container-test-run-certificates
checks.aarch64-linux.certificates
· build #462
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 52)13ca: Waiting for journal at /build/vm-state-ca/var/log/journal...14server: systemd-nspawn running (pid 55)15client: systemd-nspawn running (pid 56)16server: Waiting for journal at /build/vm-state-server/var/log/journal...17client: Waiting for journal at /build/vm-state-client/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container ca on /build/vm-state-ca.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container server on /build/vm-state-server.31ca # [6500611.861316] ca systemd-journald[78]: Journal started32ca # [6500611.861381] ca systemd-journald[78]: Runtime Journal (/run/log/journal/2a921ad8cd154f2989f75d2fd5cf3562) is 8M, max 2.5G, 2.4G free.33ca # [6500611.869281] ca systemd[1]: Starting Flush Journal to Persistent Storage...34ca # [6500611.870065] ca systemd[1]: Starting Network Name Resolution...35ca # [6500611.871091] ca systemd[1]: Starting Create Static Device Nodes in /dev...36ca # [6500611.880106] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562 is 1.589ms for 5 entries.37ca # [6500611.880106] ca systemd-journald[78]: System Journal (/var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562) is 8M, max 4G, 3.9G free.38ca # [6500611.889459] ca systemd[1]: Finished Create Static Device Nodes in /dev.39ca # [6500611.890654] ca systemd[1]: Reached target Preparation for Local File Systems.40ca # [6500611.890769] ca systemd[1]: Reached target Local File Systems.41ca # [6500611.891591] ca systemd[1]: Listening on Boot Loader Control Service Socket.42ca # [6500611.891638] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container43ca # [6500611.892919] ca systemd[1]: Starting Save Transient machine-id to Disk...44ca # [6500611.892969] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys45ca # [6500611.900946] ca systemd[1]: Finished Flush Journal to Persistent Storage.46ca # [6500611.903444] ca systemd[1]: Starting Create System Files and Directories...47ca # [6500611.917696] ca systemd-tmpfiles[123]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted48ca # [6500611.917913] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal failed: Operation not permitted49ca # [6500611.918061] ca systemd-tmpfiles[123]: fchmod() of /var/log/journal/2a921ad8cd154f2989f75d2fd5cf3562 failed: Operation not permitted50ca # [6500611.918278] ca systemd-tmpfiles[123]: fchmod() of /run/log/journal failed: Operation not permitted51ca # [6500611.919931] ca systemd[1]: Finished Create System Files and Directories.52ca # [6500611.920948] ca systemd[1]: Starting Rebuild Journal Catalog...53ca # [6500611.921627] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...54ca # [6500611.928097] ca systemd[1]: Finished Save Transient machine-id to Disk.55ca # [6500611.932993] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.56ca # [6500611.940185] ca systemd[1]: Finished Rebuild Journal Catalog.57ca # [6500611.941636] ca systemd[1]: Starting Update is Completed...58ca # [6500611.951788] ca systemd[1]: Finished Update is Completed.59server # [6500611.857405] server systemd-journald[69]: Journal started60server # [6500611.857466] server systemd-journald[69]: Runtime Journal (/run/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c) is 8M, max 2.5G, 2.4G free.61server # [6500611.864803] server systemd[1]: Starting Flush Journal to Persistent Storage...62server # [6500611.865573] server systemd[1]: Starting Network Name Resolution...63server # [6500611.866267] server systemd[1]: Starting Create Static Device Nodes in /dev...64server # [6500611.873572] server systemd-journald[69]: Time spent on flushing to /var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c is 1.602ms for 5 entries.65server # [6500611.873572] server systemd-journald[69]: System Journal (/var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c) is 8M, max 4G, 3.9G free.66server # [6500611.884823] server systemd[1]: Finished Create Static Device Nodes in /dev.67server # [6500611.885533] server systemd[1]: Reached target Preparation for Local File Systems.68server # [6500611.885649] server systemd[1]: Reached target Local File Systems.69server # [6500611.886487] server systemd[1]: Listening on Boot Loader Control Service Socket.70server # [6500611.886530] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container71server # [6500611.887371] server systemd[1]: Starting Save Transient machine-id to Disk...72server # [6500611.887410] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys73server # [6500611.901134] server systemd[1]: Finished Flush Journal to Persistent Storage.74server # [6500611.903018] server systemd[1]: Starting Create System Files and Directories...75server # [6500611.920585] server systemd-tmpfiles[119]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted76server # [6500611.920797] server systemd-tmpfiles[119]: fchmod() of /var/log/journal failed: Operation not permitted77client # [6500611.850824] client systemd-journald[69]: Journal started78server # [6500611.921169] server systemd-tmpfiles[119]: fchmod() of /var/log/journal/37f6c3329ee44a62ae708ed5ffa2fd5c failed: Operation not permitted79client # [6500611.850882] client systemd-journald[69]: Runtime Journal (/run/log/journal/68f0507a662d47329cd277824b4ceed4) is 8M, max 2.5G, 2.4G free.80server # [6500611.921376] server systemd-tmpfiles[119]: fchmod() of /run/log/journal failed: Operation not permitted81client # [6500611.852408] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.82server # [6500611.923687] server systemd[1]: Finished Create System Files and Directories.83server # [6500611.924833] server systemd[1]: Starting Rebuild Journal Catalog...84server # [6500611.925596] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...85server # [6500611.925936] server systemd[1]: Finished Save Transient machine-id to Disk.86server # [6500611.937864] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.87server # [6500611.943449] server systemd[1]: Finished Rebuild Journal Catalog.88server # [6500611.944465] server systemd[1]: Starting Update is Completed...89server # [6500611.953404] server systemd[1]: Finished Update is Completed.90client # [6500611.861447] client systemd[1]: Starting Flush Journal to Persistent Storage...91client # [6500611.862344] client systemd[1]: Starting Network Name Resolution...92client # [6500611.863225] client systemd[1]: Starting Create Static Device Nodes in /dev...93client # [6500611.872581] client systemd-journald[69]: Time spent on flushing to /var/log/journal/68f0507a662d47329cd277824b4ceed4 is 1.544ms for 6 entries.94client # [6500611.872581] client systemd-journald[69]: System Journal (/var/log/journal/68f0507a662d47329cd277824b4ceed4) is 8M, max 4G, 3.9G free.95client # [6500611.879377] client systemd[1]: Finished Create Static Device Nodes in /dev.96client # [6500611.880084] client systemd[1]: Reached target Preparation for Local File Systems.97client # [6500611.880224] client systemd[1]: Reached target Local File Systems.98client # [6500611.881072] client systemd[1]: Listening on Boot Loader Control Service Socket.99client # [6500611.881114] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container100client # [6500611.882022] client systemd[1]: Starting Save Transient machine-id to Disk...101client # [6500611.882059] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys102client # [6500611.900472] client systemd[1]: Finished Flush Journal to Persistent Storage.103client # [6500611.901706] client systemd[1]: Starting Create System Files and Directories...104client # [6500611.916904] client systemd-tmpfiles[120]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted105client # [6500611.917114] client systemd-tmpfiles[120]: fchmod() of /var/log/journal failed: Operation not permitted106client # [6500611.917259] client systemd-tmpfiles[120]: fchmod() of /var/log/journal/68f0507a662d47329cd277824b4ceed4 failed: Operation not permitted107client # [6500611.917485] client systemd-tmpfiles[120]: fchmod() of /run/log/journal failed: Operation not permitted108client # [6500611.919617] client systemd[1]: Finished Create System Files and Directories.109client # [6500611.920817] client systemd[1]: Starting Rebuild Journal Catalog...110client # [6500611.921623] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...111client # [6500611.927827] client systemd[1]: Finished Save Transient machine-id to Disk.112client # [6500611.933015] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.113client # [6500611.940388] client systemd[1]: Finished Rebuild Journal Catalog.114client # [6500611.941474] client systemd[1]: Starting Update is Completed...115client # [6500611.952132] client systemd[1]: Finished Update is Completed.116client # [6500612.076719] client systemd[1]: Finished Firewall.117client # [6500612.076867] client systemd[1]: Reached target Preparation for Network.118client # [6500612.077080] client systemd[1]: Listening on Network Management Resolve Hook Socket.119client # [6500612.078089] client systemd[1]: Starting Network Management...120ca # [6500612.144177] ca systemd[1]: Finished Firewall.121ca # [6500612.144363] ca systemd[1]: Reached target Preparation for Network.122ca # [6500612.144568] ca systemd[1]: Listening on Network Management Resolve Hook Socket.123ca # [6500612.145665] ca systemd[1]: Starting Network Management...124server # [6500612.144215] server systemd[1]: Finished Firewall.125server # [6500612.144865] server systemd[1]: Reached target Preparation for Network.126server # [6500612.145147] server systemd[1]: Listening on Network Management Resolve Hook Socket.127server # [6500612.146248] server systemd[1]: Starting Network Management...128client # [6500612.551313] client systemd-networkd[183]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted129client # [6500612.551402] client systemd-networkd[183]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted130client # [6500612.558414] client systemd-networkd[183]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.131client # [6500612.558572] client systemd-networkd[183]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.132client # [6500612.558726] client systemd-networkd[183]: lo: Link UP133client # [6500612.558730] client systemd-networkd[183]: lo: Gained carrier134client # [6500612.558897] client systemd-networkd[183]: eth1: Configuring with /etc/systemd/network/40-eth1.network.135client # [6500612.559276] client systemd[1]: Started Network Management.136client # [6500612.559356] client systemd-networkd[183]: eth1: Link UP137client # [6500612.559674] client systemd-networkd[183]: eth1: Gained carrier138client # [6500612.560259] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...139client # [6500612.581966] client systemd-resolved[93]: Positive Trust Anchors:140client # [6500612.581976] client systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d141client # [6500612.581981] client systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16142client # [6500612.582016] client systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test143client # [6500612.600789] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.144client # [6500612.604495] client systemd-resolved[93]: Using system hostname 'client'.145client # [6500612.605849] client systemd[1]: Started Network Name Resolution.146client # [6500612.605973] client systemd[1]: Reached target Network.147client # [6500612.606087] client systemd[1]: Reached target System Initialization.148client # [6500612.606182] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container149client # [6500612.606242] client systemd[1]: Started Daily Cleanup of Temporary Directories.150client # [6500612.606280] client systemd[1]: Reached target Timer Units.151client # [6500612.606500] client systemd[1]: Listening on D-Bus System Message Bus Socket.152client # [6500612.606713] client systemd[1]: Listening on Nix Daemon Socket.153client # [6500612.606925] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.154client # [6500612.606972] client systemd[1]: Reached target Socket Units.155client # [6500612.607053] client systemd[1]: Reached target Basic System.156client # [6500612.608791] client systemd[1]: Starting Import lastlog data into lastlog2 database...157client # [6500612.610283] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...158client # [6500612.612540] client systemd[1]: Starting D-Bus System Message Bus...159client # [6500612.631712] client systemd[1]: Finished Import lastlog data into lastlog2 database.160client # [6500612.794059] client nsncd[189]: Aug 23 05:07:18.847 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"161client # [6500612.794211] client systemd[1]: Started Name Service Cache Daemon (nsncd).162client # [6500612.794319] client systemd[1]: Reached target Host and Network Name Lookups.163client # [6500612.794419] client systemd[1]: Reached target User and Group Name Lookups.164client # [6500612.796394] client systemd[1]: Starting User Login Management...165client # [6500612.797872] client systemd[1]: Starting Permit User Sessions...166server # [6500612.565875] server systemd-networkd[187]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted167server # [6500612.565960] server systemd-networkd[187]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted168server # [6500612.573153] server systemd-networkd[187]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.169server # [6500612.573468] server systemd-networkd[187]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.170server # [6500612.573608] server systemd-networkd[187]: lo: Link UP171server # [6500612.573612] server systemd-networkd[187]: lo: Gained carrier172server # [6500612.573775] server systemd-networkd[187]: eth1: Configuring with /etc/systemd/network/40-eth1.network.173server # [6500612.574188] server systemd[1]: Started Network Management.174server # [6500612.592196] server systemd-resolved[92]: Positive Trust Anchors:175server # [6500612.592206] server systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d176server # [6500612.592209] server systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16177server # [6500612.592245] server systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test178server # [6500612.592337] server systemd-networkd[187]: eth1: Link UP179server # [6500612.592677] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...180server # [6500612.592713] server systemd-networkd[187]: eth1: Gained carrier181server # [6500612.614036] server systemd-resolved[92]: Using system hostname 'server'.182server # [6500612.615309] server systemd[1]: Started Network Name Resolution.183server # [6500612.615390] server systemd[1]: Reached target Network.184server # [6500612.615457] server systemd[1]: Reached target Network is Online.185server # [6500612.615505] server systemd[1]: Reached target System Initialization.186server # [6500612.615723] server systemd[1]: Started Renew ACME Certificate for test.foo.187server # [6500612.615756] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container188server # [6500612.615782] server systemd[1]: Started Daily Cleanup of Temporary Directories.189server # [6500612.615804] server systemd[1]: Reached target Timer Units.190server # [6500612.615934] server systemd[1]: Listening on D-Bus System Message Bus Socket.191server # [6500612.616063] server systemd[1]: Listening on Nix Daemon Socket.192server # [6500612.616187] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.193server # [6500612.616216] server systemd[1]: Reached target Socket Units.194server # [6500612.616259] server systemd[1]: Reached target Basic System.195server # [6500612.617562] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...196server # [6500612.618409] server systemd[1]: Starting Import lastlog data into lastlog2 database...197server # [6500612.618451] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem198server # [6500612.619349] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...199server # [6500612.620787] server systemd[1]: Starting D-Bus System Message Bus...200server # [6500612.640256] server systemd[1]: Finished Import lastlog data into lastlog2 database.201server # [6500612.646081] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.202server # [6500612.743524] server acme-setup-privileged[191]: + set -euo pipefail203server # [6500612.743524] server acme-setup-privileged[191]: + cd /var/lib/acme204server # [6500612.743964] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts205server # [6500612.745202] server acme-setup-privileged[191]: + chown -R acme .lego/accounts206server # [6500612.746805] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo207server # [6500612.746839] server acme-setup-privileged[191]: + '[' -d test.foo ']'208server # [6500612.746839] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo209server # [6500612.746839] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']'210server # [6500612.779450] server systemd[1]: Started Name Service Cache Daemon (nsncd).211server # [6500612.779708] server nsncd[193]: Aug 23 05:07:18.832 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"212server # [6500612.779536] server systemd[1]: Reached target Host and Network Name Lookups.213server # [6500612.779605] server systemd[1]: Reached target User and Group Name Lookups.214server # [6500612.780960] server systemd[1]: Starting User Login Management...215server # [6500612.782072] server systemd[1]: Starting Permit User Sessions...216server # [6500612.792687] server systemd[1]: Finished Permit User Sessions.217server # [6500612.794425] server systemd[1]: Started Console Getty.218server # [6500612.794476] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0219server # [6500612.794497] server systemd[1]: Reached target Login Prompts.220ca # [6500612.567360] ca systemd-networkd[196]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted221ca # [6500612.567439] ca systemd-networkd[196]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted222ca # [6500612.574573] ca systemd-networkd[196]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.223ca # [6500612.574737] ca systemd-networkd[196]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.224ca # [6500612.574875] ca systemd-networkd[196]: lo: Link UP225ca # [6500612.574879] ca systemd-networkd[196]: lo: Gained carrier226ca # [6500612.575054] ca systemd-networkd[196]: eth1: Configuring with /etc/systemd/network/40-eth1.network.227ca # [6500612.575414] ca systemd[1]: Started Network Management.228ca # [6500612.587751] ca systemd-resolved[99]: Positive Trust Anchors:229ca # [6500612.587761] ca systemd-resolved[99]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d230ca # [6500612.587765] ca systemd-resolved[99]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16231ca # [6500612.587799] ca systemd-resolved[99]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test232ca # [6500612.592489] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...233ca # [6500612.592674] ca systemd-networkd[196]: eth1: Link UP234ca # [6500612.592984] ca systemd-networkd[196]: eth1: Gained carrier235ca # [6500612.609344] ca systemd-resolved[99]: Using system hostname 'ca'.236ca # [6500612.610656] ca systemd[1]: Started Network Name Resolution.237ca # [6500612.610777] ca systemd[1]: Reached target Network.238ca # [6500612.610886] ca systemd[1]: Reached target Network is Online.239ca # [6500612.610983] ca systemd[1]: Reached target System Initialization.240ca # [6500612.611341] ca systemd[1]: Started Renew ACME Certificate for ca.foo.241ca # [6500612.611392] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container242ca # [6500612.611439] ca systemd[1]: Started Daily Cleanup of Temporary Directories.243ca # [6500612.611477] ca systemd[1]: Reached target Timer Units.244ca # [6500612.611692] ca systemd[1]: Listening on D-Bus System Message Bus Socket.245ca # [6500612.611883] ca systemd[1]: Listening on Nix Daemon Socket.246ca # [6500612.612127] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.247ca # [6500612.612180] ca systemd[1]: Reached target Socket Units.248ca # [6500612.612265] ca systemd[1]: Reached target Basic System.249ca # [6500612.614404] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...250ca # [6500612.615705] ca systemd[1]: Starting Import lastlog data into lastlog2 database...251ca # [6500612.615778] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem252ca # [6500612.617196] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...253ca # [6500612.618873] ca systemd[1]: Starting step-ca service...254ca # [6500612.621275] ca systemd[1]: Starting D-Bus System Message Bus...255ca # [6500612.640921] ca systemd[1]: Finished Import lastlog data into lastlog2 database.256ca # [6500612.643220] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.257ca # [6500612.777410] ca acme-setup-privileged[200]: + set -euo pipefail258ca # [6500612.777410] ca acme-setup-privileged[200]: + cd /var/lib/acme259ca # [6500612.777410] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts260ca # [6500612.779225] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts261ca # [6500612.780879] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo262ca # [6500612.780924] ca acme-setup-privileged[200]: + '[' -d ca.foo ']'263ca # [6500612.780924] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo264ca # [6500612.780924] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']'265ca # [6500612.797793] ca nsncd[202]: Aug 23 05:07:18.850 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"266ca # [6500612.797977] ca systemd[1]: Started Name Service Cache Daemon (nsncd).267ca # [6500612.798088] ca systemd[1]: Reached target Host and Network Name Lookups.268ca # [6500612.798195] ca systemd[1]: Reached target User and Group Name Lookups.269ca # [6500612.800195] ca systemd[1]: Starting User Login Management...270ca # [6500612.801414] ca systemd[1]: Starting Permit User Sessions...271ca # [6500612.811375] ca systemd[1]: Finished Permit User Sessions.272ca # [6500612.812723] ca systemd[1]: Started Console Getty.273ca # [6500612.812775] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0274ca # [6500612.812797] ca systemd[1]: Reached target Login Prompts.275ca # [6500612.846125] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.276client # [6500612.808282] client systemd[1]: Finished Permit User Sessions.277client # [6500612.810161] client systemd[1]: Started Console Getty.278client # [6500612.810211] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0279client # [6500612.810237] client systemd[1]: Reached target Login Prompts.280client # [6500612.835064] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.281client # [6500612.895904] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...282client # [6500612.896873] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'283client # [6500612.896873] client dbus-broker-launch[190]: Invalid user-name in /nix/store/s0a40wv0lnwiz13r43fk318ri3wv536k-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"284client # [6500612.897249] client systemd[1]: Started D-Bus System Message Bus.285client # [6500612.904814] client dbus-broker-launch[190]: Ready286ca # [6500612.921347] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'...287ca # [6500612.922186] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync'288ca # [6500612.922186] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/mfvkn1zwby5692v4kx3ynjdz34b2lkq3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"289ca # [6500612.922599] ca systemd[1]: Started D-Bus System Message Bus.290ca # [6500612.929789] ca dbus-broker-launch[204]: Ready291server # [6500612.843470] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.292server # [6500612.914133] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'...293server # [6500612.916228] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync'294server # [6500612.916228] server dbus-broker-launch[194]: Invalid user-name in /nix/store/lxnlg1wvz5bx4xfzc75k21l11ngxkyck-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"295server # [6500612.916606] server systemd[1]: Started D-Bus System Message Bus.296server # [6500612.926656] server dbus-broker-launch[194]: Ready297ca # [6500613.271567] ca systemd-logind[235]: New seat seat0.298ca # [6500613.271840] ca systemd[1]: Started User Login Management.299ca # [6500613.300737] ca systemd[1]: Starting linger-users.service...300ca # [6500613.312549] ca acme-setup-start[219]: + set -euo pipefail301ca # [6500613.312549] ca acme-setup-start[219]: + test -e ca/key.pem302ca # [6500613.313125] ca acme-setup-start[219]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local303ca # [6500613.313412] ca systemd[1]: linger-users.service: Deactivated successfully.304ca # [6500613.313491] ca systemd[1]: Finished linger-users.service.305ca # [6500613.331359] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.306ca # [6500613.332904] ca systemd[1]: Starting Ensure certificate for ca.foo...307server # [6500613.251252] server systemd-logind[224]: New seat seat0.308server # [6500613.251481] server systemd[1]: Started User Login Management.309server # [6500613.253549] server systemd[1]: Starting linger-users.service...310server # [6500613.284169] server acme-setup-start[208]: + set -euo pipefail311server # [6500613.284169] server acme-setup-start[208]: + test -e ca/key.pem312server # [6500613.284169] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local313server # [6500613.308584] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.314server # [6500613.311202] server systemd[1]: Starting Ensure certificate for test.foo...315server # [6500613.311779] server systemd[1]: linger-users.service: Deactivated successfully.316server # [6500613.311958] server systemd[1]: Finished linger-users.service.317client # [6500613.252934] client systemd-logind[205]: New seat seat0.318client # [6500613.253103] client systemd[1]: Started User Login Management.319client # [6500613.254947] client systemd[1]: Starting linger-users.service...320client # [6500613.311755] client systemd[1]: linger-users.service: Deactivated successfully.321client # [6500613.311927] client systemd[1]: Finished linger-users.service.322client # [6500613.312516] client systemd[1]: Reached target Multi-User System.323client # [6500613.312785] client systemd[1]: Startup finished in 1.854s.324ca # [6500613.549326] ca step-ca[203]: badger 2026/08/23 05:07:19 INFO: All 0 tables opened in 0s325ca # [6500613.553143] ca step-ca[203]: 2026/08/23 05:07:19 Building new tls configuration using step-ca x509 Signer Interface326ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Starting Smallstep CA/0.30.2 (linux/arm64)327ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Documentation: https://u.step.sm/docs/ca328ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Community Discord: https://u.step.sm/discord329ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Config file: /etc/smallstep/ca.json330ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 The primary server URL is https://ca.foo:1443331ca # [6500613.558816] ca step-ca[203]: 2026/08/23 05:07:19 Root certificates are available at https://ca.foo:1443/roots.pem332ca # [6500613.559125] ca step-ca[203]: 2026/08/23 05:07:19 X.509 Root Fingerprint: fcec151c7705057538ab7b446472065d7ea631e5f4168a5856ccb5b20a98592a333ca # [6500613.559465] ca systemd[1]: Started step-ca service.334ca # [6500613.559885] ca step-ca[203]: 2026/08/23 05:07:19 Serving HTTPS on 0.0.0.0:1443 ...335ca # [6500613.732248] ca systemd-networkd[196]: eth1: Gained IPv6LL336ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 337server # [6500613.794091] server acme-test.foo-start[244]: Waiting to acquire lock in /run/acme/338server # [6500613.796916] server acme-test.foo-start[244]: + '[' -e out/acme-success ']'339server # [6500613.797002] server acme-test.foo-start[244]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=340server # [6500613.812135] server acme-test.foo-start[255]: + cd test.foo341server # [6500613.812135] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem342server # [6500613.813939] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'343server # [6500613.814281] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem344server # [6500613.815419] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'345server # [6500613.815674] server acme-test.foo-start[244]: + cat out/cert.pem ca/cert.pem346server # [6500613.817430] server acme-test.foo-start[244]: + cp ca/cert.pem out/chain.pem347server # [6500613.819128] server acme-test.foo-start[244]: + cat out/key.pem out/fullchain.pem348server # [6500613.821041] server acme-test.foo-start[244]: + for fixpath in out certificates349server # [6500613.821041] server acme-test.foo-start[244]: + '[' -d out ']'350server # [6500613.821147] server acme-test.foo-start[244]: + chmod -R u=rwX,g=rX,o= out351server # [6500613.822626] server acme-test.foo-start[244]: + chown -R acme:nginx out352server # [6500613.826215] server acme-test.foo-start[244]: + for fixpath in out certificates353server # [6500613.826215] server acme-test.foo-start[244]: + '[' -d certificates ']'354server # [6500613.829548] server systemd[1]: Finished Ensure certificate for test.foo.355server # [6500613.832119] server systemd[1]: Starting Nginx Web Server...356ca # [6500613.826065] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/357ca # [6500613.829999] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'358ca # [6500613.829999] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=359ca # [6500613.845408] ca acme-ca.foo-start[294]: + cd ca.foo360ca # [6500613.845955] ca acme-ca.foo-start[294]: + cp -vp cert.pem ../out/cert.pem361ca # [6500613.847186] ca acme-ca.foo-start[295]: 'cert.pem' -> '../out/cert.pem'362ca # [6500613.847495] ca acme-ca.foo-start[294]: + cp -vp key.pem ../out/key.pem363ca # [6500613.848745] ca acme-ca.foo-start[294]: 'key.pem' -> '../out/key.pem'364ca # [6500613.848971] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem365ca # [6500613.850966] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem366ca # [6500613.852786] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem367ca # [6500613.854564] ca acme-ca.foo-start[256]: + for fixpath in out certificates368ca # [6500613.854564] ca acme-ca.foo-start[256]: + '[' -d out ']'369ca # [6500613.854666] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out370ca # [6500613.856138] ca acme-ca.foo-start[256]: + chown -R acme:nginx out371ca # [6500613.859559] ca acme-ca.foo-start[256]: + for fixpath in out certificates372ca # [6500613.859610] ca acme-ca.foo-start[256]: + '[' -d certificates ']'373ca # [6500613.868317] ca systemd[1]: Finished Ensure certificate for ca.foo.374ca # [6500613.870679] ca systemd[1]: Starting Nginx Web Server...375server # [6500614.144189] server systemd-networkd[187]: eth1: Gained IPv6LL376server # [6500614.380547] server nginx-pre-start[267]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok377server # [6500614.381111] server nginx-pre-start[267]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful378server # [6500614.387477] server systemd[1]: Started Nginx Web Server.379server # [6500614.388399] server systemd[1]: Reached target Multi-User System.380server # [6500614.390661] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...381ca # [6500614.380742] ca nginx-pre-start[306]: nginx: the configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf syntax is ok382ca # [6500614.381301] ca nginx-pre-start[306]: nginx: configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf test is successful383ca # [6500614.386980] ca systemd[1]: Started Nginx Web Server.384ca # [6500614.387861] ca systemd[1]: Reached target Multi-User System.385ca # [6500614.390157] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...386client # [6500614.592474] client systemd-networkd[183]: eth1: Gained IPv6LL387server # [6500614.949405] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/388server # [6500614.952430] server acme-order-renew-test.foo-start[270]: + set -euo pipefail389server # [6500614.952505] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108390server # [6500614.952629] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt391server # [6500614.954363] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run392ca # [6500614.981200] ca acme-order-renew-ca.foo-start[309]: Waiting to acquire lock in /run/acme/393server # [6500614.986951] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 No key found for account none@none.tld. Generating a P256 key.394ca # [6500614.984214] ca acme-order-renew-ca.foo-start[309]: + set -euo pipefail395server # [6500614.987308] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key396ca # [6500614.984294] ca acme-order-renew-ca.foo-start[309]: + echo 88dc4fc401a6091a1bd9397server # [6500615.019164] server acme-order-renew-test.foo-start[282]: 2026/08/23 05:07:21 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority398ca # [6500614.984415] ca acme-order-renew-ca.foo-start[309]: + cmp -s domainhash.txt certificates/domainhash.txt399server # [6500615.019647] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.400ca # [6500614.985486] ca acme-order-renew-ca.foo-start[309]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run401server # [6500615.019647] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.402ca # [6500615.001540] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 No key found for account none@none.tld. Generating a P256 key.403server # [6500615.019711] server acme-order-renew-test.foo-start[270]: + exit 10404ca # [6500615.001870] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key405server # [6500615.024294] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a406ca # [6500615.030121] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration="140.802µs" duration-ns=140802 fields.time="2026-08-23T05:07:21Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=548494c3-34f7-474e-8301-1ce479c80ffe response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=407server # [6500615.024493] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.408ca # [6500615.030578] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] acme: Registering account for none@none.tld409server # [6500615.024903] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.410ca # [6500615.064964] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=34.12683ms duration-ns=34126830 fields.time="2026-08-23T05:07:21Z" method=HEAD name=ca nonce=WDVpZkRUSThiTjh3SlpXSzFVUVBIM0pkVnFpaXRZeHY path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=75fa54f2-aecd-46ff-adbf-61d24d9ff185 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=411server # [6500615.025397] server systemd[1]: Startup finished in 3.551s.412ca # [6500615.070946] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=4.845987ms duration-ns=4845987 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=N1N5R2o3ZnFZemg4aFZBbkNGVXhnTElTb2RZbzU4Rm4 path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4d4afc02-c130-4244-b678-772bdcabdbe6 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/G5R8VvwgrrJVywpJufSegqCZbjp4aoIr/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=413ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: !!!! HEADS UP !!!!414ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: Your account credentials have been saved in your415ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: configuration directory at "accounts".416ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: You should make a secure backup of this folder now. This417ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: configuration directory will also contain private keys418ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: generated by lego and certificates obtained from the ACME419ca # [6500615.071504] ca acme-order-renew-ca.foo-start[321]: server. Making regular backups of this folder is ideal.420ca # [6500615.071637] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate421ca # [6500615.077920] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=5.101351ms duration-ns=5101351 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=ZDlQS3V4UEpVaGhoR2JrMXBveGc3SDlQZ0FtMHFYTXk path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=39f0c766-178e-4479-924a-886eb685e66e response="{\"id\":\"CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8\",\"status\":\"pending\",\"expires\":\"2026-08-24T05:07:21Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T05:06:21Z\",\"notAfter\":\"2026-11-21T05:07:21Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=422ca # [6500615.137419] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=2.17059ms duration-ns=2170590 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=SXRQSXJTREthdzZOVkJKYmdxbmpzOXowZ3RRTGlkNlE path=/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=773bd64c-ba93-4ed9-9768-5a3d1dc339d5 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/VWnhR7wyAWWHZaXSfFBCShY5Rr1XAdHu\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/sTNDgBbN06jXY5MefWWSaFDKXORUQk0F\"}],\"wildcard\":false,\"expires\":\"2026-08-24T05:07:21Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=423ca # [6500615.137835] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs424ca # [6500615.137835] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01425ca # [6500615.137903] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: use http-01 solver426ca # [6500615.137903] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Trying to solve HTTP-01427ca # [6500615.143245] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=4.543663ms duration-ns=4543663 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=eG9pbVBka1lhZjRORmRZc0ZWVjVpYlc5MDhpR1poVmM path=/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=338e0c7c-c3c9-49a2-be57-6ac950dc4155 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"fHXaEl3PYFw1ysZJgvSom07qQF7PTFxY\",\"validated\":\"2026-08-23T05:07:21Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs/XasNQ7IiMyQQY8KBjLoSV6fDJtlRmJ0R\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=428ca # [6500615.143655] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] The server validated our request429ca # [6500615.143759] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates430ca # [6500615.153901] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info duration=8.353075ms duration-ns=8353075 fields.time="2026-08-23T05:07:21Z" method=POST name=ca nonce=YnFDNkh6S3JrcW5KNm4xdm9iUU1hN0JlREJ0Rmk0UmE path=/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=50394c24-e025-4d2e-b144-6518c5e72a7f response="{\"id\":\"CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8\",\"status\":\"valid\",\"expires\":\"2026-08-24T05:07:21Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T05:06:21Z\",\"notAfter\":\"2026-11-21T05:07:21Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/kvXGJMkXSxLUgqhgEvmnAOBKUnULZOIs\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/CXpO6n2ZbXn2Bho3QxH0UbptGRGnlaj8/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/I4eGuXnaFODGmMnw9z2N6PYIFc79EsCC\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=431ca # [6500615.156748] ca step-ca[203]: time="2026-08-23T05:07:21Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQLL+SdUkxaVehxXVozU3fGzAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMwNTA2MjFaFw0yNjExMjEwNTA3MjFaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABHpcXSAt9JBTZpXzJjzyh/SHfk1Wcs7MRTFpKvERZ6zRgWCTo5+ON2rvepKVSAgoRb7RvX4up3TqmlS0qgMMMUajgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQURdoTElgWrVYb7AqodImklu7+hVEwHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEAzE8DOqyfwbLcJMzOgh53FVeQHvZHKfS/XXb9eQQq8OgCIHBUAA9y2hXBpFUhN7PYVj83RN+H+1zHvnCP0u6sTB1V duration=1.821105ms duration-ns=1821105 fields.time="2026-08-23T05:07:21Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=dlg0TnhaQzU0b3UwdzRKbnI4Zk9NNnRkMGttd0NxcGM path=/acme/acme/certificate/I4eGuXnaFODGmMnw9z2N6PYIFc79EsCC protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=0ef02efc-43a8-4b55-b8cc-bf6a4ce03cf6 sans="map[dns:[ca.foo]]" serial=59480731038665738344749825069994073883 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T05:06:21Z" valid-to="2026-11-21T05:07:21Z"432ca # [6500615.157066] ca acme-order-renew-ca.foo-start[321]: 2026/08/23 05:07:21 [INFO] [ca.foo] Server responded with a certificate.433ca # [6500615.163447] ca acme-order-renew-ca.foo-start[309]: + mv domainhash.txt certificates/434ca # [6500615.165175] ca acme-order-renew-ca.foo-start[309]: + touch out/acme-success435ca # [6500615.166944] ca acme-order-renew-ca.foo-start[309]: + cmp -s certificates/ca.foo.crt out/fullchain.pem436ca # [6500615.168255] ca acme-order-renew-ca.foo-start[309]: + touch out/renewed437ca # [6500615.170086] ca acme-order-renew-ca.foo-start[309]: + echo Installing new certificate438ca # [6500615.170086] ca acme-order-renew-ca.foo-start[309]: Installing new certificate439ca # [6500615.170129] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.crt out/fullchain.pem440ca # [6500615.171763] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'441ca # [6500615.171995] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.key out/key.pem442ca # [6500615.173507] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem'443ca # [6500615.173751] ca acme-order-renew-ca.foo-start[309]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem444ca # [6500615.175152] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'445ca # [6500615.175381] ca acme-order-renew-ca.foo-start[309]: + ln -sf fullchain.pem out/cert.pem446ca # [6500615.176875] ca acme-order-renew-ca.foo-start[309]: + cat out/key.pem out/fullchain.pem447ca # [6500615.178643] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates448ca # [6500615.178665] ca acme-order-renew-ca.foo-start[309]: + '[' -d out ']'449ca # [6500615.178665] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= out450ca # [6500615.180210] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx out451ca # [6500615.182670] ca acme-order-renew-ca.foo-start[309]: + for fixpath in out certificates452ca # [6500615.182706] ca acme-order-renew-ca.foo-start[309]: + '[' -d certificates ']'453ca # [6500615.182706] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=rX,o= certificates454ca # [6500615.184450] ca acme-order-renew-ca.foo-start[309]: + chown -R acme:nginx certificates455ca # [6500615.187374] ca acme-order-renew-ca.foo-start[309]: + chmod -R u=rwX,g=,o= accounts/.456ca # [6500615.322770] ca systemd[1]: Reloading Nginx Web Server...457ca # [6500615.326710] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.458ca # [6500615.326902] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.459ca # [6500615.875183] ca nginx[371]: nginx: the configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf syntax is ok460ca # [6500615.875824] ca nginx[371]: nginx: configuration file /nix/store/lfwd10qpyi3s44q1cn5nrgcwqdpyj8fr-nginx.conf test is successful461ca # [6500616.401291] ca systemd[1]: Reloaded Nginx Web Server.462ca # [6500616.401789] ca systemd[1]: Startup finished in 4.907s.463ca # [6500616.634000] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...464ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.37 seconds)465ca # [6500617.160546] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/466ca # [6500617.163402] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail467ca # [6500617.163477] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9468ca # [6500617.163580] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt469ca # [6500617.164877] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']'470ca # [6500617.164909] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']'471ca # [6500617.165346] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key472ca # [6500617.168394] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'473ca # [6500617.168458] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic474ca # [6500617.209228] ca step-ca[203]: time="2026-08-23T05:07:23Z" level=info duration="61.401µs" duration-ns=61401 fields.time="2026-08-23T05:07:23Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3ad63061-f386-440a-9ebf-1620a28b6722 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=475ca # [6500617.209537] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 05:07:23 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint476ca # [6500617.209537] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 05:07:23 [INFO] [ca.foo] The certificate expires at 2026-11-21T05:07:21Z, the renewal can be performed in 1439h59m37.737312855s: no renewal.477ca # [6500617.210133] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/478ca # [6500617.212185] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success479ca # [6500617.213535] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem480ca # [6500617.214782] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates481ca # [6500617.214804] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']'482ca # [6500617.214804] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out483ca # [6500617.216311] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out484ca # [6500617.219235] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates485ca # [6500617.219255] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']'486ca # [6500617.219273] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates487ca # [6500617.221023] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates488ca # [6500617.223914] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/.489ca # [6500617.315930] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.490ca # [6500617.316263] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.491server: must succeed: systemctl restart acme-test.foo.service492server # [6500620.348390] server systemd[1]: acme-test.foo.service: Deactivated successfully.493server # [6500620.348760] server systemd[1]: Stopped Ensure certificate for test.foo.494server # [6500620.350000] server systemd[1]: Stopping Ensure certificate for test.foo...495server # [6500620.352271] server systemd[1]: Starting Ensure certificate for test.foo...496server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.55 seconds)497client: waiting for success: curl -v https://test.foo498* Host test.foo:443 was resolved.499* IPv6: 2001:db8:1::3500* IPv4: 192.168.1.3501* Trying [2001:db8:1::3]:443...502* ALPN: curl offers h2,http/1.1503} [5 bytes data]504* TLSv1.3 (OUT), TLS handshake, Client hello (1):505} [1552 bytes data]506* SSL Trust Anchors:507* OpenSSL default paths (fallback)508{ [5 bytes data]509* TLSv1.3 (IN), TLS handshake, Server hello (2):510{ [1210 bytes data]511* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):512{ [1 bytes data]513* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):514{ [19 bytes data]515* TLSv1.3 (IN), TLS handshake, Certificate (11):516{ [1009 bytes data]517* TLSv1.3 (IN), TLS handshake, CERT verify (15):518{ [111 bytes data]519* TLSv1.3 (IN), TLS handshake, Finished (20):520{ [52 bytes data]521* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):522} [1 bytes data]523* TLSv1.3 (OUT), TLS handshake, Finished (20):524} [52 bytes data]525* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey526* ALPN: server accepted h2527* Server certificate:528* subject: CN=test.foo529* start date: Aug 23 05:07:19 2026 GMT530* expire date: Sep 22 05:07:19 2028 GMT531* issuer: CN=minica root ca 7f712c532* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384533* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384534* subjectAltName: "test.foo" matches cert's "test.foo"535* OpenSSL verify result: 13536* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)537* closing connection #0538curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)539More details here: https://curl.se/docs/sslcerts.html540541curl failed to verify the legitimacy of the server and therefore could not542establish a secure connection to it. To learn more about this situation and543how to fix it, please visit the webpage mentioned above.544server # [6500620.825977] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/545server # [6500620.828277] server acme-test.foo-start[316]: + '[' -e out/acme-success ']'546server # [6500620.828277] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=547server # [6500620.841762] server acme-test.foo-start[326]: + cd test.foo548server # [6500620.842281] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem549server # [6500620.843177] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem'550server # [6500620.843485] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem551server # [6500620.844473] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem'552server # [6500620.844676] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem553server # [6500620.846112] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem554server # [6500620.847916] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem555server # [6500620.850108] server acme-test.foo-start[316]: + for fixpath in out certificates556server # [6500620.850108] server acme-test.foo-start[316]: + '[' -d out ']'557server # [6500620.850203] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out558server # [6500620.851968] server acme-test.foo-start[316]: + chown -R acme:nginx out559server # [6500620.854518] server acme-test.foo-start[316]: + for fixpath in out certificates560server # [6500620.854518] server acme-test.foo-start[316]: + '[' -d certificates ']'561server # [6500620.880267] server systemd[1]: Finished Ensure certificate for test.foo.562server # [6500620.883040] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...563server # [6500621.345960] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/564server # [6500621.348701] server acme-order-renew-test.foo-start[334]: + set -euo pipefail565server # [6500621.348784] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108566server # [6500621.348887] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt567server # [6500621.349946] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run568server # [6500621.401353] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] acme: Registering account for none@none.tld569server # [6500621.435275] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!!570server # [6500621.435275] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your571server # [6500621.435275] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts".572server # [6500621.435275] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This573server # [6500621.435275] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys574server # [6500621.435275] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME575server # [6500621.435275] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal.576server # [6500621.435504] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Obtaining bundled SAN certificate577server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl578server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01579server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: use http-01 solver580server # [6500621.508973] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Trying to solve HTTP-01581server # [6500621.514900] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] The server validated our request582server # [6500621.514998] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] acme: Validations succeeded; requesting certificates583server # [6500621.532434] server acme-order-renew-test.foo-start[342]: 2026/08/23 05:07:27 [INFO] [test.foo] Server responded with a certificate.584server # [6500621.537629] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/585server # [6500621.539398] server acme-order-renew-test.foo-start[334]: + touch out/acme-success586server # [6500621.540976] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem587server # [6500621.541981] server acme-order-renew-test.foo-start[334]: + touch out/renewed588server # [6500621.543879] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate589server # [6500621.543879] server acme-order-renew-test.foo-start[334]: Installing new certificate590server # [6500621.543879] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem591server # [6500621.545212] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'592server # [6500621.545468] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem593server # [6500621.547212] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem'594server # [6500621.547804] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem595server # [6500621.548897] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'596server # [6500621.549215] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem597server # [6500621.550694] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem598server # [6500621.552766] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates599server # [6500621.552766] server acme-order-renew-test.foo-start[334]: + '[' -d out ']'600server # [6500621.552879] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out601server # [6500621.554451] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out602server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates603server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']'604server # [6500621.557937] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates605server # [6500621.559535] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates606server # [6500621.562257] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/.607server # [6500621.676386] server systemd[1]: Reloading Nginx Web Server...608ca # [6500621.400750] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration="46.6µs" duration-ns=46600 fields.time="2026-08-23T05:07:27Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=f5d56d68-f43b-41b3-8a99-c47e8c073e92 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=609ca # [6500621.427513] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=24.020731ms duration-ns=24020731 fields.time="2026-08-23T05:07:27Z" method=HEAD name=ca nonce=U0RIQk41VUh1Y3didWI4YTdHUlFVdTNHVlBrUHNVMzk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=89e49d32-f31f-4df6-9c05-abcfd0c74674 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=610ca # [6500621.434274] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.125963ms duration-ns=3125963 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=TFNQQ2dMMGlQS2oyS2hwWDZjVWxlZVJEaDZsMk5XWks path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=6324d669-d3b2-48a2-b334-9d1a8031ced9 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/igIzwC3W85NeXgDRwp8lpZLI0ZVWVU2G/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=611ca # [6500621.441749] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.034001ms duration-ns=3034001 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=ckJ4Q0VSNHZVdHBRTXVHWGNLNXUzdElEZlRja3M2Zjc path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=5e886723-2633-439a-b1a7-36d62ee3cafb response="{\"id\":\"RndZXJdzQRfnyMbfhxHerCvOnirDurtx\",\"status\":\"pending\",\"expires\":\"2026-08-24T05:07:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T05:06:27Z\",\"notAfter\":\"2026-11-21T05:07:27Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl\"],\"finalize\":\"https://ca.foo/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=612ca # [6500621.508492] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=5.889402ms duration-ns=5889402 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=S1Z5WWVncjNxTmlmWnpOQVkxa2dob2FpRlpQM0VQMkM path=/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl protocol=HTTP/1.1 referer= remote-address="::1" request-id=b6c28cc4-788b-4b57-bd6f-d90a55209d19 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/mCrqSQrUr1VIgn4DzF6aAVDZadurcqLO\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/kLci9guDgRQ2k2r9LiVcrUhJQdBzfHqE\"}],\"wildcard\":false,\"expires\":\"2026-08-24T05:07:27Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=613ca # [6500621.514397] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=3.371246ms duration-ns=3371246 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=c2pBb1pvZDgzSUROTFQ0R0RIWEZpN0oxNW5tTDMwcDI path=/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=4461682d-6fba-44bb-90df-a15f71f8b7af response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"VnHx3izpK8QZFHDiRVh8Wlgskkh4dwWQ\",\"validated\":\"2026-08-23T05:07:27Z\",\"url\":\"https://ca.foo/acme/acme/challenge/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl/B2nU2zTfL2u2s2YzjIbJeyA24jbm2xFy\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=614ca # [6500621.528081] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info duration=8.014591ms duration-ns=8014591 fields.time="2026-08-23T05:07:27Z" method=POST name=ca nonce=RzIwUXhIVHVtakM2TnBDbjE1VGRza2pHbXU2VGVBUWM path=/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=6905658c-13ad-4576-98ad-56be6b1ce030 response="{\"id\":\"RndZXJdzQRfnyMbfhxHerCvOnirDurtx\",\"status\":\"valid\",\"expires\":\"2026-08-24T05:07:27Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T05:06:27Z\",\"notAfter\":\"2026-11-21T05:07:27Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ACETKuLpYHJB507ZvDiEB1O8pdwBIKyl\"],\"finalize\":\"https://ca.foo/acme/acme/order/RndZXJdzQRfnyMbfhxHerCvOnirDurtx/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/IpL2sAOC4reACaCXuPzKVH7OMULvfaeq\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=615ca # [6500621.532064] ca step-ca[203]: time="2026-08-23T05:07:27Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQZvr1PMqh20LLd7C1dZt7izAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMwNTA2MjdaFw0yNjExMjEwNTA3MjdaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEtDB3wMWmGHzIgkpa6wtXgEfPPloIYxar+bwZJ9QEO/FiS/iyZWyxrEpxrDnVaAjuDz1QTn+guHGvF+NMJWKqHqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBSRLm3cwwN92rKOFoTaiEm+ePDd5zAfBgNVHSMEGDAWgBQGEt3Z8fVc8Wn7df06ngK72vfNjTATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgG2YMD62b6kEiM+sxkFNU5mMAK8V6JSooo48adHgLZw8CIHFLtHwr1DoCPcQJchr7zbUn358B3CQGGzMxweIzz7B/ duration=1.569022ms duration-ns=1569022 fields.time="2026-08-23T05:07:27Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=MXFSS3FZQmhpQkZpOXUzOGRnMTd4TXNMbE8wNU9rYkQ path=/acme/acme/certificate/IpL2sAOC4reACaCXuPzKVH7OMULvfaeq protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=1a39db71-e715-4902-ba45-e2f031fe0e1b sans="map[dns:[test.foo]]" serial=136884303791449415929710964822104570763 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T05:06:27Z" valid-to="2026-11-21T05:07:27Z"616* Host test.foo:443 was resolved.617* IPv6: 2001:db8:1::3618* IPv4: 192.168.1.3619* Trying [2001:db8:1::3]:443...620* ALPN: curl offers h2,http/1.1621} [5 bytes data]622* TLSv1.3 (OUT), TLS handshake, Client hello (1):623} [1552 bytes data]624* SSL Trust Anchors:625* OpenSSL default paths (fallback)626{ [5 bytes data]627* TLSv1.3 (IN), TLS handshake, Server hello (2):628{ [1210 bytes data]629* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):630{ [1 bytes data]631* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):632{ [19 bytes data]633* TLSv1.3 (IN), TLS handshake, Certificate (11):634{ [1009 bytes data]635* TLSv1.3 (IN), TLS handshake, CERT verify (15):636{ [111 bytes data]637* TLSv1.3 (IN), TLS handshake, Finished (20):638{ [52 bytes data]639* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):640} [1 bytes data]641* TLSv1.3 (OUT), TLS handshake, Finished (20):642} [52 bytes data]643* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey644* ALPN: server accepted h2645* Server certificate:646* subject: CN=test.foo647* start date: Aug 23 05:07:19 2026 GMT648* expire date: Sep 22 05:07:19 2028 GMT649* issuer: CN=minica root ca 7f712c650* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384651* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384652* subjectAltName: "test.foo" matches cert's "test.foo"653* OpenSSL verify result: 13654* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)655* closing connection #0656curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)657More details here: https://curl.se/docs/sslcerts.html658659curl failed to verify the legitimacy of the server and therefore could not660establish a secure connection to it. To learn more about this situation and661how to fix it, please visit the webpage mentioned above.662server # [6500621.681116] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.663server # [6500621.681476] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.664server # [6500622.194547] server nginx[391]: nginx: the configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf syntax is ok665server # [6500622.195083] server nginx[391]: nginx: configuration file /nix/store/cg1ianm6b7c0wkyi3akik85ix2jk9h6y-nginx.conf test is successful666* Host test.foo:443 was resolved.667* IPv6: 2001:db8:1::3668* IPv4: 192.168.1.3669* Trying [2001:db8:1::3]:443...670* ALPN: curl offers h2,http/1.1671} [5 bytes data]672* TLSv1.3 (OUT), TLS handshake, Client hello (1):673} [1552 bytes data]674* SSL Trust Anchors:675* OpenSSL default paths (fallback)676{ [5 bytes data]677* TLSv1.3 (IN), TLS handshake, Server hello (2):678{ [1210 bytes data]679* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):680{ [1 bytes data]681* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):682{ [19 bytes data]683* TLSv1.3 (IN), TLS handshake, Certificate (11):684{ [929 bytes data]685* TLSv1.3 (IN), TLS handshake, CERT verify (15):686{ [79 bytes data]687* TLSv1.3 (IN), TLS handshake, Finished (20):688{ [52 bytes data]689* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):690} [1 bytes data]691* TLSv1.3 (OUT), TLS handshake, Finished (20):692} [52 bytes data]693* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey694* ALPN: server accepted h2695* Server certificate:696* subject: CN=test.foo697* start date: Aug 23 05:06:27 2026 GMT698* expire date: Nov 21 05:07:27 2026 GMT699* issuer: CN=Clan Intermediate CA700* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256701* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256702* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256703* subjectAltName: "test.foo" matches cert's "test.foo"704* OpenSSL verify result: 0705* SSL certificate verified via OpenSSL.706* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 45794 707 % Total % Received % Xferd Average Speed Time Time Time Current708 Dload Upload Total Spent Left Speed709 0 0 0 0 0 0 0 0 0* using HTTP/2710* [HTTP/2] [1] OPENED stream for https://test.foo/711* [HTTP/2] [1] [:method: GET]712* [HTTP/2] [1] [:scheme: https]713* [HTTP/2] [1] [:authority: test.foo]714* [HTTP/2] [1] [:path: /]715* [HTTP/2] [1] [user-agent: curl/8.21.0]716* [HTTP/2] [1] [accept: */*]717} [5 bytes data]718719720721722723* Request completely sent off724{ [5 bytes data]725* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):726{ [265 bytes data]727* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):728{ [265 bytes data]729730731732733734735736{ [5 bytes data]737100 20 100 20 0 0 829 0 0738* Connection #0 to host test.foo:443 left intact739client: (finished: waiting for success: curl -v https://test.foo, in 2.13 seconds)740client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2741Certificate:742 Data:743 Version: 3 (0x2)744 Serial Number:745 66:fa:f5:3c:ca:a1:db:42:cb:77:b0:b5:75:9b:7b:8b746 Signature Algorithm: ecdsa-with-SHA256747 Issuer: CN=Clan Intermediate CA748 Validity749 Not Before: Aug 23 05:06:27 2026 GMT750 Not After : Nov 21 05:07:27 2026 GMT751 Subject: CN=test.foo752 Subject Public Key Info:753 Public Key Algorithm: id-ecPublicKey754 Public-Key: (256 bit)755 pub:756 04:b4:30:77:c0:c5:a6:18:7c:c8:82:4a:5a:eb:0b:757 57:80:47:cf:3e:5a:08:63:16:ab:f9:bc:19:27:d4:758 04:3b:f1:62:4b:f8:b2:65:6c:b1:ac:4a:71:ac:39:759 d5:68:08:ee:0f:3d:50:4e:7f:a0:b8:71:af:17:e3:760 4c:25:62:aa:1e761 ASN1 OID: prime256v1762 NIST CURVE: P-256763 X509v3 extensions:764 X509v3 Key Usage: critical765 Digital Signature766 X509v3 Extended Key Usage: 767 TLS Web Server Authentication, TLS Web Client Authentication768 X509v3 Subject Key Identifier: 769 91:2E:6D:DC:C3:03:7D:DA:B2:8E:16:84:DA:88:49:BE:78:F0:DD:E7770 X509v3 Authority Key Identifier: 771 06:12:DD:D9:F1:F5:5C:F1:69:FB:75:FD:3A:9E:02:BB:DA:F7:CD:8D772 X509v3 Subject Alternative Name: 773 DNS:test.foo774 1.3.6.1.4.1.37476.9000.64.1: 775 0......acme..776 Signature Algorithm: ecdsa-with-SHA256777 Signature Value:778 30:44:02:20:1b:66:0c:0f:ad:9b:ea:41:22:33:eb:31:90:53:779 54:e6:63:00:2b:c5:7a:25:2a:28:a3:8f:1a:74:78:0b:67:0f:780 02:20:71:4b:b4:7c:2b:d4:3a:02:3d:c4:09:72:1a:fb:cd:b5:781 27:df:9f:01:dc:24:06:1b:33:31:c1:e2:33:cf:b0:7f782client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)783(finished: run the VM test script, in 12.10 seconds)784server # [6500622.806688] server systemd[1]: Reloaded Nginx Web Server.785test script finished in 12.15s786cleanup787kill NspawnMachine (pid 52)788kill NspawnMachine (pid 56)789Container ca terminated by signal KILL.790kill NspawnMachine (pid 55)791Container client terminated by signal KILL.792Container server terminated by signal KILL.793(finished: cleanup, in 0.54 seconds)