TLSv1.3 (OUT), TLS handshake, Finished (20):786} [52 bytes data]787* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey788* ALPN: server accepted h2789* Server certificate:790* subject: CN=test.foo791* start date: Aug 18 15:06:33 2026 GMT792* expire date: Sep 17 15:06:33 2028 GMT793* issuer: CN=minica root ca 084f42794* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384795* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384796* subjectAltName: "test.foo" matches cert's "test.foo"797* OpenSSL verify result: 13798* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)799* closing connection #0800curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)801More details here: https://curl.se/docs/sslcerts.html802803curl failed to verify the legitimacy of the server and therefore could not804establish a secure connection to it. To learn more about this situation and805how to fix it, please visit the webpage mentioned above.806server # [6104580.541385] server systemd[1]: Reloaded Nginx Web Server.807* Trying [2001:db8:1::3]:443...808* Host test.foo:443 was resolved.809* IPv6: 2001:db8:1::3810* IPv4: 192.168.1.3811* ALPN: curl offers h2,http/1.1812} [5 bytes data]813* TLSv1.3 (OUT), TLS handshake, Client hello (1):814} [1552 bytes data]815* SSL Trust Anchors:816* OpenSSL default paths (fallback)817{ [5 bytes data]818* TLSv1.3 (IN), TLS handshake, Server hello (2):819{ [1210 bytes data]820* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):821{ [1 bytes data]822* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):823{ [19 bytes data]824* TLSv1.3 (IN), TLS handshake, Certificate (11):825{ [932 bytes data]826* TLSv1.3 (IN), TLS handshake, CERT verify (15):827{ [78 bytes data]828* TLSv1.3 (IN), TLS handshake, Finished (20):829{ [52 bytes data]830* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):831} [1 bytes data]832* TLSv1.3 (OUT), TLS handshake, Finished (20):833} [52 bytes data]834* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey835* ALPN: server accepted h2836* Server certificate:837* subject: CN=test.foo838* start date: Aug 18 15:05:42 2026 GMT839* expire date: Nov 16 15:06:42 2026 GMT840* issuer: CN=Clan Intermediate CA841* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256842* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256843* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256844* subjectAltName: "test.foo" matches cert's "test.foo"845* OpenSSL verify result: 0846* SSL certificate verified via OpenSSL.847* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 41066 848 % Total % Received % Xferd Average Speed Time Time Time Current849 Dload Upload Total Spent Left Speed850 0 0 0 0 0 0 0 0 0* using HTTP/2851* [HTTP/2] [1] OPENED stream for https://test.foo/852* [HTTP/2] [1] [:method: GET]853* [HTTP/2] [1] [:scheme: https]854* [HTTP/2] [1] [:authority: test.foo]855* [HTTP/2] [1] [:path: /]856* [HTTP/2] [1] [user-agent: curl/8.21.0]857* [HTTP/2] [1] [accept: */*]858} [5 bytes data]859860861862863864* Request completely sent off865{ [5 bytes data]866* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):867{ [265 bytes data]868* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):869{ [265 bytes data]870871872873874875876877{ [5 bytes data]878100 20 100 20 0 0 840 0 0879* Connection #0 to host test.foo:443 left intact880client: (finished: waiting for success: curl -v https://test.foo, in 5.29 seconds)881client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2882Certificate:883 Data:884 Version: 3 (0x2)885 Serial Number:886 52:05:a2:da:f5:ad:91:b3:02:e0:f6:de:3c:45:1d:f9887 Signature Algorithm: ecdsa-with-SHA256888 Issuer: CN=Clan Intermediate CA889 Validity890 Not Before: Aug 18 15:05:42 2026 GMT891 Not After : Nov 16 15:06:42 2026 GMT892 Subject: CN=test.foo893 Subject Public Key Info:894 Public Key Algorithm: id-ecPublicKey895 Public-Key: (256 bit)896 pub:897 04:5d:34:e0:58:8b:cb:59:9e:8c:f9:da:2e:c9:e5:898 de:85:5c:69:03:0d:75:a5:4c:3e:98:58:04:3b:e9:899 29:ed:7b:67:04:1c:0a:6e:ce:45:7b:22:9d:55:8c:900 f0:93:86:46:be:a3:ca:43:95:45:98:77:74:42:df:901 fe:7c:60:20:f5902 ASN1 OID: prime256v1903 NIST CURVE: P-256904 X509v3 extensions:905 X509v3 Key Usage: critical906 Digital Signature907 X509v3 Extended Key Usage: 908 TLS Web Server Authentication, TLS Web Client Authentication909 X509v3 Subject Key Identifier: 910 7D:9A:EA:AF:39:0D:B2:60:DC:83:7F:15:D2:F0:E3:F1:7E:B7:49:6A911 X509v3 Authority Key Identifier: 912 28:5F:27:82:E3:AD:3B:D6:A7:5E:93:47:0A:9E:45:C0:66:5B:95:6C913 X509v3 Subject Alternative Name: 914 DNS:test.foo915 1.3.6.1.4.1.37476.9000.64.1: 916 0......acme..917 Signature Algorithm: ecdsa-with-SHA256918 Signature Value:919 30:46:02:21:00:97:e8:29:42:0b:97:20:e5:40:76:7a:8b:5c:920 c3:d1:a7:fc:af:a9:69:86:9a:9e:d1:d9:42:fa:22:b6:cb:a7:921 7f:02:21:00:bf:c1:5d:c3:19:bd:f7:76:a4:38:68:11:9f:03:922 e9:d5:1e:49:18:a0:e9:3a:1c:fa:93:e2:be:b2:3f:0b:96:d6923client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)924(finished: run the VM test script, in 17.65 seconds)925test script finished in 25.60s926cleanup927kill NspawnMachine (pid 53)928kill NspawnMachine (pid 54)929Container ca terminated by signal KILL.930kill NspawnMachine (pid 55)931Container client terminated by signal KILL.932Container server terminated by signal KILL.933(finished: cleanup, in 1.10 seconds)