these 85 derivations will be built: /nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv /nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv /nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv /nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv /nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv /nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv /nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv /nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv /nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv /nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv /nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv /nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv /nix/store/g8zvdc7xxnmgnx1qh04xhiz3qgkddvqr-unit-nix-daemon.service.drv /nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv /nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv /nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv /nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv /nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv /nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv /nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv /nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv /nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv /nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv /nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv /nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/8i2c45ik5apccpdsd7kc5pr4zi434cbv-system-units.drv /nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv /nix/store/l36d5z838si62gvyhprpqq4q5pv3nf1a-etc.drv /nix/store/1aknm3kxwik2rn37s74ilz8r2mxxim67-activate.drv /nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv /nix/store/dgcdihsqi8qwcyd0kxwbmj933kqisv5z-nixos-system-server-test.drv /nix/store/02j4rvfjn4w62a59gyglzfd64jfw6y9f-run-server-nspawn.drv /nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv /nix/store/jpzicclk96dz0wcwjbfaddaygk6gvqki-nginx.conf.drv /nix/store/v6swhk9fr5gl0ljwsyc7acjf9fv8jiil-unit-script-nginx-pre-start.drv /nix/store/2iylka6m737l3bai4j1ml4q7j4vbw408-unit-nginx.service.drv /nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv /nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv /nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv /nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv /nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv /nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv /nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv /nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv /nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv /nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv /nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv /nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv /nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv /nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv /nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv /nix/store/071hwibqxbawm8k3jrd9nivxrdi1lba6-system-units.drv /nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv /nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv /nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv /nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv /nix/store/1cc5pcy5kwg3626s7gxv234r2i7x0rax-system-units.drv /nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv /nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv /nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv /nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv /nix/store/b5f1xw8dflmbi32jqfii9i2nk143x6ky-etc.drv /nix/store/il9c1ysdj5vlf8qz1g2zyizrzwllyvd1-activate.drv /nix/store/53i50bi5sjcvpxdg0zzac803v5zl544x-nixos-system-client-test.drv /nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv /nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv /nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv /nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv /nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv /nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv /nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv /nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv /nix/store/flwa7x6gcjc42sh9jk7chgiaz83m08x1-etc.drv /nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv /nix/store/78g8xy1x7gl5cll8kpyawz8cq5y94c7r-activate.drv /nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv /nix/store/hmhh5pbbss0xndq1k6vcdsch9x71p28f-nixos-system-ca-test.drv /nix/store/a0md0ssmcbm92kg6ksyzmsmhz80r4392-run-ca-nspawn.drv /nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv /nix/store/r42idgq2fvd9zlpwcww9nsdhi79i3h61-run-client-nspawn.drv /nix/store/c5ymda04wd7h0xp6mlg0abh4dl2fszwi-driverConfiguration.json.drv /nix/store/ywbys7f0zhbdhdpm64sav7my9l6pm5al-nixos-test-driver-certificates.drv /nix/store/n9qa1hcv17llsnmmlkqlpz9rsjgpz0sj-container-test-run-certificates.drv this path will be fetched (19.5 MiB download, 67.0 MiB unpacked): /nix/store/9zffz42v1gbfs8dwi61v4m09skszgl9x-step-ca-0.30.2 building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/npnkh4ksqp735b0d8frfk6ykpnz5h93r-test-script.drv' building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0aznxyzb6x331csg7gjn8cw5xl2605pi-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/6855qyfnz0gs4rb5b4vjlakqwsx0c0pl-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/wjhip83zz49nc47jj082bc1iqs952j99-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/wdmlx6iw9y50c5cq986zgi8znnv17vzg-acme-postrun.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5kwb66n6agcknly2n8bbfs5cv91dv1sa-acme-postrun.drv' building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mq9cj4xvysnxn3pp9g2ga0dv4sa522f5-X-Restart-Triggers-acme-ca.foo.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/fz71wbciagliv9pms7wfvv7br3qafxf9-acme-setup-privileged.drv' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kq0bqn3imkz42wrzfjcgy8gv5xlrv7dm-acme-setup-privileged.drv' building '/nix/store/n9g0f07vxaqnxyhk0kknrkn9p86b038l-ca.json.drv' ca.json> structuredAttrs is enabled building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/gml8r4jzrx8pxi8kgp8dskjbyaw0a0fs-dbus-1.drv' building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fic80krmpyc0vdr46jg8vn3n1f0g2j73-dbus-1.drv' building '/nix/store/jikfvff8i9zx37pq9b1panvndrsy8j3d-etc-hostname.drv' building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/hzgn023msyi298l2f9svhhnkfsiswhl5-X-Restart-Triggers-step-ca.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/zaygn692fzw3y7hvi0y2nspp3vxdf4zf-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/y7ns3ivxr9c8ml8rsgrv8vxhl3rvs287-extra-hosts.drv' building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/mrnpn8dw7zhx50b8swf2sk27a7pj7fa5-X-Restart-Triggers-dbus-broker.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/4d11adikk9i02khvknlf61i542avljxa-nginx.conf.drv' nginx.conf> structuredAttrs is enabled building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dh1wa3c5fhmdlcpd9xkpnykq2qg54anb-hosts.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/if2dfikfrcj1g6phg8p3i4r8h3bh1h2i-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jpzicclk96dz0wcwjbfaddaygk6gvqki-nginx.conf.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/6mg9yicgv0wiph6gwsvwc4wfp90czgnz-hosts.drv' building '/nix/store/qm5bs8gz77908r3xxdgpf9dsb5dqx02l-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/m81apsb191x7gyhs948a701r8f8hx8cq-decrypt-age-secrets.drv' building '/nix/store/7xhzzhwx91bfjzgmbb86yh8p45gcx7ry-unit-step-ca.service.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/jpzicclk96dz0wcwjbfaddaygk6gvqki-nginx.conf.drv' nginx.conf> structuredAttrs is enabled nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kjql7xf5v2jlgmmrdnz87nan6jmlgyaj-unit-script-nginx-pre-start.drv' building '/nix/store/6sm958a7y1snbxnxrn1zd96mjkqsw88h-string-hosts.drv' building '/nix/store/hfkx72smrjg3my0r04xwnjgl62ypyxjv-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126... building '/nix/store/v6swhk9fr5gl0ljwsyc7acjf9fv8jiil-unit-script-nginx-pre-start.drv' on 'ssh-ng://builder@build01.clan.lol' nss-cacert-3.126> patching script interpreter paths in /nix/store/71w9yl59gjgj860klfvjavl61nsn01mj-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/bh4z9rzwsbms55bwhlh34zfr561dq731-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/q5087i3qbf8kc16y51d8g8h6lpql03cj-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/cm3hncx7la5am6sa2bifhj7j7i2kr5i8-nss-cacert-3.126-hashed building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ap3wq0i9pnqfn49ifmvrfdx7w4adzh7q-hosts.drv' building '/nix/store/g8zvdc7xxnmgnx1qh04xhiz3qgkddvqr-unit-nix-daemon.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v6swhk9fr5gl0ljwsyc7acjf9fv8jiil-unit-script-nginx-pre-start.drv' building '/nix/store/2iylka6m737l3bai4j1ml4q7j4vbw408-unit-nginx.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ihcyabx8107x0z51x1p00ss738m1by4z-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/kv244kzjv2wsq4aj781mgqyi03rkwppz-system-generators.drv' building '/nix/store/fa3m94n9x9h6rvcvv1b7xmbvzxxndg04-system-path.drv' system-path> structuredAttrs is enabled system-path> created 1718 symlinks in user environment building '/nix/store/0qwh8fffppcjq01653fjj6r7907455zi-unit-acme-renew-ca.foo.timer.drv' unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/s5w4iyfc3045nw29paigrfppw226il7m-unit-acme-renew-test.foo.timer.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/f203kgg6m46v2nbzkkrdhl2d9y4qzacn-unit-acme-setup.service.drv' unit-acme-setup.service> structuredAttrs is enabled building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/g8zvdc7xxnmgnx1qh04xhiz3qgkddvqr-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ikk469l2wssyvzhq1n3iyvza3f30jvc5-system-shutdown.drv' building '/nix/store/2iylka6m737l3bai4j1ml4q7j4vbw408-unit-nginx.service.drv' unit-nginx.service> structuredAttrs is enabled building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/h8wqiaffc333h4n15l9fq1wrz4849l51-dbus-1.drv' building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/rkdgv9ib3kg999rh445ciz27785ymvsz-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/vmqvd0rvmykcidv0gjl4r70al3wi6z6m-unit-acme-account-2c44cb477b4787b2cf13.target.drv' unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/iirbp9qwsg0x7jpwm7402lgm0na53ckw-unit-acme-account-d22a46d9459bf683a338.target.drv' unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled building '/nix/store/glzjf1igzk1rfzd4cj7cdcbxhrwkakn0-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/m5iwi6jigzhhka4fg48a5vdkd9b03dh5-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/k7p5hmpmjprhf8avpip5hqgwal6ynyar-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/8qkprx2lxqa0w7ryv1wdv215wh2ssm2w-unit-script-acme-ca.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/v0agb0fwq6paim03a7lsnb83qkp757vm-unit-script-acme-order-renew-test.foo-start.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/szfhwf43fshi1j5zn2qxg6sw88gl50bp-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/rc0xfdqfzrswra98nqzjl9n07aid02gw-unit-script-acme-test.foo-start.drv' building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ma7d068wl7r81dsprwq8db0ccvml111w-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/rxza4c9r2hn3j3zgdxs9a31qsg80jqyk-unit-nginx-config-reload.service.drv' unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/jxm6hpbyi9ja04zj89z6qzrwjy2pk16q-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/v3nx0zrihjmvhv4y66pgi93mm3g8d50v-unit-acme-order-renew-test.foo.service.drv' unit-acme-order-renew-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/5688dcrhyryshi5mg565pcam7bs83cn7-unit-acme-ca.foo.service.drv' unit-acme-ca.foo.service> structuredAttrs is enabled building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c2pygc22m06f5j91981i00smr1dw9d9f-user-generators.drv' building '/nix/store/0ksihnydzfrkng1zyj3i8a7lx7djrxf7-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ri0ml0q189k97pgc95bl40zynmrry94r-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/071hwibqxbawm8k3jrd9nivxrdi1lba6-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/5byjaqq8fvvhkpibph0xvk5464lnadf5-user-units.drv' building '/nix/store/ya9vnsc16n65kc9lhqmjnniq63dvccgk-user-units.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/n8kq25yp0abv3g3xazmwmrg2k23n1jav-unit-acme-test.foo.service.drv' unit-acme-test.foo.service> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/c5ddj5j6j88aw15558234rxzaq62jifn-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/1cc5pcy5kwg3626s7gxv234r2i7x0rax-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/8i2c45ik5apccpdsd7kc5pr4zi434cbv-system-units.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1cc5pcy5kwg3626s7gxv234r2i7x0rax-system-units.drv' building '/nix/store/8i2c45ik5apccpdsd7kc5pr4zi434cbv-system-units.drv' building '/nix/store/071hwibqxbawm8k3jrd9nivxrdi1lba6-system-units.drv' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/3ni9n87isj6rmj1xwjmalgwffs9liy3m-users-groups.json.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/kpnx9pmqq0n5h7vdyzfybxcn9pxw6f2h-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully building '/nix/store/7rqra8im5r7cfw2gwb8d6ibs9anghpb7-users-groups.json.drv' building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/wjz3fhbqidbl8nqk3vqnv7gjsx43380z-dry-activate.drv' building '/nix/store/b5f1xw8dflmbi32jqfii9i2nk143x6ky-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/flwa7x6gcjc42sh9jk7chgiaz83m08x1-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/l36d5z838si62gvyhprpqq4q5pv3nf1a-etc.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/l36d5z838si62gvyhprpqq4q5pv3nf1a-etc.drv' building '/nix/store/flwa7x6gcjc42sh9jk7chgiaz83m08x1-etc.drv' building '/nix/store/b5f1xw8dflmbi32jqfii9i2nk143x6ky-etc.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/78g8xy1x7gl5cll8kpyawz8cq5y94c7r-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/jhfpd5015s8x7a59gfcfhda9dpqqlbah-dry-activate.drv' building '/nix/store/1aknm3kxwik2rn37s74ilz8r2mxxim67-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/78g8xy1x7gl5cll8kpyawz8cq5y94c7r-activate.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/1aknm3kxwik2rn37s74ilz8r2mxxim67-activate.drv' building '/nix/store/il9c1ysdj5vlf8qz1g2zyizrzwllyvd1-activate.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hmhh5pbbss0xndq1k6vcdsch9x71p28f-nixos-system-ca-test.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/dgcdihsqi8qwcyd0kxwbmj933kqisv5z-nixos-system-server-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/hmhh5pbbss0xndq1k6vcdsch9x71p28f-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/a0md0ssmcbm92kg6ksyzmsmhz80r4392-run-ca-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/il9c1ysdj5vlf8qz1g2zyizrzwllyvd1-activate.drv' building '/nix/store/dgcdihsqi8qwcyd0kxwbmj933kqisv5z-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/a0md0ssmcbm92kg6ksyzmsmhz80r4392-run-ca-nspawn.drv' building '/nix/store/53i50bi5sjcvpxdg0zzac803v5zl544x-nixos-system-client-test.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/02j4rvfjn4w62a59gyglzfd64jfw6y9f-run-server-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/02j4rvfjn4w62a59gyglzfd64jfw6y9f-run-server-nspawn.drv' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/53i50bi5sjcvpxdg0zzac803v5zl544x-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/r42idgq2fvd9zlpwcww9nsdhi79i3h61-run-client-nspawn.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/r42idgq2fvd9zlpwcww9nsdhi79i3h61-run-client-nspawn.drv' building '/nix/store/c5ymda04wd7h0xp6mlg0abh4dl2fszwi-driverConfiguration.json.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/c5ymda04wd7h0xp6mlg0abh4dl2fszwi-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/ywbys7f0zhbdhdpm64sav7my9l6pm5al-nixos-test-driver-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' building '/nix/store/ywbys7f0zhbdhdpm64sav7my9l6pm5al-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/n9qa1hcv17llsnmmlkqlpz9rsjgpz0sj-container-test-run-certificates.drv' on 'ssh-ng://builder@build01.clan.lol' warning: SQLite database '/nix/var/nix/db/db.sqlite' is busy building '/nix/store/n9qa1hcv17llsnmmlkqlpz9rsjgpz0sj-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> client # [6727726.648362] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [6727726.660992] ca systemd-journald[77]: Journal started container-test-run-certificates> client # [6727726.648429] client systemd-journald[69]: Runtime Journal (/run/log/journal/db952a3da14940acb0d4d14906bba396) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> ca # [6727726.661048] ca systemd-journald[77]: Runtime Journal (/run/log/journal/83737126434c40f5b558a2195ea254b7) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6727726.650310] client systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> ca # [6727726.666057] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [6727726.657613] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6727726.675735] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6727726.667457] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> ca # [6727726.676923] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [6727726.668468] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6727726.678698] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6727726.686816] ca systemd-journald[77]: Time spent on flushing to /var/log/journal/83737126434c40f5b558a2195ea254b7 is 1.680ms for 6 entries. container-test-run-certificates> client # [6727726.669306] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6727726.686816] ca systemd-journald[77]: System Journal (/var/log/journal/83737126434c40f5b558a2195ea254b7) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [6727726.678001] client systemd-journald[69]: Time spent on flushing to /var/log/journal/db952a3da14940acb0d4d14906bba396 is 1.916ms for 7 entries. container-test-run-certificates> ca # [6727726.696210] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> client # [6727726.678001] client systemd-journald[69]: System Journal (/var/log/journal/db952a3da14940acb0d4d14906bba396) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6727726.697033] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> client # [6727726.686688] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [6727726.647800] server systemd-journald[69]: Journal started container-test-run-certificates> client # [6727726.687049] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [6727726.647859] server systemd-journald[69]: Runtime Journal (/run/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6) is 8M, max 2.5G, 2.4G free. container-test-run-certificates> client # [6727726.687142] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> server # [6727726.650497] server systemd[1]: Finished Apply Kernel Variables. container-test-run-certificates> client # [6727726.687915] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6727726.697170] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [6727726.687963] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6727726.698140] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [6727726.689154] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6727726.657599] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [6727726.698191] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6727726.668167] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [6727726.689205] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6727726.699082] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> server # [6727726.669291] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> ca # [6727726.699121] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [6727726.670127] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [6727726.705380] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [6727726.678776] server systemd-journald[69]: Time spent on flushing to /var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6 is 1.746ms for 7 entries. container-test-run-certificates> ca # [6727726.706403] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6727726.678776] server systemd-journald[69]: System Journal (/var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [6727726.722577] ca systemd-tmpfiles[125]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6727726.686077] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [6727726.722784] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6727726.686909] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [6727726.722909] ca systemd-tmpfiles[125]: fchmod() of /var/log/journal/83737126434c40f5b558a2195ea254b7 failed: Operation not permitted container-test-run-certificates> server # [6727726.687037] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [6727726.723094] ca systemd-tmpfiles[125]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6727726.687916] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [6727726.724735] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6727726.687967] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6727726.725846] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6727726.689243] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [6727726.726826] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6727726.689289] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [6727726.740531] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6727726.704284] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6727726.747389] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6727726.696811] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [6727726.748422] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6727726.706076] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [6727726.758163] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6727726.698191] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [6727726.715257] server systemd-tmpfiles[118]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [6727726.715445] server systemd-tmpfiles[118]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [6727726.715569] server systemd-tmpfiles[118]: fchmod() of /var/log/journal/4fed7f9986dd44c38b8c8aa8dbb8fce6 failed: Operation not permitted container-test-run-certificates> server # [6727726.715753] server systemd-tmpfiles[118]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [6727726.717438] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [6727726.718727] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [6727726.719670] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [6727726.732151] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [6727726.740392] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [6727726.741574] server systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [6727726.751638] server systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [6727726.722181] client systemd-tmpfiles[122]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> client # [6727726.722380] client systemd-tmpfiles[122]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [6727726.722511] client systemd-tmpfiles[122]: fchmod() of /var/log/journal/db952a3da14940acb0d4d14906bba396 failed: Operation not permitted container-test-run-certificates> client # [6727726.722705] client systemd-tmpfiles[122]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> client # [6727726.724364] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [6727726.725553] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [6727726.726359] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [6727726.739182] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [6727726.746093] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> client # [6727726.747208] client systemd[1]: Starting Update is Completed... container-test-run-certificates> client # [6727726.757846] client systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [6727726.803653] server systemd[1]: Finished Firewall. container-test-run-certificates> server # [6727726.803817] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> server # [6727726.804063] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> server # [6727726.805157] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [6727726.801973] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [6727726.802128] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [6727726.802351] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [6727726.803514] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [6727726.814274] ca systemd[1]: Finished Firewall. container-test-run-certificates> ca # [6727726.814979] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [6727726.815517] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [6727726.816756] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [6727727.068472] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [6727727.070411] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> server # [6727727.072124] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [6727727.435118] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6727727.435213] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [6727727.442418] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6727727.442579] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [6727727.442750] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [6727727.442755] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [6727727.442964] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [6727727.443348] client systemd[1]: Started Network Management. container-test-run-certificates> client # [6727727.443613] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [6727727.443801] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [6727727.444512] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> client # [6727727.466742] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [6727727.625869] client systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> client # [6727727.625883] client systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [6727727.625886] client systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [6727727.625921] client systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [6727727.636651] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> client # [6727727.648419] client systemd-resolved[97]: Using system hostname 'client'. container-test-run-certificates> client # [6727727.649919] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [6727727.650055] client systemd[1]: Reached target Network. container-test-run-certificates> client # [6727727.650169] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [6727727.650273] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [6727727.650332] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [6727727.650370] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [6727727.650643] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [6727727.650854] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [6727727.651066] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [6727727.651114] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [6727727.651197] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [6727727.653402] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [6727727.654736] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [6727727.688501] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6727727.420800] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6727727.420904] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [6727727.429220] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6727727.429406] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [6727727.429654] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [6727727.429659] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [6727727.429913] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [6727727.430516] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [6727727.430844] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [6727727.430999] server systemd[1]: Started Network Management. container-test-run-certificates> server # [6727727.432172] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [6727727.443508] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [6727727.631781] server systemd-resolved[97]: Positive Trust Anchors: container-test-run-certificates> server # [6727727.631794] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [6727727.631798] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [6727727.631832] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [6727727.636943] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [6727727.654591] server systemd-resolved[97]: Using system hostname 'server'. container-test-run-certificates> server # [6727727.655995] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [6727727.656095] server systemd[1]: Reached target Network. container-test-run-certificates> server # [6727727.656149] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [6727727.656197] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [6727727.656413] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [6727727.656447] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [6727727.656468] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [6727727.656489] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [6727727.656625] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [6727727.656745] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [6727727.656852] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [6727727.656877] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [6727727.656916] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [6727727.688605] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6727727.439023] ca systemd-networkd[194]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6727727.439115] ca systemd-networkd[194]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [6727727.446096] ca systemd-networkd[194]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6727727.446255] ca systemd-networkd[194]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [6727727.446421] ca systemd-networkd[194]: lo: Link UP container-test-run-certificates> ca # [6727727.446425] ca systemd-networkd[194]: lo: Gained carrier container-test-run-certificates> ca # [6727727.446632] ca systemd-networkd[194]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [6727727.446995] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [6727727.447080] ca systemd-networkd[194]: eth1: Link UP container-test-run-certificates> ca # [6727727.447334] ca systemd-networkd[194]: eth1: Gained carrier container-test-run-certificates> ca # [6727727.448054] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [6727727.494079] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [6727727.626444] ca systemd-resolved[104]: Positive Trust Anchors: container-test-run-certificates> ca # [6727727.626456] ca systemd-resolved[104]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [6727727.626460] ca systemd-resolved[104]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [6727727.626494] ca systemd-resolved[104]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [6727727.647652] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [6727727.648847] ca systemd-resolved[104]: Using system hostname 'ca'. container-test-run-certificates> ca # [6727727.650214] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [6727727.650294] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [6727727.650347] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [6727727.650390] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [6727727.650579] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [6727727.650605] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [6727727.650621] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [6727727.650638] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [6727727.650751] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [6727727.650849] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [6727727.650952] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [6727727.650971] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [6727727.651005] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [6727727.652465] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [6727727.653131] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [6727727.653168] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [6727727.653947] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [6727727.655291] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [6727727.688487] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6727727.689759] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [6727727.689807] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [6727727.690758] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [6727727.692172] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [6727727.707138] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [6727727.796109] server acme-setup-privileged[192]: + set -euo pipefail container-test-run-certificates> server # [6727727.796109] server acme-setup-privileged[192]: + cd /var/lib/acme container-test-run-certificates> server # [6727727.796109] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> server # [6727727.797362] server acme-setup-privileged[192]: + chown -R acme .lego/accounts container-test-run-certificates> server # [6727727.798934] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6727727.798987] server acme-setup-privileged[192]: + '[' -d test.foo ']' container-test-run-certificates> server # [6727727.799016] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [6727727.799016] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [6727727.812189] server nsncd[194]: Aug 25 20:12:33.865 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [6727727.812298] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [6727727.812373] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [6727727.812436] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [6727727.841113] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [6727727.842079] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [6727727.852109] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [6727727.853292] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [6727727.853343] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [6727727.853362] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [6727727.704339] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> client # [6727727.836642] client nsncd[189]: Aug 25 20:12:33.889 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [6727727.836738] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [6727727.836811] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [6727727.836878] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [6727727.841274] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [6727727.842112] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [6727727.852639] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [6727727.853574] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [6727727.853610] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [6727727.853629] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6727727.727344] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory container-test-run-certificates> ca # [6727727.727375] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory container-test-run-certificates> ca # [6727727.727425] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'. container-test-run-certificates> ca # [6727727.727492] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [6727727.790883] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> ca # [6727727.790883] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> ca # [6727727.791262] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [6727727.792778] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [6727727.794149] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6727727.794171] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [6727727.794171] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [6727727.794209] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [6727727.817642] ca nsncd[202]: Aug 25 20:12:33.870 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [6727727.817626] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [6727727.817757] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [6727727.817864] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [6727727.841789] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [6727727.843187] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [6727727.854044] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [6727727.855739] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [6727727.855791] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [6727727.855814] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [6727727.982674] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6727727.969925] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [6727727.972102] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [6727727.972102] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [6727727.972591] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [6727727.980892] client dbus-broker-launch[190]: Ready container-test-run-certificates> ca # [6727727.983869] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [6727727.974861] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [6727727.983869] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6727727.976480] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [6727727.984204] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [6727727.991761] ca dbus-broker-launch[204]: Ready container-test-run-certificates> server # [6727727.976480] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [6727727.976953] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [6727727.984290] server dbus-broker-launch[195]: Ready container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [6727728.570452] server systemd-logind[220]: New seat seat0. container-test-run-certificates> server # [6727728.570661] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [6727728.583535] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [6727728.596097] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [6727728.596275] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [6727728.706622] server acme-setup-start[208]: + set -euo pipefail container-test-run-certificates> server # [6727728.706622] server acme-setup-start[208]: + test -e ca/key.pem container-test-run-certificates> server # [6727728.706622] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [6727728.726605] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [6727728.728270] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> ca # [6727728.635404] ca systemd-logind[229]: New seat seat0. container-test-run-certificates> ca # [6727728.635643] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [6727728.637434] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [6727728.649894] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [6727728.649970] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [6727728.721226] ca acme-setup-start[215]: + set -euo pipefail container-test-run-certificates> ca # [6727728.721226] ca acme-setup-start[215]: + test -e ca/key.pem container-test-run-certificates> ca # [6727728.721650] ca acme-setup-start[215]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [6727728.772174] ca systemd-networkd[194]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6727728.884232] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [6727728.886576] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> client # [6727728.628103] client systemd-logind[205]: New seat seat0. container-test-run-certificates> client # [6727728.632200] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [6727728.633900] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [6727728.649222] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [6727728.649400] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [6727728.650480] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [6727728.651057] client systemd[1]: Startup finished in 2.399s. container-test-run-certificates> server # [6727728.832148] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6727728.954797] ca step-ca[203]: badger 2026/08/25 20:12:35 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [6727728.960086] ca step-ca[203]: 2026/08/25 20:12:35 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Starting Smallstep CA/0.30.2 (linux/arm64) container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [6727728.966917] ca step-ca[203]: 2026/08/25 20:12:35 X.509 Root Fingerprint: fcec151c7705057538ab7b446472065d7ea631e5f4168a5856ccb5b20a98592a container-test-run-certificates> ca # [6727728.967468] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [6727728.967844] ca step-ca[203]: 2026/08/25 20:12:35 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [6727729.472171] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca # [6727729.512209] ca acme-ca.foo-start[279]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6727729.515439] ca acme-ca.foo-start[279]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [6727729.515439] ca acme-ca.foo-start[279]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [6727729.528167] ca acme-ca.foo-start[289]: + cd ca.foo container-test-run-certificates> ca # [6727729.528167] ca acme-ca.foo-start[289]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [6727729.530821] ca acme-ca.foo-start[290]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [6727729.531086] ca acme-ca.foo-start[289]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [6727729.531742] ca acme-ca.foo-start[289]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [6727729.531863] ca acme-ca.foo-start[279]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [6727729.536031] ca acme-ca.foo-start[279]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [6727729.536031] ca acme-ca.foo-start[279]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6727729.537392] ca acme-ca.foo-start[279]: + for fixpath in out certificates container-test-run-certificates> ca # [6727729.537392] ca acme-ca.foo-start[279]: + '[' -d out ']' container-test-run-certificates> ca # [6727729.537392] ca acme-ca.foo-start[279]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6727729.538659] ca acme-ca.foo-start[279]: + chown -R acme:nginx out container-test-run-certificates> ca # [6727729.542226] ca acme-ca.foo-start[279]: + for fixpath in out certificates container-test-run-certificates> ca # [6727729.542259] ca acme-ca.foo-start[279]: + '[' -d certificates ']' container-test-run-certificates> ca # [6727729.592305] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [6727729.594436] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> server # [6727729.500500] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6727729.503424] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6727729.503503] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6727729.516271] server acme-test.foo-start[254]: + cd test.foo container-test-run-certificates> server # [6727729.516271] server acme-test.foo-start[254]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6727729.517735] server acme-test.foo-start[255]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6727729.517965] server acme-test.foo-start[254]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6727729.519198] server acme-test.foo-start[254]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6727729.519705] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6727729.521445] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6727729.523291] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6727729.525443] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6727729.525443] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [6727729.525443] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6727729.527315] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [6727729.531030] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [6727729.531030] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [6727729.534690] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6727729.536311] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [6727730.213153] ca nginx-pre-start[301]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok container-test-run-certificates> ca # [6727730.213586] ca nginx-pre-start[301]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful container-test-run-certificates> ca # [6727730.288584] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [6727730.289166] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [6727730.291275] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> server # [6727730.200747] server nginx-pre-start[266]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6727730.201468] server nginx-pre-start[266]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> server # [6727730.208444] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [6727730.208907] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> server # [6727730.210740] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [6727730.925506] ca acme-order-renew-ca.foo-start[304]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6727730.928764] ca acme-order-renew-ca.foo-start[304]: + set -euo pipefail container-test-run-certificates> ca # [6727730.928843] ca acme-order-renew-ca.foo-start[304]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6727730.928955] ca acme-order-renew-ca.foo-start[304]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6727730.929975] ca acme-order-renew-ca.foo-start[304]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [6727730.953827] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [6727730.954167] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [6727730.993052] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration="117.842µs" duration-ns=117842 fields.time="2026-08-25T20:12:37Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=68ba46ae-2dc4-4b51-b95c-432334e58472 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727730.993655] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [6727731.099171] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=105.236909ms duration-ns=105236909 fields.time="2026-08-25T20:12:37Z" method=HEAD name=ca nonce=azRERThTZUNUZUVJdjEyeGp0S1Uwd3FndEdyR3lrNlQ path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=b7c1d69c-80a1-4284-bdf2-cc5dcc79037f size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.110639] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=9.828137ms duration-ns=9828137 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=WnVHbU9JN0ljcWFLRGNrTEZCNkJ0anpRRmEwYW1XVTI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=83ee88f2-8371-4ba0-93aa-939baf1eeefc response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/ef0VYV0Qd6ZzBjV9crXbBl2iR2AJsed2/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: Your account credentials have been saved in your container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: configuration directory at "accounts". container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: configuration directory will also contain private keys container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [6727731.110973] ca acme-order-renew-ca.foo-start[316]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [6727731.111126] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [6727731.114384] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=2.933041ms duration-ns=2933041 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=RXZjRlJnSXdkTXdYa0R4OGQ1UFdwdE45T3U2bmdYVWs path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4ca26361-178e-4efb-8eba-52a6ef8800b8 response="{\"id\":\"yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:12:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:11:37Z\",\"notAfter\":\"2026-11-23T20:12:37Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.175701] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=4.465143ms duration-ns=4465143 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=NVF0NjdTR1pCc2R0dllqMWMzUXY0V25YVFd1U0VHSHI path=/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3 protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=90a9d0a6-0697-47a1-a7ba-13c008f96d06 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/k8msQ5iZ7mrKnQ1V81PFd84VD37Bj9dg\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/F13Cvbvon9XKKQJlXNDwQ9Q6P5W7GxkW\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:12:37Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3 container-test-run-certificates> ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [6727731.175951] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6727730.889422] server acme-order-renew-test.foo-start[269]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6727730.891960] server acme-order-renew-test.foo-start[269]: + set -euo pipefail container-test-run-certificates> server # [6727730.892064] server acme-order-renew-test.foo-start[269]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6727730.892225] server acme-order-renew-test.foo-start[269]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6727730.893227] server acme-order-renew-test.foo-start[269]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6727730.953763] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [6727730.954402] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> server # [6727730.994701] server acme-order-renew-test.foo-start[280]: 2026/08/25 20:12:37 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [6727731.000457] server acme-order-renew-test.foo-start[269]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6727731.000457] server acme-order-renew-test.foo-start[269]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [6727731.000457] server acme-order-renew-test.foo-start[269]: + exit 10 container-test-run-certificates> server # [6727730.998562] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [6727730.998647] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [6727730.998888] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [6727730.999140] server systemd[1]: Startup finished in 4.749s. container-test-run-certificates> ca # [6727731.180337] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=3.858893ms duration-ns=3858893 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=enlQRmNjNWVTWEtGb1o2Zm9uSGd1VHh2cmd2V1lDTFc path=/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=10c8cf53-3090-4e82-b31e-717d3433819d response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"esQ6cub25rT0YpJV1nub8t0Wa7bqBouS\",\"validated\":\"2026-08-25T20:12:37Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3/VsPp6z52Q02QHUEFkp9rtPCE5naybGmn\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.180559] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [6727731.180623] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [6727731.188382] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info duration=7.002458ms duration-ns=7002458 fields.time="2026-08-25T20:12:37Z" method=POST name=ca nonce=OGVQcGxRRXNsa2xueWhwOEU5bGljSXJHanBEaEZJVGI path=/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ae39cc37-4f46-4881-acd2-8bbdefda5b43 response="{\"id\":\"yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:12:37Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:11:37Z\",\"notAfter\":\"2026-11-23T20:12:37Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/p85kfUVm3ndPsPdxWTpAyb6uGUQR6Yw3\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/yxJqKKS5GAQ9GltQkRsBoYG0NBShinjy/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/4bg35RCvlXxBjF3XSAl5knQENSNg87yG\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727731.190407] ca step-ca[203]: time="2026-08-25T20:12:37Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQVkjqozZg1IYbcsMbVY7ObjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjUyMDExMzdaFw0yNjExMjMyMDEyMzdaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABAUZHx61gjPxrSGcQAjoyXeCSGKgDql3Yxlj5x6e56uOzh0K7SPuXEmbUqwCOEzPrGN+4C6emjary85DU36ClxGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUK+yTnkbR3iEMZ79kPF1pPYYJQ+UwHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiEAhJCZdD0RUYiOvJYoYFymjAHVzj1WmjpwqZJ88uzYrW0CIFa0dkx3vO+EVhvdEYeGIw/BNooNhxRRosteGdWFknM4 duration=1.544942ms duration-ns=1544942 fields.time="2026-08-25T20:12:37Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=NHdmOFlZTVNLTm5oMFpFeHcwWXpTaHV1aW5pbjR2Vmg path=/acme/acme/certificate/4bg35RCvlXxBjF3XSAl5knQENSNg87yG protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=49409ea4-0fc2-4f09-bbb8-333720c3ee9a sans="map[dns:[ca.foo]]" serial=114692212026184267999519404386589527662 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-25T20:11:37Z" valid-to="2026-11-23T20:12:37Z" container-test-run-certificates> ca # [6727731.190578] ca acme-order-renew-ca.foo-start[316]: 2026/08/25 20:12:37 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [6727731.194551] ca acme-order-renew-ca.foo-start[304]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6727731.196412] ca acme-order-renew-ca.foo-start[304]: + touch out/acme-success container-test-run-certificates> ca # [6727731.198146] ca acme-order-renew-ca.foo-start[304]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6727731.199384] ca acme-order-renew-ca.foo-start[304]: + touch out/renewed container-test-run-certificates> ca # [6727731.200740] ca acme-order-renew-ca.foo-start[304]: + echo Installing new certificate container-test-run-certificates> ca # [6727731.200740] ca acme-order-renew-ca.foo-start[304]: Installing new certificate container-test-run-certificates> ca # [6727731.200782] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6727731.202262] ca acme-order-renew-ca.foo-start[347]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [6727731.202492] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [6727731.203875] ca acme-order-renew-ca.foo-start[348]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [6727731.204156] ca acme-order-renew-ca.foo-start[304]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [6727731.205370] ca acme-order-renew-ca.foo-start[349]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [6727731.205555] ca acme-order-renew-ca.foo-start[304]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [6727731.206916] ca acme-order-renew-ca.foo-start[304]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [6727731.208942] ca acme-order-renew-ca.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> ca # [6727731.208966] ca acme-order-renew-ca.foo-start[304]: + '[' -d out ']' container-test-run-certificates> ca # [6727731.208966] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6727731.210857] ca acme-order-renew-ca.foo-start[304]: + chown -R acme:nginx out container-test-run-certificates> ca # [6727731.214090] ca acme-order-renew-ca.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> ca # [6727731.214116] ca acme-order-renew-ca.foo-start[304]: + '[' -d certificates ']' container-test-run-certificates> ca # [6727731.214116] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6727731.215464] ca acme-order-renew-ca.foo-start[304]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6727731.217944] ca acme-order-renew-ca.foo-start[304]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6727731.337278] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> ca # [6727731.341372] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6727731.341557] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> ca # [6727732.091457] ca nginx[365]: nginx: the configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf syntax is ok container-test-run-certificates> ca # [6727732.091812] ca nginx[365]: nginx: configuration file /nix/store/rpw8s0qslkrw9ja2wjf8348wp60q8nma-nginx.conf test is successful container-test-run-certificates> ca # [6727732.645279] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [6727732.645865] ca systemd[1]: Startup finished in 6.381s. container-test-run-certificates> ca # [6727732.917164] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 4.91 seconds) container-test-run-certificates> ca # [6727733.477280] ca acme-order-renew-ca.foo-start[380]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [6727733.480119] ca acme-order-renew-ca.foo-start[380]: + set -euo pipefail container-test-run-certificates> ca # [6727733.480197] ca acme-order-renew-ca.foo-start[380]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [6727733.480311] ca acme-order-renew-ca.foo-start[380]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [6727733.481270] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [6727733.481306] ca acme-order-renew-ca.foo-start[380]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [6727733.481856] ca acme-order-renew-ca.foo-start[388]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [6727733.485272] ca acme-order-renew-ca.foo-start[380]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [6727733.485310] ca acme-order-renew-ca.foo-start[380]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [6727733.530731] ca step-ca[203]: time="2026-08-25T20:12:39Z" level=info duration="51.48µs" duration-ns=51480 fields.time="2026-08-25T20:12:39Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4c1f916f-b3fe-4cb7-a925-c7d31fb945d2 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727733.531310] ca acme-order-renew-ca.foo-start[389]: 2026/08/25 20:12:39 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [6727733.531310] ca acme-order-renew-ca.foo-start[389]: 2026/08/25 20:12:39 [INFO] [ca.foo] The certificate expires at 2026-11-23T20:12:37Z, the renewal can be performed in 1439h59m37.415516455s: no renewal. container-test-run-certificates> ca # [6727733.531902] ca acme-order-renew-ca.foo-start[380]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [6727733.533957] ca acme-order-renew-ca.foo-start[380]: + touch out/acme-success container-test-run-certificates> ca # [6727733.535271] ca acme-order-renew-ca.foo-start[380]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [6727733.536592] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates container-test-run-certificates> ca # [6727733.536622] ca acme-order-renew-ca.foo-start[380]: + '[' -d out ']' container-test-run-certificates> ca # [6727733.536622] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [6727733.538200] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx out container-test-run-certificates> ca # [6727733.540762] ca acme-order-renew-ca.foo-start[380]: + for fixpath in out certificates container-test-run-certificates> ca # [6727733.540762] ca acme-order-renew-ca.foo-start[380]: + '[' -d certificates ']' container-test-run-certificates> ca # [6727733.540852] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [6727733.542460] ca acme-order-renew-ca.foo-start[380]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [6727733.545851] ca acme-order-renew-ca.foo-start[380]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [6727733.655365] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [6727733.655583] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [6727736.686236] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6727736.686464] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [6727736.687410] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [6727736.721798] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.79 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:12:35 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:12:35 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 064d82 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6727737.427606] server acme-test.foo-start[314]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6727737.430757] server acme-test.foo-start[314]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [6727737.430757] server acme-test.foo-start[314]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [6727737.446584] server acme-test.foo-start[324]: + cd test.foo container-test-run-certificates> server # [6727737.447074] server acme-test.foo-start[324]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [6727737.448614] server acme-test.foo-start[325]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [6727737.448870] server acme-test.foo-start[324]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [6727737.450494] server acme-test.foo-start[324]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [6727737.450770] server acme-test.foo-start[314]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [6727737.452564] server acme-test.foo-start[314]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [6727737.454225] server acme-test.foo-start[314]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6727737.457250] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [6727737.457250] server acme-test.foo-start[314]: + '[' -d out ']' container-test-run-certificates> server # [6727737.457340] server acme-test.foo-start[314]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6727737.459620] server acme-test.foo-start[314]: + chown -R acme:nginx out container-test-run-certificates> server # [6727737.462151] server acme-test.foo-start[314]: + for fixpath in out certificates container-test-run-certificates> server # [6727737.462223] server acme-test.foo-start[314]: + '[' -d certificates ']' container-test-run-certificates> server # [6727737.466759] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [6727737.469570] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> server # [6727738.296744] server acme-order-renew-test.foo-start[332]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [6727738.300179] server acme-order-renew-test.foo-start[332]: + set -euo pipefail container-test-run-certificates> server # [6727738.300262] server acme-order-renew-test.foo-start[332]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [6727738.300377] server acme-order-renew-test.foo-start[332]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [6727738.301638] server acme-order-renew-test.foo-start[332]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [6727738.350852] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: !!!! HEADS UP !!!! container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: Your account credentials have been saved in your container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: configuration directory at "accounts". container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: configuration directory will also contain private keys container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [6727738.396447] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh container-test-run-certificates> server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [6727738.468578] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [6727738.479756] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [6727738.480164] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [6727738.500866] server acme-order-renew-test.foo-start[340]: 2026/08/25 20:12:44 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [6727738.504979] server acme-order-renew-test.foo-start[332]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [6727738.507036] server acme-order-renew-test.foo-start[332]: + touch out/acme-success container-test-run-certificates> server # [6727738.508700] server acme-order-renew-test.foo-start[332]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6727738.509942] server acme-order-renew-test.foo-start[332]: + touch out/renewed container-test-run-certificates> server # [6727738.511463] server acme-order-renew-test.foo-start[332]: + echo Installing new certificate container-test-run-certificates> server # [6727738.511463] server acme-order-renew-test.foo-start[332]: Installing new certificate container-test-run-certificates> server # [6727738.511463] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [6727738.513398] server acme-order-renew-test.foo-start[372]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [6727738.513794] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [6727738.515385] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [6727738.515695] server acme-order-renew-test.foo-start[332]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [6727738.517119] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [6727738.517431] server acme-order-renew-test.foo-start[332]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [6727738.519200] server acme-order-renew-test.foo-start[332]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [6727738.521767] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [6727738.521767] server acme-order-renew-test.foo-start[332]: + '[' -d out ']' container-test-run-certificates> server # [6727738.521884] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [6727738.523761] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx out container-test-run-certificates> server # [6727738.527028] server acme-order-renew-test.foo-start[332]: + for fixpath in out certificates container-test-run-certificates> server # [6727738.527028] server acme-order-renew-test.foo-start[332]: + '[' -d certificates ']' container-test-run-certificates> server # [6727738.527132] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [6727738.529008] server acme-order-renew-test.foo-start[332]: + chown -R acme:nginx certificates container-test-run-certificates> server # [6727738.532507] server acme-order-renew-test.foo-start[332]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:12:35 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:12:35 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 064d82 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> ca # [6727738.349877] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration="71.761µs" duration-ns=71761 fields.time="2026-08-25T20:12:44Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=bca36da8-f243-4b3e-ae52-dd9a2abf658c response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.388816] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=34.100956ms duration-ns=34100956 fields.time="2026-08-25T20:12:44Z" method=HEAD name=ca nonce=S0wweTBEdDV2VjVvUFVTYndxZzJxcml0WVM2NmM1SlU path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=1b0a2dc1-88db-4f0a-be95-c246b162008d size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.395460] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=4.030456ms duration-ns=4030456 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=SFJtZndza2E2VTAzSURPMHhNWEpTc3g2NHdKNWJ3SUw path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=9540cdf6-ad25-4da6-9112-6cc26c94152a response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/e5HhSvl4Yutwza84keaozJtmKIvV31i0/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.403906] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=5.427476ms duration-ns=5427476 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=cjdmSEhXWmxkUW1Mbm12WEUwNWRXd0F3RkV1WHF6T3Q path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=4f15f238-49fa-4026-880a-574356e0f7ba response="{\"id\":\"Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:12:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:11:44Z\",\"notAfter\":\"2026-11-23T20:12:44Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh\"],\"finalize\":\"https://ca.foo/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.467697] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=4.468382ms duration-ns=4468382 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=cFBnYTlRd1VIZXNkU1FEY3ZoZ1hmWE9YRVJTblVPbW0 path=/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh protocol=HTTP/1.1 referer= remote-address="::1" request-id=935589a3-9974-4a00-8fa1-76bc7b277ce2 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/RHB8PPDQlpzUtTvXGuPbY6rrT4rIvWB9\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/KKV2e3EuBRYfasLfF75bcq24JmXeyzLJ\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:12:44Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.479059] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=6.848855ms duration-ns=6848855 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=R010aHd2SmhhTmc3MWVyb09kRVMzUXdoenZLRzgzUGU path=/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=a40f5555-8962-477e-8152-da925082c086 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"vFQ1Y3UeLUthpvbWBpdfa75hfY069jsm\",\"validated\":\"2026-08-25T20:12:44Z\",\"url\":\"https://ca.foo/acme/acme/challenge/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh/4exjjeKvaLsSm6wNDAU05EjYwbRcB6Yh\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.492578] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info duration=9.383211ms duration-ns=9383211 fields.time="2026-08-25T20:12:44Z" method=POST name=ca nonce=Snc5TnFnQWcxQmtDTjBRcVhyOFVJZ0lNQTBLTWszR0g path=/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=a3d1a7b3-f3c3-4c01-b082-e8f06dd7cc28 response="{\"id\":\"Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:12:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:11:44Z\",\"notAfter\":\"2026-11-23T20:12:44Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/ipffwDJwSGyQjEIc3DOt7T4K5Hs1Afqh\"],\"finalize\":\"https://ca.foo/acme/acme/order/Gc3xmhN9kDJL2ZKjr2iKoL1DRYObTmbH/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/ASUzr58lcz0NgoCQzTJjdFvJaUob61hH\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= container-test-run-certificates> ca # [6727738.500333] ca step-ca[203]: time="2026-08-25T20:12:44Z" level=info certificate="MIIB1zCCAX6gAwIBAgIRAOs7E39U6X19oLrlQiJ50N0wCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI1MjAxMTQ0WhcNMjYxMTIzMjAxMjQ0WjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABN+KlnUhCUOXLgcLIZTh2HU0lLU2kD6jay0b8PJuc+KuHL6QagorBEUrsr0ssPUNEbcDIVR8O/681FAgkyyW4NejgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUc3PxjjHihkT85kpjLWv8s28pdeswHwYDVR0jBBgwFoAUBhLd2fH1XPFp+3X9Op4Cu9r3zY0wEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0cAMEQCIHQAVdeluA6nxG/J9hDmcaQPpDbF9ugeKYedcptalSlRAiAXKmUiEOv+CVCEXCZPBLfHtOKfcOpeFL0purmvIX5QzQ==" duration=3.641091ms duration-ns=3641091 fields.time="2026-08-25T20:12:44Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=bEMxUVFjS0J1d1EzcW01bDQzNHRyWUdFbFlRT21wOTk path=/acme/acme/certificate/ASUzr58lcz0NgoCQzTJjdFvJaUob61hH protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=dd9759da-89cf-4622-bea3-d8207b0d8fab sans="map[dns:[test.foo]]" serial=312675319978146906809985271581040562397 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-25T20:11:44Z" valid-to="2026-11-23T20:12:44Z" container-test-run-certificates> server # [6727738.647136] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [6727738.651171] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [6727738.651399] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1011 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [112 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:12:35 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:12:35 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 064d82 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [6727739.383840] server nginx[390]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok container-test-run-certificates> server # [6727739.384523] server nginx[390]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful container-test-run-certificates> server # [6727739.970319] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [930 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [79 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:11:44 2026 GMT container-test-run-certificates> * expire date: Nov 23 20:12:44 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 34860 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 697 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.19 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> eb:3b:13:7f:54:e9:7d:7d:a0:ba:e5:42:22:79:d0:dd container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 25 20:11:44 2026 GMT container-test-run-certificates> Not After : Nov 23 20:12:44 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:df:8a:96:75:21:09:43:97:2e:07:0b:21:94:e1: container-test-run-certificates> d8:75:34:94:b5:36:90:3e:a3:6b:2d:1b:f0:f2:6e: container-test-run-certificates> 73:e2:ae:1c:be:90:6a:0a:2b:04:45:2b:b2:bd:2c: container-test-run-certificates> b0:f5:0d:11:b7:03:21:54:7c:3b:fe:bc:d4:50:20: container-test-run-certificates> 93:2c:96:e0:d7 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> 73:73:F1:8E:31:E2:86:44:FC:E6:4A:63:2D:6B:FC:B3:6F:29:75:EB container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 06:12:DD:D9:F1:F5:5C:F1:69:FB:75:FD:3A:9E:02:BB:DA:F7:CD:8D container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:44:02:20:74:00:55:d7:a5:b8:0e:a7:c4:6f:c9:f6:10:e6: container-test-run-certificates> 71:a4:0f:a4:36:c5:f6:e8:1e:29:87:9d:72:9b:5a:95:29:51: container-test-run-certificates> 02:20:17:2a:65:22:10:eb:fe:09:50:84:5c:26:4f:04:b7:c7: container-test-run-certificates> b4:e2:9f:70:ea:5e:14:bd:29:ba:b9:af:21:7e:50:cd container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.05 seconds) container-test-run-certificates> (finished: run the VM test script, in 14.95 seconds) container-test-run-certificates> test script finished in 48.65s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.54 seconds) post-build step Upload to niks3: ok time=2026-08-25T20:13:21.379Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-25T20:13:22.454Z level=INFO msg="Uploading 1 narinfos" time=2026-08-25T20:13:22.691Z level=INFO msg="Upload complete. (1.362s)"