container-test-run-certificates
checks.aarch64-linux.certificates
· build #441
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14server: systemd-nspawn running (pid 55)15ca: Waiting for journal at /build/vm-state-ca/var/log/journal...16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container ca on /build/vm-state-ca.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container server on /build/vm-state-server.31ca # [6241464.107781] ca systemd-journald[78]: Journal started32ca # [6241464.107831] ca systemd-journald[78]: Runtime Journal (/run/log/journal/ad4cad6dcc814c8e80b6efe185576e22) is 8M, max 2.5G, 2.4G free.33ca # [6241464.110733] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.34client # [6241464.087429] client systemd-journald[69]: Journal started35ca # [6241464.119478] ca systemd[1]: Starting Flush Journal to Persistent Storage...36client # [6241464.087484] client systemd-journald[69]: Runtime Journal (/run/log/journal/2c2c42a61adc456fb7c671ac075b19d8) is 8M, max 2.5G, 2.4G free.37ca # [6241464.120350] ca systemd[1]: Starting Network Name Resolution...38client # [6241464.088704] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.39ca # [6241464.121020] ca systemd[1]: Starting Create Static Device Nodes in /dev...40client # [6241464.098190] client systemd[1]: Starting Flush Journal to Persistent Storage...41ca # [6241464.128403] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/ad4cad6dcc814c8e80b6efe185576e22 is 2.097ms for 6 entries.42client # [6241464.099019] client systemd[1]: Starting Network Name Resolution...43ca # [6241464.128403] ca systemd-journald[78]: System Journal (/var/log/journal/ad4cad6dcc814c8e80b6efe185576e22) is 8M, max 4G, 3.9G free.44client # [6241464.099710] client systemd[1]: Starting Create Static Device Nodes in /dev...45ca # [6241464.134784] ca systemd[1]: Finished Create Static Device Nodes in /dev.46client # [6241464.109023] client systemd-journald[69]: Time spent on flushing to /var/log/journal/2c2c42a61adc456fb7c671ac075b19d8 is 1.820ms for 6 entries.47ca # [6241464.135039] ca systemd[1]: Reached target Preparation for Local File Systems.48client # [6241464.109023] client systemd-journald[69]: System Journal (/var/log/journal/2c2c42a61adc456fb7c671ac075b19d8) is 8M, max 4G, 3.9G free.49ca # [6241464.135121] ca systemd[1]: Reached target Local File Systems.50client # [6241464.111175] client systemd[1]: Finished Create Static Device Nodes in /dev.51ca # [6241464.135846] ca systemd[1]: Listening on Boot Loader Control Service Socket.52client # [6241464.111811] client systemd[1]: Reached target Preparation for Local File Systems.53ca # [6241464.135890] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container54client # [6241464.111920] client systemd[1]: Reached target Local File Systems.55ca # [6241464.136708] ca systemd[1]: Starting Save Transient machine-id to Disk...56client # [6241464.112736] client systemd[1]: Listening on Boot Loader Control Service Socket.57ca # [6241464.136739] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys58client # [6241464.112782] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container59ca # [6241464.142167] ca systemd[1]: Finished Flush Journal to Persistent Storage.60client # [6241464.113669] client systemd[1]: Starting Save Transient machine-id to Disk...61ca # [6241464.143583] ca systemd[1]: Starting Create System Files and Directories...62client # [6241464.113703] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys63ca # [6241464.161806] ca systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted64client # [6241464.137601] client systemd[1]: Finished Flush Journal to Persistent Storage.65client # [6241464.138805] client systemd[1]: Starting Create System Files and Directories...66client # [6241464.155367] client systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted67ca # [6241464.162030] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted68client # [6241464.155536] client systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted69ca # [6241464.162177] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal/ad4cad6dcc814c8e80b6efe185576e22 failed: Operation not permitted70client # [6241464.155653] client systemd-tmpfiles[121]: fchmod() of /var/log/journal/2c2c42a61adc456fb7c671ac075b19d8 failed: Operation not permitted71ca # [6241464.162400] ca systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted72client # [6241464.155833] client systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted73ca # [6241464.164512] ca systemd[1]: Finished Create System Files and Directories.74client # [6241464.157618] client systemd[1]: Finished Create System Files and Directories.75ca # [6241464.165551] ca systemd[1]: Starting Rebuild Journal Catalog...76client # [6241464.158739] client systemd[1]: Starting Rebuild Journal Catalog...77ca # [6241464.166208] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...78client # [6241464.159521] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...79ca # [6241464.177074] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.80client # [6241464.173263] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.81ca # [6241464.186960] ca systemd[1]: Finished Rebuild Journal Catalog.82client # [6241464.198619] client systemd[1]: Finished Rebuild Journal Catalog.83ca # [6241464.187923] ca systemd[1]: Starting Update is Completed...84client # [6241464.199679] client systemd[1]: Starting Update is Completed...85ca # [6241464.197540] ca systemd[1]: Finished Update is Completed.86client # [6241464.204187] client systemd[1]: Finished Save Transient machine-id to Disk.87ca # [6241464.204513] ca systemd[1]: Finished Save Transient machine-id to Disk.88client # [6241464.209575] client systemd[1]: Finished Update is Completed.89client # [6241464.233979] client systemd[1]: Finished Firewall.90client # [6241464.234137] client systemd[1]: Reached target Preparation for Network.91client # [6241464.234355] client systemd[1]: Listening on Network Management Resolve Hook Socket.92client # [6241464.235368] client systemd[1]: Starting Network Management...93server # [6241464.091944] server systemd-journald[69]: Journal started94server # [6241464.091998] server systemd-journald[69]: Runtime Journal (/run/log/journal/df5c9048075a4de09d1fa84b9fd13219) is 8M, max 2.5G, 2.4G free.95server # [6241464.096591] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.96server # [6241464.105031] server systemd[1]: Starting Flush Journal to Persistent Storage...97server # [6241464.105841] server systemd[1]: Starting Network Name Resolution...98server # [6241464.106620] server systemd[1]: Starting Create Static Device Nodes in /dev...99server # [6241464.115346] server systemd-journald[69]: Time spent on flushing to /var/log/journal/df5c9048075a4de09d1fa84b9fd13219 is 1.685ms for 6 entries.100server # [6241464.115346] server systemd-journald[69]: System Journal (/var/log/journal/df5c9048075a4de09d1fa84b9fd13219) is 8M, max 4G, 3.9G free.101server # [6241464.122187] server systemd[1]: Finished Create Static Device Nodes in /dev.102server # [6241464.122416] server systemd[1]: Reached target Preparation for Local File Systems.103server # [6241464.122499] server systemd[1]: Reached target Local File Systems.104server # [6241464.123232] server systemd[1]: Listening on Boot Loader Control Service Socket.105server # [6241464.123277] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container106server # [6241464.124164] server systemd[1]: Starting Save Transient machine-id to Disk...107server # [6241464.124196] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys108server # [6241464.140353] server systemd[1]: Finished Flush Journal to Persistent Storage.109server # [6241464.141789] server systemd[1]: Starting Create System Files and Directories...110server # [6241464.156386] server systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted111server # [6241464.156560] server systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted112server # [6241464.156676] server systemd-tmpfiles[121]: fchmod() of /var/log/journal/df5c9048075a4de09d1fa84b9fd13219 failed: Operation not permitted113server # [6241464.156853] server systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted114server # [6241464.158225] server systemd[1]: Finished Create System Files and Directories.115server # [6241464.159192] server systemd[1]: Starting Rebuild Journal Catalog...116server # [6241464.159832] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...117server # [6241464.171497] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.118server # [6241464.180708] server systemd[1]: Finished Rebuild Journal Catalog.119server # [6241464.181801] server systemd[1]: Starting Update is Completed...120server # [6241464.191329] server systemd[1]: Finished Update is Completed.121server # [6241464.204223] server systemd[1]: Finished Save Transient machine-id to Disk.122server # [6241464.241006] server systemd[1]: Finished Firewall.123server # [6241464.241159] server systemd[1]: Reached target Preparation for Network.124server # [6241464.241385] server systemd[1]: Listening on Network Management Resolve Hook Socket.125server # [6241464.242416] server systemd[1]: Starting Network Management...126ca # [6241464.259253] ca systemd[1]: Finished Firewall.127ca # [6241464.259396] ca systemd[1]: Reached target Preparation for Network.128ca # [6241464.259608] ca systemd[1]: Listening on Network Management Resolve Hook Socket.129ca # [6241464.260605] ca systemd[1]: Starting Network Management...130client # [6241464.650395] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted131client # [6241464.650491] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted132client # [6241464.657189] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.133client # [6241464.657349] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.134client # [6241464.657521] client systemd-networkd[183]: lo: Link UP135client # [6241464.657526] client systemd-networkd[183]: lo: Gained carrier136client # [6241464.657716] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network.137client # [6241464.658205] client systemd-networkd[183]: eth1: Link UP138client # [6241464.658509] client systemd[1]: Started Network Management.139client # [6241464.659520] client systemd-networkd[183]: eth1: Gained carrier140client # [6241464.659642] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...141client # [6241464.723268] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.142client # [6241464.834063] client systemd-resolved[92]: Positive Trust Anchors:143client # [6241464.834076] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d144client # [6241464.834080] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16145client # [6241464.834113] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test146client # [6241464.857138] client systemd-resolved[92]: Using system hostname 'client'.147client # [6241464.858529] client systemd[1]: Started Network Name Resolution.148client # [6241464.858747] client systemd[1]: Reached target Network.149client # [6241464.858894] client systemd[1]: Reached target System Initialization.150client # [6241464.859024] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container151client # [6241464.859125] client systemd[1]: Started Daily Cleanup of Temporary Directories.152client # [6241464.859206] client systemd[1]: Reached target Timer Units.153client # [6241464.859577] client systemd[1]: Listening on D-Bus System Message Bus Socket.154client # [6241464.859867] client systemd[1]: Listening on Nix Daemon Socket.155client # [6241464.860182] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.156client # [6241464.860256] client systemd[1]: Reached target Socket Units.157client # [6241464.860367] client systemd[1]: Reached target Basic System.158client # [6241464.908464] client systemd[1]: Starting Import lastlog data into lastlog2 database...159server # [6241464.659871] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted160server # [6241464.659966] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted161server # [6241464.668304] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.162server # [6241464.668470] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.163server # [6241464.668633] server systemd-networkd[187]: lo: Link UP164server # [6241464.668637] server systemd-networkd[187]: lo: Gained carrier165server # [6241464.668849] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network.166server # [6241464.669248] server systemd[1]: Started Network Management.167server # [6241464.712314] server systemd-networkd[187]: eth1: Link UP168server # [6241464.712641] server systemd-networkd[187]: eth1: Gained carrier169server # [6241464.712721] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...170server # [6241464.763164] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.171server # [6241464.829952] server systemd-resolved[94]: Positive Trust Anchors:172server # [6241464.829964] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d173server # [6241464.829968] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16174server # [6241464.830003] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test175server # [6241464.852926] server systemd-resolved[94]: Using system hostname 'server'.176server # [6241464.854340] server systemd[1]: Started Network Name Resolution.177server # [6241464.854475] server systemd[1]: Reached target Network.178server # [6241464.854544] server systemd[1]: Reached target Network is Online.179server # [6241464.854610] server systemd[1]: Reached target System Initialization.180server # [6241464.854861] server systemd[1]: Started Renew ACME Certificate for test.foo.181server # [6241464.854932] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container182server # [6241464.854965] server systemd[1]: Started Daily Cleanup of Temporary Directories.183server # [6241464.854991] server systemd[1]: Reached target Timer Units.184server # [6241464.855125] server systemd[1]: Listening on D-Bus System Message Bus Socket.185server # [6241464.855264] server systemd[1]: Listening on Nix Daemon Socket.186server # [6241464.855405] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.187server # [6241464.855430] server systemd[1]: Reached target Socket Units.188server # [6241464.855469] server systemd[1]: Reached target Basic System.189server # [6241464.857146] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...190server # [6241464.857912] server systemd[1]: Starting Import lastlog data into lastlog2 database...191server # [6241464.857955] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem192server # [6241464.858760] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...193server # [6241464.860531] server systemd[1]: Starting D-Bus System Message Bus...194ca # [6241464.683052] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted195ca # [6241464.683145] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted196ca # [6241464.689944] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.197ca # [6241464.690105] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.198ca # [6241464.690264] ca systemd-networkd[196]: lo: Link UP199ca # [6241464.690268] ca systemd-networkd[196]: lo: Gained carrier200ca # [6241464.690453] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network.201ca # [6241464.690872] ca systemd[1]: Started Network Management.202ca # [6241464.712713] ca systemd-networkd[196]: eth1: Link UP203ca # [6241464.712727] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...204ca # [6241464.713121] ca systemd-networkd[196]: eth1: Gained carrier205ca # [6241464.763200] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.206ca # [6241464.840788] ca systemd-resolved[102]: Positive Trust Anchors:207ca # [6241464.840802] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d208ca # [6241464.840805] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16209ca # [6241464.840841] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test210ca # [6241464.863529] ca systemd-resolved[102]: Using system hostname 'ca'.211ca # [6241464.864955] ca systemd[1]: Started Network Name Resolution.212ca # [6241464.865148] ca systemd[1]: Reached target Network.213ca # [6241464.865271] ca systemd[1]: Reached target Network is Online.214ca # [6241464.865389] ca systemd[1]: Reached target System Initialization.215ca # [6241464.865828] ca systemd[1]: Started Renew ACME Certificate for ca.foo.216ca # [6241464.865921] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container217ca # [6241464.865985] ca systemd[1]: Started Daily Cleanup of Temporary Directories.218ca # [6241464.866042] ca systemd[1]: Reached target Timer Units.219ca # [6241464.866300] ca systemd[1]: Listening on D-Bus System Message Bus Socket.220ca # [6241464.866533] ca systemd[1]: Listening on Nix Daemon Socket.221ca # [6241464.866819] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.222ca # [6241464.866887] ca systemd[1]: Reached target Socket Units.223ca # [6241464.866972] ca systemd[1]: Reached target Basic System.224ca # [6241464.909097] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...225ca # [6241464.911912] ca systemd[1]: Starting Import lastlog data into lastlog2 database...226ca # [6241464.911994] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem227ca # [6241464.916174] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...228ca # [6241464.918796] ca systemd[1]: Starting step-ca service...229ca # [6241464.925549] ca systemd[1]: Starting D-Bus System Message Bus...230ca # [6241464.937812] ca systemd[1]: Finished Import lastlog data into lastlog2 database.231ca # [6241465.046725] ca acme-setup-privileged[201]: + set -euo pipefail232ca # [6241465.046725] ca acme-setup-privileged[201]: + cd /var/lib/acme233ca # [6241465.046725] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts234ca # [6241465.048537] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts235ca # [6241465.050216] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo236ca # [6241465.050216] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'237ca # [6241465.050370] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo238ca # [6241465.050370] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'239ca # [6241465.069887] ca nsncd[203]: Aug 20 05:08:11.123 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"240ca # [6241465.069951] ca systemd[1]: Started Name Service Cache Daemon (nsncd).241ca # [6241465.070025] ca systemd[1]: Reached target Host and Network Name Lookups.242ca # [6241465.070089] ca systemd[1]: Reached target User and Group Name Lookups.243ca # [6241465.097064] ca systemd[1]: Starting User Login Management...244ca # [6241465.098090] ca systemd[1]: Starting Permit User Sessions...245ca # [6241465.106568] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.246ca # [6241465.107825] ca systemd[1]: Finished Permit User Sessions.247ca # [6241465.109382] ca systemd[1]: Started Console Getty.248ca # [6241465.109427] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0249ca # [6241465.109448] ca systemd[1]: Reached target Login Prompts.250client # [6241464.910068] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...251client # [6241464.912476] client systemd[1]: Starting D-Bus System Message Bus...252client # [6241464.930296] client systemd[1]: Finished Import lastlog data into lastlog2 database.253client # [6241465.073470] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.254client # [6241465.092051] client nsncd[189]: Aug 20 05:08:11.145 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"255client # [6241465.097033] client systemd[1]: Started Name Service Cache Daemon (nsncd).256client # [6241465.097080] client systemd[1]: Reached target Host and Network Name Lookups.257client # [6241465.097151] client systemd[1]: Reached target User and Group Name Lookups.258client # [6241465.098583] client systemd[1]: Starting User Login Management...259client # [6241465.099670] client systemd[1]: Starting Permit User Sessions...260client # [6241465.111453] client systemd[1]: Finished Permit User Sessions.261client # [6241465.113452] client systemd[1]: Started Console Getty.262client # [6241465.113547] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0263client # [6241465.113617] client systemd[1]: Reached target Login Prompts.264server # [6241464.924764] server systemd[1]: Finished Import lastlog data into lastlog2 database.265server # [6241465.054563] server acme-setup-privileged[192]: + set -euo pipefail266server # [6241465.054563] server acme-setup-privileged[192]: + cd /var/lib/acme267server # [6241465.055224] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts268server # [6241465.056056] server acme-setup-privileged[192]: + chown -R acme .lego/accounts269server # [6241465.057790] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo270server # [6241465.057859] server acme-setup-privileged[192]: + '[' -d test.foo ']'271server # [6241465.057859] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo272server # [6241465.057859] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'273server # [6241465.063473] server nsncd[194]: Aug 20 05:08:11.116 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"274server # [6241465.063580] server systemd[1]: Started Name Service Cache Daemon (nsncd).275server # [6241465.063653] server systemd[1]: Reached target Host and Network Name Lookups.276server # [6241465.063720] server systemd[1]: Reached target User and Group Name Lookups.277server # [6241465.097120] server systemd[1]: Starting User Login Management...278server # [6241465.097955] server systemd[1]: Starting Permit User Sessions...279server # [6241465.106598] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.280server # [6241465.107857] server systemd[1]: Finished Permit User Sessions.281server # [6241465.109686] server systemd[1]: Started Console Getty.282server # [6241465.109735] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0283server # [6241465.109756] server systemd[1]: Reached target Login Prompts.284server # [6241465.218487] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...285server # [6241465.219069] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'286server # [6241465.219069] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3mkgnlb89jy49c4a1z0swjahhcvmnw8p-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"287server # [6241465.219529] server systemd[1]: Started D-Bus System Message Bus.288server # [6241465.226981] server dbus-broker-launch[195]: Ready289client # [6241465.202773] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...290client # [6241465.203753] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'291client # [6241465.203753] client dbus-broker-launch[190]: Invalid user-name in /nix/store/71vmh4xl6s5dgp2wq5sm5rdd4lr016c0-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"292client # [6241465.204236] client systemd[1]: Started D-Bus System Message Bus.293client # [6241465.211428] client dbus-broker-launch[190]: Ready294ca # [6241465.193901] ca dbus-broker-launch[211]: Looking up NSS user entry for 'systemd-timesync'...295ca # [6241465.194645] ca dbus-broker-launch[211]: NSS returned no entry for 'systemd-timesync'296ca # [6241465.194645] ca dbus-broker-launch[211]: Invalid user-name in /nix/store/bz7ygr15ilclf6krkxd1w5j7l4dw4kny-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"297ca # [6241465.195276] ca systemd[1]: Started D-Bus System Message Bus.298ca # [6241465.202868] ca dbus-broker-launch[211]: Ready299client # [6241465.625911] client systemd-logind[205]: New seat seat0.300client # [6241465.626114] client systemd[1]: Started User Login Management.301client # [6241465.627382] client systemd[1]: Starting linger-users.service...302client # [6241465.685609] client systemd[1]: linger-users.service: Deactivated successfully.303client # [6241465.685742] client systemd[1]: Finished linger-users.service.304client # [6241465.686163] client systemd[1]: Reached target Multi-User System.305client # [6241465.686382] client systemd[1]: Startup finished in 1.971s.306ca # [6241465.647398] ca systemd-logind[231]: New seat seat0.307ca # [6241465.647582] ca systemd[1]: Started User Login Management.308ca # [6241465.676410] ca systemd[1]: Starting linger-users.service...309ca # [6241465.690451] ca systemd[1]: linger-users.service: Deactivated successfully.310ca # [6241465.690569] ca systemd[1]: Finished linger-users.service.311ca # [6241465.705481] ca acme-setup-start[219]: + set -euo pipefail312ca # [6241465.705740] ca acme-setup-start[219]: + test -e ca/key.pem313ca # [6241465.705740] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local314ca # [6241465.727523] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.315ca # [6241465.729445] ca systemd[1]: Starting Ensure certificate for ca.foo...316ca # [6241465.797283] ca step-ca[207]: badger 2026/08/20 05:08:11 INFO: All 0 tables opened in 0s317ca # [6241465.801273] ca step-ca[207]: 2026/08/20 05:08:11 Building new tls configuration using step-ca x509 Signer Interface318ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Starting Smallstep CA/0.30.2 (linux/arm64)319ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Documentation: https://u.step.sm/docs/ca320ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Community Discord: https://u.step.sm/discord321ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Config file: /etc/smallstep/ca.json322ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 The primary server URL is https://ca.foo:1443323ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Root certificates are available at https://ca.foo:1443/roots.pem324ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 X.509 Root Fingerprint: e826ba1017ed9c6d1e80bbc83d56e54b4763fd0cf6f59c398a4f0b383416ea71325ca # [6241465.807283] ca systemd[1]: Started step-ca service.326ca # [6241465.807463] ca step-ca[207]: 2026/08/20 05:08:11 Serving HTTPS on 0.0.0.0:1443 ...327server # [6241465.623233] server systemd-logind[219]: New seat seat0.328server # [6241465.623450] server systemd[1]: Started User Login Management.329server # [6241465.624594] server systemd[1]: Starting linger-users.service...330server # [6241465.666972] server acme-setup-start[208]: + set -euo pipefail331server # [6241465.666972] server acme-setup-start[208]: + test -e ca/key.pem332server # [6241465.667265] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local333server # [6241465.684733] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.334server # [6241465.687522] server systemd[1]: Starting Ensure certificate for test.foo...335server # [6241465.688160] server systemd[1]: linger-users.service: Deactivated successfully.336server # [6241465.688364] server systemd[1]: Finished linger-users.service.337client # [6241465.888470] client systemd-networkd[183]: eth1: Gained IPv6LL338ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 339ca # [6241466.052189] ca systemd-networkd[196]: eth1: Gained IPv6LL340ca # [6241466.254053] ca acme-ca.foo-start[284]: Waiting to acquire lock in /run/acme/341ca # [6241466.257300] ca acme-ca.foo-start[284]: + '[' -e out/acme-success ']'342ca # [6241466.257300] ca acme-ca.foo-start[284]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=343ca # [6241466.272712] ca acme-ca.foo-start[294]: + cd ca.foo344ca # [6241466.273781] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem345ca # [6241466.275065] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem'346ca # [6241466.275511] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem347ca # [6241466.276805] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem'348ca # [6241466.277072] ca acme-ca.foo-start[284]: + cat out/cert.pem ca/cert.pem349ca # [6241466.279474] ca acme-ca.foo-start[284]: + cp ca/cert.pem out/chain.pem350ca # [6241466.281249] ca acme-ca.foo-start[284]: + cat out/key.pem out/fullchain.pem351ca # [6241466.282723] ca acme-ca.foo-start[284]: + for fixpath in out certificates352ca # [6241466.282761] ca acme-ca.foo-start[284]: + '[' -d out ']'353ca # [6241466.282761] ca acme-ca.foo-start[284]: + chmod -R u=rwX,g=rX,o= out354ca # [6241466.284304] ca acme-ca.foo-start[284]: + chown -R acme:nginx out355ca # [6241466.287188] ca acme-ca.foo-start[284]: + for fixpath in out certificates356ca # [6241466.287232] ca acme-ca.foo-start[284]: + '[' -d certificates ']'357ca # [6241466.291228] ca systemd[1]: Finished Ensure certificate for ca.foo.358ca # [6241466.292941] ca systemd[1]: Starting Nginx Web Server...359server # [6241466.212785] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/360server # [6241466.215729] server acme-test.foo-start[244]: + '[' -e out/acme-success ']'361server # [6241466.215729] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=362server # [6241466.230867] server acme-test.foo-start[255]: + cd test.foo363server # [6241466.231513] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem364server # [6241466.232477] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'365server # [6241466.233035] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem366server # [6241466.235054] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'367server # [6241466.235286] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem368server # [6241466.237656] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem369server # [6241466.239465] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem370server # [6241466.242066] server acme-test.foo-start[244]: + for fixpath in out certificates371server # [6241466.242066] server acme-test.foo-start[244]: + '[' -d out ']'372server # [6241466.242066] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out373server # [6241466.243705] server acme-test.foo-start[244]: + chown -R acme:nginx out374server # [6241466.247185] server acme-test.foo-start[244]: + for fixpath in out certificates375server # [6241466.247216] server acme-test.foo-start[244]: + '[' -d certificates ']'376server # [6241466.251052] server systemd[1]: Finished Ensure certificate for test.foo.377server # [6241466.253122] server systemd[1]: Starting Nginx Web Server...378server # [6241466.432270] server systemd-networkd[187]: eth1: Gained IPv6LL379ca # [6241466.932832] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok380ca # [6241466.932832] ca nginx-pre-start[306]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful381ca # [6241466.938698] ca systemd[1]: Started Nginx Web Server.382ca # [6241466.939307] ca systemd[1]: Reached target Multi-User System.383server # [6241466.890775] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok384ca # [6241466.941005] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...385server # [6241466.891199] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful386server # [6241466.897165] server systemd[1]: Started Nginx Web Server.387server # [6241466.897575] server systemd[1]: Reached target Multi-User System.388server # [6241466.899168] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...389server # [6241467.488884] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/390server # [6241467.492352] server acme-order-renew-test.foo-start[270]: + set -euo pipefail391server # [6241467.492448] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108392server # [6241467.492546] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt393server # [6241467.493724] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run394server # [6241467.513265] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:13 No key found for account none@none.tld. Generating a P256 key.395server # [6241467.513677] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:13 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key396ca # [6241467.517203] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/397ca # [6241467.520032] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail398ca # [6241467.520113] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9399ca # [6241467.520221] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt400ca # [6241467.521275] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run401ca # [6241467.536913] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 No key found for account none@none.tld. Generating a P256 key.402ca # [6241467.537408] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key403ca # [6241467.566662] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration="105.121µs" duration-ns=105121 fields.time="2026-08-20T05:08:13Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6f574c1d-55b2-44f1-985d-07ac060e7696 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=404ca # [6241467.567132] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] acme: Registering account for none@none.tld405ca # [6241467.571293] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=3.998976ms duration-ns=3998976 fields.time="2026-08-20T05:08:13Z" method=HEAD name=ca nonce=NlJTcVNQT2E3VGwxMjNZM2REUHNHdHBremdWVW1mSWs path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a0240468-ec13-41b6-82ac-fd701614a952 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=406ca # [6241467.575502] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=3.063523ms duration-ns=3063523 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=Q2hwTkZlWDRVRVJPNGFPdkFZOTBCUFR5SWg4N1ZNYmM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=cea3a5ea-b96c-413b-8a2d-06c09ccbb38f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/zIzEC4PPgL3rCVFRfz8MmNoiIzGTGx90/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=407ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!!408ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your409ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts".410ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This411ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys412ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME413ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal.414ca # [6241467.576049] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate415ca # [6241467.580637] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=4.26722ms duration-ns=4267220 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=WExPem5VcUdsekhnTUdISGplTndnYVVOUklVcGxEamg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=01adc5fa-c53e-4277-952b-a9310d312ced response="{\"id\":\"XFO5hUsrryH9yjASd3FLF6glHn5l9Km8\",\"status\":\"pending\",\"expires\":\"2026-08-21T05:08:13Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-20T05:07:13Z\",\"notAfter\":\"2026-11-18T05:08:13Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=416ca # [6241467.640093] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=2.375274ms duration-ns=2375274 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=a1ljd0ZDblMxNUNHTlVtN2lkcjJOSE1VMENNRHkxZHI path=/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9e2d9e2c-20b5-4c9e-a0c7-4c1d1bf00ee1 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/zuurmQ4me09hYzVLahgVGOAXTZgcf1iP\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/ratJZND2IkaqSPcYcwCUCUx3HHZQJH5D\"}],\"wildcard\":false,\"expires\":\"2026-08-21T05:08:13Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=417ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I418ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01419ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: use http-01 solver420ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Trying to solve HTTP-01421ca # [6241467.646170] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=5.064631ms duration-ns=5064631 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=YVg2cE1ackczZ1k4QXdZaUp3NzV5eUxiaVV3RjJYTUo path=/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9d508e48-51a8-4a65-b978-7f3d26a01362 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"validated\":\"2026-08-20T05:08:13Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=422ca # [6241467.646445] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] The server validated our request423ca # [6241467.646528] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates424ca # [6241467.655766] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=8.337797ms duration-ns=8337797 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=MmFnbE1zZlRkaFJnSEN0a1RwcEVlTnhVZEJyd2dMU2Y path=/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=774827d2-a00f-46f0-ab86-6b6ea5ba64b0 response="{\"id\":\"XFO5hUsrryH9yjASd3FLF6glHn5l9Km8\",\"status\":\"valid\",\"expires\":\"2026-08-21T05:08:13Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-20T05:07:13Z\",\"notAfter\":\"2026-11-18T05:08:13Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/sNZvUuga4Ljez2avFZhwvomwVY88F44f\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=425ca # [6241467.658544] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAJLFXDxvxDBi/4pC6z7ZZrswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODIwMDUwNzEzWhcNMjYxMTE4MDUwODEzWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS6Rsl6WiLW9zlNJW/TDFu3rl9GSQHTGQW6LoUQA5EMcPbEf+Z9m7AoDNrVc+Pr5A9NB/NiPILW3ZZtKsgj0H99o4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFKQOoQHjUT6y2SNBRQPcEaFho/UTMB8GA1UdIwQYMBaAFChfJ4LjrTvWp16TRwqeRcBmW5VsMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAKiYC0gebkqA/H/pu65bVkwo7g3M3Nh+Kx7KkiGmWn22AiBH6f6FDK2nQdIPedpHtzgnbisnfnbmmiOh8Tqf5fJiEQ==" duration=1.837785ms duration-ns=1837785 fields.time="2026-08-20T05:08:13Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UHA2MTNlZ3FpRkJlWUxaeEtaSG9YTEoxdmVKNk5pOXk path=/acme/acme/certificate/sNZvUuga4Ljez2avFZhwvomwVY88F44f protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=383de0a1-fefb-45e7-a32b-9451bfe462a7 sans="map[dns:[ca.foo]]" serial=195092040635692379346915067855338301115 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-20T05:07:13Z" valid-to="2026-11-18T05:08:13Z"426ca # [6241467.658828] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] Server responded with a certificate.427ca # [6241467.664295] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/428ca # [6241467.666264] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success429ca # [6241467.667907] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem430ca # [6241467.669065] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed431ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate432ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: Installing new certificate433ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem434ca # [6241467.672296] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'435ca # [6241467.672668] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem436ca # [6241467.674056] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.key' -> 'out/key.pem'437ca # [6241467.674372] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem438ca # [6241467.675729] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'439ca # [6241467.676081] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem440ca # [6241467.677718] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem441ca # [6241467.679693] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates442ca # [6241467.679693] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']'443ca # [6241467.679805] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out444ca # [6241467.681348] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out445ca # [6241467.684190] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates446ca # [6241467.684190] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']'447ca # [6241467.684325] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates448ca # [6241467.685882] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates449ca # [6241467.688499] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/.450ca # [6241467.943596] ca systemd[1]: Reloading Nginx Web Server...451ca # [6241467.947753] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.452ca # [6241467.947928] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.453server # [6241468.564411] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:14 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority454server # [6241468.569172] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.455server # [6241468.569172] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.456server # [6241468.569172] server acme-order-renew-test.foo-start[270]: + exit 10457server # [6241468.573162] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a458server # [6241468.573243] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.459server # [6241468.573492] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.460server # [6241468.588197] server systemd[1]: Startup finished in 4.873s.461ca # [6241468.742250] ca nginx[370]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok462ca # [6241468.742882] ca nginx[370]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful463ca # [6241469.320377] ca systemd[1]: Reloaded Nginx Web Server.464ca # [6241469.321019] ca systemd[1]: Startup finished in 5.593s.465ca # [6241469.410095] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...466ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.90 seconds)467ca # [6241469.945723] ca acme-order-renew-ca.foo-start[385]: Waiting to acquire lock in /run/acme/468ca # [6241469.948989] ca acme-order-renew-ca.foo-start[385]: + set -euo pipefail469ca # [6241469.949080] ca acme-order-renew-ca.foo-start[385]: + echo 88dc4fc401a6091a1bd9470ca # [6241469.949171] ca acme-order-renew-ca.foo-start[385]: + cmp -s domainhash.txt certificates/domainhash.txt471ca # [6241469.950343] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.key ']'472ca # [6241469.950396] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.crt ']'473ca # [6241469.950786] ca acme-order-renew-ca.foo-start[393]: ++ find accounts -name none@none.tld.key474ca # [6241469.954137] ca acme-order-renew-ca.foo-start[385]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'475ca # [6241469.954137] ca acme-order-renew-ca.foo-start[385]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic476ca # [6241469.995623] ca step-ca[207]: time="2026-08-20T05:08:16Z" level=info duration="59.72µs" duration-ns=59720 fields.time="2026-08-20T05:08:16Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c3ff4073-eb82-4bff-b627-f3bffaebe5c1 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=477ca # [6241469.996113] ca acme-order-renew-ca.foo-start[394]: 2026/08/20 05:08:16 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint478ca # [6241469.996113] ca acme-order-renew-ca.foo-start[394]: 2026/08/20 05:08:16 [INFO] [ca.foo] The certificate expires at 2026-11-18T05:08:13Z, the renewal can be performed in 1439h59m36.950873801s: no renewal.479ca # [6241469.996500] ca acme-order-renew-ca.foo-start[385]: + mv domainhash.txt certificates/480ca # [6241469.998241] ca acme-order-renew-ca.foo-start[385]: + touch out/acme-success481ca # [6241470.000038] ca acme-order-renew-ca.foo-start[385]: + cmp -s certificates/ca.foo.crt out/fullchain.pem482ca # [6241470.001057] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates483ca # [6241470.001088] ca acme-order-renew-ca.foo-start[385]: + '[' -d out ']'484ca # [6241470.001088] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= out485ca # [6241470.002488] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx out486ca # [6241470.004843] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates487ca # [6241470.004880] ca acme-order-renew-ca.foo-start[385]: + '[' -d certificates ']'488ca # [6241470.004880] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= certificates489ca # [6241470.006211] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx certificates490ca # [6241470.008754] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=,o= accounts/.491ca # [6241470.141908] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.492ca # [6241470.142106] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.493server: must succeed: systemctl restart acme-test.foo.service494server # [6241473.171048] server systemd[1]: acme-test.foo.service: Deactivated successfully.495server # [6241473.171359] server systemd[1]: Stopped Ensure certificate for test.foo.496server # [6241473.172726] server systemd[1]: Stopping Ensure certificate for test.foo...497server # [6241473.197874] server systemd[1]: Starting Ensure certificate for test.foo...498server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.59 seconds)499client: waiting for success: curl -v https://test.foo500* Host test.foo:443 was resolved.501* IPv6: 2001:db8:1::3502* IPv4: 192.168.1.3503* Trying [2001:db8:1::3]:443...504* ALPN: curl offers h2,http/1.1505} [5 bytes data]506* TLSv1.3 (OUT), TLS handshake, Client hello (1):507} [1552 bytes data]508* SSL Trust Anchors:509* OpenSSL default paths (fallback)510{ [5 bytes data]511* TLSv1.3 (IN), TLS handshake, Server hello (2):512{ [1210 bytes data]513* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):514{ [1 bytes data]515* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):516{ [19 bytes data]517* TLSv1.3 (IN), TLS handshake, Certificate (11):518{ [1010 bytes data]519* TLSv1.3 (IN), TLS handshake, CERT verify (15):520{ [112 bytes data]521* TLSv1.3 (IN), TLS handshake, Finished (20):522{ [52 bytes data]523* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):524} [1 bytes data]525* TLSv1.3 (OUT), TLS handshake, Finished (20):526} [52 bytes data]527* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey528* ALPN: server accepted h2529* Server certificate:530* subject: CN=test.foo531* start date: Aug 20 05:08:12 2026 GMT532* expire date: Sep 19 05:08:12 2028 GMT533* issuer: CN=minica root ca 2da5d6534* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384535* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384536* subjectAltName: "test.foo" matches cert's "test.foo"537* OpenSSL verify result: 13538* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)539* closing connection #0540curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)541More details here: https://curl.se/docs/sslcerts.html542543curl failed to verify the legitimacy of the server and therefore could not544establish a secure connection to it. To learn more about this situation and545how to fix it, please visit the webpage mentioned above.546server # [6241473.701933] server acme-test.foo-start[317]: Waiting to acquire lock in /run/acme/547server # [6241473.704838] server acme-test.foo-start[317]: + '[' -e out/acme-success ']'548server # [6241473.704838] server acme-test.foo-start[317]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=549server # [6241473.723834] server acme-test.foo-start[326]: + cd test.foo550server # [6241473.724183] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem551server # [6241473.725590] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem'552server # [6241473.725807] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem553server # [6241473.727276] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem'554server # [6241473.727536] server acme-test.foo-start[317]: + cat out/cert.pem ca/cert.pem555server # [6241473.729500] server acme-test.foo-start[317]: + cp ca/cert.pem out/chain.pem556server # [6241473.730898] server acme-test.foo-start[317]: + cat out/key.pem out/fullchain.pem557server # [6241473.733027] server acme-test.foo-start[317]: + for fixpath in out certificates558server # [6241473.733027] server acme-test.foo-start[317]: + '[' -d out ']'559server # [6241473.733133] server acme-test.foo-start[317]: + chmod -R u=rwX,g=rX,o= out560server # [6241473.734424] server acme-test.foo-start[317]: + chown -R acme:nginx out561server # [6241473.738049] server acme-test.foo-start[317]: + for fixpath in out certificates562server # [6241473.738049] server acme-test.foo-start[317]: + '[' -d certificates ']'563server # [6241473.741490] server systemd[1]: Finished Ensure certificate for test.foo.564server # [6241473.744757] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...565server # [6241474.349417] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/566server # [6241474.352580] server acme-order-renew-test.foo-start[334]: + set -euo pipefail567server # [6241474.352663] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108568server # [6241474.352780] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt569server # [6241474.354040] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run570server # [6241474.415420] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] acme: Registering account for none@none.tld571server # [6241474.426599] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!!572server # [6241474.426599] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your573server # [6241474.426599] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts".574server # [6241474.426599] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This575server # [6241474.426599] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys576server # [6241474.426599] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME577server # [6241474.426599] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal.578server # [6241474.426811] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Obtaining bundled SAN certificate579server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl580server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01581server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: use http-01 solver582server # [6241474.497573] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Trying to solve HTTP-01583server # [6241474.507485] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] The server validated our request584server # [6241474.507584] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Validations succeeded; requesting certificates585server # [6241474.528737] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] Server responded with a certificate.586server # [6241474.533826] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/587server # [6241474.535987] server acme-order-renew-test.foo-start[334]: + touch out/acme-success588server # [6241474.537716] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem589server # [6241474.538853] server acme-order-renew-test.foo-start[334]: + touch out/renewed590server # [6241474.540645] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate591server # [6241474.540645] server acme-order-renew-test.foo-start[334]: Installing new certificate592server # [6241474.540645] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem593server # [6241474.542378] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'594server # [6241474.542665] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem595server # [6241474.544841] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem'596server # [6241474.545091] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem597server # [6241474.546752] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'598server # [6241474.547047] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem599server # [6241474.548733] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem600server # [6241474.550634] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates601server # [6241474.550634] server acme-order-renew-test.foo-start[334]: + '[' -d out ']'602server # [6241474.550731] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out603server # [6241474.552415] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out604server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates605server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']'606server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates607server # [6241474.557754] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates608server # [6241474.561351] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/.609ca # [6241474.414711] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration="60.641µs" duration-ns=60641 fields.time="2026-08-20T05:08:20Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=50a3de0a-7dd1-4970-9f83-41e9bf5610c8 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=610ca # [6241474.419804] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration="739.051µs" duration-ns=739051 fields.time="2026-08-20T05:08:20Z" method=HEAD name=ca nonce=SjMxZEF5QldMRmpGUGQwYTAzb1VyMG9URFF6NzBVbkI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=283baf4e-492e-4b54-9e5f-9db1b43819b6 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=611ca # [6241474.425993] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=2.79772ms duration-ns=2797720 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=bFl4S2l3VW9TOUtaeWtVT1dzYTRYTlZQZkhTcmdWOGs path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=563965d3-809e-4597-908f-08613f70342e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/ufjbnX9FVM7YLuF7ATHm6jtZ8KCwBINo/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=612ca # [6241474.433741] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=3.793494ms duration-ns=3793494 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=TTlzWm5pNkgydkphWm1DYnFYWmVOaHRUT2lRWVhuYTM path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=86e62806-c15d-44fb-ba99-d4e5bf2410dc response="{\"id\":\"pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f\",\"status\":\"pending\",\"expires\":\"2026-08-21T05:08:20Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-20T05:07:20Z\",\"notAfter\":\"2026-11-18T05:08:20Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl\"],\"finalize\":\"https://ca.foo/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=613ca # [6241474.496570] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=2.08247ms duration-ns=2082470 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=YWJGUTJhTFBCSVkzTElkUGRNTTZZS1FLNVU2aWM4Q2M path=/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl protocol=HTTP/1.1 referer= remote-address="::1" request-id=edbafcc2-b62f-40e3-8fd1-5bc22f1ca527 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/ldfAcYFVqMS4eeNxGEJGVVj8jbq2dteY\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/xOsJfi1tanYjCO42J5LJef7TwsMNn9W5\"}],\"wildcard\":false,\"expires\":\"2026-08-21T05:08:20Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [6241474.506832] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=5.01539ms duration-ns=5015390 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=T1haTnQ1U0c3bzVJTVFPM1FUNm1hR0VPdzRzSldxamM path=/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d72b411e-49b9-41fd-a5de-78c2d2b0dd56 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"validated\":\"2026-08-20T05:08:20Z\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=615ca # [6241474.521253] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=8.434119ms duration-ns=8434119 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=U0NLeHpoeTR6ZmhjakFTNHgwc2RVeWJFaXdCQkFmNmo path=/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=5494bb6c-9084-4a72-8c14-06412d761dd8 response="{\"id\":\"pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f\",\"status\":\"valid\",\"expires\":\"2026-08-21T05:08:20Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-20T05:07:20Z\",\"notAfter\":\"2026-11-18T05:08:20Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl\"],\"finalize\":\"https://ca.foo/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/9gRORyk0H6NiydUPR4B0pXxYYhWqh1Iq\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=616ca # [6241474.527872] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQOJiPvH7SoiDEwLvemtzZojAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjAwNTA3MjBaFw0yNjExMTgwNTA4MjBaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyjfvZNfoaP0BrJOTLHmjsaV5emYMefx5GbkXQIM4xxwsa9e22fuy/tvgflUGjqjskPXwNCmDdPHl+YsRm1J6I6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTRXQHQ5mmnHpMSgN2BprDIx5BZwTAfBgNVHSMEGDAWgBQoXyeC46071qdek0cKnkXAZluVbDATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgAY7Hij8z7d992hJMwX9Ll79pq3wWx/OLxXwMIheKDjgCIQChR2Jp9+JcqCwyZgCLOHay3hpyu9rnBDmG65qUF+or6A==" duration=1.942907ms duration-ns=1942907 fields.time="2026-08-20T05:08:20Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=THBIQzM2a2tEODVmdEFLT1oySVJTTnFHWTREVUpyMmk path=/acme/acme/certificate/9gRORyk0H6NiydUPR4B0pXxYYhWqh1Iq protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c0a202d9-cc9f-461c-89c1-4e96832ff83b sans="map[dns:[test.foo]]" serial=75228912205170208840168047079895914914 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-20T05:07:20Z" valid-to="2026-11-18T05:08:20Z"617* Host test.foo:443 was resolved.618* IPv6: 2001:db8:1::3619* IPv4: 192.168.1.3620* Trying [2001:db8:1::3]:443...621* ALPN: curl offers h2,http/1.1622} [5 bytes data]623* TLSv1.3 (OUT), TLS handshake, Client hello (1):624} [1552 bytes data]625* SSL Trust Anchors:626* OpenSSL default paths (fallback)627{ [5 bytes data]628* TLSv1.3 (IN), TLS handshake, Server hello (2):629{ [1210 bytes data]630* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):631{ [1 bytes data]632* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):633{ [19 bytes data]634* TLSv1.3 (IN), TLS handshake, Certificate (11):635{ [1010 bytes data]636* TLSv1.3 (IN), TLS handshake, CERT verify (15):637{ [112 bytes data]638* TLSv1.3 (IN), TLS handshake, Finished (20):639{ [52 bytes data]640* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):641} [1 bytes data]642* TLSv1.3 (OUT), TLS handshake, Finished (20):643} [52 bytes data]644* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey645* ALPN: server accepted h2646* Server certificate:647* subject: CN=test.foo648* start date: Aug 20 05:08:12 2026 GMT649* expire date: Sep 19 05:08:12 2028 GMT650* issuer: CN=minica root ca 2da5d6651* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384652* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384653* subjectAltName: "test.foo" matches cert's "test.foo"654* OpenSSL verify result: 13655* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)656* closing connection #0657curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)658More details here: https://curl.se/docs/sslcerts.html659660curl failed to verify the legitimacy of the server and therefore could not661establish a secure connection to it. To learn more about this situation and662how to fix it, please visit the webpage mentioned above.663server # [6241474.698855] server systemd[1]: Reloading Nginx Web Server...664server # [6241474.703308] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.665server # [6241474.703580] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.666server # [6241475.301320] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok667server # [6241475.301929] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful668* Host test.foo:443 was resolved.669* IPv6: 2001:db8:1::3670* IPv4: 192.168.1.3671* Trying [2001:db8:1::3]:443...672* ALPN: curl offers h2,http/1.1673} [5 bytes data]674* TLSv1.3 (OUT), TLS handshake, Client hello (1):675} [1552 bytes data]676* SSL Trust Anchors:677* OpenSSL default paths (fallback)678{ [5 bytes data]679* TLSv1.3 (IN), TLS handshake, Server hello (2):680{ [1210 bytes data]681* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):682{ [1 bytes data]683* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):684{ [19 bytes data]685* TLSv1.3 (IN), TLS handshake, Certificate (11):686{ [1010 bytes data]687* TLSv1.3 (IN), TLS handshake, CERT verify (15):688{ [111 bytes data]689* TLSv1.3 (IN), TLS handshake, Finished (20):690{ [52 bytes data]691* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):692} [1 bytes data]693* TLSv1.3 (OUT), TLS handshake, Finished (20):694} [52 bytes data]695* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey696* ALPN: server accepted h2697* Server certificate:698* subject: CN=test.foo699* start date: Aug 20 05:08:12 2026 GMT700* expire date: Sep 19 05:08:12 2028 GMT701* issuer: CN=minica root ca 2da5d6702* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384703* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384704* subjectAltName: "test.foo" matches cert's "test.foo"705* OpenSSL verify result: 13706* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)707* closing connection #0708curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)709More details here: https://curl.se/docs/sslcerts.html710711curl failed to verify the legitimacy of the server and therefore could not712establish a secure connection to it. To learn more about this situation and713how to fix it, please visit the webpage mentioned above.714server # [6241475.913883] server systemd[1]: Reloaded Nginx Web Server.715* Host test.foo:443 was resolved.716* IPv6: 2001:db8:1::3717* IPv4: 192.168.1.3718* Trying [2001:db8:1::3]:443...719* ALPN: curl offers h2,http/1.1720} [5 bytes data]721* TLSv1.3 (OUT), TLS handshake, Client hello (1):722} [1552 bytes data]723* SSL Trust Anchors:724* OpenSSL default paths (fallback)725{ [5 bytes data]726* TLSv1.3 (IN), TLS handshake, Server hello (2):727{ [1210 bytes data]728* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):729{ [1 bytes data]730* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):731{ [19 bytes data]732* TLSv1.3 (IN), TLS handshake, Certificate (11):733{ [931 bytes data]734* TLSv1.3 (IN), TLS handshake, CERT verify (15):735{ [79 bytes data]736* TLSv1.3 (IN), TLS handshake, Finished (20):737{ [52 bytes data]738* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):739} [1 bytes data]740* TLSv1.3 (OUT), TLS handshake, Finished (20):741} [52 bytes data]742* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey743* ALPN: server accepted h2744* Server certificate:745* subject: CN=test.foo746* start date: Aug 20 05:07:20 2026 GMT747* expire date: Nov 18 05:08:20 2026 GMT748* issuer: CN=Clan Intermediate CA749* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256750* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256751* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256752* subjectAltName: "test.foo" matches cert's "test.foo"753* OpenSSL verify result: 0754* SSL certificate verified via OpenSSL.755* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 41540 756 % Total % Received % Xferd Average Speed Time Time Time Current757 Dload Upload Total Spent Left Speed758 0 0 0 0 0 0 0 0 0* using HTTP/2759* [HTTP/2] [1] OPENED stream for https://test.foo/760* [HTTP/2] [1] [:method: GET]761* [HTTP/2] [1] [:scheme: https]762* [HTTP/2] [1] [:authority: test.foo]763* [HTTP/2] [1] [:path: /]764* [HTTP/2] [1] [user-agent: curl/8.21.0]765* [HTTP/2] [1] [accept: */*]766} [5 bytes data]767768769770771772* Request completely sent off773{ [5 bytes data]774* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):775{ [265 bytes data]776* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):777{ [265 bytes data]778779780781782783784785{ [5 bytes data]786100 20 100 20 0 0 755 0 0787* Connection #0 to host test.foo:443 left intact788client: (finished: waiting for success: curl -v https://test.foo, in 3.20 seconds)789client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2790Certificate:791 Data:792 Version: 3 (0x2)793 Serial Number:794 38:98:8f:bc:7e:d2:a2:20:c4:c0:bb:de:9a:dc:d9:a2795 Signature Algorithm: ecdsa-with-SHA256796 Issuer: CN=Clan Intermediate CA797 Validity798 Not Before: Aug 20 05:07:20 2026 GMT799 Not After : Nov 18 05:08:20 2026 GMT800 Subject: CN=test.foo801 Subject Public Key Info:802 Public Key Algorithm: id-ecPublicKey803 Public-Key: (256 bit)804 pub:805 04:ca:37:ef:64:d7:e8:68:fd:01:ac:93:93:2c:79:806 a3:b1:a5:79:7a:66:0c:79:fc:79:19:b9:17:40:83:807 38:c7:1c:2c:6b:d7:b6:d9:fb:b2:fe:db:e0:7e:55:808 06:8e:a8:ec:90:f5:f0:34:29:83:74:f1:e5:f9:8b:809 11:9b:52:7a:23810 ASN1 OID: prime256v1811 NIST CURVE: P-256812 X509v3 extensions:813 X509v3 Key Usage: critical814 Digital Signature815 X509v3 Extended Key Usage: 816 TLS Web Server Authentication, TLS Web Client Authentication817 X509v3 Subject Key Identifier: 818 D1:5D:01:D0:E6:69:A7:1E:93:12:80:DD:81:A6:B0:C8:C7:90:59:C1819 X509v3 Authority Key Identifier: 820 28:5F:27:82:E3:AD:3B:D6:A7:5E:93:47:0A:9E:45:C0:66:5B:95:6C821 X509v3 Subject Alternative Name: 822 DNS:test.foo823 1.3.6.1.4.1.37476.9000.64.1: 824 0......acme..825 Signature Algorithm: ecdsa-with-SHA256826 Signature Value:827 30:45:02:20:01:8e:c7:8a:3f:33:ed:df:7d:da:12:4c:c1:7f:828 4b:97:bf:69:ab:7c:16:c7:f3:8b:c5:7c:0c:22:17:8a:0e:38:829 02:21:00:a1:47:62:69:f7:e2:5c:a8:2c:32:66:00:8b:38:76:830 b2:de:1a:72:bb:da:e7:04:39:86:eb:9a:94:17:ea:2b:e8831client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds)832(finished: run the VM test script, in 13.74 seconds)833test script finished in 13.78s834cleanup835kill NspawnMachine (pid 53)836kill NspawnMachine (pid 54)837kill NspawnMachine (pid 55)838Container ca terminated by signal KILL.839Container client terminated by signal KILL.840(finished: cleanup, in 0.44 seconds)841Container server terminated by signal KILL.