nixbot

builds

succeeded container-test-run-certificates checks.aarch64-linux.certificates · build #500 · raw

1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13client: systemd-nspawn running (pid 54)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15server: systemd-nspawn running (pid 55)16client: Waiting for journal at /build/vm-state-client/var/log/journal...17server: Waiting for journal at /build/vm-state-server/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container server on /build/vm-state-server.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container ca on /build/vm-state-ca.31client # [6727726.648362] client systemd-journald[69]: Journal started32ca # [6727726.660992] ca systemd-journald[77]: Journal started33client # [6727726.648429] client systemd-journald[69]: Runtime Journal (/run/log/journal/db952a3da14940acb0d4d14906bba396) is 8M, max 2.5G, 2.4G free.34ca # [6727726.661048] ca systemd-journald[77]: Runtime Journal (/run/log/journal/83737126434c40f5b558a2195ea254b7) is 8M, max 2.5G, 2.4G free.35client # [6727726.650310] client systemd[1]: Finished Apply Kernel Variables.36ca # [6727726.666057] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully.37client # [6727726.657613] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.38ca # [6727726.675735] ca systemd[1]: Starting Flush Journal to Persistent Storage...39client # [6727726.667457] client systemd[1]: Starting Flush Journal to Persistent Storage...40ca # [6727726.676923] ca systemd[1]: Starting Network Name Resolution...41client # [6727726.668468] client systemd[1]: Starting Network Name Resolution...42ca # [6727726.678698] ca systemd[1]: Starting Create Static Device Nodes in /dev...43ca # [6727726.686816] ca systemd-journald[77]: Time spent on flushing to /var/log/journal/83737126434c40f5b558a2195ea254b7 is 1.680ms for 6 entries.44client # [6727726.669306] client systemd[1]: Starting Create Static Device Nodes in /dev...45ca # [6727726.686816] ca systemd-journald[77]: System Journal (/var/log/journal/83737126434c40f5b558a2195ea254b7) is 8M, max 4G, 3.9G free.46client # [6727726.678001] client systemd-journald[69]: Time spent on flushing to /var/log/journal/db952a3da14940acb0d4d14906bba396 is 1.916ms for 7 entries.47ca # [6727726.696210] ca systemd[1]: Finished Create Static Device Nodes in /dev.48client # [6727726.678001] client systemd-journald[69]: System Journal (/var/log/journal/db952a3da14940acb0d4d14906bba396) is 8M, max 4G, 3.9G free.49ca # [6727726.697033] ca systemd[1]: Reached target Preparation for Local File Systems.50client # [6727726.686688] client systemd[1]: Finished Create Static Device Nodes in /dev.51server # [6727726.647800] server systemd-journald[69]: Journal started52client # [6727726.687049] client systemd[1]: Reached target Preparation for Local File Systems.53server # [6727726.647859] server systemd-journald[69]: Runtime Journal (/run/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6) is 8M, max 2.5G, 2.4G free.54client # [6727726.687142] client systemd[1]: Reached target Local File Systems.55server # [6727726.650497] server systemd[1]: Finished Apply Kernel Variables.56client # [6727726.687915] client systemd[1]: Listening on Boot Loader Control Service Socket.57ca # [6727726.697170] ca systemd[1]: Reached target Local File Systems.58client # [6727726.687963] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container59ca # [6727726.698140] ca systemd[1]: Listening on Boot Loader Control Service Socket.60client # [6727726.689154] client systemd[1]: Starting Save Transient machine-id to Disk...61server # [6727726.657599] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.62ca # [6727726.698191] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container63server # [6727726.668167] server systemd[1]: Starting Flush Journal to Persistent Storage...64client # [6727726.689205] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys65ca # [6727726.699082] ca systemd[1]: Starting Save Transient machine-id to Disk...66server # [6727726.669291] server systemd[1]: Starting Network Name Resolution...67ca # [6727726.699121] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys68server # [6727726.670127] server systemd[1]: Starting Create Static Device Nodes in /dev...69ca # [6727726.705380] ca systemd[1]: Finished Flush Journal to Persistent Storage.70server # [6727726.678776] server systemd-journald[69]: Time spent on flushing to /var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6 is 1.746ms for 7 entries.71ca # [6727726.706403] ca systemd[1]: Starting Create System Files and Directories...72server # [6727726.678776] server systemd-journald[69]: System Journal (/var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6) is 8M, max 4G, 3.9G free.73ca # [6727726.722577] ca systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted74server # [6727726.686077] server systemd[1]: Finished Create Static Device Nodes in /dev.75ca # [6727726.722784] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted76server # [6727726.686909] server systemd[1]: Reached target Preparation for Local File Systems.77ca # [6727726.722909] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal/83737126434c40f5b558a2195ea254b7 failed: Operation not permitted78server # [6727726.687037] server systemd[1]: Reached target Local File Systems.79ca # [6727726.723094] ca systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted80server # [6727726.687916] server systemd[1]: Listening on Boot Loader Control Service Socket.81ca # [6727726.724735] ca systemd[1]: Finished Create System Files and Directories.82server # [6727726.687967] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container83ca # [6727726.725846] ca systemd[1]: Starting Rebuild Journal Catalog...84server # [6727726.689243] server systemd[1]: Starting Save Transient machine-id to Disk...85ca # [6727726.726826] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...86server # [6727726.689289] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys87ca # [6727726.740531] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.88client # [6727726.704284] client systemd[1]: Finished Flush Journal to Persistent Storage.89ca # [6727726.747389] ca systemd[1]: Finished Rebuild Journal Catalog.90server # [6727726.696811] server systemd[1]: Finished Flush Journal to Persistent Storage.91ca # [6727726.748422] ca systemd[1]: Starting Update is Completed...92client # [6727726.706076] client systemd[1]: Starting Create System Files and Directories...93ca # [6727726.758163] ca systemd[1]: Finished Update is Completed.94server # [6727726.698191] server systemd[1]: Starting Create System Files and Directories...95server # [6727726.715257] server systemd-tmpfiles[118]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted96server # [6727726.715445] server systemd-tmpfiles[118]: fchmod() of /var/log/journal failed: Operation not permitted97server # [6727726.715569] server systemd-tmpfiles[118]: fchmod() of /var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6 failed: Operation not permitted98server # [6727726.715753] server systemd-tmpfiles[118]: fchmod() of /run/log/journal failed: Operation not permitted99server # [6727726.717438] server systemd[1]: Finished Create System Files and Directories.100server # [6727726.718727] server systemd[1]: Starting Rebuild Journal Catalog...101server # [6727726.719670] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...102server # [6727726.732151] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.103server # [6727726.740392] server systemd[1]: Finished Rebuild Journal Catalog.104server # [6727726.741574] server systemd[1]: Starting Update is Completed...105server # [6727726.751638] server systemd[1]: Finished Update is Completed.106client # [6727726.722181] client systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted107client # [6727726.722380] client systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted108client # [6727726.722511] client systemd-tmpfiles[122]: fchmod() of /var/log/journal/db952a3da14940acb0d4d14906bba396 failed: Operation not permitted109client # [6727726.722705] client systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted110client # [6727726.724364] client systemd[1]: Finished Create System Files and Directories.111client # [6727726.725553] client systemd[1]: Starting Rebuild Journal Catalog...112client # [6727726.726359] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...113client # [6727726.739182] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.114client # [6727726.746093] client systemd[1]: Finished Rebuild Journal Catalog.115client # [6727726.747208] client systemd[1]: Starting Update is Completed...116client # [6727726.757846] client systemd[1]: Finished Update is Completed.117server # [6727726.803653] server systemd[1]: Finished Firewall.118server # [6727726.803817] server systemd[1]: Reached target Preparation for Network.119server # [6727726.804063] server systemd[1]: Listening on Network Management Resolve Hook Socket.120server # [6727726.805157] server systemd[1]: Starting Network Management...121client # [6727726.801973] client systemd[1]: Finished Firewall.122client # [6727726.802128] client systemd[1]: Reached target Preparation for Network.123client # [6727726.802351] client systemd[1]: Listening on Network Management Resolve Hook Socket.124client # [6727726.803514] client systemd[1]: Starting Network Management...125ca # [6727726.814274] ca systemd[1]: Finished Firewall.126ca # [6727726.814979] ca systemd[1]: Reached target Preparation for Network.127ca # [6727726.815517] ca systemd[1]: Listening on Network Management Resolve Hook Socket.128ca # [6727726.816756] ca systemd[1]: Starting Network Management...129client # [6727727.068472] client systemd[1]: Finished Save Transient machine-id to Disk.130ca # [6727727.070411] ca systemd[1]: Finished Save Transient machine-id to Disk.131server # [6727727.072124] server systemd[1]: Finished Save Transient machine-id to Disk.132client # [6727727.435118] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted133client # [6727727.435213] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted134client # [6727727.442418] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.135client # [6727727.442579] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.136client # [6727727.442750] client systemd-networkd[182]: lo: Link UP137client # [6727727.442755] client systemd-networkd[182]: lo: Gained carrier138client # [6727727.442964] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.139client # [6727727.443348] client systemd[1]: Started Network Management.140client # [6727727.443613] client systemd-networkd[182]: eth1: Link UP141client # [6727727.443801] client systemd-networkd[182]: eth1: Gained carrier142client # [6727727.444512] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...143client # [6727727.466742] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.144client # [6727727.625869] client systemd-resolved[97]: Positive Trust Anchors:145client # [6727727.625883] client systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d146client # [6727727.625886] client systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16147client # [6727727.625921] client systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test148client # [6727727.636651] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.149client # [6727727.648419] client systemd-resolved[97]: Using system hostname 'client'.150client # [6727727.649919] client systemd[1]: Started Network Name Resolution.151client # [6727727.650055] client systemd[1]: Reached target Network.152client # [6727727.650169] client systemd[1]: Reached target System Initialization.153client # [6727727.650273] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container154client # [6727727.650332] client systemd[1]: Started Daily Cleanup of Temporary Directories.155client # [6727727.650370] client systemd[1]: Reached target Timer Units.156client # [6727727.650643] client systemd[1]: Listening on D-Bus System Message Bus Socket.157client # [6727727.650854] client systemd[1]: Listening on Nix Daemon Socket.158client # [6727727.651066] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.159client # [6727727.651114] client systemd[1]: Reached target Socket Units.160client # [6727727.651197] client systemd[1]: Reached target Basic System.161client # [6727727.653402] client systemd[1]: Starting Import lastlog data into lastlog2 database...162client # [6727727.654736] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...163client # [6727727.688501] client systemd[1]: Starting D-Bus System Message Bus...164server # [6727727.420800] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted165server # [6727727.420904] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted166server # [6727727.429220] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.167server # [6727727.429406] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.168server # [6727727.429654] server systemd-networkd[186]: lo: Link UP169server # [6727727.429659] server systemd-networkd[186]: lo: Gained carrier170server # [6727727.429913] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.171server # [6727727.430516] server systemd-networkd[186]: eth1: Link UP172server # [6727727.430844] server systemd-networkd[186]: eth1: Gained carrier173server # [6727727.430999] server systemd[1]: Started Network Management.174server # [6727727.432172] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...175server # [6727727.443508] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.176server # [6727727.631781] server systemd-resolved[97]: Positive Trust Anchors:177server # [6727727.631794] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d178server # [6727727.631798] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16179server # [6727727.631832] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test180server # [6727727.636943] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.181server # [6727727.654591] server systemd-resolved[97]: Using system hostname 'server'.182server # [6727727.655995] server systemd[1]: Started Network Name Resolution.183server # [6727727.656095] server systemd[1]: Reached target Network.184server # [6727727.656149] server systemd[1]: Reached target Network is Online.185server # [6727727.656197] server systemd[1]: Reached target System Initialization.186server # [6727727.656413] server systemd[1]: Started Renew ACME Certificate for test.foo.187server # [6727727.656447] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container188server # [6727727.656468] server systemd[1]: Started Daily Cleanup of Temporary Directories.189server # [6727727.656489] server systemd[1]: Reached target Timer Units.190server # [6727727.656625] server systemd[1]: Listening on D-Bus System Message Bus Socket.191server # [6727727.656745] server systemd[1]: Listening on Nix Daemon Socket.192server # [6727727.656852] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.193server # [6727727.656877] server systemd[1]: Reached target Socket Units.194server # [6727727.656916] server systemd[1]: Reached target Basic System.195server # [6727727.688605] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...196ca # [6727727.439023] ca systemd-networkd[194]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted197ca # [6727727.439115] ca systemd-networkd[194]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted198ca # [6727727.446096] ca systemd-networkd[194]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.199ca # [6727727.446255] ca systemd-networkd[194]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.200ca # [6727727.446421] ca systemd-networkd[194]: lo: Link UP201ca # [6727727.446425] ca systemd-networkd[194]: lo: Gained carrier202ca # [6727727.446632] ca systemd-networkd[194]: eth1: Configuring with /etc/systemd/network/40-eth1.network.203ca # [6727727.446995] ca systemd[1]: Started Network Management.204ca # [6727727.447080] ca systemd-networkd[194]: eth1: Link UP205ca # [6727727.447334] ca systemd-networkd[194]: eth1: Gained carrier206ca # [6727727.448054] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...207ca # [6727727.494079] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.208ca # [6727727.626444] ca systemd-resolved[104]: Positive Trust Anchors:209ca # [6727727.626456] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d210ca # [6727727.626460] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16211ca # [6727727.626494] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test212ca # [6727727.647652] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.213ca # [6727727.648847] ca systemd-resolved[104]: Using system hostname 'ca'.214ca # [6727727.650214] ca systemd[1]: Started Network Name Resolution.215ca # [6727727.650294] ca systemd[1]: Reached target Network.216ca # [6727727.650347] ca systemd[1]: Reached target Network is Online.217ca # [6727727.650390] ca systemd[1]: Reached target System Initialization.218ca # [6727727.650579] ca systemd[1]: Started Renew ACME Certificate for ca.foo.219ca # [6727727.650605] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container220ca # [6727727.650621] ca systemd[1]: Started Daily Cleanup of Temporary Directories.221ca # [6727727.650638] ca systemd[1]: Reached target Timer Units.222ca # [6727727.650751] ca systemd[1]: Listening on D-Bus System Message Bus Socket.223ca # [6727727.650849] ca systemd[1]: Listening on Nix Daemon Socket.224ca # [6727727.650952] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.225ca # [6727727.650971] ca systemd[1]: Reached target Socket Units.226ca # [6727727.651005] ca systemd[1]: Reached target Basic System.227ca # [6727727.652465] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...228ca # [6727727.653131] ca systemd[1]: Starting Import lastlog data into lastlog2 database...229ca # [6727727.653168] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem230ca # [6727727.653947] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...231ca # [6727727.655291] ca systemd[1]: Starting step-ca service...232ca # [6727727.688487] ca systemd[1]: Starting D-Bus System Message Bus...233server # [6727727.689759] server systemd[1]: Starting Import lastlog data into lastlog2 database...234server # [6727727.689807] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem235server # [6727727.690758] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...236server # [6727727.692172] server systemd[1]: Starting D-Bus System Message Bus...237server # [6727727.707138] server systemd[1]: Finished Import lastlog data into lastlog2 database.238server # [6727727.796109] server acme-setup-privileged[192]: + set -euo pipefail239server # [6727727.796109] server acme-setup-privileged[192]: + cd /var/lib/acme240server # [6727727.796109] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts241server # [6727727.797362] server acme-setup-privileged[192]: + chown -R acme .lego/accounts242server # [6727727.798934] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo243server # [6727727.798987] server acme-setup-privileged[192]: + '[' -d test.foo ']'244server # [6727727.799016] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo245server # [6727727.799016] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'246server # [6727727.812189] server nsncd[194]: Aug 25 20:12:33.865 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"247server # [6727727.812298] server systemd[1]: Started Name Service Cache Daemon (nsncd).248server # [6727727.812373] server systemd[1]: Reached target Host and Network Name Lookups.249server # [6727727.812436] server systemd[1]: Reached target User and Group Name Lookups.250server # [6727727.841113] server systemd[1]: Starting User Login Management...251server # [6727727.842079] server systemd[1]: Starting Permit User Sessions...252server # [6727727.852109] server systemd[1]: Finished Permit User Sessions.253server # [6727727.853292] server systemd[1]: Started Console Getty.254server # [6727727.853343] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0255server # [6727727.853362] server systemd[1]: Reached target Login Prompts.256client # [6727727.704339] client systemd[1]: Finished Import lastlog data into lastlog2 database.257client # [6727727.836642] client nsncd[189]: Aug 25 20:12:33.889 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"258client # [6727727.836738] client systemd[1]: Started Name Service Cache Daemon (nsncd).259client # [6727727.836811] client systemd[1]: Reached target Host and Network Name Lookups.260client # [6727727.836878] client systemd[1]: Reached target User and Group Name Lookups.261client # [6727727.841274] client systemd[1]: Starting User Login Management...262client # [6727727.842112] client systemd[1]: Starting Permit User Sessions...263client # [6727727.852639] client systemd[1]: Finished Permit User Sessions.264client # [6727727.853574] client systemd[1]: Started Console Getty.265client # [6727727.853610] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0266client # [6727727.853629] client systemd[1]: Reached target Login Prompts.267ca # [6727727.727344] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory268ca # [6727727.727375] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory269ca # [6727727.727425] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'.270ca # [6727727.727492] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database.271ca # [6727727.790883] ca acme-setup-privileged[200]: + set -euo pipefail272ca # [6727727.790883] ca acme-setup-privileged[200]: + cd /var/lib/acme273ca # [6727727.791262] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts274ca # [6727727.792778] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts275ca # [6727727.794149] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo276ca # [6727727.794171] ca acme-setup-privileged[200]: + '[' -d ca.foo ']'277ca # [6727727.794171] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo278ca # [6727727.794209] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']'279ca # [6727727.817642] ca nsncd[202]: Aug 25 20:12:33.870 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"280ca # [6727727.817626] ca systemd[1]: Started Name Service Cache Daemon (nsncd).281ca # [6727727.817757] ca systemd[1]: Reached target Host and Network Name Lookups.282ca # [6727727.817864] ca systemd[1]: Reached target User and Group Name Lookups.283ca # [6727727.841789] ca systemd[1]: Starting User Login Management...284ca # [6727727.843187] ca systemd[1]: Starting Permit User Sessions...285ca # [6727727.854044] ca systemd[1]: Finished Permit User Sessions.286ca # [6727727.855739] ca systemd[1]: Started Console Getty.287ca # [6727727.855791] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0288ca # [6727727.855814] ca systemd[1]: Reached target Login Prompts.289ca # [6727727.982674] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'...290client # [6727727.969925] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...291client # [6727727.972102] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'292client # [6727727.972102] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"293client # [6727727.972591] client systemd[1]: Started D-Bus System Message Bus.294client # [6727727.980892] client dbus-broker-launch[190]: Ready295ca # [6727727.983869] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync'296server # [6727727.974861] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...297ca # [6727727.983869] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"298server # [6727727.976480] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'299ca # [6727727.984204] ca systemd[1]: Started D-Bus System Message Bus.300ca # [6727727.991761] ca dbus-broker-launch[204]: Ready301server # [6727727.976480] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"302server # [6727727.976953] server systemd[1]: Started D-Bus System Message Bus.303server # [6727727.984290] server dbus-broker-launch[195]: Ready304ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 305server # [6727728.570452] server systemd-logind[220]: New seat seat0.306server # [6727728.570661] server systemd[1]: Started User Login Management.307server # [6727728.583535] server systemd[1]: Starting linger-users.service...308server # [6727728.596097] server systemd[1]: linger-users.service: Deactivated successfully.309server # [6727728.596275] server systemd[1]: Finished linger-users.service.310server # [6727728.706622] server acme-setup-start[208]: + set -euo pipefail311server # [6727728.706622] server acme-setup-start[208]: + test -e ca/key.pem312server # [6727728.706622] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local313server # [6727728.726605] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.314server # [6727728.728270] server systemd[1]: Starting Ensure certificate for test.foo...315ca # [6727728.635404] ca systemd-logind[229]: New seat seat0.316ca # [6727728.635643] ca systemd[1]: Started User Login Management.317ca # [6727728.637434] ca systemd[1]: Starting linger-users.service...318ca # [6727728.649894] ca systemd[1]: linger-users.service: Deactivated successfully.319ca # [6727728.649970] ca systemd[1]: Finished linger-users.service.320ca # [6727728.721226] ca acme-setup-start[215]: + set -euo pipefail321ca # [6727728.721226] ca acme-setup-start[215]: + test -e ca/key.pem322ca # [6727728.721650] ca acme-setup-start[215]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local323ca # [6727728.772174] ca systemd-networkd[194]: eth1: Gained IPv6LL324ca # [6727728.884232] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.325ca # [6727728.886576] ca systemd[1]: Starting Ensure certificate for ca.foo...326client # [6727728.628103] client systemd-logind[205]: New seat seat0.327client # [6727728.632200] client systemd[1]: Started User Login Management.328client # [6727728.633900] client systemd[1]: Starting linger-users.service...329client # [6727728.649222] client systemd[1]: linger-users.service: Deactivated successfully.330client # [6727728.649400] client systemd[1]: Finished linger-users.service.331client # [6727728.650480] client systemd[1]: Reached target Multi-User System.332client # [6727728.651057] client systemd[1]: Startup finished in 2.399s.333server # [6727728.832148] server systemd-networkd[186]: eth1: Gained IPv6LL334ca # [6727728.954797] ca step-ca[203]: badger 2026/08/25 20:12:35 INFO: All 0 tables opened in 0s335ca # [6727728.960086] ca step-ca[203]: 2026/08/25 20:12:35 Building new tls configuration using step-ca x509 Signer Interface336ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Starting Smallstep CA/0.30.2 (linux/arm64)337ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Documentation: https://u.step.sm/docs/ca338ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Community Discord: https://u.step.sm/discord339ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Config file: /etc/smallstep/ca.json340ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 The primary server URL is https://ca.foo:1443341ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Root certificates are available at https://ca.foo:1443/roots.pem342ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 X.509 Root Fingerprint: fcec151c7705057538ab7b446472065d7ea631e5f4168a5856ccb5b20a98592a343ca # [6727728.967468] ca systemd[1]: Started step-ca service.344ca # [6727728.967844] ca step-ca[203]: 2026/08/25 20:12:35 Serving HTTPS on 0.0.0.0:1443 ...345client # [6727729.472171] client systemd-networkd[182]: eth1: Gained IPv6LL346ca # [6727729.512209] ca acme-ca.foo-start[279]: Waiting to acquire lock in /run/acme/347ca # [6727729.515439] ca acme-ca.foo-start[279]: + '[' -e out/acme-success ']'348ca # [6727729.515439] ca acme-ca.foo-start[279]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=349ca # [6727729.528167] ca acme-ca.foo-start[289]: + cd ca.foo350ca # [6727729.528167] ca acme-ca.foo-start[289]: + cp -vp cert.pem ../out/cert.pem351ca # [6727729.530821] ca acme-ca.foo-start[290]: 'cert.pem' -> '../out/cert.pem'352ca # [6727729.531086] ca acme-ca.foo-start[289]: + cp -vp key.pem ../out/key.pem353ca # [6727729.531742] ca acme-ca.foo-start[289]: 'key.pem' -> '../out/key.pem'354ca # [6727729.531863] ca acme-ca.foo-start[279]: + cat out/cert.pem ca/cert.pem355ca # [6727729.536031] ca acme-ca.foo-start[279]: + cp ca/cert.pem out/chain.pem356ca # [6727729.536031] ca acme-ca.foo-start[279]: + cat out/key.pem out/fullchain.pem357ca # [6727729.537392] ca acme-ca.foo-start[279]: + for fixpath in out certificates358ca # [6727729.537392] ca acme-ca.foo-start[279]: + '[' -d out ']'359ca # [6727729.537392] ca acme-ca.foo-start[279]: + chmod -R u=rwX,g=rX,o= out360ca # [6727729.538659] ca acme-ca.foo-start[279]: + chown -R acme:nginx out361ca # [6727729.542226] ca acme-ca.foo-start[279]: + for fixpath in out certificates362ca # [6727729.542259] ca acme-ca.foo-start[279]: + '[' -d certificates ']'363ca # [6727729.592305] ca systemd[1]: Finished Ensure certificate for ca.foo.364ca # [6727729.594436] ca systemd[1]: Starting Nginx Web Server...365server # [6727729.500500] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/366server # [6727729.503424] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'367server # [6727729.503503] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=368server # [6727729.516271] server acme-test.foo-start[254]: + cd test.foo369server # [6727729.516271] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem370server # [6727729.517735] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem'371server # [6727729.517965] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem372server # [6727729.519198] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem'373server # [6727729.519705] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem374server # [6727729.521445] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem375server # [6727729.523291] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem376server # [6727729.525443] server acme-test.foo-start[245]: + for fixpath in out certificates377server # [6727729.525443] server acme-test.foo-start[245]: + '[' -d out ']'378server # [6727729.525443] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out379server # [6727729.527315] server acme-test.foo-start[245]: + chown -R acme:nginx out380server # [6727729.531030] server acme-test.foo-start[245]: + for fixpath in out certificates381server # [6727729.531030] server acme-test.foo-start[245]: + '[' -d certificates ']'382server # [6727729.534690] server systemd[1]: Finished Ensure certificate for test.foo.383server # [6727729.536311] server systemd[1]: Starting Nginx Web Server...384ca # [6727730.213153] ca nginx-pre-start[301]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok385ca # [6727730.213586] ca nginx-pre-start[301]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful386ca # [6727730.288584] ca systemd[1]: Started Nginx Web Server.387ca # [6727730.289166] ca systemd[1]: Reached target Multi-User System.388ca # [6727730.291275] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...389server # [6727730.200747] server nginx-pre-start[266]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok390server # [6727730.201468] server nginx-pre-start[266]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful391server # [6727730.208444] server systemd[1]: Started Nginx Web Server.392server # [6727730.208907] server systemd[1]: Reached target Multi-User System.393server # [6727730.210740] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...394ca # [6727730.925506] ca acme-order-renew-ca.foo-start[304]: Waiting to acquire lock in /run/acme/395ca # [6727730.928764] ca acme-order-renew-ca.foo-start[304]: + set -euo pipefail396ca # [6727730.928843] ca acme-order-renew-ca.foo-start[304]: + echo 88dc4fc401a6091a1bd9397ca # [6727730.928955] ca acme-order-renew-ca.foo-start[304]: + cmp -s domainhash.txt certificates/domainhash.txt398ca # [6727730.929975] ca acme-order-renew-ca.foo-start[304]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run399ca # [6727730.953827] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 No key found for account none@none.tld. Generating a P256 key.400ca # [6727730.954167] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key401ca # [6727730.993052] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration="117.842µs" duration-ns=117842 fields.time="2026-08-25T20:12:37Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=68ba46ae-2dc4-4b51-b95c-432334e58472 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=402ca # [6727730.993655] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] acme: Registering account for none@none.tld403ca # [6727731.099171] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=105.236909ms duration-ns=105236909 fields.time="2026-08-25T20:12:37Z" method=HEAD name=ca nonce=azRERThTZUNUZUVJdjEyeGp0S1Uwd3FndEdyR3lrNlQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b7c1d69c-80a1-4284-bdf2-cc5dcc79037f size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=404ca # [6727731.110639] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=9.828137ms duration-ns=9828137 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=WnVHbU9JN0ljcWFLRGNrTEZCNkJ0anpRRmEwYW1XVTI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=83ee88f2-8371-4ba0-93aa-939baf1eeefc response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/ef0VYV0Qd6ZzBjV9crXbBl2iR2AJsed2/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=405ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: !!!! HEADS UP !!!!406ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: Your account credentials have been saved in your407ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: configuration directory at "accounts".408ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: You should make a secure backup of this folder now. This409ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: configuration directory will also contain private keys410ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: generated by lego and certificates obtained from the ACME411ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: server. Making regular backups of this folder is ideal.412ca # [6727731.111126] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate413ca # [6727731.114384] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=2.933041ms duration-ns=2933041 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=RXZjRlJnSXdkTXdYa0R4OGQ1UFdwdE45T3U2bmdYVWs path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4ca26361-178e-4efb-8eba-52a6ef8800b8 response="{\"id\":\"yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:12:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:11:37Z\",\"notAfter\":\"2026-11-23T20:12:37Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=414ca # [6727731.175701] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=4.465143ms duration-ns=4465143 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=NVF0NjdTR1pCc2R0dllqMWMzUXY0V25YVFd1U0VHSHI path=/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=90a9d0a6-0697-47a1-a7ba-13c008f96d06 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/k8msQ5iZ7mrKnQ1V81PFd84VD37Bj9dg\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/F13Cvbvon9XKKQJlXNDwQ9Q6P5W7GxkW\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:12:37Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=415ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3416ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01417ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: use http-01 solver418ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Trying to solve HTTP-01419server # [6727730.889422] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/420server # [6727730.891960] server acme-order-renew-test.foo-start[269]: + set -euo pipefail421server # [6727730.892064] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108422server # [6727730.892225] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt423server # [6727730.893227] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run424server # [6727730.953763] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 No key found for account none@none.tld. Generating a P256 key.425server # [6727730.954402] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key426server # [6727730.994701] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority427server # [6727731.000457] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.428server # [6727731.000457] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.429server # [6727731.000457] server acme-order-renew-test.foo-start[269]: + exit 10430server # [6727730.998562] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a431server # [6727730.998647] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.432server # [6727730.998888] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.433server # [6727730.999140] server systemd[1]: Startup finished in 4.749s.434ca # [6727731.180337] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=3.858893ms duration-ns=3858893 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=enlQRmNjNWVTWEtGb1o2Zm9uSGd1VHh2cmd2V1lDTFc path=/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=10c8cf53-3090-4e82-b31e-717d3433819d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"validated\":\"2026-08-25T20:12:37Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=435ca # [6727731.180559] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] The server validated our request436ca # [6727731.180623] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates437ca # [6727731.188382] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=7.002458ms duration-ns=7002458 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=OGVQcGxRRXNsa2xueWhwOEU5bGljSXJHanBEaEZJVGI path=/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ae39cc37-4f46-4881-acd2-8bbdefda5b43 response="{\"id\":\"yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:12:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:11:37Z\",\"notAfter\":\"2026-11-23T20:12:37Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/4bg35RCvlXxBjF3XSAl5knQENSNg87yG\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=438ca # [6727731.190407] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQVkjqozZg1IYbcsMbVY7ObjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjUyMDExMzdaFw0yNjExMjMyMDEyMzdaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAUZHx61gjPxrSGcQAjoyXeCSGKgDql3Yxlj5x6e56uOzh0K7SPuXEmbUqwCOEzPrGN+4C6emjary85DU36ClxGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUK+yTnkbR3iEMZ79kPF1pPYYJQ+UwHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEAhJCZdD0RUYiOvJYoYFymjAHVzj1WmjpwqZJ88uzYrW0CIFa0dkx3vO+EVhvdEYeGIw/BNooNhxRRosteGdWFknM4 duration=1.544942ms duration-ns=1544942 fields.time="2026-08-25T20:12:37Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=NHdmOFlZTVNLTm5oMFpFeHcwWXpTaHV1aW5pbjR2Vmg path=/acme/acme/certificate/4bg35RCvlXxBjF3XSAl5knQENSNg87yG protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=49409ea4-0fc2-4f09-bbb8-333720c3ee9a sans="map[dns:[ca.foo]]" serial=114692212026184267999519404386589527662 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-25T20:11:37Z" valid-to="2026-11-23T20:12:37Z"439ca # [6727731.190578] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] Server responded with a certificate.440ca # [6727731.194551] ca acme-order-renew-ca.foo-start[304]: + mv domainhash.txt certificates/441ca # [6727731.196412] ca acme-order-renew-ca.foo-start[304]: + touch out/acme-success442ca # [6727731.198146] ca acme-order-renew-ca.foo-start[304]: + cmp -s certificates/ca.foo.crt out/fullchain.pem443ca # [6727731.199384] ca acme-order-renew-ca.foo-start[304]: + touch out/renewed444ca # [6727731.200740] ca acme-order-renew-ca.foo-start[304]: + echo Installing new certificate445ca # [6727731.200740] ca acme-order-renew-ca.foo-start[304]: Installing new certificate446ca # [6727731.200782] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.crt out/fullchain.pem447ca # [6727731.202262] ca acme-order-renew-ca.foo-start[347]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'448ca # [6727731.202492] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.key out/key.pem449ca # [6727731.203875] ca acme-order-renew-ca.foo-start[348]: 'certificates/ca.foo.key' -> 'out/key.pem'450ca # [6727731.204156] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem451ca # [6727731.205370] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'452ca # [6727731.205555] ca acme-order-renew-ca.foo-start[304]: + ln -sf fullchain.pem out/cert.pem453ca # [6727731.206916] ca acme-order-renew-ca.foo-start[304]: + cat out/key.pem out/fullchain.pem454ca # [6727731.208942] ca acme-order-renew-ca.foo-start[304]: + for fixpath in out certificates455ca # [6727731.208966] ca acme-order-renew-ca.foo-start[304]: + '[' -d out ']'456ca # [6727731.208966] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=rX,o= out457ca # [6727731.210857] ca acme-order-renew-ca.foo-start[304]: + chown -R acme:nginx out458ca # [6727731.214090] ca acme-order-renew-ca.foo-start[304]: + for fixpath in out certificates459ca # [6727731.214116] ca acme-order-renew-ca.foo-start[304]: + '[' -d certificates ']'460ca # [6727731.214116] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=rX,o= certificates461ca # [6727731.215464] ca acme-order-renew-ca.foo-start[304]: + chown -R acme:nginx certificates462ca # [6727731.217944] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=,o= accounts/.463ca # [6727731.337278] ca systemd[1]: Reloading Nginx Web Server...464ca # [6727731.341372] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.465ca # [6727731.341557] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.466ca # [6727732.091457] ca nginx[365]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok467ca # [6727732.091812] ca nginx[365]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful468ca # [6727732.645279] ca systemd[1]: Reloaded Nginx Web Server.469ca # [6727732.645865] ca systemd[1]: Startup finished in 6.381s.470ca # [6727732.917164] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...471ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 4.91 seconds)472ca # [6727733.477280] ca acme-order-renew-ca.foo-start[380]: Waiting to acquire lock in /run/acme/473ca # [6727733.480119] ca acme-order-renew-ca.foo-start[380]: + set -euo pipefail474ca # [6727733.480197] ca acme-order-renew-ca.foo-start[380]: + echo 88dc4fc401a6091a1bd9475ca # [6727733.480311] ca acme-order-renew-ca.foo-start[380]: + cmp -s domainhash.txt certificates/domainhash.txt476ca # [6727733.481270] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.key ']'477ca # [6727733.481306] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.crt ']'478ca # [6727733.481856] ca acme-order-renew-ca.foo-start[388]: ++ find accounts -name none@none.tld.key479ca # [6727733.485272] ca acme-order-renew-ca.foo-start[380]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'480ca # [6727733.485310] ca acme-order-renew-ca.foo-start[380]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic481ca # [6727733.530731] ca step-ca[203]: time="2026-08-25T20:12:39Z" level=info duration="51.48µs" duration-ns=51480 fields.time="2026-08-25T20:12:39Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4c1f916f-b3fe-4cb7-a925-c7d31fb945d2 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=482ca # [6727733.531310] ca acme-order-renew-ca.foo-start[389]: 2026/08/25 20:12:39 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint483ca # [6727733.531310] ca acme-order-renew-ca.foo-start[389]: 2026/08/25 20:12:39 [INFO] [ca.foo] The certificate expires at 2026-11-23T20:12:37Z, the renewal can be performed in 1439h59m37.415516455s: no renewal.484ca # [6727733.531902] ca acme-order-renew-ca.foo-start[380]: + mv domainhash.txt certificates/485ca # [6727733.533957] ca acme-order-renew-ca.foo-start[380]: + touch out/acme-success486ca # [6727733.535271] ca acme-order-renew-ca.foo-start[380]: + cmp -s certificates/ca.foo.crt out/fullchain.pem487ca # [6727733.536592] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates488ca # [6727733.536622] ca acme-order-renew-ca.foo-start[380]: + '[' -d out ']'489ca # [6727733.536622] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= out490ca # [6727733.538200] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx out491ca # [6727733.540762] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates492ca # [6727733.540762] ca acme-order-renew-ca.foo-start[380]: + '[' -d certificates ']'493ca # [6727733.540852] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= certificates494ca # [6727733.542460] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx certificates495ca # [6727733.545851] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=,o= accounts/.496ca # [6727733.655365] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.497ca # [6727733.655583] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.498server: must succeed: systemctl restart acme-test.foo.service499server # [6727736.686236] server systemd[1]: acme-test.foo.service: Deactivated successfully.500server # [6727736.686464] server systemd[1]: Stopped Ensure certificate for test.foo.501server # [6727736.687410] server systemd[1]: Stopping Ensure certificate for test.foo...502server # [6727736.721798] server systemd[1]: Starting Ensure certificate for test.foo...503server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.79 seconds)504client: waiting for success: curl -v https://test.foo505* Host test.foo:443 was resolved.506* IPv6: 2001:db8:1::3507* IPv4: 192.168.1.3508* Trying [2001:db8:1::3]:443...509* ALPN: curl offers h2,http/1.1510} [5 bytes data]511* TLSv1.3 (OUT), TLS handshake, Client hello (1):512} [1552 bytes data]513* SSL Trust Anchors:514* OpenSSL default paths (fallback)515{ [5 bytes data]516* TLSv1.3 (IN), TLS handshake, Server hello (2):517{ [1210 bytes data]518* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):519{ [1 bytes data]520* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):521{ [19 bytes data]522* TLSv1.3 (IN), TLS handshake, Certificate (11):523{ [1011 bytes data]524* TLSv1.3 (IN), TLS handshake, CERT verify (15):525{ [112 bytes data]526* TLSv1.3 (IN), TLS handshake, Finished (20):527{ [52 bytes data]528* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):529} [1 bytes data]530* TLSv1.3 (OUT), TLS handshake, Finished (20):531} [52 bytes data]532* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey533* ALPN: server accepted h2534* Server certificate:535* subject: CN=test.foo536* start date: Aug 25 20:12:35 2026 GMT537* expire date: Sep 24 20:12:35 2028 GMT538* issuer: CN=minica root ca 064d82539* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384540* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384541* subjectAltName: "test.foo" matches cert's "test.foo"542* OpenSSL verify result: 13543* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)544* closing connection #0545curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)546More details here: https://curl.se/docs/sslcerts.html547548curl failed to verify the legitimacy of the server and therefore could not549establish a secure connection to it. To learn more about this situation and550how to fix it, please visit the webpage mentioned above.551server # [6727737.427606] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/552server # [6727737.430757] server acme-test.foo-start[314]: + '[' -e out/acme-success ']'553server # [6727737.430757] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=554server # [6727737.446584] server acme-test.foo-start[324]: + cd test.foo555server # [6727737.447074] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem556server # [6727737.448614] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem'557server # [6727737.448870] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem558server # [6727737.450494] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem'559server # [6727737.450770] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem560server # [6727737.452564] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem561server # [6727737.454225] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem562server # [6727737.457250] server acme-test.foo-start[314]: + for fixpath in out certificates563server # [6727737.457250] server acme-test.foo-start[314]: + '[' -d out ']'564server # [6727737.457340] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out565server # [6727737.459620] server acme-test.foo-start[314]: + chown -R acme:nginx out566server # [6727737.462151] server acme-test.foo-start[314]: + for fixpath in out certificates567server # [6727737.462223] server acme-test.foo-start[314]: + '[' -d certificates ']'568server # [6727737.466759] server systemd[1]: Finished Ensure certificate for test.foo.569server # [6727737.469570] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...570* Host test.foo:443 was resolved.571* IPv6: 2001:db8:1::3572* IPv4: 192.168.1.3573* Trying [2001:db8:1::3]:443...574* ALPN: curl offers h2,http/1.1575} [5 bytes data]576* TLSv1.3 (OUT), TLS handshake, Client hello (1):577} [1552 bytes data]578* SSL Trust Anchors:579server # [6727738.296744] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/580server # [6727738.300179] server acme-order-renew-test.foo-start[332]: + set -euo pipefail581server # [6727738.300262] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108582server # [6727738.300377] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt583server # [6727738.301638] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run584server # [6727738.350852] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] acme: Registering account for none@none.tld585server # [6727738.396447] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!!586server # [6727738.396447] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your587server # [6727738.396447] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts".588server # [6727738.396447] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This589server # [6727738.396447] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys590server # [6727738.396447] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME591server # [6727738.396447] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal.592server # [6727738.396447] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Obtaining bundled SAN certificate593server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh594server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01595server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: use http-01 solver596server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Trying to solve HTTP-01597server # [6727738.479756] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] The server validated our request598server # [6727738.480164] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Validations succeeded; requesting certificates599server # [6727738.500866] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] Server responded with a certificate.600server # [6727738.504979] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/601server # [6727738.507036] server acme-order-renew-test.foo-start[332]: + touch out/acme-success602server # [6727738.508700] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem603server # [6727738.509942] server acme-order-renew-test.foo-start[332]: + touch out/renewed604server # [6727738.511463] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate605server # [6727738.511463] server acme-order-renew-test.foo-start[332]: Installing new certificate606server # [6727738.511463] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem607server # [6727738.513398] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'608server # [6727738.513794] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem609server # [6727738.515385] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem'610server # [6727738.515695] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem611server # [6727738.517119] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'612server # [6727738.517431] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem613server # [6727738.519200] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem614server # [6727738.521767] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates615server # [6727738.521767] server acme-order-renew-test.foo-start[332]: + '[' -d out ']'616server # [6727738.521884] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out617server # [6727738.523761] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out618server # [6727738.527028] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates619server # [6727738.527028] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']'620server # [6727738.527132] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates621server # [6727738.529008] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates622server # [6727738.532507] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/.623* OpenSSL default paths (fallback)624{ [5 bytes data]625* TLSv1.3 (IN), TLS handshake, Server hello (2):626{ [1210 bytes data]627* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):628{ [1 bytes data]629* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):630{ [19 bytes data]631* TLSv1.3 (IN), TLS handshake, Certificate (11):632{ [1011 bytes data]633* TLSv1.3 (IN), TLS handshake, CERT verify (15):634{ [112 bytes data]635* TLSv1.3 (IN), TLS handshake, Finished (20):636{ [52 bytes data]637* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):638} [1 bytes data]639* TLSv1.3 (OUT), TLS handshake, Finished (20):640} [52 bytes data]641* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey642* ALPN: server accepted h2643* Server certificate:644* subject: CN=test.foo645* start date: Aug 25 20:12:35 2026 GMT646* expire date: Sep 24 20:12:35 2028 GMT647* issuer: CN=minica root ca 064d82648* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384649* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384650* subjectAltName: "test.foo" matches cert's "test.foo"651* OpenSSL verify result: 13652* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)653* closing connection #0654curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)655More details here: https://curl.se/docs/sslcerts.html656657curl failed to verify the legitimacy of the server and therefore could not658establish a secure connection to it. To learn more about this situation and659how to fix it, please visit the webpage mentioned above.660ca # [6727738.349877] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration="71.761µs" duration-ns=71761 fields.time="2026-08-25T20:12:44Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=bca36da8-f243-4b3e-ae52-dd9a2abf658c response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=661ca # [6727738.388816] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=34.100956ms duration-ns=34100956 fields.time="2026-08-25T20:12:44Z" method=HEAD name=ca nonce=S0wweTBEdDV2VjVvUFVTYndxZzJxcml0WVM2NmM1SlU path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1b0a2dc1-88db-4f0a-be95-c246b162008d size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=662ca # [6727738.395460] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=4.030456ms duration-ns=4030456 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=SFJtZndza2E2VTAzSURPMHhNWEpTc3g2NHdKNWJ3SUw path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=9540cdf6-ad25-4da6-9112-6cc26c94152a response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/e5HhSvl4Yutwza84keaozJtmKIvV31i0/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=663ca # [6727738.403906] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=5.427476ms duration-ns=5427476 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=cjdmSEhXWmxkUW1Mbm12WEUwNWRXd0F3RkV1WHF6T3Q path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=4f15f238-49fa-4026-880a-574356e0f7ba response="{\"id\":\"Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:12:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:11:44Z\",\"notAfter\":\"2026-11-23T20:12:44Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh\"],\"finalize\":\"https://ca.foo/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=664ca # [6727738.467697] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=4.468382ms duration-ns=4468382 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=cFBnYTlRd1VIZXNkU1FEY3ZoZ1hmWE9YRVJTblVPbW0 path=/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh protocol=HTTP/1.1 referer= remote-address="::1" request-id=935589a3-9974-4a00-8fa1-76bc7b277ce2 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/RHB8PPDQlpzUtTvXGuPbY6rrT4rIvWB9\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/KKV2e3EuBRYfasLfF75bcq24JmXeyzLJ\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:12:44Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=665ca # [6727738.479059] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=6.848855ms duration-ns=6848855 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=R010aHd2SmhhTmc3MWVyb09kRVMzUXdoenZLRzgzUGU path=/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=a40f5555-8962-477e-8152-da925082c086 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"validated\":\"2026-08-25T20:12:44Z\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=666ca # [6727738.492578] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=9.383211ms duration-ns=9383211 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=Snc5TnFnQWcxQmtDTjBRcVhyOFVJZ0lNQTBLTWszR0g path=/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=a3d1a7b3-f3c3-4c01-b082-e8f06dd7cc28 response="{\"id\":\"Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:12:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:11:44Z\",\"notAfter\":\"2026-11-23T20:12:44Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh\"],\"finalize\":\"https://ca.foo/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/ASUzr58lcz0NgoCQzTJjdFvJaUob61hH\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=667ca # [6727738.500333] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info certificate="MIIB1zCCAX6gAwIBAgIRAOs7E39U6X19oLrlQiJ50N0wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI1MjAxMTQ0WhcNMjYxMTIzMjAxMjQ0WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABN+KlnUhCUOXLgcLIZTh2HU0lLU2kD6jay0b8PJuc+KuHL6QagorBEUrsr0ssPUNEbcDIVR8O/681FAgkyyW4NejgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUc3PxjjHihkT85kpjLWv8s28pdeswHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0cAMEQCIHQAVdeluA6nxG/J9hDmcaQPpDbF9ugeKYedcptalSlRAiAXKmUiEOv+CVCEXCZPBLfHtOKfcOpeFL0purmvIX5QzQ==" duration=3.641091ms duration-ns=3641091 fields.time="2026-08-25T20:12:44Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=bEMxUVFjS0J1d1EzcW01bDQzNHRyWUdFbFlRT21wOTk path=/acme/acme/certificate/ASUzr58lcz0NgoCQzTJjdFvJaUob61hH protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=dd9759da-89cf-4622-bea3-d8207b0d8fab sans="map[dns:[test.foo]]" serial=312675319978146906809985271581040562397 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-25T20:11:44Z" valid-to="2026-11-23T20:12:44Z"668server # [6727738.647136] server systemd[1]: Reloading Nginx Web Server...669server # [6727738.651171] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.670server # [6727738.651399] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.671* Host test.foo:443 was resolved.672* IPv6: 2001:db8:1::3673* IPv4: 192.168.1.3674* Trying [2001:db8:1::3]:443...675* ALPN: curl offers h2,http/1.1676} [5 bytes data]677* TLSv1.3 (OUT), TLS handshake, Client hello (1):678} [1552 bytes data]679* SSL Trust Anchors:680* OpenSSL default paths (fallback)681{ [5 bytes data]682* TLSv1.3 (IN), TLS handshake, Server hello (2):683{ [1210 bytes data]684* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):685{ [1 bytes data]686* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):687{ [19 bytes data]688* TLSv1.3 (IN), TLS handshake, Certificate (11):689{ [1011 bytes data]690* TLSv1.3 (IN), TLS handshake, CERT verify (15):691{ [112 bytes data]692* TLSv1.3 (IN), TLS handshake, Finished (20):693{ [52 bytes data]694* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):695} [1 bytes data]696* TLSv1.3 (OUT), TLS handshake, Finished (20):697} [52 bytes data]698* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey699* ALPN: server accepted h2700* Server certificate:701* subject: CN=test.foo702* start date: Aug 25 20:12:35 2026 GMT703* expire date: Sep 24 20:12:35 2028 GMT704* issuer: CN=minica root ca 064d82705* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384706* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384707* subjectAltName: "test.foo" matches cert's "test.foo"708* OpenSSL verify result: 13709* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)710* closing connection #0711curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)712More details here: https://curl.se/docs/sslcerts.html713714curl failed to verify the legitimacy of the server and therefore could not715establish a secure connection to it. To learn more about this situation and716how to fix it, please visit the webpage mentioned above.717server # [6727739.383840] server nginx[390]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok718server # [6727739.384523] server nginx[390]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful719server # [6727739.970319] server systemd[1]: Reloaded Nginx Web Server.720* Host test.foo:443 was resolved.721* IPv6: 2001:db8:1::3722* IPv4: 192.168.1.3723* Trying [2001:db8:1::3]:443...724* ALPN: curl offers h2,http/1.1725} [5 bytes data]726* TLSv1.3 (OUT), TLS handshake, Client hello (1):727} [1552 bytes data]728* SSL Trust Anchors:729* OpenSSL default paths (fallback)730{ [5 bytes data]731* TLSv1.3 (IN), TLS handshake, Server hello (2):732{ [1210 bytes data]733* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):734{ [1 bytes data]735* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):736{ [19 bytes data]737* TLSv1.3 (IN), TLS handshake, Certificate (11):738{ [930 bytes data]739* TLSv1.3 (IN), TLS handshake, CERT verify (15):740{ [79 bytes data]741* TLSv1.3 (IN), TLS handshake, Finished (20):742{ [52 bytes data]743* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):744} [1 bytes data]745* TLSv1.3 (OUT), TLS handshake, Finished (20):746} [52 bytes data]747* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey748* ALPN: server accepted h2749* Server certificate:750* subject: CN=test.foo751* start date: Aug 25 20:11:44 2026 GMT752* expire date: Nov 23 20:12:44 2026 GMT753* issuer: CN=Clan Intermediate CA754* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256755* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256756* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256757* subjectAltName: "test.foo" matches cert's "test.foo"758* OpenSSL verify result: 0759* SSL certificate verified via OpenSSL.760* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 34860 761 % Total % Received % Xferd Average Speed Time Time Time Current762 Dload Upload Total Spent Left Speed763 0 0 0 0 0 0 0 0 0* using HTTP/2764* [HTTP/2] [1] OPENED stream for https://test.foo/765* [HTTP/2] [1] [:method: GET]766* [HTTP/2] [1] [:scheme: https]767* [HTTP/2] [1] [:authority: test.foo]768* [HTTP/2] [1] [:path: /]769* [HTTP/2] [1] [user-agent: curl/8.21.0]770* [HTTP/2] [1] [accept: */*]771} [5 bytes data]772773774775776777* Request completely sent off778{ [5 bytes data]779* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):780{ [265 bytes data]781* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):782{ [265 bytes data]783784785786787788789790{ [5 bytes data]791100 20 100 20 0 0 697 0 0792* Connection #0 to host test.foo:443 left intact793client: (finished: waiting for success: curl -v https://test.foo, in 3.19 seconds)794client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2795Certificate:796 Data:797 Version: 3 (0x2)798 Serial Number:799 eb:3b:13:7f:54:e9:7d:7d:a0:ba:e5:42:22:79:d0:dd800 Signature Algorithm: ecdsa-with-SHA256801 Issuer: CN=Clan Intermediate CA802 Validity803 Not Before: Aug 25 20:11:44 2026 GMT804 Not After : Nov 23 20:12:44 2026 GMT805 Subject: CN=test.foo806 Subject Public Key Info:807 Public Key Algorithm: id-ecPublicKey808 Public-Key: (256 bit)809 pub:810 04:df:8a:96:75:21:09:43:97:2e:07:0b:21:94:e1:811 d8:75:34:94:b5:36:90:3e:a3:6b:2d:1b:f0:f2:6e:812 73:e2:ae:1c:be:90:6a:0a:2b:04:45:2b:b2:bd:2c:813 b0:f5:0d:11:b7:03:21:54:7c:3b:fe:bc:d4:50:20:814 93:2c:96:e0:d7815 ASN1 OID: prime256v1816 NIST CURVE: P-256817 X509v3 extensions:818 X509v3 Key Usage: critical819 Digital Signature820 X509v3 Extended Key Usage: 821 TLS Web Server Authentication, TLS Web Client Authentication822 X509v3 Subject Key Identifier: 823 73:73:F1:8E:31:E2:86:44:FC:E6:4A:63:2D:6B:FC:B3:6F:29:75:EB824 X509v3 Authority Key Identifier: 825 06:12:DD:D9:F1:F5:5C:F1:69:FB:75:FD:3A:9E:02:BB:DA:F7:CD:8D826 X509v3 Subject Alternative Name: 827 DNS:test.foo828 1.3.6.1.4.1.37476.9000.64.1: 829 0......acme..830 Signature Algorithm: ecdsa-with-SHA256831 Signature Value:832 30:44:02:20:74:00:55:d7:a5:b8:0e:a7:c4:6f:c9:f6:10:e6:833 71:a4:0f:a4:36:c5:f6:e8:1e:29:87:9d:72:9b:5a:95:29:51:834 02:20:17:2a:65:22:10:eb:fe:09:50:84:5c:26:4f:04:b7:c7:835 b4:e2:9f:70:ea:5e:14:bd:29:ba:b9:af:21:7e:50:cd836client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds)837(finished: run the VM test script, in 14.95 seconds)838test script finished in 48.65s839cleanup840kill NspawnMachine (pid 53)841kill NspawnMachine (pid 54)842kill NspawnMachine (pid 55)843Container ca terminated by signal KILL.844Container client terminated by signal KILL.845Container server terminated by signal KILL.846(finished: cleanup, in 0.54 seconds)