these 85 derivations will be built: /nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv /nix/store/kqdmgkabks3v2s561v989f8fhi0fxvj6-nss-cacert-3.126.drv /nix/store/g8v9839mxncw81k5zydczinyvynib2hq-unit-nix-daemon.service.drv /nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv /nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv /nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv /nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv /nix/store/0yvb13i3nkmrvn5p5ljxh62w5b2fxg1s-system-units.drv /nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv /nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv /nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv /nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv /nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv /nix/store/01dajcn8jwxrl4cpb1xlx1nqhf8hh8hq-etc.drv /nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv /nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv /nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv /nix/store/9ayv2pgmki814qmdnv46rcr8a0pv6a0r-ca.json.drv /nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv /nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv /nix/store/hzl9dfgz8y3570p9rh4nvqynlfn4kyzj-nginx.conf.drv /nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv /nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv /nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv /nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv /nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv /nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv /nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv /nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv /nix/store/kp55vv7mfi1dlhb393nncly0wzllbbn0-unit-script-nginx-pre-start.drv /nix/store/2l5v49h6c1wy78dprx7a5r9q4xrik766-unit-nginx.service.drv /nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv /nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv /nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv /nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv /nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv /nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv /nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv /nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv /nix/store/zjb83x9v1vim9sqf6p6n3r5cihs9svv6-X-Restart-Triggers-step-ca.drv /nix/store/skcf5bdf43r9swdlvmy7zc1nw0pk2wij-unit-step-ca.service.drv /nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv /nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv /nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv /nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv /nix/store/s0gxjfil8k0y1sd7wgvlsld138phspx0-system-units.drv /nix/store/f6zzascblxy2rr55vwbaqd8038v1kxpj-etc.drv /nix/store/0qggrrwasqkclar8nvhw4rdbl4s7dar6-activate.drv /nix/store/25ldlkga9sa0pil8x1ajjj75fdarfzby-activate.drv /nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv /nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv /nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv /nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv /nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv /nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv /nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv /nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv /nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv /nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv /nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv /nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv /nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv /nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv /nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv /nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv /nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv /nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv /nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv /nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv /nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv /nix/store/vq5yc1d0iyp01fj6fn3kw50xi2d525ka-system-units.drv /nix/store/ivk76rfnpkchky8xniq7y6cj9q4cy7d9-etc.drv /nix/store/7l309y4yckkx76bqw5ny4615cyxrgmds-activate.drv /nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv /nix/store/4d9j54ga37v0dyg31pm93w0b0scfaxja-nixos-system-server-test.drv /nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv /nix/store/iwz96d4415k12hymsrkx7g6lnv5v4m03-nixos-system-ca-test.drv /nix/store/dgspkk65b3r5rhpnhb36ljd6f2xivsvm-run-ca-nspawn.drv /nix/store/gfc7lawjcy1s7jqnlyia76icv0mhw85f-run-server-nspawn.drv /nix/store/z3kh1zi97lrv9l789qm4blsjnjn8s51n-nixos-system-client-test.drv /nix/store/iibz7zd519faa3ypw3384943ki4aplvi-run-client-nspawn.drv /nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv /nix/store/7g6whzd6ryzlpj5fri0r8j4kpm01jvj2-driverConfiguration.json.drv /nix/store/7vig0mh8kw9b0sri9ba47xx0pngvsihi-nixos-test-driver-certificates.drv /nix/store/5ryfvgrns36bwk1bmnr4j0jk92mrachk-container-test-run-certificates.drv this path will be fetched (21.7 MiB download, 71.4 MiB unpacked): /nix/store/dlpj6bc50h35a0glvslc6vnrq4xgp93j-step-ca-0.30.2 building '/nix/store/qq6ms440xlly2q027kys1f9j2bh6yy0i-test-script.drv' building '/nix/store/53hnawxj96bx7praki7i4v57slvk3nl8-system-path.drv' building '/nix/store/i9dp3pxhd8i3wwisb7p3hyb99pazmsf8-system-path.drv' building '/nix/store/nmwkd9rbaz11m00amisn6fc8kqzzmf95-system-path.drv' building '/nix/store/fwdgn1p9i71a2z91qy80lx5m46vnj148-etc-hostname.drv' building '/nix/store/hzl9dfgz8y3570p9rh4nvqynlfn4kyzj-nginx.conf.drv' building '/nix/store/jrln6ldic7lf2wk4m78mymqw3g9ikjl8-nginx.conf.drv' building '/nix/store/lylvrr8cbsf0k9h5jlbg5h2n5bhljsq8-extra-hosts.drv' building '/nix/store/qfsrvg58wd78nr87mq8fs9vjav0bx7h7-string-hosts.drv' building '/nix/store/7irk03vanc5xlvca6i17vaq7j2pk794x-unit-acme-account-2c44cb477b4787b2cf13.target.drv' nginx.conf> structuredAttrs is enabled nginx.conf> structuredAttrs is enabled system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment system-path> structuredAttrs is enabled system-path> created 1723 symlinks in user environment unit-acme-account-2c44cb477b4787b2cf13.target> structuredAttrs is enabled building '/nix/store/hxjsdq5h221qjz2yv66s48292zr5572v-acme-setup-privileged.drv' building '/nix/store/vnvlniy3jw707y5758y6vkgmxgja643k-acme-setup-privileged.drv' building '/nix/store/bfnbi0ivq2qlkdya7mfcyrgal3l75f72-unit-acme-renew-test.foo.timer.drv' building '/nix/store/4sfz05hhn9cnswrfbqhr9r41zizqd315-unit-script-acme-ca.foo-start.drv' unit-acme-renew-test.foo.timer> structuredAttrs is enabled building '/nix/store/s7iyb8q0dvr6dgpffrcyslvjnwlzkh7x-acme-postrun.drv' building '/nix/store/c6028b7d6mzlxrwdh9hvwz3fnc81n86b-hosts.drv' building '/nix/store/x7d0nslv3qznin20gmhr0c5qnwnavwp2-unit-acme-account-d22a46d9459bf683a338.target.drv' building '/nix/store/d2avhjb4s4fnivfvc5m03l7w0paydb6b-unit-acme-renew-ca.foo.timer.drv' building '/nix/store/jxb6x753fqh9qsdfr6kd1dd06snj68sb-unit-script-acme-test.foo-start.drv' nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> nginx.conf> nginx.conf> ==================== Results =================== nginx.conf> No issues found. nginx.conf> nginx.conf> ==================== Summary =================== nginx.conf> Total issues: nginx.conf> Unspecified: 0 nginx.conf> Low: 0 nginx.conf> Medium: 0 nginx.conf> High: 0 nginx.conf> unit-acme-account-d22a46d9459bf683a338.target> structuredAttrs is enabled unit-acme-renew-ca.foo.timer> structuredAttrs is enabled building '/nix/store/ab41sxhfkmh965c1b96j4zmzrjccdw2x-X-Restart-Triggers-acme-ca.foo.drv' building '/nix/store/33ysc61mi11kshcq09hc1x9hpw72sbi0-X-Restart-Triggers-acme-test.foo.drv' building '/nix/store/i24rhm6bgwms3ib5b4b2cqgl5sxm2n6c-hosts.drv' building '/nix/store/p5f8qdav49r8y6hj0x3nbp79b23vrx5j-hosts.drv' building '/nix/store/mbmq2fnjrl6rjd4f5chjqn21h72n6g51-unit-script-acme-order-renew-ca.foo-start.drv' building '/nix/store/xk1djxalc44cx697ca7p2vaj698dpczg-unit-script-acme-order-renew-test.foo-start.drv' building '/nix/store/kqdmgkabks3v2s561v989f8fhi0fxvj6-nss-cacert-3.126.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/3cdmcd9isw2rag9rhnb76hi2wgz276m7-acme-postrun.drv' building '/nix/store/9ayv2pgmki814qmdnv46rcr8a0pv6a0r-ca.json.drv' building '/nix/store/7rfsbl4zr4jzakgvvbz6aqcgka7wmk3j-dbus-1.drv' building '/nix/store/pg4s5a7kkvw6djddjxlfmcsn2ya7laab-dbus-1.drv' building '/nix/store/x3i9qpwy7sx46p4fzrsrjc4pjkh6idgf-dbus-1.drv' building '/nix/store/c32hn00sk7i5n3iwl5dwlg87kqv8hgm5-unit-acme-setup.service.drv' building '/nix/store/iw0qimh0h18z57rx7946jnvg2z4y6wmh-unit-acme-setup.service.drv' building '/nix/store/qxpp164gsfgzyas2kmd8wg3qyakqzavi-unit-nginx-config-reload.service.drv' building '/nix/store/0dazh70qwhpgsvnf5ws7zfdbrmzlhg6l-users-groups.json.drv' building '/nix/store/9s6z42mqv300c0zqsy258gi9lpdmq6my-users-groups.json.drv' ca.json> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-acme-setup.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled building '/nix/store/yj1akmznrbkvc723n3iypygm9ahzqsak-unit-acme-ca.foo.service.drv' building '/nix/store/cg3qqfszqzzbmw4dm4jxz0c07i07blyy-unit-acme-order-renew-test.foo.service.drv' building '/nix/store/300lzbbn313vjl4xwmbp5fij40zhv6w6-unit-acme-test.foo.service.drv' building '/nix/store/3sx1ynm5g6cjrl5y260pg0ppp0v4d4wa-unit-script-nginx-pre-start.drv' building '/nix/store/kp55vv7mfi1dlhb393nncly0wzllbbn0-unit-script-nginx-pre-start.drv' building '/nix/store/ivblry47xynlrmn3f7xplcdykhz54kb5-user-generators.drv' unit-acme-ca.foo.service> structuredAttrs is enabled unit-acme-order-renew-test.foo.service> structuredAttrs is enabled unit-acme-test.foo.service> structuredAttrs is enabled building '/nix/store/frqjymwgfg7lwzcla6s2c5d36jj3zsnn-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/kjmkg96s7i10bkdcw918a5qfjz4yscmd-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/yl0v25cmi7rhvhlfavl9h9ix619h8xq4-X-Restart-Triggers-dbus-broker.drv' building '/nix/store/p665x5g4cf75qyf0riiwhgjzp3qzi5c6-dry-activate.drv' building '/nix/store/i30rzaj5iwfdzlrlxm0rhlar4xp6k7n7-system-generators.drv' building '/nix/store/hd50zk417rykvdbbfgngqwkgwfp7m6d9-system-shutdown.drv' building '/nix/store/n132wcg6ip1grxd37ychp1006wkzhcza-unit-acme-order-renew-ca.foo.service.drv' unit-acme-order-renew-ca.foo.service> structuredAttrs is enabled building '/nix/store/zjb83x9v1vim9sqf6p6n3r5cihs9svv6-X-Restart-Triggers-step-ca.drv' building '/nix/store/fw9zzn8p2819xmxzbwjbp5b5nng9h5sj-unit-nginx-config-reload.service.drv' building '/nix/store/2l5v49h6c1wy78dprx7a5r9q4xrik766-unit-nginx.service.drv' building '/nix/store/n0i5fnzbsb0zkkiw16301r4q69pzkdmc-unit-nginx.service.drv' building '/nix/store/2b20aiq8sa50pk3pm5zdzywvmx360iv9-unit-dbus-broker.service.drv' building '/nix/store/g3pbjwbabwkr9akggrlfgxyx1fyfz5lf-unit-dbus-broker.service.drv' building '/nix/store/mjcag0kvnj4h286hg3rvrgwgz6kwa4w9-unit-dbus-broker.service.drv' building '/nix/store/n5lgd8kjn863127n3hw4a4m51iiqdncz-unit-dbus-broker.service.drv' building '/nix/store/wbjwlajk0a2j6c39hgmd5g319ljv0wn9-unit-dbus-broker.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled unit-nginx-config-reload.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled unit-nginx.service> structuredAttrs is enabled building '/nix/store/yr14jpn42fdik55sz046ycmpk4myrss7-unit-dbus-broker.service.drv' building '/nix/store/skcf5bdf43r9swdlvmy7zc1nw0pk2wij-unit-step-ca.service.drv' unit-dbus-broker.service> structuredAttrs is enabled unit-dbus-broker.service> structuredAttrs is enabled building '/nix/store/4npi5hfjyzgqr0fgxwpcaif1ll5qvl6l-user-units.drv' building '/nix/store/qgciair8g6hxi7i3lispy9i41fycaqgq-user-units.drv' unit-step-ca.service> structuredAttrs is enabled building '/nix/store/k3wap5inj84acy6l6jh9112p23whxx0x-user-units.drv' building '/nix/store/kqdmgkabks3v2s561v989f8fhi0fxvj6-nss-cacert-3.126.drv' nss-cacert-3.126> Running phase: unpackPhase nss-cacert-3.126> Running phase: patchPhase nss-cacert-3.126> Running phase: updateAutotoolsGnuConfigScriptsPhase nss-cacert-3.126> Running phase: configurePhase nss-cacert-3.126> no configure script, doing nothing nss-cacert-3.126> Running phase: buildPhase building '/nix/store/zgn8l3zykpfi77634937kwqpd6ajsh3z-vars-check-certificates.drv' vars-check-certificates> Running vars check using Nix-based executor... vars-check-certificates> ✓ All vars checks completed successfully nss-cacert-3.126> Running phase: installPhase nss-cacert-3.126> Running phase: fixupPhase nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/6mmfc96ysxj29y58mwnrknzxqpl4i90i-nss-cacert-3.126 nss-cacert-3.126> checking for references to /build/ in /nix/store/6mmfc96ysxj29y58mwnrknzxqpl4i90i-nss-cacert-3.126... nss-cacert-3.126> patching script interpreter paths in /nix/store/6mmfc96ysxj29y58mwnrknzxqpl4i90i-nss-cacert-3.126 nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/j48snrfaz90y3vfb00ki136sqz5986m9-nss-cacert-3.126-unbundled nss-cacert-3.126> checking for references to /build/ in /nix/store/j48snrfaz90y3vfb00ki136sqz5986m9-nss-cacert-3.126-unbundled... nss-cacert-3.126> patching script interpreter paths in /nix/store/j48snrfaz90y3vfb00ki136sqz5986m9-nss-cacert-3.126-unbundled nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/sq0zd970k2jvv3mz9bn4gpfmk7lf4d9v-nss-cacert-3.126-p11kit nss-cacert-3.126> checking for references to /build/ in /nix/store/sq0zd970k2jvv3mz9bn4gpfmk7lf4d9v-nss-cacert-3.126-p11kit... nss-cacert-3.126> patching script interpreter paths in /nix/store/sq0zd970k2jvv3mz9bn4gpfmk7lf4d9v-nss-cacert-3.126-p11kit nss-cacert-3.126> shrinking RPATHs of ELF executables and libraries in /nix/store/y4sg3fnp4diyfynby7kgvh1h2afxls8l-nss-cacert-3.126-hashed nss-cacert-3.126> checking for references to /build/ in /nix/store/y4sg3fnp4diyfynby7kgvh1h2afxls8l-nss-cacert-3.126-hashed... nss-cacert-3.126> patching script interpreter paths in /nix/store/y4sg3fnp4diyfynby7kgvh1h2afxls8l-nss-cacert-3.126-hashed building '/nix/store/g8v9839mxncw81k5zydczinyvynib2hq-unit-nix-daemon.service.drv' unit-nix-daemon.service> structuredAttrs is enabled building '/nix/store/0yvb13i3nkmrvn5p5ljxh62w5b2fxg1s-system-units.drv' building '/nix/store/s0gxjfil8k0y1sd7wgvlsld138phspx0-system-units.drv' building '/nix/store/vq5yc1d0iyp01fj6fn3kw50xi2d525ka-system-units.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/01dajcn8jwxrl4cpb1xlx1nqhf8hh8hq-etc.drv' building '/nix/store/f6zzascblxy2rr55vwbaqd8038v1kxpj-etc.drv' building '/nix/store/ivk76rfnpkchky8xniq7y6cj9q4cy7d9-etc.drv' building '/nix/store/25ldlkga9sa0pil8x1ajjj75fdarfzby-activate.drv' building '/nix/store/z3kh1zi97lrv9l789qm4blsjnjn8s51n-nixos-system-client-test.drv' nixos-system-client-test> structuredAttrs is enabled building '/nix/store/7l309y4yckkx76bqw5ny4615cyxrgmds-activate.drv' building '/nix/store/iibz7zd519faa3ypw3384943ki4aplvi-run-client-nspawn.drv' building '/nix/store/4d9j54ga37v0dyg31pm93w0b0scfaxja-nixos-system-server-test.drv' nixos-system-server-test> structuredAttrs is enabled building '/nix/store/gfc7lawjcy1s7jqnlyia76icv0mhw85f-run-server-nspawn.drv' building '/nix/store/002fkkc4qws591jghypmy48812j723yl-decrypt-age-secrets.drv' building '/nix/store/0qggrrwasqkclar8nvhw4rdbl4s7dar6-activate.drv' building '/nix/store/varyvj2bd1w0xikmym53l2lbay5pcz6z-dry-activate.drv' building '/nix/store/iwz96d4415k12hymsrkx7g6lnv5v4m03-nixos-system-ca-test.drv' nixos-system-ca-test> structuredAttrs is enabled building '/nix/store/dgspkk65b3r5rhpnhb36ljd6f2xivsvm-run-ca-nspawn.drv' building '/nix/store/7g6whzd6ryzlpj5fri0r8j4kpm01jvj2-driverConfiguration.json.drv' driverConfiguration.json> structuredAttrs is enabled building '/nix/store/7vig0mh8kw9b0sri9ba47xx0pngvsihi-nixos-test-driver-certificates.drv' nixos-test-driver-certificates> Running type check (enable/disable: config.skipTypeCheck) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipTypeCheck nixos-test-driver-certificates> All checks passed! nixos-test-driver-certificates> Linting test script (enable/disable: config.skipLint) nixos-test-driver-certificates> See https://nixos.org/manual/nixos/stable/#test-opt-skipLint nixos-test-driver-certificates> All checks passed! building '/nix/store/5ryfvgrns36bwk1bmnr4j0jk92mrachk-container-test-run-certificates.drv' on 'ssh-ng://builder@build-x86-01.clan.lol' building '/nix/store/5ryfvgrns36bwk1bmnr4j0jk92mrachk-container-test-run-certificates.drv' container-test-run-certificates> Machine state will be reset. To keep it, pass --keep-machine-state container-test-run-certificates> start all VLans container-test-run-certificates> (finished: start all VLans, in 0.00 seconds) container-test-run-certificates> container-test-run-certificates> Test will time out and terminate in 3600.0 seconds container-test-run-certificates> run the VM test script container-test-run-certificates> additionally exposed symbols: container-test-run-certificates> ca, client, server, container-test-run-certificates> vlan1, container-test-run-certificates> start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh container-test-run-certificates> start all VMs container-test-run-certificates> client: systemd-nspawn running (pid 54) container-test-run-certificates> ca: systemd-nspawn running (pid 53) container-test-run-certificates> client: Waiting for journal at /build/vm-state-client/var/log/journal... container-test-run-certificates> server: systemd-nspawn running (pid 55) container-test-run-certificates> ca: Waiting for journal at /build/vm-state-ca/var/log/journal... container-test-run-certificates> server: Waiting for journal at /build/vm-state-server/var/log/journal... container-test-run-certificates> (finished: start all VMs, in 0.00 seconds) container-test-run-certificates> nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE container-test-run-certificates> nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container server on /build/vm-state-server. container-test-run-certificates> ░ Spawning container ca on /build/vm-state-ca. container-test-run-certificates> Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file. container-test-run-certificates> ░ Spawning container client on /build/vm-state-client. container-test-run-certificates> ca # [7466924.140451] ca systemd-journald[78]: Journal started container-test-run-certificates> client # [7466924.139621] client systemd-journald[69]: Journal started container-test-run-certificates> ca # [7466924.140480] ca systemd-journald[78]: Runtime Journal (/run/log/journal/fe31bb18f2fd4e5ca13f763e2b1438a6) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> client # [7466924.139655] client systemd-journald[69]: Runtime Journal (/run/log/journal/e1e82b3f0a67417badd499b8adf229d3) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [7466924.145451] ca systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> client # [7466924.144187] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7466924.151457] ca systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7466924.149588] client systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> server # [7466924.145907] server systemd-journald[69]: Journal started container-test-run-certificates> client # [7466924.149998] client systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7466924.145934] server systemd-journald[69]: Runtime Journal (/run/log/journal/6d593de3fd634580a09730f66e6fe1c1) is 8M, max 3.7G, 3.7G free. container-test-run-certificates> ca # [7466924.151853] ca systemd[1]: Starting Network Name Resolution... container-test-run-certificates> server # [7466924.146824] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully. container-test-run-certificates> ca # [7466924.152170] ca systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> client # [7466924.150378] client systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> ca # [7466924.157639] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/fe31bb18f2fd4e5ca13f763e2b1438a6 is 1.534ms for 6 entries. container-test-run-certificates> client # [7466924.155365] client systemd-journald[69]: Time spent on flushing to /var/log/journal/e1e82b3f0a67417badd499b8adf229d3 is 1.337ms for 6 entries. container-test-run-certificates> server # [7466924.152286] server systemd[1]: Starting Flush Journal to Persistent Storage... container-test-run-certificates> client # [7466924.155365] client systemd-journald[69]: System Journal (/var/log/journal/e1e82b3f0a67417badd499b8adf229d3) is 8M, max 4G, 3.9G free. container-test-run-certificates> server # [7466924.152635] server systemd[1]: Starting Network Name Resolution... container-test-run-certificates> client # [7466924.163716] client systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7466924.157639] ca systemd-journald[78]: System Journal (/var/log/journal/fe31bb18f2fd4e5ca13f763e2b1438a6) is 8M, max 4G, 3.9G free. container-test-run-certificates> client # [7466924.164330] client systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> server # [7466924.152955] server systemd[1]: Starting Create Static Device Nodes in /dev... container-test-run-certificates> server # [7466924.158355] server systemd-journald[69]: Time spent on flushing to /var/log/journal/6d593de3fd634580a09730f66e6fe1c1 is 1.353ms for 6 entries. container-test-run-certificates> ca # [7466924.163718] ca systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> server # [7466924.158355] server systemd-journald[69]: System Journal (/var/log/journal/6d593de3fd634580a09730f66e6fe1c1) is 8M, max 4G, 3.9G free. container-test-run-certificates> ca # [7466924.164332] ca systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> client # [7466924.164704] client systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7466924.164896] ca systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> server # [7466924.170554] server systemd[1]: Finished Flush Journal to Persistent Storage. container-test-run-certificates> ca # [7466924.164947] ca systemd[1]: Reached target Local File Systems. container-test-run-certificates> client # [7466924.164760] client systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7466924.165379] ca systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> client # [7466924.165286] client systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> server # [7466924.170765] server systemd[1]: Finished Create Static Device Nodes in /dev. container-test-run-certificates> ca # [7466924.165408] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7466924.165315] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7466924.171580] server systemd[1]: Reached target Preparation for Local File Systems. container-test-run-certificates> ca # [7466924.165826] ca systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> client # [7466924.165831] client systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7466924.166252] ca systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> server # [7466924.171631] server systemd[1]: Reached target Local File Systems. container-test-run-certificates> ca # [7466924.166271] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> server # [7466924.172095] server systemd[1]: Listening on Boot Loader Control Service Socket. container-test-run-certificates> ca # [7466924.188584] ca systemd-tmpfiles[126]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7466924.172122] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7466924.166225] client systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> client # [7466924.166245] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> ca # [7466924.188790] ca systemd-tmpfiles[126]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> client # [7466924.188033] client systemd-tmpfiles[117]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> server # [7466924.172557] server systemd[1]: Starting Save Transient machine-id to Disk... container-test-run-certificates> ca # [7466924.188926] ca systemd-tmpfiles[126]: fchmod() of /var/log/journal/fe31bb18f2fd4e5ca13f763e2b1438a6 failed: Operation not permitted container-test-run-certificates> server # [7466924.172938] server systemd[1]: Starting Create System Files and Directories... container-test-run-certificates> ca # [7466924.189133] ca systemd-tmpfiles[126]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7466924.172957] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys container-test-run-certificates> client # [7466924.188224] client systemd-tmpfiles[117]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> server # [7466924.188258] server systemd-tmpfiles[117]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted container-test-run-certificates> ca # [7466924.190701] ca systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> server # [7466924.188435] server systemd-tmpfiles[117]: fchmod() of /var/log/journal failed: Operation not permitted container-test-run-certificates> ca # [7466924.191671] ca systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> server # [7466924.188551] server systemd-tmpfiles[117]: fchmod() of /var/log/journal/6d593de3fd634580a09730f66e6fe1c1 failed: Operation not permitted container-test-run-certificates> ca # [7466924.192096] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7466924.188723] server systemd-tmpfiles[117]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7466924.189461] server systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> client # [7466924.188345] client systemd-tmpfiles[117]: fchmod() of /var/log/journal/e1e82b3f0a67417badd499b8adf229d3 failed: Operation not permitted container-test-run-certificates> server # [7466924.190501] server systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> client # [7466924.188498] client systemd-tmpfiles[117]: fchmod() of /run/log/journal failed: Operation not permitted container-test-run-certificates> server # [7466924.190952] server systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> client # [7466924.189652] client systemd[1]: Finished Create System Files and Directories. container-test-run-certificates> ca # [7466924.200097] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> client # [7466924.190554] client systemd[1]: Starting Rebuild Journal Catalog... container-test-run-certificates> ca # [7466924.207127] ca systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7466924.199631] server systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> ca # [7466924.207720] ca systemd[1]: Starting Update is Completed... container-test-run-certificates> server # [7466924.206252] server systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> ca # [7466924.226589] ca systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7466924.206897] server systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7466924.241231] ca systemd[1]: Finished Firewall. container-test-run-certificates> server # [7466924.226615] server systemd[1]: Finished Update is Completed. container-test-run-certificates> server # [7466924.241873] server systemd[1]: Finished Firewall. container-test-run-certificates> client # [7466924.191101] client systemd[1]: Starting Record System Boot/Shutdown in UTMP... container-test-run-certificates> server # [7466924.241983] server systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7466924.199721] client systemd[1]: Finished Record System Boot/Shutdown in UTMP. container-test-run-certificates> server # [7466924.242146] server systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> ca # [7466924.241303] ca systemd[1]: Reached target Preparation for Network. container-test-run-certificates> ca # [7466924.241462] ca systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7466924.207031] client systemd[1]: Finished Rebuild Journal Catalog. container-test-run-certificates> server # [7466924.243033] server systemd[1]: Starting Network Management... container-test-run-certificates> client # [7466924.207902] client systemd[1]: Starting Update is Completed... container-test-run-certificates> ca # [7466924.242042] ca systemd[1]: Starting Network Management... container-test-run-certificates> client # [7466924.226893] client systemd[1]: Finished Update is Completed. container-test-run-certificates> client # [7466924.238665] client systemd[1]: Finished Firewall. container-test-run-certificates> client # [7466924.238780] client systemd[1]: Reached target Preparation for Network. container-test-run-certificates> client # [7466924.238943] client systemd[1]: Listening on Network Management Resolve Hook Socket. container-test-run-certificates> client # [7466924.239609] client systemd[1]: Starting Network Management... container-test-run-certificates> ca # [7466924.545217] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7466924.545324] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> ca # [7466924.551066] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7466924.551377] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> ca # [7466924.551480] ca systemd-networkd[195]: lo: Link UP container-test-run-certificates> ca # [7466924.551483] ca systemd-networkd[195]: lo: Gained carrier container-test-run-certificates> ca # [7466924.551672] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> ca # [7466924.552032] ca systemd[1]: Started Network Management. container-test-run-certificates> ca # [7466924.552099] ca systemd-networkd[195]: eth1: Link UP container-test-run-certificates> ca # [7466924.552299] ca systemd-networkd[195]: eth1: Gained carrier container-test-run-certificates> ca # [7466924.553036] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> ca # [7466924.574562] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> ca # [7466924.753557] ca systemd-resolved[107]: Positive Trust Anchors: container-test-run-certificates> ca # [7466924.753567] ca systemd-resolved[107]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> ca # [7466924.753569] ca systemd-resolved[107]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> ca # [7466924.753587] ca systemd-resolved[107]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> ca # [7466924.764739] ca systemd-resolved[107]: Using system hostname 'ca'. container-test-run-certificates> ca # [7466924.765759] ca systemd[1]: Started Network Name Resolution. container-test-run-certificates> ca # [7466924.765829] ca systemd[1]: Reached target Network. container-test-run-certificates> ca # [7466924.765875] ca systemd[1]: Reached target Network is Online. container-test-run-certificates> ca # [7466924.765907] ca systemd[1]: Reached target System Initialization. container-test-run-certificates> ca # [7466924.766105] ca systemd[1]: Started Renew ACME Certificate for ca.foo. container-test-run-certificates> ca # [7466924.766126] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> ca # [7466924.766143] ca systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> ca # [7466924.766159] ca systemd[1]: Reached target Timer Units. container-test-run-certificates> ca # [7466924.766262] ca systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> ca # [7466924.766346] ca systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> ca # [7466924.766440] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> ca # [7466924.766455] ca systemd[1]: Reached target Socket Units. container-test-run-certificates> ca # [7466924.766482] ca systemd[1]: Reached target Basic System. container-test-run-certificates> ca # [7466924.767579] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> ca # [7466924.768032] ca systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> ca # [7466924.768057] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem container-test-run-certificates> ca # [7466924.768964] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> ca # [7466924.769579] ca systemd[1]: Starting step-ca service... container-test-run-certificates> ca # [7466924.770446] ca systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7466924.560031] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7466924.560131] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> server # [7466924.567147] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7466924.567311] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> server # [7466924.567399] server systemd-networkd[186]: lo: Link UP container-test-run-certificates> server # [7466924.567403] server systemd-networkd[186]: lo: Gained carrier container-test-run-certificates> server # [7466924.567568] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> server # [7466924.567872] server systemd[1]: Started Network Management. container-test-run-certificates> server # [7466924.568161] server systemd-networkd[186]: eth1: Link UP container-test-run-certificates> server # [7466924.568334] server systemd-networkd[186]: eth1: Gained carrier container-test-run-certificates> server # [7466924.568831] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd... container-test-run-certificates> server # [7466924.584570] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd. container-test-run-certificates> server # [7466924.776282] server systemd-resolved[93]: Positive Trust Anchors: container-test-run-certificates> server # [7466924.776290] server systemd-resolved[93]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> server # [7466924.776293] server systemd-resolved[93]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> server # [7466924.776310] server systemd-resolved[93]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> server # [7466924.787260] server systemd-resolved[93]: Using system hostname 'server'. container-test-run-certificates> server # [7466924.788175] server systemd[1]: Started Network Name Resolution. container-test-run-certificates> server # [7466924.788227] server systemd[1]: Reached target Network. container-test-run-certificates> server # [7466924.788254] server systemd[1]: Reached target Network is Online. container-test-run-certificates> server # [7466924.788280] server systemd[1]: Reached target System Initialization. container-test-run-certificates> server # [7466924.788416] server systemd[1]: Started Renew ACME Certificate for test.foo. container-test-run-certificates> server # [7466924.788437] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> server # [7466924.788451] server systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> server # [7466924.788462] server systemd[1]: Reached target Timer Units. container-test-run-certificates> server # [7466924.788529] server systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> server # [7466924.788591] server systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> server # [7466924.788667] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> server # [7466924.788677] server systemd[1]: Reached target Socket Units. container-test-run-certificates> server # [7466924.788699] server systemd[1]: Reached target Basic System. container-test-run-certificates> server # [7466924.792257] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure... container-test-run-certificates> server # [7466924.793024] server systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> server # [7466924.793051] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem container-test-run-certificates> server # [7466924.793759] server systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> server # [7466924.794877] server systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> server # [7466924.806131] server systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> server # [7466924.883127] server acme-setup-privileged[191]: + set -euo pipefail container-test-run-certificates> server # [7466924.883127] server acme-setup-privileged[191]: + cd /var/lib/acme container-test-run-certificates> server # [7466924.883127] server acme-setup-privileged[191]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> client # [7466924.577795] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7466924.577876] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted container-test-run-certificates> client # [7466924.583352] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7466924.583499] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section. container-test-run-certificates> client # [7466924.583589] client systemd-networkd[182]: lo: Link UP container-test-run-certificates> client # [7466924.583595] client systemd-networkd[182]: lo: Gained carrier container-test-run-certificates> client # [7466924.583745] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network. container-test-run-certificates> client # [7466924.584045] client systemd[1]: Started Network Management. container-test-run-certificates> client # [7466924.584085] client systemd-networkd[182]: eth1: Link UP container-test-run-certificates> client # [7466924.584249] client systemd-networkd[182]: eth1: Gained carrier container-test-run-certificates> client # [7466924.584622] client systemd[1]: systemd-networkd-persistent-storage.service: Failed to spawn executor: No such file or directory container-test-run-certificates> client # [7466924.584634] client systemd[1]: systemd-networkd-persistent-storage.service: Failed to spawn 'start' task: No such file or directory container-test-run-certificates> client # [7466924.584658] client systemd[1]: systemd-networkd-persistent-storage.service: Failed with result 'resources'. container-test-run-certificates> client # [7466924.584690] client systemd[1]: Failed to start Enable Persistent Storage in systemd-networkd. container-test-run-certificates> client # [7466924.763577] client systemd-resolved[95]: Positive Trust Anchors: container-test-run-certificates> client # [7466924.763586] client systemd-resolved[95]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d container-test-run-certificates> client # [7466924.763590] client systemd-resolved[95]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16 container-test-run-certificates> client # [7466924.763609] client systemd-resolved[95]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test container-test-run-certificates> client # [7466924.775927] client systemd-resolved[95]: Using system hostname 'client'. container-test-run-certificates> client # [7466924.776887] client systemd[1]: Started Network Name Resolution. container-test-run-certificates> client # [7466924.776955] client systemd[1]: Reached target Network. container-test-run-certificates> client # [7466924.777019] client systemd[1]: Reached target System Initialization. container-test-run-certificates> client # [7466924.777075] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container container-test-run-certificates> client # [7466924.777098] client systemd[1]: Started Daily Cleanup of Temporary Directories. container-test-run-certificates> client # [7466924.777114] client systemd[1]: Reached target Timer Units. container-test-run-certificates> client # [7466924.777231] client systemd[1]: Listening on D-Bus System Message Bus Socket. container-test-run-certificates> client # [7466924.777343] client systemd[1]: Listening on Nix Daemon Socket. container-test-run-certificates> client # [7466924.777458] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket. container-test-run-certificates> client # [7466924.777484] client systemd[1]: Reached target Socket Units. container-test-run-certificates> client # [7466924.777523] client systemd[1]: Reached target Basic System. container-test-run-certificates> client # [7466924.792228] client systemd[1]: Starting Import lastlog data into lastlog2 database... container-test-run-certificates> client # [7466924.793044] client systemd[1]: Starting Name Service Cache Daemon (nsncd)... container-test-run-certificates> client # [7466924.794095] client systemd[1]: Starting D-Bus System Message Bus... container-test-run-certificates> client # [7466924.804957] client systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7466924.803710] ca systemd[1]: Finished Import lastlog data into lastlog2 database. container-test-run-certificates> ca # [7466924.892148] ca acme-setup-privileged[200]: + set -euo pipefail container-test-run-certificates> ca # [7466924.892148] ca acme-setup-privileged[200]: + cd /var/lib/acme container-test-run-certificates> ca # [7466924.892455] ca acme-setup-privileged[200]: + chmod -R u=rwX,g=,o= .lego/accounts container-test-run-certificates> ca # [7466924.893274] ca acme-setup-privileged[200]: + chown -R acme .lego/accounts container-test-run-certificates> ca # [7466924.894454] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7466924.894487] ca acme-setup-privileged[200]: + '[' -d ca.foo ']' container-test-run-certificates> ca # [7466924.894487] ca acme-setup-privileged[200]: + for fixpath in ca.foo .lego/ca.foo container-test-run-certificates> ca # [7466924.894487] ca acme-setup-privileged[200]: + '[' -d .lego/ca.foo ']' container-test-run-certificates> ca # [7466924.910105] ca nsncd[202]: Aug 25 20:09:42.275 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> ca # [7466924.912711] ca systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> ca # [7466924.912826] ca systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> ca # [7466924.912869] ca systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> ca # [7466924.913814] ca systemd[1]: Starting User Login Management... container-test-run-certificates> ca # [7466924.914508] ca systemd[1]: Starting Permit User Sessions... container-test-run-certificates> ca # [7466924.920723] ca systemd[1]: Finished Permit User Sessions. container-test-run-certificates> ca # [7466924.921499] ca systemd[1]: Started Console Getty. container-test-run-certificates> ca # [7466924.921519] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> ca # [7466924.921530] ca systemd[1]: Reached target Login Prompts. container-test-run-certificates> ca # [7466925.013140] ca dbus-broker-launch[204]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> ca # [7466925.013590] ca dbus-broker-launch[204]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> ca # [7466925.013590] ca dbus-broker-launch[204]: Invalid user-name in /nix/store/dyyq5fj9d2iyrp213l8wpy3imn4cyazg-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> ca # [7466925.014006] ca systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> ca # [7466925.020364] ca dbus-broker-launch[204]: Ready container-test-run-certificates> server # [7466924.884399] server acme-setup-privileged[191]: + chown -R acme .lego/accounts container-test-run-certificates> server # [7466924.885533] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7466924.885572] server acme-setup-privileged[191]: + '[' -d test.foo ']' container-test-run-certificates> server # [7466924.885572] server acme-setup-privileged[191]: + for fixpath in test.foo .lego/test.foo container-test-run-certificates> server # [7466924.885572] server acme-setup-privileged[191]: + '[' -d .lego/test.foo ']' container-test-run-certificates> server # [7466924.902646] server nsncd[193]: Aug 25 20:09:42.268 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> server # [7466924.902722] server systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> server # [7466924.902778] server systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> server # [7466924.902818] server systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> server # [7466924.912957] server systemd[1]: Starting User Login Management... container-test-run-certificates> server # [7466924.913580] server systemd[1]: Starting Permit User Sessions... container-test-run-certificates> server # [7466924.921495] server systemd[1]: Finished Permit User Sessions. container-test-run-certificates> server # [7466924.922163] server systemd[1]: Started Console Getty. container-test-run-certificates> server # [7466924.922187] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> server # [7466924.922202] server systemd[1]: Reached target Login Prompts. container-test-run-certificates> server # [7466924.983505] server dbus-broker-launch[194]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> server # [7466924.984100] server dbus-broker-launch[194]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> server # [7466924.984100] server dbus-broker-launch[194]: Invalid user-name in /nix/store/3998vwjgq9b8mfq8zd315f0dx0zdhk3x-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> server # [7466924.984816] server systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> server # [7466924.989254] server dbus-broker-launch[194]: Ready container-test-run-certificates> server # [7466925.062845] server systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7466924.892518] client nsncd[185]: Aug 25 20:09:42.258 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket" container-test-run-certificates> client # [7466924.892611] client systemd[1]: Started Name Service Cache Daemon (nsncd). container-test-run-certificates> client # [7466924.892659] client systemd[1]: Reached target Host and Network Name Lookups. container-test-run-certificates> client # [7466924.892690] client systemd[1]: Reached target User and Group Name Lookups. container-test-run-certificates> client # [7466924.894176] client systemd[1]: Starting User Login Management... container-test-run-certificates> client # [7466924.913083] client systemd[1]: Starting Permit User Sessions... container-test-run-certificates> client # [7466924.920128] client systemd[1]: Finished Permit User Sessions. container-test-run-certificates> client # [7466924.921596] client systemd[1]: Started Console Getty. container-test-run-certificates> client # [7466924.921630] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0 container-test-run-certificates> client # [7466924.921649] client systemd[1]: Reached target Login Prompts. container-test-run-certificates> client # [7466925.020019] client dbus-broker-launch[186]: Looking up NSS user entry for 'systemd-timesync'... container-test-run-certificates> client # [7466925.020526] client dbus-broker-launch[186]: NSS returned no entry for 'systemd-timesync' container-test-run-certificates> client # [7466925.020526] client dbus-broker-launch[186]: Invalid user-name in /nix/store/n25qs0cxdhj6rld8wlnm0r6dhj2cw2r3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync" container-test-run-certificates> client # [7466925.020828] client systemd[1]: Started D-Bus System Message Bus. container-test-run-certificates> client # [7466925.025878] client dbus-broker-launch[186]: Ready container-test-run-certificates> client # [7466925.062745] client systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> client # [7466925.136287] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> server # [7466925.140739] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7466925.062882] ca systemd[1]: Finished Save Transient machine-id to Disk. container-test-run-certificates> ca # [7466925.138561] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully. container-test-run-certificates> ca # [7466925.437024] ca systemd-logind[229]: New seat seat0. container-test-run-certificates> ca # [7466925.437119] ca systemd[1]: Started User Login Management. container-test-run-certificates> ca # [7466925.441300] ca systemd[1]: Starting linger-users.service... container-test-run-certificates> ca # [7466925.451381] ca systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> ca # [7466925.451435] ca systemd[1]: Finished linger-users.service. container-test-run-certificates> ca # [7466925.474900] ca acme-setup-start[218]: + set -euo pipefail container-test-run-certificates> ca # [7466925.475108] ca acme-setup-start[218]: + test -e ca/key.pem container-test-run-certificates> ca # [7466925.475108] ca acme-setup-start[218]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> ca # [7466925.481831] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> ca # [7466925.482740] ca systemd[1]: Starting Ensure certificate for ca.foo... container-test-run-certificates> ca # [7466925.601107] ca step-ca[203]: badger 2026/08/25 20:09:42 INFO: All 0 tables opened in 0s container-test-run-certificates> ca # [7466925.604486] ca step-ca[203]: 2026/08/25 20:09:42 Building new tls configuration using step-ca x509 Signer Interface container-test-run-certificates> ca # [7466925.608193] ca step-ca[203]: 2026/08/25 20:09:42 Starting Smallstep CA/0.30.2 (linux/amd64) container-test-run-certificates> ca # [7466925.608193] ca step-ca[203]: 2026/08/25 20:09:42 Documentation: https://u.step.sm/docs/ca container-test-run-certificates> ca # [7466925.608193] ca step-ca[203]: 2026/08/25 20:09:42 Community Discord: https://u.step.sm/discord container-test-run-certificates> ca # [7466925.608193] ca step-ca[203]: 2026/08/25 20:09:42 Config file: /etc/smallstep/ca.json container-test-run-certificates> ca # [7466925.608193] ca step-ca[203]: 2026/08/25 20:09:42 The primary server URL is https://ca.foo:1443 container-test-run-certificates> ca # [7466925.608321] ca step-ca[203]: 2026/08/25 20:09:42 Root certificates are available at https://ca.foo:1443/roots.pem container-test-run-certificates> ca # [7466925.608321] ca step-ca[203]: 2026/08/25 20:09:42 X.509 Root Fingerprint: 8e51cab3286f777a675b86c8a0b3925bf8d37508e859d9a1597fed41f3332d1f container-test-run-certificates> ca # [7466925.608326] ca systemd[1]: Started step-ca service. container-test-run-certificates> ca # [7466925.608402] ca step-ca[203]: 2026/08/25 20:09:42 Serving HTTPS on 0.0.0.0:1443 ... container-test-run-certificates> client # [7466925.424539] client systemd-logind[201]: New seat seat0. container-test-run-certificates> client # [7466925.424664] client systemd[1]: Started User Login Management. container-test-run-certificates> client # [7466925.425428] client systemd[1]: Starting linger-users.service... container-test-run-certificates> client # [7466925.451049] client systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> client # [7466925.451099] client systemd[1]: Finished linger-users.service. container-test-run-certificates> client # [7466925.451416] client systemd[1]: Reached target Multi-User System. container-test-run-certificates> client # [7466925.451533] client systemd[1]: Startup finished in 1.602s. container-test-run-certificates> server # [7466925.427829] server systemd-logind[219]: New seat seat0. container-test-run-certificates> server # [7466925.427922] server systemd[1]: Started User Login Management. container-test-run-certificates> server # [7466925.441346] server systemd[1]: Starting linger-users.service... container-test-run-certificates> server # [7466925.450812] server systemd[1]: linger-users.service: Deactivated successfully. container-test-run-certificates> server # [7466925.451063] server systemd[1]: Finished linger-users.service. container-test-run-certificates> server # [7466925.455302] server acme-setup-start[207]: + set -euo pipefail container-test-run-certificates> server # [7466925.455302] server acme-setup-start[207]: + test -e ca/key.pem container-test-run-certificates> server # [7466925.455498] server acme-setup-start[207]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local container-test-run-certificates> server # [7466925.463187] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure. container-test-run-certificates> server # [7466925.464344] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server # [7466925.694087] server systemd-networkd[186]: eth1: Gained IPv6LL container-test-run-certificates> server # [7466925.837779] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7466925.839391] server acme-test.foo-start[245]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7466925.839437] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7466925.843901] server acme-test.foo-start[255]: + cd test.foo container-test-run-certificates> server # [7466925.844143] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7466925.845008] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7466925.845217] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7466925.845973] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7466925.846463] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7466925.847653] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7466925.848616] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7466925.849719] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7466925.849719] server acme-test.foo-start[245]: + '[' -d out ']' container-test-run-certificates> server # [7466925.849771] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7466925.850709] server acme-test.foo-start[245]: + chown -R acme:nginx out container-test-run-certificates> server # [7466925.852509] server acme-test.foo-start[245]: + for fixpath in out certificates container-test-run-certificates> server # [7466925.852509] server acme-test.foo-start[245]: + '[' -d certificates ']' container-test-run-certificates> server # [7466925.854544] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7466925.855509] server systemd[1]: Starting Nginx Web Server... container-test-run-certificates> ca # [7466925.694185] ca systemd-networkd[195]: eth1: Gained IPv6LL container-test-run-certificates> ca # [7466925.866338] ca acme-ca.foo-start[256]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7466925.867972] ca acme-ca.foo-start[256]: + '[' -e out/acme-success ']' container-test-run-certificates> ca # [7466925.868083] ca acme-ca.foo-start[256]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses= container-test-run-certificates> ca # [7466925.872458] ca acme-ca.foo-start[284]: + cd ca.foo container-test-run-certificates> ca # [7466925.872700] ca acme-ca.foo-start[284]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> ca # [7466925.873699] ca acme-ca.foo-start[285]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> ca # [7466925.873913] ca acme-ca.foo-start[284]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> ca # [7466925.874649] ca acme-ca.foo-start[284]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> ca # [7466925.874768] ca acme-ca.foo-start[256]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> ca # [7466925.875791] ca acme-ca.foo-start[256]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> ca # [7466925.876618] ca acme-ca.foo-start[256]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7466925.877418] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7466925.877418] ca acme-ca.foo-start[256]: + '[' -d out ']' container-test-run-certificates> ca # [7466925.877529] ca acme-ca.foo-start[256]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7466925.878807] ca acme-ca.foo-start[256]: + chown -R acme:nginx out container-test-run-certificates> ca # [7466925.880557] ca acme-ca.foo-start[256]: + for fixpath in out certificates container-test-run-certificates> ca # [7466925.880584] ca acme-ca.foo-start[256]: + '[' -d certificates ']' container-test-run-certificates> ca # [7466925.882361] ca systemd[1]: Finished Ensure certificate for ca.foo. container-test-run-certificates> ca # [7466925.883365] ca systemd[1]: Starting Nginx Web Server... container-test-run-certificates> client # [7466925.758099] client systemd-networkd[182]: eth1: Gained IPv6LL container-test-run-certificates> ca: must succeed: systemctl restart acme-order-renew-ca.foo.service container-test-run-certificates> server # [7466926.311662] server nginx-pre-start[267]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> ca # [7466926.336534] ca nginx-pre-start[296]: nginx: the configuration file /nix/store/d38pk82zk80i7ncqql5ybaj5971v4136-nginx.conf syntax is ok container-test-run-certificates> server # [7466926.312123] server nginx-pre-start[267]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> server # [7466926.317462] server systemd[1]: Started Nginx Web Server. container-test-run-certificates> ca # [7466926.336962] ca nginx-pre-start[296]: nginx: configuration file /nix/store/d38pk82zk80i7ncqql5ybaj5971v4136-nginx.conf test is successful container-test-run-certificates> server # [7466926.317802] server systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7466926.340081] ca systemd[1]: Started Nginx Web Server. container-test-run-certificates> server # [7466926.318706] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> ca # [7466926.340437] ca systemd[1]: Reached target Multi-User System. container-test-run-certificates> ca # [7466926.341407] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca # [7466926.822932] ca acme-order-renew-ca.foo-start[299]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7466926.824806] ca acme-order-renew-ca.foo-start[299]: + set -euo pipefail container-test-run-certificates> ca # [7466926.824866] ca acme-order-renew-ca.foo-start[299]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7466926.825053] ca acme-order-renew-ca.foo-start[299]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7466926.826936] ca acme-order-renew-ca.foo-start[299]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run container-test-run-certificates> ca # [7466926.840674] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> ca # [7466926.841166] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7466926.857244] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration="131.017µs" duration-ns=131017 fields.time="2026-08-25T20:09:44Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=0a390f3c-d168-40ec-830b-83f150616c97 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.857801] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> ca # [7466926.859414] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=1.707866ms duration-ns=1707866 fields.time="2026-08-25T20:09:44Z" method=HEAD name=ca nonce=Q054YmZzdlJWNnhlNzFJckhmMVlFQ0RCUkpEWkZ0Zk4 path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=57e3c047-615e-4724-aa99-d39de4fcf4d1 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.862236] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=2.293269ms duration-ns=2293269 fields.time="2026-08-25T20:09:44Z" method=POST name=ca nonce=aE45Z2VHeUpDencxTEQwc1R2WG03Z05tZXlvc0xHTjI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=a35c1ec1-f443-45c7-b422-45949f3d9428 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/h0Ky4vBej7xD0NjV1yojaAQQmXa9b48C/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: !!!! HEADS UP !!!! container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: Your account credentials have been saved in your container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: configuration directory at "accounts". container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: You should make a secure backup of this folder now. This container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: configuration directory will also contain private keys container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: generated by lego and certificates obtained from the ACME container-test-run-certificates> ca # [7466926.862670] ca acme-order-renew-ca.foo-start[311]: server. Making regular backups of this folder is ideal. container-test-run-certificates> ca # [7466926.862842] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7466926.865821] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=2.697109ms duration-ns=2697109 fields.time="2026-08-25T20:09:44Z" method=POST name=ca nonce=eWFHT2g1TmFrbzdiUDB2Q1FzMktnY25SSkxHdWd6OHE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=3fb9a4f2-a705-47f1-9d2f-27393919a62b response="{\"id\":\"q5nlI47QEK2sAxfrfx8SMmWqeSbzes5z\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:09:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:08:44Z\",\"notAfter\":\"2026-11-23T20:09:44Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/q5nlI47QEK2sAxfrfx8SMmWqeSbzes5z/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.924132] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=1.231659ms duration-ns=1231659 fields.time="2026-08-25T20:09:44Z" method=POST name=ca nonce=bm4zMU5EeWg2SEc0aFVlQUtsYmdTaE15RkxiaVg3Vmc path=/acme/acme/authz/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=bdef1f2b-d2e0-4bb4-b52f-f524c7d837ce response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"XGCV8SHJhZ2PdIrR1A4XC5pbziiX58ZA\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx/8Ihm9o4HZKKoasWoXZTzuq7rFw8zc8qi\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"XGCV8SHJhZ2PdIrR1A4XC5pbziiX58ZA\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx/mTcetO4Uez79S09WMKMowfXzFFpuDGbt\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"XGCV8SHJhZ2PdIrR1A4XC5pbziiX58ZA\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx/YwKgSu39OeeZSgoUkxMJpQOWlNzcyyJS\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:09:44Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.924388] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx container-test-run-certificates> ca # [7466926.924388] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> ca # [7466926.924469] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] acme: use http-01 solver container-test-run-certificates> ca # [7466926.924469] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> ca # [7466926.927376] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=2.629562ms duration-ns=2629562 fields.time="2026-08-25T20:09:44Z" method=POST name=ca nonce=THNFZ25hQ2FCcWl5ZDNsMnpwYmVYS09CWHd4UVpoZXM path=/acme/acme/challenge/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx/mTcetO4Uez79S09WMKMowfXzFFpuDGbt protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4a270984-b8c6-4cdd-91e7-a9c2033d784f response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"XGCV8SHJhZ2PdIrR1A4XC5pbziiX58ZA\",\"validated\":\"2026-08-25T20:09:44Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx/mTcetO4Uez79S09WMKMowfXzFFpuDGbt\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.927649] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] The server validated our request container-test-run-certificates> ca # [7466926.927743] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> ca # [7466926.932015] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info duration=3.80196ms duration-ns=3801960 fields.time="2026-08-25T20:09:44Z" method=POST name=ca nonce=d2t5NDZvT1d3bmV4QVRFNWdtM1Z0VERLUVIxenQyOW4 path=/acme/acme/order/q5nlI47QEK2sAxfrfx8SMmWqeSbzes5z/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=53677b31-7017-4a2a-8ee0-47e03f1df563 response="{\"id\":\"q5nlI47QEK2sAxfrfx8SMmWqeSbzes5z\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:09:44Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-25T20:08:44Z\",\"notAfter\":\"2026-11-23T20:09:44Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/GQON4F7VnDmmYe4PiQDsUQCgPRXLrFwx\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/q5nlI47QEK2sAxfrfx8SMmWqeSbzes5z/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/h6kgd1j49uQvFtwso75vv9YdKTBFsUtz\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466926.933301] ca step-ca[203]: time="2026-08-25T20:09:44Z" level=info certificate=MIIB0zCCAXmgAwIBAgIQDBkNSo2Q/13u/PoKie1ulDAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjUyMDA4NDRaFw0yNjExMjMyMDA5NDRaMBExDzANBgNVBAMTBmNhLmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABKNikShBNHMlAdYT9f2b1Y3UrNYWSKojCs8Bvwamw2iIYKS9pS05fi17ZoN0PMOgHhOwZePOSsy1JRLibf7mMKGjgaQwgaEwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQU4fcfoMZUAkV4HnxYH99uoY1cxnkwHwYDVR0jBBgwFoAUL8Iew7PCG9+fYpunmHKbilK2wxUwEQYDVR0RBAowCIIGY2EuZm9vMB0GDCsGAQQBgqRkxihAAQQNMAsCAQYEBGFjbWUEADAKBggqhkjOPQQDAgNIADBFAiB3yASTFfakBb01F8EVvbGsYu7lNWfvBzrW7CWEAeJ1QwIhAPwg22LSNEilSzYGOMAt6xHVtZn8/OhCU56FwPHwb28u duration="810.816µs" duration-ns=810816 fields.time="2026-08-25T20:09:44Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=T1FySXh6ZnNhR3EzZXY1Tk1IWHBkWXI2YXcxZ0ZKUkU path=/acme/acme/certificate/h6kgd1j49uQvFtwso75vv9YdKTBFsUtz protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=5a8b1209-9f82-4274-88ce-605331ad2f99 sans="map[dns:[ca.foo]]" serial=16080812948903912331890846272311881364 size=1340 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-25T20:08:44Z" valid-to="2026-11-23T20:09:44Z" container-test-run-certificates> ca # [7466926.933438] ca acme-order-renew-ca.foo-start[311]: 2026/08/25 20:09:44 [INFO] [ca.foo] Server responded with a certificate. container-test-run-certificates> ca # [7466926.936553] ca acme-order-renew-ca.foo-start[299]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7466926.938113] ca acme-order-renew-ca.foo-start[299]: + touch out/acme-success container-test-run-certificates> ca # [7466926.939176] ca acme-order-renew-ca.foo-start[299]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7466926.940040] ca acme-order-renew-ca.foo-start[299]: + touch out/renewed container-test-run-certificates> ca # [7466926.940856] ca acme-order-renew-ca.foo-start[299]: + echo Installing new certificate container-test-run-certificates> ca # [7466926.940856] ca acme-order-renew-ca.foo-start[299]: Installing new certificate container-test-run-certificates> ca # [7466926.940856] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7466926.942481] ca acme-order-renew-ca.foo-start[331]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> ca # [7466926.942765] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.key out/key.pem container-test-run-certificates> ca # [7466926.944164] ca acme-order-renew-ca.foo-start[332]: 'certificates/ca.foo.key' -> 'out/key.pem' container-test-run-certificates> ca # [7466926.944428] ca acme-order-renew-ca.foo-start[299]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem container-test-run-certificates> ca # [7466926.945317] ca acme-order-renew-ca.foo-start[333]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> ca # [7466926.945485] ca acme-order-renew-ca.foo-start[299]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> ca # [7466926.946403] ca acme-order-renew-ca.foo-start[299]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> ca # [7466926.947260] ca acme-order-renew-ca.foo-start[299]: + for fixpath in out certificates container-test-run-certificates> ca # [7466926.947284] ca acme-order-renew-ca.foo-start[299]: + '[' -d out ']' container-test-run-certificates> ca # [7466926.947284] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7466926.948228] ca acme-order-renew-ca.foo-start[299]: + chown -R acme:nginx out container-test-run-certificates> ca # [7466926.951455] ca acme-order-renew-ca.foo-start[299]: + for fixpath in out certificates container-test-run-certificates> ca # [7466926.951487] ca acme-order-renew-ca.foo-start[299]: + '[' -d certificates ']' container-test-run-certificates> ca # [7466926.951487] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7466926.953041] ca acme-order-renew-ca.foo-start[299]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7466926.954736] ca acme-order-renew-ca.foo-start[299]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7466927.077326] ca systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7466926.780991] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7466926.783141] server acme-order-renew-test.foo-start[270]: + set -euo pipefail container-test-run-certificates> server # [7466926.783221] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7466926.783329] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7466926.784127] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7466926.796716] server acme-order-renew-test.foo-start[282]: 2026/08/25 20:09:44 No key found for account none@none.tld. Generating a P256 key. container-test-run-certificates> server # [7466926.797530] server acme-order-renew-test.foo-start[282]: 2026/08/25 20:09:44 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key container-test-run-certificates> ca # [7466927.081363] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7466927.081667] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server # [7466927.838885] server acme-order-renew-test.foo-start[282]: 2026/08/25 20:09:45 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 2 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority container-test-run-certificates> server # [7466927.846596] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7466927.846596] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start. container-test-run-certificates> server # [7466927.846596] server acme-order-renew-test.foo-start[270]: + exit 10 container-test-run-certificates> server # [7466927.848089] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a container-test-run-certificates> server # [7466927.848200] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'. container-test-run-certificates> server # [7466927.848608] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7466927.849590] server systemd[1]: Startup finished in 3.997s. container-test-run-certificates> ca # [7466927.992801] ca nginx[349]: nginx: the configuration file /nix/store/d38pk82zk80i7ncqql5ybaj5971v4136-nginx.conf syntax is ok container-test-run-certificates> ca # [7466927.993218] ca nginx[349]: nginx: configuration file /nix/store/d38pk82zk80i7ncqql5ybaj5971v4136-nginx.conf test is successful container-test-run-certificates> ca # [7466928.636797] ca systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> ca # [7466928.637015] ca systemd[1]: Startup finished in 4.779s. container-test-run-certificates> ca # [7466929.127558] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo... container-test-run-certificates> ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 3.25 seconds) container-test-run-certificates> ca # [7466929.575182] ca acme-order-renew-ca.foo-start[364]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> ca # [7466929.577095] ca acme-order-renew-ca.foo-start[364]: + set -euo pipefail container-test-run-certificates> ca # [7466929.577161] ca acme-order-renew-ca.foo-start[364]: + echo 88dc4fc401a6091a1bd9 container-test-run-certificates> ca # [7466929.577246] ca acme-order-renew-ca.foo-start[364]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> ca # [7466929.577912] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.key ']' container-test-run-certificates> ca # [7466929.577938] ca acme-order-renew-ca.foo-start[364]: + '[' -e certificates/ca.foo.crt ']' container-test-run-certificates> ca # [7466929.578142] ca acme-order-renew-ca.foo-start[372]: ++ find accounts -name none@none.tld.key container-test-run-certificates> ca # [7466929.579606] ca acme-order-renew-ca.foo-start[364]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']' container-test-run-certificates> ca # [7466929.579640] ca acme-order-renew-ca.foo-start[364]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic container-test-run-certificates> ca # [7466929.605806] ca step-ca[203]: time="2026-08-25T20:09:46Z" level=info duration="75.261µs" duration-ns=75261 fields.time="2026-08-25T20:09:46Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=349552d4-40e9-48e7-979a-2314a9c2a678 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466929.614818] ca acme-order-renew-ca.foo-start[373]: 2026/08/25 20:09:46 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint container-test-run-certificates> ca # [7466929.614818] ca acme-order-renew-ca.foo-start[373]: 2026/08/25 20:09:46 [INFO] [ca.foo] The certificate expires at 2026-11-23T20:09:44Z, the renewal can be performed in 1439h59m37.02826797s: no renewal. container-test-run-certificates> ca # [7466929.615007] ca acme-order-renew-ca.foo-start[364]: + mv domainhash.txt certificates/ container-test-run-certificates> ca # [7466929.615799] ca acme-order-renew-ca.foo-start[364]: + touch out/acme-success container-test-run-certificates> ca # [7466929.616866] ca acme-order-renew-ca.foo-start[364]: + cmp -s certificates/ca.foo.crt out/fullchain.pem container-test-run-certificates> ca # [7466929.617579] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7466929.617608] ca acme-order-renew-ca.foo-start[364]: + '[' -d out ']' container-test-run-certificates> ca # [7466929.617608] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> ca # [7466929.618527] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx out container-test-run-certificates> ca # [7466929.620186] ca acme-order-renew-ca.foo-start[364]: + for fixpath in out certificates container-test-run-certificates> ca # [7466929.620210] ca acme-order-renew-ca.foo-start[364]: + '[' -d certificates ']' container-test-run-certificates> ca # [7466929.620210] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> ca # [7466929.639212] ca acme-order-renew-ca.foo-start[364]: + chown -R acme:nginx certificates container-test-run-certificates> ca # [7466929.641093] ca acme-order-renew-ca.foo-start[364]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> ca # [7466929.724879] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully. container-test-run-certificates> ca # [7466929.725105] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo. container-test-run-certificates> server: must succeed: systemctl restart acme-test.foo.service container-test-run-certificates> server # [7466932.735087] server systemd[1]: acme-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7466932.735207] server systemd[1]: Stopped Ensure certificate for test.foo. container-test-run-certificates> server # [7466932.736062] server systemd[1]: Stopping Ensure certificate for test.foo... container-test-run-certificates> server # [7466932.736918] server systemd[1]: Starting Ensure certificate for test.foo... container-test-run-certificates> server: (finished: must succeed: systemctl restart acme-test.foo.service, in 0.44 seconds) container-test-run-certificates> client: waiting for success: curl -v https://test.foo container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [110 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:09:43 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:09:43 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6c9380 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7466933.120494] server acme-test.foo-start[304]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7466933.121357] server acme-test.foo-start[304]: + '[' -e out/acme-success ']' container-test-run-certificates> server # [7466933.121378] server acme-test.foo-start[304]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses= container-test-run-certificates> server # [7466933.126292] server acme-test.foo-start[314]: + cd test.foo container-test-run-certificates> server # [7466933.126620] server acme-test.foo-start[314]: + cp -vp cert.pem ../out/cert.pem container-test-run-certificates> server # [7466933.135710] server acme-test.foo-start[315]: 'cert.pem' -> '../out/cert.pem' container-test-run-certificates> server # [7466933.135947] server acme-test.foo-start[314]: + cp -vp key.pem ../out/key.pem container-test-run-certificates> server # [7466933.147591] server acme-test.foo-start[314]: 'key.pem' -> '../out/key.pem' container-test-run-certificates> server # [7466933.147841] server acme-test.foo-start[304]: + cat out/cert.pem ca/cert.pem container-test-run-certificates> server # [7466933.155721] server acme-test.foo-start[304]: + cp ca/cert.pem out/chain.pem container-test-run-certificates> server # [7466933.156768] server acme-test.foo-start[304]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7466933.163823] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [7466933.163823] server acme-test.foo-start[304]: + '[' -d out ']' container-test-run-certificates> server # [7466933.163862] server acme-test.foo-start[304]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7466933.164641] server acme-test.foo-start[304]: + chown -R acme:nginx out container-test-run-certificates> server # [7466933.166406] server acme-test.foo-start[304]: + for fixpath in out certificates container-test-run-certificates> server # [7466933.166406] server acme-test.foo-start[304]: + '[' -d certificates ']' container-test-run-certificates> server # [7466933.168075] server systemd[1]: Finished Ensure certificate for test.foo. container-test-run-certificates> server # [7466933.169601] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo... container-test-run-certificates> server # [7466933.546263] server acme-order-renew-test.foo-start[322]: Waiting to acquire lock in /run/acme/ container-test-run-certificates> server # [7466933.547624] server acme-order-renew-test.foo-start[322]: + set -euo pipefail container-test-run-certificates> server # [7466933.547665] server acme-order-renew-test.foo-start[322]: + echo ad12aa6741ce4bd2c108 container-test-run-certificates> server # [7466933.547720] server acme-order-renew-test.foo-start[322]: + cmp -s domainhash.txt certificates/domainhash.txt container-test-run-certificates> server # [7466933.548304] server acme-order-renew-test.foo-start[322]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run container-test-run-certificates> server # [7466933.572606] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:50 [INFO] acme: Registering account for none@none.tld container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: !!!! HEADS UP !!!! container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: Your account credentials have been saved in your container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: configuration directory at "accounts". container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: You should make a secure backup of this folder now. This container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: configuration directory will also contain private keys container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: generated by lego and certificates obtained from the ACME container-test-run-certificates> server # [7466933.739347] server acme-order-renew-test.foo-start[330]: server. Making regular backups of this folder is ideal. container-test-run-certificates> server # [7466933.739522] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] acme: Obtaining bundled SAN certificate container-test-run-certificates> ca # [7466933.572200] ca step-ca[203]: time="2026-08-25T20:09:50Z" level=info duration="40.766µs" duration-ns=40766 fields.time="2026-08-25T20:09:50Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=1041a532-cb1a-4a5b-bcfb-dbc244a8681b response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466933.614410] ca step-ca[203]: time="2026-08-25T20:09:50Z" level=info duration=40.573006ms duration-ns=40573006 fields.time="2026-08-25T20:09:50Z" method=HEAD name=ca nonce=T3J4RjR0ZnJ4S1NCaGdqckJvNlZMRndzTmZWMjBwc0w path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=93ea3cf8-4c56-42f6-a969-84bb62a71912 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466933.738849] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info duration=122.954243ms duration-ns=122954243 fields.time="2026-08-25T20:09:50Z" method=POST name=ca nonce=aXRKWUJPTUhIeFc4VGdLTFJMUklyOFp2OEd0TGRJVVo path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=881cac47-0d19-499f-b028-addeff3a22f5 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/VISyr0ESwft0lr9Cyq6tUp1MBYi8FrH5/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:09:43 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:09:43 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6c9380 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> ca # [7466934.073037] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info duration=332.299995ms duration-ns=332299995 fields.time="2026-08-25T20:09:51Z" method=POST name=ca nonce=YWtRbmU3dTFVenZiQVhBUEJxMzFNbVpEV3RjZXQ0Z0s path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=7cd525f2-4d9b-4302-9f8f-08eb63d9edc5 response="{\"id\":\"jEPX7jgV6bByEyrbzbTV9LY16Wq28QjX\",\"status\":\"pending\",\"expires\":\"2026-08-26T20:09:51Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:08:51Z\",\"notAfter\":\"2026-11-23T20:09:51Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3\"],\"finalize\":\"https://ca.foo/acme/acme/order/jEPX7jgV6bByEyrbzbTV9LY16Wq28QjX/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466934.195840] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info duration=65.180906ms duration-ns=65180906 fields.time="2026-08-25T20:09:51Z" method=POST name=ca nonce=MUJRNXNIQkNoQzlNbTlYekVoM2oxWmJuekd1YWFXajQ path=/acme/acme/authz/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3 protocol=HTTP/1.1 referer= remote-address="::1" request-id=fb9ac9ad-67e2-4d3e-8e5b-eca569124678 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"DNUHTMw8nTjyXLC49x7SYzE7fIPnj8sS\",\"url\":\"https://ca.foo/acme/acme/challenge/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3/oZsQOtrHRTI0mpXZu1PuqlOzHpcUi4mM\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"DNUHTMw8nTjyXLC49x7SYzE7fIPnj8sS\",\"url\":\"https://ca.foo/acme/acme/challenge/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3/CGzKT6qZLeADYNK9tZ124kdA7e2bc8SU\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"DNUHTMw8nTjyXLC49x7SYzE7fIPnj8sS\",\"url\":\"https://ca.foo/acme/acme/challenge/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3/y7WIEbW1staQ8yp6Uyl34SWj2rywij4C\"}],\"wildcard\":false,\"expires\":\"2026-08-26T20:09:51Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466934.271170] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info duration=74.158012ms duration-ns=74158012 fields.time="2026-08-25T20:09:51Z" method=POST name=ca nonce=TWxmaXB1U1Z0dzI1YzdTWXlPdVJmWm9PUHhJM1hQSTQ path=/acme/acme/challenge/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3/CGzKT6qZLeADYNK9tZ124kdA7e2bc8SU protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=8e36498e-6cab-4507-89f4-56797c70ef52 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"DNUHTMw8nTjyXLC49x7SYzE7fIPnj8sS\",\"validated\":\"2026-08-25T20:09:51Z\",\"url\":\"https://ca.foo/acme/acme/challenge/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3/CGzKT6qZLeADYNK9tZ124kdA7e2bc8SU\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466934.286569] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info duration=14.257829ms duration-ns=14257829 fields.time="2026-08-25T20:09:51Z" method=POST name=ca nonce=dnYyOGRNcXlCeWNEVHJHQnZZalNrUVhtSTN3QlVTUzY path=/acme/acme/order/jEPX7jgV6bByEyrbzbTV9LY16Wq28QjX/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=da83dd35-786a-42c3-a428-25c2a6162abf response="{\"id\":\"jEPX7jgV6bByEyrbzbTV9LY16Wq28QjX\",\"status\":\"valid\",\"expires\":\"2026-08-26T20:09:51Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-25T20:08:51Z\",\"notAfter\":\"2026-11-23T20:09:51Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3\"],\"finalize\":\"https://ca.foo/acme/acme/order/jEPX7jgV6bByEyrbzbTV9LY16Wq28QjX/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/XdOo6svTQBjN2dC2mUEva5Wd18tzEruf\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= container-test-run-certificates> ca # [7466934.289059] ca step-ca[203]: time="2026-08-25T20:09:51Z" level=info certificate="MIIB2DCCAX2gAwIBAgIQeZNSnXsxNCLCSyJ8z+eQvjAKBggqhkjOPQQDAjAfMR0wGwYDVQQDExRDbGFuIEludGVybWVkaWF0ZSBDQTAeFw0yNjA4MjUyMDA4NTFaFw0yNjExMjMyMDA5NTFaMBMxETAPBgNVBAMTCHRlc3QuZm9vMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAErumg3QtuXZqdG8fgCAsZSg4pfns+FVgpAmnj7yvrrhAfNiFm+K3armLivXxpENhwijzPINp4Pa4jes9DHzuhI6OBpjCBozAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBTt+vtOhHLZcGjtETVIfqalJskw0TAfBgNVHSMEGDAWgBQvwh7Ds8Ib359im6eYcpuKUrbDFTATBgNVHREEDDAKggh0ZXN0LmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSQAwRgIhAI1KcsQ9JYkWXMC8eAW73IHFF9GxLqoud111NxVS4DURAiEAtmsSdFSShEIBb2CtkHUA2a8R4O597D1inYawspL6CNI=" duration=1.645198ms duration-ns=1645198 fields.time="2026-08-25T20:09:51Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=QWE1djlLZU1nVVJHWU5tWU5iTmx6M2FkZGZGSHk4MnU path=/acme/acme/certificate/XdOo6svTQBjN2dC2mUEva5Wd18tzEruf protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=dfc4d730-8e38-4f3a-a554-977fe8ef5349 sans="map[dns:[test.foo]]" serial=161601530762714594236663692911777910974 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; amd64)" user-id= valid-from="2026-08-25T20:08:51Z" valid-to="2026-11-23T20:09:51Z" container-test-run-certificates> server # [7466934.196143] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/xHOzEH42nFXf9KVXFcqxqX8Mf8Z3OzN3 container-test-run-certificates> server # [7466934.196143] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01 container-test-run-certificates> server # [7466934.196143] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] acme: use http-01 solver container-test-run-certificates> server # [7466934.196143] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] acme: Trying to solve HTTP-01 container-test-run-certificates> server # [7466934.271373] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] The server validated our request container-test-run-certificates> server # [7466934.271424] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] acme: Validations succeeded; requesting certificates container-test-run-certificates> server # [7466934.289196] server acme-order-renew-test.foo-start[330]: 2026/08/25 20:09:51 [INFO] [test.foo] Server responded with a certificate. container-test-run-certificates> server # [7466934.291559] server acme-order-renew-test.foo-start[322]: + mv domainhash.txt certificates/ container-test-run-certificates> server # [7466934.292649] server acme-order-renew-test.foo-start[322]: + touch out/acme-success container-test-run-certificates> server # [7466934.293524] server acme-order-renew-test.foo-start[322]: + cmp -s certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7466934.294174] server acme-order-renew-test.foo-start[322]: + touch out/renewed container-test-run-certificates> server # [7466934.295120] server acme-order-renew-test.foo-start[322]: + echo Installing new certificate container-test-run-certificates> server # [7466934.295143] server acme-order-renew-test.foo-start[322]: Installing new certificate container-test-run-certificates> server # [7466934.295143] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.crt out/fullchain.pem container-test-run-certificates> server # [7466934.295846] server acme-order-renew-test.foo-start[350]: 'certificates/test.foo.crt' -> 'out/fullchain.pem' container-test-run-certificates> server # [7466934.295974] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.key out/key.pem container-test-run-certificates> server # [7466934.296717] server acme-order-renew-test.foo-start[351]: 'certificates/test.foo.key' -> 'out/key.pem' container-test-run-certificates> server # [7466934.296862] server acme-order-renew-test.foo-start[322]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem container-test-run-certificates> server # [7466934.297572] server acme-order-renew-test.foo-start[352]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem' container-test-run-certificates> server # [7466934.297689] server acme-order-renew-test.foo-start[322]: + ln -sf fullchain.pem out/cert.pem container-test-run-certificates> server # [7466934.298510] server acme-order-renew-test.foo-start[322]: + cat out/key.pem out/fullchain.pem container-test-run-certificates> server # [7466934.299333] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [7466934.299349] server acme-order-renew-test.foo-start[322]: + '[' -d out ']' container-test-run-certificates> server # [7466934.299349] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= out container-test-run-certificates> server # [7466934.300104] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx out container-test-run-certificates> server # [7466934.301480] server acme-order-renew-test.foo-start[322]: + for fixpath in out certificates container-test-run-certificates> server # [7466934.301499] server acme-order-renew-test.foo-start[322]: + '[' -d certificates ']' container-test-run-certificates> server # [7466934.301499] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=rX,o= certificates container-test-run-certificates> server # [7466934.302284] server acme-order-renew-test.foo-start[322]: + chown -R acme:nginx certificates container-test-run-certificates> server # [7466934.303829] server acme-order-renew-test.foo-start[322]: + chmod -R u=rwX,g=,o= accounts/. container-test-run-certificates> server # [7466934.390291] server systemd[1]: Reloading Nginx Web Server... container-test-run-certificates> server # [7466934.393129] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully. container-test-run-certificates> server # [7466934.393299] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo. container-test-run-certificates> server # [7466934.763170] server nginx[368]: nginx: the configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf syntax is ok container-test-run-certificates> server # [7466934.763401] server nginx[368]: nginx: configuration file /nix/store/nfgk30pbmji62whlqlbylrn263ifbnzr-nginx.conf test is successful container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [1010 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [111 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:09:43 2026 GMT container-test-run-certificates> * expire date: Sep 24 20:09:43 2028 GMT container-test-run-certificates> * issuer: CN=minica root ca 6c9380 container-test-run-certificates> * Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 13 container-test-run-certificates> * SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> * closing connection #0 container-test-run-certificates> curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19) container-test-run-certificates> More details here: https://curl.se/docs/sslcerts.html container-test-run-certificates> container-test-run-certificates> curl failed to verify the legitimacy of the server and therefore could not container-test-run-certificates> establish a secure connection to it. To learn more about this situation and container-test-run-certificates> how to fix it, please visit the webpage mentioned above. container-test-run-certificates> server # [7466935.121448] server systemd[1]: Reloaded Nginx Web Server. container-test-run-certificates> * Host test.foo:443 was resolved. container-test-run-certificates> * IPv6: 2001:db8:1::3 container-test-run-certificates> * IPv4: 192.168.1.3 container-test-run-certificates> * Trying [2001:db8:1::3]:443... container-test-run-certificates> * ALPN: curl offers h2,http/1.1 container-test-run-certificates> } [5 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Client hello (1): container-test-run-certificates> } [1552 bytes data] container-test-run-certificates> * SSL Trust Anchors: container-test-run-certificates> * OpenSSL default paths (fallback) container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Server hello (2): container-test-run-certificates> { [1210 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS change cipher, Change cipher spec (1): container-test-run-certificates> { [1 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): container-test-run-certificates> { [19 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Certificate (11): container-test-run-certificates> { [932 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, CERT verify (15): container-test-run-certificates> { [78 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Finished (20): container-test-run-certificates> { [52 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): container-test-run-certificates> } [1 bytes data] container-test-run-certificates> * TLSv1.3 (OUT), TLS handshake, Finished (20): container-test-run-certificates> } [52 bytes data] container-test-run-certificates> * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey container-test-run-certificates> * ALPN: server accepted h2 container-test-run-certificates> * Server certificate: container-test-run-certificates> * subject: CN=test.foo container-test-run-certificates> * start date: Aug 25 20:08:51 2026 GMT container-test-run-certificates> * expire date: Nov 23 20:09:51 2026 GMT container-test-run-certificates> * issuer: CN=Clan Intermediate CA container-test-run-certificates> * Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256 container-test-run-certificates> * subjectAltName: "test.foo" matches cert's "test.foo" container-test-run-certificates> * OpenSSL verify result: 0 container-test-run-certificates> * SSL certificate verified via OpenSSL. container-test-run-certificates> * Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 59510 container-test-run-certificates> % Total % Received % Xferd Average Speed Time Time Time Current container-test-run-certificates> Dload Upload Total Spent Left Speed container-test-run-certificates> 0 0 0 0 0 0 0 0 0* using HTTP/2 container-test-run-certificates> * [HTTP/2] [1] OPENED stream for https://test.foo/ container-test-run-certificates> * [HTTP/2] [1] [:method: GET] container-test-run-certificates> * [HTTP/2] [1] [:scheme: https] container-test-run-certificates> * [HTTP/2] [1] [:authority: test.foo] container-test-run-certificates> * [HTTP/2] [1] [:path: /] container-test-run-certificates> * [HTTP/2] [1] [user-agent: curl/8.21.0] container-test-run-certificates> * [HTTP/2] [1] [accept: */*] container-test-run-certificates> } [5 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> * Request completely sent off container-test-run-certificates> { [5 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): container-test-run-certificates> { [265 bytes data] container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> container-test-run-certificates> { [5 bytes data] container-test-run-certificates> 100 20 100 20 0 0 1498 0 0 container-test-run-certificates> * Connection #0 to host test.foo:443 left intact container-test-run-certificates> client: (finished: waiting for success: curl -v https://test.foo, in 3.09 seconds) container-test-run-certificates> client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2 container-test-run-certificates> Certificate: container-test-run-certificates> Data: container-test-run-certificates> Version: 3 (0x2) container-test-run-certificates> Serial Number: container-test-run-certificates> 79:93:52:9d:7b:31:34:22:c2:4b:22:7c:cf:e7:90:be container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Issuer: CN=Clan Intermediate CA container-test-run-certificates> Validity container-test-run-certificates> Not Before: Aug 25 20:08:51 2026 GMT container-test-run-certificates> Not After : Nov 23 20:09:51 2026 GMT container-test-run-certificates> Subject: CN=test.foo container-test-run-certificates> Subject Public Key Info: container-test-run-certificates> Public Key Algorithm: id-ecPublicKey container-test-run-certificates> Public-Key: (256 bit) container-test-run-certificates> pub: container-test-run-certificates> 04:ae:e9:a0:dd:0b:6e:5d:9a:9d:1b:c7:e0:08:0b: container-test-run-certificates> 19:4a:0e:29:7e:7b:3e:15:58:29:02:69:e3:ef:2b: container-test-run-certificates> eb:ae:10:1f:36:21:66:f8:ad:da:ae:62:e2:bd:7c: container-test-run-certificates> 69:10:d8:70:8a:3c:cf:20:da:78:3d:ae:23:7a:cf: container-test-run-certificates> 43:1f:3b:a1:23 container-test-run-certificates> ASN1 OID: prime256v1 container-test-run-certificates> NIST CURVE: P-256 container-test-run-certificates> X509v3 extensions: container-test-run-certificates> X509v3 Key Usage: critical container-test-run-certificates> Digital Signature container-test-run-certificates> X509v3 Extended Key Usage: container-test-run-certificates> TLS Web Server Authentication, TLS Web Client Authentication container-test-run-certificates> X509v3 Subject Key Identifier: container-test-run-certificates> ED:FA:FB:4E:84:72:D9:70:68:ED:11:35:48:7E:A6:A5:26:C9:30:D1 container-test-run-certificates> X509v3 Authority Key Identifier: container-test-run-certificates> 2F:C2:1E:C3:B3:C2:1B:DF:9F:62:9B:A7:98:72:9B:8A:52:B6:C3:15 container-test-run-certificates> X509v3 Subject Alternative Name: container-test-run-certificates> DNS:test.foo container-test-run-certificates> 1.3.6.1.4.1.37476.9000.64.1: container-test-run-certificates> 0......acme.. container-test-run-certificates> Signature Algorithm: ecdsa-with-SHA256 container-test-run-certificates> Signature Value: container-test-run-certificates> 30:46:02:21:00:8d:4a:72:c4:3d:25:89:16:5c:c0:bc:78:05: container-test-run-certificates> bb:dc:81:c5:17:d1:b1:2e:aa:2e:77:5d:75:37:15:52:e0:35: container-test-run-certificates> 11:02:21:00:b6:6b:12:74:54:92:84:42:01:6f:60:ad:90:75: container-test-run-certificates> 00:d9:af:11:e0:ee:7d:ec:3d:62:9d:86:b0:b2:92:fa:08:d2 container-test-run-certificates> client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo /dev/null | openssl x509 -text -noout 1>&2, in 0.02 seconds) container-test-run-certificates> (finished: run the VM test script, in 12.80 seconds) container-test-run-certificates> test script finished in 12.85s container-test-run-certificates> cleanup container-test-run-certificates> kill NspawnMachine (pid 53) container-test-run-certificates> kill NspawnMachine (pid 54) container-test-run-certificates> Container ca terminated by signal KILL. container-test-run-certificates> kill NspawnMachine (pid 55) container-test-run-certificates> Container client terminated by signal KILL. container-test-run-certificates> Container server terminated by signal KILL. container-test-run-certificates> (finished: cleanup, in 0.24 seconds) post-build step Upload to niks3: ok time=2026-08-25T20:09:54.701Z level=INFO msg="Uploading 0 paths to niks3.clan.lol (1 already cached)" time=2026-08-25T20:09:56.758Z level=INFO msg="Uploading 1 narinfos" time=2026-08-25T20:10:07.331Z level=WARN msg="Request returned retryable status, retrying" attempt=1 max_attempts=6 backoff=100ms status=500 url="https://s3.eu-central-003.backblazeb2.com/clan-cache-geninf/2arc7yd6bx06589cmxxgk1xj9wiz96ap.narinfo?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=003eaae730241090000000009%2F20260825%2Feu-central-003%2Fs3%2Faws4_request&X-Amz-Date=20260825T200954Z&X-Amz-Expires=18000&X-Amz-SignedHeaders=host&X-Amz-Signature=68018df113226dd2790269563a7ffd4f0db921bbd0c8cafee771b64ff6a4bedb" time=2026-08-25T20:10:07.616Z level=INFO msg="Upload complete. (13.086s)"