these 94 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv /nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv /nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/vvnbd6vsh6ridrkhkcq82x0a1m65d327-system-path.drv /nix/store/16arw3wnvxfwlnv2d53bhy5pdnjc28vc-dbus-1.drv /nix/store/8j7cv4bq1rrbbbci44nyw16q8vl0v30z-nginx.conf.drv /nix/store/3476w6gcm05zib3y5pqc8n5az3356nya-unit-script-nginx-pre-start.drv /nix/store/a592w3ld5fsiafnmmp6rw3qyafyihjja-unit-nginx.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/zawx03hrjnzcbw6iypzajm6dwaibn0zl-X-Restart-Triggers-dbus-broker.drv /nix/store/cy6v9fkzdb5b6py3w1dc43qdkbl8l09g-unit-dbus-broker.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv /nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv /nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv /nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv /nix/store/2i94ilb4nhy3wvkklmgfkgdbs75r5pp2-ca.json.drv /nix/store/5xh262rsm3iddh9xjxb9zcj88bn081y6-X-Restart-Triggers-step-ca.drv /nix/store/jbq8qk2f3hf42ymasagwkp5q2v8f11vx-unit-step-ca.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv /nix/store/nrjvykkmy5k08dfz2nmn1bfrvkymv2ca-nss-cacert-3.126.drv /nix/store/sa16z9f2yfwzpgig43n63m6nsahsvzf5-unit-nix-daemon.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv /nix/store/23shbywhqdv186vrbcm46cd9bjskvyla-system-units.drv /nix/store/pkdkhdijp8bly889li089chynpq5b892-system-path.drv /nix/store/5pqvjcgrdhqlib9nzimzhqrrvzpn94y3-dbus-1.drv /nix/store/2zxw57qnqr355kyf6q3bv7z2hmfq2nrz-X-Restart-Triggers-dbus-broker.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/zgv7673gvv64rhqrkky8d6bndcdpqbz5-unit-dbus-broker.service.drv /nix/store/3saba3kck2kq3fknpzx5k39qdnca46gh-user-units.drv /nix/store/5hbd752ciwfvlmh3268p4nga0lzrmjrx-system-path.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/q9vhcd2rlwv3k7c1gxm1mpjzzm4rqmz6-unit-dbus-broker.service.drv /nix/store/iyjl8hkbg7rsjrximvsdlpsl99cphscm-system-units.drv /nix/store/hywyr3n8b8qx41wlkjqiwiyz5v3y3aii-unit-dbus-broker.service.drv /nix/store/vayg8ddf12fz4l3y6d96236qx3i5q5fg-user-units.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/y4dm6ngg135wipcbj688iz6hkhyri063-etc.drv /nix/store/wzf538qfsl7fp5rpi320j3crcf5m9zn5-activate.drv /nix/store/9jkx3kcmh213pa6mhql36hch70vkzzlk-nixos-system-client-test.drv /nix/store/5pwzhm7kn55nzc83gwxc11nddj8lcbfr-run-client-nspawn.drv /nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv /nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/m6qklqxv9hgffzb952gkpv4wrmlhsic3-dbus-1.drv /nix/store/srhs8k87f22p13ym9xr8pam0gig3qq8y-X-Restart-Triggers-dbus-broker.drv /nix/store/bi7svq5n8495fvqzbnsqhdv2ng39244g-unit-dbus-broker.service.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/l1s9vlnmj304pph87z4dd8bkg8975bah-system-units.drv /nix/store/bibipb5v9v6mfvjvqav7bj3gr4waa65c-unit-dbus-broker.service.drv /nix/store/q293savqjiz7132195km4kd0209dhl30-user-units.drv /nix/store/b4j18rqx3h8172w5jmybvz7a8k1ybyq3-etc.drv /nix/store/brfwmk5wahln51rxq9cb693a9mkaqsq6-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/lnc4hypfkhcbdq565zn5m32f3kzi75pv-nixos-system-server-test.drv /nix/store/fq7bhahxdvn0n9z1308rr7i8xfwja0x8-run-server-nspawn.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv /nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv /nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/qd5x3hwv34zzlaxf41lrhkqixgk11viv-etc.drv /nix/store/lh98gzaiwlxpibcnapradp1l5b9ab83k-activate.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/zsr5hy159l69gnaq4x8dghf6ddnb7ydh-nixos-system-ca-test.drv /nix/store/ix4d4c1pc6n7pjn5953mzbzbr4zi0l9f-run-ca-nspawn.drv /nix/store/s8qniv8z90llaqy1qdsl4787dnk6bk49-driverConfiguration.json.drv /nix/store/g3rd9r3dv2hgbc06xsqxp4759xzc8gi2-nixos-test-driver-certificates.drv /nix/store/hnh6p5vlx79vv54iwwq98ysamkh58drb-container-test-run-certificates.drv these 3 paths will be fetched (24.4 MiB download, 75.8 MiB unpacked): /nix/store/qfjhplgaj6zn71pd29p28wxngj5l4bys-openssl-3.6.3-man /nix/store/fwwgviqhlwxaigb610fvpiciz2di7wjg-python3.14-buildcatrust-0.5.1 /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/8j7cv4bq1rrbbbci44nyw16q8vl0v30z-nginx.conf.drv' building '/nix/store/zj90w6lc85i1d1v38bkh0rrmrhcdladk-nginx.conf.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/krkpg8k1xmxf1p29pi6qrni0bnq088ka-nixos-tmpfiles.d.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/a0fjq2lmggzgmdqmw61ppvcrk0ns78lv-firewall-start.drv' building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/hx1vv9x2bvhhvsgxz8wbknybbsvqp4f0-tmpfiles.d.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' unit-acme-renew-test.foo.timer> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/5l0dhhj9lqdgym7sdhqkn96v42fsrm6j-cacert-extra-certificates-bundle.crt.drv' building '/nix/store/05l61ybxsccw6az5wkv1yr6i1znk7973-firewall-reload.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/3476w6gcm05zib3y5pqc8n5az3356nya-unit-script-nginx-pre-start.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/kp8dljswwwkqk7w5ngkh88cqwvv8vfmw-X-Restart-Triggers-systemd-tmpfiles-resetup.drv' building '/nix/store/05gw6yyrzlhj5mg2zfdp7m6ng902jxsr-cacert-blocklist.txt.drv' building '/nix/store/5hbd752ciwfvlmh3268p4nga0lzrmjrx-system-path.drv' building '/nix/store/pkdkhdijp8bly889li089chynpq5b892-system-path.drv' building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' system-path> structuredAttrs is enabled system-path> structuredAttrs is enabled unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/vvnbd6vsh6ridrkhkcq82x0a1m65d327-system-path.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/yw288val3xcd0lvrg7fj24317b904nz9-unit-firewall.service.drv' building '/nix/store/626vr6qxr75bf847lvfkg7i4bnfnpzba-unit-script-nginx-pre-start.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' system-path> created 1723 symlinks in user environment system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-test.foo.service> structuredAttrs is enabled unit-firewall.service> structuredAttrs is enabled building '/nix/store/2i94ilb4nhy3wvkklmgfkgdbs75r5pp2-ca.json.drv' building '/nix/store/a592w3ld5fsiafnmmp6rw3qyafyihjja-unit-nginx.service.drv' building '/nix/store/h92cs5q4q590p6vvaxjf9f83ashdimxp-unit-systemd-tmpfiles-resetup.service.drv' building '/nix/store/nrjvykkmy5k08dfz2nmn1bfrvkymv2ca-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/hnybad4kbrwhb7bnb2g5xa3q9p2gl48g-unit-nginx.service.drv' ca.json> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-systemd-tmpfiles-resetup.service> structuredAttrs is enabled building '/nix/store/16arw3wnvxfwlnv2d53bhy5pdnjc28vc-dbus-1.drv' building '/nix/store/5pqvjcgrdhqlib9nzimzhqrrvzpn94y3-dbus-1.drv' building '/nix/store/m6qklqxv9hgffzb952gkpv4wrmlhsic3-dbus-1.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/zawx03hrjnzcbw6iypzajm6dwaibn0zl-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/5xh262rsm3iddh9xjxb9zcj88bn081y6-X-Restart-Triggers-step-ca.drv' building '/nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv' building '/nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv' building '/nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/2zxw57qnqr355kyf6q3bv7z2hmfq2nrz-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/srhs8k87f22p13ym9xr8pam0gig3qq8y-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/cy6v9fkzdb5b6py3w1dc43qdkbl8l09g-unit-dbus-broker.service.drv' building '/nix/store/zgv7673gvv64rhqrkky8d6bndcdpqbz5-unit-dbus-broker.service.drv' building '/nix/store/jbq8qk2f3hf42ymasagwkp5q2v8f11vx-unit-step-ca.service.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/bi7svq5n8495fvqzbnsqhdv2ng39244g-unit-dbus-broker.service.drv' building '/nix/store/bibipb5v9v6mfvjvqav7bj3gr4waa65c-unit-dbus-broker.service.drv' building '/nix/store/hywyr3n8b8qx41wlkjqiwiyz5v3y3aii-unit-dbus-broker.service.drv' building '/nix/store/q9vhcd2rlwv3k7c1gxm1mpjzzm4rqmz6-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-step-ca.service> structuredAttrs is enabled building '/nix/store/3saba3kck2kq3fknpzx5k39qdnca46gh-user-units.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/q293savqjiz7132195km4kd0209dhl30-user-units.drv' building '/nix/store/vayg8ddf12fz4l3y6d96236qx3i5q5fg-user-units.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/nrjvykkmy5k08dfz2nmn1bfrvkymv2ca-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/2chq9i738qjbabhwk4gnkx2fr3bybwzy-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/2chq9i738qjbabhwk4gnkx2fr3bybwzy-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/2chq9i738qjbabhwk4gnkx2fr3bybwzy-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/bjgrx2jhq9klk5sd8i1l3ijh3fbc31cr-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/bjgrx2jhq9klk5sd8i1l3ijh3fbc31cr-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/bjgrx2jhq9klk5sd8i1l3ijh3fbc31cr-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/53qagkk89qmxfddib07zxh6prkpq0bhp-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/53qagkk89qmxfddib07zxh6prkpq0bhp-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/53qagkk89qmxfddib07zxh6prkpq0bhp-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/k6l9y25p630b9rsfsm005sr8cr6x0w88-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/k6l9y25p630b9rsfsm005sr8cr6x0w88-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/k6l9y25p630b9rsfsm005sr8cr6x0w88-nss-cacert-3.126-hashed building '/nix/store/sa16z9f2yfwzpgig43n63m6nsahsvzf5-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/23shbywhqdv186vrbcm46cd9bjskvyla-system-units.drv' building '/nix/store/iyjl8hkbg7rsjrximvsdlpsl99cphscm-system-units.drv' building '/nix/store/l1s9vlnmj304pph87z4dd8bkg8975bah-system-units.drv' building '/nix/store/qd5x3hwv34zzlaxf41lrhkqixgk11viv-etc.drv' building '/nix/store/b4j18rqx3h8172w5jmybvz7a8k1ybyq3-etc.drv' building '/nix/store/y4dm6ngg135wipcbj688iz6hkhyri063-etc.drv' building '/nix/store/lh98gzaiwlxpibcnapradp1l5b9ab83k-activate.drv' building '/nix/store/zsr5hy159l69gnaq4x8dghf6ddnb7ydh-nixos-system-ca-test.drv' building '/nix/store/brfwmk5wahln51rxq9cb693a9mkaqsq6-activate.drv' building '/nix/store/wzf538qfsl7fp5rpi320j3crcf5m9zn5-activate.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/ix4d4c1pc6n7pjn5953mzbzbr4zi0l9f-run-ca-nspawn.drv' building '/nix/store/9jkx3kcmh213pa6mhql36hch70vkzzlk-nixos-system-client-test.drv' building '/nix/store/lnc4hypfkhcbdq565zn5m32f3kzi75pv-nixos-system-server-test.drv' nixos-system-client-test> structuredAttrs is enabled nixos-system-server-test> structuredAttrs is enabled building '/nix/store/5pwzhm7kn55nzc83gwxc11nddj8lcbfr-run-client-nspawn.drv' building '/nix/store/fq7bhahxdvn0n9z1308rr7i8xfwja0x8-run-server-nspawn.drv' building '/nix/store/s8qniv8z90llaqy1qdsl4787dnk6bk49-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/g3rd9r3dv2hgbc06xsqxp4759xzc8gi2-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/hnh6p5vlx79vv54iwwq98ysamkh58drb-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/hnh6p5vlx79vv54iwwq98ysamkh58drb-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> client # [7073479.203997] client systemd-journald[69]: Journal started container-test-run-certificates> client # [7073479.204064] client systemd-journald[69]: Runtime Journal (/run/log/journal/2dd3756c428848c9b0f8c7e97b6be49f) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7073479.204939] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [7073479.208597] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7073479.213269] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7073479.213733] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7073479.214082] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7073479.217694] client systemd-journald[69]: Time spent on flushing to /var/log/journal/2dd3756c428848c9b0f8c7e97b6be49f is 1.019ms for 7 entries. container-test-run-certificates> client # [7073479.217694] client systemd-journald[69]: System Journal (/var/log/journal/2dd3756c428848c9b0f8c7e97b6be49f) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7073479.224528] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [7073479.224943] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [7073479.225011] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7073479.225500] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7073479.225527] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7073479.225877] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7073479.225894] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7073479.229593] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7073479.230624] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7073479.254706] client systemd-tmpfiles[113]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [7073479.254881] client systemd-tmpfiles[113]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7073479.254983] client systemd-tmpfiles[113]: fchmod() of /var/log/journal/2dd3756c428848c9b0f8c7e97b6be49f failed: Operation not permitted container-test-run-certificates> client # [7073479.255149] client systemd-tmpfiles[113]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [7073479.263487] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7073479.264619] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7073479.265115] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7073479.275869] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7073479.278279] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [7073479.278817] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [7073479.288226] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [7073479.313149] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [7073479.313292] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7073479.313508] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7073479.314269] client systemd[1]: Starting Network Management... container-test-run-certificates> client # [7073479.428771] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7073479.628818] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7073479.628936] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7073479.636810] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7073479.637006] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7073479.637173] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7073479.637179] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7073479.637405] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7073479.637924] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7073479.638012] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7073479.638199] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7073479.639239] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [7073479.667508] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7073479.210591] server systemd-journald[69]: Journal started container-test-run-certificates> ca # [7073479.212361] ca systemd-journald[78]: Journal started container-test-run-certificates> server # [7073479.210620] server systemd-journald[69]: Runtime Journal (/run/log/journal/46679bdf626e40d2a66012b781417d38) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [7073479.212387] ca systemd-journald[78]: Runtime Journal (/run/log/journal/eabb4d40ae4f4c9aa1d24b5677c73bad) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> server # [7073479.213362] server systemd[1]: Listening on Journal Log Access Socket. container-test-run-certificates> ca # [7073479.215476] ca systemd[1]: Listening on Journal Log Access Socket. container-test-run-certificates> server # [7073479.213568] server systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [7073479.215668] ca systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> server # [7073479.219553] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7073479.223175] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7073479.230006] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [7073479.228142] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [7073479.230455] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7073479.228746] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [7073479.230784] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [7073479.229239] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7073479.234716] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/eabb4d40ae4f4c9aa1d24b5677c73bad is 1.090ms for 8 entries. container-test-run-certificates> ca # [7073479.234716] ca systemd-journald[78]: System Journal (/var/log/journal/eabb4d40ae4f4c9aa1d24b5677c73bad) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [7073479.232992] server systemd-journald[69]: Time spent on flushing to /var/log/journal/46679bdf626e40d2a66012b781417d38 is 1.422ms for 8 entries. container-test-run-certificates> ca # [7073479.247395] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7073479.232992] server systemd-journald[69]: System Journal (/var/log/journal/46679bdf626e40d2a66012b781417d38) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7073479.247933] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7073479.244817] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7073479.247988] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [7073479.245360] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7073479.248449] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7073479.245420] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7073479.248476] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7073479.245922] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7073479.263267] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [7073479.245956] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7073479.263315] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7073479.246406] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7073479.263785] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7073479.246423] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7073479.264963] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7073479.263292] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7073479.278563] ca systemd-tmpfiles[140]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7073479.264696] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7073479.278725] ca systemd-tmpfiles[140]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7073479.280421] server systemd-tmpfiles[136]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7073479.278833] ca systemd-tmpfiles[140]: fchmod() of /var/log/journal/eabb4d40ae4f4c9aa1d24b5677c73bad failed: Operation not permitted container-test-run-certificates> server # [7073479.280584] server systemd-tmpfiles[136]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7073479.278998] ca systemd-tmpfiles[140]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7073479.280686] server systemd-tmpfiles[136]: fchmod() of /var/log/journal/46679bdf626e40d2a66012b781417d38 failed: Operation not permitted container-test-run-certificates> ca # [7073479.280278] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7073479.280841] server systemd-tmpfiles[136]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7073479.281387] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7073479.282370] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [7073479.281893] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7073479.283438] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7073479.290066] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7073479.284185] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> ca # [7073479.295611] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7073479.294200] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7073479.296297] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7073479.299733] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7073479.302219] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7073479.300399] server systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7073479.323579] ca systemd[1]: Finished Firewall. container-test-run-certificates> server # [7073479.308214] server systemd[1]: Finished Update is Completed. container-test-run-certificates> ca # [7073479.323720] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [7073479.323727] server systemd[1]: Finished Firewall. container-test-run-certificates> ca # [7073479.323928] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [7073479.323875] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7073479.325033] ca systemd[1]: Starting Network Management... container-test-run-certificates> server # [7073479.324119] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7073479.427261] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [7073479.325209] server systemd[1]: Starting Network Management... container-test-run-certificates> ca # [7073479.665369] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7073479.428067] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7073479.665483] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7073479.672885] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7073479.673086] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7073479.673209] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7073479.673215] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7073479.673467] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7073479.673800] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7073479.673862] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [7073479.674512] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7073479.674838] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7073479.705385] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [7073479.802332] ca systemd-resolved[106]: Positive Trust Anchors: container-test-run-certificates> ca # [7073479.802350] ca systemd-resolved[106]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7073479.802358] ca systemd-resolved[106]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7073479.802384] ca systemd-resolved[106]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7073479.815520] ca systemd-resolved[106]: Using system hostname 'ca'. container-test-run-certificates> ca # [7073479.816516] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7073479.816579] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7073479.816619] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7073479.816654] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7073479.816808] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7073479.816834] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7073479.816851] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7073479.816862] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7073479.816952] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7073479.817027] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7073479.817104] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7073479.817116] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7073479.817138] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7073479.817952] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7073479.818435] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7073479.818457] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7073479.818935] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7073479.819447] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7073479.836225] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> ca # [7073479.846586] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7073479.910257] ca acme-setup-privileged[201]: + set -euo pipefail container-test-run-certificates> ca # [7073479.910257] ca acme-setup-privileged[201]: + cd /var/lib/acme container-test-run-certificates> ca # [7073479.910257] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7073479.910984] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7073479.911765] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7073479.911799] ca acme-setup-privileged[201]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7073479.911799] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7073479.911799] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7073479.930596] ca nsncd[203]: Aug 21 06:52:17.296 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7073479.930664] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7073479.930718] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7073479.930759] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7073479.746504] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7073479.746591] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7073479.751999] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7073479.752145] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7073479.752231] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7073479.752234] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7073479.752388] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7073479.752661] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7073479.752717] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7073479.752878] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7073479.753376] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7073479.782241] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7073479.839563] server systemd-resolved[99]: Positive Trust Anchors: container-test-run-certificates> server # [7073479.839572] server systemd-resolved[99]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7073479.839575] server systemd-resolved[99]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7073479.839602] server systemd-resolved[99]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7073479.851629] server systemd-resolved[99]: Using system hostname 'server'. container-test-run-certificates> server # [7073479.852727] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7073479.852781] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7073479.852814] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7073479.852847] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7073479.852989] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7073479.853017] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7073479.853030] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7073479.853042] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7073479.853135] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7073479.853218] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7073479.853307] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7073479.853323] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7073479.853347] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7073479.854177] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7073479.854511] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7073479.854529] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7073479.854878] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7073479.855503] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7073479.865230] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7073479.905291] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [7073479.905291] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [7073479.905574] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [7073479.906068] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7073479.906863] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7073479.906900] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [7073479.906900] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7073479.906900] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [7073479.934713] server nsncd[194]: Aug 21 06:52:17.300 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7073479.934820] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [7073479.934887] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [7073479.934934] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7073479.935857] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7073479.936350] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7073479.941884] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7073479.942499] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7073479.942528] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7073479.942543] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7073480.048969] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7073480.049546] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7073480.049546] server dbus-broker-launch[195]: Invalid user-name in /nix/store/i07ax2azh137q21v82w3q45c0js9fly3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7073479.925315] client systemd-resolved[92]: Positive Trust Anchors: container-test-run-certificates> client # [7073479.925327] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7073479.925332] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7073479.925349] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7073479.938162] client systemd-resolved[92]: Using system hostname 'client'. container-test-run-certificates> client # [7073479.939254] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7073479.939332] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7073479.939385] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7073479.939434] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7073479.939457] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7073479.939469] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7073479.939582] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7073479.939674] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7073479.939771] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7073479.939785] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7073479.939813] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7073479.940894] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7073479.941495] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7073479.942343] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [7073479.952548] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [7073480.047174] client nsncd[189]: Aug 21 06:52:17.412 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7073480.047267] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7073480.047335] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7073480.047383] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7073480.048434] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7073480.048950] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7073480.071497] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7073480.072332] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7073480.072359] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7073480.072372] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7073480.124613] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7073480.125173] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7073480.125173] client dbus-broker-launch[190]: Invalid user-name in /nix/store/5pivbx8np0dpzpvygn9yh82mv02g42s5-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7073480.125588] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7073480.129214] client dbus-broker-launch[190]: Ready container-test-run-certificates> client # [7073480.195761] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7073479.931638] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7073479.932073] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7073479.939281] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7073479.940636] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7073479.940673] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [7073479.940686] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7073480.050672] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7073480.051694] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7073480.051694] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/i5waaswaym40wgzzl0nm5vgqy7ksmgqs-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7073480.051444] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7073480.055215] ca dbus-broker-launch[205]: Ready container-test-run-certificates> ca # [7073480.208231] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7073480.049925] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7073480.054178] server dbus-broker-launch[195]: Ready container-test-run-certificates> server # [7073480.203591] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7073480.361524] ca systemd-logind[230]: New seat seat0. container-test-run-certificates> ca # [7073480.361689] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7073480.368344] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7073480.369271] ca acme-setup-start[219]: + set -euo pipefail container-test-run-certificates> ca # [7073480.369451] ca acme-setup-start[219]: + test -e ca/key.pem container-test-run-certificates> ca # [7073480.369451] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7073480.376600] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7073480.376857] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7073480.376902] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7073480.378682] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> server # [7073480.343627] server systemd-logind[224]: New seat seat0. container-test-run-certificates> server # [7073480.343763] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7073480.344847] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7073480.367337] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [7073480.367337] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [7073480.367624] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7073480.374421] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7073480.374763] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7073480.374840] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [7073480.376092] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [7073480.523409] ca step-ca[204]: badger 2026/08/21 06:52:17 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7073480.525418] ca step-ca[204]: 2026/08/21 06:52:17 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7073480.527808] ca step-ca[204]: 2026/08/21 06:52:17 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [7073480.527808] ca step-ca[204]: 2026/08/21 06:52:17 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7073480.527808] ca step-ca[204]: 2026/08/21 06:52:17 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7073480.527856] ca step-ca[204]: 2026/08/21 06:52:17 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7073480.527856] ca step-ca[204]: 2026/08/21 06:52:17 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7073480.527856] ca step-ca[204]: 2026/08/21 06:52:17 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7073480.527856] ca step-ca[204]: 2026/08/21 06:52:17 X.509 Root Fingerprint: 8f791a8e9aa3e1383375820291f03d0c59adbdb0533fafb596c3a49a5860a708 container-test-run-certificates> ca # [7073480.527949] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7073480.528014] ca step-ca[204]: 2026/08/21 06:52:17 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [7073480.459497] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [7073480.459648] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [7073480.460466] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7073480.492243] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7073480.492387] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7073480.492713] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7073480.492833] client systemd[1]: Startup finished in 1.557s. container-test-run-certificates> ca # [7073480.817108] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7073480.818695] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7073480.818732] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7073480.823354] ca acme-ca.foo-start[283]: + cd ca.foo container-test-run-certificates> ca # [7073480.823638] ca acme-ca.foo-start[283]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7073480.824350] ca acme-ca.foo-start[284]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7073480.824504] ca acme-ca.foo-start[283]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7073480.825545] ca acme-ca.foo-start[283]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7073480.825678] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7073480.826640] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7073480.827492] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7073480.828345] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7073480.828363] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [7073480.828363] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7073480.829342] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [7073480.831169] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7073480.831169] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [7073480.832919] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7073480.833868] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [7073480.748852] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7073480.750135] server acme-test.foo-start[244]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7073480.750172] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7073480.754725] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [7073480.754878] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7073480.755619] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7073480.755725] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7073480.756322] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7073480.756434] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7073480.757211] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7073480.757937] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7073480.758675] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7073480.758696] server acme-test.foo-start[244]: + '[' -d out ']' container-test-run-certificates> server # [7073480.758696] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7073480.759409] server acme-test.foo-start[244]: + chown -R acme:nginx out container-test-run-certificates> server # [7073480.761093] server acme-test.foo-start[244]: + for fixpath in out certificates container-test-run-certificates> server # [7073480.761093] server acme-test.foo-start[244]: + '[' -d certificates ']' container-test-run-certificates> server # [7073480.762985] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7073480.763906] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [7073481.149355] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> server # [7073481.132670] server nginx-pre-start[266]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [7073481.133122] server nginx-pre-start[266]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [7073481.139313] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7073481.139657] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [7073481.140579] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7073481.254409] ca nginx-pre-start[295]: nginx: the configuration file /nix/store/1zya8130szardq7b35zp58jlj3jil439-nginx.conf syntax is ok container-test-run-certificates> ca # [7073481.254796] ca nginx-pre-start[295]: nginx: configuration file /nix/store/1zya8130szardq7b35zp58jlj3jil439-nginx.conf test is successful container-test-run-certificates> ca # [7073481.257923] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7073481.258191] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7073481.258850] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [7073481.470090] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [7073481.536143] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7073481.537820] server acme-order-renew-test.foo-start[269]: + set -euo pipefail container-test-run-certificates> server # [7073481.537877] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7073481.537910] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7073481.538587] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7073481.547208] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:18 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7073481.547382] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:18 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [7073481.726064] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7073481.628163] ca acme-order-renew-ca.foo-start[298]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7073481.629843] ca acme-order-renew-ca.foo-start[298]: + set -euo pipefail container-test-run-certificates> ca # [7073481.629884] ca acme-order-renew-ca.foo-start[298]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7073481.629938] ca acme-order-renew-ca.foo-start[298]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7073481.630623] ca acme-order-renew-ca.foo-start[298]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7073481.638476] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7073481.638680] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7073481.649982] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration="75.042µs" duration-ns=75042 fields.time="2026-08-21T06:52:19Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9d4e63f8-98e7-4f8b-bf5f-54074b0c7c2b response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.650212] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7073481.655592] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration=5.375083ms duration-ns=5375083 fields.time="2026-08-21T06:52:19Z" method=HEAD name=ca nonce=N0hzNldtMXRxdFNTWW5OWGl4Wm9sNXRJVUtFYTkwc3g path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=db471628-6fbf-4830-b2d8-a2f355a44dfe size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.656710] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration="810.166µs" duration-ns=810166 fields.time="2026-08-21T06:52:19Z" method=POST name=ca nonce=SWxBT2R0dllVbDJPYXpHNU5JS2lBWUlXMG9GYnFQdWE path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b60f2ba5-a4ad-46a9-96ee-f0fc04af889b response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/dkeft0LUu4CTrNhQCewCYOv71LSEuaNv/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: Your account credentials have been saved in your container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: configuration directory at "accounts". container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: configuration directory will also contain private keys container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7073481.656817] ca acme-order-renew-ca.foo-start[310]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7073481.656888] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7073481.658366] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration=1.356986ms duration-ns=1356986 fields.time="2026-08-21T06:52:19Z" method=POST name=ca nonce=SDI2c1I4TDNjWHBLR3FUNFhsYmlQNXhqRWp4RTdSRUk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=15b94d41-69f6-4c88-b161-81df8e38d105 response="{\"id\":\"8ztu6NqxSTBkFSQ9AXdsl97fdbisNzkB\",\"status\":\"pending\",\"expires\":\"2026-08-22T06:52:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-21T06:51:19Z\",\"notAfter\":\"2026-11-19T06:52:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/8ztu6NqxSTBkFSQ9AXdsl97fdbisNzkB/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.715365] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration="591.494µs" duration-ns=591494 fields.time="2026-08-21T06:52:19Z" method=POST name=ca nonce=NkV4dzFFOHp0ODdMTkppb2VhUUZSN3J1Y2xLNUtjWlI path=/acme/acme/authz/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9d9a0d42-2adb-4977-b928-f594eb2804a8 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"GaiB9LQep3Kq2aqlDUCq1tXpDZepRxAb\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq/Lfk3nZTS9tPVULgrhKLsZBzh7pU5lR6g\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"GaiB9LQep3Kq2aqlDUCq1tXpDZepRxAb\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq/bJMlwVCgw8jt9P2fgTcXvPnaFlfzzMSY\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"GaiB9LQep3Kq2aqlDUCq1tXpDZepRxAb\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq/Qaq7TTg0GSBjPvjMEdPUlCVShkuAoH61\"}],\"wildcard\":false,\"expires\":\"2026-08-22T06:52:19Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.715485] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq container-test-run-certificates> ca # [7073481.715485] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7073481.715485] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7073481.715566] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7073481.717200] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration=1.524972ms duration-ns=1524972 fields.time="2026-08-21T06:52:19Z" method=POST name=ca nonce=UnVTOHVuc0VWWks0TW5iVDhFbDd1RGNMWUlQTXNNU0U path=/acme/acme/challenge/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq/bJMlwVCgw8jt9P2fgTcXvPnaFlfzzMSY protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=abc3ed9a-a3fb-4eba-9b72-c2d22a1fa42e response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"GaiB9LQep3Kq2aqlDUCq1tXpDZepRxAb\",\"validated\":\"2026-08-21T06:52:19Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq/bJMlwVCgw8jt9P2fgTcXvPnaFlfzzMSY\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.717383] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7073481.717421] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7073481.719650] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info duration=1.924635ms duration-ns=1924635 fields.time="2026-08-21T06:52:19Z" method=POST name=ca nonce=MlVoT3dVSlRIWnpBQ1JQZkhvQkV0R21kYzRiUWNDdkw path=/acme/acme/order/8ztu6NqxSTBkFSQ9AXdsl97fdbisNzkB/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2e08a425-26b8-4eac-b3e6-dcd32aebeacd response="{\"id\":\"8ztu6NqxSTBkFSQ9AXdsl97fdbisNzkB\",\"status\":\"valid\",\"expires\":\"2026-08-22T06:52:19Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-21T06:51:19Z\",\"notAfter\":\"2026-11-19T06:52:19Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/mCL28O0j1SjWHo7GtWmK4ncU5VzXgacq\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/8ztu6NqxSTBkFSQ9AXdsl97fdbisNzkB/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/bmzRakyISsM9FDA1KHEiri1AoRfR9U6H\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073481.720423] ca step-ca[204]: time="2026-08-21T06:52:19Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRANbgVi6kNlP8I+QwzfSmGKkwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODIxMDY1MTE5WhcNMjYxMTE5MDY1MjE5WjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAST0PTHW6WJpQWg/+JpFuBP0jLRBhHMeAwe37GBZRch328IBqvalC1CIFQc8O2JQ1r+f9PH1Ziv9Fh+j2CUbXlfo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFLGkDAYoPVZRCr1nJ4+SJmCSA7+JMB8GA1UdIwQYMBaAFPSoIVQwLInrPQwpHuepfaWUFEzPMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgHJ2pGr+d/KfczAKE5G7FteNmg01p+BUJuRESdgQLTJUCIQCulZY62ga3k3xlu65UyMRtisuHjTZwJxXr1LG9XnHxkw==" duration="520.07µs" duration-ns=520070 fields.time="2026-08-21T06:52:19Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=QXpnVVB2U2w2YXpsMGo0ckkzMk1vbjd4cUYwaERTUjk path=/acme/acme/certificate/bmzRakyISsM9FDA1KHEiri1AoRfR9U6H protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=1f4d2974-df49-4b6e-9cb6-5c17f2efe4af sans="map[dns:[ca.foo]]" serial=285619613576826408102565142593177786537 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-21T06:51:19Z" valid-to="2026-11-19T06:52:19Z" container-test-run-certificates> ca # [7073481.720503] ca acme-order-renew-ca.foo-start[310]: 2026/08/21 06:52:19 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7073481.722785] ca acme-order-renew-ca.foo-start[298]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7073481.723990] ca acme-order-renew-ca.foo-start[298]: + touch out/acme-success container-test-run-certificates> ca # [7073481.724776] ca acme-order-renew-ca.foo-start[298]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7073481.725363] ca acme-order-renew-ca.foo-start[298]: + touch out/renewed container-test-run-certificates> ca # [7073481.726116] ca acme-order-renew-ca.foo-start[298]: + echo Installing new certificate container-test-run-certificates> ca # [7073481.726116] ca acme-order-renew-ca.foo-start[298]: Installing new certificate container-test-run-certificates> ca # [7073481.726135] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7073481.726962] ca acme-order-renew-ca.foo-start[330]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7073481.727093] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7073481.727929] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7073481.728110] ca acme-order-renew-ca.foo-start[298]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7073481.728812] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7073481.728927] ca acme-order-renew-ca.foo-start[298]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7073481.729808] ca acme-order-renew-ca.foo-start[298]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7073481.730645] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7073481.730656] ca acme-order-renew-ca.foo-start[298]: + '[' -d out ']' container-test-run-certificates> ca # [7073481.730656] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7073481.731657] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx out container-test-run-certificates> ca # [7073481.732988] ca acme-order-renew-ca.foo-start[298]: + for fixpath in out certificates container-test-run-certificates> ca # [7073481.733004] ca acme-order-renew-ca.foo-start[298]: + '[' -d certificates ']' container-test-run-certificates> ca # [7073481.733004] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7073481.733786] ca acme-order-renew-ca.foo-start[298]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7073481.735080] ca acme-order-renew-ca.foo-start[298]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7073481.805360] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [7073481.807371] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7073481.807478] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [7073482.148542] ca nginx[348]: nginx: the configuration file /nix/store/1zya8130szardq7b35zp58jlj3jil439-nginx.conf syntax is ok container-test-run-certificates> ca # [7073482.148705] ca nginx[348]: nginx: configuration file /nix/store/1zya8130szardq7b35zp58jlj3jil439-nginx.conf test is successful container-test-run-certificates> ca # [7073482.473216] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7073482.473382] ca systemd[1]: Startup finished in 3.526s. container-test-run-certificates> ca # [7073482.811463] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 1.59 seconds) container-test-run-certificates> ca # [7073483.150338] ca acme-order-renew-ca.foo-start[363]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7073483.152093] ca acme-order-renew-ca.foo-start[363]: + set -euo pipefail container-test-run-certificates> ca # [7073483.152126] ca acme-order-renew-ca.foo-start[363]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7073483.152175] ca acme-order-renew-ca.foo-start[363]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7073483.152960] ca acme-order-renew-ca.foo-start[363]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7073483.152960] ca acme-order-renew-ca.foo-start[363]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7073483.153232] ca acme-order-renew-ca.foo-start[371]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7073483.154628] ca acme-order-renew-ca.foo-start[363]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7073483.154677] ca acme-order-renew-ca.foo-start[363]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7073483.173055] ca step-ca[204]: time="2026-08-21T06:52:20Z" level=info duration="41.328µs" duration-ns=41328 fields.time="2026-08-21T06:52:20Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7d93e0a4-408b-49a4-9de6-a466a90d7a48 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073483.173287] ca acme-order-renew-ca.foo-start[372]: 2026/08/21 06:52:20 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7073483.173287] ca acme-order-renew-ca.foo-start[372]: 2026/08/21 06:52:20 [INFO] [ca.foo] The certificate expires at 2026-11-19T06:52:19Z, the renewal can be performed in 1439h59m38.461118056s: no renewal. container-test-run-certificates> ca # [7073483.173405] ca acme-order-renew-ca.foo-start[363]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7073483.174628] ca acme-order-renew-ca.foo-start[363]: + touch out/acme-success container-test-run-certificates> ca # [7073483.175419] ca acme-order-renew-ca.foo-start[363]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7073483.176038] ca acme-order-renew-ca.foo-start[363]: + for fixpath in out certificates container-test-run-certificates> ca # [7073483.176048] ca acme-order-renew-ca.foo-start[363]: + '[' -d out ']' container-test-run-certificates> ca # [7073483.176048] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7073483.176851] ca acme-order-renew-ca.foo-start[363]: + chown -R acme:nginx out container-test-run-certificates> ca # [7073483.178220] ca acme-order-renew-ca.foo-start[363]: + for fixpath in out certificates container-test-run-certificates> ca # [7073483.178238] ca acme-order-renew-ca.foo-start[363]: + '[' -d certificates ']' container-test-run-certificates> ca # [7073483.178238] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7073483.179147] ca acme-order-renew-ca.foo-start[363]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7073483.180451] ca acme-order-renew-ca.foo-start[363]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7073483.262455] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7073483.262548] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server: still waiting for container 'server' to reach ready state... container-test-run-certificates> server: still waiting for container 'server' to reach ready state... container-test-run-certificates> ca # [7073512.562594] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration="35.677µs" duration-ns=35677 fields.time="2026-08-21T06:52:49Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=a00081be-3acc-4a33-bef3-9944a3f15a47 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.564369] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration="446.221µs" duration-ns=446221 fields.time="2026-08-21T06:52:49Z" method=HEAD name=ca nonce=RDM5MzE5Q2hEbjdjaGNQbW9nanJvV285N1hoamxzNWk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=870170be-d3a8-4c90-be8f-c54242a5576d size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.565986] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration="738.431µs" duration-ns=738431 fields.time="2026-08-21T06:52:49Z" method=POST name=ca nonce=bFNLYWdraDY1YUN3MURXVUp0bGEzZ3BGak56a0dFZDU path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=3ce2ce30-c119-4bf9-8ea3-0a092cfe631d response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/fmeFg3gKOcQLSE1cEPwoo4Hoc1xTyce3/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.568311] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration=1.283838ms duration-ns=1283838 fields.time="2026-08-21T06:52:49Z" method=POST name=ca nonce=VFo3NnMxME5tZXdaM0xpV1FCREFnR3owVWFvYUt0R1U path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=dbded11e-c22a-4126-9d48-ed37f4e47135 response="{\"id\":\"1rE6hJ1ybwUA87SYv4e9tLxPrgYowUPP\",\"status\":\"pending\",\"expires\":\"2026-08-22T06:52:49Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-21T06:51:49Z\",\"notAfter\":\"2026-11-19T06:52:49Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq\"],\"finalize\":\"https://ca.foo/acme/acme/order/1rE6hJ1ybwUA87SYv4e9tLxPrgYowUPP/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.626429] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration="647.39µs" duration-ns=647390 fields.time="2026-08-21T06:52:49Z" method=POST name=ca nonce=a21OZ0huQlJZeEM0TTVlVGk4NzN4dUVWQldlemRibDM path=/acme/acme/authz/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq protocol=HTTP/1.1 referer= remote-address="::1" request-id=aeb9e70d-b57c-4567-8d99-7fcf28e6d50e response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"ySPKHiu5iMUgVYEn8PCaI0Q90SRpEon6\",\"url\":\"https://ca.foo/acme/acme/challenge/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq/3I55UovTHzjBMIrm3xJBf4j02tffIkCe\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"ySPKHiu5iMUgVYEn8PCaI0Q90SRpEon6\",\"url\":\"https://ca.foo/acme/acme/challenge/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq/H4wGgfQ85MswrcJFVC5Z4Bc5M6y8wLy1\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"ySPKHiu5iMUgVYEn8PCaI0Q90SRpEon6\",\"url\":\"https://ca.foo/acme/acme/challenge/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq/Di5pGGhJpM7ylHxCBH5cULt3mzLwZusO\"}],\"wildcard\":false,\"expires\":\"2026-08-22T06:52:49Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.628994] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration=1.526755ms duration-ns=1526755 fields.time="2026-08-21T06:52:49Z" method=POST name=ca nonce=QVA5N09MR1NWWHByajJEWE9ZMVhDT2hZRHhlb3BFb3o path=/acme/acme/challenge/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq/H4wGgfQ85MswrcJFVC5Z4Bc5M6y8wLy1 protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1d7bc213-5ea1-4b9b-a70d-f0506bf26057 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"ySPKHiu5iMUgVYEn8PCaI0Q90SRpEon6\",\"validated\":\"2026-08-21T06:52:49Z\",\"url\":\"https://ca.foo/acme/acme/challenge/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq/H4wGgfQ85MswrcJFVC5Z4Bc5M6y8wLy1\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.631940] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info duration=1.846117ms duration-ns=1846117 fields.time="2026-08-21T06:52:49Z" method=POST name=ca nonce=QllYWDRBQVBBUnRPTFlxMkFYZ3JqekUxV3h6TlBCSEw path=/acme/acme/order/1rE6hJ1ybwUA87SYv4e9tLxPrgYowUPP/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=04bf2c1c-4b58-4383-a5ee-c2607063674f response="{\"id\":\"1rE6hJ1ybwUA87SYv4e9tLxPrgYowUPP\",\"status\":\"valid\",\"expires\":\"2026-08-22T06:52:49Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-21T06:51:49Z\",\"notAfter\":\"2026-11-19T06:52:49Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq\"],\"finalize\":\"https://ca.foo/acme/acme/order/1rE6hJ1ybwUA87SYv4e9tLxPrgYowUPP/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/uUTXGJUPooJwaJL08hIaTkNJblLvOGFp\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7073512.633088] ca step-ca[204]: time="2026-08-21T06:52:49Z" level=info certificate="MIIB1zCCAX2gAwIBAgIQZAYTp0ZR+5neqy6NUya8rzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjEwNjUxNDlaFw0yNjExMTkwNjUyNDlaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE0ZOWQiq633Bx/DJI1MLC8Skb+FXEGqVmo3l3qHrWVkt0bQcLrX6eL0uoRh0NtdYquqbAR6GaeT23yvaGvd6QsaOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBQDpJG4Z7A6XN4DnrKr2xbsNuTAWTAfBgNVHSMEGDAWgBT0qCFUMCyJ6z0MKR7nqX2llBRMzzATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgLpHVW2w8DyyzGy0ZgPoikcnCsMYR+x+7xvcyo+MosZECIQDjRFTJzNaHPKkqfBxQy0Wr09dn4Fr0IN0oRhCibdQxBw==" duration="416.695µs" duration-ns=416695 fields.time="2026-08-21T06:52:49Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=T202dFlOeHg5a3pvVUZVUnZ4M2pQZzVMbndYMExjekU path=/acme/acme/certificate/uUTXGJUPooJwaJL08hIaTkNJblLvOGFp protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=cd7bd3f9-7944-4964-8d45-4ea9c1f9f024 sans="map[dns:[test.foo]]" serial=132954351978291467351301274739977665711 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-21T06:51:49Z" valid-to="2026-11-19T06:52:49Z" container-test-run-certificates> server # [7073512.562862] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: Your account credentials have been saved in your container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: configuration directory at "accounts". container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: configuration directory will also contain private keys container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7073512.566207] server acme-order-renew-test.foo-start[281]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7073512.566348] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [7073512.626665] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/fWhXCYBHuxGnXCLPdFTixiVsVEtsoImq container-test-run-certificates> server # [7073512.626665] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7073512.626665] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7073512.626665] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7073512.629196] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7073512.629261] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7073512.633212] server acme-order-renew-test.foo-start[281]: 2026/08/21 06:52:49 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7073512.635459] server acme-order-renew-test.foo-start[269]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7073512.636616] server acme-order-renew-test.foo-start[269]: + touch out/acme-success container-test-run-certificates> server # [7073512.637508] server acme-order-renew-test.foo-start[269]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7073512.638058] server acme-order-renew-test.foo-start[269]: + touch out/renewed container-test-run-certificates> server # [7073512.638753] server acme-order-renew-test.foo-start[269]: + echo Installing new certificate container-test-run-certificates> server # [7073512.638753] server acme-order-renew-test.foo-start[269]: Installing new certificate container-test-run-certificates> server # [7073512.638788] server acme-order-renew-test.foo-start[269]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7073512.639473] server acme-order-renew-test.foo-start[303]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7073512.639594] server acme-order-renew-test.foo-start[269]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7073512.640293] server acme-order-renew-test.foo-start[304]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7073512.640408] server acme-order-renew-test.foo-start[269]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7073512.641086] server acme-order-renew-test.foo-start[305]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7073512.641194] server acme-order-renew-test.foo-start[269]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7073512.641970] server acme-order-renew-test.foo-start[269]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7073512.642839] server acme-order-renew-test.foo-start[269]: + for fixpath in out certificates container-test-run-certificates> server # [7073512.642866] server acme-order-renew-test.foo-start[269]: + '[' -d out ']' container-test-run-certificates> server # [7073512.642866] server acme-order-renew-test.foo-start[269]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7073512.643632] server acme-order-renew-test.foo-start[269]: + chown -R acme:nginx out container-test-run-certificates> server # [7073512.645150] server acme-order-renew-test.foo-start[269]: + for fixpath in out certificates container-test-run-certificates> server # [7073512.645164] server acme-order-renew-test.foo-start[269]: + '[' -d certificates ']' container-test-run-certificates> server # [7073512.645164] server acme-order-renew-test.foo-start[269]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7073512.645964] server acme-order-renew-test.foo-start[269]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7073512.647407] server acme-order-renew-test.foo-start[269]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7073512.722993] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7073512.724914] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7073512.725032] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7073513.079521] server nginx[321]: nginx: the configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf syntax is ok container-test-run-certificates> server # [7073513.079703] server nginx[321]: nginx: configuration file /nix/store/wkxz4hka5qs8dgkzynp4dx3grs3s3mw2-nginx.conf test is successful container-test-run-certificates> server # [7073513.438855] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> server # [7073513.439082] server systemd[1]: Startup finished in 34.504s. container-test-run-certificates> server # [7073513.906356] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7073513.906457] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7073513.907073] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7073513.907969] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 28.03 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [931 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [80 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 21 06:51:49 2026 GMT container-test-run-certificates> * expire date: Nov 19 06:52:49 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 50494 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1577 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 0.02 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 64:06:13:a7:46:51:fb:99:de:ab:2e:8d:53:26:bc:af container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 21 06:51:49 2026 GMT container-test-run-certificates> Not After : Nov 19 06:52:49 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:d1:93:96:42:2a:ba:df:70:71:fc:32:48:d4:c2: container-test-run-certificates> c2:f1:29:1b:f8:55:c4:1a:a5:66:a3:79:77:a8:7a: container-test-run-certificates> d6:56:4b:74:6d:07:0b:ad:7e:9e:2f:4b:a8:46:1d: container-test-run-certificates> 0d:b5:d6:2a:ba:a6:c0:47:a1:9a:79:3d:b7:ca:f6: container-test-run-certificates> 86:bd:de:90:b1 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 03:A4:91:B8:67:B0:3A:5C:DE:03:9E:B2:AB:DB:16:EC:36:E4:C0:59 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> F4:A8:21:54:30:2C:89:EB:3D:0C:29:1E:E7:A9:7D:A5:94:14:4C:CF container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:45:02:20:2e:91:d5:5b:6c:3c:0f:2c:b3:1b:2d:19:80:fa: container-test-run-certificates> 22:91:c9:c2:b0:c6:11:fb:1f:bb:c6:f7:32:a3:e3:28:b1:91: container-test-run-certificates> 02:21:00:e3:44:54:c9:cc:d6:87:3c:a9:2a:7c:1c:50:cb:45: container-test-run-certificates> ab:d3:d7:67:e0:5a:f4:20:dd:28:46:10:a2:6d:d4:31:07 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 35.67 seconds) container-test-run-certificates> test script finished in 35.72s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.24 seconds) post-build step Upload to niks3: ok time=2026-08-21T06:52:52.308Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-21T06:52:52.622Z level=INFO msg="Uploading 1 narinfos" time=2026-08-21T06:52:52.835Z level=INFO msg="Upload complete. (581ms)"