these 87 derivations will be built: /nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv /nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv /nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv /nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv /nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv /nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv /nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv /nix/store/55r3xbviq6l3zgziig53rhs351x7xj6l-cacert-extra-certificates-bundle.crt.drv /nix/store/x52vjn5rprsx9n1jd5m287f9yhs1ffqn-cacert-blocklist.txt.drv /nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv /nix/store/zjixmmmwxxnsrqfrcvdi5kc7sg2hx4dd-unit-nix-daemon.service.drv /nix/store/41nz7xm9bip5dy7320vz1n5w0cqsnqr5-system-units.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv /nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv /nix/store/p907anzqjw4bz1zq22v4vd7nzwdxc3sn-etc.drv /nix/store/mshy3cigghh4lhdd8rbr9lazm3y6kra1-activate.drv /nix/store/vzxifhyx250scbjsk2dd5wcrn21v9rcl-nixos-system-client-test.drv /nix/store/2l3h0m63xfr68x0mjj6pc6qdgw0vi79q-run-client-nspawn.drv /nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv /nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/rd87f66ad5c3y0aw6m9ys2nmy6z210pf-system-units.drv /nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv /nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv /nix/store/l76i8c3p5lrk9x0bc3s8ihdgghcpb5ny-etc.drv /nix/store/fazvzzkrxg0aldqlsmrbyrig7mf4qfch-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/6mxv6nd11qi8dfs9rm97kvh406d7plzp-nixos-system-server-test.drv /nix/store/3zyb8a3p6fpkvsn9na7x5s0cvgn4xndm-run-server-nspawn.drv /nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv /nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv /nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv /nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv /nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv /nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv /nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv /nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv /nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv /nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv /nix/store/w3f8g8q2plavp4zkh817qvj7g29qdm1g-system-units.drv /nix/store/j12z45czg8nwjp0grkqijp8zlsrnc2sa-etc.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/vi6kx2paiy5g31pan95a3yhrr19w04l4-activate.drv /nix/store/47za8gcgg6wb9g5z4imijz2y0wiwynhx-nixos-system-ca-test.drv /nix/store/j7hcm3w1vpjb6b3s9kdcd492a1j78kfb-run-ca-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/apx56iy0yijpsqky00q89dpl5j5r21rh-driverConfiguration.json.drv /nix/store/d2bdxmicv0v5sxpq76j2wj1bwcgiw2qf-nixos-test-driver-certificates.drv /nix/store/bp1rfmbwvq9s7wjvpvh1w769yshb2qmk-container-test-run-certificates.drv these 2 paths will be fetched (22.1 MiB download, 71.0 MiB unpacked): /nix/store/1psq003v8r8611bv7bk74xdwz9z6dgaj-openssl-3.6.3-man /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/b1wakvsznndfrig5xjpba9fwk6lpwkw3-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/57rffvyz1v996a4nmx5rzak7gaiffd8d-system-path.drv' system-path> structuredAttrs is enabled building '/nix/store/18fph232asdns0l1wpwxnqc3v86zzx7r-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' system-path> created 1718 symlinks in user environment building '/nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5m1cfc1nmb9cbzniv4dpgdv38ivj0qsz-unit-script-nginx-pre-start.drv' building '/nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pa90nb5i4avk1dcjbzqw29l30fm150sx-dbus-1.drv' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ixvvfqmkvpvfkz56fq4946vh61msr5hh-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/skf8nz991czh5gpm41hbaqakj5f7hf0c-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/0b9f0r4388f6f8hmhac74gfzn1rgk82q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/966l9k8f9k6y5373c1rsvdh4647rcvjf-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k398xkx7mfqk70rwygca42rjfj745kf2-dbus-1.drv' building '/nix/store/33cqcqqvm72xwbvp5zvp2vhpz17g33cm-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zp4xg9lzm2xahzw1jncgrn6qgq5gl73m-user-units.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/k5phpbqvva59rzp4cx71phpv7ckmrncv-nss-cacert-3.126.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d4vj54sx388dyibi2ja6r7jckm4ra5bl-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/0xkhp1jyiww6v4dp6inpsvhj8ms1wmi6-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/1fr2a3iklngc5j6bsfymlk844vkxgahb-nss-cacert-3.126-unbundled building '/nix/store/c4fbynx5fd1rrxwjc0lz2lavigal41hi-system-path.drv' system-path> structuredAttrs is enabled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/b2f8gd0bxmgn7746nk6g2bxg8b73shsh-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed... nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nss-cacert-3.126> patching script interpreter paths in /nix/store/5iyqm7jlnc3pa4rc1ajgcjfpi8wxmif3-nss-cacert-3.126-hashed building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' system-path> created 1718 symlinks in user environment building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' building '/nix/store/zjixmmmwxxnsrqfrcvdi5kc7sg2hx4dd-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/h3d7mc9w4db0f16y276r3v617dg92b7d-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zjixmmmwxxnsrqfrcvdi5kc7sg2hx4dd-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' building '/nix/store/8v8nx7xkgmlz39rnf6l90mdmzhz8c9yx-unit-script-nginx-pre-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g4lprx9wmm1d2wsmkpxiksv270j1rgi0-X-Restart-Triggers-step-ca.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/pcnshfwmx0pai079bwabz5xkg6xx9976-dbus-1.drv' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/q09l6f2dgvy5zb98z7ypkhsf8hqkmxac-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/84y63g9jnm1wzggblz2ch6sslj97gm2q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/j2jdcyp4233cn5lky6zlsk016msb24sr-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/f2lrnjzwsjlgwcgy4k6irw184vg9sayn-user-units.drv' building '/nix/store/fpz2bqfgazq73k7ga6j1vl77vhp3vjzs-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/73hr9ga3nmp6xbkx5lfh22n9das8a3qk-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/w3f8g8q2plavp4zkh817qvj7g29qdm1g-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/pz32s1dvwxxi3kv0z31isr5qrzvpra0m-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/l7rzpls3kbqdq5zi9q9r91qg33fj3ffy-user-units.drv' building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled building '/nix/store/w3f8g8q2plavp4zkh817qvj7g29qdm1g-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4vmdhi01wjbc35gr3hbhw007gp34p9vc-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/41nz7xm9bip5dy7320vz1n5w0cqsnqr5-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/j12z45czg8nwjp0grkqijp8zlsrnc2sa-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rd87f66ad5c3y0aw6m9ys2nmy6z210pf-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/41nz7xm9bip5dy7320vz1n5w0cqsnqr5-system-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j12z45czg8nwjp0grkqijp8zlsrnc2sa-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/vi6kx2paiy5g31pan95a3yhrr19w04l4-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p907anzqjw4bz1zq22v4vd7nzwdxc3sn-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rd87f66ad5c3y0aw6m9ys2nmy6z210pf-system-units.drv' building '/nix/store/vi6kx2paiy5g31pan95a3yhrr19w04l4-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/p907anzqjw4bz1zq22v4vd7nzwdxc3sn-etc.drv' building '/nix/store/47za8gcgg6wb9g5z4imijz2y0wiwynhx-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/47za8gcgg6wb9g5z4imijz2y0wiwynhx-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mshy3cigghh4lhdd8rbr9lazm3y6kra1-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l76i8c3p5lrk9x0bc3s8ihdgghcpb5ny-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l76i8c3p5lrk9x0bc3s8ihdgghcpb5ny-etc.drv' building '/nix/store/j7hcm3w1vpjb6b3s9kdcd492a1j78kfb-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fazvzzkrxg0aldqlsmrbyrig7mf4qfch-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/j7hcm3w1vpjb6b3s9kdcd492a1j78kfb-run-ca-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/mshy3cigghh4lhdd8rbr9lazm3y6kra1-activate.drv' building '/nix/store/vzxifhyx250scbjsk2dd5wcrn21v9rcl-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fazvzzkrxg0aldqlsmrbyrig7mf4qfch-activate.drv' building '/nix/store/6mxv6nd11qi8dfs9rm97kvh406d7plzp-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vzxifhyx250scbjsk2dd5wcrn21v9rcl-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/2l3h0m63xfr68x0mjj6pc6qdgw0vi79q-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/2l3h0m63xfr68x0mjj6pc6qdgw0vi79q-run-client-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6mxv6nd11qi8dfs9rm97kvh406d7plzp-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/3zyb8a3p6fpkvsn9na7x5s0cvgn4xndm-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/3zyb8a3p6fpkvsn9na7x5s0cvgn4xndm-run-server-nspawn.drv' building '/nix/store/apx56iy0yijpsqky00q89dpl5j5r21rh-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/apx56iy0yijpsqky00q89dpl5j5r21rh-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/d2bdxmicv0v5sxpq76j2wj1bwcgiw2qf-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/d2bdxmicv0v5sxpq76j2wj1bwcgiw2qf-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/bp1rfmbwvq9s7wjvpvh1w769yshb2qmk-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/bp1rfmbwvq9s7wjvpvh1w769yshb2qmk-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ca # [6241464.107781] ca systemd-journald[78]: Journal started container-test-run-certificates> ca # [6241464.107831] ca systemd-journald[78]: Runtime Journal (/run/log/journal/ad4cad6dcc814c8e80b6efe185576e22) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6241464.110733] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6241464.087429] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6241464.119478] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6241464.087484] client systemd-journald[69]: Runtime Journal (/run/log/journal/2c2c42a61adc456fb7c671ac075b19d8) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6241464.120350] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6241464.088704] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6241464.121020] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [6241464.098190] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6241464.128403] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/ad4cad6dcc814c8e80b6efe185576e22 is 2.097ms for 6 entries. container-test-run-certificates> client # [6241464.099019] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6241464.128403] ca systemd-journald[78]: System Journal (/var/log/journal/ad4cad6dcc814c8e80b6efe185576e22) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6241464.099710] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6241464.134784] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6241464.109023] client systemd-journald[69]: Time spent on flushing to /var/log/journal/2c2c42a61adc456fb7c671ac075b19d8 is 1.820ms for 6 entries. container-test-run-certificates> ca # [6241464.135039] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6241464.109023] client systemd-journald[69]: System Journal (/var/log/journal/2c2c42a61adc456fb7c671ac075b19d8) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6241464.135121] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6241464.111175] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6241464.135846] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6241464.111811] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6241464.135890] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6241464.111920] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6241464.136708] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [6241464.112736] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6241464.136739] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [6241464.112782] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6241464.142167] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6241464.113669] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6241464.143583] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6241464.113703] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6241464.161806] ca systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6241464.137601] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [6241464.138805] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [6241464.155367] client systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [6241464.162030] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6241464.155536] client systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6241464.162177] ca systemd-tmpfiles[122]: fchmod() of /var/log/journal/ad4cad6dcc814c8e80b6efe185576e22 failed: Operation not permitted container-test-run-certificates> client # [6241464.155653] client systemd-tmpfiles[121]: fchmod() of /var/log/journal/2c2c42a61adc456fb7c671ac075b19d8 failed: Operation not permitted container-test-run-certificates> ca # [6241464.162400] ca systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6241464.155833] client systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [6241464.164512] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6241464.157618] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [6241464.165551] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6241464.158739] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [6241464.166208] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6241464.159521] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [6241464.177074] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6241464.173263] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [6241464.186960] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6241464.198619] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [6241464.187923] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6241464.199679] client systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [6241464.197540] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6241464.204187] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6241464.204513] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6241464.209575] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6241464.233979] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6241464.234137] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6241464.234355] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6241464.235368] client systemd[1]: Starting Network Management... container-test-run-certificates> server # [6241464.091944] server systemd-journald[69]: Journal started container-test-run-certificates> server # [6241464.091998] server systemd-journald[69]: Runtime Journal (/run/log/journal/df5c9048075a4de09d1fa84b9fd13219) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> server # [6241464.096591] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> server # [6241464.105031] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [6241464.105841] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [6241464.106620] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [6241464.115346] server systemd-journald[69]: Time spent on flushing to /var/log/journal/df5c9048075a4de09d1fa84b9fd13219 is 1.685ms for 6 entries. container-test-run-certificates> server # [6241464.115346] server systemd-journald[69]: System Journal (/var/log/journal/df5c9048075a4de09d1fa84b9fd13219) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [6241464.122187] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6241464.122416] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6241464.122499] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6241464.123232] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [6241464.123277] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6241464.124164] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6241464.124196] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6241464.140353] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6241464.141789] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6241464.156386] server systemd-tmpfiles[121]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6241464.156560] server systemd-tmpfiles[121]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6241464.156676] server systemd-tmpfiles[121]: fchmod() of /var/log/journal/df5c9048075a4de09d1fa84b9fd13219 failed: Operation not permitted container-test-run-certificates> server # [6241464.156853] server systemd-tmpfiles[121]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6241464.158225] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6241464.159192] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6241464.159832] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6241464.171497] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6241464.180708] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6241464.181801] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6241464.191329] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6241464.204223] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6241464.241006] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6241464.241159] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6241464.241385] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6241464.242416] server systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6241464.259253] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6241464.259396] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6241464.259608] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6241464.260605] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6241464.650395] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6241464.650491] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6241464.657189] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6241464.657349] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6241464.657521] client systemd-networkd[183]: lo: Link UP container-test-run-certificates> client # [6241464.657526] client systemd-networkd[183]: lo: Gained carrier container-test-run-certificates> client # [6241464.657716] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6241464.658205] client systemd-networkd[183]: eth1: Link UP container-test-run-certificates> client # [6241464.658509] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6241464.659520] client systemd-networkd[183]: eth1: Gained carrier container-test-run-certificates> client # [6241464.659642] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6241464.723268] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6241464.834063] client systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> client # [6241464.834076] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6241464.834080] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6241464.834113] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6241464.857138] client systemd-resolved[92]: Using system hostname 'client'. container-test-run-certificates> client # [6241464.858529] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6241464.858747] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6241464.858894] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6241464.859024] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6241464.859125] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6241464.859206] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6241464.859577] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6241464.859867] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6241464.860182] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6241464.860256] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6241464.860367] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6241464.908464] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6241464.659871] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6241464.659966] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6241464.668304] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6241464.668470] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6241464.668633] server systemd-networkd[187]: lo: Link UP container-test-run-certificates> server # [6241464.668637] server systemd-networkd[187]: lo: Gained carrier container-test-run-certificates> server # [6241464.668849] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6241464.669248] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6241464.712314] server systemd-networkd[187]: eth1: Link UP container-test-run-certificates> server # [6241464.712641] server systemd-networkd[187]: eth1: Gained carrier container-test-run-certificates> server # [6241464.712721] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6241464.763164] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6241464.829952] server systemd-resolved[94]: Positive Trust Anchors: container-test-run-certificates> server # [6241464.829964] server systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6241464.829968] server systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6241464.830003] server systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6241464.852926] server systemd-resolved[94]: Using system hostname 'server'. container-test-run-certificates> server # [6241464.854340] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6241464.854475] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6241464.854544] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6241464.854610] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6241464.854861] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6241464.854932] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6241464.854965] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6241464.854991] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6241464.855125] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6241464.855264] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6241464.855405] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6241464.855430] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6241464.855469] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6241464.857146] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [6241464.857912] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6241464.857955] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6241464.858760] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6241464.860531] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6241464.683052] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6241464.683145] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6241464.689944] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6241464.690105] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6241464.690264] ca systemd-networkd[196]: lo: Link UP container-test-run-certificates> ca # [6241464.690268] ca systemd-networkd[196]: lo: Gained carrier container-test-run-certificates> ca # [6241464.690453] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6241464.690872] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6241464.712713] ca systemd-networkd[196]: eth1: Link UP container-test-run-certificates> ca # [6241464.712727] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6241464.713121] ca systemd-networkd[196]: eth1: Gained carrier container-test-run-certificates> ca # [6241464.763200] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6241464.840788] ca systemd-resolved[102]: Positive Trust Anchors: container-test-run-certificates> ca # [6241464.840802] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6241464.840805] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6241464.840841] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6241464.863529] ca systemd-resolved[102]: Using system hostname 'ca'. container-test-run-certificates> ca # [6241464.864955] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6241464.865148] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6241464.865271] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6241464.865389] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6241464.865828] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6241464.865921] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6241464.865985] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6241464.866042] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6241464.866300] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6241464.866533] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6241464.866819] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6241464.866887] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6241464.866972] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6241464.909097] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6241464.911912] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6241464.911994] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6241464.916174] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6241464.918796] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6241464.925549] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [6241464.937812] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6241465.046725] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [6241465.046725] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [6241465.046725] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6241465.048537] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6241465.050216] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6241465.050216] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6241465.050370] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6241465.050370] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6241465.069887] ca nsncd[203]: Aug 20 05:08:11.123 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6241465.069951] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6241465.070025] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6241465.070089] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6241465.097064] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6241465.098090] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6241465.106568] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6241465.107825] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6241465.109382] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6241465.109427] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6241465.109448] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6241464.910068] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6241464.912476] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [6241464.930296] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6241465.073470] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6241465.092051] client nsncd[189]: Aug 20 05:08:11.145 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6241465.097033] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6241465.097080] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6241465.097151] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6241465.098583] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6241465.099670] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6241465.111453] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6241465.113452] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6241465.113547] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6241465.113617] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6241464.924764] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6241465.054563] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6241465.054563] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6241465.055224] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6241465.056056] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6241465.057790] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6241465.057859] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6241465.057859] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6241465.057859] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6241465.063473] server nsncd[194]: Aug 20 05:08:11.116 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6241465.063580] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6241465.063653] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6241465.063720] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6241465.097120] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6241465.097955] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6241465.106598] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6241465.107857] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6241465.109686] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6241465.109735] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6241465.109756] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [6241465.218487] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [6241465.219069] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6241465.219069] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3mkgnlb89jy49c4a1z0swjahhcvmnw8p-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6241465.219529] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6241465.226981] server dbus-broker-launch[195]: Ready container-test-run-certificates> client # [6241465.202773] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6241465.203753] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6241465.203753] client dbus-broker-launch[190]: Invalid user-name in /nix/store/71vmh4xl6s5dgp2wq5sm5rdd4lr016c0-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6241465.204236] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6241465.211428] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6241465.193901] ca dbus-broker-launch[211]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6241465.194645] ca dbus-broker-launch[211]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6241465.194645] ca dbus-broker-launch[211]: Invalid user-name in /nix/store/bz7ygr15ilclf6krkxd1w5j7l4dw4kny-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [6241465.195276] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6241465.202868] ca dbus-broker-launch[211]: Ready container-test-run-certificates> client # [6241465.625911] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6241465.626114] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6241465.627382] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6241465.685609] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6241465.685742] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6241465.686163] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6241465.686382] client systemd[1]: Startup finished in 1.971s. container-test-run-certificates> ca # [6241465.647398] ca systemd-logind[231]: New seat seat0. container-test-run-certificates> ca # [6241465.647582] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6241465.676410] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6241465.690451] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6241465.690569] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6241465.705481] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [6241465.705740] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [6241465.705740] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6241465.727523] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6241465.729445] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [6241465.797283] ca step-ca[207]: badger 2026/08/20 05:08:11 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6241465.801273] ca step-ca[207]: 2026/08/20 05:08:11 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6241465.806597] ca step-ca[207]: 2026/08/20 05:08:11 X.509 Root Fingerprint: e826ba1017ed9c6d1e80bbc83d56e54b4763fd0cf6f59c398a4f0b383416ea71 container-test-run-certificates> ca # [6241465.807283] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6241465.807463] ca step-ca[207]: 2026/08/20 05:08:11 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> server # [6241465.623233] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [6241465.623450] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6241465.624594] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6241465.666972] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6241465.666972] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6241465.667265] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6241465.684733] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6241465.687522] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [6241465.688160] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6241465.688364] server systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6241465.888470] client systemd-networkd[183]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> ca # [6241466.052189] ca systemd-networkd[196]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6241466.254053] ca acme-ca.foo-start[284]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6241466.257300] ca acme-ca.foo-start[284]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6241466.257300] ca acme-ca.foo-start[284]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6241466.272712] ca acme-ca.foo-start[294]: + cd ca.foo container-test-run-certificates> ca # [6241466.273781] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6241466.275065] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6241466.275511] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6241466.276805] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6241466.277072] ca acme-ca.foo-start[284]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6241466.279474] ca acme-ca.foo-start[284]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6241466.281249] ca acme-ca.foo-start[284]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6241466.282723] ca acme-ca.foo-start[284]: + for fixpath in out certificates container-test-run-certificates> ca # [6241466.282761] ca acme-ca.foo-start[284]: + '[' -d out ']' container-test-run-certificates> ca # [6241466.282761] ca acme-ca.foo-start[284]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6241466.284304] ca acme-ca.foo-start[284]: + chown -R acme:nginx out container-test-run-certificates> ca # [6241466.287188] ca acme-ca.foo-start[284]: + for fixpath in out certificates container-test-run-certificates> ca # [6241466.287232] ca acme-ca.foo-start[284]: + '[' -d certificates ']' container-test-run-certificates> ca # [6241466.291228] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6241466.292941] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6241466.212785] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6241466.215729] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6241466.215729] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6241466.230867] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [6241466.231513] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6241466.232477] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6241466.233035] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6241466.235054] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6241466.235286] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6241466.237656] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6241466.239465] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6241466.242066] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6241466.242066] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [6241466.242066] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6241466.243705] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [6241466.247185] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [6241466.247216] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [6241466.251052] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6241466.253122] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6241466.432270] server systemd-networkd[187]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6241466.932832] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok container-test-run-certificates> ca # [6241466.932832] ca nginx-pre-start[306]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful container-test-run-certificates> ca # [6241466.938698] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6241466.939307] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6241466.890775] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> ca # [6241466.941005] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6241466.891199] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> server # [6241466.897165] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6241466.897575] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6241466.899168] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6241467.488884] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6241467.492352] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [6241467.492448] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6241467.492546] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6241467.493724] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6241467.513265] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:13 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6241467.513677] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:13 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6241467.517203] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6241467.520032] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail container-test-run-certificates> ca # [6241467.520113] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6241467.520221] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6241467.521275] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6241467.536913] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6241467.537408] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6241467.566662] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration="105.121µs" duration-ns=105121 fields.time="2026-08-20T05:08:13Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6f574c1d-55b2-44f1-985d-07ac060e7696 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.567132] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6241467.571293] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=3.998976ms duration-ns=3998976 fields.time="2026-08-20T05:08:13Z" method=HEAD name=ca nonce=NlJTcVNQT2E3VGwxMjNZM2REUHNHdHBremdWVW1mSWs path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a0240468-ec13-41b6-82ac-fd701614a952 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.575502] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=3.063523ms duration-ns=3063523 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=Q2hwTkZlWDRVRVJPNGFPdkFZOTBCUFR5SWg4N1ZNYmM path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=cea3a5ea-b96c-413b-8a2d-06c09ccbb38f response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/zIzEC4PPgL3rCVFRfz8MmNoiIzGTGx90/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts". container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6241467.575844] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6241467.576049] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6241467.580637] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=4.26722ms duration-ns=4267220 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=WExPem5VcUdsekhnTUdISGplTndnYVVOUklVcGxEamg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=01adc5fa-c53e-4277-952b-a9310d312ced response="{\"id\":\"XFO5hUsrryH9yjASd3FLF6glHn5l9Km8\",\"status\":\"pending\",\"expires\":\"2026-08-21T05:08:13Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-20T05:07:13Z\",\"notAfter\":\"2026-11-18T05:08:13Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.640093] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=2.375274ms duration-ns=2375274 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=a1ljd0ZDblMxNUNHTlVtN2lkcjJOSE1VMENNRHkxZHI path=/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9e2d9e2c-20b5-4c9e-a0c7-4c1d1bf00ee1 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/zuurmQ4me09hYzVLahgVGOAXTZgcf1iP\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/ratJZND2IkaqSPcYcwCUCUx3HHZQJH5D\"}],\"wildcard\":false,\"expires\":\"2026-08-21T05:08:13Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I container-test-run-certificates> ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6241467.640501] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [6241467.646170] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=5.064631ms duration-ns=5064631 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=YVg2cE1ackczZ1k4QXdZaUp3NzV5eUxiaVV3RjJYTUo path=/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9d508e48-51a8-4a65-b978-7f3d26a01362 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"GGcvbNVZUB4kU0nYm1WO37qUgLNLZCBS\",\"validated\":\"2026-08-20T05:08:13Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I/iJQ9cREenZSZgoaYeHpsWDi85UGSDZRw\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.646445] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6241467.646528] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6241467.655766] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info duration=8.337797ms duration-ns=8337797 fields.time="2026-08-20T05:08:13Z" method=POST name=ca nonce=MmFnbE1zZlRkaFJnSEN0a1RwcEVlTnhVZEJyd2dMU2Y path=/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=774827d2-a00f-46f0-ab86-6b6ea5ba64b0 response="{\"id\":\"XFO5hUsrryH9yjASd3FLF6glHn5l9Km8\",\"status\":\"valid\",\"expires\":\"2026-08-21T05:08:13Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-20T05:07:13Z\",\"notAfter\":\"2026-11-18T05:08:13Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/5WTOqXFkz6McXDuB8KlKJJBvy997VW1I\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/XFO5hUsrryH9yjASd3FLF6glHn5l9Km8/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/sNZvUuga4Ljez2avFZhwvomwVY88F44f\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241467.658544] ca step-ca[207]: time="2026-08-20T05:08:13Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAJLFXDxvxDBi/4pC6z7ZZrswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODIwMDUwNzEzWhcNMjYxMTE4MDUwODEzWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS6Rsl6WiLW9zlNJW/TDFu3rl9GSQHTGQW6LoUQA5EMcPbEf+Z9m7AoDNrVc+Pr5A9NB/NiPILW3ZZtKsgj0H99o4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFKQOoQHjUT6y2SNBRQPcEaFho/UTMB8GA1UdIwQYMBaAFChfJ4LjrTvWp16TRwqeRcBmW5VsMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIhAKiYC0gebkqA/H/pu65bVkwo7g3M3Nh+Kx7KkiGmWn22AiBH6f6FDK2nQdIPedpHtzgnbisnfnbmmiOh8Tqf5fJiEQ==" duration=1.837785ms duration-ns=1837785 fields.time="2026-08-20T05:08:13Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=UHA2MTNlZ3FpRkJlWUxaeEtaSG9YTEoxdmVKNk5pOXk path=/acme/acme/certificate/sNZvUuga4Ljez2avFZhwvomwVY88F44f protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=383de0a1-fefb-45e7-a32b-9451bfe462a7 sans="map[dns:[ca.foo]]" serial=195092040635692379346915067855338301115 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-20T05:07:13Z" valid-to="2026-11-18T05:08:13Z" container-test-run-certificates> ca # [6241467.658828] ca acme-order-renew-ca.foo-start[320]: 2026/08/20 05:08:13 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6241467.664295] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6241467.666264] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success container-test-run-certificates> ca # [6241467.667907] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6241467.669065] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed container-test-run-certificates> ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate container-test-run-certificates> ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: Installing new certificate container-test-run-certificates> ca # [6241467.670619] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6241467.672296] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6241467.672668] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6241467.674056] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6241467.674372] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6241467.675729] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6241467.676081] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6241467.677718] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6241467.679693] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6241467.679693] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']' container-test-run-certificates> ca # [6241467.679805] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6241467.681348] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out container-test-run-certificates> ca # [6241467.684190] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates container-test-run-certificates> ca # [6241467.684190] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']' container-test-run-certificates> ca # [6241467.684325] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6241467.685882] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6241467.688499] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6241467.943596] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6241467.947753] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6241467.947928] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server # [6241468.564411] server acme-order-renew-test.foo-start[282]: 2026/08/20 05:08:14 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6241468.569172] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6241468.569172] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6241468.569172] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [6241468.573162] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6241468.573243] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6241468.573492] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6241468.588197] server systemd[1]: Startup finished in 4.873s. container-test-run-certificates> ca # [6241468.742250] ca nginx[370]: nginx: the configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf syntax is ok container-test-run-certificates> ca # [6241468.742882] ca nginx[370]: nginx: configuration file /nix/store/kijspw8hclw37aj8kl8y20jfn91c8ssx-nginx.conf test is successful container-test-run-certificates> ca # [6241469.320377] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6241469.321019] ca systemd[1]: Startup finished in 5.593s. container-test-run-certificates> ca # [6241469.410095] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.90 seconds) container-test-run-certificates> ca # [6241469.945723] ca acme-order-renew-ca.foo-start[385]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6241469.948989] ca acme-order-renew-ca.foo-start[385]: + set -euo pipefail container-test-run-certificates> ca # [6241469.949080] ca acme-order-renew-ca.foo-start[385]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6241469.949171] ca acme-order-renew-ca.foo-start[385]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6241469.950343] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6241469.950396] ca acme-order-renew-ca.foo-start[385]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6241469.950786] ca acme-order-renew-ca.foo-start[393]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6241469.954137] ca acme-order-renew-ca.foo-start[385]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6241469.954137] ca acme-order-renew-ca.foo-start[385]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6241469.995623] ca step-ca[207]: time="2026-08-20T05:08:16Z" level=info duration="59.72µs" duration-ns=59720 fields.time="2026-08-20T05:08:16Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=c3ff4073-eb82-4bff-b627-f3bffaebe5c1 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241469.996113] ca acme-order-renew-ca.foo-start[394]: 2026/08/20 05:08:16 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6241469.996113] ca acme-order-renew-ca.foo-start[394]: 2026/08/20 05:08:16 [INFO] [ca.foo] The certificate expires at 2026-11-18T05:08:13Z, the renewal can be performed in 1439h59m36.950873801s: no renewal. container-test-run-certificates> ca # [6241469.996500] ca acme-order-renew-ca.foo-start[385]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6241469.998241] ca acme-order-renew-ca.foo-start[385]: + touch out/acme-success container-test-run-certificates> ca # [6241470.000038] ca acme-order-renew-ca.foo-start[385]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6241470.001057] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates container-test-run-certificates> ca # [6241470.001088] ca acme-order-renew-ca.foo-start[385]: + '[' -d out ']' container-test-run-certificates> ca # [6241470.001088] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6241470.002488] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx out container-test-run-certificates> ca # [6241470.004843] ca acme-order-renew-ca.foo-start[385]: + for fixpath in out certificates container-test-run-certificates> ca # [6241470.004880] ca acme-order-renew-ca.foo-start[385]: + '[' -d certificates ']' container-test-run-certificates> ca # [6241470.004880] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6241470.006211] ca acme-order-renew-ca.foo-start[385]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6241470.008754] ca acme-order-renew-ca.foo-start[385]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6241470.141908] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6241470.142106] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6241473.171048] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6241473.171359] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6241473.172726] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6241473.197874] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.59 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 20 05:08:12 2026 GMT container-test-run-certificates> * expire date: Sep 19 05:08:12 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 2da5d6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6241473.701933] server acme-test.foo-start[317]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6241473.704838] server acme-test.foo-start[317]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6241473.704838] server acme-test.foo-start[317]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6241473.723834] server acme-test.foo-start[326]: + cd test.foo container-test-run-certificates> server # [6241473.724183] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6241473.725590] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6241473.725807] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6241473.727276] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6241473.727536] server acme-test.foo-start[317]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6241473.729500] server acme-test.foo-start[317]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6241473.730898] server acme-test.foo-start[317]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6241473.733027] server acme-test.foo-start[317]: + for fixpath in out certificates container-test-run-certificates> server # [6241473.733027] server acme-test.foo-start[317]: + '[' -d out ']' container-test-run-certificates> server # [6241473.733133] server acme-test.foo-start[317]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6241473.734424] server acme-test.foo-start[317]: + chown -R acme:nginx out container-test-run-certificates> server # [6241473.738049] server acme-test.foo-start[317]: + for fixpath in out certificates container-test-run-certificates> server # [6241473.738049] server acme-test.foo-start[317]: + '[' -d certificates ']' container-test-run-certificates> server # [6241473.741490] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6241473.744757] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [6241474.349417] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6241474.352580] server acme-order-renew-test.foo-start[334]: + set -euo pipefail container-test-run-certificates> server # [6241474.352663] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6241474.352780] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6241474.354040] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6241474.415420] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts". container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6241474.426599] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6241474.426811] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl container-test-run-certificates> server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6241474.497425] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6241474.497573] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6241474.507485] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6241474.507584] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6241474.528737] server acme-order-renew-test.foo-start[342]: 2026/08/20 05:08:20 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6241474.533826] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6241474.535987] server acme-order-renew-test.foo-start[334]: + touch out/acme-success container-test-run-certificates> server # [6241474.537716] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6241474.538853] server acme-order-renew-test.foo-start[334]: + touch out/renewed container-test-run-certificates> server # [6241474.540645] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate container-test-run-certificates> server # [6241474.540645] server acme-order-renew-test.foo-start[334]: Installing new certificate container-test-run-certificates> server # [6241474.540645] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6241474.542378] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6241474.542665] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6241474.544841] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6241474.545091] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6241474.546752] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6241474.547047] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6241474.548733] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6241474.550634] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [6241474.550634] server acme-order-renew-test.foo-start[334]: + '[' -d out ']' container-test-run-certificates> server # [6241474.550731] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6241474.552415] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out container-test-run-certificates> server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates container-test-run-certificates> server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']' container-test-run-certificates> server # [6241474.555797] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6241474.557754] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6241474.561351] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6241474.414711] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration="60.641µs" duration-ns=60641 fields.time="2026-08-20T05:08:20Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=50a3de0a-7dd1-4970-9f83-41e9bf5610c8 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.419804] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration="739.051µs" duration-ns=739051 fields.time="2026-08-20T05:08:20Z" method=HEAD name=ca nonce=SjMxZEF5QldMRmpGUGQwYTAzb1VyMG9URFF6NzBVbkI path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=283baf4e-492e-4b54-9e5f-9db1b43819b6 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.425993] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=2.79772ms duration-ns=2797720 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=bFl4S2l3VW9TOUtaeWtVT1dzYTRYTlZQZkhTcmdWOGs path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=563965d3-809e-4597-908f-08613f70342e response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/ufjbnX9FVM7YLuF7ATHm6jtZ8KCwBINo/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.433741] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=3.793494ms duration-ns=3793494 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=TTlzWm5pNkgydkphWm1DYnFYWmVOaHRUT2lRWVhuYTM path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=86e62806-c15d-44fb-ba99-d4e5bf2410dc response="{\"id\":\"pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f\",\"status\":\"pending\",\"expires\":\"2026-08-21T05:08:20Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-20T05:07:20Z\",\"notAfter\":\"2026-11-18T05:08:20Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl\"],\"finalize\":\"https://ca.foo/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.496570] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=2.08247ms duration-ns=2082470 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=YWJGUTJhTFBCSVkzTElkUGRNTTZZS1FLNVU2aWM4Q2M path=/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl protocol=HTTP/1.1 referer= remote-address="::1" request-id=edbafcc2-b62f-40e3-8fd1-5bc22f1ca527 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/ldfAcYFVqMS4eeNxGEJGVVj8jbq2dteY\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/xOsJfi1tanYjCO42J5LJef7TwsMNn9W5\"}],\"wildcard\":false,\"expires\":\"2026-08-21T05:08:20Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.506832] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=5.01539ms duration-ns=5015390 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=T1haTnQ1U0c3bzVJTVFPM1FUNm1hR0VPdzRzSldxamM path=/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d72b411e-49b9-41fd-a5de-78c2d2b0dd56 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"lliKtJfchB7hTZGkWtwN7XoFWcqnW2SH\",\"validated\":\"2026-08-20T05:08:20Z\",\"url\":\"https://ca.foo/acme/acme/challenge/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl/cRxBl6AvZTFqw5oDsQGCmtGzFJ6er29p\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.521253] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info duration=8.434119ms duration-ns=8434119 fields.time="2026-08-20T05:08:20Z" method=POST name=ca nonce=U0NLeHpoeTR6ZmhjakFTNHgwc2RVeWJFaXdCQkFmNmo path=/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=5494bb6c-9084-4a72-8c14-06412d761dd8 response="{\"id\":\"pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f\",\"status\":\"valid\",\"expires\":\"2026-08-21T05:08:20Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-20T05:07:20Z\",\"notAfter\":\"2026-11-18T05:08:20Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/NbB0tlsKdTtzAmRUF92ZRqs6y4NF53fl\"],\"finalize\":\"https://ca.foo/acme/acme/order/pSIJRJOp6ahcsnxTEnPB3o9edhSKBO2f/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/9gRORyk0H6NiydUPR4B0pXxYYhWqh1Iq\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6241474.527872] ca step-ca[207]: time="2026-08-20T05:08:20Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQOJiPvH7SoiDEwLvemtzZojAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjAwNTA3MjBaFw0yNjExMTgwNTA4MjBaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyjfvZNfoaP0BrJOTLHmjsaV5emYMefx5GbkXQIM4xxwsa9e22fuy/tvgflUGjqjskPXwNCmDdPHl+YsRm1J6I6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTRXQHQ5mmnHpMSgN2BprDIx5BZwTAfBgNVHSMEGDAWgBQoXyeC46071qdek0cKnkXAZluVbDATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgAY7Hij8z7d992hJMwX9Ll79pq3wWx/OLxXwMIheKDjgCIQChR2Jp9+JcqCwyZgCLOHay3hpyu9rnBDmG65qUF+or6A==" duration=1.942907ms duration-ns=1942907 fields.time="2026-08-20T05:08:20Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=THBIQzM2a2tEODVmdEFLT1oySVJTTnFHWTREVUpyMmk path=/acme/acme/certificate/9gRORyk0H6NiydUPR4B0pXxYYhWqh1Iq protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=c0a202d9-cc9f-461c-89c1-4e96832ff83b sans="map[dns:[test.foo]]" serial=75228912205170208840168047079895914914 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-20T05:07:20Z" valid-to="2026-11-18T05:08:20Z" container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 20 05:08:12 2026 GMT container-test-run-certificates> * expire date: Sep 19 05:08:12 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 2da5d6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6241474.698855] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6241474.703308] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6241474.703580] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6241475.301320] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok container-test-run-certificates> server # [6241475.301929] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 20 05:08:12 2026 GMT container-test-run-certificates> * expire date: Sep 19 05:08:12 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 2da5d6 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6241475.913883] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 20 05:07:20 2026 GMT container-test-run-certificates> * expire date: Nov 18 05:08:20 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 41540 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 755 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.20 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 38:98:8f:bc:7e:d2:a2:20:c4:c0:bb:de:9a:dc:d9:a2 container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 20 05:07:20 2026 GMT container-test-run-certificates> Not After : Nov 18 05:08:20 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:ca:37:ef:64:d7:e8:68:fd:01:ac:93:93:2c:79: container-test-run-certificates> a3:b1:a5:79:7a:66:0c:79:fc:79:19:b9:17:40:83: container-test-run-certificates> 38:c7:1c:2c:6b:d7:b6:d9:fb:b2:fe:db:e0:7e:55: container-test-run-certificates> 06:8e:a8:ec:90:f5:f0:34:29:83:74:f1:e5:f9:8b: container-test-run-certificates> 11:9b:52:7a:23 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> D1:5D:01:D0:E6:69:A7:1E:93:12:80:DD:81:A6:B0:C8:C7:90:59:C1 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 28:5F:27:82:E3:AD:3B:D6:A7:5E:93:47:0A:9E:45:C0:66:5B:95:6C container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:01:8e:c7:8a:3f:33:ed:df:7d:da:12:4c:c1:7f: container-test-run-certificates> 4b:97:bf:69:ab:7c:16:c7:f3:8b:c5:7c:0c:22:17:8a:0e:38: container-test-run-certificates> 02:21:00:a1:47:62:69:f7:e2:5c:a8:2c:32:66:00:8b:38:76: container-test-run-certificates> b2:de:1a:72:bb:da:e7:04:39:86:eb:9a:94:17:ea:2b:e8 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds) container-test-run-certificates> (finished: run the VM test script, in 13.74 seconds) container-test-run-certificates> test script finished in 13.78s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.44 seconds) container-test-run-certificates> Container server terminated by signal KILL. post-build step Upload to niks3: ok time=2026-08-20T05:08:23.966Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-20T05:08:24.421Z level=INFO msg="Uploading 1 narinfos" time=2026-08-20T05:08:24.820Z level=INFO msg="Upload complete. (905ms)"