nixbot

builds

succeeded container-test-run-certificates checks.aarch64-linux.certificates · build #464 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14server: systemd-nspawn running (pid 56)15client: Waiting for journal at /build/vm-state-client/var/log/journal...16ca: Waiting for journal at /build/vm-state-ca/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.28░ Spawning container server on /build/vm-state-server.29░ Spawning container ca on /build/vm-state-ca.30░ Spawning container client on /build/vm-state-client.31client # [6518509.211294] client systemd-journald[69]: Journal started32client # [6518509.211348] client systemd-journald[69]: Runtime Journal (/run/log/journal/90e337d46bf640cbb3b6047aa17354cc) is 8M, max 2.5G, 2.4G free.33client # [6518509.216405] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.34client # [6518509.224330] client systemd[1]: Starting Flush Journal to Persistent Storage...35client # [6518509.225138] client systemd[1]: Starting Network Name Resolution...36client # [6518509.225807] client systemd[1]: Starting Create Static Device Nodes in /dev...37client # [6518509.234670] client systemd-journald[69]: Time spent on flushing to /var/log/journal/90e337d46bf640cbb3b6047aa17354cc is 1.118ms for 6 entries.38client # [6518509.234670] client systemd-journald[69]: System Journal (/var/log/journal/90e337d46bf640cbb3b6047aa17354cc) is 8M, max 4G, 3.9G free.39client # [6518509.238843] client systemd[1]: Finished Create Static Device Nodes in /dev.40client # [6518509.239073] client systemd[1]: Reached target Preparation for Local File Systems.41client # [6518509.239154] client systemd[1]: Reached target Local File Systems.42client # [6518509.239882] client systemd[1]: Listening on Boot Loader Control Service Socket.43client # [6518509.239924] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container44client # [6518509.240958] client systemd[1]: Starting Save Transient machine-id to Disk...45client # [6518509.241000] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys46client # [6518509.266814] client systemd[1]: Finished Flush Journal to Persistent Storage.47client # [6518509.268685] client systemd[1]: Starting Create System Files and Directories...48client # [6518509.283235] client systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted49client # [6518509.283413] client systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted50client # [6518509.283539] client systemd-tmpfiles[125]: fchmod() of /var/log/journal/90e337d46bf640cbb3b6047aa17354cc failed: Operation not permitted51client # [6518509.283737] client systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted52client # [6518509.285555] client systemd[1]: Finished Create System Files and Directories.53client # [6518509.287555] client systemd[1]: Starting Rebuild Journal Catalog...54client # [6518509.288339] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...55client # [6518509.300320] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.56client # [6518509.307335] client systemd[1]: Finished Rebuild Journal Catalog.57ca # [6518509.228718] ca systemd-journald[78]: Journal started58server # [6518509.223413] server systemd-journald[69]: Journal started59client # [6518509.308388] client systemd[1]: Starting Update is Completed...60server # [6518509.223465] server systemd-journald[69]: Runtime Journal (/run/log/journal/1e2a693a856f4d889854b80ec8ebb9eb) is 8M, max 2.5G, 2.4G free.61ca # [6518509.228775] ca systemd-journald[78]: Runtime Journal (/run/log/journal/15947bd6f7224108be7c2eb3beb8599d) is 8M, max 2.5G, 2.4G free.62server # [6518509.229400] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.63ca # [6518509.237981] ca systemd[1]: Starting Flush Journal to Persistent Storage...64ca # [6518509.238775] ca systemd[1]: Starting Network Name Resolution...65server # [6518509.238125] server systemd[1]: Starting Flush Journal to Persistent Storage...66ca # [6518509.239463] ca systemd[1]: Starting Create Static Device Nodes in /dev...67ca # [6518509.246559] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/15947bd6f7224108be7c2eb3beb8599d is 1.085ms for 5 entries.68ca # [6518509.246559] ca systemd-journald[78]: System Journal (/var/log/journal/15947bd6f7224108be7c2eb3beb8599d) is 8M, max 4G, 3.9G free.69ca # [6518509.260543] ca systemd[1]: Finished Create Static Device Nodes in /dev.70ca # [6518509.260802] ca systemd[1]: Finished Flush Journal to Persistent Storage.71ca # [6518509.261470] ca systemd[1]: Reached target Preparation for Local File Systems.72ca # [6518509.261582] ca systemd[1]: Reached target Local File Systems.73ca # [6518509.262370] ca systemd[1]: Listening on Boot Loader Control Service Socket.74ca # [6518509.262419] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container75ca # [6518509.263270] ca systemd[1]: Starting Save Transient machine-id to Disk...76ca # [6518509.264008] ca systemd[1]: Starting Create System Files and Directories...77ca # [6518509.264038] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys78ca # [6518509.279050] ca systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted79ca # [6518509.279243] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted80ca # [6518509.279378] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal/15947bd6f7224108be7c2eb3beb8599d failed: Operation not permitted81ca # [6518509.279573] ca systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted82ca # [6518509.280696] ca systemd[1]: Finished Create System Files and Directories.83ca # [6518509.282691] ca systemd[1]: Starting Rebuild Journal Catalog...84server # [6518509.238997] server systemd[1]: Starting Network Name Resolution...85ca # [6518509.283504] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...86server # [6518509.239681] server systemd[1]: Starting Create Static Device Nodes in /dev...87ca # [6518509.294625] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.88server # [6518509.246997] server systemd-journald[69]: Time spent on flushing to /var/log/journal/1e2a693a856f4d889854b80ec8ebb9eb is 1.314ms for 6 entries.89ca # [6518509.302110] ca systemd[1]: Finished Rebuild Journal Catalog.90server # [6518509.246997] server systemd-journald[69]: System Journal (/var/log/journal/1e2a693a856f4d889854b80ec8ebb9eb) is 8M, max 4G, 3.9G free.91ca # [6518509.303221] ca systemd[1]: Starting Update is Completed...92server # [6518509.260552] server systemd[1]: Finished Create Static Device Nodes in /dev.93ca # [6518509.313870] ca systemd[1]: Finished Update is Completed.94server # [6518509.260848] server systemd[1]: Reached target Preparation for Local File Systems.95server # [6518509.260939] server systemd[1]: Reached target Local File Systems.96server # [6518509.261707] server systemd[1]: Listening on Boot Loader Control Service Socket.97server # [6518509.261750] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container98server # [6518509.262624] server systemd[1]: Starting Save Transient machine-id to Disk...99server # [6518509.262660] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys100server # [6518509.267619] server systemd[1]: Finished Flush Journal to Persistent Storage.101server # [6518509.269065] server systemd[1]: Starting Create System Files and Directories...102server # [6518509.285031] server systemd-tmpfiles[117]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted103server # [6518509.285735] server systemd-tmpfiles[117]: fchmod() of /var/log/journal failed: Operation not permitted104server # [6518509.285896] server systemd-tmpfiles[117]: fchmod() of /var/log/journal/1e2a693a856f4d889854b80ec8ebb9eb failed: Operation not permitted105server # [6518509.286282] server systemd-tmpfiles[117]: fchmod() of /run/log/journal failed: Operation not permitted106server # [6518509.288343] server systemd[1]: Finished Create System Files and Directories.107server # [6518509.289377] server systemd[1]: Starting Rebuild Journal Catalog...108server # [6518509.290080] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...109server # [6518509.302696] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.110server # [6518509.309446] server systemd[1]: Finished Rebuild Journal Catalog.111server # [6518509.310437] server systemd[1]: Starting Update is Completed...112client # [6518509.318968] client systemd[1]: Finished Update is Completed.113client # [6518509.357540] client systemd[1]: Finished Firewall.114server # [6518509.320824] server systemd[1]: Finished Update is Completed.115client # [6518509.357768] client systemd[1]: Reached target Preparation for Network.116server # [6518509.379213] server systemd[1]: Finished Firewall.117client # [6518509.358077] client systemd[1]: Listening on Network Management Resolve Hook Socket.118client # [6518509.359218] client systemd[1]: Starting Network Management...119ca # [6518509.374106] ca systemd[1]: Finished Firewall.120server # [6518509.379356] server systemd[1]: Reached target Preparation for Network.121ca # [6518509.374254] ca systemd[1]: Reached target Preparation for Network.122server # [6518509.379576] server systemd[1]: Listening on Network Management Resolve Hook Socket.123ca # [6518509.374464] ca systemd[1]: Listening on Network Management Resolve Hook Socket.124server # [6518509.380583] server systemd[1]: Starting Network Management...125ca # [6518509.375473] ca systemd[1]: Starting Network Management...126server # [6518509.836051] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted127server # [6518509.836152] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted128server # [6518509.842984] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.129server # [6518509.843155] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.130server # [6518509.843325] server systemd-networkd[186]: lo: Link UP131server # [6518509.843328] server systemd-networkd[186]: lo: Gained carrier132server # [6518509.843493] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.133server # [6518509.843841] server systemd[1]: Started Network Management.134server # [6518509.844157] server systemd-networkd[186]: eth1: Link UP135server # [6518509.844454] server systemd-networkd[186]: eth1: Gained carrier136server # [6518509.844923] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...137server # [6518509.866174] server systemd[1]: Finished Save Transient machine-id to Disk.138server # [6518509.882012] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.139server # [6518510.025171] server systemd-resolved[93]: Positive Trust Anchors:140server # [6518510.025183] server systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d141server # [6518510.025186] server systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16142server # [6518510.025221] server systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test143server # [6518510.047280] server systemd-resolved[93]: Using system hostname 'server'.144server # [6518510.049047] server systemd[1]: Started Network Name Resolution.145server # [6518510.049126] server systemd[1]: Reached target Network.146server # [6518510.049189] server systemd[1]: Reached target Network is Online.147server # [6518510.049238] server systemd[1]: Reached target System Initialization.148server # [6518510.049444] server systemd[1]: Started Renew ACME Certificate for test.foo.149server # [6518510.049477] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container150server # [6518510.049502] server systemd[1]: Started Daily Cleanup of Temporary Directories.151server # [6518510.049523] server systemd[1]: Reached target Timer Units.152server # [6518510.049656] server systemd[1]: Listening on D-Bus System Message Bus Socket.153server # [6518510.049758] server systemd[1]: Listening on Nix Daemon Socket.154server # [6518510.049865] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.155server # [6518510.049889] server systemd[1]: Reached target Socket Units.156server # [6518510.049926] server systemd[1]: Reached target Basic System.157server # [6518510.051218] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...158server # [6518510.052022] server systemd[1]: Starting Import lastlog data into lastlog2 database...159server # [6518510.052063] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem160server # [6518510.052883] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...161server # [6518510.054152] server systemd[1]: Starting D-Bus System Message Bus...162client # [6518509.825098] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted163ca # [6518509.836049] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted164client # [6518509.825191] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted165client # [6518509.831964] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.166ca # [6518509.836143] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted167client # [6518509.832145] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.168ca # [6518509.842946] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.169client # [6518509.832311] client systemd-networkd[182]: lo: Link UP170ca # [6518509.843111] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.171client # [6518509.832319] client systemd-networkd[182]: lo: Gained carrier172ca # [6518509.843278] ca systemd-networkd[195]: lo: Link UP173client # [6518509.832514] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.174ca # [6518509.843280] ca systemd-networkd[195]: lo: Gained carrier175client # [6518509.832939] client systemd[1]: Started Network Management.176ca # [6518509.843456] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.177client # [6518509.832987] client systemd-networkd[182]: eth1: Link UP178ca # [6518509.843847] ca systemd[1]: Started Network Management.179client # [6518509.833234] client systemd-networkd[182]: eth1: Gained carrier180ca # [6518509.843925] ca systemd-networkd[195]: eth1: Link UP181client # [6518509.834085] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...182ca # [6518509.844203] ca systemd-networkd[195]: eth1: Gained carrier183client # [6518509.861446] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.184client # [6518509.866501] client systemd[1]: Finished Save Transient machine-id to Disk.185ca # [6518509.844901] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...186client # [6518510.046744] client systemd-resolved[92]: Positive Trust Anchors:187ca # [6518509.865640] ca systemd[1]: Finished Save Transient machine-id to Disk.188client # [6518510.046757] client systemd-resolved[92]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d189ca # [6518509.881998] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.190client # [6518510.046760] client systemd-resolved[92]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16191ca # [6518510.031479] ca systemd-resolved[104]: Positive Trust Anchors:192client # [6518510.046796] client systemd-resolved[92]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test193ca # [6518510.031492] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d194client # [6518510.068937] client systemd-resolved[92]: Using system hostname 'client'.195ca # [6518510.031495] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16196client # [6518510.070325] client systemd[1]: Started Network Name Resolution.197ca # [6518510.031529] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test198client # [6518510.070401] client systemd[1]: Reached target Network.199ca # [6518510.053947] ca systemd-resolved[104]: Using system hostname 'ca'.200client # [6518510.070464] client systemd[1]: Reached target System Initialization.201ca # [6518510.055370] ca systemd[1]: Started Network Name Resolution.202client # [6518510.070503] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container203ca # [6518510.055442] ca systemd[1]: Reached target Network.204client # [6518510.070531] client systemd[1]: Started Daily Cleanup of Temporary Directories.205ca # [6518510.055503] ca systemd[1]: Reached target Network is Online.206client # [6518510.070545] client systemd[1]: Reached target Timer Units.207ca # [6518510.055546] ca systemd[1]: Reached target System Initialization.208client # [6518510.070659] client systemd[1]: Listening on D-Bus System Message Bus Socket.209ca # [6518510.055757] ca systemd[1]: Started Renew ACME Certificate for ca.foo.210client # [6518510.070767] client systemd[1]: Listening on Nix Daemon Socket.211ca # [6518510.055789] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container212client # [6518510.070860] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.213ca # [6518510.055812] ca systemd[1]: Started Daily Cleanup of Temporary Directories.214client # [6518510.070881] client systemd[1]: Reached target Socket Units.215ca # [6518510.055829] ca systemd[1]: Reached target Timer Units.216client # [6518510.070915] client systemd[1]: Reached target Basic System.217ca # [6518510.055946] ca systemd[1]: Listening on D-Bus System Message Bus Socket.218client # [6518510.088513] client systemd[1]: Starting Import lastlog data into lastlog2 database...219ca # [6518510.056077] ca systemd[1]: Listening on Nix Daemon Socket.220ca # [6518510.056196] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.221ca # [6518510.056219] ca systemd[1]: Reached target Socket Units.222ca # [6518510.056262] ca systemd[1]: Reached target Basic System.223ca # [6518510.088513] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...224ca # [6518510.089663] ca systemd[1]: Starting Import lastlog data into lastlog2 database...225ca # [6518510.089727] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem226ca # [6518510.090866] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...227ca # [6518510.092261] ca systemd[1]: Starting step-ca service...228ca # [6518510.093405] ca systemd[1]: Starting D-Bus System Message Bus...229ca # [6518510.108654] ca systemd[1]: Finished Import lastlog data into lastlog2 database.230ca # [6518510.213789] ca acme-setup-privileged[201]: + set -euo pipefail231ca # [6518510.213789] ca acme-setup-privileged[201]: + cd /var/lib/acme232ca # [6518510.213789] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts233ca # [6518510.214535] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts234ca # [6518510.216407] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo235ca # [6518510.216407] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'236ca # [6518510.216407] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo237ca # [6518510.216533] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'238ca # [6518510.222535] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.239ca # [6518510.225819] ca nsncd[203]: Aug 23 10:05:36.278 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"240ca # [6518510.225975] ca systemd[1]: Started Name Service Cache Daemon (nsncd).241ca # [6518510.226081] ca systemd[1]: Reached target Host and Network Name Lookups.242ca # [6518510.226164] ca systemd[1]: Reached target User and Group Name Lookups.243ca # [6518510.227637] ca systemd[1]: Starting User Login Management...244ca # [6518510.228879] ca systemd[1]: Starting Permit User Sessions...245ca # [6518510.238470] ca systemd[1]: Finished Permit User Sessions.246ca # [6518510.239543] ca systemd[1]: Started Console Getty.247ca # [6518510.239584] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0248ca # [6518510.239602] ca systemd[1]: Reached target Login Prompts.249ca # [6518510.339389] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...250client # [6518510.089624] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...251client # [6518510.091437] client systemd[1]: Starting D-Bus System Message Bus...252client # [6518510.108544] client systemd[1]: Finished Import lastlog data into lastlog2 database.253client # [6518510.201651] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.254client # [6518510.214170] client nsncd[189]: Aug 23 10:05:36.267 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"255client # [6518510.214246] client systemd[1]: Started Name Service Cache Daemon (nsncd).256client # [6518510.214301] client systemd[1]: Reached target Host and Network Name Lookups.257client # [6518510.214363] client systemd[1]: Reached target User and Group Name Lookups.258client # [6518510.215761] client systemd[1]: Starting User Login Management...259client # [6518510.216708] client systemd[1]: Starting Permit User Sessions...260client # [6518510.226998] client systemd[1]: Finished Permit User Sessions.261client # [6518510.228184] client systemd[1]: Started Console Getty.262client # [6518510.228228] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0263client # [6518510.228246] client systemd[1]: Reached target Login Prompts.264client # [6518510.330667] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...265client # [6518510.331347] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'266client # [6518510.331347] client dbus-broker-launch[190]: Invalid user-name in /nix/store/71vmh4xl6s5dgp2wq5sm5rdd4lr016c0-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"267client # [6518510.331703] client systemd[1]: Started D-Bus System Message Bus.268client # [6518510.338747] client dbus-broker-launch[190]: Ready269server # [6518510.104908] server systemd[1]: Finished Import lastlog data into lastlog2 database.270server # [6518510.190115] server acme-setup-privileged[192]: + set -euo pipefail271server # [6518510.190115] server acme-setup-privileged[192]: + cd /var/lib/acme272server # [6518510.190115] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts273server # [6518510.191645] server acme-setup-privileged[192]: + chown -R acme .lego/accounts274server # [6518510.193570] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo275server # [6518510.193603] server acme-setup-privileged[192]: + '[' -d test.foo ']'276server # [6518510.193603] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo277server # [6518510.193603] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'278server # [6518510.214761] server nsncd[194]: Aug 23 10:05:36.267 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"279server # [6518510.223052] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.280server # [6518510.223901] server systemd[1]: Started Name Service Cache Daemon (nsncd).281server # [6518510.224499] server systemd[1]: Reached target Host and Network Name Lookups.282server # [6518510.224576] server systemd[1]: Reached target User and Group Name Lookups.283server # [6518510.225653] server systemd[1]: Starting User Login Management...284server # [6518510.226586] server systemd[1]: Starting Permit User Sessions...285server # [6518510.236359] server systemd[1]: Finished Permit User Sessions.286server # [6518510.238087] server systemd[1]: Started Console Getty.287server # [6518510.238162] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0288server # [6518510.238208] server systemd[1]: Reached target Login Prompts.289server # [6518510.333522] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...290server # [6518510.334129] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'291server # [6518510.334129] server dbus-broker-launch[195]: Invalid user-name in /nix/store/3mkgnlb89jy49c4a1z0swjahhcvmnw8p-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"292server # [6518510.334562] server systemd[1]: Started D-Bus System Message Bus.293server # [6518510.342681] server dbus-broker-launch[195]: Ready294ca # [6518510.339870] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'295ca # [6518510.339870] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/bz7ygr15ilclf6krkxd1w5j7l4dw4kny-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"296ca # [6518510.340271] ca systemd[1]: Started D-Bus System Message Bus.297ca # [6518510.346978] ca dbus-broker-launch[205]: Ready298server # [6518510.864033] server systemd-logind[219]: New seat seat0.299server # [6518510.864223] server systemd[1]: Started User Login Management.300server # [6518510.865381] server systemd[1]: Starting linger-users.service...301server # [6518510.907675] server systemd[1]: linger-users.service: Deactivated successfully.302server # [6518510.907816] server systemd[1]: Finished linger-users.service.303server # [6518510.944905] server acme-setup-start[208]: + set -euo pipefail304ca # [6518510.876329] ca systemd-logind[230]: New seat seat0.305server # [6518510.944905] server acme-setup-start[208]: + test -e ca/key.pem306server # [6518510.945283] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local307server # [6518510.962679] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.308server # [6518510.964146] server systemd[1]: Starting Ensure certificate for test.foo...309ca # [6518510.876535] ca systemd[1]: Started User Login Management.310ca # [6518510.880146] ca systemd-networkd[195]: eth1: Gained IPv6LL311ca # [6518510.900548] ca systemd[1]: Starting linger-users.service...312ca # [6518510.911708] ca systemd[1]: linger-users.service: Deactivated successfully.313ca # [6518510.911906] ca systemd[1]: Finished linger-users.service.314ca # [6518510.939145] ca acme-setup-start[218]: + set -euo pipefail315ca # [6518510.939145] ca acme-setup-start[218]: + test -e ca/key.pem316ca # [6518510.939680] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local317ca # [6518510.955355] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.318ca # [6518510.956914] ca systemd[1]: Starting Ensure certificate for ca.foo...319ca # [6518511.052950] ca step-ca[204]: badger 2026/08/23 10:05:37 INFO: All 0 tables opened in 0s320ca # [6518511.056557] ca step-ca[204]: 2026/08/23 10:05:37 Building new tls configuration using step-ca x509 Signer Interface321ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 Starting Smallstep CA/0.30.2 (linux/arm64)322ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 Documentation: https://u.step.sm/docs/ca323ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 Community Discord: https://u.step.sm/discord324ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 Config file: /etc/smallstep/ca.json325ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 The primary server URL is https://ca.foo:1443326ca # [6518511.061373] ca step-ca[204]: 2026/08/23 10:05:37 Root certificates are available at https://ca.foo:1443/roots.pem327ca # [6518511.061497] ca step-ca[204]: 2026/08/23 10:05:37 X.509 Root Fingerprint: fcec151c7705057538ab7b446472065d7ea631e5f4168a5856ccb5b20a98592a328ca # [6518511.061621] ca systemd[1]: Started step-ca service.329ca # [6518511.061902] ca step-ca[204]: 2026/08/23 10:05:37 Serving HTTPS on 0.0.0.0:1443 ...330client # [6518510.885807] client systemd-logind[205]: New seat seat0.331client # [6518510.886301] client systemd[1]: Started User Login Management.332client # [6518510.901222] client systemd[1]: Starting linger-users.service...333client # [6518510.912259] client systemd[1]: linger-users.service: Deactivated successfully.334client # [6518510.912332] client systemd[1]: Finished linger-users.service.335client # [6518510.912718] client systemd[1]: Reached target Multi-User System.336client # [6518510.912955] client systemd[1]: Startup finished in 2.106s.337ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 338client # [6518511.428145] client systemd-networkd[182]: eth1: Gained IPv6LL339server # [6518511.776128] server systemd-networkd[186]: eth1: Gained IPv6LL340ca # [6518511.786276] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/341server # [6518511.794599] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/342ca # [6518511.788987] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']'343ca # [6518511.789032] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=344server # [6518511.797058] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'345ca # [6518511.799436] ca acme-ca.foo-start[293]: + cd ca.foo346server # [6518511.797102] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=347ca # [6518511.799660] ca acme-ca.foo-start[293]: + cp -vp cert.pem ../out/cert.pem348server # [6518511.808162] server acme-test.foo-start[255]: + cd test.foo349ca # [6518511.800749] ca acme-ca.foo-start[294]: 'cert.pem' -> '../out/cert.pem'350server # [6518511.808374] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem351ca # [6518511.801090] ca acme-ca.foo-start[293]: + cp -vp key.pem ../out/key.pem352server # [6518511.809865] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'353ca # [6518511.802318] ca acme-ca.foo-start[293]: 'key.pem' -> '../out/key.pem'354server # [6518511.810138] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem355ca # [6518511.802581] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem356server # [6518511.811314] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'357ca # [6518511.804195] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem358server # [6518511.811584] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem359ca # [6518511.805587] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem360server # [6518511.813421] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem361ca # [6518511.807105] ca acme-ca.foo-start[256]: + for fixpath in out certificates362server # [6518511.815105] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem363ca # [6518511.807136] ca acme-ca.foo-start[256]: + '[' -d out ']'364server # [6518511.816574] server acme-test.foo-start[245]: + for fixpath in out certificates365ca # [6518511.807136] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out366server # [6518511.816599] server acme-test.foo-start[245]: + '[' -d out ']'367ca # [6518511.808864] ca acme-ca.foo-start[256]: + chown -R acme:nginx out368server # [6518511.816599] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out369ca # [6518511.811123] ca acme-ca.foo-start[256]: + for fixpath in out certificates370server # [6518511.818033] server acme-test.foo-start[245]: + chown -R acme:nginx out371ca # [6518511.811123] ca acme-ca.foo-start[256]: + '[' -d certificates ']'372server # [6518511.820157] server acme-test.foo-start[245]: + for fixpath in out certificates373ca # [6518511.815379] ca systemd[1]: Finished Ensure certificate for ca.foo.374server # [6518511.820178] server acme-test.foo-start[245]: + '[' -d certificates ']'375ca # [6518511.816829] ca systemd[1]: Starting Nginx Web Server...376server # [6518511.848365] server systemd[1]: Finished Ensure certificate for test.foo.377server # [6518511.849755] server systemd[1]: Starting Nginx Web Server...378server # [6518512.589942] server nginx-pre-start[267]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok379server # [6518512.590259] server nginx-pre-start[267]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful380server # [6518512.632431] server systemd[1]: Started Nginx Web Server.381server # [6518512.632876] server systemd[1]: Reached target Multi-User System.382server # [6518512.634251] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...383ca # [6518512.609118] ca nginx-pre-start[305]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok384ca # [6518512.609449] ca nginx-pre-start[305]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful385ca # [6518512.632918] ca systemd[1]: Started Nginx Web Server.386ca # [6518512.633344] ca systemd[1]: Reached target Multi-User System.387ca # [6518512.634694] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...388server # [6518513.338394] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/389ca # [6518513.368921] ca acme-order-renew-ca.foo-start[308]: Waiting to acquire lock in /run/acme/390server # [6518513.341145] server acme-order-renew-test.foo-start[270]: + set -euo pipefail391ca # [6518513.371323] ca acme-order-renew-ca.foo-start[308]: + set -euo pipefail392server # [6518513.341222] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108393ca # [6518513.371404] ca acme-order-renew-ca.foo-start[308]: + echo 88dc4fc401a6091a1bd9394server # [6518513.341333] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt395ca # [6518513.371523] ca acme-order-renew-ca.foo-start[308]: + cmp -s domainhash.txt certificates/domainhash.txt396server # [6518513.342386] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run397ca # [6518513.372575] ca acme-order-renew-ca.foo-start[308]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run398server # [6518513.356893] server acme-order-renew-test.foo-start[282]: 2026/08/23 10:05:39 No key found for account none@none.tld. Generating a P256 key.399ca # [6518513.391677] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 No key found for account none@none.tld. Generating a P256 key.400server # [6518513.357189] server acme-order-renew-test.foo-start[282]: 2026/08/23 10:05:39 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key401ca # [6518513.392072] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key402server # [6518513.388678] server acme-order-renew-test.foo-start[282]: 2026/08/23 10:05:39 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority403ca # [6518513.413534] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration="99.201µs" duration-ns=99201 fields.time="2026-08-23T10:05:39Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=f6782dfe-f527-4df9-adad-70e5bb7fbbb4 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=404ca # [6518513.414067] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] acme: Registering account for none@none.tld405ca # [6518513.425333] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=11.246555ms duration-ns=11246555 fields.time="2026-08-23T10:05:39Z" method=HEAD name=ca nonce=MjJmeGdvaGRFNWhCWThiRzBJeEZTSjZHQVhZTzBCbmE path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=deded5a3-29ca-4779-8aed-d320467f213b size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=406ca # [6518513.428826] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=2.707838ms duration-ns=2707838 fields.time="2026-08-23T10:05:39Z" method=POST name=ca nonce=Z0gwSG5SUTJyTUw1VkpFY2NucHk0NUdLaWdON1RXb0o path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=15a858a9-5e61-4c29-9f17-380a09e935c3 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/1df1znBdcfxcJsSOi3ker0qqSGVfTjj4/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=407server # [6518513.389167] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.408ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: !!!! HEADS UP !!!!409ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: Your account credentials have been saved in your410ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: configuration directory at "accounts".411ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: You should make a secure backup of this folder now. This412ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: configuration directory will also contain private keys413server # [6518513.389167] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.414ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: generated by lego and certificates obtained from the ACME415server # [6518513.389228] server acme-order-renew-test.foo-start[270]: + exit 10416ca # [6518513.429128] ca acme-order-renew-ca.foo-start[320]: server. Making regular backups of this folder is ideal.417server # [6518513.393029] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a418ca # [6518513.429258] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate419server # [6518513.393122] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.420ca # [6518513.432426] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=2.89932ms duration-ns=2899320 fields.time="2026-08-23T10:05:39Z" method=POST name=ca nonce=SDREZndVTVFTSDRjQVRGcnpucDNZTGowQkQ3Z3l6SXU path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=7db04c50-807d-4892-b2ff-da5c5d709b66 response="{\"id\":\"tyOq3sjEEiD1QQfMhiB6FSvOVcVJvcdr\",\"status\":\"pending\",\"expires\":\"2026-08-24T10:05:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T10:04:39Z\",\"notAfter\":\"2026-11-21T10:05:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/tyOq3sjEEiD1QQfMhiB6FSvOVcVJvcdr/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=421server # [6518513.393365] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.422ca # [6518513.492192] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=2.956961ms duration-ns=2956961 fields.time="2026-08-23T10:05:39Z" method=POST name=ca nonce=MExXZ0ZJYmVtVFNJUFVZZ0lCZ1NwM09mYTYzZnhEZjE path=/acme/acme/authz/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6adf37ac-00bc-402d-8665-40023d65bbb7 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"WgJJoi9ssHJ6HFWQfZBMNub0JyVgXSNZ\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP/bTgTONxsRwQ1myAMFcnj0PI0xD6GyvEL\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"WgJJoi9ssHJ6HFWQfZBMNub0JyVgXSNZ\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP/Foae7aqkLvfGHmugnk0YGeqZfs3jKKZk\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"WgJJoi9ssHJ6HFWQfZBMNub0JyVgXSNZ\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP/HP2QzeyAngSMZD4QUL2Y2jjGq2YLSCIX\"}],\"wildcard\":false,\"expires\":\"2026-08-24T10:05:39Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=423server # [6518513.393699] server systemd[1]: Startup finished in 4.607s.424ca # [6518513.492461] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP425ca # [6518513.492461] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01426ca # [6518513.492461] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] acme: use http-01 solver427ca # [6518513.492461] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] acme: Trying to solve HTTP-01428ca # [6518513.496300] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=3.379647ms duration-ns=3379647 fields.time="2026-08-23T10:05:39Z" method=POST name=ca nonce=cDBRdWNWd0thWXFGOXp5aXBXYzNjSDFpNk1NUG9mZ1k path=/acme/acme/challenge/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP/Foae7aqkLvfGHmugnk0YGeqZfs3jKKZk protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=819fef5b-630f-4040-ab26-ec1c57d4202b response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"WgJJoi9ssHJ6HFWQfZBMNub0JyVgXSNZ\",\"validated\":\"2026-08-23T10:05:39Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP/Foae7aqkLvfGHmugnk0YGeqZfs3jKKZk\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=429ca # [6518513.496509] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] The server validated our request430ca # [6518513.496568] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates431ca # [6518513.506939] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info duration=9.580373ms duration-ns=9580373 fields.time="2026-08-23T10:05:39Z" method=POST name=ca nonce=SXFZWGhNdUV6QUljRVpOUDVGWEYyMnN6TTY1eEU3Uk0 path=/acme/acme/order/tyOq3sjEEiD1QQfMhiB6FSvOVcVJvcdr/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=d0b0b803-686d-42df-b56c-908acd16ca58 response="{\"id\":\"tyOq3sjEEiD1QQfMhiB6FSvOVcVJvcdr\",\"status\":\"valid\",\"expires\":\"2026-08-24T10:05:39Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-23T10:04:39Z\",\"notAfter\":\"2026-11-21T10:05:39Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/DtaeG2nLDWQWZVkR3Z9lTAjg3EXi5OlP\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/tyOq3sjEEiD1QQfMhiB6FSvOVcVJvcdr/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/lPZxiEjPGeZJJowZFRCaA1agvtcpNLXQ\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=432ca # [6518513.508613] ca step-ca[204]: time="2026-08-23T10:05:39Z" level=info certificate="MIIB0jCCAXmgAwIBAgIQHegpgmB9bIcOXpYUdi20hTAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMxMDA0MzlaFw0yNjExMjExMDA1MzlaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABPMBkPnU/a1rtMlEnUwTMUGTwnGpzu8GVDkgeEB4Id5/moB7HZE+/XszR+zS39yYkDlQqNu0JY4xVcb3oeGJ8YGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQURU/Mj/qr8y9LaF9Ut8R2y1PciBMwHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNHADBEAiBygZx1V9RDom+EpxbaMiD/OcTCWxkm0Dj9XU8PsUTppwIgB5y59aLP80o/1Yy+6RQFGV1L7HncqI4QexPbH5tqiw4=" duration=1.169096ms duration-ns=1169096 fields.time="2026-08-23T10:05:39Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=WFRtSnk4UGs0eEpXMGpadGVEcnc1S2RWemZpZFc0M2E path=/acme/acme/certificate/lPZxiEjPGeZJJowZFRCaA1agvtcpNLXQ protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=99bac07d-20ce-49b8-ab28-bda2e8f8f989 sans="map[dns:[ca.foo]]" serial=39753066657259706074107733990383137925 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T10:04:39Z" valid-to="2026-11-21T10:05:39Z"433ca # [6518513.508788] ca acme-order-renew-ca.foo-start[320]: 2026/08/23 10:05:39 [INFO] [ca.foo] Server responded with a certificate.434ca # [6518513.514638] ca acme-order-renew-ca.foo-start[308]: + mv domainhash.txt certificates/435ca # [6518513.516278] ca acme-order-renew-ca.foo-start[308]: + touch out/acme-success436ca # [6518513.517618] ca acme-order-renew-ca.foo-start[308]: + cmp -s certificates/ca.foo.crt out/fullchain.pem437ca # [6518513.518597] ca acme-order-renew-ca.foo-start[308]: + touch out/renewed438ca # [6518513.520346] ca acme-order-renew-ca.foo-start[308]: + echo Installing new certificate439ca # [6518513.520346] ca acme-order-renew-ca.foo-start[308]: Installing new certificate440ca # [6518513.520391] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.crt out/fullchain.pem441ca # [6518513.521622] ca acme-order-renew-ca.foo-start[353]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'442ca # [6518513.521845] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.key out/key.pem443ca # [6518513.523469] ca acme-order-renew-ca.foo-start[354]: 'certificates/ca.foo.key' -> 'out/key.pem'444ca # [6518513.523730] ca acme-order-renew-ca.foo-start[308]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem445ca # [6518513.525113] ca acme-order-renew-ca.foo-start[355]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'446ca # [6518513.525318] ca acme-order-renew-ca.foo-start[308]: + ln -sf fullchain.pem out/cert.pem447ca # [6518513.527067] ca acme-order-renew-ca.foo-start[308]: + cat out/key.pem out/fullchain.pem448ca # [6518513.528858] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates449ca # [6518513.528881] ca acme-order-renew-ca.foo-start[308]: + '[' -d out ']'450ca # [6518513.528881] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= out451ca # [6518513.530249] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx out452ca # [6518513.532503] ca acme-order-renew-ca.foo-start[308]: + for fixpath in out certificates453ca # [6518513.532532] ca acme-order-renew-ca.foo-start[308]: + '[' -d certificates ']'454ca # [6518513.532532] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=rX,o= certificates455ca # [6518513.533860] ca acme-order-renew-ca.foo-start[308]: + chown -R acme:nginx certificates456ca # [6518513.536184] ca acme-order-renew-ca.foo-start[308]: + chmod -R u=rwX,g=,o= accounts/.457ca # [6518513.723904] ca systemd[1]: Reloading Nginx Web Server...458ca # [6518513.728850] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.459ca # [6518513.729020] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.460ca # [6518514.319588] ca nginx[371]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok461ca # [6518514.319919] ca nginx[371]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful462ca # [6518514.926584] ca systemd[1]: Reloaded Nginx Web Server.463ca # [6518514.926904] ca systemd[1]: Startup finished in 6.102s.464ca # [6518514.976471] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...465ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 4.47 seconds)466ca # [6518515.544779] ca acme-order-renew-ca.foo-start[386]: Waiting to acquire lock in /run/acme/467ca # [6518515.547647] ca acme-order-renew-ca.foo-start[386]: + set -euo pipefail468ca # [6518515.547721] ca acme-order-renew-ca.foo-start[386]: + echo 88dc4fc401a6091a1bd9469ca # [6518515.547832] ca acme-order-renew-ca.foo-start[386]: + cmp -s domainhash.txt certificates/domainhash.txt470ca # [6518515.548951] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.key ']'471ca # [6518515.548995] ca acme-order-renew-ca.foo-start[386]: + '[' -e certificates/ca.foo.crt ']'472ca # [6518515.549326] ca acme-order-renew-ca.foo-start[394]: ++ find accounts -name none@none.tld.key473ca # [6518515.551387] ca acme-order-renew-ca.foo-start[386]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'474ca # [6518515.551438] ca acme-order-renew-ca.foo-start[386]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic475ca # [6518515.593247] ca step-ca[204]: time="2026-08-23T10:05:41Z" level=info duration="52.961µs" duration-ns=52961 fields.time="2026-08-23T10:05:41Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=03e87de5-768b-4dbd-9190-f7bcb91cfa9e response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=476ca # [6518515.593674] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 10:05:41 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint477ca # [6518515.593674] ca acme-order-renew-ca.foo-start[395]: 2026/08/23 10:05:41 [INFO] [ca.foo] The certificate expires at 2026-11-21T10:05:39Z, the renewal can be performed in 1439h59m37.353206568s: no renewal.478ca # [6518515.594160] ca acme-order-renew-ca.foo-start[386]: + mv domainhash.txt certificates/479ca # [6518515.596297] ca acme-order-renew-ca.foo-start[386]: + touch out/acme-success480ca # [6518515.597714] ca acme-order-renew-ca.foo-start[386]: + cmp -s certificates/ca.foo.crt out/fullchain.pem481ca # [6518515.598668] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates482ca # [6518515.598699] ca acme-order-renew-ca.foo-start[386]: + '[' -d out ']'483ca # [6518515.598699] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= out484ca # [6518515.599993] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx out485ca # [6518515.602338] ca acme-order-renew-ca.foo-start[386]: + for fixpath in out certificates486ca # [6518515.602338] ca acme-order-renew-ca.foo-start[386]: + '[' -d certificates ']'487ca # [6518515.602389] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=rX,o= certificates488ca # [6518515.604434] ca acme-order-renew-ca.foo-start[386]: + chown -R acme:nginx certificates489ca # [6518515.606971] ca acme-order-renew-ca.foo-start[386]: + chmod -R u=rwX,g=,o= accounts/.490ca # [6518515.777122] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.491ca # [6518515.777433] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.492server: must succeed: systemctl restart acme-test.foo.service493server # [6518518.800707] server systemd[1]: acme-test.foo.service: Deactivated successfully.494server # [6518518.800883] server systemd[1]: Stopped Ensure certificate for test.foo.495server # [6518518.801596] server systemd[1]: Stopping Ensure certificate for test.foo...496server # [6518518.802981] server systemd[1]: Starting Ensure certificate for test.foo...497server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.68 seconds)498client: waiting for success: curl -v https://test.foo499* Host test.foo:443 was resolved.500* IPv6: 2001:db8:1::3501* IPv4: 192.168.1.3502* Trying [2001:db8:1::3]:443...503* ALPN: curl offers h2,http/1.1504} [5 bytes data]505* TLSv1.3 (OUT), TLS handshake, Client hello (1):506} [1552 bytes data]507* SSL Trust Anchors:508* OpenSSL default paths (fallback)509{ [5 bytes data]510* TLSv1.3 (IN), TLS handshake, Server hello (2):511{ [1210 bytes data]512* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):513{ [1 bytes data]514* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):515{ [19 bytes data]516* TLSv1.3 (IN), TLS handshake, Certificate (11):517{ [1008 bytes data]518* TLSv1.3 (IN), TLS handshake, CERT verify (15):519{ [111 bytes data]520* TLSv1.3 (IN), TLS handshake, Finished (20):521{ [52 bytes data]522* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):523} [1 bytes data]524* TLSv1.3 (OUT), TLS handshake, Finished (20):525} [52 bytes data]526* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey527* ALPN: server accepted h2528* Server certificate:529* subject: CN=test.foo530* start date: Aug 23 10:05:37 2026 GMT531* expire date: Sep 22 10:05:37 2028 GMT532* issuer: CN=minica root ca 7454ac533* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384534* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384535* subjectAltName: "test.foo" matches cert's "test.foo"536* OpenSSL verify result: 13537* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)538* closing connection #0539curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)540More details here: https://curl.se/docs/sslcerts.html541542curl failed to verify the legitimacy of the server and therefore could not543establish a secure connection to it. To learn more about this situation and544how to fix it, please visit the webpage mentioned above.545server # [6518519.434616] server acme-test.foo-start[316]: Waiting to acquire lock in /run/acme/546server # [6518519.437110] server acme-test.foo-start[316]: + '[' -e out/acme-success ']'547server # [6518519.437110] server acme-test.foo-start[316]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=548server # [6518519.450800] server acme-test.foo-start[326]: + cd test.foo549server # [6518519.450800] server acme-test.foo-start[326]: + cp -vp cert.pem ../out/cert.pem550server # [6518519.452980] server acme-test.foo-start[327]: 'cert.pem' -> '../out/cert.pem'551server # [6518519.453164] server acme-test.foo-start[326]: + cp -vp key.pem ../out/key.pem552server # [6518519.453941] server acme-test.foo-start[326]: 'key.pem' -> '../out/key.pem'553server # [6518519.454155] server acme-test.foo-start[316]: + cat out/cert.pem ca/cert.pem554server # [6518519.455875] server acme-test.foo-start[316]: + cp ca/cert.pem out/chain.pem555server # [6518519.457642] server acme-test.foo-start[316]: + cat out/key.pem out/fullchain.pem556server # [6518519.459285] server acme-test.foo-start[316]: + for fixpath in out certificates557server # [6518519.459308] server acme-test.foo-start[316]: + '[' -d out ']'558server # [6518519.459325] server acme-test.foo-start[316]: + chmod -R u=rwX,g=rX,o= out559server # [6518519.460854] server acme-test.foo-start[316]: + chown -R acme:nginx out560server # [6518519.465181] server acme-test.foo-start[316]: + for fixpath in out certificates561server # [6518519.465181] server acme-test.foo-start[316]: + '[' -d certificates ']'562server # [6518519.469433] server systemd[1]: Finished Ensure certificate for test.foo.563server # [6518519.471831] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...564* Host test.foo:443 was resolved.565* IPv6: 2001:db8:1::3566* IPv4: 192.168.1.3567* Trying [2001:db8:1::3]:443...568* ALPN: curl offers h2,http/1.1569} [5 bytes data]570* TLSv1.3 (OUT), TLS handshake, Client hello (1):571} [1552 bytes data]572* SSL Trust Anchors:573* OpenSSL default paths (fallback)574{ [5 bytes data]575* TLSv1.3 (IN), TLS handshake, Server hello (2):576{ [1210 bytes data]577* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):578{ [1 bytes data]579* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):580{ [19 bytes data]581* TLSv1.3 (IN), TLS handshake, Certificate (11):582{ [1008 bytes data]583* TLSv1.3 (IN), TLS handshake, CERT verify (15):584{ [110 bytes data]585* TLSv1.3 (IN), TLS handshake, Finished (20):586{ [52 bytes data]587* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):588} [1 bytes data]589* TLSv1.3 (OUT), TLS handshake, Finished (20):590} [52 bytes data]591* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey592* ALPN: server accepted h2593* Server certificate:594* subject: CN=test.foo595* start date: Aug 23 10:05:37 2026 GMT596* expire date: Sep 22 10:05:37 2028 GMT597* issuer: CN=minica root ca 7454ac598* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384599* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384600* subjectAltName: "test.foo" matches cert's "test.foo"601* OpenSSL verify result: 13602* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)603* closing connection #0604curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)605More details here: https://curl.se/docs/sslcerts.html606607curl failed to verify the legitimacy of the server and therefore could not608establish a secure connection to it. To learn more about this situation and609how to fix it, please visit the webpage mentioned above.610server # [6518520.361169] server acme-order-renew-test.foo-start[334]: Waiting to acquire lock in /run/acme/611server # [6518520.364088] server acme-order-renew-test.foo-start[334]: + set -euo pipefail612server # [6518520.364152] server acme-order-renew-test.foo-start[334]: + echo ad12aa6741ce4bd2c108613server # [6518520.364273] server acme-order-renew-test.foo-start[334]: + cmp -s domainhash.txt certificates/domainhash.txt614server # [6518520.365597] server acme-order-renew-test.foo-start[334]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run615server # [6518520.407120] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] acme: Registering account for none@none.tld616server # [6518520.426243] server acme-order-renew-test.foo-start[342]: !!!! HEADS UP !!!!617server # [6518520.426243] server acme-order-renew-test.foo-start[342]: Your account credentials have been saved in your618server # [6518520.426243] server acme-order-renew-test.foo-start[342]: configuration directory at "accounts".619server # [6518520.426243] server acme-order-renew-test.foo-start[342]: You should make a secure backup of this folder now. This620server # [6518520.426243] server acme-order-renew-test.foo-start[342]: configuration directory will also contain private keys621server # [6518520.426243] server acme-order-renew-test.foo-start[342]: generated by lego and certificates obtained from the ACME622server # [6518520.426243] server acme-order-renew-test.foo-start[342]: server. Making regular backups of this folder is ideal.623server # [6518520.426481] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] acme: Obtaining bundled SAN certificate624server # [6518520.497863] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK625server # [6518520.497863] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01626server # [6518520.497863] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] acme: use http-01 solver627server # [6518520.497971] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] acme: Trying to solve HTTP-01628server # [6518520.504429] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] The server validated our request629server # [6518520.504491] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] acme: Validations succeeded; requesting certificates630server # [6518520.521529] server acme-order-renew-test.foo-start[342]: 2026/08/23 10:05:46 [INFO] [test.foo] Server responded with a certificate.631server # [6518520.525522] server acme-order-renew-test.foo-start[334]: + mv domainhash.txt certificates/632server # [6518520.527187] server acme-order-renew-test.foo-start[334]: + touch out/acme-success633server # [6518520.528727] server acme-order-renew-test.foo-start[334]: + cmp -s certificates/test.foo.crt out/fullchain.pem634server # [6518520.529804] server acme-order-renew-test.foo-start[334]: + touch out/renewed635server # [6518520.531099] server acme-order-renew-test.foo-start[334]: + echo Installing new certificate636server # [6518520.531099] server acme-order-renew-test.foo-start[334]: Installing new certificate637server # [6518520.531149] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.crt out/fullchain.pem638server # [6518520.532468] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'639server # [6518520.532725] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.key out/key.pem640server # [6518520.534190] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.key' -> 'out/key.pem'641server # [6518520.534421] server acme-order-renew-test.foo-start[334]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem642server # [6518520.535661] server acme-order-renew-test.foo-start[376]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'643server # [6518520.535887] server acme-order-renew-test.foo-start[334]: + ln -sf fullchain.pem out/cert.pem644server # [6518520.537352] server acme-order-renew-test.foo-start[334]: + cat out/key.pem out/fullchain.pem645server # [6518520.538945] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates646server # [6518520.538966] server acme-order-renew-test.foo-start[334]: + '[' -d out ']'647server # [6518520.538984] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= out648server # [6518520.540502] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx out649server # [6518520.542832] server acme-order-renew-test.foo-start[334]: + for fixpath in out certificates650server # [6518520.542864] server acme-order-renew-test.foo-start[334]: + '[' -d certificates ']'651server # [6518520.542864] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=rX,o= certificates652server # [6518520.544577] server acme-order-renew-test.foo-start[334]: + chown -R acme:nginx certificates653server # [6518520.547926] server acme-order-renew-test.foo-start[334]: + chmod -R u=rwX,g=,o= accounts/.654ca # [6518520.406656] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration="44.921µs" duration-ns=44921 fields.time="2026-08-23T10:05:46Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=513f260a-5b20-4551-b842-2414e9fa5657 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=655ca # [6518520.418453] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=9.307488ms duration-ns=9307488 fields.time="2026-08-23T10:05:46Z" method=HEAD name=ca nonce=RDBYMzc0NDBZa3lOd0MwWWtDdVZXdGxxeEE4NnBVcmk path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f50ab0f2-cee2-420f-aa11-0b3c36531bd1 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=656ca # [6518520.425709] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=4.841707ms duration-ns=4841707 fields.time="2026-08-23T10:05:46Z" method=POST name=ca nonce=OHNoS20wZVdFeVY3clJFVWdjZTVmTlJ2NVNoNVB3Yks path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=29547f8c-f9aa-4ab6-9447-2db753e53775 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/l3vyh1wlyrC86BFK6HlQFWuCd2izZW8m/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=657ca # [6518520.434604] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=6.287567ms duration-ns=6287567 fields.time="2026-08-23T10:05:46Z" method=POST name=ca nonce=SGFYVEI2aTg1eWN6TzRzYkthRTV1Z1MxVjFYZWdlalE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=d4dbb66c-7ad9-4b49-af95-a16af7701fab response="{\"id\":\"JuoB5ymNKlWrQJil714zw4nMpE6zoTgu\",\"status\":\"pending\",\"expires\":\"2026-08-24T10:05:46Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T10:04:46Z\",\"notAfter\":\"2026-11-21T10:05:46Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK\"],\"finalize\":\"https://ca.foo/acme/acme/order/JuoB5ymNKlWrQJil714zw4nMpE6zoTgu/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=658ca # [6518520.497337] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=4.398981ms duration-ns=4398981 fields.time="2026-08-23T10:05:46Z" method=POST name=ca nonce=ZzA5eHNwWGlXN0pKa1dDUDlYVEZ6QlZTNE5ibTgxV3Y path=/acme/acme/authz/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK protocol=HTTP/1.1 referer= remote-address="::1" request-id=1542544a-63b4-4eb7-95c6-7c3efb324764 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"dTMHIsjAF6LIZf7j9UBBvDqe3NHKWNLu\",\"url\":\"https://ca.foo/acme/acme/challenge/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK/CFmWRc3TrOPIzBF04auXIac6boGs8hOH\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"dTMHIsjAF6LIZf7j9UBBvDqe3NHKWNLu\",\"url\":\"https://ca.foo/acme/acme/challenge/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK/skCpB5sEUdwOLcpSGtycdZEyiRrpPzcz\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"dTMHIsjAF6LIZf7j9UBBvDqe3NHKWNLu\",\"url\":\"https://ca.foo/acme/acme/challenge/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK/4ljbpFn3OKNG4Uyuc3keSUGKDJ2XovpJ\"}],\"wildcard\":false,\"expires\":\"2026-08-24T10:05:46Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=659ca # [6518520.503970] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=4.180058ms duration-ns=4180058 fields.time="2026-08-23T10:05:46Z" method=POST name=ca nonce=bTUzTnVHV3BLdmM2aVR4M044TUIwVWdBZjRqR3hkZGs path=/acme/acme/challenge/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK/skCpB5sEUdwOLcpSGtycdZEyiRrpPzcz protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=22ea2967-41b1-462a-a7f9-e758ace0586d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"dTMHIsjAF6LIZf7j9UBBvDqe3NHKWNLu\",\"validated\":\"2026-08-23T10:05:46Z\",\"url\":\"https://ca.foo/acme/acme/challenge/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK/skCpB5sEUdwOLcpSGtycdZEyiRrpPzcz\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=660ca # [6518520.512703] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info duration=6.084164ms duration-ns=6084164 fields.time="2026-08-23T10:05:46Z" method=POST name=ca nonce=eE5iR2pDczlrY09ncFMxejhTSTh5dWRSUWNJeklIdjM path=/acme/acme/order/JuoB5ymNKlWrQJil714zw4nMpE6zoTgu/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=dc92ef34-d29c-48b6-a1ad-30eeaca8a088 response="{\"id\":\"JuoB5ymNKlWrQJil714zw4nMpE6zoTgu\",\"status\":\"valid\",\"expires\":\"2026-08-24T10:05:46Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-23T10:04:46Z\",\"notAfter\":\"2026-11-21T10:05:46Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/6a7nIOTZDjVW5GQle5j1RC6R3yLldHKK\"],\"finalize\":\"https://ca.foo/acme/acme/order/JuoB5ymNKlWrQJil714zw4nMpE6zoTgu/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/BSQN1L5Qk32DSwFs657RfLFxc29nuJtE\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=661ca # [6518520.521093] ca step-ca[204]: time="2026-08-23T10:05:46Z" level=info certificate=MIIB1jCCAX2gAwIBAgIQIx1l6WVjnmAVV0vMv+llezAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjMxMDA0NDZaFw0yNjExMjExMDA1NDZaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEThLLnUIFc46m0iryiAxa9lGFGHtWdTCfSaOBYEJ51AW9qrc88VRnZaA6IqHnVxEZD4exjP1DQxSgHxvP2XO/yqOBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBReAm1Kt0kw6gHFwBREhGgWwmV+ijAfBgNVHSMEGDAWgBQGEt3Z8fVc8Wn7df06ngK72vfNjTATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDRwAwRAIgPwZP7DRo/pJ/QQxfhAQuicDO8z1pcfzYa7s0OgvKcs0CIHxp4FWI3AG0BZe408aJLWBoKdyctUBfIZShrPhJ54yl duration=6.239886ms duration-ns=6239886 fields.time="2026-08-23T10:05:46Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=b3I3cUpsbWZHbUgxdlNjallsVHpYQVZJOTlJNVV1Y0U path=/acme/acme/certificate/BSQN1L5Qk32DSwFs657RfLFxc29nuJtE protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=1dc2b15e-2f10-4150-9c3d-55503542565f sans="map[dns:[test.foo]]" serial=46675623476279817749591315321574745467 size=1344 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-23T10:04:46Z" valid-to="2026-11-21T10:05:46Z"662server # [6518520.754470] server systemd[1]: Reloading Nginx Web Server...663server # [6518520.758484] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.664server # [6518520.758668] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.665* Host test.foo:443 was resolved.666* IPv6: 2001:db8:1::3667* IPv4: 192.168.1.3668* Trying [2001:db8:1::3]:443...669* ALPN: curl offers h2,http/1.1670} [5 bytes data]671* TLSv1.3 (OUT), TLS handshake, Client hello (1):672} [1552 bytes data]673* SSL Trust Anchors:674* OpenSSL default paths (fallback)675{ [5 bytes data]676* TLSv1.3 (IN), TLS handshake, Server hello (2):677{ [1210 bytes data]678* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):679{ [1 bytes data]680* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):681{ [19 bytes data]682* TLSv1.3 (IN), TLS handshake, Certificate (11):683{ [1008 bytes data]684* TLSv1.3 (IN), TLS handshake, CERT verify (15):685{ [110 bytes data]686* TLSv1.3 (IN), TLS handshake, Finished (20):687{ [52 bytes data]688* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):689} [1 bytes data]690* TLSv1.3 (OUT), TLS handshake, Finished (20):691} [52 bytes data]692* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey693* ALPN: server accepted h2694* Server certificate:695* subject: CN=test.foo696* start date: Aug 23 10:05:37 2026 GMT697* expire date: Sep 22 10:05:37 2028 GMT698* issuer: CN=minica root ca 7454ac699* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384700* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384701* subjectAltName: "test.foo" matches cert's "test.foo"702* OpenSSL verify result: 13703* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)704* closing connection #0705curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)706More details here: https://curl.se/docs/sslcerts.html707708curl failed to verify the legitimacy of the server and therefore could not709establish a secure connection to it. To learn more about this situation and710how to fix it, please visit the webpage mentioned above.711server # [6518521.619997] server nginx[392]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok712server # [6518521.620344] server nginx[392]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful713* Trying [2001:db8:1::3]:443...714* Host test.foo:443 was resolved.715* IPv6: 2001:db8:1::3716* IPv4: 192.168.1.3717* ALPN: curl offers h2,http/1.1718} [5 bytes data]719* TLSv1.3 (OUT), TLS handshake, Client hello (1):720} [1552 bytes data]721* SSL Trust Anchors:722* OpenSSL default paths (fallback)723{ [5 bytes data]724* TLSv1.3 (IN), TLS handshake, Server hello (2):725{ [1210 bytes data]726* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):727{ [1 bytes data]728* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):729{ [19 bytes data]730* TLSv1.3 (IN), TLS handshake, Certificate (11):731{ [1008 bytes data]732* TLSv1.3 (IN), TLS handshake, CERT verify (15):733{ [110 bytes data]734* TLSv1.3 (IN), TLS handshake, Finished (20):735{ [52 bytes data]736* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):737} [1 bytes data]738* TLSv1.3 (OUT), TLS handshake, Finished (20):739} [52 bytes data]740* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey741* ALPN: server accepted h2742* Server certificate:743* subject: CN=test.foo744* start date: Aug 23 10:05:37 2026 GMT745* expire date: Sep 22 10:05:37 2028 GMT746* issuer: CN=minica root ca 7454ac747* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384748* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384749* subjectAltName: "test.foo" matches cert's "test.foo"750* OpenSSL verify result: 13751* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)752* closing connection #0753curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)754More details here: https://curl.se/docs/sslcerts.html755756curl failed to verify the legitimacy of the server and therefore could not757establish a secure connection to it. To learn more about this situation and758how to fix it, please visit the webpage mentioned above.759server # [6518522.686634] server systemd[1]: Reloaded Nginx Web Server.760* Host test.foo:443 was resolved.761* IPv6: 2001:db8:1::3762* IPv4: 192.168.1.3763* Trying [2001:db8:1::3]:443...764* ALPN: curl offers h2,http/1.1765} [5 bytes data]766* TLSv1.3 (OUT), TLS handshake, Client hello (1):767} [1552 bytes data]768* SSL Trust Anchors:769* OpenSSL default paths (fallback)770{ [5 bytes data]771* TLSv1.3 (IN), TLS handshake, Server hello (2):772{ [1210 bytes data]773* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):774{ [1 bytes data]775* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):776{ [19 bytes data]777* TLSv1.3 (IN), TLS handshake, Certificate (11):778{ [929 bytes data]779* TLSv1.3 (IN), TLS handshake, CERT verify (15):780{ [78 bytes data]781* TLSv1.3 (IN), TLS handshake, Finished (20):782{ [52 bytes data]783* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):784} [1 bytes data]785* TLSv1.3 (OUT), TLS handshake, Finished (20):786} [52 bytes data]787* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey788* ALPN: server accepted h2789* Server certificate:790* subject: CN=test.foo791* start date: Aug 23 10:04:46 2026 GMT792* expire date: Nov 21 10:05:46 2026 GMT793* issuer: CN=Clan Intermediate CA794* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256795* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256796* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256797* subjectAltName: "test.foo" matches cert's "test.foo"798* OpenSSL verify result: 0799* SSL certificate verified via OpenSSL.800* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 54090 801 % Total % Received % Xferd Average Speed Time Time Time Current802 Dload Upload Total Spent Left Speed803 0 0 0 0 0 0 0 0 0* using HTTP/2804* [HTTP/2] [1] OPENED stream for https://test.foo/805* [HTTP/2] [1] [:method: GET]806* [HTTP/2] [1] [:scheme: https]807* [HTTP/2] [1] [:authority: test.foo]808* [HTTP/2] [1] [:path: /]809* [HTTP/2] [1] [user-agent: curl/8.21.0]810* [HTTP/2] [1] [accept: */*]811} [5 bytes data]812813814815816817* Request completely sent off818{ [5 bytes data]819* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):820{ [265 bytes data]821* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):822{ [265 bytes data]823824825826827828829830{ [5 bytes data]831100 20 100 20 0 0 813 0 0832* Connection #0 to host test.foo:443 left intact833client: (finished: waiting for success: curl -v https://test.foo, in 4.21 seconds)834client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2835Certificate:836 Data:837 Version: 3 (0x2)838 Serial Number:839 23:1d:65:e9:65:63:9e:60:15:57:4b:cc:bf:e9:65:7b840 Signature Algorithm: ecdsa-with-SHA256841 Issuer: CN=Clan Intermediate CA842 Validity843 Not Before: Aug 23 10:04:46 2026 GMT844 Not After : Nov 21 10:05:46 2026 GMT845 Subject: CN=test.foo846 Subject Public Key Info:847 Public Key Algorithm: id-ecPublicKey848 Public-Key: (256 bit)849 pub:850 04:4e:12:cb:9d:42:05:73:8e:a6:d2:2a:f2:88:0c:851 5a:f6:51:85:18:7b:56:75:30:9f:49:a3:81:60:42:852 79:d4:05:bd:aa:b7:3c:f1:54:67:65:a0:3a:22:a1:853 e7:57:11:19:0f:87:b1:8c:fd:43:43:14:a0:1f:1b:854 cf:d9:73:bf:ca855 ASN1 OID: prime256v1856 NIST CURVE: P-256857 X509v3 extensions:858 X509v3 Key Usage: critical859 Digital Signature860 X509v3 Extended Key Usage: 861 TLS Web Server Authentication, TLS Web Client Authentication862 X509v3 Subject Key Identifier: 863 5E:02:6D:4A:B7:49:30:EA:01:C5:C0:14:44:84:68:16:C2:65:7E:8A864 X509v3 Authority Key Identifier: 865 06:12:DD:D9:F1:F5:5C:F1:69:FB:75:FD:3A:9E:02:BB:DA:F7:CD:8D866 X509v3 Subject Alternative Name: 867 DNS:test.foo868 1.3.6.1.4.1.37476.9000.64.1: 869 0......acme..870 Signature Algorithm: ecdsa-with-SHA256871 Signature Value:872 30:44:02:20:3f:06:4f:ec:34:68:fe:92:7f:41:0c:5f:84:04:873 2e:89:c0:ce:f3:3d:69:71:fc:d8:6b:bb:34:3a:0b:ca:72:cd:874 02:20:7c:69:e0:55:88:dc:01:b4:05:97:b8:d3:c6:89:2d:60:875 68:29:dc:9c:b5:40:5f:21:94:a1:ac:f8:49:e7:8c:a5876client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)877(finished: run the VM test script, in 15.41 seconds)878test script finished in 15.47s879cleanup880kill NspawnMachine (pid 53)881kill NspawnMachine (pid 54)882Container ca terminated by signal KILL.883kill NspawnMachine (pid 56)884Container client terminated by signal KILL.885(finished: cleanup, in 0.49 seconds)886Container server terminated by signal KILL.