container-test-run-certificates
checks.aarch64-linux.certificates
· build #505
· raw
1Machine state will be reset. To keep it, pass --keep-machine-state2start all VLans3(finished: start all VLans, in 0.00 seconds)45Test will time out and terminate in 3600.0 seconds6run the VM test script7additionally exposed symbols:8 ca, client, server,9 vlan1,10 start_all, test_script, machines, machines_qemu, machines_nspawn, vlans, driver, log, os, create_machine, subtest, run_tests, join_all, retry, serial_stdout_off, serial_stdout_on, polling_condition, BaseMachine, QemuMachine, NspawnMachine, t, debug, dump_machine_ssh11start all VMs12ca: systemd-nspawn running (pid 53)13server: systemd-nspawn running (pid 54)14ca: Waiting for journal at /build/vm-state-ca/var/log/journal...15client: systemd-nspawn running (pid 55)16server: Waiting for journal at /build/vm-state-server/var/log/journal...17client: Waiting for journal at /build/vm-state-client/var/log/journal...18(finished: start all VMs, in 0.00 seconds)19nixos-nspawn(client): TAP vde-tap1 not found; container will be isolated from VDE20nixos-nspawn(client): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.21nixos-nspawn(server): TAP vde-tap1 not found; container will be isolated from VDE22nixos-nspawn(server): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.23nixos-nspawn(ca): TAP vde-tap1 not found; container will be isolated from VDE24nixos-nspawn(ca): A common reason for this is that /dev/net is not available in the Nix sandbox. Try adding /dev/net to extra-sandbox-paths.25Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.26Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.27░ Spawning container client on /build/vm-state-client.28░ Spawning container server on /build/vm-state-server.29Note: in a future version of systemd-nspawn the default set of permitted socket address families will be restricted to AF_INET, AF_INET6 and AF_UNIX. Use --restrict-address-families= to configure the set of permitted socket address families, or set RestrictAddressFamilies= in a .nspawn file.30░ Spawning container ca on /build/vm-state-ca.31ca # [6785532.270870] ca systemd-journald[78]: Journal started32ca # [6785532.270931] ca systemd-journald[78]: Runtime Journal (/run/log/journal/7e63e525c42b4810985f5ce7a02d0425) is 8M, max 2.5G, 2.4G free.33ca # [6785532.278395] ca systemd[1]: Starting Flush Journal to Persistent Storage...34ca # [6785532.279225] ca systemd[1]: Starting Network Name Resolution...35ca # [6785532.279878] ca systemd[1]: Starting Create Static Device Nodes in /dev...36ca # [6785532.288663] ca systemd-journald[78]: Time spent on flushing to /var/log/journal/7e63e525c42b4810985f5ce7a02d0425 is 1.243ms for 5 entries.37ca # [6785532.288663] ca systemd-journald[78]: System Journal (/var/log/journal/7e63e525c42b4810985f5ce7a02d0425) is 8M, max 4G, 3.9G free.38ca # [6785532.299830] ca systemd[1]: Finished Create Static Device Nodes in /dev.39ca # [6785532.300504] ca systemd[1]: Reached target Preparation for Local File Systems.40ca # [6785532.300624] ca systemd[1]: Reached target Local File Systems.41ca # [6785532.301469] ca systemd[1]: Listening on Boot Loader Control Service Socket.42ca # [6785532.301515] ca systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container43ca # [6785532.302415] ca systemd[1]: Starting Save Transient machine-id to Disk...44ca # [6785532.302456] ca systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys45ca # [6785532.302994] ca systemd[1]: Finished Flush Journal to Persistent Storage.46ca # [6785532.304694] ca systemd[1]: Starting Create System Files and Directories...47ca # [6785532.319267] ca systemd-tmpfiles[124]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted48ca # [6785532.319478] ca systemd-tmpfiles[124]: fchmod() of /var/log/journal failed: Operation not permitted49ca # [6785532.319617] ca systemd-tmpfiles[124]: fchmod() of /var/log/journal/7e63e525c42b4810985f5ce7a02d0425 failed: Operation not permitted50ca # [6785532.319865] ca systemd-tmpfiles[124]: fchmod() of /run/log/journal failed: Operation not permitted51ca # [6785532.321254] ca systemd[1]: Finished Create System Files and Directories.52ca # [6785532.322360] ca systemd[1]: Starting Rebuild Journal Catalog...53ca # [6785532.323106] ca systemd[1]: Starting Record System Boot/Shutdown in UTMP...54ca # [6785532.339019] ca systemd[1]: Finished Record System Boot/Shutdown in UTMP.55ca # [6785532.345619] ca systemd[1]: Finished Rebuild Journal Catalog.56ca # [6785532.347338] ca systemd[1]: Starting Update is Completed...57ca # [6785532.357740] ca systemd[1]: Finished Update is Completed.58ca # [6785532.413438] ca systemd[1]: Finished Firewall.59ca # [6785532.413666] ca systemd[1]: Reached target Preparation for Network.60ca # [6785532.413909] ca systemd[1]: Listening on Network Management Resolve Hook Socket.61ca # [6785532.414997] ca systemd[1]: Starting Network Management...62client # [6785532.253314] client systemd-journald[69]: Journal started63client # [6785532.253367] client systemd-journald[69]: Runtime Journal (/run/log/journal/767e071c2fc24b09b5f983d2f3fac17d) is 8M, max 2.5G, 2.4G free.64client # [6785532.259507] client systemd[1]: Finished Create Static Device Nodes in /dev gracefully.65client # [6785532.268164] client systemd[1]: Starting Flush Journal to Persistent Storage...66client # [6785532.269058] client systemd[1]: Starting Network Name Resolution...67client # [6785532.269768] client systemd[1]: Starting Create Static Device Nodes in /dev...68client # [6785532.279200] client systemd-journald[69]: Time spent on flushing to /var/log/journal/767e071c2fc24b09b5f983d2f3fac17d is 953us for 6 entries.69client # [6785532.279200] client systemd-journald[69]: System Journal (/var/log/journal/767e071c2fc24b09b5f983d2f3fac17d) is 8M, max 4G, 3.9G free.70client # [6785532.286495] client systemd[1]: Finished Create Static Device Nodes in /dev.71client # [6785532.286776] client systemd[1]: Reached target Preparation for Local File Systems.72client # [6785532.286866] client systemd[1]: Reached target Local File Systems.73client # [6785532.287611] client systemd[1]: Listening on Boot Loader Control Service Socket.74client # [6785532.287654] client systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container75client # [6785532.288596] client systemd[1]: Starting Save Transient machine-id to Disk...76client # [6785532.288634] client systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys77client # [6785532.292686] client systemd[1]: Finished Flush Journal to Persistent Storage.78client # [6785532.294148] client systemd[1]: Starting Create System Files and Directories...79client # [6785532.308947] client systemd-tmpfiles[115]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted80client # [6785532.309119] client systemd-tmpfiles[115]: fchmod() of /var/log/journal failed: Operation not permitted81client # [6785532.309238] client systemd-tmpfiles[115]: fchmod() of /var/log/journal/767e071c2fc24b09b5f983d2f3fac17d failed: Operation not permitted82client # [6785532.309415] client systemd-tmpfiles[115]: fchmod() of /run/log/journal failed: Operation not permitted83client # [6785532.310787] client systemd[1]: Finished Create System Files and Directories.84client # [6785532.311878] client systemd[1]: Starting Rebuild Journal Catalog...85client # [6785532.312763] client systemd[1]: Starting Record System Boot/Shutdown in UTMP...86client # [6785532.325682] client systemd[1]: Finished Record System Boot/Shutdown in UTMP.87server # [6785532.254081] server systemd-journald[69]: Journal started88client # [6785532.332430] client systemd[1]: Finished Rebuild Journal Catalog.89client # [6785532.333599] client systemd[1]: Starting Update is Completed...90client # [6785532.343627] client systemd[1]: Finished Update is Completed.91client # [6785532.394300] client systemd[1]: Finished Firewall.92client # [6785532.394446] client systemd[1]: Reached target Preparation for Network.93client # [6785532.394666] client systemd[1]: Listening on Network Management Resolve Hook Socket.94server # [6785532.254130] server systemd-journald[69]: Runtime Journal (/run/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b) is 8M, max 2.5G, 2.4G free.95server # [6785532.262420] server systemd[1]: Finished Create Static Device Nodes in /dev gracefully.96server # [6785532.271972] server systemd[1]: Starting Flush Journal to Persistent Storage...97client # [6785532.395808] client systemd[1]: Starting Network Management...98server # [6785532.272841] server systemd[1]: Starting Network Name Resolution...99server # [6785532.273542] server systemd[1]: Starting Create Static Device Nodes in /dev...100server # [6785532.280735] server systemd-journald[69]: Time spent on flushing to /var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b is 996us for 6 entries.101server # [6785532.280735] server systemd-journald[69]: System Journal (/var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b) is 8M, max 4G, 3.9G free.102server # [6785532.286463] server systemd[1]: Finished Create Static Device Nodes in /dev.103server # [6785532.287135] server systemd[1]: Reached target Preparation for Local File Systems.104server # [6785532.287250] server systemd[1]: Reached target Local File Systems.105server # [6785532.288156] server systemd[1]: Listening on Boot Loader Control Service Socket.106server # [6785532.288204] server systemd[1]: Update Boot Loader Random Seed skipped, unmet condition check ConditionVirtualization=!container107server # [6785532.289061] server systemd[1]: Starting Save Transient machine-id to Disk...108server # [6785532.289096] server systemd[1]: Rule-based Manager for Device Events and Files skipped, unmet condition check ConditionPathIsReadWrite=/sys109server # [6785532.292737] server systemd[1]: Finished Flush Journal to Persistent Storage.110server # [6785532.294157] server systemd[1]: Starting Create System Files and Directories...111server # [6785532.311660] server systemd-tmpfiles[116]: Cannot set file attributes for '/var/empty', value=0x00000010, mask=0x00000010, ignoring: Operation not permitted112server # [6785532.311890] server systemd-tmpfiles[116]: fchmod() of /var/log/journal failed: Operation not permitted113server # [6785532.312075] server systemd-tmpfiles[116]: fchmod() of /var/log/journal/d2eae9343c444187b5ef88dfcf0b8f0b failed: Operation not permitted114server # [6785532.312329] server systemd-tmpfiles[116]: fchmod() of /run/log/journal failed: Operation not permitted115server # [6785532.314241] server systemd[1]: Finished Create System Files and Directories.116server # [6785532.315350] server systemd[1]: Starting Rebuild Journal Catalog...117server # [6785532.316157] server systemd[1]: Starting Record System Boot/Shutdown in UTMP...118server # [6785532.328221] server systemd[1]: Finished Record System Boot/Shutdown in UTMP.119server # [6785532.334584] server systemd[1]: Finished Rebuild Journal Catalog.120server # [6785532.335704] server systemd[1]: Starting Update is Completed...121server # [6785532.347402] server systemd[1]: Finished Update is Completed.122server # [6785532.415853] server systemd[1]: Finished Firewall.123server # [6785532.416055] server systemd[1]: Reached target Preparation for Network.124server # [6785532.416345] server systemd[1]: Listening on Network Management Resolve Hook Socket.125server # [6785532.417625] server systemd[1]: Starting Network Management...126client # [6785532.821044] client systemd[1]: Finished Save Transient machine-id to Disk.127server # [6785532.821367] server systemd[1]: Finished Save Transient machine-id to Disk.128ca # [6785532.827139] ca systemd[1]: Finished Save Transient machine-id to Disk.129ca # [6785533.237897] ca systemd-networkd[195]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted130server # [6785533.243219] server systemd[1]: etc-machine\x2did.mount: Deactivated successfully.131ca # [6785533.237989] ca systemd-networkd[195]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted132server # [6785533.256900] server systemd-networkd[186]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted133ca # [6785533.245211] ca systemd-networkd[195]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.134server # [6785533.256990] server systemd-networkd[186]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted135ca # [6785533.245374] ca systemd-networkd[195]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.136server # [6785533.264607] server systemd-networkd[186]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.137ca # [6785533.245540] ca systemd-networkd[195]: lo: Link UP138server # [6785533.264772] server systemd-networkd[186]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.139ca # [6785533.245546] ca systemd-networkd[195]: lo: Gained carrier140server # [6785533.264945] server systemd-networkd[186]: lo: Link UP141ca # [6785533.245757] ca systemd-networkd[195]: eth1: Configuring with /etc/systemd/network/40-eth1.network.142server # [6785533.264948] server systemd-networkd[186]: lo: Gained carrier143ca # [6785533.246130] ca systemd[1]: Started Network Management.144ca # [6785533.246200] ca systemd-networkd[195]: eth1: Link UP145ca # [6785533.246407] ca systemd-networkd[195]: eth1: Gained carrier146ca # [6785533.247122] ca systemd[1]: Starting Enable Persistent Storage in systemd-networkd...147ca # [6785533.254609] ca systemd[1]: etc-machine\x2did.mount: Deactivated successfully.148ca # [6785533.278371] ca systemd[1]: Finished Enable Persistent Storage in systemd-networkd.149server # [6785533.265140] server systemd-networkd[186]: eth1: Configuring with /etc/systemd/network/40-eth1.network.150server # [6785533.265525] server systemd[1]: Started Network Management.151server # [6785533.265647] server systemd-networkd[186]: eth1: Link UP152server # [6785533.265961] server systemd-networkd[186]: eth1: Gained carrier153server # [6785533.266757] server systemd[1]: Starting Enable Persistent Storage in systemd-networkd...154server # [6785533.294525] server systemd[1]: Finished Enable Persistent Storage in systemd-networkd.155client # [6785533.181608] client systemd-networkd[182]: Failed to increase receive buffer size for general netlink socket, ignoring: Operation not permitted156client # [6785533.181702] client systemd-networkd[182]: Failed to increase receive buffer size for nftables netlink socket, ignoring: Operation not permitted157client # [6785533.204579] client systemd-networkd[182]: /etc/systemd/network/99-ethernet-default-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.158client # [6785533.204744] client systemd-networkd[182]: /etc/systemd/network/99-wireless-client-dhcp.network: No valid settings found in the [Match] section, ignoring file. To match all interfaces, add Name=* in the [Match] section.159client # [6785533.204913] client systemd-networkd[182]: lo: Link UP160client # [6785533.204917] client systemd-networkd[182]: lo: Gained carrier161client # [6785533.205129] client systemd-networkd[182]: eth1: Configuring with /etc/systemd/network/40-eth1.network.162client # [6785533.205537] client systemd[1]: Started Network Management.163client # [6785533.205600] client systemd-networkd[182]: eth1: Link UP164client # [6785533.205925] client systemd-networkd[182]: eth1: Gained carrier165client # [6785533.207231] client systemd[1]: Starting Enable Persistent Storage in systemd-networkd...166client # [6785533.242584] client systemd[1]: etc-machine\x2did.mount: Deactivated successfully.167client # [6785533.252442] client systemd[1]: Finished Enable Persistent Storage in systemd-networkd.168ca # [6785533.566611] ca systemd-resolved[102]: Positive Trust Anchors:169ca # [6785533.566622] ca systemd-resolved[102]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d170ca # [6785533.566626] ca systemd-resolved[102]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16171ca # [6785533.566661] ca systemd-resolved[102]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test172ca # [6785533.589635] ca systemd-resolved[102]: Using system hostname 'ca'.173ca # [6785533.591084] ca systemd[1]: Started Network Name Resolution.174ca # [6785533.591186] ca systemd[1]: Reached target Network.175ca # [6785533.591262] ca systemd[1]: Reached target Network is Online.176ca # [6785533.591319] ca systemd[1]: Reached target System Initialization.177ca # [6785533.591589] ca systemd[1]: Started Renew ACME Certificate for ca.foo.178ca # [6785533.591625] ca systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container179ca # [6785533.591656] ca systemd[1]: Started Daily Cleanup of Temporary Directories.180ca # [6785533.591685] ca systemd[1]: Reached target Timer Units.181ca # [6785533.591860] ca systemd[1]: Listening on D-Bus System Message Bus Socket.182ca # [6785533.592053] ca systemd[1]: Listening on Nix Daemon Socket.183ca # [6785533.592218] ca systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.184ca # [6785533.592243] ca systemd[1]: Reached target Socket Units.185ca # [6785533.592304] ca systemd[1]: Reached target Basic System.186ca # [6785533.593869] ca systemd[1]: Starting Set up the ACME certificate renewal infrastructure...187ca # [6785533.594860] ca systemd[1]: Starting Import lastlog data into lastlog2 database...188ca # [6785533.594915] ca systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/ca.foo/fullchain.pem189ca # [6785533.595940] ca systemd[1]: Starting Name Service Cache Daemon (nsncd)...190ca # [6785533.597170] ca systemd[1]: Starting step-ca service...191ca # [6785533.628802] ca systemd[1]: Starting D-Bus System Message Bus...192ca # [6785533.666614] ca systemd[1]: lastlog2-import.service: Failed to spawn executor: No such file or directory193ca # [6785533.666645] ca systemd[1]: lastlog2-import.service: Failed to spawn 'start-post' task: No such file or directory194ca # [6785533.666685] ca systemd[1]: lastlog2-import.service: Failed with result 'resources'.195ca # [6785533.666748] ca systemd[1]: Failed to start Import lastlog data into lastlog2 database.196ca # [6785533.772744] ca acme-setup-privileged[201]: + set -euo pipefail197ca # [6785533.772744] ca acme-setup-privileged[201]: + cd /var/lib/acme198ca # [6785533.772744] ca acme-setup-privileged[201]: + chmod -R u=rwX,g=,o= .lego/accounts199ca # [6785533.774681] ca acme-setup-privileged[201]: + chown -R acme .lego/accounts200ca # [6785533.776180] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo201ca # [6785533.776257] ca acme-setup-privileged[201]: + '[' -d ca.foo ']'202ca # [6785533.776257] ca acme-setup-privileged[201]: + for fixpath in ca.foo .lego/ca.foo203ca # [6785533.776257] ca acme-setup-privileged[201]: + '[' -d .lego/ca.foo ']'204ca # [6785533.816437] ca nsncd[203]: Aug 26 12:15:59.869 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"205ca # [6785533.816542] ca systemd[1]: Started Name Service Cache Daemon (nsncd).206ca # [6785533.816622] ca systemd[1]: Reached target Host and Network Name Lookups.207ca # [6785533.816691] ca systemd[1]: Reached target User and Group Name Lookups.208client # [6785533.569978] client systemd-resolved[94]: Positive Trust Anchors:209client # [6785533.569990] client systemd-resolved[94]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d210client # [6785533.569994] client systemd-resolved[94]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16211client # [6785533.570036] client systemd-resolved[94]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test212client # [6785533.592544] client systemd-resolved[94]: Using system hostname 'client'.213client # [6785533.593928] client systemd[1]: Started Network Name Resolution.214client # [6785533.594004] client systemd[1]: Reached target Network.215client # [6785533.594068] client systemd[1]: Reached target System Initialization.216client # [6785533.594112] client systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container217client # [6785533.594136] client systemd[1]: Started Daily Cleanup of Temporary Directories.218client # [6785533.594152] client systemd[1]: Reached target Timer Units.219client # [6785533.594274] client systemd[1]: Listening on D-Bus System Message Bus Socket.220client # [6785533.594461] client systemd[1]: Listening on Nix Daemon Socket.221client # [6785533.594578] client systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.222client # [6785533.594599] client systemd[1]: Reached target Socket Units.223client # [6785533.594635] client systemd[1]: Reached target Basic System.224client # [6785533.595742] client systemd[1]: Starting Import lastlog data into lastlog2 database...225client # [6785533.596610] client systemd[1]: Starting Name Service Cache Daemon (nsncd)...226client # [6785533.597768] client systemd[1]: Starting D-Bus System Message Bus...227client # [6785533.643931] client systemd[1]: Finished Import lastlog data into lastlog2 database.228client # [6785533.795278] client systemd[1]: Started Name Service Cache Daemon (nsncd).229client # [6785533.795342] client systemd[1]: Reached target Host and Network Name Lookups.230client # [6785533.795445] client nsncd[189]: Aug 26 12:15:59.848 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"231client # [6785533.795401] client systemd[1]: Reached target User and Group Name Lookups.232server # [6785533.593404] server systemd-resolved[97]: Positive Trust Anchors:233server # [6785533.593415] server systemd-resolved[97]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d234server # [6785533.593419] server systemd-resolved[97]: . IN DS 38696 8 2 683d2d0acb8c9b712a1948b27f741219298d0a450d612c483af444a4c0fb2b16235server # [6785533.593454] server systemd-resolved[97]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 170.0.0.192.in-addr.arpa 171.0.0.192.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa ipv4only.arpa resolver.arpa corp home internal intranet lan local private test236server # [6785533.615770] server systemd-resolved[97]: Using system hostname 'server'.237server # [6785533.617202] server systemd[1]: Started Network Name Resolution.238server # [6785533.617292] server systemd[1]: Reached target Network.239server # [6785533.617348] server systemd[1]: Reached target Network is Online.240server # [6785533.617393] server systemd[1]: Reached target System Initialization.241server # [6785533.617619] server systemd[1]: Started Renew ACME Certificate for test.foo.242server # [6785533.617658] server systemd[1]: Discard unused filesystem blocks once a week skipped, unmet condition check ConditionVirtualization=!container243server # [6785533.617682] server systemd[1]: Started Daily Cleanup of Temporary Directories.244server # [6785533.617699] server systemd[1]: Reached target Timer Units.245server # [6785533.617841] server systemd[1]: Listening on D-Bus System Message Bus Socket.246server # [6785533.617961] server systemd[1]: Listening on Nix Daemon Socket.247server # [6785533.618072] server systemd[1]: Listening on Virtual Machine and Container Registration Service Socket.248server # [6785533.618092] server systemd[1]: Reached target Socket Units.249server # [6785533.618130] server systemd[1]: Reached target Basic System.250server # [6785533.628902] server systemd[1]: Starting Set up the ACME certificate renewal infrastructure...251server # [6785533.629926] server systemd[1]: Starting Import lastlog data into lastlog2 database...252server # [6785533.629978] server systemd[1]: nginx-config-reload.service skipped, unmet condition check ConditionPathExists=/var/lib/acme/test.foo/fullchain.pem253server # [6785533.630902] server systemd[1]: Starting Name Service Cache Daemon (nsncd)...254server # [6785533.632194] server systemd[1]: Starting D-Bus System Message Bus...255server # [6785533.647446] server systemd[1]: Finished Import lastlog data into lastlog2 database.256server # [6785533.767516] server acme-setup-privileged[192]: + set -euo pipefail257server # [6785533.767516] server acme-setup-privileged[192]: + cd /var/lib/acme258server # [6785533.767909] server acme-setup-privileged[192]: + chmod -R u=rwX,g=,o= .lego/accounts259server # [6785533.769424] server acme-setup-privileged[192]: + chown -R acme .lego/accounts260server # [6785533.770801] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo261server # [6785533.770829] server acme-setup-privileged[192]: + '[' -d test.foo ']'262server # [6785533.770829] server acme-setup-privileged[192]: + for fixpath in test.foo .lego/test.foo263server # [6785533.770829] server acme-setup-privileged[192]: + '[' -d .lego/test.foo ']'264server # [6785533.788937] server nsncd[194]: Aug 26 12:15:59.842 INFO started, config: Config { ignored_request_types: {}, worker_count: 8, handoff_timeout: 10s }, path: "/var/run/nscd/socket"265server # [6785533.789013] server systemd[1]: Started Name Service Cache Daemon (nsncd).266server # [6785533.789083] server systemd[1]: Reached target Host and Network Name Lookups.267server # [6785533.789141] server systemd[1]: Reached target User and Group Name Lookups.268server # [6785533.826405] server systemd[1]: Starting User Login Management...269server # [6785533.827296] server systemd[1]: Starting Permit User Sessions...270server # [6785533.837090] server systemd[1]: Finished Permit User Sessions.271server # [6785533.838842] server systemd[1]: Started Console Getty.272server # [6785533.838890] server systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0273server # [6785533.838912] server systemd[1]: Reached target Login Prompts.274client # [6785533.826865] client systemd[1]: Starting User Login Management...275ca # [6785533.826614] ca systemd[1]: Starting User Login Management...276client # [6785533.827897] client systemd[1]: Starting Permit User Sessions...277ca # [6785533.827515] ca systemd[1]: Starting Permit User Sessions...278client # [6785533.837093] client systemd[1]: Finished Permit User Sessions.279ca # [6785533.837353] ca systemd[1]: Finished Permit User Sessions.280client # [6785533.838391] client systemd[1]: Started Console Getty.281ca # [6785533.838433] ca systemd[1]: Started Console Getty.282client # [6785533.838444] client systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0283ca # [6785533.838479] ca systemd[1]: Getty on tty1 skipped, unmet condition check ConditionPathExists=/dev/tty0284client # [6785533.838473] client systemd[1]: Reached target Login Prompts.285ca # [6785533.838497] ca systemd[1]: Reached target Login Prompts.286client # [6785533.973203] client dbus-broker-launch[190]: Looking up NSS user entry for 'systemd-timesync'...287ca # [6785533.967802] ca dbus-broker-launch[205]: Looking up NSS user entry for 'systemd-timesync'...288client # [6785533.973875] client dbus-broker-launch[190]: NSS returned no entry for 'systemd-timesync'289ca # [6785533.969130] ca dbus-broker-launch[205]: NSS returned no entry for 'systemd-timesync'290client # [6785533.973875] client dbus-broker-launch[190]: Invalid user-name in /nix/store/zrbrcrcf4ksfm9isn90jq44dzyd6g8f3-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"291ca # [6785533.969130] ca dbus-broker-launch[205]: Invalid user-name in /nix/store/gj5k0v2rcdsvmwzrdidpx1a8s0szjk65-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"292client # [6785533.974243] client systemd[1]: Started D-Bus System Message Bus.293ca # [6785533.969521] ca systemd[1]: Started D-Bus System Message Bus.294client # [6785533.982715] client dbus-broker-launch[190]: Ready295ca # [6785533.976923] ca dbus-broker-launch[205]: Ready296server # [6785533.958953] server dbus-broker-launch[195]: Looking up NSS user entry for 'systemd-timesync'...297server # [6785533.960117] server dbus-broker-launch[195]: NSS returned no entry for 'systemd-timesync'298server # [6785533.960117] server dbus-broker-launch[195]: Invalid user-name in /nix/store/qlm5ds27nygd7kx149cwgpvarjrvks9s-system-path/share/dbus-1/system.d/org.freedesktop.timesync1.conf +16: user="systemd-timesync"299server # [6785533.960537] server systemd[1]: Started D-Bus System Message Bus.300server # [6785533.967364] server dbus-broker-launch[195]: Ready301ca: must succeed: systemctl restart acme-order-renew-ca.foo.service 302client # [6785534.492242] client systemd-logind[205]: New seat seat0.303client # [6785534.492446] client systemd[1]: Started User Login Management.304ca # [6785534.508939] ca systemd-logind[229]: New seat seat0.305client # [6785534.493781] client systemd[1]: Starting linger-users.service...306client # [6785534.532115] client systemd-networkd[182]: eth1: Gained IPv6LL307client # [6785534.572172] client systemd[1]: linger-users.service: Deactivated successfully.308client # [6785534.572339] client systemd[1]: Finished linger-users.service.309client # [6785534.572797] client systemd[1]: Reached target Multi-User System.310client # [6785534.573096] client systemd[1]: Startup finished in 2.698s.311ca # [6785534.509145] ca systemd[1]: Started User Login Management.312ca # [6785534.565226] ca systemd[1]: Starting linger-users.service...313ca # [6785534.582725] ca systemd[1]: linger-users.service: Deactivated successfully.314ca # [6785534.582827] ca systemd[1]: Finished linger-users.service.315ca # [6785534.584887] ca acme-setup-start[217]: + set -euo pipefail316ca # [6785534.584887] ca acme-setup-start[217]: + test -e ca/key.pem317ca # [6785534.585163] ca acme-setup-start[217]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local318ca # [6785534.603603] ca systemd[1]: Finished Set up the ACME certificate renewal infrastructure.319ca # [6785534.605602] ca systemd[1]: Starting Ensure certificate for ca.foo...320server # [6785534.491127] server systemd-logind[220]: New seat seat0.321server # [6785534.491340] server systemd[1]: Started User Login Management.322server # [6785534.492679] server systemd[1]: Starting linger-users.service...323server # [6785534.573345] server systemd[1]: linger-users.service: Deactivated successfully.324server # [6785534.573613] server systemd[1]: Finished linger-users.service.325server # [6785534.596835] server acme-setup-start[208]: + set -euo pipefail326server # [6785534.596835] server acme-setup-start[208]: + test -e ca/key.pem327server # [6785534.597216] server acme-setup-start[208]: + minica --ca-key ca/key.pem --ca-cert ca/cert.pem --domains selfsigned.local328server # [6785534.616241] server systemd[1]: Finished Set up the ACME certificate renewal infrastructure.329server # [6785534.617765] server systemd[1]: Starting Ensure certificate for test.foo...330ca # [6785534.782937] ca step-ca[204]: badger 2026/08/26 12:16:00 INFO: All 0 tables opened in 0s331ca # [6785534.791208] ca step-ca[204]: 2026/08/26 12:16:00 Building new tls configuration using step-ca x509 Signer Interface332ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Starting Smallstep CA/0.30.2 (linux/arm64)333ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Documentation: https://u.step.sm/docs/ca334ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Community Discord: https://u.step.sm/discord335ca # [6785534.799707] ca step-ca[204]: 2026/08/26 12:16:00 Config file: /etc/smallstep/ca.json336ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 The primary server URL is https://ca.foo:1443337ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 Root certificates are available at https://ca.foo:1443/roots.pem338ca # [6785534.799840] ca step-ca[204]: 2026/08/26 12:16:00 X.509 Root Fingerprint: 7a856cf932568ccf9b2e70d04a3169330937fca36c9d131456048caa7c0dc90f339ca # [6785534.800261] ca systemd[1]: Started step-ca service.340ca # [6785534.800471] ca step-ca[204]: 2026/08/26 12:16:00 Serving HTTPS on 0.0.0.0:1443 ...341server # [6785535.013991] server systemd-networkd[186]: eth1: Gained IPv6LL342server # [6785535.182745] server acme-test.foo-start[245]: Waiting to acquire lock in /run/acme/343server # [6785535.185996] server acme-test.foo-start[245]: + '[' -e out/acme-success ']'344server # [6785535.186047] server acme-test.foo-start[245]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=345server # [6785535.196486] server acme-test.foo-start[255]: + cd test.foo346server # [6785535.196833] server acme-test.foo-start[255]: + cp -vp cert.pem ../out/cert.pem347server # [6785535.197800] server acme-test.foo-start[256]: 'cert.pem' -> '../out/cert.pem'348server # [6785535.198036] server acme-test.foo-start[255]: + cp -vp key.pem ../out/key.pem349server # [6785535.199096] server acme-test.foo-start[255]: 'key.pem' -> '../out/key.pem'350server # [6785535.199312] server acme-test.foo-start[245]: + cat out/cert.pem ca/cert.pem351server # [6785535.200836] server acme-test.foo-start[245]: + cp ca/cert.pem out/chain.pem352server # [6785535.202351] server acme-test.foo-start[245]: + cat out/key.pem out/fullchain.pem353server # [6785535.204168] server acme-test.foo-start[245]: + for fixpath in out certificates354server # [6785535.204168] server acme-test.foo-start[245]: + '[' -d out ']'355server # [6785535.204168] server acme-test.foo-start[245]: + chmod -R u=rwX,g=rX,o= out356server # [6785535.205830] server acme-test.foo-start[245]: + chown -R acme:nginx out357server # [6785535.208604] server acme-test.foo-start[245]: + for fixpath in out certificates358server # [6785535.208628] server acme-test.foo-start[245]: + '[' -d certificates ']'359server # [6785535.211667] server systemd[1]: Finished Ensure certificate for test.foo.360server # [6785535.213202] server systemd[1]: Starting Nginx Web Server...361ca # [6785535.108132] ca systemd-networkd[195]: eth1: Gained IPv6LL362ca # [6785535.176680] ca acme-ca.foo-start[254]: Waiting to acquire lock in /run/acme/363ca # [6785535.179293] ca acme-ca.foo-start[254]: + '[' -e out/acme-success ']'364ca # [6785535.179364] ca acme-ca.foo-start[254]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=ca.foo --ip-addresses=365ca # [6785535.190243] ca acme-ca.foo-start[292]: + cd ca.foo366ca # [6785535.190556] ca acme-ca.foo-start[292]: + cp -vp cert.pem ../out/cert.pem367ca # [6785535.191740] ca acme-ca.foo-start[293]: 'cert.pem' -> '../out/cert.pem'368ca # [6785535.192090] ca acme-ca.foo-start[292]: + cp -vp key.pem ../out/key.pem369ca # [6785535.193368] ca acme-ca.foo-start[292]: 'key.pem' -> '../out/key.pem'370ca # [6785535.193612] ca acme-ca.foo-start[254]: + cat out/cert.pem ca/cert.pem371ca # [6785535.195062] ca acme-ca.foo-start[254]: + cp ca/cert.pem out/chain.pem372ca # [6785535.196647] ca acme-ca.foo-start[254]: + cat out/key.pem out/fullchain.pem373ca # [6785535.198183] ca acme-ca.foo-start[254]: + for fixpath in out certificates374ca # [6785535.198211] ca acme-ca.foo-start[254]: + '[' -d out ']'375ca # [6785535.198211] ca acme-ca.foo-start[254]: + chmod -R u=rwX,g=rX,o= out376ca # [6785535.200154] ca acme-ca.foo-start[254]: + chown -R acme:nginx out377ca # [6785535.203261] ca acme-ca.foo-start[254]: + for fixpath in out certificates378ca # [6785535.203289] ca acme-ca.foo-start[254]: + '[' -d certificates ']'379ca # [6785535.206976] ca systemd[1]: Finished Ensure certificate for ca.foo.380ca # [6785535.209793] ca systemd[1]: Starting Nginx Web Server...381server # [6785535.919414] server nginx-pre-start[267]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok382server # [6785535.919755] server nginx-pre-start[267]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful383server # [6785535.930430] server systemd[1]: Started Nginx Web Server.384server # [6785535.930827] server systemd[1]: Reached target Multi-User System.385server # [6785535.932140] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...386ca # [6785535.934246] ca nginx-pre-start[304]: nginx: the configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf syntax is ok387ca # [6785535.934570] ca nginx-pre-start[304]: nginx: configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf test is successful388ca # [6785535.941039] ca systemd[1]: Started Nginx Web Server.389ca # [6785535.942480] ca systemd[1]: Reached target Multi-User System.390ca # [6785535.944767] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...391ca # [6785536.550516] ca acme-order-renew-ca.foo-start[307]: Waiting to acquire lock in /run/acme/392ca # [6785536.553530] ca acme-order-renew-ca.foo-start[307]: + set -euo pipefail393ca # [6785536.553612] ca acme-order-renew-ca.foo-start[307]: + echo 88dc4fc401a6091a1bd9394ca # [6785536.553727] ca acme-order-renew-ca.foo-start[307]: + cmp -s domainhash.txt certificates/domainhash.txt395ca # [6785536.554911] ca acme-order-renew-ca.foo-start[307]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo run396ca # [6785536.569652] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 No key found for account none@none.tld. Generating a P256 key.397ca # [6785536.570132] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 Saved key to accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key398ca # [6785536.600078] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration="179.402µs" duration-ns=179402 fields.time="2026-08-26T12:16:02Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=ec7bf55f-39d7-4ed0-b938-043889afd872 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=399ca # [6785536.600499] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] acme: Registering account for none@none.tld400ca # [6785536.675204] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=74.57445ms duration-ns=74574450 fields.time="2026-08-26T12:16:02Z" method=HEAD name=ca nonce=N1pia1hEQWFEc3hYcXRXUzFud3pYTldnb3BEQ0Nkbkw path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=45034aa7-06e0-4507-95b6-1633379f40e9 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=401ca # [6785536.677645] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=1.380779ms duration-ns=1380779 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=d0RsUXI3cUsxV0JBVExXN2ZQY3ZqeGo4QVN6d3BVS1U path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=9abc5c22-98f7-4df5-8967-fbe492897780 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo:1443/acme/acme/account/D7v5xIHEsyxNBDGnM8ILm6BAE8QyptkV/orders\"}" size=143 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=402ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: !!!! HEADS UP !!!!403ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: Your account credentials have been saved in your404ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: configuration directory at "accounts".405ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: You should make a secure backup of this folder now. This406ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: configuration directory will also contain private keys407ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: generated by lego and certificates obtained from the ACME408ca # [6785536.678057] ca acme-order-renew-ca.foo-start[318]: server. Making regular backups of this folder is ideal.409ca # [6785536.678373] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Obtaining bundled SAN certificate410ca # [6785536.682742] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=3.951215ms duration-ns=3951215 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=T2xWeUE3U3Btd0lwT1Ayd1YxRjAwMXY1QkNuOHVYczg path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=65f4bd6d-ae1a-42cc-8895-b2ebe884f386 response="{\"id\":\"uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:16:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:15:02Z\",\"notAfter\":\"2026-11-24T12:16:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize\"}" size=392 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=411ca # [6785536.741699] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=1.948668ms duration-ns=1948668 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=ck9NUnp0RVlpcDg1Q291UGc3T1BXM3ZRamtodFltMDU path=/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6f92427a-a8a6-4f40-b91c-42e20ed58829 response="{\"identifier\":{\"type\":\"dns\",\"value\":\"ca.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/rq6cv9uCicGVXZnieTJKEf8BImckd7tn\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/Cdom49XcQOqA6Ex4r4Wy8L5q4u0Miz9D\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:16:02Z\"}" size=719 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=412ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] AuthURL: https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd413ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Could not find solver for: tls-alpn-01414ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: use http-01 solver415ca # [6785536.741999] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Trying to solve HTTP-01416ca # [6785536.745827] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=3.377568ms duration-ns=3377568 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=QzV6aHJBbEk0c0NXbHFIbFg4aHNlN1A2VmxZaElCVFk path=/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=6a44c20b-bac7-42ce-9411-ddcac93c8b56 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"l27M4lucLdtaIwaVUfC2GqAjlbQiahTT\",\"validated\":\"2026-08-26T12:16:02Z\",\"url\":\"https://ca.foo:1443/acme/acme/challenge/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd/D42RXDrvMo40aTkE7MvRQBJ0Ce2RkJvN\"}" size=228 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=417ca # [6785536.746200] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] The server validated our request418ca # [6785536.746317] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] acme: Validations succeeded; requesting certificates419ca # [6785536.754241] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info duration=6.183247ms duration-ns=6183247 fields.time="2026-08-26T12:16:02Z" method=POST name=ca nonce=U0JJeU5nVVI2ZGlJVnlCc3BQTTBVeUdQOFRhU0tTVFQ path=/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=4050e44e-fa68-4234-a10b-81b8c15bf85c response="{\"id\":\"uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:16:02Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"ca.foo\"}],\"notBefore\":\"2026-08-26T12:15:02Z\",\"notAfter\":\"2026-11-24T12:16:02Z\",\"authorizations\":[\"https://ca.foo:1443/acme/acme/authz/XG0wS6ZsLKmT4s3YRQareDDl5DhTpRCd\"],\"finalize\":\"https://ca.foo:1443/acme/acme/order/uTV1wruqVLnvaqDaqgrKWV70Vu2S2igp/finalize\",\"certificate\":\"https://ca.foo:1443/acme/acme/certificate/M6eJzLDpNSnlYazXMmfnmWeEPRfptCFH\"}" size=481 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=420ca # [6785536.756675] ca step-ca[204]: time="2026-08-26T12:16:02Z" level=info certificate="MIIB1DCCAXqgAwIBAgIRAMnNYbZb4rpPiy7WTZga9bYwCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI2MTIxNTAyWhcNMjYxMTI0MTIxNjAyWjARMQ8wDQYDVQQDEwZjYS5mb28wWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAS7NDuDqGo9+NaysmkgI07KbwbD9RiszeM8Xu5Wc4NpJHoG1e7O1omITymAsoOxvFqv3cSG7EXR8i/Yt9PnNT/Zo4GkMIGhMA4GA1UdDwEB/wQEAwIHgDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFAHjBREIJeX40rDu2mof7KpMewMjMB8GA1UdIwQYMBaAFFhS1wyNYKB84hY5AYxPLJisTA6QMBEGA1UdEQQKMAiCBmNhLmZvbzAdBgwrBgEEAYKkZMYoQAEEDTALAgEGBARhY21lBAAwCgYIKoZIzj0EAwIDSAAwRQIgV8/5PXUx8y93koYpiLfvuZY9B7yvb13ZuqwT2oLGSbQCIQD9I2QZUarg2XIm0qk5iC7DS0JsMgWW8JUSf3UrlPmOKQ==" duration=1.4249ms duration-ns=1424900 fields.time="2026-08-26T12:16:02Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=amdVQklwME8zenFwV2l3Y1AwQThjWk40bkhvcVk5Tkk path=/acme/acme/certificate/M6eJzLDpNSnlYazXMmfnmWeEPRfptCFH protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address="2001:db8:1::1" request-id=0728d696-d04b-492a-ae52-2e15d52d2631 sans="map[dns:[ca.foo]]" serial=268241229850462094882117627845669483958 size=1344 status=200 subject=ca.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-26T12:15:02Z" valid-to="2026-11-24T12:16:02Z"421ca # [6785536.756872] ca acme-order-renew-ca.foo-start[318]: 2026/08/26 12:16:02 [INFO] [ca.foo] Server responded with a certificate.422ca # [6785536.760749] ca acme-order-renew-ca.foo-start[307]: + mv domainhash.txt certificates/423ca # [6785536.762650] ca acme-order-renew-ca.foo-start[307]: + touch out/acme-success424ca # [6785536.764667] ca acme-order-renew-ca.foo-start[307]: + cmp -s certificates/ca.foo.crt out/fullchain.pem425ca # [6785536.765714] ca acme-order-renew-ca.foo-start[307]: + touch out/renewed426ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: + echo Installing new certificate427ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: Installing new certificate428ca # [6785536.767100] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.crt out/fullchain.pem429ca # [6785536.768909] ca acme-order-renew-ca.foo-start[350]: 'certificates/ca.foo.crt' -> 'out/fullchain.pem'430ca # [6785536.769268] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.key out/key.pem431ca # [6785536.770454] ca acme-order-renew-ca.foo-start[351]: 'certificates/ca.foo.key' -> 'out/key.pem'432ca # [6785536.770760] ca acme-order-renew-ca.foo-start[307]: + cp -vp certificates/ca.foo.issuer.crt out/chain.pem433ca # [6785536.772578] ca acme-order-renew-ca.foo-start[352]: 'certificates/ca.foo.issuer.crt' -> 'out/chain.pem'434ca # [6785536.772887] ca acme-order-renew-ca.foo-start[307]: + ln -sf fullchain.pem out/cert.pem435ca # [6785536.774346] ca acme-order-renew-ca.foo-start[307]: + cat out/key.pem out/fullchain.pem436ca # [6785536.776310] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates437ca # [6785536.776310] ca acme-order-renew-ca.foo-start[307]: + '[' -d out ']'438ca # [6785536.776407] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= out439ca # [6785536.778146] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx out440ca # [6785536.780794] ca acme-order-renew-ca.foo-start[307]: + for fixpath in out certificates441ca # [6785536.780794] ca acme-order-renew-ca.foo-start[307]: + '[' -d certificates ']'442ca # [6785536.780892] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=rX,o= certificates443ca # [6785536.782261] ca acme-order-renew-ca.foo-start[307]: + chown -R acme:nginx certificates444ca # [6785536.784944] ca acme-order-renew-ca.foo-start[307]: + chmod -R u=rwX,g=,o= accounts/.445server # [6785536.527567] server acme-order-renew-test.foo-start[270]: Waiting to acquire lock in /run/acme/446server # [6785536.530949] server acme-order-renew-test.foo-start[270]: + set -euo pipefail447server # [6785536.531023] server acme-order-renew-test.foo-start[270]: + echo ad12aa6741ce4bd2c108448server # [6785536.531135] server acme-order-renew-test.foo-start[270]: + cmp -s domainhash.txt certificates/domainhash.txt449server # [6785536.532222] server acme-order-renew-test.foo-start[270]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run450server # [6785536.565463] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 No key found for account none@none.tld. Generating a P256 key.451server # [6785536.565894] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 Saved key to accounts/ca.foo/none@none.tld/keys/none@none.tld.key452server # [6785536.601119] server acme-order-renew-test.foo-start[281]: 2026/08/26 12:16:02 Could not create client: get directory at 'https://ca.foo/acme/acme/directory': Get "https://ca.foo/acme/acme/directory": GET https://ca.foo/acme/acme/directory giving up after 1 attempt(s): Get "https://ca.foo/acme/acme/directory": tls: failed to verify certificate: x509: certificate signed by unknown authority453server # [6785536.602739] server acme-order-renew-test.foo-start[270]: + echo Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.454server # [6785536.602739] server acme-order-renew-test.foo-start[270]: Failed to fetch certificates. This may mean your DNS records are set up incorrectly. Self-signed certs are in place and dependant services will still start.455server # [6785536.602739] server acme-order-renew-test.foo-start[270]: + exit 10456server # [6785536.608534] server systemd[1]: acme-order-renew-test.foo.service: Main process exited, code=exited, status=10/n/a457server # [6785536.608628] server systemd[1]: acme-order-renew-test.foo.service: Failed with result 'exit-code'.458server # [6785536.608916] server systemd[1]: Failed to start Order (and renew) ACME certificate for test.foo.459server # [6785536.609318] server systemd[1]: Startup finished in 4.733s.460ca # [6785536.909722] ca systemd[1]: Reloading Nginx Web Server...461ca # [6785536.913553] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.462ca # [6785536.913722] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.463ca # [6785538.237724] ca nginx[368]: nginx: the configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf syntax is ok464ca # [6785538.238121] ca nginx[368]: nginx: configuration file /nix/store/y7l31xmgdb36n6qsx9xzk3vs64xjpv8v-nginx.conf test is successful465ca # [6785538.821446] ca systemd[1]: Reloaded Nginx Web Server.466ca # [6785538.821825] ca systemd[1]: Startup finished in 6.936s.467ca # [6785539.101950] ca systemd[1]: Starting Order (and renew) ACME certificate for ca.foo...468ca: (finished: must succeed: systemctl restart acme-order-renew-ca.foo.service , in 5.69 seconds)469ca # [6785539.899104] ca acme-order-renew-ca.foo-start[383]: Waiting to acquire lock in /run/acme/470ca # [6785539.901727] ca acme-order-renew-ca.foo-start[383]: + set -euo pipefail471ca # [6785539.901805] ca acme-order-renew-ca.foo-start[383]: + echo 88dc4fc401a6091a1bd9472ca # [6785539.901917] ca acme-order-renew-ca.foo-start[383]: + cmp -s domainhash.txt certificates/domainhash.txt473ca # [6785539.903117] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.key ']'474ca # [6785539.903159] ca acme-order-renew-ca.foo-start[383]: + '[' -e certificates/ca.foo.crt ']'475ca # [6785539.903544] ca acme-order-renew-ca.foo-start[391]: ++ find accounts -name none@none.tld.key476ca # [6785539.905744] ca acme-order-renew-ca.foo-start[383]: + '[' -n accounts/ca.foo_1443/none@none.tld/keys/none@none.tld.key ']'477ca # [6785539.905782] ca acme-order-renew-ca.foo-start[383]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo:1443/acme/acme/directory --key-type ec256 -d ca.foo renew --no-random-sleep --dynamic478ca # [6785539.943964] ca step-ca[204]: time="2026-08-26T12:16:05Z" level=info duration="89.001µs" duration-ns=89001 fields.time="2026-08-26T12:16:05Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="2001:db8:1::1" request-id=2c4d91d3-ca4a-4440-9bf9-9f422da1ea95 response="{\"newNonce\":\"https://ca.foo:1443/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo:1443/acme/acme/new-account\",\"newOrder\":\"https://ca.foo:1443/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo:1443/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo:1443/acme/acme/key-change\"}" size=277 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=479ca # [6785539.944412] ca acme-order-renew-ca.foo-start[392]: 2026/08/26 12:16:05 [WARN] [ca.foo] acme: renewalInfo[get/post]: server does not advertise a renewal info endpoint480ca # [6785539.944412] ca acme-order-renew-ca.foo-start[392]: 2026/08/26 12:16:05 [INFO] [ca.foo] The certificate expires at 2026-11-24T12:16:02Z, the renewal can be performed in 1439h59m36.002541756s: no renewal.481ca # [6785539.945067] ca acme-order-renew-ca.foo-start[383]: + mv domainhash.txt certificates/482ca # [6785539.946873] ca acme-order-renew-ca.foo-start[383]: + touch out/acme-success483ca # [6785539.948429] ca acme-order-renew-ca.foo-start[383]: + cmp -s certificates/ca.foo.crt out/fullchain.pem484ca # [6785539.949537] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates485ca # [6785539.949537] ca acme-order-renew-ca.foo-start[383]: + '[' -d out ']'486ca # [6785539.949608] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= out487ca # [6785539.950967] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx out488ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + for fixpath in out certificates489ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + '[' -d certificates ']'490ca # [6785539.953757] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=rX,o= certificates491ca # [6785539.955186] ca acme-order-renew-ca.foo-start[383]: + chown -R acme:nginx certificates492ca # [6785539.957713] ca acme-order-renew-ca.foo-start[383]: + chmod -R u=rwX,g=,o= accounts/.493ca # [6785540.134539] ca systemd[1]: acme-order-renew-ca.foo.service: Deactivated successfully.494ca # [6785540.140263] ca systemd[1]: Finished Order (and renew) ACME certificate for ca.foo.495server: must succeed: systemctl restart acme-test.foo.service496server # [6785543.161181] server systemd[1]: acme-test.foo.service: Deactivated successfully.497server # [6785543.161398] server systemd[1]: Stopped Ensure certificate for test.foo.498server # [6785543.162309] server systemd[1]: Stopping Ensure certificate for test.foo...499server # [6785543.163960] server systemd[1]: Starting Ensure certificate for test.foo...500server: (finished: must succeed: systemctl restart acme-test.foo.service, in 1.24 seconds)501client: waiting for success: curl -v https://test.foo502* Host test.foo:443 was resolved.503* IPv6: 2001:db8:1::3504* IPv4: 192.168.1.3505* Trying [2001:db8:1::3]:443...506* ALPN: curl offers h2,http/1.1507} [5 bytes data]508* TLSv1.3 (OUT), TLS handshake, Client hello (1):509} [1552 bytes data]510* SSL Trust Anchors:511* OpenSSL default paths (fallback)512{ [5 bytes data]513* TLSv1.3 (IN), TLS handshake, Server hello (2):514{ [1210 bytes data]515* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):516{ [1 bytes data]517* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):518{ [19 bytes data]519* TLSv1.3 (IN), TLS handshake, Certificate (11):520{ [1008 bytes data]521* TLSv1.3 (IN), TLS handshake, CERT verify (15):522{ [110 bytes data]523* TLSv1.3 (IN), TLS handshake, Finished (20):524{ [52 bytes data]525* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):526} [1 bytes data]527* TLSv1.3 (OUT), TLS handshake, Finished (20):528} [52 bytes data]529* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey530* ALPN: server accepted h2531* Server certificate:532* subject: CN=test.foo533* start date: Aug 26 12:16:01 2026 GMT534* expire date: Sep 25 12:16:01 2028 GMT535* issuer: CN=minica root ca 4bb5c8536* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384537* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384538* subjectAltName: "test.foo" matches cert's "test.foo"539* OpenSSL verify result: 13540* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)541* closing connection #0542curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)543More details here: https://curl.se/docs/sslcerts.html544545curl failed to verify the legitimacy of the server and therefore could not546establish a secure connection to it. To learn more about this situation and547how to fix it, please visit the webpage mentioned above.548server # [6785544.338381] server acme-test.foo-start[315]: Waiting to acquire lock in /run/acme/549server # [6785544.341113] server acme-test.foo-start[315]: + '[' -e out/acme-success ']'550server # [6785544.341152] server acme-test.foo-start[315]: + minica --ca-cert=ca/cert.pem --ca-key=ca/key.pem --domains=test.foo --ip-addresses=551server # [6785544.351910] server acme-test.foo-start[325]: + cd test.foo552server # [6785544.352320] server acme-test.foo-start[325]: + cp -vp cert.pem ../out/cert.pem553server # [6785544.353502] server acme-test.foo-start[326]: 'cert.pem' -> '../out/cert.pem'554server # [6785544.353884] server acme-test.foo-start[325]: + cp -vp key.pem ../out/key.pem555server # [6785544.355396] server acme-test.foo-start[325]: 'key.pem' -> '../out/key.pem'556server # [6785544.355477] server acme-test.foo-start[315]: + cat out/cert.pem ca/cert.pem557server # [6785544.356992] server acme-test.foo-start[315]: + cp ca/cert.pem out/chain.pem558server # [6785544.358501] server acme-test.foo-start[315]: + cat out/key.pem out/fullchain.pem559server # [6785544.360069] server acme-test.foo-start[315]: + for fixpath in out certificates560server # [6785544.360069] server acme-test.foo-start[315]: + '[' -d out ']'561server # [6785544.360111] server acme-test.foo-start[315]: + chmod -R u=rwX,g=rX,o= out562server # [6785544.361490] server acme-test.foo-start[315]: + chown -R acme:nginx out563server # [6785544.363905] server acme-test.foo-start[315]: + for fixpath in out certificates564server # [6785544.363927] server acme-test.foo-start[315]: + '[' -d certificates ']'565server # [6785544.384577] server systemd[1]: Finished Ensure certificate for test.foo.566server # [6785544.387310] server systemd[1]: Starting Order (and renew) ACME certificate for test.foo...567* Host test.foo:443 was resolved.568* IPv6: 2001:db8:1::3569* IPv4: 192.168.1.3570* Trying [2001:db8:1::3]:443...571* ALPN: curl offers h2,http/1.1572} [5 bytes data]573* TLSv1.3 (OUT), TLS handshake, Client hello (1):574} [1552 bytes data]575* SSL Trust Anchors:576* OpenSSL default paths (fallback)577{ [5 bytes data]578* TLSv1.3 (IN), TLS handshake, Server hello (2):579{ [1210 bytes data]580* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):581{ [1 bytes data]582* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):583{ [19 bytes data]584* TLSv1.3 (IN), TLS handshake, Certificate (11):585{ [1008 bytes data]586* TLSv1.3 (IN), TLS handshake, CERT verify (15):587{ [111 bytes data]588* TLSv1.3 (IN), TLS handshake, Finished (20):589{ [52 bytes data]590* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):591} [1 bytes data]592* TLSv1.3 (OUT), TLS handshake, Finished (20):593} [52 bytes data]594* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey595* ALPN: server accepted h2596* Server certificate:597* subject: CN=test.foo598* start date: Aug 26 12:16:01 2026 GMT599* expire date: Sep 25 12:16:01 2028 GMT600* issuer: CN=minica root ca 4bb5c8601* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384602* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384603* subjectAltName: "test.foo" matches cert's "test.foo"604* OpenSSL verify result: 13605* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)606* closing connection #0607curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)608More details here: https://curl.se/docs/sslcerts.html609610curl failed to verify the legitimacy of the server and therefore could not611establish a secure connection to it. To learn more about this situation and612how to fix it, please visit the webpage mentioned above.613server # [6785545.431972] server acme-order-renew-test.foo-start[333]: Waiting to acquire lock in /run/acme/614server # [6785545.434467] server acme-order-renew-test.foo-start[333]: + set -euo pipefail615server # [6785545.434548] server acme-order-renew-test.foo-start[333]: + echo ad12aa6741ce4bd2c108616server # [6785545.434668] server acme-order-renew-test.foo-start[333]: + cmp -s domainhash.txt certificates/domainhash.txt617server # [6785545.435886] server acme-order-renew-test.foo-start[333]: + lego --accept-tos --path . --email none@none.tld --http --http.webroot /var/lib/acme/acme-challenge --server https://ca.foo/acme/acme/directory --key-type ec256 -d test.foo run618server # [6785545.475046] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] acme: Registering account for none@none.tld619server # [6785545.483084] server acme-order-renew-test.foo-start[341]: !!!! HEADS UP !!!!620server # [6785545.483084] server acme-order-renew-test.foo-start[341]: Your account credentials have been saved in your621server # [6785545.483084] server acme-order-renew-test.foo-start[341]: configuration directory at "accounts".622server # [6785545.483084] server acme-order-renew-test.foo-start[341]: You should make a secure backup of this folder now. This623server # [6785545.483084] server acme-order-renew-test.foo-start[341]: configuration directory will also contain private keys624server # [6785545.483084] server acme-order-renew-test.foo-start[341]: generated by lego and certificates obtained from the ACME625server # [6785545.483084] server acme-order-renew-test.foo-start[341]: server. Making regular backups of this folder is ideal.626server # [6785545.483316] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Obtaining bundled SAN certificate627server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] AuthURL: https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U628server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Could not find solver for: tls-alpn-01629server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: use http-01 solver630server # [6785545.548145] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Trying to solve HTTP-01631server # [6785545.554011] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] The server validated our request632server # [6785545.554100] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] acme: Validations succeeded; requesting certificates633server # [6785545.570670] server acme-order-renew-test.foo-start[341]: 2026/08/26 12:16:11 [INFO] [test.foo] Server responded with a certificate.634server # [6785545.576300] server acme-order-renew-test.foo-start[333]: + mv domainhash.txt certificates/635server # [6785545.578221] server acme-order-renew-test.foo-start[333]: + touch out/acme-success636server # [6785545.579993] server acme-order-renew-test.foo-start[333]: + cmp -s certificates/test.foo.crt out/fullchain.pem637server # [6785545.580978] server acme-order-renew-test.foo-start[333]: + touch out/renewed638server # [6785545.582527] server acme-order-renew-test.foo-start[333]: + echo Installing new certificate639server # [6785545.582527] server acme-order-renew-test.foo-start[333]: Installing new certificate640server # [6785545.582571] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.crt out/fullchain.pem641server # [6785545.584131] server acme-order-renew-test.foo-start[373]: 'certificates/test.foo.crt' -> 'out/fullchain.pem'642server # [6785545.584368] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.key out/key.pem643server # [6785545.585993] server acme-order-renew-test.foo-start[374]: 'certificates/test.foo.key' -> 'out/key.pem'644server # [6785545.586244] server acme-order-renew-test.foo-start[333]: + cp -vp certificates/test.foo.issuer.crt out/chain.pem645server # [6785545.588247] server acme-order-renew-test.foo-start[375]: 'certificates/test.foo.issuer.crt' -> 'out/chain.pem'646server # [6785545.588573] server acme-order-renew-test.foo-start[333]: + ln -sf fullchain.pem out/cert.pem647server # [6785545.590360] server acme-order-renew-test.foo-start[333]: + cat out/key.pem out/fullchain.pem648server # [6785545.592011] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates649server # [6785545.592034] server acme-order-renew-test.foo-start[333]: + '[' -d out ']'650server # [6785545.592051] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= out651server # [6785545.593750] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx out652server # [6785545.605638] server acme-order-renew-test.foo-start[333]: + for fixpath in out certificates653server # [6785545.605725] server acme-order-renew-test.foo-start[333]: + '[' -d certificates ']'654server # [6785545.605725] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=rX,o= certificates655server # [6785545.607602] server acme-order-renew-test.foo-start[333]: + chown -R acme:nginx certificates656server # [6785545.615011] server acme-order-renew-test.foo-start[333]: + chmod -R u=rwX,g=,o= accounts/.657ca # [6785545.474621] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration="41.281µs" duration-ns=41281 fields.time="2026-08-26T12:16:11Z" method=GET name=ca path=/acme/acme/directory protocol=HTTP/1.1 referer= remote-address="::1" request-id=52ad4777-54ce-4962-970b-ac80fa841065 response="{\"newNonce\":\"https://ca.foo/acme/acme/new-nonce\",\"newAccount\":\"https://ca.foo/acme/acme/new-account\",\"newOrder\":\"https://ca.foo/acme/acme/new-order\",\"revokeCert\":\"https://ca.foo/acme/acme/revoke-cert\",\"keyChange\":\"https://ca.foo/acme/acme/key-change\"}" size=252 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=658ca # [6785545.478089] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration="837.131µs" duration-ns=837131 fields.time="2026-08-26T12:16:11Z" method=HEAD name=ca nonce=ZHlVTVlhUkl2S2ZHaEhiM2hOaVM1cGdaWmh6b0I3V0U path=/acme/acme/new-nonce protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=f1d03e5f-cf5c-47cf-9550-77d83a2655a6 size=0 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=659ca # [6785545.482672] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=2.082789ms duration-ns=2082789 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=RWFadzBpN01QcXhseFUxZDY3OTN5emFFaGVhZk1OcXI path=/acme/acme/new-account protocol=HTTP/1.1 referer= remote-address="::1" request-id=881bd361-d120-4be0-b8d1-ffdceb922997 response="{\"contact\":[\"mailto:none@none.tld\"],\"status\":\"valid\",\"orders\":\"https://ca.foo/acme/acme/account/8axzW5GdqbXyPn7FR20OjyL6wTP4ERqP/orders\"}" size=138 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=660ca # [6785545.487310] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=2.314313ms duration-ns=2314313 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=cVR6VmlvRTR5OXBtdThnOGhyTGVDbkdtSXZ6cHUwUFE path=/acme/acme/new-order protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=b11d283c-f3e3-4d9c-bf2b-e92a1814cf36 response="{\"id\":\"JAULuF60olOy5jd5EVSXhiSX0mCAXg5h\",\"status\":\"pending\",\"expires\":\"2026-08-27T12:16:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:15:11Z\",\"notAfter\":\"2026-11-24T12:16:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U\"],\"finalize\":\"https://ca.foo/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize\"}" size=384 status=201 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=661ca # [6785545.547714] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=1.40666ms duration-ns=1406660 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=MkhrRVJFMkN6S2NFOU11a2ZYUkdWUEliWlVYUVBkRUQ path=/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U protocol=HTTP/1.1 referer= remote-address="::1" request-id=2cedd9ec-0a6a-41a2-9aae-b61294dfc20f response="{\"identifier\":{\"type\":\"dns\",\"value\":\"test.foo\"},\"status\":\"pending\",\"challenges\":[{\"type\":\"dns-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/3evSENTl9XNAxeyLpMgdEw1HMY2yM3OT\"},{\"type\":\"http-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux\"},{\"type\":\"tls-alpn-01\",\"status\":\"pending\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/xOJz1YZ11TfuXWnAuLzzliXvMuY26hN2\"}],\"wildcard\":false,\"expires\":\"2026-08-27T12:16:11Z\"}" size=706 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=662ca # [6785545.553411] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=3.245005ms duration-ns=3245005 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=MnlrNTFVM2NUN0M5RDRRbmNaSmJCSUpvazNmZ2hib0Q path=/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux protocol=HTTP/1.1 referer= remote-address=127.0.0.1 request-id=b33289a2-d757-48e8-92c9-6c6ae7a1bfb7 response="{\"type\":\"http-01\",\"status\":\"valid\",\"token\":\"3AkNm0wANSBhMgeJUfWWvlACNEyujZDx\",\"validated\":\"2026-08-26T12:16:11Z\",\"url\":\"https://ca.foo/acme/acme/challenge/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U/HvdtXgNyMLJZdPXPz2qBZ4yYw8oI98ux\"}" size=223 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=663ca # [6785545.566104] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info duration=7.976392ms duration-ns=7976392 fields.time="2026-08-26T12:16:11Z" method=POST name=ca nonce=a29ldHhhQ05ZVGNPZXM4cW95d2ZCOVUxclBzd3VCTW4 path=/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize protocol=HTTP/1.1 referer= remote-address="::1" request-id=19d2fdcf-4df1-4f19-8882-3640e9568a24 response="{\"id\":\"JAULuF60olOy5jd5EVSXhiSX0mCAXg5h\",\"status\":\"valid\",\"expires\":\"2026-08-27T12:16:11Z\",\"identifiers\":[{\"type\":\"dns\",\"value\":\"test.foo\"}],\"notBefore\":\"2026-08-26T12:15:11Z\",\"notAfter\":\"2026-11-24T12:16:11Z\",\"authorizations\":[\"https://ca.foo/acme/acme/authz/lFaJuAh8QZ7u2JUrcQ6iVlFDw4POer0U\"],\"finalize\":\"https://ca.foo/acme/acme/order/JAULuF60olOy5jd5EVSXhiSX0mCAXg5h/finalize\",\"certificate\":\"https://ca.foo/acme/acme/certificate/UIOBwsXwlIyzqfDa2wY0BMPSfTsp18pP\"}" size=468 status=200 user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id=664ca # [6785545.570228] ca step-ca[204]: time="2026-08-26T12:16:11Z" level=info certificate="MIIB2DCCAX6gAwIBAgIRAMb2nDRdoZMAEpuFB7BL/nswCgYIKoZIzj0EAwIwHzEdMBsGA1UEAxMUQ2xhbiBJbnRlcm1lZGlhdGUgQ0EwHhcNMjYwODI2MTIxNTExWhcNMjYxMTI0MTIxNjExWjATMREwDwYDVQQDEwh0ZXN0LmZvbzBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABKP9hI3Ab1RpZXLGuKmYvTlv6yHfjBJ8ZCqWK3yitJ6VfABA8dU7NfcxAXVoB6oN1fHXN6BIq+v5QoAHGME+2h6jgaYwgaMwDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAdBgNVHQ4EFgQUaAyQMu+U6L2ivGEw8sxJPUQ9OnEwHwYDVR0jBBgwFoAUWFLXDI1goHziFjkBjE8smKxMDpAwEwYDVR0RBAwwCoIIdGVzdC5mb28wHQYMKwYBBAGCpGTGKEABBA0wCwIBBgQEYWNtZQQAMAoGCCqGSM49BAMCA0gAMEUCIGSOFOqNqXnW4z/a/4T3BZSlzEduRtQZET599LxX11U1AiEA3985pVwCpYGuP4eq3P1Tzl7ba0Qrk/bz6NdRLcTUVlc=" duration=1.228098ms duration-ns=1228098 fields.time="2026-08-26T12:16:11Z" issuer="Clan Intermediate CA" method=POST name=ca nonce=R2tyV2J1Ynlhckp2RUNuQlVFb3J1b3lMMXd1Y0djZ1g path=/acme/acme/certificate/UIOBwsXwlIyzqfDa2wY0BMPSfTsp18pP protocol=HTTP/1.1 provisioner=acme public-key="ECDSA P-256" referer= remote-address=127.0.0.1 request-id=a46b932a-1677-4503-938c-f24bbbae2458 sans="map[dns:[test.foo]]" serial=264467616397352967993460830776503041659 size=1348 status=200 subject=test.foo user-agent="lego-cli/4.35.2 xenolf-acme/4.35.2 (release; linux; arm64)" user-id= valid-from="2026-08-26T12:15:11Z" valid-to="2026-11-24T12:16:11Z"665server # [6785545.827676] server systemd[1]: Reloading Nginx Web Server...666server # [6785545.831559] server systemd[1]: acme-order-renew-test.foo.service: Deactivated successfully.667server # [6785545.831748] server systemd[1]: Finished Order (and renew) ACME certificate for test.foo.668* Host test.foo:443 was resolved.669* IPv6: 2001:db8:1::3670* IPv4: 192.168.1.3671* Trying [2001:db8:1::3]:443...672* ALPN: curl offers h2,http/1.1673} [5 bytes data]674* TLSv1.3 (OUT), TLS handshake, Client hello (1):675} [1552 bytes data]676* SSL Trust Anchors:677* OpenSSL default paths (fallback)678{ [5 bytes data]679* TLSv1.3 (IN), TLS handshake, Server hello (2):680{ [1210 bytes data]681* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):682{ [1 bytes data]683* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):684{ [19 bytes data]685* TLSv1.3 (IN), TLS handshake, Certificate (11):686{ [1008 bytes data]687* TLSv1.3 (IN), TLS handshake, CERT verify (15):688{ [112 bytes data]689* TLSv1.3 (IN), TLS handshake, Finished (20):690{ [52 bytes data]691* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):692} [1 bytes data]693* TLSv1.3 (OUT), TLS handshake, Finished (20):694} [52 bytes data]695* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey696* ALPN: server accepted h2697* Server certificate:698* subject: CN=test.foo699* start date: Aug 26 12:16:01 2026 GMT700* expire date: Sep 25 12:16:01 2028 GMT701* issuer: CN=minica root ca 4bb5c8702* Certificate level 0: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384703* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384704* subjectAltName: "test.foo" matches cert's "test.foo"705* OpenSSL verify result: 13706* SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)707* closing connection #0708curl: (60) SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)709More details here: https://curl.se/docs/sslcerts.html710711curl failed to verify the legitimacy of the server and therefore could not712establish a secure connection to it. To learn more about this situation and713how to fix it, please visit the webpage mentioned above.714server # [6785546.546111] server nginx[391]: nginx: the configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf syntax is ok715server # [6785546.546479] server nginx[391]: nginx: configuration file /nix/store/41f929z481vklb35mvyivnvwnnf9i59x-nginx.conf test is successful716server # [6785547.181700] server systemd[1]: Reloaded Nginx Web Server.717* Host test.foo:443 was resolved.718* IPv6: 2001:db8:1::3719* IPv4: 192.168.1.3720* Trying [2001:db8:1::3]:443...721* ALPN: curl offers h2,http/1.1722} [5 bytes data]723* TLSv1.3 (OUT), TLS handshake, Client hello (1):724} [1552 bytes data]725* SSL Trust Anchors:726* OpenSSL default paths (fallback)727{ [5 bytes data]728* TLSv1.3 (IN), TLS handshake, Server hello (2):729{ [1210 bytes data]730* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):731{ [1 bytes data]732* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):733{ [19 bytes data]734* TLSv1.3 (IN), TLS handshake, Certificate (11):735{ [931 bytes data]736* TLSv1.3 (IN), TLS handshake, CERT verify (15):737{ [79 bytes data]738* TLSv1.3 (IN), TLS handshake, Finished (20):739{ [52 bytes data]740* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):741} [1 bytes data]742* TLSv1.3 (OUT), TLS handshake, Finished (20):743} [52 bytes data]744* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519MLKEM768 / id-ecPublicKey745* ALPN: server accepted h2746* Server certificate:747* subject: CN=test.foo748* start date: Aug 26 12:15:11 2026 GMT749* expire date: Nov 24 12:16:11 2026 GMT750* issuer: CN=Clan Intermediate CA751* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256752* Certificate level 1: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256753* Certificate level 2: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA256754* subjectAltName: "test.foo" matches cert's "test.foo"755* OpenSSL verify result: 0756* SSL certificate verified via OpenSSL.757* Established connection to test.foo (2001:db8:1::3 port 443) from 2001:db8:1::2 port 53342 758 % Total % Received % Xferd Average Speed Time Time Time Current759 Dload Upload Total Spent Left Speed760 0 0 0 0 0 0 0 0 0* using HTTP/2761* [HTTP/2] [1] OPENED stream for https://test.foo/762* [HTTP/2] [1] [:method: GET]763* [HTTP/2] [1] [:scheme: https]764* [HTTP/2] [1] [:authority: test.foo]765* [HTTP/2] [1] [:path: /]766* [HTTP/2] [1] [user-agent: curl/8.21.0]767* [HTTP/2] [1] [accept: */*]768} [5 bytes data]769770771772773774* Request completely sent off775{ [5 bytes data]776* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):777{ [265 bytes data]778* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):779{ [265 bytes data]780781782783784785786787{ [5 bytes data]788100 20 100 20 0 0 797 0 0789* Connection #0 to host test.foo:443 left intact790client: (finished: waiting for success: curl -v https://test.foo, in 3.16 seconds)791client: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2792Certificate:793 Data:794 Version: 3 (0x2)795 Serial Number:796 c6:f6:9c:34:5d:a1:93:00:12:9b:85:07:b0:4b:fe:7b797 Signature Algorithm: ecdsa-with-SHA256798 Issuer: CN=Clan Intermediate CA799 Validity800 Not Before: Aug 26 12:15:11 2026 GMT801 Not After : Nov 24 12:16:11 2026 GMT802 Subject: CN=test.foo803 Subject Public Key Info:804 Public Key Algorithm: id-ecPublicKey805 Public-Key: (256 bit)806 pub:807 04:a3:fd:84:8d:c0:6f:54:69:65:72:c6:b8:a9:98:808 bd:39:6f:eb:21:df:8c:12:7c:64:2a:96:2b:7c:a2:809 b4:9e:95:7c:00:40:f1:d5:3b:35:f7:31:01:75:68:810 07:aa:0d:d5:f1:d7:37:a0:48:ab:eb:f9:42:80:07:811 18:c1:3e:da:1e812 ASN1 OID: prime256v1813 NIST CURVE: P-256814 X509v3 extensions:815 X509v3 Key Usage: critical816 Digital Signature817 X509v3 Extended Key Usage: 818 TLS Web Server Authentication, TLS Web Client Authentication819 X509v3 Subject Key Identifier: 820 68:0C:90:32:EF:94:E8:BD:A2:BC:61:30:F2:CC:49:3D:44:3D:3A:71821 X509v3 Authority Key Identifier: 822 58:52:D7:0C:8D:60:A0:7C:E2:16:39:01:8C:4F:2C:98:AC:4C:0E:90823 X509v3 Subject Alternative Name: 824 DNS:test.foo825 1.3.6.1.4.1.37476.9000.64.1: 826 0......acme..827 Signature Algorithm: ecdsa-with-SHA256828 Signature Value:829 30:45:02:20:64:8e:14:ea:8d:a9:79:d6:e3:3f:da:ff:84:f7:830 05:94:a5:cc:47:6e:46:d4:19:11:3e:7d:f4:bc:57:d7:55:35:831 02:21:00:df:df:39:a5:5c:02:a5:81:ae:3f:87:aa:dc:fd:53:832 ce:5e:db:6b:44:2b:93:f6:f3:e8:d7:51:2d:c4:d4:56:57833client: (finished: must succeed: openssl s_client -connect test.foo:443 -servername test.foo </dev/null 2>/dev/null | openssl x509 -text -noout 1>&2, in 0.04 seconds)834(finished: run the VM test script, in 16.14 seconds)835test script finished in 16.23s836cleanup837kill NspawnMachine (pid 53)838kill NspawnMachine (pid 55)839Container ca terminated by signal KILL.840kill NspawnMachine (pid 54)841Container client terminated by signal KILL.842Container server terminated by signal KILL.843(finished: cleanup, in 0.64 seconds)